• Sending squid access.log to remote syslog WITH mac address

    1
    0 Votes
    1 Posts
    353 Views
    No one has replied
  • 0 Votes
    4 Posts
    574 Views
    T
    This is still in cron 30 12 * * * root /usr/bin/nice -n20 /etc/rc.update_urltables without suricata installed
  • Multiples crashes, error on different equipment

    Moved
    8
    0 Votes
    8 Posts
    848 Views
    Ozer_imO
    It's been two weeks now that a new router is in place and everything is working properly. It seems that starting from scratch and manually reconfiguring the router without going through the import/export tool has solved the problem!
  • 0 Votes
    3 Posts
    223 Views
    V
    thanks it work.
  • Subnet load/traffic... one or many pfSense boxes?

    5
    0 Votes
    5 Posts
    496 Views
    P
    I guess I'd make that call based on how reliable the hardware is, but generally I try to go for just one box no matter the size. Just because it's an easier setup, easier planning, documentation etc. And usually less money. But there's really nothing wrong with doing your setup. If your main concern is uptime, I'd put one box as central router with multi-WAN and put the other one as HA to automatically take over if the first one fails. I would make a LAN network (VLAN1) for devices such as switches, AP's etc, then two or more VLAN's for users. In the past when I've built large networks I have sometimes created a 22-network (255.255.252.0 subnet mask) just to get a few extra IP's, and sometimes I've limited them to about 50 devices per network, depending on the type of traffic. Smartphones and such is good to keep down in numbers as they broadcast a lot of traffic, but if there's *nix devices it doesn't matter as much. The main thing I go for is to try and keep as much as possible with software, since it's easier to replace one box and restore config than to troubleshoot and replace several boxes. Correctly done, you can even replace a router on remote with a novice customer moving a cable or two.
  • Can't Add OPT interface

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    No problem.
  • Unable to access OpenVPN server externally

    8
    0 Votes
    8 Posts
    552 Views
    stephenw10S
    Yup change it there and re-export the config. Or edit the config on the client directly to use the real public IP. Steve
  • enabled Wan static IP. now have DHCP server added?

    4
    0 Votes
    4 Posts
    464 Views
    stephenw10S
    Good point! Any interface with a static IPv4 address in a subnet large enough to have IPs available to lease.
  • CPU Activity - Possible Problem ?

    6
    0 Votes
    6 Posts
    948 Views
    ?
    little over a year later i find myself here. then i think ok let me scroll down, there are MANY 'zio_free_issue_' i assume this means free/available threads for write capability (zfs - input/output - free - issue - then the rest i assume is threads and then counts or something..) trails off compared to most in the forums i know jack nothin about specifics like this (excluding majority networking) but the labeling makes sense thanks either way to everyone
  • Another rookie pfSense & FiOS setup question

    15
    0 Votes
    15 Posts
    2k Views
    MikeV7896M
    I don't have FiOS TV, which apparently can be a major issue if you do, since some of their newer TV hardware REQUIRES the use of a FiOS router to retain full functionality of the boxes. But without the TV piece, I just have my pfSense box connected to the Ethernet connection on my ONT. I didn't have to do anything fancy for it to work (WAN is set to DHCP), and have no issues getting nearly full speed out of my Gigabit connection. IPv6 is not yet available unless you're in one of the four (possibly five) areas that seem to be in their testing for it. DSLReports is great for provider-specific setup questions.
  • SSH key wiped after reboot

    5
    0 Votes
    5 Posts
    2k Views
    E
    Thanks, this really worked. Disappointed I can't use my CLI Shell to copy across, but at least it's working.
  • 0 Votes
    3 Posts
    506 Views
    J
    @kiokoman , nice. Thanks! I donated $100 directly to the BSD Foundation instead.
  • pFsense on a HP Thin Client, AMD CPU G-T56N

    2
    0 Votes
    2 Posts
    841 Views
    stephenw10S
    Use different NIC types. AltQ is not supported by whatever devices you have. You should avoid USB NICs in general. See: https://docs.netgate.com/pfsense/en/latest/hardware/network-interface-drivers-with-altq-traffic-shaping-support.html In addition to the list linked there we add VLAN interfaces so one option would be to add vlans and apply the shaping on that. Steve
  • Ark server

    2
    0 Votes
    2 Posts
    467 Views
    stephenw10S
    The NAT reflection mode will make no difference to clients connecting externally or to the server itself connecting out. Do you see traffic blocked in the firewall log? Do you see oncoming states opened to the server? Steve
  • Vmware using ZFS mirror mode with 2 virtual hard drives (any advantage?)

    3
    0 Votes
    3 Posts
    373 Views
    stephenw10S
    With two virtual drives you can still recover one from the other if the filesystem is somehow damaged beyond repair. I don't think I've ever seen it done though. Generally if you're running on a hypervisor you probably have a UPS. Steve
  • ntp only connecting to some time servers

    28
    0 Votes
    28 Posts
    3k Views
    JKnottJ
    @nback said in ntp only connecting to some time servers: Fixed it! Set a default gateway for ipv6. You shouldn't have to. That should happen automagically, through router advertisements.
  • Port Forwarding

    14
    0 Votes
    14 Posts
    1k Views
    N
    @stephenw10 Thanks for the link - I will definitely watch.
  • Config changed to OLD configuration after reboot

    2
    0 Votes
    2 Posts
    356 Views
    kiokomanK
    how about Diagnostics / Backup & Restore / Config History ?
  • Snort Start at boot

    3
    0 Votes
    3 Posts
    460 Views
    P
    Thanks for your reply. It worked.
  • Strange issue - not sure how to fix

    93
    0 Votes
    93 Posts
    18k Views
    P
    OK - have removed all the other interfaces from system/routing/gateways, and have left the 1 remaining interface (WAN) as the selected default. No problems connecting to any of the VPN server instances. And DNS resolution remains functional. I will continue to monitor, but it really does appear that this problem has now been solved. Thanks again to @johnpoz and @stephenw10 .
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.