Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issues to registration system

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    23 Posts 7 Posters 3.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chaosmassive @FischKopp
      last edited by

      @FischKopp can you tell more in details what configuration need to be done?
      i also encounter this issue in my homelab

      F 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        You're seeing that exact same error?

        If you send me your NDI in chat I can check if we are seeing it and what status it has.

        Steve

        1 Reply Last reply Reply Quote 0
        • F
          FischKopp @chaosmassive
          last edited by

          @chaosmassive The necessary "workaround" is documented in the comment - what are you missing? :-)

          U 1 Reply Last reply Reply Quote 0
          • U
            UmbraAtrox @FischKopp
            last edited by UmbraAtrox

            @FischKopp
            This is the rule i created, but the network error for registering is still there. Edit: Took it a few minutes, now the register dialogue works but when i click on register it says thank you but stays unregistered. Package manager also not working.
            d6fb656c-aac3-4f69-8b76-4fd6d9efb2c1-image.png

            bootableB 1 Reply Last reply Reply Quote 0
            • bootableB
              bootable @UmbraAtrox
              last edited by

              @UmbraAtrox I replaced the Source Network all (0.0.0.0) by This Firewall, so its only apply to the firewall !!


              It is me Ruben
              Bootable Computación - Argentina.
              pfSense/Netgate Certificate Partner
              Pardon for my English - I am not an English speaker.
              Thanks a lot for yours invaluable time.

              U 1 Reply Last reply Reply Quote 1
              • U
                UmbraAtrox @bootable
                last edited by UmbraAtrox

                @bootable Thanks, everything works now. It seems to also have worked with 0.0.0.0 but i changed it to "this firewall". The register didn't work for me because pfsense still doesn't show a error when a already used key is used. New key + your nat rule = works

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, I'd be very interested to know what NAT states are created with that rule. You should never need to NAT traffic from the firewall itself unless it's from localhost.

                  With that rule in place the firewall will NAT it's own traffic and that will include IPSec connections that may fail with it set.

                  Steve

                  bootableB 1 Reply Last reply Reply Quote 0
                  • bootableB
                    bootable @stephenw10
                    last edited by

                    @stephenw10 That's true, I agree but some times if you modify in some way the routing table like add nat out rules, do that the system refresh something unexplainable


                    It is me Ruben
                    Bootable Computación - Argentina.
                    pfSense/Netgate Certificate Partner
                    Pardon for my English - I am not an English speaker.
                    Thanks a lot for yours invaluable time.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yes it could restore a default route for example. I would be wary about adding a NAT rule for all traffic. I have seen that break things numerous times!

                      bootableB 1 Reply Last reply Reply Quote 0
                      • bootableB
                        bootable @stephenw10
                        last edited by

                        @stephenw10 Yes that is why In my way to add that rule, I put the source as this firewall only, and not 0.0.0.0


                        It is me Ruben
                        Bootable Computación - Argentina.
                        pfSense/Netgate Certificate Partner
                        Pardon for my English - I am not an English speaker.
                        Thanks a lot for yours invaluable time.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          That still catches traffic from the WAN IP though which is what should not be done and what can break IPSec, for example.

                          1 Reply Last reply Reply Quote 0
                          • C
                            Collingwood
                            last edited by

                            I encountered a similar issue and found a solution by disconnecting all inactive ExpressVPN OpenVPN clients. Previously, I had them connected at all times to switch interfaces quickly if a streaming service blocked me. However, with only one active OpenVPN client connected to my VPN WAN interface, the problem was resolved and everything is functioning correctly now.

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnjces
                              last edited by

                              This is an old post so hoping my guess is accurate regarding the issue in the first post.

                              I am building up a new system and only have the LAN interface active with a LAN gateway attached and have been able to get modules downloaded and etc. The WAN interface is disabled and not connected yet.

                              My hunch is that for some reason NetGate wants to see something from the WAN side or firewall directly from this device. Otherwise one cannot register the box. Is my hunch correct?

                              If so, why can't we register a box in a semi online mode, no WAN connection yet.

                              Thanks for any thoughts!

                              JOhn

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                You don't need a 'WAN' specifically to register. As long as the firewall has a default route and can connect out it should be able to reach the registration system.

                                You would want to have the WAN NIC physically present in the device before registering though even if it's disabled. If you add it later you would change the system NDI and have to re-register.

                                Steve

                                J 1 Reply Last reply Reply Quote 0
                                • J
                                  johnjces @stephenw10
                                  last edited by

                                  @stephenw10

                                  Thank-you for the reply!

                                  Well... my WAN interface is enabled but it is not attached to any wan switch as I am just trying to configure it up and have everything mostly ready to swap and go... plug and play maybe?!

                                  I tried again several times and the same thing comes up every time.

                                  Thank you for choosing Netgate pfSense® Plus
                                  The registration system is not currently available. Please check your network connection and try again.

                                  Is the system down and been down for some period of time? I can download modules and was able to update to the latest version, 2.7.0. There may be a x.x.5 update? Dunno.

                                  Anyway, any other workaround?

                                  Thanks!

                                  John

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Not it's not down. Can the firewall ping out? Can it resolve hosts? Is it trying to use IPv6?

                                    J 1 Reply Last reply Reply Quote 0
                                    • J
                                      johnjces @stephenw10
                                      last edited by

                                      @stephenw10

                                      Yes to all questions. Using my lan gateway on the lan interface only. Using OpenDNS to resolve names.

                                      WAN interface is enabled, set with my ISPs Static credentials, (ready to go when I get everything configured. Still learning), but attached to nothing... no WAN connection yet. Just an empty RJ45 receptacle.

                                      Thank you again very much!

                                      John

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Ok try setting the firewall to prefer IPv4 in System > Advanced > Networking.

                                        J 1 Reply Last reply Reply Quote 1
                                        • J
                                          johnjces @stephenw10
                                          last edited by

                                          @stephenw10

                                          Thanks! That did the trick!

                                          John

                                          1 Reply Last reply Reply Quote 1
                                          • R raaalf referenced this topic on
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.