What's new

Using pfSense with a L3 core switch

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

DNS forwarding will not work if you are running PfblockerNG. I think it requires unbound.
It actually works even with forwarding I'm using it that way myself in fact. You need to put rules in place though regardless of having pfblocker enabled or not, to redirect DNS queries. Additionally IPv4/v6 and DNSBL DoT/DoH blocklists in pfBlocker also helps. Not perfect but works pretty well.

Just follow above example for DoT as well...

And I use this as well..

I'm sure more experienced ones here can correct any wrong info here...
 
I have not run PfblockerNG so I was just repeating what someone said. Good to know it works with DNS forwarding.
I am not sure what rules you are talking about as I just select DNS forwarding service in Pfsense and it works. DNS resolver needs to be disabled. I am just using port 53 for DNS forwarding.

PS
I do have firewall rules to pass QUAD9 and block port 53 and port 853
 
Last edited:
So, I have turned off hyperthreading in BIOS and I think my pfsense router is running smoother. My CPU usage has gone up a little from 3% to 5%.

Otherwise, I am just waiting for the next Pfsense release which should be out around the end of the month.

I have been thinking about buying an Intel 10g NIC X710-T2L. You need the L on the end for it to work from what I have read. Sounds like it is a low heat card for 10g. I would like to be able to plug into my 10g Cisco switch and plug into a 2.5 nBase-T modem.
 
So, I have turned off hyperthreading in BIOS and I think my pfsense router is running smoother. My CPU usage has gone up a little from 3% to 5%.

That's a good move - the BSD community has never been major fans of Intel's Hyperthreading...
 
So, I have turned off hyperthreading in BIOS and I think my pfsense router is running smoother. My CPU usage has gone up a little from 3% to 5%.

Otherwise, I am just waiting for the next Pfsense release which should be out around the end of the month.

I have been thinking about buying an Intel 10g NIC X710-T2L. You need the L on the end for it to work from what I have read. Sounds like it is a low heat card for 10g. I would like to be able to plug into my 10g Cisco switch and plug into a 2.5 nBase-T modem.

What made you look at that? I am pretty sure HT is also turned on but i never bothered looking into the effects of it, if any. I have an Intel X550-T2 in my pfSense box. That works perfectly fine.
 
Last edited:
What made you look at that? I am pretty sure HT is also turned on but i never bothered looking into the effects of it, if any. I have an Intel X550-T2 in my pfSense box. That works perfectly fine.
Does your card link at 2.5g? I think the x710-T2L runs a little cooler and that is my reason for choosing it.
Has anybody run a x710-T2L?

I just remembered one day that I turned off hyperthreading many years ago when I was running Pfsense probably 2.0. It just popped into my head recently.

What I am seeing is it scrolls a big, long page faster. And I am using DNS forwarding right now because of the errors on unbound which will be fixed next release.
 
Last edited:
Has /anybody of merit/?

By disabling Hyperthreading, one can avoid a majority of the speculation vulns out there (Spectre, Meltdown, etc) - and consider the tasking/purpose for the pfSense (and derivatives), there's not much benefit in any case...

one might actually see benefits with regards to latency....

At least the sysctl to enable/disable is present in pfSense, so one can try either mode...
 
I just figured out that my Xeon E3-1220v2 doesn't support HT so i don't have to bother about that one.
 
I just figured out that my Xeon E3-1220v2 doesn't support HT so i don't have to bother about that one.
Your processor has 4 hyperthreads and 4 cores. You should check your BIOS it may be turned off already.
Screenshot 2024-03-18.png
 
Looks like the new Pfsense 24.03 is now in RC so I would think we will see the new version soon.
Curious to see if i will be forced to move to CE or can just upgrade my plus-version.
 
Curious to see if i will be forced to move to CE or can just upgrade my plus-version.
I thought I read our + license is still going to be good for a year and then we expire. If you install CE you will still have the option to upgrade to + until our license expires. This is providing you don't change the hardware which will invalidate the license. No more free licenses as you have to pay.
 
I just upgraded to Pfsense 24.03. It seems to be working fine. It was a painless upgrade. It did what it was supposed to do and upgraded without issues. I think they did a fine job.
 
Now that I have upgraded and everything seems to be working. I switched today from DNS forwarding to DNS resolver.
 

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top