• Cannot connect ('passthrough') to IKEv2 vpn remote work server

    7
    0 Votes
    7 Posts
    1k Views
    S

    @DaddyGo

    ISP router with IKEv2 passthrough (NAT1) + pfSense IKEv2 passthrough(?) (NAT2) + Win10 with VPN client SW)

    Yes the above is the current setup.

    As is apparent, I don't know enough about this, but I was trying to apply the same principle to my separate, unrelated internal OpenVPN server. Where I had to passthrough ports on the ISP router for it to work.

    Win10 (work administered) is using Win10's built-in IKEv2 VPN.

    I read pfsense cannot be set-up as a IKEv2 client with username /password authentication?

  • VirginMedia - Modem Mode packet loss

    6
    0 Votes
    6 Posts
    724 Views
    C

    What is your pfsense build running on? Is it virtualised by any chance?

    It may not be the same issue as mine, but I had EXACTLY the same symptoms you are seeing with Virgin Media and their 'super hub' - turned out that it was the Virtual NIC driver which was causing the issues. I wasn't using the latest VMNX3 driver on this specific VM, so I changed that and just like magic all those issues disappeared.

    As i say, it may be totally unrelated to you but I thought I'd share in case it helped.

  • I keep getting these E-mail's from pfSense

    5
    0 Votes
    5 Posts
    733 Views
    ikifarI

    I haven't received any E-mails today so lets hope so

  • Scripting adding / removing alias host address ?

    2
    0 Votes
    2 Posts
    381 Views
    T

    I've resolved this using:
    https://github.com/jaredhendrickson13/pfsense-automator

  • Can I access pfsense and local websit using https on same public IP?

    2
    0 Votes
    2 Posts
    216 Views
    JKnottJ

    @Alanesi

    There is a method where the header is examined for the original URL and the connection forwarded based on that. However, I have no experience with that and it would require something beyond the basic pfSense.

  • 0 Votes
    5 Posts
    694 Views
    stephenw10S

    You probably don't need to go higher than 1M IMO. Currently, at least.

    Larger tables will cause more effect from 10414 if you're hitting that too. Until 2.4.5p1 is released.

    Steve

  • pfctl eating too much cpu

    Locked
    2
    0 Votes
    2 Posts
    327 Views
    jimpJ

    https://forum.netgate.com/post/908806

  • sonewconn: pcb: Listen queue overflow flooding logs

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Look at the output of netstat -LaAn and see what port number that pcb corresponds to, and then look at sockstat and see what is listening on that port.

    That one process is being overloaded with requests, whatever it may be.

  • Route Between two pfSense boxes

    7
    0 Votes
    7 Posts
    556 Views
    W

    The two pfSense boxes can ping ALL of each others' interfaces.
    But the hosts within each respective Subnet can not be pinged. I think I may have taken a step back in terms of making things work. Here is a new more accurate diagram with some pfsense parameters attached.

    Untitled.jpg

  • WOL Service - Not waking up mac mini and pc tower in SMB office

    3
    0 Votes
    3 Posts
    334 Views
    V

    John, will scope those variables out, thanks.

  • I Cannot Access Books on Google Play. (Squid is disabled)

    2
    0 Votes
    2 Posts
    159 Views
    stephenw10S

    Could be any number of things. What error do you see?

    https://docs.netgate.com/pfsense/en/latest/routing/unable-to-access-some-websites.html

    Steve

  • 0 Votes
    7 Posts
    880 Views
    L

    Yes, you are right, and this is a little bit complicated situation.
    Our users complain that they can access sites with "wrong" web server setup directly, but behind squid proxy. And there are many sites (including goverment related), which are still wrong, but needed to be accessed.. on the other hand, nobody can force site admins to update to proper config. Here comes in OpenSSL 1.1.1, which is able to handle this situation. And yes, I do not want to allow accept expired certs in squid.
    I assume that squid uses pfsense's cert store, but I could not find exact documentation.

  • rc.update_bogons.sh

    4
    0 Votes
    4 Posts
    837 Views
    GertjanG

    @Cornelp said in rc.update_bogons.sh:

    Anyone knows what this could be? Or where its coming from?

    These was (still is ?) a cert issue with the root certificate of .netgate.com 5also pfsense.org ?) - the root certificate is used / maintained by the certificate authority.

    Check out the first 30 or lines when executing manually:

    curl -v https://files.pfsense.org/lists/fullbogons-ipv4.txt

    You should find :

    .. * subject: OU=Domain Control Validated; OU=PositiveSSL Wildcard; CN=*.pfsense.org * start date: Aug 10 00:00:00 2018 GMT * expire date: Aug 21 23:59:59 2020 GMT * subjectAltName: host "files.pfsense.org" matched cert's "*.pfsense.org" * issuer: C=GB; ST=Greater Manchester; L=Salford; O=COMODO CA Limited; CN=COMODO RSA Domain Validation Secure Server CA * SSL certificate verify ok. ...
  • Problem with IPTV from Telenor

    7
    0 Votes
    7 Posts
    1k Views
    E

    Thanks for the answer!

    After i got the REAL hw that my pfsense will run on, it suddenly worked without promiscous mode, it has 4xIntel NICs, so om guessing the problem i had with the other hw was maybe bad realtek/marvel drivers? Thought it might be usefull info for someone els with the same problem

  • Temperature Monitoring on HPE Gen10 Plus Microservers?

    1
    1 Votes
    1 Posts
    454 Views
    No one has replied
  • Block-Online-Gambling

    Locked
    4
    0 Votes
    4 Posts
    896 Views
    stephenw10S

    What service?

    Waaaay more info needed.

    But in general use pfBlocker (DNS-BL) to block sites at DNS level or Squid/Squidguard to filter webtraffic.

    Steve

  • Bypass At&t fiber BGW210-700

    103
    0 Votes
    103 Posts
    25k Views
    stephenw10S

    Yup. This now seems to be the best source: https://github.com/MonkWho/pfatt

  • How do you find devices w/ Link-local IPv4 address on your network

    13
    0 Votes
    13 Posts
    3k Views
    JKnottJ

    @johnpoz

    Yeah, I just checked that. Arp cache won't catch anything that's not in the subnet. I suppose tcpdump --immediate-mode might work to capture for a script.

  • Really Strange Behaviour - Have I been Hacked?

    13
    0 Votes
    13 Posts
    1k Views
    G

    @chpalmer said in Really Strange Behaviour - Have I been Hacked?:

    SIP clients are designed to keep the connection live. 24/7. Some devices are better designed than others.

    SIP was not originally designed to be behind NAT. NAT was hacked in (emphasis on hack) later when the idea of marketing to the residential and small business markets. Vonage was sued early on for patent infringement. Since then other carriers are being very careful to keep out of that particular court room and thus everyone does things just a little different.

    The problem becomes when you as a customer of one company with their specific devices has an issue trying to find someone that knows that exact system and their requirements/method of operation can be difficult. Generally things are close enough and the knowledge that is bestowed is usually enough. But little things can crop up and stimie everyone..

    You don't want your ATA states to expire normally. The whole idea is that a constant connection is kept active between the ATA/phone device and the carrier SIP server. Otherwise you would not be happy with the quality of your VOIP carrier.

    Thanks for the reply @chpalmer - As a result of your email, I did a quick pcap to see what what going on (now that my system is functioning normally), and from what I can see the ATA sends a UDP packet about very 20-25s to keep the firewall open.

    And I agree with you that documentation of SIP is somewhat "spotty"... you may have uncovered the reason why. I don't know when that was or when the suit occurred, but IIUC a patent is good for 17 years, so it should hopefully be expiring soon as this is a very mature protocol.

  • A little support for a home user.

    50
    0 Votes
    50 Posts
    4k Views
    DaddyGoD

    I wrote on a similar thing here on the forum about 7 months ago, it was just a DOCSIS issue (DOCSIS modem + WAN dynamic IP)

    MAC spoofing was useful, because the CMTS and EdgeQAM in the ISP network, were manufactured by Cisco.

    pcEngines APU MAC vendor address CMTS doesn't seem to like it and at the moment we spoofed the MAC address of an old E900 Cisco router, the APU pfSense box immediately got the DHCP lease on WAN interface.

    (perhaps Cisco to Cisco)

    52ec5c9b-c26f-4e72-9226-b11efa2c55de-image.png

    and ☺

    e1744a86-91c1-4f5c-beb6-ad51fd3c138f-image.png

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.