• Alert Flooding

    15
    0 Votes
    15 Posts
    1k Views
    J
    @gertjan I guess that is the "nuclear" option to the original issue, remove the underlying functionality that caused the log entries to begin with...
  • pfSense + Unifi network, LAN works not WIFI

    15
    0 Votes
    15 Posts
    2k Views
    P
    @swemattias nic pass though to pfsense is simpler imo. Hardware off loading can also then still be used
  • get the packet zize

    4
    0 Votes
    4 Posts
    501 Views
    stephenw10S
    Ok, you probably need to use NetFlow data then.
  • Auto configuration backup shows no backups

    15
    0 Votes
    15 Posts
    2k Views
    R
    @steve_b I am looking into moving the users and the certificates of the pfSense machines to a dedicated solution. Thanks for the help with this issue!
  • Export CA | Do I have to pay attention to anything?

    4
    0 Votes
    4 Posts
    537 Views
    stephenw10S
    @slu said in Export CA | Do I have to pay attention to anything?: You mean the CN name or something like this? Yes. Or someones email address etc. Something you may not want public. Steve
  • Different proxy for different interfaces

    proxy interfaces
    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    So you just need to redirect traffic to them in pfSense? You can just use port forwards for that. That's what Squid does if you set it to transparent mode. Steve
  • Static ARP entry through ui?

    17
    0 Votes
    17 Posts
    3k Views
    jimpJ
    Yikes that is ugly. If it's that badly configured, have you tried logging into that random device with default credentials and turning off DHCP? :-)
  • AWS specific support?

    3
    0 Votes
    3 Posts
    295 Views
    I
    @stephenw10 Hi Steve I submitted a post earlier, here https://forum.netgate.com/topic/166622/i-need-to-restart-the-ovpn-tunnels-after-a-pfsense-reboot/2
  • PPPOE wan will not connect -

    113
    0 Votes
    113 Posts
    28k Views
    C
    Read thru most however I have a protectli PFSENSE ( 2.5..2 ) box behind my ISP fiber modem. In the setup i just put in my PPPOE username and password and it set it up and just works. My ISP here in Dubai requires my wan to be connected on a certain port on the modem ( ONT4) Otherr than that it just works and I am not a real technical guy.
  • BufferBloat on Protectli running PFSense 2.5.2

    1
    0 Votes
    1 Posts
    379 Views
    No one has replied
  • (solved) SG-3100 lost console connection after macOS update

    2
    0 Votes
    2 Posts
    236 Views
    wgstarksW
    Solved this issue. It appears that the most recent macOS update disabled the UART bridge used for serial comms. Re-installed the driver from Silicon Labs and everything is working.
  • Gateway monitor / Loss

    3
    0 Votes
    3 Posts
    407 Views
    maverickwsM
    @steveits lol you're amazing :D that's exactly it! Thanks a lot!! Cheers
  • pfsense packet process order

    4
    0 Votes
    4 Posts
    610 Views
    bmeeksB
    @mgcsec said in pfsense packet process order: @stephenw10 thank you! and then where are local services/plugins involved? for example Nginx in that chain? NAT=>FW=>Nginx=>NAT=>FW=>Upstream? For some services, yes, this is the processing order. But for others such as the IDS/IPS packages, this is the processing order: IDS/IPS => NAT => FW (for inbound traffic on WAN) IDS/IPS => FW => NAT (for inbound traffic on LAN)
  • Pfsense not responding to large packet pings

    52
    0 Votes
    52 Posts
    10k Views
    stephenw10S
    Do that have the same capabilities? Try: ifconfig -vvvma Are those vmxnet NICs the pfSense VM has assigned currently? If not try assigning one to something and see if that responds to large packets. This seems likely to be an issue with the bxe driver or the NIC itself but we need to confirm that by, for example, showing vmx is not affected. Steve
  • E-Mail server not updating

    3
    0 Votes
    3 Posts
    402 Views
    N
    Hi Steve - Brilliant suggestion. Evidently my password manager was pre-empting my updates. Now email works! Thanks, Neil
  • SG1100 - High CPU usage after 21.05.1-RELEASE (arm64)

    13
    0 Votes
    13 Posts
    1k Views
    jimpJ
    Aside from pcscd, you should also disable log compression when rotating on there. Given the output from top, it was the log compression that was having trouble keeping up with the rate of logs being written at the time. Status > System Logs, Settings tab, set Log Compression to None.
  • Design help for better control

    24
    0 Votes
    24 Posts
    2k Views
    M
    @johnpoz root cause analysis was suggested in a different forum. Wire shark did capture vlan traffic on port going to ESX host. But pktcap-uw did not capture any on vmnic. Promiscuous mode was enabled too. Switch configuration is correct. Only data point which I still could not figure out is wireshark trace contains icmpv6 but not icmp dhcp discovery. Neither ipv6 is enable on pfsense or unifi.
  • What is the best way to monitor traffic ?

    3
    0 Votes
    3 Posts
    441 Views
    bingo600B
    @rbarden I use NTOP-NG. But nothing is "free" in terms of cpu cycles or promiscious mode on the netcards. /Bingo
  • wan port mode setting problem

    7
    0 Votes
    7 Posts
    770 Views
    c-amgC
    thank you
  • DNS amplification?

    2
    0 Votes
    2 Posts
    275 Views
    stephenw10S
    That doesn't seem like a huge number for 5 mins. I would expect far more if you were actually being used as part of an attack. That seems like it could just be a bad DNS server configured. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.