• Routed IPsec using if_ipsec VTI interfaces

    Pinned
    45
    3 Votes
    45 Posts
    12k Views
    jimpJ

    @obrienmd said in Routed IPsec using if_ipsec VTI interfaces:

    On latest devel for factory and CE, everything functionally is looking great. Had to restart *pinger (I forget which one is used these days) for gateways to get out of pending after initial interface bring-up, but packets are all flowing, no weird state issues, very solid :)

    Great! I'll have to check back on the gateways, one of mine is OK and it comes right up, I had disabled gateway monitoring on the other pair because it was interfering with the packet captures I was taking when diagnosing some of the other traffic issues above.

  • Want 2.4.x to be released faster? Help test feedback tickets!

    Pinned
    9
    0 Votes
    9 Posts
    11k Views
    lohphatL

    @jimp Thanks! I feel I need to pitch in more QA where I can since I don't code anymore.

  • HEADS UP: 2.4 does not support i386 or NanoBSD

    Pinned Locked
    10
    0 Votes
    10 Posts
    13k Views
    jimpJ

    Bits don't matter. Age and availability of hardware matter. You're comparing apples and oranges.

    That's all fodder for another thread, though.

    Locking this as it's only attracting tangents, it was meant as an announcement only.

  • Upgrading 64-bit NanoBSD from 2.3 to 2.4

    Pinned
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • radvd.conf syntax error - won't start

    Moved
    4
    0 Votes
    4 Posts
    9k Views
    jimpJ

    Set Debug in the DHCP6 Client Configuration on WAN as well, then check the logs (main system log, routing log, etc) to see what shows up.

  • DHCP relay over TUN OpenVPN

    5
    0 Votes
    5 Posts
    9k Views
    S

    @eidolontubes Example below...

    (LAN 192.168.1.0)---(Netgate OpenVPN Client TAP VPN IP 10.10.10.2)---Internet---(Netgate OpenVPN Server TAP VPN IP 10.10.10.1)---(Remote LAN 192.168.10.0 - DHCP Server 192.168.10.5)

    Leave "IPv4 Remote network(s)" blank in your OpenVPN config. Use system routing instead.

    On VPN Client side
    Create Gateway 10.10.10.1
    Create Route 192.168.10.0 -> 10.10.10.1
    DHCP Relay 192.168.10.5

    On VPN Server side
    Create Gateway 10.10.10.2
    Create Route 192.168.1.0 -> 10.10.10.2

  • Backup & Restore PHP error

    2
    0 Votes
    2 Posts
    722 Views
    stephenw10S

    Yes, it looks like that fix didn't make it into the last build before we stopped snapshots to move to FreeBSD 12.

    https://redmine.pfsense.org/issues/9316

    Applying the commit on that ticker via the System Patches package fixes it though:
    e0b32eb9e6b040fd14025b5c32644959ba67250e

    Steve

  • Ntopng redis issues

    6
    0 Votes
    6 Posts
    3k Views
    H

    @doktornotor This worked for me too! Thank you!

  • LCDProc givin some php errors on boot

    5
    0 Votes
    5 Posts
    971 Views
    S

    Hey i use it also it works, but i have the errors above, if i remove LCDProc from pfsense they disappear, when i install LCDproc back they again appear but LCDProc works ! can you put out a screenshot with your settings please ? maybe there needs to be something setup that i did not

  • Did updater get broken?

    3
    0 Votes
    3 Posts
    768 Views
    B

    Ah OK, that makes sense.

    Thanks for the reply.

  • Atom C3758 - Supermicro A2SDi-8C-HLN4F - PFsense?

    Moved
    16
    0 Votes
    16 Posts
    12k Views
    R

    @ozlecz I am getting 300dl/30ul using a 5 way round robin PIA VPN outgoing setup. Using PIA's high encryption I get 150dl/30ul which may be a limitation on their end.

  • 0 Votes
    15 Posts
    8k Views
    stephenw10S

    On a system effected by this it should normally boot correctly after an upgrade but with no console. The webgui should still be accessible though.

    If for some reason it is not interrupting the boot to reach the loader prompt and doing:

    set kern.vty=sc boot

    Should allow it to boot with a working console to correct whatever other problem exists.

    Steve

  • EFI install problem

    11
    0 Votes
    11 Posts
    7k Views
    I

    i have same issue anybody find the solution @dcol @jimp @barakah @Kain

  • 0 Votes
    2 Posts
    795 Views
    jimpJ

    Looks like that is due to squid moving versions, on 2.4.5 the package uses the www/squid3 port so it didn't pick up the settings in our config that were for www/squid. I pushed a fix, squid will get rebuilt with the new settings.

  • Traffic Shaper By Interface

    2
    0 Votes
    2 Posts
    759 Views
    A

    Hello,
    Since you can't share bandwidth across multiple interfaces, you are left with three options.
    Give each LAN segment a fixed amount of bandwidth for each of the WANs. No bandwidth shared, free bandwidth from one interface cannot be used by the others
    Configure each LAN segment like the above multi-wan-single-lan shaping, but you won't gain a whole lot
    Don't do any LAN shaping.
    1 and 2 will have the same queue setups, just the amount of bandwidth assigned to the queues will be different.
    Best,
    Arso

  • 2.4.5 Bug Tracker Update?

    2
    0 Votes
    2 Posts
    556 Views
    jimpJ

    We're focused on 2.4.4-p1 and nothing else right now. Hoping to have it out very soon.

  • DHCPv6 Client Broken in latest snapshot

    55
    0 Votes
    55 Posts
    15k Views
    jimpJ

    Great news! Thanks for testing

  • [Fixed] SG1000 Won't boot after latest update

    10
    0 Votes
    10 Posts
    1k Views
    jimpJ

    Still working on it. Waiting on the latest snapshot to come out today to test the recovery image and then to test upgrades as well. Hopefully should be OK today.

  • 2.4.4.1 Download?

    3
    0 Votes
    3 Posts
    630 Views
    B

    Oh ok, thanks.

  • [Fixed] No local user authentication on 10-20 snap for GUI

    5
    0 Votes
    5 Posts
    1k Views
    T

    @rschell said in No local user authentication on 10-20 snap for GUI:

    the change set for issue #9051 appears to have caused this. If the router is relying on local authentication, the changes block checking the local database.

    Thank you for pointing this out, I have reverted the files to their old contents per the diffs and all is well.

    Diffs here:
    https://redmine.pfsense.org/projects/pfsense/repository/revisions/fe1afbb7549907e0d1cdfbf85d5f36d075a6a916/diff/src/etc/inc/auth.inc
    https://redmine.pfsense.org/projects/pfsense/repository/revisions/fe1afbb7549907e0d1cdfbf85d5f36d075a6a916/diff/src/etc/inc/priv.inc

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.