• PfSense + Omada controller

    11
    0 Votes
    11 Posts
    7k Views
    J
    @ahmetakkaya I agree with noplan...you can and should do this with 2 VMs on a single machine. The Omada controller is free to download for Windows or Linux (https://www.tp-link.com/us/support/download/omada-software-controller/). There are many choices of VMs for Linux...take your choice. Then install Pfsense on a separate VM. You just have to spend some time configuring the interfaces. You really want to keep the firewall separate from other software.
  • auditd not available / cant run it

    2
    0 Votes
    2 Posts
    362 Views
    stephenw10S
    It's not included in pfSense. There's no easy way to add it outside installing it from FreeBSD with all the reasons that's a bad idea. https://docs.netgate.com/pfsense/en/latest/recipes/freebsd-pkg-repo.html#concerns-warnings Steve
  • PPPoE with VLANs (Phone/IPTV)

    3
    0 Votes
    3 Posts
    875 Views
    stephenw10S
    There have been a number of other threads detailing this sort of setup for other providers but it usually complex! Looking at the config he uses for Mikrotik it looks like he's just bridging the internal TV port with a vlan on the WAN side trunk. But I could be wrong, I don't use Mikrotik. Steve
  • Snort log files to rsyslog server

    2
    0 Votes
    2 Posts
    743 Views
    bmeeksB
    Sure, on the INTERFACE SETTINGS tab for the Snort interface, you can choose to send logs to the system log (which is syslog). You can also configure some of the metadata tags that are attached. So go to the INTERFACES tab in Snort, and then either double-click on the interface line in the table or click the edit icon (the little pencil) on the right side of the table row to bring up the INTERFACE SETTINGS tab. Within pfSense you can configure the system logs to be sent to a remote syslog server, if you want to do that.
  • OpenVPN showing twice under rules

    4
    0 Votes
    4 Posts
    555 Views
    stephenw10S
    Yes, that is correct. If you assign the server as an interface you have to restart the instance afterwards for the new settings to apply. You almost always want to have the rules on the assigned interface tab and not on the group OpenVPN tab. That is required for policy routing to create the firewall states correctly. Steve
  • Am I being attacked?

    29
    0 Votes
    29 Posts
    4k Views
    JKnottJ
    @bmeeks said in Am I being attacked?: The moral of this story (from the article) is don't open stuff like SSH on the WAN side of your firewall. It should be don't use ssh with a password. Use passwordless ssh instead. Ssh supports that. You create a public/private key pair, to allow access.
  • Rename network interface?

    12
    0 Votes
    12 Posts
    2k Views
    V
    @noplan said in Rename network interface?: OPT13 .... I suspect you deleted and recreated interfaces quite often.
  • 0 Votes
    35 Posts
    33k Views
    stephenw10S
    This is almost certainly not the same issue. Many, many things have changed since 2016! Please open a new thread with the actual crash report you're seeing. Steve
  • How to transfer RRD data from CE to Plus

    3
    0 Votes
    3 Posts
    470 Views
    T
    @stephenw10 Yes, I've tried deleting all the .rrd files in that folder, repeated the import of just the RRD Data from the old box with pfSense CE into the SG-3100. I can see the .rrd files get created in the folder, but still no data appearing on RRD Summary or Traffic Totals.
  • SSL generation

    3
    0 Votes
    3 Posts
    493 Views
    johnpozJ
    @stephenw10 said in SSL generation: cert with a longer lifetime that you control. Exactly openvpn does not care if the cert has a 10 year life.. There is little reason to change these certs for the sake of changing them, unless you feel they have been compromised. If so just revoke them and issue new. Or change them out on a schedule you come up with, but don't have to worry about if the schedule gets pushed here or there because its going to expire, etc.
  • Create CA cert for unraid

    9
    0 Votes
    9 Posts
    1k Views
    C
    @johnpoz My haprox cert is a wildcard cert *test.ca and in pfsense i created a Host Override as unraid.test.ca which points to the unraid server ip. By doing this, unraid.test.ca is only available via LAN as it is not registered on my domain dns. Also for my acme i have it set to auto renew that cert before it expires. Great suggestions, appreciate the tips :)
  • OpenVPN pfSense cannot ping router

    2
    0 Votes
    2 Posts
    345 Views
    C
    I got this working.. I created the opnvpn interface and then that showed up in the outgoing network interface under dns resolver which is had set as (ALL) and now everything works.
  • all services fail to start all packages gone

    10
    0 Votes
    10 Posts
    1k Views
    wgstarksW
    @stephenw10 said in all services fail to start all packages gone: Looks like this is the gw_leds script which it appears you're also running: https://forum.netgate.com/topic/165680/sg-3100-21-05-1-kern-ipc-maxpipekva-exceeded-see-tuning-7 Steve Thanks. I’ll follow that post.
  • onboard/discreet LAN/WAN interfaces

    4
    0 Votes
    4 Posts
    593 Views
    stephenw10S
    I assume you mean you're not doing any internal routing but are still routing between WAN and LAN? Otherwise you would have to be bridging WAN and LAN. Either way in that setup both WAN and LAN are carrying the same traffic so it really doesn't matter which way you assign the NICs. Steve
  • Do hosts list support "a.b.example.com"?

    2
    0 Votes
    2 Posts
    388 Views
    stephenw10S
    When you put FQDNs in an alias like that they are resolved by filterdns when the ruleset is built. Anything that the firewall can resolve should work correctly there. Steve
  • Bricked after Update 2.4.5-p1 to 2.5.2-RELEASE

    Moved
    11
    0 Votes
    11 Posts
    1k Views
    A
    @stephenw10 said in Bricked after Update 2.4.5-p1 to 2.5.2-RELEASE: Everything except checksum off loading should be disabled by default so I would look at LRO if you changed that. Steve I will leave the APU in place. The former device was cobbled together from spare parts anyway (but it worked for years...). Thank you for all the input.
  • pfTop in 2.5.0

    6
    0 Votes
    6 Posts
    477 Views
    NogBadTheBadN
    Do you have consecutive sections of zeros replaced with two colons ?
  • Sonicwall to pfsense - conversion tool

    11
    1 Votes
    11 Posts
    5k Views
    stephenw10S
    The situation is largely unchanged. The pro services team can convert an existing config from another firewall but it's a manual process for them. There is no tool for doing it. Steve
  • LAN randomly stops routing traffic with pfSense 2.4.2-RELEASE-p1

    3
    0 Votes
    3 Posts
    386 Views
    stephenw10S
    Mmm, 2.4.2p1 is really old. With the release of 21.05.1 though there should be much reason not to be on that now. If you absolutely need Snort (and can't use Suricata) for some reason you might want to stay on 2.4.5p1. Steve
  • Squid Proxy bypasses firewall rules

    3
    0 Votes
    3 Posts
    635 Views
    P
    @stephenw10 thanks yea I worked out my problem. Because I has a rule at the bottom of floating that blocked anything I didn't specifically allow out, I then was allowing WAN to HTTP/HTTPS for Squid and it was quick matching. I had to rejig that block all rule to avoid HTTP/HTTPS so that it allows that traffic by default (No quick rule allow needed for WAN) and then I catch any bad traffic with the explicit deny rules. Seems to work now.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.