• PfSense dropping wan ip

    2
    0 Votes
    2 Posts
    218 Views
    S
    All, Succeeding some further investigation the issue at hand seems to be due and related to the Gateway Monitoring Deamon requiring some modest adjustment in configuration parameters. I cannot say with categorical certainty it was due to the upgrade from 2.5.2 to 2.6, but surely did become evident in succession the upgrade. That said, some additional configuration changes were made to the router configuration thereafter as well, so perhaps something changed unintentionally. One thing to note: If you have your WAN and LAN ports both running over one Ethernet port using VLANs (as I do), then it is important to assure that a drop of the WAN IP address does not cause the port to get shutdown as this could make it very difficult to access. That said, nothing prevents access to the router from the console. Thus, the issue can now be declared resolved. Stuart
  • Upgrading from CE to Plus (Home or Lab), downsides?

    Moved
    3
    1 Votes
    3 Posts
    544 Views
    stephenw10S
    As a home user not really. You can always reinstall 2.6 if you really want to. Steve
  • Is there a command to view current cpu clock speed?

    15
    0 Votes
    15 Posts
    5k Views
    B
    @stephenw10 said in Is there a command to view current cpu clock speed?: How did it show those things enabled? The second output is after enabling it? In the BIOS? powerd relies on some driver to actually control the cpu speed, est(4) for Intel CPUs. And that relies on either hard coded values or, far more commonly, values passed to it by ACPI. It's not unusual for those to be wrong or missing unfortunately. Steve No both outputs are taken right after one another it shows the proc jumping all around to different clock speeds as the processor sees fit. My guess is the usage of hwpstate_intel is what allows the different visibility into the two different operating systems. https://www.freebsd.org/cgi/man.cgi?query=hwpstate_intel&apropos=0&sektion=4&manpath=FreeBSD+13-current&arch=default&format=html
  • Pfsense theme 5 coloums makes the theme useless

    7
    0 Votes
    7 Posts
    792 Views
    stephenw10S
    Because 12 divides by 1,2,3,4 and 6 but not 5.
  • "pcscd PC/SC Smart Card Daemon" ?

    70
    0 Votes
    70 Posts
    32k Views
    chudakC
    @jimp that's what I meant :) Thank you !
  • Using pfSense for website hosting protection

    4
    0 Votes
    4 Posts
    2k Views
    S
    @jimfreeze An IDS package like Snort or Suricata has rules that can look for things like SSH attempts or other web requests. There isn't a great way to block specific URLs but maybe you can write your own rules if you're really familiar with doing so. I would read up on implementing it in the forum here before jumping in, and not block by default for a while until you can observe what alerts are being triggered.
  • PHP error in outgoing NAT page

    9
    0 Votes
    9 Posts
    964 Views
    S
    Hi! I cant describe how it happends.. its. long time ago... . Thanks.. this fixed it also for me! ""Remove empty rule <rule></rule> from <outbound>" in the config file."
  • Changing Resolution on VGA Console

    16
    0 Votes
    16 Posts
    8k Views
    R
    @sergei_shablovsky hint.sc.0.flags should be "0x0080" for VESA, not "0x180", per the man page here: https://www.freebsd.org/cgi/man.cgi?query=sc&sektion=4 So for mode 279 (1024x768x16), in /boot/device.hints it should be hint.sc.0.at="isa" hint.sc.0.flags="0x0080" hint.sc.0.vesa_mode="0x117" and in /boot/loader.conf make sure you have kern.vty=sc
  • Random network connection issues

    4
    0 Votes
    4 Posts
    614 Views
    stephenw10S
    Unable to connect to some random sites like that is usually either an MTU issue or a bad subnet mask somewhere. Since you're unable to ping or even reach the first hop in a traceroute it's unlikely to be MTU so check the routing table for some bad route. Steve
  • Segmentation fault when attempting to upgrade 2.5.2 -> 2.6.0

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S
    Yes, it's only 5.2 that is no longer supported upstream and was removed. The expected behaviour is that the package would simply be removed at upgrade. But that is not the case currently. So if you have zabbix_agent52 installed it should be removed before upgrading until we get a fix in. Steve
  • vnstat makes weird stats on my pppoe0 interface

    6
    0 Votes
    6 Posts
    669 Views
    stephenw10S
    Mmm, those are not specifically defined. That is the correct file though, you can see where the process is started here: /usr/local/etc/rc.d/vnstatd.sh
  • Can pfSense utilize client certs for authentication with LDAP server?

    2
    0 Votes
    2 Posts
    372 Views
    jimpJ
    CE cannot, Plus can.
  • pfSense GUI/SSH unresponsive and some routing breaks

    7
    0 Votes
    7 Posts
    959 Views
    stephenw10S
    The console may seem unresponsive when you connect to it after this has happened but try entering ctl+t. That can often produce a response when nothing else will and shows what process the system is waiting on. Also if you can log the serial output during the issue there may be an error show there that cannot be written to the system log. Steve
  • Potential DNS Rebind attack detected

    3
    0 Votes
    3 Posts
    683 Views
    stephenw10S
    If the firewall is actually configured with that FQDN it won't throw that warning.
  • 0 Votes
    6 Posts
    816 Views
    stephenw10S
    If your switch is pulling a DHCP lease you can see is current but you can't connect to it it might be time to reset it. Make sure you're using a client in the same subnet. It may well block connections from outside it's own subnet by default. Steve
  • Setting up high availability LDAP authentication using FreeIPA

    1
    0 Votes
    1 Posts
    212 Views
    No one has replied
  • Showing Traffic Stats on the last 30 Days on Grafana

    5
    0 Votes
    5 Posts
    812 Views
    Gamienator 0G
    Thanks for all your help, I wrote my own solution now: https://github.com/Hornochs/pfsense_trafficstats_into_influxdb I parse in a python script the data of vnstat and push it into a database. I still have to figure out, why vnstats thinks on my pppoe interfac I have a transfer of 4 GB when I'm reconnecting.
  • VPN with ExpressVPN cut bandwidth by 80%

    7
    0 Votes
    7 Posts
    925 Views
    D
    @stephenw10 Echo the above comments entirely. Super important you run a CPU that supports Intel aes ni instructions too - it's got a lot work to do with the encryption remember. Without I'd expect about what you're getting. I'm getting well over 400mbs from nordvpn with my i3-5010U setup on a 500mbs line which is fine for me. You're going to need some pretty serious hardware (well above 300 bucks) if you're looking to get anywhere near your line speed with any VPN provider. Prepare to get your wallet out again. All that said - your super fast line is probably costing fairly serious cash so I wouldn't consider say a cost equivalent to a year or two's subscription disproportionate for the router.
  • the network does not rise after turning off the power

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    If you remove one of the configured interfaces and reboot it will ask you to re-assign the interfaces at the console. That's how pfSense has always worked. Simply removing the Ethernet cable so it has no link obviously does not do that though. If you add new interfaces that use the same driver as existing NICs the interface order may be renumbered but they would still exist so you wouldn't be asked to reassign. Exactly what interfaces are you using here? You have mentioned both wifi and USB interfaces but no specifics. Steve
  • Oddness of Traffic Status, RRD Sumary and NTP...

    7
    0 Votes
    7 Posts
    448 Views
    provelsP
    @stephenw10 Thanks. I will, and I think I've read that host time sync is only for maintaining the VMs time when the VM is off, but conversely it doesn't seem the host should loop with the VMs NTP either. I'll give it a try and delete all the present RRD data since it's corrupt anyway. Thanks again.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.