• 2 Votes
    4 Posts
    1k Views
    joshgreyzJ

    Thank you both. I don't know how to close this topic as https://forum.netgate.com/post/1073281 is the post to use.

  • 0 Votes
    3 Posts
    765 Views
    F

    @johnpoz AH ok, sorry for the bother, but thank you for the reply!

  • connectivity delay for new clients

    5
    0 Votes
    5 Posts
    675 Views
    GertjanG

    @stephenw10 said in connectivity delay for new clients:

    Partial IPv6 connectivity can introduce delays like that whilst Windows tries to use v6 and then falls back to v4.

    Nice catch 👍

  • Same Rule ID for multiple Interfaces

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S

    The firewall logs pull up the rule description from the current running ruleset based on the identifier. But the ruleset that was running when that log entry was created may have been different. Thus what shows there as the 'Permit to Internet' rule may have been something different at the time. And that seems likely because there is no way that rule could have matched that traffic. Unless it was far more open previously.
    However any single rule that could match all those entries would have to be something that applied to all interfaces. When you look at the ruleset directly that would be a rule without an interface specified.

    Steve

  • Notifications

    3
    0 Votes
    3 Posts
    482 Views
    stephenw10S

    Yup, probably an authrorised device key required there like gmail uses since you can use a 2FA login.

    Steve

  • Will pfSense 2.7/23.01 become a bottleneck for new features and fixes?

    5
    0 Votes
    5 Posts
    1k Views
    keyserK

    @stephenw10 Yes, Multiple IPsec VPN instanses, so I could have several Mobile VPN implementatios with very different settings running on different WAN IPs.

  • Changing physical ports in config

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S

    Indeed, when you restore a config it will reinstall any packages referenced in it. But that shouldn't be a problem as long as you have a valid WAN connection.

    Steve

  • HAProxy and ACME certification not working

    2
    0 Votes
    2 Posts
    771 Views
    V

    @hefin
    The client certificate might not be, what you need. This is meant for authenticating the client on the server.

    You have to assign the certificate to the frontend.

    BTW: you should better hide your public IP, at least if it's static.

  • pfSense partition size?

    13
    0 Votes
    13 Posts
    2k Views
    JKnottJ

    @stephenw10

    Apparently it is a 32 GB. I thought I bought a 64. The invoice doesn't say and the web site shows both 32 & 64 available. On the Ali Express site, you select the options you want to build the computer.

    Well, not a problem. As I mentioned, I'm only using 4% of the 24 GB partition.

  • ARP reports bogons

    91
    0 Votes
    91 Posts
    17k Views
    stephenw10S

    I've never tried but you could add static ARP entries for everything on all devices. I can only imagine it being a complete nightmare though! You'd be chasing connectivity issues forever. Hard to recommend. 😉

  • Website thinks I'm behind VPN

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ

    @michmoor concur - if the IP is what his ISP gave him - time to ask the ISP why its showing as a VPN and has such a horrible reputation.. Might be time to change ISPs as well..

    I checked a few other reputation sites, and not seeing the IP he connected to the forums listed - but that one site I linked to above - sure doesn't like it.. Gives it a really bad score, says its vpn/proxy and and high risk, says listed on spam lists - but if I check spam lists I don't see it there, etc.

  • Connecting to Rogers 8 Gb fibre

    5
    0 Votes
    5 Posts
    633 Views
    JKnottJ

    @stephenw10

    I did some more reading and it appears they provide an unmanaged switch that connects to the ONT, but customers are free to use their own switch. Of course 10 Gb switches are expensive.

    I'm going to ask about lower bandwidth connections.

  • Help with pfSense, cPanel DNS Only and Plesk Slave DNS Manager

    2
    0 Votes
    2 Posts
    521 Views
    E

    OK, just setup the DNS Clustering on the Azure box to the Almalinux box and that worked. So it's either a failure of the API key or the internal IP range issue.

  • Login Credentials Failing

    16
    0 Votes
    16 Posts
    922 Views
    S

    @steveits Thank you so much Steve for thinking outside the box and replying back, very nice of to go out of your way.

  • PF PORTKNOCKING IS POSSIBLE?

    2
    0 Votes
    2 Posts
    457 Views
    stephenw10S

    No, there is no port knocking implementation in pfSense. Yet.

    There is at least one open feature request: https://redmine.pfsense.org/issues/8547

    Steve

  • Dynamic routing over IPSec tunnels

    7
    0 Votes
    7 Posts
    1k Views
    stephenw10S

    You can't route via a gateway group and you can't set a metric on a route directly so using dynamic routing, like OSPF, is usually how this is done.

    You could just use policy routing if the PA can do some sort of reply-to to make sure replies come back over the same link. And if you only need to open connections toward the PA.

    Steve

  • 0 Votes
    1 Posts
    188 Views
    No one has replied
  • Where to make a suggestion for a software addition

    2
  • Error loading rules

    3
    0 Votes
    3 Posts
    873 Views
    J

    @jbeez fixed... definitely user error. I was restoring a filter.inc from a prior version. Restored the proper one and its good to go.

  • Avahi, Multicast mDNS not Functioning?

    3
    0 Votes
    3 Posts
    860 Views
    johnpozJ

    @tyler_rm your links vs just posting the image here is a bit off putting for someone wanting to help.

    Here is a post I did year a go or so on how to validate if avahi is working.

    https://forum.netgate.com/post/1003226

    I personally am not a fan of breaking the L2 barrier like this - but in the link I go over how to actually validate if its working or not, etc. Hope that helps.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.