• Block video streaming in YouTube, facebook and WhatsApp web sites !!!

    8
    0 Votes
    8 Posts
    6k Views
    A

    @yahav02
    your given solution works perfectly on desktop pc and laptop. But I am unable to do this on smart phones (android and iPhone devices), as I am not aware of how to enable ssl inspection for mobile devices. please guide

  • Memory usage

    6
    0 Votes
    6 Posts
    498 Views
    stephenw10S

    I won't pretend to be a FreeBSD memory expert. 😉

    However if you want that value to include only Free memory you can just edit that file so the line is:

    $usedMem = $totalMem - $freeMem;

    You can include that as an auto-installing patch even if you wanted it to survive updates.

    Steve

  • Package Manager/Avaliable packages empty

    12
    0 Votes
    12 Posts
    2k Views
    M

    @manilx For what it's worth: Fixed by reflashing and restoring saved backup.

    BTW: https://docs.netgate.com/pfsense/en/latest/solutions/netgate-8200/reinstall-pfsense.html states that

    "If there is an existing installation on this device, the Recover config.xml option will attempt to mount the existing installation drive and copy the previous configuration, including SSH keys. Choose that option first, then proceed through the install as usual."

    Did not happen, it just installed as factory default. Had to reassign interfaces/IP's to get access to the web console an then restore backup.

    After that smooth sailing.

    Took me 15min, a lot less time than fiddling around trying to fix/locate the issue.

  • Synology Package Manager Issue

    24
    0 Votes
    24 Posts
    2k Views
    M

    @jabren said in Synology Package Manager Issue:

    so I’ll be adding my previous configurations one by one to see what may have caused it.

    Thats a good idea. For each configuration you add back wait a day before adding the next one.

  • [Solved] Am I really using pfSense as NTP server ...?

    31
    0 Votes
    31 Posts
    4k Views
    F

    @JonathanLee Hi,
    This would probably be as good too. My rule above is Any for all my interfaces. It seems to work as intended, all traffic goes to pfSense as is now. But will remember this to try in case of issues in the future. Thanks :)

  • Proper way to restore configuration on new vm

    Moved
    21
    0 Votes
    21 Posts
    2k Views
    D

    @stephenw10 Possible

  • IPsec DPD failure action

    2
    0 Votes
    2 Posts
    1k Views
    stephenw10S

    DPD must be enabled on both ends or it will not be enabled when the tunnel negotiates.

    If the DPD response fails the existing SADs are removed and the tunnel attempts to renegotiate.

    See: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/configure-p1.html?highlight=dpd#advanced-options

    Steve

  • [REQUEST] for a native cloudflared plugin

    2
    1 Votes
    2 Posts
    202 Views
    stephenw10S

    Open a feature request: https://redmine.pfsense.org/

    I recall some discussion of it in the past.

  • 0 Votes
    8 Posts
    774 Views
    M

    @stephenw10 thank you for your reply and for the link you provided.

    Thank you to all of you, guys, for sharing with me your experience.

    Mauro

  • pfSense DNS stops working - searching logs

    8
    0 Votes
    8 Posts
    565 Views
    M

    @stephenw10 Fair enough. Appreciate it man.

  • ATT Resident Gateway 802.1x

    5
    0 Votes
    5 Posts
    688 Views
    M

    @tkronic , it works much better than the old 5268AC. But I am not sure is the pfSense working better or bwg320-500. It is probably the pfSense because I actually never used the bwg320 as the router. I went directly to the pfSense. Here are the basic stat difference that I have measured.
    For 5268AC, ping to 8.8.8.8 averages 3ms, pfSense is 2ms.
    For 5268AC, rings lose connection usually less then 2 minutes. pfSense still happens but it is far more stable, every couple of days.
    Speedtest comparison is not relevant as I upgraded from 500 to 1gb. However, I get 975mb up, and 982mb down.

    My pfSense is a white-box: 2.5GbE Firewall Appliance Mini PC, 12th Gen Intel N100(up to 3.4GHz) Fanless Mini Computer Router with 4xIntel I226 Nics 8GB DDR5 Ram 128GB

    The only note I will say is that rebooting pfSense does not always survive the public ip binding. Rebooting the ONT, bwg320 and pfsense all together will take a few minutes but it will always come up. My pfsense has been up for 8 days running the acme, arpwatch, notes, ntopng and openvpn. Works well for sure.

  • No DNS after upgrading from 23.01 to 23.05 - unbound issue?

    20
    0 Votes
    20 Posts
    4k Views
    H

    @Gertjan @TAC57 @SteveITS There seems to be some good news: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=270912

    "Jaap Akkerhuis 2023-06-01 12:41:18 UTC
    A fix is developed by upstairs. There will be a new release within weeks with this fix. For the inpatients among us, a prerelease is made available https://github.com/NLnetLabs/unbound/issues/887#issuecomment-1570136710."

  • Automatically create .xml full backup

    3
    0 Votes
    3 Posts
    400 Views
    R

    @Ivan-70 said in Automatically create .xml full backup:

    Is there a way to automatically create a full backup of pfsense every day (or at a predefined time)?

    You can with CRON.

    In the online documentation there are a number of options covered that are supported. https://docs.netgate.com/pfsense/en/latest/backup/remote-backup.html

  • 22.05-RELEASE (amd64) Unable to check for updates?

    61
    0 Votes
    61 Posts
    24k Views
    stephenw10S

    @TAC57 said in 22.05-RELEASE (amd64) Unable to check for updates?:

    Like this?
    WAN tcp 96.46.xx.xx:31132 (192.168.30.112:45300) -> 8.8.4.4:53 FIN_WAIT_2:FIN_WAIT_2 4 / 4 277 B / 409 B

    Not like that. That's a connection from a LAN side client that's being NAT'd. Unbound would be using the WAN directly with no NAT.

    The only issue with Unbound I'm aware of only applied to DoT only so disabling that would have removed it.
    https://redmine.pfsense.org/issues/14056

    You can try the workaround there: https://redmine.pfsense.org/issues/14056#note-6 However I wouldn't expect it to do anything to a default resolver config.

    Steve

  • Pfsense 22.05 ix driver vs intel-ix-kmod.

    24
    0 Votes
    24 Posts
    3k Views
    stephenw10S

    Nice catch! Odd though, I wouldn't have expected those errors to reach pfSense.

  • Can PFsense handle 10/10 Gbe Internet?

    35
    1 Votes
    35 Posts
    10k Views
    RobbieTTR

    @johnpoz said in Can PFsense handle 10/10 Gbe Internet?:

    yeah if you want to run at gig across a 10G link that would make sense.. ;)

    In my case it is running a 10 Gbit link on an SFP+ DAC from the 6100 to my first switch.

    ☕️

  • 0 Votes
    9 Posts
    767 Views
    stephenw10S

    No problem I should have been clearer. Yes, the console is however you operate directly on the firewall. So either a serial console, if the hardware has one, or the 'vga console', using a keybiard and monitor dircetly.

  • Main PFS box works, WAN doesn't work on aux PFS box w/ same config

    Moved
    8
    0 Votes
    8 Posts
    719 Views
    R

    It looks like the problem wound up being one of name resolution. Once I gave pfSense the DNS IP addresses that Comcast gave me, things started working. The weird thing was, it wasn't set on the main pfSense box either and it was working. Now, one thing that changed in the middle of all this was that the Comcast cable modem was replaced; there was a lightning strike nearby that apparently fried the one of four functionally identical Ethernet ports on the back of the modem (with cable plugged in, pfSense reported "down" for that jack but "up" for any of the others) and screwed it up in other ways so that even plugged into a working jack in the modem pfSense wasn't getting out. So I'm good for now (am continuing to run on the aux box) and have a process for moving configs from one box to the other. Now I need to build out the config more so that I've got externally-reachable boxes on one of the other quad NIC ports.

  • error loading rules proto ipv6 from any to any

    19
    0 Votes
    19 Posts
    2k Views
    A

    I am also using IPv6 over IPv4 here, so that makes sense.

    I ended up moving back to 22.05 and restoring my backup from before that upgrade for now. This error was annoying, but what pushed me was a spent a day trying to get multiwan failover that was working before working in 23.05 and just couldn't get it to actually fail over like it should. worked instantly in 22.05 . maybe after a few more releases I'll give 23.x another shot, but for now I just need this to work as expected.

  • Rebuild PFSense without losing data

    4
    0 Votes
    4 Posts
    515 Views
    G

    @SteveITS I did a clean install

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.