Subcategories

  • Discussions and feedback related to this forum

    608 Topics
    3k Posts
    johnpozJ
    @Popolou well that is recent for sure.. I don't recall putting that in - maybe?? Fixed now it seems which is the good thing. Thanks for bringing to attention.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    27 Topics
    114 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • FreeBSD vs Linux Networking

    1
    2 Votes
    1 Posts
    446 Views
    No one has replied
  • TCP/IP UDP joke

    1
    0 Votes
    1 Posts
    352 Views
    No one has replied
  • Span Layer 2 between Data Centers

    9
    1 Votes
    9 Posts
    4k Views
    johnpozJ
    openvpn tap would not be the same no.. I personally have never had to deal vxlan drivers on a device since our DCs that we need to do extended vlans across are all connected via dark fiber ;) Clearly some advantages of working with enterprise networks and real budgets - hehehe
  • High availability CARP with different model Netgate routers

    3
    0 Votes
    3 Posts
    466 Views
    E
    Ok, if it's a lot of work I may get another 3100 and retire the 2220.
  • pfSense on Hyperv with CL gig fiber pppoe/vl201

    1
    0 Votes
    1 Posts
    278 Views
    No one has replied
  • hardware compatibility?

    3
    0 Votes
    3 Posts
    509 Views
    fireodoF
    @randomaustralian Check the compatibility of your desired Hardware with FreeBSD 11.2 and if its compatible then it will work with pfsense.
  • pfsense keeping securelevel=3 after reboot.

    7
    0 Votes
    7 Posts
    1k Views
    JeGrJ
    @jmatz88 said in pfsense keeping securelevel=3 after reboot.: I think they get a head start to use the default credentials before we get our hands on the computers so that might be why they have root access so quickly. Then that defeats the purpose of the competition, doesn't it? If you say your aim is to "defend your network", then you should be the one that get's access. No one worth their pay would install a firewall with access to the WAN/insecure network granted and default credentials still in place (even 2.4.4 gives now very big warnings about that). If they get a head start to "attack" a device with default credentials that is no competition to defend but a cleanup job - and the most secure way would be to kill the box (re-install) and bring it back if it is secured - and doesn't have WAN access at all to the web UI. ;) Just 0.02$ because that sounded more like a kobayashi-maru as a "competition" :)
  • VPN Tunnel - No Gateway on TUN interface

    6
    0 Votes
    6 Posts
    978 Views
    JeGrJ
    @rg0s9 said in VPN Tunnel - No Gateway on TUN interface: @viragomann Thanks for your replies here. What seems to have done the trick is creating an opt interface for the VPN. This interface now has the first ip address in the tunnel range, and i can now get to devices on the LAN. What was throwing me was it doesnt seem to be referenced in any material i have viewed. Cheers Yeah that's because normally it isn't required at all. I'm running it on multiple client sites without an interface mapped to it. As @viragomann said, you only need to assign a opt interface to it, if you want to route somehting TO the VPN. As you describe the VPN as dial-in so you can actually maintain some things on their LAN, it's not necessary. Just clicked through the wizard and got a working VPN without any problems, so I think that some other little piece was missing you fixed before assigning the interface. Only thing that changes with the interface are that you get a VPN GW that is visible to the GUI, you get an extra interface tab for that VPN (instead of just using the OpenVPN group interface for your rules) and ... that's probably it ;) Greets
  • What am I missing?

    5
    0 Votes
    5 Posts
    745 Views
    Kevin45K
    @slimypizza said in What am I missing?: In addition to setting up a VPN server, you might have fun setting up a reverse proxy. I use HAPROXY for this. Good Idea, I am also going to give it a try, to this reverse proxy.
  • GRE Tunnel seems to be one way only.

    2
    0 Votes
    2 Posts
    840 Views
    jimpJ
    If you can ping router to router, then it's almost certainly an issue with routing or firewall rules, either on the firewalls on either side, or on the devices behind the firewall(s).
  • How to access wifi router/AP connected to LAN1/2 admin page from LAN

    8
    0 Votes
    8 Posts
    870 Views
    K
    @derelict Thanks for the solution. This worked.
  • LoadBalancers and client IP

    5
    0 Votes
    5 Posts
    924 Views
    Z
    OK I will read about transparent client ip, thanks. The source client ip should be used by traefik with a simple LB in TCP mode. I have tried to create an apache server with a simple port forwarding and I can get the client ip using the Remote-Addr headers and set the x-forwarded-for header to pass it through ProxyPass. The app server logs the correct IPs. I will try with the loadblancer tomorrow. After that if it works, there is a traefik miss-configuration/issue ?!!
  • Hardware Question

    3
    0 Votes
    3 Posts
    567 Views
    stephenw10S
    It will be fine and definitely keep the SSD. Spinning drives offer pretty no advantages in a firewall at this point. Steve
  • Windows pc not working with pfsense

    3
    0 Votes
    3 Posts
    553 Views
    B
    I had a similar issue but thanks for the topic which is discussed in detail. I will read all the discussions and see if it solves my issue.
  • pfSense blocking SSL connections/apps on unraid

    3
    0 Votes
    3 Posts
    1k Views
    M
    Well it's always good to resolve your own problems. When I installed pfSense, I changed my private IP scheme to 10.10 from 192.168 and one of the files in nextcloud was configured with the old IP. So now it's working. In case anyone is having difficulty with ssl connections on hosts, I put the following info into dns resolver at the bottom for adding a host override. I'm connecting via SSL to unraid. host - long chain of characters before unraid.net in your address bar parent domain - unraid.net IP - unraid IP address
  • 0 Votes
    3 Posts
    419 Views
    L
    @jegr Thanks, I will try this as soon as possible!
  • Noob: Port scan show open ports

    newbie
    4
    0 Votes
    4 Posts
    1k Views
    H
    Firewall rules are by interface, not IP address.
  • Call For GETDNS and STUBBY package on PfSense

    1
    0 Votes
    1 Posts
    362 Views
    No one has replied
  • increase socket and solve squid error

    4
    0 Votes
    4 Posts
    1k Views
    I
    @harrybells said in increase socket and solve squid error: o many open files With uni Hi Harrybells, where the parameters /proc/sys/net/ipv4/tcp_fin_timeout are changed? In my pfsense I don't have the folder /proc/sys Thanks in advance
  • Add user SSL Certificate on pfSense

    9
    0 Votes
    9 Posts
    1k Views
    johnpozJ
    afapark.com is registered and public... But even the public facing doesn't do https.. It listens on 443 but all it does it give errors.. Can not even connect via s_client to get any info..
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.