Replaced cable on BCE2 (CAT7) --> same issue
I finally changed the port to BCE1 and everything is back to normal (had to force the port in 1000BaseT from PFSense though).



I've just upgraded from 2.4.3 to 2.4.3_1 on a Dell R710 (using BCM5709 hardware).
Now my LAN (holding 2 VLANs) cannot negotiate more than 100Mbps.

Any hints/ideas/suggestions ? Tomorrow everybody in the company will probably kill me when they'll see the "improved" speeds from 1Gbps internet down to 100Mbps :)

I have 4 Gigabit Ethernet ports on the Dell 710

BCE0 --> WAN (PPPoE)
BCE1 --> not used
BCE2 --> LAN (VLAN5) ---> only negotiates @ 100Mbps
BCE3 --> LAN (VLAN10) ---> negotiates OK @ 1000Mbps

Thanks for confirming that I'm not the only one experiencing the issue.

I wonder if Mr.  Ivor Kreso who wrote the official article is among the forum's readers/admins.

DHCP and DNS / DNS over TLS with CloudFlare not working for LAN hosts
« on: April 04, 2018, 02:18:50 am »

I've followed this article: and now none of the Windows or Linux machine on my 2 VLANs are able to perform DNS resolution.

If I don't use the custom settings
ssl-upstream: yes
do-tcp: yes
name: "."

Everything works fine, but IMHO it doesn't use TLS anymore.

it also had issues when upgrading to 2.4.2 it seems :(

General Discussion / Re: Bogons if ISP has private IP addresses
« on: March 12, 2018, 03:45:24 am »
General Discussion / Bogons if ISP has private IP addresses
« on: March 12, 2018, 02:24:23 am »
Hello everybody,

Sorry if I posted in the wrong area, but I didn't know where exactly to put the question.

My ISP is using some private IP addresses in its network and I'm wondering if blocking bogons on PFSense's WAN interface can cause issue.
To have an idea, here is a traceroute:

Tracing route to []
over a maximum of 30 hops:

  1    <1 ms    <1 ms    <1 ms --> PFSense Box
ISP Traffic below:
  2     1 ms    <1 ms     1 ms
  3     2 ms     1 ms     2 ms
  4    39 ms    39 ms    43 ms
  5    40 ms    40 ms    45 ms []
  6    41 ms    40 ms    40 ms []
  7   139 ms   139 ms   139 ms []
  8   139 ms   139 ms   191 ms []
  9   140 ms   169 ms   140 ms []
 10   139 ms   149 ms   139 ms []
 11   140 ms   140 ms   141 ms []
 12   135 ms   135 ms   135 ms []
 13   140 ms   153 ms   141 ms []
 14   138 ms   139 ms   138 ms []
 15   140 ms   139 ms   140 ms []
 16   142 ms   143 ms   142 ms []
 17   141 ms   141 ms   141 ms []
 18   142 ms   142 ms   142 ms []
 19   143 ms   143 ms   143 ms []

Here comes the issue... I cannot have 2 default gateways.

That's not an issue, that is normal. If you have more than one gateway for an address family you need to do policy based routing.

Here comes the issue... I cannot have 2 default gateways.
If I follow the article and put interface OPT as default gateway, the clients from VLAN1 won't be able to use my ISP's IPv6.

 OPT2_TUNNELV6  OPT2  2001:470:1f1a:699::1  2001:470:1f1a:699::1  Interface OPT2_TUNNELV6 Gateway      
 WAN_DHCP6 (default)    WAN  fe80::1  fe80::1  Interface WAN_DHCP6 Gateway      
I know how it is...
I have a /64 for about 3 years now, since Digi (the main ISP in Romania) provides it.
Sadly, the move to /56 will come sometimes this year (no timeline defined).

Now back to our sheep (revenons a nos moutons :) )...
I can't seem to find a way to assign the /64 from Hurricane Electric to the second VLAN I have.
I only have a LAN tab, that points to VLAN1 and I need to et HE's V6 to VLAN2 (that is on a different NIC Card).

If I can't figure it out, I'll probably send them an e-mail.

Thanks Gertjan.

Well, if I get a /48 or /56 from HE.NET it will probably work.
Why: because I have 2 VLANs and would like to have IPv6 on both VLANs, which I can't do with a /64 from my ISP.
Quick question:
I have the following setup:
- WAN over PPPoE that offers both IPv4 and IPv6 (::/64)
- LAN (IPV4 DHCP, IPv6 using track WAN)
- LAN2 (different VLAN) - IPv4 DHCP

I tried to setup an HE.NET IPv6 TunnelBroker, and when setting up the IPv6 static IP on LAN2 (following the article:, I get IP address overlapping - a bit normal since both IP addresses in the guide are in the same /64 if I read correctly).
Packages / Can we run Squid both as a proxy and as a reverse proxy ?
« on: January 31, 2018, 02:21:08 am »
I want to start configuring a reverse proxy on PFSense to replace my aging Microsoft TMG.
IPv6 / Monitoring IPv6 WAN logs
« on: January 14, 2018, 09:12:13 am »

I have native IPv6 from my ISP assigned though PPPoE with Prefix Delegation (they assign a /64).
This week the ISP upgraded the firmware on the ONT providing the connection and so far I encounter the following issue:
- PFSense WAN interface periodically loses its IPv6 IP.
First I suspected a port flap or something, but the uptime of the interface is in the range of days.

Is there a way I can find in PFSense logs when the interface lost its IPv6 address ?

pfBlockerNG / Re: DNS Whitelist
« on: January 09, 2018, 02:24:59 am »
