• Unable to ping certain hosts

    4
    0 Votes
    4 Posts
    540 Views
    X
    Hm so it looks like none of the client isolation settings can be enabled when it is in AP mode. But I'll keep an eye on the AP if it happens again.
  • Slow routing speeds

    27
    0 Votes
    27 Posts
    3k Views
    ?
    @stephenw10 said in Slow routing speeds: @hngaminguk said in Slow routing speeds: Only annoyance being that the 2100 states a max of 881Mbps for Firewall (10k ACLs) I am not well versed into knowing how many ACLs I am using but I assume my setup currently has less? So I could likely hit 1Gbps? No, using fewer firewall rules will not allow it to hit 1Gbps between two subnets. Enabling pf to set any number of rules will introduce that overhead. Steve Okay thanks for the confirmation, in that case I will have to go for a 3rd party option such as https://www.ebay.co.uk/itm/Intel-Atom-E3845-4-LAN-3G-4G-4G-RAM-64G-SSD-Fanless-pfSense-Firewall-AES-NI-/114644549859?mkcid=16&mkevt=1&_trksid=p2349624.m46890.l49286&mkrid=710-127635-2958-0
  • Outgoing traffic security?

    6
    0 Votes
    6 Posts
    755 Views
    D
    This would be just one tool of many. True, a smart hacker may try to distribute the transfer over time/destinations. Some aren't that diligent.
  • PFSense UI not detecting externally created certs as server certs

    17
    0 Votes
    17 Posts
    2k Views
    M
    @stephenw10 I needed to add server into the nsCertType and serverAuth into extendedKeyUsage in the x509 extensions but need to add the x509 extensions as a command line arg to openssl, adding them into the config file dosent seem to work. Have to create it this way: openssl x509 -CAcreateserial -req -days 7300 -in $cert_dir/$cert_name.csr -CA $cert_dir/id_rsa.crt -CAkey $cert_dir/id_rsa -passin pass:$ca_pwd -sha256 -extfile <(printf "$extFile") -out $cert_dir/$cert_name.crt the -extfile get the contests of the x509 stuff.
  • PfSense AWS not passing traffic

    Moved
    6
    0 Votes
    6 Posts
    642 Views
    P
    @stephenw10 That got it - many thanks Stephen.
  • ATT poor upload speeds

    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S
    Ah, nice catch. Yeah I'm always suspicious with one bad port on a NIC. If it's physically damaged you're probably OK but if it took an electrical surge is the other port going to fail.... Steve
  • Does bsd tcp hybla apply?

    5
    0 Votes
    5 Posts
    750 Views
    stephenw10S
    Is there a FreeBSD implementation? It would have to exist there before we could use it. I don't see it listed a congestion control algorithm there either. https://github.com/freebsd/freebsd-src/blob/main/sys/netinet/cc/cc.h Steve
  • System Log Errors : send() failed (40: Message too long) !!

    7
    0 Votes
    7 Posts
    830 Views
    stephenw10S
    @stephenw10 said in System Log Errors : send() failed (40: Message too long) !!: With a custom login page? Exactly. Previous reports of this were caused by a bad custom port page that was creating a forward incorrectly. Steve
  • 0 Votes
    4 Posts
    505 Views
    stephenw10S
    Well, for example, traffic sourced from 'vlan_10' should never be leaving the VLAN10 interface. Assuming 'vlan_10' in the VLAN10 subnet. Traffic from the LAN subnet to other devices on the LAN subnet would never pass pfSense at all so the LAN rule there would also never catch anything. Steve
  • Chromecast not working, nothing blocked in log

    5
    0 Votes
    5 Posts
    576 Views
    johnpozJ
    Yeah you shouldn't be using public space internally, unless its your space.. That space is the French telecom "orange" If your devices are connected to the same wifi network and same AP.. pfsense has nothing to do with them talking to each other. And nothing to do with their discovery of each other through some L2 protocol. Discovery of chromecast https://developers.google.com/cast/docs/discovery
  • Upgrade from 2.3.4 i386 to latest 64bit

    7
    0 Votes
    7 Posts
    874 Views
    johnpozJ
    @batrams good to hear ;) You might want to sign up https://www.netgate.com/resources/newsletters if your log into your pfsense every now and then ;) setup the little RSS widget, so then you should see stuff about new versions, etc. [image: 1638719395510-rssfeed.jpg] Or just hang out around here - there is normally quite a bit of whoha about new releases as they come out.
  • uPnP not working properly

    10
    0 Votes
    10 Posts
    3k Views
    S
    Thanks. I'll do that with one of the devices that allows the public address.
  • SG-1100 Unable to Check for Updates

    4
    0 Votes
    4 Posts
    498 Views
    S
    I posted in the wrong forum. Looks like the issue was resolved in the development forum. $ sed -i '' -e 's/%%MIRROR_TYPE%%/srv/; s/%%SIGNATURE_TYPE%%/fingerprints/' /usr/local/share/pfSense/pkg/repos/pfSense-repo-devel.conf
  • Swap ON or OFF in PfSense

    2
    0 Votes
    2 Posts
    2k Views
    stephenw10S
    Unless you have specific concerns about space or drive writes etc just accepting the defaults is fine. In general pfSense should never use SWAP and of you see it swapping it's usually because something is misconfigured. I still have some test systems that run from CF and on those I always disable SWAP because of the limited write cycles there. Steve
  • Weird video scrubbing on trint.com - buffer never completes

    10
    0 Votes
    10 Posts
    1k Views
    K
    @johnpoz just whittling that down now. We don't think we've made any changes, but another service that streams has just started misbehaving on domained machines too. It effects all browsers so we are investigating the build... And as I type I am thinking the only other thing is ESET Antivirus updates as this all started happening at the same time. Servers are unaffected, byod too.
  • Random disconnects

    3
    0 Votes
    3 Posts
    576 Views
    stephenw10S
    @artifice said in Random disconnects: I have been having some issues with the following error That is not an error. That shows dpinger starting and the values it's using. That typically indicates the WAN disconnected and reconnected but could be something else. We need to see a more complete set of logs surrounding the incident really. Steve
  • Crash Report

    14
    0 Votes
    14 Posts
    1k Views
    stephenw10S
    If it fails to mount root because of filesystem damage you can run a manual check: https://docs.netgate.com/pfsense/en/latest/troubleshooting/filesystem-check.html#manual-filesystem-check Steve
  • Proper UPS management

    12
    0 Votes
    12 Posts
    1k Views
    stephenw10S
    Ah, yes the UPS can simply not supply power again until it has charged to some specified level. Assuming it can be set for that.
  • NRPE3 process 100% CPU load

    3
    0 Votes
    3 Posts
    566 Views
    stephenw10S
    You could be hitting the route-to/reply-to bug that was fixed in 2.5.2: https://docs.netgate.com/pfsense/en/latest/releases/2-5-2.html#rules-nat https://redmine.pfsense.org/issues/11805 Though I agree the nrpe service should not behave like that. That's probably an upstream bug though. Steve
  • Difficulty access the internet using my VLAN as an Guest Access Point

    36
    0 Votes
    36 Posts
    3k Views
    stephenw10S
    These are worthy topics for discussion but we are derailing @cxcmax's thread I suggest moving to a new thread in off-topic to discuss VLANs in general. Thanks. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.