• Automated backup script (alive again)

    1
    0 Votes
    1 Posts
    245 Views
    No one has replied
  • PfSense crashes while watching AppleTV

    5
    0 Votes
    5 Posts
    684 Views
    V

    Thank you for your tips!

    I'll try to run the Apple TV on a separate LAN interface.

  • Ensuring i don't make noise on WAN?

    14
    0 Votes
    14 Posts
    1k Views
    JKnottJ

    @mirkwoody:

    True.

    He said that even some off-the-shelf known brand routers would be kicked off.. because.. noise..

    That's the first I've heard of that one.

  • Kaby Lake Installer hangs

    3
    0 Votes
    3 Posts
    690 Views
    C

    Thanks JIM.

    Sorry the installer was 2.3.4 from usb, I downloaded the 2.4 as you suggested and it installed fine thanks again for always giving great advice.

    PDS

    PFSENSE runs fantastic on these Kaby lake, and at Idle are really  low power did over 1 hour just on the UPS  (around 4W)

  • Yet Another Crash Report

    2
    0 Votes
    2 Posts
    405 Views
    C

    Even better. Now I have a bug report as well!

    bug.txt

  • MOVED: Squid Guard Proxy when admin port changed?

    Locked
    1
    0 Votes
    1 Posts
    192 Views
    No one has replied
  • Upload partial edited config backup?

    3
    0 Votes
    3 Posts
    426 Views
    valnarV

    OK cool.  Thanks

  • Packet Capture v2.4RC

    3
    0 Votes
    3 Posts
    599 Views
    jimpJ

    Also: What type of interface is your WAN? (brand/make/model/driver name and also how it's configured such as static, dhcp, pppoe, etc)

  • Switching from untagged LAN to 8021q tagged LAN

    8
    0 Votes
    8 Posts
    866 Views
    dotdashD

    @xphiles:

    can you then disable the LAN port and still carry traffic over the VLANs?

    In the original example, the LAN was moved to the tagged vlan and the raw interface was no longer assigned to an interface, so no you would not disable the LAN.

  • Need help

    3
    0 Votes
    3 Posts
    570 Views
    D

  • PFSense allow Chrome Remote Desktop

    2
    0 Votes
    2 Posts
    2k Views
    GertjanG

    Hi,

    The default firewall rule present on LAN will handle the job : pass all.

    I'm not using any Google tools myself (except their mail services) but I guess "Chrome Remote Desktop" works the same way as "TeamViewer" : there is no need to setup something on your router. There is nothing that says you have to "NAT" something on your router.
    Which is quiet logic because Google want to see all the information you see, so all info passes by THEIR servers fist. This means that both app on both sides connects to a central Google server, which means that both devices - the controller and the "controlled one" make outbound connections only, which means pfSense is set up by default just fine.

  • After 2.4.0 update, LAN IP will not configure

    4
    0 Votes
    4 Posts
    462 Views
    D

  • Plain-language newbie security instructions

    5
    0 Votes
    5 Posts
    782 Views
    B

    yes, your firewall is up and running from the moment you install it and plug it in. It runs out of the box for almost all network configurations, and is secure in that configuration.

    As far as uploading files to your box, yes you can do it from the webgui, or from SSH. It's as simple as creating a new file and copying the list of IPs into the new file. Then point pfBlockerNG to that file, it might be done with DNSBL? I'm sure you could also import the list as an alias and just use that on firewall.
    I've never imported a list to an alias before and don't have a pfsense box to look at right now but I'm almost certain there is a webgui button for it?

    If you named the list "BAD_IP" then the rule would be something along
    BLOCK any_source_ip on any_source_port > BAD_IP

    Again, I've never done it that way but am pretty sure that will work. I don't know how you're compiling your list but the problem with most self-maintained lists of bad IP's is that IP's are dynamic and will change over time. So after enough time you'll eventually not be blocking bad guys anymore but will be blocking whatever computer or service is now behind that IP.

    Depending on what you are trying to block with this personal list, you can probably either find a maintained list that covers it and is updated by a service, or use an IDS/IPS to block the IP's.

  • SNTP Problem getting connection!

    9
    0 Votes
    9 Posts
    2k Views
    P

    i reinstalled suricata . i did these a serveral times before i solved my problem with sntp.
    at the moment everything works without any problem. still don´t know exactly what solved the sntp problem.

    by the way…

    i use suricata now in monitor mode because i want to change it to "block on drop" but i do not quite understand it.

    see my post. perhaps you could help me with my questions?

    -> https://forum.pfsense.org/index.php?topic=137669.msg752860#msg752860

  • Reliable traffic counter?

    2
    0 Votes
    2 Posts
    524 Views
    H

    Does nobody have an idea why the vnstat values are quite far off the actual traffic passing through the system?

  • ISCSI Possible?

    2
    0 Votes
    2 Posts
    1k Views
    F

    I don't know if this would work but I can say it is ill advised from a security standpoint..
    You don't want your internet facing firewall to do anything but routing and network tasks.
    iSCSI file serving is something you want to do behind pfSense not on top of it.

  • Pfsense goes down every morning

    18
    0 Votes
    18 Posts
    3k Views
    ?

    What should I be looking for?

    In Germany it is common that many of the ISPs are cutting the Internet connection once a day, could this be the
    point you should also looking for?

    If there is a double NAT situation you could try out to set at the pfSense WAN settings a satic IP address from the
    network of the router in front of that pfSense box. Because the DHCP lease will be out after xyz minutes/days/weeks
    or so on.

  • Show the Number of Active LAN Clients

    4
    0 Votes
    4 Posts
    1k Views
    ?

    Internal:

    The ARP table as named above Squid & SARG perhaps

    External:

    CentOS and NAGIOS2 TclMon on an APU, NUC or other small device On a small external device such the RaspBerry PI or the netgate MinnowBoard Turbot series and a Linux or FreeBSD
    OS on it with CACTI and MRTG.
  • Pfsense without nanobsd image

    7
    0 Votes
    7 Posts
    939 Views
    ?

    I learn that release 2.4 will have no nanobsd image.

    32Bit and NANO BSD are gone, but there fore we got ARM support and some other nice things, so it was nothing
    less but more changed against other things that are available now.

    If I install pfsense to a compact flash drive, how can I reduce writing to CF?

    Alternately you may go with a 4 GB or 8 GB IDE flash module or with a IDE SSD that might be the best option in my eyes.

    Currently, I have a old PC with a 2G CF card with nanobsd image installed on a IDE slot, it works great for more than 5 years.

    32Bit hardware? This might be also running out too! So newer hardware will be not so really high in price,
    the APU2C4 or the SG series might be holding for Internet account with lower speeds.

    Is it possible to have a similar installation like this after 2.4 released, I mean with minial CF wear out problem?

    As stated above you should try out a small IDE SSD.

    Thanks for you reply. I will only need snort package. Is snort only write to /tmp or /var?

    What is your Internet connection speed?

    BTW: How much disk space is required for a full pfsense install, I cannot find it documented
    anywhere

    pfSense and snort is able to install on a small 16 GB mSATA storage. The APU2C4 is able to get around
    for ~199 € and the SG-2220 is able to get for $299.

  • Selective routing via VPN interface

    22
    0 Votes
    22 Posts
    4k Views
    I

    Wonderful. Thank you again for sticking by a novice like me.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.