• Unable to download Mac / IOS updates

    9
    0 Votes
    9 Posts
    8k Views
    KOMK
    Teaching you how to use Wireshark is beyond the scope of what I'm willing to do here.  Sorry, but it's a big topic.  I know about enough to be dangerous after having worked my way through this book: https://www.amazon.ca/Troubleshooting-Wireshark-Performance-Problems-Solution-ebook/dp/B00I2VL1WA/ There should be YouTube videos that can get you started, or feel free to post your .cap file here for the gang to look at and assist with.
  • Future of nanoBSD images for CF Cards

    8
    0 Votes
    8 Posts
    2k Views
    S
    can you suggest any hardware x64 to run it not so much pricey? Axiomtek NA342D or Axiomtek NA342R
  • Netgate SG-8860 LAN interface acting up

    2
    0 Votes
    2 Posts
    503 Views
    H
    Update: I've just upgraded to pfsense 2.3.2 release p1 and the unit rebooted and then i could not access some sites once more. I disabled and re-enabled the lan0 interface and everything was fine again. This a bug?
  • Serious problems with Realltek Nic. Help!!

    6
    0 Votes
    6 Posts
    1k Views
    T
    ok i see
  • 0 Votes
    11 Posts
    1k Views
    Z
    @KOM: become part of a botnet That is something I haven't thought about! But I still see no evidence of any remote attacks on my version of pfsense.
  • Getting Started and CLI configurations

    4
    0 Votes
    4 Posts
    732 Views
    A
    @dotdash: If it's not on the menu, you have to do it through the gui. Anything added from the shell will not survive a reboot/filter reload. Thanks!
  • ELK and PF 2.3

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blocking Searches in Google by KeyWords

    8
    0 Votes
    8 Posts
    4k Views
    KOMK
    I think what is next of that is optional, isn't? Yes and no.  If you don't want your users going around the proxy just by disabling it in their LAN connection settings then this step is mandatory. I haven't worked through aGH's guide.  I use squid in explicit mode with WPAD.  I only use it as a platform for URL filtering, not caching at all.  Everything works for me. Do you see any evidence that https is being processed by squid?
  • RTP RTCP load balance

    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Bridging WAN with a VLAN

    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • Update check & package install behind MITM proxy?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IGMP Trouble in 2.3.2

    1
    0 Votes
    1 Posts
    496 Views
    No one has replied
  • Clients on different switches cannot talk to each other

    6
    0 Votes
    6 Posts
    2k Views
    johnpozJ
    Why are you calling them layer 3 switches if your just using them in layer 2? if you are not routing on them, then they are just layer 2.  what is trying to talk, stuff in the same vlan or between vlans.  If pfsense is routing between the vlans then you need to allow for the firewall rules.
  • 4 Vlans - Use L3 Switch or PfSense?

    20
    0 Votes
    20 Posts
    8k Views
    johnpozJ
    vswitch in esxi can not be layer 3 switches.. They can not route.  And no you shoudn't be using layer 3 switches (downstream routing) in your network unless you have specific need for routing at wirespeed vs control.  And when you do this then you need to connect your downstream routers with a transit network or your going to run into asymmetrical routing issues.
  • Avocent DSR4030 KVM JNLP

    2
    0 Votes
    2 Posts
    3k Views
    N
    In general it was suggested to white list (snort stuff) https://forum.pfsense.org/index.php?topic=36228.msg186815#msg186815 suppress gen_id 122, sig_id 3 suppress gen_id 122, sig_id 23 I just turned off snort I found that I had to change one additional setting in addition to jdk.tls.disabledAlgorithms. #jdk.certpath.disabledAlgorithms=MD2, MD5, RSA keySize < 1024 jdk.certpath.disabledAlgorithms=MD2 #jdk.tls.disabledAlgorithms=SSLv3, RC4, MD5withRSA, DH keySize < 768 jdk.tls.disabledAlgorithms=SSLv3, RC4 This is for jre1.8.0_73. Edit the Java.security file found \Program Files (x86)\Java\jre1.8.0_65\lib\security and restart
  • Create a DMZ in VirtualBox using two pfSense instences

    9
    0 Votes
    9 Posts
    10k Views
    KOMK
    If so HOW do I set it up ? Add another interface in VB, on intnet2 or whatever.  Then in pfSense (you're driving me nuts with pf Sence btw ;D ) you just configure the OPT1 interface from the console.
  • Spotify Connect cross VLAN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Updateable alias based on multiple URL aliases

    3
    0 Votes
    3 Posts
    761 Views
    C
    Best solution I can find, which isn't too bad for regional CIDR ranges, is to just manually update the network alias (which has multiple table URLs) monthly. Not ideal for more frequent lists but works well for my application. Cheers for the help.
  • Hard Reset Corrupting Config

    3
    0 Votes
    3 Posts
    1k Views
    P
    @YipYip: Was just wanting to understand that is itt normal that pfsense will or can corrupt itself if you hard reset the box. Is this normal or is there an underlying hardware compatability problem ? (I am running intel i350 and i5 8 gig) I'd say that it's very far from normal but of course always a risk if doing hard resets. Unfortunately I've had many (>10) unplanned power failures over the last 3 years because of initial lack of an UPS and then lately had one UPS malfunctioning several times until I managed to correctly diagnose the issue. I've never experienced any configuration corruption. In my opinion, if you expect frequent hard resets of your firewall that's probably a more important problem to focus on solving than the possibility of the configuration to become corrupted. If it is normal how do you backup/restore if this occurs without too much pain ? I've never had to use it but I'd expect the Diagnostics, Backup/Restore option to be usable.
  • How do I block ads using pfsense?

    9
    0 Votes
    9 Posts
    13k Views
    G
    maybe members of this board,  who are paid employees,  are helping anti block advocates  to assert their view of things…..?
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.