• Rc.conf_mount_rw periodic failures in logs

    3
    0 Votes
    3 Posts
    846 Views
    C
    Thanks for the response. I ran /etc/rc.conf_mount_rw via SSH - it returned successfully very fast. I then ran /etc/rc.conf_mount_ro - it took a few seconds, then also completed successfully (both commands verified by looking at the output from "mount") After the filesystem was mounted read only - I ran fsck -y /cf - and it produced the following result: ** /dev/ufs/cf ** Last Mounted on /cf ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 33 files, 8520 used, 92535 free (39 frags, 11562 blocks, 0.0% fragmentation) ***** FILE SYSTEM IS CLEAN *****
  • PFsense + Radius for authoritzation for VM

    1
    0 Votes
    1 Posts
    522 Views
    No one has replied
  • Unable To Communicate b/w WAN & DMZ

    1
    0 Votes
    1 Posts
    318 Views
    No one has replied
  • How to block VPN Tunneling bypass from Proxy

    2
    0 Votes
    2 Posts
    2k Views
    M
    You could block all outbound traffic from the offenders, then when they complain you remind them of the policy they are violating and you'll unblock when they stop violating.
  • Mystery ping problem - blacklisted IP?

    3
    0 Votes
    3 Posts
    661 Views
    johnpozJ
    Well you should not be natting between 2 lan segments.. So you checked the arp table and pfsense arp table showed correct for the machine you were putting the .40 address on?  Could the .40 ping pfsense interface? I have never had to reboot pfsense because something wasn't working, I have had to clear states for a specific connection sometimes when trying to block something when there was a state already.  Only time had to reboot pfsense was when updating it. So your connections to pfsense from this .40 box is just to switch and then pfsense interface on same switch.  Your just doing dumb switch or do you have vlans setup, etc. etc.
  • Slow download/upload speeds behind Firebox/Pfsense

    5
    0 Votes
    5 Posts
    2k Views
    J
    Ah dang,  yep didnt catch that…...thanks for pointing it out!
  • VPN setup behind firewall with a bridged pfsense box

    3
    0 Votes
    3 Posts
    711 Views
    D
    I use the pfSense box to run captive portal and a seperate vlan for wireless network.  I also use it just to monitor bandwidth and get stats.  I want to keep the Comcast box as the lans main dhcp server/gateway for now.  That will change down the road but at the moment I'm not ready to make that switch.
  • 0 Votes
    1 Posts
    341 Views
    No one has replied
  • Setup pfSense Schedule recurrently, How?

    4
    0 Votes
    4 Posts
    943 Views
    D
    @pfcode: But they are tied to the Month (e.g. September_15), which isn't what I want,  aren't they? No, they are not (also, read the notes there) - it's just the GUI calendar being completely confusing
  • Wake-On-LAN Broke?

    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Monitor Badwidth consuption

    3
    0 Votes
    3 Posts
    770 Views
    H
    @tobiascapin: Sorry… https://doc.pfsense.org/index.php/How_can_I_monitor_bandwidth_usage You're doing better than most people who ask questions.
  • New pfSense Installation (reassurance needed)

    8
    0 Votes
    8 Posts
    1k Views
    H
    We have a $250,000 high end firewall that is loaded with bugs and limitations and could be easily replaced with $10k of machines and some opensource software that many companies use. Instead of learning the underling issues, "admins" resort to pre-configured systems that are really expensive, and if the system doesn't have a check-box for a certain situation, not much you can do.
  • Exempt NAT

    2
    0 Votes
    2 Posts
    781 Views
    jimpJ
    Can you explain more about what exactly you're trying to do? Port forwards have a "No RDR", and a "Not" flag for the destination… Outbound NAT rules have a "Do not NAT" option and "Not" on the destination. If you're looking to exclude certain things from NAT, usually those are not necessary even. If you can describe the scenario with more detail then perhaps we can help figure out a solution.
  • Slow connection with CAT6

    12
    0 Votes
    12 Posts
    2k Views
    johnpozJ
    yeah a cable tester is good tool for the belt for anyone that deals with cabling be it you make your own or buy predone, etc. Simple testers can be as cheap as <$50 for sure.. Now if you want a fancy specification validation tool you can get into the 1000's so kind of out of the realm of home user diyer ;) The cheap ones won't point out issues in quality of the cable but will real quick tell you if wiring is wrong, shorts/opens, etc.  So nice tool to check a cable before you put it into use, etc.  And that you crimped them correctly, etc.
  • Pfsense as firewall good or not good?

    8
    0 Votes
    8 Posts
    4k Views
    M
    http://wiki.mikrotik.com/wiki/Manual:RouterOS_features https://www.pfsense.org/about-pfsense/features.html
  • 0 Votes
    3 Posts
    875 Views
    T
    @SoonerLater: After some hours of reading the Wiki, I still have some pre-sales questions. I am considering buying a SG-2220 to replace my existing Wal-Mart quality Linksys router. Q. - Can I create complex access schedules under pfSense which restrict certain MAC and/or IP addresses from (1) all network and internet access, (2) all internet access, (3) filtered internet access?  Sometimes I don't want my kids (teenagers) to be able to access anything outside their own computer (no local network and no internet). Sometimes I just want to limit their access (e.g. Wikipedia is OK; Blood Guts and Gore Gaming is not). Yes.  It's not easy and will be a lot of work, but it can be done. Content filtering can be done with a package or something else like OpenDNS for example.  Both require configurations. Q. - Can I create schedules which start one day and end another? One would think this is obvious, but on my existing cheapie router, I can't have a schedule that runs from 10pm to 6am, because the moronic interface on my router can't figure out that I mean 6am the next day. Yes, see the Schedule screen shot enclosed. Q. - After programming pfSense with my schedules, can I create simple toggles that my wife, who is even less tech than I am, can login to toggle on or off restrictions for certain MAC and/or IP addresses? No.  Schedules are time-based firewall rules.  You would need to modify those rules in the pfSense interface.  So there would be some navigation, identification of the appropriate rule, and enabling/disabling that rule.  Since you seem to have complex schedules, there will be quite a few rules. Q. - Can I setup the DHCP service so that certain MAC addresses are always denied a lease? I like to setup my router so that everything that is normally on my network has a reserved address. The only devices to get DHCP leases should be guests, and I want to be able to easily toggle DHCP service on and off. Yes, but it might be easier to use Captive Portal instead.  You can exempt your devices from using captive portal by MAC, and those that you want to allow access onto the network would need to go through the captive portal. Q. - Can I setup logging for specific MAC and/or IP addresses which logs all addresses that devices visits and when? When you're used to spending <$100 for a router, spending $300 is a big step up. No doubt that pfSense is incredibly robust, but after much research, I still can't determine whether I can program it to keep my kids from wasting hours in the middle of the night playing games and surfing the web. No.  There may be a package that does this, but none that I've used.  pfSense is a firewall/router, not a networking monitoring appliance.  I think E2guardian might do this, but I'm not sure.  It's a package that is awaiting approval, so you'd need to install it on your own in the meantime.
  • Memory Usage

    12
    0 Votes
    12 Posts
    2k Views
    KOMK
    Yes, I know but users usually tune this particular option so it's what I check first.  It still shouldn't be a problem if he has used the default 16x256 cache structure.
  • WAN is Gateway?

    4
    0 Votes
    4 Posts
    912 Views
    KOMK
    If you're assigning an IP via DHCP then you don't need to specify anything.
  • What are thes errors?

    13
    0 Votes
    13 Posts
    5k Views
    F
    @packetsTObananas: I know this thread is old, but changing the default value under  System - Advanced - Networking - Firewall/NAT - Firewall Maximum Table Entries to 1,000,000 worked for me.  8) Happy my n00b topic could help haha  ::)
  • MOVED: blacklist issue

    Locked
    1
    0 Votes
    1 Posts
    367 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.