• RAM Disk enabled, but still constant writes to disk…

    34
    0 Votes
    34 Posts
    6k Views
    E

    Adding a client machine to my test network generates some writes on my test installation, which confirms it is related to the existence of client machines. Since it's unlikely related to traffic (as most of that is logged in RAM), I guessed it maybe something related to DHCP leases.

    I used a modified version of the find command listed by BlueScreenOfTOM above to identify some files being written to, and it seems like /etc/hosts is being written to quite regularly.

    I looked at the contents and it seems to be related to the DHCP leases getting written to the /etc/hosts files

    I believe this is caused by "Register DHCP leases in the DNS Resolver" being selected in the DHCP server settings, so I have removed that for now. Given my hostname is not really legit, these are pretty much pointless anyway.

    So far, disabling that has reduced the writes to zero.
    6cf5ea10-5535-45c3-9d71-535d270fbd11-image.png
    So perhaps the mystery is solved? :)

  • PFSense States monitoring

    4
    0 Votes
    4 Posts
    681 Views
    stephenw10S

    Ah, OK. Well since I can't replicate it in 2.4.4 it's probably something that has been fixed since 2.3.2 was released in 2016.

    You should upgrade for many reasons but an additional one is to retest this on that hardware/network in 2.4.4.

    Steve

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    21 Views
    No one has replied
  • Missing something obvious - pppoe with multiple IP address on WAN

    4
    0 Votes
    4 Posts
    919 Views
    stephenw10S

    Run a packet capture on the internal interface do you see the ping requests or replies there?

    Check the state table for open states using the .25 IP.

    Make sure you can ping out from the .25 IP in Diag > Ping.

    Steve

  • Setting up pfSense and L3 switch

    12
    0 Votes
    12 Posts
    3k Views
    W

    I followed the advice of bmeeks and have the VLAN routing done by pfSense.

    As my main goal was to ensure high throughput between my Server and domain joined clients (all on the same VLAN) and all of those devices are wired to the Netgear M4300-28G-PoE+ switch, the data is handled at L2 level by the switch and does therefore (to my understanding) not pass via the pfSense box.

    In the end, I also ditched the ISP Fritzbox because I didn't manage to get PPPoE passthrough working; my ISP gave me a fiber to ethernet converter instead.

    Everything has been working great ever since.

  • Package Manager ' There are no packages currently installed.'

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ

    https://docs.netgate.com/pfsense/en/latest/install/upgrade-troubleshooting.html

  • Configure two lan interface on the same pfsense

    6
    0 Votes
    6 Posts
    797 Views
    A

    Yep, right here (see attachment) under the Interfaces tab.

    Screen Shot 2020-01-23 at 11.27.08 AM.png

    Your new LAN can either be an actual network port if you have an open port on your pfsense box, or it can be virtual (VLAN) if you want to do it that way.

    Then see here for some setup instructions for this new interface:
    https://docs.netgate.com/pfsense/en/latest/interfaces/interface-settings.html

    Jeff

  • Our ISP asking strange configuration for WAN Connection

    15
    0 Votes
    15 Posts
    1k Views
    E

    I've couldn't detect what is not working, after upper comment the ISP installed additional router between pfsense and radiolink switch. Now we're using 176.xx IP for the WAN Interface. Thanks for all comments.

  • pfSense Freeradius as auth server for all pfSense firewalls

    11
    0 Votes
    11 Posts
    890 Views
    NogBadTheBadN

    secondary

    Screenshot 2020-01-22 at 14.16.18.png

    Screenshot 2020-01-22 at 14.16.45.png

    Screenshot 2020-01-22 at 14.16.52.png

  • Creating a backup of /root etc.

    3
    0 Votes
    3 Posts
    317 Views
    G

    @johnpoz said in Creating a backup of /Root etc.:

    Why would you want to do this? Just back up the config, have some install media around... Worse case you install pfsense clean and restore you backup.

    You can just use the ACB as well
    https://docs.netgate.com/pfsense/en/latest/backup/autoconfigbackup.html

    @johnpoz thanks for the input - here's what I'm trying to accomplish. I have some custom stuff that I would like to backup to a flash drive and be able to restore without depending on the network or another computer (just the pfSense box). Most of it is in root, and I have also created a user CUSTOM which is under /home/custom - I hope that I won't have to use it, but just in case something gets lost I want a fallback.

    Also note that as it stands the backup plugin can not backup root (see note above) - I don't know if Netgate is the maintainer or if it is someone else.

    As for the autoconfigbackup, I would love to use it, but I would rather have it point to a box inside my firewall - call me paranoid, but I keep finding out that things we thought were secure, aren't because of error or improvements in hacking tools. If it is never in the cloud, then it can't get stolen from the cloud.

    @johnpoz as an aside ". Worse case you install pfsense clean and restore you backup." - I it was just the base pfSense, I would agree with you completely .... but what about a use case where there are a lot of plugins? How does one make sure none of them have changed since they were installed/disappeared from the plugin repo? I had a problems several years back where I couldn't get the config to restore properly without connectivity, and I couldn't get connectivity with a working pfSense. I think that some changes have been made since then, but it is so long ago all I can remember is that I had a very uncomfortable several hours trying to get things back up.

  • Mapping ISP provided Static IP to MAC addresses -behind Pfsense

    22
    0 Votes
    22 Posts
    2k Views
    stephenw10S

    Yeah it's like I said you can bridge the VLAN the server is on to the WAN. So:

    Edit the server VLAN interface and set it to v4 type none.

    Create a new bridge in Intercaces > Assignments > Bridges and add the WAN and the server vlan interface to it.

    Set the server to be a dhcp client.

    Make sure you have firewall rules on the server VLAN interface to allow the dhcp client traffic. And any other traffic you may need. Be aware that rules use 'Server net' will no longer be valid since that interface no longer has an IP or subnet.

    Add rules to WAN to allow whatever traffic you need to reach the VoIP server.

    Steve

  • Pfsense in Azure - Cannot reach host on IPsec tunnel

    35
    0 Votes
    35 Posts
    5k Views
    stephenw10S

    You may need a route to 10.233.2.0/24 if that is not accessible via the default route but only then.

    I assume you can access the pfSense webgui from 10.233.2.4?

    Otherwise you would only need those routes to establish connections over the VPN from the firewall itself rather than from hosts behind it.

    Your screenshot where you have 10.233.2.0/24 in the P2, which is required, shows 0 packets in or out on it but it also shows as established for 0 seconds. If you have that up, or both P2s there, and send traffic from either end do you see the packet counter increase in either direction?

    Steve

  • [SOLVED] PfSense Certificates Disappers

    3
    0 Votes
    3 Posts
    395 Views
    manjotscM

    @jimp Thanks, fixed.

    Annotation 2020-01-20 121352.png

  • Something Weird with Network after Box went offline

    10
    0 Votes
    10 Posts
    523 Views
    stephenw10S

    Hmm, well hard to say without more logs etc from the time. Unbound was not responding for some reason. Neither was any other DNS server configured for the system. Without anything in System > General that could only be servers handed to pfSense by the ISP via DHCP on WAN.

  • 0 Votes
    13 Posts
    2k Views
    GertjanG

    You're right.

    6743f69d-639a-4060-a514-af60c52ee008-image.png

    Test :

    d0ba3ebe-8738-4385-ad29-69e89e3e05c5-image.png

    which is correct.

  • how do you disconnect reconnect network interface command line

    4
    1 Votes
    4 Posts
    572 Views
    C

    @stephenw10 thank you works great (:

  • Nzbget bugging down pfsense

    2
    0 Votes
    2 Posts
    475 Views
    stephenw10S

    It's clearly maxing out something. You should definitely test over a wired connection first though you could just be seeing wifi issues.

    Steve

  • Can't figure out why my phone is blocked from apps.

    6
    0 Votes
    6 Posts
    678 Views
    M

    @JKnott Yep the phone was connected to the network, it had a static ip at first, then i removed its static from pfsense, which gave it a dchp address. All the internet worked, the only things that didnt work were the walmart app, amazon app, and affirm app. I could browse the internet, download off of play store, and play games. I dont understand what happened, after I formatted the pfsense hard drive and reinstalled it, my phone could connect to the apps. It was 100 percent something i did in pfsense some how, because I could connect to those apps on my other internet from a different provider, and at walmart.

  • No Internet from WIFI connection on Router from 2nd LAN subnet

    45
    0 Votes
    45 Posts
    6k Views
    ?

    @stephenw10 kk, that solves it. I'll go firewall route! Thanks!

  • Delay when connecting via specific Interface.

    6
    0 Votes
    6 Posts
    511 Views
    stephenw10S

    Well that could definitely be true, why would they allow access to their DNS servers publicly?

    That doesn't explain why you saw the delay to IP addresses directly though.

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.