Latest topic 7 d ago

forum.netgate.com

forum.netgate.com

NodeBB forum in English. 11 sections tracked: Netgate Nexus, Español, Messages from the pfSense Team, NAT, General pfSense Questions, Firewalling, Problems Installing or Upgrading pfSense Software, TNSR, TNSR Announcements, TNSR Feedback and Problems Installing or Upgrading TNSR Software.

Discussions per day
7
Discussions collected
292
Messages per day
28
Sections
11
Sources tracked
12
Engine
NodeBB

Latest discussions

Collected every 4 hours from the forum's public feed. Only the title, the link and the beginning of the message are reproduced; every link points back to the source.

Does pfSense frequently change core features with its releases?

@Wallofbutter Added to what has been said above, the authors of ISC DHCP told us : "ISC DHCOP has now and EOL", but they didn't left us out there in the dark. They decided to write it all over again from the ground up, as they have acquired some experience with creating a DHCP server ^^ So, it's more a special case of a "new version".

IPv6 Invalid range?

@AndyRH [image: 1788771071684-18864a1f-be5b-4fb2-9b4d-aee06ef52aeb-image.png] That's the IPv6 DHCP pool setup that is cleary 'static' minded, not dynamic. Prefixs can change at any time, hard coding a full prefix start end en pool IPv6 is plain wrong. The GUI is aware that you use tracking, so it should allow ::1000 -> ::2000 where the prefix part is implicit. The pfSense 'PGP' GUI does accept : [image: 1788771233001-073a5698-6061-4495-ba03-8330a956a754-image.png] but it's still not ok. Try setting up a "DHCPv6 Static Mappings" like [image: 1788771356273-56cb0d11-d6ca-4a67-aa93-a2e7f0ce92e2-image.png] and now you wind up with [26.07-RELEASE][root@pfSense.bhf.tld]/root: host epackferpar22 epackferpar22.brit-hotel-fumel.net has address 192.168.1.26 epackferpar22.brit-hotel-fumel.net has IPv6 address 2a01:dead:beef:7ce2::cc epackferpar22.brit-hotel-fumel.net has IPv6 address ::cc Check the /etc/hosts file and you'll understand what's happening. So, with DHCPv6 Static Mappings" you have to use the dynamic prefix (the left part of the ::) as a 'static' and keep on checking, as if the prefix changes (and it will tomorrow, next week, or over two years), things will break.

Interface restart loop

Ah, only after a reboot though? If you're able to trigger that again try checking if unbounctl is stuck trying to restart unbound: ps -aux | grep unbound The logs look like it is starting Unbound but it fails because something is already using the port, probably the previous instance of Unbound. I've once hit this and manually killing stuck unbound instances allowed it to return to normal. However it's not clear if that was a symptom or cause.

pfblocker shows after one day only, thousand of connections to netgate, wondering whats goin on?

@TommyMoo yeah I am not seeing 1800 - but really close to it at the 24 hour mark or so. Be it 500 or 1500, etc. Still seems like a very large number of queries for why? I drastically reduce the number of outbound queries performed by increasing the ttl from 60 seconds to 1 hour.. I just don't understand why so many queries would need to be made in the first place.. 1800 in 24 hours is over 60 an hour.. How does that make sense? Especially when out of the box unbound resolves, and the ttl is 60 seconds.. Why would you drive that much traffic to your own NSers? Is it trying to validate if unbound is running? if so for why it sure doesn't warn you if it is - and if it isn't how would it resolve where to send the email, etc.,

No sé si es PFsense o es el servidor externo a la red local

Buen día a todos tengo la siguiente arquitectura 1.- Servidor Microsoft Windows Server 2022 donde tengo los servicios: AD DHCP DNS IIS <- este ya lo voy a retirar 2.- Servidor Microsoft Windows Server 2022 donde tengo el servicio: Archivo y almacenamie list itemnto 3.- Servidor Microsoft Windows Server 2022 donde tengo el servicio: IIS 4.- Servidor con PFSense 2.9.0 1 Lan y 2 WAN en failover Solo firewall Deshabilitado el servicio de DHCP Deshabilitado el IPv6 en las 3 interfaces Los DNS configurados por mi son el windows server (IP privada), 8.8.8.8 y nunca he sabido por qué automáticamente se colocan las puertas de enlace de los modem como DNS Bien entrando de lleno a mi problema es que los usuarios navegan sin ningún problema, ven videos, redes sociales, etc. pero no logran entrar a una página del Sistema de Administración Tributaria (SAT/Gobierno), les pondré la ruta que usan los usuarios: https://www.sat.gob.mx/portal/public/home sin problema entran Clic en tramites y servicios https://www.sat.gob.mx/portal/public/tramites-y-servicios Sin problema entran Clic en factura electrónica https://www.sat.gob.mx/portal/public/tramites/factura-electronica Sin problema entran Clic en servicios de factura se abre en esa misma pagina un menú Clic en Consulta, cancela y recupera tus facturas Clic en Servicio consulta y recupera Se abre intentando abrir la página https://portalcfdi.facturaelectronica.sat.gob.mx y ahí inicia el problema Automáticamente te redirige a la URL https://cfdi

Netgate Nexus coreDNS fails to start on Boot / Reboot

Netgate device: SG2100 Version: 26.07 With the release of 26.07 and coreDNS I was eager to try ZTE. Before I use it on my SG 6100 I wanted to test with my SG2100. I have been working now for several days and I have failed to get ZTE working. Im trouble shooting first thing I noticed is that coreDNS service fails to start on system reboot and has to be started manually. Steps taken so far to resolve this. Factory rest the SG2100 - I noticed that this doesn't appear to reset the Nexus config and as such doesn't reset the coreDNS config. In an attempt to reset the Nexus config I disabled it and reinstalled it, this too fails to reset the config or at least the old logs are still there. I looked through this forum as well as Netgate's documentation site and was unable to find a documented procedure on how to rest Nexus. Reinstall pfSense+ - Next I went through the process of getting the installer, wiping the ssd and reinstalling pfSense 26.07, fearing that there may have been artifacts from the last ver of pfSense +. To that end with just going through the pfSense + Setup Wizard, Enabling Nexus, changing the port on Unbound, and enabling coreDNS with its wizard it still fails to start after reboot. I'm happy to supply logs to help troubleshoot I just need to know which ones and at what level. Mike

Starlink V5 with pfsense

@rpsmith LOL.. yeah still boo! I have enough resources around that I could so some fancy Wireguard stuff but would rather have the clean connection with no extra NAT of any kind. Even with the public IP address you are still basically behind their CGNAT with port forwarding. But I will deal with that to finally move away from the place I reside now to somewhere that I truly need Starlink. ;)

292 discussions collected since 28 August 2026. Track this forum by keyword →