• Strange issue with 10.0.0.0/24 ip for subnets for LAN.

    2
    0 Votes
    2 Posts
    248 Views
    stephenw10S

    Hmm, but it is somehow routing traffic on every interface?

    Can you ping out from the console to anything?

  • Log rotation options grayed out

    2
    0 Votes
    2 Posts
    119 Views
    X

    Please disregard. The field looks grayed out but it turns out you can actually change the values. Sorry!

    (Side note - BIND stopped writing to resolver.log after I changed the setting but I was able to fix this by restarting the named service on Status > Services)

  • Beta Broken Update module? 24.11-RC

    2
    0 Votes
    2 Posts
    181 Views
    stephenw10S

    It probably is fixable. You might be seeing that error temporarily anyway.

    But try running at the CLI:

    pfSense-repoc -N

    pkg-static -d update

    What error(s) are shown?

    Steve

  • 23.09 Unbound killed failing to reclaim memory

    34
    0 Votes
    34 Posts
    7k Views
    M

    @jimp The Unbound crash happened again today. The Unbound crash has not happened in months, particularly since reducing memory size parameters. It's been so long, in fact, that I removed service watchdog a week or two ago, thinking the issue was resolved. So much for that.

    Here's various symptoms:

    The only relevant error message I found in the System>General log is: Nov 24 10:57:21 kernel pid 54097 (unbound), jid 0, uid 59, was killed: a thread waited too long to allocate a page

    Note this error is different than those in the past where Unbound was killed failing to reclaim memory. End result is the same: dead Unbound and dead production on my network (without service_watchdog, which I have now restored to service).

    I haven't found any relevant messages in the Unbound logs.

    The Status>Monitoring>System>Memory shows a puzzling zeroing of all parameters at about the same time as the Unbound crash:

    f65f0225-4352-4253-801a-02172f323524-image.png

    So, while I've been admonished in this forum to not use service_watchdog, I can't maintain production uptime without while these Unbound discrepancies live on.

    If there's something more I can do to assist Netgate in figuring this out, please let me know. I'll be happy to do whatever I'm able.

    Thanks!

  • 2.7.0 / wiped after reboot

    10
    0 Votes
    10 Posts
    548 Views
    H

    After fixing the backup node, i encounter the exact same issue on the master node...
    Snapshot before reboot to be able to recover the config file !

  • pfSense WAN interface wont get IP address

    Moved
    18
    0 Votes
    18 Posts
    35k Views
    O

    Using Spectrum as ISP and was pulling my hair out on why the Netgate sg-2100 wasn't getting a WAN ip address. After unplugging the modem and the Netgate for a few minutes, then plugging in the cable modem then the Netgate did it get a WAN IP address on the device, thanks!

  • Start service sslh at boottime

    3
    0 Votes
    3 Posts
    211 Views
    F

    @stephenw10 Thx! It works :-)

  • Cloudflare tunnels with Docker connector security

    11
    0 Votes
    11 Posts
    733 Views
    A

    Thanks again for your replies.

    I enjoy playing around with all this networking and security stuff.

    Very exciting.

    And pfsense is the best!

    And a great support community - thank-you.

  • 0 Votes
    5 Posts
    379 Views
    stephenw10S

    But like home, pro, server etc?

  • Bluetooth and pfsense running in a PC

    3
    0 Votes
    3 Posts
    169 Views
    stephenw10S

    No that's not possible. And you really don't want to have that sort of service on a firewall anyway.

  • Convert pfsense ova file to qcow2 fails with either virt-v2v or qemu-img

    4
    0 Votes
    4 Posts
    442 Views
    stephenw10S

    @dutsnekcirf said in Convert pfsense ova file to qcow2 fails with either virt-v2v or qemu-img:

    I'm wondering how well this works.

    Very well. All the config is in that file. It should restore and be identical. The only issue you will have are he interface names will probably be different (vmx vs vtnet) so they will need to be re-assigned when you import it.

    Steve

  • Is it hacking?

    12
    0 Votes
    12 Posts
    796 Views
    JonathanLeeJ

    @Antibiotic get rid of that torrent client eventually it’s gonna break stuff if you keep using it. Trust me. Stop using it, think about how many ports you need open. It just takes one bad download

  • Arpwatch Notification receipient ignored

    3
    0 Votes
    3 Posts
    214 Views
    I

    @stephenw10 I'm also noticing this behavior. I'm on pfSense version 24.03-RELEASE.

  • Slow WAN Good LAN

    9
    0 Votes
    9 Posts
    388 Views
    R

    @stephenw10

    Both really.

    My infrastructure segment is inaccessible unless you can either get on that vlan through a physical port on the switch, or via a VPN that the FW originates as the server to get on an administrative network.

    There are also client mode VPN connections to a commercial provider.

    Regardless of if the traffic is coming in via the admin VPN and then out WAN, or on the local segment and then routed over the client VPN out to the web it takes a big hit to throughput. It would be difficult to pin down if it affects traffic both ways given the huge imbalance in the down/up speeds.

    It does seem to be limited to traffic routed externally that has the issue though. Running a speed test from the admin net to a local server works as expected despite going through a vpn tunnel to get to that network. But anything either from the admin vpn or going over the external commercial vpn to an external site is heavily limited.

  • pfsense cannot establish a direct connection to the ISP

    8
    0 Votes
    8 Posts
    539 Views
    B

    Thank you very much for your help. It works now! I have just reinstalled the pfsense.

  • Raw Log - how to remove "1" on the beginning log string ?

    8
    0 Votes
    8 Posts
    473 Views
    stephenw10S

    Mmm, I'm not sure we can anything about that. The webgui handles that formatting fine.

    I believe that's actually the syslog version, which i9s part of the expected format.

  • strange crash report everyday

    8
    0 Votes
    8 Posts
    412 Views
    stephenw10S

    If you created the VM in ESXi 8.0 then it's probably OK. But the VM version is separate to the ESXi version.

  • Restart webConfigurator from webConfigurator

    3
    0 Votes
    3 Posts
    749 Views
    stephenw10S

    Yes it should do that anyway. If you renew the cert for example.

  • Disable hardware checksum offload

    10
    0 Votes
    10 Posts
    2k Views
    J

    @jriofrio
    Just to corroborate your statement about (in my case) not need it to disable the hardware checksum with the intel x540.

    You are correct, I enable it back and reboot the firewall, tested the connection of OPT1 (2nd LAN) and all works good, no problems accessing websites.
    Also, I deleted the DoT rule for the 2nd LAN.

    All good.. I'm please with the results.

    PS: couldn't sleep , so i decided to do the changes now that no one is using the internet....

  • 4200 24.03 crash: fatal trap 12

    3
    0 Votes
    3 Posts
    285 Views
    LarryFahnoeL

    @kprovost Though my eye is untrained, I would agree that mine looks very similar. It has happened only once, so I will keep an eye on it and watch for when 24.11 goes GA. Thanks.

    --Larry

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.