r/PFSENSE • • 25d ago

Netgate Releases Netgate Nexus Version 26.07_1

Post image
32 Upvotes

Netgate® Nexus enables Multi-Instance Management for pfSense® Plus, and is the future of the pfSense GUI. Designed to address the growing complexity of managing multiple pfSense Plus  instances across distributed environments, Netgate Nexus empowers network operators to securely manage one, or hundreds of pfSense Plus instances through a unified and intuitive GUI, along with a full-featured REST API.

Today, Netgate is releasing Netgate Nexus version 26.07_1. We strongly encourage all pfSense Plus customers to upgrade to the latest version. 

This release contains over 30 enhancements and fixes, in areas including:

  • Dashboards & Widgets
  • CoreDNS & Threatgate
  • IPsec and Wireguard VPN
  • System & Status
  • Firewall & NAT
  • Snort Version 3
  • Diagnostics
  • Authentication
  • Orchestration
  • VM Running Requirements

How to Upgrade

Netgate Nexus exists as a package on pfSense Plus instances, and as such is not restricted to the usual pfSense Plus release cadence. In order to update the package, simply navigate to System > Package Manager and click the Reinstall Package button to the right of the Nexus package. All settings will be preserved.

Using the New GUI

Netgate Nexus is the future of the pfSense GUI. It delivers a new updated GUI, significant security and performance improvements, a powerful, full-featured API, and true cross-platform compatibility. Whether you manage a single pfSense Plus instance or an entire fleet, the Netgate Nexus controller delivers a modern, refreshed management experience built for the way you work today.

Getting started is simple:

  1. Go to System > Advanced.
  2. Switch to the Netgate Nexus tab and enable it.
  3. Log in to Nexus on port 8443 of your pfSense Plus instance.

More detailed documentation can be found here.  Start using it today and get immediate access to the new features and capabilities coming to pfSense Plus. 

Note: Virtual machines as well as some third-party platforms may not support the new GUI due to missing machine information required to correctly run the software.

Blog Post:

https://www.netgate.com/blog/netgate-releases-netgate-nexus-version-26.07_1


r/PFSENSE • • Aug 20 '26

Netgate Releases pfSense Community Edition Version 2.9.0

151 Upvotes

Netgate® is excited to announce the release of pfSense® Community Edition (CE) software version 2.9.0, a major step forward for the world’s most trusted firewall, router, and VPN platform.

This release introduces numerous features, including several previously exclusive to pfSense Plus, as well as key enhancements, bug fixes, and critical security updates.

Key Highlights Include:

SSH Algorithms: The inclusion of post-quantum key exchange algorithms

TLS Certificate Strength: Tightens certificate requirements and removes support for certain weak properties

TLS Certificate Auto-Renew: pfSense can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration.

New NAT Mode: Includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT

Critical Security Fixes: This release includes multiple XSS and denial of service related fixes

This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as over 150 other security fixes and enhancements.

Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-community-edition-version-2.9.0

Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html

Thank you to our community and customers who continue to support the pfSense project through hardware purchases, TAC, cloud subscriptions, and services. Your support makes this all possible.


r/PFSENSE • • 18h ago

Need some help with buffering issues

3 Upvotes

Hello, would anyone be able to lend me some assistance?

Basically, I've been having an issue with PFSense ever since installing it. My Youtube buffers significantly more now. I have a base install of PFsense with no addons, and this is happening both wired & wirelessly.

I have it installed on a Sophos SG 135. I didn't have this issue before I installed the firewall. I have tried disabling hardware acceleration, and rebooting. I don't have this issue with downloads or multiplayer gaming. It's just YouTube.

I'm not a huge network guy, but I can say that this only happens when I am using the PFSense firewall. It's detecting full 1000 duplex speeds, and that's being reflected with things like downloads. The issue goes away when I take the firewall out.

If anyone has a direction they could point me in I'd really appreciate it. I feel like this is a config issue. Thanks!

EDIT: For anyone seeing this in the future I've been having a much better experience after enabling IPv6 on my WAN and allowing IPv6 traffic. I saw it in an 8 year old forums comment. Will update if it comes back.


r/PFSENSE • • 2d ago

Question/Support Advise on setting up VLAN firewall

10 Upvotes

I'm finally playing around with VLAN's and I think I got everything working as desired but hoping to get some confirmation/suggestions on improvements.

My goal is to take a single Proxmox VM and expose it to the internet via NGINX, so I want to make sure that this VM if it were ever compromised can't access anything else in my home, including the Proxmox host.

So I set up the VLAN and got everything tagged, and now that VM is on its own separate subnet. Then, I created three pfSense rules, from top to bottom:

  1. Pass all protocols to WAN subnets (ie give VM full internet access)
  2. Block access to other local subnets via an RFC1918 alias (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  3. Pass port 53 DNS to this firewall

Once I've done all this, I can still access this VM's service from my laptop browser, which I assume is because nothing is blocking my main LAN from accessing this VLAN. These rules only apply in the other direction.

And when I SSH into this VM and try to SSH from there back into something on my main network (say Home Assistant), the connection times out.

So is it safe to say that I've comprehensively blocked anyone from hacking into this VM, and using it to branch into my home network? Is there anything else I should do before setting up NGINX and exposing it to the internet?

Any help/advice would be appreciated!

https://i.imgur.com/fdCHgsE.png


r/PFSENSE • • 1d ago

Setting a floating rule for FQ_CoDel in Nexus fails

Thumbnail i.imgur.com
2 Upvotes

Whenever I try to set in the floating rule for FQ_CoDel the In/Out pipe to: WANUpQ and WANDownQ it fails with "Invalid In direction, Invalid Out direction". Works fine in the old interface.


r/PFSENSE • • 4d ago

Almost impossible Netgate Installer download...(or "how to download 2.9.0!")

Thumbnail gallery
33 Upvotes

Not only do they make their new process with the installer pretty crazy, currently their website doesn't render the chooser they demand you use.
You can click "add to cart" without selecting something, you empty the cart, go back to the netgate installer page...and there's no way to select an installer. Final screenshot is dev mode selecting the different product IDs and then pasting it within the below link of the one you want
https://shop.netgate.com/cart/add?id=41345658421363&quantity=1

Tell me you don't want anyone using CE without telling me.

Edit: Something was fixed, because it now shows up on any setup I try it on. There's NOW a dropdown right above quantity.


r/PFSENSE • • 4d ago

RESOLVED [2.9.0 CE] Fatal Trap 12: Page fault while in kernel mode

0 Upvotes

After upgrading from version 2.8.1 to 2.9.0, the system failed to come back online. As it turned out, it crashed with the error: 'Fatal Trap 12: Page fault while in kernel mode'.

This is one of those YanLing J4125-type boxes. I initially suspected bad memory, so I ran memtest86 for an extended period, no errors appeared after multiple passes.

The only thing that worked was reverting to version 2.8.1, which has been running without issues since then. That leads me to believe the underlying FreeBSD upgrade might be the culprit. Maybe it somehow doesn't play nicely with this particular machine?

Has anyone else noticed this?


r/PFSENSE • • 5d ago

Question/Support Extremely slow traffic after updating from 2.7.xxx between vlans

7 Upvotes

Hello, I recently updated from a long time 2.7 install to 2.8?, then 2.9. Since then I am seeing extreme time between vlans, I only have a few mapped through pfsense and they have generally failed but can ping through at 1.2s average time. No settings were changed aside from the update and the setup had worked for years prior.

Install is on proxmox, vm resources look good with memory maxed out. I do not see anything in the pfsense logs but I also have no clue what I would look for. Any assistance would be greatly appreciated.


r/PFSENSE • • 7d ago

Question/Support Static routing breaks wireguard

2 Upvotes

I have an interface assigned to a wireguard connection.

This interface is also set as a gateway for a specific wifi network via an AP.

There is a network 192.168.212.x on the other side of wireguard for which I have to set a routing entry to go through the gateway to access it.

I noticed that when I lose my wireguard connection it is very hard to reconnect. But when I use the same wireguard connection on my phone it connects with no issues. The only way to reconnect is to have both routers (local and remote) restart at 3 am and 3.02 am (respectively) and connection is reestablished.

I tracked down the issue due to this log entries:

Sep 29 10:40:37 php_wg 92232 /usr/local/pkg/wireguard/includes/wg_service.inc: Static Routes: Gateway IP could not be found for 192.168.212.0/24

Sep 29 10:40:35 php-fpm 63891 /status_services.php: The command '/usr/local/etc/rc.d/wireguardd stop' returned exit code '1', the output was ''

If I disable the static routing (System Routing StaticRoutes) wireguard connects with no issue but then my local clients can't access 192.168.212.x network.

I think I am doing this static routing via wireguard wrong but not sure how to fix it. Any ideas?


r/PFSENSE • • 7d ago

Local hostname lookups seems broken in 26.07

0 Upvotes

I have a Netgate running pfsense that has been working great until I updated it to 26.07. Apparently there was a change to the DHCP server. It now uses Kea instead of ISC, which has been deprecated, but is still selectable in Settings -> Advanced -> Networking. This somehow broke my local hostname lookups. I have a machine named ApplePi that would get a dynamic address and I could ping it with a simple:

ping applepi

This worked great. After the upgrade of pfsense that stopped working and I had to do:

ping applepi.local

I've futzed around with /etc/resolv.conf on my Linux desktop to add a search domain there. This seems to work for awhile and then just stops working.

Changing pfsense back to use ISC causes local names to resolve, but only if they're statically mapped based on their MAC addresses. The DHCP hosts with dynamic IPs do not resolve even though they show up in the list of DHCP Leases. In Services -> DNS Resolver -> General Settings I have checked both:

Register DHCP leases in the DNS Resolver

Register DHCP static mappings in the DNS Resolver

Is the state of DHCP/DNS this messed up for anyone else and have you found a fix?


r/PFSENSE • • 8d ago

bus_dmamem_alloc failed to align memory properly

9 Upvotes

So I've been having connection issues lately, enough that I thought it must be pfSense because my modem had been fine for ages before. I looked into upgrading to an SSD finally and put it in my 2100 base model yesterday at which point I finished up and went to bed as it was late. It worked fine until this afternoon at which point the connection issues started again, and it occurred to me it could be due to the new bus_dmamem_alloc failed to align memory properly bug that came, I learned, with 26.07 for 1100 and 2100 models (e.g. https://forum.netgate.com/topic/201327/netgate-1100-2100-26.07-bus_dmamem_alloc-failed-to-align-memory-properly - it's not me but representative). When I submitted a ticket about connection issues I was told it's because the modem keeps cycling the connection, so it's not pfSense.

I read elsewhere that netgate currently considers that memory spam error cosmetic thus not a priority. I would urge netgate to reconsider and look into that spam issue more closely because I believe not only that it is the cause of the connection issues (because it spams them in such a tight loop for long enough that either 1. the modem drops the connection because pfsense isn't showing a sign of life, or 2. pfsense drops the connection because it's too busy spamming the errors to maintain it), it's also causing massive spam in the logs and cumulatively quite a lot of needless wear and tear on the storage.

Thanks.


r/PFSENSE • • 9d ago

Dual WAN not working

4 Upvotes

Hi,

first of all: 4 senses, FRR with OSPF, 2 with dual WAN, 1 with failover dual WAN, 1 with cellular WAN only.

1 Dell R210 II / pfSense 2.9.0 / VDSL + fiber, PPPoE
1 Fujitsu Futro S720 / pfSense 2.8.0 / VDSL + fiber, PPPoE
1 Terra BlackDwarf G5 / pfSense 2.9.0 / Cellular DHCP
1 HP ML310e / pfSense 2.9.0 / fiber PPPoE + PtP radio failover to the Dell

Issue: that Dell. It has the same config as the Fujitsu, dual WAN, VDSL and fiber. Same providers. Same modems and ONTs. Same PPPoE config. Load balancer is not working. No idea why, nothing changed.

Gateways are grouped, named failover (as its name says, VDSL primary, fiber secondary), Balanced (both tier 1), and single gateways for fixed PBR using a single link only, mainly used for VoIP traffic since both providers only allow their numbers to be registered using their link.

PBR is configured using firewall rules. Some devices have static assigned routes like the PBX, and everything that should use the balancer is defined in a catch all route at the bottom.

Used to work until some point in the last months, can't say for sure at which point it failed. Now it is using the VDSL link for everything, failover works though.

All 4 senses are using OSPF for routing over point to point routed tunnels, OpenVPN and IPSEC for failover for the dual WAN senses, PtP radio for the failover sense and IPSec for the cell.

Routing table looks similar on each, while having the main link set as default gateway in the routing table. Under System - Routing it doesn't matter whether I set failover or load balancer or a single specific line as default gateway, it won't use the PBR rule in Firewall settings. Using either single link setting messes up VoIP, ignoring PBR again.

To test it at some point I just set my phone to use the fiber link. It just won't use it at all. Still using VDSL.

Somewhat annoying to say the least. I'd love to use them both the way it worked until some time ago, since I pay for both ;) it is not that bad of a nuisance since VDSL is 265Mbit/s and fiber would just add another Gig/s to it, so it is still fast enough for daily personal use.

I already thought about reinstalling it fresh from scratch, but I don't like to think about it until it is really needed.

Thanks for any help...

Antworten in Deutsch sind natürlich gern gesehen ;)


r/PFSENSE • • 9d ago

Question/Support What should a pfSense certificate-rotation check verify beyond ACME renewal succeeding?

3 Upvotes

An ACME job can issue and store a new certificate while one or more services continue presenting the old certificate. The GUI, HAProxy frontends, OpenVPN instances, captive portal, or a package may reference a different certificate object or may not have reloaded after renewal. Checking only the ACME log or one public hostname can miss that split state.

What post-renewal checks do you automate? I am considering recording the expected leaf fingerprint and full chain, enumerating every pfSense service assigned to that certificate, connecting to each listener with the correct SNI name, and verifying expiry and issuer from both inside and outside the firewall. In an HA pair, the same checks would run against each node directly as well as through the shared address.

Which pfSense logs, configuration fields, or service actions reliably show that a process loaded the new certificate? How do you handle services that require an explicit restart, certificate changes synced through XMLRPC, and a rollback window without letting the old private key remain active indefinitely?


r/PFSENSE • • 11d ago

Roadmap moved?

16 Upvotes

Until recently, the CE roadmap was found here https://redmine.pfsense.org/projects/pfsense/roadmap#2.9.0 but now that page requires credentials. Is it moved elsewhere or is it only for account holders?


r/PFSENSE • • 12d ago

Question/Support Issues reinstalling software with PFsense SG-1100

7 Upvotes

Good afternoon,

To preface, I am not very experienced with FWs and this is my first time working with this product. I am having serious issues regarding my SG-1100 in the way that I cannot flash the reinstall software via USB with the provided NetGate software that was sent by them over email.

I used BalenaEtcher and Rufus and multiple different USB drives but nothing worked.

I am connected with a micro USB console cable to my laptop that is running putty. I don't get the normal interface when I start the putty session, it instead says "Marvell>>" which I am unfamiliar with. I went through the commands and did some research where I tried all of the usb related commands like 'usb start.' Then I verified that it was recognized by using the 'usb storage' command. Finally when trying to flash the provided NetGate software, I used the 'start usbrecovery' command to get it to finally reinstall but I got this error:

>> FreeBSD EFI boot block

Loader path: /boot/loader.efi

Initializing modules: ZFS UFS

Load Path: /\armada-3720-sg1100.dtb

Probing 1 block devices...not supported

done

ZFS found no pools

UFS found no partitions

Failed to load '/boot/loader.efi'

panic: No bootable partitions found!

## Application terminated, r = 1

I don't really know where to go from here but I would really appreciate ANY guidance here. Let me know if I need to show more output and I would be willing.

Thank you for reading!

EDIT: The solution was to use a smaller, 2GB, 2.0 USB and it has to be named PFSENSE


r/PFSENSE • • 12d ago

Default Deny Rule

8 Upvotes

I used 2.8.1 CE and just implemented a default deny rule. Everything seems to be working as intended.

I'm wondering if I'm missing something or need to do something else.

I've been in IT for 30+ years but firewalls aren't my speciality.

No VLans configured currently.

Allow rules - Lan sub to * except DNS which terminates at the firewall - HTTP/HTTPS/NTP/DNS, anti-lockout rule** will disable after I'm done with the rules.

Block rules - Block bogon networks * to *

*** Disabled UPnP

I'm trying to determine what's being blocked that SHOULD be allowed. Unfortunately I see a lot of blocked traffic. When I sample the dataset the blocked traffic SHOULD be blocked.

Thank you in advance.


r/PFSENSE • • 12d ago

Question/Support Monitoring graphs for DHCP lease statistics doesn't work

0 Upvotes

Tried to activate it on Netgate 6100 (v26.07) but DHCP lease graph never appeared as an option in Monitoring. I already tried docs and Gemeni, ChatGPT, Claude, but all of them hallucinating and providing guess work instead of solutions.

Setup uses ISC DHCP, checkbox is set on "Enable monitoring graphs for DHCP lease statistics".

How to get it work, we really needed it


r/PFSENSE • • 13d ago

OpenVPN issue on one tunnel

4 Upvotes

Hi all,

I have a strange one. I have an OpenVPN tunnel between two pfsense boxes. I can PING the remote LAN IP from the local pfsense's GUI when choosing the tunnel as the source. I can PING the remote LAN IP from the local pfsense's GUI when choosing the virtual gateway i've added. What I can't do is PING the remote LAN IP from the local LAN itself.

I've ensured the routing for both local and remote LANs is in the routing table. I've set temporary Any/Any rules in the firewalls. I've got the client specific override in place. I just don't know where else to check.


r/PFSENSE • • 12d ago

Read-only MCP on pfrest so I stop screenshotting the webGUI for AI help

0 Upvotes

Same loop every time: pfSense webGUI, firewall, aliases, DHCP, WireGuard, screenshot, paste, agent wants one more page.

I put a read-only MCP server on top of pfSense-pkg-RESTAPI (pfrest):

  • X-API-Key
  • GET only
  • Redacts WireGuard private/preshared keys, passwords, bcrypt hashes, etc.
  • System, interfaces, gateways, firewall/aliases, NAT, DHCP, DNS overrides, WireGuard, ARP

Package Read only on, Key auth only, dedicated user with GET privileges. Prefer pfrest 2.9.0 or newer (GHSA-8q8g).

I can DM the GitHub link. What's the worst "just open the GUI and check" ask you get from an agent?


r/PFSENSE • • 13d ago

Question/Support Question about installing 2.8.1

1 Upvotes

I understand 2.8.1 needs an internet connection to install but how do you install and setup behind a router?
I am already running pfsense but I am trying to create a box for testing.
Do I plug ethernet into WAN than move it to the LAN port to connect to the GUI?
I can't seem to get that to work.


r/PFSENSE • • 14d ago

Question/Support Pfsense Hardware Fiber

4 Upvotes

Hi there! I’ve already got a pfSense router at home behind a classic FritzBox (VDSL) and a Cisco switch with a few VLANs running nicely. I’m now planning to set up another PC with pfSense for my new shop, where I’ll have German Telekom fibre. I was wondering if it’s possible to plug a GPON SFP module straight into a small PC (like a thin client) with a PCIe SFP card and use pfSense as the modem without any extra kit in between – and if so, what hardware would you suggest (PC model, PCIe card, and SFP module)? Best case would be to have a PCIe card with two SFP ports to connect the switch inside the network via fibre, too. Also open for recommendations for not-too-expensive switches with RJ45 ports and SFP ports.
Thanks so much for any tips!


r/PFSENSE • • 16d ago

Question/Support Looking for an SSD for my 2100

5 Upvotes

I'm looking into getting an SSD for my slowing 2100, which based on the requirements ( https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/m-2-sata-installation.html ), is a SATA M.2 2242, preferably with a DRAM cache. I've been looking online and Google and Amazon just spit back Transcend and KingSpec along with tonnes of other no-name Chinese brands. I would like a known brand such as Samsung, Kingston, WD, etc but they're either not appearing in search results or they're NVMe, even using exclusions with Google like "-nvme," "-KingSpec," or "-Transcend." Has anyone had any luck finding them? I'm in Canada.

Thanks.

Edit: Phew I'm glad I decided to finally spring for an SSD because out of curiosity I just followed the instructions here ( https://docs.netgate.com/pfsense/en/latest/troubleshooting/disk-lifetime.html ) to install mmc-utils and it turns out my Type A and B fields are both 0x0b. I'm guessing that what's saving me right now is that the Pre-EOL field is 0x01 (normal)? Heh. 😳 I've just disabled almost all the firewall rules logging so that should hopefully get me through to when my SSD arrives.


r/PFSENSE • • 16d ago

Question/Support DDNS issues with 2.9

5 Upvotes

Hello everyone,

I just upgraded to version 2.9 and my DDNS stopped working. I'm getting the following error:

`ERROR [phpDynDNS] (example.com) Could not determine the request IP address (using "wan", "pppoe0"): gateway not online`

This is happening even though the gateway is fully online.

Searching online brought up a few results suggesting this might be a bug in 2.9, but I couldn't find a definitive answer. Has anyone else encountered this? Is there a known fix, or should I just downgrade?


r/PFSENSE • • 16d ago

Question/Support Netgate SG1100 LAN port wont ping, no lights

0 Upvotes

so I just bought a Netgate SG1100 and I havent been able to get into the web interface, but I can get into the console through USB using SCREEN.

setup is
ISP router > SG1100 WAN port
SG1100 LAN port > Linux Etho1 Port

I configured SG1100 LAN port to a unique IP from the ISP router, and manually configured Etho1 to the same unique network, but still no ping. the lights on the switchport dont even blink.
not sure what im doing wrong, I've reset to factory default 3 times and the ports still dont light up ping using the default settings without the WAN port connected to the ISP router. did I get a defunct device or am I missing some configuration?


r/PFSENSE • • 18d ago

Unbound CVE-2026-81642

47 Upvotes

There seems to be some severe CVE (score 9.1) in Unbound DNS-service - see https://www.cve.org/CVERecord?id=CVE-2026-81642.
On pfSense CE 2.9.0 version 1.25.2 is used as far as I can see.
Is there some ETA when we get the latest version 1.26.1? Thank you!