• PfSense becomes unresponsive occasionally (Alix 2d13, pfSense 2.2.2)

    7
    0 Votes
    7 Posts
    1k Views
    -flo- 0-
    I have a traffic shaping in place but not on a WLAN. My Alix has only the built in LAN ports. I increased the maximum limit of mbufs now. I have observed an absolute stable and very low amount of mbufs allocated at all times (in the RRD graphs). I'm not expert enough to understand which facts have an influence on used mbufs so it's difficult for me to trace an increase down to specific behavior of hosts in the network. Because the RRD graphs stop to display data on midnight before a crash of my pfSense I did not observe the amount of used mbufs shortly before a crash yet. I changed the RRD backup cycle to one hour now. Maybe the next time I can actually see an increase of used mbufs in the RRD graphs (if this does not occur only within minutes before a crash). Are there know typical scenarios which cause used mbufs to increase dramatically? I rather suspect that something else is eating up memory which has been reserved for mbufs. In other words something else / another process has higher priority when requesting memory than the network processes / the mbufs reservation. Is this possible at all in FreeBSD? -flo-
  • MOVED: squid and squidguard are running but not working

    Locked
    1
    0 Votes
    1 Posts
    429 Views
    No one has replied
  • How do you automate pFsense Changes?

    8
    0 Votes
    8 Posts
    3k Views
    F
    @three18ti: I just added 10 host DNS overrides entries and it was PAINFUL!  Copy the host name, copy the domain, copy the IP, submit, wait for the page to load, scroll to the bottom of the page, click the plus button, wait for the page to reload, repeat. It easily took me 30 mins to add those ten entries.  I have a few dozen more to do tomorrow.  (And that's not even mentioning the stuff we want to do with VMware which will require automatic updates without human intervention). Apparently there is not going to be an API…[1] So, pFsense gurus, how do you automate firewall changes?  Any awesome Chef recipes?  Or should we be looking at a paid Cisco product if we need automation? Thanks for any advice! [1]  https://forum.pfsense.org/index.php?topic=76587.0 Have you tried the "Advanced" menu?  For example: bogus-nxdomain=198.105.244.24 bogus-nxdomain=198.105.254.24 address=/examplez.com/127.0.0.1 The Advanced menu for dnsmasq here is over 1100 lines long.  running ps -Aww isn't pretty, but it works nicely from the first domain to the last!
  • Symmetrical Pipe and poor Upload speed

    8
    0 Votes
    8 Posts
    1k Views
    johnpozJ
    The configurations options in squid are vast…  Just my opinion but not really a fan of running a proxy on my actual firewall.. If you require a proxy then I would do that on its own setup..  If you have a firewall in front of pfsense - why don't you just setup a squid box?  Seems odd to me to run pfsense just to get squid going, since squid is a addon package to pfsense and provided more as convenience..  I would move your question to the squid forums or the package section this forum. Do you have any delay pools setup in squid? http://wiki.squid-cache.org/Features/DelayPools?highlight=%28delay_pools%29 This is normally how you would limit speeds.. Out of curiosity why do you "need" squid or a proxy in general?
  • MOVED: Upload limit not working

    Locked
    1
    0 Votes
    1 Posts
    348 Views
    No one has replied
  • 2 Switches in a row Speedtests are slower and Internet feels clumsy

    6
    0 Votes
    6 Posts
    1k Views
    dennypageD
    @johnpoz: gs108e is NOT a layer 3 switch - not by a freaking LONG shot!!!  Its a barely not dumb switch, lets call it a mentally challenged switch because smart would not be the word I would used and retarded is not really PC ;) Okay, I'm not going to lie. This seriously made me laugh out loud.
  • Need to span a vlan present on one interface to another

    2
    0 Votes
    2 Posts
    476 Views
    C
    Bridge the VLAN to the other NIC.
  • Please HELP

    7
    0 Votes
    7 Posts
    2k Views
    V
    This could be a nice one to have a watch too as you are totally new to pfSense:- A 50mins video with pfSense 2.2.2 firewall setup and features overview. https://youtu.be/dfix8WsNSHc
  • MOVED: Issue with pfsense/vmware/vlans

    Locked
    1
    0 Votes
    1 Posts
    477 Views
    No one has replied
  • What is the best way to set this up?

    3
    0 Votes
    3 Posts
    686 Views
    T
    You already have the most optimal setup. What's wrong with having the wireless AP connected to the switch? What cable modem do you have? Some Hitron models have been known to have major problem connecting to 100Mbit NICs.
  • Leap second

    10
    0 Votes
    10 Posts
    3k Views
    H
    NTPD RRD shows an average of 0.14ms offset and a maximum 0.4ms offset over the past 24 hours.
  • Alias URL Table Delete Not Complete

    1
    0 Votes
    1 Posts
    534 Views
    No one has replied
  • PPPoE over VLAN

    7
    0 Votes
    7 Posts
    1k Views
    B
    Hi neo243, wow that is exactly what fixed it! I constantly had to chose between VLAN6 or PPPoE on my interface but this has enabled me to do both! Thanks everyone for all your efforts! Grt Bram
  • Motherboard swap questions

    8
    0 Votes
    8 Posts
    2k Views
    S
    OK - so Scythe sent me another set of brackets, install is now complete and working fine.  So, for anybody wanting to do a motherboard swap, I can confirm that, in my case at least, everything went just fine.  I did end up keeping my NC360T card and hooking up my WAN/LAN wires to the exact same ports (keeping the motherboard's NICs for future expansion or what not), but pfSense just fired up as if nothing had happened. Two questions, though : 1.  I used to see the CPU temp in the dashboard, with my AMD CPU.  I don't anymore with the X3430.  Is there a reason for this?  Can I restore it? 2.  Is there such a thing as ipmitool in pfsense?  My searches seem to indicate there is, but a simple command to reset the IPMI password, which worked fine on FreeNAS (ipmitool -I open user set password 2 ADMIN, to reset to the default "ADMIN" for example) didn't work in pfSense - device not found or some such.  I didn't try modifying fan parameters with ipmitool, just figured I'd ask you guys first. Totally unrelated : anybody else seeing arpwatch as a red "X" on the dashboard ever since update to 2.2.3? Cheers!
  • User Assigned Privileges Question

    2
    0 Votes
    2 Posts
    812 Views
    jimpJ
    Are you certain the user is being put into the correct group? I can't think of any reason why that privilege wouldn't work from LDAP unless the user wasn't actually being detected as a member of the group that included the privilege.
  • Very basic question

    2
    0 Votes
    2 Posts
    608 Views
    KOMK
    Incoming traffic on WAN is blocked by default.  LAN is wide open.  Any extra interfaces like OPT1 will have to have at least one rule added to allow access out. https://doc.pfsense.org/index.php/Main_Page
  • Traffic Graph remote vs local

    1
    0 Votes
    1 Posts
    680 Views
    No one has replied
  • Issue

    2
    0 Votes
    2 Posts
    529 Views
    D
    Huh… No, restarting webserver does no network damage.  :o
  • Routing and pfsense

    4
    0 Votes
    4 Posts
    981 Views
    D
    Ipsec may be a more hopeful possibility with the TZ210. You might post a question in the IPSEC forum about creating a connection with Sonicwall. I would like to just install openvpn on the phone and PC but, she still needs access To other network resources. If you create a RoadWarrior setup and install the client on your wife's PC she can have access to anything at work and at home as necessary. One useful piece of information - the TZ210 is now EOL as of 2015-06-01. Might be another reason to switch to a better supported firewall (hint hint).
  • Alias URL Table Domain Case Sensitivity w/HTTPS

    3
    0 Votes
    3 Posts
    818 Views
    N
    Except that https works fine with some mixed case domain names.  Such as https://www.Team-CYMRU.org/Services/Bogons/fullbogons-ipv4.txt for instance.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.