• How Enable PPTP Server

    Locked Moved
    9
    0 Votes
    9 Posts
    1k Views
    jimpJ

    No, don't do that. That version is over two years out of date. PPTP is insecure and must be avoided. There is no way to use it on current and secure versions of pfSense.

  • reassigning interfaces, now no Internet

    4
    0 Votes
    4 Posts
    549 Views
    T

    Thanks, will try that.

    FYI, my DD-WRT is presently pointing to 8.8.8.8, 8.8.4.4 for DNS. However this is behind the China Telecom modem/router and DD-WRT is getting a WAN ip address of 192.168.1.7 (turning that China Telecom box into bridge mode would be nice) (Talking to tech support here in China is a waste of time due to my lack of Chinese language. My Chinese friends are not tech savvy enough to help )

  • SSH not working - "pid 34138 (sshd), uid 0: exited on signal 4"

    1
    0 Votes
    1 Posts
    247 Views
    No one has replied
  • How to monitor and graph an IP address other than gateway monitor

    2
    0 Votes
    2 Posts
    344 Views
    DerelictD

    Use something like zabbix, solarwinds, or another network monitoring system maybe?

    pfSense is not an NMS. It is a firewall.

  • Setting up pfsense with two subnets?

    4
    0 Votes
    4 Posts
    616 Views
    M

    @jknott

    Thankfully i bought the TL-SG1016DE V3 so it doesn't have the vlan bug.

  • LAN Interface Down/Unreachable

    2
    0 Votes
    2 Posts
    2k Views
    7

    Ok guys, I know this is going to kill any credibility I might have ever had but....the interface names, and places on the motherboard did not line up... So I was using igb0 (first port from left) for WAN, igb1 (second port) for LAN, and igb2 (third port) for OPT1. It turns out, port 1 is igb0, port 2 is igb2, and port 3 is igb3. I figured it was 0 1 2 3.

    I discovered this by using the "auto-assignment" feature, I never thought that the numbers wouldn't be sequential.

    And thus, I am now able to access the webConfigurator. Lesson of the day: Don't trust random almost no-name Chinese MFGs to make everything sensical.

    I'm adding this post for posterity to make sure they remember to chickity check themselves before they spend 8 hours troubleshooting what seems like an insane problem.

    Also I found this document at some point to help me achieve what I want to for my pass-through style: http://users.ox.ac.uk/~clas0415/assets/Setting-up-pfSense-as-a-Stateful-Bridging-Firewall-with-commodity-hardware.pdf

  • DNSThingy on pfSense + pfBlockerNG

    3
    0 Votes
    3 Posts
    847 Views
    chudakC

    @artooro is it really true ? I saw it's conflicting with NAT port forward on 443.

    And it's understandable pfBNG and DNSThingy both need to use it, no ?

  • ntpd does not update?

    3
    0 Votes
    3 Posts
    826 Views
    ?

    @knebb
    Final solution:
    Outbound-NAT was misconfigured to always map to the VirtualIP even in backup mode.

    Switched to automated outbound NAT and now working fine.

  • DNS_PROBE_FINISHED_BAD_CONFIG

    1
    0 Votes
    1 Posts
    839 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • Performance Impact on Disabling the Kernel PTI?

    3
    0 Votes
    3 Posts
    3k Views
    E

    It's mostly less then %1 cpu load, but we are running on such an environment that any less latency is an important gain. So I am doing everything to increase the performance.

    What is the performance gain when I disable it? %10?
    and the risk that something may go wrong, such as not a successful reboot?

  • GRE tunnel only comes back online after firewall change

    2
    0 Votes
    2 Posts
    345 Views
    jimpJ

    Look under Diagnostics > States and compare what you see for the remote GRE endpoint before and after reloading the filter.

  • SSL Certificates for Local IP address [Solved]

    15
    0 Votes
    15 Posts
    8k Views
    jimpJ

    @johnpoz said in SSL Certificates for Local IP address:

    Does that method also allow for rfc1918 IP san entries? Or for a use of domain that is not valid on the public via tld, like local.lan, or single label domains that many users are found of

    No, it can't have IP address SANs and must have a valid domain that exists in public DNS. The hostname doesn't need to be public, but the domain has to be registered/have name servers.

    If so will have to play with this. But then again not too many switches and other devices have support for ACME that I have seen. Sot he local CA still has multiple advantages IMO.

    Yeah, for that kind of thing it could be a PITA to constantly update them with the ACME cert since it wouldn't be automated. Local CA does win out in that scenario.

  • is this a bug

    Locked
    2
    0 Votes
    2 Posts
    274 Views
    jimpJ

    More than likely it's a configuration issue, but that question still belongs in the Cache/Proxy board, not here.

  • Need to know throughput of Pfsense 2.3.5 VM running on ESXi 6.5

    4
    0 Votes
    4 Posts
    508 Views
    johnpozJ

    Yeah why would you be running 2.3.5, clearly you can not be 32bit limited. And your esxi is not even current either. But has mentioned its impossible to even guess without some details of your hardware.

  • OPT interface no connection after VPN setup

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • Pfsense w/API the v3 blog post

    1
    1 Votes
    1 Posts
    231 Views
    No one has replied
  • GEOM mirror in Pfsense 2.4

    4
    0 Votes
    4 Posts
    2k Views
    johnpozJ

    Thanks JimP for quick response.. I normally don't play with this stuff - but did recall a major change with the installer on 2.4..

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • wake-on-lan and permission denied error

    3
    0 Votes
    3 Posts
    936 Views
    A

    Yes, both interfaces are on the same system.

    It's a Netgate SG-2440, so there are four identical Ethernet interfaces. I can use the wake command from the command-line on three out of the four interfaces. WOL from igb2 also seems to work from the web interface. Only wake from the command line with igb2 is giving the permission error.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.