• Porting BGE Driver to IFLIB...

    27
    0 Votes
    27 Posts
    3k Views
    NollipfSenseN

    @NRgia said in Porting BGE Driver to IFLIB...:

    Because I don't want to hijack @NollipfSense 's thread anymore

    I would not worry about it ... I left the thread open for others, such as yourself who may want to attempt the porting ... thank you for contributing!

  • Custom Build Box?

    3
    0 Votes
    3 Posts
    734 Views
    NollipfSenseN

    @StarsAndBars I went with using a quad-core i7 Apple Mac Mini server ... replaced hard drive with SSD mirror and thunderbolt 2 PCI enclosure with an Intel i350 ... easy to upgrade to 10GBe, nice small form factor, low electricity consumption. I must say though that I like and sometimes drool when I see Netgate XG-7100U or desktop.

  • Trouble Installing from USB onto APU2

    6
    0 Votes
    6 Posts
    726 Views
    S

    @dotdash

    I definately get those same CAM error messages as you indicated. All I do is boot to an existing image, connect the console cable and putty in, drop to shell, and plug in the USB drives. Happens pretty much any time I use a USB 3.0 drive. I've plugged in 3 of them with the same issues. A USB 2 drive that I have doesn't do it.

  • 601.423468 [3911] netmap_transmit em1 full hwcur 222 hwtail 155 qlen 66

    3
    0 Votes
    3 Posts
    849 Views
    Cool_CoronaC

    @bmeeks Thanks B.

    Waiting for the 2.4.5p1 release to be available to upgrade the CPU cores to 16 again. Hopefully it will solve the problem.

  • ARM Cortex vs Intel?

    9
    0 Votes
    9 Posts
    2k Views
    valnarV

    I'm going back to the drawing board. I think at this point I should stick with something Intel based. Thanks for all the replies.

  • Best config money can buy

    Locked
    12
    0 Votes
    12 Posts
    2k Views
    johnpozJ

    Spammer is my bet ;)

  • Predicting resources used by packages

    6
    0 Votes
    6 Posts
    603 Views
    bmeeksB

    @riftor_77 said in Predicting resources used by packages:

    Thanks for all the responses so far. For context, I set up my system similar to pfSense baseline guide with VPN, Guest and VLAN support and then added pfBlocker and Suricata on top.

    My question is actually how to calculate what changing each of those many variables will add or subtract from the resource load. I want to find it my ideal settings, calculate how much resources everything takes, and then build my system to those specifications.

    For example, if I am using pfBlocker and I add another feed, how do I calculate the additional CPU and RAM usage that adding that feed will require? Let me know if I am clearly explaining my request.

    Why not simply run a controlled test and see for yourself? Measure CPU and RAM usage while running traffic through the box with iperf without that additional feed enabled, then repeat the exact same test with the feed enabled. You can even do it several times and compute an average. I doubt you see very much of a change, though.

    Just remember to reset the states in between the tests to be sure the firewall actually inspects the test traffic against the entire rule chain and does not use an existing state established during the first test to bypass a bunch of rules in the second test.

  • Hardware recommendations for new user

    14
    0 Votes
    14 Posts
    1k Views
    C

    @valnar said in Hardware recommendations for new user:

    If one of your requirements is route at gigabit speeds (#6) internally, and not just be limited to the 100Mb Internet speed, then some of the smaller units won't suffice. That said, I do have a PC Engines APU2 myself for my pfSense box it's great, but it won't go much more than 600-700Mb.

    Yeah, I would definitely want to keep internally routing at gigabit speeds. My understanding from watching some of the Lawrence Systems reviews is that it isn't an issue with the 3100 and above. My concern with that unit is whether is can reliably do OpenVPN at > 100Mbps and secondly, if it's up to the task if I were to start installing packages. The LS review suggests it is, but I've seen some posts suggesting it might not be.

    Thanks

  • Temperature sensor : Intel NIC

    6
    0 Votes
    6 Posts
    2k Views
    stephenw10S

    Yep, that's probably a good idea.

    If it can be read I doubt it would be that hard to display it.

    Steve

  • Zotac CI323 Installation - Controller Failures

    25
    0 Votes
    25 Posts
    11k Views
    N

    @Orbixx said in Zotac CI323 Installation - Controller Failures:

    @noconnor Any luck?

    I added those entries to /boot/loader.conf.local and that has definitely bypassed the boot issues. I did try adding those elements to System > Advanced > System Tunables (for config backup) but couldn't get that to work. I'm pretty sure that was a just me entering them wrong.

    I haven't tried moving over to a 2.5 version yet to see if that makes a difference.

    edit:
    Actually, reading the docs for System Tunables, it looks like I was mistaken and those values (Loader Tunables) are not applicable to System Tunables.

  • 0 Votes
    15 Posts
    2k Views
    stephenw10S

    Yeah, that's a huge latency. When it reloads normally it's barely noticeable.

    I would at least test disabling smp to see if it solves the issue. If it does that is fixed in 2.4.5p1 so that will be a permanent solution.

    Steve

  • Problem with Intel Pro 1000

    17
    0 Votes
    17 Posts
    2k Views
    T

    Thank you guys, very much. All your suggestions and comments really helped me get familiar with pfSense. I'm starting to question why I went such a long time avoiding it.

    The NC-365T card came in and pfSense recognized it right away. But before it came in I had already learned how to use VLANs for the multiple internal subnets. Now I believe that VLANs is the best solution. It saves ports on the switch. Plus, the bottleneck is still the going to be the WAN connection and not the single Trunk port for all the subnets. I also learned how to use Virtual IP addresses for my static IP subnet on my WAN. In my opinion, pfSense rocks.

    I will be using the NC-365T on my Hyper-V Server to separate NAS devices and shared printers into different VLANs.

  • Found that Realtek NICs are now adequately supported

    4
    0 Votes
    4 Posts
    598 Views
    D

    @Pippin: In my case it would be for home use. Problem was that I purchased that fanless PC before realizing that it would pose a problem. I was pleasantly surprised that the problem had gone away in the meantime.

    I am also wondering, whether Intel NICs carry a licensing premium.

  • Netgate SG-1000 Slowdown Connection Speed

    2
    0 Votes
    2 Posts
    214 Views
    stephenw10S

    The SG-1000 was a lower powered device, I would expect to see ~130Mbps through it in a typical install.

    So 94Mbps seems low but you will never see anywhere near 500Mbps.

    Steve

  • Firebox LCD Driver for LCDProc

    398
    0 Votes
    398 Posts
    471k Views
    D

    @stephenw10 yea, very strange. It seems to me that the lcdproc service window where you set that information isn't copying and saving that information.
    Thanks again

  • Connectivity issues after applying new configuration

    2
    0 Votes
    2 Posts
    144 Views
    stephenw10S

    What exactly happens? What connectivity is lost?

    This happens with any config change? Creating a new interface is quite a big config change compared to, say, creating an alias.

    Nothing in that setup should present an issue, they are all well tested components.

    When you hit this what do you do to regain connectivity?

    Steve

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • Any out of the box working pcie LTE modems found?

    7
    0 Votes
    7 Posts
    952 Views
    stephenw10S

    I had a GSM modem in the 90's and I assure you it's not that bad. 😉

    I agree it could be a lot better. The best thing you could do to improve matters is to port umb(4) driver from OpenBSD to FreeBSD, or persuade someone else to port it.

    Steve

  • Any benefit to going 10Gig on LAN interface with Gigabit WAN?

    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S

    I've been running this card for a while:

    ix0@pci0:2:0:0: class=0x020000 card=0x17d3103c chip=0x10fb8086 rev=0x01 hdr=0x00 vendor = 'Intel Corporation' device = '82599ES 10-Gigabit SFI/SFP+ Network Connection' class = network subclass = ethernet

    It causes reboot problems but that's almost certainly a BIOS issue in that particular box. It's an HP-560SFP+ card.

    x520 in general should definitely be supported, it's been in the ixgbe driver for years.

    Steve

  • How Do you Check NIC Interfaces In PFSense/FreeBSD?

    12
    0 Votes
    12 Posts
    23k Views
    DaddyGoD

    As in the previous posts before me, a suspiciously cheap card is sure to cause trouble, there are plenty of fake Chinese clones out there :-).
    It can be said that there is a good support for Intel cards under FreeBSD, but not all chipsets are suitable.
    It's a question of what you want to use it for in the pfSense?

    I350-based cards are perfect, with a smaller compromise I210 and possibly I211-based. (igb4) - https://www.freebsd.org/cgi/man.cgi?igb(4)

    As Steve recommended, search for possibly used brand (HP, Dell, etc.) cards based on Intel Ethernet controller.
    I would also take into account the recommendation of "bmeeks" (Bill Meeks) for your future use of NGFW:

    " Snort Package 4.0 Inline IPS Mode Configuration

    IMPORTANT HARDWARE LIMITATION
    The new Inline IPS Mode of Snort will only work on interfaces running on a supported network interface card (NIC). Only the following NIC families currently have netmap support in FreeBSD and hence pfSense: em, igb, ixgb, ixl, lem, re or cxgbe. If your NIC driver is not from one of these families, netmap and Inline IPS Mode is not going to work properly, if it works at all."

    The question of dual / quad is the extent of usage and the question of segmentation, how big is your network?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.