Subcategories

  • Discussions about TNSR

    17 Topics
    55 Posts
    P
    We’re excited to announce the release of Netgate TNSR 25.10, our latest update packed with powerful new features, expanded capabilities, and over 35 bug fixes and enhancements. What’s New in version 25.10? VPF NAT Endpoint-Independent Mode - useful in large scale CGNAT scenarios VPF NAT Source-IP Hash Mode - improves behavior for protocols such as SIP VPF NAT Rule Port Ranges - dedicate outbound source port ranges different tenants VPF Filter Port Tables - define groupings of IP services ports into a VPF table WireGuard FQDN Peer Configuration - configure peers using FQDNs Legacy Dataplane NAT Removed - Legacy Dataplane NAT functionality has been removed. If you are still using legacy dataplane NAT, please convert to VPF NAT before updating to this version. Release Notes: https://docs.netgate.com/tnsr/en/latest/releases/release-notes-25.10.html Blog Post: https://www.netgate.com/blog/netgate-releases-tnsr-software-version-25.10 Video: https://youtu.be/EH1qUcsZ8do
  • Discussions about TNSR

    40 Topics
    112 Posts
    P
    Feels like it’s been a while since this topic was brought up, and so much has happened since then. TNSR has really filled out but I’m sure there’s other features our users would love see in future releases. So with that said, please share your feature requests here and let’s see what we can do! —pfGeorge
  • Discussions about installing or upgrading TNSR software

    49 Topics
    195 Posts
    patient0P
    @shood said in install pfsense on opnsense DEC2700: Did you face any problems after installing pfSense on DEC OpenSense? Nope, all working normal. But I did use only the 10Gbit ports (ax0, ax1).
  • Using TNSR Software to Conserve Address Space and Improve Security

    Pinned Locked
    4
    2 Votes
    4 Posts
    2k Views
    No one has replied
  • TNSR Feature Request and Bug Reporting

    Pinned
    20
    3 Votes
    20 Posts
    10k Views
    D
    Giving us the ability to manually set interface speeds and/or duplex settings would be helpful. Explain your use case Say you have a TNSR router and you want to hook it up to an ISP handoff for MPLS or a mux/demux or whatever, their equipment hands off a 10Gbps link to your 10Gbps link, but they may only be providing you 2Gbps bandwidth. This can muddy the waters with OSPF if you don't statically set the link cost. Setting the reference bandwidth to 10Gb and statically setting the speed of the link to 2Gbps would then auto set the OSPF cost of the interface. Another use case would be if you're connecting a 10Gb interface to a 1Gb interface, or some legacy equipment. I do not know the ins and outs of how TNSR negotiates speed/duplex settings, but it can't be good if TNSR decides that a link is 10Gb when it's effectively receiving 1Gbps on the other end. Also if you're in a lab environment, like emulated Eve-NG or GNS3, not being able to set the speeds manually results in inconsistencies in how fast the link actually is so you can't get a good idea of what real-world links/routing tables are going to look like. Describe the problem and propose a solution I've had all of the above problems. Being able to say "speed 1000" or "speed 10000" would have been able to resolve most of my issues without having to buy more transceivers or rearrange what ports are able to dynamically negotiate speeds. (This is prevalent on the older models of TNSR hardware, where the board's NICS could not negotiate, but the add-on card could negotiate speeds). Is it a bug? No, just not a feature.
  • TNSR Resources

    Pinned
    2
    2 Votes
    2 Posts
    5k Views
    No one has replied
  • TARJETAS DE RED

    1
    0 Votes
    1 Posts
    246 Views
    No one has replied
  • 0 Votes
    3 Posts
    2k Views
    D
    Hi @Tyronejackson839, Thanks for the awesome advice! Your ACL tips worked perfectly—enabling fragment-checking and lean rules secured my nginx webserver without sacrificing performance. Really appreciate your detailed help! Best, David James | Founder of The Yes No Button!
  • VLAN and Internet Access

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Support for MCLAG

    1
    0 Votes
    1 Posts
    759 Views
    No one has replied
  • 0 Votes
    3 Posts
    2k Views
    R
    @gigabitguru Pro tip - if you have an active tnsr software sub you should open a ticket. You can see, from the parent category, that there's not a lot of tnsr activity over here. I am not someone that can help you out -- but simply directing you to TAC if you need/want more responsive suggestions. Cheers.
  • bgp address families

    1
    1 Votes
    1 Posts
    1k Views
    No one has replied
  • VRRP expected MAC address behavior

    1
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • IPv6: Host Interface RA (Router Advertisement) Surpression Missing?

    1
    0 Votes
    1 Posts
    278 Views
    No one has replied
  • hello

    pfsense 2.4.4
    3
    0 Votes
    3 Posts
    1k Views
    JonathanLeeJ
    @retgvtbyrey I think for TNSR licensed users you can open a support ticket with Netgate and skip the forum even.
  • TNSR ECMP Algorithms?

    8
    0 Votes
    8 Posts
    3k Views
    R
    Balances traffic based on source IP, destination IP, source port, destination port, and protocol, allowing effective load distribution while maintaining session consistency.
  • DHCP Relay/ip helper (Forward DHCP requests to a different server)

    4
    0 Votes
    4 Posts
    1k Views
    fractal_boyF
    [image: 1728327473006-ea74c66d-e6b1-43ac-adec-f892d5d69899-image.png]
  • Does TNSR support PPPOE client and UPNP service ?

    16
    0 Votes
    16 Posts
    4k Views
    RobbieTTR
    @jwt said in Does TNSR support PPPOE client and UPNP service ?: Of note: we have recently developed a new pppoe stack for FreeBSD (and thus pfsense) which avoids using netgraph. It is netgraph which is causing the poor performance, and the single-threading. I’d expect that code to make its way to a pfsense release in the next six months. I also expect to be able to leverage that code (which we control the copyright to) to be able to implement a VPP based pppoe client for Netgate products. This is extraordinary good news and somewhat buried in this thread. Happy to run tests on one of my routers when you need feedback.
  • TNSR Lab on EVE-NG

    9
    0 Votes
    9 Posts
    5k Views
    fractal_boyF
    thanks all for your input. GNS3 and EVE-NG images are on our radar. We are working on this.
  • how to change ring buffer to 4096

    7
    1 Votes
    7 Posts
    1k Views
    C
    this was their answer: "If you get 3 Full Views, please check this guide: https://docs.netgate.com/tnsr/en/latest/dynamicrouting/bgp/tuning.html" well... yes thank you.
  • Netgate 6100 Max with TNSR and 10GBaseT SFP+ modules

    2
    1 Votes
    2 Posts
    684 Views
    C
    After reading a comment in this thread - https://www.reddit.com/r/Netgate/comments/1bzsv4m/the_sfp_10gbaset_80m_copper_rj45_transceiver_for/ - I found the problem. I was testing to a 1gig port on a Cisco switch. Temporarily moved it to a 10G port on a server and the interface is up and working.
  • TNSR Load Balancing Methods

    tnsr
    5
    1 Votes
    5 Posts
    2k Views
    fractal_boyF
    did you try something like this? R1 tnsr(config)# sh run route route table ipv4-VRF:0 id 0 route 0.0.0.0/0 next-hop 0 via 10.100.1.2 e1 next-hop 1 via 10.100.0.2 e2 exit exit R1 tnsr(config)# sh route Route Table ipv4-VRF:0 AF: ipv4 ID: 0 ----------------------------------------- 0.0.0.0/0 via 10.100.0.2 e2 weight 1 preference 0 via 10.100.1.2 e1 weight 1 preference 0
  • Clarification on ACL and NAT Interaction in TNSR

    2
    0 Votes
    2 Posts
    1k Views
    DerelictD
    @olivertbuffet For outbound ("in2out") traffic, translation is done first and then output ACLs are evaluated. For inbound ("out2in"), it's the opposite. Input ACLs are evaluated and then translation. This matches the documentation here: https://docs.netgate.com/tnsr/en/latest/acl/acl-nat.html#acl-and-nat-interaction Where in the documentation did you see it is the same in both directions so it can be evaluated and corrected if necessary?
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.