r/PFSENSE Jun 10 '26

Keeping the Netgate 3100 Alive, One Upstream Patch at a Time

42 Upvotes

What does End of Life really mean? At Netgate®, it doesn't necessarily mean the end of software updates.

The Netgate 3100, an ARMv7-based appliance, reached end of sale in 2021 and EOL in 2023, yet many of these appliances are still performing critical networking duties today. That's why we continue to support hardware that customers depend on long after its official lifecycle ends. As such, we have continued to ship pfSense® software updates for the 3100 long past its formal retirement, and the upcoming pfSense Plus 26.07 release will continue to support it.

That ongoing commitment keeps us honest about a corner of the ecosystem that the rest of the industry has largely moved on from: 32-bit ARM. The wider open-source community increasingly assumes 64-bit targets, and that assumption quietly creeps into upstream code until a build breaks.

A recent example landed in our build of iprange, a small but heavily used utility from the FireHOL project for managing IP address sets. In pfSense software, iprange backs pfBlockerNG, which leans on exactly those capabilities that iprange provides. Instead of maintaining a local patch, we developed a portable fix, contributed it upstream, and worked with the project maintainer to ensure long-term compatibility across architectures.

Why does this matter?

  • Keeps existing Netgate 3100 deployments running securely and reliably
  •  Reduces technical debt for maintainers and users alike
  •  Strengthens the open-source ecosystem for everyone

Open source works best when companies don't just consume software, they contribute back. This is one small example of how we're helping preserve compatibility, extend hardware life, and support the customers who continue to rely on these systems every day.

Read the full story on our blog: 

https://www.netgate.com/blog/keeping-the-netgate-3100-alive-one-upstream-patch-at-a-time

#Netgate #OpenSource #pfSense #Networking #Infrastructure #OpenSourceSoftware #SoftwareEngineering #ARM #NetworkSecurity


r/PFSENSE May 27 '26

Now Available: pfSense Plus version 26.03.1

70 Upvotes

Netgate® announces the release of pfSense® Plus software version 26.03.1. This maintenance software release contains over 20 fixes and enhancements, including security improvements. All pfSense Plus software users are encouraged to upgrade to this new version. 

Key security improvements include fixes for:

  • Potential Stored XSS in diag_arp.php when using ISC DHCP
  • Potential XSS in RSS Widget feed content post titles
  • Potential XSS in Captive Portal widget
  • Fixes for vulnerabilities discovered in the DHCP client
  • Several base system packages were updated to address various upstream security issues.

Additional areas of improvement include:

  • Aliases/Tables
  • LDAP Authentication
  • Captive Portal
  • Console Menu
  • Dashboard
  • IPsec
  • OpenVPN
  • Firewall Rules/NAT

Fixes and improvements exist in other areas as well.  Please see the Release Notes for detailed information.


r/PFSENSE 11h ago

Making PFSense more stable when WAN/internet link goes down

5 Upvotes

I have had some issues with my PFSense (CE 2.8.1) becoming unstable for my home network when the internet link (WAN interface which is DHCP) goes down or becomes unstable. I find that routing across the home network is badly effected in this situation.

I use PFSense for as my main home network router and use 2 VLANs (IoT and Secure), DNS (DNS Resolver), DHCP etc.

I think I have made the changes necessary to improve its stability in this situation but wanted to check what others have done to fix this stability issue.

Any guidance would be appreciated.


r/PFSENSE 1d ago

Pci riser cables

3 Upvotes

hey guys, looking at building a mini itx pfsense box. are riser cables prone to corrupting data? looking at using a 4 port 1gb card or a 2 port 10gb card but don't want data corruption. any help would be much appreciated.


r/PFSENSE 2d ago

Policy-based routing for a specific destination (CDN) via VPN gateway – pfBlockerNG alias only partially working

2 Upvotes

In pfSense, I want to route traffic for a specific destination through a VPN gateway using policy-based routing. So that all devices in my network is routed if they want to connect to the specified destination. I specifically do not want all the internet traffic(netflix,spotify, etc.) on a device in my network would be routed through the vpn gateway.

So to achive that, I followed a YouTube video that recommends using pfBlockerNG to create DNS-based aliases for this purpose. It works for simple domains like ipchicken.com or dnsleaktest.com, but fails for my target service.

The service probably uses a CDN, so it resolves to many different IPs that may change over time. pfBlockerNG's alias doesn't seem to capture all of them. When I monitor states/connections, I see traffic going to IPs not included in the alias, so my firewall rule (which uses the alias as destination + VPN gateway) is not matching.

How can I reliably route all traffic for a CDN-protected(?) domain through my VPN in pfSense?


r/PFSENSE 2d ago

Force a specific client to use other DNS ?

2 Upvotes

As the tittle says, it´s possible to force some clients to use other DNS (like, for example, google´s 8888) instead of the PFSENSE DHCP internal DNS resolver ?

Thanks.


r/PFSENSE 5d ago

Avahi

2 Upvotes

Has anyone had luck with MDNS using Avahi? When looking at states I only get one way traffic.

Are you all getting two way traffic as I only get one way traffic.

I have never been able to get our iPads to cast on our TV.


r/PFSENSE 6d ago

ISC vs KEA DHCP

12 Upvotes

I've been using pfsense (currently CE 2.8.1) on a standalone box for my home for close to 10 years. I've always used ISC for my DHCP backend. I tried switching to KEA a year or two ago because of the notification that ISC is reaching EOL, but it had issues. I switched back to ISC because that has always "just worked" and I don't have time to troubleshoot DHCP (my "home project" plate is overloaded with things that can't be resolved with a simple checkbox).

With a web search you can see that many others have had issues with KEA, but those search results are from 2024/25. Is this because KEA has been improved? Or have most people given up?

If anyone had issues with KEA in the past, but now they're resolved, I'd like to hear what you have to say about it. Likewise for anyone who tried it in the past, had issues, then tried it again recently and still have issues.

If people wonder why I don't just test it myself, DHCP issues don't always show up immediately and I travel for work. Network issues showing up while I'm out of town sucks because neither my wife nor my kids are capable of fixing something like this, but they're totally capable of complaining about it.


r/PFSENSE 6d ago

In need of new router, pfsense seems interesting

5 Upvotes

Hi all,

I’m recently in need of new (home) networking equipment and, due to unfortunate time lines, I don’t have as much time to do research as I’d like. I’m hoping you guys can help me see if pfsense (likely through netgate) is suitable for me?

My previous set up was through an ASUS Merlin router.

Here’s where the router met my expectations:

1) Wireguard client with device touting

Here’s where the router fell short of expectations:

1) While I don’t mind CLI, I strongly want to deal with stuff through one interface. With the ASUS router, I could not forward traffic based on destination domain without ssh-ing into the box. I’d rather have all CLI or all GUI.

2) The VPN kill switch prevented the router from connecting via wireguard because the time would reset itself and there was no easy way to bypass NTP domains without each individual IP address

3) VLAN creation seems… not as stable as I’d like. I’d ideally like to create four separate VLANs and I want to be able to control which ones can talk to each other. I’d like to be able to add both distinct wireless devices into any of these VLANs (I’ve never tried this is it possible?). Ideally some of these VLANs can be on a wireguard VPN clienta

Also, because of timelines, I would likely be limited to less than a day worth of documentation reading and set up time. Is this possible?


r/PFSENSE 6d ago

pfSense+ 26.07, not much?

5 Upvotes

I noticed a new pfSense+ beta was available for 26.07, so I started looking around.

I started out on the netgate docs, but there wasn't anything there but an acknowledgement that the next version exists. No announcement post on Reddit like previous betas. The amount of issues in redmine can be counted on two hands. The same can be said for 26.10 in redmine.

What's up with the project? Did the entire development team walk out?

Edit: Some of you pointed out that most changes are in the pfsense 2.9.0 roadmap. I guess I was looking in the wrong place. Thanks for pointing that out!


r/PFSENSE 6d ago

What is a feature you wish pfsense had?

18 Upvotes

In some ways I view pfsense as better than an enterprise grade firewall due to the ability to install packages, like Tailscale (which is clutch), but what would you say are the key drivers preventing pfsense from being in enterprise? Or which features or capabilities do you think pfsense should have to be considered at that level?


r/PFSENSE 10d ago

Announcement Julioliraup/Antiphishing Suricata ruleset added upstream — pfSense guide available

15 Upvotes

Hello FW ADMs,

If you monitor malicious egress or ingress connections on your network edge using Suricata, julioliraup/Antiphishing is now available natively inside the upstream suricata-update ecosystem.

The ruleset provides frequently updated TLS, DNS, and HTTP signatures (SIDs 6000000 - 6100000) specifically tailored to block phishing campaigns. You can inspect the live database of tracked indicators on our companion portal: https://github.com/julioliraup/AT

Platform Integration Status:

Community Collaboration

This is a transparent, community-funded project (GPL-v3). Since phishing infrastructure cycles rapidly, the best way to support us right now is by deploying the ruleset and providing real-world feedback.

If you run into false positives, have suggestions for the rule generation script, or want to help us develop new features for the web dashboard, please open an issue or pull request on our GitHub!

GitHub: https://github.com/julioliraup/Antiphishing


r/PFSENSE 12d ago

freePBX useing Pfsence & PfBlockerNG to autoblock

Thumbnail
2 Upvotes

r/PFSENSE 13d ago

Nat type problem

0 Upvotes

Sometimes not Sometimes its open and the next day or abt 5 hours its moderate or unavailable so on router the dmz its enabled and also upnp. so whats the problem??


r/PFSENSE 14d ago

What’s the largest production network you’re running on pfSense?

33 Upvotes

I’m curious to see how far people are pushing pfSense in real-world production environments.

I’m not talking about a home lab or a small office. I’m interested in large deployments where pfSense is a critical part of the infrastructure.

I’d love to know things like:

  • Approximate number of users/devices
  • Peak concurrent users
  • Internet bandwidth (single or multiple WANs)
  • Average/peak traffic throughput
  • CARP HA (yes/no)
  • pfsync/XMLRPC Sync
  • Number of VLANs
  • VPN usage (IPsec, WireGuard, OpenVPN)
  • IDS/IPS (Suricata, Snort, Zenarmor…)
  • Hardware specifications
  • Any scaling challenges you’ve faced

For example:

  • 5,000+ users
  • Multiple ISP links
  • 10 Gbps+
  • CARP High Availability
  • Hundreds of VLANs
  • Large VPN deployments
  • Multi-site environments

I’m especially interested in hearing from universities, hospitals, ISPs, hotels, manufacturing, stadiums, airports, enterprise campuses, or anyone operating pfSense at serious scale.

What’s your largest deployment, and what have you learned from it?

At what point, if any, did you consider moving away from pfSense to another platform (FortiGate, Palo Alto, Juniper, Cisco, etc.), and what made you stay or switch?


r/PFSENSE 14d ago

Double NAT

2 Upvotes

I have router from my ISP then a pfsense, and then my main core switch that is doing all my routing. Switching voip systems and they did a test and said I had double nat, which listed my pfsense address and main switch address. The main switch gets routed to my pfsense then it routes out to the ISP router. I can't seem to just turn off NAT at the pfsense it seems, I feel like I am missing something simple. Any suggestions Thanks

Now that I have a little more time to explain, the lan side is 10.250.0.1 goes to core switch with multiple vlans, the wan ip is to 164.x.x.253 then goes to 164.x.x.254 isp gateway which I can't get rid of because of some other management services, how can I get rid of using nat on the pfsense then.


r/PFSENSE 14d ago

Announcement Passive Optical Network

1 Upvotes

Does anyone know in passive Optical Network system , where do they implement firewall at OLT or ONU side or both , and do OLT control ACL rules of ONU side firewall or not ?

Please help me


r/PFSENSE 16d ago

KEA with pfsense, is it ready for prime time?

8 Upvotes

Long time pfsense user, Months ago, tried to turn on kea for dhcp, big mess, just didnt work, acted like it was working, but it just refused to hand out IPs

This weekend, decided to wipe, install newest, and try again. Sorted acted like it worked, gave out some IPs, but then 8 hours later, I notice alerts that devices are offline. Turns out NO leases were handed out in the past 6 hours.

Switched back to ISC, and things started showing back up.

Is there some special process that needs to happen for this to work?

Everything I read is two camps:

  1. Yep works great, used it a bunch of places, it works fine
    or
  2. Worked for a while, then things stopped working and I switched back

I feel like after all these versions, this SHOULD be more streamlined, but here I am. I'm just glad I noticed what was going on, I wasted 3 hours trying to understand why systems fell apart...


r/PFSENSE 17d ago

Windows file sharing across different subnets/interfaces

7 Upvotes

Is there any way to configure a rule so I can access files on my wife's notebook from my PC where both machines are on different subnets/interfaces? My PC is on a subnet on "LAN" interface and the notebook is on a different subnet that's on "WIFI" virtual interface.
I just want to be able to open the disk on the notebook from Windows File explorer by entering \\notebookname\d$, but I cannot figure out what kind of rule do I need.


r/PFSENSE 20d ago

Trying to set up NordVpn on OpenVpn, it refuses connection.

3 Upvotes

Hi everyone,

I have pfsense 2.8 and I’m trying to set up a VPN on my router with NordVPN. Their instructions say 2.5. but I’m not sure if that matters or not.
I am trying to use server us8567 and the port in the ovpn file says port 53 while the official instructions say 1194. I have tried both in the client.

https://support.nordvpn.com/hc/en-us/articles/20285211284497-pfSense-setup-with-NordVPN

My client will run it just keeps saying “Waiting for response from peer”.

My only other thing is I have pfblockerng in use on the router for ad blocking and a separate open VPN to allow my phone to connect to my network remotely. I am hoping these two things are not interfering with something . (They shouldn’t honestly but who knows)

I don’t know what to do, is it the Dns settings? In General DNS Server settings I have 4 servers, two nordvpn provides and 2 for my ad blocking. Would that be a problem?

Sorry if it’s a bit rambling, I’ve been going in circles on this and it’s a little frustrating to follow the instructions exactly and not have it work. If you need more details on what else I tried let me know.


r/PFSENSE 21d ago

Configuration Assistance for odd (to me) multiple connection situation

3 Upvotes

Hello.

I have an unusual (to me) configuration I'm trying to configure on a NetGate SG-3100 running pfSense 23.09.1 and I'm looking for advice or help with configuration. I shut down a business that was in an office having several satellites with a Cisco based VPN network and for compliance reasons must maintain something similar to that network with the old servers in my home. Now, I'm working to exit cloud services personally with self hosting (think Immich and NextCloud)

I have two connections to my ISP at my home. One is for residential use and I cannot obtain a fixed IP address on this connection. The second is a commercial account and I have three fixed public IP addresses. The residential network is configured as 172.16.1.x and is totally separate from the NetGate router. The public IP addresses on the other are 66.x.x.68/25. The Netgate router is .68, an email server is .69, and a planned NAS is .70.

For fast implementation when my office closed, the mail server at 66.x.x.69 was setup on a switch in front of the router. Dumb, but had no choice. Now, I'd like to get everything behind the NetGate. I don't need any NAT on the NetGate. The only devices will be the mail server and the NAS. No clients/workstations/PCs.

I can create a small VLAN (say 192.168.15.x) on the router and on the NAS using a second ethernet port on the NAS. I plan to use Nginix to route traffic based on subdomains I've created on the 66.x.x.70 address.

I want the email server to keep a public address (66.x.x.69) in its network configuration. I've no desire to reconfigure.

I want the NAS to be port forwarded on 80 and 443 to the internal (192.168.15.x) address so Nginix can route to the appropriate ports based on the subdomains.

Security is not part of this question. Just router configuration.

How do I do this on pfSense? I cannot get past the bridging for the mail server. I get errors like "IP Address 66.x.x.69 is being used by or overlaps with WAN (66.x.x.68/25) and "A valid IPv4 gateway must be specified" when I have entered the IP address of the ISP upstream gateway.


r/PFSENSE 21d ago

Comcast Business Static IP (/28) Issue & Sanity Check

5 Upvotes

Hello everyone :-) I am having an issue, and I am hoping someone can help me. We have Comcast Business as our ISP and we have a /28 static IP block from them.

Usable range: xx.xx.xx.209 - xx.xx.xx.221
Gateway: xx.xx.xx.222
Subnet Mask: 255.255.255.240

The issue is, if I go to Assignments->WAN, make the following changes:

IPv4 Configuration Type: Static IPv4
IPv6 Configuration Type: None
IPv4 Address: xx.xx.xx.209/28
Upstream Gateway: xx.xx.xx.222

This fails to work. I have to change the IPv4 address field to xx.xx.xx.210/28 in order for everything to work.

Unless I am missing something, isn't xx.xx.xx.209/28 supposed to work if I put it in the IPv4 Address field? That is the first usable IP that Comcast gave me and from what I understand, you configure pfSense to use the first usable IP that Comcast gives you. Then for the rest of the Static IPs, you create Virtual IPs (with IP Alias) type.

Is this not correct? Any help here would be appreciated!

P.S. Not sure if this has anything to do with it, but in the Virtual IP section, there is an entry for xx.xx.xx.209/32 (IP Alias) and xx.xx.xx.210/32 (Proxy ARP). I don't believe this has anything to do with it, but, I thought I would mention it just in case it does.


r/PFSENSE 22d ago

Realtek on 2.8.1?

7 Upvotes

Do I still need to manually install Realtek drivers in 2026 for them to work? Are there extra settings for Realteks to be stable?


r/PFSENSE 22d ago

Solved: Why my Suricata Nmap scan alerts never fired

Thumbnail
1 Upvotes

r/PFSENSE 23d ago

Connectivity issues as a new PFSense user

2 Upvotes

Hello, i'm very new to PFSense, i just installed it on Oracle's VM following a book that's from 2021 so some of the things don't line up. I'm having problem setting up my WAN and i don't know what to do anymore, treat me like a five year old when explaining some things. Thanks