• URLs auto update aws ip

    5
    0 Votes
    5 Posts
    776 Views
    T
    Hi Checked the IP list, there are some duplicated IP addresses in AWS IP list. Pfsense do not import the duplicated IP addresses. Thanks!
  • Packet Loss on 2.4.5p1 Similar to what was Reported on 2.4.5

    8
    0 Votes
    8 Posts
    886 Views
    stephenw10S
    In 2.4.5p1 you can leave the max tables value at the default, which is now 400000. 120seconds with no traffic is something significant. I would expect to see something logged. Or at least something in the monitoring graphs, maybe for CPU usage. Try a packet capture on WAN when that's happening. Is anything leaving? Anything coming back? Steve
  • Help diagnosing packet loss

    5
    0 Votes
    5 Posts
    651 Views
    stephenw10S
    Yeah I think if you're really seeing 600Mbps download there with peaks at 800 that loss is just the hardware limits. Steve
  • Firewalling/NAT/Port Problem?

    12
    0 Votes
    12 Posts
    976 Views
    charles_moodyC
    @Gertjan I already have everything in place Intel(R) Atom(TM) CPU E3845 @ 1.91GHz 8GB RAM and 4 Intel NICS [image: 1601488204900-rack.jpg] I know how to set this box up, done that quite a few times to get the desired results; I then followed the guide I posted because of "Things as "security" are as good as the knowledge of the admin", and my knowledge in Network is limited, so I thought to follow a top-post I found on Reddit. As I can't troubleshoot due to limited knowledge, I'll follow your guide and learn along the way. After installing 1400m of CAT6a, 5 new PoE APs, IoT, security and several servers I badly want this network to behave the way I want. Let's see where this journey is leading cheers
  • Health Checks for PfSense

    healthcheck pfsense
    2
    0 Votes
    2 Posts
    1k Views
    johnpozJ
    @nash27 said in Health Checks for PfSense: route53 healthchecks Don't those check from multiple locations? If your blocking access to where those checks are coming from - then yes they would fail. I would assume that if your opening 443 on pfsense to the internet for managment, you would have that locked down to specific IPs - atleast that is what any sane person would do ;)
  • AD Auth cache?

    8
    0 Votes
    8 Posts
    752 Views
    stephenw10S
    I'd have to guess it's because you are locking the account rather than disabling or removing it. AD it probably returning that in some additional string that only applies to Windows and not general LDAP auth. Try running a pcap and see what it's sending if you can. If any of it in unencrypted. I doubt you are the first to hit this. Steve
  • XG-7100 lost power...is it booting?

    3
    0 Votes
    3 Posts
    393 Views
    GertjanG
    inode ... => file system issue .... => repair file system. And probably your UPS is overloaded or the battery isn't what it used to be.
  • NTP not syncing with clients

    ntp ntpd
    15
    0 Votes
    15 Posts
    3k Views
    GertjanG
    @Yo5hi said in NTP not syncing with clients: I just wish that my devices don't have to wait 60-80 secs on boot to sync. So, it boots, asks the time ones - got it, and sets it's own clock, and wants be sure and checks up a second time. It pauses the entire system while waiting for that ?? No RTC, bad NTP implementation ... hummm.
  • Unable to access any network that uses the same ISP as I do

    46
    0 Votes
    46 Posts
    17k Views
    GertjanG
    @AKEGEC said in Unable to access any network that uses the same ISP as I do: Well we have a different opinion about that and that’s ok. All of it ?
  • pfSense-on-a-Stick | Adding VLAN for VPN only

    5
    0 Votes
    5 Posts
    543 Views
    stephenw10S
    Start a continuous ping from a client on VLAN 40. Run packet captures on each interface to see where the pings are going and what's coming back. It's almost certainly a conflict of some sort with symptoms like that though. Steve
  • Email notification configuration

    1
    0 Votes
    1 Posts
    266 Views
    No one has replied
  • Speed issues PPPoE

    40
    0 Votes
    40 Posts
    11k Views
    stephenw10S
    Urgh, well that sucks. But as I understand it the OP here is still using the ISPs modem so it shouldn't apply. Steve
  • diagnose stuttering performance

    13
    0 Votes
    13 Posts
    2k Views
    Raffi_R
    @meem said in diagnose stuttering performance: I can see that I get 30-40 dns HUPS per hour - looking at the settings, I hadn't changed the default lease time for my new VLANS so i've made that change now. It was at the default (2hours)... made it 8 hours now. Looking at my Splunk logs I can see that i've been getting 30-40 HUPS per hour every hour (including throughout the night) That could do it. Hopefully, changing that to 8 hours is enough. I've seen rogue DHCP clients ask for an address every hour regardless of the default setting in pfSense. If changing that is not enough, see if unchecking DHCP registration helps just as test. You then have to decide if your need to lookup hosts by names outweighs having stable DNS, or you can try to track down any remaining rogue DHCP clients on the network not following the 8 hour lease time.
  • Netstat connections X Maximum Concurrent Connections

    Moved
    7
    0 Votes
    7 Posts
    1k Views
    M
    Indeed, when the resolution value for the same period is deepened, the values obtained in the report are different. Below the last 30 days with 01 hour resolution on the same network. [image: 1601384960619-monitoring-traffic-1h.png]
  • pfSense interfering with ssh session to virtual machines?

    3
    0 Votes
    3 Posts
    376 Views
    H
    Just trying to add as much potentially useful info here: Here's two traceroutes in both directions. Run on workstation: traceroute to VM traceroute to 192.168.100.184 (192.168.100.184), 30 hops max, 60 byte packets 1 192.168.10.1 (192.168.10.1) 1.207 ms 1.173 ms 1.158 ms 2 server.localdomain (192.168.10.101) 1.196 ms 1.199 ms 1.198 ms 3 192.168.100.184 (192.168.100.184) 1.459 ms 1.473 ms 1.461 ms Run on VM: traceroute to workstation traceroute to 192.168.10.100 (192.168.10.100), 30 hops max, 60 byte packets 1 192.168.100.1 (192.168.100.1) 0.154 ms 0.130 ms 0.117 ms 2 workstation.localdomain (192.168.10.100) 1.105 ms 1.097 ms 1.085 ms
  • About PFsense Rule Authorization

    2
    0 Votes
    2 Posts
    162 Views
    stephenw10S
    No, not really. Nothing like that exists in pfSense. Steve
  • My pfsense 2.3.5 Atom CPU N270

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    Do you have the full crash report? We need at least the full panic string from the message buffer and the backtrace from the ddb file. But it's unlikely we can do much in 2.3.5. Steve
  • Unable to Mount NVME Hard Drive

    7
    0 Votes
    7 Posts
    2k Views
    GertjanG
    @ProfessorManhattan said in Unable to Mount NVME Hard Drive: If I use this method, can I have a usable hard drive? First, check out what ZFS is. If your pfSense isn't using ZFS right : it is an install option, something you choose at the very beginning. You could compare adding a drive to pfSense as adding a drive to a PC using some Windows OS : It (the SATA port) has to be enabled in the BIOS) and the BIOS has to recognize it. When booting your OS Windows, there will be NO D: or E: that represents the drive. You have to use the DiskManger thing to partition it. And format it using FAT32 or more recent scheme. You have to assign a drive letter. Only then ... you ... can use that D:\ drive - Windows itself doesn't care about it, it lives on the C:\ and won't touch the new D:\ what so ever. FreeBSD drives are mounted using the /etc/fstab file. This file can be edited, and will get overwritten by pfSense whenever it sees fit (upgrades etc). Consider using the EarlyShellCmd and have your drive mounted wherever you want. It will be something like /root/mybidrive/ The directory /root/mybidrive/ will be situated on your new big drive, not the original pfSense drive. You could even do more dramatic things like placing the entire /var/ on another drive but you wind up modifying hardcoded settings and files. It not worth it ... Just re install pfSense on the newer, bigger drive. Don't forget : it's a firewall , not some Desktop PC etc.
  • High Disk Write - php

    3
    0 Votes
    3 Posts
    359 Views
    T
    As it turns out, I have a computer running malwarebytes on my network and it kept trying to report "usage and threat statistics" back to malwarebytes. turning this off seems to have resolved it. I will post back if this reoccurs. Thanks.
  • dpinger gateway packetloss issues

    9
    1 Votes
    9 Posts
    1k Views
    stephenw10S
    Yes, that could be if the limiters never caught that traffic. Glad you were able to resolve it. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.