• getting DNS leaks

    14
    0 Votes
    14 Posts
    1k Views
    N

    @bluecovenant said in getting DNS leaks:

    hmmm i just rebooted with the "dns server override" unchecked, and got a leak again. any other suggestions? could this be a problem with how the vpn interface is set up?

    @bluecovenant said in getting DNS leaks:

    "dns server override"

    I had same issue as you, and i resolved it by using DoT. See my thread here. The other not so elegant solution is to configure your DHCP server so it hands out proton DNS IP`s to your clients directly.

  • Renew certificat OpenVPN Server

    10
    0 Votes
    10 Posts
    3k Views
    S

    @viragomann thank you for the confirming feedback!

    EDIT: ps: it worked out great, thanks again

  • Is it possible to access the pfsense console remotely?

    9
    0 Votes
    9 Posts
    596 Views
    G

    @patient0 said in Is it possible to access the pfsense console remotely?:

    @jriofrio there are KVM-Over-IP available but they are mostly not cheap.

    Like TinyPilot Voyager for $350 is an example.

    Or a new one on Kickstarter is JetKVM for $69 according to their website (Lawerence System did a review on it). But be careful with Kickstarter projects, they may not come alive.

    Or build a PiKVM... https://docs.pikvm.org/v2/
    All you need is a Pi4 (preferably) and a HDMI to CSI module.

  • Is there a tutorial for switching to KEA?

    11
    0 Votes
    11 Posts
    638 Views
    S

    @jimp
    Yes, very simple. I'm on “KEA” now and everything's OK 👍

  • Recover backup from ACB without original DEVICE key

    Moved
    2
    0 Votes
    2 Posts
    296 Views
    stephenw10S

    Send me the tip in chat and I'll check.

    Steve

  • Potential DNS Rebind attack detected on my local network

    62
    0 Votes
    62 Posts
    6k Views
    johnpozJ

    @comet424 resolving local resources that are listed in unbound be it via dhcp registration or static dhcp registration or host overrides has zero to do with any public dns service you would forward too.. They are not going to resolve your local resources, nor should they even i you put records up there because any ns you forward or that is not actually unbound itself that returns a rfc1918 address would be a rebind and is dangerous behavior.

  • High CPU since 24.11 Plus upgrade - x86 Install

    3
    0 Votes
    3 Posts
    522 Views
    stephenw10S

    Yup check the load average from the command line without the gui open and see if that is significantly lower.

  • 24.11 - KEA DHCP/DNS Logging customization?

    7
    0 Votes
    7 Posts
    925 Views
    stephenw10S

    ChatGPT has helped spammers a lot! 🙄

  • 24.11 on 8200 “NTP” status flashes

    4
    0 Votes
    4 Posts
    306 Views
    M

    @cmcdonald

    I see the same, never seen the flash before. :)

  • How to undoSystem_Patches 2.2.11_16 on 2.7.2

    Locked
    5
    0 Votes
    5 Posts
    278 Views
    jimpJ

    Your issue has nothing to do with those patches. Please start a new thread about your issue specifically, not what you think caused them, because it is not the new patches.

  • System_Patches 2.2.11_16 is also for 2.7.2 right?

    Locked
    15
    0 Votes
    15 Posts
    728 Views
    jimpJ

    Nothing in the new patches touches PPPoE either. You need to start a new thread with an appropriate title in the appropriate category and start with what your issue is not what you speculate the cause might be.

  • 5G/LTE mobile WAN hardware modems

    4
    0 Votes
    4 Posts
    398 Views
    E

    @Clouseau

    LM1200

    $40 from Netgear, $25 from Amazon

    I have the older LB2120 connected to pfSense for dual WAN failover.

  • VLAN for a Failover Modem and one of my Subnet networks (for camers)

    1
    0 Votes
    1 Posts
    106 Views
    No one has replied
  • radvd crashes with 4 DNS servers in DHCPv6 scope

    3
    0 Votes
    3 Posts
    209 Views
    F

    @marcosm Yes, that's right. I've created a bug report in Redmine.

    Bug #15876

  • Multiple PfSense accesing one Freeradius server

    5
    0 Votes
    5 Posts
    301 Views
    NogBadTheBadN

    Did you try running radsniff -x on the cli of your freeradius box?

  • pfSense can ping ISP gateway but not connect to internet

    16
    0 Votes
    16 Posts
    3k Views
    F

    @DominikHoffmann Thank you!

  • Help me with a simple pfSense config

    19
    0 Votes
    19 Posts
    1k Views
    johnpozJ

    @eagle61 I think its strange no matter who you are or what region of the world your in ;)

    There is no possible way those can not be changed.. If they don't know how to do it, or have no access to the router - I would check if the username/password is just default for the make and model for sure.

    Then call the isp for help, those clearly not default.. So even if the isp set them up initially, not like they can not change them.. Its not like they said ok we can set this IP exactly once.. Once you set it your locked to that IP forever! ;)

    But no there is going to be no way you can just slide pfsense into your original setup without some down time.. And you sure are not going to be able to route with the same networks on 2 legs of a router..

    Lets say you could route even.. If some client on your 192.168.10 network wants to talk to 192.168.10.1 as its gateway.. How would that work.. He says oh need to send this to my gateway 192.168.10.1 - let me arp for that.. ooops no answer, = no access to anything off my network.

    So you would have to change the gateway on the client to point to pfsense 192.168.10.x address on the lan side.. So you would have to touch every device on your 10 anyway.. And then still policy route if you wanted specific devices to use a specific gateway.. But you can not do that anyway..

    So bite the bullet, schedule some down time with the business and set this up correctly.

  • [SOLVED] DNS issue with mullvad wireguard clients.

    7
    0 Votes
    7 Posts
    1k Views
    N

    @Bob-Dig said in [SOLVED] DNS issue with mullvad wireguard clients.:

    @nimrod said in [SOLVED] DNS issue with mullvad wireguard clients.:

    Ill mark this as resolved.

    Great, although that was more luck than anything else. 😉

    Well, it worked. And it never came to my mind yesterday. I wasted hours on this with no acceptable solution.

    If you still have problems, maybe switching the DNS to WAN instead of the VPN will solve it.

    Switching to WAN produces DNS leak with my old settings.

    With DoT it is still encrypted and you have to trust mullvad in any case.

    I dont have problem with that. Thats how it was when i was using openvpn. But openvpn didnt had issues with DNS once i reboot.

  • Netgate 2100 LAN Ports

    9
    0 Votes
    9 Posts
    528 Views
    stephenw10S

    So you're connecting some servers on OPT2 and want to put HAProxy in front of them?

    First get the port, VLAN and switch configured in the same way you did for OPT1. Connect the server(s) and make sure they are in the correct subnet and are reachable.

    Then add HAProxy.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.