• CPU Activity - Possible Problem ?

    6
    0 Votes
    6 Posts
    941 Views
    ?

    little over a year later i find myself here. then i think ok let me scroll down, there are MANY 'zio_free_issue_'

    i assume this means free/available threads for write capability (zfs - input/output - free - issue - then the rest i assume is threads and then counts or something..) trails off

    compared to most in the forums i know jack nothin about specifics like this (excluding majority networking) but the labeling makes sense

    thanks either way to everyone 👍 👨‍💻

  • Another rookie pfSense & FiOS setup question

    15
    0 Votes
    15 Posts
    2k Views
    MikeV7896M

    I don't have FiOS TV, which apparently can be a major issue if you do, since some of their newer TV hardware REQUIRES the use of a FiOS router to retain full functionality of the boxes.

    But without the TV piece, I just have my pfSense box connected to the Ethernet connection on my ONT. I didn't have to do anything fancy for it to work (WAN is set to DHCP), and have no issues getting nearly full speed out of my Gigabit connection. IPv6 is not yet available unless you're in one of the four (possibly five) areas that seem to be in their testing for it.

    DSLReports is great for provider-specific setup questions.

  • SSH key wiped after reboot

    5
    0 Votes
    5 Posts
    2k Views
    E

    Thanks, this really worked.
    Disappointed I can't use my CLI Shell to copy across, but at least it's working.

  • 0 Votes
    3 Posts
    497 Views
    J

    @kiokoman , nice. Thanks!

    I donated $100 directly to the BSD Foundation instead.

  • pFsense on a HP Thin Client, AMD CPU G-T56N

    2
    0 Votes
    2 Posts
    840 Views
    stephenw10S

    Use different NIC types. AltQ is not supported by whatever devices you have. You should avoid USB NICs in general.

    See: https://docs.netgate.com/pfsense/en/latest/hardware/network-interface-drivers-with-altq-traffic-shaping-support.html

    In addition to the list linked there we add VLAN interfaces so one option would be to add vlans and apply the shaping on that.

    Steve

  • Ark server

    2
    0 Votes
    2 Posts
    461 Views
    stephenw10S

    The NAT reflection mode will make no difference to clients connecting externally or to the server itself connecting out.

    Do you see traffic blocked in the firewall log?

    Do you see oncoming states opened to the server?

    Steve

  • Vmware using ZFS mirror mode with 2 virtual hard drives (any advantage?)

    3
    0 Votes
    3 Posts
    370 Views
    stephenw10S

    With two virtual drives you can still recover one from the other if the filesystem is somehow damaged beyond repair.

    I don't think I've ever seen it done though. Generally if you're running on a hypervisor you probably have a UPS.

    Steve

  • ntp only connecting to some time servers

    28
    0 Votes
    28 Posts
    3k Views
    JKnottJ

    @nback said in ntp only connecting to some time servers:

    Fixed it! Set a default gateway for ipv6.

    You shouldn't have to. That should happen automagically, through router advertisements.

  • Port Forwarding

    14
    0 Votes
    14 Posts
    1k Views
    N

    @stephenw10 Thanks for the link - I will definitely watch.

  • Config changed to OLD configuration after reboot

    2
    0 Votes
    2 Posts
    349 Views
    kiokomanK

    how about Diagnostics / Backup & Restore / Config History ?

  • Snort Start at boot

    3
    0 Votes
    3 Posts
    452 Views
    P

    Thanks for your reply. It worked.

  • Strange issue - not sure how to fix

    93
    0 Votes
    93 Posts
    17k Views
    P

    OK - have removed all the other interfaces from system/routing/gateways, and have left the 1 remaining interface (WAN) as the selected default. No problems connecting to any of the VPN server instances. And DNS resolution remains functional. I will continue to monitor, but it really does appear that this problem has now been solved. Thanks again to @johnpoz and @stephenw10 .

  • Configuration with Two SIP Connections

    17
    0 Votes
    17 Posts
    2k Views
    L

    @stephenw10

    Thank you for your concern in my case.

    When the configuration from the second provider is directly done to the PBX Box while the first is through pfsense, I can use both Providers at the same time. My situation is, I do not want to hook providers into into the PBX hoping in the future I may have other Voice Connection from other providers as well. Connecting the PBX through the switch I think in my case is the optimal one just as I described in the diagram.

    -Lusekelo

  • VOIP - Moments of Silence in conversations. (Is this the Solution?)

    3
    0 Votes
    3 Posts
    465 Views
    stephenw10S

    Yes, for most that is not required but if the keep alive packet spacing is too high you may need to set conservative mode. Or use custom timeouts as you did.

    Steve

  • Bandwith Limit only for Internet

    2
    0 Votes
    2 Posts
    242 Views
    stephenw10S

    Setup Limiters to whatever bandwidth you need. Put default internet traffic in to those Limiters with firewall rules on LAN. Pass local traffic with rules above those that are unlimited.
    https://docs.netgate.com/pfsense/en/latest/book/trafficshaper/limiters.html

    Steve

  • changed LTE router, now heavy delay, but down/up Speed is fine

    30
    0 Votes
    30 Posts
    2k Views
    GertjanG

    Keep in mind that 1.1.1.1's primary goal is harvesting your DNS requests. Not replying on your ICMP requests, so if they (1.1.1.1) decide to stop doing that, for example for bandwidth reasons, your WAN could get marked as offline.

  • Set LAN rule to block outbound to one IP, can still ping it

    9
    1 Votes
    9 Posts
    813 Views
    J

    I'm not sure what's going on with this thing, creating or changing rules doesn't take effect unless it's rebooted. That's new behavior, it's always been immediate before this. I'm going to rebuild it tomorrow. Thanks everyone for the help.

  • Simple firewall as router

    6
    0 Votes
    6 Posts
    617 Views
    stephenw10S

    But it is only the reply traffic that goes back out though pfSense yes?

    As I said you will need an OUT rule on WAN since that will also be out of state TCP traffic.

    Let's see a screenshot of the blocked traffic you're seeing,

    Steve

  • 0 Votes
    12 Posts
    1k Views
    stephenw10S

    Ok so:

    Run through the OpenVPN remote access setup wizard

    Create a test user in System > User Manager and make sure you add a client certificate to that user created against the same CA the wizard created.

    Install the Client Export Package. You should now see the various client types available for your test user in VPN > OpenVPN > Client Export.

    Pretty much what it says here:
    https://docs.netgate.com/pfsense/en/latest/book/openvpn/using-the-openvpn-server-wizard-for-remote-access.html

    Steve

  • WAN IP and Public IP are not the same

    4
    0 Votes
    4 Posts
    738 Views
    V

    I had that situation months ago. I called the ISP and asked for a public IP and I got it immediately with no discussion.
    But that may depend on your internet contract.
    Maybe IPv6 is an option for you.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.