• This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • Firewall logs wan source ip 0.0.0.0 blocked

    26
    0 Votes
    26 Posts
    5k Views
    johnpozJ
    sniff/packet capture on your wan... Open the capture in wireshark. Or just run a tcpdump with -e should also show it. Looks like your seeing them every few seconds so you sniff should only need to be very short.
  • dns isp hijacking

    5
    0 Votes
    5 Posts
    755 Views
    KOMK
    Start a new thread about it in the pfblocker sub. This has nothing to do with your 'DNS servers from ISP' issue. By unchecking that box, your ISP's DNS are no longer in your list.
  • Turn off ICMPv6 option 31(RDNSS host name)?

    7
    0 Votes
    7 Posts
    616 Views
    JKnottJ
    @jimp I see the line '$radvdconf .= "\tDNSSL {$config['system']['domain']} { };\n";' Will removing ['domain'] from that line remove option 31 from the RA? Or just remove the domain name, leaving an empty option 31? The reason I'm trying to do this is so that the pfSense RA matches the one from the cell phone as closely as possible, to see if this option is causing the problem.
  • pfSense within AWS environment

    3
    0 Votes
    3 Posts
    428 Views
    stephenw10S
    Be sure to have source/destination check disabled if you're not NATing, which you probably aren't. https://docs.aws.amazon.com/vpc/latest/userguide/VPC_NAT_Instance.html#EIP_Disable_SrcDestCheck Steve
  • Issue with YouTube and other mobile apps not functioning

    2
    0 Votes
    2 Posts
    273 Views
    stephenw10S
    You should upgrade to 2.4.4 if you're running 2.4.0. Check to see if those URLs actually resolve when the sites fail. What are your clients using for DNS? Steve
  • VPN LT2P and MacOS

    2
    0 Votes
    2 Posts
    446 Views
    stephenw10S
    I assume you're using L2TP over IPSec rather than unencrypted L2TP? Did you ever see any hits in the firewall logs before adding those floating rules? If the VPN is actually dropping rather then the connection across it that sounds more likely something timing out. And since the Windows client seems unaffected it's probably something specific the MacOS client is setting. Do you see anything in the VPN logs at either end when the tunnel drops? I would recommend switching to IKEv2 mobile IPSec or OpenVPN to be honest. Both if those work well with current MacOS (and most other things). Steve
  • Is it possible to rename the interfaces?

    3
    0 Votes
    3 Posts
    994 Views
    J
    Thanks Steve. I think it wouldn't be a bad feature to have, or at least a way to order interfaces within the GUI, especially the monitoring parts; especially if one has many interfaces/Vlans. Cheers
  • Possible to set Content-Type with mail.php?

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • Private key weight 26GB?

    6
    0 Votes
    6 Posts
    568 Views
    jimpJ
    You probably mistyped that command in a way that caused openssl to fill up that drive or at least run until it died some other way. That isn't something you'd normally see.
  • How to watch disk usage and send mail in pfSense.

    5
    0 Votes
    5 Posts
    580 Views
    JKnottJ
    I did and nothing showed up. With something like a firewall, there shouldn't be such an increase in disk usage, as you might get with a regular computer. Maybe you should try finding out where those large files are coming from. .
  • Upgrade made to display a crash message, what to do?

    2
    0 Votes
    2 Posts
    265 Views
    jimpJ
    If the crash report is empty then there is nothing to worry about: https://redmine.pfsense.org/issues/8915
  • Logs show different logs than expected

    2
    0 Votes
    2 Posts
    260 Views
    jimpJ
    You'll need to provide some examples of what you mean there. When you set a rule to log and then save/apply you will see a log entry for all new connections made from that point on -- not for every packet and not for connections already open when you clicked the apply button. If you want to see every packet of incoming traffic at that moment, use a packet capture, not the firewall log.
  • pfsense doesn't block port on wan

    25
    0 Votes
    25 Posts
    4k Views
    johnpozJ
    As Derelict has been trying to tell you for this whole thread. Now create your firewall rule with dest of your IP of your nat, ie 192.168.x.x Put that above your rule that allows it.. And that IP would be blocked.
  • "Bypass Proxy for These Destination IPs" breaking transparent proxy

    9
    0 Votes
    9 Posts
    3k Views
    E
    @akuma1x Thanks for the help Bypass squid for the client is not an option. It's also my workstation not dedicated steam box. I used the do not cache option and it worked for me. Only trick was to enter ".steamcontent.com" instead of "steamcontent.com", the little dot catches all subdomains. I also had to manually edit the squidav conf to bypass antivirus for steam, otherwise it will still use quite a bit memory and lots of CPU. abort \.steamcontent\.com As you can see if squid can be bypassed totally for certain domains then things can be a little easier. Or if the squidav GUI is more versatile...
  • CARP and Interface Missmatch

    3
    0 Votes
    3 Posts
    337 Views
    N
    Ahh i was able to make a "new" sorting by deleting the VPN interface ;) Ok that was easy. Thx to give some hints.
  • Routed /29 subnet from ISP and exposing services to internet

    2
    0 Votes
    2 Posts
    386 Views
    johnpozJ
    @jkmuk said in Routed /29 subnet from ISP and exposing services to internet: how a /29 subnet is normally setup in pfsense for exposing internal services to the internet? By actually just routing it - ie you this /29 on a interface connected on your lan side of pfsense and just firewall rules to allow inbound and outbound traffic. Is how you would normally do it. Since your question really has nothing to do with that and your natting to private IPs - your questions should be in the load balancing section. Since that is what your question is about.
  • pfsense goes into dummy state after a 2 or 3 days.

    8
    0 Votes
    8 Posts
    653 Views
    S
    Which type of scsi controller do you use in your VM ? What do you see in VM console after ''dummy state''? I can't interact with the VM at the command line either Make sure to hit Scroll Lock next time - sometimes console ''freezes'' and don't show last messages/current screen.
  • FreeBSD and Intel PRO/1000 PT Quad Port Server Adapter (82571)

    5
    0 Votes
    5 Posts
    3k Views
    N
    pan_2...thanks for the response. I currently have a Intel E1G44HT I340-T4 4 port PCIe Ethernet Server Adapter (Intel 82580 controller) in my pfSense computer and use it for my LAN and WLAN interfaces and have had no issues with this NIC. However, in the FreeBSD hardware notes, I can't find an 82580 controller listed in any driver section; there is a listing for an Intel Single, Dual and Quad Gigabit Ethernet Controller (82580) in the igb(4) driver section but I don't know if that 82580 listing is meant for the controller or not. The igb(4) driver supports Gigabit Ethernet adapters based on the Intel 82575 and 82576 controller chips. Indeed, a means to return/refund is at the top of the list. I'm just looking for a PCIe, <= 4x, quad port gigabit NIC that will work with Suricata in Inline Mode. I've not had any issues with Intel NIC cards in the past which is why I was looking in the FreeBSD hardware notes in the em(4) driver section. Trying to find one that is either not discontinued or fiber seems a little more difficult than I expected.
  • The gateway: XXXX is invalid or unknown, not using it.

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    stephenw10S
    Locking this topic, it's waaaay too old. But, yes, if you have firewall rules that have a gateway set that's been removed it will throw that error. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.