Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Recent
    Log in to post
    Load new posts
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • All tags
    • 7

      Squid on 2.8

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      10
      0 Votes
      10 Posts
      407 Views
      GertjanG

      @jc1976 said in Squid on 2.8:

      upgrade an issue developed between suricata, pfblocker, and unbound. when i disable the two packages, all works fine

      Let's consider :
      If you leave the 'unbound' (the resolver) settings to "all default", the way you found them when you first installed pfSense.
      You remove / don't install the extra stuff = suricata and pfblocker.
      Then : no issues what so ever.
      Right ?

      This means your issue isn't "pfSense 2.8.0" or the upgrade. Its an 'ordinary' package settings issue - call the admin 😊

      Tell you boss that suricata can only filter non TLS traffic **, something that doesn't exist anymore. Check for yourself : who visits http (port 80) sites these day ? Who collects mail using port 110 ? Who sends mail using port 25 ?
      Imho : suricata, for what it's worth, can't do much these days, it can 'see' the data payload in the packets. Everything is TLS these days.

      ** It is possible to do TLS filtering, but that demands a 'proxy' setup, making you a real expert.

      pfBlockerng is blocking you, DNS or something else ? That's any easy one, and rather simple do debug.

    • luckman212L

      25.07.r.20250715.1733 - incorrect help link on System → Advanced → Netgate Nexus

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      1 Votes
      2 Posts
      60 Views
      stephenw10S

      Hmm, I thought we'd fixed that. Let me see...

      Ah, maybe not: https://redmine.pfsense.org/issues/16207

    • T

      NAT Reflection Issue with Dual WAN Setup in pfSense 2.7.2

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      87 Views
      stephenw10S

      The default LAN to any rule should pass that traffic.

      What rule did you add exactly?

    • M

      Issue with ACME Certificates Refresh & Restarting HAProxy

      Watching Ignoring Scheduled Pinned Locked Moved ACME acme haproxy
      5
      1 Votes
      5 Posts
      2k Views
      GertjanG

      @EChondo

      What's your pfSense version ?
      The instructions are shown here :

      1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

      A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

      @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

      I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

      No need to wait x days.
      You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

    • Bob.DigB

      25.07.r.20250709.2036 First Boot WireGuard Service not running

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      37
      0 Votes
      37 Posts
      490 Views
      Bob.DigB

      @stephenw10 Today I rebooted the host (Hyper-V) and had no problem at all. Don't know if this points towards being a weird virtualization issue... But then, why would WireGuard be effected...

    • N

      [RESOLVED] IPSec tunnel OK but routers can't ping each others

      Watching Ignoring Scheduled Pinned Locked Moved IPsec
      6
      0 Votes
      6 Posts
      15k Views
      A

      @nicolasfo said in [RESOLVED] IPSec tunnel OK but routers can't ping each others:

      You can know everything about everything thanks to Google. But if you don't know what to search, it is useless.

      The problem is resolved, by adding a bogus route, by hand.

      Here's the explanation :

      https://doc.pfsense.org/index.php/Why_can%27t_I_query_SNMP,_use_syslog,_NTP,_or_other_services_initiated_by_the_firewall_itself_over_IPsec_VPN

      Thanks for help

      Oh my god this worked! Created an account just to say THANK YOU for this. I have a pfSense<->Unifi connected via IPSec. Applying it on the pfSense side makes pfSense->Unifi direct gateway/FW connection possible. Applying it on the Unifi side made my IPSec work perfectly.

      Again, thank you!

    • D

      web GUI unresponsive after restoring config from SG-5100 to 8200

      Watching Ignoring Scheduled Pinned Locked Moved webGUI
      2
      0 Votes
      2 Posts
      27 Views
      S

      @dlogan From the console restart the webconfigurator and/or PHP. Check the logs?

    • J

      Installing 2.8 behind archaic PPPoE/VLAN from CenturyLink

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      5
      0 Votes
      5 Posts
      183 Views
      stephenw10S

      @jhg said in Installing 2.8 behind archaic PPPoE/VLAN from CenturyLink:

      Is this available yet?

      It's in testing now. No issues so far so should be available soon,

    • G

      Vodafone UK IPv6 Configuration

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      18
      0 Votes
      18 Posts
      3k Views
      A

      @drodgers Hey. I'm going through this exact thing now with Vodafone and pfSense and struggling. I've replicated your settings but it seems very intermittent.

      My clients get ipv6 addresses and can ping out fine however browsing this forums dies because it responds with and ipv6 address.

      For some reason as soon as I enable ipv6 netflix and paramount also stop streaming 🤦 They browse fine but as soon as you try to play a video it's a no go.

      Any ideas or pointers please or could you post your most recent working config please?

    • A

      Vodafone UK - IPv6

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      4
      0 Votes
      4 Posts
      110 Views
      patient0P

      @ashleygavin said in Vodafone UK - IPv6:

      What error do you get if you wget -6 a website?
      And you have the two default LAN firewall rules, one for IPv4 and one for IPv6, and only the LAN net? On WAN you won't need any rules for accessing internet. And do you see open states for the (web) connection?

      NAT would not be a topic for IPv6 in the default config.

    • I

      check_upgrade: "Updating repositories metadata" returned error code 1

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      84
      0 Votes
      84 Posts
      12k Views
      H

      I had same issue for a long time.

      Then I tried pkg update -f and got an error for SunnyVally repository
      I figured that I had a old version of zenarmor installed that matches the FreeBSD 14 and not 15.
      Upgraded the zenarmor to the latest version.

      Haven't had any of the error messages for some time now. hopefully that was it.

      Maybe this can be helpfull to someone.

    • B

      2.8.0 config.xml wont apply with /etc/rc.reload_all

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      6
      0 Votes
      6 Posts
      137 Views
      stephenw10S

      What gets logged when you run that in 2.8?

    • A

      Port Forwarding Not Forwarding Traffic To Destination Of VOIP PBX.

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      1
      0 Votes
      1 Posts
      17 Views
      No one has replied
    • G

      Traffic flows to wan not other subnet

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN
      9
      0 Votes
      9 Posts
      179 Views
      chpalmerC

      @greatbush while I have about 3 minutes here
      do you realize that windows machines by default will not allow pings and such from outside their own subnet to come in? Just trying to rule out any issues that you might have with Windows firewall on those machines..

    • K

      Can't access port-forwarded/natted services from another local network

      Watching Ignoring Scheduled Pinned Locked Moved NAT
      5
      0 Votes
      5 Posts
      17 Views
      K

      @johnpoz I see, thanks for explaining and the help!

    • A

      Tailscale Package Stuck in "Offline" State - GUI Broken After Reinstall

      Watching Ignoring Scheduled Pinned Locked Moved Tailscale
      1
      0 Votes
      1 Posts
      35 Views
      No one has replied
    • M

      System daemon waagent on Alpine Linux with s6

      Watching Ignoring Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
      5
      0 Votes
      5 Posts
      88 Views
      M

      I have already solved the problem by using the Python library. You can delete my post. Thank you for your help)

    • W

      Teams Issues

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      8
      0 Votes
      8 Posts
      275 Views
      GertjanG

      @wc2l said in Teams Issues:

      teams.microsoft.com works just fine.
      Host "msg.teams.microsoft.com" could not be resolved.

      Same for me.

      edit : while waiting, read also C:\Program Files (x86)\Microsoft Teams Network Assessment Tool\Usage.docx - this is a Microsoft tool with a manual / notice .... ( 😊 )

    • G

      Does this look like my pfSense was hacked

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      7
      0 Votes
      7 Posts
      3k Views
      GertjanG

      @luckman212

      Click on the image :

      1c8c8a2b-ed5f-4dd1-8694-8be0e58350e8-image.png

      I didn't test other search engines ...

      edit : the link @kpa posted is, imho, the best answer ( and totally not-FreeBSD related ^^ ).

    • R

      SG-1100 Recovery Help Needed

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      11
      0 Votes
      11 Posts
      61 Views
      stephenw10S

      Yes that's correct. The 1100 has only one NIC (mvneta0) and an internal switch with VLANs to separate the ports. But, as I said, you shouldn't need to make any changes there it's detected and set automatically for any Netgate device.