• Block LAN-Host completly (traffic)

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    No. There isn't any long-term usage tracking that would work in that way. Not with a normal network anyhow. If it were Captive Portal-controlled and with access authenticated by RADIUS, with RADIUS set to track usage and deny access, that might work. I believe there are examples of this elsewhere here on the forum if you search a bit for terms like "captive portal radius bandwidth" you might turn up some relevant hits.
  • Per device daily data limits?

    3
    0 Votes
    3 Posts
    2k Views
    B
    Maybe I shouldn't say this on these forums but have you had a look at Gargoyle (based on OpenWRT)? It seems to be very good at the sort of quotas you're describing. http://www.gargoyle-router.com/index.php Gargoyle is Linux-based but, for future reference, pfSense is FreeBSD-based.  ;)
  • Traffic Shaping with TCP Limiters and caching - general info / tips

    4
    0 Votes
    4 Posts
    2k Views
    S
    LAN Rule [image: LANRules.jpg] [image: LANRules.jpg_thumb]
  • Limiters how it works inside ?

    1
    0 Votes
    1 Posts
    747 Views
    No one has replied
  • Layer 7 p2p is catching all my traffic and PASSing the non p2p

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Multiple floating rules, no "quick". Which rule is applied?

    2
    0 Votes
    2 Posts
    1k Views
    S
    "Non-floating" rules are just specialized "floating" rules in which the interface is pre-set and "quick" is used for all of the rules (this is done by pfSense for quick and easy every day per-interface rule creation). When pfSense is applying the rules, the rules from the floating table will be put before the non-floating rules.
  • P2P rules not catching traffic (Yes, I've searched)

    9
    0 Votes
    9 Posts
    4k Views
    E
    @senser: Outgoing traffic that was put into queue X of the WAN interface will result in related incoming traffic being put into queue X of the LAN interface (if it exists) and vice versa. Thats why I told you to give queues the same name on both interfaces. Ah, learned something new. Wish this was in the guides. I watched a YouTube video about setting things up for optimum bandwidth usage, and the guy split all the queues by suffixing them with U or D depending on interface. I see now that this isn't the best way to do it. I'll go ahead and fix all my other queues accordingly… lol Thanks again for everything.
  • Traffic shaping confusing me with it's behavior….

    2
    0 Votes
    2 Posts
    1k Views
    B
    Is there something funky with the queue bandwidth limitations? (Ie, set the bandwidth for an interface to 50 Mb) ? I've been playing with downstream's queue options (my lan interface's queue options)  If I set it to 50Mb/s it hits around 37 Mbs. if I set it to 56 it gets around 47mbs. If I set it for 58 and 59 respectively ,It caps out further without killing my connection (latency etc) (best result so far is 51mbs) If I set to 60.. it somehow spikes to 56+ mbs and i begin to have latency due to filling my pipe.  It's a bit curious how small increments prior to 60mbs settings didn't change it much, but setting it to 60 and the entire thing blows up. haha.
  • Outbound shaping with OpenVpn

    1
    0 Votes
    1 Posts
    839 Views
    No one has replied
  • Layer 7 how to? Can't find any documentation.

    3
    0 Votes
    3 Posts
    2k Views
    M
    Just being a PASS rule doesn't explain why Diablo saw all traffic honor the L7.  This says that all packets matched the L7. Doubtful. I have the same problem trying to use the L7's.  I add the FTP L7 to my floating FTP Wan out dst port 21 rule and all web traffic comes to a screeching halt.  What an FTP rule has to do with HTTP traffic is beyond me.  I have yet to find one explaination of how to use L7 Pass to Match.  I set a tag (match) word on the pass rule and followed this rule with a "match to" and queue but doesn't work.  With or without the dst port 21 in the second rule, same result.
  • HFSC - seperating bandwitdh from delay

    2
    0 Votes
    2 Posts
    1k Views
    KOMK
    While I'm just as lost as most when it comes to pfSense and HFSC, something I read seemed to indicate that, on a realtime service curve, d is the maximum time elapsed before it gets its m1 or m2 rate fulfilled.  For example, if you had a game that required 500Kb bandwidth with a good ping of 30ms or lower, you would specify m1 = 500Kb, d = 30ms, m2 = 500Kb.  I don't even know if you need to specify m1 in the rt case where burst is not a requirement. Please bear in kind that I don't know what I'm talking about, and the above could be complete nonsense.
  • Proxy bandwidth limitation per users

    2
    0 Votes
    2 Posts
    1k Views
    S
    Anybody help me?…
  • Dedicated Pipe for VOIP Subnet

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Interface Limiter?

    1
    0 Votes
    1 Posts
    993 Views
    No one has replied
  • Shaping with multiple LANs and different priorities.

    5
    0 Votes
    5 Posts
    4k Views
    B
    Any hint on how to go about the "transparent bridge" to be able to shape? I put my 3 LAN connections all in VLANs now, so that they all connect to the pfSense box on one physical NIC.                                             /====VLAN2 = Internal LAN pfSense-NIC=== VLAN2+3+4 =Managed Switch  ====VLAN3 = Client LAN                                             \====VLAN4 = WiFi LAN So now I would need to bridge that NIC to another interface and then shape on that interface? What do I have to do to get that Bridge working?
  • Traffic shaping not working properly

    1
    0 Votes
    1 Posts
    921 Views
    No one has replied
  • 0 Votes
    2 Posts
    1k Views
    T
    Need to create match rule on floating tab and not on lan tab. This thread solved my problems http://forum.pfsense.org/index.php?topic=61315.0
  • Traffic shapper is off but traffic still limited

    2
    0 Votes
    2 Posts
    1k Views
    T
    Please explain in more detail. Is the pfsense the LAN router and gateway for the other two computers? If LAN-LAN is allowed through your switches (no source port filter, no vlan) then I cannot see how a third router or server on LAN should be able to influence on that.
  • Diagnostics: Limiter Info only shows 2 limiters

    2
    0 Votes
    2 Posts
    2k Views
    T
    I found that if I created a limiter with more than 100 in Queue Size than the limiter setup would freeze. That meening I could add or edit limiters, but they where not changed on the limiter info page and not taken into acocunt in the traffic shaper. Did you create a limiter with more than 100 in queu size? Else you have have found a new porblem. Good luck
  • Traffic shaping limiter killing internet connection

    3
    0 Votes
    3 Posts
    2k Views
    T
    I have a setup with limiters both in and out. I think I once tried to remove one of them and traffic stopped. That sounds like your situation. If I am correct then just create a 120Mbit limier and add it as the other limiter, that you expected not to use.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.