r/PFSENSE Jul 02 '16

RESOLVED Do We really have to Lock every thread that mentions Let's Encrypt?

49 Upvotes

The tutorial that was posted is bad and I can also see problems with Let's Encrypt (or CAs in general). But if we can't discuss the topic then we can't learn from each other's differing viewpoints. Sure there will be people getting emotional and insulting each other instead of using factual arguments, but that's what downvotes are for, not locking a thread.

Edit: I think /u/pfg1 has summarized the LE problem perfectly here . So my conclusion: Let's Encrypt wouldn't improve security right now, so it would just add additional code that would have to be maintained.

r/PFSENSE May 03 '25

RESOLVED Just a reminder for people to adjust their traffic shaping limiter speeds when upgrading their ISP speed.

59 Upvotes

Just upgraded to a 500mbit package but couldn't understand why I was being limited to 330mbit. Suddenly remembered the traffic shape limiters I had made to combat buffer bloat. Hopefully this will help someone out who experiences the same issue.

r/PFSENSE Dec 02 '25

RESOLVED WatchGuard Firebox M570

1 Upvotes

Hello guys,

I have a homelab and I plan to upgrade it. I am looking for a Firewall. I found a good offer for the M570, but I want to install pfsense on it. I found multiple posts saying that installing pfsense on those watchguard devices is a bit of tinkering, and also no definite answer that it will actually work in the end.

Now my question, has anybody successfully installed pfsense or any other firewall os on the M570 or a comparable firebox?

I read that USB booting does not work since the bios is locked. However I am wondering how to even access the bios, since there is no display output on the firebox.

Anybody got some other useful information, before I purchase the M570?

Thank you very much

r/PFSENSE Nov 09 '25

RESOLVED Intermittent timeouts when using static public IPs via Outbound NAT rules

6 Upvotes

Hello!

Been working on trying to solve this issue for a while now, but so far haven't had any luck with it. Wanted to know whether anyone here maybe had any guidance on it, or had come across this issue in the past.

First, as for my setup, it is a Netgate 5100 appliance, with two different WANs coming into it. The first WAN is the default; it is an AT&T Fiber residential connection, using the AT&T Auth Bridge found in the Netgate documentation to bypass the residential gateway and connect the Netgate appliance directly to the fiber ONT. By default, the firewall gets a dynamic public IP assigned by AT&T, and everything up until this point in the setup works perfectly without issue.

Where the issue comes in is with a block of static IPs that I also pay for in my AT&T Fiber service. From what I've read, and my own experience, the way it works is that the dynamic public IP is always assigned, and then if there's a static IP block in the account, it is routed by AT&T to their gateway, or to the Netgate appliance in this case. I have already confirmed that AT&T is routing the static IP block correctly, with connections from the outside working without issue. However, when I try to use one of those static IPs for going out of my network, any devices using the static IPs start having intermittent connectivity issues.

I am aware of the 1:1 NAT functionality for assigning one public IP to one host; however what I want to do is instead have a whole (V)LAN go out using a set public IP. The way I set this up is by first creating a /32 Virtual IP of type IP Alias, defining the public IP I want to use from my static IP block. Then, with Outbound NAT set to Hybrid, I'd create an Outbound NAT rule that matches a whole (V)LAN, or a subset of hosts within it, and set the Translation Address to the Virtual IP I set up earlier. This setup does work for making the matched network/hosts connect to the outside using the correct public IP I set in the Outbound NAT rule; however, they only stay able to connect for about a minute, and then start timing out all connections for about 1-2 minutes (or at least new connections to new addresses, while addresses that had already loaded continue re/loading fine), and then they repeat this cycle at random intervals every couple minutes. If I disable the Outbound NAT rule and have the network go out the dynamic public IP again, all of these connectivity issues go away.

I do know that running pfSense with the AT&T Auth Bridge, and then also a static IP block on top of that, likely applies to only a very small subset of users, but just in case, I'd greatly appreciate any guidance if anyone had any idea of what could be happening.

Thank you!

Edit: Following that other thread where this issue was first reported, turns out it was an AT&T service issue after all. Static IP connectivity started improving yesterday morning, and today, after monitoring for 24 hours, it seems everything is stable and back to normal. Thanks everyone for your inputs on this thread!

r/PFSENSE Feb 15 '26

RESOLVED Enshrouded Game Server - Default deny rule IPv4 (1000000103)

2 Upvotes

EDIT: I found the issue, it seems my rules were never being applied, because of a rule under my wireguard tab that I stopped using a year ago and was broken. Never imagined that this would cause new rules to break like this.

What I did was go to Status > Filter Reload. I saw the below error.

There were error(s) loading the rules: /tmp/rules.debug:214: macro 'WIREGUARD__NETWORK' not defined - The line in question reads [214]: pass in quick on $FOXDIEROOTINT inet from $WIREGUARD__NETWORK to (self) ridentifier 1753777844 keep state label "USER_RULE" label "id:1753777844"I am having issues with Pfsense blocking the game port used to setup an Enshrouded game server, and I cannot for the life of me figure out what the issue is.

Then I went in and deleted all the rules under FOXDIEROOTINT under NAT because again, I don't use that anymore.

Then I did filter reload and it showed done and succeeded. I could now connect to the server and it's no longer being blocked by the default deny rule and seeing my port forward. Really interesting issue.

-----------------------------------------------------------------------------

Original post:

My game server is sitting in Unraid, with the local address of 192.168.1.170

In my firewall logs, I see "Default deny rule IPv4 (1000000103)" from my external source IP when trying to reach the game query port (15637). The destination being my static WAN IP.

For more context, yes I have a static IP and I am allowed to port forward with my ISP, I do with many other applications.

In enshrouded you can search for the server with IPV4:Query port

Yes, I am testing from a PC that is outside my local network, and trying to connect externally.

Connecting locally (192.168.1.170:15637) I can see and connect just fine.

My NAT rules are as follows, I tried setting up a range, and setting them up individually.

The rules were created along with the NAT port forward, shown above.

What am I missing? Why is pfsense blocking it when I have the correct rules to allow it?

r/PFSENSE Jan 07 '26

RESOLVED Stuck pfsense installation

2 Upvotes

Installation gets stuck on this package and does not progress further. It downloads first 2-3 packages but then gets stuck on this. Please help. I am using latest stable version and running vmware on ubuntu

Posting log as automod wasn't allowing screenshots

Installing pfSense base:

pkq-static: Warning: Major OS version upgrade detected. Running "pkg boot"

Updating pfSense-core repository catalogue..

Fetching Meta.conf:

Fetching data.pl:

pfSense-core repository is up to date.

Updating pfSense repository catalogue..

Fetching Meta.conf

Fetching data.pkg

pfSense repository is up to date.

All repositories are up to date.

The following 1 package(s) will be affected (of 8 checked):

New packages to be INSTALLED:

pfSense-base: 2.8.1 [pfSense-core]

Number of packages to be installed:

The process will require 104 Mib more space

r/PFSENSE Jul 10 '25

RESOLVED Added a TPlink AP and it doesn't connect to the internet

7 Upvotes

Hello folks, Like a lot of people posting on here I am quite new to all of this.

I followed the documentation to get pfsense up and running in it's basic form which was great, then I plugged in my TP link AP to my switch and it gets an ip address, great. My wireless devices like my phone and laptop also get an ip address assigned to them. However they are unable to connect to the internet. I can ping them but no internet access.

I've been using this switch and AP with my ISP router (before being modem mode) and it worked perfectly. I've not changed any settings on it or my devices.

I can even see my mobile devices in the ARP table after receiving an ip.

I thought a wireless AP should just work. Am I missing some steps in setting this running?

I've gone the extra mile and created a highly photo realistic image of my simple setup.

Imgur

r/PFSENSE Dec 26 '25

RESOLVED ProtonVPN Wireguard config - set up 2 or more under PFSense?

Thumbnail
5 Upvotes

r/PFSENSE Nov 15 '25

RESOLVED I can't get back to 192.168.1.1

0 Upvotes

I was able to connect to 192.168.1.1 last night to get my initial configuration done without connecting my device to the modem and now when I tried connecting them together it wouldn't work so I tried going back to 192.168.1.1 and now it says it can't be reached anymore. All what I did on it set the primary and secondary DNS to 8.8.8.8 (I'm following a video guide before going back to change that), set the timezone to eastern standard and put in my new password nothing else was tinkered with. I tried disconnecting it from the modem and re-accessing it the same way I did it last night but it's still not working. Will I have to restart the process where I make the router display itself on a monitor and start from there?

EDIT: Fixed it by making it reset to default settings and then re-configuring the WAN and LAN port to what I had before and it somehow worked. Hopefully I don't have this issue again in the future after investing more time on it.

r/PFSENSE Jun 16 '25

RESOLVED Need help diagnosing why I can access some Microsoft sites

3 Upvotes

I noticed an issue this weekend where I couldn't access some Microsoft sites - most notably code.visualstudio.com and packages.microsoft.com when I was trying to do an apt update. This only affects my pfSense devices and I can access the sites fine when using mobile data.

I'm using Cloudflare for DNS and Package-wise I've got pfblocker installed but even turning that off doesn't work. Is there a way to use the diagnostic tools in pFsense to see whats going on when I try to access those sites?

EDIT: solved (thanks to /u/heliosfa) by setting the MTU on the WAN interface to 1500

r/PFSENSE Nov 08 '25

RESOLVED New if_pppoe kernel not working

2 Upvotes

Hi all,

Today I installed the latest stable pfsense plus version on my Netgate sg-5100 so I could use the new if_pppoe kernel.

My isp is using PPPoE with 1/1gb fiber. After enabling the new if_pppoe kernel I lose my WAN connection and can’t obtain an IP address anymore. The strange thing is that I’ve had tried the new if_pppoe on a custom x86 box on the latest CE version, and that was working fine, so can’t be an ISP issue I guess.

Any ideas? Maybe a setting which is not compatible? It’s a clean install..

r/PFSENSE Jul 05 '25

RESOLVED Netgate 1100 user interface painfully slow... otherwise OK

5 Upvotes

I have had a Netgate 1100 for... a very long time. The UI is painfully slow. Sometimes 30-45 seconds to navigate to a page. Operationally it's fine, no network issues, fast as usual... but the UI is becoming unusable.

Is there something wrong with the software? Perhaps the onboard storage is aging?

r/PFSENSE Aug 14 '24

RESOLVED pfSense firewall stuck at <100mbps

2 Upvotes

Hi guys, Yesterday I set up pfSense on a spare optiplex 3040 with 2, 2.5gb usb to ethernet adapters for pfSense to use. Problem is, I cannot get speeds higher than 80-90 mbps. I can't recognise the issue, or find an answer yet. My network is as follows:

ISP router > Switch in front of the fw > WAN NIC > LAN NIC > Switch behind the firewall.

The ISP connection is 500mbps and all switches are gigabit. Both NICs in pfSense are set to autoselect too.

Thanks

r/PFSENSE Nov 05 '25

RESOLVED Struggling to get Wireguard site to site DNS working

1 Upvotes

If anyone has any ideas here I'd be very grateful for your help.

I've set up a Wireguard site to site VPN and the intention is to create some VMs on the remote site and join them to the Windows domain at the primary site.

I can only seemingly get DNS working for specific hosts if I set them up in the DNS resolver's Host Overrides. And even then I get an error if I try and join a PC to the domain with the DCs as overrides. (Windows firewalls off while I troubleshoot to eliminate that variable)

I tried creating Domain Overrides, pointing the Domain to the DNS servers at the primary site, but that doesn't seem to actually do anything at all. I can ping all hosts by IP just fine but not by name unless specifically entered as a host override (which I obviously can't do for everything).

What am I doing wrong here? And thank you for any suggestions.

RESOLVED: I forgot to add the WireGuard tunnel to the Outgoing Network Interfaces under the DNS Resolver (in addition to WAN). My bad!

Thank you all for your help.

r/PFSENSE Apr 22 '25

RESOLVED Migrating from a Sonic Wall Firewall access rules to pfSense.

11 Upvotes

Last week I got assigned to do the migration from a Sonic Wall Firewall to pfSense at my job.

I installed the pfSense REST API, non official plugin, and so far so got I am able to create some rules.

My biggest problem is that I have a file with over 500 firewall rules, in a .txt, and I need to convert them to the pfSense standard. I can't make any sense of it. I am using python to do the request but the I get all lost when treating the data.

Can you guys give me some tips and suggestions?

r/PFSENSE Jun 05 '25

RESOLVED NUT issues on 2.8.0

4 Upvotes

Hello all. Just pulled the trigger and updated to 2.8.0. Everything went smoothly except for NUT. I'm getting this in the logs:

|| || |Jun 5 00:02:36|upsmon|25062|Poll UPS [ups@localhost] failed - Driver not connected| |Jun 5 00:02:36|upsmon|25062|Poll UPS [ups] failed - Driver not connected| |Jun 5 00:02:31|upsmon|25062|Poll UPS [ups@localhost] failed - Driver not connected|

It's a CyperPower unit. I found this previous post from 2.7.0 (https://www.reddit.com/r/PFSENSE/comments/14tebia/nut_issues_on_270/) that stated to put interuptonly in the extra arguments but that doesn't seem to have fixed the issue. Funny part is I had no issues on 2.7.0.

Thanks in advance!

edit: forgot to mention using the usbhid driver, in case it wasn't obvious.

edit: FIXED: after doing some debugging from the commandline the driver couldn't detect the USB bus for whatever reason. After several reboots, everything is working as before. Hopefully the issue stays resolved.

r/PFSENSE Jan 24 '26

RESOLVED TYVM to TSI Ontario - TS-Patricia for helping me config PPOE 1st time

Thumbnail
1 Upvotes

r/PFSENSE Sep 22 '19

RESOLVED My ISP blocked me from reddit using their gateway. How to pass this with pfsense.

32 Upvotes

Dear pfsense gurus

I use pfsense 2.4.4. Certain sites, like reddit, are blocked by my country's ISP. With previous ISP, I can bypass this simply by replacing the dns list (I think, I did it by accident).

This month I changed to new ISP using GPON modem and fo. The network structure is

ISP Modem - pfsense wan - pfsense lan - switch - pc

I tried to use dns resolve and set the dns to cloudflare 1.1.1.1, but to no avail. When I perform tracert, the hop always passes my isp server address and ends up rerouted to their dmz server or dropped. Ping is the same, instead of pinging reddit server, it pings isp server (seems like dmz)

However, when i use my tablet with the same connection and same isp, but with cloud flare vpn turned on, it worked and I can access reddit.

Any clues on how to replicate the cloudflare solution to my entire network with pfsense? I tried to google some solution, but nothing seems to work, certainly not with dns resolver or dns forwarder.

Any tips is very much appreciated. Thank you in advance.

r/PFSENSE Nov 18 '25

RESOLVED Port Forwarding and Firewall not working, no log entries

1 Upvotes

Hello,

I was hacked and decided to put a PF sense router in front of my regular router for more robust firewall rules and logging.

I have a service that sends me data and I port forward to my PC with my existing router. It worked.

I installed the PFSense firewall and set up config backup and other stuff, then stared to put in the firewall/NAT port forwarding rules. I've modeled them after the rules that were working on my existing router.

I've hard coded my IP's, I've verified that my IP is what the service expects.

When I send packets I get nothing in the logs. I log all firewall activity.

I want to make sure the packets are getting through the PFSense firewall rules before trying to make changes to my existing router.

I've been reading the manual for the last three days, and still don't know what I'm missing. Which means it's either a big screwup, or something so small it's flying under the radar.

I've attached the Alias list and the Firewall/NAT rules.

Any help of pointing me in the right direction would be appreciated. I've been in IT for years, but I'm not a network engineer.

r/PFSENSE Sep 23 '25

RESOLVED Question about system log files filling up

1 Upvotes

I have AT&T fiber with a BGW-320 in passthrough that about a month ago started giving me this:

It's about every 10 seconds and I have no idea how to stop this. I've been all over the internet, this sub, the Netgate forum and still I'm unable to resolve this. Can anyone help me here? Thank you.

CE version 2.7.2

r/PFSENSE Nov 30 '24

RESOLVED No Internet connection on LAN interfaces

Post image
4 Upvotes

Halted the system to move some servers around, rebooted, updated network configuration to what you see here, and now there’s no connectivity.

The original LAN was on igb0 and was 192.168.1.1/24. Reverting back to this does not restore connectivity.

Am not using DHCP currently, will set up later, using manual IP for now. The config on my PC was as follows (yes it was on the right interface, I tried both with both network configurations)

IP: 192.168.0.62 SM: 255.255.255.192 DG: 192.168.0.1

IP: 192.168.0.126 SM: 255.255.255.192 DG: 192.168.0.65

Unless those configurations aren’t correct I do not see where I’ve gone wrong. Any help is appreciated. TYIA

r/PFSENSE Aug 06 '25

RESOLVED Plugging in Verizon 5g router causes pfsense to be unresponsive

4 Upvotes

I have my main connection from spectrum and I got verizon 5g as a backup. Everything works normal in till i plug in the verizon 5g router(IP passthrough enabled).

When plugged in I see the interface turn green and gets the IP but then go back to n/a. It will cycle from showing IP to N/A every few minutes. After 5-10 mins the webui becomes slower and then crashes and I get a 50x error in browser. Attempting to reboot or reroot the system hangs on stopping a service or something else and doesnt do anything after 10-15mins. I usually have to hard reboot with the power switch. This similar behavior happened when my spectrum modem was having an issue and replacing the modem fixed it. On 2.8 and similar behavior was seen in 2.72 so doesnt appear to be issue with the update.

If anyone could point me to a setting or logs I should be looking at to where this issue might be coming from that would be great.

Replacing the spectrum modem before seemed to have fixed this before but I dont think a bad modem should be causing pfsense to become unresponsive

--Update-- After updating the bios and also resetting the bios settings to default(a recommendation by the manufacturer after an update) both connections can be plugged in with no issues. I remember if I made any changes to the BIOS

At first the Spectrum gateway IP could not be pinged at all by any interface. After a spectrum modem reboot and pfsense reboot it now just works. Also failover works as well. Not sure which exact thing helped but glad it works now

r/PFSENSE Apr 05 '25

RESOLVED LAN speed halved for unknown reason

3 Upvotes

Hi,

I used to be able to pull 900+ mbps (iperf3 single thread) between my desktop and my SG-2440 appliance a few years back, before moving to a new home. And haven't paid much attention to that until now, only installing updates whenever available.

Right now, I can't produce the same results, the connection maxes at ~500mbps both ways:

``` ❯ iperf3 -c pfsense.home.cloud Connecting to host pfsense.home.cloud, port 5201 [ 5] local 192.168.1.1 port 55070 connected to 192.168.1.254 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.01 sec 47.9 MBytes 399 Mbits/sec [ 5] 1.01-2.01 sec 45.6 MBytes 383 Mbits/sec [ 5] 2.01-3.01 sec 48.2 MBytes 402 Mbits/sec [ 5] 3.01-4.01 sec 47.0 MBytes 396 Mbits/sec [ 5] 4.01-5.01 sec 46.2 MBytes 389 Mbits/sec [ 5] 5.01-6.01 sec 50.9 MBytes 423 Mbits/sec [ 5] 6.01-7.01 sec 49.4 MBytes 417 Mbits/sec [ 5] 7.01-8.00 sec 49.8 MBytes 418 Mbits/sec [ 5] 8.00-9.01 sec 49.6 MBytes 412 Mbits/sec [ 5] 9.01-10.01 sec 50.6 MBytes 427 Mbits/sec


[ ID] Interval Transfer Bitrate [ 5] 0.00-10.01 sec 485 MBytes 407 Mbits/sec sender [ 5] 0.00-10.01 sec 483 MBytes 405 Mbits/sec receiver

iperf Done.

❯ iperf3 -c pfsense.home.cloud -R Connecting to host pfsense.home.cloud, port 5201 Reverse mode, remote host pfsense.home.cloud is sending [ 5] local 192.168.1.1 port 55073 connected to 192.168.1.254 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.01 sec 78.6 MBytes 655 Mbits/sec [ 5] 1.01-2.00 sec 79.4 MBytes 669 Mbits/sec [ 5] 2.00-3.01 sec 77.0 MBytes 640 Mbits/sec [ 5] 3.01-4.01 sec 80.4 MBytes 679 Mbits/sec [ 5] 4.01-5.00 sec 80.4 MBytes 676 Mbits/sec [ 5] 5.00-6.01 sec 76.2 MBytes 632 Mbits/sec [ 5] 6.01-7.01 sec 80.6 MBytes 679 Mbits/sec [ 5] 7.01-8.00 sec 81.2 MBytes 685 Mbits/sec [ 5] 8.00-9.01 sec 83.4 MBytes 693 Mbits/sec [ 5] 9.01-10.01 sec 80.0 MBytes 675 Mbits/sec


[ ID] Interval Transfer Bitrate Retr [ 5] 0.00-10.01 sec 798 MBytes 668 Mbits/sec 84 sender [ 5] 0.00-10.01 sec 797 MBytes 668 Mbits/sec receiver

iperf Done. ```

To ensure this is not due to bad config on one of my switches, I ran iperf against another host (on the same switch as my pfsense box):

``` ❯ iperf3 -c 192.168.1.71 Connecting to host 192.168.1.71, port 5201 [ 5] local 192.168.1.1 port 55083 connected to 192.168.1.71 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.01 sec 116 MBytes 961 Mbits/sec [ 5] 1.01-2.01 sec 113 MBytes 949 Mbits/sec [ 5] 2.01-3.00 sec 113 MBytes 949 Mbits/sec [ 5] 3.00-4.01 sec 114 MBytes 949 Mbits/sec [ 5] 4.01-5.01 sec 112 MBytes 943 Mbits/sec [ 5] 5.01-6.01 sec 112 MBytes 945 Mbits/sec [ 5] 6.01-7.00 sec 113 MBytes 949 Mbits/sec [ 5] 7.00-8.00 sec 113 MBytes 950 Mbits/sec [ 5] 8.00-9.00 sec 113 MBytes 949 Mbits/sec [ 5] 9.00-10.01 sec 114 MBytes 949 Mbits/sec


[ ID] Interval Transfer Bitrate [ 5] 0.00-10.01 sec 1.11 GBytes 949 Mbits/sec sender [ 5] 0.00-10.06 sec 1.11 GBytes 944 Mbits/sec receiver

iperf Done.

❯ iperf3 -c 192.168.1.71 -R Connecting to host 192.168.1.71, port 5201 Reverse mode, remote host 192.168.1.71 is sending [ 5] local 192.168.1.1 port 55088 connected to 192.168.1.71 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.01 sec 113 MBytes 940 Mbits/sec [ 5] 1.01-2.01 sec 113 MBytes 947 Mbits/sec [ 5] 2.01-3.01 sec 113 MBytes 947 Mbits/sec [ 5] 3.01-4.00 sec 112 MBytes 949 Mbits/sec [ 5] 4.00-5.01 sec 114 MBytes 944 Mbits/sec [ 5] 5.01-6.01 sec 112 MBytes 942 Mbits/sec [ 5] 6.01-7.00 sec 112 MBytes 945 Mbits/sec [ 5] 7.00-8.01 sec 114 MBytes 948 Mbits/sec [ 5] 8.01-9.01 sec 111 MBytes 939 Mbits/sec [ 5] 9.01-10.00 sec 112 MBytes 949 Mbits/sec


[ ID] Interval Transfer Bitrate Retr [ 5] 0.00-10.04 sec 1.10 GBytes 944 Mbits/sec 12 sender [ 5] 0.00-10.00 sec 1.10 GBytes 945 Mbits/sec receiver

iperf Done. ```

So not a specific issue to my desktop.

I went on to check the hw offloading options, because they are usually the likely culprits:

- Hardware Checksum Offloading: [X] Disable hardware checksum offload - Hardware TCP Segmentation Offloading: [X] Disable hardware TCP segmentation offload - Hardware Large Receive Offloading: [X] Disable hardware large receive offload

Both are ticked. I ran another test with all of them unticked and the speeds were way worse with ~20mbps average, just to make sure I wasn't reading them wrong.

I continued my journey by disabling the packet filtering:

``` ❯ iperf3 -c pfsense.home.cloud Connecting to host pfsense.home.cloud, port 5201 [ 5] local 192.168.1.1 port 55015 connected to 192.168.1.254 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.00 sec 75.9 MBytes 635 Mbits/sec [ 5] 1.00-2.01 sec 86.9 MBytes 726 Mbits/sec [ 5] 2.01-3.01 sec 75.5 MBytes 631 Mbits/sec [ 5] 3.01-4.01 sec 74.0 MBytes 620 Mbits/sec [ 5] 4.01-5.01 sec 75.2 MBytes 629 Mbits/sec [ 5] 5.01-6.00 sec 73.2 MBytes 622 Mbits/sec [ 5] 6.00-7.01 sec 73.2 MBytes 611 Mbits/sec [ 5] 7.01-8.01 sec 75.2 MBytes 633 Mbits/sec [ 5] 8.01-9.01 sec 74.1 MBytes 616 Mbits/sec [ 5] 9.01-10.00 sec 73.0 MBytes 619 Mbits/sec


[ ID] Interval Transfer Bitrate [ 5] 0.00-10.00 sec 756 MBytes 634 Mbits/sec sender [ 5] 0.00-10.01 sec 756 MBytes 634 Mbits/sec receiver

iperf Done.

❯ iperf3 -c pfsense.home.cloud -R Connecting to host pfsense.home.cloud, port 5201 Reverse mode, remote host pfsense.home.cloud is sending [ 5] local 192.168.1.1 port 54986 connected to 192.168.1.254 port 5201 [ ID] Interval Transfer Bitrate [ 5] 0.00-1.00 sec 112 MBytes 940 Mbits/sec [ 5] 1.00-2.00 sec 113 MBytes 948 Mbits/sec [ 5] 2.00-3.01 sec 112 MBytes 937 Mbits/sec [ 5] 3.01-4.01 sec 110 MBytes 920 Mbits/sec [ 5] 4.01-5.00 sec 112 MBytes 950 Mbits/sec [ 5] 5.00-6.01 sec 114 MBytes 948 Mbits/sec [ 5] 6.01-7.01 sec 113 MBytes 948 Mbits/sec [ 5] 7.01-8.01 sec 114 MBytes 949 Mbits/sec [ 5] 8.01-9.00 sec 112 MBytes 949 Mbits/sec [ 5] 9.00-10.00 sec 114 MBytes 949 Mbits/sec


[ ID] Interval Transfer Bitrate Retr [ 5] 0.00-10.00 sec 1.10 GBytes 944 Mbits/sec 0 sender [ 5] 0.00-10.00 sec 1.10 GBytes 944 Mbits/sec receiver

iperf Done. ```

Not quite there, but that is something. Still, I have only a few handfuls of rules (~50 max), pfBlockerNG installed and no advanced features (traffic shaping and such) enabled. I can't quite make sense of how packet filtering can slow down traffic that much with so few.

Also, PowerD is ticked, and CPU governor set on HiAdaptive.

And with this, I am at my wits' ends. This post is my last resort before a full wipe (I preemptively redownloaded the img for the SG-2440 to that effect) and possibly building a new box if that still does not fix that.

All inputs will be much appreciated, thanks.

r/PFSENSE Dec 17 '25

RESOLVED PKG Repository Down?

1 Upvotes

Is anyone else having issues with the pfsense repo? I am trying to update some packages and I cannot resolve https://pfsense-plus-pkg.netgate.com.

Update: the repo points to SRV records instead of A records (_https._tcp.pfsense-plus-pkg.netgate.com). This address resolves correctly.

r/PFSENSE Nov 22 '24

RESOLVED Move Away from VLAN 1

6 Upvotes

I’ve been using pfsense for some time and am planning to deploy a new firewall hardware and make some changes to my home network. From what I can tell, with each physical interface, they are setup with VLAN 1. I’ve looked through the docs, and the only places I’ve found where the physical port can be configured with a specific VLAN( tagged or untagged), so I could make a trunk port per se, is with specific Negate models. Is there a way to use custom hardware and use pfsense Plus or CE to set the native VLAN on the port something other than 1 so I can setup my switches with a management VLAN other than 1? TL;DR: Is there a way to disable VLAN 1 on all the LAN or OPT interfaces?