• pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    17k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    85k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • CPU Load High on V2.8.1

    12
    2
    0 Votes
    12 Posts
    90 Views
    B
    @SteveITS the vpn setup is : Mode: Peer to Peer ( Shared Key ) Data Ciphers: AES-128-CBC, AES-128-GCM, AES-256-GCM, AES-256-CBC Digest: SHA256 The data rate is 4,5-4,7 MBytes/sec. pfSense 1 has i5-7200U with 16GB Ram (9% used) pfSense 2 has Intel(R) Celeron(R) CPU J1900 with 4GB Ram (12% used)
  • Console menu for user, over ssh ?

    4
    0 Votes
    4 Posts
    2k Views
    chpalmerC
    Ive done this before but cannot find the instructions I used.. How does one get the user the menu on an SSH session log in? I keep the admin account non log in accessible..
  • Unable to update repository pfSense (26.03)

    15
    0 Votes
    15 Posts
    306 Views
    B
    @stephenw10 Thanks for your help. That fixed it for me. Doesn't look like I can edit the post title to say solved.
  • Why is a new install of pfSense 26.03 showing a build date of May 8?

    2
    0 Votes
    2 Posts
    69 Views
    GertjanG
    @axellarsson Did you read the the thread ? Unable to update repository pfSense (26.03) ? I'm seeing [image: 1778482417198-5122ab23-98b3-4f1e-8957-65d535e0e220-image.png] and no updates avaible. Probably a repos glitch, something like that.
  • WAN disruptions with 802.1X Authentication Bridging

    4
    0 Votes
    4 Posts
    83 Views
    B
    @stephenw10 A MAC conflict is what it feels like. This setup requires the pfSense appliance to spoof the MAC of the RG. But the rules are set up to only send specific Ethernet packets out the “MODEM” (RG) interface. It may be a coincidence but my pfSense appliance was showing an available upgrade for a week or so but I was avoiding taking it until I could coordinate with the wife. Then the day I started having issues, I go to the appliance and the purple light which indicates an upgrade is available was back to blue. I was getting concerned that maybe Netgate had a way to force upgrade me. Before I could look into it, I was working from home and struggling with zoom interruptions.
  • Acme certificate expiring notice after deletion

    4
    0 Votes
    4 Posts
    83 Views
    stephenw10S
    Hmm, check the config file for the the cert reference number. It must still be present somewhere.
  • Custom ICAP to DLP

    2
    0 Votes
    2 Posts
    49 Views
    stephenw10S
    Like using the icap part of Squid?
  • CE 2.8.1 bsnmpd Memory Leak

    49
    0 Votes
    49 Posts
    7k Views
    K
    @keyser As I said in https://forum.netgate.com/post/1229469 : we have been unable to reproduce a leak. Try to narrow down the specific OID that triggers the leak. Probably the easiest way to do that is to disable the query to half of them and to see if the leak remains. If it does not, switch the disabled halves and try again. Once you identify a leaking half split that one in half and repeat the exercise until you have it narrowed down, ideally down to one, but just a handful would be a useful step already.
  • SSl certificates for all home network

    50
    0 Votes
    50 Posts
    1k Views
    johnpozJ
    @Gertjan yeah I think there are some ways to do acme via script via the new os server.. But I just installed my own, and its good til 2035 ;) [image: 1778173237048-osserver.jpg]
  • Pfsense crashing daily on protectli vault

    crash 2.8.1 pfsense
    5
    0 Votes
    5 Posts
    203 Views
    K
    @stephenw10 No worries, thanks for looking into this.
  • RESOLVED - 26.03 - Failure updating ACME certificate

    28
    1
    0 Votes
    28 Posts
    639 Views
    S
    @Gertjan Thank you! The link you provided : https://github.com/acmesh-official/acme.sh/issues/6851 is the solution, so I created a new ‘Token’ with domain:read dns:read dns:write I put the ‘code’ in place of the other one, and miraculously, it's finally working now [image: 1778154784906-0dacebe3-c924-49f0-abbd-992b82bd738e-image.png] As for the second one, I’ve tried too many times and I’m stuck until tomorrow evening, but I’m confident because I’ve made the same changes I know I’m repeating myself, but thank you again for all your help
  • BSNMP causing massive memory use spikes since 26.03 update

    6
    1
    0 Votes
    6 Posts
    143 Views
    keyserK
    I can confirm it is some kind of memory leak in BSNMPD. Both firewalls shows the BSNMPD process slowly but steadily allocating more and more memory. So this is very likely the same case/issue as the previously referenced thread. Let’s use that thread going forward and stop posting here :-)
  • Netgate 6100 unstable since upgrade to 26.03

    21
    0 Votes
    21 Posts
    553 Views
    C
    @dennypage yes, sorry, that is provided by HACS so you can ignore it.
  • Rogue DHCP Server

    31
    0 Votes
    31 Posts
    432 Views
    stephenw10S
    @JKnott said in Rogue DHCP Server: then a request from the client and finally an acknowledge from the server. Right. I guess I forgot (or never knew!) that the dhcprequest is also broadcast the first time. At lease renew it is unicast which is what you more normally see.
  • MFA for pfSense

    3
    0 Votes
    3 Posts
    99 Views
    KOMK
    @ortizat Kind of. pfSense supports TOTP logins via the FreeRadius package.
  • Syslog service doesn't start correctly in 26.03-RELEASE

    18
    0 Votes
    18 Posts
    319 Views
    F
    Just the first time I saw it.
  • VXLAN over wireguard. Unexpected MTU reset bug(?) (PFSENSE+)

    11
    0 Votes
    11 Posts
    538 Views
    stephenw10S
    Yeah open a bug report. It's always better to track it that way anyway.
  • pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec

    5
    0 Votes
    5 Posts
    272 Views
    stephenw10S
    @tinfoilmatt said in pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec: If the FreeBSD driver supports them. We see what you did there. Well there are some newer CPUs with QAT that are not yet supported at all by the driver shipped in pfSense. So YMMV!
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.