• can not allocate memory error latest firmware

    2
    0 Votes
    2 Posts
    624 Views
    johnpozJ
    @scorpoin said in can not allocate memory error latest firmware: arp: writing to routing socket: Cannot allocate memory could this be related https://forum.netgate.com/topic/152998/arp-writing-to-routing-socket-cannot-allocate-memory or here https://forum.netgate.com/post/976491 You see that error though because it cannot allocate memory in the ARP table for an IP in a subnet the firewall doesn't have an interface in. Which is probably because the re NIC has gone AWOL.
  • Packet Capture

    7
    0 Votes
    7 Posts
    860 Views
    JKnottJ
    @deanfourie Here's a good reference for TCP/IP: TCP/IP Tutorial and Technical Overview
  • L2TP/IPsec VS OpenVPN on pfSense

    6
    0 Votes
    6 Posts
    954 Views
    ?
    @nollipfsense said in L2TP/IPsec VS OpenVPN on pfSense: My use case is both personal, and business (home office) so I'll emulate yours. Hello, a little bit late but for the records it is also pending on what hardware is in usage and for what you need it. pfSense to pfSense I would prefer IPsec with QAT on (if available on both sides) pfSense to other I would prefer IPSec with AES-NI on|-left aligned paragraph Mobile device to pfSense IPSec is your hero OpenVPN became or is the hidden defacto industrial standard WireGuard the future hope IPSec war proofed and spread out widely
  • Command-line for changing the mac address and renewing IP

    17
    0 Votes
    17 Posts
    2k Views
    P
    So I am also interested in this as I have a HA firewall and can only do CARP on the LAN networks. My provider, AT&T, gives me the option of PASS-THROUGH providing "real" WAN IP via DHCP and I lock it down to a single MAC on the Router/Gateway (RG). So my primary firewall has a spoofed MAC on the WAN that matches the one the RG has configured to hand out leases. My standby HA firewall has the hardware MAC on the WAN interface. The primary gets the "real" WAN IP, publicly routable, and the secondary firewall gets a 192.168.5.X IP from the RG. If I spoofed the MAC on the secondary WAN and shutdown the primary then released/renewed on the secondary it would get the "real" IP on the secondary. Now I say it is "real" since AT&T does some type of bridge NAT but the NAT table on the RG is still in play. I am interested in what @chansiuming was looking to do based on my ISP quirks. I could write a simple script to check CARP status and when it becomes MASTER do the down of WAN, spoof MAC, bring up WAN and boom it should work.
  • Netgate Services and Support

    2
    0 Votes
    2 Posts
    299 Views
    stephenw10S
    Do you have general connectivity? Have you tried hitting the refresh button there? That pull the status from ews.netgate.com. That service is functioning normally right now. Steve
  • VMware Workstation VMs Web Traffic Being Blocked

    221
    0 Votes
    221 Posts
    62k Views
    D
    @stephenw10 Oh I see. Yep PCAP was on the VM (172.16.0.202). Yep I don't get it. I see what you're saying and all just can't wrap my head around what is going on here.
  • BOOTP command

    2
    0 Votes
    2 Posts
    421 Views
    stephenw10S
    Those are the changes you made? Can't you just set a static IP to regain access and revert that? Steve
  • Accessing External Port Internally?

    3
    0 Votes
    3 Posts
    439 Views
    C
    @stephenw10 that worked, thank you so much!
  • Did you Ever Edit a pfSense XML Config File in VScode?

    3
    0 Votes
    3 Posts
    623 Views
    stephenw10S
    Never used VSCode but it's just xml. What changes do you need to make though? Usually a config move between hardware should only require re-assigning the interfaces (renaming them in the config). I assume this is a more extensive network change? Steve
  • 2.60 GUI causes services to fail?

    12
    0 Votes
    12 Posts
    1k Views
    stephenw10S
    Hmm, maybe it's failing to rotate the logs at all then. sshguard is enabled for webgui logins whether or not SSH is enabled. Steve
  • pfSense 2.6 & Pushover "Devices"

    4
    0 Votes
    4 Posts
    833 Views
    stephenw10S
    It doesn't look like the error checking includes a 30 character limit there. But even if it did entering a value in the config directly bypasses that. You can open a feature request to include a custom options field: https://redmine.pfsense.org/ Steve
  • DDNS Notification toggle option

    4
    0 Votes
    4 Posts
    616 Views
    stephenw10S
    Yes, that would change it from 01.01 to 12.01.
  • How to configure Comcast "EDI" on pfsense?

    comcast edi lan
    3
    0 Votes
    3 Posts
    1k Views
    stephenw10S
    Also see: https://docs.netgate.com/pfsense/en/latest/firewall/additional-ip-addresses.html Steve
  • Crazy DMZ Port Behavior.

    3
    0 Votes
    3 Posts
    519 Views
    TAC57T
    @stephenw10 Steve, thanks for the input. I guess I'll have to wait for things to go south and your suggestions.
  • 0 Votes
    11 Posts
    1k Views
    stephenw10S
    Both are forms of NAT, translating IP addresses/ports. pfSense just uses the term port forwarding for inbound. Steve
  • Solved: Unknown servers on VLAN

    27
    0 Votes
    27 Posts
    4k Views
    L
    @johnpoz said in Unknown servers on VLAN: @lewis yeah arp scanning is very fast, and most anything is going to answer an arp, even if firewall blocking all protocols and ping, etc. Only problem with that sort of scan is you have to be on the same L2.. But for what your looking for its prob more in line with what your looking to do.. Yes, basically just wanting to make sure I have my own relatively secure LAN (VLAN) network. I'll do it again once everything is up.
  • Authentication Server (LDAP) Missing Client Certificate Option

    15
    0 Votes
    15 Posts
    1k Views
    M
    @stephenw10 Ahh, I see, good to know, thanks!
  • Helium Miner - Port Forwarding Issue

    9
    0 Votes
    9 Posts
    1k Views
    johnpozJ
    @zzkazu said in Helium Miner - Port Forwarding Issue: outlined by "Lawrence Systems" on you tube He says to block the whole planet - normally they put out pretty good info.. I would be disappointed if they said to setup what you had to be honest..
  • Pfsense Auto Config Backup (ACB) down?

    3
    0 Votes
    3 Posts
    264 Views
    dotmaxD
    Now it seems back online. thank you Max
  • Increasing nginx/php-fpm timeout?

    2
    0 Votes
    2 Posts
    765 Views
    S
    @maliaga See if this thread helps.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.