• Windows Server IPSec VPN Behind pfSense

    IPsec
    5
    0 Votes
    5 Posts
    1k Views
    S
    @Cortexian is the Windows firewall disabled/configured? https://docs.netgate.com/pfsense/en/latest/troubleshooting/nat-port-forwards.html
  • Big issues related to Firewall logging.

    Firewalling
    13
    0 Votes
    13 Posts
    2k Views
    L
    I did a small modification in my rule group. A small change in the rule description and I reordered the rules so that the rule without iP-options comes before the rule with IP-options set. [image: 1757332567767-ab160041-b646-49cf-bd66-3ded176aa5e1-image.png] [image: 1757332473112-c760c5e7-6843-4ee5-a322-6d8f32d3361c-image.png] Note that there are a couple of addresses: source 0.0.0.0 destination 224.0.0.22 source 192.168.100.2 destination 224.0.0.22 source 192.168.100.1 destination 224.0.0.1 192.168.100.1 = vlan gateway 224.0.0.22 = is used for the IGMPv3 protocol. This protocol is used by hosts to manage its multicast interests 224.0.0.1 = is a well-known multicast address reserved for the all-hosts group, meaning it addresses all devices that have joined the multicast group 192.168.100.2 = address inside my VM-lan assigned to the VM-host. I do not know why it behaves like this, however for this moment (during this test) I leave it as it is.
  • IPSec bypass some traffic via script

    IPsec
    1
    0 Votes
    1 Posts
    372 Views
    No one has replied
  • Now Available: pfSense® CE 2.8.1-RELEASE

    Messages from the pfSense Team
    14
    6 Votes
    14 Posts
    2k Views
    sokeadaS
    @sandrinho1976 said in Now Available: pfSense CE 2.8.1-RELEASE: Any news for the Zabbix Proxy 7 package? Is this what you're looking for? [image: 1757294811547-5175ce88-06b3-4abf-bf4d-91c593ccf8e6-image.png]
  • Can't access webgui after pfSense VM cloning and WAN IP change.

    webGUI
    8
    0 Votes
    8 Posts
    1k Views
    S
    @Matlock well you have no rule allowing access from your PC to pfSense port 443. I’d ensure the internet can’t access it for sure.
  • Outbound ping blocked

    Firewalling
    12
    0 Votes
    12 Posts
    3k Views
    P
    Hello, Same issue here, a "gateway monitoring" rule blocks IPv6 gateway monitoring. Removing the monitor address from the gateway configuration and re-adding it causes the rule to disappear and monitoring works again until next interface reset. The issue began after upgrade to 2.8.0 and is still here in 2.8.1. Best regards, Ed
  • DNSBL and IPv6

    pfBlockerNG
    2
    0 Votes
    2 Posts
    4k Views
    tinfoilmattT
    @BiloxiGeek said in DNSBL and IPv6: Does it just follow the IPv4 address that is listed above that? In my case it would end up being ::10.0.0.86 Yes. In this specific context that's the notation being used. (Full IPv6 web server address, for reference then, would be: http://[0000:0000:0000:0000:0010:0000:0000:0086]) Nota bene: I use 0.0.0.0 which renders the DNSBL webserver useless and inaccessible, but otherwise returns 0.0.0.0 or ::/NOERROR answers to all blocked lookups.
  • ACME renew cert fail after update from v24.11 to v25.07.01

    Moved ACME
    3
    0 Votes
    3 Posts
    1k Views
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • 25.7.1 package issue

    General pfSense Questions
    6
    0 Votes
    6 Posts
    4k Views
    S
    @hescominsoon said in 25.7.1 package issue: 25.07.1-RELEASE on both and yesw i access both in private mode which auto clears when i close the tab. Minor nitpick…Private/incognito tabs all share the same session so cookies/cache would clear when closing the window/all private tabs.
  • Feodo Tracker Botnet C2 IP Rules down for almost 48h

    IDS/IPS
    2
    0 Votes
    2 Posts
    508 Views
    fireodoF
    @Gradius said in Feodo Tracker Botnet C2 IP Rules down for almost 48h: Any mirror or alternative ? No - AFAIK ... Edit (08.09.2025): Its UP again!
  • 0 Votes
    58 Posts
    9k Views
    stephenw10S
    Well that's not a bug if the gateways used were marked as down. That's the expected behaviour in 2.8.X. If the gateway being marked down is a change since 2.7.2 that could be a separate problem.
  • Switched to AT&T fiber, IPv6 tunnel broken

    General pfSense Questions
    44
    0 Votes
    44 Posts
    5k Views
    BiloxiGeekB
    @marcg I finally got the PD on the pfSense and I'm working through the reservations I had set to the tunnel so they get an reserved address within the PD. I had wanted to keep the tunnel from he.net but I never could get that working. If the BGW320 ever gets a different prefix I'll have to change any AAAA records at he.net's free DNS services. Won't be too difficult and I could script it through their API if it starts to happen often enough. I've had the same prefix for about a week now. Same IPv4 since I put the SG4200 online. I don't expect any changes but since I'm on the gulf coast it's somewhat likely that I could lose power and/or network for multiple days if a hurricane rolls through town. That could cause a change in the leases.
  • How to update to the latest Tailscale version?

    Tailscale
    179
    1 Votes
    179 Posts
    63k Views
    E
    Updated CE 2.7.2 to 1.86.4_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.4_1.pkg Freshports
  • Order / Timing of Booting Modem and pfsense PC

    General pfSense Questions
    16
    0 Votes
    16 Posts
    503 Views
    N
    And 192.168.100.1 is part of the DOCSIS specification. That's because all cable modems run with this IP address.
  • 0 Votes
    3 Posts
    170 Views
    G
    @SteveITS Thanks very much, i knew i must have missed something. Clean Firewall logs now.
  • 0 Votes
    2 Posts
    2k Views
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Package realtek-re-kmod198 for pfSense 2.8.0 (amd64)

    Hardware
    33
    1 Votes
    33 Posts
    7k Views
    zeroepochZ
    I just updated to pfSense 2.8.1 and my existing build/package of the Realtek 198.00 kernel module still works fine. I installed pfSense in VirtualBox first and checked that the kernel module loads there before updating my router.
  • 0 Votes
    6 Posts
    2k Views
    stephenw10S
    Now you can upgrade to 25.07.1.
  • GeoIP Blocking with pfBlockerNG

    Firewalling
    11
    0 Votes
    11 Posts
    2k Views
    S
    …and for a couple years, give or take, MaxMind has required the additional field/info to update so the geoIP data probably isn’t updating.
  • New PPPoE backend, some feedback

    Development
    242
    0 Votes
    242 Posts
    42k Views
    P
    @louis2 Yes several of us are having this issue. A fix seems to be to go to: Status - Gateways - then click the recycle button to restart the Gateway service, it should then switch to online. [image: 1757154148879-40cda19d-00df-4fb7-bfae-7a166768f3ee-image.png]