I reinstalled nexus and it now works. Ted Quade
Fórum Netgate
forum.netgate.com ↗Fórum NodeBB em inglês. 11 seções acompanhadas: Netgate Nexus, Español, Messages from the pfSense Team, NAT, General pfSense Questions, Firewalling, Problems Installing or Upgrading pfSense Software, TNSR, TNSR Announcements, TNSR Feedback e Problems Installing or Upgrading TNSR Software.
- Discussões por dia
- 5
- Discussões coletadas
- 342
- Mensagens por dia
- 17
- Seções
- 11
- Fontes acompanhadas
- 12
- Motor
- NodeBB
Últimas discussões
Coletadas a cada 4 horas do feed público do fórum. Reproduzimos apenas o título, o link e o começo da mensagem; cada link leva à fonte.
@Gertjan Thank you. I never realized the "states" column does show the rejected info. The logs does show this worked.
“IPv6: Host Interface RA (Router Advertisement) Suppression Missing?” raises an important networking issue, since proper router advertisement settings can help maintain reliable and well-managed connections. In the gaming space, 3 Patti Land offers an engaging Teen Patti card-gaming experience for players who enjoy casual online games. My website is gaming-related, and https://3patti-land.pk/ provides more information about 3 Patti Land for readers interested in online card gaming.
Hi all, When I remove Snort 2 and and install Snort 3 using the new Nexus controller and setup Snort on the pre-compiled Balanced rule set applied to the WAN - the Netgate 4200 stops routing and I lose access to the device. I can not even ping it when directly connecting to the device via ethernet. The only way to get access again is by serial console and running pfctl -d and disabling the firewall - with the WAN physically disconnected of course. I can't find any info on the Netgate docs site with regards to Snort 3 in Nexus. Does anyone have any idea what might be happening and is there any documentation on Snort 3 you can point me to. Thanks.
said in CoreDNS Groups Prefix: forcefully redirect all DNS queries I mean I would but the problem described here is still not tackled: https://forum.netgate.com/topic/201131/26.07-release-port-forward-is-missing-pass/11?_=1789294343778
@njaimo Yeah tailscale/wireguard would also work fine. I just find it odd that a proxy service like that would allow an attacker to even try to open a connection to your box. I expect a user to login to the remote front end before it allows anything over the link back to your home box. Thus any sort of attack would be against the proxy not your device. But I guess this is not that.
@keyser said in Netgate Releases Netgate Nexus Version 26.07_1: Threatgate cannot be used because it max’es listsizes out at 4999 entries This is one of the main things holding me back right now, along with ThreatDB not being available yet. Also, the last time I tested GeoIP, it created the aliases and I added them to the rules, but they wouldn't match and ended up blocking all traffic instead. Glad they fixed this, though: CoreDNS now starts automatically after reboot The second thing is missing DNS reply logging - in fact logging as a whole from Nexus services I don't care as much about DNS replies... I just need logs showing what's actually being blocked by the ThreatGate DNS integration.
@image101llc None of those really affected anything other than the OpenVPN bug, and that is mitigated by using a tls key. iirc that's the default setting.
@pfGeorge Thanks for the heads-up, much appreciated!
@patient0 Oh shoot ... you are right, missed it the first time around. https://forum.netgate.com/topic/201200/2.9.0-apu2-huawei-me909s-120-4g-modem-not-detected
@abarna said in optional interface Ip is showing pfsense GUI: eb gui in other VM using pfsense IP only.Not using optional interface ip.then what should i do? Allow what you want, where you want - the whole point of a firewall ;) Like in my example - where I allow ping, dns and ntp to the firewall address before I block other access. Put your rule above where you block - based on what criteria you want - be it source IP, destination IP, port/protocol - whatever combo works for allowing what you want, etc.. Before you block. Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated after.
@phil_socket95 Thanks for the advice. IPv6 doesn't change the behavior, but I get your point; I'll simply take IPv6 out of the equation for now, as testing it is a hassle—it causes outages at times when CPU usage is high. Good point regarding RSS; I'll keep a closer eye on that. Another thing: after running further tests, I noticed the problem occurs under two different circumstances when ZTE is enabled: Restarting the pfnet-controller service and letting ThreatGate refresh the feeds for the first time (this takes at least 3 hours, as that is the minimum allowed interval); CPU usage spikes immediately after the refresh. Restarting the pfnet-controller service and changing the ThreatGate refresh interval to more than 24 hours to prevent a refresh; in this case, CPU usage increases gradually over time. I'll need to write up a new summary of all this when I have the time.
342 discussões coletadas desde 28 August 2026. Acompanhe este fórum com uma palavra-chave →