• Pfsense Installation

    2
    0 Votes
    2 Posts
    443 Views
    dotdashD

    You will only get the assign interfaces prompt if you are not using common nics. pfSense will auto assign em, igb, and other commonly used nics.

  • Is there a section in this Forum for AWS Instances?

    2
    0 Votes
    2 Posts
    237 Views
    KOMK

    Not that I know of.  Post questions/issues either here in General Questions or Virtualization.

  • What is the best way to automate the provisionning of PFSense in AWS?

    1
    0 Votes
    1 Posts
    600 Views
    No one has replied
  • Replacing a firewall w/pfsense - Many blocked IPs question.

    7
    0 Votes
    7 Posts
    535 Views
    GertjanG

    @DennisT:

    We already use OpenDNS but that isn't effective unless the attacker is using DNS (which many don't).

    Thanks !!! Just fine like that.
    This one goes to my ;D list …

  • STP and network

    86
    0 Votes
    86 Posts
    22k Views
    DerelictD

    Well, your server issues are not pfSense issues. Need to do whatever it is that they support.

  • Sharing a usb printer over different networks

    2
    0 Votes
    2 Posts
    286 Views
    johnpozJ

    Comes down to what method of sharing your your going to use.. Just simple windows sharing of the printer SMB? or IPP, or 9100 which is common jetdirect port.

    But yes you would need firewall rule to allow whatever port/protocol you use to access the shared printer.  From a security point of view this normally not all that bad of thing - you limit who has access to the printer, and its just a printer.

    Is your printer not able to just direct connect to the network via wire or wireless.. USB printers are pretty old school if you ask me..  Even your $70 throw away inkjets come with wifi normally these days.

  • Ebay stops loading for no apparent reason!

    1
    0 Votes
    1 Posts
    219 Views
    No one has replied
  • Port 22, 1723 and 110 show open? I have no open ports…

    11
    0 Votes
    11 Posts
    1k Views
    DerelictD

    Just run a packet capture on tcp port 110 on WAN and run another shields up test.

    If you do not see the traffic on the WAN port, shields up is seeing a response from something upstream.

  • Sending bandwidth usage to a Logstash server

    1
    0 Votes
    1 Posts
    191 Views
    No one has replied
  • Logs of changes in firewall settings by admin group.

    2
    0 Votes
    2 Posts
    252 Views
    NogBadTheBadN

    AFAIK the only way of doing this is Diagnostics -> Backup & Restore -> Config History and do a diff between changes and create individual user ids.

    Increase the Configuration Backup Cache Settings size too.

  • Lets encript and haproxy.cfg

    5
    0 Votes
    5 Posts
    1k Views
    A

    thank you PiBa

  • Dpinger service dont start

    11
    0 Votes
    11 Posts
    5k Views
    DerelictD

    Amazing.

  • Reoccurring issues prior to 2.4.0 upgrade

    3
    0 Votes
    3 Posts
    410 Views
    D

    yet something else to ponder:

    Tried to unistall a package and it failed.

    >>> Removing pfSense-pkg-ntopng... pkg-static: Warning: Major OS version upgrade detected.  Running "pkg-static install -f pkg" recommended Checking integrity... done (0 conflicting) Deinstallation has been requested for the following 1 packages (of 0 packages in the universe): Installed packages to be REMOVED: pfSense-pkg-ntopng-0.8.10 Number of packages to be removed: 1 [1/1] Deinstalling pfSense-pkg-ntopng-0.8.10... Warning: Module 'session' already loaded in Unknown on line 0 Warning: Module 'bcmath' already loaded in Unknown on line 0 Warning: Module 'ctype' already loaded in Unknown on line 0 Warning: Module 'curl' already loaded in Unknown on line 0 Warning: Module 'dom' already loaded in Unknown on line 0 Warning: Module 'filter' already loaded in Unknown on line 0 Warning: Module 'gettext' already loaded in Unknown on line 0 Warning: Module 'hash' already loaded in Unknown on line 0 Warning: Module 'json' already loaded in Unknown on line 0 Warning: Module 'ldap' already loaded in Unknown on line 0 Warning: Module 'mbstring' already loaded in Unknown on line 0 Warning: Module 'mcrypt' already loaded in Unknown on line 0 Warning: Module 'openssl' already loaded in Unknown on line 0 Warning: Module 'pcntl' already loaded in Unknown on line 0 Warning: Module 'pfSense' already loaded in Unknown on line 0 Warning: Module 'posix' already loaded in Unknown on line 0 Warning: Module 'radius' already loaded in Unknown on line 0 Warning: Module 'readline' already loaded in Unknown on line 0 Warning: Module 'rrd' already loaded in Unknown on line 0 Warning: Module 'shmop' already loaded in Unknown on line 0 Warning: Module 'sqlite3' already loaded in Unknown on line 0 Warning: Module 'ssh2' already loaded in Unknown on line 0 Warning: Module 'xml' already loaded in Unknown on line 0 Warning: Module 'xmlwriter' already loaded in Unknown on line 0 Warning: Module 'zlib' already loaded in Unknown on line 0 Warning: Module 'zmq' already loaded in Unknown on line 0 Warning: Module 'suhosin' already loaded in Unknown on line 0 Warning: Module 'xmlreader' already loaded in Unknown on line 0 Removing ntopng components... Menu items... done. Services... done. Loading package instructions... Deinstall commands... done. [1/1] Deleting files for pfSense-pkg-ntopng-0.8.10: ........ done Warning: Module 'session' already loaded in Unknown on line 0 Warning: Module 'bcmath' already loaded in Unknown on line 0 Warning: Module 'ctype' already loaded in Unknown on line 0 Warning: Module 'curl' already loaded in Unknown on line 0 Warning: Module 'dom' already loaded in Unknown on line 0 Warning: Module 'filter' already loaded in Unknown on line 0 Warning: Module 'gettext' already loaded in Unknown on line 0 Warning: Module 'hash' already loaded in Unknown on line 0 Warning: Module 'json' already loaded in Unknown on line 0 Warning: Module 'ldap' already loaded in Unknown on line 0 Warning: Module 'mbstring' already loaded in Unknown on line 0 Warning: Module 'mcrypt' already loaded in Unknown on line 0 Warning: Module 'openssl' already loaded in Unknown on line 0 Warning: Module 'pcntl' already loaded in Unknown on line 0 Warning: Module 'pfSense' already loaded in Unknown on line 0 Warning: Module 'posix' already loaded in Unknown on line 0 Warning: Module 'radius' already loaded in Unknown on line 0 Warning: Module 'readline' already loaded in Unknown on line 0 Warning: Module 'rrd' already loaded in Unknown on line 0 Warning: Module 'shmop' already loaded in Unknown on line 0 Warning: Module 'sqlite3' already loaded in Unknown on line 0 Warning: Module 'ssh2' already loaded in Unknown on line 0 Warning: Module 'xml' already loaded in Unknown on line 0 Warning: Module 'xmlwriter' already loaded in Unknown on line 0 Warning: Module 'zlib' already loaded in Unknown on line 0 Warning: Module 'zmq' already loaded in Unknown on line 0 Warning: Module 'suhosin' already loaded in Unknown on line 0 Warning: Module 'xmlreader' already loaded in Unknown on line 0 Removing ntopng components... Configuration... done. >>> Removing stale packages..

    Very close to just wiping it and reloading it.

  • Accessing internal net with virtual IP via openVPN

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • Processor counts drop to zero

    2
    0 Votes
    2 Posts
    305 Views
    K

    In case anybody runs into this issue, it was caused by having the time sync services turned on in Hyper-V. We disabled the time sync services offered by Hyper-V (in the Hyper-V manager) and the issue went away.

  • Notification e-mail for WAN down, shows green in web

    3
    0 Votes
    3 Posts
    472 Views
    C

    Thanks for the reply, the issue re-appeared today.

    Here is the log of the WAN in question:

    Nov 27 14:35:08 dpinger: OPT4_WAN_DHCP_DHCP 8.8.8.8: Clear latency 497157us stddev 968654us loss 0%
    Nov 27 14:34:14 dpinger: OPT4_WAN_DHCP_DHCP 8.8.8.8: Alarm latency 517317us stddev 803024us loss 0%

    The mail messages stated that:
    _MONITOR: OPT4_WAN_DHCP_DHCP is down, omitting from routing group MainOut
    8.8.8.8|10.11.1.2|OPT4_WAN_DHCP_DHCP|517.759ms|802.821ms|0.0%|down

    MONITOR: OPT4_WAN_DHCP_DHCP is available now, adding to routing group MainOut
    8.8.8.8|10.11.1.2|OPT4_WAN_DHCP_DHCP|499.966ms|814.632ms|0.0%|delay_

    I guess the WAN was ommited due to high latency, which occurs when a line is really busy.

    Maybe change the latency thresholds (200/500)?

    Best regards

    Kostas

  • Trying to get VLANs working with TP-Link TL-SG1016DE switch

    6
    0 Votes
    6 Posts
    2k Views
    JKnottJ

    Now that I understand, at least I think, that a tagged port is expecting tagged packets, instead of tagging them.

    No, a tagged port is an access port that accepts untagged frames and then tags them.  A trunk port accepts all frames, tagged or not.

  • Inside out - egress filtering

    3
    0 Votes
    3 Posts
    552 Views
    QinnQ

    @NogBadTheBad:

    Put your IOT equipment on its own subnet and do the following on the IOT interface:-

    1st rule allow IOT net to this firewall DHCP, NTP, etc …
    2nd rule block IOT net to LAN net
    3rd rule allow IOT net to any

    Thanks for your advise, but here that was already the case, all IOT devices are in a different subnet and are rejected when trying to access any other subnet. Only a few selected subnets can reach this IOT subnet through a NAT rule.

  • Difficulties Getting Pfsense on GCP

    3
    0 Votes
    3 Posts
    2k Views
    G

    Hi all,
    here are all the steps I´ve done to complete the PFSense installation on a GCP instance:

    References (Credits):

    Route Card: https://groups.google.com/forum/#!topic/gce-discussion/tPYonu9dwbc

    nlienard: https://gist.github.com/nlienard/0ca5aa8397af6e90d70f

    Desra Blog: http://desrablog.blogspot.co.uk/2017/11/using-t1n1wall-on-google-compute-engine.html

    Google Cloud Documentation

    The pfsense downloads contain a disk image inside, the instructions say that you extract it, rename it (to the convention gce expects) and compress it again.  you can do this in your cloud console or a linux system:
    wget https://nyifiles.pfsense.org/mirror/downloads/pfSense-CE-memstick-serial-2.4.2-RELEASE-amd64.img.gz
    gunzip pfSense-CE-memstick-serial-2.4.2-RELEASE-amd64.img.gz
    mv pfSense-CE-memstick-serial-2.4.2-RELEASE-amd64.img disk.raw
    tar -Sczf pfSense-CE-memstick-serial-2.4.2-RELEASE-amd64.img.tar.gz disk.raw

    Create an image based on the file you uploaded to the bucket:

    Activate the serial console on the project:
    sudo ./google-cloud-sdk/bin/gcloud compute project-info add-metada –metadata=serial-port-enable

    Create an instance and add a second disk to it:

    Use the serial console to perform the install:
    sudo ./google-cloud-sdk/bin/gcloud compute connect-to-serial-port [INSTANCE_NAME] – zone [ZONE]

    Install the PFSense on the second disk:

    Create a snapshot from this disk you created:
    Create an instance from this disk:
    Use the serial to perform the setup:
    sudo ./google-cloud-sdk/bin/gcloud compute connect-to-serial-port [INSTANCE_NAME] – zone [ZONE]

    Using the shell, disable HTTP REFERER:
    "pfSsh.php playback disablereferercheck"

    from that point on, you can access the GUI with the external IP address provided on the instance.

    Hope it helps someone.

    Gustavo

  • [solved] Script to disable rules based on keyword

    5
    0 Votes
    5 Posts
    1k Views
    J

    @PiBa:

    There are a few issues i think :)
    The code you have 'creates' a run2 file, but im not sure how you execute that.. Seemed to be missing the Not enough includes, the $value does not modify the original use &$value to keep the reference to the original array value that needs to be modified.

    I would probably create a php file /root/script.sh that can be directly executed when given execute permissions chmod +x /root/script.sh
    Below code 'works for me' :) .

    #!/usr/local/bin/php-cgi -f require_once("globals.inc"); require_once("filter.inc"); require_once("util.inc"); require_once("config.inc"); global $config; $config = parse_config(true); foreach ($config[filter][rule] as &$value) { if (strpos(strtolower($value[descr]), 'pfb_dnsbl_allow_access_to_vip') !== false) { $value[disabled] = true; //unset($value[disabled]); print_r($value); } } write_config(gettext("Firewall: Rules - saved/edited a firewall rule.")); $retval |= filter_configure(); print_r($retval);

    Thanks a lot! Works well.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.