• ipsec vti with custom outbound nat bug?

    NAT
    1
    5
    0 Votes
    1 Posts
    20 Views
    No one has replied
  • The system became unresponsive

    Plus 25.11 Snapshots
    22
    0 Votes
    22 Posts
    451 Views
    stephenw10S
    Well it far higher than even the 1M default we usually set and that is generally far bigger than it needs to be. But you also show only 1400 states which is nothing. If you exhaust the mbufs that would definitely cause a problem. But you should also see that logging an error.
  • Unable to set unbound option on some options in feeds

    pfBlockerNG
    3
    1
    0 Votes
    3 Posts
    50 Views
    S
    @shady28 Are you maybe looking at IP block list feeds vs DNSBL feeds?
  • easylist nordic no domains error

    pfBlockerNG pfblockerng easylist
    5
    0 Votes
    5 Posts
    52 Views
    F
    @fireodo thank you very much for the help I will look into the sanity check.
  • X-ray VPN implementation in future releases of pfSense+

    Development
    17
    0 Votes
    17 Posts
    3k Views
    E
    Is it just me, or does it seem like the KISS (Keep It Simple [redacted]) answer is to install X-Ray on an officially supported platform or a VPS and tunnel traffic through that?
  • 0 Votes
    73 Posts
    12k Views
    B
    @slu said in Syslog service in pfSense v2.8.1 often stop itself: @jrey years ago there was a p1 release: https://docs.netgate.com/pfsense/en/latest/releases/2-3-5-p1.html Thanks for the source
  • 23.09.1 from 23.05.1 freeRadius broke

    pfSense Packages
    10
    0 Votes
    10 Posts
    1k Views
    V
    Note to self under the latest release I had to set decipher list to cipher_list = "DEFAULT@SECLEVEL=0"
  • Crash on saving after deselecting all allowed ciphers

    OpenVPN
    4
    0 Votes
    4 Posts
    156 Views
    A
    @nobanzai +1 amd64 15.0-CURRENT FreeBSD 15.0-CURRENT #21 RELENG_2_8_1-n256095-47c932dcc0e9: Thu Aug 28 16:27:48 UTC 2025 root@pfsense-build-release-amd64-1.eng.atx.netgate.com:/var/jenkins/workspace/pfSense-CE-snapshots-2_8_1-main/obj/amd64/AupY3aTL/var/jenkins/workspace/pfSense-CE- Crash report details: PHP Errors: [16-Nov-2025 21:48:05 Europe/] PHP Fatal error: Uncaught TypeError: Form_Select::__construct(): Argument #4 ($values) must be of type array, null given, called in /usr/local/www/vpn_openvpn_client.php on line 942 and defined in /usr/local/www/classes/Form/Select.class.php:31 Stack trace: #0 /usr/local/www/vpn_openvpn_client.php(942): Form_Select->__construct() #1 {main} thrown in /usr/local/www/classes/Form/Select.class.php on line 31 I'm temporery fix it. Use diag_edit.php edit /usr/local/www/vpn_openvpn_client.php & saved history version 4b9165e "Default to an empty array for functions expecting a countable value Do this for foreach() and count()." https://github.com/pfsense/pfsense/blob/4b9165e5ad3f47c36d1dec3a585a60b629bcdc3a/src/usr/local/www/vpn_openvpn_client.php and edit ciphers in client.
  • Now Available: pfSense® CE 2.8.1-RELEASE

    Messages from the pfSense Team
    27
    6 Votes
    27 Posts
    4k Views
    V
    @dennypage Create an igmp rule on your floating rules, and do not set the direction to in. Set: Interface Leave: Direction to any Set: Protocol to IGMP only Set: Source to any Set: Destination to any Set: Quick Set: Adavanced Options, Allow IP options For example if you have pfblocker dnsbl auto rules (ping auto rule, permit auto rule) on top, it can cause trouble on the states. Check: the States of this rule. You should see tcp and upd packets as well, 443. If you set the direction on your lan intarfce to in, you should see igmp only, otherwise you have to place at the very top of all your other floating rules before everything else.
  • Openwrt ONE

    Wireless openwrt wifi
    10
    0 Votes
    10 Posts
    3k Views
    JonathanLeeJ
    @w0w You can also run Squid on OpenWRT I am told there is so many packages I have been playing with OpenWRT because TP-Link was doing so weird data harvesting and pfsense caught it in the act after I just installed openwrt per @johnpoz recommendations. I just run it in bridge mode now
  • BUG? 24.11 ACME IPV6 cloudflare issues, ipv4 not respected?

    ACME
    3
    0 Votes
    3 Posts
    999 Views
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Session timeout adjustable in 23.01?

    General pfSense Questions
    9
    0 Votes
    9 Posts
    2k Views
    luckman212L
    @jimp Is this still a known issue somewhere? I have my session timeout set at 1440 (should be 24h) but I get logged out way sooner than that, seems like 1-2 hours. I don't see anything odd in the system log, and my client IP is not changing. I will note: I often see /tmp/sess_* files piling up. I sometimes need to clean these out. There can be dozen or more. All of them have a 0 byte size, with the exception of a single file (which I assume to be the active login session) (25.11 snapshots) screenshot [image: 1763314289448-b800a099-52d7-4523-85b3-5398bf578f29-image-resized.png]
  • Problema com DNS Forwader

    Moved Portuguese
    1
    0 Votes
    1 Posts
    36 Views
    No one has replied
  • 25.11 BETA - What's new?

    Moved Plus 25.11 Snapshots
    11
    0 Votes
    11 Posts
    708 Views
    R
    @SteveITS Thank you!!
  • filterlog output question

    DHCP and DNS
    1
    0 Votes
    1 Posts
    25 Views
    No one has replied
  • Force TV out opposite WAN

    WireGuard
    3
    0 Votes
    3 Posts
    66 Views
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • CISA Update Feeds

    Off-Topic & Non-Support Discussion
    2
    1
    1 Votes
    2 Posts
    84 Views
    S
    @provels said in CISA Update Feeds: https://www.cisa.gov/ Thank you, CISA is clearly an excellant resource. Jim
  • Block access to webserver, allow just specific addresses

    Firewalling
    3
    0 Votes
    3 Posts
    52 Views
    D
    @SteveITS Thank you for your quick answer!
  • IPV6 with Zen, not receiving an IP Address

    IPv6
    15
    2
    0 Votes
    15 Posts
    166 Views
    M
    @FollyDude-0 I'm still trying to find it, not sure if I binned it. I might ask if I can borrow one if I can't find it. We are on FTTP with a /29 - works pretty good.
  • 2 Votes
    34 Posts
    33k Views
    S
    Hello everyone, Is there an update to this entry? Image 2 no longer seems to work/be available. Thank you very much.