• VPN and Dedicated servers

    10
    0 Votes
    10 Posts
    996 Views
    G
    @tunnlrat Wireguard is the bomb. You'll get way better performance over it than you will OVPN. Performance will ultimately be based on the power of your router CPU but you will likely be able to push packets at a great rate per second.
  • After Upgrade to 2.6.0 traffic sent over VPN Tunnel sporadically hangs

    4
    0 Votes
    4 Posts
    602 Views
    P
    @stephenw10 Just a quick followup that I figured out the issue to this problem. The problem had to do with a rule cleanup that took place prior to the upgrade. While while the rules that were cleaned up didn't pertain to the VPN traffic directly, it did reveal that the rules specific to this segment's traffic were impacted by two specific issues. 1. The direction of the traffic flow since a floating rule that altered the gateway used existed. and 2. Quick match was not enabled which means the rules pertaining to the traffic were not being applied immediately and were PROBABLY being addressed by a rule downstream. some additional tcpdumps that showed the return traffic hitting the firewall on the new VLAN segment for the VPN, but NOT hitting one of our SERVER VLANS where the request originated. This pinpointed the issue as being firewall related. I didn't want to just dismiss it as a bug without further troubleshooting, but was running out of ideas initially. At any rate, all has been fixed and is working again. Thanks so much again for chiming in!
  • Setup Router behind Router for Testing

    16
    0 Votes
    16 Posts
    1k Views
    stephenw10S
    Could have potentially been this: https://redmine.pfsense.org/issues/13381 Steve
  • PS3 help getting NAT 2 from pfsense 2.6.0?

    20
    0 Votes
    20 Posts
    2k Views
    stephenw10S
    Hmm. Well that implies it requires UPnP. You could test that by disabling UPnP though. And that means it can't work behind double NAT. However if it works by simply disabling the VPN you should be able to simply route the console traffic past it. It seems likely the VPN is changing the default route on the firewall. Or perhaps causing UPnP to show the VPN interface as the external IP. Steve
  • Allow traffic

    firewall rules
    3
    0 Votes
    3 Posts
    942 Views
    R
    @akinori said in Allow traffic: going to let traffic coming from LAN interface going out to WAN and vice versa? By default pfSense will pass all traffic out and in on the LAN interface. WAN blocks all inbound traffic by default and will allow all outbound traffic without any special rules.
  • Pfsense

    newbie networking
    12
    0 Votes
    12 Posts
    2k Views
    M
    Issue with the flux capacitor?
  • Strange Speed Issue with 5gbit AT&T Fiber Upload

    7
    0 Votes
    7 Posts
    916 Views
    stephenw10S
    I would definitely test enabling (or disabling) flow control at the link level on the NIC. Some connections absolutely require that.
  • Responding to port 80 on WAN side

    17
    0 Votes
    17 Posts
    2k Views
    L
    @johnpoz, I've done nothing for you to act so childish in this question and have provided what ever information I can but you just keep on making assumptions and even saying my info is BS. There is nothing mysterious here, it's just something where I cannot share the customers technology. They are doing something that's proprietary and that's that. The only thing I can share is my mention of UDP and that's where it doesn't work with a host, it has to be bare metal. Again, thank you for your help.
  • metronet fiber, internet goes down roughly every 24 hours

    45
    0 Votes
    45 Posts
    10k Views
    stephenw10S
    Yes, that sounds very much like you're hitting that issue. Try setting the supersede option and see if it returns.
  • USB MFA Key and Pfsense Login?

    3
    1 Votes
    3 Posts
    665 Views
    JonathanLeeJ
    @stephenw10 Thanks for the reply!!
  • Mail server rejecting connections

    16
    0 Votes
    16 Posts
    2k Views
    L
    The SIP server is on the same LAN as the phones. It used to be external but it's local now. Different lines use different ports, 5060, 5061, 5062, 5064 on 4 line phones for example but there's also just one phone.
  • Auto Configuration Backup (ACB) is down

    7
    1 Votes
    7 Posts
    864 Views
    geminateG
    Perfect, thanks! Everything appears to be working again.
  • How to create a static NDP entry

    5
    0 Votes
    5 Posts
    883 Views
    E
    @johnpoz Ok, that is great anyway. Really thank you.
  • need help on pfsense setup on virtualbox

    6
    0 Votes
    6 Posts
    2k Views
    stephenw10S
    @bengregory said in need help on pfsense setup on virtualbox: now i can't access gui from pc3 and 4 and can't ping pfsense and can only access the pfsense gui from pc in the virtualbox That's good. That's what I expect to happen unless you have added firewall rules to allow it on WAN and routes to the LAN subnet so PCs 3/4 know how to reach it. They should be able to access the pfSense GUI on the WAN IP if the WAN firewall rules are passing that. Anything you do to make PCs 3 & 4 send their traffic via pfSense is going to be a hack with that network topology. You should have them on a separate layer 2 segment. However to do that you would need to set the pfSense WAN as the default gateway on PCs 3 & 4 dircetly. Then you need firewall rules in pfSense to allow traffic from them into the WAN. And you need a custom outbound NAT rule in pfSense to NAT traffic from the WAN subnet to the WAN address. Otherwise you will have asymmetric routing. This would be a really horrible setup! Steve
  • new pfsense firewall blocks many websites

    20
    0 Votes
    20 Posts
    3k Views
    johnpozJ
    @pirod said in new pfsense firewall blocks many websites: was on static ipv4 I guess. Not sure why. Well if it was static you would of had to have set the IP, etc It defaults to dhcp that is for sure. BTW - still waiting for where you see all the complaints with no answers ;) I see many people complaining the same and no real answers are given.
  • TAC Lite Disassociated with Device

    3
    0 Votes
    3 Posts
    511 Views
    G
    thanks.... Netgate Support got me sorted
  • 0 Votes
    5 Posts
    1k Views
    johnpozJ
    @stepinsky you would need to edit the subject (ie your first post) then you can edit that and add a tag of solved, etc.
  • Slow to NO Internet-Unless using VPN

    6
    0 Votes
    6 Posts
    838 Views
    J
    Now that Frontier has resolved the corruption on their end, my problem is now resolved. Thank you everyone.
  • Problems restoring my config

    Moved
    4
    0 Votes
    4 Posts
    428 Views
    R
    @thedragon said in Problems restoring my config: Is there anything in particular that causes the second set of tags to be added? Yes, the specific software-related bug I linked to caused it. In the next release the double-tag will be ignored.
  • 0 Votes
    7 Posts
    748 Views
    N
    @stephenw10 hi Steve, the version I use is the 2.6.0. In the file config.xml I have tried only to modify the "username" On friday I will test the alternative format in the field "URL" in the config.xml file I will update you thank you for now! regards sblack
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.