• Are pfSense CE and pfSense pro configuration backups compatible?

    2
    0 Votes
    2 Posts
    163 Views
    jimpJ
    It's less about Plus vs CE and more about the config format. Look at the table here: https://docs.netgate.com/pfsense/en/latest/releases/versions.html Note the "Config Rev" column. You can restore an older config revision to a system with a newer revision but not vice versa. See https://docs.netgate.com/pfsense/en/latest/backup/restore-different-version.html for details. Going from CE to Plus there isn't any concern about config items either. Going from Plus to CE anything specific to Plus would end up just sitting unused in the configuration, it wouldn't be removed in most cases.
  • After configuring WireGuard VPN I can no longer log in to my modem

    Moved
    16
    0 Votes
    16 Posts
    674 Views
    sarrasineS
    @stephenw10 Thank you, Stephen, appreciate it!
  • PFsense stops sending traffic after upgrade

    15
    0 Votes
    15 Posts
    683 Views
    stephenw10S
    Hmm, yes the fact it's ARPing for the LAN side gateway and the gateway is responding but it's NOT in the pfSense table does seem to point at the NIC not passing traffic. At least inbound. Yet it appears in a packet capture so the driver is seeing it.
  • How to manage multiple websites behind pfSeense

    10
    0 Votes
    10 Posts
    3k Views
    V
    @nick-loenders Yes, you can do this. But to be accurate, you have to forward a certain destination IP and port to a target IP and port, not domains, pfSense can't see them. So you forward 81.82.120.21:443 to 192.168.10.11:21443 81.82.120.22:443 to 192.168.10.11:22443 81.82.121.23:443 to 192.168.10.11:23443
  • Please , Idont want to reinstall again!!!!

    Moved
    31
    0 Votes
    31 Posts
    1k Views
    stephenw10S
    OutBound NAT. The /1 route being passed by the VPN provider is a more precise route than the default route which is /0. So it would be used in preference. That's likely why you see the DNS states on the VPN interface. That should work. I prefer to set the VPN client not to pull routes from the server and then add policy routing for clients/subnets I want to use the VPN.
  • Exceeded input buffer (on reboot)

    6
    0 Votes
    6 Posts
    278 Views
    O
    @stephenw10 said in Exceeded input buffer (on reboot): It could well have ended up with a newer boot loader when starting from 2.7.2. That could explain the difference. Possibly as I think most times I saw it I had restored from 2.6.x clean install restore and then upgraded. It is certainly an odd error as searching for it exactly yields few results. If it reoccurs I will come back here with a video or screenshot.
  • Large packet sizes fail to send to internet

    19
    0 Votes
    19 Posts
    1k Views
    O
    @stephenw10 said in Large packet sizes fail to send to internet: You can use the new Net Installer to install Plus directly if the NDI is eligible. I had missed that post when it came out. That certainly resolves my concerns once it makes it out of beta. In the meantime it looks like things are stable again and we found the oddities that were causing issues. Thank you for your assistance.
  • pfSense feature request. DHCP Leases: filter by interface.

    7
    0 Votes
    7 Posts
    306 Views
    D
    @SteveITS I'll have to chalk it up to me being super tired yesterday. I honestly did not see that anywhere -- but I've registered now and submitted my comment.
  • How to block an IP address or Mac address

    8
    0 Votes
    8 Posts
    4k Views
    johnpozJ
    @stephenw10 hahah - that could be staged, but it wouldn't be unthinkable that was a legit conversation... I take it that was some video off his doorbell camera or something. Pretty funny either way. But more funny if actually legit conversation.
  • This topic is deleted!

    4
    0 Votes
    4 Posts
    18 Views
    No one has replied
  • pfSense WAN dhcp client exiting (error)

    68
    0 Votes
    68 Posts
    12k Views
    stephenw10S
    Ok testing here....
  • How come no discussion about this April 1 blog post?

    2
    0 Votes
    2 Posts
    259 Views
    stephenw10S
    There were some threads discussing it. For example: https://forum.netgate.com/topic/187100/serious
  • Architecture for securing home network with exposed web server

    37
    0 Votes
    37 Posts
    2k Views
    stephenw10S
    Nope that rule would not have allowed an outbound connection. But none of those prevent inbound connections and once the state is open the replies can use that. However that would require something allowing inbound connection to reach the pfSense VM. So a port forward on the ISP router and another port forward on the pfSense VM to reach the server. You don't have those as far as I know so if you were able to browse the site hosted on the server coming from some external IP address then the connection must have been coming over the tunnel to Cloudflare. That tunnel must have been created outbound from the server when you had a rule to allow it at some point. I would bet that if you had rebooted the server or pfSense at that point the connection would have failed.
  • TLS Error, reconnecting

    Moved
    5
    0 Votes
    5 Posts
    323 Views
    johnpozJ
    @AlexDesro18 said in TLS Error, reconnecting: Wan interface it says it's missing rules. Do you see something like this on your wan? [image: 1713625047575-rulesjpg.jpg] The "wan" needs no rules, but it defaults to having block rfc and bogon.. But maybe he removed those? [image: 1713625115934-rules.jpg] The rfc and bogon are the only rules that would be on your "wan" unless you add something.
  • Pkg Errors After Updating/Installing Packages

    8
    0 Votes
    8 Posts
    494 Views
    D
    I ended up figuring it out by a couple of things. I don't know why the UI was saying up to date, but after running some of the commands and I set the default gateway for the "temp" WAN connection, then the commands started working and the UI started saying update available. There was some kind of connectivity issue resolving the DNS for the repo's and I don't know why hard setting the default gateway made it work, but thats what happened. I was able to update to the newest version and the pkg commands work again. Thanks for the consult.
  • What should I buy? - Netgate Appliance

    5
    0 Votes
    5 Posts
    303 Views
    stephenw10S
    If you need to run HAProxy and pfBlockerNG though I would want a 4200.
  • VPN IPSEC fully disabled Phase 1 blocked on Connecting Status

    3
    0 Votes
    3 Posts
    147 Views
    P
    Hello @stephenw10 Thank you for you reply. Finally, we solved issue. Phase 1 disabled was in Ikve1 config mode and VPN IPsec status blocked on Connecting message indicated ikve2 So we reenabled Phase1 with ikve2 + we force disconnect Phase 1 from vpn status and now it's oks Best Regards
  • Router Locking Up (maybe due to excessive lan traffic?)

    64
    0 Votes
    64 Posts
    6k Views
    X
    @VioletDragon MTU is blank on all interfaces, so I assume default / 1500 In so far as I understand OSI, its all Layer 3. Its all firewall rules, no ethernet rules. No I haven't tried a fresh install. I guess I should do that.
  • Best Network Topology with Current Hardware

    36
    0 Votes
    36 Posts
    3k Views
    S
    @kjk54 said in Best Network Topology with Current Hardware: @stevencavanagh Things are often not what they seem.:) Very true!
  • "Post content was flagged as spam by Akismet.com"

    10
    6 Votes
    10 Posts
    2k Views
    _
    Similarly for me
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.