Subcategories

  • Discussions about TNSR

    18 Topics
    56 Posts
    P
    We’re excited to announce the release of Netgate TNSR 26.02, our latest update packed with powerful new features, expanded capabilities, and over 30 bug fixes and enhancements. What’s New in version 26.02? VPF High Availability State Synchronization Allows peers to automatically re-synchronize connection data when they restart VPF Statistics Output Filters Users can now filter VPF connection statistics output by connection type. This makes troubleshooting and gathering NAT statistics simpler and easier to read. Dynamic Routing Prefix-List Sequence Numbers Input validation no longer allows sequence numbers to start at 0. Upgrading TNSR will renumber entries in the prefix list starting at 1 VPP and DPDK Updates VPP is updated to version Stable/2510, and DPDK is updated to 25.07 Release Notes: https://docs.netgate.com/tnsr/en/latest/releases/release-notes-26.02.html Blog Post: https://www.netgate.com/blog/netgate-releases-tnsr-software-version-26.02 Learn More: https://www.netgate.com/tnsr
  • Discussions about TNSR

    41 Topics
    113 Posts
    P
    Feels like it’s been a while since this topic was brought up, and so much has happened since then. TNSR has really filled out but I’m sure there’s other features our users would love see in future releases. So with that said, please share your feature requests here and let’s see what we can do! —pfGeorge
  • Discussions about installing or upgrading TNSR software

    50 Topics
    196 Posts
    patient0P
    @shood said in install pfsense on opnsense DEC2700: Did you face any problems after installing pfSense on DEC OpenSense? Nope, all working normal. But I did use only the 10Gbit ports (ax0, ax1).
  • Static NAT Port Forward Range

    Moved
    4
    0 Votes
    4 Posts
    1k Views
    JonathanLeeJ
    @swinn Sorry about that, I do network address translation with aliases in pfSense plus for lan traffic right now [image: 1680146807279-screenshot-2023-03-29-at-8.26.06-pm-resized.png] Again Static nat for WAN connection can also be done with port ranges 8080:8081 or 8080-8081 [image: 1680146955354-screenshot-2023-03-29-at-8.27.29-pm-resized.png] https://docs.netgate.com/pfsense/en/latest/nat/outbound.html Does that help?
  • TNSR ISO shasums

    2
    0 Votes
    2 Posts
    1k Views
    F
    @fatred if crowdsourcing is a thing, i have the following BTW: 526275cf9021846401076f454df9a4631a6d2676868479079e8ed78128fd3b04 TNSR-DVD-22.10-2-x86_64-jammy.iso e3b703e3b97657197d93e32bfea2913f8c135f06940c0ae64abc76e50e263c73 TNSR-DVD-23.02-3-x86_64.iso
  • MAP-T not working

    1
    0 Votes
    1 Posts
    522 Views
    No one has replied
  • Is a TNSR Switch Installation Possible

    2
    0 Votes
    2 Posts
    897 Views
    DerelictD
    @sentein Not sure what you are asking. TNSR will almost certainly be able to communicate with it at layer 2/3 it as a switch/router in the regular sense, but loading TNSR directly on it is probably not going to be possible.
  • BondEthernet interfaces don't get status from slave(s)

    3
    0 Votes
    3 Posts
    1k Views
    M
    After speaking to someone at Netgate, this looks like it is a potential bug with 22.10-2. Thanks, Mike
  • VRRP / track-interface - Can't use BondEthernet

    4
    0 Votes
    4 Posts
    1k Views
    M
    My specific issue came down to the fact that the BondInterface needs to be enabled before it can be used as a track-interface. e.g. interface bond 1 mode lacp load-balance l34 exit NOTE: interface BondEthernet1 is not enable. When trying to add the track-interface rtrexllab01 tnsr(config)# interface GigabitEthernet1/0/0 rtrexllab01 tnsr(config-interface)# ip vrrp-virtual-router 1 rtrexllab01 tnsr(config-vrrp4)# tr BondEthernet0 BondEthernet0.610 GigabitEthernet1/0/0 GigabitEthernet1/0/1 TenGigabitEthernet2/0/0 TenGigabitEthernet2/0/1 rtrexllab01 tnsr(config-vrrp4)# track-interface As seen above, the BondInterface1 is not available. rtrexllab01 tnsr(config)# interface BondEthernet1 rtrexllab01 tnsr(config-interface)# enable rtrexllab01 tnsr(config-interface)# exit rtrexllab01 tnsr(config)# interface GigabitEthernet1/0/0 rtrexllab01 tnsr(config-interface)# ip vrrp-virtual-router 1 rtrexllab01 tnsr(config-vrrp4)# tr BondEthernet0 BondEthernet0.610 BondEthernet1 GigabitEthernet1/0/0 GigabitEthernet1/0/1 TenGigabitEthernet2/0/0 TenGigabitEthernet2/0/1 rtrexllab01 tnsr(config-vrrp4)# track-interface BondEthernet1 is not available to use as a track-interface. Thanks, Mike
  • VRRP with E1000e ESXI 7.0?

    9
    0 Votes
    9 Posts
    2k Views
    Cool_CoronaC
    @machoherbivore9 Use failover on the Vswitch instead so the TNSR works like normal but Vsphere takes over the failover unnoticed.
  • TNSR VRF BGP

    1
    0 Votes
    1 Posts
    628 Views
    No one has replied
  • Routing - LAN w. Public IPs to WAN

    9
    0 Votes
    9 Posts
    2k Views
    DerelictD
    @talwell Perhaps the subnet is not routed properly by the ISP?
  • TNSR 22.10-2 / BNX2X

    3
    0 Votes
    3 Posts
    1k Views
    M
    @russellc You are indeed correct. Looking though syslog I see: Feb 10 13:33:57 tnsrlab01 ModemManager[821]: <info> [base-manager] couldn't check support for device '/sys/devices/pci0000:00/0000:00:01.0/0000:01:00.1': not supported by any plugin Feb 10 13:33:57 tnsrlab01 ModemManager[821]: <info> [base-manager] couldn't check support for device '/sys/devices/pci0000:00/0000:00:01.0/0000:01:00.0': not supported by any plugin Feb 10 13:35:05 tnsrlab01 ModemManager[821]: <info> [base-manager] couldn't check support for device '/sys/devices/pci0000:00/0000:00:01.0/0000:01:00.0': not supported by any plugin Feb 10 13:35:05 tnsrlab01 ModemManager[821]: <info> [base-manager] couldn't check support for device '/sys/devices/pci0000:00/0000:00:01.0/0000:01:00.1': not supported by any plugin Feb 10 13:49:49 tnsrlab01 vpp[1534]: vpp[1534]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.0 Feb 10 13:49:49 tnsrlab01 vpp[1534]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.0 Feb 10 13:49:49 tnsrlab01 vpp[1534]: vpp[1534]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Feb 10 13:49:49 tnsrlab01 vpp[1534]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Feb 10 14:00:04 tnsrlab01 vpp[1573]: vpp[1573]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.0 Feb 10 14:00:04 tnsrlab01 vpp[1573]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.0 Feb 10 14:00:04 tnsrlab01 vpp[1573]: vpp[1573]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Feb 10 14:00:04 tnsrlab01 vpp[1573]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Feb 10 14:01:16 tnsrlab01 vpp[1593]: vpp[1593]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Feb 10 14:01:16 tnsrlab01 vpp[1593]: dpdk: Unsupported PCI device 0x14e4:0x168e found at PCI address 0000:01:00.1 Thank you for the information. Mike
  • TNSR to SD-WAN

    2
    0 Votes
    2 Posts
    689 Views
    M
    @heinola Can you provide more details? SDWAN is a very broad topic. What are you trying to accomplish with TNSR and PA?
  • TNSR & Baremetal Build Recommendations.

    3
    0 Votes
    3 Posts
    1k Views
    M
    Hi Jake, A list of components that are tested for compatibility with TNSR specifically can be found here. You'll find compatible processors and NICs in that document. While AMD Epyc may install and run, we do not test these processors, so it is recommended to stick to Intel so that we can guarantee compatibility with TNSR, not just DPDK and VPP. The hardware requirements to achieve your throughput requirements will likely depend on the finer details of your use-case. Since you mention a CPIC card, I am assuming there is some IPSec requirement here in addition to the BGP peering you mention in the post. Please feel free to reach out to me at sales@netgate.com and we can set up a call to discuss your requirements in more detail. We'd be happy to assist with an evaluation and help you achieve your goals with TNSR. Thanks, Max
  • What is the function of host acl?

    2
    0 Votes
    2 Posts
    579 Views
    L
    i got it , https://docs.netgate.com/tnsr/en/latest/acl/host.html TNSR can also create host ACLs to control traffic on host interfaces, such as the management interface .
  • Prometheus/Grafana Question

    8
    1
    0 Votes
    8 Posts
    3k Views
    R
    Which metrics are you querying to get the live interface traffic data? I just started setting this up myself and I cannot seem to find the right one, only byte totals used that keeps climbing and never drops. I may be dumb and doing it wrong, though. lol
  • How to get SSH working on my network

    20
    0 Votes
    20 Posts
    4k Views
    johnpozJ
    @gabe-a said in How to get SSH working on my network: I'll try to trace the route the traffic There is not a "trace" of traffic - you would need to sniff and see how when you ssh hostname that name is being resolved to an IP, is it a netbios broadcast, was a dns query to your routers IP using a fqdn query or just hostname, or did it add a suffix like .local, etc. , was it mdns via multicast? If I didn't on purpose completely disable mdns on any client that tries and do it - I would show you an example.. But I on purpose disable mdns on my windows machines - because it a horrible chatty protocol that I have zero use for - I resolve anything on my network via a simple dns query.. to my unbound running on pfsense or my pihole. What I can show you for example when I ssh to say my nas.. what happens.. I flush the machines local dns cache so I know it has to find the IP for nas.local.lan, as you can see it does a dns query to my dns it points to, in my cache my pihole on 192.168.3.10 and gets an answer [image: 1671555357898-dns.jpg] showing where my client points for dns, and that I have mdns disabled - its horrible horrible chatty noise producing protocol.. [image: 1671555540908-mdns.jpg] That it is enabled by default is horrible yet another horrible choice by MS if you ask me ;) avahi is a tool that will pass mdns across network boundaries - it has zero use for you, because as you have stated all your devices on the same network. But I have gone over how to troubleshoot that and set it up a few times.. Even though I dislike using it, and don't on my network, I know how it works and I know how to set it up, etc. I just not a fan of breaking network boundaries like that.. If you want to discover something via a L2 method - then you need to be on that L2 ;) None which has anything to do with you, since you have clearly stated all your devices are on the same network connected to a dumb switch.. Here for example is some mdns on my wireless network my phone and printer are on.. [image: 1671556293170-mdns-resized.jpg] You can see my phone 192.168.2.198 sending out queries, and the stuff it already knows about, and you see a response from my printer on 192.168.2.50 to the multicast address. What I don't see is any directed unicast responses directly from the printer to the phone for example. I would have to setup span port of where my AP is to see that, since my printer is wired.. Iphone loves to use airprint to find printers - wish I could just give it the fqdn or IP of the printer so I didn't have to allow for that nonsense noise on my network.. My PC for example has no issue just printing to the fqdn of the printer across vlans.. But vs breaking the boundary - I just put the printer on the same vlan as my wireless that devices that insist on using mdns, so I don't have to break boundaries passing mdns across network segments. edit: here I did a sniff directly on my AP via tcpdump for this sort of traffic.. This way I did not have to really change anything on my networks or clients or create a span port to see the traffic.. 12:29:06.767697 IP 192.168.2.198.5353 > 224.0.0.251.5353: 0 A (QU)? BRN30055C116AD9.local. (39) 12:29:06.787748 IP 192.168.2.50.5353 > 192.168.2.198.5353: 0*- [0q] 1/0/0 A 192.168.2.50 (49) You can see where my phone 2.198 did a query to the multicast address, and the printer at 2.50 did a directed unicast answer back to the phones specific IP..
  • Announcing the Netgate 8200 with TNSR Software

    1
    0 Votes
    1 Posts
    513 Views
    No one has replied
  • Interface Config

    Moved
    2
    0 Votes
    2 Posts
    888 Views
    jimpJ
    service dataplane restart restarts the VPP daemon and will definitely affect service. While that daemon is restarting, no traffic can pass. Thankfully it usually restarts very quickly so the disruption would be minimal, but still best to do in a brief maintenance window.
  • TNSR Software Release 22.10 is here!

    2
    1 Votes
    2 Posts
    1k Views
    No one has replied
  • IPSEC max speed for like Palo Alto SASE Prisma

    3
    0 Votes
    3 Posts
    1k Views
    F
    @mleighton Thank you, yes I know there is lots of factors, I just wanted to know that IPSEC for a fact is awesome on the TNSR platform. I am looking forward to get started working with it :) and will update here when we something working with Prisma Thanks Felix
  • ipfix crashing clixon and dataplane

    2
    0 Votes
    2 Posts
    1k Views
    L
    when i rebooted tnsr interface looking down on show interface command
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.