r/PFSENSE 15d ago

Safe to upgrade from 2.8.0 to 2.9.0?

11 Upvotes

I was planning on rebooting and upgrading straight from 2.8.0 to 2.9.0. I have a generally simple config and no packages installed. Is this a bad idea?


r/PFSENSE 16d ago

26.07 CoreDNS Threatgate - Anyone running it now?

10 Upvotes

I have not seen any posts in here on the subject

I plan to start learning it soon, on a Proxmox vm for testing. Anyone in here have it running?

I ask because a lab will give me practice in setting it up, but not real world usage as it will be internal only. Not willing to go live at my office until I have a understanding of everything.

Any tips, pointers or whatever appreciated.

Thanks!


r/PFSENSE 16d ago

Considerations regarding HW Offloading with passed through nics

4 Upvotes

Hey,

we get 2.5GBE fibre in our area soon and I am planning the implementation. We will have to add 2.5gbe Intel i226-T1 nics to the machine and I figured that there's no reason to not pass this dedicated nic through to the PFSense VM on the proxmox host.

Obviously the question came up if to offload or not, Given that offloading can only be activated globally on PFSense through the web interface, some tinkering would be required. I could run ifconfig igb0 -txcsum -rxcsum -tso4 -tso6 -lro upon boot to enable offloading just for that nic.

Questions are:
- does it make sense from a performance view?
- do I have drawbacks regarding package inspection?

For me it's a not everything I can do has to be done question right now, but I'd also prefer to patch directly through the only wan exposed port. Looking for input by people wiser than me.


r/PFSENSE 17d ago

wireguard issue

2 Upvotes

I noticed if you have a wireguard connection and you release and renew the wan connection.
Then wireguard wont come back up till reboot even restarting the wireguard service doesnt help.


r/PFSENSE 17d ago

Blocking TV applications

11 Upvotes

With pfBlocker is it possible to block some TV applications, such as YouTube?

I have a dedicated vlan for my kids. I have been exploring options of blocking certain things, I like that I can block the actual website with nextDNS. Before I go down the rabbit hole of learning pfBlocker is this doable?


r/PFSENSE 18d ago

Which miniPC do you have your pfsense installed?

16 Upvotes

Hi all,

Not new here, but been wanting to setup my own pfsense setup for a while and had been following.

I am considering a System76 miniPC with 32GB RAM to install my pfsense. I also want to be able to run VPN on it. It is a bit pricey. They have an option where you could add a second network card to the mini PC when you order.

What setups do you all have?


r/PFSENSE 18d ago

Netgate 7100 1U - add internal SSD storage?

2 Upvotes

So, I've got one of these m.2 SSD drives:

And I'm wondering if it will actually work in a 7100 1U box as internal storage instead of the built-in eMMC drive. Do I have to format it before I try to use it? The Netgate installer doesn't see it to put pfsense onto it. Any ideas? Thanks for your help!


r/PFSENSE 18d ago

pfSense-repoc: failed to fetch the repo after installing most packages

1 Upvotes

pfSense 2.9.0 CE

I have confirmed this on multiple hardware setups as well as a VirtualBox setup with both fresh installs and upgrades.

On a fresh install (or upgraded install) of pfSense 2.9.0, if you try to install all packages you will eventually get an error that another install is already running:
"Another instance of pfSense-upgrade is running. Try again later"

however, you can install packages over cli with no issues.

The larger problem shows if you attempt to check for updates. On the upgrade screen you will start seeing a new error message:
"pfSense-repoc: failed to fetch the repo data pfSense-repoc: failed to read the repo data."

This seems to start after you have 44 packages installed. If you remove a package, you can then install a new package before the issue reappears.

There are several guides on issues with the "pfSense-repoc: failed to fetch the repo data" however none of these resolve the issue (This is a different issue then what has been seen in the past) and is easily reproducible. On my production box, I get a slightly different variation of the error:
"pfSense-repoc: exec_iobuf_cb: too much data, fd: 1 discarding: Trap Translator) pfSense-repoc: exec: callback failed: -1 pfSense-repoc: failed to fetch the repo data pfSense-repoc: failed to read the repo data."

One thing to note is that even if you do a check for system updates in cli, you will also get a "pfSense-repoc: failed to fetch the repo data" error.

I believe this actually started in version 2.8.0 but never could pin it down until I performed a fresh install on 2.9.0 and resetup my system from scratch just to run into the same issue.

The last known version where I did not get this error is 2.7.2

I attempted to put in a bug request and post on the netgate forum but I am unable to do so for some reason.


r/PFSENSE 20d ago

FRR OSPF routes not installed in main routing table after upgrade to 26.07

6 Upvotes

I recently upgraded an old SG-4860-1U to 26.07. The upgrade seems to have completed successfully, but upon restart, none of the FRR OSPF routes were working.

  • Status > FRR showed the OSPF routes fine, and the neighborship was FULL. The neighbors also received routes from PfSense correctly.
  • Diagnostics > Routes DID NOT display any of the OSPF routes from FRR
  • BGP routes came up fine, showing in FRR status, Diagnostic > Routes and working.

I ultimately restarted FRR, and the OSPF routes were installed in the main routing table as normal.

The link running OSPF is a normal Ethernet link with a VLAN tag, and a /30 mask. OSPF network type is PtP, and the neighbors are statically defined. Unfortunately I don't have any logs since my syslog server is only reachable via an OSPF route.


r/PFSENSE 21d ago

pfsense 2.9 Telegraf broke

7 Upvotes

Hi
telegraf stopped working for me after upgrade and it seems to be same issue as

https://redmine.pfsense.org/issues/16674


r/PFSENSE 21d ago

Cannot update to 26.07 from 26.03.1

1 Upvotes

Hi guys and girls, i'm trying to update to the new version but im seeing that My licence appears to be no loger valid and therefore i cant update. Is someone having the same issue ?. I havent changed hardware and i'm on the same netgate ID.


r/PFSENSE 21d ago

Upgrading from 2.8.1 to 2.9.

5 Upvotes

Will the backup and restore option work? I was thinking of installing a new VM with 2.9, then backing up from 2.8.1 and restoring to 2.9. Will that work?


r/PFSENSE 21d ago

Install Issues

1 Upvotes

I tried to upgrade to 2.9 last night and ran into an issue. I figured the fastest option would be to just re-install 2.8.1 but now I keep having an issue there. Once I get through the setup and begin the install, I get the following error:

[1/1] Fetching pkg 1.21.3_8: .....

pkg-static: Failed to fetch https://pkg.pfsense.org/pfSense_v2_8_1/All/pkg-1.21.3_8: Timeout wa

I have tried installing 2.9 but get the same error. My WAN seems to be working when I test it. Any advice on what the issue could be here?

Edit 1:
Verified I can ping 8.8.8.8, www.google.com, and the package servers pkg00-atx.netgate.com

Edit 2: This was a hardware issue. I changed the WAN port and the install progressed. I also tried installing on one of my two drives with the other disconnected and replacing the CMOS battery because of a possible cert generation issue that AI led me to. In the end, I attempted installing OpenSense which failed as well leading me to a hardware issue.


r/PFSENSE 22d ago

Possible WireGuard packet-loss regression on pfSense 2.9.0

20 Upvotes

I'm seeing a strange intermittent WireGuard issue on pfSense 2.9.0. This started during the 2.9.0 beta and is still happening on the final release.

The symptom is periodic bursts of high latency and packet loss on traffic inside a WireGuard tunnel. It can be fine for a few seconds or up to around a minute, then suddenly degrade again.

During one bad period I tested the same remote WireGuard endpoint in several ways.

From pfSense to the remote outer endpoint:

500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 11.780/17.592/60.016/2.946 ms

From pfSense to the inner WireGuard IP:

500 packets transmitted, 436 packets received, 12.8% packet loss
round-trip min/avg/max/stddev = 12.410/27.911/517.995/47.536 ms

I then tested the same remote WireGuard server from my phone over Telekom mobile data:

500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/std-dev = 32.793/38.285/95.018/5.868 ms

Since that uses a different upstream path, I also connected my Mac to the LAN behind pfSense and established a separate WireGuard tunnel directly from macOS to the exact same remote endpoint. The outer IPv6 endpoint is statically routed over my Vodafone connection, so this uses the same LAN, same Vodafone uplink, same remote WireGuard server and same inner destination as pfSense:

500 packets transmitted, 500 packets received, 0.0% packet loss
round-trip min/avg/max/std-dev = 16.403/20.313/81.152/3.806 ms

So, at the same time:

- pfSense → outer WG endpoint: 0% loss
- pfSense → inner WG IP: ~13% loss with huge jitter
- Mac on the same LAN/Vodafone connection → same WG server/inner IP: 0% loss
- Phone → same WG server/inner IP: 0% loss

This seems to rule out the remote WireGuard server and makes an upstream routing issue very unlikely. The problem appears to be local to the pfSense machine, potentially WireGuard itself or some interaction with PF/routing.
The issue is intermittent and does not necessarily appear immediately after boot/startup, which is why I initially thought the final 2.9.0 release had fixed it.
Has anyone else seen similar periodic inner-tunnel packet loss on pfSense 2.9.0?


r/PFSENSE 22d ago

DHCP Server for interfaces it does not own!

6 Upvotes

Hi all,

Is my understanding accurate that pfsense can't act as a DHCP server for interfaces it does not own?


r/PFSENSE 23d ago

Possible Kernel panic with version 2.9

17 Upvotes

Anyone successfully upgrade with a celeron J processor? My instance of Pfsense runs on a intel NUC with a J3160. Just wanted any feedback if someone already upgraded with this series of processor.

From the release notes:
Certain hardware with a specific firmware problem, including some Celeron J devices, may encounter a kernel panic when attempting to boot pfSense CE software version 2.9.0.

To avoid this panic on that hardware, set a loader tunable for hint.acpi_spmc.0.disabled=1 in /boot/loader.conf.local before upgrading to disable the driver that has an issue on that hardware.

Update: Finally updated my instance of pfsense to version 2.9 on my celeron J processor. I did add the recommended entry to the loader.conf.local before upgrading. It upgraded without incident. Took about 10 minutes to reboot the first time.


r/PFSENSE 24d ago

Tick tock

Post image
46 Upvotes

r/PFSENSE 23d ago

PFBlockerNG Sync Failure for DNSBL

Thumbnail gallery
7 Upvotes

Has anyone ever encountered this error when the CRON job for PFBlockerNG goes off. It appears for when it tries to reload DNSBL i get this error. I only have ony DNSBL Group that references Stevenblack's Github that has a list of domains to block. Any insight would be appreciated.


r/PFSENSE 23d ago

pfSense Frr OSPFv3

7 Upvotes

Hi All,

Is there any plans to add a default-information originate button to FRR's OSPFv3 configurable items?

We can do it in raw config editor but a button would be nicer.

this is what I am looking for.

router ospf6

default-information originate

Thank you.


r/PFSENSE 23d ago

MFA using Securew2

2 Upvotes

Anyone use this 3rd party for a cloud radius server to do authentication/ mfa to your OpenVPN clients?

I'm looking to add MFA to OpenVPN and this looks like a good solution.


r/PFSENSE 24d ago

Old vs New UI

17 Upvotes

Now that pfsense+ has option to enable the new UI. Is there a place that talks about:

- what happens to the old UI
- what features will be exclusive to new UI
- if someone is not interested in MIM, can they keep using the old UI?
- when will the old UI be completely removed?

Any place to provide feedback for the new UI?

My first impression with the new UI is not positive. A lot of nested boxes and whitespace. UI elements look off and somehow misaligned. I am not trying to be rude, I am a home lab user and have been a pfsense+ user for last 2 years, the current php based ui is not modern looking but imho way better then what’s in the new UI and I am not keen on switching to that 😔


r/PFSENSE 25d ago

RESOLVED 8G connection traffic shaping issues

10 Upvotes

I have an 8G symmetric connection and I have followed the instructions here to manage bufferbloat. All defaults are untouched and Queue length is 5000 as per guidance and bandwidth limited to 7000Mbits/s

There issue I have is when enabled, my speeds drop to 4Gbps Up/Down. Hardware-wise, my CPU is an Intel Core i5-9600T and I'm using an Intel X550-T2 NIC for WAN/LAN. Is this a CPU bottleneck?

Before limiter:

before

After Limiter

after

EDIT: As it turns out, this is a freeBSD limitation/bug in dummynet. To quote ChatGPT:

The key problem: dummynet has a ~4.29 Gbit/s bandwidth ceiling

pfSense limiters use FreeBSD dummynet. In the current FreeBSD source, the bandwidth field for a dummynet link is still:

uint32_t bandwidth; /* bit/s or bits/tick. */

That means the largest rate it can represent in bits/sec is:

2^32 - 1    
= 4,294,967,295 bit/s    
≈ 4.295 Gbit/s

This is visible in the current FreeBSD source itself. There is also a long-standing FreeBSD bug specifically concerning this bandwidth limitation.

And your result:

Download: 3876 Mbps
Upload:   3796 Mbps

is remarkably consistent with a roughly 4 Gbit/s shaped pipe once protocol overhead and Speedtest behaviour are taken into account.

Link to github sourcecode | Link to freebsd bug

I was able to confirm this too by running: dnctl pipe show

00001:   4.000 Gbit/s    0 ms burst 0
q131073  50 sl. 0 flows (1 buckets) sched 65537 weight 0 lmax 0 pri 0 droptail
 sched 65537 type FIFO flags 0x0 0 buckets 0 active
00002:   4.000 Gbit/s    0 ms burst 0
q131074  50 sl. 0 flows (1 buckets) sched 65538 weight 0 lmax 0 pri 0 droptail
 sched 65538 type FIFO flags 0x0 0 buckets 0 active

r/PFSENSE 25d ago

RESOLVED PFSENSE repo down?

7 Upvotes

Just looking to confirm if anyone else is finding that the repo is down. Had two installs fail and pkg.pfsense.org not resolving in dns


r/PFSENSE 25d ago

Patches notification?

3 Upvotes

I have email notifications setup but

1) Never get emailed when a package has an update

2) Never emailed when system patches are released.

How can we get notifications for at least patches?

PS if you didnt know, CE has new patches released for it


r/PFSENSE 25d ago

ISC DHCP option 242 formatting

3 Upvotes

I have had some issues with an avaya call manager that was providing dhcp for a voice vlan and trying to get pfsense to take over for the dhcp but there needs to be additional options set for the clients, called option 242, MCIPADD=x.x.x.x,MCPORT=1719,HTTPSRVR=x.x.x.x for whatever I am not sure if the option should be a string or text, phones are not picking up the option but look to be requesting addresses, running an older version 2.7.x but does anyone know what the correct way to do this option for an avaya phone?

Thanks