• Newbie question re security

    3
    0 Votes
    3 Posts
    1k Views
    Z
    I am currently using VOIP.  It is set up on my LAN behind my (off the shelf) D-link router.  As far as I know, nobody has has invaded my network - this was more of a theoretical question, as I pondered whether there might be a security vulnerability in my network (i.e. could someone take over my VOIP device and use it to launch an attack on other devices in my LAN?).  Would it be considered best practice to run the VOIP on its own vlan or is that overkill? And also for open VPN - this was also theoretical - how difficult would it be for someone to penetrate through that hole if I used 2048 or 4096 bit keys, and combined it with user authentication?
  • Random internet outages - cable modem, pfSense or both to blame?

    5
    0 Votes
    5 Posts
    1k Views
    B
    Thanks. I'll keep an eye on internet connection.
  • 0 Votes
    4 Posts
    2k Views
    O
    =changed OS to 2.2.4 and it works =replaced the ssd and it works with 2.2.6 as well
  • PfSense as L2TP client to ISP - not working

    1
    0 Votes
    1 Posts
    803 Views
    No one has replied
  • Slow upload

    4
    0 Votes
    4 Posts
    1k Views
    U
    ok that did not seem to matter I set the MTU to 1470 and no difference. I even ran ifconfig and the settings did change to 1470 in there. Does the hard drive affect the throughput on the network cards? I have another PC in the shed I might drag it out and test that. See if it produces the same results, I had another 3 NIC brand new as well in the shed will try them also but this board only has 1 PCI slot why I had to go with a seperate dual port intel card for it lol
  • /var in ram =>lightsquid lost on reboot

    3
    0 Votes
    3 Posts
    865 Views
    P
    OK, thanks jimp. I'll have to change path for these logs.
  • WAN failing to properly reconnect after ISP issues

    8
    0 Votes
    8 Posts
    2k Views
    U
    you should be able to replicate a outage by unplugging the cable from your modem, The one that comes from the wall socket. I wouldnt pull out the cable between the modem and PFsense as it could be a miss match in communication from the modem and router. As I say mine works fine on the default autoselect (one at the very top) but not when its just plain autoselect. But if you know what it always uses then setting it manually like you have should work. Just run some test to make sure it is not affecting performance.
  • Crash - kern.ipc.nmbufs limit reached

    3
    0 Votes
    3 Posts
    1k Views
    H
    Increase mbufs. See nic tuning on the wiki
  • Ping time greater than 1ms from PC to router?

    5
    0 Votes
    5 Posts
    4k Views
    H
    Ping doesn't actually measure network latency, it measure's network latency plus the network stack of the host OS. It's very possible you're just seeing network scheduling fluctuations.
  • Resolver Issue with iPhone6s

    1
    0 Votes
    1 Posts
    517 Views
    No one has replied
  • Listen queue overflow

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Pfsense instead of CyberRoam for community home please advice

    1
    0 Votes
    1 Posts
    484 Views
    No one has replied
  • Pfsense reporting and auditing

    5
    0 Votes
    5 Posts
    2k Views
    M
    @lovene: I need to audit all firewall activity but cannot achieve this. I need to print audit reports of all changes. Exactly what do you mean by "all firewall activity"?  All packets in and out, blocked packets, passed packets?  Logins?  File changes? "All" has the potential to cover a lot of ground, specific help requires specificity of what you are trying to accomplish.
  • VoIP problems when PPPoE reconnects

    1
    0 Votes
    1 Posts
    525 Views
    No one has replied
  • Slow bandwidth high CPU consumption

    5
    0 Votes
    5 Posts
    1k Views
    M
    whats the output of ifconfig -a?  Is your WAN interface at the correct speed and duplex?  What did you do with "traffic shaping"?
  • Swap usage with 16gb of RAM o.O

    5
    0 Votes
    5 Posts
    2k Views
    H
    I see squid running. I bet you had a memory spike once or more that caused some pages to get swapped out, but those pages have yet to be referenced again and just stay in limbo until the next time they are needed. Also, you don't need to reach 100% memory usage to get paging. Memory gets fragmented and if there are no large enough contiguous segments, the kernel may need to swap out pages to effectively defrag the memory.
  • What is best way to run 300 VLAN on network using PFSense.

    21
    0 Votes
    21 Posts
    5k Views
    G
    @Derelict: pfSense will do multiple scopes just fine. It just can't be configured to accept helper requests from multiple subnets on one interface. Well that's just silly.
  • SPI with pfSense?

    3
    0 Votes
    3 Posts
    5k Views
    johnpozJ
    your typical off the shelf router is a firewall as well, it just has limited features in allowing configuration of the rules.  Many of them have very limited outbound controls, and inbound are all pretty much just port forwards with varying degrees of features depending on the make and model. But in a nutshell out of the box pfsense is same as any off the shelf home router in what it does.  It nats, all inbound traffic that is not direct answer to a request is blocked, while the default outbound rules from lan are any any.  This is pretty much what every off the shelf router does. Where pfsense allows you to go way beyond what any off the shelf router would allow you to do when you want to get fancier than that.  But if you want to use it like that - that is pretty much how it is out of the box. And yes you could even enable UPnP if you want it..  Where your off the self router is normally just an on and off checkbox, pfsense allows you to get fancier with allows and deny specific ports or deny from all except a specific IP to request, etc..
  • IPV6 question

    5
    0 Votes
    5 Posts
    1k Views
    KOMK
    BTW, there is a dedicated IPv6 forum.
  • Connect Router to Internet

    6
    0 Votes
    6 Posts
    2k Views
    A
    Please can someone give me a hand on this one?????
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.