• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    51k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    83k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • sshguard generate an email

    3
    0 Votes
    3 Posts
    43 Views
    S
    @Gertjan That is a lot of words. For future folks searching config file is /usr/local/etc/sshguard.conf It contains two lines by default. One to tell where the auth log is, the other for the backend / usr/local/libexec/sshg-fw-pf The backend could easily be edited to send a mail. One could also modify the direct executable script that is always running as Gertjan suggests at /usr/local/sbin/sshguard. If one had normal sendmail and were looking for actual logins, could just append: sendmail name@somewhere.com < /root/notice.txt and notice.txt be: xXxWARNINGxXx Failed ssh attempt internal to network xyz xXxWARNINGxXx However we're not that simple, nor do I want a real login. We can't have sendmail. I'll dig into the php and find some way to fiddle with it so that I don't have to figure it out again 2 years from now.
  • STunnel cannot start after upgrade to 26.03

    7
    0 Votes
    7 Posts
    174 Views
    S
    @stephenw10 thank you for your time, Stephen. I look forward to the solution.
  • Is it a bug?

    7
    7
    0 Votes
    7 Posts
    52 Views
    A
    @stephenw10 said in Is it a bug?: If you set the LAN IPv6 type to static with an address then you will be able to disable the service then set LAN as none again. Yes, its was a good idea))) Now KEA DCHP6 server is disabled)))
  • To do 26.03 or not?! That is the question!

    15
    0 Votes
    15 Posts
    477 Views
    GPinzoneG
    @chudak This had to be one of the smoothest upgrades on my 4100 ever. I expected it to take a lot longer than it did. I should note that this was from 25.07.1 to 26.03 as I skipped the problematic 25.11.1 release entirely. I did not need to do anything special, like uninstall PfBlockerNG prior to upgrading.
  • L2TP tunnel struggles to reconnect

    36
    0 Votes
    36 Posts
    420 Views
    A
    Happy to give a hand when you get to the IPv6. I can help coding, reviewing, and or debugging.
  • pFSense vs Unifi gateway / firewall

    41
    0 Votes
    41 Posts
    2k Views
    AndyRHA
    @coxhaus said in pFSense vs Unifi gateway / firewall: My latency is so low right now, but I am sure it will be better. I surprisingly found removing the ATT modem thing lowered my internet latency by 1/3. (3ms or so to 2ms) Lookup WAS-110 and the 8311 project on Discord. 10Gb (provisioned 1.2Gb) into pfSense, 10Gb out to my Aruba switch, which can do layer 3 routing. Speed test is always 1.2Gb with a ping of normally 2ms.
  • Using pfSense to optimize access for media-heavy web apps?

    2
    0 Votes
    2 Posts
    52 Views
    stephenw10S
    It depends! But generally it's better not to implement any of those things unless you are addressing specific problems. So you are hosting this server behind pfSense? And clients are external? What sort of WAN connection do you have?
  • Issue with unresolvable new urltable aliases

    2
    0 Votes
    2 Posts
    49 Views
    stephenw10S
    You are hosting those on the firewall itself? Are they being updated? By pfBlocker perhaps? Do you see the tables populated?
  • License banner "update"

    3
    1
    0 Votes
    3 Posts
    94 Views
    stephenw10S
    Should be fixed now.
  • pfSense keeps crashing

    18
    0 Votes
    18 Posts
    318 Views
    G
    @stephenw10 I have not had time to look t the trace again, will let you know
  • After upgrade to 26.03, multiple WireGuard errors showing in system log

    9
    0 Votes
    9 Posts
    136 Views
    C
    @stephenw10 I changed the client config for my cloud client to be static (i.e. not dynamic) - not sure why I hadn't done that before to be honest. The connection now recovers within seconds after a WireGuard service restart!
  • pfSense Plus - Hardware upgrade help

    5
    0 Votes
    5 Posts
    89 Views
    M
    Thanks very much, @stephenw10. I'll send you the NDI when I start the install this Friday or Saturday.
  • After upgrade to 26.03, IPv6 VIPS do not work on WireGuard interfaces

    6
    0 Votes
    6 Posts
    78 Views
    C
    @stephenw10 yes. Not sure why they didn't seem to be previously. Probably a mistake on my part, sorry.
  • Strange issue with pfSense after move

    4
    0 Votes
    4 Posts
    78 Views
    U
    I got it, restarting the web interface worked. Thanks for all the helpful replies!
  • Unbound SSL handshake failed on every pfBlockerNG DNSBL reload - SG-1100

    5
    0 Votes
    5 Posts
    129 Views
    stephenw10S
    Yes, you almost always want to use Python mode with DNS-BL and Unbound. Especially if you have DHCP registering in Unbound which restarts it often.
  • pfSense LDAP Auth Source Shell Login Issue

    4
    0 Votes
    4 Posts
    99 Views
    stephenw10S
    Mmm, OK let's see if we can replicate that...
  • Installation problems

    8
    0 Votes
    8 Posts
    296 Views
    W
    @nimrod I finally got it working. took out the drive and put into a Sabrent NVME USB C enclosure. Disk manager in Windows 11 pro could not see the pfsense drive. Used MiniTool partition wizard freeware to remove all partitions and format to FAT 32. Crystaldisk Info said drive is at 100% health. So is not defective and total volume was seen. Just in case I did a full format in Windows 11 and came through fine as tested by Crystaldisk Info 100% health. Installed 2.7.2, I know 2.8.1 is the newest version but at setup it asks for a valid WAN connection, my ISP is Community fibre and am not on CGNAT. Since my connection is DHCP 2.5 Gig symmetrical and have tried in the past and it fails to get a connection to Pfsense servers so I have to use 2.7.2. All my Ethernet interfaces were recognised in Console ( two i226 and 2 x550 ). It was strange that when assigning interfaces it took many tries and eventually all were. I used the x550 for WAN and LAN. Backed up my config file to another computer. Then updated to 2.8.1 in Web GUI. Now I have a working Pfsense firewall. But the install problem with 2.8 is a big headache that I rather not go through. SSD in Pfsense is seen as 100% health.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.