• How to script rules on OpenAppID to block torrents

    14
    0 Votes
    14 Posts
    2k Views
    bmeeksB
    I will clarify my statement by saying you can't do this on pfSense using the Snort GUI package. You can potentially set something up if you go totally command-line with Snort and do not use the GUI at all. The GUI package cannot support inline IPS mode. If you use the standalone binary, you can configure DAQ to use netmap IPS mode, but only if you are willing to use two actual physical interfaces and bridge them with a cross-over cable, or else put Snort and DAQ on a separate box that sits between your LAN and pfSense. None of this is easy to set up, and it would be something you would be on your own to configure and support.
  • CPU C States and latency

    1
    0 Votes
    1 Posts
    427 Views
    No one has replied
  • UPnP needs a restart almost every day.

    8
    0 Votes
    8 Posts
    2k Views
    T
    Not a thing. It just stops. The routing log is pretty desolate. I haven't found log entries anywhere else, though part of the problem is knowing what to look for .. and ending up going back through syslog to find them. It hasn't died since I posted yesterday and UPnP rules are still present.
  • Having LAN issues related to a new switch

    39
    0 Votes
    39 Posts
    3k Views
    johnpozJ
    Setting static anywhere... Unless your ISP is doing something really wonky, even dhcp from your ISP would stay the same.. And even if that doesn't - that is the whole point of dynamic dns. My comment was made towards the OP comment that he has need to get to his devices, etc.. so he sets a "static" ip on them.. This is lack of understanding of how dhcp actually works is all. Unless your connecting to some public network like at starbucks or something where there are hundreds or even 1000's of more devices using the network than what the dhcp scope is setup - unless your client actually relinquishes the lease or is offline for extended period.. Typically the client will maintain the same IP they have always gotten.. In a home setup with a handful of devices and a /24 scope.. Its almost impossible that a dhcp client would get a different IP then the first one it gets when first joining the network.. Unless old leases are removed from the dhcpd, and or dhcp server changes, etc. etc.. btw for clarity if I say set a static - I mean on the device, if done with dhcp then to me that is a "reservation" - this term static dhcp is an oxymoron...
  • Traffic Graphs

    4
    0 Votes
    4 Posts
    546 Views
    D
    Thank you Bruce. I can tell you that in version 2.4.4 it isnt fix it, I already have that version and still with the same issue.
  • Notification on Connection

    3
    0 Votes
    3 Posts
    419 Views
    H
    @KOM Right. Shouldn't be too hard to write a custom piece of code that simply created a pop up notification or a few beeps whenever a certain IP is logged. What you can do with this is limited only by your knowledge of php it seems.
  • 0 Votes
    11 Posts
    1k Views
    johnpozJ
    You normally don't use eap-tls in when you need to do such a thing.
  • LDAP Extended Query with Multiple Groups

    6
    0 Votes
    6 Posts
    13k Views
    L
    https://redmine.pfsense.org/issues/9527 might be of interest too for rfc 2307 enabled
  • Issue Disable interface vlan

    2
    0 Votes
    2 Posts
    273 Views
    jimpJ
    That shouldn't happen, but without more details, such as a crash report, it's impossible to say why it did. First things first you need to upgrade to a supported release, 2.4.4-p2.
  • Load Balancing DNS with relayd

    Locked
    16
    0 Votes
    16 Posts
    6k Views
    johnpozJ
    You don't need a ttl of 60 to load share.. They do it because they like lots and lots of queries because you get charged per query.. Set to 5 or 10 minutes.. 30 or so.. Come on 60 freaking seconds.. Lets get real.. I believe that is what they default too.. And people using them never update... The only reason you might ever get down to be a 60 second ttl is when your about ready to flip to another NS.. And you should really work that down from whatever your standard is, as you get closer to the switch over date and time, and then as soon as you flip over you would ramp it back up.. Another issue with current dns is that iot devices are not set to do any local caching - so every freaking time they want to go somewhere like every few minutes they have to query for it.. And if where they go has a 60 second ttl, its just nuts... No the dns cache would not be shared via ha pair - I don't think so.. doesn't make a lot of sense to be able to do that. Your not active active, your active/standby, etc..
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • postmap command

    11
    0 Votes
    11 Posts
    2k Views
    L
    solved i run squidGuard - C all to rebuild files database for sorry and thanks
  • Realtek RTL8111H drivers for FreeBSD

    9
    0 Votes
    9 Posts
    5k Views
    GertjanG
    Hi, You have a 1GB capable switch somewhere ? Put it between your modem and pfSense and check link speed again, both WAN cables.
  • pfSense Crash Report

    2
    0 Votes
    2 Posts
    346 Views
    stephenw10S
    Looks to be some issue with the bxe driver/NIC. This doesn't look ideal: bxe0: ERROR: Changing VLAN_HWFILTER is not supported! This is also bad: Sleeping thread (tid 100411, pid 62759) owns a non-sleepable lock That seems to be the problem. It looks like a software issue, same crash every time. You might try a 2.5 snapshot to get the FreeBSD 12 drivers. Though I don't see anything to specifically address this in the driver history: https://github.com/freebsd/freebsd/commits/master/sys/dev/bxe Steve
  • Skype on Pfsense

    4
    0 Votes
    4 Posts
    945 Views
    S
    @Azim Did you find any solution until now? because I am also not able to use skype while using transparent proxy... please let me know if you find any solution to got it working....
  • New User Help! Azure Pfsense, I Can't See Website

    18
    0 Votes
    18 Posts
    2k Views
    stephenw10S
    No worries.
  • 0 Votes
    5 Posts
    1k Views
    stephenw10S
    Seems like an issue with the device itself. What firmware version do you have?
  • So, I’m confused.

    30
    0 Votes
    30 Posts
    3k Views
    S
    @johnpoz I can sing it in R&B, Pop, Hip-Hop, and Country. Still working on Rap but it doesn't sound quite right... Maybe we should form a pfBand...
  • SONOS and Google home mini in different VLAN ( PfSense + Unifi AC-PRO )

    9
    0 Votes
    9 Posts
    3k Views
    johnpozJ
    @luckyzor said in SONOS and Google home mini in different VLAN ( PfSense + Unifi AC-PRO ): there are any solution without a physical manageable switch? Not any good ones - you could bridge interfaces as mentioned already... But you really should avoid that at all costs.. A smart switch that can do vlans is only around $40 USD.. Would be 8 port gig.. This would give you almost infinite flexibility in putting different devices or vswitches on different vlans. You for sure could find higher end switches with higher port density say off ebay or something.. But 8 port should give you what you need for sure.
  • Display DDM Values of GBICs

    2
    0 Votes
    2 Posts
    339 Views
    stephenw10S
    Use ifconfig -v to see the additional values for all interfaces. Some will show more with additional verbose switches. [2.4.4-RELEASE][root@7100.stevew.lan]/root: ifconfig -v ix0 ix0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8400b8<VLAN_MTU,VLAN_HWTAGGING,JUMBO_MTU,VLAN_HWCSUM,VLAN_HWTSO> ether 00:08:a2:0e:a5:91 hwaddr 00:08:a2:0e:a5:91 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect status: no carrier plugged: SFP/SFP+/SFP28 10G Base-SR (LC) vendor: FINISAR CORP. PN: FTLX8571D3BCV-CK SN: ANL1C1V DATE: 2012-11-21 module temperature: 34.26 C Voltage: 3.31 Volts RX: 0.00 mW (-inf dBm) TX: 0.63 mW (-1.96 dBm) Steve
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.