home.social

#netgate — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #netgate, aggregated by home.social.

  1. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  2. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  3. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  4. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  5. I've decided to take the leap and update my #NetGate #pfSense box to 26.03-RELEASE. Here's hoping it's stable and doesn't do all the random lockups I was seeing that kept me on 24.0x

  6. pfSense Plus 26.03 (still a Relase Candidate) adds a “Certificate Profile” field to the Certificate Services interface. If you’re using Let’s Encrypt you can put in “shortlived” to switch to six-day certs on your web UI, HAProxy, etc. #pfSense #pfSensePlus #Netgate

  7. @ij
    Was mich bei #pfSense zunehmends mehr stört, ist der kontinuierlich steigende Druck zur #Monetarisierung seitens #netgate. Als Nutzer der CE biste immer mehr benachteiligt, und das wird so auch bewusst weiter voran getrieben. An Images kommt man nur noch mit einem Login und auch Supportinformationen im öffentlichen Forum sind nicht mehr uneingeschränkt einsehbar.

    Auch der Zwang zur Online-Installation ist dadurch motiviert und schafft für den Nutzer erhebliche Problemfälle. Beispielsweise, wenn man per #Terraform eine ganze Systemlandschaft hinter einer Firewall aufbauen möchte. Das wird dann echt zum Krampf.

  8. Kaum macht man es richtig, schon funktioniert's. Wer hätte das ahnen können!?!

    In Ruhe vorbereitet auf einem Testsystem, habe ich jetzt die exportierte config.xml überarbeitet und dabei die Einträge für openvpn, ipsec und outbound NAT entfernt. Das ließ sich auf einer frisch installierten #pfSense 2.8.1 importieren und ich bin wieder im Rennen.

    Trotzdem werde ich mir mittelfristig ansehen, ob ich nicht besser zu #opnSense migriere. In den letzten Jahren hat Firma #netgate einiges in eine Richtung gelenkt, die mir nicht gefällt.

  9. pfSense Plus 2025.11.1 is out with some bug fixes and changes including reduced TLS certificate lifetime. I had no issues remotely updating my 2100. #pfSense #pfSensePlus #Netgate docs.netgate.com/pfsense/relea

  10. For anyone using #pfsense, I wrote this little converter [1] that takes the xml and generates a #Markdown file for each interface and its firewall rules. It also generates an alias.md file that has flags of whether that alias is dead/ unused or not.

    At $DAYJOB, we have to audit our firewall rules on a recurring basis, and this is a good way for us to update our docs quicker.

    [1] gitlab.com/jeremygonyea/pfsens

    #netgate #pfsese #exporters #audit #sysadmin

  11. @homelab_de

    Motiviert durch die Telekom, die ungefragt Daten über meine Geräte im LAN erfasst und auf deren Kundenportal für mich "aufbereitet", möchte ich gerne meinen Speedport als DSL-Modem nutzen und dahinter meine eigene Firewall, DNS-Infrastruktur, Wifi, DHCP betreiben.

    Als Firewall schwebt mit eine Netgate Appliance mit PFSense CE vor.

    Zwei 1 Gbit/s Ports reichen. Ich würde den "LAN" Port ohnehin als Trunk mit tagged VLANs konfigurieren (DMZ und LAN-VLAN)

    Ich würde darüber auch gerne Wireguard als VPN einsetzen (was über ein separates Paket möglich ist).

    Hat jemand Erfahrungen mit PFSense auf Netgate Appliances?

    shop.netgate.com/products/1100

    #pfsense #netgate #homelab #selfhost

  12. After another major change to my #NetGate setup, I finally remembered to save another damned local backup. I'm still a little amused at the 4ish whole megabytes it's worried about when I back up RRD data as well.

  13. The beta cycle has started for pfSense Plus 25.11. There don’t seem to be any release notes yet but here are the open bugs. redmine.pfsense.org/versions/82 #Netgate #pfSense #pfSensePlus

  14. pfSense Plus 25.07 release candidate is out! I updated my Negate 2100 and everything seems good so far. #Netgate #pfSense #pfSensePlus docs.netgate.com/pfsense/relea

  15. 🦾 Why I use OPNsense over pfSense, and why I don't trust Netgate at all • Adam Conway

    「 From domain disputes, licensing changes, security issues, and more, there's a lot that simply doesn't sit right with me. That's not to say that OPNsense is perfect, but the company's negatively perceived actions have not been anywhere near as controversial 」

    xda-developers.com/why-use-opn

    #OPNsense #pfSense #freebsd #netgate

  16. Hey Fedi, was ist denn Deine Meinung zu #Netgate Firewalls? Ich würde gerne mein Heimnetz etwas besser unter Kontrolle bringen und unnötige Trackingkommunikation von "smarten" Geräten unterbinden und am liebsten auch die ganzen anderen Privacy-feindlichen Vorgänge, denen man täglich so ausgesetzt ist, schon auf Netzwerkebene blockieren. Taugen die Geräte von Netgate was oder ist das überteuert? Wie geht Ihr mit dieser Sache um? Ist-Zustand ist sehr basic: Bislang habe ich nur eine Fritzbox, AVM-Mesh-APs und ein paar unmanaged Switches für die Ethernetkabel.

    #followerpower #firewall #privacy #fragfedi #boost

  17. #Netgate #pfSense CE 2.8.0 is here! I knew it was on the way, but wouldn’t have placed any bets on it beating 25.03 out the gate. netgate.com/blog/netgate-relea

  18. Something strange with my #Unifi gear...

    Recently replaced my UDM Pro with a CloudKey Gen2 Plus (because I don't need the gateway function as my #Netgate #pfSense is taking care of this).

    According to the screenshot, my WiFi APs are offline as well as the Protect cameras.
    But: both are working.

    Maybe that's because of the "management" VLAN 31 instead of default VLAN 1?

  19. Just realized that my #pfSense #Netgate 6100 has 4x 2.5 GbE ports. At least my #Unifi switch reports 2.5 GbE now... before connecting to the switch those ports were connected to the UDM Pro, which only has 1 GbE...

  20. I‘m reworking my #homelab rack setup. First two pics are before (from last year), the other two pics are the result of todays work. Alas, some cables need to be exchanged, though…

    Lately I replaced the # Unifi Standard 24 PoE switch with Pro HD 24 PoE with Etherlighting. And the #Netgate 6100 #pfsense has replaced the UDM Pro as gateway and Firewall…

    EDIT:
    the A1000 and the Indy were removed from the rack. The UPS and the server moved some RUs higher. The purpose of the upper patch panel is to be able to use the short cables from above/below. In the back the connection goes hidden from the Pfsense to the UDM Pro ports.

    Only annoyance: Why is are the port of the Unifi patch panel not labeled?! Hmpf...

  21. #pfsense service toot:

    Using #ACME certificates on your #freeradius for wifi authentication and things stop working after 60 days when the cert renews?

    in the acme configuration add the follwing php-command to the actions list:

    require_once('/usr/local/pkg/freeradius.inc'); freeradius_eapconf_resync(true);

    (Long time lingering bug in pfsense, #netgate is not willing to fix)

  22. I'm coming into the #pfsense vs #opnsense debate way late, and I'm too ignorant to take a side right now. I did get a #netgate box on a recommendation, that's currently sitting in my desk only hooked up to a serial console.

    But otherwise, no skin in the game currently.

  23. peculiar problem, #wireguard between #mikrotik #routeros and #netgate 2100 #pfsense. R->P is fully saturating the link ( 50Mbps ) while P-R is at its 1/100th ( link is 500Mbps ) and it barely does 5Mbps. Thats TCPv6. UDPv6 is only doing 1Mbps. Tests with #iperf3

  24. peculiar problem, #wireguard between #mikrotik #routeros and #netgate 2100 #pfsense. R->P is fully saturating the link ( 50Mbps ) while P-R is at its 1/100th ( link is 500Mbps ) and it barely does 5Mbps. Thats TCPv6. UDPv6 is only doing 1Mbps. Tests with #iperf3

  25. peculiar problem, between and 2100 . R->P is fully saturating the link ( 50Mbps ) while P-R is at its 1/100th ( link is 500Mbps ) and it barely does 5Mbps. Thats TCPv6. UDPv6 is only doing 1Mbps. Tests with

  26. #KeaDHCP on #Netgate #PFSense Apparently you folk haven't figured out that there are people who may have devices that need to be able to switch between multiple mac addresses with the same IP address, say a printer with both wireless and wired connections, but it can't use both at the same time. In fact at this time the printer can't seem to figure out how to work with the infrastructure wireless at all, but that's on HP.

  27. #KeaDHCP on #Netgate #PFSense Apparently you folk haven't figured out that there are people who may have devices that need to be able to switch between multiple mac addresses with the same IP address, say a printer with both wireless and wired connections, but it can't use both at the same time. In fact at this time the printer can't seem to figure out how to work with the infrastructure wireless at all, but that's on HP.

  28. #KeaDHCP on #Netgate #PFSense Apparently you folk haven't figured out that there are people who may have devices that need to be able to switch between multiple mac addresses with the same IP address, say a printer with both wireless and wired connections, but it can't use both at the same time. In fact at this time the printer can't seem to figure out how to work with the infrastructure wireless at all, but that's on HP.

  29. "🔥 pfSense Security Alert: Critical Vulnerabilities Uncovered by SonarCloud 🛡️"

    SonarCloud's vigilant scanning reveals two critical vulnerabilities in pfSense, a widely used open-source firewall: XSS (CVE-2023-42325) and Command Injection (CVE-2023-42326). These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on pfSense appliances, highlighting the importance of continuous security vigilance even within trusted network perimeters. Thanks to swift action by Netgate, patches are now available. A reminder to always keep your systems updated!

    📚 Source: Oskar Zeino-Mahmalat's article on SonarSource SonarSource Blog

    Tags: #pfSense #Cybersecurity #Vulnerabilities #XSS #CommandInjection #Netgate #SonarCloud #SecurityPatch 🚨🔒💻