• Restoring config from beta releases

    10
    0 Votes
    10 Posts
    1k Views
    stephenw10S

    Hmm, that's the first time I've ever seen that.
    If that's a common problem we need to fix it. How exactly were you getting the config file from the APU?

    Steve

  • huawei e8372 pfsense 2.4.3

    2
    0 Votes
    2 Posts
    268 Views
    stephenw10S

    Which parts of that other thread did you follow exactly? Please retail what you have done.

    Steve

  • Multi-tenant Managed Firewall

    3
    0 Votes
    3 Posts
    971 Views
    A

    @derelict said in Multi-tenant Managed Firewall:

    The permissions system in pfSense is likely not going to work for that. There is nothing resembling a multi-instance pfSense.

    Thanks for answer.

    Best regards,

    Alexandre

  • Monitoring multiple PFSense devices

    2
    0 Votes
    2 Posts
    625 Views
    bepoB

    Hello @siil-it,

    you can monitor the general pfSense state with SNMP within your classic monitoring.
    For the snort alert you have to configure a syslog server and handle the messages from snort on your syslog server.

    Kind regards

  • Login incorrect (Failed retrieving values required to evaluate condition)

    5
    0 Votes
    5 Posts
    5k Views
    B

    0_1531304315743_CA.png 0_1531304319226_CA2.png 0_1531304326596_CA3.png 0_1531304331667_CA4.png 0_1531304343129_interfaces.png 0_1531304348196_LDAP.png 0_1531304354900_LDAP2.png 0_1531304360776_nasclient.png 0_1531304365364_settings.png 0_1531304371489_settings2.png 0_1531304376890_settings3.png

  • Assigning Privilidges to AD Groups via RADIUS

    2
    0 Votes
    2 Posts
    310 Views
    U

    I have assigned this privileges. Seems ok for me. If there are other recommendation, let me know

    0_1531252323427_pfSense Operator Assigned Privilidges.JPG

  • Recommendations for a lot of simultaneous connections

    3
    0 Votes
    3 Posts
    662 Views
    S

    I don't know much about DD-WRT but we have run into instances with lower end routers not handling lots of connections. I think some just have a fixed size state table. The first was a LONG time ago when we starting having our clients' PCs connect in to our management service. We switched to m0n0wall (and then later to pfSense) on an old/spare PC and it cleared right up. A couple years ago we ran into it again at a client with a mid range (for D-Link) D-Link router who had about 5 PCs and 10 phones...the router would just stop passing traffic and you couldn't connect to its web interface. We've since just given up on D-Link type hardware for more than about 5-10 PCs/devices.

    Currently our traffic goes through an SG-3100 for our building an then an old cast off PC we use that runs Suricata. My point is the hardware is likely not limiting your connections and you should NOT need shiny new hardware for pfSense...most likely some sort of limitation in DD-WRT.

    The only limitation for pfSense moving forward is that v2.5 will require AES-NI CPU support...so about 2012 or later CPUs if I recall correctly.

  • arpresolve: can't allocate llinfo for [wanip] on igb1

    3
    0 Votes
    3 Posts
    950 Views
    beremonavabiB

    Thanks. Hopefully, that will keep NTP running, too.

    EDIT: Never mind this paragraph. I found the log entry about states being killed. OP: As far as I can tell, pfSense killed the states on the former IP address when it noticed the first change to the wanip. But, I don't see it killing them when the wanip changed to a valid one. It's possible I'm missing it in the logs, but shouldn't it have done so?

  • Port aggregation

    5
    0 Votes
    5 Posts
    739 Views
    johnpozJ

    @tbbz8x8 said in Port aggregation:

    I have absolutely no use for more vlans as I only have one device that uses Ethernet

    @jknott said in Port aggregation:

    Unless it's over 1 Gb, aggregation won't accomplish much

    Even if over 1 gig, wouldn't matter lagg is not going to allow 1 device to use more than 1 physical path..

    From the OP statements - other than a failover for failed port.. I don't see any use to setting up a lag.. And what switch is he using? Most likely since he doesn't have any vlans, just the 1 lan connection more than likely doesn't even have as smart switch capable of lagg, etc.

  • No internet Connection. LAN side.

    11
    0 Votes
    11 Posts
    1k Views
    stephenw10S

    I would suspect some hardware off loading not playing nicely.

    Things can get weird when you are testing from the host itself as traffic does not actually enter/leave the NIC. It not subject to the same path as traffic from external clients.

    Steve

  • NTP server remain in Soliciting pool server

    36
    0 Votes
    36 Posts
    13k Views
    J

    attached two trace, one of my ntp local server and one of pfsense box with the same server configured.

    1_1531170243257_pfsense.pcap 0_1531170243256_local.pcap

  • warning unresponsive script

    4
    0 Votes
    4 Posts
    766 Views
    R

    @stephenw10

    yes it was lastpass causing the issue. thank you.

  • How to display the Traffic Graph feature on another website.

    1
    0 Votes
    1 Posts
    555 Views
    No one has replied
  • Disable Auto-added VPN rules???

    6
    0 Votes
    6 Posts
    3k Views
    DerelictD

    No. If you needed to NAT on IPsec you would use the NAT in IPsec Phase 2 not Outbound NAT.

    Once the Phase 1 (IKE) tunnel is up you can forget all about the WAN interface.

    In your case, if you wanted to only pass traffic between those hosts you would probably want to make these Phase 2 Networks:

    Local Network Remote network Host 192.168.2.61 Host 192.168.81.3 Host 192.168.2.61 Host 192.168.81.4 Host 192.168.2.61 Host 192.168.81.5

    You can further enforce inbound connections with proper rules on the IPsec tab.

  • Tmobile cellspot - OPT1 interface

    8
    0 Votes
    8 Posts
    939 Views
    DerelictD

    Seems like a personal choice.

  • PfSense reload pfctl rules

    8
    0 Votes
    8 Posts
    5k Views
    stephenw10S

    When I run that command I see this in the system logs (reversed):

    Jul 8 12:30:23 php-cgi rc.update_urltables: /etc/rc.update_urltables: pfB_Spamhaus does not need updating. Jul 8 12:30:23 php-cgi rc.update_urltables: /etc/rc.update_urltables: pfB_NAmerica_v4 does not need updating. Jul 8 12:30:23 php-cgi rc.update_urltables: /etc/rc.update_urltables: Starting URL table alias updates Jul 8 12:30:00 php-cgi rc.update_urltables: /etc/rc.update_urltables: Starting up.

    Those are url aliases added by pfBlocker that point to lists of IPs.
    Do you not see that logged for your custom alias?

    Steve

  • "403 Forbidden" please help !

    4
    0 Votes
    4 Posts
    535 Views
    emammadovE

    When you select option 15 "Restore recent configuration" it will show you two options: view and restore. Select view and look at the previous dates that you want to restore. I think, it will show you 30 recent configurations. Type the number of the backup and press enter, wait a moment. Then try to login pfSense web gui.

  • VLAN Help Requested: I Give....diagram & screenshots included

    24
    0 Votes
    24 Posts
    3k Views
    P

    I am back trying to solve this problem.

    One thing I have noticed on the wireless clients is I can get them to connect to the VLAN ONLY if the interface is selected as the same as my LAN interface.

    Example:

    LAN is on igb1 (switch is patched to this physical port to port 1 on switch)
    VLAN10 set to igb2 = No IP address on wireless device (phone)
    VLAN10 set to igb1 = IP address connects and appears in DHCP table correct (192.168.10.100)

    From there, the phone says "Connected, no internet" which leads me to believe the issue is with the firewall rules. I believe my Pass rule is correct but would like to know if I need to add NAT rules. A recent post in this category had a guy connecting a Ubiquiti AP to an unmanaged switch and he required a NAT rule as well as a firewall rule. I have attempted to duplicate both but cannot make it out to the internet.

    As always the help is appreciated.

    UPDATE:

    Progress. The phone is now on the internet. I had to select the SECURE interface in the DNS Resolver in addition to the already selected LAN & localhost.

    I still have the firewall rules but deleted the NAT rules I was trying to make. So I'm still looking for answers there.

    ETA: IT WORKS!!!

    I chased this all night but it came down to my NAT rules being set to manual due to an older OpenVPN setup. One click on Auto and all devices have internet.

    Talk about a nightmare. I'll get to setting up the VPN later.

  • How to down grade from Devel to Stable?

    6
    0 Votes
    6 Posts
    915 Views
    D

    @gentlejoe This is what I can find https://forum.netgate.com/category/28/development

  • Export system logs and statistics into word or PDF format..

    2
    0 Votes
    2 Posts
    6k Views
    vicWellerV

    There are no tools in order to do so to one of those extensions exactly. As far as I know, you need something like this in order to proceed with this thing https://4000a-125-2-form.pdffiller.com/ that's actually an editing tool for pdf's but fits well for your purpose as well as it cost not that much as the other tools with these features

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.