• Including configuration in other files

    4
    0 Votes
    4 Posts
    382 Views
    stephenw10S

    So you mean the credentials pfSense uses to connect to the LDAP server?

    No, that is contained in the pfSense config. It would be rewritten from the config at boot or when any change was made to the authentication system.

  • 2.7 RC DNSresolver does not work with routed vlans on Cisco L3 switch

    4
    0 Votes
    4 Posts
    401 Views
    NollipfSenseN

    @coxhaus said in 2.7 RC DNSresolver does not work with routed vlans on Cisco L3 switch:

    None of my Apple devices are responding on my Apple vlan

    What's your Apple vlan, a switch? Apple doesn't make any network switch...oh, it's a Cisco!

  • Crash report after upgrade to 23.05

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S

    Not sure at this point. We'll update that ticket as we know more.

  • Modem Management when using pfSense multizone setup

    5
    0 Votes
    5 Posts
    479 Views
    stephenw10S

    Yes it depends on the modem. If it has a route to the pfSense WAN you don't need to do anything. Some modems do not and require you NAT to their subnet so they can reply.

  • combine fios g1100 with separate netgate 2100

    Moved
    8
    0 Votes
    8 Posts
    743 Views
    S

    @leakin 😊

  • [SOLVED]system and interrupt burn the CPU every 3 minus

    2
    0 Votes
    2 Posts
    152 Views
    insmodI

    I've found the answer,because the network burst every 3 minus.

    network.png

  • 0 Votes
    6 Posts
    478 Views
    stephenw10S

    Hmm, do you have any traffic shaping enabled?

    I assume those are igb NICs?

  • WAN interface configuration issue

    3
    0 Votes
    3 Posts
    388 Views
    G

    @stephenw10 Thanks for your answer, I understand now the problem

  • First hard crash in years on pfSense

    46
    0 Votes
    46 Posts
    8k Views
    keyserK

    @stephenw10 At the risk of jinx'ing it, I'm going to declare the situation resolved by upgrading to 23.05. My box has been 100% stable for 34 days now which is 20-30 days more than it ever would on 23.01 before crashing with a hardware error.
    So something is better in 23.05 on my particular 6100 :-)

    Looking forward to 23.05.1 with the IPsec fix it includes :-)

  • Accessing Sip server over OpenVPN

    17
    0 Votes
    17 Posts
    2k Views
    stephenw10S

    Ok, well you likely could also correct it by converting A2 to routing only and leaving the VPN on A1 which might be easier for you with all the other clients.

  • No-ip auto confirm?

    7
    0 Votes
    7 Posts
    2k Views
    GertjanG

    @tjabas said in No-ip auto confirm?:

    i have installed this plugin

    What did you chose ? Are you using a docker (whatever that light be) ? A debian setup ?
    Installed where ?

  • Slow performance on new N4000 i226V pfsense 2.7.0-Beta

    9
    0 Votes
    9 Posts
    1k Views
    W

    @jimp Thank you for the info. After upgrading 3 units to the RC, everything works as it should

  • Need help - can't reach website by FQDN or the IP Address

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S

    @johnpoz said in Need help - can't reach website by FQDN or the IP Address:

    Maybe that fqdn should only be used in the US?

    Yup, that seems possible.

  • opt1 direct to wan

    9
    0 Votes
    9 Posts
    736 Views
    E

    @stephenw10 Thank you, I can live with what it is. elmo

  • Changes to IPsec tunnels leads to routing instability

    10
    0 Votes
    10 Posts
    1k Views
    M

    @pete35 Update on this.

    I secured this contract. We're using a pair of Juniper SRX 380s as we got 10Gbps dual DIA circuits

    I am posting lessons learned for posterity's sake and a cautionary tale for others who search for something similar to this.

    pfSense cannot perform advanced routing in a stable way. FRR needing to be reloaded for changes is a problem that i do not blame pfSense on. Thats just the way the package currently functions but still should be taken into account. I got over 15 sites in a hub and spoke set up. If i update frr im breaking connectivity for all sites. When won't I have to make a route map change? Add a new BGP neighbor? There is no maintenance window in the world that a company would approve a global outage. There are workarounds for this I suppose but not worth exploring.

    As I outlined in my redmine, there is an issue with IPsec that impacts FRR in a negative way. The problem isnt with FRR.
    If there is a need to do routing over IPsec (obviously utilizing VTIs) then pick another firewall. Imagine you have a datacenter terminating over 50 IPsec tunnels. All you do is update the IPsec configuration or even onboard another site and click apply. You just broke routing within the enterprise. Thats absolutely insane and scary. This is something that can be replicated by TAC per the redmine. I cant recommend in good conscience deploying pfSense in that situation.
    I got extremely lucky in that my client paid thousands of dollars on the 6100s to make the sacrifice of getting the Juniper head-end SRXs to manage all of this.
    I really do advise anyone reading this to reconsider something else if your solution requires dynamic routing with IPsec. Beware,..

    Lastly, there are lots of things that pfSense gets right. I will continue to deploy it in much less advanced scenarios but cannot use it going forward on topologies that require High availability with routing. The software just cant do it. This was indeed an eye-opener for me but we all learn the hard way.

  • [SOLVED]egrep used lots of CPU,what did it grep ?

    24
    0 Votes
    24 Posts
    2k Views
    insmodI

    @stephenw10

    But for a shorter time?
    Yes,so if I did not use netdata to monitor the system very minus,I can not find it in the "top" command.

    Did he updater script get re-written? It would if you make any changes to the graph settings.
    I did not "save view",just update graph.

  • Delay in sending syslogs towards remote logging server.

    3
    0 Votes
    3 Posts
    367 Views
    stephenw10S

    How do you have the syslog exporting setup? I've never seen it do anything except send close to instantly though. I can't imagine anything buffering 1h of logs locally.

    Check the timezone is set correctly. The clocks are sync'd on both systems.

    Steve

  • Blank Console Screen

    Moved
    2
    0 Votes
    2 Posts
    319 Views
    P

    @py Writing out the problem gave me a hint. Cleared the BIOS and was able to get the console back up. Looks like it had somehow enabled "Above 4G decoding." Disabling that worked.

  • NAT Logging feature

    2
    0 Votes
    2 Posts
    133 Views
    stephenw10S

    You probably want to export and log netflow data if you want that sort of detail:
    https://docs.netgate.com/pfsense/en/latest/recipes/netflow-with-softflowd.html

    Or you could enable logging on the pass firewall rules and export those logs to a syslog server:
    https://docs.netgate.com/pfsense/en/latest/monitoring/logs/remote.html

    Steve

  • 23.05-1 RC - High(er) Memory usage

    7
    0 Votes
    7 Posts
    783 Views
    bingo600B

    @stephenw10
    That was on "Home" 23.5

    I just tried again, and i can't seem to replicate the failure.
    It asks for "View name" immediately now.

    I did notice that i had two open Web sessions to the Monitor page, when i had the issue , and might have done changes via both.
    Could that have caused troubles ?

    Well it works now, but "I swear it was weird" when i wrote about it.

    Btw: After the "Reset Data" (RRD) my temps are showing again on the "Home" 23.5
    13a01440-5aff-4e95-bc47-5dcc6b94cab2-image.png

    As always, thanx for your time,support & wisdom 👍

    /Bingo

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.