• WAN IPs: Alias or add multi-port NIC ports

    2
    0 Votes
    2 Posts
    544 Views
    DerelictD
    Firewall > Virtual IPs You cannot have multiple interfaces on the same subnet.
  • High latency on local setup - question

    1
    0 Votes
    1 Posts
    450 Views
    No one has replied
  • PFsense connected with a Cable Modem/Router

    12
    0 Votes
    12 Posts
    4k Views
    G
    @bradtn: @guardian: @bradtn: @guardian: Make sure that you don't have Block Private Networks enabled (or a pfBlocker/Suricata/Snort) rule that trips when it sees a 192.168.x.x packet.  I've been trying to get up to speed on setting up pfSense and for now have to run behind a similar NAT… box has been up for about 3 weeks no sweat, so unless the modem is going down, you should be fine. Where Do I find said settings? Look under    Interfaces / WAN or    Interfaces / LAN - at the bottom under Reserved Networks (If you are using the new 2.3.1 or 2.3.2 interface) are you using any of  these: pfBlocker/Suricata/Snort?  If so, then you need to check the rules/blocklists - Firewall log should give you a hint if you are seeing stuff blocked. Its a fresh install so I do not believe so? If I recall correctly they are CHECKED BY DEFAULT
  • Traffic Graph: definition of "in" and "out"

    2
    0 Votes
    2 Posts
    480 Views
    KOMK
    That's it exactly. ![pfSense Inbound vs Outbound.png](/public/imported_attachments/1/pfSense Inbound vs Outbound.png) ![pfSense Inbound vs Outbound.png_thumb](/public/imported_attachments/1/pfSense Inbound vs Outbound.png_thumb)
  • OPENVPN first time setup

    6
    0 Votes
    6 Posts
    1k Views
    DerelictD
    If you can ping the pfSense LAN interface (or bring up the pfSense gui when connecting to the LAN interface address) from the OpenVPN client then your tunnel is probably up and correctly configured. If you cannot connect to other devices on the pfSense LAN, that is almost always the local firewall on the TARGET host preventing access from foreign subnets.
  • Bridge Issues on SG-8860 1U

    4
    0 Votes
    4 Posts
    728 Views
    DerelictD
    When bridging is necessary, it generally works fine. If you have to ask "should I use a switch or a bridge" the best answer is pretty much always a switch. You really don't want layer 2 traffic between the two switches going through a bridge.
  • Create a multi-machines PFSense administration network

    8
    0 Votes
    8 Posts
    1k Views
    C
    @heper: csrf error does not occur on interfaces. So if you assign an interface to your vpn, then it all works indeed. And IPSec will do it too: once sites are connected through IPSec tunnel, this is as simple as defining FW rules  8)
  • Outgoing Mail

    7
    0 Votes
    7 Posts
    1k Views
    DerelictD
    I also agree, but some packages, like HA Proxy, might exist so pfSense can function as a proxy OR a firewall. Not necessarily a proxy AND a firewall. That is just an example. HA proxy generally runs fine on the firewall though it could certainly be argued it is not the best place for it. Just because the packages exist doesn't mean they can all be run at the same time on the same node without issues.
  • Post 2.3.2 Upgrade - Slow Browsing / DNS Issue - Workaround Found

    3
    0 Votes
    3 Posts
    2k Views
    DerelictD
    What version did you upgrade from? You can generally run into trouble if you use something like AD and google as "Primary" and "Secondary" DNS servers (there really is no such thing as it is completely up to the client which DNS server is used first. Some query them all simultaneously and take the first answer, some query one, time out, then try the next, etc.) All of the DNS servers used in a particular context should return the same answers to every query from the same source. Your AD will have AD information, google will not. Problems such as these are best investigated using DNS tools such as dig/drill. Without seeing the actual queries and answers it's tough to tell what you were seeing. I can't see deselecting All interfaces to listen on having any effect. The forarder was either listening on the interface in question or it wasn't. All binds to all.
  • Archer C9 and pfSense?

    5
    0 Votes
    5 Posts
    3k Views
    G
    The crap software in most consumer grade routers makes them good as an access point, but not a lot more.  The C9 should be pretty decent - a lot better than the WRT54GL (running dd-wrt) that I'm using-but even that works… good enough to stream a bit of Youtube or browse.
  • Appear in the logs many times

    3
    0 Votes
    3 Posts
    1k Views
    T
    ok  I try it , thank u。  ;D
  • 504 Gateway Timeout on four new VMs running pfsense 2.3.2

    1
    0 Votes
    1 Posts
    560 Views
    No one has replied
  • Download limit for all user

    2
    0 Votes
    2 Posts
    572 Views
    H
    you can create a limiter on lan https://doc.pfsense.org/index.php/Limiters check dynamic queue creation
  • Pfsense ids(snort) on bridge interface

    1
    0 Votes
    1 Posts
    570 Views
    No one has replied
  • Fatal error every other day

    1
    0 Votes
    1 Posts
    453 Views
    No one has replied
  • Automated WOL with OMV+Plex on Access

    5
    0 Votes
    5 Posts
    3k Views
    K
    Thank you, I added that now. Where would you place the script to load it propery? In here? /usr/local/etc/rc.d/
  • Effects of packetloss on the system.

    5
    0 Votes
    5 Posts
    1k Views
    C
    That's basically idle. Any loss is likely attributable to a problem on your Internet connection. The processes you see coming and going are from updaterrd's stats gathering.
  • Downloading new 2.3.2 ISO image -> 5 KB/s???

    3
    0 Votes
    3 Posts
    597 Views
    C
    There was a problem earlier, fixed this morning.
  • 2 Factor Authenication

    10
    0 Votes
    10 Posts
    2k Views
    jdillardJ
    @Harvy66: I hate SMS based 2FA. It requires wireless connectivity and SMS has been shown to be easy to snoop on for people in the know. The US National Institute of Standards and Technology (NIST) has released the latest draft version of the Digital Authentication Guideline that contains language hinting at a future ban on SMS-based Two-Factor Authentication (2FA): http://news.softpedia.com/news/nist-prepares-to-ban-sms-based-two-factor-authentication-506617.shtml
  • [SOLVED] Set MTU on LAGG interface

    1
    1 Votes
    1 Posts
    3k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.