Subcategories

  • Discussions and feedback related to this forum

    607 Topics
    3k Posts
    johnpozJ

    @microserfs and what IP was that - clearly your current IPv6 address is not block that I show you connected with.. And the only other IPv4 I see you using is not blocked.. You would have to let me know what IP you were coming from that was blocked.. Send it to me via PM if you don't want to make it public.

  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    27 Topics
    114 Posts
    w0wW

    @sef1414
    Name it "run.sh", copy to pf and chmod according documentation
    https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option
    You will see messages in the system log like those quoted in the script after logger command.

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • This topic is deleted!

    Locked Moved
    10
    0 Votes
    10 Posts
    183 Views
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    7 Views
    No one has replied
  • New network design

    4
    0 Votes
    4 Posts
    626 Views
    W

    Thank's for the tips, I have never used VLAN before but I will definitely look into that right now. Just a few more questions:

    If I add a 4 port network pci card into my proxmox machine, is it possible to dedicate 1 port to a specific virtual machine? Maybe this way I can easily split the network traffic using the managed switch. My switch has 4 Gigabit SFP ports, will I have any benefits if I connect the hypervisor and the freenas machine to the switch using SFP port with a DAC cable? I mean I know it's still a 1Gbit port but I don't know if I will get benefits on speed using that.

    Thank you :)

  • Was My ISP on Phishing Expedition?

    3
    0 Votes
    3 Posts
    594 Views
    NollipfSenseN

    @Gertjan said in Was My ISP on Phishing Expedition?:

    How can the ISP (want to) connect to a router's LAN address ?
    This upstream router, the one above pfSense, has a firewall , right ?

    Thank you Gertjan for responding! Yes, yes...it wasn't going anywhere. The only upstream above the pfSense is the cable modem...so, it wasn't going anywhere pass the NIC.

    @Gertjan said in Was My ISP on Phishing Expedition?:

    The IDS running on pfSense sees suspected DNS packets ... why ?
    Do you let 'unknown' DNS packets coming in ? Are you hosting a master or salve DNS server ?

    Because the NIC with IDS/IPS would see the packet before the firewall would. No, that's strictly forbidden. No, no master nor slave...just the edge pfSense does DNS.

    @Gertjan said in Was My ISP on Phishing Expedition?:

    My pfSense WAN interface uses the default rule : none. So, nothing comes in - except answers from stuff I asked for. I guess ... I'm not even "IDS", I trust my LAN devices.

    Same here...have highly trusted LAN govern by a new Mikrotik RB450Gx4; however, its default LAN is 192.168.88.1...but that's not its current custom IP address configuration that is 10.0.8.1. That's why I am curious why the connection attempt to that default address or to 10.8.8.1...none exist on my network. However, my ISP knew that I had the earlier Mikrotik RB450G when that was my edge router.

    What I am suspecting is my ISP was wanting to make it look as if I have Internet by issuing a private address to make the cable modem appear to be working by the link light blinking. I came to this conclusion because shortly after the intrusion event attempt, I received a call from the ISP that they were coming out to my home to test. It seems that they wanted to extract additional fee(s) for service.

    Of course, I am highly pissed...these are things they have done to the common uninformed person, and it's deceitful. Does my suspicion reasonable...makes sense?

  • Discord server for pfSense?

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    johnpozJ

    All of those chat services are not the best for tech support... You need history, you need easy ability to post images, etc.. discord doesn't even have threads... Its just one large freaking chat... Not conductive for tech support... its conductive for clan chatting during a game raid.. ;)

    User X helps Y 3 weeks ago, how does user Z now with the same issue find the info?

  • Failover&High Aviability

    15
    0 Votes
    15 Posts
    1k Views
    P

    @viragomann
    In the case of the second rule of any addresses on the CARP VIP again gw offline.

  • Adding pfSense to existing home network

    8
    0 Votes
    8 Posts
    7k Views
    johnpozJ

    I have ran dd-wrt on all brands, never had issue one with it.. I did brink one once while drunk and put the wrong firmware on it, but recovered it with the paperclip trick..

    The sg1100 would be a good choice for sure if your not full gig internet.. It can sure get close to that.. My house is that big either and I have 3 AP.. Users don't quite understand that having 1 single wifi router in the corner of your house under your desk is not the best source of wifi for the house ;)

    And yeah you have access to your attic - very easy to mount correctly ;)

  • High latency

    6
    0 Votes
    6 Posts
    1k Views
    T

    Hi,

    thanks for response.

    About the Hardware: its a dualcore Intel cpu
    e51ea87f-c40b-401b-9c69-976c875895c3-image.png
    The utilization does not change while latency issue.

    I pointed the "german" news site oute cause they user other cdn for adds then the american (i guess).
    Since i can avoid the issue by blocking the addvertisment it hints that way.
    dnslogs look clean.
    Also dnsresolution works fine so far.

    About the ISP topic:
    I can immediately solve the latency by unplug the pfsense from isp router and verify by connect my pc to it.
    Else it takes about 20 min to recover, also pfsense does work normal if i unplug the lan.
    So it looks the root cause sits on the client pc after opening this kind of sites.
    I cant reproduce this behaviour on the isp router when connecting my pc direct.

    About the fault topic:
    I do not blame my pfsense for that, but i would like to understand the issue going on and be able to debug such a network problem on my firewall.

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    12 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • Dual WAN for Wireless Links on the same subnet

    6
    0 Votes
    6 Posts
    659 Views
    NogBadTheBadN

    @jacoventer

    You could try LACP, to be honest I'd use FAILOVER.

  • DHCP Server register to multiple DNS Resolvers

    1
    0 Votes
    1 Posts
    157 Views
    No one has replied
  • pfSense User Manager

    2
    0 Votes
    2 Posts
    220 Views
    kiokomanK

    afaik there is no limit on how many users can be created, concurrent connection are another matter.

  • KSP

    4
    0 Votes
    4 Posts
    550 Views
    KOMK

    I'm also just learning, and I've watched about 20 hours of videos just to get to this point. Kerbal has the highest learning curve of any game I've ever played. I made it to Minmus and back, but got stuck on Mun.

    Right now I'm playing with a music mod so that I can add appropriate music to my situations. Nothing better than drifting through space listening to Ozric Tentacles (psychedelic space-rock), or the Gravity or Interstellar soundtracks.

  • Replace Palo Alto Firewalls with PFSense Appliances

    1
    0 Votes
    1 Posts
    239 Views
    No one has replied
  • Best way using pfSense to block Torrent / P2P

    22
    0 Votes
    22 Posts
    16k Views
    bmeeksB

    @provels said in Best way using pfSense to block Torrent / P2P:

    @WD_Doug Include use of P2P and Torrenting as violations in your employee computer use policy and fire the SOB. Worked for me.

    +1

    I worked for a very large Fortune 500 corporation in the U.S., and that was exactly the policy in place. Depending on the particular severity of the offense, you got one free "forgiveness" (but a write up still went in your file to potentially be used against you at annual review time), but a subsequent offense got you the door (as in "out the door"). Some first-time offenses (such as a downloading/viewing or heaven forbid, distributing, porn) got you fired right away. No second chance.

  • TIL netflix is using freebsd to serve content ;)

    5
    0 Votes
    5 Posts
    393 Views
    stephenw10S

    And now I want Super Mario on my firewall....

  • SMB network advice - what next?

    4
    0 Votes
    4 Posts
    485 Views
    awebsterA

    You can certainly isolate access to only certain hosts and not others.
    In addition, you can choose what protocols, for instance, you could allow SMB access to your file server, but not allow RDP.
    SSH is a bit trickier since you can tunnel other protocols through it, so you might need to disable that functionality on the SSH server first.

  • I think your book needs to be update.....

    9
    0 Votes
    9 Posts
    840 Views
    johnpozJ

    Dude I hear you... And I don't get it either.. What is written is correct, but I think he doesn't like that the term private was used vs say unallocated and now allocated.. Because 1/8 was never in the private space - it was reserved and not allocated..

    Thats my take on it.. I think its fine as written.. His confusion over something that is quite clear, is what is confusing to me ;)

    I think he should suggest the "wording/update" that he thinks would be less confusing ;)

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.