Subcategories

  • Discussions and feedback related to this forum

    607 Topics
    3k Posts
    johnpozJ

    @microserfs and what IP was that - clearly your current IPv6 address is not block that I show you connected with.. And the only other IPv4 I see you using is not blocked.. You would have to let me know what IP you were coming from that was blocked.. Send it to me via PM if you don't want to make it public.

  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    27 Topics
    114 Posts
    w0wW

    @sef1414
    Name it "run.sh", copy to pf and chmod according documentation
    https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option
    You will see messages in the system log like those quoted in the script after logger command.

  • Squid Allow all subnets

    2
    0 Votes
    2 Posts
    447 Views
    KOMK

    ??? The General tab of Squid's options has a Proxy Interfaces section with a combobox of all your interfaces. Pick the ones you want.

  • Old Copper Cico Router to New AT&T Router on SG-8860 pfSense Firewall

    3
    0 Votes
    3 Posts
    575 Views
    V

    Hey Steve, thanks for the information.

    I will be sure to avoid any firewall mis-configuration and verify the current settings - as they were implemented before I had the job - do not cause any speed loss errors on bandwidth throughput.

    Much appreciated.

  • Can I set up 2 VLANs, so they get same DHCP?

    5
    0 Votes
    5 Posts
    828 Views
    pfrickrollP

    As Grimson mentioned, I just put both signals on the same VLAN. For some reason I thought VLANs are predetermined on AP I know its pretty stupid to think that but for some reason I had idea thats how it is with EAP 1300. Anyway, everything works as intended as of now. Going to play with it more and then move onto Win Server and see how things work there.

  • pfsense wifi Vending machine

    7
    0 Votes
    7 Posts
    2k Views
    A

    The idea is to simplify the process. The customer would not need to purchase a voucher from tyeh counter or kiosk.

    See the link below. This on is made in the Philippines A coin operated Wifi machine

    https://www.google.com.ph/url?sa=t&source=web&rct=j&url=https://www.adopisowifi.com/articles/&ved=2ahUKEwj98OHy5IDdAhVMOY8KHc85Ad8QFjABegQIBxAB&usg=AOvVaw1UhJuudl4WNVpiAj1QHA_V&cshid=1534945349119

  • Watchguard firebox video header pinout

    5
    0 Votes
    5 Posts
    674 Views
    stephenw10S

    I'm pretty sure it was a standard pinout for both connectors. The VGA header is 2mm not 0.1" as you say.

    However I don't see anything obvious now. You can probably test the ground pins and infer the rest from their positions... assuming it is standard.

    Steve

  • Best Processing Power vs Power Efficiency Compromise - Home Gigabit

    3
    0 Votes
    3 Posts
    732 Views
    S

    So to add to @rainer_d comment, I've recently purchased the APU2C4 as my pfsense box and frankly considering the costs I'm rather impressed. I'm have a WAN\LAN setup running Squid, Squid Guard, Suricata, PFBlockerng, and ntopng - my main focus is keeping my kids from getting into too much trouble as they start exploring the internet. Looking at the performance to energy cost, I really feel this box hits a lot of check boxes. Sadly, I'm limited in my bandwidth so I can't speak to how it handles on 1Gbps, but I've hear you can get close but I don't know if would need to limit the packages your running.

    If you do end up do end up looking at the APU2 setup, here is what I came up with so far to improve performance:

    Get thermal grease and stand the box vertically - Reduced my CPU temp by 10C Avoid ClamAV, it will eat the CPUs alive with large downloads Suricata seems to perform better than Snort, but is twice as hard to setup... but twice the trouble is twice the fun in my book. Between the multi core support and the APU2 supported inline mode, you can get IDS on without to much impact to your system. Get the 4GB version, it's not much more and gives you lots of RAM to play with.
  • How to forward UDP port 5198 for Amateur Radio Echolink

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD

    Adding the WAN rule will not add a port forward.

    You add a port forward in Firewall > NAT, Port Forward. There you can optionally (recommended) have the port forward automatically maintain the firewall rule on WAN for you.

    Yes, you need both ports forwarded.

    In your case you can do a range from 5198 to 5199 and do it in one rule.

  • PFSense IPSec site to site VPN behind ISP provided Modem

    9
    0 Votes
    9 Posts
    1k Views
    C

    @nogbadthebad Aahh okay. Thank you so much!

  • Static Route

    2
    0 Votes
    2 Posts
    421 Views
    V

    So you want to route the whole upstream traffic to the Sonicwall?
    Just open the gateway settings and check "Default Gateway". No extra route needed.

  • PFSense with unraid docker Nowplaying

    14
    0 Votes
    14 Posts
    2k Views
    S

    Yeah, I posted a thing for him on lime-tech about it, I just haven’t gotten an answer yet. I’m sure he is busy. Thank you for all your help and time!

  • What VPN Services Works with PLEX XBOX Web Chat online Port Forwarding

    9
    0 Votes
    9 Posts
    1k Views
    O

    As per OP's question What VPN Services Works with Plex/ Xbox. I would like to recommend a few such as NordVPN, Express VPN, PureVPN.
    I would like to refer the Best VPN for Plex as it also provides a guide on [spam link removed]
    I hope the guide helps.

  • Account not valid

    5
    0 Votes
    5 Posts
    826 Views
    O

    Well I guess I had the same issue and then got registered again.

  • which version to install?

    3
    0 Votes
    3 Posts
    568 Views
    O

    Since you are mentioning you want to grab the image on my USB key, Just use etcher as Deredict mentioned above.

  • 2.4.4 is looking to be big

    4
    0 Votes
    4 Posts
    844 Views
    H

    Cool. Thanks for the info guys. I was trying to better understand the difficulties and reasoning.

    Talk about back luck of timing with all of the EOLs. I can't wait!

  • Mailing lists gone away?

    2
    0 Votes
    2 Posts
    537 Views
    jimpJ

    The mailing lists were retired due to GDPR. A message was sent out just before the lists were shut down.

    They were low traffic anyhow, and discussion is better served here on the forum or Reddit.

  • no connection from Pfsense server LAN to router's WAN

    7
    0 Votes
    7 Posts
    731 Views
    7

    I cannot even ping gateway from router which is ip of LAN interface

  • Multiple lan interfaces(ports)

    4
    0 Votes
    4 Posts
    780 Views
    johnpozJ

    Yes you can "bridge" interfaces to somewhat simulate a "switch" It is going to SUCK performance wise and completely over complicate the configuration. Are you filtering on each member, are you filtering just on the bridge interface, etc.

    Oh did I say it SUCKS before compared to an actual switch port - right?

    If you have a switch - there is ZERO reason to contemplate WASTING a very useful router interface that could be used for you know another network so you could actually firewall between your networks/vlans on your "router" vs using it as a switch port ;)

    If you need/want a switch on your router/firewall - then buy hardware that actually as built in switch ports. The sg3100 for example, or the 7100.. Pretty sure their other new models coming will also include actual switch ports.

    Yes you can bridge - No you have no reason to do it.. Is like you CAN if you really wanted to poke yourself in the eye with a stick.. But normally people tend to think this a bad idea.. Same goes for using router interfaces as switch ports via bridging them ;)

  • Renumbering my network. Any pitfalls?

    11
    0 Votes
    11 Posts
    2k Views
    DerelictD

    Let this thread serve as an example of seeing the problem, setting a maintenance window, and renumbering. It can be a MUCH better path than trying to NAT all the things because you decided to deploy 192.168.1.0/24 or, much worse, 10.0.0.0/8.

  • No longer need to shape

    3
    0 Votes
    3 Posts
    560 Views
    H

    @kom It actually seems they made some sort of changes since the last time I did testing over a year ago. I did some new testing before the bandwidth upgrade and noticed these changes.

  • error: Jul 10 17:19:26 dpinger WANGW *.*.*.*: sendto error: 64

    3
    0 Votes
    3 Posts
    6k Views
    C

    @derelict Thank you.
    How to suppress these error messages? This IP is not down, and the device is under our control.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.