• 0 Votes
    16 Posts
    2k Views
    G
    @Gertjan said in Question re slow DNS resolution/General DNS Resolver Options setup/Troubleshooting: @Gertjan said in Question re slow DNS resolution/General DNS Resolver Options setup/Troubleshooting: clog /var/log/resolver.log | grep 'Restart of Followup : Since the last Jun 9 09:29:03 pfsense unbound: [31040:0] notice: Restart of unbound 1.10.1. posted previously, I had no more unbound resstarts. That is : I update pfBlockerNG-devel feeds every 3 days, or less frequent (if they are themselves updated every week, I respect that time frame - no need to update all feeds every hour as seen elsewhere) as pfBlockerNG will restart unbound if one or more of the lists changed. Thanks for the update @Gertjan - I'm not 100% sure what happened, but I think that I might have had a problem with one of the feeds. I did a bit of a cleanup, and got rid of a couple of feeds. The system still restarts, but just once an hour, and it doesn't seem to cause problems with DNS resolution now. I have a script running as we speak that does a dig microsoft.com every 5 seconds until such time as an error occurs. It ran for several hours yesterday, and I have it running again now.
  • Dyndns client fatal erros

    3
    0 Votes
    3 Posts
    498 Views
    GertjanG
    @Clouseau said in Dyndns client fatal erros: [0_1591770268498_PHP_errors.log](Uploading 100%) That error is you failing to upload something to the forum. Like an image : [image: 1591776003251-fb8a71d1-87f4-4196-8857-5b3fd820920b-image.png]
  • Recent config changes keep being lost

    1
    0 Votes
    1 Posts
    260 Views
    No one has replied
  • Port forward to UDP 10000 is NOT working

    1
    0 Votes
    1 Posts
    138 Views
    No one has replied
  • Cannot connect ('passthrough') to IKEv2 vpn remote work server

    7
    0 Votes
    7 Posts
    1k Views
    S
    @DaddyGo ISP router with IKEv2 passthrough (NAT1) + pfSense IKEv2 passthrough(?) (NAT2) + Win10 with VPN client SW) Yes the above is the current setup. As is apparent, I don't know enough about this, but I was trying to apply the same principle to my separate, unrelated internal OpenVPN server. Where I had to passthrough ports on the ISP router for it to work. Win10 (work administered) is using Win10's built-in IKEv2 VPN. I read pfsense cannot be set-up as a IKEv2 client with username /password authentication?
  • VirginMedia - Modem Mode packet loss

    6
    0 Votes
    6 Posts
    735 Views
    C
    What is your pfsense build running on? Is it virtualised by any chance? It may not be the same issue as mine, but I had EXACTLY the same symptoms you are seeing with Virgin Media and their 'super hub' - turned out that it was the Virtual NIC driver which was causing the issues. I wasn't using the latest VMNX3 driver on this specific VM, so I changed that and just like magic all those issues disappeared. As i say, it may be totally unrelated to you but I thought I'd share in case it helped.
  • I keep getting these E-mail's from pfSense

    5
    0 Votes
    5 Posts
    741 Views
    ikifarI
    I haven't received any E-mails today so lets hope so
  • Scripting adding / removing alias host address ?

    2
    0 Votes
    2 Posts
    384 Views
    T
    I've resolved this using: https://github.com/jaredhendrickson13/pfsense-automator
  • Can I access pfsense and local websit using https on same public IP?

    2
    0 Votes
    2 Posts
    216 Views
    JKnottJ
    @Alanesi There is a method where the header is examined for the original URL and the connection forwarded based on that. However, I have no experience with that and it would require something beyond the basic pfSense.
  • 0 Votes
    5 Posts
    703 Views
    stephenw10S
    You probably don't need to go higher than 1M IMO. Currently, at least. Larger tables will cause more effect from 10414 if you're hitting that too. Until 2.4.5p1 is released. Steve
  • pfctl eating too much cpu

    Locked
    2
    0 Votes
    2 Posts
    331 Views
    jimpJ
    https://forum.netgate.com/post/908806
  • sonewconn: pcb: Listen queue overflow flooding logs

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Look at the output of netstat -LaAn and see what port number that pcb corresponds to, and then look at sockstat and see what is listening on that port. That one process is being overloaded with requests, whatever it may be.
  • Route Between two pfSense boxes

    7
    0 Votes
    7 Posts
    559 Views
    W
    The two pfSense boxes can ping ALL of each others' interfaces. But the hosts within each respective Subnet can not be pinged. I think I may have taken a step back in terms of making things work. Here is a new more accurate diagram with some pfsense parameters attached. [image: 1591643514763-untitled.jpg]
  • WOL Service - Not waking up mac mini and pc tower in SMB office

    3
    0 Votes
    3 Posts
    341 Views
    V
    John, will scope those variables out, thanks.
  • I Cannot Access Books on Google Play. (Squid is disabled)

    2
    0 Votes
    2 Posts
    159 Views
    stephenw10S
    Could be any number of things. What error do you see? https://docs.netgate.com/pfsense/en/latest/routing/unable-to-access-some-websites.html Steve
  • 0 Votes
    7 Posts
    895 Views
    L
    Yes, you are right, and this is a little bit complicated situation. Our users complain that they can access sites with "wrong" web server setup directly, but behind squid proxy. And there are many sites (including goverment related), which are still wrong, but needed to be accessed.. on the other hand, nobody can force site admins to update to proper config. Here comes in OpenSSL 1.1.1, which is able to handle this situation. And yes, I do not want to allow accept expired certs in squid. I assume that squid uses pfsense's cert store, but I could not find exact documentation.
  • rc.update_bogons.sh

    4
    0 Votes
    4 Posts
    849 Views
    GertjanG
    @Cornelp said in rc.update_bogons.sh: Anyone knows what this could be? Or where its coming from? These was (still is ?) a cert issue with the root certificate of .netgate.com 5also pfsense.org ?) - the root certificate is used / maintained by the certificate authority. Check out the first 30 or lines when executing manually: curl -v https://files.pfsense.org/lists/fullbogons-ipv4.txt You should find : .. * subject: OU=Domain Control Validated; OU=PositiveSSL Wildcard; CN=*.pfsense.org * start date: Aug 10 00:00:00 2018 GMT * expire date: Aug 21 23:59:59 2020 GMT * subjectAltName: host "files.pfsense.org" matched cert's "*.pfsense.org" * issuer: C=GB; ST=Greater Manchester; L=Salford; O=COMODO CA Limited; CN=COMODO RSA Domain Validation Secure Server CA * SSL certificate verify ok. ...
  • Problem with IPTV from Telenor

    7
    0 Votes
    7 Posts
    1k Views
    E
    Thanks for the answer! After i got the REAL hw that my pfsense will run on, it suddenly worked without promiscous mode, it has 4xIntel NICs, so om guessing the problem i had with the other hw was maybe bad realtek/marvel drivers? Thought it might be usefull info for someone els with the same problem
  • Temperature Monitoring on HPE Gen10 Plus Microservers?

    1
    1 Votes
    1 Posts
    458 Views
    No one has replied
  • Block-Online-Gambling

    Locked
    4
    0 Votes
    4 Posts
    903 Views
    stephenw10S
    What service? Waaaay more info needed. But in general use pfBlocker (DNS-BL) to block sites at DNS level or Squid/Squidguard to filter webtraffic. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.