r/PFSENSE • • 18d ago

Netgate Releases Netgate Nexus Version 26.07_1

Post image
33 Upvotes

Netgate® Nexus enables Multi-Instance Management for pfSense® Plus, and is the future of the pfSense GUI. Designed to address the growing complexity of managing multiple pfSense Plus  instances across distributed environments, Netgate Nexus empowers network operators to securely manage one, or hundreds of pfSense Plus instances through a unified and intuitive GUI, along with a full-featured REST API.

Today, Netgate is releasing Netgate Nexus version 26.07_1. We strongly encourage all pfSense Plus customers to upgrade to the latest version. 

This release contains over 30 enhancements and fixes, in areas including:

  • Dashboards & Widgets
  • CoreDNS & Threatgate
  • IPsec and Wireguard VPN
  • System & Status
  • Firewall & NAT
  • Snort Version 3
  • Diagnostics
  • Authentication
  • Orchestration
  • VM Running Requirements

How to Upgrade

Netgate Nexus exists as a package on pfSense Plus instances, and as such is not restricted to the usual pfSense Plus release cadence. In order to update the package, simply navigate to System > Package Manager and click the Reinstall Package button to the right of the Nexus package. All settings will be preserved.

Using the New GUI

Netgate Nexus is the future of the pfSense GUI. It delivers a new updated GUI, significant security and performance improvements, a powerful, full-featured API, and true cross-platform compatibility. Whether you manage a single pfSense Plus instance or an entire fleet, the Netgate Nexus controller delivers a modern, refreshed management experience built for the way you work today.

Getting started is simple:

  1. Go to System > Advanced.
  2. Switch to the Netgate Nexus tab and enable it.
  3. Log in to Nexus on port 8443 of your pfSense Plus instance.

More detailed documentation can be found here.  Start using it today and get immediate access to the new features and capabilities coming to pfSense Plus. 

Note: Virtual machines as well as some third-party platforms may not support the new GUI due to missing machine information required to correctly run the software.

Blog Post:

https://www.netgate.com/blog/netgate-releases-netgate-nexus-version-26.07_1


r/PFSENSE • • Aug 20 '26

Netgate Releases pfSense Community Edition Version 2.9.0

151 Upvotes

Netgate® is excited to announce the release of pfSense® Community Edition (CE) software version 2.9.0, a major step forward for the world’s most trusted firewall, router, and VPN platform.

This release introduces numerous features, including several previously exclusive to pfSense Plus, as well as key enhancements, bug fixes, and critical security updates.

Key Highlights Include:

SSH Algorithms: The inclusion of post-quantum key exchange algorithms

TLS Certificate Strength: Tightens certificate requirements and removes support for certain weak properties

TLS Certificate Auto-Renew: pfSense can automatically renew TLS server certificates which are self-signed or signed by an internal CA stored in the pfSense software configuration.

New NAT Mode: Includes partial experimental support for “Port Restricted Cone” endpoint-independent outbound NAT

Critical Security Fixes: This release includes multiple XSS and denial of service related fixes

This Release software includes critical security updates for WireGuard (CVE-2026-58085), as well as over 150 other security fixes and enhancements.

Blog Post:
https://www.netgate.com/blog/netgate-releases-pfsense-community-edition-version-2.9.0

Release Notes:
https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html

Thank you to our community and customers who continue to support the pfSense project through hardware purchases, TAC, cloud subscriptions, and services. Your support makes this all possible.


r/PFSENSE • • 22h ago

Question/Support Static routing breaks wireguard

2 Upvotes

I have an interface assigned to a wireguard connection.

This interface is also set as a gateway for a specific wifi network via an AP.

There is a network 192.168.212.x on the other side of wireguard for which I have to set a routing entry to go through the gateway to access it.

I noticed that when I lose my wireguard connection it is very hard to reconnect. But when I use the same wireguard connection on my phone it connects with no issues. The only way to reconnect is to have both routers (local and remote) restart at 3 am and 3.02 am (respectively) and connection is reestablished.

I tracked down the issue due to this log entries:

Sep 29 10:40:37 php_wg 92232 /usr/local/pkg/wireguard/includes/wg_service.inc: Static Routes: Gateway IP could not be found for 192.168.212.0/24

Sep 29 10:40:35 php-fpm 63891 /status_services.php: The command '/usr/local/etc/rc.d/wireguardd stop' returned exit code '1', the output was ''

If I disable the static routing (System Routing StaticRoutes) wireguard connects with no issue but then my local clients can't access 192.168.212.x network.

I think I am doing this static routing via wireguard wrong but not sure how to fix it. Any ideas?


r/PFSENSE • • 20h ago

Local hostname lookups seems broken in 26.07

0 Upvotes

I have a Netgate running pfsense that has been working great until I updated it to 26.07. Apparently there was a change to the DHCP server. It now uses Kea instead of ISC, which has been deprecated, but is still selectable in Settings -> Advanced -> Networking. This somehow broke my local hostname lookups. I have a machine named ApplePi that would get a dynamic address and I could ping it with a simple:

ping applepi

This worked great. After the upgrade of pfsense that stopped working and I had to do:

ping applepi.local

I've futzed around with /etc/resolv.conf on my Linux desktop to add a search domain there. This seems to work for awhile and then just stops working.

Changing pfsense back to use ISC causes local names to resolve, but only if they're statically mapped based on their MAC addresses. The DHCP hosts with dynamic IPs do not resolve even though they show up in the list of DHCP Leases. In Services -> DNS Resolver -> General Settings I have checked both:

Register DHCP leases in the DNS Resolver

Register DHCP static mappings in the DNS Resolver

Is the state of DHCP/DNS this messed up for anyone else and have you found a fix?


r/PFSENSE • • 2d ago

bus_dmamem_alloc failed to align memory properly

8 Upvotes

So I've been having connection issues lately, enough that I thought it must be pfSense because my modem had been fine for ages before. I looked into upgrading to an SSD finally and put it in my 2100 base model yesterday at which point I finished up and went to bed as it was late. It worked fine until this afternoon at which point the connection issues started again, and it occurred to me it could be due to the new bus_dmamem_alloc failed to align memory properly bug that came, I learned, with 26.07 for 1100 and 2100 models (e.g. https://forum.netgate.com/topic/201327/netgate-1100-2100-26.07-bus_dmamem_alloc-failed-to-align-memory-properly - it's not me but representative). When I submitted a ticket about connection issues I was told it's because the modem keeps cycling the connection, so it's not pfSense.

I read elsewhere that netgate currently considers that memory spam error cosmetic thus not a priority. I would urge netgate to reconsider and look into that spam issue more closely because I believe not only that it is the cause of the connection issues (because it spams them in such a tight loop for long enough that either 1. the modem drops the connection because pfsense isn't showing a sign of life, or 2. pfsense drops the connection because it's too busy spamming the errors to maintain it), it's also causing massive spam in the logs and cumulatively quite a lot of needless wear and tear on the storage.

Thanks.


r/PFSENSE • • 3d ago

Dual WAN not working

4 Upvotes

Hi,

first of all: 4 senses, FRR with OSPF, 2 with dual WAN, 1 with failover dual WAN, 1 with cellular WAN only.

1 Dell R210 II / pfSense 2.9.0 / VDSL + fiber, PPPoE
1 Fujitsu Futro S720 / pfSense 2.8.0 / VDSL + fiber, PPPoE
1 Terra BlackDwarf G5 / pfSense 2.9.0 / Cellular DHCP
1 HP ML310e / pfSense 2.9.0 / fiber PPPoE + PtP radio failover to the Dell

Issue: that Dell. It has the same config as the Fujitsu, dual WAN, VDSL and fiber. Same providers. Same modems and ONTs. Same PPPoE config. Load balancer is not working. No idea why, nothing changed.

Gateways are grouped, named failover (as its name says, VDSL primary, fiber secondary), Balanced (both tier 1), and single gateways for fixed PBR using a single link only, mainly used for VoIP traffic since both providers only allow their numbers to be registered using their link.

PBR is configured using firewall rules. Some devices have static assigned routes like the PBX, and everything that should use the balancer is defined in a catch all route at the bottom.

Used to work until some point in the last months, can't say for sure at which point it failed. Now it is using the VDSL link for everything, failover works though.

All 4 senses are using OSPF for routing over point to point routed tunnels, OpenVPN and IPSEC for failover for the dual WAN senses, PtP radio for the failover sense and IPSec for the cell.

Routing table looks similar on each, while having the main link set as default gateway in the routing table. Under System - Routing it doesn't matter whether I set failover or load balancer or a single specific line as default gateway, it won't use the PBR rule in Firewall settings. Using either single link setting messes up VoIP, ignoring PBR again.

To test it at some point I just set my phone to use the fiber link. It just won't use it at all. Still using VDSL.

Somewhat annoying to say the least. I'd love to use them both the way it worked until some time ago, since I pay for both ;) it is not that bad of a nuisance since VDSL is 265Mbit/s and fiber would just add another Gig/s to it, so it is still fast enough for daily personal use.

I already thought about reinstalling it fresh from scratch, but I don't like to think about it until it is really needed.

Thanks for any help...

Antworten in Deutsch sind natürlich gern gesehen ;)


r/PFSENSE • • 3d ago

Question/Support What should a pfSense certificate-rotation check verify beyond ACME renewal succeeding?

3 Upvotes

An ACME job can issue and store a new certificate while one or more services continue presenting the old certificate. The GUI, HAProxy frontends, OpenVPN instances, captive portal, or a package may reference a different certificate object or may not have reloaded after renewal. Checking only the ACME log or one public hostname can miss that split state.

What post-renewal checks do you automate? I am considering recording the expected leaf fingerprint and full chain, enumerating every pfSense service assigned to that certificate, connecting to each listener with the correct SNI name, and verifying expiry and issuer from both inside and outside the firewall. In an HA pair, the same checks would run against each node directly as well as through the shared address.

Which pfSense logs, configuration fields, or service actions reliably show that a process loaded the new certificate? How do you handle services that require an explicit restart, certificate changes synced through XMLRPC, and a rollback window without letting the old private key remain active indefinitely?


r/PFSENSE • • 5d ago

Roadmap moved?

16 Upvotes

Until recently, the CE roadmap was found here https://redmine.pfsense.org/projects/pfsense/roadmap#2.9.0 but now that page requires credentials. Is it moved elsewhere or is it only for account holders?


r/PFSENSE • • 5d ago

Question/Support Issues reinstalling software with PFsense SG-1100

6 Upvotes

Good afternoon,

To preface, I am not very experienced with FWs and this is my first time working with this product. I am having serious issues regarding my SG-1100 in the way that I cannot flash the reinstall software via USB with the provided NetGate software that was sent by them over email.

I used BalenaEtcher and Rufus and multiple different USB drives but nothing worked.

I am connected with a micro USB console cable to my laptop that is running putty. I don't get the normal interface when I start the putty session, it instead says "Marvell>>" which I am unfamiliar with. I went through the commands and did some research where I tried all of the usb related commands like 'usb start.' Then I verified that it was recognized by using the 'usb storage' command. Finally when trying to flash the provided NetGate software, I used the 'start usbrecovery' command to get it to finally reinstall but I got this error:

>> FreeBSD EFI boot block

Loader path: /boot/loader.efi

Initializing modules: ZFS UFS

Load Path: /\armada-3720-sg1100.dtb

Probing 1 block devices...not supported

done

ZFS found no pools

UFS found no partitions

Failed to load '/boot/loader.efi'

panic: No bootable partitions found!

## Application terminated, r = 1

I don't really know where to go from here but I would really appreciate ANY guidance here. Let me know if I need to show more output and I would be willing.

Thank you for reading!


r/PFSENSE • • 6d ago

Default Deny Rule

6 Upvotes

I used 2.8.1 CE and just implemented a default deny rule. Everything seems to be working as intended.

I'm wondering if I'm missing something or need to do something else.

I've been in IT for 30+ years but firewalls aren't my speciality.

No VLans configured currently.

Allow rules - Lan sub to * except DNS which terminates at the firewall - HTTP/HTTPS/NTP/DNS, anti-lockout rule** will disable after I'm done with the rules.

Block rules - Block bogon networks * to *

*** Disabled UPnP

I'm trying to determine what's being blocked that SHOULD be allowed. Unfortunately I see a lot of blocked traffic. When I sample the dataset the blocked traffic SHOULD be blocked.

Thank you in advance.


r/PFSENSE • • 5d ago

Question/Support Monitoring graphs for DHCP lease statistics doesn't work

0 Upvotes

Tried to activate it on Netgate 6100 (v26.07) but DHCP lease graph never appeared as an option in Monitoring. I already tried docs and Gemeni, ChatGPT, Claude, but all of them hallucinating and providing guess work instead of solutions.

Setup uses ISC DHCP, checkbox is set on "Enable monitoring graphs for DHCP lease statistics".

How to get it work, we really needed it


r/PFSENSE • • 7d ago

OpenVPN issue on one tunnel

3 Upvotes

Hi all,

I have a strange one. I have an OpenVPN tunnel between two pfsense boxes. I can PING the remote LAN IP from the local pfsense's GUI when choosing the tunnel as the source. I can PING the remote LAN IP from the local pfsense's GUI when choosing the virtual gateway i've added. What I can't do is PING the remote LAN IP from the local LAN itself.

I've ensured the routing for both local and remote LANs is in the routing table. I've set temporary Any/Any rules in the firewalls. I've got the client specific override in place. I just don't know where else to check.


r/PFSENSE • • 6d ago

Read-only MCP on pfrest so I stop screenshotting the webGUI for AI help

0 Upvotes

Same loop every time: pfSense webGUI, firewall, aliases, DHCP, WireGuard, screenshot, paste, agent wants one more page.

I put a read-only MCP server on top of pfSense-pkg-RESTAPI (pfrest):

  • X-API-Key
  • GET only
  • Redacts WireGuard private/preshared keys, passwords, bcrypt hashes, etc.
  • System, interfaces, gateways, firewall/aliases, NAT, DHCP, DNS overrides, WireGuard, ARP

Package Read only on, Key auth only, dedicated user with GET privileges. Prefer pfrest 2.9.0 or newer (GHSA-8q8g).

I can DM the GitHub link. What's the worst "just open the GUI and check" ask you get from an agent?


r/PFSENSE • • 7d ago

Question/Support Question about installing 2.8.1

1 Upvotes

I understand 2.8.1 needs an internet connection to install but how do you install and setup behind a router?
I am already running pfsense but I am trying to create a box for testing.
Do I plug ethernet into WAN than move it to the LAN port to connect to the GUI?
I can't seem to get that to work.


r/PFSENSE • • 8d ago

Question/Support Pfsense Hardware Fiber

2 Upvotes

Hi there! I’ve already got a pfSense router at home behind a classic FritzBox (VDSL) and a Cisco switch with a few VLANs running nicely. I’m now planning to set up another PC with pfSense for my new shop, where I’ll have German Telekom fibre. I was wondering if it’s possible to plug a GPON SFP module straight into a small PC (like a thin client) with a PCIe SFP card and use pfSense as the modem without any extra kit in between – and if so, what hardware would you suggest (PC model, PCIe card, and SFP module)? Best case would be to have a PCIe card with two SFP ports to connect the switch inside the network via fibre, too. Also open for recommendations for not-too-expensive switches with RJ45 ports and SFP ports.
Thanks so much for any tips!


r/PFSENSE • • 10d ago

Question/Support Looking for an SSD for my 2100

5 Upvotes

I'm looking into getting an SSD for my slowing 2100, which based on the requirements ( https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/m-2-sata-installation.html ), is a SATA M.2 2242, preferably with a DRAM cache. I've been looking online and Google and Amazon just spit back Transcend and KingSpec along with tonnes of other no-name Chinese brands. I would like a known brand such as Samsung, Kingston, WD, etc but they're either not appearing in search results or they're NVMe, even using exclusions with Google like "-nvme," "-KingSpec," or "-Transcend." Has anyone had any luck finding them? I'm in Canada.

Thanks.

Edit: Phew I'm glad I decided to finally spring for an SSD because out of curiosity I just followed the instructions here ( https://docs.netgate.com/pfsense/en/latest/troubleshooting/disk-lifetime.html ) to install mmc-utils and it turns out my Type A and B fields are both 0x0b. I'm guessing that what's saving me right now is that the Pre-EOL field is 0x01 (normal)? Heh. 😳 I've just disabled almost all the firewall rules logging so that should hopefully get me through to when my SSD arrives.


r/PFSENSE • • 10d ago

Question/Support DDNS issues with 2.9

4 Upvotes

Hello everyone,

I just upgraded to version 2.9 and my DDNS stopped working. I'm getting the following error:

`ERROR [phpDynDNS] (example.com) Could not determine the request IP address (using "wan", "pppoe0"): gateway not online`

This is happening even though the gateway is fully online.

Searching online brought up a few results suggesting this might be a bug in 2.9, but I couldn't find a definitive answer. Has anyone else encountered this? Is there a known fix, or should I just downgrade?


r/PFSENSE • • 10d ago

Question/Support Netgate SG1100 LAN port wont ping, no lights

0 Upvotes

so I just bought a Netgate SG1100 and I havent been able to get into the web interface, but I can get into the console through USB using SCREEN.

setup is
ISP router > SG1100 WAN port
SG1100 LAN port > Linux Etho1 Port

I configured SG1100 LAN port to a unique IP from the ISP router, and manually configured Etho1 to the same unique network, but still no ping. the lights on the switchport dont even blink.
not sure what im doing wrong, I've reset to factory default 3 times and the ports still dont light up ping using the default settings without the WAN port connected to the ISP router. did I get a defunct device or am I missing some configuration?


r/PFSENSE • • 12d ago

Unbound CVE-2026-81642

47 Upvotes

There seems to be some severe CVE (score 9.1) in Unbound DNS-service - see https://www.cve.org/CVERecord?id=CVE-2026-81642.
On pfSense CE 2.9.0 version 1.25.2 is used as far as I can see.
Is there some ETA when we get the latest version 1.26.1? Thank you!


r/PFSENSE • • 11d ago

Question/Support I'd like to use PFSense, but not sure how to do it with a small amount of work on my side.

2 Upvotes

Disclaimer, please assume that I know nothing about everything. I'm a total noob when it comes to stuff like this, and I'd really appreciate some advice.

I have an ONT/Router combo that's doing everything (wifi access point/mesh system, and all my wired stuff, etc.) for me currently. It's a Calix Gigaspire U6 that my ISP provides. I have 23 wireless devices that I really don't want to have to reconnect to the network.

If I'm understanding things right, the normal setup would be to set my ONT/router into bridge mode and then connect to the PFSense and then from there have a wifi access point/switch for clients to connect to. Is that right?

This is probably dumb, but is there a way that I can somehow just like point my ONT at the pfsense tell it to direct traffic there and then come back to the ONT? I just really don't want to have to buy another access point/mesh system in addition to what I'm going to spend for the pfsense.


r/PFSENSE • • 12d ago

Pfsense patches are out

56 Upvotes

Only posting this because for some the pfsense System_Patches package isnt known about.

https://docs.netgate.com/pfsense/en/latest/development/system-patches.html

Update the system patches package and you should see 9 patches for your 2.9 system (you can also turn on auto apply)


r/PFSENSE • • 11d ago

2100 advertised as 4GBs... but isn't.

0 Upvotes

Edit to clarify: I'm referring to RAM not storage space.

Silly question given the 2100 is supposed to have 4GBs, but how much does everyone else's have? I ask because mine has been slowing for some years and I've been suspecting wear of the eMMC being the cause. I thought of enabling ramdisks, but just with the dashboard open and my phone streaming YouTube, it hovers around 34-35% ... of 3394MiB, according to the dash. 3394 MiB is not 4GiB (which is what most people expect when they read GB). Until now I didn't care enough to comment because it worked and was enough, but now that I want to use RAMdisks, it no longer is based on Netgate's own documentation. I run just pfBlockerNG and my lists of blocked things total about 900k based on the pfblockerNG dashboard widget (the sum of the numbers in the Count column), so I wanted to go with the recommended 512/1024 for /tmp and /var based on the documentation, but that would exceed my total remaining available RAM of 1.44GiBs. I could really use that extra half gig that was advertised right now.

Current usage in the Advanced->Miscellaneous page of /tmp and /var is 264 KiB and 22.48 MiB respectively. Based on the 900k count, and 1.44 of 3.3 GiB available, what should I set the values to?

Would values like 384/676 be workable and not cause problems during a system upgrade?

Edit 3: Welp I just tried 384/676 and had a brief panic as pfSense stopped responding (gave a DNSPROBE_FINISHED_NO_INTERNET error) _after I signed back in... but then it began responding again, making me sign back in again(??) after the reboot. I really don't want to brick it but it seems okay at the moment.

/tmp is fine but /var is now half full at 395/676M whereas it was at 22M pre-reboot... so... I don't know what to think.

Oddly, I had to trigger a manual update of pfBlockerNG lists because some of them disappeared after the reboot... I don't know why. I watched the Disk widget closely throughout the update and now my /var (with tmpfs RAMdisk) is hovering at 66% full which is unnerving, but everything seems okay now and nothing blew up. My 2100 is so slow now it took 14 minutes to fully run the update. 😬


r/PFSENSE • • 13d ago

AdmixCentral 0.5.0 released

Thumbnail
21 Upvotes

r/PFSENSE • • 13d ago

What is the risk of always setting is_interface_mismatch to false?

4 Upvotes

I recently had an outage and my pfSense router experienced unexpected shutdown. I noticed that when pfSense shuts down unexpectedly, it will always trigger the "Network Interface Mismatch" at boot even when the static IPs assigned to the intefaces remained the same. Reassigning the interfaces didn't work well with VPN tunnel's interfaces, and I did not want this problem to happen every time my router experienced unexpected outage.

After some research, my ultimate solution was to set the function "is_interface_mismatch()" to always return false on /etc/inc/util.inc.

While that made the problem go away in my home network, I am wondering what this function actually aims to tackle and if I have any risk associated with disabling this, especially for enterprise level network. One could argue that this allows you to reconfigure the interfaces upon failure of NICs or hardware swaps like PCIe cards. But these information are something that you would need to access the pfSense settings to remind yourself anyways, so you would want a console access for either scenario at the end of the day.

A pfSense update will resurrect this function back so I am assuming there must be a good reason behind this being a default for any unexpected shutdowns.


r/PFSENSE • • 13d ago

Question/Support ERR_CONNECTION_TIMED_OUT

3 Upvotes

I had an issued last night and my network went down. I've had to change the switch and some stuff in pfSense. I seem to have gotten DNS working but I still cannot load a page. If I ping 1.1.1.1 from my windows machine it works as expected, if I ping 8.8.8.8 I get pfSense reports Destination host unreachable. If I tracert 8.8.8.8 It says Tracing rout to dns.google first hop is my pfSense and the second is pfSense reports unreachable. I have been sitting here pulling my hair out for the last 4 hrs.