• pfSense Plus

    20
    0 Votes
    20 Posts
    1k Views
    N

    @bmeeks pfSense is showing me it's using igb (igb0, igb1, igb7).

    Here is the offloading:
    offloading.png

    Is there a specific Intel based NIC card that you would recommend that doesn't have any issues with pfSense? Just wondering.

  • What is [kernel{if_io_tqq_X}] ?

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S

    Yeah, since the re-write of many drivers to use the iflib framework the loading appears differently. So 2.6 and higher.

    That loading level is not necessarily any sort of issue. It depends how much traffic it was passing at that point and when the CPU is.

    Steve

  • pfSense 2.6.0-RELEASE (amd64) - WebGui interface

    2
    0 Votes
    2 Posts
    463 Views
    stephenw10S

    The webgui listens on all the firewall IPs.

    How do you have the host override configured?

    Steve

  • Notice about Filter Reload on PPPoE Reset

    13
    0 Votes
    13 Posts
    1k Views
    stephenw10S

    Ah, no sorry, not for a block! 🤦

  • When the FreeBSD 13 come into the pfSense???!!!

    6
    0 Votes
    6 Posts
    1k Views
    M

    @sergei_shablovsky

    I agree with Sergei, I hope we see pfs on freebsd 13 soon. I use frontier fiber and freebsd 13 resolves the issue of the wan interface not being able to grab an ip from dhcp because frontier and all the other telco's tag their transmission with vlan 0.

  • 0 Votes
    6 Posts
    877 Views
    E

    Just an update on this, I purchased a new intel NIC and the connection has been solid ever since, no dropped packets, no wan down. For anyone else reading, the updated realtek drivers helped a little, but it took a day before the dropouts slowed (no idea why). It also helped when I moved my realtek nic from WAN to LAN. The ultimate fix appears to be as @bmeeks suggested "change out the Realtek NIC for an Intel variety"

  • setting up pfSense after years of uysing it

    21
    0 Votes
    21 Posts
    2k Views
    randomaustralianR

    c83e9ff0-9081-4795-bb5b-00682d637599-image.png

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • Console password - how to boot after

    10
    0 Votes
    10 Posts
    909 Views
    S

    @johnpoz Thanks for helping

  • HA and OpenVPN access the two routers

    3
    0 Votes
    3 Posts
    381 Views
    A

    @viragomann thanks so much and sorry for missing that previous post.

  • installing pfsence on firebox T35

    5
    0 Votes
    5 Posts
    2k Views
  • Snort Inline IPS Speeds

    4
    0 Votes
    4 Posts
    646 Views
    bmeeksB

    @droidus said in Snort Inline IPS Speeds:

    @bmeeks
    It is the Protectli FW4B - 4 Port Intel® J3160. I have 8 GB RAM total.

    That hardware should easily do much better than the 10/10 you said you are seeing.

    I can already guess your next question, but sorry, "no, I have no idea why you are not seeing better performance" ... 😀. That slow throughput is certainly not the case with many other users here on similar types of hardware in terms of capability. You will likely never get line-rate Gigabit traffic inspection with Snort unless you have a screaming fast CPU, but you should get better than 200 Mbps with most hardware.

  • 0 Votes
    7 Posts
    1k Views
    R

    @marcosm They are not totally separate. It is physically impossible to turn off the the VPN service in the OpenVPN area unless you delete the VPN interface in the interface area. I was told this was done to prevent unwanted behavior but I was suggesting that it be changed to where disabling the interface is all that is needed to be able to turn off the OpenVPN.

  • Autoconfig Backup errors after update to 22.05

    13
    0 Votes
    13 Posts
    2k Views
    I

    @stephenw10

    The problem seems to have disappeared, only change done was is pfBlockerNG set the DNSBL Mode to Python Mod.

    After the change no more errors with Autoconfig Backup.

    Thanks for you support.

  • removing pfSense + activation code

    4
    0 Votes
    4 Posts
    680 Views
    R

    @deanfourie Yes.

  • Best way to upgrade 2.5.2ce to 22.05 plus

    18
    0 Votes
    18 Posts
    2k Views
    JeGrJ

    @stephenw10 If I can apply further information, I'd be happy to help

  • Monitor Outbound DNS requests

    5
    0 Votes
    5 Posts
    902 Views
    GertjanG

    @treestomp said in Monitor Outbound DNS requests:

    does DoH/DoT still have an effect or it's encrypted to the VPN anyway?

    Nearly all traffic is already TLS these days, so VPN "to protect your data" is not needed.
    The exception is of course classic DNS traffic.

    DoH is more a DNS generated by the end user client's application : even your router, pfSense, can't "see" it. pfBlockerNG can only block it, if it's a known DoH endpoint server.

  • Multiple VPNs via Gateway Groups?

    8
    0 Votes
    8 Posts
    930 Views
    S

    @viragomann yes I prefer certain VPNs for work or personal.

    I do it via having different interfaces so all the firewall rules switch at once. However, it's annoying to switch DNS settings as well

    I am/was struggling to get it to work via Gateway Groups. Do you know where I can find more on this because the official Netgate documentation only elaborated on setting up the proper gateway, not changing

  • bug found: ipsec vpn ipv4 and web management do not work together

    8
    0 Votes
    8 Posts
    944 Views
    M

    @nevolex

    Thanks for the update, glad to hear it's fixed!

  • Question about entry in /boot/loader.conf file

    2
    0 Votes
    2 Posts
    411 Views
    provelsP

    @tibere86
    Create a file called "loader.conf.local" in the /boot folder. That will stay between reboots.
    I use WinSCP to attach to the FW and create/edit because it's easiest for me.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.