pfSense Menu Reference - All Web GUI Menu Items

The pfSense web interface contains seven top-level menus, each grouping functions of a specific category. Below is a complete listing of every menu item with its navigation path and a brief description of its purpose. For detailed configuration guidance on each feature, consult the corresponding documentation section.

System

The System menu holds general system settings, user management, certificates, updates, and routing configuration.

Menu ItemPathDescription
General SetupSystem > General SetupHostname, domain, DNS servers, time zone, and GUI theme
AdvancedSystem > AdvancedAdvanced settings: admin access, firewall/NAT tuning, networking, notifications, miscellaneous
Cert ManagerSystem > Cert ManagerCertificate authority, server and user certificate management, CRL administration
High Avail. SyncSystem > High Avail. SyncXMLRPC configuration synchronization between HA cluster nodes
LogoutSystem > LogoutEnd the current administrator session
Package ManagerSystem > Package ManagerInstall, remove, and update additional packages
RoutingSystem > RoutingGateway management, gateway groups, and static route configuration
Setup WizardSystem > Setup WizardInitial system configuration wizard
UpdateSystem > UpdateCheck for and install pfSense updates
User ManagerSystem > User ManagerLocal user and group management, LDAP/RADIUS authentication server configuration

Interfaces

The Interfaces menu contains network interface settings, VLANs, bridges, and link aggregation.

Menu ItemPathDescription
Interface AssignmentsInterfaces > AssignmentsMap physical and virtual ports to logical interfaces
Interface GroupsInterfaces > Assignments > Interface GroupsGroup interfaces for shared firewall rule application
WirelessInterfaces > Assignments > WirelessCreate virtual wireless interfaces (VAP)
VLANsInterfaces > Assignments > VLANsCreate 802.1Q VLAN interfaces
BridgesInterfaces > Assignments > BridgesCreate Layer 2 network bridges between interfaces
GIFInterfaces > Assignments > GIFsCreate GIF tunnels (Generic Tunnel Interface) for IPv6-in-IPv4 encapsulation
GREInterfaces > Assignments > GREsCreate GRE tunnels (Generic Routing Encapsulation)
LAGGInterfaces > Assignments > LAGGsAggregate physical interfaces (LACP, failover, loadbalance, roundrobin)
QinQInterfaces > Assignments > QinQCreate QinQ interfaces (802.1ad, VLAN stacking)
PPPsInterfaces > Assignments > PPPsConfigure PPPoE, PPTP, and L2TP WAN connections
WANInterfaces > WANWAN interface parameters (IP address, gateway, MTU, MSS)
LANInterfaces > LANLAN interface parameters
OPTnInterfaces > OPTnAdditional interface configuration (OPT1, OPT2, and so on)

Firewall

The Firewall menu manages packet filtering rules, NAT, aliases, and traffic shaping.

Menu ItemPathDescription
AliasesFirewall > AliasesCreate named groups of IP addresses, ports, and URLs for use in rules
NATFirewall > NATConfigure Port Forward, 1:1 NAT, and Outbound NAT
RulesFirewall > RulesManage firewall rules per interface (WAN, LAN, OPTn, Floating Rules)
SchedulesFirewall > SchedulesCreate time-based schedules for conditional firewall rule enforcement
Traffic ShaperFirewall > Traffic ShaperConfigure QoS and bandwidth management (ALTQ, Limiters)
Virtual IPsFirewall > Virtual IPsCreate virtual IP addresses (CARP, IP Alias, Proxy ARP, Other)

Services

The Services menu holds configuration for network services provided by pfSense.

Menu ItemPathDescription
Captive PortalServices > Captive PortalConfigure an authentication portal for guest and public networks
DHCP RelayServices > DHCP RelayRelay DHCP requests to an external DHCP server
DHCP ServerServices > DHCP ServerConfigure the DHCP server per interface (pools, static mappings, options)
DHCPv6 Server & RAServices > DHCPv6 Server & RAConfigure DHCPv6 and Router Advertisement for IPv6 networks
DNS ForwarderServices > DNS ForwarderDNS proxy based on dnsmasq (host overrides, domain overrides)
DNS ResolverServices > DNS ResolverRecursive DNS resolver based on Unbound (DNSSEC, DNS over TLS, host overrides)
Dynamic DNSServices > Dynamic DNSUpdate DNS records automatically when the WAN IP address changes
IGMP ProxyServices > IGMP ProxyProxy IGMP traffic between interfaces for multicast streams (IPTV)
NTPServices > NTPNTP server and time synchronization settings
PPPoE ServerServices > PPPoE ServerCreate a PPPoE server to provide client connections
SNMPServices > SNMPConfigure the SNMP agent for system monitoring by external NMS platforms
UPnP & NAT-PMPServices > UPnP & NAT-PMPAutomatic NAT rule creation on application request (gaming, torrents)
Wake-on-LANServices > Wake-on-LANSend WoL packets to remotely power on network devices

VPN

The VPN menu contains settings for all supported VPN connection types.

Menu ItemPathDescription
IPsecVPN > IPsecConfigure IPsec VPN - Phase 1/Phase 2 tunnels, mobile clients
L2TPVPN > L2TPConfigure the L2TP VPN server (typically used alongside IPsec)
OpenVPNVPN > OpenVPNConfigure OpenVPN - servers, clients, site-to-site and remote access
WireGuardVPN > WireGuardConfigure WireGuard VPN - tunnels, peers, key generation

Status

The Status menu provides information about the current state of the system and all its components.

Menu ItemPathDescription
CARP (failover)Status > CARP (failover)CARP virtual IP status and high availability cluster state
DashboardStatus > DashboardMain monitoring dashboard with widgets (CPU load, memory, traffic, services)
DHCP LeasesStatus > DHCP LeasesList of active and static DHCP leases per interface
Filter ReloadStatus > Filter ReloadPacket filter reload status and manual filter reload trigger
GatewaysStatus > GatewaysGateway status, RTT, packet loss, and monitoring state
InterfacesStatus > InterfacesStatus of all network interfaces (IP, MAC, statistics, link speed)
IPsecStatus > IPsecIPsec tunnel status for Phase 1 and Phase 2, SA state
LogsStatus > LogsSystem logs: System, Firewall, DHCP, DNS, VPN, Gateway, Routing, and others
MonitoringStatus > MonitoringRRD graphs: traffic, link quality, system resource utilization
NTPStatus > NTPNTP synchronization status and list of configured time servers
OpenVPNStatus > OpenVPNOpenVPN server status and connected clients
QueuesStatus > QueuesTraffic shaper queue statistics (ALTQ)
ServicesStatus > ServicesList of all services with running/stopped status indicators
Traffic GraphStatus > Traffic GraphReal-time traffic graphs per interface
UPnP & NAT-PMPStatus > UPnP & NAT-PMPList of current NAT rules created via UPnP
WireGuardStatus > WireGuardWireGuard tunnel status, connected peers, handshake time, traffic counters

Diagnostics

The Diagnostics menu contains troubleshooting tools, backup utilities, and system management functions.

Menu ItemPathDescription
ARP TableDiagnostics > ARP TableARP table showing IP-to-MAC address mappings on local networks
AuthenticationDiagnostics > AuthenticationTest user authentication against configured servers (LDAP, RADIUS)
Backup & RestoreDiagnostics > Backup & RestoreBack up and restore the system configuration (XML)
Command PromptDiagnostics > Command PromptExecute shell commands and PHP code through the web interface
DNS LookupDiagnostics > DNS LookupPerform DNS queries for name resolution diagnostics
Edit FileDiagnostics > Edit FileEdit files on the filesystem through the web interface
Factory DefaultsDiagnostics > Factory DefaultsReset the configuration to factory defaults
Halt SystemDiagnostics > Halt SystemPerform a clean system shutdown
Limiter InfoDiagnostics > Limiter InfoDisplay configured limiters and their current state
NDP TableDiagnostics > NDP TableNDP (Neighbor Discovery Protocol) table for IPv6 neighbors
Packet CaptureDiagnostics > Packet CaptureCapture network packets (tcpdump) on a selected interface with filtering
pfInfoDiagnostics > pfInfoPacket filter statistics (counters, states, tables)
pfTopDiagnostics > pfTopReal-time active connections in the packet filter (top-like view for pf)
PingDiagnostics > PingSend ICMP requests to verify host reachability
RebootDiagnostics > RebootReboot the pfSense system
RoutesDiagnostics > RoutesSystem routing table (IPv4 and IPv6)
S.M.A.R.T. StatusDiagnostics > S.M.A.R.T. StatusStorage device health status via S.M.A.R.T. data
SocketsDiagnostics > SocketsList of open network sockets (listening ports and connections)
StatesDiagnostics > StatesPacket filter state table (active connections, NAT translations)
States SummaryDiagnostics > States SummaryFirewall state summary grouped by IP, port, and protocol
System ActivityDiagnostics > System ActivitySystem process activity (equivalent to the top command)
TablesDiagnostics > TablesContents of pf tables (bogons, snort2c, virusprot, and custom tables)
TracerouteDiagnostics > TracerouteTrace the network route to a specified host
Last updated on