• tagging traffic on Windows and route it on pfsense

    5
    0 Votes
    5 Posts
    979 Views
    johnpozJ

    No what I saying is that is how you could flag traffic in windows. Then you should be able to route that traffic with whatever specific marker you put.

    There is no other way I know of to tag or mark traffic coming from a specific application other than with dcsp.

    You can route traffic in pfsense really easy based upon source IP, source port, Dest port, dest IP, etc. And then you can tag that traffic for other rules to process, etc. But that is not what you asked - you asked per application how to mark the traffic.

    So for example you could part traffic that is coming from your browser with af11, and traffic coming from say application XYZ with af12.. Then you could tag traffic coming from IP of your box with af11 as browser, and traffic with af12 as application and then route it based on those tags i pfsense rules.

    This way even if going to the same dest IP, you could could tell what is browser traffic and what is application traffic.

  • 0 Votes
    12 Posts
    2k Views
    H

    Yeah a regression is a possibility. But as you say, I would have thought this would have caused somebody else issues as well previously. Anything you manage to find is appreciated, thanks for looking at it.

  • Suricata floods system log

    4
    0 Votes
    4 Posts
    789 Views
    stephenw10S

    That setting makes no difference to the firewall log it only affects Suricata logs in the System log.

    You can still see the Suricata logs by going to the logs tab in Services > Suricata.

    Steve

  • Obtaining update status checking never stops

    10
    0 Votes
    10 Posts
    964 Views
    B

    @jimp Updating :) 2.3.6.a.20180612.1214 [pfSense-core] Done! Thanks again!

    Bob

  • Intel Lazy FP State Restore CPU bug

    2
    0 Votes
    2 Posts
    617 Views
    ivorI

    A patch to FreeBSD -HEAD has been issued and we are evaluating. More information soon, pfSense development snapshots will be first to have this fix

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • Basic questions - Scenario suggestions

    2
    0 Votes
    2 Posts
    546 Views
    A

    @alexandre-dezembro

    Scenario example:

    https://uploaddeimagens.com.br/imagens/pfsense-png

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    43 Views
    No one has replied
  • Loader.conf.local deleted on restart

    23
    0 Votes
    23 Posts
    4k Views
    C

    @jimp @stephenw10

    Can confirm that patch has fixed the issue. Thanks for looking into it.

    [2.4.3-RELEASE][admin@pfSense.localdomain]/root: cat /boot/loader.conf.local comconsole_port="0x2e0" legal.intel_wpi.license_ack=1 legal.intel_ipw.license_ack=1 legal.intel_iwi.license_ack=1
  • Problem loading netdata

    3
    0 Votes
    3 Posts
    1k Views
    ?

    the solution is this:
    in the config file (/usr/local/etc/netdata/netdata.conf), change the line:

    bind to = 127.0.0.1

    to

    bind to = *

    and restart the netdata service:

    kill <pid> service netdata onestart
  • Server for NTP

    4
    0 Votes
    4 Posts
    1k Views
    johnpozJ

    As jahonix mentions, any software that wants to put in a url to pool in their software as default is asked to create their own unique fqdn for the pool, etc. So this is pfsense playing nice with ntp.org

    http://www.pool.ntp.org/vendors.html

    Anyone smart to even look into where or what its using for ntp should prob change this to either their own ntp servers of choice or the fqdn pool urls for their region of the globe.

    For example if you want to use the pool and your in the US you should use say

    server 0.us.pool.ntp.org server 1.us.pool.ntp.org server 2.us.pool.ntp.org server 3.us.pool.ntp.org

    You can find a full listing here

    http://www.pool.ntp.org/zone/@

  • GUI for NAT

    10
    0 Votes
    10 Posts
    2k Views
    T

    Thank you for all.

  • Cant Access WebGUI via VPN?

    18
    0 Votes
    18 Posts
    3k Views
    D

    Just to update this. It appears that the install on pfSense was somehow corrupt, a full reinstall gave me back access to the GUI via my VPN!

  • IP DNS Suggestion

    Moved
    3
    0 Votes
    3 Posts
    630 Views
    SoarinS

    Thank you Stephen, I'll do that right now.

  • Why DNS Resolver appears to be 3x slower than DNS Forwarder?

    5
    0 Votes
    5 Posts
    687 Views
    KOMK

    Honestly, unless there is a problem I don't waste my time tweaking for that extra 1 ms. Netgate uses resolver by default because it just works out of the box without the need to specify upstream servers. If you're concerned with speed, use the forwarder with your ISP's local DNS.

    As for testing, DNS Bench by Steve Gibson is one such tool.

  • Trying to use lcd screen on astaro 220

    5
    0 Votes
    5 Posts
    896 Views
    stephenw10S

    Not really. If you're using the SDEC driver though they will be connected to the input pins on the parallel port. You could try reading the port directly.
    Probably easier to just try various combinations of the buttons specified by the driver until they line up.

    Steve

  • ZFS and CPU usage

    1
    0 Votes
    1 Posts
    541 Views
    No one has replied
  • Discovery across vlans

    64
    0 Votes
    64 Posts
    20k Views
    stephenw10S

    That^.
    Seems like a fairly accurate description to me.

    There are 3rd party apps for controlling Denon/Marantz stuff. One of those might work for you.

    Steve

  • No access to OPT1 from any interface

    Moved
    4
    0 Votes
    4 Posts
    584 Views
    stephenw10S

    So what IS working here?

    Do you have DHCP enabled on OPT1? Are clients pulling a lease from it?

    With outbound NAT in manu7al mode you will have to add outbound NAT rules for the new OPT1 subnet.

    Do you see any alerts in the GUI? It may be failing to load the new ruleset correctly. You should still be able to ping from LAN to OPT1 though even without any new rules.

    Steve

  • On boot, stuck "Starting DNs Resolver"

    2
    0 Votes
    2 Posts
    401 Views
    stephenw10S

    Anything special in your unbound config? Assuming you're running unbound.

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.