Complete pfSense keyboard shortcuts and commands reference — 13 shortcuts across 2 categories. Quick reference cheat sheet for Windows & Mac.
pfSense is managed from its web UI, but two lower layers matter when the UI is unreachable or a change must be scripted: the console menu you see on the physical or serial console, and the pfctl commands that talk to the packet filter underneath. The table lists both; the notes explain which pfctl commands are safe and which one can leave the firewall wide open.
| Shortcut | Action | Description |
|---|---|---|
| pfctl -sr | Show rules | Show current firewall rules. |
| pfctl -ss | Connection state | Show active connection state. |
| pfctl -d | Disable firewall | Disable packet filtering. |
| pfctl -e | Enable firewall | Enable packet filtering. |
| pfctl -f /etc/pf.conf | Reload rules | Reload firewall rules. |
| pfctl -sn | Show NAT rules | Display currently loaded NAT rules. |
| pfctl -si | Filter stats | Show packet filter statistics and counters. |
| pfctl -k [host] | Kill states | Kill all states for a specific host. |
| pfSsh.php | PHP shell | Open the pfSense developer PHP shell. |
| Shortcut | Action | Description |
|---|---|---|
| Option 1 | Assign interfaces | Re-assign WAN/LAN network interfaces from the console. |
| Option 2 | Set interface IP | Configure an interface IP address from the console. |
| Option 5 | Reboot | Reboot the firewall from the console menu. |
| Option 8 | Shell | Drop to a root shell from the console menu. |
The most essential pfSense shortcuts are: pfctl -sr (Show rules), pfctl -ss (Connection state), pfctl -d (Disable firewall).
These are command-line commands — type them in your terminal or console. Combine them with shell history search (Ctrl + R) and aliases to work even faster.
The pfSense shortcut for show rules is pfctl -sr. Show current firewall rules.
Yes — use My Stack to combine pfSense shortcuts with any other platform on this site into one printable reference, which is useful if your daily workflow spans several tools.
The numbered menu appears on the console after boot. Option 1 assigns interfaces — the first step on new hardware, and the fix when a NIC change leaves WAN and LAN swapped — and Option 2 sets an interface's IP address and can enable DHCP on the LAN, which is how you regain web access after locking yourself out with a bad address. Option 5 reboots and Option 8 drops to a FreeBSD shell where pfctl and the rest live.
pfctl -sr prints the active rule set as pf sees it, which is what to compare against the UI when a rule "should" match. pfctl -sn shows NAT rules and pfctl -ss the state table — every tracked connection — and pfctl -si prints filter statistics and counters. pfctl -k [host] kills the states for a host, which forces existing connections to be re-evaluated after a rule change without restarting anything.
pfctl -d disables packet filtering entirely: traffic passes with no rules and no NAT, which is occasionally the fastest way to prove whether the firewall is the problem, and always the wrong state to leave a machine in. pfctl -e re-enables it. pfctl -f /etc/pf.conf reloads the rules from the file pfSense generates; editing that file by hand is overwritten on the next UI change, so make persistent changes in the UI or through pfSsh.php, the PHP shell that scripts configuration the same way the UI does.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"