Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics

    • All categories
    • H

      Can’t access LAN from iPhone WG app

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard
      38
      0 Votes
      38 Posts
      6k Views
      TommyMooT
      @hfederau good manual to recheck setup -> https://www.wundertech.net/how-to-set-up-tailscale-on-pfsense/
    • A

      Strange Routing Issue

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      21
      0 Votes
      21 Posts
      1k Views
      A
      @SteveITS I'll try the filer reload thing Thanks The alerts are an error that kept coming up after I restored a backup - with some mismatched interface assignments - etc Do you have any suggestions on how to get rid of the error? Can I get rid of the issue at an ssh level ?? If I recall right it is a rule on an interface or network that doesn't even exist and is not shown in the GUI[image: 1758751783303-image-9-24-25-at-6.05-pm-resized.jpeg]
    • J

      No Internet access with VLAN via OPT1

      Watching Ignoring Scheduled Pinned Locked Moved L2/Switching/VLANs
      17
      0 Votes
      17 Posts
      289 Views
      GertjanG
      @jogovogo said in No Internet access with VLAN via OPT1: My first surprise is that I'm now on the firewall, but why? The web server that serves the pfSense GUI runs on all assigned interfaces. When you installed pfSense, there was a pass rule for incoming traffic on the initial LAN interface : it accepts all traffic. When you add more LAN type interfaces, the ones called OPTx, there will be no inital rules, so you can't access anything. DHCP will work as pfSense will add hidden DHCP (UDP port 67 and 68) rules, but nothing else (no http https dns icmp etc etc etc etc). When you add a pas rules for TCP, UDP, etc, things "start to work". When you use addresses like this : [image: 1758697659291-89b7f27a-e729-4579-81c1-cb12989a7d3f-image.png] you use IP addresses. So, even is DNS is not working, then that won't be an issue. Your browser doesn't need to use use DNS (for translating host names to IP addresses) as you already gave an IP. It can contact the device 192.168.151.1 right away. You've allowed TCP IPv4 traffic to port 477, which is apparently your changed your pfSense https web GUI interface port. @jogovogo said in No Internet access with VLAN via OPT1: The issue has been resolved, simply, by restarting the DNS resolver. Euh ...... As you've changed lost of things at the same moment, it's hard to tell why dns (== the resolver) didn't work initially. Normally, when you add an new interface like your OPT1 interface, system processes like DNS (the resolver) gets restarted. The resolver will listen to All Interfaces : [image: 1758698045123-e07276c8-27b7-4a13-b999-ca154f396adf-image.png] by default so it would work right away on the new OPT interface. Again, you still have to add a firewall rule to allow DNS traffic to reach the pfSense DNS port 53 of course.
    • P

      new if_pppoe Backend - getting HA/CARP to work like in MPD

      Watching Ignoring Scheduled Pinned Locked Moved Development
      42
      1 Votes
      42 Posts
      3k Views
      w0wW
      @perrin This is just switching on maintenance mode on the primary, nothing unusual.
    • J

      No-IP DDNS Client - Broken in 2.8.1 ?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      13
      0 Votes
      13 Posts
      1k Views
      J
      @stephenw10 BINGO !! Thanks again as ever. My ISP recently changed the behaviour on the fibre accounts. The upstream gateway showed offline - I changed the monitor IP and - all working - thanks so much!!
    • C

      Issue with WAN speed negotiation after upgrading from 2.7 to 2.8 or 2.8.1

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      12
      0 Votes
      12 Posts
      2k Views
      stephenw10S
      What happens if you set the media to 100M without setting the mediaopt value so it still tries to negotiate that?
    • P

      Now Available: pfSense® Plus 25.07-RELEASE

      Watching Ignoring Scheduled Pinned Locked Moved Messages from the pfSense Team
      71
      6 Votes
      71 Posts
      7k Views
      M
      I'm opening a new thread about the pfBlockerNG and configuration history.
    • w0wW

      New PPPoE backend, some feedback

      Watching Ignoring Scheduled Pinned Locked Moved Development
      255
      0 Votes
      255 Posts
      45k Views
      A
      In addition to the ping issue, there is also an issue where the Gateway address (Gateway IPv6) is not set. Am I the only one for whom the Gateway address (Gateway IPv6) is not set when using if_pppoe? If so, I assume it's due to the uniqueness of setting only IPv6 for one PPPoE session. Specifically, if_pppoe assumes that IPv4 is configured. However, since there is no IPv4 configuration, if_pppoe cannot set the IPv4 Gateway (WAN_PPPOE). It is determined that an error has occurred in the IPv4 Gateway setting, and the IPv6 Gateway (WAN_DHCP6) setting is canceled. Is this guess correct?
    • w0wW

      25.11: Fatal trap 12 on reboot

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.11 Development Snapshots
      10
      0 Votes
      10 Posts
      746 Views
      stephenw10S
      Thanks. That's interesting. It looks like a different bug to me. Those are almost identical backtraces in the IPv6 stack. We are looking at it....
    • planedropP

      CARP Setup Constant Listen Queue Log Entries And Traffic Dropping

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      10
      0 Votes
      10 Posts
      3k Views
      stephenw10S
      I'm not aware of any new issues in isc-dhcpd. It depends how it failed. If it was unable to service requests but was still running it might log an error. If it was just so busy it stopped responding you might see that in the logs. Or, yes, if it just crashed out you might see that in the main system log.
    • P

      NAT to different interface than WAN

      Watching Ignoring Scheduled Pinned Locked Moved NAT
      10
      0 Votes
      10 Posts
      540 Views
      V
      @Pagi So I guss, the NAT address changed to the WAN address. Set it to LAN3 address and it should do, what you want.
    • JonathanLeeJ

      Serving different WPADs per subnet with Unbound

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS host overrides unbound wpad
      9
      0 Votes
      9 Posts
      586 Views
      johnpozJ
      @JonathanLee guest.arpa - it really should be guest.home.arpa. .arpa was not set a special use tld.. The domain home.arpa was set If you want to use any domain name you want with tld, then use the special use tld .internal I don't think its been fully approved as of yet, but believe an rfc has been submitted.. But guest.arpa for sure is not a special use domain.
    • T

      PfSense VM on ProxMox : Qemu-agent installation

      Watching Ignoring Scheduled Pinned Locked Moved Virtualization
      51
      11 Votes
      51 Posts
      82k Views
      weehooeyW
      @lifeofguenter Ah. I see that now. I did not realized the windows scrolled. @weehooey your script does not work. When I install qemu-guest-agent it already installs a start script: What you are showing is not what our script does. I can tell you that we tested using the script we provided, and it works on 2.8.1. Perhaps you have not marked your script as executable?
    • AndyRHA

      IPv6 minor question

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      9
      0 Votes
      9 Posts
      2k Views
      AndyRHA
      @JKnott I do not expect ATT to change my address, I have had the same IP4 address for over 7 years. Right now I am making sure I understand how PiHole will behave and get in place my DNS blocking to prevent to use of rouge DNS. I suspect to solution will be to block all IPv6 port 53 (except PiHole) and force the use of internal IPv6 and continue to masquerade IP4 rouge DNS requests.
    • J

      Why not a CNAME?

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      8
      0 Votes
      8 Posts
      388 Views
      tinfoilmattT
      @johnpoz said in Why not a CNAME?: But I am not aware of anyway to dynamically change what fqdn a cname record points to other than via a API into the dns.. Or maybe you could script something with unbound-control. Agreed.
    • D

      Alias edits causing firewall rule black holes

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      8
      0 Votes
      8 Posts
      590 Views
      D
      @SteveITS yes when I add a subnet to the alias it appears in the table, when I remove the subnet from the alias it disappears in the table. So that works as expected.
    • B

      Pfsense - OpenVpn

      Watching Ignoring Scheduled Pinned Locked Moved Español
      11
      0 Votes
      11 Posts
      3k Views
      L
      @Belcebu-Gdl Hola. Los logs se pueden incrementar en VPN - OPENVPN - SERVERS - editar el servidor - Verbosity level https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configure-server-advanced.html Para comprobar los certificados de un usuario, ir a SYSTEM - USER MANAGER - USERS - editar usuario - USER CERTIFICATES. Los certificados de usuario se pueden comprobar en SYSTEM - CERTIFICATES - CERTIFICATES. Se puede comprobar que son de la misma CA que el servidor openvpn. Puedes comprobar la autentiación de los usuarios en DIAGNOSTICS - AUTHENTICATION. Y puedes dar permisos de admin a los usuarios y comprobar si pueden entrar vía web a pfsense. Esto es para comprobar la autenticación mediante otro método. Un saludo.
    • C

      if_pppoe problems with php-fpm causing loops. (resolved)

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      74
      0 Votes
      74 Posts
      12k Views
      C
      @stephenw10 Yep IP alias for me.
    • G

      lan clients periodically drop ipv6 connectivity

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      19
      0 Votes
      19 Posts
      2k Views
      JKnottJ
      @gambit100 I doubt it is related to your problem, it just caught my eye. The problem is should you ever need to connect to a home.com network, it won't work. That's why they came up with a top level domain name to be used for that sort of thing, in that it will never be assigned to anyone.
    • S

      Netgate 8200 MAX VLAN & Switch Configuration Issue

      Watching Ignoring Scheduled Pinned Locked Moved L2/Switching/VLANs
      25
      0 Votes
      25 Posts
      2k Views
      S
      @patient0 Got it, will explore 'Shellcmd' package Thank you!