• ESXI with pfSense router

    2
    0 Votes
    2 Posts
    956 Views
    T
    Pls flowup link http://www.pfsensevietnam.com/2016/05/pfsense-install-on-vmware-esxi-as.html
  • Routing radius thru IPSEC

    2
    0 Votes
    2 Posts
    699 Views
    N
    Well after a few hours of reading and googling, I have come up with a way that works….. Is it right?...not sure but it works On the captive portal router,  I have set a new gateway with a non-local route (under advance settings) and address of 192.168.20.1, then i set up a static route to send all traffic for 192.168.10.18/32 thru the new non local gateway.  Finally I have set a new rule under the wan to only allow 192.168.10.18/32 ports 1812 & 1813. And poof it works. I hope this help anyone else that is trying to do something like this :-) Dickie
  • Request

    3
    0 Votes
    3 Posts
    865 Views
    R
    In my case I have a blocks that are not being used on an interface directly. Some are being used for NAT. I have a superset route that includes these blocks. If I put them in with null as the gateway, then the NATs don't work. If I don't have them in as a route then the NATs are used in the correct conditions, but in all other conditions the traffic is forwarded to the hop for the supernet. Thanks, Rhongomiant
  • 2 WAN - 2 LAN - Portforwarding

    42
    0 Votes
    42 Posts
    11k Views
    G
    WAN1 & WAN2 has the same GW. My servers is Dedicated and the two Internet that i have is the same. the only different is that they have different WAN IP. For the switching suggestion, i already check it. i can not fully understand the other thinks that you wrote… thanks a lot for your time...
  • Routing between two IPSEC tunnels

    1
    0 Votes
    1 Posts
    708 Views
    No one has replied
  • My gateway monitoring is not working correctly after upgrading to 2.3

    2
    0 Votes
    2 Posts
    1k Views
    C
    https://forum.pfsense.org/index.php?topic=110043.0
  • Routing Between Separate PFSense Firewall Pairs

    2
    0 Votes
    2 Posts
    937 Views
    K
    For incoming packet on any given interface it goes like this: 1. Address rewriting, rdr or nat rules. 2. Packet filtering by the filter rules. Rules can set route-to for the packets to take different route at 3. 3. Routing if the destination of the packet (after NAT mind you) is not a local address. Outgoing is in the same order for 1. and 2. but routing has already happened obviously.
  • Need fresh eyes for routing between vlans

    6
    0 Votes
    6 Posts
    2k Views
    A
    Thank you very much for the suggestions! Finally i opted for a different solution… I have created a LAGG interface for igb1+igb2 and trunk ports on cisco switch...applied the VLAN tags and everything is now working as expected!
  • Pfsense 2.3 HA hangs after about a week

    3
    0 Votes
    3 Posts
    864 Views
    P
    Yes, I do! Thanks for the suggestion, hope for a quick resolution!
  • MultiWAN and Routing Issue

    3
    0 Votes
    3 Posts
    1k Views
    K
    Thanks for the quick response georgeman! I looked up 'policy route negation rule' and the following how-to came up: https://doc.pfsense.org/index.php/Bypassing_Policy_Routing Using on the info in the above link I created a pass rule on the LAN interface where the LAN subnet was the destination. When I placed this rule first the website accessible via WAN1 became available to LAN hosts. From what I understand because the packets are destined for a NAT'd host via WAN interface and are therefore supposed to be 'reflected' back to the internal host without being routed to the Internet. Without the above rule the packets were hitting the load balancing LAN policy which sent them out the wrong gateway… Is this correct? I am still getting used to pfSense's nuances... while I am happy that it is now working, does having a rule like this somehow open a big hole in our security? Bonus Question: If I turn off NAT reflection would it be impossible for a LAN host to access an open TCP port on the WAN interface?
  • 2 lan routing issue

    22
    0 Votes
    22 Posts
    3k Views
    D
    Thanks for the reply, but i resolved the issues with a reload of pfsense.
  • Multi wan with multi DNS servers

    2
    0 Votes
    2 Posts
    584 Views
    G
    pfSense usually queries all the DNS servers simultaneously. If you have pfSense acting as a DNS forwarder (though dnsmasq or unbound), you cannot control in this way which server is queried depending on routing rules.
  • Unable to route a static public IP over VLAN

    2
    0 Votes
    2 Posts
    481 Views
    G
    @dynamicuser: I have asked them to route it to a next-hop IP of my pfSense WAN IP - 52.132.180.66, they have done this. What does that exactly mean? Is there a local gateway on that new subnet? I guess the ISP placed the new subnet on the same WAN link? You would need Virtual IPs if this is the case.
  • A secure site login is failing with dual-WAN

    2
    0 Votes
    2 Posts
    462 Views
    dotdashD
    Create a failover group and a load balancer group. Have a rule matching https with a failover gateway before the rule with a balancer gateway. You could also try the sticky option, but I haven't played with that in a long time.
  • If username x = abc net if username y = xyz net help me ?

    4
    0 Votes
    4 Posts
    747 Views
    johnpozJ
    google dynamic vlan radius, the ability to do this going to come down to the feature set of your switch.. If all you have is some dumb soho switch or even a entry level smart switch your most likely out of luck. You need something with a decent feature set to support this on your switch. If your wanting to do with via wifi ssid vlans, then your going to need a decent AP..  The unifi ap line has finally got around to implementing this, they have had some beta firmware out for a while now.  And I see they just added it to the 5.02 beta that is out for the controller. What switch(es) do you have and what wifi if your wanting to do it on wifi.  And can help point you how to configure it.  your also going to need a radius server - which you can run on pfsense if you want.  I run radius on pfsense for auth on one of my wifi networks. If looking for something to control switches for dynamic vlans or just a nac system check out packetfense. On side note – "pfsense 2.1.5"  why do so many people not upgrade??  I just don't get it...
  • MPLS failover / same destination via different gateways

    4
    0 Votes
    4 Posts
    1k Views
    M
    Hi, first sorry for my english. I have a similar scenario, and I resolved in this way. I create 2 VPN tunnel (peer to peer) one for ADSL (client and server both with the same setting) and the other one for MPLS (client and server both with the same setting) . This permit create an adicional interface per each tunnel. This interface need to be enable but leave in blank all the settings, the interface will use the IP address confgured in the Open VPN P2P (either client and server) only need to put a name and enable. Once you finish this the interfaces will appear at the dashboard, and if the tunnels are up they will you show the IP address used, dont forget open the ports used in firewall rules. This is only needed at server side of Open VPN. The client dont need listen port. The last you need to do is create a gateway group with the gateways associated OPENVPN dynamic gateways, in the same tier if you want load balancing or diferent tiers y you want failover. Once you create the gateway group, only need to assign it at one LAN roule in the firewall for example: in site 1 you need to create a rule that permit traffic from any source to dstination 10.0.2.0/24 use gatewaygroup (this "gateway group" you find at advanced setting inside the firewall rule). and in site 2 you need the opossiterule for example. permit traffic from any source to destination 10.0.1.0/24 use gatewaygroup. I worked a lot for this configuration. Both OpenVPN and VPN assigned interfaces dont need any firewall rules, leave it empty. Saludos, Max. Sorry again for the "English".
  • Printing across LANs

    2
    0 Votes
    2 Posts
    893 Views
    H
    powercycle the printer / update firmware some models have a terrible networking stack
  • Unable to receive email after starting OpenVPN services.

    2
    0 Votes
    2 Posts
    478 Views
    C
    Guessing you're letting it push you a default gateway, which you probably don't want. That in and of itself doesn't suffice though (reply-to should route it back out correctly). Second issue, you probably have a static IP WAN with no gateway chosen under Interfaces>WAN, so it's not setting reply-to.
  • How to detect WAN gateway is functioning if it is behind a modem?

    2
    0 Votes
    2 Posts
    406 Views
    C
    Set the monitor IP to something like 8.8.8.8, then it'll ensure it's bound to that interface.
  • Public IP on WAN is VPN IP

    1
    0 Votes
    1 Posts
    563 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.