• Youtube block

    Locked
    5
    0 Votes
    5 Posts
    14k Views
    C

    You can just assign those machines the open dns ip addresses the rest could reach another dns server, skipping the policy's. Ok its not the best professional option, but it would still work?

  • Cross platform restore?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    R

    @stephenw10:

    It's in the drop down menu on the updater settings tab. Probably safest to just select it from there but they are, for current release:
    For 32bit

    Steve

    OK, now I feel like an idiot…  of course thats where they are.  Duly noted, changed and backed up.
    Thanks again,
    Rick

  • Monitoring few pfsense boxes

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    C

    Cheers Steve!

  • What's the use of MAC spoofing on PPPoE interface?

    Locked
    13
    0 Votes
    13 Posts
    6k Views
    K

    If you want to retain em0's original address but still use spoofing for PPPoE, I guess a workaround would be to create a bridge interface first with the desired MAC address and then create a new PPPoE connection over that (if pfSense allows it).

    Otherwise just changing em0's address works.

  • Multi LAN problem

    Locked
    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S

    @riversr54:

    The one thing that has me stumped though is why I can't even ping it…does that make sense for the default configuration for the second LAN default settings?

    That's normal. By default everything is blocked. That includes ICMP. The only exception to this is DHCP traffic if you have it enabled on the interface.

    Steve

  • Pfsense User Manager Page

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    jimpJ

    It is not a vulnerability, it's a limitation in the user manager. If you don't want someone to change another user's password, don't give them the ability to manage users.

  • Open router

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    C

    Lol what Steve said

  • User Access to change squid local password

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    I could be wrong! And correct me someone please. But personally the easiest way to do what your doing is introducing Ldap so users can auth to active directly and change their passwords in there own windows environment

  • Port forwarding (Remote desktop) hangs pfsense

    Locked
    22
    0 Votes
    22 Posts
    16k Views
    C

    Sorry if iv miss read. Are you using VMware workstation? What version? Id personally say its something to do with the virtual machine. Can you try maybe installing open vm tools as a 3rd party package? Just an idea….

  • Installation 2.0.3 i386 hang up at 38%

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    C

    Can i also add pfsense works amazing on VMware. And as a virtual machine you can chop the 1tb down and its amazing!

  • [Solved] Cronjob / Script not working for update of A-record

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to block http & https freelance websites?

    Locked
    3
    0 Votes
    3 Posts
    901 Views
    C

    Squid and Squid Guard are amazing! But the easiest stress free option is to use OpenDNS.com! Go on that! your love it!

  • PPPOE Connection up, run a script

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Pfsense as Firewall and router,dd-wrt router as AP need some help

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    stephenw10S

    You should have your DD-wrt box setup as an access point only so:
    Disable DHCP on the dd-wrt box.
    Enable DHCP on the pfSense OPT1 interface.
    Set the dd-wrt box to a static IP in the OPT1 subnet so you can access it later.
    Connect the ethernet cable from the pfSense OPT1 interface to one of the dd-wrt LAN ports.
    Add firewall rules to the pfSense OPT1 interface to allow traffic from the wireless clients to your server.

    Steve

  • VLAN not working (except DHCP)

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    M

    resolved by doing the following, create vlan, and then adds the vlan vlan physical interface that was craiada, eg RE0, re0_vlan1 a bridge, then asymp interface creates another interface, opt2 eg, ai the interface will be connected to interface bridge0 eg, there went all the normal traffic.

    ![Sem título.jpg_thumb](/public/imported_attachments/1/Sem título.jpg_thumb)
    ![Sem título.jpg](/public/imported_attachments/1/Sem título.jpg)

  • Rule banned my IP, how/where to unban?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    That actually lands you in a special table. The place you'd need to clear is under Diagnostics > Tables, "virusprot" I believe.

    Remove the record from that table and you should be able to send packets again, or just wait for the entry to timeout (takes a couple hours)

  • Firewall Log Shows My WAN IP keeps changing, AND I am on a STATIC IP

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    I

    Thank-You very much Jimp for the very prompt reply. You relieved a lot of stress. Briefly I built a server and mail system mostly for my children on the East Coast and I was using a WRT54G router with DD-WRT and a pgm called WallWatcher to monitor port probes and the like. Someone turned me on to pfSense and I am just starting to learn this stuff for an old man in my mid 60's.
        Again, thanks an awful lot for the help.

  • Can VLANs do that? Some advanced stuff…

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    ?

    QinQ sounds interesting, can't clearly tell if it will work.

    I'm running Supermicro X7SPA-HF in a M350 chassis,
    I haven't see a compatible riser card / IO Panel so a third nic isn't in the cards.
    Currently have em0/em1 dedicated to the modems and LAN via a USB adapter which is very dirty.

    wallabybob's #2 looks to be the only solid option at this point.

  • /etc/ssh /root/.ssh not restored from config.xml after prior sshd enable?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    those are not kept in the config.xml file.

    /etc/ssh keys are re-created when the host boots up the first time.

    Root's authorized_keys are written out from config.xml using admin's User Manager account entry. Manual changes to files in that directory are not kept and are not needed.

  • Gmail Notification

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    C

    Notifications are used for.. if a WAN connection was to go down if your in a multiwan setup. As far as i am aware. This is also a 3rd party package for emailing RRD graphs, and that package uses those details. So its good to have! I love that 3rd party package. Customers love seeing there data display like it.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.