• Streaming services discover using vpn

    20
    0 Votes
    20 Posts
    2k Views
    JonathanLeeJ

    @johnpoz it had sandbox folders in it like snapshots of something. I never deleted that. It was really weird. Both V-100 spotlight folders and .trashes had that. I don't expose the NAS it's protected behind the firewall. Could have been a timebomb bug and it never got implemented because I blocked it. I thought maybe someone else has that bug and they don't know what is making the IP show as high risk. I don't even think OS x uses sandbox Microsoft does. Someone has to have seen this weird HDD resources consumption issue too. One can say it's the perfect place to hide. Some hidden folders that no one really looks at on any USB drive that is plugged into a apple OS. An invasive actor might use it for a container to do proxy chains with, or an exit node. The normal users would not think to look at it, they just use the NAS and the NAS uses their Internet without them knowing. That could cause a bad IP reputation without them knowing. I was flat out confused, thinking why is the folders all the sudden so massive in size. Just a weird situation. It's like a scary Halloween Pumpkin bug. Hey, that reminds me of the Metasploit's pumpkin I saw during a lab in October.

    Screenshot_20230916-103329.png

    Screenshot_20230916-103348.png

  • Upgraded mobo lost internet connectivity

    8
    0 Votes
    8 Posts
    733 Views
    johnpozJ

    @THEVIKING said in Upgraded mobo lost internet connectivity:

    I have Pfsense router setup to send all traffic thru VPN to 192.168.20.100 (my PC)

    This doesn't make a lot of sense - so your pc is hosting vpn server? That outside clients connect too? Or your routing your traffic out through a vpn on pfsense (client to some vpn service)

    You have some vpn on pfsense and your doing a port forward through the vpn?

    None of these scenarios have anything to do with you changing the mother board your pc and pfsense.. Not one of those scenarios has anything to do with pfsense and you changing your pc motherboard.

    The only thing that could change on your pc that might effect something you have setup on pfsense is the IP address of your PC, if its still 192.168.20.100 pfsense doesn't give 2 shits what motherboard or OS or anything - it only cares about the IP address.

  • frustrating installation issue

    8
    0 Votes
    8 Posts
    783 Views
    stephenw10S

    A D2250 should work it would just be bandwidth limiting for PPPoE. But something like that will already be old, better to start with something newer anyway. 👍

  • Confusion in understanding one of the "Deny unknown clients" setting

    13
    0 Votes
    13 Posts
    2k Views
    johnpozJ

    @SteveITS said in Confusion in understanding one of the "Deny unknown clients" setting:

    We used to have tenants

    While that seems like a very valid use case.. Thanks for a great example.. But that kind of puts you a bit above your typical home/smb sort of use don't you think ;)

  • POrtal cautive doesnt work with iphone and android

    4
    0 Votes
    4 Posts
    478 Views
    stephenw10S

    Mmm, in fact it generally work better with mobile devices in my experience. Any recent version of Android or iOS can detect the redirection and prompt the user before they've even opened a browser.

  • Netgate 2100 & NUT or apcusbd w/ BX1000M

    8
    0 Votes
    8 Posts
    716 Views
    G

    lol yeah, @dennypage with just that it still works.

  • No backups could be located for this device.

    1
    0 Votes
    1 Posts
    127 Views
    No one has replied
  • Problem with traffic or limited traffic

    8
    0 Votes
    8 Posts
    691 Views
    stephenw10S

    So was it passing full speed until recently?

  • Port forwarding not working properly

    26
    0 Votes
    26 Posts
    2k Views
    stephenw10S

    That's what I would expect because the system routing table should be correct. Incoming traffic should always come from that route unless you have some route asymmetry somehow.

    It's the port forwards (NAT) that allows traffic from a single source IP to arrive via any gateway.

  • 0 Votes
    4 Posts
    468 Views
    stephenw10S

    Is the OpenVPN server configured to listen on 'any' interface?

    If you can put a switch between igb2 and that PC? That would solve this.

    However if you set OPT1 to track interface for IPv6 it will probably stop this happening. Even if you have no IPv6 on the WAN.

  • 0 Votes
    5 Posts
    515 Views
    stephenw10S

    No solution yet as far as I know. Any progress here should be on the bug report.

  • Access from internet router to LAN

    11
    0 Votes
    11 Posts
    1k Views
    johnpozJ

    @macaruchi said in Access from internet router to LAN:

    No, it doesnt

    So how would you expect pfsense to forward something that never gets to pfsense?

    Either you don't have the forward setup correctly in the router in front of pfsense, or the traffic is never even getting to that router for it to forward.. You sure when you went to can you see me that the IP it sent the traffic too was the routers wan IP that you setup the forward to pfsense wan IP?

  • Adding Netgate 3100 to existing network

    16
    0 Votes
    16 Posts
    1k Views
    P

    @stephenw10
    That makes sense.
    Thanks

  • If someone accesses the PFSense admin screen, can I put in an attack tool?

    16
    0 Votes
    16 Posts
    1k Views
    johnpozJ

    @stephenw10 yup that is a very good viable option.

    Or use that opt1 for your normal network, because the "lan" has the anti-lock out rule on it.

  • Crash

    3
    0 Votes
    3 Posts
    212 Views
    C

    @stephenw10
    Ok, I changed my hard drive. We’ll see!

  • CVE-2023-4809 in 2.7.0-RELEASE i.e FreeBSD 14.0 ?

    Moved
    6
    0 Votes
    6 Posts
    881 Views
    stephenw10S

    There is no specific rule to block it. All unsolicited traffic is blocked inbound by default.

    Traffic is scrubbed by default which prevents fragments passing but even if you disabled that most rules would not pass fragmented traffic because they cannot match without the header info.
    See: https://man.freebsd.org/cgi/man.cgi?query=pf.conf#FRAGMENT_HANDLING

    There's no way to actively pass fragments from the GUI, there is no fragment option on user rules.

  • Will pensense join vpp/dpdk

    7
    0 Votes
    7 Posts
    664 Views
    NollipfSenseN

    @planedrop said in Will pensense join vpp/dpdk:

    @NollipfSense I am guessing a typo, though that might be a difficult one to do....

    LMAO...

  • PHP Error

    6
    0 Votes
    6 Posts
    553 Views
    J

    It's defiantly Home Assistant. I assume deleting the integration didn't completely get rid of everything. I'll have to do some poking around and see if I can find out how to disable whatever is left.

  • having issue migrating OpenVPN Shared Key to SSL/TLS

    2
    0 Votes
    2 Posts
    388 Views
    stephenw10S

    Commonly it's because there are no iroutes to allow the OpenVPN server to know which subnets exist behind which clients. Those are not required in a shared key setup because it can only ever be point-to-point.

    https://docs.netgate.com/pfsense/en/latest/recipes/openvpn-s2s-tls.html#create-client-specific-overrides

    Steve

  • Netgate 7100 1U will not boot various errors

    3
    0 Votes
    3 Posts
    451 Views
    J

    @stephenw10 That's great, thank you. I'll get that done

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.