• userland calling deprecated sysctl, please rebuild world

    25
    0 Votes
    25 Posts
    2k Views
    stephenw10S
    Nice find.
  • Host OverRide for UnFi APs

    47
    0 Votes
    47 Posts
    8k Views
    stephenw10S
    Ah, well similar deal if the VPN client is routing all your traffic over the VPN.
  • Block most ports

    3
    0 Votes
    3 Posts
    474 Views
    stephenw10S
    Do you mean outgoing connections? You can allow only the ports you need. You will find there are a lot of ports you didn't realise you needed for most environments. Steve
  • Route traffic out and back in

    3
    0 Votes
    3 Posts
    482 Views
    stephenw10S
    Yeah, DNS override or NAT reflection: https://docs.netgate.com/pfsense/en/latest/recipes/port-forwards-from-local-networks.html Steve
  • AWS pfSense+ Loopback interface

    8
    0 Votes
    8 Posts
    841 Views
    stephenw10S
    Yes, the AWS AMI deploys with mobile IPSec configured but disabled. It has that VIP set to allow mobile IPSec clients to use it for DNS. Steve
  • Traffic Graphs

    6
    1 Votes
    6 Posts
    699 Views
    stephenw10S
    It's always by an interface perspective. How else could it be?
  • OPT1 needs LAN DNS access

    109
    0 Votes
    109 Posts
    20k Views
    L
    @johnpoz LOl, correct :). Thanks very much for all of your input. Even if I am not able to commit it all to memory, I have these threads to come back to when I'm stuck.
  • Weird DHCP server issue.

    9
    0 Votes
    9 Posts
    912 Views
    stephenw10S
    Clear those alerts and reload the filter in Status > Filter Reload to make sure the current ruleset is loading. Those pfBlocker errors are quite common at boot though and not usually a problem. Steve
  • Do the OpenSSH 7.9 CVEs apply to pfSense?

    6
    0 Votes
    6 Posts
    750 Views
    johnpozJ
    @skilledinept said in Do the OpenSSH 7.9 CVEs apply to pfSense?: -to see how readily is info like this available to scanner. you could turn off the banner, Not sure if pfsense allows for that in the gui? But if your allowed to talk to the ssh and try and negotiate a connection to "auth" you would still be able to get info like what algos and ciphers are possible. You could edit the sshd conf directly, but that would just get reverted on update, etc. Security scanners can be very useful - and fun even. But a lot of what they report really needs to be taken with a grain of salt, if not a whole freaking tablespoon of it ;) But it did do its job - it got you curious, and looking into, and now you prob make for a more secure setup even if what it had reported wasn't really valid ;)
  • Delete a permanent ARP entry when pFSense refuses to do so.

    7
    0 Votes
    7 Posts
    1k Views
    B
    @johnpoz many thanks I shall take it on the chin and update .... will see how things play after that - I guess I took the 'you're on the latest version' for granted.
  • Migrating existing dnsmasq into pfSense

    4
    0 Votes
    4 Posts
    550 Views
    L
    I've created a script to convert the dnsmasq.conf dhcp-host to XML to insert into the config file. I then read it in with vi. It's mostly manual. I also told the dns to include the static dhcp entries. I can now resolve the local names and I hope the DHCP works. I won't know for a few hours.
  • WAN optimization/acceleration

    ipsec ipsec vti qos slow throughput proxy
    16
    0 Votes
    16 Posts
    3k Views
    N
    @rtw915 said in WAN optimization/acceleration: Now the SQL team needs me to find a way to improve SQL linked server transfer rates to synchronize transactions. This will bring you back to the initial wan accelerator solution. The only other possible solution is to redesing the db subsystem, utilizing some way of sql replication, taking into consideration propagation delays
  • WhatsApp is showing connecting but can't connect

    2
    0 Votes
    2 Posts
    327 Views
    GertjanG
    @mike_broxt said in WhatsApp is showing connecting but can't connect: After setting up a NetgateSG-1100 Go back to default, and redo your setting up sequence. Do it step by step - and test each step. As soon as Whatapp breaks, undo the last step. Done !?! pfSense doesn't block whatsapp out of the box.
  • Netgate2100 not getting WAN

    Moved
    4
    0 Votes
    4 Posts
    559 Views
    F
    @steveits Yeah, I'll clear the field and see if that makes a difference. And thanks for confirming my thoughts on the SSHguard. :)
  • pfSense 2.5.2 keeps crashing periodically

    13
    0 Votes
    13 Posts
    2k Views
    stephenw10S
    Hmm, I wonder what that's causing that would trigger this...
  • What's a pfSense equivalent to standard linux minicom?

    6
    0 Votes
    6 Posts
    950 Views
    MrPeteM
    @jknott said in What's a pfSense equivalent to standard linux minicom?: It uses a 2400N81 weird serial cable protocol. That isn't weird, it's just slow. It's the cable that's weird ;) -- Designed so if you plug in a standard 9 pin serial, the UPS shuts down My pfsense box runs 8N1 @115.6K. 8N1 is pretty much standard for anything faster than the 110B you'd find on a Teletype machine. That's 8 data bits, no parity and 1 stop bit. BTW, I started in telecom as a bench tech overhauling Teletype machines, where the ASCII models ran 110B... Oh how I know! I used the Teletype and other slow links...we had one at home for my dad's R&D work when I was in jr/sr high school. Graduated to a 300 baud Silent 700 after a while. I had unlimited remote access to the mainframe. Pushed that and paper tape and punch cards out of the way during college. Built a bunch of "glass teletypes" -- adm-3a -- for our university Low Overhead Timeshare System. (They sold as a kit for $200 less than pre-built... paid me $50 to assemble. They assumed $3 an hour and 16 hours, but soon I had that reversed: 3 hr build time, so $16 an hour. Not bad pay for a freshman in 1975 :) )
  • reset anti-lockout rule

    8
    0 Votes
    8 Posts
    1k Views
    stephenw10S
    That looks fine for general access. You don't really need those top two rules, the pass-all rule covers that traffic. The anti-lockout rule will be on your VLAN10 interface. Steve
  • Azure VPN > Head Office > OpenVPN - No Access

    5
    0 Votes
    5 Posts
    562 Views
    T
    That was it! I had everything set up on pfSense after adding the P2, but the Azure VNET wasn't aware of the 10.8.0.0/24 address space. Thanks Stephen.
  • Youtube app can't play , Please help

    2
    0 Votes
    2 Posts
    201 Views
    stephenw10S
    How do you have Wireguard configured? Is the traffic using it? Steve
  • Datadog agent on Pfsense/freeBSD

    1
    0 Votes
    1 Posts
    777 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.