• Accidentally turned off Lan interface

    3
    0 Votes
    3 Posts
    3k Views
    L
    I did something similar just this week. My work around was to go to the console and "Restore recent configuration" Option 15. Think I had to reboot it after that too but it worked.
  • 0 Votes
    4 Posts
    813 Views
    L
    OK I followed the original instructions and got the stable branch of the Unifi controller, which was fixed to major version 4. You have to explicitly set the repo to version 5 to get the latest. The latest controller has the ability to "Enable RADIUS assigned VLAN", which is what I wanted, so all good. However, it still isn't passing through the tagged VLAN attribute. I guess before I figure that out I should figure out another problem - I have assigned a test client device a static IP in Freeradius/Mysql. The Framed-IP-Address attribute contains the value I want and this is correctly returned in the Access-Accept message from the Freeradius server (along with the VLAN tag). However, pfSense is overwriting the IP with a DHCP-assigned IP from within the pfSense LAN's range. The Unifi AP has "Using DHCP" set on it. I think that means it's acting as a client, not as a DHCP server. I can also force it to have a static IP from within pfSense's range, but I haven't tried that. It's actually getting a statically set IP from pfSense, which I specified in pfSense's DHCP server page. I have no explicit setting in pfSense's LAN DHCP server for the client device I'm testing with (the one being authorized by Freeradius). In Freeradius (as I mentioned) it's getting a static IP but in pfSense's DHCP leases it gets a totally different dynamic IP and all traffic is to/from the dynamic IP. Is it possible that pfSense ignores the Framed-IP-Address attribute? Should I be looking at pfSense, Freeradius or the AP to fix this?
  • WebGUI Hang Up after assign LAN interfaces

    4
    0 Votes
    4 Posts
    648 Views
    KOMK
    Well, considering you have provided almost nothing for information, all we can do is wild guesses.  How do you recover, reboot?  Anything in the System log at the time of the hang?  Is it possible that NIC has a problem?
  • Unable to download Mac / IOS updates

    9
    0 Votes
    9 Posts
    8k Views
    KOMK
    Teaching you how to use Wireshark is beyond the scope of what I'm willing to do here.  Sorry, but it's a big topic.  I know about enough to be dangerous after having worked my way through this book: https://www.amazon.ca/Troubleshooting-Wireshark-Performance-Problems-Solution-ebook/dp/B00I2VL1WA/ There should be YouTube videos that can get you started, or feel free to post your .cap file here for the gang to look at and assist with.
  • Future of nanoBSD images for CF Cards

    8
    0 Votes
    8 Posts
    2k Views
    S
    can you suggest any hardware x64 to run it not so much pricey? Axiomtek NA342D or Axiomtek NA342R
  • Netgate SG-8860 LAN interface acting up

    2
    0 Votes
    2 Posts
    503 Views
    H
    Update: I've just upgraded to pfsense 2.3.2 release p1 and the unit rebooted and then i could not access some sites once more. I disabled and re-enabled the lan0 interface and everything was fine again. This a bug?
  • Serious problems with Realltek Nic. Help!!

    6
    0 Votes
    6 Posts
    1k Views
    T
    ok i see
  • 0 Votes
    11 Posts
    1k Views
    Z
    @KOM: become part of a botnet That is something I haven't thought about! But I still see no evidence of any remote attacks on my version of pfsense.
  • Getting Started and CLI configurations

    4
    0 Votes
    4 Posts
    732 Views
    A
    @dotdash: If it's not on the menu, you have to do it through the gui. Anything added from the shell will not survive a reboot/filter reload. Thanks!
  • ELK and PF 2.3

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blocking Searches in Google by KeyWords

    8
    0 Votes
    8 Posts
    4k Views
    KOMK
    I think what is next of that is optional, isn't? Yes and no.  If you don't want your users going around the proxy just by disabling it in their LAN connection settings then this step is mandatory. I haven't worked through aGH's guide.  I use squid in explicit mode with WPAD.  I only use it as a platform for URL filtering, not caching at all.  Everything works for me. Do you see any evidence that https is being processed by squid?
  • RTP RTCP load balance

    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Bridging WAN with a VLAN

    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • Update check & package install behind MITM proxy?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IGMP Trouble in 2.3.2

    1
    0 Votes
    1 Posts
    496 Views
    No one has replied
  • Clients on different switches cannot talk to each other

    6
    0 Votes
    6 Posts
    2k Views
    johnpozJ
    Why are you calling them layer 3 switches if your just using them in layer 2? if you are not routing on them, then they are just layer 2.  what is trying to talk, stuff in the same vlan or between vlans.  If pfsense is routing between the vlans then you need to allow for the firewall rules.
  • 4 Vlans - Use L3 Switch or PfSense?

    20
    0 Votes
    20 Posts
    8k Views
    johnpozJ
    vswitch in esxi can not be layer 3 switches.. They can not route.  And no you shoudn't be using layer 3 switches (downstream routing) in your network unless you have specific need for routing at wirespeed vs control.  And when you do this then you need to connect your downstream routers with a transit network or your going to run into asymmetrical routing issues.
  • Avocent DSR4030 KVM JNLP

    2
    0 Votes
    2 Posts
    3k Views
    N
    In general it was suggested to white list (snort stuff) https://forum.pfsense.org/index.php?topic=36228.msg186815#msg186815 suppress gen_id 122, sig_id 3 suppress gen_id 122, sig_id 23 I just turned off snort I found that I had to change one additional setting in addition to jdk.tls.disabledAlgorithms. #jdk.certpath.disabledAlgorithms=MD2, MD5, RSA keySize < 1024 jdk.certpath.disabledAlgorithms=MD2 #jdk.tls.disabledAlgorithms=SSLv3, RC4, MD5withRSA, DH keySize < 768 jdk.tls.disabledAlgorithms=SSLv3, RC4 This is for jre1.8.0_73. Edit the Java.security file found \Program Files (x86)\Java\jre1.8.0_65\lib\security and restart
  • Create a DMZ in VirtualBox using two pfSense instences

    9
    0 Votes
    9 Posts
    10k Views
    KOMK
    If so HOW do I set it up ? Add another interface in VB, on intnet2 or whatever.  Then in pfSense (you're driving me nuts with pf Sence btw ;D ) you just configure the OPT1 interface from the console.
  • Spotify Connect cross VLAN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.