• Restoring Virtual IP (CARP) settings "only"?

    3
    0 Votes
    3 Posts
    1k Views
    H
    @doktornotor: Backup the config, edit the XML as required, restore the config? I actually wanted to avoid that, as it becomes a bit painful to edit the big file, while it could've been simpler to just restore (like for the DHCP/Interfaces/VLANs) the specific part, or know that it'll get restored with eg the Interfaces
  • Port speed and duplex issue

    5
    0 Votes
    5 Posts
    2k Views
    DerelictD
    Realtek NIC? The drivers are unreliable where hard-setting like that in certain cases I think. But if it's working and the interface is not taking errors you are probably OK.
  • Client PC's internet connection timeouts

    1
    0 Votes
    1 Posts
    405 Views
    No one has replied
  • Network HiccUps

    5
    0 Votes
    5 Posts
    1k Views
    G
    Yesterday it did it once every 20 or 30 mins, i am still wondering what would that be I am a VoIP providor, so i know is not me as a carrier, we now fired a lot of people and we are down to 45 agents, we use codec G729 I Just need to know if there is any tool to log traffic on a network, store destination and bandwidth speed at a particular time, so i can trace it down better I am a newbie, so, guidance will be appreciated Thanks so much !!! [image: Hiccups.png] [image: Hiccups.png_thumb]
  • Ram requirement to run 64bit pfsense 2.3.2

    4
    0 Votes
    4 Posts
    4k Views
    KOMK
    Yes, it's more than enough.
  • Allowing PC access to only specified WebSites

    3
    0 Votes
    3 Posts
    632 Views
    V
    You have also to grant DNS access to the client.
  • Sleep question

    2
    0 Votes
    2 Posts
    567 Views
    V
    Maybe the result of a power outage? pfSense doesn't go in sleep mode, of course.
  • Connection Dropping | Watchguard Firebox x550e

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Export darkstat data to file

    2
    0 Votes
    2 Posts
    934 Views
    P
    Did you ever find a solution to this?
  • Configuration Query

    3
    0 Votes
    3 Posts
    631 Views
    Z
    Many thanks for your reply. I plan to try this in the next week or so.. I'll post back how I get on. Regards
  • Manage the VOIP and TOIP service

    6
    0 Votes
    6 Posts
    1k Views
    ?
    I suggest to consider all the voice devices/services completely separately from the router. You could set up and use the SIP-Proxy on pfSense You could set up the asterisk or FreePBX packet too Or you install asterisk or FreePBX on an Raspberry PI 3.0 together with Linux as the VOIP appliance! All services running on the pfSense could be narrowing down the entire throughput and/or causing problems. So if this VOIP will be outside you may have enough power to run Snort or Suricata on the pfSense appliance.
  • Web Server Access

    2
    0 Votes
    2 Posts
    2k Views
    D
    Beyond a NAT rule on WAN, this has nothing to do with pfSense. You need to configure your Netgear router to know where to send packets.
  • Add a Guest WIFI using 6-port Netgate & unmanaged switch

    3
    0 Votes
    3 Posts
    876 Views
    ?
    We have a staff WiFi and want to add a guest WiFi. Do we have to buy a VLAN-capable managed switch, or can we use a spare pfSense eth port? The WLAN APs should be having VLAN support, so you could set up a VLAN for private (staff) one and a guest network. If there will be a domain or AD/DC managed network at the worksplace you could also high up the security for the entire network, by using something such as; LDAP Server or role on MS Windows Server for wired devices Radius Server or role on MS Windows Server or Linux Server for all WiFi devices (staff) Captive Portal on the pfSense for all WiFi clients (guest network) VLANs with his own subnet –192.168.1.0/24 staff WiFi -- 192.168.2.0/24 for guests WiFi -- 192.168.3.0/24 printers -- 192.168.4.0/24 PCs -- 192.168.5.0/24 servers and so on..... Current cfg: -pfSense 2.3.2 -Netgate 6-port, Port1:GW1/Comcast, Port2:GW2/AT&T, Port3:LAN/172.16.30.1 Would be nice to know now your budget here in that game play! -24-port unmanaged GbE switch, LAN Would be able to get a Cisco SG200-24P or Cisco SG300-24P switch likes you are able to pay or need it. The SG300 is a layer3 switch that is able to route the VLANs by it self and mostly with wire speed! -(4) EdiMax CAP1200 APs, (1) is the array controller and (3) are APs within the array, Staff WiFi Are they VLAN capable? -Windows Server DHCP server, 172.16.30.20 serving 172.16.30.x (can use pfSense's DHCP if rqd) Would be nice to see some other security roles on that server! -8-port GbE PoE switch for the APs, unmanaged. Connects to the (4) CAP1200 APs and to the 24-port LAN switch And also here you might be able to handle that traffic with a smaller variant of that named above switches I was guessing! SG200-10P or SG300-10P. Steps to add an isolated Guest WiFi ???? Create on the pfSense some VLANs and also on the Switch and then on the WiFi APs! They must be tagged between the pfSense and the Switch and also between the Switch and the WiFi APs, because there should be holding then even 2 VLANs each for a WiFi location one for the staff and one for the guests. -Cfg EdiMax CAP1200 APs for STAFF VLAN10 and GUEST VLAN20 (choose tagged opt, yes??) There are two available scenarios: You will need VLAN capable Switch and WLAN APs Connected over a PoE Switch that is capable of VLANs You will need only VLAN capable WiFi APs You might connecting the WiFi APs directly to the pfSense appliance Please not the VLAN1 is the default VLAN on many switches so it should be for the admins only! It would be also making many sense to activate the client isolation for the guest and staff WiFi VLAN because then all devices are not able to have a look on the other devices inside of that VLAN. -8-Port PoE AP switch, move eth that was going to 24-port LAN switch so now goes to Netgate eth Port4 Is that PoE Switch VLAN capable? Are the WiFi APs multi-VLAN capable? There would be two common ways to go, pending on what the switches and WiFi APs are able to do and also based on your budget. 1. pfSense is routing the entire VLANs and you may only need a layer2 Switch 2. The Switch is routing the entire VLANs and the pfSense is holding the Captive Portal for guests and the Windows Server has a radius server role installed that is securing the WiFi clients for the staff. For sure there are many other ways out there to go with but this both might be the most common ways. Get a SG200-24P (Layer2) pfSense is routing then the VLANs or SG300-24P (Layer3) the switch it self will then routing the entire VLANs and connect them all to that switch!
  • OSSEC Agent for pfSense ?

    10
    0 Votes
    10 Posts
    9k Views
    ?
    You make an interesting argument - and I'm not saying you're wrong. It is not only an argument, this is more pending on the circumstance that this both IDS systems are doing not the same thing!!! One is watching and sniffing in the network or the network traffic it self and the other one is watching on the host OS of an Server, PC or other devices watching their registry, file system or other elementary or urgent points in that OS. However, your definition of a "router" vs a "server" seems at odds. What here should be better matching is perhaps something such as TripWire or something else similar to that but not a Host IDS (HIDS). One thing is OS related and the other one is network related or pointed. The Server has an OS that is perhaps hardened the firewall or router OS (firmware) must be hardened. For example: what is the difference between a pfSense device running an OpenSSH endpoint vs a server running the same thing? pfSense is a firewall distribution (but here working likes a firmware of an network device) and let us say CentOS & SoftEtherVPN are an OS & Software. Their fore what you are asking for should be matching more well this software or perhaps able to realize combined installed on an appliance; fail2ban DenyHost TripWire How do you make the judgement in this case as to which device warrants an OSSEC agent? Its not me, you should perhaps read the statements and jobs that the software coder where telling their clients and perhaps too you could read about the differences NIDS and HIDS. OSSec getting started
  • WAN GW is indicated down after setup change, but it's up

    6
    0 Votes
    6 Posts
    930 Views
    ?
    Btw. my PPPoE IP starts with 79 and the GW starts with 217. Might this be the reason Edit: Just got an IP from the 217 subnet so, this is not the reason. Also I can't ping the GW at all when I'm not connected to a VPN. Any further help ?
  • Wake On Lan All dhcp leases via shell

    1
    0 Votes
    1 Posts
    629 Views
    No one has replied
  • Monitoring Traffic WLAN Interface per IP

    1
    0 Votes
    1 Posts
    958 Views
    No one has replied
  • MOVED: Time drift/system clock too fast on a PFSense VM

    Locked
    1
    0 Votes
    1 Posts
    372 Views
    No one has replied
  • Weird - openSSL running better without hardware crypto?

    8
    0 Votes
    8 Posts
    1k Views
    R
    Thanks again for the replies everyone. I'm learning a lot (and reading Mastering pfSense to try to get the best out of it). I'm currently considering upgrading the APU2C4 to a Dell PowerEdge T20 (Xeon E3-1225 v3), which should handle our line speed for VPN easily. The APU handles our 200Mbps ISP speed (no VPN) without even breaking a sweat, just a few % CPU, but it'd be nice to offload the VPN to the router/firewall rather than having multiple locally connected clients at home.
  • Antivirus filter / Malware

    6
    0 Votes
    6 Posts
    4k Views
    S
    Cool thanks! I stopped it then started it again. Now it seems ok!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.