• e6000sw0port3: link state changed to DOWN

    10
    0 Votes
    10 Posts
    1k Views
    C
    @stephenw10 said in e6000sw0port3: link state changed to DOWN: The LAN side DHCP issue could be unrelated. It could be a rogue DHCP server in some other device for example. Check the logs for reported IP conflicts. Hello Steve, Would you be so kind to continue anything you wish to add to this discussion in the other topic? I prepared a post for you there with a reply to your suggestion.
  • wan - lan bridge multicast

    3
    0 Votes
    3 Posts
    479 Views
    E
    @stephenw10 Thanks. I'll try and tell about
  • Home License Use

    Moved
    5
    0 Votes
    5 Posts
    681 Views
    M
    THX @dobby_ i will do that
  • WAN dhclient (DHCP) issues - bug in time intervals?

    34
    0 Votes
    34 Posts
    5k Views
    stephenw10S
    @keyser said in WAN dhclient (DHCP) issues - bug in time intervals?: vlan.pcp Ah, OK I see, it's because the renewals are unicast and don't use the bpf rule. So, yes something similar is required there. Set the tagging on the pf pass-out rule if they are enabled in the dhclient. Let's see...
  • E-Mail Notification SPAM since 23.01

    21
    0 Votes
    21 Posts
    2k Views
    Y
    @jimp it seems it neeeded a restart after I applied the suggested patches. It just stopped the next day. I will keep an eye on it.
  • PC Engines APU2 - 23.01- Working fine

    Moved
    19
    2 Votes
    19 Posts
    2k Views
    Dobby_D
    @fireodo said in PC Engines APU2 - 23.01- Working fine: @dobby_ said in PC Engines APU2 - 23.01- Working fine: Did you get it working? Iam using 23.05 RC and 2.7 now No. There is no kernel module for freeBSD 14 :-( Thanks for that information then I could save the time for searching for an workaround, I was thinking perhaps I have overlooked something or was not able to find it right.
  • No ip on wan

    Moved no ip on wan
    12
    0 Votes
    12 Posts
    1k Views
    J
    It's working thank you. Tomorrow I get the temporary access point for wifi. Cross fingers it goes okay. I'll create a new topic if it doesn't. The problem is the onboard Realtek nic is either bad or just isn't compatible with pfsense.
  • Internet keeps dropping

    Moved
    5
    0 Votes
    5 Posts
    693 Views
    stephenw10S
    Yes, check the logs when this happens, what's actually being triggered? I'd also recommend setting the default v4 gateway in System > Routing > Gateways to WAN_DHCP instead of 'automatic'. Steve
  • pfSense on netgate 6100 stops passing traffic multiple times per day

    16
    0 Votes
    16 Posts
    2k Views
    stephenw10S
    @dragonfly said in pfSense on netgate 6100 stops passing traffic multiple times per day: there was an external IP address that was mercilessly hitting the firewall If it was hitting the firewall I assume I was being blocked? If so adding a different rule to block it wouldn't change anything. Unless the new rule is non-logging and hit rate was so high that the number of block logs was creating a significant load.
  • Change default SSH shell?

    3
    0 Votes
    3 Posts
    556 Views
    F
    @jimp said in Change default SSH shell?: While you can't change the default without affecting things like the menu, you can have ssh start whatever you want. There are not a lot of alternatives available, though. But there is bash which you can install via pkg install bash. Then SSH in with: $ ssh root@x.x.x.x -t bash Be aware if you try to use bash -l it will end up going right into the menu if you use root or admin. As a regular non-root user that should be OK. Alternately, consider either having it run your preferred shell at the end of the tcsh .tcshrc or even patching the menu file (/etc/rc.initial) to run it directly for option 8. Thanks! Well, there were a few options, and I think loading it from .tcshrc sounds like the best option, least intrusive :) I'll give it a go!
  • Delegate on-boarding/off-boarding tasks (user creation and removal)

    3
    0 Votes
    3 Posts
    409 Views
    Dobby_D
    @ferchu Thoughts? MS AD Server or VM with LDAP & Radius role LDAP Server & Radius Server based on Linux or BSD MikroTik RouterOS with user manager (RB1100AHx4 (ARM)) pfSense with captive portal and the only have allowed to enter the CP menue for managing.
  • 0 Votes
    2 Posts
    290 Views
    G
    Shoo, managed to get in using pfsenses' IP from a different vlan. Now time to change my shorts.
  • Netgate 1100 not getting IP address from WAN

    Moved
    4
    0 Votes
    4 Posts
    336 Views
    W
    Well, today my laptop was able to get a proper route and is able to use the internet as would be expected. I have no idea what is different from today as compared to yesterday. "I changed nothing" except that I unplugged the power from both the Netgate 1100 and the Arris S33 router overnight. I powered them up this morning, first the S33 and let it power up completely. I then powered up the 1100 waiting until the Console Menu popped up and then plugged in the S33 to the WAN port of the 1100. The final steps were to plug in my usb to ethernet adapter into the laptop, I then started Wireshark and started capturing packets. No packets were being captured, as expected as the there was not cable connected between the laptop and the 1100. The final step was plugging in the cable to the 1100 LAN port. Wireshark started capturing packets and shortly I had an address and a "proper" looking route: $ ip a show dev enp0s13f0u3 6: enp0s13f0u3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 00:05:1b:b0:6f:f0 brd ff:ff:ff:ff:ff:ff inet 192.168.1.105/24 brd 192.168.1.255 scope global dynamic noprefixroute enp0s13f0u3 valid_lft 6386sec preferred_lft 6386sec inet6 2601:647:cb00:470a::2000/128 scope global dynamic noprefixroute valid_lft 6388sec preferred_lft 3688sec inet6 2601:647:cb00:470a:37d:3b80:545c:c086/64 scope global dynamic noprefixroute valid_lft 86396sec preferred_lft 14396sec inet6 fe80::faff:5f36:799d:482d/64 scope link noprefixroute valid_lft forever preferred_lft forever $ ip r show dev enp0s13f0u3 default via 192.168.1.1 proto dhcp src 192.168.1.105 metric 100 192.168.1.0/24 proto kernel scope link src 192.168.1.105 metric 100 And I could ping ucsc.edu: $ ping ucsc.edu PING ucsc.edu (128.114.119.88) 56(84) bytes of data. 64 bytes from resnet.ucsc.edu (128.114.119.88): icmp_seq=1 ttl=53 time=12.1 ms 64 bytes from resnet.ucsc.edu (128.114.119.88): icmp_seq=2 ttl=53 time=15.0 ms 64 bytes from webops-vip88.ucsc.edu (128.114.119.88): icmp_seq=3 ttl=53 time=11.9 ms 64 bytes from webops-vip88.ucsc.edu (128.114.119.88): icmp_seq=4 ttl=53 time=11.4 ms 64 bytes from resnet.ucsc.edu (128.114.119.88): icmp_seq=5 ttl=53 time=11.1 ms 64 bytes from webops-vip88.ucsc.edu (128.114.119.88): icmp_seq=6 ttl=53 time=11.1 ms ^C --- ucsc.edu ping statistics --- 6 packets transmitted, 6 received, 0% packet loss, time 5008ms rtt min/avg/max/mdev = 11.053/12.102/15.016/1.361 ms Not sure what I learned, I suspect I did something wrong, but for now I'll chalk it up to "be patient" and "never give up" :) Thanks @SteveITS
  • Multicast/IGMP, Bonjour and UPNP Full enable double check?

    5
    0 Votes
    5 Posts
    1k Views
    R
    @rickybaker said in Multicast/IGMP, Bonjour and UPNP Full enable double check?: irect need for any setting. And as far as I can tell, the LAN settings on the Unifi Controller software don't really affect anything without a Unifi Gateway (which I don't have, just the pfsense) lol I found this, my own post, while troubleshooting this exact same issue after creating an IoT subnet VLAN (always document the solutions kids!). @eustachy did you have to enable anything specifically to enable Multicast, Avahi and upnp across vlans?
  • Site to Site with Multi-WAN

    4
    0 Votes
    4 Posts
    579 Views
    M
    Routed IPsec VTI: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/routed-vti.html FRR package: https://docs.netgate.com/pfsense/en/latest/packages/frr/index.html?highlight=frr#frr-package Basically, you would have two tunnels running at the same time at each side and FRR package would run OSPF or BGP dynamic routing protocols.
  • OpenVPN SAML support

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    OpenVPN AS is not the same as OpenVPN. OpenVPN AS is their commercial product, not the open source server/client that is found in pfSense software and others. That is OpenVPN "community" and it does not support SAML as far as I'm aware.
  • 0 Votes
    5 Posts
    673 Views
    M
    @dobby_ thank you, I really appreciated the content of the link you provided. I'm a newbie and this kind of documentation is really important for me.
  • 0 Votes
    4 Posts
    536 Views
    stephenw10S
    Yes, that file, like everything else, is generated from data in the main config. So after a restart manual changes there would be replaced.
  • 0 Votes
    2 Posts
    302 Views
    stephenw10S
    Does it work as expected if you call between internal extensions? In situations like this it's almost always because the PBX is sending it's internal IP address for external devices to connect to with RTP and that of course fails. However that doesn't prevent outgoing audio normally. What states do you see to and from the base-station when the call is connected but no audio is passed? Steve
  • Customisation of syslog priority

    2
    0 Votes
    2 Posts
    285 Views
    stephenw10S
    No, there's no way to do that in the pfSense config.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.