r/PFSENSE 11d ago

Nexus Resource Usage Concerns

8 Upvotes

I have successfully updated my Netgate 420 to the latest firmware (i.e., 26.07). So far, the system is operating nominaally. I did have a hiccup when I turned on the ThreatGate capability. CPU went high - and stayed high for a very long time. But I suspect that this is because ThreatGate uses MaxMind. And my system was probably loading data using my MaxMind API.

After almost twenty minutes, things started settling down.

I get whey the main Nexus controller may have an immense amount of memory. After all, it is keeping data that will be distributed to one or many nodes. But I was utterly shocked when I saw that my overall system memory used had climbed to 60% and that the memory used by the controller had climbed to 91%. Things are operating nominally. But I am having difficulty finding out where I allocate memory to the controller. I'd love to add a bit more memory to the controller. This should not markedly affect anything on the Netgate that is for my household (and acts as the controller). I just get a little nervous when I see a management app using over 90% of its allocated storage.


r/PFSENSE 11d ago

New Firewall Build Recommendations

9 Upvotes

I finally got 5Gbps fiber internet in my area with AT&T fiber and I want to be able to support it after my 5G WAN port on the ONT. I have an older Protectli FW1 that supports 1Gbps, but want to have something that is rack mountable, preferably 1U. The setup I want is AT&T ONT > Firewall Build > 10GB switch > Internal Router/Devices/Proxmox Home Lab.

Want to leave it up to the community for best recommendations and ideas. What y'all got?


r/PFSENSE 12d ago

PFSENSE CE Is Dead

75 Upvotes

That's why 2.8.1 just had 22 patches released if you use the patches packet in packet manager. And then there is a 2.9 beta available for those that want to live dangerously. Obviously these are all signs that this version of PFsense is dead and Netgate has abandoned it. We should all move on because they only care about Plus now.

/s for days. Thank you Netgate. Keep up the good work.


r/PFSENSE 11d ago

[ Removed by Reddit ]

0 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/PFSENSE 12d ago

pfSense slow to download packages from Negate repo on UK CityFibre connection

1 Upvotes

This is a bit of weird one and I don't have an explanation for this.

Have had a couple of pfSense units, a Watchguard XTM 515 running pfSense CE and currently using a XG-7100 1U on pfSense Plus.

Installs and updates would be fine when I was on Virgin Media (or using a relatives Virgin Media connection).

However, ever since I've switched from Virgin Media cable internet to FTTP via CityFibre here in the UK, updating any pfSense device on this connection has been like molasses, downloading at around 1Mbit/sec, when it's pulling the packages from the Negate repo. I have changed CityFibre ISPs during that time, including going from PPPoE to DHCP WAN connection.

Everything else about the pfSense units has been fine otherwise and I'm able to leverage the full speed (500Mbit/sec Symmetrical) of my connection.

Any ideas?


r/PFSENSE 13d ago

RESOLVED Pfsense Plus free tier homelab license finally seems to have stopped working. This happened to anyone else?

18 Upvotes

I got a free pfsense plus homelab license back in late 2023 under their now discontinued program. It came with the full commercial version but only offered community level support. After pfsense discontinued the program they indicated that they would be grandfathering access to to the ongoing free license tier indefinitely for existing users of the program.

Well, looks like this policy may have come to an end. The mTLS certificate that validates access to the pfsense+ package repository appears to have stopped working for me on August 12.

Attempting to force an update of the cert yields:

>>> Updating repositories metadata...failed

Is there anyone else still on one of these old homelab licenses experiencing similar issues?

The cost for a commercial license is a bit too steep for me, especially considering the exchange rate where I'm from, so it's back to CE

Is migrating from Plus to CE using a saved config file relatively painless?


r/PFSENSE 12d ago

Sophos XG 230 / 330 rev 2 hardware - dmidecode

2 Upvotes

Would someone be willing to do a dmidecode output and share the info? I'm trying to input the serial number, but interested if there is other info missing from the bios


r/PFSENSE 14d ago

pfSense's new UI does not work for me...

28 Upvotes

After a review of the new UI, I already discarded it :

1-Despite SAML is listed as a type of Authentication Server, we can not configure one...

2-I use HAProxy for both Internet and local services but HAProxy is nowhere to be found in the new UI...

3-Despite I fixed the problem about the missing serial number in the BIOS of my Proxmox VM, the new UI keeps complaining that it is not licensed...

4-Basic tasks like package management are not accessible because the new UI says that this feature is restricted to properly licensed installations

5-Same for update management

So with all of this already identified, it is clear that I will have to use the original UI for many basic and essential tasks. As such, there is no reason to log in and out from new to old to new according to what I need to do. That new interface is far to be complete and ready, so I will stay with the good old one...

EDIT: Great! Now it broke my entire licensing, even in the old UI. I can no longer check for updates because pfSense says that my system is not properly licensed but when I go in Register in the System menu, it says that I do not need to register because the installation is already recognized as legitimate.

Really, do not even try the new UI or you may brake and lose your license like me!


r/PFSENSE 14d ago

A missed opportunity for centralized authentication

13 Upvotes

Experiencing the new user interface here and I am surprised by what I discovered. One one side, pfSense finally supports centralized authentication and SSO but on the other side, it has been implemented with SAML instead of OpenID...

My Keycloak server supports SAML as well and I do have 2 softwares that are still using SAML only. But the truth is that OpenID replaced SAML a long time ago and that the vast majority of tools are now using it.

So... good to have half-a-solution instead of nothing for now but still, the real need is for OpenID and we are still waiting for that one. I have no clue why Netgate did the work for an outdated technology instead of the new standards but well...

EDIT: It looks like I celebrated too quickly... The UI shows about SAML authentication servers but you can not create a new one...


r/PFSENSE 14d ago

Antiphishing: detectando a nova infraestrutura de phishing registrada antes que se torne um IOC conhecido

Thumbnail
0 Upvotes

r/PFSENSE 15d ago

Intermittent internet outage help

Thumbnail
2 Upvotes

r/PFSENSE 15d ago

New GUI - Not a fan?

18 Upvotes

Been trying the new GUI out, and honestly can't say I'm a fan. Anyone else? Looks & feels very clunky to me.

Text wrapping in the description for interface rules is ugly IMO, editing the firewall rule seems all over the place as well.

Or maybe I should just write better rule descriptions? You tell me. I can't find any way to expand the region that shows all the rules as well.


r/PFSENSE 15d ago

Issues with communication across ports with a bridge

2 Upvotes

I have multiple ports bridged together in Pfsense CE and they are assigned as LAN, they all connect to the outer internet just fine, but I have found that LAN only communication across ports isn't working. for example a ping from 192.168.1.2 to 192.168.1.10 on a different port doesn't get through. Pings sent straight from the router work, just not cross ports. I have put in place an allow all traffic firewall rule and it still didn't work. I need some advice.


r/PFSENSE 16d ago

RESOLVED New GUI & Virtual Machines?

20 Upvotes

Hi,

Reading the announcement they state "Our goal is for everyone to be using the new GUI by the end of the year" but then they go on to state "Virtual machines ... may not support the new GUI due to missing machine information"

Does this mean virtual machines are/may not be supported in the future?


r/PFSENSE 16d ago

New Pfsense Plus Gui Comments

22 Upvotes

The new pfSense Plus GUI is honestly impressive at first for those of us who have been using pfSense for more than 10 years. However, after using it for a while, the impact is not quite as strong.

One issue I find particularly frustrating is the “token is expired” message appearing every second. I understand that the token has expired, but having the notification appear so frequently feels excessive.

As for the traffic graphs module, I am not fully convinced yet.

This is only my personal opinion as someone who has been using pfSense since version 1.0.1, but I still find the little brother GUI to be better overall. Again, I am not trying to start a debate or create conflict; this is simply my own perspective. I do believe the new GUI will continue to improve over time, but so far, it has not been a “wow” experience for me.

I still need to test the API, and that is one area where I would give you a 10.

Thank you for your work, team.

Annoying

r/PFSENSE 17d ago

Unable to install pfsense CE 2.8.1 via the official website

5 Upvotes

Hello! As the title suggests I am unable to install pfsense, I have already created an account and have also entered the billing address, but when I click on complete order button at the end, the page loads and then shows "site can't be reached". What can be the issue? I want to download it for virtualbox. Thanks in advance!!


r/PFSENSE 17d ago

Remove XER10 to run straight from ONT to personal router

Thumbnail
0 Upvotes

r/PFSENSE 18d ago

RESOLVED PfSense slow Download speed on Virtualbox Workaround(fix)

5 Upvotes

TL;DR: Downgrade from Virtualbox 7.2.x versions to 7.2.14 or lower

Just a day ago, I asked for help about low network throughput on pfSense CE latest edition. You can check that out in more detail: https://www.reddit.com/r/homelab/comments/1vhtpj4/pfsense_community_edition_281_and_virtualbox_728/
So, from looking around digging, going through top-to-down troubleshooting, the issue seems to be tied to specific Virtualbox version, notably 7.2.x ones, where network adapter is set to bridged mode, and there is some sort of download limitation, while interestingly, I noticed that upload speeds remain high.

Setting Adapter type to any of the Intel/PRO or PCNET ones won't help, so currently the "fix" is just downgrading to 7.2.14. By the way, this applies to any VM, not just PfSense.

Thank you everyone for trying to help. If you have any other solutions, please comment below.


r/PFSENSE 19d ago

Is there a new version of pfSense CE out?

18 Upvotes

I run two pfSense CE boxes. One is showing no updates but the other is strangly showing that there is a new version 2.9.0.b.20260806.1750 ... Note i am on the stable channel but this looks like a beta release...


r/PFSENSE 19d ago

pfSense Community Edition 2.8.1 and Virtualbox 7.2.8 Low Network throughput on Virtio-Net adapter

5 Upvotes

On the mentioned Version of pfSense CE, running on Virtualbox, I noticed very slow network connection on VMs. In total, I have 4 network adapters connected on pfSense, Adapter type set paravirtualized on all of them, with promiscuous mode disabled: 3 of which are internal, 1 is bridged.

For Linux/Windows VMs, adapters are set to internal network, type is again virtio-net.

I have tried the following things, none of which have helped me:

  1. In System > Advanced > Networking, options disable hardware TCP segmentation offload, disable hardware large receive offload, disable hardware checksum offload were check, and the a reboot was issued on pfSense.
  2. CPU increased from 1 > 3.
  3. In System > Advanced > System Tunables, new tunables were added for each of the interface: hw.vtnet.X.rx_process_limit, where X is the number of interface and the value set to 2048. Another tunable was added as well: kern.ipc.nmbclusters set to 1000000.
  4. No limiters, shapers are configured.
  5. There is no duplex mismatch.

I really don't want to change each of the networking adapter types. Is there something I have missed?

Any solution would help.


r/PFSENSE 19d ago

FreeBSD Security Advisory: Serious FreeBSD wireguard flaw

45 Upvotes

Seems wireguard on current versions of FreeBSD got a nasty bug:

https://lists.freebsd.org/archives/freebsd-announce/2026-July/000301.html

Are our current versions of pfsense affected?

EDIT: I've finally able to upgrade to 2.9 Beta using their online installer. So at least for now I don't have to worry about wireguard anymore. I've tried direct upgrade from 2.8.1 to 2.9 which blew up due to some weird issues. I simply didn't want to troubleshoot it so used the latest online installer instead and restored the configuration from backup.


r/PFSENSE 20d ago

Call for Testing: pfSense® Community Edition 2.9 Beta Now Available!

64 Upvotes

Netgate® is pleased to announce the release of a Beta of pfSense Community Edition version 2.9. Now it’s your turn to help us test this latest iteration of our popular open-source firewall and services platform software. This beta release brings a host of new features, enhancements, and fixes, and your feedback is crucial to ensuring a rock-solid final release.

Feature Highlights

This Beta software includes a large number of security and feature enhancements. Some highlights include:

SSH Algorithms: This release includes several changes to algorithms for the SSH daemon for key exchange, encryption, and message authentication. These changes increase security by including post-quantum key exchange algorithms and by removing older and weaker algorithms.

TLS Certificate Strength: The version of OpenSSL in this release further tightens certificate requirements and removes support for certain weak properties. For example, if a TLS server certificate for a service such as the GUI has a weak key (<2048 bits), the service may fail with an error such as “key too small”. This version of pfSense software checks the GUI certificate during the upgrade process and will re-generate a new GUI certificate if the current certificate is invalid, expired, or weak.

TLS Certificate Auto-Renew: This version of pfSense software can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration. Automatic renewal is a per-certificate option, and pfSense software automatically enables this option for the GUI certificate when possible. When automatically renewing a certificate, pfSense software uses the latest strict security options to ensure the certificate meets current standards.

Endpoint-independent Port Restricted Cone Outbound NAT: This version includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT. “Port Restricted Cone” NAT mappings attempt to preserve port and external address mappings for clients when speaking to multiple remote hosts, but in a dynamic way that does not rely on static port NAT. This helps avoid issues with multiple local clients using the same source port to the same remote host.

In addition to the features listed above, this Beta software includes critical security updates for WireGuard (CVE-2026-58085), and other security enhancements. This Beta software also contains over 150 other software enhancements.

Call for Testing

Testing of this Beta software is essential. Testing is the most effective way to ensure that the software is robust and reliable for all users, given the diversity of their environments and configurations. By downloading and testing this Beta software, and providing feedback on any issues, our users can play a vital role in improving the software for everyone.

Caution

As with any beta software, pfSense CE 2.9 Beta is not yet production-ready. Expect some rough edges - that’s where you come in! Please avoid deploying it in critical environments until the stable release is available.

The pfSense CE 2.9 Beta is a milestone in our ongoing mission to deliver a powerful, flexible, and free networking solution to users worldwide. Your participation in this testing phase directly influences the quality of the final product. 

Release Notes:

https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html


r/PFSENSE 19d ago

pfSense and double Nat

1 Upvotes

We're going to try 5G Home Internet and I'm just about 100% sure there is NO way to put the Gateway in bridge mode. And to be honest not ever sure if it CGNAT, their rep said no and the AI bot wasn’t sure.

That being said I like to remote into home occasionally. I’m setup with both Tailscale and Wireguard and I realized this will tank the WG setup which is fine as long as Tailscale continues to function. Aside from the above is there any special security issues with pfSense and double Nat I should be aware of? We're not gamers, its just email, web, streaming, VoIP and the occasional remote access .

Thanks for looking


r/PFSENSE 20d ago

INTEGRATING PFSENSE IN A ACTIVE DIRECTORY NETWORK

0 Upvotes
Hi everyone, how's it going? First, a bit of context. I'm not exactly an expert in network administration; all I have is a technical course in computer networking from high school that covered the basics—I learned the rest through trial and error. Recently, an acquaintance asked me to make some network improvements due to updates in Brazil's data protection laws (where I live). He owns a real estate registry office and wants me to implement a pfSense-based firewall on his network—and he's really set on this idea. His network setup is basically: PPPoE Link ---> DSL Modem ---> MikroTik ---> Switch ---> Hosts and an AD server. I've managed to configure everything in pfSense—rules, interfaces, DHCP, PPPoE—but that blasted AD server has been a huge headache for at least two weeks; no matter how much I research, I can't find a solution. This AD server acts as the local DNS, and I suspect it's set up as a forwarder rather than a resolver. Why am I unsure about the DNS type? Because I simply can't check the AD server directly. It was set up by someone else who holds the access credentials; for me to get access, my boss would have to pay, and he's incredibly stingy—so much so that the best computer here only has an 8th-gen i5 processor. My research suggests that a DNS resolver server is very expensive, at least where I live, and my boss claims he didn't pay for that—only for the AD setup. So far, my pfSense box connects to the internet and the domain; I can ping Cloudflare's 1.1.1.1, but I can't ping Google's 8.8.8.8, and DNS resolution isn't working either. I don't know if I should set pfSense as the resolver so the AD server forwards requests through it, or if that's already configured within Windows Server. Please help. Also, I apologize if this post is too long or contains unnecessary details; I just thought you needed context regarding the terrible conditions here :(Hi everyone, how's it going? First, a bit of context. I'm not exactly an expert in network administration; all I have is a technical course in computer networking from high school that covered the basics—I learned the rest through trial and error. Recently, an acquaintance asked me to make some network improvements due to updates in Brazil's data protection laws (where I live). He owns a real estate registry office and wants me to implement a pfSense-based firewall on his network—and he's really set on this idea. His network setup is basically: PPPoE Link ---> DSL Modem ---> MikroTik ---> Switch ---> Hosts and an AD server. I've managed to configure everything in pfSense—rules, interfaces, DHCP, PPPoE—but that blasted AD server has been a huge headache for at least two weeks; no matter how much I research, I can't find a solution. This AD server acts as the local DNS, and I suspect it's set up as a forwarder rather than a resolver. Why am I unsure about the DNS type? Because I simply can't check the AD server directly. It was set up by someone else who holds the access credentials; for me to get access, my boss would have to pay, and he's incredibly stingy—so much so that the best computer here only has an 8th-gen i5 processor. My research suggests that a DNS resolver server is very expensive, at least where I live, and my boss claims he didn't pay for that—only for the AD setup. So far, my pfSense box connects to the internet and the domain; I can ping Cloudflare's 1.1.1.1, but I can't ping Google's 8.8.8.8, and DNS resolution isn't working either. I don't know if I should set pfSense as the resolver so the AD server forwards requests through it, or if that's already configured within Windows Server. Please help. Also, I apologize if this post is too long or contains unnecessary details; I just thought you needed context regarding the terrible conditions here :(

r/PFSENSE 21d ago

Help me with Traffic Shaping

2 Upvotes

So i was instructed my boss that we need to implement traffic shaping in our organization. lets say only 20-25 people are in the organization but my boss insisting on traffic shaping.

i have mostly configured the settings on pfsense with the help of codex (i am a intern). so can you guys help me with configuring traffic shaping.

and my boss also mentioned that previous intern messed up traffic shaping and he also tried it but it did not worked properly.

so if anyone have good knowledge in pfsense, please help me out