• Localhost IPv6 added as resolver after 24.11 upgrade

    8
    0 Votes
    8 Posts
    423 Views
    GertjanG

    @jim82 said in Localhost IPv6 added as resolver after 24.11 upgrade:

    it's a viable option

    But limited in time.
    I'm like everybody else, I saw IPv6 coming, and thought back then (early 2000) : "wow, that's something my kids have to deal with, IPv4 rocks, works fine, and I've other things to do".
    Now, its 2024. Every OS on planet earth will use initially IPv6, and if that doesn't work out, it will fall back to IPv4 if available.
    Read again what I've just said. For every connection that is created, this decision step is taken.

    True, not every ISP offers a IPv6 connection. Lets presume most do now. And if they do, chances are the connection is pretty broken in the way they implemented it "not as it should be". (RFCs are clear, but they are like us : don't want to learn new things, and, it costs them $€)
    We've seen this already happening ones, when IPv4 went mainstream for 'everybody', when ISPs were created. It took a decade or so for IPv4 as a connection method became a no-brainer. These days, it works out of the box, with much knowledge needed.

    Anyway, if you can, make IPv6 work. deal with it now. Our kids have already enough problems to deal with, like flooding, overheated planet and so on 😊

  • Plex through surfshark wireguard pfsense vpn

    77
    0 Votes
    77 Posts
    9k Views
    G

    @jhmc93 said in Plex through surfshark wireguard pfsense vpn:

    @Patch pfsense doesn’t have a WiFi device to broadcast WiFi. Pfsense is a side step as it also ran off a power line network plug for just my media servers, so I narrowed it down so when I connect to my isp WiFi my Plex shows indirect connections but if I join my VPN program through my laptop it goes back a normal connection.

    Yes, that ^ otherwise what is the point of having pfsense at all?
    If you are looking to improve network safety/security and perhaps add more functionality, you really need to move everything over to be on the LAN side of pfsense.
    Right now you are just making life difficult for yourself.

    The best, and also cheapest solution would be if you can connect pfsense directly to the incoming cable (ISP WAN cable in pfsense instead of ISP router). Then turn off DHCP in the ISP modem, and connect one of it's LAN ports to pfsense LAN. This turns it into an AP and you are good to go...

    Otherwise check if the ISP router has bridge/passthrough mode. If not you need to place pfsense in a DMZ, which the router probably has.

  • what could be wrong - client access to search

    1
    0 Votes
    1 Posts
    155 Views
    No one has replied
  • assist in finding matching rule

    8
    0 Votes
    8 Posts
    402 Views
    stephenw10S

    You can sort of do it using the pftop state and rules views but you don't get the rule description (label). The label view doesn't really help.

  • dtrace command to analyze file modification

    4
    0 Votes
    4 Posts
    297 Views
    GertjanG

    @jarlel

    dtrace has quiet a list of conditions to be met for it to work.
    The kernel has to have supported modules, and compiled with 'trace' options set. I wouldn't be surprised that can't be found on pfSense, a firewall.
    A FreeBSD dev station, yeah, of course.
    Look here.

    @jarlel said in dtrace command to analyze file modification:

    I am trying to find a way to detect changes

    An idea :
    The file your interested in, change the owner and or the read write execute flags.
    Make it read only for everybody.
    What will happens now ... will the process that actually updates = writes, will it cash ? complain ?
    FreeRadius has some pretty extensive logging : just stop / kill it in the GUI, and then on the console (or SSH) access, fire it up :

    radiusd -X

    If a process fails, freeradius or some other process, you should see it complaining - in the logs of course.

  • Cannot set LDAP to use group for OpenVPN authentication

    4
    1 Votes
    4 Posts
    276 Views
    stephenw10S

    Hmm, so it appears that just the extended query is filtering out all users even though they should be members of the G_Open_VPN group?

  • Rules for Rustdesk stopped working

    11
    1 Votes
    11 Posts
    705 Views
    D

    @stephenw10 hmm will have to look out for that. Part of the reason for doing it also to tinker and learn more about the possibilities. I don't learn as much from just reading but from guided setups then messing around with them once I see how it is supposed to work.

  • Network time protocol and wifi thermostat

    9
    0 Votes
    9 Posts
    505 Views
    N

    It does have a switchable setting to turn DST on and off. Basically I just had to unregister the device, remove the location defined, recreate the location then register the device. All good now.

  • CaN I setup PPOE on Modem instead of Pfsense?

    Moved
    5
    0 Votes
    5 Posts
    151 Views
    stephenw10S

    Yup, exactly just recover it during the install or at boot afterwards using the External Config Locator. 👍

  • NTP driving me crazy: offset -1410.220612 sec

    10
    0 Votes
    10 Posts
    610 Views
    GertjanG

    @provels said in NTP driving me crazy: offset -1410.220612 sec:

    They say the man with 2 watches never really knows what time it is.

    That's why you pool them up 😊

  • Backup Netgate Device ID

    3
    0 Votes
    3 Posts
    175 Views
    T

    Ok i'll write you privatly

  • 0 Votes
    7 Posts
    361 Views
    M

    @Gertjan

    Yes these two are the ones I meant by saying "default".

    but yeah you are absolutely right about the others generated by other packages.

    @stephenw10

    Thanks for the info dear 🙏

  • SG2100 100% CPU usage post upgrade to 24.11

    Moved
    12
    0 Votes
    12 Posts
    2k Views
    stephenw10S

    What widgets do you have on the dash?

    Did you try the suggested patch to revert the widget refresh method?

  • How to handle Crash-Report

    8
    0 Votes
    8 Posts
    242 Views
    E

    @stephenw10 said in How to handle Crash-Report:

    Is this the first time you've seen it?

    Yes, it was first time.
    I do use pfsense since mid June 2024. So not for very long

  • pfSsh playback can't run as non-root after 24.11 update

    7
    0 Votes
    7 Posts
    730 Views
    stephenw10S

    Mmm, that is probably the way to go. Those scripts are expected to be run as root. Curious that it changed in 24.11 though.

  • blocking Youtube and tiktok using rule firewall and fetched ip list

    7
    0 Votes
    7 Posts
    323 Views
    R

    @stephenw10 this is what I was looking for thanks a lot

  • Cannot connect to Internet after editing WAN's name

    10
    0 Votes
    10 Posts
    764 Views
    stephenw10S

    I haven't been able to replicate this so far. Changing the name of the WAN or editing other values on it doesn't by itself appear to cause a problem. It must be some combination of things or some unique config. 🤔

  • i915kms not loading/DisplayPort or HDMI console not mounting post boot

    9
    0 Votes
    9 Posts
    833 Views
    stephenw10S

    If its actually being used you would see a bunch of logs indicating the new device when that module is loaded.

  • establish site to site vpn with aws vpc

    6
    0 Votes
    6 Posts
    174 Views
    stephenw10S

    Well yes.
    Where is pfSense running in that case?

    If it's in AWS then you need to use the elastic IP assigned to it there. I had thought you were using the AWS VPC wizard remotely.

  • Solved - Why won't this work (restore config into backup device)?

    5
    0 Votes
    5 Posts
    234 Views
    N

    @stephenw10 Got it. For some reason it didn't like Brave (my usual browser).

    Switched to ungoogled chromium and it worked fine. Restored my backup and I'm waiting currently as it reinstalls packages.

    Thanks for your help.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.