• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    31k Views
    STLJonnyS
    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from. I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.
  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    11k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    65k Views
    V
    Mine may be typical, maybe not..... Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do. I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help. [image: 1697753147328-pfsense1.png]
  • Kernel panic related to BGP and IPv6 after upgrading to 2.8.0

    2
    0 Votes
    2 Posts
    136 Views
    JonathanLeeJ
    @EdoFede do you have the crash dump file ?
  • Switched to AT&T fiber, IPv6 tunnel broken

    39
    0 Votes
    39 Posts
    872 Views
    JonathanLeeJ
    @BiloxiGeek do you have a static ipv4? I pay extra for a static address it helps because my tunnel ipv4 address stays the same and my vpn also.
  • ARPWatch typo in subject of email notifications

    1
    0 Votes
    1 Posts
    47 Views
    No one has replied
  • 0 Votes
    4 Posts
    120 Views
    M
    Reporting back, it doesn't work. It gets connected, pings go through, but upon more serious data transfer I get socket errors and after a while I get LCP errors and a disconnection. Frustrating, especially that it worked pretty OK with 2.7.2. Off to buy a 4G modem with ethernet adapter :)
  • 25.07 unbound - pfblocker - python - syslog

    56
    0 Votes
    56 Posts
    3k Views
    kmpK
    @stephenw10 I did not know about that. Thanks - implemented and it's working!
  • Port Forwarding stopped working after upgrading to 2.8.0

    126
    0 Votes
    126 Posts
    7k Views
    stephenw10S
    Ok so all clients are using pfSense for DNS. Both VPN and non-VPN clients. So that means to avoid a 'DNS leak' reported on vpn clients that Unbound must send all queries over the VPN. Either by resolving using the VPN interfaces only or by forwarding to the PIA DNS servers only. That does mean that if the VPN is down no clients will be able to resolve. Both vpn and non-vpn clients. I'm not sure why you have added the DNS servers to the VPN client config. Those should be passed to you by the server. But Unbound won't use them there either way. It can only forward to servers configured in general setup. A better setup here would be to put vpn clients on a separate interface. That way you can easily pass them different DNS servers to use etc.
  • Wireguard fails after reboot (2.8.0)

    28
    0 Votes
    28 Posts
    2k Views
    B
    @stephenw10 [image: 1756994395455-easeus_2025_09_-4_14_59_20.png]
  • High CPU usage from egrep in pfSense+ v25.07.1

    14
    0 Votes
    14 Posts
    252 Views
    stephenw10S
    Yup, I'm running on a 3100 too which is probably many times slower than your CPU. Either way it looks like it's probably the multiple process spawning causing the issue. Let's see if they start to multiply again over time.
  • 24.11 - KEA DHCP/DNS Logging customization?

    14
    0 Votes
    14 Posts
    2k Views
    AmarandA
    @keyser Fantastic, thank you! Yeah, I ended up getting to the JSON settings before I saw your reply, and I had DEBUG instead of just INFO and the logs were going crazy! I think, with as active as my network is, and as chatty as the DHCP devices are, I'm going to ignore the web GUI, and just tail the logs over SSH. That way I can grep and sed to my heart's content. I also set-up log rotation using the built-in method, so that's good. Every once in a while I have these bursts of pfSense learning.
  • IPv6 Link Local in Interface Status

    2
    0 Votes
    2 Posts
    105 Views
    tinfoilmattT
    @azalea You can read more about the specific notation you're asking about, the zone index, in this Wikipedia subsection of the "IPv6 address" article.
  • Update Clarity

    13
    0 Votes
    13 Posts
    317 Views
    stephenw10S
    You can choose to boot the old kernel at the bootloader menu. But that's only the kernel, it will still fail to boot if the rest of the system is broken. In ZFS you can create a snapshot boot environment before upgrading you can roll back to. Plus does that automatically.
  • 0 Votes
    3 Posts
    167 Views
    stephenw10S
    Yup, that's fixed in current versions.
  • 25.7.1 package issue

    3
    0 Votes
    3 Posts
    254 Views
    provelsP
    Browser cache need clearing?
  • CGNAT and IP Passthrough

    12
    0 Votes
    12 Posts
    327 Views
    M
    @tman222 I've got T-Mobile Home Internet (THMI) set up as my backup to Starlink in a pfSense failover gateway group. It is kept alive by a ping to 8.8.8.8 and my gateway always has the ipv4 address of 192.168.12.1. The pfSense interface gets .12 address, right now, .12.145. For science, I turned on ipv6 dhcp to get the one and only ipv6 address from the TMHI gateway and it did get an ipv6 address it couldn't really do much with, kept alive by pinging the ipv6 of 8.8.8.8. Until it didn't work. One day the ipv6 address and interface was just dead and the ipv6 address wouldn't come back with some usual efforts. Since it was just an experiment, I shut the ipv6 off. Since TMHI won't give a prefix, it's really not much use that I can tell to have the router interface have an ipv6 address with nothing else downstream. So it just uses ipv4. Note, I have shut off all the wifi on the box and just use it through the ethernet port. I used a great IOS app called HINT Control to shut off the wifi on the TMHI gateway. I have my own wifi, so I don't need it polluting the em spectrum with more. Since we live in the sticks, both our Starlink and TMHI use CGNAT of a sort but I don't have any problems with double-NAT with either. It just works.
  • Order / Timing of Booting Modem and pfsense PC

    15
    0 Votes
    15 Posts
    270 Views
    montreelM
    @stephenw10 thanks
  • if_pppoe problems with php-fpm causing loops. (resolved)

    66
    0 Votes
    66 Posts
    4k Views
    C
    @stephenw10 Thank you for providing these commands, and confirmation more logging is coming as well. The ISP is still investigating, I did setup an auto recovery mechanism which involved rebooting pfSense after 3 failed responses from the gateway in a 3 minute period, but now with the down up commands this will be a quicker and cleaner process, and since cycling the ppp is far less of an interruption than rebooting, I can do it without waiting 3 minutes as well. https://forum.netgate.com/post/1223518
  • Ecobee thermostat can’t connect to servers

    103
    0 Votes
    103 Posts
    4k Views
    stephenw10S
    I think you may be over reacting to users questions. There are plenty of things pfSense could be better at! Most commonly when we see reports of some service that worked fine behind some other router but not pfSense it's either a NAT issue or some ALG/Proxy that was present on the other device but not in pfSense. Try setting a static source port. The difficulty here is that it doesn't fail immediately. It looks as though the ecobee server marks the IP address bad in some way after some time and presumably after some conection event that pfSense fails to pass. But we have yet to see exactly what that is which makes it difficult to diagnose.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.