• What causes this in the logs?

    6
    0 Votes
    6 Posts
    1k Views
    J
    Yes, I can always remove the team. However now I'm curious because I have a NAS that has an adaptive load balanced nic team with 2 nics. No log entries from that nic team - however that is running Linux. This machine has windows. Interesting…. Thanks for the help! :-)
  • PfSense is not a switch?

    5
    0 Votes
    5 Posts
    1k Views
    C
    @johnpoz: If you bridged 4 ports together you would have a "HUB".. Since all packets seen on 1 port would go out all the other ports.. This is how a bridge works.. Not true with our bridges, they learn MACs the same as a switch and send traffic accordingly just like a switch. The "use an actual switch" mentality is largely for performance reasons. People tend to show up wanting to use some Pentium III they pulled from a dumpster with a handful of crap Realtek NICs shoved in it then wonder why they can't push a gigabit of traffic between internal hosts. Firewalls aren't switches. In some limited circumstances, where you don't care about performance between internal hosts much, and require filtering between every internal host, it's a fine idea. People just tend to expect it to work the same way as the switch built into their consumer router, and it's not the same at all. Huge diff between multiple NICs in a firewall or router and a switch.
  • How to block config page over WAN!!! BIGGG issue!!

    15
    0 Votes
    15 Posts
    3k Views
    H
    @kiyu: …as I mention I have no idea about it.. ... State your hardware, draw a logistical network diagram. Write an operational specification for the flows. Prepare to rewrite the pfSense config. Meanwhile temporary you have to block all WAN's ingress to (22,80,443) or do at least [System: Advanced: Admin Access (TCP port)] not on 80 or 443 as doktornotor said already.
  • MOVED: pfsense 2.1.5 block windos update

    Locked
    1
    0 Votes
    1 Posts
    439 Views
    No one has replied
  • How to deny access of facebook

    7
    0 Votes
    7 Posts
    2k Views
    BBcan177B
    You can actually do both… In Unbound or dnsmasq, create a Domain override. Also use pfBlockerNG to download the most recent IPs automatically daily/weekly as required. Hurricane Electric is a great source to collect IPs for almost any site.
  • Pkg add and update

    4
    0 Votes
    4 Posts
    1k Views
    C
    You must be on nano version judging by that, or else have /var/ enabled as a RAM disk. You can't run MySQL on nano or where /var is a RAM disk. Running MySQL on the firewall at all is probably a bad idea too, better to keep server roles on servers.
  • Alias to the WAN ip

    6
    0 Votes
    6 Posts
    2k Views
    DerelictD
    I don't think so. A roundabout way might be to set an alias to an FQDN and set the FQDN to a hostname dynamically updated by dyndns on WAN.  That probably won't reflect changes fast enough. Are you configuring Services > Load Balancer > Virtual Servers?  I can't think of an effective way to use a dynamic address there.  Depends on how quickly you need it to update. I looked in /tmp/rules.debug and everywhere that references WAN address has been replaced by the actual IP address, not an alias to it.
  • Slow tranfer data

    2
    0 Votes
    2 Posts
    709 Views
    johnpozJ
    you could search for xenserver here - you will find lots of info about issues with xenserver example https://forum.pfsense.org/index.php?topic=85797.0 Like first hit searching xenserver pfsense on google.
  • MOVED: How to restart pptp service?

    Locked
    1
    0 Votes
    1 Posts
    478 Views
    No one has replied
  • How to configure PFSense to use my own local DNS

    11
    0 Votes
    11 Posts
    7k Views
    R
    What I've done on my network is configure DHCP to supply the pfSense system as the primary DNS (and my local servers as secondary and tertiary in case pfSense system is down).  Then on pfSense I set DNS Resolver (Unbound) to forward DNS requests for my local domain to my DNS servers.  Its not exactly what you asked but I think it accomplishes the same goals.  Plus it allows pfSense to act as a cache and it knows the upstream (ISP) DNS servers.
  • MOVED: Ayuda Soy nuevo en pfsense y o encuentro la puerta

    Locked
    1
    0 Votes
    1 Posts
    406 Views
    No one has replied
  • Pfsense keyword filtering

    11
    0 Votes
    11 Posts
    5k Views
    N
    @jatgm1: im tired of hearing pathetic morons talk about a childerens game. Then stop hanging around with pathetic morons. If that is not a possibility then get some ear plugs. @jatgm1: if you want to play it whatever, but its installed on the computer and we have the xbox game theres no reason he should need to watch god damn videos that some sad saps made. Who is "we"? Who is "he"?
  • User level control and filtering?

    1
    0 Votes
    1 Posts
    418 Views
    No one has replied
  • Router on a stick problems: Double Bandwidth and OpenVPN chokes

    6
    0 Votes
    6 Posts
    2k Views
    N
    Since this thread is still the top result on searching for double wan bandwidth, I'm posting another pic from my 2.2.2 64bit system. It appears that this problem has been re-identified… but just for posterity and clarity, see the attached pic. ![double traffic.png](/public/imported_attachments/1/double traffic.png) ![double traffic.png_thumb](/public/imported_attachments/1/double traffic.png_thumb)
  • DNS Black Hole

    24
    0 Votes
    24 Posts
    3k Views
    DerelictD
    This is all moot anyway.  No matter what you do with DNS if the client web browser is asking for an https connection and the captive portal gets in the middle, a certificate error must be displayed. We, as IP networking professionals, should never, ever, EVER implement anything that, by design, will present certificate errors to users.  Connections to https sites before captive portal is negotiated should simply hang.  Don't like it?  Don't use a captive portal.
  • 0 Votes
    1 Posts
    354 Views
    No one has replied
  • PFsense limiting bandwidth (causing slowness)

    4
    0 Votes
    4 Posts
    1k Views
    H
    Have you done an iperf to, from, and through PFSense? You want to make sure it works as expected in an ideal case before trying to hunt down issues in unideal cases. In all issues in life, when debugging problems, eliminate as many variables as possible.
  • High CPU load help

    7
    0 Votes
    7 Posts
    2k Views
    F
    Oh, thanks for clarifying everyone.  Appreciate the feedback.
  • How to bring interface up from pfsense commandline?

    7
    0 Votes
    7 Posts
    26k Views
    E
    I have modified Steve's solution as follows and it works on [2.2.2-RELEASE]: /etc/rc.linkup interface=opt1 action=start Matt
  • Splunk, pfSense and Home Monitor

    7
    0 Votes
    7 Posts
    5k Views
    B
    If you are using pfSense 2.2.2 the log format is very different from what is was when that blog was posted. Have you installed version 2.0.2 of the the TA-pfsense Splunk add-on?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.