Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense 25.11 broke my lan.

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    178 Posts 14 Posters 6.4k Views 15 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      wisepds
      last edited by

      Hi.
      I have updated and pfsense can ping google, and WAN's are in green, all in the router is ok, but all lan devices go offline. Nas, dead, Proxmox dead, computers, offline, VPN to pfsense Works!
      PV6 is off in my pfsense.
      Reverted to previous version.
      What's happening?

      W w0wW 2 Replies Last reply Reply Quote 0
      • W Offline
        wisepds @wisepds
        last edited by wisepds

        I don't know if is PFBLOCKER but i have 2 wans... TELEFONICA AND ADAMO... PPPOE and DHCP both with IPV6 "none". In routing, FAILOVER as primary WAN and again IPV6 to none.

        Pfsense can ping to google.es

        Any clue?
        Thanks!

        a3d7af82-bcf8-4645-bdaf-045dcef0f178-image.png

        b482a608-71e0-425a-a6ec-e19e85a32f75-image.png

        dfcfe620-1eb3-4d54-97a5-28bec547407e-image.png

        6e98397e-8300-4516-b649-2732cd4f5f46-image.png

        NO UPDATES in package manager:

        083cfded-46ee-41ec-81d0-9d2fcc813d72-image.png

        S 1 Reply Last reply Reply Quote 0
        • S Offline
          SteveITS Rebel Alliance @wisepds
          last edited by

          @wisepds packages get upgraded/reinstalled at upgrade so that’s expected.

          What isn’t working exactly? DNS? Ping to pfSense? DHCP?

          Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
          Upvote 👍 helpful posts!

          W 1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            What firewall rules do you have on internal interfaces?

            Do you have any match rules? Do you have quick set?

            W 1 Reply Last reply Reply Quote 0
            • w0wW Offline
              w0w @wisepds
              last edited by

              @wisepds
              And what hardware is pfSense running on?

              W 1 Reply Last reply Reply Quote 0
              • W Offline
                wisepds @w0w
                last edited by

                @w0w It's a Proxmox MV under a Ryzen threadripper.3995WX. No problem in 5 years.

                w0wW 1 Reply Last reply Reply Quote 0
                • W Offline
                  wisepds @stephenw10
                  last edited by

                  @stephenw10 My lan and wan rules are the same for 5 years.
                  With 25.07 works perfect. I can't imagine que a Freebsd base update can broke rules.

                  stephenw10S 1 Reply Last reply Reply Quote 0
                  • W Offline
                    wisepds @SteveITS
                    last edited by

                    @SteveITS Update process complete without problems, after reboot, all devices under the pfsense can't access to internet.

                    This night i will update again. My problem is that i only can update at night... 😅
                    Do you want specific test or any information before/after update?

                    I have another pfsense+ inside lan only for openvpn. I will update too..

                    1 Reply Last reply Reply Quote 0
                    • w0wW Offline
                      w0w @wisepds
                      last edited by w0w

                      @wisepds said in Pfsense 25.11 broke my lan.:

                      @w0w It's a Proxmox

                      So it using pppoe over vtnet interface?

                      https://forum.netgate.com/topic/199313/pfsense-vm-on-proxmox-pppoe-only-works-when-parent-nic-is-pci-passthrough-virtual-nic-breaks-lan-wan-traffic?_=1765957424791

                      W 2 Replies Last reply Reply Quote 0
                      • W Offline
                        wisepds @w0w
                        last edited by

                        @w0w Yes, here in spain ppoe Movistar is Vlan 6. but it works because pfsense have internet and i can connect to openvpn.

                        1 Reply Last reply Reply Quote 0
                        • W Offline
                          wisepds @w0w
                          last edited by

                          @w0w
                          OH! I hope this is a bug.. no, my WAN PPOE es virtIO because PFSENSE ID are attached to MAC cards.. so if i migrate my PFSENSE MV from one node to another my PFSENSE licence will lost being passthrough!!!

                          This is impossible to assume!

                          S w0wW 2 Replies Last reply Reply Quote 0
                          • stephenw10S Offline
                            stephenw10 Netgate Administrator @wisepds
                            last edited by

                            @wisepds said in Pfsense 25.11 broke my lan.:

                            With 25.07 works perfect. I can't imagine que a Freebsd base update can broke rules.

                            It could if you have match rules with quick set and have been relying on the broken behaviour. Typically those are added as floating rules for traffic shaping. Do you have that?

                            W 1 Reply Last reply Reply Quote 0
                            • W Offline
                              wisepds @stephenw10
                              last edited by

                              @stephenw10 My floating rules:

                              09f07e49-4adc-4202-ba34-cc5b7b9e2af2-image.png

                              1 Reply Last reply Reply Quote 0
                              • S Offline
                                SteveITS Rebel Alliance @wisepds
                                last edited by

                                @wisepds said in Pfsense 25.11 broke my lan.:

                                @w0w
                                OH! I hope this is a bug.. no, my WAN PPOE es virtIO because PFSENSE ID are attached to MAC cards.. so if i migrate my PFSENSE MV from one node to another my PFSENSE licence will lost being passthrough!!!

                                This is impossible to assume!

                                If you were not using passthrough then In the Proxmox VM assign each NICs its current MAC address.

                                It’s been posted elsewhere Netgate is working on a fingerprint/different method instead of NDI/MAC for the Plus license so maybe in the future…

                                Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                                When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                                Upvote 👍 helpful posts!

                                W 1 Reply Last reply Reply Quote 0
                                • w0wW Offline
                                  w0w @wisepds
                                  last edited by

                                  @wisepds

                                  I don’t get it…

                                  So you’re using VirtIO, which means you have the same bug as me (and as the other person in the thread I linked above), right?

                                  Why do you need to migrate from one node to another? Did you read the thread?

                                  You can try adding the following to loader.conf.local:

                                  hw.vtnet.tso_disable=1
                                  hw.vtnet.csum_disable=1
                                  

                                  …and see if it helps.

                                  W 2 Replies Last reply Reply Quote 1
                                  • W Offline
                                    wisepds @SteveITS
                                    last edited by

                                    @SteveITS But for now it's the method. For us passthrough is not an option.

                                    I think this release is problematic. A lot of people with problems.

                                    Any possible solution for my setup or i must wait for a fix?

                                    1 Reply Last reply Reply Quote 0
                                    • W Offline
                                      wisepds @w0w
                                      last edited by

                                      @w0w We have a cluster... if one node dies, we have HA to migrate all MV's to another node.

                                      It's impossible for us use physical mac nics (Passthroug) while netgate use this data for fingerprint/Licence.

                                      I think you'r right... we have the same problem...
                                      This is unacceptable in a software with paid suscription.

                                      w0wW 1 Reply Last reply Reply Quote 0
                                      • w0wW Offline
                                        w0w @wisepds
                                        last edited by w0w

                                        @wisepds said in Pfsense 25.11 broke my lan.:

                                        It's impossible for us use physical mac nics (Passthroug) while netgate use this data for fingerprint/Licence.

                                        If you are lucky one, you don't need to do passthrough. Read my previous message. If you don't want to mess with it, stay on the 25.07

                                        W 1 Reply Last reply Reply Quote 0
                                        • W Offline
                                          wisepds @w0w
                                          last edited by

                                          @w0w do you think a fix is coming?

                                          w0wW 2 Replies Last reply Reply Quote 0
                                          • w0wW Offline
                                            w0w @wisepds
                                            last edited by

                                            @wisepds said in Pfsense 25.11 broke my lan.:

                                            This is unacceptable in a software with paid suscription.

                                            You can create a ticket. https://www.netgate.com/tac-support-request

                                            W 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.