• Import CA from my UCS-Server

    3
    0 Votes
    3 Posts
    851 Views
    stephenw10S
    Yes, export the CA cert, not the key, as x.509 if you want to import it into pfSense.
  • Question on ACB

    5
    0 Votes
    5 Posts
    736 Views
    stephenw10S
    Yes, it's something we would like to see. A new front-end for accessing and managing backups outside the pfSense interface is something we are working towards. Steve
  • WAN shows as down, even when functional

    8
    0 Votes
    8 Posts
    865 Views
    stephenw10S
    Yeah, it depends on the order it was applied and what version that change was made in since I believe there is now code to prevent it. I looks like you hit that new code by switching to a Eth interface and back. Good to know. Steve
  • Restoring from Auto Cloud Backup does not reinstall packages

    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S
    Ah, yup that will do it. And it sure makes for a crappy experience at the client end! Disabling v6 on the LAN in pfSense will prevent it. Or setting it up correctly if your ISP gives you a PD you can use. Steve
  • Restore config to SG-2100 from dissimilar hw

    Moved
    9
    0 Votes
    9 Posts
    1k Views
    M
    Thanks for your help everyone. I had only two interfaces configured (wan1 and lan1) even though the sophos device had 4 physical lans only one was needed. I backed up the Community Edition that was originally installed & configured onto the sophos. I then booted up the Netgate SG-2100 and did a restore through the menu options in the web config. Everything worked for me. I think I might have had to name and/or assign the eth ports. For not being familiar with the product and concerned if help would be available when I needed it this went well for me. I hope it helps anyone in the future who is contemplating a change from the Community edition to the netgate hardware. Thanks again everyone
  • 1 Votes
    3 Posts
    579 Views
    P
    @jimp Thank you for the clarification.
  • Help with ATLS21QGE 7055021

    4
    0 Votes
    4 Posts
    728 Views
    stephenw10S
    If you have build tools on the firewall you have to ensure only the right users can run them or the result, which is an attack surface in itself. Yeah, there are a number of threads here on the forum from people trying to use this card and I don't see anyone who managed to build a driver for it. Steve
  • Memory Usage High in 22.01?

    6
    0 Votes
    6 Posts
    1k Views
    jimpJ
    @areckethennu said in Memory Usage High in 22.01?: I also switched to ZFS. That alone will cause the system to use more RAM than it would with UFS.
  • Since upgrading to 2.6 WAN cuts out every few hours

    12
    0 Votes
    12 Posts
    1k Views
    stephenw10S
    Mmm, it could always be some coincidental fault and nothing to do with the update.
  • Speedtest turns to crap

    6
    0 Votes
    6 Posts
    884 Views
    stephenw10S
    None of that stuff has been necessary for some versions now. But likely won't hurt. If you need custom loader variables though you should put them in /boot/loader.conf.local (create that file). The loader.conf will be overwritten with pfSense changes/upgrades. You see any errors on the interfaces? Anything in the system logs? Clearly not a loading issue. Steve
  • updated to 22.01 - SG1100 high CPU usage '/sbin/pfctl -vvsr'

    16
    0 Votes
    16 Posts
    2k Views
    P
    @bbcan177 said in updated to 22.01 - SG1100 high CPU usage '/sbin/pfctl -vvsr': https://www.reddit.com/r/pfBlockerNG/comments/sk9txi/ip_block_logging_not_working_pfsense_260rc/hvv99s1/?utm_source=reddit&utm_medium=web2x&context=3 Installed the patch and it solved it! Thanks!
  • Redirect WEB to VPN Vanish CLient

    3
    0 Votes
    3 Posts
    263 Views
    stephenw10S
    You can policy route specific destinations to use the VPN gateway but you need to define them. That means it's easy for small sites with static IPs but more difficult for anything with a lot of IPs and almost impossible to match 100% for something like facebook.com. It is possible to define an alias using an ASNumber which can be used. pfBlocker can update that automatically. Steve
  • 0 Votes
    25 Posts
    5k Views
    JKnottJ
    @chpalmer WOW! At least I have worked in an cable head end. I find I tend to know more about some of the things than the "support" people do. Then again, half a century of experience in telecom, computers and networks may contribute to that. When I had a problem with IPv6 about 3 years ago, I found I had to teach even 2nd level support and a senior tech the finer points about it. BTW, I used to do 3rd level support at IBM.
  • pfSense loses WAN/LAN connectivity - Need Help Checking Logs

    3
    0 Votes
    3 Posts
    346 Views
    stephenw10S
    How are those interfaces physically connected? You have log entries there showing the NICs losing link, like the cable was disconnected or whatever they are attached to rebooted. Now I would normally call into question the Realtek NICs have but there are also logs for em0 losing link. Steve
  • 0 Votes
    3 Posts
    433 Views
    stephenw10S
    Hmm, odd. I wouldn't expect anything to change there unless the NICs themselves were changed. Sometimes editing the config file directly is the easiest way. You just have to be careful. It's all too easy to make a typo and end up with something that won't load. Re-assigning interfaces like that is a typical scenario where editing the file is often the simplest solution. You shouldn't need to change anything in the rules, the only definitions using the physical NICs would be the Interafaces and LAGG. Even the VLAN should noy be in your case because they are on lagg0. Steve
  • Upgrade 21.05.2 to 22.01 - no VLAN internet conection

    13
    0 Votes
    13 Posts
    1k Views
    stephenw10S
    OK thanks. There's definitely some issue there. We are trying to pin it down.
  • Noob problem with NAT I think

    10
    0 Votes
    10 Posts
    912 Views
    stephenw10S
    Nice. I would recommend moving to a symmetric routing design though. At some point that will come back to bite you otherwise. Steve
  • The time is 1 hour later

    10
    0 Votes
    10 Posts
    894 Views
    C
    @mer I did have to do some hardware config with my proxmox server that also have pfsense so I did have to shutdown a few minutes. When I did power up everything I notice now the firewall show right time so now everything works :) Feel strange that I have to do a restart of pfsense :) Thanks alot for all the help and support.
  • After restore, no reboot-Halt and problems with packages

    5
    0 Votes
    5 Posts
    667 Views
    stephenw10S
    Yes, if you hit that issue the install/uninstall script hangs when it's finished. That stalls the package reinstall process so any other packages that haven't yet been installed will not be until you kill the script. It should then install the others though. Steve
  • Periodically loss of packets on OpenVPN and on WAN in general

    3
    0 Votes
    3 Posts
    365 Views
    SipriusPTS
    @jknott I know the difference between UDP and TCP. I have started to isolate traffic. You gave me an idea. I will get a raspberry pi, and will connect it to ISP router, and will record any interruptions, to see if it occurs at the same time of my netgate. I've being using pfsense for the pass 5 years (VMs and netgate boxs from small to medium sizes like 7100 series) and never encounter any issue like this, but you know, sometimes after a while we start questioning all the parts.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.