• Access Modem @ 192.168.15.1

    Moved
    16
    0 Votes
    16 Posts
    2k Views
    M
    Hi all, I posted the cause previously. The problem was simply that pfsense was not the default GW on the LAN. GW @ 10.0.0.1 pfSense @ 10.0.0.254 pfSense was set up in parallel to the existing GW so it could be configured to replace the existing GW. As pfSense was not the default GW none of the LAN traffic was being routed there and accordingly the modem GUI could not be accessed from the LAN. Simply adding a 2nd GW of 10.0.0.254 to the workstation, temporarily, allowed the modem GUI to be accessed.
  • Find Lan device IP in WAN Interface Logs

    16
    0 Votes
    16 Posts
    1k Views
    T
    @johnpoz I think bigger box would be fine .. keep in mind i virtualized pfsense vm on a server with 5GB of ram just for it anly 2 instances of suricata activated one on wan and other on one of my lan interfaces and that consumes about 3GB on normal and adding one more instance increase it to 4.5 and go to swap part :D
  • pfSense server unexpectedly halted

    4
    0 Votes
    4 Posts
    566 Views
    stephenw10S
    Ah, well a power cut would explain it!
  • I am looking for HW for pfSense in KVM

    Moved
    5
    0 Votes
    5 Posts
    1k Views
    G
    @dobby_ thx Not long ago, the Odroid H3+ board was introduced. The positive thing is that the MB has 2x 2.5 GB NICs (Realtek, no Intel chip). CPU N6005 If I had known that 1GB of traffic could really handle it, I would have considered buying it. Odroid H3+
  • MTU in PFSense 1436 - how to optimise against rest of network.

    2
    0 Votes
    2 Posts
    907 Views
    stephenw10S
    How are you testing exactly? What hardware are you using for pfSense? I assume the interface MTUs are all at least 1500? Steve
  • Back and Restore pfSense Configuration

    Moved
    6
    0 Votes
    6 Posts
    834 Views
    stephenw10S
    We can convert that for you but you should be able to import it into the 6100 directly. It will ask you re-assign the interfaces from the VLAN on mvneta0 in the 1100 to whatever NICs you want to use the 6100 and then reboot to that. If you have additional VLANs you need or PPPoE interfaces etc it's usually easier to modify the config in advance. Steve
  • Dhcp if block on pfsense?

    4
    0 Votes
    4 Posts
    641 Views
    stephenw10S
    Hmm, well pfSense does have the ability to send different boot files for different client types so you may be able to do that: [image: 1666659180710-screenshot-from-2022-10-25-01-52-30.png] Otherwise you would need to arrange some sort of override for the auto-generated conf file. I thought there might be something build in for that, like there is for mpd.conf, but I cant see anything. Ancient but would probably still work: https://happy-coder.com/2014/06/27/pfsense-custom-dhcpd-configuration/ YMMV! If you do find something that works you might drop a reply here as that looks like the same problem: https://forum.netgate.com/topic/174712/ltsp-on-vlans-pfsense Steve
  • IPv6 Question

    64
    0 Votes
    64 Posts
    11k Views
    stephenw10S
    Mmm, fun*. I'll have to watch out for that.
  • MTU Size somewhere set to 1436

    1
    0 Votes
    1 Posts
    231 Views
    No one has replied
  • Setting host-uniq for PPPoE

    12
    0 Votes
    12 Posts
    3k Views
    R
    @febu see [image: 1666641600688-405070ad-8da8-468b-b50d-7634b0cb8dfd-image.png]
  • pfsense upload slow on hyper-v

    7
    0 Votes
    7 Posts
    834 Views
    stephenw10S
    Almost certainly this: https://redmine.pfsense.org/issues/12873 There are workarounds in the linked thread there for 2.6 if you need to use that. Steve
  • Routing Wireguard Clients via VPN Gateway.

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S
    Huh, interesting I missed that.
  • ipv6 vlan leak

    8
    0 Votes
    8 Posts
    915 Views
    stephenw10S
    Yup. Using VLAN1 bad! https://docs.netgate.com/pfsense/en/latest/vlan/security.html#using-the-default-vlan-1 Steve
  • Hide TCP Blocks in logs

    7
    0 Votes
    7 Posts
    913 Views
    stephenw10S
    Yup, that would work. Traffic blocked by Snort shouldn't appear under the default block rule though. Snort has it's own rule it blocks with in Legacy mode. Or in in-line mode it blocks before the firewall rules are parsed anyway. Steve
  • weird internet access issue

    45
    0 Votes
    45 Posts
    9k Views
    P
    @stephenw10 I will make sure it's set to that, thank you so much for helping me through this! I guess we can close the issue. I think I'm good now. Appreciate it.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    7 Views
    No one has replied
  • pfsense software directory structure on netgate 5100?

    6
    0 Votes
    6 Posts
    753 Views
    R
    @gertjan Thank you. Much easier to navigate. It never occurred to me to access via SSH other than from the serial port. The firewall is located in an inhospitable location that makes it difficult to use a direct connection. I'm on now using Putty.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    16 Views
    No one has replied
  • 0 Votes
    3 Posts
    522 Views
    C
    @stephenw10 Yes, you are correct. That was impacting the system. I first setup a test system in lab with same 2.6 config and performed a webgui update 2.6 to 2.7.0-DEVELOPMENT. On 2.7.0-DEVELOPMENT the system does not exhibit the issues described in first post. On production machine I followed your instructions and applied patch "Disable pf counter data preservation to temporarily work around latency when reloading large rulesets (Redmine #12827)". Issue appears resolved. Thank you!
  • Disappearance of part of my PfSense CE 2.6.0 configuration

    3
    0 Votes
    3 Posts
    424 Views
    stephenw10S
    Or roll back to a snapshot in Proxmox if you have one.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.