• WHS2011 rules

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    N

    Thats what I was trying to find out stephen

    So long as I have some information to go by, that will allow me to be able to work on the rest of it

    I just have to remember to backup the config now, as I have the squid proxy server finally working as it should be (man you wouldnt believe what relief it is to finally see it working as it should).

    I've transferred the Wireless NIC from the Sun Workstation to my Proliant ML350 G5 (which is going to be built as the Fileserver/Backup Server)

    But do you think finding 15k RPM SAS drives is cheap? lol as well as DDR3 ECC Ram, lol  ;D

    I've configured the pfsense box as best I can for now, so I have to finish the rest of it after work tomorrow (Have to be up by 5am to be ready for work  ::) )

  • Inter-vlan routing

    Locked
    24
    0 Votes
    24 Posts
    13k Views
    stephenw10S

    Ah yes.  :-[

  • Suggestions for multiwan with a natted router

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    N

    I am not sure if I understand you correct but for pfsense it is independet if there is another router which does NAT on the interface.
    What you describe - or like I understand it - it is doueble NAT. This is working.

    You can do LoadBalancing and Failover as you like.

    ISP–--NAT-Router1--------NAT-pfsense-------LAN
    ISP2--------------------------

    On the pfsense interface which connects to the other NAT-Router you will probably have to uncheck "block private networks"

  • Import ipfw rules

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    No way to do so. It would be faster to manually import than write and validate something to do it in an automated fashion unless you have thousands of rules.

  • Lan,OPT1,OPT2 firewall rules

    Locked
    13
    0 Votes
    13 Posts
    21k Views
    stephenw10S

    Nope.
    I think you may have misunderstood what the netmask is.
    The netmask is simply how the IP protocol defines the subnet that each machine is in, what other addresses it can talk to. See: http://www.computerhope.com/jargon/n/netmask.htm

    Steve

  • Equal bandwidth sharing by all hosts using dummynet

    Locked
    1
    0 Votes
    1 Posts
    889 Views
    No one has replied
  • Problem getting to websites - via NAT Qwest modem

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    R

    Thanks, I will look into that.

  • Existing connections ignore route changes

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    A

    I wonder if my question is not clear, too complex, or really nobody knows.

    From my testing it seems like NATed connections (only ones I tested) do not obey any routing changes for existing connections.  I wonder if that is one of the reasons for the option below is defaulted to disabled.  To make sure any existing connections are terminated for the wan when routing changes.  WIthout doing that it would appear that packets for states that were already connected before a routing change would still be going to a dead gateway until the TCP times out.

    There must be a way to make sure packets are routed according to the routing table for already established connections when a route changes.

    Advanced->Gateway Monitoring - States By default the monitoring process will flush states for a gateway that goes down. This option overrides that behavior by not clearing states for existing connections.
  • Authenticate to multiple backend AD servers

    Locked
    1
    0 Votes
    1 Posts
    852 Views
    No one has replied
  • Problems with RRD Graphs

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    J

    Hm, ok, but this is a remote location with a satellite connection only.

    Is there any other way of fixing it?

    Thanks in advance.

    BR,
    Jarle

  • MOVED: freeradius question

    Locked
    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Get max performance from fiberlink with Pfsense possible?

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    stephenw10S

    Doesn't actually help provide an explanation either way!
    The 'ethernet extentions' product is routed via their fibre network, which is presumably shared with other traffic, where as the extensions+ product is swiched ethernet.
    Plenty of people complaining about virgin media in general though.  ::)

    Steve

  • Interface bridging

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    jimpJ

    There is also

    http://doc.pfsense.org/index.php/What_is_a_bridged_interface_and_how_would_one_be_used%3F

    If you clicked the category at the bottom of the link you posted (for "Bridging") that shows up.

    I just added a "See also" link to the page so it's a little more obvious.

  • SIP phone behind pfSense wall

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    No.

  • Telnet on Pfsense

    Locked
    7
    0 Votes
    7 Posts
    7k Views
    K

    @XIII:

    @k6usy:

    To many bots out there trying to crack simple passwords I would rather not have the traffic going to my router.

    Thats why you use key based SSH authentication, cuts down on the exposure drastically.

    That works too.

  • Fowarding connections based on subdomain

    Locked
    1
    0 Votes
    1 Posts
    983 Views
    No one has replied
  • PFsense not passing/routing traffic between WAN/LAN

    Locked
    6
    0 Votes
    6 Posts
    22k Views
    S

    Thank you Wallybob for walking me through routing troubleshooting. It was a routing problem all along. I thought the AP was acting as a bridge, but it was actually a DHCP server and didn't know where to forward 192.168.2.0/24 traffic. FACEPALM In my defense, it's my first week on the job…  :P

    Lessons learned:
    PFSense does not randomly drop traffic.
    If you can't reach something because of routing, you do not always get Destination Host Unreachable when pinging.
    Have faith in the system logs.

    Thanks,
    Seanny

  • Setting up Pfsense with C class through ADSL modem

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    E

    If you can get them to route those addresses to a separate static IP in a different subnet (like maybe your existing static IP, for example), you could do this with routing instead of bridging and your DHCP server could directly hand out public IP addresses on the local side.

  • Routing entries - is there any limit? [ANSWERED]

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    The limit would be at what point the XML gets so big it causes performance degradation. That's so high that it's WAY beyond what any sane network would have in static routes, I've seen systems with hundreds of static routes on slow hardware with no impact, could easily do many thousands. Beyond a few hundred you probably aren't routing very optimally, or should be using a dynamic routing protocol. People run the BGP package with multiple full Internet routing table feeds, that's over 350,000 routes in the routing table, and 2-3+ times that in BGP.

  • How to stop downloads from YTD YouTube Downloader software

    Locked
    11
    0 Votes
    11 Posts
    19k Views
    N

    @dreamslacker:

    @nearones:

    Can some one guide me how to make rule for mime type in pfsense, i had gon through many docs, but all r on SQUID

    You don't.  You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well.  That's that.  No buts.

    Short of actually sniffing traffic and writing your own layer7 patterns to block YTD, you're out of luck.
    Even so, I believe that YTD, like most download software can spoof normal browser traffic so you would be out of luck there as well.

    What you have isn't a network policy problem.  It's a system policy problem.
    If you want to stop YTD, get on the systems and actually amend the GPs to prevent it from installing or running to begin with.  Alternatively, use a software firewall on the system that simply drops traffic originating from the YTD software.

    You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well.

    What u said is also the good method to block some other websites like onlinegames, porn websites. But how can i do that in pfsense.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.