• LAN cannot access internet

    Moved
    16
    0 Votes
    16 Posts
    2k Views
    johnpozJ

    @syorke what part are you not getting that if your rule says only 192.168.1/24 can use this interface with the lan2port subnets, how would 192.168.0.x be able to use it?

    You need to allow both 192.168.1 and 192.168.0 - you can do that with a 2nd rule, you could do that with using a cidr of 192.168.0/23 you could create an alias that has both networks in it.. Or you could just make it an any with the "*" like your antilock out rule.

    No you shouldn't use a modem vip I created for use on my network.. I posted up a screen shot of my outbound nats - I highlighted the part you should be looking for that downstream network to be in.

  • Dpinger issue

    10
    0 Votes
    10 Posts
    732 Views
    dennypageD

    @cheleby Were you able to start dpinger via the command line to check the error as @stephenw10 suggested?

  • Confused since the introduction of pfSense Plus

    3
    0 Votes
    3 Posts
    643 Views
    S

    @louis2 said in Confused since the introduction of pfSense Plus:

    Could I go back

    You can install CE and restore your config file if the "config rev" is the same or earlier:
    https://docs.netgate.com/pfsense/en/latest/releases/versions.html
    https://docs.netgate.com/pfsense/en/latest/backup/restore-different-version.html

    @louis2 said in Confused since the introduction of pfSense Plus:

    what would happen when updating the FW-hardware

    If the generated NDI changes (based on hardware changes) the license is invalidated.

  • Should I continue being a happy Netgate low cost SG-1000 user ?

    3
    0 Votes
    3 Posts
    561 Views
    stephenw10S

    You should be thinking about replacing it. There have been a lot of bugs fixed since 22.05.

    We have nothing planned that would sell at <$100 as far as I know. Really you would be looking at something used to fit that price range IMO.

  • 0 Votes
    7 Posts
    698 Views
    stephenw10S

    If you're asking can you run pfSense as a VM in proxmox then the answer is yes. But there are some caveats! It's a more complex setup to be sure the traffic is all passing through the VM. If you have to reboot proxmox you lose your router/firewall. There are lots of users doing exactly that though.

  • Use ipv4 default gateway as variable in a script

    8
    0 Votes
    8 Posts
    524 Views
    GPz1100G

    The above got put into action this evening. Apparently it's been 2 weeks already since the last disconnect. Entire outage lasted about 6 s while dhcp renewed and other services refreshed.

    Im quite confident this is not a pfsense issue but rather att. I will post a thread on reddit, perhaps someone knows something I don't.

    The other option is to reconnect the att provided ONT back into the loop instead of the third party sfp stick. Wait 2 weeks to see if it disconnects too.

  • netgate licencing and hardware changes

    3
    0 Votes
    3 Posts
    314 Views
    M

    @stephenw10 said in netgate licencing and hardware changes:

    Nope it would not. The ordering of NICs is not important.

    Thank you 😊

  • Wan picking up Xfinity gateway address as WAN ip

    4
    0 Votes
    4 Posts
    206 Views
    johnpozJ

    @cheapie408 where in your "modem" which doesn't have a public IP.. You mean your gateway, a modem/router combo that you put into bridge mode.. Modems don't get put into bridge mode.

    And yeah its possible for them to passthru a different public IP to the client than what it has.. Many of those devices can do passthru, ie bridge mode and also still do nat for devices connected to its other ports, etc.

    Have seen this a lot in business deployments of comcast/xfinity.

    Rebooting switches wouldn't have anything to do with it - other then the interfaces would cycle if you rebooted the switch, do you have a switch between your isp device and pfsense wan?

  • ipad MAC address not showing in DHCP list?

    1
    0 Votes
    1 Posts
    95 Views
    No one has replied
  • uploading encrypted netgate pfSense Plus config

    2
    0 Votes
    2 Posts
    151 Views
    stephenw10S

    Probably a temporary connection failure. Try making a manual backup and make sure it appears in the backup list.

  • Error on Tailscale Interface

    8
    0 Votes
    8 Posts
    548 Views
    stephenw10S

    For whatever reason the system alias TAILSCALE__NETWORK is not being populated so the firewall rules cannot be loaded.

    So if you replace those in your firewall rules with the actual subnet it will then be valid and load.

  • pfSense Keeps Crashing

    4
    0 Votes
    4 Posts
    742 Views
    B

    Did Protectli ever get back to you? Is it resolved? Im curious because I have a similar issue with my hardware. I have it sitting at the BIOS screen to see if it may be hardware rather than software based.

    Thanks!

  • rsync updated

    5
    1 Votes
    5 Posts
    437 Views
    stephenw10S

    2.7.2 does include that functionality yes. It's the ability to check the current or any available repo for updates:

    [2.7.2-RELEASE][admin@t70.stevew.lan]/root: pfSense-upgrade -h Usage: pfSense-upgrade [-46bdfhnRUy] [-l logfile] [-p socket] [-c|-u|[-i|-d] pkg_name] -4 - Force IPv4 -6 - Force IPv6 -b - Platform is booting -d - Turn on debug -f - Force package installation -h - Show this usage help -l logfile - Logfile path (defaults to /cf/conf/upgrade_log.txt) -n - Dry run -p socket - Write pkg progress to socket -R - Do not reboot (this can be dangerous) -U - Do not update repository information -y - Assume yes as the answer to any possible interaction The following parameters are mutually exclusive: -c - Check if update is available in the current repo -C - Check if upgrade is available in any of the available repos -i pkg_name - Install package PKG_NAME -r pkg_name - Remove package PKG_NAME -u - Update repository information

    But 2.7.2 is latest version anyway so safe to upgrade rsync there.

  • Static-routes between two nested pfSense

    4
    0 Votes
    4 Posts
    318 Views
    V

    @MacUsers
    By default pfSense blocks all private address ranges on WAN. To disable this, go into the WAN interface setting and remove the check at "block private networks".

    Also you need to add a rule to the WAN to allow access to the web GUI.

  • 15% lost packets pinging pfSense

    12
    0 Votes
    12 Posts
    738 Views
    stephenw10S

    Yup so that's only the grep command you're running. Kea is not running.

  • PFSense Plus 24.XX still bugged

    Moved
    2
    0 Votes
    2 Posts
    254 Views
    stephenw10S

    If states have already been opened they will continue to pass traffic even if new rules would prevent those states.

  • Crash Errors (think it is the API)

    15
    0 Votes
    15 Posts
    886 Views
    stephenw10S

    Hmm, I not aware of any blacklisting there. Could be co-incidental I guess.

  • AutoConfigBackup not showing newer backups

    7
    0 Votes
    7 Posts
    470 Views
    S

    @stephenw10 Done! Thanks for reviewing; let me know if you need anything else from me.

    SG

  • 25GB Connection on PFsense possible now?

    2
    0 Votes
    2 Posts
    250 Views
    stephenw10S

    Well you test there seems to show it's possible with the right NICs. There have been a few other similar posts. Most systems will not though.

    I haven't tried it personally, I can only dream of 1G where I am! 🙄

  • Moving License to other hardware

    5
    0 Votes
    5 Posts
    451 Views
    stephenw10S

    If you have a paid Plus subscription then open a ticket with TAC to discuss. Usually it can be migrated if you had to replace failed hardware for example.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.