• [SOLVED] Avaya IP Office v9 remote site phone failing

    18
    0 Votes
    18 Posts
    3k Views
    L
    @stephenw10 Based on the idea you had about why I needed that rule at all, I went ahead and disabled that rule. Everything seems to still be working just fine. Guess that's what happens when you follow some guides on how to do things. The guide I followed was accurate to get the forwarding to work properly, but it was also why I added that NAT rule. If you can, can you update the title of this thread to include [SOLVED] in it, just in case anyone else runs across this. Thanks again for help. :)
  • Dashboard Configuration

    2
    0 Votes
    2 Posts
    238 Views
    stephenw10S
    It lools like you have either a lot of columns on your dashboard or you're viewing it in a narrow window. Using less columns should make it wider. Steve
  • PPPoE session dropping intermittently

    8
    0 Votes
    8 Posts
    1k Views
    O
    4 days uptime. Looks like it was a fault in the ISP router!
  • how to check which user is browsing which web sites??

    9
    0 Votes
    9 Posts
    3k Views
    stephenw10S
    Squid is a package you install in pfSense to proxy and log http/s traffic. https://docs.netgate.com/pfsense/en/latest/cache-proxy/index.html#squid If you watch the video I linked above it walks through the entire process. Steve
  • 0 Votes
    7 Posts
    1k Views
    stephenw10S
    This could easily be something in your browser filling the credential fields when you switch back to page. I've hit similar things before though not on that page. Steve
  • Performance Tuning for 1.5gbit Internet and 10Gbit LAN

    26
    0 Votes
    26 Posts
    4k Views
    stephenw10S
    That looks like plenty in hand in performance terms. No cpu core is anywhere near 100%. The bxe processes are not at 100%. I would have to guess the limit is somewhere else. You might try running tests from the pfSense box itself. It's not a good way to show absolute values but you have CPU cycles to spare and it will allow you to test the WAN and LAN separately. So you could run iperf on pfSense and test to it from the client to be sure you're getting speeds on the LAN that are above 1Gbps. You won't see 10Gbps but if you see, say, 4Gbps you know that's not limiting. You can run the CLI speedtest client on pfSense to test only the WAN. That might show almost anything! My experience is that it usually shows low speeds on high bandwidth WANs but if it shows closer to 1200Mbps that would prove the WAN is good. Steve
  • Logs System, what could it be?

    4
    0 Votes
    4 Posts
    561 Views
    lean-on-heL
    @kiokoman Its a PFsense 2.4.4 P3 running on a Xen hypervisor, so yes it is a virtuel machine.
  • DISK USAGE ALLMOST FULL

    6
    0 Votes
    6 Posts
    818 Views
    DerelictD
    Based on the service status in his screenshot it's neither of those. But it looks like he went dark on us anyway.
  • 0 Votes
    8 Posts
    1k Views
    J
    @petreza yes, but we know about this thread. We will get back to you.
  • WAN upgrade from /29 to /28

    13
    0 Votes
    13 Posts
    1k Views
    K
    @jimp Thanks for the heads up, Im not aware of my /28 addresses yet so I will hold fire on adjusting anything.
  • Pfsense 2FA failed on Freeradius

    pfsense
    1
    0 Votes
    1 Posts
    147 Views
    No one has replied
  • Two Customers Using One Firewall

    7
    0 Votes
    7 Posts
    860 Views
    stephenw10S
    Yes, you can bridge a 2nd interface to your WAN and allow them to use a single public IP directly. You should also be able to apply Limiters to that traffic. Whether or not you should is a different question. Steve
  • setting up alert when public ip access to internal server via NAT

    4
    0 Votes
    4 Posts
    433 Views
    stephenw10S
    Yup, probably. Unless that rule has a restricted source.
  • Sending squid access.log to remote syslog WITH mac address

    1
    0 Votes
    1 Posts
    354 Views
    No one has replied
  • 0 Votes
    4 Posts
    574 Views
    T
    This is still in cron 30 12 * * * root /usr/bin/nice -n20 /etc/rc.update_urltables without suricata installed
  • Multiples crashes, error on different equipment

    Moved
    8
    0 Votes
    8 Posts
    850 Views
    Ozer_imO
    It's been two weeks now that a new router is in place and everything is working properly. It seems that starting from scratch and manually reconfiguring the router without going through the import/export tool has solved the problem!
  • 0 Votes
    3 Posts
    224 Views
    V
    thanks it work.
  • Subnet load/traffic... one or many pfSense boxes?

    5
    0 Votes
    5 Posts
    497 Views
    P
    I guess I'd make that call based on how reliable the hardware is, but generally I try to go for just one box no matter the size. Just because it's an easier setup, easier planning, documentation etc. And usually less money. But there's really nothing wrong with doing your setup. If your main concern is uptime, I'd put one box as central router with multi-WAN and put the other one as HA to automatically take over if the first one fails. I would make a LAN network (VLAN1) for devices such as switches, AP's etc, then two or more VLAN's for users. In the past when I've built large networks I have sometimes created a 22-network (255.255.252.0 subnet mask) just to get a few extra IP's, and sometimes I've limited them to about 50 devices per network, depending on the type of traffic. Smartphones and such is good to keep down in numbers as they broadcast a lot of traffic, but if there's *nix devices it doesn't matter as much. The main thing I go for is to try and keep as much as possible with software, since it's easier to replace one box and restore config than to troubleshoot and replace several boxes. Correctly done, you can even replace a router on remote with a novice customer moving a cable or two.
  • Can't Add OPT interface

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    No problem.
  • Unable to access OpenVPN server externally

    8
    0 Votes
    8 Posts
    553 Views
    stephenw10S
    Yup change it there and re-export the config. Or edit the config on the client directly to use the real public IP. Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.