• OSPF Issues

    7
    0 Votes
    7 Posts
    1k Views
    P

    @jlauzer

    https://www.netgate.com/blog/wireguard-removed-from-pfsense-ce-and-pfsense-plus-software.html

    https://www.netgate.com/blog/painful-lessons-learned-in-security-and-community.html

  • Pimd support?

    6
    0 Votes
    6 Posts
    1k Views
    612brokeaf6

    @dutsnekcirf said in Pimd support?:

    @612brokeaf I've been interested in getting away from troglobit's pimd package as well and would love to switch to FRR's pimd. The main reason I'm interested in doing so is because I want to avoid using multiple packages by separate developers that could conflict with each other.

    Yeah a cleaner solution would be nice, but troglobit's pimd works. MSDP is what I'm really after with FRR's pimd, otherwise the other pimd works fine.

    My understanding; however, is that FRR's implementation of PIMD isn't quite as complete as troglobit's pimd.

    That's in FreeBSD. FRR isn't as widely used and tested on FreeBSD as it is on Linux (bar pfSense maybe).

    Perhaps that's what you meant when you said that you're after SM and not SSM. I'm not quite familiar with the differences there.

    I should have stated ASM not SM, still sparse mode. Any Source Multicast - join to *,G(roup) rather than S(ource),G. With SSM there is no need for an RP, you just send joins towards the source. I need static RPs so BSR is of not much use for me.

    I need to eliminate slow start for multicast so I'm looking at FRR's pimd mostly because of MSDP, so I can have local RPs / anycast RP between sites. Right now I am forced to place the RP in one location, with loss or resiliency under failure conditions. I may be forced to use BSR.

    Anyhow, over years of using pfSense I think I've learned to trust their judgement more. If a package is not available, 4/5 chance it's for a good reason.

    I would still ove to hear from the team re. how frequent multicast requirements are, especially for non-local distribution. PfSense is seen as a security/fw first, routing second, type of platform.

  • OpenBGPD last version available on pfSense?

    6
    0 Votes
    6 Posts
    2k Views
    cmcdonaldC

    @marcus_1302 it wasn’t very clear because you said you were trying to actually install it, not just document the last version to support it. Glad you got your answer. But yeah, check out the dynamic routing with FRR hangout (https://youtu.be/4IlKcB17rWk), Jim talks a bit about converting OpenBGPd installs to FRR.

  • Filter some routes

    28
    0 Votes
    28 Posts
    3k Views
    P

    @ulrik said in Filter some routes:

    You may check the raw configuration in frr.conf, does it make any changes in the configuration when this option is selected? Furthermore if you dont want to distribute any routes, why should it be listed in the interfaces?

  • FRR refuses to start with BFD Labels on pfsense 2.5

    3
    0 Votes
    3 Posts
    408 Views
    viktor_gV

    BFD labels removed from FRR WebGUI

    see https://redmine.pfsense.org/issues/11477

    Please update to FRR 1.1.0_6

  • FRR 7.5 full bgp table very slow and AS paths not working

    7
    0 Votes
    7 Posts
    2k Views
    viktor_gV

    fixed in FRR 1.1.0_6

  • Running FRR on both Primary and Backup pfSense

    1
    0 Votes
    1 Posts
    340 Views
    No one has replied
  • frr and 2.5.0

    6
    0 Votes
    6 Posts
    1k Views
    S

    @viktor_g

    Hello,

    I go my config to work by deleting all the route maps, acls, and prefix lists.

    I have a bunch of pfsense firewalls that i'm upgrading and will be sending logs.

    Ty,
    Sean

  • FRR BRP Route Aggregation and Load Sharing

    1
    0 Votes
    1 Posts
    344 Views
    No one has replied
  • add RPKI route map in GUI

    2
    0 Votes
    2 Posts
    470 Views
  • FRR-OSPFv3 crashs with redundant ABR

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • BGP over IPSec resets every time when re-authentication of Phase 1 happens.

    11
    0 Votes
    11 Posts
    2k Views
    ?

    @oremountain Usually it is the better choice to setup bgp with loopback adapters - I was just to lazy to configure an additional interface and static routes for each IPsec peer.

    Maybe you try to reconfigure one peer bgp session directly on a VTI Interface, see if it helps.

  • route map in combination bgp ipv6 not functional

    2
    0 Votes
    2 Posts
    414 Views
    Z

    https://redmine.pfsense.org/issues/10816

  • BGP Routes are not used after IPSec Event

    5
    0 Votes
    5 Posts
    713 Views
    O

    @zawi thats my setup from the beginning.
    IPSEC with VTI.
    Virtual CARP IP Address for both Firewalls.
    BGP Listening on CARP IP.

    edit: CARP IP is on WAN, not the VTI or something.

  • IPSec tunnel to FRR transition

    2
    0 Votes
    2 Posts
    423 Views
    Z

    Do you mean you are going to use FRR over IPsec?

  • Is the following configuraiton possible with the GUI/CLI?

    4
    0 Votes
    4 Posts
    832 Views
    ?

    @avvero

    VXLAN isn't available on pfSense in any stable Release yet. According to release notes it will be implemented in version 2.5.0.

  • RPKI

    2
    0 Votes
    2 Posts
    387 Views
    viktor_gV

    @wavesound see pfSense 2.5 FRR version

    Screenshot from 2021-01-13 13-50-35.png

  • IPsec Tunnel to FRR transition

    1
    0 Votes
    1 Posts
    256 Views
    No one has replied
  • Multiwan default routing with FRR BGP

    2
    0 Votes
    2 Posts
    410 Views
    Z

    the best way(if you have more than one WAN is to assign VIP to localhost then use it as updating source of BGP.

  • Multiple WAN issue with IPSec VTI + FRR

    Moved
    2
    0 Votes
    2 Posts
    710 Views
    B

    In case anyone stumbles across this. The solution is to create a rule on the LAN interface that uses the "default" gateway for packets headed toward subnets that live on the other side of the VTI tunnels. This new rule needs to be higher in the list than the rule that you create which redirects incoming packets to a gateway group.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.