• WAN/LAN assignment

    12
    0 Votes
    12 Posts
    1k Views
    stephenw10S
    It's easy to lock yourself out during the creation of the bridge because you would usually reassign LAN and bridge. So if you are connected via the LAN you must take care. As long as you have access via some other means, such as the console, you can just roll-back. Steve
  • ACME certificate renewal requires reboot

    2
    0 Votes
    2 Posts
    491 Views
    stephenw10S
    Yes you need to set the action on the cert for whatever is using it so it starts using the new cert. Steve
  • Issues transferring to new hardware

    13
    0 Votes
    13 Posts
    1k Views
    stephenw10S
    Yup, that should work. Be interesting if it does though, with the same module. Hard to see what's different there.
  • Only getting 5% LAN network speed on Ookla from both LAN's

    8
    0 Votes
    8 Posts
    922 Views
    stephenw10S
    Mmm, there are some USB adapters that will do 2.5G under FreeBSD but.... don't expect that!
  • Thinking of spinning up my own Nextcloud. How do I protect it ?

    10
    0 Votes
    10 Posts
    1k Views
    S
    So you have couple options: • Setup any VPN on pfsense or your NAS and use it to file sharing (NextCloud) service. • Setup NextCloud through Nginx on NAS and setup correct access policies in nginx to access only to share links, and with other access to admin/sharing only from local network or VPN IPs. • Setup NextCloud on NAS and haproxy on pfsense. And do same as above but on haproxy side. Last two options are pretty complicated, and required good knowlege in nginx or haproxy configs. There are no way to limit file sharing service only on firewall/nat. If you open access to share links you automatically open access to admin panel. You must understand that almost all hacked and cryptolocked NASes on web was hacked through file sharing services that expose whole file sharing service to web. And you need limit unrestricted access only to file shares. Any links that not fall into allowed category should be dropped without any access to NextCloud server.
  • 0 Votes
    28 Posts
    8k Views
    M
    @lange-ludo Thanks, I had the same issue upgrading to 2.6.0 and this fixed it for me.
  • Where to look to find issue

    10
    0 Votes
    10 Posts
    1k Views
    F
    On last reply and this can be put to rest. using there device and setting to bridge mode only granted me a day with no notifications and no loss of internet. My guess is that recently they must have implemented something that checks for the nokia router. I only say this because while it's setup as a router and i put my pfsense box in the DMZ of the nokia router no issues whatsoever. Thanks @stephenw10 for replying
  • Bug in Monitor IP ?

    7
    0 Votes
    7 Posts
    884 Views
    R
    The only downside I have experienced with this is when you have a DNS you use tied to monitoring a WAN that is offline -- you lose use of that server.
  • DNSBL native support?

    9
    0 Votes
    9 Posts
    1k Views
    CreationGuyC
    @gertjan Thanks for your preferential answer on trying to gear me in another direction. I simply wanted to know how to do this in a technical manor. I'll research else where.
  • Starlink problem with SG2440 22.05

    38
    0 Votes
    38 Posts
    6k Views
    A
    Update! I heard back from Starlink. They were nice enough to let me know I should only have one router in my network and sent instructions on how to change DNS addresses. I reopened the ticket, explained again, and asked for it to be escalated to a higher tier support so it can be sent to hardware engineering. We will see. Adam
  • pfSense 2.6.0 High latency and packet loss.

    38
    0 Votes
    38 Posts
    7k Views
    stephenw10S
    Ah, then you will hit this: https://redmine.pfsense.org/issues/12954 It's fixed in 2.7 and 22.05. You could upgrade to either of those as a test. With a link exhibiting buffer-bloat that badly you probably need shaping of some sort. You could try using an ALTQ shaper instead. Steve
  • 0 Votes
    5 Posts
    669 Views
    K
    It's always DNS After much experimenting (thanks @stephenw10) I figured out the problem. We use DNS Filter as our upstream DNS resolver. DNS Filter is tied to specific IP addresses and refuses to resolve if the request is coming from an "unknown" address. New network connection was unknown so some addresses that could be resolved locally or were cached worked. Thus why it worked for a few seconds. I finally figured it out when I tried entering IP addresses and that worked. (Hint, 1.1.1.1 is a good webpage to try if you are ever in this situation.) Sigh. My fault.
  • Restoring Pfsense config in a new system with less eth ports

    Moved
    3
    0 Votes
    3 Posts
    527 Views
    J
    @stephenw10 said in Restoring Pfsense config in a new system with less eth ports: If there are NICs in the config that do not exist on the firewall it will ask you to re-assign the interfaces. The same as if you restore a config into a system that uses different NICs/drivers even if the number is the same. With a large number of interfaces it can be easier to edit the config file directly but that does open the possibility of typos as you say. Steve Thank you. Gladly, I use mainly 2 interfaces, so I need to take care of them first and the new device would have at least 2 eth ports, so I'm not worried. Regarding the NICs, I'm not concerned about it because I can lose/overwrite them, I was just wondering if the process breaks.
  • Any issue in changing the pfsense hostname?

    4
    0 Votes
    4 Posts
    864 Views
    johnpozJ
    @jt40 just create a CA in pfsense, then create a cert with that CA and have your browser(s) trust that CA. [image: 1661096763603-cert.jpg] You can put whatever SANs you need to IPs, old name, etc.. I had created this cert way before browsers started limited valid dates to like 398 days or whatever they limit to these days.. So you can see mine is good til 2027, and browser has no complaints about it. Once you create this CA you can create certs for any other stuff on your network that wants a cert, printers gui, switch gui, unifi controller gui, nas gui, etc. etc.. And since you trust the CA in your browser it will be happy with the cert and no complaints. [image: 1661097107451-nas.jpg]
  • Wireguard Routing Problems - Help wanted

    wireguard routing assymetric vpn
    10
    0 Votes
    10 Posts
    2k Views
    G
    @stephenw10 I deleted the WireGuard tunnel then I set it up all over again. Done the same thing at VPS. Rebooted remote VM and pfSense and it started working. I have no idea what happened before but I thanks you for all the support you provided!! Thanks a lot :-) kind regards
  • How to restore the last auto backup through shell

    2
    0 Votes
    2 Posts
    433 Views
    GertjanG
    @kreki1986 There is.. Number 15 : Restore recent configuration List the backup sets (sub menu 1) , and pick for example 01 or 02 to restore, using sub menu 2.
  • Listing Devices Downstream From a Port

    18
    0 Votes
    18 Posts
    2k Views
    stephenw10S
    Did the ifconfig output just not show the interfaces then? What the bridge learns is which MAC addresses are connected to which bridge members. Hard to see how it could not show that.
  • Upload issues in Windows 10 on PF v2.6.0

    2
    0 Votes
    2 Posts
    425 Views
    stephenw10S
    That RSC issue only affects pfSense running as a VM in Hyper-V. So the same client connected via wifi gets the expected upload speed? And that still goes through pfSense? Restrictions if that sort of order are usually either unintentional traffic shaping or a speed-duplex mismatch in a link somewhere. Steve
  • OpenVPN routing problems

    15
    0 Votes
    15 Posts
    1k Views
    G
    Hi all thanks for the support so far but I was sick for the last days and in this meantime the VPS deleted my inactive VM instance so I have to setup my VM and tunnel all over again... I'll try again later and if I don't succed I'll try ipsec or wg tunnel later. thanks for the support kind regards
  • LAN crash with WAN still online

    5
    0 Votes
    5 Posts
    680 Views
    W
    @stephenw10 Thank you
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.