Categories

  • 380 Topics
    1k Posts
    M
    Following up on this.. EVPN at the control plane with a anycast gateway would help here....
  • 122k Topics
    784k Posts
    tinfoilmattT
    Modems don't issue IP addresses. It looks like it's just traffic 'bouncing around' the ISP's environment, outside OP's firewall. @larryjb When you screencap the firewall log and obfuscate your external IP, it'd be helpful for troubleshooting purposes to leave the destination port visible. This is at the bottom of the firewall log: [image: 1786649810354-7b34f973-ee45-4d76-a0bd-018a8dfa9c07-image.png] You might consider unchecking all those boxes like I've done to disable unnecessary WAN block logging like this. It will degrade the lifespan of your storage device and gum up your firewall log, as you're seeing here.
  • 21k Topics
    130k Posts
    dennypageD
    FYI, I've updated the pfSense package in the first post with an updated status page. It's still based on chronyc, but is better organized and more efficient. It also offers control over data refreshing. Source is viewable here for those interested. One handed Javascript coding is so much fun!
  • 43k Topics
    268k Posts
    JeGrJ
    @slu said in HaGeZi DNS Listen (alt. Link): @JeGr danke ich bin überzeugt. Das bedeutet das DNS Setup wäre: Client -> pfSense -> Pi-hole -> Provider DNS anstatt: Client -> pfSense -> Provider DNS Nein, tatsächlich ist das Setup - wie es in meiner Welt auch am meisten Sinn macht: <Clients_aus_diversen_VLANs> --> <PiHole(s)> --> <pfSense> --> Upstream Grund sehr simpel: PiHole und AdGuard nutzen DNSmasq daher schnell und RAM freundlich. Aber DNSmasq braucht nen Forwarder. Der ist pfSense mit Unbound, der wiederum im Resolver Mode DNS via Root DNS Server macht und damit weniger anfällig gegen DNS Probleme an einem SPOF ist (1.1.1.1 down - egal) DNSSEC sauber machen/beantworten kann (bei Forwarding ist die Information oft wertlos, weil dem Forwarder vertraut werden muss) Du dann auf Unbound nach wie vor deine internen Überschreibungen und Hosts definieren kannst ohne das alles im Pihole zu managen Du damit die Sense selbst und ggf. ein zwei spezifische Geräte vom DNS Blocking ausnehmen kannst (bspw. pfSense, Hypervisor und NAS sprechen direkt weil wenig DNS notwendig aber wichtig dass es zu Updates läuft - alles andere spricht via internem DNS Pi). Und wenn man irgendwann total abfährt, kann man sich statt dem Unbound auch ein DoHoT Konstrukt dazwischen werfen und das dann nutzen
  • Information about hardware available from Netgate

    3k Topics
    21k Posts
    stephenw10S
    Hmm, that's odd. I wouldn't expect anything to be running with it disabled. Perhaps something had failed to stop? Had it been rebooted?
  • Information about hardware available from Netgate

    44 Topics
    211 Posts
    AriKellyA
    It looks like unified web management could be coming soon. It would be great if it means easier control and management of all web services in one place. Let's see if any companies announce more details about it!
  • Feel free to talk about anything and everything here

    4k Topics
    19k Posts
    stephenw10S
    You should just set the identifier to something specific but valid. So I'd use FQDN, it doesn't change with actual IP address used. It only needs to match at each end.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
Privacy Policy · Cookie Policy

Looks like your connection to Netgate Forum was lost, please wait while we try to reconnect.