• negate_networks Empty Table

    2
    0 Votes
    2 Posts
    242 Views
    jimpJ
    It's a default table that is usually populated with local networks that need to bypass policy routing (e.g. LAN to LAN2/DMZ type traffic). It could be empty if you only have one local interface, or if you don't use policy routing.
  • pfsense WAN on private network

    7
    0 Votes
    7 Posts
    2k Views
    S
    @penguin-nut said in pfsense WAN on private network: Disable hardware checksum offload FYI, documented at https://www.netgate.com/docs/pfsense/book/config/advanced-networking.html?highlight=xen#hardware-checksum-offloading
  • Cannot delete "incomplete" device from arp table.

    13
    0 Votes
    13 Posts
    5k Views
    D
    @jknott I'm not going to jump the gun but I think I found it. I'm using Home Assistant for my home automation and inside it I have setup trackers for devices. I ping the devices and if they do not respond I send a message to my phone telling which device is down. In my code I was still pinging those old IP's. Lets hope that was it. Thank you so much for your help.
  • 2.3 release needed for testing

    Locked
    19
    0 Votes
    19 Posts
    1k Views
    ?
    @selianto pfSense 2.3.x is End of Life. As such, we do not offer older releases for download, nor do we support them. If you have an urgent upgrade project, you should consider a Netgate Global Support subscription. The Support team may be able to assist with the upgrade in a way that does not require having to use an outdated image. If you would like more information about a Netgate Global Support subscription, please email sales@netgate.com or if you need help now, you can find our different Netgate Global Support subscriptions here: https://netgate.com/support
  • [Authentication] Password with special character gets rejected?!

    8
    0 Votes
    8 Posts
    1k Views
    8
    Okay. Thanks for the explanation.
  • How long entry should be found in the logs

    8
    0 Votes
    8 Posts
    908 Views
    chudakC
    @jimp Very confusing but ok, thx ! Case to have real syslog server
  • Hostname of pfsense is attached to openvpn file

    2
    0 Votes
    2 Posts
    236 Views
    jimpJ
    There is no way to exclude the hostname, it does this to ensure the filenames are unique between firewalls, so if you connect to multiple firewalls, the filenames are not the same. I'm not sure it makes much difference for the hostname in that context, whether or not you want it to show "pfsense" there or another hostname is up to you.
  • Can't allocate llinfo

    6
    0 Votes
    6 Posts
    3k Views
    jimpJ
    The most common time I see this is when my cable connection renews DHCP and switches to a different subnet. Some states are still pointing at the old gateway which is no longer valid, thus the error. I suspect a similar issue happened there, probably as @heper said, it came from the cable modem. Lots of cable modems will hand you a private address if you lose upstream sync.
  • Port Forwarding

    28
    0 Votes
    28 Posts
    3k Views
    johnpozJ
    Do your sniff, diag packet capture on your lan interface... Do you see the syn to your ftp server private IP... If you do not see an answer its not pfsense that is your problem. Here I just setup a port forward for ftp (21) and can you see me shows closed.. [image: 1548858567386-ftprst-resized.png] See how my client on 192.168.2.11 sent a RST... Basically he said to F off ;)
  • Multi WAN, interference between connections?

    2
    0 Votes
    2 Posts
    279 Views
    stephenw10S
    In what way does the the WAN 'go down'? What do you see logged? Are you running 2.4.4p2? There were some default gateway issues in 2.4.4. Steve
  • LAN ARP Packets on WAN port

    7
    0 Votes
    7 Posts
    729 Views
    S
    Im am using only Cisco 3750 switches in the network. It was 100% opperator error.
  • EAP-TLS Device Authentication

    3
    0 Votes
    3 Posts
    372 Views
    M
    LOL Read the book! Thanks Sir
  • Intel 10GB NIC tcpdump

    4
    0 Votes
    4 Posts
    734 Views
    stephenw10S
    Hmm, so the command remained the same? Just the interfaces in lagg0 that changed? Steve
  • 0 Votes
    8 Posts
    980 Views
    stephenw10S
    Does it do the same on different switch ports? It could be a bad port. It's not any sort of limitation in pfSense. All Gigabit NICs should link at 1Gbps regardless of whether or not the hardware can make full use of that. Steve
  • group manager not available 2.3.4-RELEASE-p1

    9
    0 Votes
    9 Posts
    845 Views
    stephenw10S
    Hmm, that's... unhelpful! Well you can at least update to 2.3.5p2 (or 2.3.6 if you go to the last dev snaphot). If there is some bug you're hitting it may have been corrected. I'm not aware of that specifically though. Steve
  • pfSense stopped recognising cable modem in bridged mode

    16
    0 Votes
    16 Posts
    3k Views
    J
    Just as an update to this. I span up a new VM with a fresh install of pfSense. Copied most of the settings across so it was ready to 'drop in'. I visited the site two weeks ago, shut down the broken pfSense, and booted the new one. Power cycled the cable modem and immediately everything worked. Two weeks in and the cable modem is still recognised and working correctly. So I assume the problem was caused by some sort of corruption in the config file.
  • High CPU load, after reset everthing ok for another 6hours

    2
    0 Votes
    2 Posts
    383 Views
    M
    I think it has something to do with the LCDPROc Packages. Will testing this now
  • Weird issue with large files

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    L3, ie layer 3... Vs L2 - layer 2... That seems to be only a layer 2 switch, so no routing..
  • 0 Votes
    7 Posts
    1k Views
    S
    I've reset the SG. Connection kills are gone. No longer nginx reports in system log. Is there another log that might help dig deeper? because just that error in system log didn't helped identifying the problem.
  • Setting Up a Lab Environment.

    8
    0 Votes
    8 Posts
    1k Views
    bepoB
    @mitch_sullo Sounds correct :-)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.