• 0 Votes
    8 Posts
    4k Views
    M

    @viragomann

    I wish to do this using a proxy service that I have subscribe to however they provide a hostname and port so I don't think I can use the GW method here.

  • Remotely Enable if_pppoe kernel driver and reboot

    7
    0 Votes
    7 Posts
    694 Views
    R

    @brookheather ~ After almost 8 days up time, this is what it shows:

    MTU: 1400
    In/out packets: 116406954/41636681 (134.50 GiB/6.15 GiB)
    In/out errors: 0/2
    Collisions: 0

    Also, my Internet connection is 1Gbps up and down fiber.

    RPSmith...

  • Normal traffic graph in "idle"?

    13
    0 Votes
    13 Posts
    876 Views
    R

    @Gertjan said in Normal traffic graph in "idle"?:

    A Windows OS ? You ever heard about telemetry data ? The keylogger you installed on your PC

    It's Ubuntu though ;)

    @Gertjan said in Normal traffic graph in "idle"?:

    What is that ?

    A website to check what is behind an IP. For example:
    https://otx.alienvault.com/indicator/ip/34.149.144.89

    @Gertjan said in Normal traffic graph in "idle"?:

    That's your browser doing auto-captive-portal detection. This is port destination 80 TCP traffic, right ?

    Yep port 80 traffic

    @Gertjan said in Normal traffic graph in "idle"?:

    You were actually using all this stuff all the time. It's always a good thing to find out how things work.

    I am still trying to figure things out. I haven't gotten into the packet capture part yet. Only superficially by checking Snort captures. I also googled what TCP Dup ACK is but I don't know if it is something to worry about or a normal occurance. The last couple of days I saw 3 out of 5 Windows computers make outgoing connections to malicious IPs that are flagged on otx.alienvault and it makes me worried. Even on a fresh Windows install I had this happen by a service that should only communicate on LAN (Windows LanmanServer). I just blocked the whole IP range to be safe. It was also blocked by Snort with "ET INFO Packed Executable Download", Misc activity 3. I hope it's just a false positive.

    @stephenw10 said in Normal traffic graph in "idle"?:

    No. The source and destination are stll the same.

    Ok great. Thank you :)

  • Pfsense updated to 2.8 and now get an crash report

    20
    0 Votes
    20 Posts
    2k Views
    randombitsR

    @stephenw10 Yes, I meant Wh it went from ~900 watt hours to ~825 watt hours per day.
    2025-06-10 13_46_34-Microsoft Excel - Yesterday.txt.png

  • Is CE 2.7.2 fully patched as secure as CE 2.8 ?

    3
    0 Votes
    3 Posts
    305 Views
    stephenw10S

    Yup the system patches package can only update run-time scripts. Some things that are packages can be updated separately so you can pkg upgrade them in the current branch.

    But a new release will have fixes and patches to core components that cannot be applied so would be considered more secure.

    However at this point there are no known issues with 2.7.2 that would concern me.

  • How to connect to XGS-PON controller

    15
    0 Votes
    15 Posts
    948 Views
    AndyRHA

    @stephenw10 Not my day, something is blocking pings... Tried SSH and it connected.
    For future generations this is the outbound NAT rule.

    672df450-669b-4b8f-bc26-593dc0025cdb-image.png

    VLAN42 is where my PC sits.

    Thank you for the help. Easier than I thought it would be.

  • Questions on State Timeouts

    4
    0 Votes
    4 Posts
    372 Views
    stephenw10S

    If it works better for XBox live then sure. 😁

    I don't have one to test so I can't really comment. Just be aware that anything you do to make states last longer is going to increase the total state count at any time. That might be no problem for you with 4G to play with. In many use cases it would be though.

  • How can I remove this IPv6 DNS entry? (post 2.8.0 upgrade)

    18
    0 Votes
    18 Posts
    1k Views
    hydnH

    @stephenw10 yes you are correct. It was to their own 853 servers (apple’s pricate browsing feature). I’m not sure exactly what I changed but the warning is gone now.

  • [solved] NTP / UDP Port 123 blocked since update 2.7.2 -> 2.8.0

    15
    0 Votes
    15 Posts
    1k Views
    stephenw10S

    Aha! Well in that case you should really find out what the asymmetry is and correct that. Using interface bound states is more secure. You may hit that asymmetry still in some other way and see more problems in the future.

    It's almost certainly because that server is multi-homed and doesn't need to be.

  • Frequent pfSense Plus GUI Crashes and Service Failures

    16
    0 Votes
    16 Posts
    1k Views
    S

    @stephenw10

    Thank you!

    After applying all the patches, I no longer encountered any crashes in the pfSense GUI.

    Will monitor the system status and this error message;

    nginx 2025/06/05 07:28:56 [error] 12856#100360: send() failed (54: Connection reset by peer) while logging to syslog, server: unix:/var/run/log

  • WAN out errors since 2.8 upgrade

    Moved
    16
    0 Votes
    16 Posts
    982 Views
    stephenw10S

    Yup I see it. I'll reach out to the dev and let him know. Though I think he's at BSDCan next week,

  • Netgate 4100 SMART: "Unable to detect device type"

    5
    0 Votes
    5 Posts
    399 Views
    S

    @courtalj You can of course. There are a few ways to reduce writing, and one ZFS change coming in 25.03.

    https://forum.netgate.com/topic/195879/netgate-2100-life-expectancy/8

  • 1 Votes
    8 Posts
    634 Views
    S

    @stephenw10 said in upgraded from SG-2220 to 4200 Max and Internet performance is extremely improved... why?:

    Disk speed would only make much difference if you're proxying/caching a lot on the firewall. Which you probably aren't.

    But when it's running at the limits of the CPU everything is getting queued. Other services, like DNS, will be slower to respond. It cannot prioritise anything unless it's already dropping/queing at some lower bandwidth.

    That's it! It is that the CPU is just bogged down because my Internet has grown to rates that the CPU load (or maybe just bus/RAM load) is taking longer to respond. Not because it's maxed out, but because it's just highly loaded.

    Glad you like the 4200! 😁

    Yah. I wish I had done this a while ago now. I can't believe how snappy things are.

  • Remove presence plus upgrade option

    2
    0 Votes
    2 Posts
    208 Views
    stephenw10S

    If you send me your NDI in chat I can make it ineligible for Plus.

  • first boot freez (pfsense 2.7.2 + protectli)

    8
    0 Votes
    8 Posts
    795 Views
    R

    Hi guys, first of all sorry for the delay, and thank you for your help. Tonight I started working on it again and I downloaded pfSense version 2.7.2 again from here: https://atxfiles.netgate.com/mirror/downloads/. I didn't use Balena Enhancer anymore, and after trying to reinstall everything, this time it worked.

  • Netgate 2100 out of space and won't start gui

    11
    0 Votes
    11 Posts
    720 Views
    A

    @stephenw10 The best of times, the worst of times.

  • System Tunables Question

    2
    0 Votes
    2 Posts
    245 Views
    stephenw10S

    Unlikely to hurt in most setups. 100 pings a second is more than most pfSense install should ever see.

    Disabling redirect shouldn't cause a problem if your network is configured correctly. In reality you would probably see a stuff stop working in a lot of networks that were being redirected. It will allow you to find those misconfigured devices though. 😉

  • Since upgrade to CE 2.8 the plus branche is gone.

    6
    0 Votes
    6 Posts
    541 Views
    stephenw10S

    Yes, exactly that. You cannot downgrade and 2.8 is newer than 24.11. When 25.03 is released it show as an available branch for eligible devices.

  • Hosting websites from behind pfsense

    2
    0 Votes
    2 Posts
    226 Views
    johnpozJ

    @kdmiller61 setup a dynamic dns for your pfsense wan IP that changes. Use that fqdn to access pfsense wan IP, setup a port forward for whatever you want to be forwarded to behind pfsense.

  • tcsh: No entry for terminal type "vanilla"

    3
    0 Votes
    3 Posts
    194 Views
    P

    @patient0 Got it, thanks for quick explanation, it is helpful.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.