• 0 Votes
    3 Posts
    623 Views
    K

    @dotgate
    I'll add a little on my own
    c) there is no problem activating these options (if the device allows it)

    https://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html
    https://man.freebsd.org/cgi/man.cgi?qat

    however, version 2.7.2 does not include the core modules of the QAT driver
    (Intel QuickAssist Technology (QAT) [Plus only])

    But, if you build your Freebsd 14.0 kernel on any test device, you can download this driver manually into the PF kernel (by copying several files)

    1928c0d4-207f-4416-b8ac-1854b2e61e0c-image.png

  • package issues after upgrading hardware

    10
    0 Votes
    10 Posts
    416 Views
    stephenw10S

    When you restore the config if should pull in any packages that were installed as long as it has access to the repo.

  • How to configure pfSense as a router for two internal LAN subnets?

    27
    0 Votes
    27 Posts
    33k Views
    stephenw10S

    If you have a downstream (internal) router with other subnets behind it pfSense needs static route to those so it knows where to route traffic.

    https://docs.netgate.com/pfsense/en/latest/routing/static.html#example-static-route

  • Netgate 8200 what tests to do with iPerf3 -> problems

    11
    0 Votes
    11 Posts
    1k Views
    S

    @stephenw10

    Thank you very much for your analysis and advice! 😊

    With the configuration changes mentioned above, I no longer have pfsense blocking, it's a bit of a shame that some settings aren't more “original” configured for a (in my case) 8200.

    I'm glad to have found the https://forum.netgate.com/topic/182534/just-purchased-a-netgate-8200-having-a-few-issues/13topic which helped me enormously to find a solution to my problem.

    EDIT

    Last test

    16c681da-6cab-4ad6-b09e-d190ec1fad3f-image.png

  • Constant: One or more OpenVPN tunnel endpoints may have changed its IP.

    20
    0 Votes
    20 Posts
    9k Views
    stephenw10S

    Yes, exactly like that.

  • PfSense - Auto reboot script when google is unreachable..

    20
    2 Votes
    20 Posts
    22k Views
    L

    @Teddy thanks that's what I was looking for and it works in version 2.7.2

  • IPSec dropped traffic, can't find explanation

    8
    0 Votes
    8 Posts
    589 Views
    stephenw10S

    In Status > IPSec you should see traffic on the packet-counters for both P2s. If you don't they either don't match the traffic or your firewall rules don't.

  • one ISP 2 IP

    30
    0 Votes
    30 Posts
    2k Views
    A

    @stephenw10 Ok, thanks)))

  • Intermitent loss of WAN routing

    13
    0 Votes
    13 Posts
    851 Views
    A

    @stephenw10 Yes, indeed :-). When pinging something continually and the problem occurs it will fail until pfSense+ ages and renews the ARP table entry or, as with my script, any ARP Request containing the layer-2 and layer-3 addresses of the pfSense+ WAN interface is transmitted to the ISP.

    Thanks @stephenw10.

    Andrew

  • About Status/DHCP Leases

    3
    0 Votes
    3 Posts
    345 Views
    GertjanG

    @Unoptanio said in About Status/DHCP Leases:

    "on line"

    is still shown. Here :

    7751a241-64e0-4f99-93a7-035954be5abd-image.png

    the green arrows.

    And before you ask : "on line" or the green arrow means probably something different as what you might think.

    "On line" or the green arrow means : the IP is in the "arp cache". See here Diagnostics > ARP Table

    pfSense, or the DHCP server, is not 'pinging' (or something else) every (lease) IP every xx seconds to see it it replies.

    Static or not : the admin knows what leases are static, as he set them up as static.
    But I get it : why showing 'n/a' twice, even if it's true, if the word "Static implies the same. Not sure why that was changed.

  • easyrule block and alias not working

    5
    0 Votes
    5 Posts
    206 Views
    D

    @stephenw10

    Yes.

    Kids_Devices Host(s) 10.10.10.50, 10.10.10.51, 10.10.10.52, 10.10.10.53, 10.10.10.54, 10.10.10.55, 10.10.10.56, 10.10.10.57, 10.10.10.58, 10.10.10.59…

  • Unable to ping across interfaces

    8
    0 Votes
    8 Posts
    675 Views
    johnpozJ

    @stephenw10 hahah, but its good... I believe this comment could be considered as covering the no route problem, or wrong route

    "what your pinging either sending its answer to somewhere else"

    But I like the clarity of making sure route is there to send it to back to pfsense.. Will keep that in mind for next thread we get about such an issue. Which I know there will be, since it is a common question to be honest ;)

  • DIOCADDRULENV: No error: 0 and DNS not resolving

    2
    0 Votes
    2 Posts
    259 Views
    stephenw10S

    What error do you see when you try a DNS Lookup?

    Are clients using pfSense for DNS?

    Is Unbound running?

  • This topic is deleted!

    0
    0 Votes
    0 Posts
    12 Views
    No one has replied
  • WAN packetloss

    7
    0 Votes
    7 Posts
    567 Views
    Sergei_ShablovskyS

    @markdudov said in WAN packetloss:

    @stephenw10

    In what cases are the gateways dropping ping requests?

    Also in case for example, when You have Your ISP's device (mediaconvertor-router) ETH up, and assigned IP by ISP's DHCP, BUT PACKETS BLOCKED on ISP's core level.

  • Problem with DNS resolver

    64
    0 Votes
    64 Posts
    6k Views
    stephenw10S

    That should be fine. And, just to be clear, I would have expected what you did before to also be fine. pkg shows that it sees that as an upgrade and takes appropriate action.

    It shouldn't be possible to have two versions on the same pkg installed.

  • Improve GUI loading speed

    3
    0 Votes
    3 Posts
    350 Views
    A

    @stephenw10 Ok. thanks

  • CVE-2023-51384 and CVE-2023-51384

    5
    0 Votes
    5 Posts
    648 Views
    S

    Also I checked my plus. It is appropriate version on plus.
    And no, this isn't holding out stuff for paying customers and shafting the community...cert token auth is generally an organization that should be paying the license fee anyway. Home users just plain don't do that very often... nor is it exploitable reasonably. Same with the system names thing. This is a rare thing...even more rare in non professional roles.

  • Generate authentication key for NTP

    4
    0 Votes
    4 Posts
    606 Views
    johnpozJ

    @markdudov so you want to generate a key for the ntp server on pfsense so your clients can auth?

    Not sure pfsense has support for that option, pretty sure the ntp auth they have available is for pfsense to auth to some ntp server as a client.

    "Authentication allows the NTP client to confirm it is communicating with the intended server, which protects against man-in-the-middle attacks."

    And I don't believe they allow for talking to more than 1 ntp server with different keys either.. Maybe in 24.03 or I know there is some patch or working on a patch for ntp auth.

    Personally I don't understand the use case for auth for local ntp.. You concerned that there will be some rogue ntp server on your network and you need to make sure your talking to the correct one via auth? Or that only your own clients on your own network are validated via auth to your server?

    Seems like extra work/config/setup for like zero benefit other than a complexity that could cause issues.. In what scenario on your own local secure network does this added complexity provide added anything? Is someone going to get on your own local network and fire up some ntp server to do mitm on your ntp traffic? For what purpose exactly? And how would they go about such a thing without having physical access or already compromised your wifi?

  • Access pfSense menu

    13
    0 Votes
    13 Posts
    829 Views
    johnpozJ

    @skogs windows added ssh many years ago.. But they always seem to be behind last I looked.

    I always just install this openssh version

    https://www.mls-software.com/opensshd.html

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.