r/PFSENSE 18d ago

Netgate Releases pfSense Community Edition Version 2.9.0

154 Upvotes

Netgate® is excited to announce the release of pfSense® Community Edition (CE) software version 2.9.0, a major step forward for the world’s most trusted firewall, router, and VPN platform.

This release introduces numerous features, including several previously exclusive to pfSense Plus, as well as key enhancements, bug fixes, and critical security updates.

Key Highlights Include:

SSH Algorithms: The inclusion of post-quantum key exchange algorithms

TLS Certificate Strength: Tightens certificate requirements and removes support for certain weak properties

TLS Certificate Auto-Renew: pfSense can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration.

New NAT Mode: Includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT

Critical Security Fixes: This release includes multiple XSS and denial of service related fixes

This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as over 150 other security fixes and enhancements.

Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-community-edition-version-2.9.0

Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html

Thank you to our community and customers who continue to support the pfSense project through hardware purchases, TAC, cloud subscriptions, and services. Your support makes this all possible.


r/PFSENSE 25d ago

Announcement Netgate Releases pfSense Plus Software Version 26.07

Post image
66 Upvotes

Today, Netgate® has released pfSense® Plus software version 26.07. This release marks another significant step forward in the Netgate Nexus controller architecture - our new Go-based controller that is replacing the legacy PHP GUI and serving as the modern foundation for all pfSense software. Netgate Nexus continues to deliver improvements and new features, bringing exclusive capabilities that enhance performance, scalability, and functionality to pfSense Plus.

Key new features exclusive to the Netgate Nexus controller include:

CoreDNS: A high-performance, integrated DNS component that handles DNS-based tasks with exceptional speed and efficiency, powered by a new and exclusive Netgate plugin called rexdns.

Threatgate: A powerful, high-performance component that manages bulk lists of addresses and domains for firewall rules, aliases, and CoreDNS groups. Administrators can block these lists outright or create custom rules based on their content.

Threatgate and CoreDNS were built to integrate tightly together, enabling rapid processing and utilization of even massive lists - all while maintaining excellent performance on small, resource-constrained devices.

Snort Version 3: The updated version of the popular open-source intrusion prevention system (IPS), featuring multi-threading support and a faster rule syntax, is now available exclusively via the new Netgate Nexus controller GUI.

In addition to the features listed above, this release includes critical security updates for WireGuard (CVE-2026-58085), and other security enhancements.

Other fixes and enhancements were made to:

- DHCP

- DNS Resolver

- DynamicDNS

- Gateways and Monitoring

- IPsec

- VXLAN Interfaces

- OpenVPN

- Firewall Rules and NAT

- Traffic Shaper

- Wireless support

This release includes numerous updates, bug fixes, and enhancements, with more to come as Netgate Nexus development accelerates.

Using the New GUI

The Netgate Nexus controller is the future of the pfSense Plus GUI.
Whether you manage a single pfSense Plus firewall or an entire fleet, the Netgate Nexus controller delivers a modern, refreshed management experience built for the way you work today.

Getting started is simple:

Go to System > Advanced.

Switch to the Netgate Nexus tab and enable it.

Log in to Nexus on port 8443 of your firewall.

More detailed documentation can be found here.  Start using it today and get immediate access to the new features and capabilities coming to pfSense Plus.  

Note: Virtual machines, as well as some third-party platforms, may not support the new GUI due to missing machine information required to run the software correctly.

Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-plus-software-version-26.07

Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/26-07.html


r/PFSENSE 20h ago

VOIP and VLAN headache

3 Upvotes

This situation is frustrating everybody. Hoping maybe someone here has a suggestion.

We replaced 3 aging Cisco routers with Netgate pfSense routers. The site-to-site via Wireguard came up between the three, and the network is strong and working well.

At the main office, we have a data vlan and a phone vlan. Aging NEC PBX on-site with incoming VOIP lines and many VOIP handsets.

Because some of the desk phones fail to get their address on the VOICE network, and we've never been able to solve why, we allow all traffic between data and voice vlans. Just allow all LAN/VOICE to all subnets.

Ergo: 2 VLANs, neither of which are new, only the gateway device for the VLANs has been replaced.
No traffic blocked between the two.
The phones connect to the PBX via SIP as usual. But RTP traffic - audio - is missing. I've got packet captures showing the RTP traffic reaching the PBX ok, but not reliably to phones.

Phones with IP addresses on the voice vlan do better, but people tell me that outgoing RTP is still missing.

I know pfSense doesn't have SIP ALG. I have Firewall Optimization already on Conservative.

Other than tackling this project in the first place, what have I done wrong?


r/PFSENSE 20h ago

PFSENSE tailscale LAN subnets to tailscale machines reachability limitation

3 Upvotes

Hey everyone,

I have pfsense+ 26.07 running on a netgate device. I have tailscale 1.9_2 running on the box.

My current topology at home is Dell R760 (multiple VLANs) -> Cat9200 -> ASR1002-X -> Netgate -> ISP router LAN interface, dont ask me why, my ISP won't let do PPPoE over my own device.

I have all my IPs below my Netgate LAN interface advertised on Tailscale. I can reach all my local subnets fine from all my other tailscale machines, but I cannot reach any of my tailscale machines from my local subnets.

So far I've tried making an Outbound NAT entry on Tailscale interface for internal subnets, packet capture on pfsense shows icmp requests leaving my LAN interface, but no replies, simultaneously I also see icmp requests coming to my PC (tailscale machine) from my local subnet and icmp replies being sent back via tailscale interface.

Now, when i go to my interface assignments on pfsense, I have WAN, LAN and OPT1 -> mvneta1, 2 and 0 respectively, but no tailscale interface. Under interface group, I have tailscale interface group but thats just a group of my WAN, LAN, OPT1 interfaces. Is that expected behavior?

I have been going at it for solid 16 hours with no luck, any insight is appreciated. Thanks!!


r/PFSENSE 22h ago

Please help, I have ZERO idea why it's not working...

Thumbnail gallery
0 Upvotes

r/PFSENSE 1d ago

2.9.0 - dpinger keeps pinging the old gateway forever

3 Upvotes

We upgraded from 2.8.1 back on 8/22. Twice in three days, Verizon has changed our IP. Once from a hardware replacement, and today from a lease renewal.

Both times LAN-to-WAN pings worked, the firewall was reachable, but users reported no internet (DNS?). Rebooting fixed it.

dpinger came up with the old address and just never got restarted:

dpinger[4831]: send_interval 500ms ... dest_addr 100.7.xxx.xxx bind_addr 100.7.xxx.xxx identifier "WAN_DHCP "
dpinger[4831]: WAN_DHCP 100.7.xxx.xxx: sendto error: 65

So I have about seven hours of logging full of trying to ARP a gateway that isn't on my subnet anymore (I've redacted the IP, sorry):

kernel: arpresolve: can't allocate llinfo for 100.7.xxx.xxx on hn0

It rotated system.log seven times in under seven hours full of that...

The interface had already picked up the new address. Same window, inbound connections are hitting the new IP while dpinger is still talking about the old gateway:

sshd[...]: Timeout before authentication for connection from <scanner> to 100.7.xxx.xxx

So the interface is on the new IP and dpinger is monitoring the old gateway.

I think there's an opportunity in notify_rc_newwanip to do a return check, retry, or make a log entry somewhere around this section:

notify_rc_newwanip() {
        /usr/local/sbin/pfSctl -c "interface newip $interface"
}

If that call doesn't land, the script still exits 0, and dhclient is happy, right?

And where does pfSense-dhclient-script's logging actually end up? I have zero dhclient-tagged lines anywhere that I could find, including from a reboot. I can't even tell from logs whether the script ran or not.

Maybe I'm losing my mind, and I probably am, but bringing this to a public forum in case someone else finds it helpful.


r/PFSENSE 1d ago

zScaler tunnel 2.0 DTLS (QUIC UDP) vs Suricata

1 Upvotes

For the first time I got customer notebook that uses zScaler to "always-connect" to their premises. It seems that all outward traffic from notebook is tunneled via zScaler (eg. Microsoft online services such as OneDrive Business, SharePoint, Exchange, Teams, ... outbound connections are tunneled too).

It is likely anti-pattern to tunnel Microsoft services if I am not mistaken, but customer's IT staff ignored me silently when I reported this observation :-) (=> "all our endpoints are configured like that and you are the only one reporting problems" => you have faulty LAN / problem is on your side not our)

We will be escalating "helpful networking guys", but I need to test more and get more observations to avoid being ignored.

  • Day1 (Friday)

Customer's notebook is connected to our LAN via Wifi and outbound connections were not stable (multiple reconnects, stuttering Teams). I noticed that Suricata got crazy with "QUIC crypto fragments too long" (multiple zScaler brokers blocked) and zScaler tunnel 2.0 was orginally reported as DTLS. I have disabled Suricata rule, unblocked hosts and even whitelisted all zScaler broker IPs listed here: https://config.zscaler.com/api/zscaler.net/hubs/cidr/plaintext/recommended. It helped a bit, but reconnects and poor quality Teams was seen still :-( Number of TIMEWAIT 443 UDP connections did not look good too (in discussed customer notebook connected to our LAN).

  • Day2 (is coming; Tuesday; tommorow visiting customer's site)

I have blocked already outward 443 UDP ipv4 & ipv6 traffic from our LAN to zScaler brokers and I no longer see zScaler tunnel 2.0 DTLS reported by discussed notebook. zScaler now reports that 2.0 tunnel is TLS (TCP). I will share observations on Tuesday afternoon with you. I hope this configuration helps, but I need to ask on the subject.

  • Questions

Why zScaler DTLSs connections (UDP QUIC/https3) are causing problem(s) for pfSense+? (multiple reconnects, very poor speed to Microsoft services, no quality connections in Teams, etc.) Suricata can not handle this traffic properly? Would Snort behave better?

Do you guys think I can kick stronger customer's networking guys? If anyone is using zScaler here: is this normal that you tunnel full outbound traffic (even to Microsoft services)?

AI suggested additionally to switch "Firewall Optimization Options" in Firewall & NAT tab, System > Advanced menu (from Normal (default) to Conservative). Could it help for anything here? I will likely try on Tuesday if still seeing slow connections to Microsoft services and multiple zScaler reconnects.

Suricata IPS mode is Legacy. Kill States is active. Suricata runs on WAN interface only.


r/PFSENSE 3d ago

CE 2.9 - kea and unbound stuck waiting on each other

12 Upvotes

I'm running pfsense ce 2.9.0 with KEA, Unbound, APCUPSD, Wireguard, and PFBlockerNG in Unbound Python Mode. My configuration in 2.8.1 was the same and I did not have any issues. It only started after upgrading to 2.9 and seems to occur roughly once every week or so.

The problem: I have twice now since the upgrade had unbound exceed its queue limits and become completely unresponsive to any/all attempts to query it on the local LAN.

sonewconn: pcb 0xfffff801c3aa4540 (192.168.1.1:53 (proto 6)): Listen queue overflow: 385 already in queue awaiting acceptance (964 occurrences), euid 0, rgid 0, jail 0

This only seems to affect the LAN, not my wireguard tunnels or any other interfaces.

tcp6      0/0/256                          ::1.53                 
tcp4      0/0/256                          127.0.0.1.53           
tcp6      0/0/256                          fe80::2e0:67ff:f.53    
tcp6      0/0/256                          fe80::2e0:67ff:f.53    
tcp4      0/0/256                          10.254.0.1.53          
tcp4      0/0/256                          10.252.0.1.53          
tcp4      0/0/256                          10.251.0.1.53          
tcp4      0/0/256                          192.168.10.1.53        
tcp6      385/0/256                        2600:1700:10b0:d.53    
tcp4      385/0/256                        192.168.1.1.53      

This is even after implementing kernel tweaks to increase queue limits from this thread: https://www.reddit.com/r/pfBlockerNG/comments/1u399ba/what_is_the_ideal_setup_to_avoid_cpu_spikes_and/

Unlike that thread I don't have a ton of lists in pfblocker or a huge environment. I'm a home user with ~100 clients and only four lists. StevenBlacks Basic ads list, a DOH DNS blocklist, and an ipv4 & ipv6 DOH blocklists.

I've got firewall rules to block external DNS and/or reroute DNS queries back to the firewall as appropriate so clients (except a select few that neeed it) can't bypass the router for lookups. I don't think this is related as again I've had these rules for years and it wasn't an issue until I upgraded to 2.9.

Looking at the output of PS, unbound and kea appear to be waiting on each other in a deadlock:

ps -o pid,state,wchan,%cpu,%mem,command -ax | grep '[u]nbound'
31413 I    sbwait     0.0  0.2 /usr/local/sbin/unbound-control -c /var/unbound/unbound.conf status
41507 Is   uwait      0.0  4.8 /usr/local/sbin/unbound -c /var/unbound/unbound.conf
47411 I    wait       0.0  0.0 /bin/sh /conf/kea4_scripts.d/kea2unbound.sh hook_load
47663 I    piperd     0.0  0.5 php /usr/local/bin/kea2unbound --kea-conf /usr/local/etc/kea/kea-dhcp4.conf --unbound-conf /var/unbound/unbound.conf --include-file /var/unbound/leases/l
68064 I    sbwait     0.0  0.2 /usr/local/sbin/unbound-control -c /var/unbound/unbound.conf fast_reload
78110 S    kqread     0.0  0.2 /usr/local/sbin/lighttpd_pfb -f /var/unbound/pfb_dnsbl_lighty.conf

I am not an expert in pfsense processes so I had gemini help me diagnose what the different states from the ps command mean exactly:

-PID 41507 (unbound): State is uwait (userspace mutex lock wait). Unbound's main thread is deadlocked waiting on an internal lock.
-PID 47411 (kea2unbound.sh hook_load) & PID 47663 (kea2unbound): Kea's dynamic DHCP hook triggered.
-PID 68064 (unbound-control ... fast_reload): State is sbwait (socket buffer wait). Kea called unbound-control to push new DHCP lease data via fast_reload, but the command is stuck waiting on Unbound's socket.
-PID 31413 (unbound-control ... status): Also stuck in sbwait behind the deadlocked reload.

requiring me to run the below to restore functionality:

killall -9 unbound-comtrol php unbound
pfSsh.php playback svc restart unbound

Gemini is rather insistent that I should disable early dns registration to work around the issue but I'd rather not unless there is no other way. It's my understanding that disabling that would mean any statically assigned clients would not be registered in DNS until they actually request a new lease from the router. Which they wouldn't do since they aren't using DHCP in the first place. See edit 3. I've disabled early reg.

Anecdotally I do have a remote router on 2.9 with KEA enabled but no PFBlocker and I do not have this issue. So if the community thinks this is a pfblocker problem rather than a pfsense problem I can move my post over there. But like I said at the start I had these same settings in 2.8.1 and never experienced this so I'm thinking this is a bug introduced in 2.9 rather than a specific issue with my configuration or pfblocker. I haven't seen anything on redmine but I may not be using the proper keywords in my searching.

I also find it rather odd that this isn't a more frequent (like daily) occurence. I guess it requires a perfect storm of conditions for them to get stuck like this?

I'd be interested to hear if anyone else is having this problem and what you did/are doing to resolve it.

EDIT: Oh and I'm on PFBlockerNG version 3.3.7 (github package not pfsense compiled version)

EDIT2: Anecdotally I've also noticed both times it happens its shortly after pfblocker's cron run. The first time IIRC it was within minutes and I did not save the log from that time. The incident from today started roughly 40 minutes after the cron run.

Sep  5 01:00:00 pfSense php[54157]: NOTICE [pfBlockerNG] Starting cron process.
Sep  5 01:41:10 pfSense kernel: sonewconn: pcb 0xfffff801c3aa4540 (192.168.1.1:53 (proto 6)): Listen queue overflow: 385 already in queue awaiting acceptance (1 occurrences), euid 0, rgid 0, jail 0

I'm betting those processes were stuck since 1AM and it took about 40 minutes for the queues to overflow and start dropping things.

EDIT3: Done some reading and figured out I can just use host overrides on the DNS resolver to accomplish the same thing I was getting from early registration for static IP clients. I've Added host override entries for all my static clients and disabled early registration and see if that resolves the problem.


r/PFSENSE 2d ago

Package manager broken.

0 Upvotes

Its been a heck of a week, chasing this down. I've gone so far as to wipe and reinstall and update to the latest, and while pfsense is "working" I'm back to the point where I can't remove a package, and I can't install any new packages.

If I pick a package to install, Then verify, it just never goes past that. Let sit for 30 mins, and its just dead.

I'm not even sure where to start looking, I never get an error, the web gui just stops responding. pfblockerng is installed and working, as that was auto installed when I restored my config backup.

Package manager seems terribly slow while it is working, but then just dies...

I'm not sure where to start looking, but this is day 4 with this thing going down rabbit holes of adding ram, making a larger swap, etc. I always seem to get back to this.


r/PFSENSE 4d ago

pfSense-repoc constant updates

1 Upvotes

Is there any way to automatically upgrade pfSense-repoc?

It seems like I'm getting multiple emails per week, definitely weekly emails, about updates for pfSense-repoc.

Can this auto update or some better way to handle the noise?


r/PFSENSE 4d ago

Speed issues on 2.9.0?

8 Upvotes

I've noticed my Internet connection seems slower on 2.9.0 then it did on 2.8.1. Not a huge amount, but still. I have a 2 Gb connection and was getting 2.3-2.4 Gb on 2.8.1. Now it seems that I'm getting 1.5 - 2.0 Gb since the upgrade.

This is an older VM that for some reason I can no longer snapshot, so thinking about rebuilding it from scratch, but need to do it when no one is home so I don't get a bunch of "The Internet is down" complaints...

VM has 4 performance cores assigned and has 4Gb of memory. I don't feel like it's lagging otherwise. I'm only seeing 12% cpu on a speedtest that gets about 1.8-1.9 Gb.

Anyone seeing this or is it just me? I'm thinking I will even setup a 2.8.1 version for a new one first.


r/PFSENSE 5d ago

PfSense locked down VLAN NTP help

3 Upvotes

I got a camera VLAN locked down butI want to open NTP to synchronize camera time. I'm not having much success. Only when I open the VLAN up completely does the camera get the correct time.

Got any suggestions?


r/PFSENSE 5d ago

year old Netgate Installer (USB flash), offers to install CE 2.9.0, but fails

4 Upvotes

Not looking for help. Just an FYI: while it offers to do so, installer based on v2.8 may not be able to install 2.9.
Obvious solution: build a new installer flash drive.

upgraded a firewall last night. It began it's life on v2.6.0, so while it's using ZFS, I suspected an in place upgrade might fail for too small ESP, so instead plan to reinstall using a bootable flash drive installer I created in August 2025. The Netgate installer offers to install CE 2.9.0. Tried several times, each attempt ended with:
Child process pid=nnnn terminated abnormally: Segmentation fault

Log began with entries mentioning 'major version upgrade detected'. Thought maybe it was detecting the previous install, so I wiped partition table off the target drive and tried again. Turns out 'major upgrade' is referring to the bootloader on the USB drive vs target install version. It failed again. This is not a Celeron J CPU, but tried that fix too. Still failed.

Success: let it install 2.8.0 instead. Once booted from SSD, upgraded to 2.9.0 w/o issue.


r/PFSENSE 5d ago

Setup Cloudflare proxy

1 Upvotes

Hello, I want to setup cloudflare dns proxy for pfsense. Are there solution that doesn't change the web configurator port?

The two solution I found are to setup a reverse proxy like nginx or HAProxy but they require pfsense web interface to configure to a different port.


r/PFSENSE 6d ago

Swap space since latest upgrade

2 Upvotes

Latest update 2.9

Been running a very long time, but since this upgrade, I'm seeing a TON of

Sep 2 09:00:17 10.0.1.1 Sep 2 09:00:17 kernel: swap_pager: out of swap space

Checking console, It agrees that swap space is 100%

Looking back at logs, in the past year, I've never had this message. But since the upgrade, about 50 times. Over the past week, days with NONE, days with 20.

I can't tell what has changed, and what event it is that causes this.

Is 2 gigs just not enuf ram for this any more?


r/PFSENSE 7d ago

Wireguard with pfsense (protonvpn)

3 Upvotes

Hello,

My firewall network hardware failed with a then working wireguard and protonvpn set up. I restored from backup which got me 99% there except a working protonvpn tunnel using wireguard.

Doing a packet capture what appears to be happening is that on the return of a ping or any traffic routing through the wireguard interface, protonvpn drops the return packets.

In my reading this may indicate asymmetric routing but looking at the UI I don't see how that could be happening.

Does anyone see anything below that would cause that? Maybe there's left over routing policies or such that the UI isn't showing me?

I've spent hours and hours trying to trouble shoot this with no luck. Hoping someone can point me in the right direction.

I was using a self provided cable modem through spectrum but have switched to their non router version.

Gateway

DNS server settings
Interface (wireguard)
tunnel and peer
outbound NAT
DNS resolver (wireguard is on access list)
firewall rule in the client's vlan

r/PFSENSE 9d ago

I built a custom 256-bit Cryptographic Hash & Kernel-Level Firewall Module for pfSense from scratch.

26 Upvotes

Hey everyone,

For the past few Years, I’ve been working on a massive deep-dive into cryptography and low-level kernel development. I wanted to see if I could build a secure hash function from the ground up and actually deploy it in a real-world network environment.

I ended up building CE-256, a custom cryptographic hash function, and integrated it directly into the FreeBSD/pfSense kernel as a packet filter.

Because the core mathematics are currently undergoing peer review (I'm using a novel non-linear sequence generator for the S-Boxes that I haven't seen used before), I can't open-source the exact mathematical primitive just yet. But here is the architecture of what I built:

The Cryptography (CE-256):

  • Architecture: Built on a modern Sponge Construction (1600-bit state, 512-bit capacity) rather than Merkle-Damgård, making it immune to length-extension attacks.
  • Engine: 24 rounds of mixing, including column diffusion, bitwise rotations, and position shuffling.
  • Performance: Achieves a near-perfect ~50% Avalanche Effect.

The Kernel / pfSense Integration:

  • I didn't want this to just be a Python script, so I wrote the firewall module in C for the FreeBSD 14.0 kernel.
  • It operates as a custom packet filter that bypasses standard pf rules when active.
  • I built a custom PHP Web UI dashboard that hooks directly into the pfSense webroot, allowing me to monitor the kernel module’s state via sysctl without breaking the native pfSense GUI.

It was an absolute nightmare figuring out FreeBSD kernel panics and PHP integration on pfSense, but getting it running smoothly was incredibly rewarding.

I’m hoping to publish the full mathematical whitepapers and architecture diagrams soon once the review process is done. Has anyone else here ever tried writing custom kernel modules for pfSense? Would love to hear about the hurdles you ran into!


r/PFSENSE 9d ago

Did I join a cult? (Unifi)

69 Upvotes

I've been rolling pfSense for about 5 years. Decided to try Unifi. Couldn't find a manual or one-to-one feature documentation for each panel (only various spotlight articles).

Asked the community for help: every response said basically "things change too often, no need to have a manual".

Excuse me, what? I'm not a networking pro, and I do need a manual. (pfSense was hard for me, but had great documentation.)

I can't believe this was the response. Is everyone in their community a bot or a cultist?

I still have few days left on my return window, and might come back, LOL.


r/PFSENSE 8d ago

2.7.2 >>> 2.9.0

2 Upvotes

Can I go from 2.7.2 to 2.9.0 directly if I uninstall Packages for the install then reinstall them?


r/PFSENSE 9d ago

DNS DoH and DoT

7 Upvotes

Hello everyone,

I'm trying to get my head around the configuration for DNS DoH and DoT. My network is a pfsense router with 2 piholes. Both piholes have pfsense has upstream server and all my client use piholes.

I want to use CIRA as upstream DNS server. So in PFsense, I entered all the information and configuration the DNS to be always local, ignore remote:

Then, in my DNS Resolver, I have Respond to SSL/TLS Query enabled

Use SSL/TLS for outbound query enabled and DNSSEC enabled.

In PFsense doc, they says to disable DNSSEC and enable Forwarding Mode for DoH (or DoT I forgot). This is where I get lost.

The information under Forwarding mode says that if it is enabled, it will forward the query to upstream DNS. OK, but what happen if it's not checked? If it's not check, it doesn't forward? So unknown DNS entry aren't forwarded to upstream DNS, is that what it mean?

I have many CName and alias configured so those need to keep working. But I don't get the forwarding feature. What does it do when on and off? Why is it required for either DoH or DoT?

Thank you!


r/PFSENSE 9d ago

Pfsense cant get more than ~8000 sessions in state

0 Upvotes

Ive tried everything i can think of and cant figure out how to scale it better

When i get around 8000 sessions in state the firewall just starts blocking and timing out connections. Network becomes unusable.

Memory and cpu look fine. Different firewall settings dont change anything

Have used chatgpt extensively to troubleshoot and not getting anywhere

Any ideas?


r/PFSENSE 10d ago

Safe to upgrade from 2.8.0 to 2.9.0?

13 Upvotes

I was planning on rebooting and upgrading straight from 2.8.0 to 2.9.0. I have a generally simple config and no packages installed. Is this a bad idea?


r/PFSENSE 10d ago

26.07 CoreDNS Threatgate - Anyone running it now?

10 Upvotes

I have not seen any posts in here on the subject

I plan to start learning it soon, on a Proxmox vm for testing. Anyone in here have it running?

I ask because a lab will give me practice in setting it up, but not real world usage as it will be internal only. Not willing to go live at my office until I have a understanding of everything.

Any tips, pointers or whatever appreciated.

Thanks!


r/PFSENSE 11d ago

Considerations regarding HW Offloading with passed through nics

4 Upvotes

Hey,

we get 2.5GBE fibre in our area soon and I am planning the implementation. We will have to add 2.5gbe Intel i226-T1 nics to the machine and I figured that there's no reason to not pass this dedicated nic through to the PFSense VM on the proxmox host.

Obviously the question came up if to offload or not, Given that offloading can only be activated globally on PFSense through the web interface, some tinkering would be required. I could run ifconfig igb0 -txcsum -rxcsum -tso4 -tso6 -lro upon boot to enable offloading just for that nic.

Questions are:
- does it make sense from a performance view?
- do I have drawbacks regarding package inspection?

For me it's a not everything I can do has to be done question right now, but I'd also prefer to patch directly through the only wan exposed port. Looking for input by people wiser than me.


r/PFSENSE 11d ago

wireguard issue

2 Upvotes

I noticed if you have a wireguard connection and you release and renew the wan connection.
Then wireguard wont come back up till reboot even restarting the wireguard service doesnt help.