• Multiple PfSense accesing one Freeradius server

    5
    0 Votes
    5 Posts
    301 Views
    NogBadTheBadN

    Did you try running radsniff -x on the cli of your freeradius box?

  • pfSense can ping ISP gateway but not connect to internet

    16
    0 Votes
    16 Posts
    3k Views
    F

    @DominikHoffmann Thank you!

  • Help me with a simple pfSense config

    19
    0 Votes
    19 Posts
    1k Views
    johnpozJ

    @eagle61 I think its strange no matter who you are or what region of the world your in ;)

    There is no possible way those can not be changed.. If they don't know how to do it, or have no access to the router - I would check if the username/password is just default for the make and model for sure.

    Then call the isp for help, those clearly not default.. So even if the isp set them up initially, not like they can not change them.. Its not like they said ok we can set this IP exactly once.. Once you set it your locked to that IP forever! ;)

    But no there is going to be no way you can just slide pfsense into your original setup without some down time.. And you sure are not going to be able to route with the same networks on 2 legs of a router..

    Lets say you could route even.. If some client on your 192.168.10 network wants to talk to 192.168.10.1 as its gateway.. How would that work.. He says oh need to send this to my gateway 192.168.10.1 - let me arp for that.. ooops no answer, = no access to anything off my network.

    So you would have to change the gateway on the client to point to pfsense 192.168.10.x address on the lan side.. So you would have to touch every device on your 10 anyway.. And then still policy route if you wanted specific devices to use a specific gateway.. But you can not do that anyway..

    So bite the bullet, schedule some down time with the business and set this up correctly.

  • [SOLVED] DNS issue with mullvad wireguard clients.

    7
    0 Votes
    7 Posts
    1k Views
    N

    @Bob-Dig said in [SOLVED] DNS issue with mullvad wireguard clients.:

    @nimrod said in [SOLVED] DNS issue with mullvad wireguard clients.:

    Ill mark this as resolved.

    Great, although that was more luck than anything else. 😉

    Well, it worked. And it never came to my mind yesterday. I wasted hours on this with no acceptable solution.

    If you still have problems, maybe switching the DNS to WAN instead of the VPN will solve it.

    Switching to WAN produces DNS leak with my old settings.

    With DoT it is still encrypted and you have to trust mullvad in any case.

    I dont have problem with that. Thats how it was when i was using openvpn. But openvpn didnt had issues with DNS once i reboot.

  • Netgate 2100 LAN Ports

    9
    0 Votes
    9 Posts
    529 Views
    stephenw10S

    So you're connecting some servers on OPT2 and want to put HAProxy in front of them?

    First get the port, VLAN and switch configured in the same way you did for OPT1. Connect the server(s) and make sure they are in the correct subnet and are reachable.

    Then add HAProxy.

  • Strange issue with 10.0.0.0/24 ip for subnets for LAN.

    2
    0 Votes
    2 Posts
    248 Views
    stephenw10S

    Hmm, but it is somehow routing traffic on every interface?

    Can you ping out from the console to anything?

  • Log rotation options grayed out

    2
    0 Votes
    2 Posts
    119 Views
    X

    Please disregard. The field looks grayed out but it turns out you can actually change the values. Sorry!

    (Side note - BIND stopped writing to resolver.log after I changed the setting but I was able to fix this by restarting the named service on Status > Services)

  • Beta Broken Update module? 24.11-RC

    2
    0 Votes
    2 Posts
    181 Views
    stephenw10S

    It probably is fixable. You might be seeing that error temporarily anyway.

    But try running at the CLI:

    pfSense-repoc -N

    pkg-static -d update

    What error(s) are shown?

    Steve

  • 23.09 Unbound killed failing to reclaim memory

    34
    0 Votes
    34 Posts
    7k Views
    M

    @jimp The Unbound crash happened again today. The Unbound crash has not happened in months, particularly since reducing memory size parameters. It's been so long, in fact, that I removed service watchdog a week or two ago, thinking the issue was resolved. So much for that.

    Here's various symptoms:

    The only relevant error message I found in the System>General log is: Nov 24 10:57:21 kernel pid 54097 (unbound), jid 0, uid 59, was killed: a thread waited too long to allocate a page

    Note this error is different than those in the past where Unbound was killed failing to reclaim memory. End result is the same: dead Unbound and dead production on my network (without service_watchdog, which I have now restored to service).

    I haven't found any relevant messages in the Unbound logs.

    The Status>Monitoring>System>Memory shows a puzzling zeroing of all parameters at about the same time as the Unbound crash:

    f65f0225-4352-4253-801a-02172f323524-image.png

    So, while I've been admonished in this forum to not use service_watchdog, I can't maintain production uptime without while these Unbound discrepancies live on.

    If there's something more I can do to assist Netgate in figuring this out, please let me know. I'll be happy to do whatever I'm able.

    Thanks!

  • 2.7.0 / wiped after reboot

    10
    0 Votes
    10 Posts
    548 Views
    H

    After fixing the backup node, i encounter the exact same issue on the master node...
    Snapshot before reboot to be able to recover the config file !

  • pfSense WAN interface wont get IP address

    Moved
    18
    0 Votes
    18 Posts
    35k Views
    O

    Using Spectrum as ISP and was pulling my hair out on why the Netgate sg-2100 wasn't getting a WAN ip address. After unplugging the modem and the Netgate for a few minutes, then plugging in the cable modem then the Netgate did it get a WAN IP address on the device, thanks!

  • Start service sslh at boottime

    3
    0 Votes
    3 Posts
    211 Views
    F

    @stephenw10 Thx! It works :-)

  • Cloudflare tunnels with Docker connector security

    11
    0 Votes
    11 Posts
    735 Views
    A

    Thanks again for your replies.

    I enjoy playing around with all this networking and security stuff.

    Very exciting.

    And pfsense is the best!

    And a great support community - thank-you.

  • 0 Votes
    5 Posts
    379 Views
    stephenw10S

    But like home, pro, server etc?

  • Bluetooth and pfsense running in a PC

    3
    0 Votes
    3 Posts
    169 Views
    stephenw10S

    No that's not possible. And you really don't want to have that sort of service on a firewall anyway.

  • Convert pfsense ova file to qcow2 fails with either virt-v2v or qemu-img

    4
    0 Votes
    4 Posts
    442 Views
    stephenw10S

    @dutsnekcirf said in Convert pfsense ova file to qcow2 fails with either virt-v2v or qemu-img:

    I'm wondering how well this works.

    Very well. All the config is in that file. It should restore and be identical. The only issue you will have are he interface names will probably be different (vmx vs vtnet) so they will need to be re-assigned when you import it.

    Steve

  • Is it hacking?

    12
    0 Votes
    12 Posts
    796 Views
    JonathanLeeJ

    @Antibiotic get rid of that torrent client eventually it’s gonna break stuff if you keep using it. Trust me. Stop using it, think about how many ports you need open. It just takes one bad download

  • Arpwatch Notification receipient ignored

    3
    0 Votes
    3 Posts
    214 Views
    I

    @stephenw10 I'm also noticing this behavior. I'm on pfSense version 24.03-RELEASE.

  • Slow WAN Good LAN

    9
    0 Votes
    9 Posts
    388 Views
    R

    @stephenw10

    Both really.

    My infrastructure segment is inaccessible unless you can either get on that vlan through a physical port on the switch, or via a VPN that the FW originates as the server to get on an administrative network.

    There are also client mode VPN connections to a commercial provider.

    Regardless of if the traffic is coming in via the admin VPN and then out WAN, or on the local segment and then routed over the client VPN out to the web it takes a big hit to throughput. It would be difficult to pin down if it affects traffic both ways given the huge imbalance in the down/up speeds.

    It does seem to be limited to traffic routed externally that has the issue though. Running a speed test from the admin net to a local server works as expected despite going through a vpn tunnel to get to that network. But anything either from the admin vpn or going over the external commercial vpn to an external site is heavily limited.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.