Subcategories

  • Discussions and feedback related to this forum

    610 Topics
    3k Posts
    G
    @stephenw10 This is my final note since it seem you will always look at this as an endpoint. It doesn't appear, it actually is, the facts are the facts. Still, moderator usually have a way to remove posts and ban single users, not just the entire herd, or at least the ones use. Perhaps those are more advance, or perhaps netgate forums lack that functionality. I never said negate took this issue lightly, I was just looking for some feedback. I have seen this process many times and for the looks of it, pfsense CE is very much in maintenance mode. Just because netgate wants to be politically correct does not mean it is not. The fact are there and they are fallowing the same path as others did. Again, this subject is just becoming redundant and it is affecting other users in the forum.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    29 Topics
    117 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • System Crash report

    5
    0 Votes
    5 Posts
    889 Views
    kiokomanK
    uhm I should have warnings coming from my server if it was that, r710 poweredge with centos, dell manager say it's all ok on my raid. i will try qemu/kvm
  • Need Help in Choosing a VPN

    Locked
    34
    0 Votes
    34 Posts
    5k Views
    stephenw10S
    Locked
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • How to manage the logs of my Rsysog Linux

    1
    0 Votes
    1 Posts
    328 Views
    No one has replied
  • Cox Internet Ingress Issue Used to Deter 3rd Party Equipment Usage

    5
    0 Votes
    5 Posts
    1k Views
    J
    yes i am aware and it is f'n tragic. people dont have any privacy anymore. its done. or maybe internet privacy was a joke to begin with. like the internet was invented for this purpose. to track everyone. not worldwide communication and sharing of knowledge and ideas like we've been led to believe. makes me wonder where neo is. ha
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    4 Views
    No one has replied
  • Interface unexpectedly down how do I troubleshoot it

    9
    0 Votes
    9 Posts
    888 Views
    M
    So I just ended up using one of my extra ports to reconfigure the vlan on it. I deleted all the other instances and redid the firewall rules. It now works. I don't know what the issue was. It's probably cleaner to keep the vlan on it's own port and not shared with my lan port. Thanks for your replies.
  • DNS not resolving and no changes made to cause issue

    7
    0 Votes
    7 Posts
    1k Views
    M
    Ok thanks.
  • 0 Votes
    16 Posts
    4k Views
    johnpozJ
    its not dns broadcasting... It would be the client doing a netbios broadcast for the hostname... Hey who is called somehost.. So your clearly not doing dns redirection. So you want to set it up correctly.. Point your clients to pfsense, or some other local NS that will resolve all your local resources, and will then forward or resolve all your public dns needs. Pointing clients to outside NS is not going to allow you to actually resolve any local resources, nor will it give you the ability to block bad stuff.. You have no control over the dns at all when you tell client to use 8.8.8.8 for their dns.. But if you have them point to something local for dns, say pfsense - you then can control stuff by blocking stuff you don't want them to get to.. You can resolve say www.whatever.com to the local IP its hosted off of, vs getting the public IP for this fqdn and having to use nat reflection. Also pointing clients locally allow you save some bandwidth, because if client A looks up www.something.com, and then client B asks for it its already cached at your local dns, and doesn't have to be looked up again, etc. So fix it already - not really sure why we are stilling having this discussion ;)
  • No Internet

    1
    1
    0 Votes
    1 Posts
    402 Views
    No one has replied
  • 0 Votes
    3 Posts
    420 Views
    stephenw10S
    Yeah it would be hard to do. Most things like that involve edits to multiple sections. You could maybe diff the configs against default and then apply it as a patch. But you would likely only be able to apply one patch as subsequent patches would not apply cleanly. Steve
  • Looking for syslogs to update my cyberattackmaps website

    4
    0 Votes
    4 Posts
    872 Views
    C
    @PhlMike said in Looking for syslogs to update my cyberattackmaps website: That is interesting, I have over 100 pfSense firewalls and I use pfmonitor as well, I could probably aggregate something if I can figure out how to automate it and remove anything sensitive. That could be interesting indeed. If you like to give it a try, maybe for just 1 one them, please let me know. If you want to I can also try make a TCP (ssl) port available instead of UDP. But then you will need some customization (syslog-ng forwarding?) in pfsense in order to send to that I believe.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    13 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    15 Views
    No one has replied
  • 0 Votes
    7 Posts
    1k Views
    JeGrJ
    @jvansyoc said in Allowing users to add/remove/modify additional user accounts but not admin accounts.: Using the FreeRadius server package on Pfsense is something I have used as will for MFA on VPN. I'd encourage you to try as - together with OpenVPN - you can actually use FR to implement things you normally would need CSO (client specific overrides) for such as handing out a static ip for specific users or time limits, logout times etc. So for every RAS VPN setup I always encourage our customers to use OVPN+FR together as it provides them more flexibility. I should clarify that I'm looking to allow the end-user access to add and remove VPN users without having to contact me or have system administrator access. The suggestion to use FreeRadius is a great idea and I will get back to this with my testing. Then I'd say go the route and couple OVPN with FR :) It will pay out in multiple ways ;)
  • This topic is deleted!

    Moved
    2
    0 Votes
    2 Posts
    66 Views
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • Motorola Buys Watchguard.. Video Solutions

    2
    0 Votes
    2 Posts
    234 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.