• PFSense - Kernel Panic on 2.0.3 - Redundant Firewalls

    3
    0 Votes
    3 Posts
    1k Views
    D
    Looks like I have the double-whammy with both igb interfaces (Intel expansion slot) as well as Broadcom on board. Thanks for the quick response, I'll deploy this on the two firewalls I'm building for the local office. I'll definitely let you know if this fixes the issue. Thanks
  • SD Card encryption

    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    We don't officially have any support for disk encryption, but FreeBSD does. It does require manually entering the password, otherwise as doktornotor said it would be pretty worthless. You can have security, or you can have convenience, you can almost never have both. http://www.freebsd.org/doc/en/books/handbook/disks-encrypting.html You need an unencrypted section of the disk in addition to the encrypted section (or two separate disks), I don't believe it supports booting from an encrypted disk for some obvious reasons. If you're that worried about someone stealing the CF, then you either need to not keep such sensitive data on it, or invest in some good physical security measures to keep it physically safe and locked up.
  • XMLRPC sync without CARP/pfsync

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    Sure, XMLRPC works with or without CARP. Some people use it just to sync aliases and such.
  • Bandwidth test = fine, browsing = impossible

    2
    0 Votes
    2 Posts
    913 Views
    S
    I should note that this is 2.1 because of RADIUS/IPSec
  • A new vulnerability was discovered in Haproxy !!!

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    The haproxy package on pfSense 2.x is already on 1.4.24. Just reinstall the package and you'll be OK.
  • Routing of the public ip to the switch in pfsense.

    6
    0 Votes
    6 Posts
    2k Views
    M
    Or I use the option virtual ips? http://doc.pfsense.org/index.php/What_are_Virtual_IP_Addresses%3F
  • Pfsense vs firewalls ??

    2
    0 Votes
    2 Posts
    804 Views
    stephenw10S
    Like this? http://doc.pfsense.org/index.php/Comparison_to_Commercial_Alternatives Steve
  • Inactive Memory problems

    9
    0 Votes
    9 Posts
    4k Views
    A
    @wallabybob: This is the sort of symptom you would see if mbufs (kernel network buffers) are (nearly) exhausted. pfSense shell command``` netstat -m reports mbuf statistics. It could be worth running a shell script on the console to loop giving a timestamp, reporting the statistics and sleeping for an hour. You could also run that in a SSH session to capture history while the console run will (hopefully) give you statistics after you lose network access. I wish mbuf counts were on an rrd graph in pfsense.  It is such an important thing to keep an eye out for.  It would be great to see the history of that over time. Thinking about it… It would be great if we could get a consensus on some very important things to monitor like this and get a script going to send an email alert when the values are approaching the maximum values.
  • Monitor (RRD) of external device (cable modem)

    1
    0 Votes
    1 Posts
    975 Views
    No one has replied
  • Migrating from smoothwall to pfsense.

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Unexplained Excess Traffic on WAN

    9
    0 Votes
    9 Posts
    4k Views
    D
    Sounds like you somehow created open proxy…
  • Failed to mount pppoe with my ISP on Pfsense 2.0.2 or 2.0.3

    6
    0 Votes
    6 Posts
    2k Views
    L
    Hi, just for information, my provider has changed is radius configuration. I obtain tha gateway and the dns. thanks for all
  • Adding a second NIC - Issue

    11
    0 Votes
    11 Posts
    3k Views
    K
    What does the pfsense status say about all of your interfaces on the main page? UP? down? Red?  Green? Also, in the drop down menu, for MAC addresses in your interfaces > assign, for the OPT1, what is the MAC?  How many choices for MACS are there?  If you count all the possible MACS is it , less, the same, more than interfaces on your system?  Are the macs you assigned to each interface different?  (not even sure if its possible to assign 1 MAC to 2 interfaces, but I'm wondering) And is 255.255.0.0 a typo?
  • Multi-pppoe server not working

    3
    0 Votes
    3 Posts
    8k Views
    C
    Try use different IP on different Server from any router
  • How to set user time out on SSH sessions?

    10
    0 Votes
    10 Posts
    2k Views
    D
    Thanks for that - I'll remember to log out from now on!
  • How to assign Virtual IP for outbound to LAN Device?

    20
    0 Votes
    20 Posts
    5k Views
    jimpJ
    The reset button is only probed during boot. If you press and hold the reset button while it's booting, it will reset to factory defaults. As doktornotor mentioned you can hijack that to replace the default config with your own, but then you could never actually do a true factory reset again (until you do a firmware upgrade and that default config goes back to a stock version)
  • PFSense - Reboot Randomly

    7
    0 Votes
    7 Posts
    2k Views
    W
    Thanks wallabybob… Shows different than acd0 in VMWare but makes sense, will be trying that, will let you know how it works. Thanks for everyones responses!!!
  • Blocking Access to Certain Web Sites for Certain Users?

    2
    0 Votes
    2 Posts
    4k Views
    K
    Dansguardian will probably serve you well andf you will get AV scanning to boot. http://forum.pfsense.org/index.php?topic=42664.0 pay attention to the section on HTTPS and forwarding to 8080 This is a more recent write up: http://thegeekninja.wordpress.com/2013/07/02/pfsense-squid3-and-dansguardian-a-better-alternative-to-squidguard/ I would stick with the stable release of squid rather than use the squid3 beta. Dansguardian is a package now so you can add it directly from package and no listing of commands is needed. Go into the ACL (access control list) Disable all the filters you don't want Make sure URL list is enabled. Edit the regexp in the banned section just adding the url of things you don't want people to see. like youtube.com       facebook.com       whyisuckattyping.com    or whatever. It will be easier to make a firewall rule for you if you make an alias including all the machines you wish to filter. For me, I disable all the filters except url and antivirus scan.
  • PfSense Firewall Schedules and Active Firewall States

    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    Scheduled rules go under a label in pf for that schedule. When the time comes, only states labeled for that schedule are killed.
  • Access remote database via portal

    2
    0 Votes
    2 Posts
    1k Views
    F
    mysql server not run, so you can't connect. My problem is same, if open shell in pfsense and write this in console "service mysql-server onestart" if you install mysql-serverxxx packet it will start and connect.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.