Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • I

      check_upgrade: "Updating repositories metadata" returned error code 1

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      84
      0 Votes
      84 Posts
      12k Views
      H

      I had same issue for a long time.

      Then I tried pkg update -f and got an error for SunnyVally repository
      I figured that I had a old version of zenarmor installed that matches the FreeBSD 14 and not 15.
      Upgraded the zenarmor to the latest version.

      Haven't had any of the error messages for some time now. hopefully that was it.

      Maybe this can be helpfull to someone.

    • R

      25.03-BETA won't install in SG-2100 (SG-1100 ok)

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      13
      0 Votes
      13 Posts
      819 Views
      R

      @stephenw10
      Thanks again.
      Well it is full of passwords and pre-shared keys and very detailed stuff but I guess we should find the culprit of it somehow.

      I did find leftovers of lcdproc before, which I cleaned at some point.
      That means that part of the config I am using was migrated from a modified WatchGuard I have used in the past.

      Let me have a look tomorrow.
      It's kind of late now in my timezone.
      Thanks!

    • R

      v2.7.2: Dynamic DNS not working with Cloudflare

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      11
      0 Votes
      11 Posts
      358 Views
      R

      @70tas Indeed the global token does not work anymore, you must use the API token. And then for the login, do not use your email address. As I wrote before: "One must use the Zone ID when using the API token."

      I have this working using the DDNS GUI. I only needed the script for debugging.

    • QinnQ

      Feed issue on SWC

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      7
      0 Votes
      7 Posts
      562 Views
      fireodoF

      @Qinn said in Feed issue on SWC:

      Got a reply from Dan and here it is solved.

      Thanks for feedback!

    • w0wW

      DNS resolver exiting when loading pfblocker 25.03.b.20250409.2208

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      124
      0 Votes
      124 Posts
      12k Views
      stephenw10S

      Good to hear.

    • P

      Now Available: pfSense® CE 2.8.0-RELEASE

      Watching Ignoring Scheduled Pinned Locked Moved Messages from the pfSense Team
      112
      12 Votes
      112 Posts
      19k Views
      stephenw10S

      You can just start a new thread in General pfSense Questions.

    • T

      NAT Reflection Issue with Dual WAN Setup in pfSense 2.7.2

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      82 Views
      stephenw10S

      The default LAN to any rule should pass that traffic.

      What rule did you add exactly?

    • B

      2.8.0 config.xml wont apply with /etc/rc.reload_all

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      120 Views
      stephenw10S

      What gets logged when you run that in 2.8?

    • Z

      VPN Client Not Using pfSense DNS Server (10.60.0.252) After Connecting via OpenVPN

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      69 Views
      stephenw10S

      Because 10.60.0.252 is the server end of the VPN tunnel at pfSense. The local DNS resolver (Unbound) listens and responds on that IP and that is where the override is set.

      Where as 8.8.8.8 is Google's DNS service that knows nothing about any local overrides you might have set. When clients use that DNS server is bypasses any local DNS overrides.

    • R

      Sudden appearance of SSDP through port 1900 from a public ip

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      6
      0 Votes
      6 Posts
      98 Views
      johnpozJ

      @rasputinthegreatest well blocking and not log would just be any any udp to that ff0e::c address or port 1900 anything, etc. And don't have it log.

      As to the scanners - that is a pfblocker alias I have.. And put that in a floating rule.

      scandeny.jpg

    • J

      Bricked (and recovered) 4200

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      6
      0 Votes
      6 Posts
      438 Views
      J

      I would agree. 18 hours in and everything continues to run smoothly. The issue related to image availability I believe is the valid answer and we can close this out as solved. Thanks everyone. -JD

    • P

      SG-1100 as VPN client only (no dhcp) adding to existing network

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      6
      0 Votes
      6 Posts
      99 Views
      V

      @phthatcher said in SG-1100 as VPN client only (no dhcp) adding to existing network:

      just assure that when the server reaches out to the web it is behind the vpn

      So all you need is to configure pfSense as default gateway on the server.

      The pfSense only needs a single interface (LAN, router-on-a-stick), connected to your LAN.
      On the VPN interface you have to add an outbound NAT rule, as mentioned in the ExpressVPN tutorial.

    • S

      pfSense and Squid going forward?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      9
      0 Votes
      9 Posts
      324 Views
      JonathanLeeJ

      https://github.com/pfsense/FreeBSD-ports/pull/1420

      Merged I could not test it but it is in there with the make file now and the distinfo file

      @stephenw10

      Let me know if you can test that out

      Dont use this I am having issues with the MASTER SITES and patches folder it wont make clean install all the way

    • LaxarusL

      if_pppoe with frequent connection losses due to ISP connection making firewall unstable

      Watching Ignoring Scheduled Pinned Locked Moved Development
      27
      0 Votes
      27 Posts
      780 Views
      stephenw10S

      You can set the size it rotates at and the number of files to retain in the log settings at Status > Logs > Settings. As long as you have the space you should be able to increase it.

    • L

      Nvidia NIC driver ^tx checksum and tso4 issues^

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      6
      0 Votes
      6 Posts
      132 Views
      stephenw10S

      Probably just that then. But you should see the set options and capabilities for those NICs like:

      [2.8.0-RELEASE][admin@t70.stevew.lan]/root: ifconfig -vm igb0 igb0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500 description: WAN options=4e100bb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWFILTER,RXCSUM_IPV6,TXCSUM_IPV6,HWSTATS,MEXTPG> capabilities=4f53fbb<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,TSO4,TSO6,LRO,WOL_UCAST,WOL_MCAST,WOL_MAGIC,VLAN_HWFILTER,VLAN_HWTSO,NETMAP,RXCSUM_IPV6,TXCSUM_IPV6,HWSTATS,MEXTPG>

      So there you can see the NIC is both checksum offload and TSO capable but only checksum is enabled.

    • R

      Sudden appearance of Block IPv4 link-local (1000000101).How to find the cause?

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      6
      0 Votes
      6 Posts
      77 Views
      johnpozJ

      @rasputinthegreatest see my edit about devices sending it out even when they have an IP on the network - my directv appliance does that.. But once you have a mac should allow you to track it down. Especially if you have a smart switch and its wired. Where you can look at the mac address table.

      If everything is working and you just don't like the noise in the logs, you can turn those off, either in log settings - I believe new 2.8 allows for not logging link local. Or you could setup a rule not to log it.

    • dennypageD

      pimd

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      235 Views
      L

      @dennypage, @maximushugus, @louis2, @jeffscott

      Good news!

      I have the PIMD version I did compile yesterday working !!
      Including the related pfSense gui.

      Not I think I can make it running the way it should in the coming week(??).

      Note that at this moment I still have the following issues:

      The warnings at compile time. Surely NOT OK!
      => I do not have the knowledge to fix this. but it does not be blocking. The man directory issue.
      => I have no idea how to solve that. My actual work around is removing the manual files from package definitions (NOT OK) Pimd does not run using the GUI.
      => At this moment I have to start pimd from the command line in debug mode and restart pimd after each config change. However pimd is running and I can access my media server.
      pimd -n -f /var/etc/pimd/pimd.conf --disable-vifs -l debug=all the firewall rules are not yet as they should be, for the test I just opened too much.

      So I have to sort out things in the coming week/weeks. But I have good hope that I can solve points 3 and 4.

      If someone can solve points 1 and 2, it would be highly appreciated!!

    • JonathanLeeJ

      Snort and GIF0 for HE tunnel broker

      Watching Ignoring Scheduled Pinned Locked Moved IDS/IPS ipv6 snort he.net gif ips
      9
      0 Votes
      9 Posts
      170 Views
      JonathanLeeJ

      @SteveITS It looks like it is detecting ipv6 better

      already is showing alerts

      Screenshot 2025-07-12 at 10.39.56.png

      It sees some ipv6 going to my interface. Again snort also would spot stuff every once a a while. My son got a bad bug on his tablet and it had a Russian email server running I checked it on virus total and it was spot on as malware known abuses so I reported it

    • georgelzaG

      multiple ISP/WAN interfaces

      Watching Ignoring Scheduled Pinned Locked Moved HA/CARP/VIPs
      6
      0 Votes
      6 Posts
      154 Views
      N

      @georgelza said in multiple ISP/WAN interfaces:

      I want to make it as simple as possible, without me becoming their IT department....

      Well, you ARE their it department.

      Leave it as it is, if it works why fix it?

    • K

      Can't access port-forwarded/natted services from another local network

      Watching Ignoring Scheduled Pinned Locked Moved NAT
      5
      0 Votes
      5 Posts
      14 Views
      K

      @johnpoz I see, thanks for explaining and the help!