Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • K

      Can't access port-forwarded/natted services from another local network

      Watching Ignoring Scheduled Pinned Locked Moved NAT
      5
      0 Votes
      5 Posts
      12 Views
      K

      @johnpoz I see, thanks for explaining and the help!

    • M

      System daemon waagent on Alpine Linux with s6

      Watching Ignoring Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
      5
      0 Votes
      5 Posts
      82 Views
      M

      I have already solved the problem by using the Python library. You can delete my post. Thank you for your help)

    • R

      Dynamic dns don't work with carp ip

      Watching Ignoring Scheduled Pinned Locked Moved HA/CARP/VIPs
      8
      0 Votes
      8 Posts
      194 Views
      M

      @lbeard said in Dynamic dns don't work with carp ip:

      Done => https://redmine.pfsense.org/issues/16326

      Great, thanks 👍 👍

    • A

      Looking for few pointers getting Suricata on PFSense to talk to my Security Onion box.

      Watching Ignoring Scheduled Pinned Locked Moved pfSense Packages
      5
      0 Votes
      5 Posts
      89 Views
      bmeeksB

      @aaronouthier said in Looking for few pointers getting Suricata on PFSense to talk to my Security Onion box.:

      Ok, so I've been researching the topic. It seems SO has an integration for PFSense. However, the FreeBSD implementation of Syslog is not optimal for this purpose, as mentioned above.

      Although I am comfortable with CLI Linux, I am effectively a Newbie with regard to BSDs.

      My next question is: What would be the least invasive method as far as the PFSense Box to export just the Suricata logs? I believe I saw an option to log to a Unix Socket. Would that be helpful coupled with something like Netcat? I'm not necessarily looking for help with such a feat, just wondering if such would likely be fruitful, or am I just chasing the infamous wild goose?

      I recommend exporting the EVE JSON log as that will be the most comprehensive. To export to a UNIX socket, change the EVE OUTPUT TYPE setting to UNIX socket. You will need to manually create the socket and give it a name. It will be up to you then to "receive" the socket data stream and redirect it elsewhere (seems you want it remote for your case to Security Onion).

    • M

      System - Package Manager - Available Packages

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      5
      0 Votes
      5 Posts
      118 Views
      M

      @SteveITS

      Thank you for the clarification. You're right — better to be safe. I’ll update FW2 when I'm on site, and then FW1, which is my usual one.

    • K

      PHP memory error

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      5
      0 Votes
      5 Posts
      376 Views
      K

      Thanks everyone. That did it. No more errors!!

    • T

      Blocking of Discord

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      5
      0 Votes
      5 Posts
      296 Views
      M

      @The-Party-of-Hell-No excellent. I’m glad some experimentation proved successful.

    • A

      Odd sudden kernel panic

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      5
      0 Votes
      5 Posts
      282 Views
      A

      @stephenw10 I believe that is mpt attempting to talk to the RAID card as if it was in IT mode, trying to count the individual drives ("REPORT LUNS"), and the card replying "No, this is RAID, you can't talk to the drives directly" ("ILLEGAL REQUEST").

      I'll run a fs check next time it's convenient to take down the entire network. Probably this evening.

    • A

      Only reverse lookups for localdomain from client, external domains work (i.e. google.com)

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      5
      0 Votes
      5 Posts
      93 Views
      johnpozJ

      @AWeidner its just pfsense trying to proect you against a rebind. When you foward to something that is normal some external public NS - which normally should not be returning rfc1918.

      You might want to read some of the history of rebind attacks. And why this good protection to have in place.

    • D

      cannot block cross traffic on sg-2100

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling solved
      9
      0 Votes
      9 Posts
      179 Views
      johnpozJ

      @detox you should be able to edit your first post and edit title with [solved] in the title, add tag.. If you can not - let me know and can do it for you. There might be some restrictions on rep ports or something - but you have 6, I would think that enough?

    • A

      Vodafone UK - IPv6

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      4
      0 Votes
      4 Posts
      90 Views
      patient0P

      @ashleygavin said in Vodafone UK - IPv6:

      What error do you get if you wget -6 a website?
      And you have the two default LAN firewall rules, one for IPv4 and one for IPv6, and only the LAN net? On WAN you won't need any rules for accessing internet. And do you see open states for the (web) connection?

      NAT would not be a topic for IPv6 in the default config.

    • A

      Can't receive GeoIP databases updates anymore, banned

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      4
      0 Votes
      4 Posts
      135 Views
      GertjanG

      @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

      Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

      You've found a reason to use a VPN.

    • luckman212L

      6100 Firmware 03.00.00.03t-uc-126

      Watching Ignoring Scheduled Pinned Locked Moved Official Netgate® Hardware
      4
      0 Votes
      4 Posts
      119 Views
      stephenw10S

      Nice. Weird though. 😕

    • N

      HAProxy configuration for roundcube

      Watching Ignoring Scheduled Pinned Locked Moved HA/CARP/VIPs
      4
      0 Votes
      4 Posts
      34 Views
      V

      @NickJH
      Not clear, what you intend to achieve with this, but the Directory container in Apache is meant to be used for local paths. "/" might not be correct here.

      If you need to describe a virtual path use "Location".

    • M

      Another failed 2.8.0CE installation due to repo connectivity issues.

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      4
      0 Votes
      4 Posts
      129 Views
      stephenw10S

      There was a backend issue that's now fixed.

    • T

      Does not have a public address and is behind NAT

      Watching Ignoring Scheduled Pinned Locked Moved IPsec
      4
      0 Votes
      4 Posts
      27 Views
      T

      @Gertjan said in Does not have a public address and is behind NAT:

      Managed to solve the problem.

      You need to enter any fictitious name and your external IP in DNS Resolver. I entered both my pfsense on one and the second pfsense.Снимок экрана 2025-07-21 в 15.38.01.png In phase 1 you need to register.
      Снимок экрана 2025-07-21 в 15.39.32.png
      After which everything started working.
    • J

      Firewall gateway address in ipv6

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      4
      0 Votes
      4 Posts
      77 Views
      J

      Hi @SteveITS.

      That was an excellent tip, I had missed the "self" target completely. This allowed me to get rid of all of my firewall aliases I needed earlier.

      Thanks!

    • P

      "Failed to fetch the pfSense pkg repositories"

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      4
      0 Votes
      4 Posts
      127 Views
      stephenw10S

      Yup, there was a backend issue. Should be good now.

    • R

      Not understanding Boot Environments

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      4
      0 Votes
      4 Posts
      132 Views
      stephenw10S

      Mmm that^.

      However what you will see is that after booting back into the 24.11 BE the update branch will still be set to 25.07-RC because that was the last thing that was done before the upgrade took the snapshot. So if you plan to run 24.11 for some time after reverting you would need to set the update branch back to 24.11 in that BE before doing any package operations.

    • G

      CE v2.8.0 issues

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      4
      1 Votes
      4 Posts
      307 Views
      stephenw10S

      Hmm, but they are policy based tunnels? And 300 Phase 1 configs not a total of 300 Phase 2 configs for example?

      I'm not aware of any issue in 2.8 that might present like that for IPSec.