• WAN slower than expected, even with LACP

    4
    0 Votes
    4 Posts
    388 Views
    stephenw10S

    The on-board NICs on the C2758 will use up 4 queues/cores. Running that top command will show what's happening.

    Steve

  • Package restart, pfSsh.php playback svc restart doesn't work, UI works

    5
    0 Votes
    5 Posts
    1k Views
    V

    Just happened today again

    [2.4.4-RELEASE][Vetal@router.place.somedomain.com]/home/Vetal: pfSsh.php playback svc restart tinc Attempting to issue restart to tinc service... tinc has been restarted.

    Nothing is added to the syslog, I did tail -f to it. Nothing related in tinc.log

    Next time I'll check "ps aux | grep tinc", today's while in "stuck state" was not wide enough to fit "/usr/local/sbin/tincd" part. I already UI-restarted it

  • [Solved] PROBLEMS WITH SERIAL CONSOLE

    14
    0 Votes
    14 Posts
    3k Views
    J

    You can consider this problem solved.

    Thanks

  • 10G NAT/Firewall performance problems

    16
    0 Votes
    16 Posts
    3k Views
    GrimsonG

    @farmwald said in 10G NAT/Firewall performance problems:

    I'm quite serious about being willing to make financial contributions to Wireguard port to PFSense.

    https://forum.netgate.com/category/30/bounties good luck.

  • configs are auto-saving once per minute

    7
    0 Votes
    7 Posts
    914 Views
    S

    No. ACB and local config backups are separate systems. A checkbox to allow vouchers syncs to be excluded from local backups might be a good idea. I'll look into that once v 2.5 is stable.

  • Freeradius 3.0 on Pfsense 2.3.4 problems

    21
    0 Votes
    21 Posts
    3k Views
    C

    That same error keeps looping every minute or so.

  • L2TP RADIUS Static user IP.

    1
    0 Votes
    1 Posts
    131 Views
    No one has replied
  • Port Alias

    4
    0 Votes
    4 Posts
    449 Views
    DerelictD

    Anther way that might make more sense when (possibly someone years from now) is reading the rule set would be to make four rules:

    pass TCP 25
    pass TCP 587
    pass TCP/UDP 53
    reject any

    You could combine 25 and 587 into a port alias but not sure it's worth it for just two ports. Anyway, that's what I would do.

  • how to delay/change service startup order.

    2
    0 Votes
    2 Posts
    568 Views
    KOMK

    https://www.freebsd.org/cgi/man.cgi?rcorder(8)

    https://serverfault.com/questions/527981/how-to-change-rc-d-startup-order-in-freebsd

    Note that any changes you make will likely be blown away at every upgrade.

  • Gateway monitoring

    7
    0 Votes
    7 Posts
    1k Views
    K

    @stephenw10

    Thanks for the reply. That completely makes sense. I'll experiment on upload traffic shaping to see if this solves my issue.

  • Internal routing of Vlans

    15
    0 Votes
    15 Posts
    2k Views
    G

    @ak-0 said in Internal routing of Vlans:

    @Derelict
    Vlan are created under physical Lan interface ig0 and parent interface for these vlan`s is ig0.

    Actually what i want to achieve is if traffic from Vlans goes out first it should reach
    Vlan gateway>>Lan gateway>> Wan port and should not do Vlan>>Wan port.
    Tracert should be
    1.Vlan IP (192.168.100.1)
    2.Lan IP (192.168.10.1)
    3.Gateway IP (1.2.3.4)
    instead of
    1.Vlan IP (192.168.100.1)
    2.Gateway IP (1.2.3.4)
    I`m trying to double NAT for Vlans, first NAT should be internal and then gateway.

    @tim-mcmanus : If we simply capture the packet and on inspection it can show the source device and then the route the packet came from. So, someone with that much information and hacking knowledge can easily walk into your network. Also, can send packet with header upside down to hit the server behind pfsense firewall, located on VLAN.

    I've worked in environments that required double NATs, and I would suggest avoiding it at all costs. The only real reason to do this is IP overlap between networks. Security through obscurity is not something to rely on, and even if they knew your internal IP was 192.168.1.20, they can't do anything with it from the outside.

  • 0 Votes
    8 Posts
    899 Views
    stephenw10S

    You are using a wireless router as an access point so this should still work if it is still routing (and NATing).

    But it would be much better to configure it as an access point only and put everything in the same subnet.

    https://docs.netgate.com/pfsense/en/latest/wireless/use-an-existing-wireless-router-with-pfsense.html

    Steve

  • Unable to Check For Updates

    Locked
    84
    0 Votes
    84 Posts
    74k Views
    tittanT

    Just go to console menu and "update from console" (option 13). After that wait for reboot and your sistem is updated and normal again.

  • L2TP VPN won't connect on new Windows 10

    2
    0 Votes
    2 Posts
    2k Views
    RicoR

    Can you show screenshots?
    Normally you just open the properties of your VPN connection, security tab and set 'Type of VPN' to L2TP.

    Also check
    https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/l2tp-ipsec.html
    and
    https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/l2tp-ipsec.html#troubleshooting

    -Rico

  • LOG

    4
    0 Votes
    4 Posts
    484 Views
    S

    @grimson RDP is open just for 1 IP... this should be a way to monitor the blocked sessions.

  • Looking for information for college project.

    10
    0 Votes
    10 Posts
    804 Views
    B

    I have installed three official Netgate pfSense boxes at three different small businesses (2 restaurants and manufacturing plant), including one at my home.

  • Web gui slow - rest of system doing OK

    4
    0 Votes
    4 Posts
    488 Views
    T

    @averyfreeman said in Web gui slow - rest of system doing OK:

    DNS appears to be working fine...

    Pretty hard to monitor or adjust settings without web gui

    What about console access? What happens when you run top?

  • Installing VIM on pfSense ¿Should I?

    17
    0 Votes
    17 Posts
    12k Views
    JKnottJ

    @mohammad-0 said in Installing VIM on pfSense ¿Should I?:

    Long story short, to install regular vim just do...

    Tnx.

    I've used vim for many years and much prefer it to the vi included with pfSense.

  • Amazon Echo no longer working

    11
    0 Votes
    11 Posts
    3k Views
    XentrkX

    @gertjan

    I don't see any traffic from the Amazon Echo when using Wireshark (this is very strange) with one caveat. It was in a failure mode. I fired up Wireshark to start debugging. I first filtered on the source IP address (ip.src == 192.168.1.162). I saw some records from the Amazon Echo that it is using MDNS protocol. A web search led me to these resources:

    https://docs.netgate.com/pfsense/en/latest/packages/avahi-package.html
    https://www.lawrencesystems.com/pfsense-and-rules-for-iot-devices-with-mdns/

    Avahi is a system which facilitates service discovery on a local network. This means that a laptop or computer may be connected into a network and instantly be able to view other people to chat with, find printers to print to or find files being shared.

    I installed Avahi and placed the Echo back in the VPN tunnel. Later on in the day, it stopped working again about 12 hours later. The Echo only appears to work consistently when assigned to the WAN iface. This morning, I assigned the Amazon Echo back to the VPN iface and will monitor some more. Based on my last experiment, I expect it to fail sometime within the next 12 hours.

  • host that virtualbox vm pfsense is running on drops connections

    1
    0 Votes
    1 Posts
    119 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.