• DNSThingy on pfSense + pfBlockerNG

    3
    0 Votes
    3 Posts
    847 Views
    chudakC

    @artooro is it really true ? I saw it's conflicting with NAT port forward on 443.

    And it's understandable pfBNG and DNSThingy both need to use it, no ?

  • ntpd does not update?

    3
    0 Votes
    3 Posts
    826 Views
    ?

    @knebb
    Final solution:
    Outbound-NAT was misconfigured to always map to the VirtualIP even in backup mode.

    Switched to automated outbound NAT and now working fine.

  • DNS_PROBE_FINISHED_BAD_CONFIG

    1
    0 Votes
    1 Posts
    839 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • Performance Impact on Disabling the Kernel PTI?

    3
    0 Votes
    3 Posts
    3k Views
    E

    It's mostly less then %1 cpu load, but we are running on such an environment that any less latency is an important gain. So I am doing everything to increase the performance.

    What is the performance gain when I disable it? %10?
    and the risk that something may go wrong, such as not a successful reboot?

  • GRE tunnel only comes back online after firewall change

    2
    0 Votes
    2 Posts
    344 Views
    jimpJ

    Look under Diagnostics > States and compare what you see for the remote GRE endpoint before and after reloading the filter.

  • SSL Certificates for Local IP address [Solved]

    15
    0 Votes
    15 Posts
    8k Views
    jimpJ

    @johnpoz said in SSL Certificates for Local IP address:

    Does that method also allow for rfc1918 IP san entries? Or for a use of domain that is not valid on the public via tld, like local.lan, or single label domains that many users are found of

    No, it can't have IP address SANs and must have a valid domain that exists in public DNS. The hostname doesn't need to be public, but the domain has to be registered/have name servers.

    If so will have to play with this. But then again not too many switches and other devices have support for ACME that I have seen. Sot he local CA still has multiple advantages IMO.

    Yeah, for that kind of thing it could be a PITA to constantly update them with the ACME cert since it wouldn't be automated. Local CA does win out in that scenario.

  • is this a bug

    Locked
    2
    0 Votes
    2 Posts
    273 Views
    jimpJ

    More than likely it's a configuration issue, but that question still belongs in the Cache/Proxy board, not here.

  • Need to know throughput of Pfsense 2.3.5 VM running on ESXi 6.5

    4
    0 Votes
    4 Posts
    507 Views
    johnpozJ

    Yeah why would you be running 2.3.5, clearly you can not be 32bit limited. And your esxi is not even current either. But has mentioned its impossible to even guess without some details of your hardware.

  • OPT interface no connection after VPN setup

    1
    0 Votes
    1 Posts
    182 Views
    No one has replied
  • Pfsense w/API the v3 blog post

    1
    1 Votes
    1 Posts
    231 Views
    No one has replied
  • GEOM mirror in Pfsense 2.4

    4
    0 Votes
    4 Posts
    2k Views
    johnpozJ

    Thanks JimP for quick response.. I normally don't play with this stuff - but did recall a major change with the installer on 2.4..

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • wake-on-lan and permission denied error

    3
    0 Votes
    3 Posts
    935 Views
    A

    Yes, both interfaces are on the same system.

    It's a Netgate SG-2440, so there are four identical Ethernet interfaces. I can use the wake command from the command-line on three out of the four interfaces. WOL from igb2 also seems to work from the web interface. Only wake from the command line with igb2 is giving the permission error.

  • No internet via ethernet, only WiFi

    3
    0 Votes
    3 Posts
    381 Views
    SammyWooS

    @bumzag IP4 IP contain valid GATEWAY parameter?

    Go to a website and if...

    Comes back and says "site unknown/not found" = DNS broken.
    Comes back and says "unreachable" = no Gateway, IP4 missing/wrong param(s).

  • Shell/CLI Equivalent of Release/Renew from Interface Status Page?

    2
    0 Votes
    2 Posts
    1k Views
    JKnottJ

    @ink

    You may find something here:
    link text

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • serial interface

    3
    0 Votes
    3 Posts
    440 Views
    jimpJ

    If you set the primary console to be the video/vga console then most of the bootup messages would only go there.

    The kernel startup messages always go to both, then the pfSense boot scripts output only to the primary console, and then all consoles get a menu.

  • redirect to 20443 port

    4
    0 Votes
    4 Posts
    457 Views
    chudakC

    Thx @jahonix
    I actually see it ob Chome and FF, very annoying

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.