• Newb alert: Can I run 2 pfsense firewalls

    3
    0 Votes
    3 Posts
    961 Views
    S
    OK. Gotcha. Thank you. I look into it
  • Bridge across LAN ports

    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S
    It's been answered plenty of times, the OP has done it correctly here. If you bridge the interfaces and move filtering from the bridge members to the bridge interface then the resulting interfaces will behave like switch. It will be much slower than even the cheapest switch (in most cases) but there are advantages. You can filter traffic between the ports for example. There are legitimate reasons to do this, buying a quad port nic just yo bridge them is not one of them. I have 3 interfaces bridged on my home box here. It has 10 NICs, they aren't removable and I don't need 10 subnets. The box cost me £40.  ;) Steve
  • Anonymouse-Proxy

    8
    0 Votes
    8 Posts
    2k Views
    K
    Yep - Now you have to block every proxy service on earth by name or IP also….  Good luck.
  • L2TP/IPsec question

    3
    0 Votes
    3 Posts
    872 Views
    R
    Thanks jimp
  • For school; students blocked from sites that teachers are allowed. How to?

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    H
    you could indeed block https intirely for students …. in the schools i work, the students NEED access to dozens of https sites to be able to do their tasks, because teachers implement new educational websites that require login/passwords. This would force me to "white list' a couple  of https site's on a weekly basis. I don't have the time for that.
  • PfSense throtteling WAN bandwidth?

    24
    0 Votes
    24 Posts
    5k Views
    K
    Sorry - Mixed my apples and oranges. Did he try switching LAN and WAN?
  • RUDP?

    2
    0 Votes
    2 Posts
    887 Views
    jimpJ
    I suppose that depends on how it's implemented. It looks like it can run over standard UDP just with its own payload format, in which case it would look no different to pfSense than normal UDP and wouldn't require any special handling.
  • Constant HDD activity

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    There are parts of the system that write periodically. Logs, gateway status, graphs, and several other things could be getting written to the disk, though it shouldn't be completely constant. If you run "top -aSH", press 'm' to switch to i/o view which will show you which active processes are writing/reading at the time. The normal top view is CPU only and wouldn't tell you much about the disk.
  • Set maximum login attempts HTTPs admin

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    The system tracks failed logins and if there are two many (I believe it's 15 in 5 minutes) then it blocks the offending IP for a couple hours to discourage brute force attacks.
  • Weird RRD Graphs average 40% packet loss normal? - Optus Cable AUS

    13
    0 Votes
    13 Posts
    3k Views
    K
    OK. Thanks everyone for their input.  It seems there does seem to be an issue with apinger….but... the main issue seems to stem from an ip phone plugged into the network (SNOM 720).  Once it was disconnected.. BAM! problem disappeared.  still waiting for enough time for the RRG graphs to verify this, but this seems to be the case. here is the graph from bandwidth (obviously from later than OP post): Traffic graphBTW.. My ISP plan with Optus Cable is 100Mbit/1.5Mbit :(
  • Stupid noob config question..!

    4
    0 Votes
    4 Posts
    1k Views
    A
    Well I have no idea what happened.. I changed nothing yet over night suddenly it's working… very strange indeed. I think maybe my DNS hadn't updated. Not ideal but at least it's working. I just need it for an assignment for uni. Thanks guys
  • Can`t bind squid to loopback

    2
    0 Votes
    2 Posts
    1k Views
    F
    Noones any explanation for this issue? I just want to understand where the problem is, even if the solution is pretty obvious (that is, dont bind squid to loopback) If someone maybe can explain to me why this problems occurs, that would help me a lot :)
  • Adding pfSense web certificate into Google Chrome

    6
    0 Votes
    6 Posts
    6k Views
    KOMK
    I played with transparent HTTPS proxy a few months ago but I'm not running it at the moment.  Yes, when I did go to HTTPS sites I didn't get any MitM warnings.
  • Traffic shaping went wrong

    1
    0 Votes
    1 Posts
    709 Views
    No one has replied
  • Kernel error on IP change of OpenVPN link

    1
    0 Votes
    1 Posts
    655 Views
    No one has replied
  • Lost WAN connection, can't understand why. How to read logs?

    2
    0 Votes
    2 Posts
    622 Views
    KOMK
    Status - System Logs is the first place to start.  From there, select the tabs that may hold detail you need eg. General and Gateways.
  • Multiwan and static ips

    1
    0 Votes
    1 Posts
    650 Views
    No one has replied
  • Interface hotplug not working

    1
    0 Votes
    1 Posts
    479 Views
    No one has replied
  • Limit Traffic After Certain Amount of Time or Amount

    2
    0 Votes
    2 Posts
    549 Views
    KOMK
    Not that I'm aware of.  You can create firewall rules that adhere to a schedule, but not like what you're asking about where it's targeted per IP with timeouts.
  • Nano with 8GB / 16GB cards: How to?

    10
    0 Votes
    10 Posts
    2k Views
    J
    @chemlud: Cards are getting bigger and cheaper and the larger the partition the lower the wear-out due to repeated use of cells? Just a short version of reasons. This isn't correct.  All modern cards I've encountered will wear-level across all cells, regardless of how large your partitions are.  Using partitions larger than you need can actually prevent wear-leveling from happening correctly depending on how your file system handles deletes.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.