• Is it hacking?

    12
    0 Votes
    12 Posts
    796 Views
    JonathanLeeJ

    @Antibiotic get rid of that torrent client eventually it’s gonna break stuff if you keep using it. Trust me. Stop using it, think about how many ports you need open. It just takes one bad download

  • Arpwatch Notification receipient ignored

    3
    0 Votes
    3 Posts
    214 Views
    I

    @stephenw10 I'm also noticing this behavior. I'm on pfSense version 24.03-RELEASE.

  • Slow WAN Good LAN

    9
    0 Votes
    9 Posts
    389 Views
    R

    @stephenw10

    Both really.

    My infrastructure segment is inaccessible unless you can either get on that vlan through a physical port on the switch, or via a VPN that the FW originates as the server to get on an administrative network.

    There are also client mode VPN connections to a commercial provider.

    Regardless of if the traffic is coming in via the admin VPN and then out WAN, or on the local segment and then routed over the client VPN out to the web it takes a big hit to throughput. It would be difficult to pin down if it affects traffic both ways given the huge imbalance in the down/up speeds.

    It does seem to be limited to traffic routed externally that has the issue though. Running a speed test from the admin net to a local server works as expected despite going through a vpn tunnel to get to that network. But anything either from the admin vpn or going over the external commercial vpn to an external site is heavily limited.

  • pfsense cannot establish a direct connection to the ISP

    8
    0 Votes
    8 Posts
    539 Views
    B

    Thank you very much for your help. It works now! I have just reinstalled the pfsense.

  • Raw Log - how to remove "1" on the beginning log string ?

    8
    0 Votes
    8 Posts
    473 Views
    stephenw10S

    Mmm, I'm not sure we can anything about that. The webgui handles that formatting fine.

    I believe that's actually the syslog version, which i9s part of the expected format.

  • strange crash report everyday

    8
    0 Votes
    8 Posts
    412 Views
    stephenw10S

    If you created the VM in ESXi 8.0 then it's probably OK. But the VM version is separate to the ESXi version.

  • Restart webConfigurator from webConfigurator

    3
    0 Votes
    3 Posts
    751 Views
    stephenw10S

    Yes it should do that anyway. If you renew the cert for example.

  • Disable hardware checksum offload

    10
    0 Votes
    10 Posts
    2k Views
    J

    @jriofrio
    Just to corroborate your statement about (in my case) not need it to disable the hardware checksum with the intel x540.

    You are correct, I enable it back and reboot the firewall, tested the connection of OPT1 (2nd LAN) and all works good, no problems accessing websites.
    Also, I deleted the DoT rule for the 2nd LAN.

    All good.. I'm please with the results.

    PS: couldn't sleep , so i decided to do the changes now that no one is using the internet....

  • 4200 24.03 crash: fatal trap 12

    3
    0 Votes
    3 Posts
    287 Views
    LarryFahnoeL

    @kprovost Though my eye is untrained, I would agree that mine looks very similar. It has happened only once, so I will keep an eye on it and watch for when 24.11 goes GA. Thanks.

    --Larry

  • No internet on LAN IPv4 with WAN IPv6 PPPoE

    Moved
    2
    0 Votes
    2 Posts
    163 Views
    stephenw10S

    They will not give you even a carrier grade NAT IPv4 address?

    You should be able to access IPv6 sites from LAN OK as long as the ISP are sending you a fix delegation to use on internal interfaces?

    Are LAN clients receiving a routable IPv6 address?

    Steve

  • Download Manually openvpn-client-export

    6
    0 Votes
    6 Posts
    395 Views
    stephenw10S

    Yup you can't install a pkg for 2.6 into 2.7.0. If you managed to force that to happen it will likely break things.

    It should work fine in 2.7.2.

  • Radius and Ldap authentication for network devices

    Moved
    5
    1 Votes
    5 Posts
    400 Views
    stephenw10S

    Hmm, so using Windows NPS your user is able to login directly in priviledge mode?

    How is that configured?

    Do you have logs from the switch?

    This probably isn't actually pfSense related if it's just between Freeradius and the switch.

  • order of updates

    3
    0 Votes
    3 Posts
    249 Views
    stephenw10S

    The packages should be updated during the upgrade anyway.

    The new pkg system with dynamic repos makes accidentally pulling in packages from the wrong repo thankfully far more difficult. Since 23.09.1 you've had to opt in to the new repo when an update is available.

  • Best VPN for UDP

    16
    0 Votes
    16 Posts
    2k Views
    stephenw10S

    Yes you will need a least that. But you may also need the IGMP proxy configured, possibly at both ends, so that clients can see the streams and subscribe to them.

  • Dynamic DNS client "extracted from local system"

    18
    0 Votes
    18 Posts
    2k Views
    S

    @Gertjan said in Dynamic DNS client "extracted from local system":

    To know if the WAN IP really changed ? Easy. Store the latest succeeded updated WAN IPv4 address locally. This is the cache file. Compare the actual WAN IPv4 with the cache ;:

    Just going to take this opportunity to point out that this causes a problem in the case where we restore to a replacement router in our lab before delivery. DDNS is updated to our office IP. Live router will not update because its cached IP didn’t change. (Workaround is to manually modify the file on disk to fool it, as I recall)

  • radiusd General question about "client upgrade"

    3
    0 Votes
    3 Posts
    524 Views
    T

    I went and changed to yes and the logs seemed to clear up.

    Thank you again.

  • Update to 24.11 System logs - DHCP

    3
    0 Votes
    3 Posts
    325 Views
    T

    @stephenw10
    system - advanced - networking - ipv6 options - no checks, but... the WAN - IPv6 Configuration Type - DHCP6 so I changed to none.

    Thank you sir!

  • How to analyse logfiles - logz.io ?

    1
    0 Votes
    1 Posts
    91 Views
    No one has replied
  • NTP status question

    4
    0 Votes
    4 Posts
    302 Views
    QinnQ

    Thnx guys 👍

  • Diagnostics > DNS Lookup - takes very long time

    3
    0 Votes
    3 Posts
    354 Views
    stephenw10S

    ::1 is IPv6 localhost. Unbound should listen on that address by default but you may have disabled that. Or if you have enabled the forwarder instead.

    If you have upgraded from a much older version you might have it added specifically in System > General Setup and can remove it from there.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.