• Unnecessary rules

    3
    0 Votes
    3 Posts
    401 Views
    jimpJ
    As @stephenw10 mentioned, using Reject internally is one good reason, but there are also other reasons someone might want explicit block/reject rules, such as: To fine-tune which blocked traffic gets logged / not logged In combination with policy routing rules and the "Skip rules when gateway is down" option so that policy routed traffic will fall through to specific block rules if a gateway is offline To make the ruleset easier to read for less experienced admins who are not familiar with the default block behavior
  • Exporting LetsEncrypt Certificates in Automated mode.

    3
    0 Votes
    3 Posts
    919 Views
    S
    @stephenw10 Thank you very much for guiding me. Steve Best Regards. SMR
  • Deny dhcp lease and lan access to unknow and unwanted devices

    9
    0 Votes
    9 Posts
    714 Views
    T
    I've done this using a selfmade captive portal page, but thanks anyway for your hints.
  • Central Configurations

    1
    0 Votes
    1 Posts
    173 Views
    No one has replied
  • Fresh install internet access issue

    15
    0 Votes
    15 Posts
    650 Views
    stephenw10S
    That looks to be working fine, it pulls an IP and then renews it every hour. Was it not working at that point?
  • Why is file sharing not recommended on a pfSense box?

    samba nfs iscsi nas storage
    8
    0 Votes
    8 Posts
    3k Views
    provelsP
    pfSense is also an enterprise-capable firewall. I don't think you'd want to bet your real business on a Linksys or Asus from Walmart. Looking at it this way, you are getting enterprise-level performance and security for your home net at no required expense except what it takes to learn to manage it. Of course, being open source, you can always get creative and roll your own: https://github.com/pfsense/
  • Netflow Data from PPPoE Server

    1
    0 Votes
    1 Posts
    122 Views
    No one has replied
  • Solved : how to add service name in pppoe server

    14
    1 Votes
    14 Posts
    3k Views
    L
    Hi, Sagardawa! I do not mean to bother you but the files you uploaded seem to be removed. I am now trying to settle my PPPoE server with a service name so that the clients would not connect to the undesired server. Could you kindly send the files again?
  • Interface with my AP cuts out regularly

    24
    0 Votes
    24 Posts
    2k Views
    DerelictD
    Right but it will be limited to "converting" the media on the other side, which 1Gbit fiber. Not the same thing. If you want the same thing, use a switch to "convert" from fiber to copper.
  • New user. Cannot get wireless router to work with WAN. *** SOLVED ***

    6
    0 Votes
    6 Posts
    228 Views
    M
    Glad it's working. Yep, plugging the AP it into the switch is the preferred deployment. However, the other way would have worked also. All you needed were firewall rules on the re0 interface allowing the traffic out and then a NAT entry on the PIA interface for the 192.168.2.0/24 subnet.
  • WAN packet loss when new LAN connection made

    3
    0 Votes
    3 Posts
    377 Views
    V
    Finally tracked the issue down which was with the firewall state sync. This was setup on seperate interface and seperated from normal LAN traffic via 802.1Q VLAN on switches (the two routers were in different areas and weren't possible to run another cable through). No idea why this was causing such problems but disabled now and rather a brief connection interuption if it switches over.
  • URL Redirect for Search Engines

    7
    0 Votes
    7 Posts
    726 Views
    H
    if you have control over those devices: https://docs.netgate.com/pfsense/en/latest/cache-proxy/wpad-autoconfigure-for-squid.html#setting-up-wpad-autoconfigure-for-the-squid-package or you can start messing with fake ssl certificates todo this transparently ... but thats messy
  • Remove LAN interface

    28
    0 Votes
    28 Posts
    5k Views
    NogBadTheBadN
    @angdigi said in Remove LAN interface: Isn't this considered "flapping". Maybe it's something on the NIC that's causing the issue and not the ISP.... Flapping is generally a term for when a mac address moves rapidly between different ports on a switch / switches.
  • pfSense halving Virgin fibre connection speed

    10
    0 Votes
    10 Posts
    1k Views
    JKnottJ
    @danneh82 said in pfSense halving Virgin fibre connection speed: Swapped data ports (luckily ran extra drops!) and now getting full speed. The problem is probably at one of the connectors. Reterminating the cable should fix that or perhaps there's a bad connector. The cable itself rarely goes bad, unless physically damaged.
  • Add Custom Tables

    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S
    Yes, there's no way to do that directly. You can try using the Netflix ASN in pfBlocker to create an alias then use that in a policy routing rule. https://forum.netgate.com/post/848939 Steve
  • how to deploy pfsense in the current network?

    6
    0 Votes
    6 Posts
    906 Views
    M
    Another vote for replacing the USG with PFsense. I haven't seen anything in your diagrams that would warrant having two firewalls in your environment.
  • NAT - Source Hash netblock - assigning GW & Broadcast

    4
    0 Votes
    4 Posts
    422 Views
    stephenw10S
    There's no other way I'm aware of I'm afraid. If you need to use source hash you need to use a subnet as the translation so you need to use a set of smaller translation rules. Steve
  • PfSense as PXE boot server

    14
    0 Votes
    14 Posts
    28k Views
    F
    nice! I'm working on a similar project. when I circle back to pxe boot from pfSense I'll expand on this.
  • Problems with flaky internet and pfSense

    38
    0 Votes
    38 Posts
    4k Views
    stephenw10S
    I would check for a missing or bad default route when this happens. Diag > Routes If there is no default route client traffic will not be able to get out. pfSense itself would not be able to ping out to arbitrary sites. However the gateway monitoring will show onlint because that has a static route via the WAN gateway. Do you have more than one gateway in System > Routing > Gateways? If the default IPv4 gateway is set to automatic setting it to the WAN dhcp gateway instead should get you back a default route if that is what you're hitting. Steve
  • Has any one use type transparent in DNS resolver?

    1
    0 Votes
    1 Posts
    170 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.