• Squid User Access Report - alternative interface?

    6
    0 Votes
    6 Posts
    1k Views
    KOMK
    Lightsquid generates reports based on squid's access.log. It's a package.  Install it.
  • PFSense Box locking up.

    1
    0 Votes
    1 Posts
    657 Views
    No one has replied
  • Doesn’t start properly

    3
    0 Votes
    3 Posts
    2k Views
    H
    Thank you very much. It showed that the mongod was hanging. It’s part of the UniFi controller running on my pfSense as well. Until now there was no problem with that. Now ipsec is running but no IPv6 traffic. Any further advice?
  • How to add new Internet Provider on exisiting Linux Unit

    1
    0 Votes
    1 Posts
    442 Views
    No one has replied
  • Changes Do Not Take Effect

    Locked
    2
    0 Votes
    2 Posts
    744 Views
    S
    This issue has been resolved. So it looks like the upgrade of pfsense from 2.2 series to 2.3 series changes how they handle group permissions. One of the things that happens is that the Router Admins group that is used for active directory integration sets a “permission” of “User - Config: Deny Config Write” which says in the description, “If present, ignores requests from this user to write config.xml.” You can fix this by logging in as admin and removing that permission setting from the router admins group.
  • Failed to limit the p2p download bandwith

    2
    0 Votes
    2 Posts
    527 Views
    H
    You're using limiters, not actual interface shaping. I have no experience with limiters, but a common issue is the IP mask used. You may be creating a limiter PER CONNECTION. If you want to shape the entire interface, use shaping, not limiters.
  • Pfsense crashing after upgrade to 2.3.1

    2
    0 Votes
    2 Posts
    860 Views
    jimpJ
    I haven't seen that one before, but it would appear at a glance to be crashing in handling of SCTP on IPv6. Are you actually using anything like that or allowing it through the firewall?
  • Group ACL

    1
    0 Votes
    1 Posts
    591 Views
    No one has replied
  • Setting changes for Better Security

    7
    0 Votes
    7 Posts
    2k Views
    K
    Controlling outgoing traffic with just firewall rules is really hard because of the multitude of TCP/UDP ports used for different applications and many of them are not officially allocated. The worst are filesharing applications such as BitTorrent that can use almost any port imaginable. You're much better off using a proxy with whitelist/blacklist techniques if you want to control outbound.
  • 2.3.1 monitoring options

    6
    0 Votes
    6 Posts
    1k Views
    R
    Thank you for your help.
  • VLAN Weirdness

    1
    0 Votes
    1 Posts
    528 Views
    No one has replied
  • New to pfSense!

    9
    0 Votes
    9 Posts
    2k Views
    KOMK
    For a new user I would recommend keeping it simple and organizing your rules per interface.  Leave the floating rules for traffic shaping.
  • State Timeout

    3
    0 Votes
    3 Posts
    1k Views
    M
    @heper: You can set a timeout for a single firewall rule (advanced section when editing) Thnx i found it, dint know that option was there, the limit is 3600 seconds.
  • Re-Upload the .gz link to a REAAAAL iso file :)

    2
    0 Votes
    2 Posts
    650 Views
    johnpozJ
    that is a link to the iso, its have been gzipped, just un gzip is.. And then you have the iso file. http://www.gzip.org/
  • Throughput Issue

    10
    0 Votes
    10 Posts
    5k Views
    N
    hey thank you for your reply, very interesting, I am now consistently seeing my line speed again 900mbps with a clean signal graph on the speedtest, I have attatched the top output now when at around 870mbps let me know if you think there is something that looks wrong still thank you so much for assisting me XD [image: topoutput.jpg] [image: topoutput.jpg_thumb]
  • Packet loss when upload

    5
    0 Votes
    5 Posts
    2k Views
    H
    It's possible your performance has actually improved. Bufferbloated networks have this peculiar characteristic that sometimes being faster makes you slower. If your ISP or drop box service has suddenly increased in performance, you may be pushing up against your max bandwidth, which can trigger many issues with bufferbloat, like high pings times and packetloss. Like kpa mentioned, give traffic shaping a try. Even something as simple as enabling Codel and setting your upload bandwidth may be enough. Very easy. It may be something else, but give the easy fixes a chance.
  • Performance issue

    9
    0 Votes
    9 Posts
    3k Views
    johnpozJ
    "even a full duplex link can handle this easily." Still bad design plan and simple… No hairpin is not a "NAT" term.. Yes you can hairpin with NAT, ie NAT "reflection".  The term hairpin means in and out same interface.. And it should be avoided if possible.  When you have multiple vlans on the same physical interface and vlan A talks to vlan B this is a hairpin, and not best for performance.  If possible if you have vlans that send a lot of traffic to each other, these vlans should be on different physical interfaces at the device making the routing decision. You say your windows machine is fast, the way you drew it - looks to be coming in different path than the interface you have your vti on?  Is that the case?  Again you state this is hosted on VM, what interface in vm are physical in the drawing what are virtual? This is esxi, where is your vmkern?  Same interface?
  • Slave Server Crash when using Traffic Shaper: Limiter

    1
    0 Votes
    1 Posts
    436 Views
    No one has replied
  • Huawei LTE usb stick non hilink (partial working)

    3
    0 Votes
    3 Posts
    2k Views
    K
    Did you get this working in all situations? What happens when the network connection fails? Does the WAN interface go down or does pfSense still think it's connected? Does it reconnect automatically or must you send the AT commands again? If so, have you automated the reconnection? It is also possible to enable legacy PPP mode for this model: http://blog.asiantuntijakaveri.fi/2015/07/convert-huawei-e3372h-153-from.html
  • /var/run running out of space

    3
    0 Votes
    3 Posts
    1k Views
    K
    Thanks Jorge!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.