• Ping between subnets on separate NIC's on the same pfSense machine

    14
    0 Votes
    14 Posts
    5k Views
    A
    @johnpoz Got it. Changed the top rule, and voila ... it works. Thanks for your help! Much appreciated.
  • Strange wifi calling problem

    14
    0 Votes
    14 Posts
    1k Views
    C
    @teamits Thank you. If i come back to Suticata i will try what you suggest. Things seem to be working now with snort so i may resist the temptation of playing more and digging another bottomless hole for myself!
  • 0 Votes
    3 Posts
    423 Views
    stephenw10S
    Indeed, much more! What type of tunnel is it? How is it configured? What is it connected to? Does traffic fail in both dircetions? Is it the same tunnel the fails each time? How long does it take to fail? Etc Steve
  • 0 Votes
    3 Posts
    449 Views
    R
    @stephenw10 thanks a lot! For further reference the corresponding FreeBSD PR is found here.
  • How to setup aliases to stop networks talking to each other

    14
    0 Votes
    14 Posts
    2k Views
    stephenw10S
    There have not been for a while and I use invert rules myself. I try to use them only for single subnet aliases though. Can't find a bug report for that now but I know I have hit it in the past. Steve
  • Updates not respecting proxy in System- Advanced- Miscellaneous

    7
    0 Votes
    7 Posts
    778 Views
    stephenw10S
    Yup. That. https://docs.netgate.com/pfsense/en/latest/troubleshooting/upgrades.html#pkg-pfsense-org-has-no-a-aaaa-record
  • 0 Votes
    15 Posts
    1k Views
    JKnottJ
    @hescominsoon said in Why Pfsense is free and who is mysterious benefactor we should be grateful ?: yes it could..but why? That would lead to it being more insecure by default. That was just to demonstrate my point that pfsense is just an interface on top of BSD and does nothing that couldn't be done by BSD alone. It would mean manually configuring all the various services, including pf, but it could be done. It's the same on Linux, where the configuration app (Yast) configures everything, including IPTables. Without that app, you could still make a good firewall, but it would take more work. BTW, I go back to the days when everything on computers was done from the command line (I was working with VAX/VMS long before I ever saw PC/MS-DOS and IBM mainframes before I bought my XT clone) and when I first heard about the Mac, I wondered why anyone would need a graphical interface. Putting Wireshark would take a lot more work than I'm prepared to do. I do use Packet Capture frequently and download the captures to examine with Wireshark. I can also put a managed switch, configured as a data tap in line with any connection to pfsense.
  • LDAP authentication for SSH for pfsense 2.4.5

    5
    0 Votes
    5 Posts
    678 Views
    jimpJ
    It required binary changes/compile options, so no, not possible on 2.4.5.
  • Any ETA

    4
    0 Votes
    4 Posts
    410 Views
    QinnQ
    @stephenw10 Thx for pointing that one out to me
  • Strange performance problem

    15
    0 Votes
    15 Posts
    812 Views
    ?
    @johnpoz said in Strange performance problem: What do you think of the odds of something like that happening are? ;) Zero. How many home networks are out there with old cheap crap "routers" that want you to believe that NAT is a firewall... So much stuff is going on. My ISP (Spectrum, formally Time Warner) will give me a /56 prefix. Nice. But, this same ISP thinks that power cycling is the cure for all issues. Begging is required to access someone who knows their head from a hole in the ground. A lot needs to improve.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    14 Views
    No one has replied
  • LAN has no carrier

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S
    What do you have limiting the bandwidth? How are you applying that? Can we see screenshots? Do you see blocked traffic in the firewall log? If you are able to connect at all through that port then it must no longer be showing as 'no carrier' I assume? Steve
  • Issue with Intel SpeedStep settings

    15
    0 Votes
    15 Posts
    6k Views
    stephenw10S
    Yup those later P4s were hungry hungry beasts!
  • sonewconn: pcb: Listen queue overflow messages in kernel log

    10
    0 Votes
    10 Posts
    10k Views
    stephenw10S
    Yes, those values you're seeing are small, 8 queued, 4 occurrences. Often if you hit a problem like that you will see far higher numbers there. If you are not seeing any actual connectivity issues you might choose to ignore it. You should not be seeing it though. Steve
  • Building my lan: do I need a managed switch for my VLANs?

    51
    0 Votes
    51 Posts
    12k Views
    D
    @valepe69 Have a look at the Netgear GS350 Series of Smart Managed Pro switches. I've used the GS308T, GS310TP and the GS324T. All solid. And the price is right. I have some spare GS308T's (I consolidated several switches) if that's all you need and are interested.
  • Removing interface - best practice?

    2
    0 Votes
    2 Posts
    305 Views
    stephenw10S
    Hmm, that absolutely shouldn't happen. As long as the assigned interfaces in the config are still present at boot pfSense should not care about other interfaces that may or may not exist on the firewall. Commonly an interface may be removed that changes the ordering of other interfaces, if they are all igb NICs for example. If you don't have any other 10G NICs in the system and have unassigned it I would not expect an issue. Steve
  • 502 Bad Gateway

    2
    0 Votes
    2 Posts
    549 Views
    NollipfSenseN
    @dzmnetworks Swap a known good working cable and see whether you get the same response. Be sure to reboot the modem when you swap cable.
  • Lost access to web portal

    3
    0 Votes
    3 Posts
    413 Views
    stephenw10S
    Yes, or roll back that last config change. https://docs.netgate.com/pfsense/en/latest/config/console-menu.html#restore-recent-configuration Steve
  • Using pfSense with another Router just for OpenVPN Load Balancing

    2
    0 Votes
    2 Posts
    311 Views
    stephenw10S
    Yeah, you don't need any sort of bridge there. The pfSense router will connect out as an OpenVPN client to remote servers without needing anything special. Steve
  • DC Cluster for LDAP Authentication?

    4
    0 Votes
    4 Posts
    575 Views
    S
    @stephenw10 Good advice. I just used my generated pfsense LDAP CA to issue another cert for the second DC and imported the CA cert and generated server cert into the certificate store on that domain controller. Totally forgot you could choose more that one auth server in the OpenVPN server config. Thanks for reminding me!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.