Subcategories

  • Discussions and feedback related to this forum

    612 Topics
    3k Posts
    tinfoilmattT
    @SteveITS Possibly something with that ESMTPSA > SMTP > ESMTPS. But yeah, who knows.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    29 Topics
    117 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • Firewall logs

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    F
    hello, my English is not very good, I have a pfsense, and have formed logs External syslog server, but the events of firewall are not regitrados in the server logs, the messages of authentication and messages of the system if, but what me intereza is really the messages of discarded or blocked packages, the server logs in freeBSD 6,1 Release, and syslog-ng 1.6, some suggestion?
  • Thinking about converting from smoothwall

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    ?
    @sdale: We are running 2.6.1.3 I look forward to playing with it  ;D
  • A lot of questions

    Locked
    14
    0 Votes
    14 Posts
    8k Views
    H
    CVS Trac is the only option but there are some bugs that have been corrected without opening tickets for them. So only looking at the tickets won't help you unless you read the commit logs as well.
  • Dd-wrt VS pfsense

    Locked
    6
    0 Votes
    6 Posts
    29k Views
    H
    hey guys, you are comparing a small linux box (200 MHz, 16 Mb RAM) to a computer with 256 or 512 Mb of RAM and a big processor. so it is normal to have unstability problem with the small router when it handels a lot of connections, bittorent and P2P…. but DD-WRT have a X86 version that runs on PCs and it is really stable and faster than Pfsense. I am using now many dd-wrt boxes as access points, and pfsense is doing the rest (DHCP, authentication...) pfsense never crash but it have a lot of bugs and missing futures. it would be appreciated if pfsense have some of DD-WRT futures like additionnal DHCP options / DNSmasq as DHCP server, windows networking is not working well in pfsense (from LAN to WAN, LAN clients cannot see PC connected on WAN domain for exemple in latest pfsense release). i think that this problem is related to a DNS / firewall bugs ? I prefer SPI firewall than pfsense, but it is a personal choice Access restrictions per IP or MAC address is also missed in actual Pfsense release. blocking P2P and other applications or website is easy with dd-wrt QoS, priority per IP, MAC, subnet or application... in VLANs also the hotspot options : DD-WRT can use chillispot, nocat, spuntik for authentications... it would be nice if chillispot can be add to pfsense via a package (it needs a package for chillispot, radius, webserver... MySQL is also preferable). a monitoring package like Rflow is also missed in pfsense, it is not perfect in dd-wrt but the best is to have a package or a small software that list all connected users (users, mac, ip, time and trafic) with the possibility to disconnect users -finally a nice future that could be easy implemented in pfsense I thnik, is the possibility to define a user groups and to add (in captive portal) its static DHCP mapping anyway pfsense is a very good firewall and the support on the forum is very fast and appreciable. Chady
  • MOVED: Any bandwidth monitors that can track monthly bandwidth usage?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Some interesting stuff

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Ssl proxy

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • How to know which rule a syslog entry is referring to?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J
    One additional mod to the pfctl form: If you want to quickly pull out a single rule: pfctl -vvs rules | grep "^@ <rulenum>"</rulenum> Where is the rule number you are seeking.  The space before my closing double quote was on purpose to terminate the pattern so that ONLY the rule number being sought is returned.  Otherwise, the above might also match some other rule number that started off with the rule number you are seeking.  Ie, '77' and '77x' (x = 0 thru 9) would all match.
  • How to install antivirus software?

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    JeGrJ
    Without knowning more details (what server- and what firewall-arch) I would respond to I want to avoid viruses on the server´s system files and in E-Mails, sent and received over the server Scan e-Mails on their way to the server via a mailgateway. It wouldn't be the first time there was some strange side effect when doing the scanning on the same system having the normal mail service on. Get them out before they reach the final destination server (and the user) and run an additional AV on the normal filesystem of the server for file services. But I would not run that kind of thing on the firewall itself. Keep the firewall architecture as clean as possible and don't mix it with further services if they don't have necessarily to do with it. E.g. split the fw-arch into three nets, WAN, DMZ and LAN and setup the mailgateway in the DMZ area. So you don't have any probably "bad things" in your LAN before it passes all your desired tests. Just my thoughts on this :)
  • Will this CARP setup work?

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    H
    Not to mention that "dumb" switches are cheaper than manageable vlan capable switches.
  • Support Consultans in Denmark

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    H
    Depending on what exactly you need I can do support for you too. You can reach me by mail at holger <dot>bauer <at>citec-ag <dot>de. Remote service shouldn't be any problem. If you need someone on site we could discuss this as well.</dot></at></dot>
  • Free Wireless across delmarva -fWad-

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • MOVED: Customize the web interface

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Upload limit on this forum

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Had to shut PFSense Down after 396 days

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    H
    Oh, just saw from the screenshot, it's even a livecd system  :o
  • PFsense Beta 2

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    S
    Beta 2 is OLD. Please update to 1.0.1.
  • Squid & Samba on pfSense

    Locked
    9
    0 Votes
    9 Posts
    16k Views
    J
    I am really looking forward to this package :)
  • Active reporting on cluster take over

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    Agree'd.  I am looking at mailing infrastructure scripts so that we can add email support to pfS.  Once this is completed we can e-mail all sorts of stuff, including this.
  • Exempt urls from load balance

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    Do a nslookup on these sites. Then add all these IPs to a hosts alias and use policybased routing to send these connections out only through one of your wans. Alternatively you could just send out https protocol only one of your wans. At our office the https rule fixed 99% of all issues with onlinebanking sites (at least if they run as browsersession rather than using a special application). Out head code has support for adding URLs as aliases btw but that version is not ready yet for productional use.
  • Re: 1.0 release - cannot upgrade from embedded updates?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    You may need to reflash then. And in the future please do not hijack threads.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.