• Alerts and monitoring of IPSec tunnel

    2
    0 Votes
    2 Posts
    1k Views
    F
    If you can see some sort of notice in the logs, perhaps one method would be to use some browser automation like http://www.seleniumhq.org/ to log in and check every few minutes, download the log, parse it and if error message is detected raise an alert via a variety of means beit email, phone or text. https://freeswitch.org/ could help you raise the alerts quite easily and runs on a few OS's. fwiw.
  • DNS probe finished error

    2
    0 Votes
    2 Posts
    4k Views
    D
    WTH is DNS probe? Did you install some "helpful" plugin? Ping pfSense by IP works? Ping 8.8.8.8 works? Ping www.google.com works? traceroute, nslookup? No info here.
  • MOVED: DNS config for local webserver with subdomains

    Locked
    1
    0 Votes
    1 Posts
    348 Views
    No one has replied
  • This doesn't look good –- Cam Scanner---- listed under System Activity

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    N
    Well, technology, more often than wanted, makes me a bit paranoid. Why is it whenever you jump to conclusions, those conclusions are rarely good?
  • No loader.conf.local in freash 2.2.2 install

    3
    0 Votes
    3 Posts
    889 Views
    C
    If you never created one, it's not there. If you need to put something there, create the file.
  • MOVED: dar Internet sin tener habilitado dhcp

    Locked
    1
    0 Votes
    1 Posts
    342 Views
    No one has replied
  • Solarwinds Config Backup stop working with 2.2.2

    1
    0 Votes
    1 Posts
    438 Views
    No one has replied
  • Weird FTP problem. Did something change in PFsense 2.2??

    Locked
    3
    0 Votes
    3 Posts
    657 Views
    R
    @KOM: FTP Proxy was removed from pfSense 2.2 https://doc.pfsense.org/index.php/FTP_without_a_Proxy Thanks, that fixed it. Nothing like ancient software to keep us busy…. :( In case its not obvious, PFsense is NOT the ancient software I am complaining about....
  • How is the out of box security?

    17
    0 Votes
    17 Posts
    4k Views
    F
    Some thoughts. Anything capable of running software of sorts, beit your computer, firewall, mobile phone, printer, photocopier, TV's, vehicles's etc with the ability to update it with new versions of software has the potential to be hacked. With that in mind, the next question is how easy is it to update? TV's can be updated over the air, some vehicles & phones similarly; now in the case of computer networks, you need to isolate everything otherwise something like stuxnet & other rogue software can be hiding in your network printers or photocopiers or switches. One way is to isolate everything into its own unique sole vlan with firewalls blocking everything thats not permitted. Permission should only be granted when you want to, like for example allowing access to update sources during dates & times of your choosing, none of this allowing anything to touch base unneccesarily like windows desktops phoning home to MS in the US when you log on for example, same for switches. Bear in mind all isp routers and firewalls all have a default allow out to the net rule including pfsense, what an easy way to walk out with your data. Audit all PC's where possible so you know what the contents of your computers hd's are frequently becuase the flaw with AV software is simply this, the AV companies need to find the virus first before they can add it to their signature database of known viruses. In other words your AV software can not protect you unless the AV company has found the virus. For point of reference, AV companies can spot variations of the same virus automatically in most cases which are the updates we receive hourly, daily weekly etc, its the new viruses that can take weeks, months, years to reverse engineer before they consider something a virus or not and thats before we get into polymorphic software. Bear in mind its entirely possible for app stores including MS updates to serve unique files just for you if you want to be really paranoid and how do you know that dll coming down the wire is what it says it is? Bear in mind its also possible to hide software in the less used parts of spin disks which no longer get formatted when reinstalling your windows OS as it does a quick NTFS format which just resets the FAT (disk index) not blank the contents (the chapters of the book). Log all traffic data in and out and have something to analyse the data so it flags up anomalies or unaccountable network traffic. Get to know the data patterns by day, week, month & year much like you would know when your car is not running quite right. In some cases block ssl traffic out of your machine as you dont know what data is being lifted/sent that could incriminate you, even your windows os tracks the files like what you send to the recycle bin and that is part of the forensics built into windows. Be careful of Google, its very machiavellian and will serve you data which can land you in court, be careful of websites you visit as some dont allow you to report questionable data, again setting you up for a fall if the authorities so desire. Work on the basis if you can think it so can they, but they will have beaten you to it in ways to access that data, and remember a request from one country to another is not always immediately illegal except where the conspiracy to commit a crime is punishable like here in the UK, which means every request GCHQ sent abroad to foreign spooks is commiting a crime even though they like to portray they dont break the law, dontcha believe it. They will even employ phishing techniques in major online news media via comments and other websites to find out the information they want to know like how easy it is to evade their detection. ;D FWIW.
  • VPN possibility?

    9
    0 Votes
    9 Posts
    1k Views
    K
    Just for reference: you are installing a different server on top of your windows 2012 file server to have external users access those files without AD permissions. Why not just configure the permissions correctly? So true I was thinking it was wierd installing a server on a server. So I just installed lls managment console and ftp service. But now my issue or worry is that if i give a VPN access (192.168.2.2) to communicate to (192.168.3.9) would it be possible for only the VPN to ping 192.168.3.9 and not my other server (192.168.3.8) Thank you
  • Vlans behind PFSense Slow

    8
    0 Votes
    8 Posts
    2k Views
    A
    I've added my layer 2 and 3 design as pictures. Indeed this is a hosted setup in a datacenter. All customers make connections over internet to their network (VLAN) Take a look at the pictures. Layer 2 picture is not correct…...eth 2 on A  to eth 3 on B is PFSYNC in PFSENSE setup......forget to correct that. Our problem is that with our GTA firewalls we had no complaining customers, but with the PFSense firewalls customers have 10 times slower browsing the internet or browse their mail is slow even apps in their VLANs are very slow. For now i put back the GTA and evrything is fine again. ![Infrastructuur design v1 0 laag 2.png](/public/imported_attachments/1/Infrastructuur design v1 0 laag 2.png) ![Infrastructuur design v1 0 laag 2.png_thumb](/public/imported_attachments/1/Infrastructuur design v1 0 laag 2.png_thumb) ![Infrastructuur design v1 0.png](/public/imported_attachments/1/Infrastructuur design v1 0.png) ![Infrastructuur design v1 0.png_thumb](/public/imported_attachments/1/Infrastructuur design v1 0.png_thumb)
  • 0 Votes
    3 Posts
    760 Views
    B
    Thanks cmb. Turns out the ISP had an undocumented radio on the network.  I guess I ended the freebie Internet for someone.
  • Monitoring my LAN: hardware + software?

    22
    0 Votes
    22 Posts
    7k Views
    M
    @KOM: A Master of Bugger-All? Didn't know that one  ;D Seems you've met some of the victims of the college bubble, with their 'MBA's'. They've paid heavy money to learn basic accounting (basic!), and some ratio formulas to assess a balance sheet (they were screwed as nobody ever told them they were looking at an irrelevant balance sheet…). Yet, I know how much IT-people feel disgusted about us economists. They mix up bankers (not economists, we warn about the messes governments create since about a millenium ago...) with us, they think we are stupid since we 'don't understand the economy'. Yet: IT-people work with 4-10 variables, we with hundreds,  and sometimes even thousands. There's even medical doctors that admit our job is way more difficult than theirs (and theirs is very extremely difficult too). Who cares: in the end hire and fire IT-people, based on efficiency and effectiveness of the the proposals is all that matters  ;D ;D ;D ;D ;D
  • How to redirect LAN traffic going to WAN IP to LAN ip

    13
    0 Votes
    13 Posts
    3k Views
    KOMK
    Just today my boss decides to argue with me.  He knows nothing, but like a lot of managers, he's The World's Smartest Man, and you aren't right unless he agrees with you. Today's gem was about VoIP.  We are looking at switching from RingCentral to another service.  He is arguing with me that the new service should just work as long as I give them the MAC addresses of the phones.  When I tell him that that isn't enough and that the phones need to know where to download their manifest from, he starts to argue.  He knows nothing.  He thinks you can route over the Internet based only on MAC address into a private LAN.  I tried to explain that it's like giving your employee a unique employee number, and then trying to locate that employee anywhere in the world just based on the employee number.  He didn't understand and continued to argue.  Then, like he always does, he goes away for awhile to research how he is right and I am wrong.  Inevitably, he finds out he was wrong and it's never mentioned again because important, arrogant, know-it-all assholes aren't allowed to admit mistakes.  I feel like Quincy M.E. sometimes.  Quincy is right 3000 times in a row, but the next case has everyone doubting him as usual (even though he's always right).
  • Occasionally seeing high CPU usage on {irq15: vr2 ata1}

    2
    0 Votes
    2 Posts
    585 Views
    A
    Maybe your hard disk is crapping out.
  • Pfsense on Watchguard x750e - Upgrade from CF to HDD?

    20
    0 Votes
    20 Posts
    4k Views
    stephenw10S
    The easiest place to check it is at the boot POST screen. It may be possible to read it with some utility from the pfSense command line, I haven't tried that. Any utilities I did use were under 8.1. You can read it from FreeDOS with the biosid command but that's less convenient. Steve
  • Support for php-MySQLi?

    6
    0 Votes
    6 Posts
    2k Views
    perikoP
    We are thinking how to accomplish this that is a good tip thanks Gertjan. Not really sure how was it lost or how you assume to get more/better answers when you start a duplicate thread every couple of days. Stop abusing pfSense firewall as a generic webserver. Sir, u don't even know what we are doing but u already again stop trying people to build a more rich firewall, we are not using pfsense as web server don't know where u get this info, we just want to connect to a external mysql server using php, we are building a app that  is related to captiveportal, php-mysql is a old driver, the new one php-mysqli is the new and has better new functions that we use. The firewall is very well check and rules to let just pass what we need no more. The other thread was related to install php-mysqli, this is related to how to add php-mysqli to the base system. But well thanks doktornotor for your advised.
  • /boot/loader.conf keeps resetting on every upgrade

    10
    0 Votes
    10 Posts
    2k Views
    dennypageD
    Touch updates the modification time on a file. If the file doesn't exist, it creates an empty one. Copying loader.conf to loader.conf.local and then editing was an as good or better approach. @Phishfry: I will have to read up on "touch" -First i have heard of it…
  • PfSense itself can't connect to updateserver or ping anything

    7
    0 Votes
    7 Posts
    1k Views
    F
    My Box has 3 interfaces but they are all in use. I have LAN, WAN1 and WAN2 because the pfsense uses 2 DSL lines.
  • NTP not working in 2.2.2

    3
    0 Votes
    3 Posts
    670 Views
    D
    Sorry - i just realized on my drive in to work what the problem is. The router's default egress path is going through a vpn and that is what is causing the problem.  NTP is working :)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.