@JonathanLee "Given that I have a true static IP setup (completely bypassing Carrier-Grade NAT on my side), is there any security benefit to manually injecting" any private LAN type address? No. Other than if you don't want to see the attempts. The WAN is already default block all unless you build a rule to allow something. I personally would like any such attempts on my WAN side to show up in the "firewall logs". I rarely to never see any unless someone has erroneously (or for ill intent) did/does something dumb.. (like the local fire department did one time a few years ago.. )
Netgate forum
forum.netgate.com ↗NodeBB-forum in het Engels. 11 rubrieken gevolgd: Netgate Nexus, Español, Messages from the pfSense Team, NAT, General pfSense Questions, Firewalling, Problems Installing or Upgrading pfSense Software, TNSR, TNSR Announcements, TNSR Feedback en Problems Installing or Upgrading TNSR Software.
- Discussies per dag
- 4
- Opgehaalde discussies
- 365
- Berichten per dag
- 14
- Rubrieken
- 11
- Gevolgde bronnen
- 12
- Software
- NodeBB
Laatste discussies
Elke 4 uur opgehaald uit de openbare feed van het forum. Alleen de titel, de link en het begin van het bericht worden weergegeven; elke link wijst terug naar de bron.
Do you have syslogs (/var/log/system.log) from around the time of that outage? That would be good place to start looking.
I am not beta testing software for netgate, isn't their plan to have everyone on Nexus by the end of the year?
Probably unrelated but Nexus is reporting 81% Memory usage while pfSense oldUI is stating 43%. Might be only a visual thing because of being a VM? [image: 1789900620659-screenshot-2026-09-20-at-12-36-45-pfsensehome.internal-netgate-nexus.png]
And there are other places which show similar behavior: [image: 1789896236323-screenshot-2026-09-20-112221.png]
I can't enable an ACL Entry according to the toggle but it is working in any case. Spoiler The old UI hadn't toggles for individual ACLs. Status of Active UPnP IGD & PCP/NAT-PMP Port Maps is only showing UPnP IGD Port Maps , the old UI can show NAT-PMP Port Maps too. Spoiler Both UIs are missing the "Int IP" though.
I made a similar observation earlier and another forum member essentially told me to shut up—that no one was forcing me to use these features. How nice. Thank you for making the same point again.
Hmm, that should never happen. Subinterface types like VLANs are excluded from the check for this reason. Have you ever manually edited the interfaces in the config? Do you have the tailscale interface assigned? It should not be.
This seem to fix this and allow the update to happen from jim-p via /r/PFSENSE sent 16 minutes ago show parent We have seen some very rare cases (single digits) where a certain CA file not having the expected content can lead to that output. It will get re-fetched and fixed if you remove it first: rm /usr/local/share/pfSense/ssl/netgate-zuul-ca.pem Then re-run the commands above: pfSense-upgrade -dc; pkg update; pkg upgrade hope that I did not screw something up
@darkhobby5 It’s certainly acting very strangely - ended up having to get another ata as thought the first was bad as every time it was connected to the vlan with internet on it the thing changed its password but not to to one given by the VoIP supplier to use after provision. Which means you can’t look and see what’s going on on the ata cos you can’t get in and reset just clears it. Insurrections from the VoIP supplier is just to open a bunch of ip addresses and port 5080 and udp The second one I got set it’self to the VoIP provider s password but nothing had been added to any of the fields on it just changed the password (both of them had the MAC address and serial number sent to the provider for provision ) firewall logs show no issues but am guessing it won’t show a NAT issue - I built this system long time ago an have forgotten most of them suff!
@Bob.Dig I agree about the less-than-beta. On the other hand, I hope they keep a todo-list and it maybe finds its way onto that list.
365 discussies opgehaald sinds 28 August 2026. Volg dit forum op zoekwoord →