• AltQ on HN(4) disable

    2
    0 Votes
    2 Posts
    478 Views
    stephenw10S
    Yes, that setting makes no difference if you don't have any hn(4) NICs. And yes they are found in Hyper-V (and Azure). The 'the multi Queue API' here applies only to hn NICs. You sacrificed mutiqueue to enable AltQ there but not on any other NIC. You can apply FQ_CoDel using Limiters, yes. https://docs.netgate.com/pfsense/en/latest/recipes/codel-limiters.html Steve
  • Nokia G-010G-A ONT SFP/SFP+ cable/transceiver module

    Moved
    6
    0 Votes
    6 Posts
    2k Views
    MarinSNBM
    @rcoleman-netgate good to know. Thank so much!
  • pfSense Plus crash after adding OVPN as interface

    openvpn interfaces crash dump
    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    Yes, it could be. I'll try to replicate and open something if there isn't anything already open.
  • LTSP on Vlans Pfsense

    30
    0 Votes
    30 Posts
    4k Views
    A
    @doguibnu I suspect the url mentioned is a place to go for help with the error, not a url being accessed during the boot process. If memory serves (it’s been many years since I’ve done ltsp), after the bios file is loaded via tftp, the initramfs file is loaded via nfs. First step here, however, would be to go to the client machine, and load a local os (from the hard drive or a flash drive, etc - not via netboot), and attempt to manually load the file in question via tftp. If it loads, then the file exists on the ltsp server and is accessible.
  • FIOS connectivity issue

    10
    0 Votes
    10 Posts
    955 Views
    stephenw10S
    Well the port test only checks the initial TCP handshake. It could still be failing later in the sequence for clients. I would probably be trying to get a packet capture of a client failing to connect and seeing exactly how it's failing. Steve
  • pFsense plus download

    3
    0 Votes
    3 Posts
    907 Views
    R
    @slowskull said in pFsense plus download: I own a Netgate 3100, would i be able to download a pfSense plus software and install it on a bare machine? or am I limited to community edition despite I own a physical Netgate machine? At current time there is no means to put Plus on non-Netgate hardware directly. You can download 2.6-RELEASE and get a token to upgrade to pfSense Plus (see this blog for more detail) and then upgrade to 22.01-RELEASE and then 22.05-RELEASE. Your 3100 image is not compatible with any other hardware, either.
  • rules error

    10
    0 Votes
    10 Posts
    998 Views
    stephenw10S
    Mmm, that should have been merged in 3.1.0_0 though.
  • Recent PPPOE Issues - not auto reconnecting for some reason, used to.

    9
    0 Votes
    9 Posts
    980 Views
    stephenw10S
    Ah you have a custom file. pfSense allows you to create the file in /conf and it will use that in preference to anything generated by the gui. That way you can use an entirely custom config if you need something that cannot be set using the gui alone. So at some point you must have created that and usually it would be to add something custom. If you just rename that file and resave the page it should create the expected file in /var/etc from the configured gui settings. Steve
  • Cannot delete/edit VLAN/Assign

    2
    0 Votes
    2 Posts
    307 Views
    hydrianH
    Nevermind. It was a user permissions issue. The user only had read-only rights on the config. Would have been nice if the UI gave me something like "User isn't authorized to do this..."
  • Slow Internet Speeds on pfSense

    7
    0 Votes
    7 Posts
    3k Views
    stephenw10S
    There are a lot of variables so... it's hard to say. If you had a load of lists loaded and relatively low end hardware you might see that. A restriction to 30Mbps is quite extreme of most hardware though. Steve
  • PFSense IoT VLAN and Matter Smart Home Devices?

    3
    0 Votes
    3 Posts
    1k Views
    NogBadTheBadN
    You need an Apple TV or HomePod, the newer versions act as thread routers. It just works with iPhones on one vlan and IOT devices on another vlan, same as it would if you were away from home. For what it’s worth I had nothing but problems with avahi and removed it after a week.
  • Gmail not loging in

    6
    0 Votes
    6 Posts
    414 Views
    stephenw10S
    Ok, so Snort or Squid could both cause this The first thing I would do is try disabling either (or both) and see if that prevents it. Also check the logs of both for blocked traffic when it happens. Steve
  • syslogd Randomly Restarting

    4
    0 Votes
    4 Posts
    640 Views
    stephenw10S
    Yes, that. Check the log files in /var/log. You will be able to see which one is being frequently rotated, it's usually pretty obvious. Then check that log to see why it's being filled so often and reduce that and/or increase the file size. Usually you also see sshguard spamming the system log: https://redmine.pfsense.org/issues/12747 Steve
  • Netgate 1100 dns stops

    50
    0 Votes
    50 Posts
    9k Views
    stephenw10S
    Also on an 1100? That's not the same error, no segfault there. It's not the crypto chip stuck in a bad state. Steve
  • "Non secure" pfSense URL

    Moved
    16
    0 Votes
    16 Posts
    2k Views
    ?
    @dobby_ said in "Non secure" pfSense URL: If someone is interested in build their own PKI at home xCA let you create your own certificates with much more abilities under your full control. xCA It is available for MacOS, Windows and Windows portable. It is nothing you must do. Only if you are interested.
  • slow pfsense IPSec performance

    52
    0 Votes
    52 Posts
    10k Views
    ?
    @mauro-tridici said in slow pfsense IPSec performance: Sure, I will try to apply your suggestions. Should I activate some other option like "Cryptographic Hardware" in addition to your suggested settings? It all depends on the hardware. If AES_NI is in the game I pfSense since 2.6 CE or Plus version will benefit from that but if there is also QAT in the game I would personally upgrade to the pfSense Plus version and try out using the QAT instead. But both together with IPSec AES-GCM.
  • How to access web GUI when internet goes down?

    21
    0 Votes
    21 Posts
    2k Views
    P
    I wanted to give an update. My internet has not been interrupted for 25 days using the QNAP card for both WAN and LAN. I have not tested a crash yet by unplugging the WAN port but eventually I'll get around to trying that.
  • Linux cannot connect to net

    6
    0 Votes
    6 Posts
    626 Views
    ?
    All Linux distros won't connect to the net, internal or external. From internal it could be based on many points here, vlans, firewall rules and and and.... From external it must be over VPN or if you talk about your servers inside of the DMZ it is another point we should now first. It might be sounding strange, but you should be providing us perhaps with some more informations, that we not have to "digging all out of your nose". VLANs, DMZ, LAN or 2 DMZs, who is doing the DCHP job, if more the than one, were all the others set up as a DHCP-Relay or not? What is all installed and activated? pfBlocker-NG Snort & Suricata lightSquid, Squid & SquidGuard Is there another router in front of pfSense? That must be accepting then the private IPs at the WAN, and so on.
  • SSL for pfsense and SS SSL in general

    5
    0 Votes
    5 Posts
    654 Views
    NE_77N
    Thank you everyone- makes sense but wanted to verify.
  • Strange WAN connectivity issue

    3
    0 Votes
    3 Posts
    738 Views
    D
    @stephenw10 I think you hit the nail on the head, I had recently made NAT changes on the Primary side as part of a setup for testing wireguard and went from automatic to hybrid and broke it by creating a NAT to the CARP address that synced to the Backup. Thanks for pointing me in the right direction.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.