<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PFSense on Michael’s Domain</title><link>https://jeltsch.org/en/tags/pfsense/</link><description>Recent content in PFSense on Michael’s Domain</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright © 2002 - 2026 Michael Jeltsch.</copyright><lastBuildDate>Fri, 24 Jul 2026 00:18:18 +0300</lastBuildDate><atom:link href="https://jeltsch.org/en/tags/pfsense/index.xml" rel="self" type="application/rss+xml"/><item><title>Unbricking the Netgate pfsense SG-3100</title><link>https://jeltsch.org/en/unbrick/</link><pubDate>Fri, 10 Nov 2023 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/unbrick/</guid><description>&lt;p&gt;The current process of restoring functionality on the Netgate pfsense SG-3100 router after an unsuccessful firmware upgrade is too difficult (although the device is magnificent otherwise). Today, I experienced the third failed upgrade within six years. Recovery worked every time without problems, but it should be MUCH easier if you want me to recommend this router to my less tech-savvy friends. To pull the recovery off, you need an 8-GB USB stick and USB cable with a high-profile micro-USB connector at one end and a regular USB-A connector at the other. These are the steps that you need to do to unbrick the device:&lt;/p&gt;</description></item><item><title>Dynamic DNS with DomainDiscount24 and pfsense</title><link>https://jeltsch.org/en/dynamic_dns_with_domaindiscount24_and_pfsense/</link><pubDate>Sat, 27 May 2023 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/dynamic_dns_with_domaindiscount24_and_pfsense/</guid><description>&lt;p&gt;Many companies offer free dynamic DNS. But since I use DomainDiscount24, I also use their dynamic DNS service. To update the IP address of vpn.jeltsch.org, I need to send an https request to a specific URL, including a password and the hostname for which I want the update:&lt;code&gt;https://dynamicdns.key-systems.net/update.php?hostname=vpn.jeltsch.org&amp;amp;password=12345678&amp;amp;ip=auto&lt;/code&gt;To automate this, I use the crontab of my pfsense router. Editing the crontab is not enabled by default, but you can download and install the cron package. After that, you get a GUI under &amp;ldquo;Services &amp;gt; Cron&amp;rdquo;, where you add the timing and the command:&lt;code&gt;/usr/local/bin/curl &amp;quot;https://dynamicdns.key-systems.net/update.php?hostname=vpn.jeltsch.org&amp;amp;password=12345678&amp;amp;ip=auto&amp;quot;&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Wake on LAN from pfsense commandline</title><link>https://jeltsch.org/en/wakeonlan/</link><pubDate>Sun, 17 Apr 2022 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/wakeonlan/</guid><description>&lt;p&gt;Pfsense is an extremely powerful firewall/router OS. I use the SG-1100 device and you can get lots of customized functionality due to the many packages that you can additionally install on top of the base configuration. I have just learned that I can use it to remotely switch on other computers that are on the same local network. Requirements:&lt;/p&gt;</description></item><item><title>PXE-booting from Netgate Pfsense SG-3100</title><link>https://jeltsch.org/en/pxe_booting_from_netgate_pfsense_sg_3100/</link><pubDate>Fri, 15 Nov 2019 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/pxe_booting_from_netgate_pfsense_sg_3100/</guid><description>&lt;p&gt;To install Linux without the need of a CD/DVD/USB-stick, I now use PXE-booting (&amp;ldquo;pixie&amp;rdquo;-booting) on our local home network. I could not find good instructions and had to try out things before it started working, but the process itself is fairly simple. Here are the steps:&lt;/p&gt;</description></item><item><title>OpenVPN server on pfsense and client on Ubuntu 16.04</title><link>https://jeltsch.org/en/openvpn_server_on_pfsense_and_client_on_ubuntu_16_04/</link><pubDate>Fri, 02 Nov 2018 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/openvpn_server_on_pfsense_and_client_on_ubuntu_16_04/</guid><description>&lt;p&gt;I have been setting up an 
 &lt;a href="https://openvpn.net" target="_blank" rel="noopener noreferrer nofollow"&gt;OpenVPN&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 server on my 
 &lt;a href="https://www.netgate.com/solutions/pfsense/sg-3100.html" target="_blank" rel="noopener noreferrer nofollow"&gt;Netgate SG-3100 router&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. I hope this makes syncronizing backups to a physically separate location easier. There are many walkthroughs to set up an OpenVPN server on a 
 &lt;a href="https://www.pfsense.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;pfsense router&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 and that works nicely. However, I am using 
 &lt;a href="https://blog.ubuntu.com/desktop" target="_blank" rel="noopener noreferrer nofollow"&gt;Ubuntu&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 16.04 at work and setting up the client requires a bit more than doing the same on MacOS or Windows. On Ubuntu, it is mandatory to update DNS information manually after establishing the VPN tunnel if you have opted for the setting to route all internet traffic originating from the client through the VPN server. If you do no update the DNA resolver information on the Ubuntu client, you can access the the VPN-internal network (in my case 10.0.0.0/24), but you cannot use hostnames. E.g. ping 
 &lt;a href="https://www.google.com" target="_blank" rel="noopener noreferrer nofollow"&gt;www.google.com&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 will fail, but ping 172.217.21.164 will succeed. Similarly, your browser will not find any URLs. And browsing with IP-addresses (&amp;ldquo;http://172.217.21.164&amp;rdquo;) is not very practical.The default configuration on Ubuntu does not allow for this update of the DNS resolver to happen automatically for security reasons. There is a script included in the 
 &lt;a href="https://packages.ubuntu.com/search?keywords=openvpn" target="_blank" rel="noopener noreferrer nofollow"&gt;Ubuntu package of openvpn&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 that updates this information (/etc/openvpn/update-resolv-conf). But in order for this to work one needs to&lt;/p&gt;</description></item><item><title>BSD and Linux</title><link>https://jeltsch.org/en/bsd_and_linux/</link><pubDate>Fri, 10 Jun 2016 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/bsd_and_linux/</guid><description>&lt;p&gt;I am used to the fact that a Linux installer honours a pre-existing install of Windows and offers to setup the computer with a dual-boot option during installation. Vice-versa no Windows installer honours any other pre-exisiting OS. Therefore I was surprised that when I tried to install Ubuntu 16.04 on my PFSense box (FreeBSD), the Ubuntu installer did not even see that a BSD install exists on the drive. I chose the &amp;ldquo;erase all&amp;rdquo; option, but when I rebooted after the installer has finished, the system went straight into PFSense without giving me any option to select Ubuntu. I guess the boot loader had not been touched by the Ubuntu installer. I booted from a live Ubuntu USB stick, reformatted the drive with fdisk and wrote zeros to the boot loader:&lt;code&gt;dd if=/dev/zero of=/dev/sda bs=512 count=1&lt;/code&gt;Then I repeated the install and everything was fine. However, my PFSense installation was lost…&lt;/p&gt;</description></item></channel></rss>