• Multiple LANs versus VLANS?

    11
    0 Votes
    11 Posts
    1k Views
    D
    Now that I actually have a little free time, I'm starting to play with my pfsense box like this: -10.1.1.1/24=management LAN -10.20.30.0/24=LAB env., have a few poweredge servers with vsphere 7, TrueNAS Scale, unRAID, might get lucky and learn something configuring Microsoft server 2022 ADDNS/DHCP within vSphere on this LAN. -172.16.1.1/24=Personal, or basic home network for laptops, etc. -192.168.20.1/24=IOT devices I guess May try to figure out using the other two ports for the home and lab LANS.....future endeavor maybe. Directing traffic via firewall rules. Management LAN will have access to ALLOW ALL and ofcourse pfsense GUI All other networks, BLOCKED from each other and also blocked to pfsense GUI I dunno.......it all sounds right in my head. I'm sure I'm missing some things. You guys foresee any issues? Is all this needed? I dunno.... Will I break something? All signs point to yes..... Will I learn something? Fosho!! Will the kids if and when I shut this mother down with some jacked up configs? Ofcourse but.......I grew up without internet, they can go without on it occasion.
  • Snort: Block but don't show alert?

    snort suppress block
    3
    0 Votes
    3 Posts
    1k Views
    L
    @bmeeks : Bummer. But I understand now. Thanks!
  • 0 Votes
    2 Posts
    818 Views
    stephenw10S
    It's because of the new RSC support in the updated hn(4) driver which is apparently broken. It only supports TCP to when you use OpenVPN (UDP) the traffic is unaffected. See: https://forum.netgate.com/topic/169884/after-upgrade-inter-v-lan-communication-is-very-slow-on-hyper-v Steve
  • DDNS doesn't update after Opt1(WAN2) recovery

    7
    0 Votes
    7 Posts
    966 Views
    stephenw10S
    Mmm, OK looks like that bug then. Updates will be on the report as they are found/patched.
  • Pfense/Openwrt : bridge interface > no network on the wireless wifi

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    If you don't need to filter between them then it's better to just have one interface as VLAN10 in pfSense and connect both those things to the vswitch with VLAN10 trunked directly. You usually can bridge VLAN interfaces like that but when you add ESXi that complicates things. You could also try bringing that traffic in untagged to pfSense and bridging those interfaces directly if you need bridging. Steve
  • Wifi interface -> NAS interface for video streaming?

    4
    0 Votes
    4 Posts
    699 Views
    stephenw10S
    In some situations that's all that is required. I have done exactly that on a system with a 'Smart' TV DNLA client and a NAS on different VLANs and it connected immediately. Steve
  • Identify traffic from MAC address or IP?

    2
    0 Votes
    2 Posts
    434 Views
    Z
    All good. Found a way. SSH into pfSense and run pftop -f 'src host 192.168.0.XXX'
  • Pfsense / Windows 10 Pro / File sharing with Iphone.

    13
    0 Votes
    13 Posts
    1k Views
    M
    @johnpoz I finally got it to work. Believe it or not, I experimented quite a bit and finally changed the format from exFAT to NTFS and it started working fine. Goes against everything I read on Google. Who knew you couldn’t trust the internet. ‍️
  • General questions

    15
    0 Votes
    15 Posts
    1k Views
    D
    @stephenw10 very true. Thank you anyway
  • Solved - This system is on a later version than official release ??

    4
    0 Votes
    4 Posts
    769 Views
    bingo600B
    This was prob. a config error from my side ... First i removed (deleted) all the "old patches" [image: 1647969183923-7601eb38-f389-4eea-bb9c-0e5c68602e83-image.png] The system still said it was on a newer version. Then @SteveITS suggested to go to the update , and there i saw it ... My "home box" is still 2.5.2 , and has has this set [image: 1647969047267-f1486378-7058-449f-a5cd-ba0b34f6531d-image.png] That was also set on the new box that runs 2.6.0 [image: 1647968958885-6060f2a6-afe7-4ec4-ac84-35b60c033ff9-image.png] After i changed to 2.6.0 the system showed i was on the latest version Thanks Gents Now i might try to "hand delete the patches" in the xml , and reupload. If you have a backup w. patches applied , and the main box dies , it's not easy to remove the patches , unless doing it in the xml. Edit: It was quite easy to remove all patches from the config.xml You just have to search for the below two XML Tags <patches> </patches> And delete everything between them. Edit2: As i fixed the DNS error too , in the new config.xml. And restored the config again wo patches. The packages was also installed .... All except Avahi , but i was notified about that , and just did an install of that one. Avahi installed wo any probs. /Bingo
  • pfsense freeze

    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S
    @m0l50n said in pfsense freeze: with mSTATA, am I better enable RAM Drive anyway? Not really. It reduces writes but also prevents using some packages and saving crash reports and your will lose some log data in the event of a power outage. With an SSD the drive writes should not be an issue anyway. Steve
  • System Time changed after reboot

    2
    0 Votes
    2 Posts
    402 Views
    stephenw10S
    Did you see anything similar on other VMs? Are you running pfSense 2.6? The system time is determined by whatever the hypervisor is sending for the system clock. If if was using a much earlier time, like 1970/1/1, pfSense will see that and set the clock at boot to the most recent known time source but not if it's ahead already. Steve
  • thinking about 2.5Gbps Switch upgrade, any issues with pfsense?

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    @ghost-0 said in thinking about 2.5Gbps Switch upgrade, any issues with pfsense?: Is this instability due to loops or a poorly configured pfSense? Almost certainly not. If you get a flood created by a loop you will not be able to access anything. Since merely restarting OpenVPN corrects it, and it sounds like that is a WAB connection, my first guess here would be that the default gateway is still set as automatic and is switching to something invalid. But STP loop prevention should only be to prevent loops in the event something is mis-wired IMO. If your switches are connected correctly you should not have any loops. Should I upgrade to 2.6.0? It depends but probably. It will do nothing for STP though. Steve
  • pfSense is slowing down my internet

    Moved
    7
    0 Votes
    7 Posts
    846 Views
    D
    @dinu Issue resolved, I have moved all my VM's to Hyper-V and I am getting 100% band with of 145Mbps download and upload. Thanks for the support guys... Dinu
  • How to block websites with pfsense without proxy?

    3
    0 Votes
    3 Posts
    576 Views
    noplanN
    pfblocker with Dnsbl is your weapon of choice here Python mode and everything is fine and good to go... Block Br np
  • Reboot question

    5
    0 Votes
    5 Posts
    793 Views
    C
    @stephenw10 thank you again!
  • Help resolving MCE crash

    4
    0 Votes
    4 Posts
    683 Views
    stephenw10S
    Ah, yes I've seen a few users hit that with different things. Nice catch!
  • pfsense 2.6.0 hang but I can ping LAN interface

    4
    0 Votes
    4 Posts
    674 Views
    M
    @stephenw10 I think you were right, I change the pfsense for another old one identical but I changed the SD Card and no problem since 4-5 days ... a record since the beginning! Thanks again!
  • Unable to reach GUI after upgrade to 2.6.0, HAProxy Down

    Moved
    1
    0 Votes
    1 Posts
    244 Views
    No one has replied
  • Performance issue on vmware esxi 7

    7
    0 Votes
    7 Posts
    2k Views
    G
    @netnerdy said in Performance issue on vmware esxi 7: Btw, You have to disable hardware large receive offload from advanced settings. Depending on the model of your physical network adapter the vmx adapter may or may not be able to handle hardware checksum offload and tcp segmentation offload. I've been chasing random drops in upload speeds with pfsense 2.6 installed on a esxi VM and this fixed it. Thankyou.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.