Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How is my ISP is able to tell I have a pfSense router?

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 5 Posters 665 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • asv345hA
      asv345h
      last edited by

      I was on the phone with my ISP just now troubleshooting a problem with their hardware when the tech casually tells me that it looks like I'm running pfSense. I'm wondering how they might know that. All internet traffic is over a VPN and dns is setup for dns-over-tls. Just curious.

      1 Reply Last reply Reply Quote 0
      • G
        GregoryO
        last edited by

        In my case, pfSense leaked it's hostname via dhcp address retrieval from ISP's DHCP server on WAN port.

        Ref. https://tools.ietf.org/html/rfc8117#page-5 , 4.1 -> Protocols That Leak Hostnames -> DHCP.

        Shortly. own hostname is included in DHCP query, while default hostname in pfSense is "pfSense";

        1 Reply Last reply Reply Quote 0
        • asv345hA
          asv345h
          last edited by

          DHCP leaking hostname never occurred to me. I set hostname to pfsense, so that would be it. Thanks.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            They can also most likely see the mac, which would point to netgate hardware if your running appliance.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • SammyWooS
              SammyWoo
              last edited by

              Never been paranoid myself but hostname is one of those things I automatically change after a install.  Guess I like to personalize my stuff, and now that u mentioned it, seeing all those default SSID in my neighborhood, so I can tell right on top, aha, somebody is running an at&t DSL…

              1 Reply Last reply Reply Quote 0
              • jahonixJ
                jahonix
                last edited by

                @SammyWoo:

                …so I can tell right on top, aha, somebody is running an at&t DSL...

                Probably better than using your family name or number.street as SSID. Knowing an ISP doesn't give you much of an attack vector.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.