• Web Configuration Error

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    Search the forum. Known error.  Upgrade.

  • Automatic reload checks?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J

    I do not understand exactly why no…?

  • Perfomence issues

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    Cry HavokC

    Might be good to see system load details and a list of what packages you have installed.

  • Gateway ip address

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Lots of ipv6 noise on local if

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    S

    Add a rule blocking IPV6 at the top of the interface rules and do not set the log checkbox.

  • SSH defence

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    D

    Denyhost is available thru pkg_add

    just note that the package may not install all dependencies - just read the message after the install

    using it with pfsense and works fine

  • Serial Console during Install

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    X

    All suggestions are appreciated!

    regards Xed

  • Root login logged multiple times over the past week

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S

    Why?  If it really bothers you this much simply disable console logins in System -> Advanced.

  • Simple lan setup issue.

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    S

    Yeh, i used to run a linux box with shorewall and had the same issue, I know its nothing to do with pfSense.

    Thanks for the help.

  • Do not know where to start for server redundancy

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    G

    This sounds more like a job for Linux Heartbeat than for Pfsense.  From what you wrote it sounds like you have intelligence at the server level to determine which should be master and which should be slave.  Linux Heartbeat does a very good job at shifting around virtual IPs and services…

    If you wanted to use Pfsense, you could set up a failover load balance pool.  The only problem there is that you would have to kill the primary server if you wanted failover to occur.

    -G

  • Migrated configuration gives the following error:

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    @sullrich:

    Those are cosmetic.  It's trying to delete prior schedule items.. No biggie.  Please file a bug report and mark it as non-priority and I will look into it.

    I have filed a bug report so I will close this thread.

    Marcel

  • 3 interface bridge?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    So the system has an onboard ethernet, 802.11a PCI and 802.11g PCI (plus usb ethernet for uplink); when I bridged g+ethernet and then set up a as a different range with different dynamics, the dhcp server wanted to serve a single range of dynamics on both interfaces (the g/eth bridge, and the a), which of course resulted in nonroutable addresses on one of the nets.

    While reconfiguring I inadvertantly bridged the a net to the g/eth net. It works, including over a reboot. Beats the heck out of me. But it's been working for over a month.

  • Loadbalance firewalls?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG

    What do you define as loadbalancing?
    pfSense can do Roundrobin balancing so not a "add the bandwiths of both WAN's together" but more a "spread the connections to both WAN's"

    What do you mean with: "My firewalls are behind a hardware loadbalancer that supports loadbalancing firewalls."
    Could you elaborate on that?

  • SSL VPN

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    Cry HavokC

    It was more Seth's posts that suggested a desire to bypass corporate security/policy.

    My 0.02 <currency>- if you want the VPN to really be secure then you need to manage the clients too.  Convenience is nice, but having your corporate network compromised because your end users can install anything they want isn't a good goal ;)  Oh, and I've seen that happen, so it's not just theory.</currency>

  • Xbox 360 –> Change Strict NAT to Open NAT

    Locked
    10
    0 Votes
    10 Posts
    12k Views
    R

    You need to enable the static port option in the advanced outbound nat options.

    http://doc.pfsense.org/index.php/Static_Port

  • FTP bandwith - Latency

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Load on the interfaces

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    Cry HavokC

    Which version of pfSense 1.2 were you using (exact version, "the latest" is meaningless)?

    Which version of m0n0wall are you using (ditto)?

  • IP Aliasses on single NIC

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    R

    I've been successful in adding VIP's using these commands for each VIP in the pfsense config (xl0 is my WAN interface):

    <system>... <shellcmd>ifconfig xl0 10.1.1.254 alias</shellcmd> <shellcmd>route add 10.1.1.0/24 -iface xl0</shellcmd> ...</system>

    Note I then had to add manual outbound NAT for each VIP created (192.168.10.0 is my LAN subnet):

    WAN | 192.168.10.0 | * | 10.1.1.0/24 | * | 10.1.1.254 | * | NO

    WAN | 192.168.10.0 | * | * | * | 192.168.0.2 | * | NO

    (The second entry is the actual WAN interface IP)

    I set this up a while ago, and foolishly didn't document any of it! So I hope this makes sense to you.

  • Inbound Load Balancer Configuration Question

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Accessing PPPoE Modem

    Locked
    23
    0 Votes
    23 Posts
    10k Views
    K

    @jahonix:

    10.0.0.2 (and 10.0.1.3) are your DNS servers on WAN as well.
    What the heck is your ISP doing there?

    Thats not my ISP, thats me. For some reason, DNS dosen't get passed through to pfSense, so I set it as 10.0.1.3 (Primary server on the wan side) and 10.0.0.2 (old router that this modem setup replaced). Reverted it to just 10.0.1.3, with the option to have it overidden enabled.

    Edit: Updated to latest snapshot (1.2-RC3 built on Mon Nov 26 14:47:57 EST 2007) and it now gets my ISP DNS servers on vr0, or it could have been the reboot I don't know, I was pressing disconnect/connect last time and not getting the ISP dns.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.