• AD users SSH connection not working

    6
    0 Votes
    6 Posts
    2k Views
    jimpJ
    It's not on anyone's radar or to-do list that I'm aware of.
  • MOVED: [HOWTO] Squid/Lightsquid Logs with MAC addresses - pfSense 2.3.2

    Locked
    1
    0 Votes
    1 Posts
    673 Views
    No one has replied
  • States Summary 504 Timeout

    1
    0 Votes
    1 Posts
    523 Views
    No one has replied
  • Bug in webgui under services -> dncp server -> Domain Search List

    2
    0 Votes
    2 Posts
    528 Views
    jimpJ
    Looking at the backend code of the page, and the GUI, it will accept either space or ; as a separator and they both work. Be sure when using ; that you don't use both a space and a ;. So either: "example.com movie.edu" OR: "example.com;movie.edu"
  • Rearrange Interfaces

    5
    0 Votes
    5 Posts
    1k Views
    jahonixJ
    PS: RRD graphs are a bit irritating now, that's absolutely correct. Since that's data from the past I can live with it.
  • Route edit does not reflect original

    2
    0 Votes
    2 Posts
    498 Views
    P
    That was a general problem due in many places in the UI to a js change. It should be fixed in recent builds by: https://github.com/pfsense/pfsense/commit/a7c47d85270fcf8c784e6af61ea2fd09f9d4f5ac related issue https://redmine.pfsense.org/issues/7625
  • 2.3.5 Developmental GUI issues

    11
    0 Votes
    11 Posts
    1k Views
    mtarboxM
    It was immediately after the eclipse did its thing.
  • Cant Change Admin name?

    5
    0 Votes
    5 Posts
    2k Views
    C
    @Derelict: You might consider a different authentication source instead of the firewall local users. Users probably shouldn't be enabled to make changes to a firewall's configuration. It sounds like you have much greater design problems than admin being called admin. ? They can only change their user accounts password, wouldn't really call that changes to a firewall. Especially seeing how that is what Jimp, is highly recommending be done lol. In not only my other thread with similar questions, but a ton other on the forums. A different Auth source is all fine and good, except now that is more hardware, to do something I can already do with the Local. Sure if I had 1000s of usernames needed, I would do that, for the 35 rooms, not even close to worth it lol. So what other options is there? To run the different auth server on the same box? Well now I have to Visualize the PFsense and Auth server, which is even more of a security issue. Even then, adding a MYSQL server and using Radius, just adds more security vulnerabilities, More OSes means more issues. I have concerns about them accessing the GUI as well, that was brought up in the other thread. Jimp is assuring me, its fine, no matter where I go with what there is going to be an issue, its just deciding on the lesser of the evils.
  • [SOLVED] alert alert-danger clearfix

    5
    0 Votes
    5 Posts
    1k Views
    L
    Thanks. The crap color was driving me crazy.
  • CPU speed only shows on occasion.

    6
    0 Votes
    6 Posts
    2k Views
    J
    I have an N3150 with 1.6GHz speed, but a boost speed of 2.08GHz.  Does pfSense ever make use of the 2.08GHz speed?  I cannot tell from the dashboard, as the clock speed goes away above 1.44GHz or so. Also, it would be nice if the speed was just always displayed, instead of the page jumping up and down as the speed display comes and goes.
  • 0 Votes
    15 Posts
    4k Views
    S
    @jimp: @spiorf: because if I can get a certificate for "pfsense.lan", anybody can, and so there is no point  in verifying certificates or using https at all. Which is not true for the reasons I stated. Nobody else can get a certificate for my firewall hostnames, because they could not pass the required validation. And LE may be complex at first, but it almost forces you to setup automation. Changing keys every 3 months is more secure and is already done by sites covering ~30% of TLS transactions. You are right. Sorry, english is not my native language.  What i really meant was " if i COULD get…". I know you can't. As i already said, I know how complex LE is, and i already use it from the beginning, setting up the required automation. And i love it! But you know what certificate transparency logs are, do you? Because I want to keep my internal hostnames private. Even more in a company. This is a good and private security model. And can secure also IP addresses. While LE cant. Everyone can do it the way he wants, but right now, you can do it your way from the GUI, while I can't (without an ugly hack).
  • BUG - WebGui and not compress js files and other resources

    15
    0 Votes
    15 Posts
    2k Views
    GertjanG
    @albgen: Checking the gui of nginx you will find that is NOT compressed. I dont know where did you see this but the standard is compressing only css (period). I was comparing this part of the nginx setup with your finding : ...                 gzip on;                 gzip_types text/plain text/css text/javascript application/x-javascript text/xml application/xml application/xml+rss application/json; .... Then I found https://stackoverflow.com/questions/23939722/nginx-gzip-not-compressing-javascript-files : this explains what you are seeing - and what needs to be done  ?
  • Problems 2.3.4_1 with Gui and pfctl

    7
    0 Votes
    7 Posts
    2k Views
    B
    Hello, reistalled pfBlockerNG and I'm having issues with aggregate process, it just sucks one core al 100% for MANY minutes (I killed it after 7:54 at 100%) with just ONE blocklist. I tried downloading it in P2P format and CIDR format, no change: agregate process seemes totally stuck. List is I-Blocklist level1. I know it's big, but in CIDR format it's just 4.2 MB and pfBlockerNG should be able to handle it. Any help? Thanks Alberto Tarantino
  • Orange and yellow highlighted network in gui

    4
    0 Votes
    4 Posts
    988 Views
    jimpJ
    It means you did a search (ctrl-F) in your browser and it is highlighting the results. You must have searched for 192.168.40
  • NEW THEME: pfsense-dark-orange

    1
    1 Votes
    1 Posts
    3k Views
    No one has replied
  • Solved: Traffic Graph Colour - Help!

    7
    0 Votes
    7 Posts
    2k Views
    C
    Still work in progress. [image: Untitled-3.png] As I am a little bit OCD there are a few continuity issues with the current dark theme that need a little tweaking so thanks to your help (InQuize) I have now been able it scratch that itch! What I needed to do was convert the colours I wanted to decimal from hex and then substitute them in the already formatted colour scale in the file d3.min.js, so, Al=[2062260,16744206,2924588,14034728,9725885,9197131,14907330,8355711,12369186,1556175].map(xn), [image: category10.png] became, Al=[38536,16777215,2924588,14034728,9725885,9197131,14907330,8355711,12369186,1556175].map(xn), [image: category10.png] ChEeSy
  • How can i change the text on the log in panel

    6
    0 Votes
    6 Posts
    1k Views
    L
    i noticed if i change the global.inc file update the name it will update the login text too but still the same issue with open vpn so i will see what i can find in that package
  • Harmonize Status-System-Logs-Firewall-Normal View versus Dynamic View

    2
    0 Votes
    2 Posts
    588 Views
    jimpJ
    The dynamic view is completely generated by javascript so it doesn't have access to all of the same information. It may be possible to bring it into parity with the main system log, but it's not currently an open feature request that I'm aware of. You can make a feature request ticket (target=Future) at https://redmine.pfsense.org/
  • OpenVPN on port 80

    2
    0 Votes
    2 Posts
    736 Views
    jimpJ
    Yes, so long as you disable the GUI redirect that occupies port 80 by default: System > Advanced, check "Disable webConfigurator redirect rule" and save And remember that running OpenVPN on TCP can be problematic and slower than UDP, any loss outside the tunnel is compounded by the inner and outer TCP connections attempting to resend, etc, etc. In some cases it's necessary though, to get around restrictions in other remote networks. You might still run into some issues if anyone remotely does protocol enforcement. With non-HTTP traffic on port 80, it might be dropped by a filter or proxy in between the client and your firewall.
  • How Can I only chang admin password, and keep the ssh root password?

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    root and admin cannot be separated, it's the same account but with two different names. Like johnpoz said, if you want someone to use a different GUI password, then create them a different user with their own username, and don't use 'admin'.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.