• HaProxy Reverse Proxy point subdomain to unique port

    5
    0 Votes
    5 Posts
    754 Views
    G
    @viragomann Sorry the pictures above where outdated, heres my updated frontend information [image: 1671662389854-screenshot_99-resized.png] [image: 1671662389441-screenshot_98-resized.png]
  • Captive Portal bypass issue

    49
    0 Votes
    49 Posts
    10k Views
    GertjanG
    @michmoor said in Captive Portal bypass issue: talking to the netgate team Euh .... the solution was already on the forum. 13747 went from Not a bug, to Duplicate, to Bug again to get solved. I guess it's a question of finding the right words when writing feedback. The official patch, as always, is much nicer : why adding a line if removing something does the job And be careful : https://redmine.pfsense.org/issues/13784 was added on the fly : A MAC can (23.01) be blocked the soft way, the user will see the message that his MAC is blocked. You can chose bewteen an error message, or a MAC block portal page to be uploaded. See here for info and example how to implement that. Or : new, see 13784 : totally rejected : the MAC becomes part of the pf rules that block any interaction with the captive portal interface. I guess the user would be able to get a DHCP lease sorted out, and that's it, nothing more.
  • Increase wap memroy

    5
    0 Votes
    5 Posts
    643 Views
    GertjanG
    @scorpoin said in Increase wap memroy: increase swap memory Re install pfSense. That's the moment you can choose partitions sizes.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    17 Views
    No one has replied
  • Pfsense Crashing

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    Hmm, it seems like something must have changed that is now consistently triggering it. That might be something external.
  • LDAP setup with AD

    2
    0 Votes
    2 Posts
    445 Views
    J
    @jmickens It seems I was using a container name and not a user group. Once I changed to a valid security group, it started working.
  • 0 Votes
    13 Posts
    1k Views
    D
    It seems to have been a DNS issue. The default settings were set to DNS Resolver after factory reset and first setup, which was probably the culprit. I turned it off and turned on the DNS forwarder instead, and now the internet works better than ever! @stephenw10 @Derelict Thanks for your help~ I still don't exactly understand how that was an issue, but it works now. Have a nice day :)
  • Blocking petalbot

    blocking petalbot
    10
    0 Votes
    10 Posts
    3k Views
    johnpozJ
    @lewis no problem - glad you got it sorted..
  • Recommendations for my pfsense setup with 5 nics

    Moved
    58
    0 Votes
    58 Posts
    9k Views
    stephenw10S
    Yes, the firewall rules in pfSense should allow you ping between all the subnets. Or send any IPv4 traffic. The clients in those subnets have to accept traffic from other subnets though.
  • pfsense url not resolved

    21
    0 Votes
    21 Posts
    2k Views
    stephenw10S
    How is that traffic shaping queue defined? What settings have you used? It could be so restrictive that traffic put into it is failing. Try removing the queue from that rule and retest. Steve
  • Adding IPv4 address to pppoe0 failed

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S
    The ISP is handing the gateway as a private IP and that's common for a PPPoE link and not normally an issue. I have that here. But, yeah, using a 192.168.x.x address is far more likely to conflict. However, exactly as I also see, that gateway does not respond to ping. You should set the monitor IP to something further upstream like 8.8.8.8 so you get real monitoring data for the link. Steve
  • Upload values in the speed test

    3
    0 Votes
    3 Posts
    579 Views
    L
    @steveits hi thanks for the reply. I tried what you suggested but unfortunately nothing
  • "The following CA/Certificate entries are expiring" message again

    4
    0 Votes
    4 Posts
    1k Views
    M
    @jimp your description fits my case exactly. Thank you very much, this solved my issue. Have a great day, Mauro
  • Is APU1c good for latest versions of pfSense?

    Moved
    6
    0 Votes
    6 Posts
    616 Views
    J
    @rcoleman-netgate said in Is APU1c good for latest versions of pfSense?: @joea IIRC this is what I did on mine last year. . . . Thanks. Just one more step required.
  • Can't get internet from LAN

    Moved
    10
    0 Votes
    10 Posts
    908 Views
    G
    @stephenw10 Thank you, I was not aware of the « Use non-local gateway » option but setting the gateway using the cli instead of the web interface seems to automatically detect wether it’s local or not and now it working as expected. Thank you all for your time of the explanations.
  • Slow download, fast upload over internet

    9
    0 Votes
    9 Posts
    954 Views
    stephenw10S
    Yep, you would think. Except errors maybe. But worth checking, we've seen weird things like that before.
  • Specifying System ID on non-Netgate Hardware?

    19
    0 Votes
    19 Posts
    2k Views
    stephenw10S
    Yeah, it returns 'pfSense' there intentionally. Anything else would be uncontrolled if it's not hardware we know about.
  • Anyone know what this error could mean.

    32
    0 Votes
    32 Posts
    4k Views
    stephenw10S
    You can read through the thread where this was initially diagnosed here: https://forum.netgate.com/topic/173923/strange-error-there-were-error-s-loading-the-rules-pfctl-pfctl_rules I doubt anything can be learned at this point since the reported errors from there will always be 'device busy'. As shown there we need to see the truss output leading up to the point where is gets stuck which is the first time pfctl is run for this that were hitting it consistently. Steve
  • [solved] Broken Pipe Error - now running

    7
    0 Votes
    7 Posts
    763 Views
    stephenw10S
    Not really unfortunately. None that I'm aware of at least.
  • Blocking certain websites To Certain IPs/Mac address on internal network

    4
    0 Votes
    4 Posts
    659 Views
    stephenw10S
    You would probably want to use the DNS blacklist feature in pfBlocker to filter requests made against the resolver in pfSense. By default pfSense will pass it's own interface IP to use for DNS via DHCP to clients. You can also force clients to use that rather than something hardcoded: https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html You would then add clients you want to be unfiltered as static dhcp leases and set a different DNS server for them to use. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.