• Another GUI over WAN issue. Settings Confirmed Correct(?)

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    pass  in  quick  on $WAN reply-to ( igb0 WAN_GATEWAY ) inet proto tcp  from any to OFFICE_STATIC_IP port 443 tracker 1474672711 flags S/SA keep state  label "USER_RULE" Looks fine - are you sure it's even listening on 443? Are the connection attempts arriving on WAN? (Do another packet capture there probably filtering on the source IP).
  • 10G TCP Performance

    6
    0 Votes
    6 Posts
    6k Views
    H
    He was doing a UDP test and attempting to send 2Gb/s over his 2Gb/s connection was causing almost 50% packetloss on average. His connection cannot support anywhere near his provisioned speed. He also had several performance tests showing he can get 1.95Gb/s over TCP, but the same test may only give him 300Mb/s only minutes later. I do agree TCP tuning becomes an issue these rates and typical WAN latencies, but that is not the current bottleneck. And TCP tuning PFSense won't gain you almost anything in for most settings. The firewall is not the sender or receiver, it's just a middleman that makes sure the state is valid.
  • PFSense Packetloss and slow connection

    8
    0 Votes
    8 Posts
    2k Views
    KOMK
    No I don't have a tutorial but it is pretty simple. :o  IMO traffic shaping is one of the hardest concepts to understand, especially if your use case is outside what the wizard supports.
  • GRE Tunnel, Possible Bug.

    1
    0 Votes
    1 Posts
    780 Views
    No one has replied
  • 2.3.2 100% cpu load with SMP

    2
    0 Votes
    2 Posts
    860 Views
    G
    This problem went away with 2.3.3
  • PFsense continues to mature, but loses critical parts along the way…

    4
    0 Votes
    4 Posts
    2k Views
    B
    Jimp, Thanks for taking the time to reply to each point. Let me say however, that while I agree that you are spot-on with your account of what was done and why, that doesn't address the concerns I bring up. Perhaps I am being too wordy or just plain vague, something I do from time to time. PFSense has and continues to be a good firewall, however it is losing its standing as the leading Open Source solution in its category. This is mainly because the category itself is changing. Firewalls are now a thing that is largely considered a basic service. Managing access at the edge of the Internet is a simple and expected function today. PFSense can not continue to simply be a "great firewall" and stay in focus to the user base. The UTM or NGFW (Next Gen Firewall) is nearly the defacto standard for managing traffic. Firewall functions like the ones PFsense provides are just a component part of these new platforms. the good news is that you are imminently qualified to keep up with this trend and stay in the forefront of the Open Source firewall category. In my opinion, the PFSense team needs to seriously consider the role that your device plays in the daily life of a network administrator. Ease of use, combined with monitoring and at-a-glance visual reporting and accurate alerting. To be more specific… Application Awareness, Stateful Inspection, Integrated Intrusion Protection System (IPS), Identity Awareness (User and Group Control), Bridged and Routed Modes, The ability to utilize external intelligence sources Nearly ALL of these things were available in the previous generation with the correct plugins applied. Let me end by saying that overall, the PFSense team has done a remarkable job of keeping the base code healthy and secure. However, the REAL value came from the features that were achievable using plugins. Feel free to go back and read the reviews 1+ years ago and beyond. you will see that the authors highlighted the plugin community as the series of "killer apps" that set PFsense above the rest of the pack. My advice is to realize that the firewall aspects of protection are now expected and no longer a significant accomplishment. Focus on the customer facing role of the platform and what it can do to EASE the daily life of the administrators and those that are protected by the platform. Design backwards from there and you will once again prove PFSense is THE standard in Open Source firewall (and moving forward NGFW) solutions. You have ALL the parts you need, and many experienced developers and community members to leverage for this effort. That includes myself - someone who designs platforms and customer facing infrastructure software solutions daily. Once you do this, your team can offer more than simple Gold Support options. The number of managed services that you could provide (like cloud / managed threat protection) are nearly limitless. All this without having to invent much in the way of "new" technology - remember PFSense has had most of this before at various times.
  • OpenVPN stability issues - error 55

    15
    0 Votes
    15 Posts
    14k Views
    PippinP
    See here too: https://forum.pfsense.org/index.php?topic=117557.msg651859#msg651859
  • Snort - how to supress a blocking rule

    3
    0 Votes
    3 Posts
    618 Views
    W
    So you're getting flag using FTP over HTTP through a web browser?
  • 0 Votes
    6 Posts
    1k Views
    J
    Hi 2 reasons for trust in one ip-block-list: Reputation and common sense, and this list does not satisfy the second condition (block all net and subnets for dreamhost, forum.pfsense.org , etc, crazy :) ) Regards.
  • What is this crashing of pho? Help

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    It's most likely related to an incorrect entry in extensions.ini or something out of order there. You may be able to fix it by forcing a reinstall of all the php extensions from the shell. The problem won't exist on 2.4 or 2.3.3 because the way extensions are loaded has fundamentally changed.
  • Log File Upper Size Limit

    2
    0 Votes
    2 Posts
    616 Views
    jimpJ
    Since performance is largely dependent on hardware, any such limit would be hard to nail down. It's reasonable to have an upper bound but figuring out what that might be across various hardware platforms and combinations would be an adventure.
  • Testing pfsense security..

    2
    0 Votes
    2 Posts
    1k Views
    KOMK
    There are lots of online scanners such as Shields Up.  Install and learn nmap if you want to go deeper.
  • 0 Votes
    2 Posts
    504 Views
    jimpJ
    Why such an old version? Try it again on pfSense 2.3.2, or at least 2.2.6.
  • Config Settings Long/Short Form Inconsistency

    6
    0 Votes
    6 Posts
    983 Views
    S
    Pushed a change to force <tag></tag>rather than <tag>This should make the config file more consistent.</tag>
  • Syslog-ng on 2.3.1/2.3.2

    1
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • Log format

    2
    0 Votes
    2 Posts
    354 Views
    jimpJ
    The log format of what? The filter? Or something else? None of the log formats are customizable, though if you have enough C programming knowledge you might be able to change the filterlog daemon to output the format you want. But it's not simple nor possible on the firewall itself.
  • Blank notices

    3
    0 Votes
    3 Posts
    689 Views
    jimpJ
    Look in the main system log, it should have an entry there as well. Something has to be generating the notice, and it's most likely from a package. The log entry from the main system log may at least show you the script that was running which generated the notice.
  • Bridge configuration on version 2.3.2p1

    3
    0 Votes
    3 Posts
    678 Views
    johnpozJ
    "Since bridging anything is just a bad idea" Hey there you go your getting it ;) So I am really confused with this statement EM2: VLAN 551 EM3: VLAN 552 Brg551552: Bridge of 551/552 So your 2 different vlans are on the same layer 3 network?  Makes Zero sense.. If your wanting to bridge 2 layer 2 networks.  This would become 1 vlan..  With 1 layer 3 network on it.  So why would you call it 2 different vlans with 2 different vlan tags?? "Once spanning-tree was disabled" That seems like a really bad idea if you ask me…
  • 2.3.2 and LDAP Group Membership

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    It was already covered in the book but I added it a couple places in the wiki just now.
  • Packages leave crumbs when uninstalled

    Locked
    3
    0 Votes
    3 Posts
    795 Views
    M
    Thank you, will do.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.