• Pfsense Firewall Setup for Static Block of 8 IPs

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Can't copy from windows through OPT1 interface

    Locked
    1
    0 Votes
    1 Posts
    969 Views
    No one has replied
  • GROWL Test Procedure and Expected Results

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    M
    Thank you, This is the key information I needed for further analysis in resolving this issue.
  • MOVED: Question about user management

    Locked
    1
    0 Votes
    1 Posts
    791 Views
    No one has replied
  • MOVED: Assistance with bandwidth limiting please?

    Locked
    1
    0 Votes
    1 Posts
    814 Views
    No one has replied
  • MOVED: Need porn IP blacklist

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Right location for custom scripts

    Locked
    1
    0 Votes
    1 Posts
    846 Views
    No one has replied
  • MOVED: Loadbalancer

    Locked
    1
    0 Votes
    1 Posts
    951 Views
    No one has replied
  • Transparent VLAN removal&addition

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    C
    @heper: but look at this: http://www.zyxel.com/support/knowledge_base/kb_detail_8603.shtml there seems to be a way to tag vlan's by ip Because you can do something on a Zyxel switch doesn't mean you can do it on BSD or any other general purpose OS. Sure it's feasible to tag specific IPs to certain VLANs in theory, in practice to do so on FreeBSD means you're in for some kernel hacking.
  • UPnP and VLANs

    Locked
    10
    0 Votes
    10 Posts
    10k Views
    M
    Glad it solved out, now we all know more ;)
  • Simple question

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    J
    Thanks. I own the book, one of the best dead tree editions I own. It is well written and nicely illustrated. Thanks, Sean
  • Automatic redirection to proxy server

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    A different subnet is not enough. It has to be on a different interface entirely.
  • MOVED: Aviso automático quando a internet sai do ar

    Locked
    1
    0 Votes
    1 Posts
    860 Views
    No one has replied
  • OPT1 extremely slow

    Locked
    17
    0 Votes
    17 Posts
    5k Views
    C
    OK, thanks!
  • Pfsense network design

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    If you wish, and if you understand the security concerns as raised by Derek Zeanah then you can have the configuration you want. All you have to do is to add rules into the PFSense firewall configuration to allow the ports you need through the server. Just make sure you add them in both directions. As Derek Zeanah said however, you should really have a firewall or other security appliance on the outer edge of your network, even if the server is supposed to be internet accessible.
  • PfSense pinging gateway every second

    Locked
    2
    0 Votes
    2 Posts
    8k Views
    stephenw10S
    pfSense uses pings to monitor the gateway for connection quality. The actual volume of traffic is very small. You can set it to monitor a different address on that interface, the modem for example, from the web interface: System>>Routing>>Gateways. Click the edit button next to WAN gateway and enter an alternative IP. You could try entering the WAN interface IP, I don't know what would happen though! Steve Edit: @cmb: It's for monitoring and quality graph. No way to disable it at this time short of hacking the source yourself.
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • PfSense 2.0 nanobsd slices

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    jimpJ
    You still need serial console access to the router to switch slices (or KVM on a full install) so it doesn't buy you all that much. If you have access via something like DRAC/ilo you can probably even reinstall remotely using an iso image.
  • Web Console Security - remote management

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    If you also restrict by IP range then it may be sufficient. If your HTTPS port is open to the world, people can still see your pfSense login screen, which is undesirable. If you have packages installed, some package files are not protected by the pfSense login process so you could be exposing information you don't intend to be public. Using a VPN is always the best way.
  • NAT default gateway question

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T
    questing bump, anyone?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.