• CARP Bug or New Feature

    5
    0 Votes
    5 Posts
    654 Views
    stephenw10S
    Mmm, that shouldn't be possible. Try running a packet capture on that interface and check the time between the CARP packets. The Sec would have to be sending in less than 1s intervals to demote the Pri. Or maybe something else using those VHIDs? Steve
  • Internet goes down a couple times a day after update

    5
    0 Votes
    5 Posts
    579 Views
    KOMK
    @helyon You need to determine if it's a DNS issue or general connectivity and that's where the ping test will tell you.
  • RADIUS - CERTIFICATE

    2
    0 Votes
    2 Posts
    387 Views
    AKEGECA
    @jimbohello I can't see what your configuration, but how about try to reboot and check if the config is still correct.
  • # at the break! - message in rules.debug if interface name is not optX

    7
    0 Votes
    7 Posts
    820 Views
    AKEGECA
    @jimp dude! you are famous. About 2017 controversy pfSense vs OPNsense in court. https://www.youtube.com/watch?v=y8R5-xNeHY8
  • how to connect pfsense to Wi-Fi?

    11
    0 Votes
    11 Posts
    2k Views
    JKnottJ
    @johnpoz said in how to connect pfsense to Wi-Fi?: NeXTSTEP ;) which was based on the Mach (kernel), and sure had some source from unix BSD.. You seem to imply that it is freebsd derived from that statement.. ;) The history of Unix is really messed up. I saw a diagram of the various Unix lineage and it was a real pile of spaghetti. This is due to the origins at AT&T and how they distributed it to colleges etc. for little more than the cost of a tape & shipping. One result was that everyone was borrowing from everyone, at least until SCO started claiming the others were stealing from them, including IBM's JFS, which was originally developed for OS/2 and ported to AIX. Since AIX was IBM's version of Unix, anything on it, including JFS, was "owned" by SCO. The various BSDs evolved from the original Berkeley Software Division (BSD), which in turn started from what AT&T had provided. Sun also did a lot of development, based on BSD. It's curious how just about the entire world, other than desktops, runs on some *nix version and most of that is now Linux, all the way from smart watches to the big supercomputers. One of my cousins is a nuclear physicist (he works with neutrinos) and runs Red Hat Linux on both his own notebook computer and on the supercomputer he uses in his work. Even that helicopter on Mars runs Linux.
  • Firewall -> Rules -> LAN very slow to load since 21.02 update.

    Moved
    3
    0 Votes
    3 Posts
    702 Views
    D
    @akegec LOL but it's a Netgate SG5100
  • 0 Votes
    6 Posts
    788 Views
    9
    @stephenw10 said in PF sense crashed after upstream ISP upgrade . Fixed but , working strangely .: 127.0.0.1 It was a DNS issue , the PF sense had been inheriting DNS from the upstream ISP ( Virgin ) . There is something wrong since the upgrade with DNS , working with PF sense . I re-entered DNS addresses 8.8.8.8 & 1.1.1.1 I changed the DNS settings , to and unchecked " DNS to be overwritten by DHCP WAN" I then set DNS Resolution Behavior tp 'Use local DNS , and ignore remote DNS " Seems to be working again now
  • Traffic Won't Route Through Outgoing VPN

    24
    0 Votes
    24 Posts
    3k Views
    C
    @viragomann You can see the DNS request just below the one going out the VPN pipe to the 1.1.1.1. It was originated on a machine in the internal net that has the 10.100.2.14 IP right now. Everything is set to query the .1 address in the subnet and then as far as my understanding goes the resolver takes care of it after that. Why it is saying the INT VPN interface is beyond me unless the traffic is getting passed there first but I wouldn't think so. The only reason I was doing it that was was to add more obscurity of the traffic on the server side. Getting connections to from a 443 that doesn't match the location of the DNS requests.
  • firewall without NAT

    40
    0 Votes
    40 Posts
    5k Views
    stephenw10S
    You might need to check 'allow IP Options' on the pass rule there: https://docs.netgate.com/pfsense/en/latest/firewall/configure.html?highlight=multicast#ip-options Steve
  • SG-3100 doesn't route traffic after WAN lost/regained

    2
    0 Votes
    2 Posts
    413 Views
    S
    @jpaquin said in SG-3100 doesn't route traffic after WAN lost/regained: no clients past the firewall can get out to the internet No DNS or they can't ping? I've seen a few posts recently about Unbound not working (though the one I can think of was "after boot").
  • No incoming S2S IPSec VPN connections. Manual telnet requests show up.

    3
    0 Votes
    3 Posts
    731 Views
    H
    I believe I got it. Turns out, the FritzBox (at least in regards to virtual ip/mac) is crap. What you see is not what you get. I crossreferenced what I saw on the FritzBox with my local computer. [image: 1622053434216-fritznet-arp-table.png] On my local computer it seems to work as expected. Furthermore I disabled the exposed host functionality and went for a simple port forward. [image: 1622053716161-fritzbox-port-forward.png] With this, initiating a vpn connection from the offsite works without any problems. I'll mark this as solved. Thanks! //edit: Ok seems I'm unable to edit my first post. Anyway for me this works now. Have great day!
  • 0 Votes
    4 Posts
    578 Views
    V
    @christophermay These other routers (presumably consumer routers) might have had NAT reflection enabled by default (without the ability to disable it), but that has other drawbacks. DNS override is the more reliable solution for that in the end.
  • L2TP default gateway

    1
    0 Votes
    1 Posts
    348 Views
    No one has replied
  • Migrating from sg3100 to a i5 firewall

    Moved
    8
    0 Votes
    8 Posts
    902 Views
    A
    Thanks you all for the insight. The XML file and modifications worked great.
  • Possible to get email alert on authentication failures?

    5
    0 Votes
    5 Posts
    809 Views
    KOMK
    @nguser6947 You can also create some LAN firewall rules to prevent access to WebGUI by anyone except your workstation.
  • Radius IP Issue

    1
    0 Votes
    1 Posts
    376 Views
    No one has replied
  • Suppress "arp: is using my IP address"

    logging
    7
    0 Votes
    7 Posts
    2k Views
    AndyRHA
    Downtime at my house is not a thing. It has been booted after this started and has only been up 23 days... embarrassingly short time... I just now got around to asking if there is a way to stop it. Thank you for the suggestions.
  • Possible routing loop? Routing loop diagnostics

    4
    0 Votes
    4 Posts
    529 Views
    stephenw10S
    Yes. What about to a different public IP? If you are hitting something odd in the route you may not hit that to a different target.
  • Packages not updating

    20
    0 Votes
    20 Posts
    2k Views
    DaddyGoD
    @akegec said in Packages not updating: I remember how it used to be, no contracts and lawyers, we just used a hand shake to make a deal without any problems. EXACTLY! I have mentioned this here before
  • Real time traffic logging?

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S
    Just how 'live' do you need it to be? You could tail the filter log at the command line if you really want to see it as it happens. You might try using the ntop-ng package. Or one of the other monitoring packages: https://docs.netgate.com/pfsense/en/latest/monitoring/graphs/bandwidth-usage.html Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.