• WAN question

    12
    0 Votes
    12 Posts
    23k Views
    johnpozJ
    That is out of the box how it pfsense is - nothing to do for that.. Not sure what part your not understanding about the default deny.. All unsolicited traffic inbound to pfsense wan is just dropped.
  • After Cable modem power down WAN Interface gets no ip

    15
    0 Votes
    15 Posts
    2k Views
    stephenw10S
    Nice!
  • Problem enabled GRE Interface (PPOE passwords not matching)

    11
    0 Votes
    11 Posts
    863 Views
    jimpJ
    I didn't see that one, but I'm not terribly crazy about adding even more JavaScript to work around that. Might be worth considering, at least.
  • Newbie HTTPS question

    7
    0 Votes
    7 Posts
    424 Views
    johnpozJ
    You can block without trusting.. You have to use explicit (I believe), ie the client has to point to the proxy.. It will send the connect command for https, so proxy know where trying to go, and can either allow or deny based on that host name... What you can not do is allow say www.domain.com but block www.domain.com/something without doing mitm... Since onlly the host is sent in the connect. There is a hangout that I believe goes over this stuff - let me see if can find it. edit: here you go https://www.netgate.com/resources/videos/squid-squidguard-and-lightsquid-on-pfsense-24.html [image: 1563542241750-peek-amp-splice.png] edit: Also if all your looking to do is block access to sites, be it http or https wouldn't pfblocker be another option?
  • SSH (Solved)

    4
    0 Votes
    4 Posts
    1k Views
    NollipfSenseN
    It seems that the secure shell daemon not have been running for some reason...all is good now.
  • pfSense bricks (WebGui + SSH)

    7
    0 Votes
    7 Posts
    931 Views
    maverickwsM
    Ok @jimp thanks for the feedback. I do hope you can add that to the roadmap, I'm sure it would be useful for many. Best regards.
  • Reverse proxy issue

    3
    0 Votes
    3 Posts
    641 Views
    O
    Outlook Web Access. About the rules i have only one rule (from any to any). If i use HAProxy what settings do i have to make?
  • ext. LDAPS auth flapping after CA import -> only working after restart

    3
    0 Votes
    3 Posts
    292 Views
    JeGrJ
    @jimp said in ext. LDAPS auth flapping after CA import -> only working after restart: Because of the, let's say "suboptimal", way that PHP requires setting up the LDAP environment for certs I really laughed hard at "suboptimal" That's why we love PHP ;) If you really want to be sure it works, then you could always use a CA for LDAP that can be validated against the global root CA list, like one from Let's Encrypt. Ah nice idea! Even if not possible ATM as that would mean re-organizing the internal AD and dependencies but a good thought for an update later along the road. I'd love to fix it, but the new method still isn't working in PHP: https://redmine.pfsense.org/issues/9417 Will have an eye on that one :) Thanks for the hint about restarting, after restarting PHP-FPM, WebGUI and the OpenVPN servers that used the LDAPS connection all is working again!
  • Big downloads are killing throughput ?

    bandwidth slow performance big download
    5
    0 Votes
    5 Posts
    1k Views
    K
    UPD: the same issue as described at the beginning of my post is happening when connecting switch to pfSense and RouterA and RouterB to that switch thus hanging two routers on one pfSense port. Seems to be not an issue with virtual switch on pfSense as in this scenario using only one port. Once separated Port5 and Port6 on pfSense to different private subnets and attaching RouterA and RouterB independently to pfSense box (+NAT with public VIPs) issue is gone. It appeared when both routers are connected to the same bridge or external switch they can't work reliably together. But I would still appreciate if someone can point me to the right direction how to investigate that further and perhaps with some Layer-2 debugging.
  • how to connect 3 elastix server to pfsense

    routing
    1
    0 Votes
    1 Posts
    189 Views
    No one has replied
  • 0 Votes
    8 Posts
    872 Views
    D
    Hi johnpoz, I will verify my connection and try to connect my two subnets to my primary pfsense. Thank you and regards for your answers.
  • Cannot see PCIE NIC , only motherboard

    16
    0 Votes
    16 Posts
    2k Views
    M
    @provels I havent managed to get it connected to the internet just yet, but a new network switch I picked up yesterday should be coming in tommorow. I'll hook it up and try it. Otherwise I did try manually downloading and installing the 2012 drivers; but as I made note of above it only displays the cards model, no luck getting it to work. Will try using online windows update though. I'll report back tomorrow. @Mats I got win server 2019 running normally now; headless. I control it with RDP over LAN.
  • Question regarding /29 public IP

    3
    0 Votes
    3 Posts
    313 Views
    kiokomanK
    XG-7100-1U ... envy that grows and don't forget Firewall / NAT / Outbound to set the correct ip to go out for every VLAN
  • PPPoE server show active sessions

    3
    0 Votes
    3 Posts
    685 Views
    R
    Thanx a lot :)
  • 0 Votes
    7 Posts
    1k Views
    C
    I still don't have the HP yet but on the current Supermicro board and the two onboard intel NIC, it would drop ping every 20-30 seconds. I'm using the latest build and only the two onboard NIC. However, when it did work, my speed test yield much better performance than the Asus router that I'm using now. on my 200mbps connection I've only yield 160 ish down but when using PFSense I'm getting closer to the advertised speeds so it's definiteyl a good start.
  • Question about throughput on SG-2220 versus SG-3100

    4
    0 Votes
    4 Posts
    539 Views
    B
    i replaced my sg2220 with a mbt 4200. every pfsense update i boot up the sg2200 and update and then put it back just in case...
  • Intermittent loss of internet connectivity

    19
    0 Votes
    19 Posts
    2k Views
    stephenw10S
    Mmm, that implies something was opening things using upnp that somehow broke opening new states perhaps. Hard to see how it could do that though. Was it open to requests from WAN maybe? Something local to the device triggering it would explain why the same setup appears fine on other hardware in other location. Steve
  • Clients can make a DNS resolution but do not see the captive portal

    6
    0 Votes
    6 Posts
    330 Views
    GertjanG
    I advise you to make the captive portal work without this "firewall2". Add "firewall2" only when everything works perfectly.
  • 0 Votes
    5 Posts
    5k Views
    S
    I have found solution The issue was in /usr/local/etc/pkg/repos/FreeBSD.conf where I previously added FreeBSD: { enabled: yes } After disabling it starts working fine
  • fwknop FreeBSD ready. Is it available on pfsense

    2
    1 Votes
    2 Posts
    1k Views
    jimpJ
    It's not a package we make available. I don't know that anyone is working on it, either. With VPNs being easy and ubiquitous, there is little need for anything as crude as port knocking these days.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.