Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • K

      Limiter source mask now after NAT when using gateway groups - 2.8 change?

      Watching Ignoring Scheduled Pinned Locked Moved Traffic Shaping
      6
      0 Votes
      6 Posts
      221 Views
      K

      @gemg83 I see what you're saying - it could be the jump from 12.3 to 14 on the BSD side.

      It really hampers the use of limiters in multi-WAN setups so it feels like an important bug (I call it a bug as it doesn't behave at all how the UI or documentation suggests, it's more like using them on a floating rule).

    • R

      Can't create schedule | "The schedule must have at least one time range configured."

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      3
      0 Votes
      3 Posts
      68 Views
      R

      @patient0 OK, that helped. I'm fairly certain I had tried clicking Add time before and it hadn't worked - with the error I previously reported. In any case, it worked for me now. Thank you!

    • dennypageD

      Has the 25.07 RC been withdrawn?

      Watching Ignoring Scheduled Pinned Locked Moved Development
      3
      3 Votes
      3 Posts
      175 Views
      dennypageD

      @cmcdonald Appears to be back/fixed. Thanks.

    • I

      SG4200 SFP+ Addon

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      3
      0 Votes
      3 Posts
      198 Views
      I

      @stephenw10

      I want to use 10GBIT DAC inside my rack and also directly attach to my ISPs Fiber. It'd be the perfect successor for the SG6100 with the SFP+ Addon installed.

    • I

      Kea client logs

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      9
      0 Votes
      9 Posts
      660 Views
      GertjanG

      @ameinild said in Kea client logs:

      I get no logging from the kea-dhcp4 service for client DCHP logs, only from the dhclient for the WAN interface.

      Well ... this is FreeBSD/( and Linux) classic log behavior : no news is good news.

    • S

      Update of pfSense Plus Software

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      3
      0 Votes
      3 Posts
      119 Views
      S

      @stephenw10

      Thank you, that was what I was not doing and really appreciate the guidance and support here. Thanks

    • P

      Wireguard gateway connection issues when using domain names for peer endpoints

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      2
      0 Votes
      2 Posts
      12 Views
      P

      Ping a mullvad domain endpoint that causes wireguard gateway to have 100% packet loss:

      1ab0f742-701a-4172-8788-74c4b5dc2ef8-image.png

    • Bob.DigB

      25.07.r.20250715.1733 New log-type?

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      0 Votes
      2 Posts
      53 Views
      RobbieTTR

      @Bob-Dig
      Not seeing those in my firewall logs. Yours do look rather odd.

    • N

      Advice on SFP+ modules for 6100

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      4
      0 Votes
      4 Posts
      293 Views
      N

      No, just ordered from Amazon.

    • B

      Hyper-V Console Dimensions/Resolution

      Watching Ignoring Scheduled Pinned Locked Moved Virtualization
      2
      0 Votes
      2 Posts
      24 Views
      provelsP

      @Bannister8487 This worked for me, but I'm on 2012R2... LOL

      Create /boot/loader.conf.local (or add to it if it exists)

      kern.vty=sc hint.sc.0.flags="0x180" hint.sc.0.vesa_mode="279"
    • M

      New pfSense Plus 25.03-BETA is here!

      Watching Ignoring Scheduled Pinned Locked Moved Messages from the pfSense Team
      55
      2 Votes
      55 Posts
      10k Views
      GertjanG

      @Gcon said in New pfSense Plus 25.03-BETA is here!:

      So if you introduce support in CE first, and then much later in Plus ...

      Probably because Plus uses 15.0 which isn't officially released yet. The latest official release is FreeBSD 14.3.
      So, afaik, driver writers (Intel ?) aren't done adapting yet.

    • J

      SG-1100 eMMC Lifetime UP

      Watching Ignoring Scheduled Pinned Locked Moved Official Netgate® Hardware
      14
      0 Votes
      14 Posts
      989 Views
      stephenw10S

      Nice. 👍

    • D

      Strange behaviour with alias firewalling: Pass is logged but traffic is blocked

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      2
      0 Votes
      2 Posts
      63 Views
      D

      I managed to resolve my above issue and for anyone ending up with the same question:

      My issue was caused because of a colleague who added a floating rule, rejecting traffic coming form another alias with logging disabled on that rule. Unfortunately that alias contained a different FQDN that resolved to the same IP of the removed FQDN.

      What is the important lesson here:

      Apparently the PF box handles floating rules AFTER interface rules. And since logging of that floating rule was disabled, the firewall log logged the allowed traffic from the interface rule, but blocked the traffic afterwards based on the floating rule with no logging! You end up seeing an allow in your log, but it is blocked in the end!

      This must be a culprit some else will face one day or another :)

    • luckman212L

      25.07 RC - no default gateway being set if default route is set to a gateway group and the Tier 1 member interface is down

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      0 Votes
      2 Posts
      65 Views
      M

      I use a gateway group as the default gateway for both IPv4 and IPv6 and it works as expected - igb0 is tier 1 and igb1 is tier 2:

      # netstat -rn | grep default default 192.168.1.254 UGS igb1 default fe80::da21:daff:fe19:dbb0%igb1 UG igb1 # ifconfig igb0 | grep status status: no carrier

      You can share the files/logs here for review:
      https://nc.netgate.com/nextcloud/s/Dj3ZbjQstNB52e7

    • A

      AutoBackup Device Key

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      2
      0 Votes
      2 Posts
      118 Views
      stephenw10S

      Do you have the NDI from the device? If you send that to me in chat I can check for an ACB key.

    • P

      IPv6 disconnects after 1 minute on some LAN clients (pfSense Plus 24.11)

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      2
      0 Votes
      2 Posts
      37 Views
      U

      What is the difference between the device/PC that IPV6 works on and the ones that don’t? I would start with looking at the IPV6 settings on the devices/PCs that are having problems. I’m going to guess that your router advertisements are managed. Try stateless DHCP advertisements and see if that solves your problem.

    • M

      System - Package Manager - Available Packages

      Watching Ignoring Scheduled Pinned Locked Moved Italiano
      2
      0 Votes
      2 Posts
      35 Views
      C

      Sulla web GUI di pfSense vai in diagnostica e poi in command prompt,nella casella execute shell command digita il seguente comando: certctl rehash
      Attendi un output e poi ricontrolla gli aggiornamenti o i pacchetti e dovrebbe funzionare.
      pfSense 2.7.0 è una versione vecchia,quindi penso dovresti aggiornare alla versione 2.7.2 e poi alla versione 2.8.0,prima di fare qualsiasi cosa ricordati di salvare il file XML della configurazione attuale di pfSense.

      Saluti

    • luckman212L

      25.07.r.20250715.1733 - incorrect help link on System → Advanced → Netgate Nexus

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      1 Votes
      2 Posts
      73 Views
      stephenw10S

      Hmm, I thought we'd fixed that. Let me see...

      Ah, maybe not: https://redmine.pfsense.org/issues/16207

    • M

      Issue with ACME Certificates Refresh & Restarting HAProxy

      Watching Ignoring Scheduled Pinned Locked Moved ACME acme haproxy
      5
      1 Votes
      5 Posts
      2k Views
      GertjanG

      @EChondo

      What's your pfSense version ?
      The instructions are shown here :

      1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

      A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

      @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

      I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

      No need to wait x days.
      You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

    • D

      web GUI unresponsive after restoring config from SG-5100 to 8200

      Watching Ignoring Scheduled Pinned Locked Moved webGUI
      2
      0 Votes
      2 Posts
      36 Views
      S

      @dlogan From the console restart the webconfigurator and/or PHP. Check the logs?