• PFBlockerng Filtering Issues

    3
    0 Votes
    3 Posts
    427 Views
    GertjanG

    @PnetG

    To fact check this :

    @stephenw10 said in PFBlockerng Filtering Issues:

    pfBlocker-ng by itself does not do anything.

    do this :

    fea78bd9-9465-4d14-96c1-9c9489dafffa-image.png

    and Save.
    The goto pfSense package de install, and remove it.
    Just for the fun, reboot pfSense.

    First check : no more issues ? Right ? If wrong, the issue wasn't pfBlockerng, as it isn't there.

    Now, install pfBlockerng. Just install - do not activate it.
    ( I can't remember if it is activated by default, though )

    But test now again : no issues what so ever, right ?

    Now, start adding changes, add a feed (one at the time / one per day !) to pfBlockerng.
    As soon as you have issues, you'll know what to undo : your last step.

  • AT&T Gateway bypass/true bridge using new authbridge

    43
    0 Votes
    43 Posts
    7k Views
    GPz1100G

    @matthewgcampbell I have never experienced a scenario where it passes traffic for a short amount of time then stops, at least not in the context of eapol auth related. It either passes or it doesn't. Then again I've never done any proxy bypasses either, can't really comment on odd behavior as a result.

    I assume you're following this - https://docs.netgate.com/pfsense/en/latest/recipes/authbridge.html ?

    You might want to give a try to one of the proxy scripts here - https://github.com/MonkWho/pfatt/tree/master . This is what we used before vlan0 compliant wpa_supplicant and dhclient.

    Edit, one other idea to try is the old dumb switch bypass method.

    I can't find a good write up but in essence you connect ethernet from ont and gateway to a dumb switch (preferably not netgear). Wait until the lights on the modem are all green and stop flashing. Disconnect gateway cable while leaving ONT/switch connected. Connect cable from the modem to your pfsense wan port (again, you're not touching the ONT/switch cable). Pfsense should be configured for dhcp on wan.

    See if you experience the same disconnect issues after x amount of time. If you do, try a release /renew on the wan. If it doesn't pull an ip, try rebooting pfsense only. This whole time, the link between the ONT and switch should remain connect and as far as ONT concerned, remain authenticated.

  • Unknown reason: network became unaccessible

    11
    0 Votes
    11 Posts
    597 Views
    stephenw10S

    If that happened I'd expect a bunch of 'xxxx is using my IP address' logs in pfSense. It's possible they have simply been rotated out though.

  • FreeRADIUS issues after update to 23.09

    6
    0 Votes
    6 Posts
    389 Views
    S

    @michmoor It’s a package bug from a few pfSense versions ago so no real release notes. Anyone who saved (or changed and saved) the default settings is ok. But it was quite confusing. We changed several things but not that one page.

    Upgrading the package triggers it also as I recall.

  • 0 Votes
    44 Posts
    3k Views
    stephenw10S

    Ah, well that's a much better solution. Adding NAT in there is always a workaround.

    That NAT looks like it should match and be applied though.

  • Firewall Rule Counters Max Size?

    23
    0 Votes
    23 Posts
    2k Views
  • New 2100, default login incorrect

    5
    0 Votes
    5 Posts
    376 Views
    J

    @stephenw10 thanks. Using the rest button worked. Somehow I missed that in the reset instructions. I appreciate the help.

  • To schedule a reboot

    34
    0 Votes
    34 Posts
    38k Views
    C

    @SteveITS

    And a simple solution without asking 10 questions in return and being told your doing things wrong.

    Thanks !

  • SG-1100, outages, no DHCP, 10 days log missing

    26
    0 Votes
    26 Posts
    1k Views
    S

    @Cabledude said in SG-1100, outages, no DHCP, 10 days log missing:

    So do you uncheck this one on your clients' devices?

    We rarely use DNSBL at a client. I use it at home and it causes enough issues there because my wife works in search so "needs" the add links on her devices. :)

    My thought is, turn on the logging if we are troubleshooting a problem that needs logging. Otherwise it's a few years of disk writes that no one looks at.

    (At clients we have a few layers of protection... DNS forwarding, advanced a/v, etc.)

  • Retain config adjustments in raddb configuration

    4
    0 Votes
    4 Posts
    173 Views
    stephenw10S

    If you add that as a patch in the System Patches package that will be retained in the config and you can just reapply it.

  • OpenVPN Alert?

    3
    0 Votes
    3 Posts
    141 Views
    rayrayrayraydogR

    @stephenw10 Thanks, that should be doable for me.

  • 2.7.0 PPPoE Continually Reconnecting

    46
    0 Votes
    46 Posts
    8k Views
    stephenw10S

    Yup, just looking for confirmation. Though this test setup was hitting it that doesn't mean it's fixed for all cases necessarily. There was a bunch of work went into the gateway/WAN handling in 24.03 though.

    If we can confirm the fix we know that will work in CE.

  • Update Remote Address on GRE with DNS IP

    10
    0 Votes
    10 Posts
    443 Views
    stephenw10S

    Doesn't really matter what you have locally it's what you're connecting to. What is supported at the remote side?

  • Speed full not handle

    23
    0 Votes
    23 Posts
    1k Views
    stephenw10S

    Yes, run a test that's showing limited download speeds. Look at the traffic graphs and check if it's using the VPN.

  • preinstall software

    4
    0 Votes
    4 Posts
    524 Views
  • cannot load /etc/bogonsv6: Invalid argument

    8
    0 Votes
    8 Posts
    869 Views
    stephenw10S

    You had to remove the bogons fles?

    It probably wasn't loading the new ruleset if that's what you saw.

  • Problem with interface name

    4
    0 Votes
    4 Posts
    336 Views
    stephenw10S

    Yup, that^.

    It could be clearer on some pages though. https://redmine.pfsense.org/issues/14555

  • Strange VPN Problem - VPN Only Allows Access to PFSense on LAN Subnet

    19
    0 Votes
    19 Posts
    1k Views
    J

    @stephenw10
    I need to go on a dang course :) :)

    I am great with Virt and Linux and MS - but I suck at firewalls :)

    Thanks mate :)

  • Using dpinger to force DHCP lease renewal

    8
    0 Votes
    8 Posts
    335 Views
    A

    @stephenw10 Great. Thank you. I'll have a play with that and see if I can up the frequency of renewals.

    Thanks
    Andrew

  • Dynamic alias with history

    9
    0 Votes
    9 Posts
    1k Views
    P

    nice information

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.