pfSense®CE Configuration Recommendations – Protectli Knowledge Base (2024)

pfSense® CE Configuration Recommendations

Overview

pfSense® CE is an open source routing and firewall software which is based on FreeBSD. An article covering installation can be found at this link. This article offers some basic recommendations to configure pfSense® CE on the Vault. Some of these recommendations had been in other articles, but for ease of use, we are consolidating them here in one article. This article includes the following areas of interest:

  • Thermal Monitoring
  • Enable Cryptographic Hardware assist with AES-NI and BDS
  • Power Management with PowerD
  • Enable Optional (OPT) ports

At the bottom of this article, there is a table with downloadable configuration files for each of the Vaults that include the settings described below.

Thermal Monitoring

The Vault has a solid state, compact design. The case is designed to dissipate the heat generated by the unit. Although the case may be warm to the touch, it most likely indicates that the system is functioning correctly. However, Thermal Monitoring can be used to verify the Vault is operating under normal thermal conditions. Intel based CPUs have built in thermal monitoring and pfSense® CE can access it to display temperatures on the dashboard. The following article will describe how to enable and monitor the thermal sensors.

Enable Thermal Monitoring

Enabling Thermal Monitoring is done through the pfSense® CE WebUI.

  • Browse to the pfSense® CE Dashboard, default 192.168.1.1 on the LAN port
  • Select "System –> Advanced" and click on the "Miscellaneous" tab
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (1)

System->Advanced

  • Scroll down to "Cryptographic & Thermal Hardware"
  • Click on "Thermal Sensors."
  • From the drop down, choose "Intel Core* CPU…"
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (2)

System->Advanced->Miscellaneous->Cryptographic & Thermal Hardware

  • Click "Save" button at the bottom of the page
  • Verify success message is displayed at the top of the page
  • Thermal monitoring of the CPUs is now enabled

Display Thermal Sensors on the Dashboard

The preceding steps enabled thermal monitoring. The following steps will show how to display thermal monitoring on the dashboard.

  • Select the Dashboard
  • Click the "+" icon in the upper right corner
  • Verify the "Available Widgets" box appears
  • Click the "+" next to Thermal Sensors
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (3)

Dashboard->Available Widgets

  • Verify the Thermal Sensors box is displayed at the bottom of the dashboard
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (4)

Dashboard with Thermal Monitoring, Idle

The screenshot above shows an example of the FW4B that is essentially idle for over 40 minutes. Note that the core temperatures range from 51 to 53 degrees C. This is well within normal range.

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (5)

The screenshot above shows an example of the same FW4B that is running an iperf test at linerate for over 40 minutes. Note that the CPU usage has increased from 3% to 30% and core temperatures range from 55 to 58 degrees C. Although this may seem high, and the case may be warm to the touch, it indicates that the case is functioning correctly and dissipating the heat. The Intel TJmax core temperatures from ark.intel.com for each of the processors is displayed in the table below.

PlatformCPUTJmax
FW1J1900105 C
FW2J1800105 C
FW2BJ306090 C
FW4AE3845110 C
FW4BJ316090 C
FW6A3865U100 C
FW6B7100U100 C
FW6C7200U100 C

Enable Cryptographic Hardware Support

Enabling Cryptographic Hardware Support is done through the pfSense® CE WebUI.

  • Browse to the pfSense® CE Dashboard, default 192.168.1.1 on the LAN port
  • Select "System –> Advanced" and click on the "Miscellaneous" tab

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (6) System->Advanced

  • Scroll down to "Cryptographic & Thermal Hardware"
  • Click on "Cryptographic Hardware."
  • From the drop down, choose "AES-NI and BSD Crypto Device"

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (7)

System->Advanced->Miscellaneous->Cryptographic & Thermal Hardware

  • Click "Save" button at the bottom of the page
  • Verify success message is displayed at the top of the page

At this point cryptographic hardware support should be enabled.

Power Management with PowerD

All of the Vault series use Intel CPUs that have Power Management features that allow the selection of power management modes. The power management modes trade performance vs. power by adjusting the frequency based on system load. PowerD is a power control utility built into pfSense® CE, which is inherited from the underlying FreeBSD operating system. In this section, we will enable PowerD and select the optimum performance vs. power settings.

Enable PowerD

In this example we will enable PowerD within the pfSense® CE WebUI.

  • Browse to the pfSense® CE Dashboard, default 192.168.1.1 on the LAN port
  • Navigate to theSystemtab and selectAdvanced from the drop down menu

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (8)

pfSense® CE Dashboard

  • Verify the Advanced page is displayed
  • Select the Miscellaneoustab
  • Verify the Miscellaneouspage is displayed
  • Scroll down to the section labeledPower Savings
  • To enable PowerD, check the box next toEnable PowerD
  • VerifyHiadaptiveis selected for the power modes as shown in the image below

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (9)

PowerD Settings

  • Scroll down to the bottom of the page and clickSave
  • Verify a message stating "The changes have been applied successfully" is displayed at the top of the page.

At this point, PowerD should be enabled for optimum power management.

How to Restore a Config File

  • Verify pfSense® has been installed correctly
  • Verify the correct configuration file has been downloaded from the table below and pfSense® will be able to access it
  • Log into the WebGUI. This is 192.168.1.1 by default.
  • The default pfSense® login user is 'admin' and password is 'pfsense'
  • Click Diagnostics on the top of the GUI
  • From the drop-down menu click Backup & Restore
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (10)
  • Click Choose File
  • Select the appropriate config, click open
  • Click Restore Configuration
pfSense®CE Configuration Recommendations – Protectli Knowledge Base (11)

If you experience any issues, please feel free to reach out: [email protected]. You can find additional information in our Knowledge Base, or reference pfsense.org directly.

pfSense®CE Configuration Recommendations – Protectli Knowledge Base (2024)
Top Articles
How to Calculate ROI in Digital Marketing
Google Cloud vs AWS: Which One Should You Choose? - GeeksforGeeks
Worcester Weather Underground
Koopa Wrapper 1 Point 0
Google Jobs Denver
OSRS Fishing Training Guide: Quick Methods To Reach Level 99 - Rune Fanatics
How do you mix essential oils with carrier oils?
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Capitulo 2B Answers Page 40
Wordle auf Deutsch - Wordle mit Deutschen Wörtern Spielen
735 Reeds Avenue 737 & 739 Reeds Ave., Red Bluff, CA 96080 - MLS# 20240686 | CENTURY 21
Aberration Surface Entrances
London Ups Store
Eva Mastromatteo Erie Pa
Epro Warrant Search
10 Fun Things to Do in Elk Grove, CA | Explore Elk Grove
Kamzz Llc
Closest Bj Near Me
Cincinnati Adult Search
The Weather Channel Local Weather Forecast
Menus - Sea Level Oyster Bar - NBPT
Like Some Annoyed Drivers Wsj Crossword
Pain Out Maxx Kratom
Wolfwalkers 123Movies
Craigslist Auburn Al
Federal Express Drop Off Center Near Me
Log in or sign up to view
10 Best Quotes From Venom (2018)
Mosley Lane Candles
Sam's Club Gas Price Hilliard
Baddies Only .Tv
Microsoftlicentiespecialist.nl - Microcenter - ICT voor het MKB
Louisville Volleyball Team Leaks
Imperialism Flocabulary Quiz Answers
Telegram update adds quote formatting and new linking options
Aliciabibs
Jail View Sumter
Ticket To Paradise Showtimes Near Regal Citrus Park
Legit Ticket Sites - Seatgeek vs Stubhub [Fees, Customer Service, Security]
Blackstone Launchpad Ucf
Discover Things To Do In Lubbock
[Teen Titans] Starfire In Heat - Chapter 1 - Umbrelloid - Teen Titans
Cleveland Save 25% - Lighthouse Immersive Studios | Buy Tickets
Doe mee met ons loyaliteitsprogramma | Victoria Club
John Wick: Kapitel 4 (2023)
Yosemite Sam Hood Ornament
Paradise leaked: An analysis of offshore data leaks
Smoke From Street Outlaws Net Worth
How to Find Mugshots: 11 Steps (with Pictures) - wikiHow
Latest Posts
Article information

Author: Patricia Veum II

Last Updated:

Views: 6174

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Patricia Veum II

Birthday: 1994-12-16

Address: 2064 Little Summit, Goldieton, MS 97651-0862

Phone: +6873952696715

Job: Principal Officer

Hobby: Rafting, Cabaret, Candle making, Jigsaw puzzles, Inline skating, Magic, Graffiti

Introduction: My name is Patricia Veum II, I am a vast, combative, smiling, famous, inexpensive, zealous, sparkling person who loves writing and wants to share my knowledge and understanding with you.