• Webgui and SSH listening on wrong ip

    27
    0 Votes
    27 Posts
    4k Views
    3
    @Derelict: somehow got automatically converted Sigh. well they weren't changed by me, i'm not on site, if you're sighing then i imagine the guy who moved it must've done something, I'm just trying to figure it out remotely after the fact, in which I have now succeeded thanks to your help.
  • Pfsense 2.3.2 ( please help )

    5
    0 Votes
    5 Posts
    1k Views
    S
    Since you said you are fumbling through Snort/Squid, etc trying to learn them, do yourself a favor and read through the Snort Rules under the Categories Tab of the interface.  Some in there may not pertain to your organization.  The best security would probably be to have them all on but categories like "Games" would likely load unnecessary rules and put extra overhead on the system.  I'm not sure why you wouldn't want people playing StarCraft in the office but you don't need every packet evaluated against those rules even if you didn't. :)  Chat could be disabled if you're not having a problem.  No on-prem email server?  Consider disabling POP or SMTP.  The more you can disable the better the system should perform, especially on config reloads.  By default we have like 18 groups disabled when we install at a clients and add some back in if they need.  And make sure to add supressions or your logs will overflow with useless info.  Search around here and you should find some good info on those. Also, know that squid, with transparent HTTP proxy enabled, works pretty well out of the gate but only on HTTP traffic, not HTTPS traffic.  If you want HTTPS filtering then you'll have a lot more to work through.  Add some extra definitions into the Freshclam section of Antivirus under Squid.  Search around here for SaneSecurity as we had a thread with that info floating around not long ago.  It'll greatly increase the effectiveness. Once you have things set up, make sure you try some speed tests and downloaders and Quickbooks and Firefox.  It has been my experience that snort blocks them.  You can easily add the exclusions from the Rules and Block tabs of Snort.  You may also want to consider altering the SquidGuard block pages to something that reflects your organization and your policy as well as information on who and how to contact in the event of a false positive.  Also check things like LogMeIn and GoToMeeting to see if they have problems getting through your new Proxy.  With all that addressed you should have things mostly under control. Most of all, Good Luck!  Personally, I'd put your new filter outside of your Firewall if you could as it likely has a lot more power than the ASA (they are generally over featured and under powered) to free its resources up, but I'm not sure exactly how you'd do that without long consideration.  It's probably easier to have it on the LAN and force all traffic to filter through it.
  • SFTP being advertised over Bonjour from pfSense box?

    9
    0 Votes
    9 Posts
    2k Views
    K
    It's not a false positive, the AVAHI service on your pfSense is really advertising SFTP even if you don't have the SSH service running. To turn it off you have to edit the AVAHI configuration.
  • Unable to check for updates

    1
    0 Votes
    1 Posts
    429 Views
    No one has replied
  • Request to pfSense.localdomain timed-out

    32
    0 Votes
    32 Posts
    7k Views
    T
    my pfsense ip is 192.168.2.1 i tried using isp dns and google ip 8.8.8.8 all websites open perfect but one new problem cant ping any thing other then google dns and isp provided dns ip. it looks like they are restricting us from using third party dns and not allowing us to ping any ip what wrong dig :( im so frustrated you asked me for "dig @pfsenseIP www.whatever.com" lubuntu@lubuntu-:~$ dig @192.168.2.1 www.facebook.com ; <<>> DiG 9.10.3-P4-Ubuntu <<>> @192.168.2.1 www.facebook.com ; (1 server found) ;; global options: +cmd ;; connection timed out; no servers could be reached lubuntu@lubuntu-:~$ Tushars-MacBook-Pro:~ tushar$ ping 208.67.222.222 PING 208.67.222.222 (208.67.222.222): 56 data bytes Request timeout for icmp_seq 0 Request timeout for icmp_seq 1 Request timeout for icmp_seq 2 Request timeout for icmp_seq 3 Request timeout for icmp_seq 4 ^C --- 208.67.222.222 ping statistics --- 6 packets transmitted, 0 packets received, 100.0% packet loss Tushars-MacBook-Pro:~ tushar$ ping 8.8.8.8 PING 8.8.8.8 (8.8.8.8): 56 data bytes 64 bytes from 8.8.8.8: icmp_seq=0 ttl=58 time=8.675 ms 64 bytes from 8.8.8.8: icmp_seq=1 ttl=58 time=11.394 ms 64 bytes from 8.8.8.8: icmp_seq=2 ttl=58 time=10.896 ms ^C --- 8.8.8.8 ping statistics --- 3 packets transmitted, 3 packets received, 0.0% packet loss round-trip min/avg/max/stddev = 8.675/10.322/11.394/1.182 ms
  • Packetfence

    2
    0 Votes
    2 Posts
    1k Views
    DerelictD
    I think you might be on the wrong forum.
  • NAT'ing external port on VIP to internet LAN IP

    8
    0 Votes
    8 Posts
    1k Views
    K
    You don't set source port requirements in the NAT rules. What the rule is now saying is "Perform the RDR only if the source port in the incoming packet is 80" (and of course the other requirements have to be met as well). This is never going to be true for regular HTTP traffic arriving to your end, the source port is going to be a randomly chosen port from range 1024:65535.
  • Reboot Stuck at "Syncing disks, vnodes remaining…0"

    3
    0 Votes
    3 Posts
    2k Views
    W
    thank you
  • PfSense affected by recent Linux kernel vulnerability (Dirty Cow)?

    4
    0 Votes
    4 Posts
    1k Views
    S
    Correct, Dirty COW only affects Linux.  BSD's (Net/Open/Free)BSD are not affected because they are not Linux.
  • Squid proxy bypass private ip address

    2
    0 Votes
    2 Posts
    2k Views
    KOMK
    You can configure that on the client, or if you're using WPAD you can include the IP ranges and DIRECT keyword.  If you're using Transparent mode, you can use the Bypass Proxy for These Destination IPs option on squid's General page.  Lastly, the proper forum for squid & squidguard questions is the Cache/Proxy forum.
  • 802.1p/q pfsense setup

    77
    0 Votes
    77 Posts
    43k Views
    R
    Hi folks, Wondering if anyone is using Cisco SMB switch for the QoS setup for the Google fiber.  If so, it would be much appreciated if the setup/configuration can be shared. -rsa
  • New to pfSense - block facebook and youtube

    2
    0 Votes
    2 Posts
    2k Views
    J
    https://www.google.co.za/url?sa=t&rct=j&q=&esrc=s&source=video&cd=2&cad=rja&uact=8&ved=0ahUKEwjinL_jqPjPAhWFF8AKHZbGCg0QtwIIJjAB&url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DnMMFxn7Z3nk&usg=AFQjCNF3_0_xk3YlNLxCwbp_UcTtuWdtyw&sig2=qXkDLFwOIuOzdye8MLpygA&bvm=bv.136593572,d.bGg
  • Captive Portal and Squid logging via AD username for BYOD

    2
    0 Votes
    2 Posts
    650 Views
    M
    Please read the seventh entry in this post: https://forum.pfsense.org/index.php?topic=119731.msg663026#msg663026
  • ARP issue on vlan

    5
    0 Votes
    5 Posts
    2k Views
    DerelictD
    What would cause the issue with devices not getting automatically added to the ARP table on pfSense? Not getting the ARP broadcast from the switch. Diagnostics > Packet Capture on LAN_1 and see what's really going on.
  • White space only in custom send/expect load-balance monitor?

    1
    0 Votes
    1 Posts
    360 Views
    No one has replied
  • FTP Server Behind pfSense, Virtual IPs

    7
    0 Votes
    7 Posts
    1k Views
    KOMK
    I'm more than happy with our new ownCloud versus our crappy old FTP server.
  • Pfsense clears up states. help needed

    3
    0 Votes
    3 Posts
    802 Views
    J
    Harvy66, thanks for your reply. I didn't mention it, but my gateways are pretty stable, so it's definitely not the case. Also in the example I provided states was cleared for SSH connection which was made from local LAN to the BACKUP node only. No other states were affected.
  • Software Raid: Installation and Disk Replacement

    2
    0 Votes
    2 Posts
    855 Views
    jimpJ
    1. Yes. Backup the config, reinstall, and restore the config. When reinstalling, use the gmirror option in the installer to make the array. 2. There is a widget for gmirror status, and Diag > GEOM mirrors for status and disk management. If you have SMTP notifications enabled, it notifies on any status change of the mirror. The diag page also offers a way to forget disks, add disks, rebuild arrays, and so on. It doesn't let you create new mirrors, however.
  • MOVED: IP Sec und die Regeln

    Locked
    1
    0 Votes
    1 Posts
    345 Views
    No one has replied
  • Interfaces Ips Error

    4
    0 Votes
    4 Posts
    694 Views
    KOMK
    It's under the Firewall menu. https://doc.pfsense.org/index.php/What_are_Virtual_IP_Addresses
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.