• Mapping Drives in Windows

    7
    0 Votes
    7 Posts
    845 Views
    A
    @johnpoz : I was originally using it as a bridge server, but the second side of that bridge server is not connected anymore and everything is on one side now. I think my best bet at this point is to take a separate computer and a separate switch and connect those to a separate NIC on the Sinology NAS so that I can access the GUI. From there maybe I can rework the network and get it put back together. To recap, when I installed the Netgate, I basically matched all of the networking. I wanted it all to be the same as it was in the sonic wall. Same, WAN, same, LAN, same port forwards. Basically, everything worked out except for the NAS. I crack into it more after the holiday. Thanks for your response.
  • VPN Ipsec without gateway

    16
    0 Votes
    16 Posts
    2k Views
    P
    @viragomann I tried it works great Thank you so much
  • Need help with Canon MX920 across subnets but post is forbidden

    8
    0 Votes
    8 Posts
    887 Views
    R
    @nollipfsense that's almost what I was doing anyway, but then that again gets the printer on a different subnet from the PC, which puts the barrier between the UDP communication, which would make the printer not function. That said, I think I may have figured out that the Canon driver potentially is only using UDP broadcast to initially find the printer if it's IP address is changed or it's a new installation. So, if I assign the printer a static IP on its network, and I temporarily move devices that need to print to it to the same network just for the driver install, then I can move the devices back to other subnets on the overall network and maintain functionality. I'll have to test this through a few reboots and several days to confirm it does indeed work, that would suffice for now. I may eventually try to figure out which UDP ports I need to relay to get the Canon drivers to work without having to move devices around between the networks, if it becomes more problematic and this workaround doesn't hold.
  • Noobie Needing help with config.

    6
    0 Votes
    6 Posts
    751 Views
    G
    Just wanted to post an update. Was able to get this unifi AP working on a different subnet by SSHing into the AP and pointing it with setinform to the controller on the other subnet.
  • Cannot ping pfSense

    Moved
    3
    0 Votes
    3 Posts
    530 Views
    N
    @victor-2 said in Cannot ping pfSense: ASRock A320M-HDV Don't use the Realtek NIC if you have Intel NICs! The Driver support is badly.
  • HTTP 403 on pfSense 2.6.0 pkg signature

    1
    0 Votes
    1 Posts
    231 Views
    No one has replied
  • Dashboard widget question

    4
    0 Votes
    4 Posts
    583 Views
    johnpozJ
    @furom you could always put in a feature request over at the pfsense redmine https://redmine.pfsense.org/ edit: not widget but if your on the normal firewall log, you can put in a !WAN for the interface and get all interfaces that are not wan.
  • New Config Loses Connectivity in Seconds

    10
    0 Votes
    10 Posts
    1k Views
    T
    @stephenw10 The ping test could have been after ARP expiration. Once the network failures were history, I tried switching to VirtIO, but speed was 35M even with offloading disabled. I set it back to Bridged, and got 250M with 4 CPUs. 2 CPUs in Virtualbox gave me over 500M. Not bad, but still ~50%. Each reboot I would lose connectivity on the i211 LAN and the only way I could get it to work was to switch it promiscuous mode on/off while the VM was running. Crap... I gave up on Virtualbox and moved it over to Hyper-V with 8 CPUs set. I got 30M, researched, and disabled RSC (even though it was already reported as disabled) via PowerShell with these commands: netsh int tcp set global rsc=disabled Get-NetAdapterRsc | Disable-NetAdapterRsc Then I could get a solid 940M in Hyper-V, AND have the luxury of auto-start after host reboot. (Lessons for anyone reading this)
  • Network Setup with PfSense

    2
    0 Votes
    2 Posts
    441 Views
    S
    @nar94k the Google router will need to forward either the OpenVPN ports or all ports to pfSense. pfSense can allow access to the OpenVPN server ports on its WAN, or if you set up a dynamic DNS hostname you can allow that hostname.
  • Possible move from IPsec to OpenVPN

    8
    0 Votes
    8 Posts
    947 Views
    M
    @jwt @stephenw10 appreciate your feedback here. Truly do.
  • Web Gui not loading after full disk

    11
    0 Votes
    11 Posts
    1k Views
    S
    @stephenw10 Yeah, I read that but it doesn't really give case scenarios. I appreciate the help.
  • Monitoring with ZABBIX

    9
    0 Votes
    9 Posts
    4k Views
    stephenw10S
    Yup, see: http://files.pfsense.org/jimp/BEGEMOT-PF-MIB.txt
  • 0 Votes
    9 Posts
    759 Views
    stephenw10S
    The phase 2 entry for each device should use the IP address they specify in the 'NAT/BINAT translation' and the real address in the 'Local Network' field. See: https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/phase-2-nat.html#example You do not need an outbound NAT rule if you can add the route to the OpenVPN tunnel at Site1. Steve
  • pfsense is shutting down or hang randomly

    16
    0 Votes
    16 Posts
    2k Views
    C
    Ryan, I ordered directly from netgate. Thanks all.
  • Does this look dodgy?

    17
    0 Votes
    17 Posts
    1k Views
    D
    Thanks guys. I normally shutdown properly but had an issue with power loss at home which was pretty regular. I have a UPS but it's just my Unraid that's plugged into that but I'll look at getting my pfSense hooked up to it too maybe. Power cuts were down to my Lava Lamp as it happens which I've now stopped using anyway. Interesting stuff though.
  • Help to setup unifi AP on pfsense

    Moved
    14
    0 Votes
    14 Posts
    6k Views
    M
    @bongo-nations You don’t need a console using only Unifi APs. I setup two U6-Lites in 5 minutes using the Unify Network app from the Apple store on iPhone and iPad. You only need a console to do more than basic setup , which is all I needed. Last week, I upgraded the U6-Lites I used for a year to two U6-Pros since they became available in my area. It took 5 minutes each to setup on the IOS app and they work perfect. They all work flawlessly with Pfsense 2.6 with no changes once setup using the app. However, if you need more than what’s available in the app, such as VLANs, you need a console. I tested the console on a Mac out of curiosity and setup an AP. After playing around I reset the AP and went back to the app. It’s all surprisingly easy. A tip which has nothing to do with getting them to work but may help: I recently got 1.2Gig from Comcast and upgraded the modem to S33 and U6-Lites to U6-Pros (I will upgrade my Protecli FW6A and HP 2520-24 switch eventually). But wifi topped about 475-500, the trick was to bump the 5Gz channel width from 40Mhz to 80Mhz in the IOS app and bingo, I got 899 on my iPad Pro 11 connected to one of the U6 Pros. Not bad considering my best wired speed is 937.
  • Any way to TRULY block DNS over https (doh)?

    7
    0 Votes
    7 Posts
    4k Views
    JonathanLeeJ
    @jknott I agree, this opens a can of worms for cyber security, just one website and one wrong web cookie could direct DoH DNS requests to a another server, I just noticed you can disable it in Chrome and on the OS side. I use Squidguard and block a list of DoH domains, many servers are in different countries. I just started looking into this with one.one.one.one and other cloudflare DoH servers. https://forum.netgate.com/topic/176693/dns-over-443?_=1672162126374 Another post with lists of DoH servers. Combined DoH servers list if you want to create a block list. Positive when it is turned off in the OS I do not see any requests on the proxy anymore. So you can block it that way. 1672081401354-combineddohlist.txt
  • usb key for encrypted zfs hdd

    34
    0 Votes
    34 Posts
    2k Views
    stephenw10S
    The example on TrueNAS is auto-decrypting the data drives but not the boot drive as see it. So it's probably not directly applicable here. To do the same with an encrypted boot drive it pretty much has to be in the bootloader I would think. Maybe moving the config file onto USB would suffice? pfSense would still boot but would be useless without the config. Many years ago m0n0wall had that option. It would require some work in current pfSense. Steve
  • RAM disk and ZFS /var/ mount points of datasets /var/log ...

    Moved
    2
    1 Votes
    2 Posts
    442 Views
    lexxaiL
    @lexxai Answer by himself. I do test dd if=/dev/zero of=/var/db/testets.db bs=1M count=100 dd if=/dev/zero of=/var/log/testets.db bs=1M count=100 Used space only on RAM disk, so ZFS not used. Question closed. [image: 1672098759423-screenshot_20221227_015132.png]
  • “Invalid WAN IP Address” error during Setup: More specific error?

    Moved
    1
    0 Votes
    1 Posts
    231 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.