• Segmenting a network with Subnets and VLANs

    6
    0 Votes
    6 Posts
    1k Views
    A
    Well I found a slightly used tp link 24 port L2 managed switch for $240, VLAN heaven here I come!
  • Block lists

    3
    0 Votes
    3 Posts
    757 Views
    BBcan177B
    This is another great site for Mail Server Blocklist validation:     http://multirbl.valli.org/ If you have your mail server on a separate WAN IP then your main WAN IP, then it looks like a device on your LAN was caught sending SPAM… Create some firewall block rules to block all outbound MAIL ports from your main WAN IP network... Enable logging, and see if you get any hits on that... Then cleanup the infected LAN device(s)...
  • Add new interface command - running vm

    6
    0 Votes
    6 Posts
    4k Views
    JeGrJ
    If I remember correctly it has something to do with the MAC address VSpehere is assigning the new interface (at random). As most unix/linux sort their interfaces with some kind of "lowest mac address first", there could be the problem in your case. If the random assigned MAC is lower than one of the other 3, it gets mangled. (I stand corrected if that's not the case here, but we had a somewhat similar incident with normal BSD and Linux hosts and vSpheres random MAC assignments) Greets
  • Managment Interface (Extra NIC )

    3
    0 Votes
    3 Posts
    811 Views
    KOMK
    Michael, you might get better results if you would post your question in one of the numerous support forums you have to scroll past instead of this general discussion forum.  They're arranged logically by topic.  The General Questions forum is a good catch-all if you aren't sure of which forum to post in.
  • How to protect a page by password?

    1
    0 Votes
    1 Posts
    402 Views
    No one has replied
  • Reinstall pfSense with backed up .xml

    5
    0 Votes
    5 Posts
    2k Views
    JeGrJ
    "Perhaps this process could be refined further with the ability to place that config.xml file on the same installer USB stick." That would be nice, but would also require to mount the FreeBSD filesystem in your currently running OS where you create said stick. If I'm not mistaken, even the installer stick is partitioned with the freebsd filesystem & slices and e.g. Windows (and some linuxes) have a bit of a problem with reading and writing to that :)
  • Access pfSense filesystems remotely

    4
    0 Votes
    4 Posts
    953 Views
    jimpJ
    There are, however, ways to mount filesystems over SCP/SSH depending on your client OS.
  • Ping Monitoring

    3
    0 Votes
    3 Posts
    947 Views
    johnpozJ
    If all want to do is monitor something via ping.. Smokeping would be what I would look into.
  • Resolve Users from AD server into Pfsense

    1
    0 Votes
    1 Posts
    452 Views
    No one has replied
  • Firewall access

    2
    0 Votes
    2 Posts
    619 Views
    johnpozJ
    Huh??  What is the masks on your 10.x.x.x networks? what is pfsense firewall IP of 10.11.12.1 and lan IP of 10.11.10.1 ??? Can you draw up your network labeling your networks and masks and what they are connected too.
  • Ldap log SquidGuard Windows

    1
    0 Votes
    1 Posts
    574 Views
    No one has replied
  • Logging username after pfsense in Sonicwall

    8
    0 Votes
    8 Posts
    1k Views
    I
    Thanks I will start a new thread as this is going off topic.
  • 0 Votes
    2 Posts
    612 Views
    W
    BUMP Is this a taboo subject in Pfsense? Sorry if it is… was not my intention.. just a thought of how to allow users  to remotely setup rules in a albeit limmited yet simple way. VPNS are not always possible and leaving my ports open for travelling users abroad is caused some issues of late. Cheers -wookiefw
  • Large packet drop with bridge interface

    1
    0 Votes
    1 Posts
    492 Views
    No one has replied
  • Using NICs on pfSense box instead of a switch?

    11
    0 Votes
    11 Posts
    9k Views
    S
    @johnpoz: So they are just moving large chunks of data back and forth? Sometimes, yeah. Most of the GbE clients wouldn't be heavily transferring files all the time, but I'd rather not have, say my laptop over Wireless AC either getting slow speeds or causing slowdowns for everything else on the switch. Even being a half-duplex medium, it would be able to eat a sizable chunk of that 1Gb uplink from the switch by itself, not factoring in other clients' regular internet+intranet traffic. @johnpoz: What exact board did you get with that many integrated nics? It's this one: https://www.supermicro.com/products/motherboard/Xeon/D/X10SDV-TP8F.cfm though I was initially considering Rangely Atom boards (like most of the mid-level appliances in the pfSense store) I decided to go with the newer Xeon-D architecture instead. So it really came down to that board and this one, which for the ~$20 price difference through the distributor I bought it through, it wasn't really worth passing up the extra GbE ports. @johnpoz: You don't need a managed switch, you don't even need a "smart" switch unless your wanting to vlan. That's my main dilemma, I need to VLAN for the access points and management network, so a smart or managed switch would be required if I can't use the ports already on my box. I'll be able to handle some of that on the router that I'd be repurposing as an AP+Switch, but it still wouldn't be able to handle the second AP upstairs or my desktop over 10Gb fiber.
  • Not getting any connection to iperf on pfsense from client

    4
    0 Votes
    4 Posts
    2k Views
    T
    Thanks i found out it is iperf2. Thanks
  • Everything works, except one single website!?!

    1
    0 Votes
    1 Posts
    258 Views
    No one has replied
  • Configure the SMTP server to receive notifications

    3
    0 Votes
    3 Posts
    3k Views
    johnpozJ
    If your using 2 factor with gmail you will need to setup a APP password in gmail that does not require the 2 factor.
  • One user belong to two groups

    1
    0 Votes
    1 Posts
    354 Views
    No one has replied
  • Can you have a Ipsec Site to Site with pfSense to SonicWall router

    2
    0 Votes
    2 Posts
    359 Views
    dotdashD
    Yes. IPSec is standard. You just have to use a standard identifier and not the Sonic ID.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.