PfSense, VLAN’s, and SSH Disconnects (and how to fix it)

For the past month or so my storage box has been driving me insane. Whenever I SSH into the box, after about 30 seconds it would always disconnect me. I checked everything from routes, to firewall rules, and nothing was amiss. I spent weeks looking for the cause of these SSH Disconnects, but to no avail. That is, until recently. After some extreme googling, I was able to figure out the cause and I had to share it.

On the server in question, I have it hooked up to two networks. One vi cable, and another using a VLAN tag on the same port. If I were to take down the VLAN interface, or the direct cable interface, then SSH would not have any disconnect issues. This lead me to believe it was a routing issue, or a network configuration problem. Well in the end, I found the cause to be none other then my firewall, PfSense!

After finding a thread on their forum with someone who shared my troubles, I was able to find a solution and I felt it should be shared. (That said thread is linked at the bottom of this post).

So, lets get started!

  1. Login to your PfSense firewall
  2. Go to System > Advanced > Firewall / NAT
  3. Set Firewall Optimization Options to Conservative
  4. Enable Clear invalid DF bits instead of dropping the packets

In the end, it should look like this:

PfSense Firewall Settings to fix SSH Disconnects

 

 

 

 

 

After this, my SSH disconnects completely disappeared! I hope you find this as useful as I did.

Citation:

http://forum.pfsense.org/index.php?topic=35203.0

58 thoughts on “PfSense, VLAN’s, and SSH Disconnects (and how to fix it)

  1. Pingback: SSH connection through UTM 9 VM dropping after 1 min - Sophos User Bulletin Board

  2. Tilghman Lesher

    Excellent! That worked for us, as well, although our symptoms were slightly different. During backup times, when the network was being stressed, this would occur to long-running persistent SSH connections. This change has allowed those sessions to remain connected.

    Reply
  3. Oliver

    I tried that solution, and at the first look it worked
    But the problem must be elsewhere. If you take a look at the help page of pfSense it shows that in the “normal” Firewall mode “tcp.opening No response yet” get terminated after 30secs which is the time ssh takes to disconnect.
    https://doc.pfsense.org/index.php/Advanced_Setup#Firewall.2FNAT

    In “conservative” mode this time is just increased to 15min!
    So i waited for 15min instead of 30sec -> and the same problem occured.

    Do you have any idea what else it could be?

    Reply
  4. Dave W

    Thank you!!!! That has been driving me crazy for the last few days. I’ve been configuring a pfSense for our new external connection and switched to using it as my gateway to test.
    As soon as I did that, and configured the VLANs on pfSense, the SSH to the switched kept bombing out after a couple of minutes.
    I thought I had configured the VLANs wrong or that the box we are using wasn’t up to the task… Then I stumbled on your post.

    Reply
  5. Nico Bouthoorn

    Thanks it was a head banger!, my situation: a internal openvpn server, a ssh session from this openvpn tunnel on a virtual subnet internally.
    The tcp sessions allway’s freezes at about 47s.

    Reply
  6. Carlos Alberto Teixeira

    Many thanks from Ceará Brazil.

    But just switch Firewall Optimization Options to Conservative solved this issue to me.

    Best regards.

    Reply
  7. User10

    Wow. Finaly I was able to find the resolution to my SSH problems behind pFsense. Thank you very much for sharing this!

    Reply
  8. Laraib

    You’re good. Thank you sooo much Sir. I wasn’t able to find any solution for it and now it’s working flawlessly!

    Reply
  9. MSH

    Thanks. This problem has vexxed me occasionally numerous times. Was for a netgate 7541 routing between interfaces.

    Reply
  10. Elba Mace

    Hi there,
    Elba here.
    I’ve uncovered an email marketing strategy that the big players don’t want you to know.
    No contact limits, flat pricing. No price change when you grow your list. Plus, you can try it all for free.
    Interested? Just reply with “Tell me more” and I’ll share the full scoop.
    Trust me, you won’t want to miss this.
    Best regards,
    Elba Mace

    Reply
  11. Yetta Wetherspoon

    Discover the best in e-commerce with Shopify

    The premier platform designed for businesses of all sizes.

    Shopify offers an easily affordable pricing structure, making it accessible for startups and established enterprises alike.

    Benefit from exceptional customer support, available 24/7 to assist with any queries or issues you might face.
    Choose Shopify to streamline your online store management, enhance your customer experience, and drive your business success.
    Join the millions of merchants who trust Shopify as their e-commerce partner.

    Start today and watch your business thrive.

    Simply Visit Us @ shopify.pxf.io/jr04aa

    Bring your ideas to life for €1/month

    Reply
  12. Dimitar Kehayov

    Dear Ladies and Gentlemen,
    accessibility to medical care is becoming increasingly difficult, which is why we offer you our unique medical service, namely: “online medical consultation”.
    We are a multidisciplinary medical team of proven health specialists in their field, who are able to adequately and quickly solve any of your medical problems, regardless of whether they are diagnostic, differential diagnostic or therapeutic!
    Simply write to us on one of your messengers at: 00359884777799, we have all available messengers and our specialist will contact you quickly.
    You can learn more about our hospital and medical activities from our website:
    https://www.toxylact.com/clinic/index.html
    With the confidence that we will be useful to you, we remain waiting for your medical cases.
    Sincerely
    Dr. Dimitar Kehayov Doctor of Medical Sciences
    Burgas
    Bulgaria

    Reply
  13. Camila M

    Hey,

    Not a pitch – just something I noticed.

    Your business feels solid.
    Your visual identity feels slightly disconnected.

    It’s subtle, but it affects how people recognize you.

    Small thing, but it shapes first impressions.

    My portfolio if you’re curious:
    https://bit.ly/m/portfolio-Camila

    Camila

    Reply
  14. Kim Greig

    Hello,

    We came across your WooCommerce store and really liked what you’re building.

    With LetsTok AI, you can turn your product listings into ready-to-use ad creatives and videos. It also helps you find and recreate competitor ads tailored to your products.

    If you’d like to explore it, you can start here:
    https://letstokvideo.com

    Thanks,
    Kim Greig
    Letstok AI

    Whenever you prefer not to get additional messages from this campaign, just fill the form at bit. ly/fillunsubform with your domain address (URL).
    Grossgstotten 87, Ithaca, CA, USA, 95374

    Reply
  15. Therese Bungaree

    Hey there,

    Plain websites are starting to feel outdated

    A lot of businesses still see their website as a collection of pages.

    Visitors do not behave that way anymore.

    Customers treat websites like conversations now.
    They arrive with intent. Questions. Urgency.
    If they cannot get answers quickly, they leave.

    No follow-up. No second attempt. No loyalty.

    Just a missed opportunity.

    The hard truth is simple:

    A website with no AI interaction is going to feel as outdated as a company that never adapted to mobile.

    That shift is already underway.

    Modern websites talk. Old ones lose.

    See it in action: https://theollehai.com

    Regards,
    Therese Bungaree
    Olleh AI

    If at any point you choose to opt-out of further communications from me, please fill the form at bit. ly/fillunsubform with your domain address (URL).
    18 Flax Court, Johnson City, CA, USA, 94269

    Reply
  16. Ruby White

    Hi Team snt.sh,

    I was reviewing your website & noticed a few issues that may be affecting its search ranking. we can help you improve it.

    May I share a detailed report of these issues along with our pricing.

    Thank you!
    Ruby White

    Reply
  17. Collin Mcdermott

    Hello,

    There are only two types of businesses now:

    Companies already using AI.
    And companies slowly being pushed behind by them.

    This shift is happening faster than most companies understand.

    Customers already expect answers without waiting. Relevant suggestions on demand. Instant interaction.

    Static websites cannot compete with conversational experiences anymore.

    That is why websites are moving from navigation to conversation

    Olleh AI helps businesses upgrade their websites with AI voice + chat agents trained on their business, services, and workflows.

    The companies moving fastest are not waiting for a perfect moment.
    They’re implementing AI now.

    See what an AI-powered website looks like:
    https://theolleh.com

    Best Regards,
    Collin Mcdermott
    Olleh

    If at any point you choose to opt-out of any more emails from me, kindly fill the form at bit. ly/fillunsubform with your domain address (URL).
    52 Eshelby Drive, Croghan, CA, USA, 94649

    Reply
  18. Camila M

    Hey,

    Not a pitch – just something I noticed.

    Your business feels solid.
    Your visual identity feels slightly disconnected.

    It’s subtle, but it affects how people recognize you.

    Small thing, but it shapes first impressions.

    My portfolio if you’re curious:
    https://bit.ly/m/portfolio-Camila

    Camila

    Reply
  19. Camila M

    Hey,

    Not a pitch – just something I noticed.

    Your business feels solid.
    Your visual identity feels slightly disconnected.

    It’s subtle, but it affects how people recognize you.

    Small thing, but it shapes first impressions.

    My portfolio if you’re curious:
    https://bit.ly/m/portfolio-Camila

    Camila

    Reply
  20. Annabelle Damron

    Hey there,

    We noticed your site and figured this may be useful for your business.

    Our platform helps you create AI-powered ads, connect your socials, and handle publishing easily — completely free to start.

    You can also scan competitor ads and recreate them for your business in seconds.

    No commitment — just free tools if you want to try it.

    Take a look here:
    https://letstalkugc.com

    – Letstok AI

    Whenever you decide not to receive subsequent correspondence from our side, simply fill the form at brnd .li/delist webpage with your domain address (URL).
    Obere Haltenstrasse 113, Greenwich, CA, USA, 92774

    Reply
  21. Frankie Benner

    Hi there,

    Waiting on AI has a real cost

    A lot of teams still put AI in the “later” category.

    It isn’t.

    AI is already becoming an operational advantage.

    Every month businesses delay AI adoption, competitors collect:

    – More insight into what visitors actually ask
    – Faster response systems
    – Better lead qualification
    – More efficient support handling
    – Stronger conversion paths

    The advantage builds on itself.
    Fast.

    We have seen this movie before with:

    – Businesses that adapted early to mobile
    – E-commerce
    – Search visibility
    – Customer attention through social channels

    Businesses that moved early built momentum while others were still debating.

    AI will be bigger than all of them.

    The businesses implementing conversational AI today are building advantages that become harder to compete against tomorrow.

    See it in action: https://theollehai.com

    Best,
    — Frankie Benner
    OllehAI

    Should you choose to opt-out of future emails from me, please fill the form at brnd .li/delist webpage with your domain address (URL).
    3284 Pearlman Avenue, Endicott, CA, USA, 92560

    Reply
  22. Blair Durant

    Hey there,

    Business websites are moving into two very different categories now:

    Companies already using AI.
    And businesses getting replaced by them.

    This change is moving faster than many teams realize.

    Customers already expect immediate replies. Relevant suggestions on demand. A real response the moment they arrive.

    Plain websites are starting to lose against sites that can answer, guide, and qualify visitors in real time.

    The shift is simple: from clicking around to asking and getting answers.

    With Olleh AI, businesses can add AI voice + chat agents that understand their offer, answer visitors, capture intent, and support real workflows.

    Your competitors are not treating this like a someday upgrade.
    They’re implementing AI now.

    Check it out:
    https://theolleh.com

    Thanks,
    Blair Durant
    The Olleh

    If at any point you choose to opt-out of subsequent notifications from this campaign, kindly fill the form at brnd .li/delist URL with your domain address (URL).
    Ludvikdalen 165, Morris, CA, USA, 94913

    Reply
  23. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    You can reach me at: [email protected]

    Camila

    Reply
  24. Judith Reinhardt

    Hello,

    Your market is being trained into AI

    Right now, businesses in every industry are training AI to:

    – Respond to customer questions instantly
    – Capture leads automatically
    – Identify serious buyers faster
    – Manage common support requests before a human is needed
    – Replace friction on websites

    Most businesses are still asking visitors to:

    – Figure things out by clicking through pages
    – Click menus and hope they find the right thing
    – Submit forms and wait

    That model is dying.

    The companies training AI now are building tomorrow’s customer-attention advantage.

    Customers are not patient browsers anymore. They ask direct questions.
    And companies that cannot answer instantly will lose attention to the ones that can.

    Check it out:
    https://theolleh.com

    Best,
    — Judith Reinhardt
    OllehAI

    If at any point you decide not to receive subsequent messages from me, feel free to fill the form at brnd .li/delist url with your domain address (URL).
    Kohaven 94, Monticello, CA, USA, 93127

    Reply
  25. Abhi Dwivedi

    Hi,

    You don’t need experience to start an Amazon FBA business if you follow the right system.

    Start here: https://paykstrt.com/55932/177130

    to see the complete training and roadmap.

    Everything is broken down into simple steps: product research, sourcing, and launching.

    Learn how beginners are building real online businesses with Amazon

    Reply
  26. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    You can reach me at: [email protected]

    Camila

    Reply
  27. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    You can reach me at: [email protected]

    Camila

    Reply
  28. sign up binance

    Thank you for your sharing. I am worried that I lack creative ideas. It is your article that makes me full of hope. Thank you. But, I have a question, can you help me?

    Reply
  29. Leonard Hedin

    Hi,

    Competitors are already training AI on their business

    Right now, businesses in every industry are training AI to:

    – Answer customer questions instantly
    – Collect qualified interest without forcing people through static forms
    – Separate casual visitors from ready-to-act prospects
    – Handle repetitive support
    – Replace friction on websites

    Most businesses are still asking visitors to:

    – “Browse pages”
    – Navigate menus instead of asking direct questions
    – “Submit forms”

    That way of handling visitors is becoming outdated fast.

    The businesses training AI today will own customer attention tomorrow.

    Customers are not patient browsers anymore. They ask direct questions.
    The business that responds first, clearly, and intelligently gets the advantage.

    Check it out now:
    https://theolleh.com

    Best,
    — Leonard Hedin
    OllehAI

    If you choose to opt-out of any more correspondence from our side, feel free to fill the form at brnd .li/delist webpage with your domain address (URL).
    64 Quai Saint-Nicolas, Binghamton, CA, USA, 92377

    Reply
  30. Carey Laidley

    Hey there,

    Your market is being trained into AI

    Right now, businesses in every industry are training AI to:

    – Answer customer questions instantly
    – Capture leads automatically
    – Qualify buyers
    – Handle repetitive support
    – Make the website feel less like a maze and more like a guided conversation

    Meanwhile most websites still depend on:

    – Figure things out by clicking through pages
    – “Click menus”
    – Fill out a form before getting any useful response

    That model is dying.

    The companies training AI now are building tomorrow’s customer-attention advantage.

    Customers are not patient browsers anymore. They ask direct questions.
    And businesses that cannot respond instantly will lose to businesses that can.

    Leave your competitors behind:
    https://theolleh.com

    Warm Regards,
    — Carey Laidley
    Olleh AI

    If you decide not to receive future emails from us, kindly fill the form at brnd .li/delist URL with your domain address (URL).
    Faerberplatz 79, New Rochelle, CA, USA, 95304

    Reply
  31. Jo Holden

    Hi,

    I’m just wondering if you’ve ever considered using snt.sh on Google Ads?

    It’s something we’ve been involved with for over 20 years now (back when it was called Adwords) and is very useful to get a step ahead of your competitors.

    Happy to send more information if it’s of interest.

    Kind Regards,
    Jo

    Reply
  32. Marisol Denison

    I’ve noticed that your snt.sh website could be missing out on approximately 1,000 visitors daily. Our AI powered traffic system is designed to significantly boost your site’s visibility. https://cutt.ly/Sw2BAXtw
    We’re offering a free trial that includes 500 targeted visitors to demonstrate the potential benefits. After the trial, we can provide up to 250,000 targeted visitors per month. This opportunity could greatly enhance your website’s reach and engagement.

    Reply
  33. Gemma Marshall

    Hi,

    I was just looking at snt.sh and wanted to ask: are you looking to scale your Instagram presence right now?

    We help brands like yours add 300+ targeted Instagram followers every month using manual outreach and ads. We can grow your existing page or even build a brand-new profile from scratch for you if you’d prefer a fresh start.

    Would you like me to send over some more info on how it works?

    Thanks for your time,
    Gemma

    Reply
  34. Rodger Floyd

    Hi there,

    Every month you delay, competitors get stronger

    A lot of teams still put AI in the “later” category.

    That is already outdated thinking.

    It’s an operational advantage happening right now.

    While some businesses wait, early adopters are collecting:

    – More real customer questions and interaction data
    – Better systems for answering without delay
    – Sharper lead qualification
    – More efficient support
    – More visitors turning into leads, bookings, and buyers

    The advantage builds on itself.
    Faster than most late adopters expect.

    This is exactly what happened with:

    – Mobile-first businesses
    – E-commerce
    – Organic search
    – Social distribution

    Businesses that moved early built momentum while others were still debating.

    This AI shift is larger because it changes how customers interact with the business itself.

    Companies adding conversational AI now are creating advantages that get harder to match later.

    Check it out now: https://theollehai.com

    Regards,
    — Rodger Floyd
    Olleh AI

    If you choose to opt-out of further emails from our side, feel free to fill the form at brnd .li/delist url with your domain address (URL).
    Pfarrgasse 19, Amsterdam, CA, USA, 92736

    Reply
  35. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    Here’s my portfolio: https://tinyurl.com/CamilaM-Brand-Designer

    Camila

    Reply
  36. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    Here’s my portfolio: https://tinyurl.com/CamilaM-Brand-Designer

    Camila

    Reply
  37. Yasuhiro Yamada

    Hi Sir,

    Please we want to inquire if you can handle our company’s affairs in USA. It’s a part-time job and will only take few minutes of your time daily and it will not bring any conflict of interest in case you are working with another company. If interested, contact this email address: [email protected]

    Regards,
    Yasuhiro Yamada
    Senior Executive Officer,
    ROHTO Pharmaceutical Co.,Ltd

    If at any point you decide not to receive any more correspondence from me, just fill the form at brnd .li/delist webpage with your domain address (URL).
    Passauer Strasse 19, Canajoharie, CA, USA, 92572

    Reply
  38. Camila M

    Hey,

    I came across your website and noticed something interesting.

    The business feels solid, but the visual identity doesn’t feel fully aligned yet. Things like the logo, colors, and overall style could work together more consistently.

    It’s a small detail, but it has a big impact on how people recognize and remember a brand.

    If you’d like, I can share a few quick observations.

    Here’s my portfolio: https://tinyurl.com/CamilaM-Brand-Designer

    Camila

    Reply
  39. Ruby White

    Hi Team snt.sh,

    I was reviewing your website & noticed a few issues that may be affecting its search ranking. we can help you improve it.

    May I share a detailed report of these issues along with our pricing.

    Thank you!
    Ruby White

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *