• Setting up Data Caps

    11
    0 Votes
    11 Posts
    2k Views
    stephenw10S
    Checkout the hangout KOM linked above. Specifically from here onwards. Steve
  • Subdomains and dns questions

    dns domain routing website port
    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S
    Yeah you should be able to use either HAProxy or reverse Squid to redirect requests based on the host headers to different internal servers. Or different ports on the same server. https://docs.netgate.com/pfsense/en/latest/packages/haproxy-package.html https://youtu.be/FJSHMyrd29E Steve
  • block access pfsense gui OPT1

    3
    0 Votes
    3 Posts
    533 Views
    stephenw10S
    @zemlik said in block access pfsense gui OPT1: blocked on OPT1 any to OPT1 address and WAN address ports 22 80 443 Yes, do that. Though you can use the system alias 'This Firewall' as shown in that link and it will cover all IPs on the firewall itself. Steve
  • installing clamav on pfsense

    5
    0 Votes
    5 Posts
    15k Views
    KOMK
    @detox It isn't really surprising that it detected known fake-virus signatures. I wonder about how effective it is in general. I've never seen any qualitative comparisons such as those done by AV-Comparatives, for example. It may not even be as effective as Windows Defender, which has been getting better every year and does fairly well in testing. At my company, I don't use any AV on the firewall, and all LAN clients have local AV protection.
  • DLNA, IGMP Proxy, VLANs, Subnets... Oh, dear...

    35
    0 Votes
    35 Posts
    5k Views
    nfld_republicN
    @stephenw10 Added pimd be added to redmine.
  • Asking here as I'm not sure if it's a firewall or nat problem.

    4
    0 Votes
    4 Posts
    471 Views
    stephenw10S
    Ah OK, then yeah it should be just a matter of adding the port forwards for those ports. Try connecting to it externally then check the state table for states on those ports. Steve
  • pfSsense Fail - PHP Startup: Unable to load dynamic library...

    7
    0 Votes
    7 Posts
    2k Views
    stephenw10S
    It's probably a filesystem issue. It could be an upgrade failure. It's probably not hardware unless the drive is failing perhaps but I would expect bigger issues in that case. The fastest way to get back up is to re-install and restore your config from that situation. You can try this though since you still have command line access: https://docs.netgate.com/pfsense/en/latest/install/upgrade-troubleshooting.html#forced-pkg-reinstall Be sure to backup the config first though if you do. Steve
  • lan rule setup for webfiltering only with firewall rules

    6
    0 Votes
    6 Posts
    586 Views
    stephenw10S
    You can use Squid ACLs directly rather than using Squidguard if you really wanted to. It's far more complex though. Steve
  • pfSense not recovering from WAN event

    5
    0 Votes
    5 Posts
    760 Views
    A
    Yes!
  • OpenVPN client cannot see VLAN network(s)

    4
    0 Votes
    4 Posts
    475 Views
    stephenw10S
    I try!
  • Unraid and Ubiquiti Unifi: STUN Communication failed

    14
    0 Votes
    14 Posts
    7k Views
    Q
    @truetype Okies nevermind, I found out the issue. I had put a pass between the two subnets, BUT i forgot and left it at TCP and not any, so UDP was not passed. Dumb mistake, but I hope it helps someone who googles and finds this. Check firewall rules!
  • OPT1 connect WAP

    16
    0 Votes
    16 Posts
    2k Views
    Z
    @Gertjan OK problem resolved. Seems I didn't have enough protocols allowed on OPT1 working now and also NTP on WAP thanks ever so much for assist.
  • Unexplained WAN/Gateway Packetloss?

    2
    0 Votes
    2 Posts
    380 Views
    stephenw10S
    Try setting the monitoring IP to something other than the gateway IP, so 8.8.8.8 for example is commonly used. That gives you a better idea of actual connection quality. The ISP gateway usually doesn't guaranty ping response. Steve
  • Using another router behind pfSense as an wireless AP

    7
    0 Votes
    7 Posts
    2k Views
    stephenw10S
    The router used as an access point can, and probably should, be on the same subnet just set as static and outside the DHCP range.... and not the same IP as anything else! That way you will still be able to access it's interface to check signal strengths or make further changes. Steve
  • Behind Pfsense Slow my Download Speed

    7
    0 Votes
    7 Posts
    983 Views
    J
    @akuma1x This is a hotel network ISP>PFSENSE>SWITCH>AP>Users
  • Best Way to Achieve this?

    4
    0 Votes
    4 Posts
    468 Views
    KOMK
    @nambi said in Best Way to Achieve this?: if I have something else using 443 would I then need to use the reverse proxy? That's one way. You could also reconfigure the web listen port for one of your servers to some other port. I tend to avoid using a reverse proxy because its extra complexity with potential issues that I'd rather avoid. Also yes, VLANs give you network separation as if they were physical interfaces. You always want to provide a gap between front-facing services and your LAN so that any exploited servers aren't used as a stepping stone to taking over your network.
  • Every couple of weeks pfSense completly stops responding?

    29
    0 Votes
    29 Posts
    4k Views
    stephenw10S
    Yup, that could be it. Though that's not one of the symptoms usually seen with Realtek NICs I would not rule it out. Steve
  • Shell - Restore Factory Defaults

    3
    0 Votes
    3 Posts
    2k Views
    P
    @stephenw10 thanks. Thankfully I had a good recent backup. Reinstalled pfsense via image provided by Netgate, restored backup back in business. Thank you
  • Connections dropping under heavy load

    18
    0 Votes
    18 Posts
    2k Views
    stephenw10S
    I mean 10k states per client does seem..... high! But it depends what those clients are doing. If those are all legitimate states then you could be hitting something else more quickly than we would otherwise expect. But, yeah, did disabling pfSync on the secondary correct the connection drops you were seeing? Steve
  • Azure pfSense ipsec IP Forwarding

    2
    0 Votes
    2 Posts
    833 Views
    J
    Solved by adding static routes in azure pfsense and adding UDR routes of the remote network in the azure route table....finally!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.