• Panic String: bpf_mcopy

    30
    0 Votes
    30 Posts
    4k Views
    stephenw10S
    I would expect that to be fine. X520 is quite common.
  • WAN interface - diferent IP and gateway

    9
    0 Votes
    9 Posts
    898 Views
    stephenw10S
    Yes, you can mask that if you need to as long as you replace it consistently in the logs so we can still see it being used. Steve
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • No IP from DHCP on my DMZ

    Moved
    3
    0 Votes
    3 Posts
    412 Views
    C
    @viragomann Thanks, did forgot it was a log to read :) Find the problem, it did look that DHCP was on but it was not.
  • Pfsense bug or hardware

    6
    0 Votes
    6 Posts
    2k Views
    stephenw10S
    I doubt you're actually seeing logs identical to that so please post your logs for review. Steve
  • NO INTERNET TRAFFIC ON LAN

    16
    0 Votes
    16 Posts
    1k Views
    stephenw10S
    @silence said in NO INTERNET TRAFFIC ON LAN: create a firewall rule on wan (to allow traffic please) Um, yeah, don't do that! You don't need rules on WAN to allow traffic to reach Google. What speed are you seeing? What do you expect to see? How are you measuring? Steve
  • I need help to read a backtrace (bt), my pfsense makes kernel panic

    Locked
    4
    0 Votes
    4 Posts
    679 Views
    stephenw10S
    This is a duplicate thread. Please continue here: https://forum.netgate.com/topic/168212/panic-string-bpf_mcopy/12 Steve
  • Pfsense and use of multicore in custom appliance

    3
    0 Votes
    3 Posts
    684 Views
    stephenw10S
    Yes, it will use multiple CPU cores. Especially if you have a bunch of packages installed where loads can be spread more evenly. But, also yes, some things are single threaded. If you need to route at or close to 10G and run things like IPS or ntop then almost nothing would be overkill. Steve
  • Seperate pfSense machine and Proxmox Machine

    8
    0 Votes
    8 Posts
    892 Views
    stephenw10S
    Like I said if you just load all the rules and don't tune anything it will alert and block on most Linux pkg updates. You need to suppress the alerts or disable the rules that are triggering it. https://docs.netgate.com/pfsense/en/latest/packages/snort/suppress-list.html We usually recommend running Snort for a least a week in non-blocking mode whilst monitoring the alerts. Only enable blocking once it's no longer alerting on legitimate traffic. Steve
  • FTTH (AON): Fritz!Box 5530 works, pfSense not

    ftth fiber fritzbox sfp vlan
    27
    0 Votes
    27 Posts
    5k Views
    stephenw10S
    @waldy327 said in FTTH (AON): Fritz!Box 5530 works, pfSense not: Or is it enough to disable "Hardware TCP Segmentation Offloading" "Hardware Large Receive Offloading" Those should be disabled anyway, they are disabled by default so definitely disabled them if you have set them enabled. Hardware offloading requires the driver and hardware to work correctly together. Something that works on an igb NIC might work on ix. It might not even work on a different NIC that also uses the igb driver. They usually do though because those Intels are the best supported. Intel contributes their own driver code to FreeBSD. To disable that as a test you can run at the command line: ifconfig ix0 -vlanhwfilter -vlanmtu -vlanhwtag -vlanhwcsum I had assumed your igb NICs are not SFP? Steve
  • NTP Status Broken?

    16
    0 Votes
    16 Posts
    2k Views
    D
    Well, I somehow resolved it... Sort of, I downloaded the configuration manually edited the XML file, removing the <ntpd>...</ntpd> section. Did a restore of full configuration, after the reboot it works, checked the NTP configuration, all looks the same. Even Debug output is all the same except now both IPv4 127.0.0.1 and IPv6 ::1 query through ntpq work. Only thing I can figure is that there is a hidden or corrupted character in old ntp configuration section.
  • Pfsense Rebooting agin and again...

    Moved
    3
    0 Votes
    3 Posts
    454 Views
    stephenw10S
    Yup could be a bad disk. Can we see the actual output leading up to the reboot? Steve
  • 22.01 ETA still holding up?

    43
    0 Votes
    43 Posts
    9k Views
    S
    My post yesterday was intended as tongue-in-cheek. Microsoft ran into this same discussion with Windows 10, after switching from three feature updates a year to two, then changing the labeling from "1909" to "20H2" because people kept expecting releases in March and September, per the numbers. It seems the misunderstanding here was that the ".01" release would definitely be out in January, not "when it's ready." Changing versioning to "21Q1" may not work with internal version numbering. I don't know if "21.1" for the first release of the year then "21.2" and "21.3" would still fit the stated goal of dating the release but might be a compromise. If one is even needed...setting the "when it's ready" expectation a bit better would be another method. I do understand the point of view where people may have been waiting for the new version to ship routers, and sympathize.
  • Complete newbie - set up guidance please

    15
    0 Votes
    15 Posts
    1k Views
    T
    @jknott said in Complete newbie - set up guidance please: @tymh said in Complete newbie - set up guidance please: Obviously I need to put pfsense in between the modem and the router, Why would you need both pfsense and another router? Now I know more about this, it would be using the Orbi as an AP rather than a router.
  • Reboot or more memory?

    15
    0 Votes
    15 Posts
    1k Views
    L
    Works fine just turning off the service if you don't reboot on a regular basis. I went from really high to 8/9% memory use since yesterday.
  • Trying to use a new 5G modem with pfSense

    5
    0 Votes
    5 Posts
    4k Views
    stephenw10S
    @patch said in Trying to use a new 5G modem with pfSense: you will need to not block local networks on your pfsense Wan The setting that pfSense has for this, Block private networks and loopback addresses, only blocks incoming connections sourced from private IPs. All incoming connections on WAN are blocked by default anyway. Having that enabled does not prevent outgoing connections in a double NAT setup like this. The only time you would need to disable that is if you were trying to connect from a client in the WAN side subnet. So for example if you had a WIFI client connected to the Telstra router and were trying to access the pfSense webgui using it's WAN IP. Steve
  • Setting up firewall - slow

    Moved
    3
    0 Votes
    3 Posts
    585 Views
    P
    @steveits _ Thanks! Let's hope so...it drives me nuts!!
  • pfSense LAG Not Working

    3
    0 Votes
    3 Posts
    485 Views
    stephenw10S
    So... working as expected for you now?
  • Qnap update Clamav antivirus db failed.

    2
    0 Votes
    2 Posts
    629 Views
    stephenw10S
    What error is given? Is this pfSense related? Steve
  • pfSense DIY box - testing interfaces

    2
    0 Votes
    2 Posts
    405 Views
    stephenw10S
    So only output drops on the switch interface? Any drops or errors on the NIC in pfSense? Flow control mismatch maybe? I wouldn't really expect to see any issues with a 1G test over 10G infrastructure. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.