• Limiting maximum WAN upload speed to CIR

    2
    0 Votes
    2 Posts
    374 Views
    H

    When you say "anything above the CIR will be discarded", do you state this as a fact or a requirement on your end? If it's a fact, then let the ISP drop the packets, TCP will back off. If it's a requirement, then you will need to use one of the traffic shapers. Different shapers have different characteristics.  HFSC has the most correct implementation and should be nearly perfect. Just enable traffic shaping on your WAN interface, set to HFSC and assign a bandwidth. Don't need to configure any queues as the entire interface will be limited to whatever rate to specify.

    Depending on your circuit, you may need to play around with some settings. If your circuit is unbuffered but hard rate-limited, you may need to reduce your bandwidth slightly under your provisioned amount due to scheduling and bursting. You may need to reduce your bandwidth a bit anyway because they may be calculating bandwidth differently, layer1 vs layer2 vs layer3, and possibly layer1/2 that is different than Ethernet.

  • Serial modem config help

    1
    0 Votes
    1 Posts
    254 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    183 Views
    No one has replied
  • Multi-Wan PfSense 2.3.4_1 - Englisch

    2
    0 Votes
    2 Posts
    405 Views
    B

    Noeone has an idea? Please help i think its only a little failure :(!

  • 2.3.4 dyndns broken

    3
    0 Votes
    3 Posts
    404 Views
    P

    Turns out it's more difficult than that for afraid.org.  Gawd!

    In their interface you have to click on "Dynamic DNS" then click on "Check out: dynamic update interface (version 2)!" Then click on "activate" after ticking your IP's which will then ACTIVATE them for Dnyamic DNS…seriously?  That's why I'm there LOL can't you just activate them?  My gosh afraid!!!

    Now they're active AND you get a proper URL without the special character "?" in it!

    Done...the struggle is real people LOL.

  • NTOPNG not upgrading and massive amount of ALERTS, any ideas?

    3
    0 Votes
    3 Posts
    507 Views
    J

    what version of ntopng is everyone running? Mine seems really low compared to the advertised version.

  • Issues connecting to Azure AD

    3
    0 Votes
    3 Posts
    814 Views
    Z

    Can anyone offer any suggestions please?

  • Speed cap

    5
    0 Votes
    5 Posts
    756 Views
    3

    It doesn't make any sense.

    Will have to try other hardware and ultimately another router. To rule out the problem.

    I don't think it can be Vmware since i can meassure the full speed on both sides of it. (both adapters)

  • Pxe boot problem

    2
    0 Votes
    2 Posts
    535 Views
    D

    So my wild guess here is, there is no default filename and the GUI doesn't offer any method to set it or change it in dhcpd conf.
    I could set it manually but yeah it would get overwritten by each change of config.

    So I'd need to change the source template. Where can that be found?

    Honestly expected more from the much praised pfsense.
    Apparently <2.3 had that feature but not anymore.

  • 0 Votes
    3 Posts
    3k Views
    S

    Have you or anyone else found a solution to this? I am stuck with the same problem!

  • 0 Votes
    1 Posts
    222 Views
    No one has replied
  • Squid Problem

    1
    0 Votes
    1 Posts
    426 Views
    No one has replied
  • Block Netflix… i know how but, what is this?

    4
    0 Votes
    4 Posts
    1k Views
    ExolonE

    To add to what PiBa has mentioned, click this link, this example has a couple of screenshots showing how to use the AS numbers to block Facebook.

  • No access to pfsense over non-default vlan

    4
    0 Votes
    4 Posts
    617 Views
    M

    I have also added a firewall rule for the associated interface allowing all traffic (source and destination) but still no difference.

  • Multiple wan?

    5
    0 Votes
    5 Posts
    837 Views
    randomaustralianR

    @tim.mcmanus:

    @randomaustralian:

    does pfsense handle multiple internet connections and load share?

    If you have more than one WAN link and they are not going to the same gateway, pfSense can use multiple WAN links.  What it will not do is bind together two or more WAN links and aggregate a connection across the combined WAN links.  It can have multiple connections across WAN links by allowing each connection to go over a different WAN link.

    this is what i was hoping for

  • Log colorizer ccze works for system log but not for filter log

    2
    0 Votes
    2 Posts
    523 Views
    M

    I've answered my own questions.  Found info in topics that didn't really relate to mine but something tripped my brain into understanding what was going on.  It's the damn commas that are screwing it up.  That's the last thing I would have thought, that's how sharp I am.  I saw trying sed to attempt to color logs and that lead me to think of just stripping the commas and that works well enough for me.  I just used:

    clog -f system.log | sed y/,// | ccze

    Sorry if this was too elementary[it's actually surprising to me that I figured it out.  Yes, it seems I'm talking to myself.  Is that a problem?  No, not unless you start having a dialogue.  Oh, OK.]

  • Sshd service not starting

    1
    0 Votes
    1 Posts
    332 Views
    No one has replied
  • NTP IPv6

    3
    0 Votes
    3 Posts
    698 Views
    V

    I am on the current version, yes.

    2.3.4-RELEASE-p1 (amd64)

  • Cant ping one device unless on same subnet…

    25
    0 Votes
    25 Posts
    3k Views
    johnpozJ

    So you state your AP is pointing to pfsense as its gateway.  Did you verify its mask?  The simple thing that would cause your exact problem is if you have the mask wrong.. Anything larger than /22 would put your 192.168.2 and 192.168.1 on the same network.  So the AP seeing a ping request from 192.168.1.x would think hey thats my network and just answer it vs sending to its gateway.  It would not be able to arp for it.. So if your sniff shows you send it ping from pfsense, and all you see back is arps this would scream the mask is wrong on the AP.

    This would explain why you can ping other stuff on the 192.168.2 network but anything from 192.168.1 can not talk to the AP.

  • Something is happening allowing access to login screen on WAN

    2
    0 Votes
    2 Posts
    573 Views
    jimpJ

    Somehow you are hitting the GUI and not HAProxy.

    If those are purely HTTP, it's possible your browser cached the HSTS info sent from the GUI redirect before you disabled it. Clear your browser cache and try it again.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.