• Do not flush states when backup WAN goes down

    7
    0 Votes
    7 Posts
    756 Views
    stephenw10S
    I agree that would/will be better. It was not possible to do that in pf when that code was added originally which is why it's like that. Steve
  • Unable to access pfsense via serial cable

    37
    0 Votes
    37 Posts
    5k Views
    stephenw10S
    @heathy65 said in Unable to access pfsense via serial cable: MNHO-073 That device has an hdmi output, does that work as a console? It may have been installed without a serial console enabled, who installed it? What image was used? Steve
  • Need some help regarding multiple traffic management in pfsense

    2
    0 Votes
    2 Posts
    249 Views
    stephenw10S
    Can you explain that differently? You are trying to bypass a 100Mb connection to the facebook CDN? You have two WANs? You are trying to limit the speed of connections to facebook? Steve
  • Intermittent TLS Handshake problem

    6
    0 Votes
    6 Posts
    772 Views
    stephenw10S
    It's hard to imagine anything in pfSense causing this, it looks like some upstream issue to me. Have you tried using a vpn and connecting over that? Does that also fail? Steve
  • FEATURE REQUEST | Captive Portal - Tarpit option

    2
    0 Votes
    2 Posts
    394 Views
    stephenw10S
    You need to open a feature request here: https://redmine.pfsense.org/projects/pfsense Unless you find something there already of course in which case add your comments to it. Steve
  • Captive portal login tarpit

    2
    0 Votes
    2 Posts
    206 Views
    F
    @pppd hello, No process are currently there agains bruteforce... You could possibly submit a feature request?
  • 0 Votes
    6 Posts
    1k Views
    I
    @nogbadthebad said in Is this a good network architecture/configuration that makes good/secure sense?: Also if you need to extend your coverage you can just add another AP. Hoping to avoid buying another AP. I will try it with all 3 SSIDs on my Unifi.
  • Traffic Graph display issue

    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    Doesn't matter if the time is correct with the correct timezone... But if your time is OFF based on the timezone it thinks its in - then yeah that is going to be problematic.. As long as the time is correct for what timezone your in, or the OS thinks its in that would not be a problem.. But if your in say central timezone, and time should be 10:03 in that tz.. but your system thinks its 1403 then yeah that is going to be problem.
  • FRR, OSPF, and Loopbacks

    9
    0 Votes
    9 Posts
    2k Views
    cmcdonaldC
    @vbman213 https://github.com/pfsense/FreeBSD-ports/pull/1011
  • Vpn Ipsec tunnel phase 2 show 0 bytes of data

    13
    0 Votes
    13 Posts
    4k Views
    stephenw10S
    If dpd is enabled then the P1 will not stay up if the route between the end points is interrupted. However if your tunnels are not using NAT-T then the P2 traffic will be ESP dircetly and it is possible for that to be blocked resulting in the tunnel establishing (over UDP port 500) but not passing traffic. Steve
  • pFsense + Radius +WPA2 Enteprise with EAP-TLS

    3
    0 Votes
    3 Posts
    879 Views
    ?
    @alexmercer I did this recently. Followed the guide referenced above. No issues at all, worked first time.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    13 Views
    No one has replied
  • Passing public /29 through one pfSense firewall to another

    15
    0 Votes
    15 Posts
    1k Views
    F
    Assigning an IP from the /29 to an interface means I can ping that IP from an external address. That shows, at least, the block is being routed to the main firewall. Couldn't get any internet access, 1:1 NAT etc working though. Have now run out of time trying to diagnose, but ISP has swapped my /29 for a /28, which is more than enough for what I need for now even considering the 4 lost addresses (3+1 interface) - so have just put it on an interface on the L2TP instance and gone the easy way. Thanks so much for your help though - absolute legend!
  • re1: watchdog timeout error

    17
    0 Votes
    17 Posts
    2k Views
    C
    @stephenw10 ah ok always learning something new everyday.. figure realtek made the driver for pfsense or the freebsd and u just use it the way they made it.. didnt know about compiling etc... and then read there is no likly the drivers be released in next version of pfsense... probably because its not a high priority kinda thing.. but always learning.. i just glad its not motherboard... as with this damn pandemic its making harder to get certain parts i appreciate the info learn something new every day
  • Cope bad peering of ISP Deutsche Telekom

    16
    0 Votes
    16 Posts
    2k Views
    stephenw10S
    Yeah, it would need to actually route to it using a static route. Outbound NAT does not route traffic. You're right though, you can't use a URL alias in a static route. Which is reasonable since adding 2055 routes to the table would be.... ugly at best! Steve
  • Su command become root without password

    2
    0 Votes
    2 Posts
    213 Views
    H
    @peter_apiit you need to set 'passwod protect console menu' (system->advanced)
  • Viber in openvpn

    7
    0 Votes
    7 Posts
    1k Views
    GertjanG
    @rumaru said in Viber in openvpn: 5242 4244 5243 9785 And any other port you might have forgot / not know about. This rule (the last one, number 4), will always work : [image: 1608531875501-0204cc9d-28c2-4701-baa6-4b49978cffcf-image.png]
  • pfsense syslog to azure sentinel

    5
    0 Votes
    5 Posts
    2k Views
    N
    @stephenw10 Yeah for some reason it's not showing on the Tech Community for public viewing anymore, I'm not sure why... You can find more information about this project on my GitHub.
  • Website blocked until login to console

    5
    0 Votes
    5 Posts
    328 Views
    stephenw10S
    @dcoens said in Website blocked until login to console: Disable DNS Forwarder: When you set that in Sys > General setup you are telling the firewall to use the defined external DNS servers for it's own connections. Like from Diag > Ping or firmware checks etc. It will otherwise ot's own DNS server, either the forwarder or the resolver whichever is enabled. It's unlikely that change would have any effect on client connectivity. Steve
  • 0 Votes
    6 Posts
    850 Views
    johnpozJ
    Yeah shortcut to the root of the nas will show you all the shares. While a drive mapping has to really go to a specific share.. You can get specific with your shortcut if you want them going direct to a specific share..
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.