• Equal bandwidth sharing by all hosts using dummynet

    Locked
    1
    0 Votes
    1 Posts
    889 Views
    No one has replied
  • Problem getting to websites - via NAT Qwest modem

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    R
    Thanks, I will look into that.
  • Existing connections ignore route changes

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    A
    I wonder if my question is not clear, too complex, or really nobody knows. From my testing it seems like NATed connections (only ones I tested) do not obey any routing changes for existing connections.  I wonder if that is one of the reasons for the option below is defaulted to disabled.  To make sure any existing connections are terminated for the wan when routing changes.  WIthout doing that it would appear that packets for states that were already connected before a routing change would still be going to a dead gateway until the TCP times out. There must be a way to make sure packets are routed according to the routing table for already established connections when a route changes. Advanced->Gateway Monitoring - States By default the monitoring process will flush states for a gateway that goes down. This option overrides that behavior by not clearing states for existing connections.
  • Authenticate to multiple backend AD servers

    Locked
    1
    0 Votes
    1 Posts
    854 Views
    No one has replied
  • Problems with RRD Graphs

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    J
    Hm, ok, but this is a remote location with a satellite connection only. Is there any other way of fixing it? Thanks in advance. BR, Jarle
  • MOVED: freeradius question

    Locked
    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Get max performance from fiberlink with Pfsense possible?

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    stephenw10S
    Doesn't actually help provide an explanation either way! The 'ethernet extentions' product is routed via their fibre network, which is presumably shared with other traffic, where as the extensions+ product is swiched ethernet. Plenty of people complaining about virgin media in general though.  ::) Steve
  • Interface bridging

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    There is also http://doc.pfsense.org/index.php/What_is_a_bridged_interface_and_how_would_one_be_used%3F If you clicked the category at the bottom of the link you posted (for "Bridging") that shows up. I just added a "See also" link to the page so it's a little more obvious.
  • SIP phone behind pfSense wall

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    No.
  • Telnet on Pfsense

    Locked
    7
    0 Votes
    7 Posts
    7k Views
    K
    @XIII: @k6usy: To many bots out there trying to crack simple passwords I would rather not have the traffic going to my router. Thats why you use key based SSH authentication, cuts down on the exposure drastically. That works too.
  • Fowarding connections based on subdomain

    Locked
    1
    0 Votes
    1 Posts
    986 Views
    No one has replied
  • PFsense not passing/routing traffic between WAN/LAN

    Locked
    6
    0 Votes
    6 Posts
    22k Views
    S
    Thank you Wallybob for walking me through routing troubleshooting. It was a routing problem all along. I thought the AP was acting as a bridge, but it was actually a DHCP server and didn't know where to forward 192.168.2.0/24 traffic. FACEPALM In my defense, it's my first week on the job…  :P Lessons learned: PFSense does not randomly drop traffic. If you can't reach something because of routing, you do not always get Destination Host Unreachable when pinging. Have faith in the system logs. Thanks, Seanny
  • Setting up Pfsense with C class through ADSL modem

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    E
    If you can get them to route those addresses to a separate static IP in a different subnet (like maybe your existing static IP, for example), you could do this with routing instead of bridging and your DHCP server could directly hand out public IP addresses on the local side.
  • Routing entries - is there any limit? [ANSWERED]

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    The limit would be at what point the XML gets so big it causes performance degradation. That's so high that it's WAY beyond what any sane network would have in static routes, I've seen systems with hundreds of static routes on slow hardware with no impact, could easily do many thousands. Beyond a few hundred you probably aren't routing very optimally, or should be using a dynamic routing protocol. People run the BGP package with multiple full Internet routing table feeds, that's over 350,000 routes in the routing table, and 2-3+ times that in BGP.
  • How to stop downloads from YTD YouTube Downloader software

    Locked
    11
    0 Votes
    11 Posts
    19k Views
    N
    @dreamslacker: @nearones: Can some one guide me how to make rule for mime type in pfsense, i had gon through many docs, but all r on SQUID You don't.  You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well.  That's that.  No buts. Short of actually sniffing traffic and writing your own layer7 patterns to block YTD, you're out of luck. Even so, I believe that YTD, like most download software can spoof normal browser traffic so you would be out of luck there as well. What you have isn't a network policy problem.  It's a system policy problem. If you want to stop YTD, get on the systems and actually amend the GPs to prevent it from installing or running to begin with.  Alternatively, use a software firewall on the system that simply drops traffic originating from the YTD software. You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well. What u said is also the good method to block some other websites like onlinegames, porn websites. But how can i do that in pfsense.
  • Need a little help

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    B
    @SGTR: Hi, For your case you should check out link http://doc.pfsense.org/index.php/FreeRADIUS_2.x_package#Accounting_with_Captive_Portal You might be put your printer different VLAN. You should check your switch conf. or port. Have you done nat rules for your clients ports? What is your nat rules? You can use traffic shapping for this. SGTR Hi SGTR, I fixed everything by just changing my setup a little. It now looks like this: Clients –-- switch ---- pfsense ---- switch ---- router ---- internet                                                     |                                                   server                                                     |                                                   printer This setup also allows me to apply stronger security on our clients. Now the only thing is trying to get daloRadius to read the FreeRadius sql hidden somewhere in pfsense, hope your link can help with that.
  • PPPoE Idle Timeout

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    http://forum.pfsense.org/index.php/topic,47594.0.html
  • PPPoE Disconnects

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    N
    There appears to be a bug in my version of PfSense.  On the WAN interface, set for PPPoE, it does not allow you to save a "0" setting for "Idle timeout."  You can save such a setting if you enter the value via the Setup Wizard, however, editing the WAN page appears to dump the setting.  One can imagine what kind of problems this bug creates. :(
  • MOVED: Basic question

    Locked
    1
    0 Votes
    1 Posts
    689 Views
    No one has replied
  • Firewall syslog logging - who can explain the pf logs?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S
    Thanks for your feedback. If we do change things anyway, it would also make sense to send a hostname or IP address within the syslog header to make it more RFC compliant. Would you like to add that to your feature request?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.