• Cannot Ping WAN Interface

    13
    0 Votes
    13 Posts
    5k Views
    GertjanG
    Bug ? Setup ! pfSense handles ICMP as per user settings. If not, this forum would be swamped by angry user posts ^^
  • Two subnets

    3
    0 Votes
    3 Posts
    499 Views
    M
    @johnpoz Sorry mod, you are right and I have edited my post. I'm not using it forever, I have just installed it to test it on Unraid but I will use pfsense following spaceinvader tutorial for Unraid. Thanks anyway for your help.
  • HA-proxy and ADFS

    1
    0 Votes
    1 Posts
    221 Views
    No one has replied
  • Venturing into VOIP

    1
    0 Votes
    1 Posts
    295 Views
    No one has replied
  • Site to Site VPN with split tunneling

    4
    0 Votes
    4 Posts
    581 Views
    RicoR
    Generally speaking in a site-to-site scenario the OpenVPN network (tunnel network) doesn't really matter to the clients on both sites, it's transparent for them. It's used by OpenVPN internally and routes the traffic to your real networks on both sites. There is a LOT really good official documentation around for VPNs: https://www.netgate.com/resources/videos/site-to-site-vpns-on-pfsense.html https://www.netgate.com/resources/videos/advanced-openvpn-on-pfsense-24.html https://docs.netgate.com/pfsense/en/latest/book/openvpn/site-to-site-example-configuration-shared-key.html https://docs.netgate.com/pfsense/en/latest/book/openvpn/site-to-site-example-configuration-ssl-tls.html -Rico
  • 0 Votes
    4 Posts
    691 Views
    M
    Additional info, system logs show several: kernel vm_thread_new: kstack allocation failed And several kernel sonewconn: pcb 0xc7274790: Listen queue overflow: 193 already in queue awaiting acceptance (1 occurrences) nginx 2020/06/12 12:39:47 [error] 937#100185: *5059 connect() to unix:/var/run/php-fpm.socket failed (61: Connection refused) while connecting to upstream, client: xx.xx.xx.xx, server: , request: "GET / HTTP/1.1", upstream: "fastcgi://unix:/var/run/php-fpm.socket:", host: "xx.xx.xx.xx:xxxx"
  • 0 Votes
    8 Posts
    7k Views
    DaddyGoD
    @CodeNinja in this case, DMZ + WAF will be your good friend something like this that I can suggest: • OS: Debian 10.x (Buster) 64bit • Apache Worker, factory package • Mod Security apache module with OWASP rules, factory package • PHP-FPM 7.3 or rather 7.4 if it goes with everything but definitely 1 version • PHP can only write where we allow it, ie it stays on the www-data user • firewall inbound to CF IPs is limited to http and https, just as SSH access is also severely limited (http can be completely disabled by likely, CF solves http-> https redirect) • SSH access is password protected + Cert. • firewall to the outside, by default everything that is needed (external APIs and their counterparts) is enabled separately • hosting-type access via SFTP, SSH, although shell access may be possible CF = CloudFlare (https://www.cloudflare.com/plans/) edit: we have had such web servers for years, nothing is secure, but we try to make it that way
  • Low bandwidth on initial install

    20
    0 Votes
    20 Posts
    1k Views
    DaddyGoD
    @twoj it is clear what you need: xFinity Router in bridge mode, if it exists for this type and your ISP allows it or you mention a modem (Arris modem) that does not contain NAT per se and you get a public IP directly the difference between the measurements is very large approx. 900 and 400 we didn't get ahead professionally, because this difference is not justified by the dual -NAT throughput, so there is still a cat hiding somewhere in the bag if you have the opportunity to exchange, please come back to us afterwards (the curiosity moves the whole world )
  • [closed] (unsolved) - Why does pfSense not reply on a ICMP echo request

    11
    0 Votes
    11 Posts
    5k Views
    CodeNinjaC
    @guardian Thanks for your time and support. We already have this problem for weeks no so my boss decided to make a "big bang" and just shut off the old network and go to the new one as we run out of time to make the switch. It will be a sh*tstorm but we have 4 days as yesterday was a free day here and today most employees are not in the office and off course we have the saturday and sunday. Till now it looks not that bad and there is a lot of progress. I wil mark this question as closed.
  • DNS resolution for OpenVPN cleints

    16
    0 Votes
    16 Posts
    2k Views
    chudakC
    Well after lots of testing and trying here is why. I had DNS Resolver options checked for: 'Enable Forwarding Mode' 'Use SSL/TLS for outgoing DNS Queries to Forwarding Servers' Un-checking them and checking back fixed the problem! I suspect that reboot will help as well, but I not very often reboot my router. Hope maybe beneficial to somebody else.
  • BT FTTP with pfsense

    1
    0 Votes
    1 Posts
    290 Views
    No one has replied
  • pfsense will not correctly pick up new ISP lease for IP address

    pfsense
    10
    0 Votes
    10 Posts
    4k Views
    J
    @kiokoman Saved my bacon! Thank you! And, despite @stephenw10's suggestion, @kiokoman had it right: date yymmddhhmm (two digit year and no seconds).
  • Multiple IP Addresses for LDAP Server

    7
    0 Votes
    7 Posts
    1k Views
    hydrianH
    @yakatz Also a word of warning, as some who deals with PHP's LDAP bindings on a regular basis, ldap_connect is incredibly picky about TLS/SSL connections. And until about PHP 7.3, they are very hard to override and allow insecure connection even for testing.
  • Easy way to restrict webConfigurator access on OpenVPN only?

    4
    0 Votes
    4 Posts
    495 Views
    chudakC
    @Gertjan @Rico Yes yes thanks ! I also found a very short and great video on the subject, so sharing for all people. https://youtu.be/AZ_ju6pCbow
  • WAN and Lo0 logs

    1
    0 Votes
    1 Posts
    169 Views
    No one has replied
  • setting a google home to static ip?

    7
    0 Votes
    7 Posts
    3k Views
    T
    thanks for your help, a reboot helped, now it works just fine :)
  • Odd HA-Deployment

    carp virtualization kvm
    1
    0 Votes
    1 Posts
    546 Views
    No one has replied
  • How to "forward" port 443 and 80 to internal web server

    1
    0 Votes
    1 Posts
    164 Views
    No one has replied
  • Best Budget Low Profile Intel Quad Port NIC (May 2020)

    10
    0 Votes
    10 Posts
    3k Views
    S
    @bingo600 said in Best Budget Low Profile Intel Quad Port NIC (May 2020): I just got a refurb IBM i340-T4 for £18 https://www.ebay.de/itm/Intel-I340-T4-IBM-49Y4242-49Y4241-Quad-Port-Ethernet-Gigabit-PCI-Network-Adapter/324173295984 Not a bad price too Has "DELTA" engraved in the Xformers ... So should not be "China cr.." Edit: Not low profile though FYI you can get x5 Intel low profile brackets that fit the E1G44ET, E1G44ET2, I340-T4, I350-T4 quad port NICs here: eBay item number:131838369914 £4.70 for the lot.
  • VLANs issues can ping but cant connect

    4
    0 Votes
    4 Posts
    548 Views
    T
    I found that after adding/changing vlans, nics and other major settings it always needs rebooted to work right. also unifi gear can be slow to provision after changes, especially if using unifi cloud and/or remote network controller.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.