Subcategories

  • Discussions and feedback related to this forum

    608 Topics
    3k Posts
    johnpozJ
    @Popolou well that is recent for sure.. I don't recall putting that in - maybe?? Fixed now it seems which is the good thing. Thanks for bringing to attention.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    27 Topics
    114 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • Seeking recommendation and insights on VyOS for networking needs

    7
    0 Votes
    7 Posts
    1k Views
    J
    @definitelynotmyusername Thank you for your insights on VyOS! I joined the VyOS community forum and got some positive feedback.
  • Topic internal sort order

    6
    0 Votes
    6 Posts
    680 Views
    johnpozJ
    @Wolfgangthegreat if you change the order - you prob do have to refresh the page your looking at.
  • What do you call a segmented network?

    8
    0 Votes
    8 Posts
    978 Views
    johnpozJ
    @AndyRH but firewalled is what they are - you put them behind a firewall or you put them on a protected network.. etc.. Why should the users freaking care? I have never worked at a company where you told the users anything about security or moving of server.. Service X will be down over the weekend, etc.. Is about the most they got.. If they asked you might tell them yeah moving the service to a new server, moving the server to a new location.. Users don't have a clue to what a firewall even is, or a network segment in the first place.. Throwing in such terms is just like speaking gibberish to them.. Might as well say sldjfsldf sjfojsdfj shoasdhjdf theh Service X lajdfnslslsfdhoet down alajlsjdjflsjdf til monday..
  • Pfsense on TPLink ER605

    3
    0 Votes
    3 Posts
    2k Views
    stephenw10S
    Looks like it's a MIPs device. pfSense CE is x86 only so...nope.
  • Anyone here has experience with Unifi L3 switches ?

    2
    0 Votes
    2 Posts
    291 Views
    M
    I've been doing a research about these switches and it seems that their L3 functions are half baked. You must use the switch as the gateway and DHCP server, there is no NAT, you need to use ACLs through the CLI to filter traffic and even if you save the configuration, it won't survive a reboot. If you are going to use this switch as a L2 only, it will do the job nicely.
  • This topic is deleted!

    3
    0 Votes
    3 Posts
    86 Views
  • This topic is deleted!

    5
    1 Votes
    5 Posts
    96 Views
  • Home/homelab network design - Am I overthinking this?

    Locked
    6
    0 Votes
    6 Posts
    1k Views
    E
    @michmoor said in Home/homelab network design - Am I overthinking this?: The amount of VLANs here are , imo, a bit of an overkill OK. Would you mind telling me what you'd do differently? And why? Do not host an email server. There will be plenty of people here that will list the multiple reasons but chief among them is that it will be extremely easy to get your IP on a bad reputation list. I know that's the conventional wisdom. I also know there are plenty of people out there who are doing it successfully and have been for years. I plan to use an SMTP relay so I don't have to worry about my IP being on a bad rep list. If you are a novice as you state then the recommendation would be to not expose any services to the internet. If you need to make your NextCloud or any other app accessible to others than a remote access VPN would be best. If you dont want to do that then look at CloudFlare tunneling but i honestly just wouldnt do it if you are not prepared in all the things that could go wrong. I'm already using CF tunneling. I plan to be prepared for worst case scenarios with a very good backup plan/system. If everything crashes and burns, OK. Great learning opportunity. If you are going down this rabbit hole of simulating an enterprise then look also into setting up a remote logging server (Graylog), perhaps a SIEM (Wazuh) which i would highly recommend considering you are exposing web servers to the world. Yep. Planning to use both of those. Maybe Zabbix and Suricata, too. All stuff I want to learn.
  • 0 Votes
    7 Posts
    983 Views
    the otherT
    @nullcure I run pfsense CE in my home network. Since I just wanted "to give it a try" a few years ago, I run it on an APU2...so I never bothered trying to upgrade to a plus version (having read as well about some problems). I plan on upgrading my network in the coming two years (changing to 2,5 GBit/s LAN), so my actual plan has a netgate device...with a plus version running. What I miss under CE is the snapshot ability. Everything else is more than enough for my personal networking needs.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • 0 Votes
    3 Posts
    721 Views
    NollipfSenseN
    @Teo-En-Ming-0 said in ChatGPT says pfsense is the most popular open source firewall in the world: ChatGPT says pfsense is the most popular open source firewall in the world ChatGPT got that right and it will take a long time for that to change...you also came to the right place for the latest and greatest info source on pfSense...don't forget to familiarize yourself with Netgate docs: https://docs.netgate.com/pfsense/en/latest/general/index.html Welcome!
  • Dell Precision 5820

    3
    0 Votes
    3 Posts
    814 Views
    NollipfSenseN
    It turned out that the Dell has four PCIe bridges that were failing. So, it was returned yesterday and now shopping for another.
  • Why you are scanned so soon

    4
    0 Votes
    4 Posts
    785 Views
    GertjanG
    @AndyRH said in Why you are scanned so soon: I found it interesting that if you get a certificate for your web site you are publicly announced and apparently scanned immediately by the bad guys. Ask for a certificate (a very public thing) from some CA, then know that they, the CA's, have to add you to the unique list, the same list half the computer related part of Havard (university in the US) is tapped into so they obtain data for their theses. Something like that. @johnpoz said in Why you are scanned so soon: would be valuable to the bad guys Hey, these guys are the future good guys, right ? No ? Anyway : you use an IPv4 : you get 'scanned'. Most of it is innocent.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • How do you design tagged and untagged networks?

    5
    0 Votes
    5 Posts
    793 Views
    bingo600B
    All my IF's with tags have PVID/"Native vlan" as 999 , and 999 is not used for anything, besides being "native". Well ... except my Unifi WiFi IF .... I made that back when you couldn't TAG the "Control" stream for the UNiFI's. And i have spread out the vlan load over two interfaces to improve throughput. Vlan1 is also unused in my networks. /Bingo
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • 2.6.0-2.7.0 update broke or worked strangely

    4
    0 Votes
    4 Posts
    832 Views
    stephenw10S
    Yup, exactly as shown in those threads. You might need to add some other epp values or disable Speedshift for your CPU.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    10 Views
    No one has replied
  • Duckdns.org down

    1
    0 Votes
    1 Posts
    230 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.