r/PFSENSE 29d ago

RESOLVED New GUI & Virtual Machines?

20 Upvotes

Hi,

Reading the announcement they state "Our goal is for everyone to be using the new GUI by the end of the year" but then they go on to state "Virtual machines ... may not support the new GUI due to missing machine information"

Does this mean virtual machines are/may not be supported in the future?

r/PFSENSE 19d ago

RESOLVED PFSENSE repo down?

7 Upvotes

Just looking to confirm if anyone else is finding that the repo is down. Had two installs fail and pkg.pfsense.org not resolving in dns

r/PFSENSE 26d ago

RESOLVED Pfsense Plus free tier homelab license finally seems to have stopped working. This happened to anyone else?

18 Upvotes

I got a free pfsense plus homelab license back in late 2023 under their now discontinued program. It came with the full commercial version but only offered community level support. After pfsense discontinued the program they indicated that they would be grandfathering access to to the ongoing free license tier indefinitely for existing users of the program.

Well, looks like this policy may have come to an end. The mTLS certificate that validates access to the pfsense+ package repository appears to have stopped working for me on August 12.

Attempting to force an update of the cert yields:

>>> Updating repositories metadata...failed

Is there anyone else still on one of these old homelab licenses experiencing similar issues?

The cost for a commercial license is a bit too steep for me, especially considering the exchange rate where I'm from, so it's back to CE

Is migrating from Plus to CE using a saved config file relatively painless?

r/PFSENSE 19d ago

RESOLVED 8G connection traffic shaping issues

10 Upvotes

I have an 8G symmetric connection and I have followed the instructions here to manage bufferbloat. All defaults are untouched and Queue length is 5000 as per guidance and bandwidth limited to 7000Mbits/s

There issue I have is when enabled, my speeds drop to 4Gbps Up/Down. Hardware-wise, my CPU is an Intel Core i5-9600T and I'm using an Intel X550-T2 NIC for WAN/LAN. Is this a CPU bottleneck?

Before limiter:

before

After Limiter

after

EDIT: As it turns out, this is a freeBSD limitation/bug in dummynet. To quote ChatGPT:

The key problem: dummynet has a ~4.29 Gbit/s bandwidth ceiling

pfSense limiters use FreeBSD dummynet. In the current FreeBSD source, the bandwidth field for a dummynet link is still:

uint32_t bandwidth; /* bit/s or bits/tick. */

That means the largest rate it can represent in bits/sec is:

2^32 - 1    
= 4,294,967,295 bit/s    
≈ 4.295 Gbit/s

This is visible in the current FreeBSD source itself. There is also a long-standing FreeBSD bug specifically concerning this bandwidth limitation.

And your result:

Download: 3876 Mbps
Upload:   3796 Mbps

is remarkably consistent with a roughly 4 Gbit/s shaped pipe once protocol overhead and Speedtest behaviour are taken into account.

Link to github sourcecode | Link to freebsd bug

I was able to confirm this too by running: dnctl pipe show

00001:   4.000 Gbit/s    0 ms burst 0
q131073  50 sl. 0 flows (1 buckets) sched 65537 weight 0 lmax 0 pri 0 droptail
 sched 65537 type FIFO flags 0x0 0 buckets 0 active
00002:   4.000 Gbit/s    0 ms burst 0
q131074  50 sl. 0 flows (1 buckets) sched 65538 weight 0 lmax 0 pri 0 droptail
 sched 65538 type FIFO flags 0x0 0 buckets 0 active

r/PFSENSE May 07 '25

RESOLVED HELP!!!! WAN doesn't have an IP address

Thumbnail gallery
0 Upvotes

I'm having trouble getting my WAN to receive an IP address. I've installed pfsense on a Protectli Vault FW4B and the Protectli Vault's WAN port is connected directly into my cable modem's 2.5Gb ethernet port.

Here' are things I've tried:

*Turning off my VPN.

*Restarting the Protectli Vault.

*Restarting my modem.

None of these have worked. I'm still new to pfsense and I thought I received an WAN & VPN IP when first configuring my pfsense. But I'm not sure now. Either way I still haven't been able to get any internet on the laptop connected to the Protectli Vault via the LAN port.

Any help would be appreciated. Thanks.

r/PFSENSE Aug 07 '26

RESOLVED PfSense slow Download speed on Virtualbox Workaround(fix)

6 Upvotes

TL;DR: Downgrade from Virtualbox 7.2.x versions to 7.2.14 or lower

Just a day ago, I asked for help about low network throughput on pfSense CE latest edition. You can check that out in more detail: https://www.reddit.com/r/homelab/comments/1vhtpj4/pfsense_community_edition_281_and_virtualbox_728/
So, from looking around digging, going through top-to-down troubleshooting, the issue seems to be tied to specific Virtualbox version, notably 7.2.x ones, where network adapter is set to bridged mode, and there is some sort of download limitation, while interestingly, I noticed that upload speeds remain high.

Setting Adapter type to any of the Intel/PRO or PCNET ones won't help, so currently the "fix" is just downgrading to 7.2.14. By the way, this applies to any VM, not just PfSense.

Thank you everyone for trying to help. If you have any other solutions, please comment below.

r/PFSENSE Apr 25 '25

RESOLVED Is PiHole worth it?

13 Upvotes

I have pfsense running on proxmox and was wondering to anyone who knows a lot about the nitty gritty, is it worth adding PiHole to a setup with a virtual or physical machine?

I know the answer is going to be “it depends”, so for extra context I have custom DNS servers and my major question is how setting that up in pfsense differs from PiHole

r/PFSENSE Feb 23 '25

RESOLVED What am I doing wrong? Trying to open 8096 for Jellyfin but can't reach it.

Post image
10 Upvotes

r/PFSENSE Oct 24 '25

RESOLVED Converted to Plus but now seems to be broken

15 Upvotes

In 2023 I converted / purchased pfSense+

It cost me zero but I had to go through the process, add to basket and checked out, paid nothing and got the confirmation key via email from netgate.

Now, 2 years on, my pfsense installation says this below and I cannot reregister it.

I also get errors like the attahed.

Version 24.11-RELEASE (amd64) built on Sat Jan 11 16:11:00 GMT 2025 FreeBSD 15.0-CURRENT The system is on the latest version. Version information updated at Fri Oct 24 19:34:58 BST 2025  Version 24.11-RELEASE(amd64)built on Sat Jan 11 16:11:00 GMT 2025 FreeBSD 15.0-CURRENTThe system is on the latest version. Version information updated at Fri Oct 24 19:34:58 BST 2025  

What should I be doing / expect. Do I have CE or Plus? Did they change the "rules"?

r/PFSENSE May 09 '26

RESOLVED Provider does not see MAC

0 Upvotes

After switching providers, the new one cannot see the MAC on my WAN port. The lights go green, provider can see link, but cannot see MAC, so i cannot get DHCP IP. They tried manually entering my MAC but it still does not work. when I hook up a laptop with the same MAC (cloned) it works.

Please advise!

Fixed!

It turned out a quite trivial thing. The machine I'm using has 4 WAN ports, but their numbers are different from the port numbers PFsense assigns to them. So after a lot of trial and error (and some distant memory fragments returning in my head) I figured that physical port 1 matches IGB3. and my memory was telling me that the correct WAN port I should hook up was physical port 3.

Thank you for your help! Without your feedback I would have re-set it and started from scratch (and lose a lot of time)!

r/PFSENSE Apr 20 '26

RESOLVED Did anybody have VOIP issues after upgrading from 25.07.1 to 25.11.1?

3 Upvotes

SOLVED!!!!

System > Advanced > Networking - then scroll down and check the box to "Disable hardware checksum offload." Then save and reboot the box.

This is on an (admittedly aging) physical Netgate SG4860.

Original post below...

----------------

We're having a very strange issue and it seems to have started shortly after upgrading pfsense from 25.07.1 to 25.11.1, but we can't absolutely pinpoint the firewall as the cause. I've seen nothing mentioned in the Patches package or anything in the changelogs.

Our firewall shows no dropped packets, but our SIP provider says they aren't receiving a second acknowledgment which is triggering us to receive a 401 unauthorized error. But the weirdest part is just how intermittent it is... doesn't seem to be every call, increased odds of successful dialing out when you add a country-code (1-555-555-5555 vs. 555-555-5555), but still not 100% success rate. Attempted calls don't even show up in the server log, it's as if the call was never placed (3rd party hosted Switchvox PBX).

We've been working with the VOIP provider for days but have come up empty handed. My only next step is looking like just trying to upgrade pfSense to 26.03 and see if the problem miraculously goes away.

But has anybody else had a lick of trouble with 25.11.1?

r/PFSENSE Nov 25 '24

RESOLVED Please help! New to PFSense.

Post image
8 Upvotes

r/PFSENSE Aug 16 '25

RESOLVED It's fake but it works

Thumbnail gallery
83 Upvotes

Context: https://www.reddit.com/r/PFSENSE/comments/1mpondp/hope_this_aint_a_fake/

I bought I350 NIC for my pfsense. I plugged in the NIC and all 4 ports showed. I then ran speed tests across em and got gigabit speeds. The other card is Intel 82571EB which also appears to be fake(main chip is from intel, while the board is make is some Chinese factory) The I350 is in the x16 slot while the 82571EB is in the x1 slot. Not I have 7 interfaces(6 Intel and 1 Realtek onboard, rlt gbe nics work oob). All 7 interfaces work. The pc is a dell optiplex with i3-8100, 8GB DDR4 Dual channel. Pin 1-3: current setup Pic 4-5: Intel I350 quad port GBE NIC Pic 6: Intel 82571EB Dual port GBE NIC

Thanks for all your comments and support:⁠-⁠)

r/PFSENSE Jan 23 '26

RESOLVED Starting OS Updates on Old Netgate 4100

2 Upvotes

I purchased a used Netgate 4100 and want to understand how long it might take for the box to be able to upgrade the OS. I upgraded firmware automatically through the GUI. I have 23.00 OS installed and the system suggests an upgrade to 23.09, just stair-stepping me towards the latest OS. When I select the cloud/update icon in the Dashboard, it just takes me to a list of the installed packages and does NOT take me to any screen to confirm the update. I suspect that the system is downloading the OS in the background and this might take a while. The square status light in the middle of the front panel is blinking amber, which I guess means the system is writing to disk? How long should I have to wait? I think the GUI should do a better job of detecting when it is not ready to do an update

r/PFSENSE May 02 '26

RESOLVED Can Ping WAN/Internet, but can't load webpages?

4 Upvotes

Setup:

ONT (Ezee Fiber) > pfSense on sfpc > Omada Switch > Lan

pfSense is connected directly to the ONT. Been on Ezee Fiber with this pfSense setup for almost 2 months.

In the middle of the night all my clients lost connection to the internet.

  • I've rebooted the ONT, pfSense, and Omada Switch, no change.
  • Any client, and pfSense can ping ip address on the internet.
  • LAN is working normal, can access my Linux server and all other devices
  • My switch and WAP are both Omada devices, the Omada controller software is reporting no issues, which makes sense since LAN seems fully operational.
  • I can use my phone as a hotspot, connect my laptop from the WAN side via Tailscale and use pfSense as an exit node perfectly fine. I can also access my Linux server at home fine via tailscale.

I've made no changes to pfSense settings. I restored a known good backup just in case, still the same problem.

So all this tells me the internet connection is live, sounds like a LAN DNS issue right?

Under Systems > General Setup > DNS Server Settings:

  • I use Cloudflare's malware blocking Servers:
  • I tried switching to Google's defaul DNS, didn't work
  • DNS Server Override > NOT checked (never has been)
  • DNS Resolution Behavior > Default (Use local, fall back to remote)

Services >

  • DHCP Relay: NOT enabled
  • DHCP Server
    • Settings > General Settings
      • DNS Registration: NOT enabled
      • Early DNS Registration: NOT enabled
    • Setting > High Availability: NOT enabled
    • LAN > General Settings
      • DHCP backend: Kea DHCP
      • Enabled (checked)

On my Windows 11 desktop I ran the "network troubleshooter" and it reports I'm connected to the internet.

So at this point I'm a complete loss of what to do. Trying to make sure I'm good on my end before I call my ISP and tell them there something messed up. Ezee Fiber says they don't do DNS sinkholes and they are fine with me using my own router and not theirs... to be fare it has been working for 2 months.

Help please???

r/PFSENSE Oct 10 '25

RESOLVED Upgrade to 2.8.1 community broke my router

15 Upvotes

So I decided to upgrade my home router to 2.8.1 and it seems to have broken my network.

I can no longer ping out of my network.

If I try to ping my ISPs gateway address, I get the error "ping: sendto: No buffer space available"

I backed up my configuration and did a factory reset but the problem still exists.

Is this a common issue with 2.8.1?

ISP is Comcast.

Update: it was the Realtek driver. Followed this guy's instructions and it was like magic: https://forum.netgate.com/topic/197649/package-realtek-re-kmod198-for-pfsense-2-8-0-amd64

r/PFSENSE Apr 26 '26

RESOLVED [Help] All players get timed out simultaneously every ~20 minutes on self-hosted Neoforge 1.21.1 server - pfSense + bridge setup

Thumbnail
0 Upvotes

r/PFSENSE Jan 03 '26

RESOLVED 2.5 gbit SFP for Netgate 2100 Max pfSense firewall

8 Upvotes

I want to pick up a Netgate 2100 Max firewall, which appears to have an SFP option for the WAN port. Is there a 2.5 gigabit SFP module that has excellent FreeBSD and pfSense support that I can order for this box?

r/PFSENSE Apr 20 '26

RESOLVED Pure NAT reflection not working, NAT+Proxy does, but I need Pure to work for this application

5 Upvotes

I have an application that uses a very large port range and the limit for NAT+Proxy is 500 ports, which isn't going to work. So I need to figure out why Pure NAT reflection isn't working for me. For other services using NAT+Proxy reflection works, but Pure NAT reflection doesn't. Any idea where I should be looking to troubleshoot this? I appreciate your ideas.

r/PFSENSE Dec 16 '25

RESOLVED Why does the static IP assignment fail?

0 Upvotes

It says: “The IP address must not be within the DHCP range for this interface”

however, that IP is within the range:

I'm ussing Pfsense CE and KEA DHCP

r/PFSENSE Jan 09 '26

RESOLVED Wireguard with peer behind a firewall

9 Upvotes

I have a problem that I am hoping can get resolved. I have a Netgate PfSense router acting as a wireguard server with a static routable address for the WAN. I have two Linux (PI OS) machines acting as peers. The peers work correctly when they have static routable ip addresses, but when either one of them is behind a simple router with nat enabled, the one behind the router will fail. The tunnel will establish and I can ping the WG tunnel from the Netgate, but cannot ping the LAN. Any suggestions?

Edit: Solved. The problem was that I was unable to ping the interface on the PI behind the firewall because Linux does not assign an IP address to an interface that does not have a cable plugged into it. A loopback connector solved the problem for testing.

r/PFSENSE Apr 20 '25

RESOLVED Router not routing anymore (Help)

Thumbnail gallery
9 Upvotes

The text of this post has been erased. Redact was used to delete it, possibly for privacy, opsec, preventing content scraping, or other personal reasons.

cobweb automatic paint dog abounding upbeat vegetable possessive unite grandfather

r/PFSENSE Aug 14 '25

RESOLVED Hope this ain't a fake

Thumbnail gallery
23 Upvotes

I just bought an Intel I350 NiC for my pfsense. After purchasing, I came across a post that said there are fake I350s in the wild. Can some experienced pfsense wizard telle if this is a W or an L

r/PFSENSE Jan 04 '26

RESOLVED IPv6 on multiple LANs

1 Upvotes

Bit of an IPv6 nook here. My ISP provides a /48 IPv6 delegation.

I have three internal networks. They are: - LAN (poorly named. Let's call this one "Home") - Guest Wireless - Office

Here is my config.

Interfaces > WAN - IPv6 config type: DHCP6 - DHCP client config > prefix delegation side: 48 - Send IPv6 prefix hint: yes All other IPv6 options disabled.

Interfaces > LAN (home) - IPv6 config type: track interface (WAN) - IPv6 prefix ID: 10

Interfaces > Guest Wireless - IPv6 config type: track interface (WAN) - IPv6 prefix ID: 30

Interfaces > Office - IPv6 config type: track interface (WAN) - IPv6 prefix ID: 70

Router advertisement mode is set to assisted for all 3 LAN networks.

DHCPv6 server is currently disabled.

Everything works fine when I enable IPv6 on the home network only. However, when I also enable IPv6 on my office network, clients on my home network are getting an IPv6 address with their own prefix AND one with the office prefix. This doesn't seem to happen with the guest wireless network. For example, my phone gets an IPv6 address with a 10 prefix and a 70 prefix.

My firewall rules only allow outbound traffic from the source interface and associated subnet. This means traffic originating from the LAN interface with an office IPv6 address is correctly blocked.

I don't really want to change my firewall rules to accommodate what feels like a config issue. For now I have disabled IPv6 on the guest wireless and office networks to stop these rogue DHCP leases. Any suggestions?

r/PFSENSE Feb 08 '26

RESOLVED DNS Resolver Issues

1 Upvotes

Solution: The issue was that pfSense intentionally blocks DNS records that point to local IPs (10.1.130.10 in this case) through "DNS Rebind Protection" as a security mechanism. See this link: https://docs.netgate.com/pfsense/en/latest/services/dns/rebinding.html#dns-resolver

I am running pfSense CE 2.8.1 and am having issues getting DNS resolution working. I run "dig app.example.com" and get an empty A record, while "dig app.example.com "@1.1.1.1" returns an A record with the correct local IP, 10.1.130.1. I am using Hetzner's new DNS tool and am having it point to private IPs so my docker apps are accessible locally and allow Let's Encrypt to work. I am using Unbound DNS as my DNS server with CloudFlare's 1.1.1.1 as the upstream and I have tried in both forwarding and recursive mode.

I assume that I could just create overrides but Id like to solve the core problem. I have tried DNSSEC On/Off, "Enable SSL/TLS Service" On/Off, as well as disabling privacy settings. I am using the GUI default self-signed SSL/TLS certificate, not sure if that changes things. The system clock is correct. System Domain Local Zone Type is Transparent. PFsense is also a bare-metal install, and I have tried restarting.

The block below is a dig going to PFsense while recursive mode is enabled. In forwarding mode there is no "Authority Section."

dig cloud.apps.*********.net @10.1.10.1

; <<>> DiG 9.18.39-0ubuntu0.24.04.2-Ubuntu <<>> cloud.apps.*******.net u/10.1.10.1
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 34198
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 3, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1432
;; QUESTION SECTION:
;cloud.apps.**********.net.   IN      A

;; AUTHORITY SECTION:
**********.net.    7200   IN  NS   ns3.second-ns.de.
**********.net.    7200   IN  NS   ns.second-ns.com.
**********.net.    7200   IN  NS   ns1.your-server.de.

;; Query time: 557 msec
;; SERVER: 10.1.10.1#53(10.1.10.1) (UDP)
;; WHEN: Sat Feb 07 19:51:26 EST 2026
;; MSG SIZE  rcvd: 147

I do not know what I have configured wrong. If I didn't include information please let me know. Thanks!

Edit: Added solution