Subcategories

  • Discussions and feedback related to this forum

    610 Topics
    3k Posts
    G
    @stephenw10 This is my final note since it seem you will always look at this as an endpoint. It doesn't appear, it actually is, the facts are the facts. Still, moderator usually have a way to remove posts and ban single users, not just the entire herd, or at least the ones use. Perhaps those are more advance, or perhaps netgate forums lack that functionality. I never said negate took this issue lightly, I was just looking for some feedback. I have seen this process many times and for the looks of it, pfsense CE is very much in maintenance mode. Just because netgate wants to be politically correct does not mean it is not. The fact are there and they are fallowing the same path as others did. Again, this subject is just becoming redundant and it is affecting other users in the forum.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    28 Topics
    115 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • 0 Votes
    5 Posts
    696 Views
    B
    @derelict I thank you for your advice man, if it wasnt for this i wouldnt have found this site. Pfsense is a great product, ill will stick around on this this forum! /D
  • Chromecast with a sound bar?

    4
    0 Votes
    4 Posts
    721 Views
    johnpozJ
    What fixed it? So you connected it how exactly? While it is for sure not normal pfsense forum topic - you should complete the thread with what exactly you did to correct your "problem" so that the next guy reading this or searching for it for the same sort of problem isn't left hanging.
  • Use in commercial environment

    7
    0 Votes
    7 Posts
    943 Views
    imWACCoI
    Thanks for the input johnpoz & Derelict I just decided to fill out the form for partner. I let them know that I'm the founder of a non-profit to get computers to vets (militaryos.com). I just happen to have a system that's too old to give out. There may be times that I need pfSense for vets also. I have a one time case for a different non-profit. But there ToS is rather restrictive and I just want to get an OK with them.
  • New Shaw Modem (XB6) Getting Very Slow VPN Speed

    9
    0 Votes
    9 Posts
    1k Views
    ?
    Just an update: after hours going back and forth with my ISP provider, they are unable to help me. Some success: However, after researching I was able to reach near 500mbps with the VPN turned on by creating 4 openvpn clients and putting them into a gateway group. these are the custom settings i have for each openvpn client: auth-user-pass /etc/openvpn-password.txt; remote-cert-tls server; reneg-sec 0; resolv-retry infinite; persist-key; persist-tun; tls-client; pull-filter ignore "auth-token"; sndbuf 1500000; rcvbuf 1500000; Problem: But I am getting weird long lag / delays. For example, I open starcraft and lots of the images, etc are blank waiting for load. After maybe 15-20seconds it will all load. Or if I am in a party and a game is started, I won't see the invite pop-up. Or youtube seems to load slow, and the images. Same with popcorn time. Anyone have any ideas about the weird delays and lags I am experiencing despite getting near 500 mbps download speeds? Thank you as always.
  • Mounting SSD on SG-5100

    3
    0 Votes
    3 Posts
    561 Views
    Orion2030O
    Perfect, Thank you !. Done, mounted, and saving sweeeet log data !
  • Update is available notification via syslog

    3
    0 Votes
    3 Posts
    480 Views
    T
    Very good idea. I "catch" a lot of things into Splunk from pfSense and the most critical things are then "routed" to slack. For sure this helps me get the most important notifications I need immediately and it get's the right attention.
  • How would you go about managing 24 pfSense boxes?

    11
    0 Votes
    11 Posts
    1k Views
    pfrickrollP
    I never dealt with FTP before, so never read up on it. My company used to upload some sensitive docs straight to FTP server about 5 years ago, at that time they didn't even think they need firewalls and VPNs.
  • ntopng getting not installed after updating to 2.4.5-DEVELOPMENT (amd64)

    3
    0 Votes
    3 Posts
    628 Views
    jimpJ
    Set your update source back to 2.4.5 / development snapshots.
  • Custom aliases using domain name

    32
    0 Votes
    32 Posts
    5k Views
    A
    @su30mki said in Custom aliases using domain name: I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? First at all, you have to configure your vlan. After that, you have to create an ACL in order to provide internet access to one vlan and block it in the other vlans. Remember set your device as a “Layer 3” device.
  • ZFS to be rebased on ZoL

    1
    1 Votes
    1 Posts
    248 Views
    No one has replied
  • pfsense is blocking Autoconfiguration IPv4 Address why ?

    2
    1
    0 Votes
    2 Posts
    989 Views
    jimpJ
    They are blocked because they have no business hitting the firewall. They can still communicate locally, but it's link-local/L2 traffic that can never route outside of its segment. You'd only receive one of those IP addresses if you had no DHCP service running. You can't use those addresses as your local network the same way you would use an RFC1918 network.
  • Packt Publishing $5 Sale

    8
    0 Votes
    8 Posts
    1k Views
    jimpJ
    If you want Packt books, wait until they are on a Humble Bundle, then set it to give all the money to charity. :-)
  • PHP Error Log

    3
    0 Votes
    3 Posts
    765 Views
    S
    I saw something very similar on an SG-3100, after upgrading several other devices to 2.4.4 or 2.4.4_1 recently. In my case if I connected to the console it showed a LAN IP but I could not ping it or connect. The boot process showed 2.4.4_1 but it looked to me like something had happened during the update and PHP 7 and/or other components had not upgraded properly. I had to reinstall from the Netgate image. Edit: I should note that in this case the upgrade process "failed" a couple of times, but I did not see an obvious reason. Eventually it "succeeded" but ended up in this state.
  • WebGui Keeps freezing

    4
    0 Votes
    4 Posts
    899 Views
    JeGrJ
    @sherifen said in WebGui Keeps freezing: I just installed my PfSense, logged into browser to make some rules.. everytime i make 1 adjustment in the browser its freezes and after a while (site cant be reached) I'd go as far as to say: You sure you aren't connection via the WAN interface or did you by any chance remove the anti lockout rule and so have no firewall rule in place that actually allows you access to the webGUI? If you have to disable the filter every time you make a change -> that triggers the filter back on of course! -> it's a sure sign, you did sth. wrong with your rules in the first place.
  • Pfsense Firewalls Rules

    8
    0 Votes
    8 Posts
    1k Views
    JeGrJ
    @vallum No, network range may not have changed, but IPs in it have changed around quite a bit. So yes, you can use a big hammer just try and hit everything with it, trying to match the correct IPs for the services. Or you can use a finer tool like a knife and cut out the services you actually want. Proxies are not that "hectic" but a finer tool for limiting access. And if that's what the OP is wanting to do, I'd have a look into it. Of course one can dismiss it as not worth the work and just go with IPs. Didn't say a thing against that. Just know, that blocking internet services today via brute-force IP usage, you'll get false positives, side effects etc. in blocking networks or hosts that are in use for multiple purposes.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • SOLUTION: ATT UVerse Slow Throughput Fix

    1
    0 Votes
    1 Posts
    528 Views
    No one has replied
  • Advice for port forwarding on upstream ISP modem

    2
    0 Votes
    2 Posts
    444 Views
    johnpozJ
    huh? If your webserver is behind pfsense then the ports are already forwarded through pfsense.. So this comcast "modem" is doing NAT? Does pfsense doesn't have a private IP or Public on its wan? Your forwarding the 3 ports through to pfsense WAN IP on your "modem" A modem doesn't do nat.. You mean you have a comcast gateway? What is the make and model of this device for comcast? You do understand that most things looking for those ports are going to directly look for them - not run through a port scan.. Where did you get the idea that pfsense blocks port scans? You do understand that pfsense blocks all ports that are not forwarded.. So say scanning ports 1, 2, 3, 4 - etc... until get to 80 would be blocked.. Why do you think that pfsense will say oh wait this source IP was checking other ports, I will not let him through to my port forwarded 80? Are you running IPS package? Snort or Suricata?
  • pfsense 2.4.4 hangs without logging errors

    9
    0 Votes
    9 Posts
    786 Views
    PuchoP
    Well, after I finally kidnapped my partner's screen and left it plugged to the box. I woke up this morning and found it waiting on the BIOS screen. Disk is dead. A bit annoying after you run all the tests you can run and still is that bloody thing..I'm glad I don't work on ER. Patient is gone, we are so sorry. I wonder if it was temperature what screw it, this is one of those fan less boxes. Thanks for the answers, anyway.
  • How to use two nics for 1 vlan?

    2
    0 Votes
    2 Posts
    266 Views
    A
    This has been talked about already here. https://forum.netgate.com/topic/84823/vlans-across-multiple-interfaces https://forum.netgate.com/topic/83080/same-vlan-on-multiple-interfaces https://forum.netgate.com/topic/79237/multiple-interfaces-with-the-same-vlan https://forum.netgate.com/topic/107612/multiple-vlans-across-physical-interfaces/3 The general consensus from those in the know - DON'T DO IT, use a managed switch instead. They're cheap. Jeff
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.