• Missing or expired CSRF token

    19
    0 Votes
    19 Posts
    14k Views
    M
    I also see this screen every time I login using Roboform. Oddly, if I ask Roboform to "Fill" the fields and press ENTER myself... I don't get the message. Looks like the way Roboform "presses Enter" is not compatible with the pfSense login page.
  • OpenSSH - patching CVE-2018-15473

    9
    0 Votes
    9 Posts
    1k Views
    C
    @fperloff said in OpenSSH - patching CVE-2018-15473: Interesting conversation about relative importance of fixing bugs vs adding to the attack surface. In this case, OpenSSH was patched, but FreeBSD doesn't use a patched version. The only options I see for passing the PCI scan are to either install a later version of OpenSSH for FreeBSD, which doesn't appear to exist, or to patch it myself and self-certify. If the latter, what tools are required and how do you patch existing software? FreeBSD itself has a newer version available in the ports tree. I dont know specifics about pfSense packages though.
  • Upgrade from 2.4.4p3 to 2.4.5_1 PHP ERROR

    5
    0 Votes
    5 Posts
    575 Views
    S
    @waynec said in Upgrade from 2.4.4p3 to 2.4.5_1 PHP ERROR: upgrading the packages before the update Don't do that, that could pull in dependencies that don't exist on 2.4.4. Best practice is to uninstall packages, upgrade, and reinstall packages. For instance I'm pretty sure I've seen posts about people who upgrade a package and find out they upgraded PHP versions, so lots of things are broken. https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide-prepare.html#packages
  • Cannot add more working Interfaces (4 NIC PC)

    6
    0 Votes
    6 Posts
    693 Views
    V
    @Gertjan You will gather I'm a newbie and more often I can break what is already configured and working! Simple traps like disable the LAN for testing on the webGUI, lose everything, no GUI, no SSH then I recover the box, hook it up to peripherals and use the last but one backup. Thanks, yes I already spotted the default /32 netmask and changed it to /24. My routing problem was linked to assignments, what physical ports were assigned when I first installed the image. The reason all my clients are static IP is I could find no easy way to filter via DNS to allow some clients and websites to go to VPN and others to bypass VPN? Yes I could configure the TV for DHCP since it is now on its own subnet without routing via VPN. In UK some video streaming services detect proxies and block access over VPN. My LG 'Smart' TV is getting old now. The LG WebOS seems very slow (compared to pc browsers). I suspect the TV processing and memory storage for apps is insufficient when I do want HDTV streams. I may solve all my streaming speeds and data link to the LG server by switching to a HDMI mini PC on my new pfsense TV port and just use the TV as the display device. Others have already posted a huge list of servers LG smart TVs can connect to in the background. A dedicated pc for TV and subscription services should simplify firewall rules for privacy. Most forget that once registering a smart TV warranty, the TV serial number, IP address and any email addresses given are linked to you. Gertjan - Thanks for your input, I will try that out. I already use pfBlocker on the private LAN. I forgot about creating a static MAC lease for the TV.
  • Setting up router before deployment

    4
    0 Votes
    4 Posts
    417 Views
    bingo600B
    He..He Been there , and "lost" the world by leaving it set to auto. Worked for a quite a while , and then some "Glitch" made it switch to the "other" Gateway , my OVPN tunnel. Since then i have always forced it to the ISP router GW. Note: I'm not using ipv6 (ISP doesn't provide) , so i left that to auto [image: 1603951186030-selection_2020102906-54-52.png]
  • Accessing Pfsense In Virtual Box

    3
    0 Votes
    3 Posts
    324 Views
    ?
    Hi sorry im new on this thing... what im trying to is to replace Cisco 1841 Router with pfsense the cisco 1841 router has failed to work properly after a recent power failure at our place and for a temporary replacement we have setup a pc with pfsense installed in virtual box with the same ip as the router. i added a static summary route in pfsense firewall rules Pfsence 10.130.0.0 255.255.0.0 10.130.50.10 virtual box setup - Nat, Bridge Adapter Virtual Box Host adapter - 10.195.50.18/255.255.254.0/10.195.50.10 Pfsense LAN 10.130.50.4 1st pc network adapter - 10.130.50.5/255.255.255.248/10.130.50.3 2nd pc network adapter - 10.195.50.19/255.255.254.0/10.195.50.10 Old Router lan interface 10.130.50.4/29 Old Router Wan interface 10.195.50.20/23 now i can access pfsense (10.130.50.4) in all my vlan..pfsense is up and running but i can't ping the pc 10.130.50.5 or 10.195.50.10 in my vlan and also i have no internet in my vlan or pfsense i am able to browse internet from the virtualbox pc and able to ping 10.195.50.10 any other pointer on how i can fix this ? what do i need to setup in pfsense in order to get internet to work ? current pfsense setup ip wan v4 : 10.195.50.20/23 ip Lan v4: 10.130.50.4/29 this is my old cisco router config Router.txt
  • New Internet Service and Modem, Gateway Pending / Unknown

    3
    0 Votes
    3 Posts
    980 Views
    C
    @viragomann A new modem from the ISP, It's not Static IP, looks like the ISP provides DHCP because if I connect it straight to a computer it gets a public IP and works, this is the Network Connection Details that gives me: IPv4 Address 76.30.XX.XX IPv4 Subnet Mask 255.255.254.0 IPv4 Default Gateway. 76.30.XX.X IPv4 DNS 75.75.75.75 75.75.76.76 I did configure the pFSense WAN interface for DHCP correct see below screenshot. [image: 1603882207039-screen-shot-2020-10-28-at-5.48.58-am.jpg] This is how the Gateway status is : [image: 1603882371746-old.jpg] The default WAN is the old internet with the old modem service that it's working fine. The WAN2 is the new Internet Service and new modem it's just stuck on Pending. Booth connections are from the same ISP Comcast. Thanks in advance.
  • PfSense migration

    5
    0 Votes
    5 Posts
    422 Views
    U
    Thank you good news!!!!!!
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • Help getting pfSense running on ESXI VM

    5
    0 Votes
    5 Posts
    535 Views
    J
    I have replaced the switch that died and now I'm working on tweaking and getting the network set up just the way I want it. Here's what I have so far... IP - 500/500 Mbps fiber to the house with PPPoE configuration to the WAN of my pfSense router. Cabling - All of the backbone wiring is brand new CAT8 cabling Router - pfSense running in a VM on my server using 2 of the 4 ports of a quad gigabit network card. Switching - 1 Unifi 8-port POE managed switch and 2 Flex-Mini POE managed switches. Access Point - 1 Unifi AC-PRO access point. I'm trying to set up a guest wifi network that gives me a sequestered network with a simple password for guests and that I can limit the bandwidth fairly easily. I'm a little confused about what to set up in pfSense and what to set up in the Unifi Controller as it seems that there is quite a bit of overlap between what each can do. I have seen some tutorials about setting up a network like I want to but they all seem to be using an older version of the Unifi Controller than the current one and the options are definitely different. Any guidance about this would be most welcome!
  • kdb_enter+0x3b: movq

    21
    0 Votes
    21 Posts
    5k Views
    bmeeksB
    @wouwie said in kdb_enter+0x3b: movq: @jimp pfSense-CE-memstick-2.5.0-DEVELOPMENT-amd64-latest supports the NIC again. FreeBSD error? pfSense-2.5 is based on FreeBSD-12 while pfSense-2.4.5 is based on FreeBSD-11. FreeBSD-12 has a rather big change with the way hardware vendors develop their NIC drivers. FreeBSD-12 uses the iflib API to wrap up a lot of NIC functionality with regards to communicating with the kernel. The iflib framework now takes care of a lot of things that formerly the individual hardware vendor software developers had to handle. My guess is the issue you were having with your hardware on FreeBSD-11 (11.3/STABLE in the case of pfSense-2.4.5) got fixed in FreeBSD-12.
  • Pfsense NOT booting

    23
    0 Votes
    23 Posts
    3k Views
    B
    It's in the Protectli knowledge base articles on installing pfSense 2.4 & FreeBSD 11.2. I've seen the issue reported with various devices using Braswell SoCs, not just those manufactured by Yanling (Protectli). As an alternative to changing the BIOS settings as you have done, there is also a work around by entering a command during installation.
  • Upgrade from 2.4.5 to 2.4.5_1 fails

    5
    0 Votes
    5 Posts
    710 Views
    M
    @kiokoman Thanks for the link. The upgrade log /conf/upgrade_log.latest.txt looks OK with a lot of expected stuff and no errors/warnings or anything else suspicious. Web UI also reports the expected version 2.4.5-RELEASE-p1 (amd64). I hope to find some time to investigate why rebooting fails but it'll have to wait for a quiet time...
  • No link on second NIC after reboot

    5
    0 Votes
    5 Posts
    699 Views
    L
    @kiokoman anyway, the messages disappeared after the Realtek-Update. The network is always available, at least for the other devices in the network.
  • Create a bootable USB flash disk on MacOs?..

    2
    0 Votes
    2 Posts
    430 Views
    ?
    Balena Etcher works great. https://www.balena.io/etcher/
  • ODROID-XU4........Go or no Go

    5
    0 Votes
    5 Posts
    1k Views
    T
    @stephenw10 Thanks for the links that's some deep stuff. A bit too granular on that topic for me however I was able to takeaway the basics which is very interesting. I have my hands in so many jars this kind of info can bog me down for the simple fact of wanting to learn all about it and then realizing I don't really have a need or use for the level of understanding I achieved.
  • Installation pfsense 2.4.5-p1 failed on HP Elite 8200

    3
    0 Votes
    3 Posts
    433 Views
    L
    @stephenw10 thanks, it's ok
  • firmware upgrade seems to have bricked the unit - how do we fix this?

    5
    0 Votes
    5 Posts
    757 Views
    J
    my issue seems to be that for some reason something still wants the old php stuff which has been zapped. I'd load a new one but don't know how to get it,. lots of message like; Warning: PHP Startup: Unable to load dynamic library 'zlib.so' (tried: /usr/local/lib/php/20131226/zlib.so (/usr/local/lib/php/20131226/zlib.so: invalid file format), /usr/local/lib/php/20131226/zlib.so.so (/usr/local/lib/php/20131226/zlib.so.so: invalid file format)) in Unknown on line 0 note old version.... and in the old version directory all the files are now 0 bytes long. I suspect it ran out of space at one stage of the upgrade. I'd load new (old) copies but don't know where to find that old version of php pkg.
  • Failed upgrade on SG-2440 2.4.4

    3
    0 Votes
    3 Posts
    433 Views
    J
    might have run out of space? look in /usr/local/lib/php/20170718/ and see if stuff missing. I see: [2.4.5-RELEASE][admin@]/conf: ls -la /usr/local/lib/php/20170718/ total 4232 drwxr-xr-x 2 root wheel 1024 Oct 9 11:02 . drwxr-xr-x 5 root wheel 512 Oct 1 05:30 .. -rw-r--r-- 1 root wheel 41696 Mar 23 2020 bcmath.so -rw-r--r-- 1 root wheel 22136 Mar 23 2020 bz2.so -rw-r--r-- 1 root wheel 16112 Mar 23 2020 ctype.so -rw-r--r-- 1 root wheel 88256 Mar 23 2020 curl.so -rw-r--r-- 1 root wheel 191912 Mar 23 2020 dom.so -rw-r--r-- 1 root wheel 42832 Mar 23 2020 filter.so -rw-r--r-- 1 root wheel 14040 Mar 23 2020 gettext.so -rw-r--r-- 1 root wheel 259664 Mar 23 2020 hash.so -rw-r--r-- 1 root wheel 461776 Mar 23 2020 intl.so -rw-r--r-- 1 root wheel 43048 Mar 23 2020 json.so -rw-r--r-- 1 root wheel 71680 Mar 23 2020 ldap.so -rw-r--r-- 1 root wheel 1074168 Mar 23 2020 mbstring.so -rw-r--r-- 1 root wheel 40768 Mar 23 2020 mcrypt.so -rw-r--r-- 1 root wheel 471088 Mar 23 2020 opcache.so -rw-r--r-- 1 root wheel 185504 Mar 23 2020 openssl.so -rw-r--r-- 1 root wheel 34272 Mar 23 2020 pcntl.so -rw-r--r-- 1 root wheel 108048 Mar 23 2020 pdo.so -rw-r--r-- 1 root wheel 28656 Mar 23 2020 pdo_sqlite.so -rw-r--r-- 1 root wheel 120272 Oct 2 01:39 pfSense.so -rw-r--r-- 1 root wheel 34880 Mar 23 2020 posix.so -rw-r--r-- 1 root wheel 49840 Mar 23 2020 radius.so -rw-r--r-- 1 root wheel 30080 Mar 23 2020 readline.so -rw-r--r-- 1 root wheel 34248 May 5 04:05 rrd.so -rw-r--r-- 1 root wheel 95232 Mar 23 2020 session.so -rw-r--r-- 1 root wheel 11912 Mar 23 2020 shmop.so -rw-r--r-- 1 root wheel 59448 Mar 23 2020 simplexml.so -rw-r--r-- 1 root wheel 91904 Mar 23 2020 sockets.so -rw-r--r-- 1 root wheel 48416 Mar 23 2020 sqlite3.so -rw-r--r-- 1 root wheel 16392 Mar 23 2020 sysvmsg.so -rw-r--r-- 1 root wheel 9464 Mar 23 2020 sysvsem.so -rw-r--r-- 1 root wheel 12648 Mar 23 2020 sysvshm.so -rw-r--r-- 1 root wheel 21416 Mar 23 2020 tokenizer.so -rw-r--r-- 1 root wheel 53120 Mar 23 2020 xml.so -rw-r--r-- 1 root wheel 34416 Mar 23 2020 xmlreader.so -rw-r--r-- 1 root wheel 48032 Mar 23 2020 xmlwriter.so -rw-r--r-- 1 root wheel 48376 Mar 23 2020 zlib.so -rw-r--r-- 1 root wheel 85680 Mar 23 2020 zmq.so [2.4.5-RELEASE][admin@]/conf: cd /etc
  • sg-3100 install on M.2 Drive

    3
    0 Votes
    3 Posts
    268 Views
    B
    @akuma1x gotcha thank you
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.