• Problem with Software Client

    10
    0 Votes
    10 Posts
    898 Views
    S
    @johnpoz thanks a lot for your helping, i will contact the support,
  • Giving remote control access to few machines

    11
    0 Votes
    11 Posts
    1k Views
    johnpozJ
    @ashima said in Giving remote control access to few machines: They were just lucky enough not to get any attack That you are aware of - your whole network could be compromised currently if someone guessed your top secret user account and password to rdp in.. Since it was for vendor support it was prob something stupid simple ;) Restricting inbound connections from trusted ip. This is a good idea for sure..
  • Syslog Webgui Log View Option

    9
    0 Votes
    9 Posts
    992 Views
    vallumV
    @stephenw10 said in Syslog Webgui Log View Option: There is now a package update available with that change in it. You should see it in package manager. Let me know if you see any problems. Steve Thanks Steve, I'll update you soon.
  • 0 Votes
    11 Posts
    803 Views
    johnpozJ
    heheheeh - yeah running limiters going to kind of "limit" your speed ;) heheheeh ROFL!!! Well atleast you found the problem..
  • Is igmpproxy (igmpproxy-0.1_3,1) still broken?

    igmp igmpproxy
    4
    0 Votes
    4 Posts
    726 Views
    T
    To make matters worse, the debug version I created and compiled, works. Apparently there is a difference between the igmpproxy-0.2.1 in the freebsd repository (I didn't build that) and the same version when built with freebsd ports. So I was able to build an instance of 0.2.1 that works, but I'll never know what is wrong with those others.
  • 4G/3G Dongle Failover - Anyway to power down while on standby?

    8
    0 Votes
    8 Posts
    947 Views
    N
    @stephenw10 Ahh all good!! Really appreciate all your help.
  • Encrypted browser-Squid connection

    5
    0 Votes
    5 Posts
    1k Views
    stephenw10S
    @evilside said in Encrypted browser-Squid connection: but I don't care, almost nobody use that browser.
  • [Noob Need help] Any good Ethernet Nic for 2.4.4 [solved]

    3
    0 Votes
    3 Posts
    420 Views
    M
    @tim-mcmanus Ahh, Thanks :D, I might go for the spf since I can future proof it, or booth. Thanks again :)
  • DMZ bridged to WAN cannot reach LAN

    25
    0 Votes
    25 Posts
    2k Views
    stephenw10S
    I think the main point here is that the best practice is to store only the minimal amount of data required in the DMZ and limit access to anything on the LAN to only what is required. However you have to make some assessment of the risk. Is the git server going to be open to the world or only restricted source IPs? The term DMZ used here implies it is exposed and needs to be walled off from other subnets but that might not be the case. Or at least not in the traditional sense. Steve
  • Backup configuration remotely

    2
    1 Votes
    2 Posts
    269 Views
    stephenw10S
    It is. Yep, just use one of the methods shown there if you need to do it. Or just use Auto Config Backup: https://www.netgate.com/docs/pfsense/backup/autoconfigbackup.html Steve
  • Problem WAN

    17
    0 Votes
    17 Posts
    796 Views
    M
    @stephenw10 After three hours of constant download at 100mb/s there was no loss of connection, I hope it continues like this. At the next restart I will check. Thanks again for the help. EDIT: I confirm that I have solved the problem by replacing the realtek drivers included in pfsense.
  • Need help for Virtual ip

    3
    0 Votes
    3 Posts
    389 Views
    stephenw10S
    More likely something upstream is configured to expect your mail server to have 88:xx:129.147 as it's public IP and you have not added an outbound NAT rule to use that for traffic coming from the mail server. A 1:1 NAT rule would handle that both ways. Steve
  • Microchip® CryptoAuthentication Device

    2
    0 Votes
    2 Posts
    432 Views
    johnpozJ
    Have to say I agree company about security isn't using dnssec for their dns.. Which is really low hanging fruit to pick too.. dnssec is not that hard ;) It really is a shame that all domains are not doing it - the hardest part is registrar that actually supports it... Even though my understanding is its a requirement to be an actual accredited registrar.. I know when I fired up a domain to play with dnssec back in 2015, they had .xyz on sale and said they supported dnssec - yet took some emails to their support to actually get their implementation on their website to work.. And I looked around at the time namecheap didn't even support... From what I recall.. While its only a domain I use for my personal stuff, and use it for mostly testing - its not that hard to add stuff or maintain sign off on your records... I have a cron job that runs, and script I run when I add new records or edit them, etc.
  • Session cookie

    3
    0 Votes
    3 Posts
    595 Views
    stephenw10S
    Exactly, you cannot. In general pfSense will not allow any connections inbound from some external web server. Only responses from servers for which outbound connections have been opened are allowed. Steve
  • Load balancing not distributing evenly...

    3
    0 Votes
    3 Posts
    452 Views
    P
    @tim-mcmanus Thanks a lot Tim... i am going to read it carefully and will post results... Pedreter.
  • Auto config backup on URL alias update

    3
    0 Votes
    3 Posts
    343 Views
    G
    But actually this is not a change, because the Alias URL remains the same, could change the IPs in the list (for sure not every night, at least in my case), but a backup it's not needed because anyway when you will reuse it it will download again the updated list. If you consider the IP list a (potential) change, then a backup should be taken also when a DNS Alias it's resolved with another IP address, it's exactly the same thing.
  • PPPoe Client Goes Down after Any other Interface config change

    3
    0 Votes
    3 Posts
    569 Views
    S
    Same behavior related here. https://redmine.pfsense.org/issues/8512
  • Spontaneous corruption?

    7
    0 Votes
    7 Posts
    783 Views
    chrismacmahonC
    First step is to see why this is happening to you. I agree it's most likely related to the configuration/local setup of the devices. Before you reboot the device, you should navigate over to Status, System Logs, take note of the information there, try expanding it to a few thousand entries, there will be something noted in this area about what is causing your lack of internet access. I would suggest getting a console session going, our SG-2440 Manual has a great guide on gaining access to the console. What packages do you have installed on your device? If you run from the command prompt df -h how much disk space is there? The more information you can get to us, the better someone can assist you.
  • High RTT latency on wan [SOLVED]

    37
    0 Votes
    37 Posts
    17k Views
    stephenw10S
    @tejas said in High RTT latency on wan [SOLVED]: I am using Pfsense 2.3.5-release-p2(i386) on Intel Pentium G2020 @ 2.90GHz Why are you running 32bit on that CPU? You should be running 2.4.4 there really. About the only reason those interfaces would not show in the Firewall > Traffic Shaper > By interface tab is if they don't support ALTQ. You would have to check exactly what hardware they are to know for sure though. I would expect the Intel NIC to support it but their ix NICs do not. What are the actual port names listed? re0, re1, em0? pfBlocker and Squid do different things they should not interfere. But bare in mind connections coming from Squid will always have the default WAN as the source IP. pfBlocker can block connections on LAN before they reach squid if you have it configured to do so. Existing states are not removed when you change the ruleset. So if you want to move a client to use a different gateway you would have to kill any open states on the old gateway or just wait for them to timeout. Only new states will use the changed rule. It is accurate. If traffic is passing and you see no states there it is not being passed by that rule. If you want to do full SSL traffic inspection you have to install the generated CA on the clients there is no way past that. However you can do 'peek and splice' to filter by FQDN only. See: https://youtu.be/xm_wEezrWf4?t=637 If any of those alerts are against legitimate traffic you need to suppress them or disable the rule that is being triggered before you switch to blocking mode or you will block required traffic. https://www.netgate.com/docs/pfsense/ids-ips/setup-snort-package.html#alert-thresholding-and-suppression Steve
  • Access Pfsense website GUI and another website slowly when block port 443

    4
    0 Votes
    4 Posts
    474 Views
    stephenw10S
    What other rules do you have on the LAN? Is the GUI running on port 443? Do you see blocked traffic in the firewall log after disabling the rule? Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.