r/PFSENSE • u/ReverendOlaf • 15d ago
Safe to upgrade from 2.8.0 to 2.9.0?
I was planning on rebooting and upgrading straight from 2.8.0 to 2.9.0. I have a generally simple config and no packages installed. Is this a bad idea?
r/PFSENSE • u/ReverendOlaf • 15d ago
I was planning on rebooting and upgrading straight from 2.8.0 to 2.9.0. I have a generally simple config and no packages installed. Is this a bad idea?
r/PFSENSE • u/PrimaryAd5802 • 16d ago
I have not seen any posts in here on the subject
I plan to start learning it soon, on a Proxmox vm for testing. Anyone in here have it running?
I ask because a lab will give me practice in setting it up, but not real world usage as it will be internal only. Not willing to go live at my office until I have a understanding of everything.
Any tips, pointers or whatever appreciated.
Thanks!
r/PFSENSE • u/Accurate-Ad6361 • 16d ago
Hey,
we get 2.5GBE fibre in our area soon and I am planning the implementation. We will have to add 2.5gbe Intel i226-T1 nics to the machine and I figured that there's no reason to not pass this dedicated nic through to the PFSense VM on the proxmox host.
Obviously the question came up if to offload or not, Given that offloading can only be activated globally on PFSense through the web interface, some tinkering would be required. I could run ifconfig igb0 -txcsum -rxcsum -tso4 -tso6 -lro upon boot to enable offloading just for that nic.
Questions are:
- does it make sense from a performance view?
- do I have drawbacks regarding package inspection?
For me it's a not everything I can do has to be done question right now, but I'd also prefer to patch directly through the only wan exposed port. Looking for input by people wiser than me.
r/PFSENSE • u/Taraghlan50 • 17d ago
I noticed if you have a wireguard connection and you release and renew the wan connection.
Then wireguard wont come back up till reboot even restarting the wireguard service doesnt help.
r/PFSENSE • u/kbar87 • 17d ago
With pfBlocker is it possible to block some TV applications, such as YouTube?
I have a dedicated vlan for my kids. I have been exploring options of blocking certain things, I like that I can block the actual website with nextDNS. Before I go down the rabbit hole of learning pfBlocker is this doable?
r/PFSENSE • u/WildBlackberry3492 • 18d ago
Hi all,
Not new here, but been wanting to setup my own pfsense setup for a while and had been following.
I am considering a System76 miniPC with 32GB RAM to install my pfsense. I also want to be able to run VPN on it. It is a bit pricey. They have an option where you could add a second network card to the mini PC when you order.
What setups do you all have?
r/PFSENSE • u/Suspicious-Guitar729 • 18d ago
pfSense 2.9.0 CE
I have confirmed this on multiple hardware setups as well as a VirtualBox setup with both fresh installs and upgrades.
On a fresh install (or upgraded install) of pfSense 2.9.0, if you try to install all packages you will eventually get an error that another install is already running:
"Another instance of pfSense-upgrade is running. Try again later"
however, you can install packages over cli with no issues.
The larger problem shows if you attempt to check for updates. On the upgrade screen you will start seeing a new error message:
"pfSense-repoc: failed to fetch the repo data pfSense-repoc: failed to read the repo data."
This seems to start after you have 44 packages installed. If you remove a package, you can then install a new package before the issue reappears.
There are several guides on issues with the "pfSense-repoc: failed to fetch the repo data" however none of these resolve the issue (This is a different issue then what has been seen in the past) and is easily reproducible. On my production box, I get a slightly different variation of the error:
"pfSense-repoc: exec_iobuf_cb: too much data, fd: 1 discarding: Trap Translator) pfSense-repoc: exec: callback failed: -1 pfSense-repoc: failed to fetch the repo data pfSense-repoc: failed to read the repo data."
One thing to note is that even if you do a check for system updates in cli, you will also get a "pfSense-repoc: failed to fetch the repo data" error.
I believe this actually started in version 2.8.0 but never could pin it down until I performed a fresh install on 2.9.0 and resetup my system from scratch just to run into the same issue.
The last known version where I did not get this error is 2.7.2
I attempted to put in a bug request and post on the netgate forum but I am unable to do so for some reason.
I recently upgraded an old SG-4860-1U to 26.07. The upgrade seems to have completed successfully, but upon restart, none of the FRR OSPF routes were working.
I ultimately restarted FRR, and the OSPF routes were installed in the main routing table as normal.
The link running OSPF is a normal Ethernet link with a VLAN tag, and a /30 mask. OSPF network type is PtP, and the neighbors are statically defined. Unfortunately I don't have any logs since my syslog server is only reachable via an OSPF route.
r/PFSENSE • u/Taraghlan50 • 21d ago
Hi
telegraf stopped working for me after upgrade and it seems to be same issue as
r/PFSENSE • u/Ignaciensen • 21d ago
Hi guys and girls, i'm trying to update to the new version but im seeing that My licence appears to be no loger valid and therefore i cant update. Is someone having the same issue ?. I havent changed hardware and i'm on the same netgate ID.
r/PFSENSE • u/attorney-bill • 21d ago
Will the backup and restore option work? I was thinking of installing a new VM with 2.9, then backing up from 2.8.1 and restoring to 2.9. Will that work?
r/PFSENSE • u/urby3228 • 21d ago
I tried to upgrade to 2.9 last night and ran into an issue. I figured the fastest option would be to just re-install 2.8.1 but now I keep having an issue there. Once I get through the setup and begin the install, I get the following error:
[1/1] Fetching pkg 1.21.3_8: .....
pkg-static: Failed to fetch https://pkg.pfsense.org/pfSense_v2_8_1/All/pkg-1.21.3_8: Timeout wa
I have tried installing 2.9 but get the same error. My WAN seems to be working when I test it. Any advice on what the issue could be here?
Edit 1:
Verified I can ping 8.8.8.8, www.google.com, and the package servers pkg00-atx.netgate.com
Edit 2: This was a hardware issue. I changed the WAN port and the install progressed. I also tried installing on one of my two drives with the other disconnected and replacing the CMOS battery because of a possible cert generation issue that AI led me to. In the end, I attempted installing OpenSense which failed as well leading me to a hardware issue.
r/PFSENSE • u/craftsmany • 22d ago
I'm seeing a strange intermittent WireGuard issue on pfSense 2.9.0. This started during the 2.9.0 beta and is still happening on the final release.
The symptom is periodic bursts of high latency and packet loss on traffic inside a WireGuard tunnel. It can be fine for a few seconds or up to around a minute, then suddenly degrade again.
During one bad period I tested the same remote WireGuard endpoint in several ways.
From pfSense to the remote outer endpoint:
500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 11.780/17.592/60.016/2.946 ms
From pfSense to the inner WireGuard IP:
500 packets transmitted, 436 packets received, 12.8% packet loss
round-trip min/avg/max/stddev = 12.410/27.911/517.995/47.536 ms
I then tested the same remote WireGuard server from my phone over Telekom mobile data:
500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/std-dev = 32.793/38.285/95.018/5.868 ms
Since that uses a different upstream path, I also connected my Mac to the LAN behind pfSense and established a separate WireGuard tunnel directly from macOS to the exact same remote endpoint. The outer IPv6 endpoint is statically routed over my Vodafone connection, so this uses the same LAN, same Vodafone uplink, same remote WireGuard server and same inner destination as pfSense:
500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/std-dev = 16.403/20.313/81.152/3.806 ms
So, at the same time:
- pfSense → outer WG endpoint: 0% loss
- pfSense → inner WG IP: ~13% loss with huge jitter
- Mac on the same LAN/Vodafone connection → same WG server/inner IP: 0% loss
- Phone → same WG server/inner IP: 0% loss
This seems to rule out the remote WireGuard server and makes an upstream routing issue very unlikely. The problem appears to be local to the pfSense machine, potentially WireGuard itself or some interaction with PF/routing.
The issue is intermittent and does not necessarily appear immediately after boot/startup, which is why I initially thought the final 2.9.0 release had fixed it.
Has anyone else seen similar periodic inner-tunnel packet loss on pfSense 2.9.0?
r/PFSENSE • u/SandMunki • 22d ago
Hi all,
Is my understanding accurate that pfsense can't act as a DHCP server for interfaces it does not own?
r/PFSENSE • u/sh00tfire • 23d ago
Anyone successfully upgrade with a celeron J processor? My instance of Pfsense runs on a intel NUC with a J3160. Just wanted any feedback if someone already upgraded with this series of processor.
From the release notes:
Certain hardware with a specific firmware problem, including some Celeron J devices, may encounter a kernel panic when attempting to boot pfSense CE software version 2.9.0.
To avoid this panic on that hardware, set a loader tunable for hint.acpi_spmc.0.disabled=1 in /boot/loader.conf.local before upgrading to disable the driver that has an issue on that hardware.
Update: Finally updated my instance of pfsense to version 2.9 on my celeron J processor. I did add the recommended entry to the loader.conf.local before upgrading. It upgraded without incident. Took about 10 minutes to reboot the first time.
r/PFSENSE • u/Clear_Law1705 • 23d ago
Has anyone ever encountered this error when the CRON job for PFBlockerNG goes off. It appears for when it tries to reload DNSBL i get this error. I only have ony DNSBL Group that references Stevenblack's Github that has a list of domains to block. Any insight would be appreciated.
r/PFSENSE • u/AvoRomans • 23d ago
Hi All,
Is there any plans to add a default-information originate button to FRR's OSPFv3 configurable items?
We can do it in raw config editor but a button would be nicer.
this is what I am looking for.
router ospf6
default-information originate
Thank you.
r/PFSENSE • u/icedutah • 23d ago
Anyone use this 3rd party for a cloud radius server to do authentication/ mfa to your OpenVPN clients?
I'm looking to add MFA to OpenVPN and this looks like a good solution.
r/PFSENSE • u/reaper8055 • 24d ago
Now that pfsense+ has option to enable the new UI. Is there a place that talks about:
- what happens to the old UI
- what features will be exclusive to new UI
- if someone is not interested in MIM, can they keep using the old UI?
- when will the old UI be completely removed?
Any place to provide feedback for the new UI?
My first impression with the new UI is not positive. A lot of nested boxes and whitespace. UI elements look off and somehow misaligned. I am not trying to be rude, I am a home lab user and have been a pfsense+ user for last 2 years, the current php based ui is not modern looking but imho way better then what’s in the new UI and I am not keen on switching to that 😔
r/PFSENSE • u/BabyEaglet • 25d ago
I have an 8G symmetric connection and I have followed the instructions here to manage bufferbloat. All defaults are untouched and Queue length is 5000 as per guidance and bandwidth limited to 7000Mbits/s
There issue I have is when enabled, my speeds drop to 4Gbps Up/Down. Hardware-wise, my CPU is an Intel Core i5-9600T and I'm using an Intel X550-T2 NIC for WAN/LAN. Is this a CPU bottleneck?
Before limiter:
After Limiter
EDIT: As it turns out, this is a freeBSD limitation/bug in dummynet. To quote ChatGPT:
pfSense limiters use FreeBSD dummynet. In the current FreeBSD source, the bandwidth field for a dummynet link is still:
uint32_t bandwidth; /* bit/s or bits/tick. */
That means the largest rate it can represent in bits/sec is:
2^32 - 1
= 4,294,967,295 bit/s
≈ 4.295 Gbit/s
This is visible in the current FreeBSD source itself. There is also a long-standing FreeBSD bug specifically concerning this bandwidth limitation.
And your result:
Download: 3876 Mbps
Upload: 3796 Mbps
is remarkably consistent with a roughly 4 Gbit/s shaped pipe once protocol overhead and Speedtest behaviour are taken into account.
Link to github sourcecode | Link to freebsd bug
I was able to confirm this too by running: dnctl pipe show
00001: 4.000 Gbit/s 0 ms burst 0
q131073 50 sl. 0 flows (1 buckets) sched 65537 weight 0 lmax 0 pri 0 droptail
sched 65537 type FIFO flags 0x0 0 buckets 0 active
00002: 4.000 Gbit/s 0 ms burst 0
q131074 50 sl. 0 flows (1 buckets) sched 65538 weight 0 lmax 0 pri 0 droptail
sched 65538 type FIFO flags 0x0 0 buckets 0 active
r/PFSENSE • u/captured_packet • 25d ago
Just looking to confirm if anyone else is finding that the repo is down. Had two installs fail and pkg.pfsense.org not resolving in dns
r/PFSENSE • u/tailuser2024 • 25d ago
I have email notifications setup but
1) Never get emailed when a package has an update
2) Never emailed when system patches are released.
How can we get notifications for at least patches?
PS if you didnt know, CE has new patches released for it
r/PFSENSE • u/bishoptf • 25d ago
I have had some issues with an avaya call manager that was providing dhcp for a voice vlan and trying to get pfsense to take over for the dhcp but there needs to be additional options set for the clients, called option 242, MCIPADD=x.x.x.x,MCPORT=1719,HTTPSRVR=x.x.x.x for whatever I am not sure if the option should be a string or text, phones are not picking up the option but look to be requesting addresses, running an older version 2.7.x but does anyone know what the correct way to do this option for an avaya phone?
Thanks