Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics

    • All categories
    • O

      Zotac ZBOX CI323 nano

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      148
      0 Votes
      148 Posts
      139k Views
      X
      Just reporting that the 1.94 driver still works with 2.4.3. No issues so far. The change log is scary.
    • M

      can't update pfsense or install packages

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      148
      0 Votes
      148 Posts
      42k Views
      L
      @mrrobot . I managed to solve the problem, but what exactly is going on? I can't say. Change DNS Resolution Behavior to "Use remote DNS Servers" and put 9.9.9.9 as your first DNS server.
    • bmeeksB

      Quick Snort Setup Instructions for New Users

      Watching Ignoring Scheduled Pinned Locked Moved IDS/IPS
      147
      5 Votes
      147 Posts
      280k Views
      bmeeksB
      @qinn, it depends totally on which precise rules are enabled and what the traffic on your network actually consists of. The goal in IDS/IPS is to get no or very few alerts and blocks. That means your network is relatively secure and clients are following the rules ... . I don't mean that to say you should never get alerts, though. Just that you don't want to be receiving hundreds per hour. Once blocking is enabled that might drive you crazy as an admin. Within the IPS Polices, the Snort team has selected rules that provide security without a ton of false positive alerts.
    • I

      One Voucher Per Device

      Watching Ignoring Scheduled Pinned Locked Moved Captive Portal
      147
      1 Votes
      147 Posts
      51k Views
      W
      @Gertjan I have two systems both 2.5-dev version . second system is up to date always. I keep an eyes on all updates and bug fixes (redmine) everyday i am testing both system in different ways. second system i didn't apply any patch and people can reuse voucher on other device so they get disconnected from old Aug 3 13:00:03 logportalauth 38072 Zone: campco - CONCURRENT LOGIN - TERMINATING OLD SESSION: 9478394944, 7c:78:7e:4d:1c:43, 10.10.21.188 Moving soon to FreeRADIUS base solution which has no issue with concurrent logins. I have already done initial testing in production environment.
    • T

      Multiple IPv6 Prefix Delegation over AT&T Residential Gateway for pfSense 2.4.5

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      147
      4 Votes
      147 Posts
      94k Views
      R
      @marcg Thank you for the tip. When I get some free time, I will check out the auto generated interface addresses prefix's.
    • C

      No DHCP on pfSense VLAN with Cisco Smart Switch

      Watching Ignoring Scheduled Pinned Locked Moved L2/Switching/VLANs
      147
      0 Votes
      147 Posts
      124k Views
      M
      @Cannondale Yeah, you're right the other one is an ET card. It adds support for SR-IOV and IPSec offload over VT card.
    • P

      2.0.2 ???

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      145
      0 Votes
      145 Posts
      69k Views
      M
      I used the Invoke Upgrade option in the WebGUI to upgrade my 2.0.1 32bit-i386 installation and it was the fastest and easiest upgrade I've ever done to one of my machines. The only thing I noticed was that I had to check the box to enable the pfBlocker package, the only package I'm using. The package didn't need to be reinstalled, just the box to enable it checked, and it kept all the CIDR lists I had set up.
    • georgelzaG

      pfSense not enabling port

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      145
      0 Votes
      145 Posts
      14k Views
      G
      @georgelza said in pfSense not enabling port: @Gblenn Yes... the VM is started via the data centre and that won't allow you to start it twice. You will need to clone it and give it new name and IP. I'd prefer to have the VM Images on local mirror via Ceph, gives me speed and Ceph will make sure there is a copy on another node. Would like someone else to chirp in here... confirm this works with Proxmox. know other Hypervisors allow this. G Yes that is my understanding as well, although I have not tried it. And I totally agree that using the local nvme's will give you way more speed. I still suggest creating a PBS VM (Proxmox Backup Server) and perhaps map e.g. a disk on your TrueNAS for that. I've had a few instanses where I have wanted to "go back in time" and restore something from a few weeks back even. Typically because I messed up and didn't realize it until some time later. other than the official proxmox forum which does not seem to have much activity, anyone aware of a active/responsive proxmox community... otherwise wondering if we can get the admin's here to create a proxmox section ;) There is a virtualization section already, with plenty Proxmox activity... https://forum.netgate.com/category/33/virtualization
    • F

      EZIO Driver for LCDproc

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      144
      1 Votes
      144 Posts
      60k Views
      stephenw10S
      Can we see a screenshot of the exact settings you're trying to enter in the package? Is it possible your browser is auto-filling hidden fields? Steve
    • S

      ipv6 broken: radvd: can't join ipv6-allrouters on <interface>

      Watching Ignoring Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
      144
      5
      0 Votes
      144 Posts
      76k Views
      yon 0Y
      This 2.4.5-p1 version also has this problem
    • L

      Using pfsense with multiple WANs

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      144
      1
      0 Votes
      144 Posts
      45k Views
      L
      Ah it dawns on me there is one thing I should mention so someone else doesn't get caught. ARP cache played a huge part in this and an accidentally left over rule in one of the firewalls as well. The firewalls were basically competing to be the gateway so things would get weird like a vm would boot up with a gw then a while later change to another. Once ARP cleared up, everything was fine.
    • bmeeksB

      Snort update coming soon – please read about an important change!

      Watching Ignoring Scheduled Pinned Locked Moved pfSense Packages
      142
      0 Votes
      142 Posts
      60k Views
      F
      @BBcan177: Hi Ben, I already have request on Redmine to add this functionality for VirusTotal and other links. https://forum.pfsense.org/index.php?topic=73406.msg400956#msg400956 https://redmine.pfsense.org/issues/3508#change-13575 You can manually edit that file for now. Perfect. And now I also know where the issues log resides. Thanks. Ben
    • M

      Verizon Fios and IPV6, Which Settings Work?

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      142
      0 Votes
      142 Posts
      93k Views
      N
      The original settings in this thread worked fine for me a few years ago when Verizon began rolling this out. Then they seemed to roll everything back in late 2023 and I went the whole of 2024 with no ipv6. I noticed this summer that I was seeing ipv6 addresses again and when looking into it, they appeared to have enabled it all again in Jan. of this year. But by the time I noticed over the summer, I had upgraded to the latest pfsense version and also switch over to KeaDHCP server. I tried using it for an online game and was noticing that I was getting dropouts for 15 minutes about every hour, so I just went back to using ipv4. This weekend I started looking at it more closely and found that every 1 hour 15 minutes, I would lose the ability to use ipv6. These are the entries I would see in my logs. The period from 9:52-10:04, I would have no ipv6 connectivity. IPv4 would renew the leases fine and connectivity there was unaffected. Oct 12 10:04:40 dhcp6c 55217 dhcp6c Received INFO Oct 12 10:04:39 dhcp6c 55217 Sending Renew Oct 12 10:04:36 dhclient 40170 bound to <redacted ip> -- renewal in 3600 seconds. Oct 12 10:04:36 dhclient 18404 Creating resolv.conf Oct 12 10:04:36 dhclient 17251 RENEW Oct 12 10:04:36 dhclient 40170 DHCPACK from <redacted ip> Oct 12 10:04:36 dhclient 40170 DHCPREQUEST on igb0 to <redacted ip> port 67 Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd017400] ALLOC_ENGINE_V6_ALLOC_FAIL_CLASSES duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: Failed to allocate an IPv6 address for client with classes: ALL, pool_lan_0, UNKNOWN Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd017400] ALLOC_ENGINE_V6_ALLOC_FAIL_NO_POOLS duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: no pools were available for the lease allocation Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd017400] ALLOC_ENGINE_V6_ALLOC_FAIL_SUBNET duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: failed to allocate an IPv6 lease in the subnet <redacted ip>::/64, subnet-id 1, shared network (none) Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd016d00] ALLOC_ENGINE_V6_ALLOC_FAIL_CLASSES duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: Failed to allocate an IPv6 address for client with classes: ALL, pool_lan_0, UNKNOWN Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd016d00] ALLOC_ENGINE_V6_ALLOC_FAIL_NO_POOLS duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: no pools were available for the lease allocation Oct 12 09:52:27 kea-dhcp6 21138 WARN [kea-dhcp6.alloc-engine.0x1c3afd016d00] ALLOC_ENGINE_V6_ALLOC_FAIL_SUBNET duid=[<redacted>], [no hwaddr info], tid=0x6b0e2c: failed to allocate an IPv6 lease in the subnet <redacted ip>::/64, subnet-id 1, shared network (none) After fooling around with various settings and searching online, I came to the conclusion that pfsense's implementation of KeaDHCP did not appear to handle renewals of the prefix delegation. I don't know if that is the right conclusion, but the config that was being generated looked to have hard coded subnet ranges and never used Kea's pd-pools config block. Ultimately, all I did to "fix" this was to disable the KeaDHCP service on my LAN interface and change the Router Advertisment-->Router Mode from Managed to Assisted and let my clients sort ipv6 themselves instead of having the router do DHCP. I could set it to Stateless but if someone can tell me what I was doing wrong I'll try and set up DHCP6 again. As I could not find others online having this problem, I assume I did not have the DHCP server configured correctly, but at least for my use case, I don't actually need DHCP6. [image: 1760369517889-beb9b838-c78b-496e-813b-653f044d6232-image.png] Since making that change, my ipv6 dropouts ceased. Also, an unexpected 1.5-2ms reduction in ping time to the target I was using. [image: 1760369744926-42176401-a3c8-4d22-b829-a9b5c0b4516a-image.png] Hopefully this helps others who might end up in a similar boat. This and the now lost thread on dslreports.com were tremendous resources for getting this working originally.
    • ?

      Increased Memory and CPU Spikes (causing latency/outage) with 2.4.5

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      141
      3
      2 Votes
      141 Posts
      56k Views
      jimpJ
      https://forum.netgate.com/post/908806
    • X

      Latest snapsot wireless bridged as well as static not working

      Watching Ignoring Scheduled Pinned Locked Moved 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
      140
      0 Votes
      140 Posts
      85k Views
      jimpJ
      Alternately, I suppose you could also just check the "Disable Hardware Checksum Offloading" option, which would have the same effect. Not sure how that might impact the ALIX overall, if at all, but if it is problematic it might be better to leave it off anyhow.
    • F

      SSD (Solid State Drive) and pfSense (Important)

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      140
      0 Votes
      140 Posts
      175k Views
      C
      @belt9: however there is still power loss issues that can and do occur with drives. I'v never heard of this? Could you tell me more about it? AFAIK, if the power is coming from the wall, and the power supply is working then there will be no issues? Where would a power loss occur between the PSU and the SSD? No no lol, there is still a ton of things to go wrong, the OS could crash, causing loss of power to the SSD, the power Supply malfunction causing the SSD to lose power, the machine could shut down due to being unplugged by mistake, a UPS only helps of the power goes out, there are still many many other things that can go wrong.
    • R

      How to: Get CPU temp

      Watching Ignoring Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
      140
      0 Votes
      140 Posts
      127k Views
      stephenw10S
      @mdima: more than awesome… that would be legen...wait for it...dary... legendary! Haha!  :D It would be good though. Steve
    • T

      23.01.b.20230106.0600 IGMP proxy stops TV stream

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      139
      0 Votes
      139 Posts
      87k Views
      M
      @thebear Ah, the order was incorrect! Could have known that :(. Changed the order and will do some further testing; let you know!
    • ArmstrongA

      Email Notification - OpenVPN Client Connect (Common Name)

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN
      138
      0 Votes
      138 Posts
      53k Views
      M
      Hi all, I do not know much about pfsense command line. Wondering if someone can help me step by step ? Do I need command line access to the router or I can use the web access to the router ? Can I use the command prompt section ? So I have to create 2 executable files name notify.sh and disconnect.sh ? How I am going to create these files ? I think I got the part to set the permissions. How can I set the permissions ? by using Execute Shell Command section on the web ? What will be in those two files ? So same code in both files ? @Armstrong said in Email Notification - OpenVPN Client Connect (Common Name): #!/usr/local/bin/php -q <?php require_once("/etc/inc/notices.inc"); $local_connect_value = " user_name: " . getenv('common_name') . " vpn_client_ip: " . getenv('ifconfig_pool_remote_ip') . " from: " . getenv('trusted_ip') . " on " . date('F j, Y, g:i a'); if ( strrchr (FILE , 'disconnect') ) { $local_connect_value .= ", duration : " . getenv('time_duration') . " seconds, received : " . getenv('bytes_received') . " bytes, send : " . getenv('bytes_sent') ." bytes. DISCONNECTED."; } notify_all_remote($local_connect_value); ?> Am I coping from <?php or from #!/user ? If it is from <?php then what I have to do with first line #!/usr/local/bin/php -q Is it possible some one can help me step by step and also tell me which part of the webconfigurator I need to use to do all this please ?
    • stephenw10S

      Watchguard Firebox M440

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      137
      0 Votes
      137 Posts
      43k Views
      stephenw10S
      You should be able to boot pfSense fairly easily, you just end up with only 3 working ports; the two SFP ports and the management port. It would be nice to have the other 24 ports accessible. Did you reach that point? Steve