• pfSense behind pfSense: only first ping coming through

    3
    0 Votes
    3 Posts
    463 Views
    A
    @jknott It has direct WAN access too. But that needs to be manually enabled, since it is established via PPPoE. There is also an internal CARP IP. That is the failover part. For normal operation though, it uses the other pfSense as its default gateway. That is the part that is not working.
  • New to pfsense, cant access web from Lan.

    19
    0 Votes
    19 Posts
    2k Views
    johnpozJ
    So the cisco is 172.16.0.1? Or is that pfsense itself? Where is the route? Seems basic routing is beyond your current skill set - so why you would want to complicate it with a downstream router is beyond me. Cisco 2800 switch VLAN2 192.168.1.253, every used port is in no shutdown mode Also you sway every port? The port connected to pfsense, ie your transit network wold not be the same layer 2 network as your 192.168.1 network..
  • Unfortunately a Programming Bug has been detected

    6
    0 Votes
    6 Posts
    619 Views
    empbillyE
    Hello, The server crashed and got stuck in a loop because of the error. I had to perform a new installation "for yesterday". The only problem after I install, copy the config.xml to the conf folder and restart, was that the error regarding partitions name. I was able to check which was the correct disk and with the command: ufs:/dev/da0s2 pfsense loaded correctly. Manual root filesystem specification: <fstype>:<device> [options] Mount <device> using filesystem <fstype> and with the specified (optional) option list. eg. ufs:/dev/da0s1a zfs:tank cd9660:/dev/acd0 ro (which is equivalent to: mount -t cd9660 -o ro /dev/acd0 /) ? List valid disk boot devices . Yield 1 second (for background tasks) <empty line> Abort manual input mountroot> With this step, will it stay permanently or do I need to configure something more?
  • Firwall Maximum Table Entries

    10
    0 Votes
    10 Posts
    4k Views
    DerelictD
    If you would listen to suggestions it would be a lot easier to assist you.
  • SSH Login Attempts

    20
    0 Votes
    20 Posts
    4k Views
    ahking19A
    Thanks. I'll take a look at using the pfBlocker aliases.
  • Custom script in /usr/local/etc/rc.d, execution order/trigger question.

    5
    0 Votes
    5 Posts
    1k Views
    w0wW
    @kpa Thanks.
  • Can't access DMZ from LAN

    12
    0 Votes
    12 Posts
    2k Views
    johnpozJ
    Dude your rules on dmz have ZERO to do with the problem.. You don't need any rules on dmz for lan to talk to dmz.. The return traffic from dmz back to your client starting the conversation with some on dmz would be allowed by the state. Do you have any rules in floating? If not then do a simple sniff on lan - do you see the traffic from your lan host going to your dmz IP your trying to talk to.. Great.. Do same sniff on dmz interface - do you see traffic when you try and talk to dmz? If so then problem on your dmz host. Post back with your sniff results.. I can duplicate this for you in like 2 minutes if you need to see pictures or something..
  • Update Failed

    5
    0 Votes
    5 Posts
    568 Views
    A
    That is our current plan for the AM, I appreciate the input!
  • High Latency on Local ping

    12
    0 Votes
    12 Posts
    4k Views
    R
    @johnpoz No I haven't done it yet. I'll post the update as soon as I redeploy my pfsense box.
  • PFSense packages offline installation?

    2
    0 Votes
    2 Posts
    947 Views
    bepoB
    @mic160 said in PFSense packages offline installation?: I have deployee PFSense in internal network as bridge where no internet is available is it possible that i can install packages like Openvpn and Snort on that by uploading packages through webconfigurator?? or by any other way??? Hello, there is no supported way to do this. You may get this done with downloading packages somewhere and install them with pkg on commandline.
  • pfSense on Routerboard hardware

    3
    0 Votes
    3 Posts
    1k Views
    H
    only netgate's own ARM devices are compatible. its unlikely the drivers needed for that routerboard are available for freeBSD
  • PPTP Problem

    Moved
    2
    0 Votes
    2 Posts
    225 Views
    H
    https://www.netgate.com/docs/pfsense/vpn/what-are-the-limitations-of-pptp-in-pfsense.html?highlight=pptp it's time to move to a different vpn setup
  • Bandwidth limit settings do not work with Squidproxy enabled.

    1
    0 Votes
    1 Posts
    151 Views
    No one has replied
  • login on ttyu0 at night time??

    5
    0 Votes
    5 Posts
    878 Views
    jimpJ
    ttyu0 is the serial console. Do you have your serial console connected anywhere? Maybe if you are connected with a USB serial adapter, when you shutdown the desktop or other PC it's plugged into, it sends a serial break which may make the menu redisplay which would cause that message.
  • Internet Disconnecting after Changing WAN Assignment

    4
    0 Votes
    4 Posts
    468 Views
    GertjanG
    Use another browser, for example a fresh installed Opera ..... and check ^^
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    208 Views
  • Show current time in webconfigurator

    3
    0 Votes
    3 Posts
    417 Views
    H
    Sorry - my fault. I looked for it and could not find it and saw other thread saying, there was none (apparently outdated). Thanks
  • Firewall issue and OpenVPN

    3
    0 Votes
    3 Posts
    482 Views
    johnpozJ
    Lan rules have NOTHING to do with unsolicited traffic TO the server.. Since the server is not creating the connection. Rules are evaluated as the traffic enters an interface from the network the interface is connected too, towards pfsense. If your vpn can talk to everything on this lan network, except this server I would look to as already mentioned firewall on this server.
  • Where are the additional TCP Timeouts? (TIME_WAIT)

    9
    0 Votes
    9 Posts
    2k Views
    DerelictD
    Those FreeBSD tunables (such as net.inet.tcp.msl) are for connections to the firewall itself (like to a web server) and have nothing to do with state timeouts in pf and connections through the firewall. The pf timeouts are in System > Advanced, Firewall & NAT.
  • Xen, pfSence, no web connections.

    7
    0 Votes
    7 Posts
    911 Views
    DerelictD
    Right. you have to upgrade CE to 2.4.3-p1. I don't think this info has been refreshed on the new forum yet. There are other threads on it. Here are the basics for what you need to do for the PV NICs: Install it, shut it down. Add the NICs you want, then in XenServer: Get the VM's uuid # xe vm-list name-label="pfSense B" | grep "^uuid" | awk '{print $NF}' 43fdd0da-73ca-22c0-97f6-0ac47ae82360 Get the UUIDs for the NICs # xe vif-list vm-uuid="43fdd0da-73ca-22c0-97f6-0ac47ae82360" | grep "^uuid" | awk '{print $NF}' 6c9cb724-705a-0449-2176-505dd332431d a4c4ec8f-de68-eab3-69c7-d5b6c8be7b53 25e0d1b6-6d9a-6480-4612-e5aca876a922 71919d5a-000c-b9b3-31ed-21fa1674ba4e 1bf1eaf3-50fe-4a12-c3fa-1341766cee08 7b50e7fd-d6ec-598d-8dd6-6068d5f2765b Turn off the checksum checking in the NICs. Run this for all of them: # xe vif-param-set uuid=6c9cb724-705a-0449-2176-505dd332431d other-config:ethtool-tx="off" Boot the VM and the traffic in should flow through fine on the PV NICs. The other major caveat is the HV NICs (reX) support altq shaping. The PV NICs (xnX) don't.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.