Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • L

      How to fork a pfSense package?

      Watching Ignoring Scheduled Pinned Locked Moved Development
      4
      0 Votes
      4 Posts
      111 Views
      L

      @cybrnook

      It looks if you are referring to the pimd engine version

      854cb5be-fd74-43b0-848a-b83df5637c1b-image.png

      Which is quite old, and as far as I know not working under FreeBSD. I have compiled the never released pimd-3.0.b1 version (using FreeBSD15 current).

    • P

      update from 25.07 beta to 25.07 RC

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      4
      0 Votes
      4 Posts
      189 Views
      GertjanG

      @PiAxel said in update from 25.07 beta to 25.07 RC:

      The last version doesn't work for me!

      ??

      How do you know that the latest version doesn't work for you, before installing that latest version ?

      ( 😊 )

    • K

      Limiter source mask now after NAT when using gateway groups - 2.8 change?

      Watching Ignoring Scheduled Pinned Locked Moved Traffic Shaping
      6
      0 Votes
      6 Posts
      219 Views
      K

      @gemg83 I see what you're saying - it could be the jump from 12.3 to 14 on the BSD side.

      It really hampers the use of limiters in multi-WAN setups so it feels like an important bug (I call it a bug as it doesn't behave at all how the UI or documentation suggests, it's more like using them on a floating rule).

    • J

      DNS problem

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      4
      0 Votes
      4 Posts
      223 Views
      GertjanG

      @jamesdun

      @jamesdun said in DNS problem:

      if the new machine wasn't picking up the correct DNS server

      Well, launch

      ipconfig /all

      and it tells you what DNS server it uses.
      Normally, a new Windows PC will use DHCP is so it's 'plug and play'.

      @jamesdun said in DNS problem:

      Both machines show the correct DNS server when NSLookup is launched, although the old one also gives it a name and the new one fails to do the reverse lookup

      Looks like the new machine isn't allowed to do DNS requests against pfSense ?

      @jamesdun said in DNS problem:

      and the new one fails to do the reverse lookup

      Humm. The new one's DNS request gets refused ...

    • D

      cannot block cross traffic on sg-2100

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling solved
      9
      0 Votes
      9 Posts
      185 Views
      johnpozJ

      @detox you should be able to edit your first post and edit title with [solved] in the title, add tag.. If you can not - let me know and can do it for you. There might be some restrictions on rep ports or something - but you have 6, I would think that enough?

    • L

      New widget for the official speedtest.net cli version.

      Watching Ignoring Scheduled Pinned Locked Moved pfSense Packages
      6
      4 Votes
      6 Posts
      948 Views
      A

      @ameinild Yes, I just confirmed at home that it is still working. I had some icon error right after install, but this seems to be fixed now. 👍

    • M

      error connection openvpn site to site

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      12
      0 Votes
      12 Posts
      226 Views
      M

      @viragomann banally ho quest problem, per riassumere
      If you download your pc from the lan dove and install the pfsense with opnvpn site to site client, pingo i server windows o i pc della lan pfsense server, invece dalla parte server non pingo nessun pc, nemmeno il pfsense client. Invece dal ping di pfsense pinggo calmly. What can you control that the server does not function?

    • E

      [SOLVED] Serial GPS NTP Displays Incorrect Source on Dashboard

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      19
      0 Votes
      19 Posts
      1k Views
      E

      @dennypage Hasn't been a problem.

      loopstats.jpg

    • C

      if_pppoe problems with php-fpm causing loops. (resolved)

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      44
      0 Votes
      44 Posts
      1k Views
      C

      @w0w I had a device that had issues with small tcp packets, it still fails on the legacy code but now passes on the new code. I didnt really consider it an issue pppoe side before, but the issue is gone on if_pppoe.

    • C

      Doubts on CARP/HA/DUALWAN

      Watching Ignoring Scheduled Pinned Locked Moved HA/CARP/VIPs
      3
      0 Votes
      3 Posts
      25 Views
      w0wW

      @chano76
      What is the pfSense version?
      How did you configure the failover group?

    • S

      rename boot environments

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      3
      0 Votes
      3 Posts
      138 Views
      S

      @Gertjan shame on me! Didn't see that ... thanks a lot!

    • T

      Upgrading Unbound version for latest pfSense Plus release?

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      3
      1 Votes
      3 Posts
      90 Views
      GertjanG

      @tman222 said in Upgrading Unbound version for latest pfSense Plus release?:

      (I didn't see it listed in the 25.07 release notes when I looked earlier).

      A couple of days (weeks ?) one of the latest pfSense Plus Beta or RC already included 1.23. That's the version I use right now.
      Since February 2025, 1.22.x was used, that's according my own release notes (I always log the upgrade process, executed form console, option 13, to a file. I don't use the GUI upgrader as that one tend to hide the obfuscate the interesting stuff.)

      If the newest unbound version, 1.23.1, concerns the 'pfSense' version of unbound, then 1.23.1 will probably be included soon.

      edit :
      @w0w => 👍

      We can actually check :

      [25.07-RC][root@pfSense.bhf.tld]/root: unbound -V Version 1.23.0 Configure line: --with-libexpat=/usr/local --with-libnghttp2 --with-ssl=/usr --enable-dnscrypt --disable-dnstap --with-dynlibmodule --enable-ecdsa --enable-event-api --enable-gost --with-libevent --with-pythonmodule=yes --with-pyunbound=yes ac_cv_path_SWIG=/usr/local/bin/swig LDFLAGS=-L/usr/local/lib --disable-subnet --disable-tfo-client --disable-tfo-server --with-pthreads --prefix=/usr/local --localstatedir=/var --mandir=/usr/local/share/man --infodir=/usr/local/share/info/ --build=amd64-portbld-freebsd15.0 Linked libs: libevent 2.1.12-stable (it uses kqueue), OpenSSL 3.0.16 11 Feb 2025 Linked modules: dns64 python dynlib respip validator iterator DNSCrypt feature available BSD licensed, see LICENSE in source package for details. Report bugs to unbound-bugs@nlnetlabs.nl or https://github.com/NLnetLabs/unbound/issues

      so the CVE deosn't apply.

    • W

      Packages config is retained in upgrade?

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      3
      0 Votes
      3 Posts
      61 Views
      S

      @Wolfgangthegreat For example (this is checked by default):
      8544523b-d69b-4088-b221-d2532912455c-image.png

    • N

      pfSense on Watchguard M370

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      314
      1 Votes
      314 Posts
      149k Views
      D

      @stephenw10 I don't have enough points to upvote, so I'll just say thank you Stephen 👍 !

      Now, if the seller agrees to selling me that M570, I should be good to tackle this thanks to all the good info supplied by the community in this thread :)

    • W

      Failed to fetch repository data

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      3
      0 Votes
      3 Posts
      56 Views
      W

      and then it worked...

    • D

      Как скачать pfsense 2.8.0?

      Watching Ignoring Scheduled Pinned Locked Moved Russian
      3
      0 Votes
      3 Posts
      83 Views
      D

      @werter
      Благодарю за ссылки!
      Поток негатива на netinstaller уже пошёл.
      Задушат pf CE походу...

    • T

      Wireguard performance - where's the limitation?

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard
      3
      0 Votes
      3 Posts
      121 Views
      T

      @Bob-Dig thanks
      But I cannot understand why the FTP performance is crippled when going via Wireguard and not when going via the WAN.
      The same happens for NFS and SMB file sharing protocols. The performance over Wireguard is rather poor, although I haven't tried these over an unencrypted WAN for obvious reasons so can't really compare.

    • Bob.DigB

      [solved] English language "question"

      Watching Ignoring Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
      3
      0 Votes
      3 Posts
      219 Views
      stephenw10S

      Mmm indeed, I would expect that to be they or it depending on whether 'peer' refers to the user or the device. More likely it's a device in that reference.

    • C

      pfblockeer 3.2.8 + pfsense 2.8.0: top1m db download fail

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      4
      0 Votes
      4 Posts
      398 Views
      sretallaS

      You can download it here now:

      https://raw.githubusercontent.com/ianb/alexa-sites/refs/heads/master/top-1m.csv

    • W

      Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions ntopng
      3
      0 Votes
      3 Posts
      141 Views
      W

      @dennypage said in Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?:

      @wolffire said in Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?:

      I really like ntopng, but I'd rather it not be able to access the internet whenever it wants.

      Is it possible to block package processes from doing so?

      You can't block individual packages. The closest you could get is to find the domain or addresses the package is accessing and block those.

      With specific regard to ntopng, I haven't examined all the callouts but I don't recall it doing much unless you were using the licensed version (activation check), or had one of ntopng's "active" modes enabled.

      Make sure you have Active Network Discovery disabled in ntopng. It's in Settings / Preferences / Network Discovery / Active Network Discovery. This option should never be enabled on pfSense. Ditto for Active Monitoring.

      Thanks for the quick answer.

      I'm a little surprised about not being able to lockdown individual processes for those 'who watches the watcher?' types of situations. Finding a dynamic workaround will be painful.

      As far as ntopng, I just don't want it to be able do anything online unless I've configured it to do so; I loath the idea of telemetry being sent off to various companies.
      Not that I've found anything (I haven't taken a serious look yet); I'm just a bit weary.

      Speaking of the settings, after reading that post about inadvertently scanning the Internet, I definitely ensured active monitoring and network discovery was turned off. 😆