• Interface does not show if its full duplex?

    10
    0 Votes
    10 Posts
    2k Views
    K
    Thanks cmb and doktornotor appreciate the help something new I learned.
  • MOVED: /usr/local/bin/mail.php is only executed from the console

    Locked
    1
    0 Votes
    1 Posts
    472 Views
    No one has replied
  • Can't access web config pages after SSL

    Locked
    13
    0 Votes
    13 Posts
    5k Views
    L
    OK. I went ahead and copied the backed up config.xml file into the /cf/conf folder, renaming the old one.  I thought worse case, it's a fresh install if this bukes the system completely. After rebooting, it has worked.  Everything is back and working. Scared to touch the SSL certs for a bit now!  Happy to access with the red warning for a bit, until I have the inclination to attempt it again!
  • Slower than expected Download Speed (Changing speed/duplex doesn't help)

    4
    0 Votes
    4 Posts
    696 Views
    P
    Anyone with information on Forum
  • LAN ping spikes

    2
    0 Votes
    2 Posts
    941 Views
    F
    A L2 cache collision in the CPU I dont think will show in the CPU utilisation, nor will any caching done by any nics with onboard processing capabilities like intel nics. Have you tried packet capturing using a separate bridged device between pfsense and your workstation to see whats actually going on with the packets across the network, you can get a better idea of what the packets are really doing then? Might also be useful. http://blog.serverfault.com/2011/03/23/performance-tuning-intel-nics/
  • SG-2440, need VLAN 1003 on LAN for Apple AirPort Extreme Guest network

    13
    0 Votes
    13 Posts
    5k Views
    N
    @jahonix: I don't want to open Pandora's box as far as wireless speeds etc. is concerned … Understood. My statements of performance are based on real world site surveys of my property, using NetSport Pro.  So my numbers are actually tests - not manufacturers spec.  I can share heat maps and documents if you're interested…  ;)
  • VPN client through PFSense not working : where to look at ?

    1
    0 Votes
    1 Posts
    481 Views
    No one has replied
  • Wanting to move back to PFSense

    9
    0 Votes
    9 Posts
    3k Views
    F
    Snort is useful, but I'd also make sure as you dont/cant use vpn's of sorts, is put the devices that need open ports on their own isolated vlan or network interface (optX). This way firmware like for some webcams cant be updated and then be used to start probing and attacking your network from within as the brute force approaches becomes easier if the next hop from the compromised device is just to your firewall and another of your network segments. Also make sure those devices have explicit rules to prevent them from logging into pfsense if on your lan interface, at the very least. If you know that access to these devices is only going to be taking place with ip addresses from a certain provider, like say the ip address blocks assigned to your smart phone provider when you access your webcam, you can also put blocks in places to stop any ip address not assigned to your smart phone provider from accessing your webcam. At the very least pfblockerNG which blocks ip addresses at the country level could be useful if noone overseas is expected to have access. However I will say, as it invariably occurs, if access from abroad is going to take place like for a business trip or holiday, more common in Europe than say the US by virtue of land mass, you can still use pfblockerNG to allow access to those countries. I've done this for customers going on business trips abroad, but always make sure you know if they are taking any connecting flights in a foreign country as they will invariably check email, office cams whilst waiting for the connecting flight so making sure you know the IP address of the airport(s) is useful. This can also be automated with your own apps thats control the pfsense or a simple cron job in some cases depending on how you approach it. Food for thought….
  • Performance Issues

    3
    0 Votes
    3 Posts
    769 Views
    KOMK
    Check the following logs when the problem happens again: System log Gateway log RRD Graphs - Quality
  • 0 Votes
    1 Posts
    326 Views
    No one has replied
  • Crash dumps on embedded/nanobsd

    3
    0 Votes
    3 Posts
    685 Views
    jimpJ
    @Alixy: Are crash dumps saved anywhere on nano?   If yes, how would I access them? No they are not. Saving crash dumps requires swap space and NanoBSD doesn't have swap space (to keep disk writes low). @Alixy: If not, is saving the serial output the only way to see any crash info on nano? Yes that's the only way.
  • L2TP/IPsec not working

    1
    0 Votes
    1 Posts
    887 Views
    No one has replied
  • Interfaces > IPv4 Upstream Gateway

    2
    0 Votes
    2 Posts
    17k Views
    jimpJ
    The gateway on an interface configuration page does a couple things: 1. Tells pfSense to treat that interface as a WAN 2. Defines were traffic exiting that interface should go (usually a WAN/ISP gateway address) If the interface is a WAN/Remote connection, it would be your next hop, typically an ISP address, CPE, upstream router, etc. For local/LAN type connections there would be no gateway specified on the interface.
  • New TCP session rate

    2
    0 Votes
    2 Posts
    804 Views
    jimpJ
    It all depends on hardware, NICs, etc. There isn't any one rate to tell. The only way to know the rate for a given installation is to test it on that hardware with your ruleset.
  • [SOLVED] Search through connected MAC addresses possible?

    5
    0 Votes
    5 Posts
    1k Views
    K
    yes you are right… i didn't test that command thoroughly enough.. thanks again
  • MOVED: [QUESTION] Search through connected MAC addresses possible?

    Locked
    1
    0 Votes
    1 Posts
    340 Views
    No one has replied
  • MOVED: Squid proxy radius TTL not working ?

    Locked
    1
    0 Votes
    1 Posts
    397 Views
    No one has replied
  • Script not working after 2.2.x upgrade

    4
    0 Votes
    4 Posts
    774 Views
    G
    You're right, I did it again and it worked this time. weird. I think it might have been because I left off the #!/bin/sh, don't know.
  • Version 2.2 - CVE-2002-1463

    9
    0 Votes
    9 Posts
    4k Views
    C
    @walbog: From the description of the original poster mike_of: i'm almost certain, it's a nessus-message…. thats why...  ;) Well, that too. ;) Yeah it is Nessus. Not that any other vulnerability scanner is better in that regard, they all seem to report their fair share of absurdity.
  • Assigning multiple WAN IP's to multiple interfaces

    17
    0 Votes
    17 Posts
    5k Views
    D
    MBUF was high because of the Intel Quad NIC. I added kern.ipc.nmbclusters="1000000" to the loader.conf.local file and now the MBUF is down to 2% Thanks for that catch.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.