• Restrict Youtube

    3
    0 Votes
    3 Posts
    2k Views
    I
    "Wait five minute or a restart of pfSense may require You can test in any browser. All Done !!" I have over a thousand people connected at the minute. I will reboot at a quieter time and report back.
  • Wan Drops and doesn't come back online

    2
    0 Votes
    2 Posts
    582 Views
    S
    did some more looking arround. I've implemented the following. https://forum.pfsense.org/index.php/topic,17243.0.html https://forum.pfsense.org/index.php?topic=51786.0 It looks like it will probably resolve the issue.
  • SG-1000 and Apple Airport Extreme

    15
    0 Votes
    15 Posts
    3k Views
    N
    Problem solved with update.
  • Hardcode Rules?

    1
    0 Votes
    1 Posts
    358 Views
    No one has replied
  • Pfsense as a Gateway for Internet services

    7
    0 Votes
    7 Posts
    1k Views
    F
    If you don't do layer3 routing on your cisco just connect a trunk of tagged vlans to pfsense, configure the vlans on the parent physical interface and create one interface for every vlan. Assign ip according to your subnets.
  • Questions about what is fastest? more info inside..

    2
    0 Votes
    2 Posts
    520 Views
    johnpozJ
    So your saying your not seeing gig?  Do you have gig wan?  Unless your wan is gig and your only seeing like 800 or something I don't see what your trying to squeeze out here?
  • PPPoE drops when adding another interface to WAN port for IPTV traffic

    1
    0 Votes
    1 Posts
    453 Views
    No one has replied
  • L3 Traffic on LAN via pfSense GW very slow

    4
    0 Votes
    4 Posts
    743 Views
    johnpozJ
    you got some sort of asymmetrical issue if your not seeing the full handshake and then traffic would be my guess. Setting state to sloppy is not something you should have to do. Can you layout your connectivity - how many vswitches?  How many physical interfaces - what is the setting do you have on the vswitch that has tagged vlans?
  • Block Website for Single IP or a Network Range

    4
    0 Votes
    4 Posts
    789 Views
    KOMK
    I tried with Group ACL method but not able to block for single IP or network. Then you're doing something wrong.  It does work.  I use it that way myself.  Maybe you have a problem with the order the ACLs are listed in? btw this really should be in the Cache/Proxy forum.
  • No open-vm-tools for 2.3.3?

    3
    0 Votes
    3 Posts
    739 Views
    A
    My fault. They were already instaled  :o ;D
  • MOVED: Can't seem to get Squid Cache + ClamAV to work

    Locked
    1
    0 Votes
    1 Posts
    273 Views
    No one has replied
  • 0 Votes
    8 Posts
    2k Views
    D
    The SCP permission works just fine with 2.3.3 and later. Of course if you don't have permissions to the directory or files as that user, you won't be able to download files from there.
  • Reg:- NAT Local Pool

    2
    0 Votes
    2 Posts
    432 Views
    D
    Eh? What client where? LAN => LAN does not go through the firewall.
  • MOVED: RADIUS accounting packets seem to be broken.

    Locked
    1
    0 Votes
    1 Posts
    227 Views
    No one has replied
  • Strange issue - can't ping AP from LAN pc (but can ping client on AP?)

    14
    0 Votes
    14 Posts
    3k Views
    johnpozJ
    U should be able add your whole lan net to allow remote admin but why?
  • A MIGHTY thank you for the new Traffic Graph widget!

    1
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • 0 Votes
    4 Posts
    2k Views
    S
    Doing OTP via LDAP/RADIUS isn't really that feasible for what we are looking at. I mean it isn't impossible, but not really something I'd like to pursue. I would encourage you to consider adding this, if feasible, as it is a nice security feature. A full implementation that integrates with AD and does enterprise certificate authentication would be cool, but that aside just something simple like SSH keys could work well. Just have the ability to add a public certificate for a user and then do a CAPI auth for that. Requires manually updating certificates and so on but gives people the ability to do 2-factor without needing an enterprise PKI setup. Just a Yubikey (or anything like it) and you are good. The SSH idea is one I may try. It will work fine, Putty-CAC works great with Yubikeys and will give you an SSH key that works properly and requests the right CAPI certificate. So it would work in that card+pin would be needed to access the system. I'll think about that and how much that gets us over just having Webadmin access restricted to a particular set of systems, which require card+pin anyhow.
  • Best Way to Add numerous IP's to aliases

    7
    0 Votes
    7 Posts
    717 Views
    KOMK
    Thanks for the tip.  I just checked the pfSense book and it doesn't go into much detail at all about URL aliases and URL tables aliases. I did misspeak earlier.  You should be using an URL alias, not URL Table.  URL Table is for when the list needs to be updated on a schedule.
  • Rate process burning CPU

    2
    0 Votes
    2 Posts
    644 Views
    jimpJ
    1. Update. 2.1 is ancient and that rate bug was fixed a long time ago. 2. Limiters do not use Rate. 3. It is safe to kill rate, it is only used to provide per-host bandwidth stats on Status > Traffic Graphs
  • FreeBSD packages on 2.3RC

    29
    0 Votes
    29 Posts
    21k Views
    jimpJ
    @whorfin: @whorfin: ngrep and socat, please Just grabbing these did seem to work: http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/ngrep-1.45_3.txz http://pkg.freebsd.org/freebsd:10:x86:64/release_3/All/socat-1.7.3.1.txz Please add tcpflow; this is particularly relevant as the version on freebsd.org requires cairo, which is a dealbreaker in embedded context. There is no option on the port to compile it without cairo. If we added it, it would also use cairo. The FreeBSD port maintainer should add an option to the port to disable cairo ("–enable-cairo=false" when running configure) and then we could set it to build without cairo in our repo. I liked tcpflow before it gained the cairo bloat. I haven't used it in years though. @s0rcier: can u please add murmur package… small mumble voice server... thanks I don't see us adding anything like that. That sort of service does not belong on a firewall.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.