r/Netgate • u/packetintransit • 18d ago
Netgate SG-2100 Max - Sale
galleryPfsense Firewall
Canada only - $400 CAD
Not used but without box.
r/Netgate • u/George-Netgate • Jun 10 '26
What does End of Life really mean? At Netgate®, it doesn't necessarily mean the end of software updates.
The Netgate 3100, an ARMv7-based appliance, reached end of sale in 2021 and EOL in 2023, yet many of these appliances are still performing critical networking duties today. That's why we continue to support hardware that customers depend on long after its official lifecycle ends. As such, we have continued to ship pfSense® software updates for the 3100 long past its formal retirement, and the upcoming pfSense Plus 26.07 release will continue to support it.
That ongoing commitment keeps us honest about a corner of the ecosystem that the rest of the industry has largely moved on from: 32-bit ARM. The wider open-source community increasingly assumes 64-bit targets, and that assumption quietly creeps into upstream code until a build breaks.
A recent example landed in our build of iprange, a small but heavily used utility from the FireHOL project for managing IP address sets. In pfSense software, iprange backs pfBlockerNG, which leans on exactly those capabilities that iprange provides. Instead of maintaining a local patch, we developed a portable fix, contributed it upstream, and worked with the project maintainer to ensure long-term compatibility across architectures.
Why does this matter?
Open source works best when companies don't just consume software, they contribute back. This is one small example of how we're helping preserve compatibility, extend hardware life, and support the customers who continue to rely on these systems every day.
Read the full story on our blog:
https://www.netgate.com/blog/keeping-the-netgate-3100-alive-one-upstream-patch-at-a-time
#Netgate #OpenSource #pfSense #Networking #Infrastructure #OpenSourceSoftware #SoftwareEngineering #ARM #NetworkSecurity
r/Netgate • u/George-Netgate • May 27 '26
Netgate® announces the release of pfSense® Plus software version 26.03.1. This maintenance software release contains over 20 fixes and enhancements, including security improvements. All pfSense Plus software users are encouraged to upgrade to this new version.
Key security improvements include fixes for:
Additional areas of improvement include:
Fixes and improvements exist in other areas as well. Please see the Release Notes for detailed information.
r/Netgate • u/packetintransit • 18d ago
Pfsense Firewall
Canada only - $400 CAD
Not used but without box.
r/Netgate • u/Work45oHSd8eZIYt • Jun 16 '26
Does anyone know if Netgate appliances support RFC 7383 for IKE fragmentation? Their chatbot couldnt help, and I can't open a ticket because I dont have TAC yet. Still evaluating.
r/Netgate • u/pshifrin • May 21 '26
Our company purchased an 8200 in December 2025 for a project that never moved forward and we are well past the return window. The unit was used once for testing and that's it. Asking $1500. Local pickup in NYC metro area or shipping within the US.
Mods please remove the post if it's not allowed.
r/Netgate • u/xaerioth • May 21 '26
Is there an expected timeline for non Netgate appliance support for this? As in, we have probably a dozen virtual pfsense machines that we'd like to be able to connect. Or is this going to be an only pfSense+ module? I get the marketing emails, but no additional details on this. Posting here, as a response would help a lot of other people too.
r/Netgate • u/OnePhilosophy5810 • May 12 '26
Hello,
I have SSL offloading running in HAProxy and a port 80 redirect to 443.
When I run ACME renew, naturally it cannot receive because of the port 80 redirect.
What is the best way to get around this problem ?
I tried creating an ACL for the path /.acme etc and then forward for that and local for not, but I didn't succeed. Needless to say, I am a brand new pfSense user, and chatGPT has given me 10 wrong solutions or so by now...
Thanks for any help 👍
r/Netgate • u/greensha3 • May 12 '26
For the past couple of days I've been try to register with for the Netgate forums. It doesn't matter which browser I try, what username I pick, whether I'm trying to do it from a work computer or home computer or with a VPN turned on or off, I keep getting the following message:

Anyone else having issues, or is it just me?
r/Netgate • u/OnePhilosophy5810 • May 10 '26
When I bought a 4200, I intended to use one port for WAN and the three others for the same LAN.
I was advised to rather use only one port and connect it to a switch, so that the 4200 got less work. Is that really a problem?
If I do want to use all 3 ports for the same LAN, do I need to make a bridge or what is the best approach?
I will use one of the ports for a switch, but prioritize another one for a server.
Thanks for your advice.
r/Netgate • u/OnePhilosophy5810 • May 07 '26
I just bought a 4200 Max, but received:
Labeled as 4200-S-USA with serial 2005xxxxxx. The USA has been hidden with a marker and EU added by hand, so it seems it was originally for the US market. The label also has: pfSense 25.11
Any concerns? Is it a refurbished?
I read somewhere that Max models start with 2008xxxxxx
And I read that older models have AMI firmware and newer have SBL.
I haven't tried to switch it on, so I have no idea if it has NVMe disk onboard.
What do you think, should I accept or return?
r/Netgate • u/MechyJasper • Apr 21 '26
I used to run a Netgate 2100 at home. I loved it, but it couldn't handle routing gigabit WAN.
About two years ago I swapped it for a janky x86 mini PC as a stopgap router, waiting for Netgate to release something with the power of a 4200 combined with something like 5GbE RJ45 or a SFP+ slot.
Unfortunately it's been quiet in the sub-800$ category since the 4200 came out, so I was starting to wonder if there are any hardware plans at this moment in or near this category?
r/Netgate • u/crusty_s0ckz • Apr 10 '26
I got a netgate 8200 for a really good deal, anyone got any good services to run on it?
r/Netgate • u/George-Netgate • Apr 01 '26
Today, Netgate® is pleased to announce the release of pfSense® Plus software version 26.03. This regularly scheduled update brings over 40 improvements, bug fixes, and enhancements. We strongly encourage all pfSense Plus customers to upgrade to the latest version.
Some new features include:
Note: There is a special message about the exciting future of pfSense software development in the official blog post.
Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-plus-software-version-26.03
Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/26-03.html
r/Netgate • u/Impressive_Fault_891 • Mar 27 '26
This is the main router in my system ,whilst I do have a spare, I am considering the recommended replacement - SG2100 which is a totally different beast internally. Would be grateful for any insights here Neil
r/Netgate • u/xaerioth • Mar 25 '26
Question for anyone still selling. As a partner, I see a lot of "Out of Stock" or "Back-ordered" for the past 6-8 months. Is the old logistics manager from Ubiquiti running the orders? Haven't seen a vendor this under-supplied since the 2020 pandemic. I get zero communications from Netgate, unless it is the usual price hike due to low supply/high demand of parts like memory and such, which I understand.
r/Netgate • u/West-Flow-577 • Mar 20 '26
So I have a NG6100 with LAN-LAN4 all bridged together. LAN goes to a switch, on that switch is the vast majority of the network, including the DHCP server (we are not using the NetGate for DHCP, we have a Windows Server doing this). Everything on the switch seems to work fine, but we are trying to test an issue with their IP Phones and the phone vendor wants us to eliminate the switch as a possible issue and so is asking us to plug a phone directly into the router.
When plugging the phone (or any other device) into LAN2-4, they don't get an IP address. When a manual address is assigned it works though.
So it seems that DHCP traffic isn't working? Do I need to set DHCP relay or something? Again, all 4 LAN ports are bridged together under OPT7, so they aren't on different network segments, they're all together, and the DHCP server is on that same network.
r/Netgate • u/[deleted] • Mar 18 '26
I didn't realize how big of a problem this was when I purchased these devices several years ago. A THIRD died tonight while trying to update to the newest version. The first one died about a month ago, then another a few weeks later. I emailed Netgate support and their actual solution is "next time buy a 2100 because you can install and SSD when the emmc dies". and sent a link to the store. What a fucking response. And of course this failure NEVER happens while it's still under warranty.
I love pfsense, but I'm disgusted with Netgate right now.. The fact that they knew about this issue for so long and it took YEARS to come up with a fix is crazy to me. Over $600 worth of dead devices and they tell me to buy a more expensive device that has replaceable storage for the next time this happens, which makes me wonder if the fix is really a fix.. Has anyone tried to replace the emmc chip? I don't want to accept that I've got 3 paperweights on my desk... Hell even if they'd just send me 3 new emmc chips I could swap them out myself and that would be fine with me. But no... Just a cold response telling me to spend more money..
r/Netgate • u/Plateau9 • Mar 16 '26
Hi folks, we have a 1537 with the add on card. I need to set up a pair of Cisco Firepower appliances but the last four available ports are 4,5,6 and 7. 6 and 7 are sfp ports. We are trying to go Cisco->Cat6->sfp but the transceivers so far are throwing the ‘Unsupported SFP+ module type was detected” from within pfsense. These were FS.com Cisco compat, second pair was Intel compat. I’ve now ordered a pair from NetGate themselves, probably should have done that to begin with.
Am I doing something incorrectly? Is there a cmd within pfsense that I can issue a command like Cisco has (service unsupported-transceivers).
Sorry, I don’t know much about these things.
Thanks for your time.
r/Netgate • u/allegiancetech • Mar 16 '26
This started with not being able to install any packages, so I tried updaing, but it kept telling me that I was up to date on v2.7.0. That led me to this post:
https://www.reddit.com/r/PFSENSE/comments/18er398/issue_unable_to_install_packages_via_the_package/
I followed the instructions in that post, which then seems to put the firewall through the motions of upgrading, but once it reboots, it is still on 2.7.0 and same issues with no packages, etc. Below is the end of the output from the upgrade:
Installed packages to be UPGRADED:
`pfSense-kernel-pfSense: 2.7.0 -> 2.7.2 [pfSense-core]`
Number of packages to be upgraded: 1
The process will require 2 MiB more space.
[1/1] Upgrading pfSense-kernel-pfSense from 2.7.0 to 2.7.2...
[1/1] Extracting pfSense-kernel-pfSense-2.7.2: .......... done
===> Keeping a copy of current kernel in /boot/kernel.old
>>> Removing unnecessary packages... done.
>>> Activating boot environment default... done.
System is going to be upgraded. Rebooting in 10 seconds.
Success
But, once it reboots, it is still at 2.7.0.
I am hoping to find a solution other than backup and reinstall, since this firewall is in a remote location and I will have to travel there to perform the re-install. Thanks.
r/Netgate • u/George-Netgate • Mar 09 '26
A new public Release Candidate for pfSense® Plus 26.03 is now available for testing!
Thank you to all users willing to test this Release Candidate. Your involvement is essential to making Netgate® 's pfSense Plus product a stronger solution for everyone.
This Release Candidate includes over 40 updates, bug fixes, and enhancements.
Some new features include:
Release Notes: https://docs.netgate.com/pfsense/en/latest/releases/26-03.html
r/Netgate • u/West-Flow-577 • Mar 04 '26
Per Title.
Like, say I have a local network of 10.0.0.0/24, and remote network of 10.69.84.0/24
I want to set up the IPSec VPN so that only traffic meant to go to the 10.69.84.0/24 network actually goes through the tunnel and all other traffic goes out the WAN without using the tunnel.
I cannot use separate interfaces to do this, I cannot use VLANs, the devices being used need to be able to "just connect"
EDIT: For example, with a SonicWall, which is what I'm used to, there's a radio button selector where I can tell it to route ALL traffic through the VPN, or only things meant for a specific remote network (I can then select that network from a dropdown listing all the Network Address Objects listed).
So how do I set it up to be similar to the second option?
r/Netgate • u/George-Netgate • Mar 03 '26
We’re excited to announce the release of Netgate® TNSR® 26.02, our latest update packed with powerful new features, expanded capabilities, and over 30 bug fixes and enhancements.
What’s New in version 26.02?
VPF High Availability State Synchronization
Allows peers to automatically re-synchronize connection data when they restart
VPF Statistics Output Filters
Users can now filter VPF connection statistics output by connection type. This makes troubleshooting and gathering NAT statistics simpler and easier to read.
Dynamic Routing Prefix-List Sequence Numbers
Input validation no longer allows sequence numbers to start at 0. Upgrading TNSR will renumber entries in the prefix list starting at 1
Release Notes: https://docs.netgate.com/tnsr/en/latest/releases/release-notes-26.02.html
Blog Post: https://www.netgate.com/blog/netgate-releases-tnsr-software-version-26.02
Learn More: https://www.netgate.com/tnsr
r/Netgate • u/0baka • Feb 24 '26
After a fresh reinstall and configuration restore, I am facing two primary issues:
To apply specific NAT rules, I attempted to assign the tailscale0 interface via Interfaces > Assignments. When assigned, the system hangs during reboot or displays the following error:
"Warning: configuration refers to interfaces that do not exist: tailscale0"
It appears the system attempts to load firewall rules before the Tailscale daemon initializes the tunnel device, causing a mismatch. I am forced to use the console (Option 1) to unassign the interface just to successfully boot.
If I leave the interface unassigned, the system boots correctly, but the Tailscale connection becomes unstable over time. It works initially after restarting the service, but eventually, I lose access from my mobile device or the remote network.
My goal is to configure Outbound NAT so that clients on my LAN can route traffic out through the Tailscale node. I have attempted to use Hybrid Outbound NAT.
Because I cannot stably assign the tailscale0 interface (due to the boot hang), it does not appear in the Transalation "Interface adress" dropdown menu, preventing me from selecting it for network translation.
I tried creating an IP Alias using the pfSense Tailscale IP to use in rules, but results have been inconsistent.
What am I doing wrong? Is anyone else experiencing the same thing?
r/Netgate • u/always_down_voted • Feb 20 '26
I have a Netgate 4100 which has it's EOL coming soon. What exactly does this mean from a cyber security standpoint? Will I miss security updates pto any CVE that may be found.