• No Internet after initial pf sense configuration

    21
    0 Votes
    21 Posts
    3k Views
    stephenw10S

    Port forwarding will not help at all with outbound connectivity.

    How are they failing? Unable to resolve IPs? No route to host? Just timing out?

    Steve

  • Noob: Comcast - getting odd IP Netgear CM modem

    3
    0 Votes
    3 Posts
    450 Views
    MikeV7896M

    Comcast has a massive address pool, and has been known to move addresses around when doing maintenance or if they need more addresses in one area that aren’t being used in another. It’s not uncommon for two different routers to pull two different IP addresses in two different subnets either.

    Also, geolocation of IP addresses isn’t an exact science, so it may take a few weeks, or even a couple months, for an address’s location to be updated by the various companies that provide geolocation services.

  • Backup only of HAproxy configuration is it possible?

    8
    0 Votes
    8 Posts
    3k Views
    ejajE

    @stephenw10

    Thanks Steve for your help.

  • 0 Votes
    5 Posts
    473 Views
    ?

    Thanks for the feedback Jimp.

  • PHP Error

    9
    0 Votes
    9 Posts
    815 Views
    emammadovE

    Thank you very much.

  • pfSense crashes after wire memory increase

    2
    0 Votes
    2 Posts
    374 Views
    jimpJ

    Are you using the DNS Resolver, perhaps? Maybe DNS over TLS? or DNSBL?

    We found out there are some memory leaks in the version of unbound shipped with 2.4.4. They were recently fixed upstream in Unbound, and we'll have them in 2.4.4-p1 soon.

    That's the only known memory leaks at the moment that I can think of.

  • NTP server / WAN IF down, sluggish connection

    5
    0 Votes
    5 Posts
    528 Views
    badgastB

    @chpalmer It's a SG-2220.... maybe your right, but how ? (via ssh.. ?)

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • Firewall logs wan source ip 0.0.0.0 blocked

    26
    0 Votes
    26 Posts
    5k Views
    johnpozJ

    sniff/packet capture on your wan... Open the capture in wireshark.

    Or just run a tcpdump with -e should also show it.

    Looks like your seeing them every few seconds so you sniff should only need to be very short.

  • dns isp hijacking

    5
    0 Votes
    5 Posts
    753 Views
    KOMK

    Start a new thread about it in the pfblocker sub. This has nothing to do with your 'DNS servers from ISP' issue. By unchecking that box, your ISP's DNS are no longer in your list.

  • Turn off ICMPv6 option 31(RDNSS host name)?

    7
    0 Votes
    7 Posts
    616 Views
    JKnottJ

    @jimp

    I see the line '$radvdconf .= "\tDNSSL {$config['system']['domain']} { };\n";'

    Will removing ['domain'] from that line remove option 31 from the RA? Or just remove the domain name, leaving an empty option 31?

    The reason I'm trying to do this is so that the pfSense RA matches the one from the cell phone as closely as possible, to see if this option is causing the problem.

  • pfSense within AWS environment

    3
    0 Votes
    3 Posts
    426 Views
    stephenw10S

    Be sure to have source/destination check disabled if you're not NATing, which you probably aren't.
    https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html#EIP_Disable_SrcDestCheck

    Steve

  • Issue with YouTube and other mobile apps not functioning

    2
    0 Votes
    2 Posts
    272 Views
    stephenw10S

    You should upgrade to 2.4.4 if you're running 2.4.0.

    Check to see if those URLs actually resolve when the sites fail. What are your clients using for DNS?

    Steve

  • VPN LT2P and MacOS

    2
    0 Votes
    2 Posts
    446 Views
    stephenw10S

    I assume you're using L2TP over IPSec rather than unencrypted L2TP?

    Did you ever see any hits in the firewall logs before adding those floating rules?

    If the VPN is actually dropping rather then the connection across it that sounds more likely something timing out. And since the Windows client seems unaffected it's probably something specific the MacOS client is setting.
    Do you see anything in the VPN logs at either end when the tunnel drops?

    I would recommend switching to IKEv2 mobile IPSec or OpenVPN to be honest. Both if those work well with current MacOS (and most other things).

    Steve

  • Is it possible to rename the interfaces?

    3
    0 Votes
    3 Posts
    992 Views
    J

    Thanks Steve.

    I think it wouldn't be a bad feature to have, or at least a way to order interfaces within the GUI, especially the monitoring parts; especially if one has many interfaces/Vlans.

    Cheers

  • Possible to set Content-Type with mail.php?

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • Private key weight 26GB?

    6
    0 Votes
    6 Posts
    568 Views
    jimpJ

    You probably mistyped that command in a way that caused openssl to fill up that drive or at least run until it died some other way. That isn't something you'd normally see.

  • How to watch disk usage and send mail in pfSense.

    5
    0 Votes
    5 Posts
    578 Views
    JKnottJ

    I did and nothing showed up. With something like a firewall, there shouldn't be such an increase in disk usage, as you might get with a regular computer. Maybe you should try finding out where those large files are coming from.
    .

  • Upgrade made to display a crash message, what to do?

    2
    0 Votes
    2 Posts
    265 Views
    jimpJ

    If the crash report is empty then there is nothing to worry about:

    https://redmine.pfsense.org/issues/8915

  • Logs show different logs than expected

    2
    0 Votes
    2 Posts
    259 Views
    jimpJ

    You'll need to provide some examples of what you mean there. When you set a rule to log and then save/apply you will see a log entry for all new connections made from that point on -- not for every packet and not for connections already open when you clicked the apply button.

    If you want to see every packet of incoming traffic at that moment, use a packet capture, not the firewall log.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.