• Unable to block traffic for Internal LAN devices with static assignments

    3
    0 Votes
    3 Posts
    256 Views
    A
    Here is a rule I setup (but it's currently disabled as you can see from the screenshot) to keep 1 single device from accessing anything off it's own subnet, thru the firewall. In my example, the host at 10.0.1.116 is blocked to any destination. [image: 1572463430021-screen-shot-2019-10-30-at-2.17.13-pm.png] Like @johnpoz says, you have to have this rule above the default allow any to any rule. Jeff
  • pfSense Time server

    ntpdate
    2
    0 Votes
    2 Posts
    220 Views
    stephenw10S
    Maybe if it's sending enough queries to be limited.
  • Please drag your screenshots into the message if you want help

    5
    3 Votes
    5 Posts
    478 Views
    GertjanG
    @johnpoz said in Please drag your screenshots into the message if you want help: emailing a bunch of bots or spammers When signing up - spammer or real person, a mail validation is used. I wasn't proposing a new mail .... just an extra line in the already existing mail with "see here for some help about how to ask questions ...."
  • VLAN cannot access to internal website

    18
    0 Votes
    18 Posts
    2k Views
    M
    @johnpoz Noted sir, Thank you. I will post another topic regarding failover, again that one is with VLAN problem :) Thank you for early christmas gift. new Knowledge ehehe
  • Bug showing up after power loss Version: 2.4.4-p3

    6
    0 Votes
    6 Posts
    565 Views
    jimpJ
    I can't say I can ever remember seeing a 'bug' that resulted in a loss of interface configuration like you describe. Maybe the filesystem was so trashed that the configuration was lost, but in that case you'd have to do a lot more than just reassign interfaces. So I suspect that maybe it's not quite exactly as you describe. But since you don't have a monitor hooked up when it fails, you can't really tell what happened for sure. When it does fail, you need to look back in the boot log and see what it's really complaining about. (Press scroll lock on the hardware console keyboard and then use the page up key to go back in the buffer, then scroll lock again to get out) It wouldn't surprise me if it's related to that hardware, given its track record/reputation, but it's entirely possible it's a red herring and you're chasing the wrong end of the problem.
  • Where to Donwload Old Installer Images

    5
    0 Votes
    5 Posts
    286 Views
    jimpJ
    You can get it done in a short maintenance window without bothering with the insecure old version. Get the new hardware up on 2.4.4-p3 without any extra configuration Restore your current config to this box -- it will be your new primary Swap in the new box in place of the old If it all works, then you take the old hardware, install 2.4.4-p3 on it and now that's your new secondary. If it didn't work, then you still have your current 2.4.4-p2 box and can swap it back in place and then investigate why it failed. If you want an extra dose of safety, then swap out the disk in the current system so you have the running copy of 2.4.2-p1 preserved. If you can't get enough of a maintenance window to do it properly, it's a management issue, not a technical one. Trying to force you to work with zero downtime is insane and shouldn't be encouraged.
  • 0 Votes
    1 Posts
    87 Views
    No one has replied
  • Ansible pfsense create users

    9
    0 Votes
    9 Posts
    2k Views
    O
    https://github.com/opoplawski/ansible-pfsense now has a basic pfsense_user module. Feedback welcome.
  • Backup pfsense with all packages

    4
    0 Votes
    4 Posts
    288 Views
    KOMK
    Yes.
  • Prevent proxy / DNS filter bypass - whitelist domains

    3
    0 Votes
    3 Posts
    385 Views
    S
    Found it, thx. I have a similar problem still. When I go to a website, the site itself might fetch scripts etc from other domains which would need to be whitelisted, too. Doing that manually is a hassle in particular when the external resources are fetched through muh.cloudfront.net while the other day it is meh.cloudfront.net. Can squid whitelist a whole website?
  • pfsense 2.3.5 and autoconfig backup

    8
    0 Votes
    8 Posts
    607 Views
    johnpozJ
    Even if your hardware is 32bit, just means its time you refresh the hardware.. Clearly any 32bit hardware in this day and age is well past its use by date ;)
  • New PFsense Build + Squid

    6
    0 Votes
    6 Posts
    644 Views
    stephenw10S
    Try enabling powerd in System > Advanced > Misc to get CPU speed scaling etc. Steve
  • does pfsense support docker

    3
    0 Votes
    3 Posts
    2k Views
    stephenw10S
    Docker running on pfSense rather than pfSense in Docker? Yeah, definitely not going to work. Also a bad idea to run anything like that on your firewall. Steve
  • Azure Marketplace - pfSense

    4
    0 Votes
    4 Posts
    456 Views
    stephenw10S
    But the admin user should be given the same password as that new user. That is done as Azure won't allow using the admin user directly. Steve
  • login by OPT port

    12
    0 Votes
    12 Posts
    691 Views
    Y
    @JKnott yes, i misread Rico's instruction and put in an invalid ip. i'm a newby to network stuff. tnx for the ed.
  • pkg-static update using 100% cpu. What is broke?

    14
    0 Votes
    14 Posts
    2k Views
    RedDelPaPaR
    @Derelict I ordered one. Guess we'll see what that does.
  • i need some help with this

    3
    0 Votes
    3 Posts
    352 Views
    L
    @JKnott i finally got it working. now i just need to figure out the port forwarding
  • 0 Votes
    11 Posts
    999 Views
    D
    @johnpoz said in Having trouble understanding the best way to connect pfSense to my environment: are you not knowing how to create a lagg interface? But your switching environment needs to support the ability to do that.. Creating a lagg over non stacked switches can be problematic at best, etc. I have Dell N2024 switches that are stacked. are you proposing to create LAG interface of type LACP and connect one port to switch 1 and the the other to switch 2? and do it from both master and backup? @johnpoz said in Having trouble understanding the best way to connect pfSense to my environment: They RDP over the public internet? - Again Ouch! each company has fiber connection to the internet and vpn ipsec to the cloud.
  • NUT driver for UPS auto shutdown

    3
    0 Votes
    3 Posts
    557 Views
    B
    @JKnott It seems to be reporting status correctly. And I do only let it run for a minute or two before I plug it back in (afraid to let the pfSense appliance turn off without being shut down).
  • pkg-static update still using 100% cpu! Unacceptable!

    55
    0 Votes
    55 Posts
    12k Views
    RedDelPaPaR
    @bmeeks Checked that reddit post and everything looks to be as it should IPv4 is my default gateway and the address is correct. No LAN gateway configured.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.