• Terrapin SSH Attack

    Pinned
    33
    16 Votes
    33 Posts
    24k Views
    STLJonnyS

    @willowen100 It basically forces your ssh (on the Windows side) to utilize that encryption algorithm. You'll need to do that on any machine you ssh from.

    I'd have rather found a more elegant workaround (preferably on the pfSense side, so the mod only has to be done in one location), but this works in a pinch.

  • pfSense Hangouts are available on YouTube!

    Pinned Locked
    1
    5 Votes
    1 Posts
    11k Views
    No one has replied
  • Share your pfSense stories!

    Pinned Moved
    76
    0 Votes
    76 Posts
    52k Views
    V

    Mine may be typical, maybe not.....
    Took over a large sennior living facility with a pretty robust it infrastructure spread between 4 IT rooms, 23 access points, 12-14 switches, and 200 internal devices and 200 guest/resident devices, all being run by a Sonicwall TZ350. I had been wanting to reallign everything network wise for some time but the TZ had 2 ports that were failing. I had worked with ClearOS from back in the ClarkConnect days and started searching for something similar. I found PfSense and it just fit what I wanted to do.
    I tested it a bit on an old Athalon64x2 rig for proof of concept and had planned on installing on a mini pc or something, but I wanted 6 nics. Standing in my main IT room I looked down and in the bottom of the rack were 4 HP DL380s, 2 of which were decommissioned 2 years ago. It's such huge overkill for hardware that it's hard to explain, but who wouldn't want redundant power supplies, raid 60 with 25 drives and remote system monitoring through ILO? lol

    I spun one up and loaded PfSense and started tweaking. 2 weeks ago I switched over and have been working out gremlins since.. Overall it's gone well, just one snag that a couple members here have been very kind in helping me work out. Thank you to this page for all the help.

    pfsense1.png

  • Questions about log messages

    26
    0 Votes
    26 Posts
    2k Views
    tinfoilmattT

    @bimmerdriver said in Questions about log messages:

    The inbound messages are all mangled the same way: fe80:5:: as opposed to fe80::.

    The outbound messages are all mangled the same way: fe80:6:: as opposed to fe80::.

    Both fe80:5::/128 (i.e., fe80:0005:0000:0000:0000:0000:0000:0000) and fe80:6::/128 (i.e., fe80:0006:0000:0000:0000:0000:0000:0000) are valid IPv6 host addresses and are within the fe80::/10 link-local reserved address block (i.e., fe80:0000:0000:0000:0000:0000:0000:0000 - febf:ffff:ffff:ffff:ffff:ffff:ffff:ffff).

  • Complete Fail replacing NIC

    Moved
    5
    0 Votes
    5 Posts
    97 Views
    stephenw10S

    So what will definitely happen here is that the NDI, which is calculated from the hardware at boot, will change because pfSense now sees different NICs in the system. That means it will be unable to connect to the pkg system to check for update etc which may cause some slowness on the dashboard which runs an update check by default. But that shouldn't cause any dramatic slowdown.

    If you restore a config in that situation it will be unable to reload packages will could cause problems.

    I can usually migrate the registered NDI to the new value one time one you have the final hardware config in place.

    @rpm5099 said in Complete Fail replacing NIC:

    However, it inexplicably causes all kinds of other bizarre issues with pfSense seemingly unrelated to interfaces at all.

    Like what? Anything other that slowness in the gui?

  • Auto config backup question

    3
    0 Votes
    3 Posts
    39 Views
    mudmanc4M

    Thanks for the reply Steve

    Saving the key is clearly stated, which I did not do.

    I assumed restoring a local backup would have said information.

    However, looking through the config file, I see the password is saved in plain text.

  • 0 Votes
    24 Posts
    267 Views
    stephenw10S

    Hmm so it did appear to upgrade to 24.03 patch 1?

    You might have a filesystem issue that cannot be fixed by the normal processes that run at boot. It's also possible you have an issue with the eMMC drive.

    Try checking the eMMC status: https://docs.netgate.com/pfsense/en/latest/troubleshooting/disk-lifetime.html#emmc

    If that looks OK then I'd try backing up the config and re-installing 24.11 clean: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/reinstall-pfsense.html

  • External access to a internal web server (VPN site2site)

    13
    0 Votes
    13 Posts
    112 Views
    W

    @viragomann, thank you very much for your help!

  • WireGuard gateway pending after reboot

    3
    0 Votes
    3 Posts
    236 Views
    A

    @LaUs3r

    I am experiencing the same even on the latest pfSense Plus beta version (25.03)

  • pfBlocker GeoIP rules getting confused ?

    5
    0 Votes
    5 Posts
    146 Views
    N

    @stephenw10 Thanks again. I've submitted a correction suggestion to MaxMind for the IP. I assume that the regular scheduled auto updates of pfBlocker databases within my pfSense also update Maxmind's free GeoIP database as well -- I noticed the free GeoIP database is updated by Maxmind every month. Cheers

  • Possibility of capturing ssl-keys using tcpdump in the pfsense shell

    11
    0 Votes
    11 Posts
    169 Views
    B

    @johnpoz

    getting a squid transparent proxy running on pfsense with ssl/mitm from scratch wasn't easy tbqh (but maybe that's another topic...)
    it is quite satisfying though to see the RT access logs flow in pfsense, and the secure lock in the browser at the same time (=
    squiddie.jpg
    but still, as you mentioned before, without the device accepting my ""internal-ca"", it's besides the point 😁

  • Schedule a reboot?

    9
    0 Votes
    9 Posts
    122 Views
  • KIA DHCP

    7
    0 Votes
    7 Posts
    126 Views
    stephenw10S

    Are you able to test in 25.03-Beta?

  • Netgate 6100 using 2.5Gbe port for WAN?

    11
    0 Votes
    11 Posts
    174 Views
    stephenw10S

    I have seen it happen in the past when the change is initially made. Somehow the dhcp server is still running on the interface. But not for a while and not beyond the initial switch.

  • 0 Votes
    16 Posts
    320 Views
    stephenw10S

    Well from what we've seen here it is googles fault. Cogent is not preventing you use other DNS servers. What's happening is that Google's servers detects you are resolving DNS from a different location than you're are sourcing requests and flags the connection as suspicious in some way requiring additional screening. The same way that some sites will do that for VPN connections. A "DNS leak" is one way sites detect it. The interesting thing is that they only flag the Cogent connection that way.

    One other thing you could do VPN all your traffic over the Cogent WAN to the same location you are resolving from.

    But I would at least try resolving locally first since that would also set the DNS and source IPs to match. With DNSSec enabled you can be pretty confident in the results. Using DoT really just outsources your trust to cloudflare.

  • BGW320-500 set up without passthrough....problems?

    10
    0 Votes
    10 Posts
    297 Views
    AndyRHA

    @BigTulsa Exactly. Allows me to run with 1 less piece of equipment and a few less cables. XGS-pon on one end and regular 10Gb SFP on the other end. My 7100 is happy with it. It does get hot, so I have a 20mm USB powered fan cooling it. Now I have a use for one of the USB ports on the firewall. 😀

    You do need to keep the ATT router ready to power up, it would be best if it is up if you have a problem.

  • How to handle Telnet access to industrial control appliance

    8
    0 Votes
    8 Posts
    139 Views
    N

    @stephenw10 Excellent thank you.

  • using pfSsh.php to set user authorized_keys

    4
    0 Votes
    4 Posts
    316 Views
    T

    24.11 changed something. New code:

    $username = 'foobar'; $user_item_config = getUserEntry($username); $usernum = $user_item_config['idx']; $user = &$user_item_config['item']; $user['authorizedkeys'] = "base-64-encoded-string-here"; config_set_path('system/user/'. $usernum . '/authorizedkeys', "base-64-encoded-string-here" ); write_config('edited SSH public key for user foobar via pfSsh.php'); local_user_set($user);
  • pfSense updates & Package Manager not working correctly

    Moved
    12
    0 Votes
    12 Posts
    148 Views
    stephenw10S

    Usual suspects are some browser plugin blocking a script or similar. Though I've never seen that particular behaviour before.

  • Why IPv6 DNS server on dashboard, when no IPv6 used?

    10
    0 Votes
    10 Posts
    120 Views
    M

    @johnpoz Ok, thank you. So to avoid any possible side effects by doing some exotic settings mentionned in your post, I decided to follow the "ocd monkey gone with simple click" suggestion.

    Thank you all.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.