• Using SafeXcel hardware crypto for SSL offloading with HAproxy?

    2
    0 Votes
    2 Posts
    351 Views
    stephenw10S
    I don't believe that's possible. Only kernel mode crypto operations can use SafeXcel, so IPSec or OpenVPN DCO.
  • LAN Errors - Pinpoint

    8
    0 Votes
    8 Posts
    465 Views
    stephenw10S
    Check the MAC stats in the sysctl output. The errors there are shown by type. For example in igb: [2.7.2-RELEASE][admin@t70.stevew.lan]/root: sysctl dev.igb.0.mac_stats dev.igb.0.mac_stats.tso_ctx_fail: 0 dev.igb.0.mac_stats.tso_txd: 0 dev.igb.0.mac_stats.tx_frames_1024_1522: 4687 dev.igb.0.mac_stats.tx_frames_512_1023: 2618 dev.igb.0.mac_stats.tx_frames_256_511: 7200 dev.igb.0.mac_stats.tx_frames_128_255: 27786 dev.igb.0.mac_stats.tx_frames_65_127: 75559 dev.igb.0.mac_stats.tx_frames_64: 722390 dev.igb.0.mac_stats.mcast_pkts_txd: 0 dev.igb.0.mac_stats.bcast_pkts_txd: 26 dev.igb.0.mac_stats.good_pkts_txd: 840240 dev.igb.0.mac_stats.total_pkts_txd: 840240 dev.igb.0.mac_stats.good_octets_txd: 68322288 dev.igb.0.mac_stats.good_octets_recvd: 145377581 dev.igb.0.mac_stats.rx_frames_1024_1522: 24579 dev.igb.0.mac_stats.rx_frames_512_1023: 4478 dev.igb.0.mac_stats.rx_frames_256_511: 9296 dev.igb.0.mac_stats.rx_frames_128_255: 6689 dev.igb.0.mac_stats.rx_frames_65_127: 53689 dev.igb.0.mac_stats.rx_frames_64: 1503308 dev.igb.0.mac_stats.mcast_pkts_recvd: 21 dev.igb.0.mac_stats.bcast_pkts_recvd: 785609 dev.igb.0.mac_stats.good_pkts_recvd: 1602039 dev.igb.0.mac_stats.total_pkts_recvd: 3127575 dev.igb.0.mac_stats.xoff_txd: 0 dev.igb.0.mac_stats.xoff_recvd: 0 dev.igb.0.mac_stats.xon_txd: 0 dev.igb.0.mac_stats.xon_recvd: 0 dev.igb.0.mac_stats.coll_ext_errs: 0 dev.igb.0.mac_stats.alignment_errs: 0 dev.igb.0.mac_stats.crc_errs: 0 dev.igb.0.mac_stats.recv_errs: 0 dev.igb.0.mac_stats.recv_jabber: 0 dev.igb.0.mac_stats.recv_oversize: 0 dev.igb.0.mac_stats.recv_fragmented: 0 dev.igb.0.mac_stats.recv_undersize: 0 dev.igb.0.mac_stats.recv_no_buff: 0 dev.igb.0.mac_stats.missed_packets: 0 dev.igb.0.mac_stats.defer_count: 0 dev.igb.0.mac_stats.sequence_errors: 0 dev.igb.0.mac_stats.symbol_errors: 0 dev.igb.0.mac_stats.collision_count: 0 dev.igb.0.mac_stats.late_coll: 0 dev.igb.0.mac_stats.multiple_coll: 0 dev.igb.0.mac_stats.single_coll: 0 dev.igb.0.mac_stats.excess_coll: 0
  • pfSense 2.7.2 does not display interface description.

    6
    0 Votes
    6 Posts
    609 Views
    stephenw10S
    Yup it's gets added to the config if you make a change to the interface. So I imagine you set the subnet there in the setup wizard and never changed anything since. Anyway glad that solved it!
  • System Shuts Down when UPS does a Self Test

    25
    0 Votes
    25 Posts
    5k Views
    P
    @dennypage Thanks!
  • SG5100 shutting down unexpectedly

    3
    0 Votes
    3 Posts
    429 Views
    P
    @SteveITS Thanks! Have taken my question to that thread.
  • netmap errors since 2.7.x

    19
    0 Votes
    19 Posts
    3k Views
    bmeeksB
    @Cobrax2 said in netmap errors since 2.7.x: Umm, tried to go back to 2.6.x but it seems that the old versions are unavailable for download? Wtf They may not be there long, so grab a copy quickly from this link: https://atxfiles.netgate.com/mirror/downloads/ There are 2.6.0, 2.7.0, 2.7.1, and 2.7.2 images posted at the link. Download the appropriate image for you (ISO or USB memstick) and make sure you save it in case you need to reinstall at some point in the future. Be very careful installing/updating packages with any older version. Be sure you set the repo under SYSTEM > UPDATE > Update Settings to the appropriate version. Failure to do that will result in either the package installation failing, or worse, breaking the install completely by pulling down shared libraries compiled for newer pfSense versions.
  • 2.7.0. 2.7.2 Upgrade Failure

    3
    0 Votes
    3 Posts
    575 Views
    B
    @SteveITS Thanks - I wound up finding this...https://forum.netgate.com/topic/184661/unable-to-upgrade-from-2-7-1-to-2-7-2-unmounting-boot-efi-done-failed/18 Which netted out to reinstalling 2.7.0, its configuration which I had backed up and then upgrading to 2.7.2 -which worked. Happy New year!
  • [Solved] Automatic Configuration Backup no longer works

    7
    1 Votes
    7 Posts
    990 Views
    S
    Hello! It is worth noting that the check_dnsavailable function in system.inc that was improved/patched is also used by other subsystems in addition to acb, such as pkg and dhcp. The change may address weirdness in those areas as well. John
  • SG-2100 Network Interfaces Question

    offloading interface sg-2100
    15
    0 Votes
    15 Posts
    2k Views
    M
    @JonathanLee said in SG-2100 Network Interfaces Question: Happy new year everyone Happy new year to everyone !! =) Going to meet my friend now, Mr. Jack Daniels.. Nice guy.. hehe
  • Sophos XG230 Rev2 Netgate Device ID

    5
    0 Votes
    5 Posts
    598 Views
    M
    @stephenw10 Indeed they are. Will decide which Sophos appliance I’m sticking with. Seen a 2nd hand Netgate 7100 that I am keeping my eye on.
  • After update to 2.7.2, auto-update checker is hopping update branches

    8
    0 Votes
    8 Posts
    831 Views
    stephenw10S
    Yes this is a known issue. It's really only cosmetic but can be confusing. https://redmine.pfsense.org/issues/15019 Yes if you really need to I can remove your NDI so it stops seeing Plus as an available upgrade.
  • NEWBIE - VLAN / L2TP / OpenVPN - Not Working?

    2
    0 Votes
    2 Posts
    332 Views
    stephenw10S
    L2TP over IPSec can work: https://docs.netgate.com/pfsense/en/latest/recipes/l2tp-ipsec.html That's a long list of failures. We'd need to get more info about any one to know more.
  • pfSense & concurrent users

    18
    0 Votes
    18 Posts
    2k Views
    johnpozJ
    @AMSUIT said in pfSense & concurrent users: i did a test with the local website using the Firewall as intermediate, and faced the same problem! Where did you state that? You stated this i had done a test with the same Moodle platform locally in our LAN (with no pfSense in the middle) and it works fine with concurrent 109 students Ok I see now where you redirected it through pfsense.. How exactly did you do that? Locally pfsense would be involved in talking to some website on your own local network and if just routed to a different segment it wouldn't nat. You setup nat reflection?
  • Add Upstream SSL Intercepting Proxy Certificate

    4
    0 Votes
    4 Posts
    681 Views
    stephenw10S
    There is a checkbox to add the CA to the system when you import it if required: [image: 1704047553418-screenshot-from-2023-12-31-18-31-58.png] However in this situation I would add the proxy IP to pfSense specifically so it doesn't need to have that CA. https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#proxy-support Steve
  • Migrating from Sophos UTM Home Use License

    sophos ips ssl reverse-proxy
    10
    0 Votes
    10 Posts
    2k Views
    M
    @jeffshead That is correct. Snort/Suricata operates outside the firewall so to speak so it cannot inspect ssl traffic. There is no mechanism within pfsense to decrypt a flow and send to an engine to inspect. This largely,in my opinion, makes the threat prevention aspect of pfsense quite useless. It would be more useful to have your endpoint mitigation tools on the clients do the protection.
  • Separate LANs unable to see each other

    12
    0 Votes
    12 Posts
    989 Views
    JonathanLeeJ
    @lkh allow windows firewall to approve ping you shouldn’t need to disable defender. Make one rule in windows firewall to approve pings.
  • After update to 2.7.1, Bad Gateway: Nginx

    Moved
    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S
    You might be able to use a driver for the specific hardware rather than the cdce driver. It's possible some specific driver gained support for that hardware in 2.7.1/2.7.2 and that's what changed.
  • High CPU and load very high after updating to 2.7.1 and 2.7.2

    12
    1 Votes
    12 Posts
    3k Views
    C
    I did do that when testing last weekend and I can confirm that with a factory default config the CPU usage and load was greater on 2.7.1 and 2.7.2. This is not an issue with the hardware, or any specify post installation configuration. This is an issue with the base system running 2.7.1 and 2.7.2 on this hardware. is there some log or debug level that i can get you output for that might allow you to narrow down the issue so that I can get this box back to running at normal utilization?
  • host website from home with Dynamic IP

    2
    0 Votes
    2 Posts
    335 Views
    johnpozJ
    @kdmiller61 the request wouldn't be dynamic. And you don't really need a client on some other pc on your network.. Pfsense can keep your IP updated to the dynamic service you are using. It supports no-ip [image: 1703866407195-noip.jpg] Or it prob supports whatever other ddns service you were using. All a ddns does is point to your internet IP, the IP on pfsense wan normally unless pfsense is behind a nat router. Just create your normal port forward rule using your wan address as the destination. This built in alias will know if pfsense wan IP changes. And just forward this to whatever IP behind pfsense.
  • 0 Votes
    3 Posts
    762 Views
    Sergei_ShablovskyS
    @stephenw10 said in Congestion control choose (BBR2, QUICK, RACK, CDG) for music streaming: Unless you're streaming music from or on pfSense itself (which you shouldn't be!) then it makes no difference what pfSense is using for those. Of course, streaming are from separate servers set. The only exceptions to that might be if you're proxying the traffic in pfSense or perhaps routing the stream over a TCP VPN. In this moment - stream traffic not proxying. Additionally most streaming is UDP anyway. Let me correct You: more and more services nowadays using TCP and QUICK. But: —— For instance, Netflix and Amazon Prime use TCP as transport layer protocol, while YouTube has adopted both UDP and TCP protocols. ——
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.