• ISP offering 1.2Gbps - What NIC(s) are recommended?

    3
    0 Votes
    3 Posts
    516 Views
    A

    @gimpymoo

    I have a custom built appliance, specs as below:
    Intel G5400
    4GB RAM
    SSD
    Intel Dual GB NIC

    If these are still your system specs, simply swapping the Intel Dual GB NIC for something like this will do it. Unless you've got extra card slots, then just add one for some extra ports.

    https://www.newegg.com/p/pl?d=intel+x540+dual+port+10gbe+nic

    Just watch out for counterfeit cards...

  • User and Password Management - CE 2.6.0

    12
    0 Votes
    12 Posts
    759 Views
    W

    @stephenw10 Sure I can grab it and put on a test box but it will take a day or so. I will post back here as soon as I have an answer.

  • ntopng upgrade

    4
    0 Votes
    4 Posts
    580 Views
    stephenw10S

    No problem. If you're able to test it I'm sure others would find that useful. 👍

  • Router setup for weirdos like me

    16
    0 Votes
    16 Posts
    2k Views
    F

    @stephenw10 said in Router setup for weirdos like me:

    @fireix said in Router setup for weirdos like me:

    Ok, so you mean that it is the best solution?

    That's what I would choose over anything else if it's available.

    You absolutely can configure pfSense as a transparent firewall if you need to it just requires some care. There is no 'transparent mode' button. It's easy to lock yourself out if the firewall if you don't have a separate management interface.

    Steve

    Having a seperate IPMI-network comes in handy in those situations :)

    For not-that-technical users, I would think it would be a very welcoming thing to have an easy method to enable transparent fw. But having tons of public webservers maybe not the exact average users do.

    Thanks for your help and advice :)

  • pfSense Root Certificate Expired

    5
    0 Votes
    5 Posts
    821 Views
    stephenw10S

    You can do that in the gui cert manager now too.

    Screenshot from 2022-04-24 21-15-37.png

    Steve

  • Connectivity problem after changing ISP

    3
    0 Votes
    3 Posts
    514 Views
    M

    Many thanks @stephenw10 for replying to my query. Sorry for replying earlier. I coudn't get back due to a mishap in family. The issue was finally resolved. I was due to fault in the ONT provided by the ISP. The bridge mode was not working properly. After follow up with ISP, they replaced the ONT and it worked.

    Thanks again for you time.

  • Not getting same speed as isp router

    32
    0 Votes
    32 Posts
    6k Views
    stephenw10S

    @marzdor said in Not getting same speed as isp router:

    I unplugged the cable from the WAN and put it in the OPT port and it showed up as 1000

    Mmm, that in combination with the fact both ports are configured the same starts to look like a problem with the port.

  • Trying to upgrade to plus and am getting this....

    2
    0 Votes
    2 Posts
    592 Views
    stephenw10S

    Open a ticket we might have to reset your NDI manually if your install is not pulling the cert correctly.

    https://www.netgate.com/tac-support-request

    Steve

  • 48 PRO switch with pfsense (how to do 10gig)

    12
    0 Votes
    12 Posts
    1k Views
    M

    @jknott I think the Netgate 1537 does 10 gig RJ45 WAN & LAN. I can going to call there sales dept Monday to see if that would be a soultion.

  • Where to stash mailreport scripts?

    2
    0 Votes
    2 Posts
    336 Views
    stephenw10S

    Traditionally things were put in /conf for that because, many years ago, it was shared between boot slices. That doesn't apply any more but custom files are often put there. I would expect /root to be fine though, I've had custom things there for years.

    Steve

  • PFSense Blocks Security Cameras

    5
    0 Votes
    5 Posts
    2k Views
    G

    @stephenw10 Thanks that helped. Once I enabled UPnP it worked.

  • New user - WAN not updating IP Address

    Moved
    4
    0 Votes
    4 Posts
    629 Views
    C

    Thanks for the suggestion. I'm not sure how often pfsense scans for the ip address for the WAN, but 8/10 times it will finally get a legit ip address, sometimes taking several minutes to register when I power down/up my modem.

  • Question about outbound NAT rule's static port range.

    4
    0 Votes
    4 Posts
    981 Views
    stephenw10S

    There is a patch for 22.01/2.6 to fix the outbound NAT (masquerade) function of miniupnpd you may want to test:
    https://forum.netgate.com/topic/169837/upnp-fix-for-multiple-clients-consoles-playing-the-same-game

    It's in the recommended patches list in the System Patches package.

    Steve

  • Incorrect description between network interfaces and system tunables

    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
  • 0 Votes
    6 Posts
    842 Views
    stephenw10S

    No worries. 😊

  • Problems between iphone and dhcp?

    56
    0 Votes
    56 Posts
    10k Views
    stephenw10S

    Thanks for following up. That could save someone else a lot of time. 👍

  • Editing loader.conf

    20
    0 Votes
    20 Posts
    9k Views
    bmeeksB

    @panzerscope said in Editing loader.conf:

    @bmeeks

    Thanks guys. So it was indeed Snort. Removed it, and the logging went away. I have since installed Suricata and so far so good. Looks like high volume traffic through the WAN is not producing any queuing issues which is awesome.

    Thank you for the feedback. Hopefully this thread may help someone else in the future with a similar issue.

    I'm glad Suricata seems to be working better for you. I collaborated with the Suricata upstream team to add the multiple queue support for netmap back during the summer of 2021.

    Just be aware that using Inline IPS Mode (which requires netmap) will cause some issues with certain other pfSense/FreeBSD features. First and foremost, limiters and shapers are not currently compatible with netmap. Secondly, VLANs do not always work well. It depends on the exact configuration. When using Inline IPS Mode, you must run the Snort or Suricata instance on the physical parent VLAN interface.

  • Daemon DHCPD use CPU 100

    6
    0 Votes
    6 Posts
    849 Views
    D

    @stephenw10 Thanks for the tip, I reinstalled the software

  • License function diff

    2
    0 Votes
    2 Posts
    370 Views
    stephenw10S

    No, it's not restricted by license.

    Steve

  • kernel mvneta0: promiscuous mode enabled

    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S

    Yes, the 2100 is arm64 and from 22.01 can run ZFS.
    The 3100 is 32bit and cannot.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.