• Can ping one way but not the other

    6
    0 Votes
    6 Posts
    2k Views
    johnpozJ

    "but I have never encountered a situation where two IPs from the same subnet can ping one way but not the other."

    You sure its pinging the correct thing.. Could be wrong mac.. And sure have seen this quite often with firewalls on hosts.  Or in a bridge if your filtering on members of the bridge it could be allowed in one direction or not the other.. etc. etc..

    There are many reasons why this could happen.  If you were on a actual L2 first thing to do is validate your devices are arping the correct mac, etc.

  • Why was /etc/passwd updated automatically?

    12
    0 Votes
    12 Posts
    4k Views
    johnpozJ

    While I am not an expert on the whole boot process of pfsense.. From a general point of view… The configuration of pfsense is stored in XML... So on boot I would assume pfsense makes sure that "all" settings that are in the config XML are placed into the appropriate files.

  • Openvpn or ipsec vpn tunnel

    5
    0 Votes
    5 Posts
    818 Views
    K

    What kind of content?  I use Plex for the 5000+ movies I have and it can live behind a dynamic IP and no need for a VPN tunnel from any location.  Plus Plex is available as a native app on every media platform.  Smart TV's Netgear Router now has Plex Media Server Built in., Iphone, Android, Mac, PC etc…

    FYI Plex Server and client are completely free!!!!!!

    Install Plex Server at home and then use the Plex client anywhere (No VPN Required) and access your content!

  • Using Developer Shell - pfSsh.php

    6
    0 Votes
    6 Posts
    1k Views
    Z

    Thanks I'll give that a try.

  • User hogging internet. How to stop it?

    8
    0 Votes
    8 Posts
    902 Views
    johnpozJ

    That is not what you stated ;)  I was making a funny about it…

    You really need to look into how shaping works and limiting though... TCP does this on its own..

    My guess would be this user is doing p2p and has hundreds of sessions running if he is eating up all the bandwidth.

    The best solution to such users is just block what they are doing or just limit them down to shit..

  • Out of state packets

    2
    0 Votes
    2 Posts
    565 Views
    DerelictD

    Figure out why the state is being closed.

    An established TCP state will not expire for 24 hours of ZERO traffic using the default firewall settings.

    If the state is no longer there it is because either side has closed it.

    More info here:

    https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    76 Views
    No one has replied
  • 0 Votes
    1 Posts
    633 Views
    No one has replied
  • How to add a DSL modem to pfSense ?

    3
    0 Votes
    3 Posts
    1k Views
    Michel-angeloM

    Thank you emammadov. I am glad to read that, the solution for adding my own modem works also on a pfSense device the way you describe. I have it set up with an old Thomson Speedtouch modem on my SG-1000 microfirewall. This thread ("How to access my Thomson Speedtouch modem web GUI through my SG-1000 microfirewall" <https://forum.pfsense.org/index.php?topic=144151.msg784762;topicseen#msg784762>) describes more of it.

    I apologise if my original post was not clear enough. I own three modems and am amazed by the low quality of these devices. Of particular importance for a DSL modem sitting at my home and facing my ISP's understatements, is to be able to evaluate the quality and performance of the upstream DSL line, which my ISP will never tell or admit.

    1 - They may not admit that the line is defective: if they do not want to correct it.

    2 - They may not admit the line is excellent, to instead keep on deliberately throttling the bandwidth from their end in an attempt to lure the customer into a more expensive contract, with the ISP's supplied modem and stuff.

    Currently, I am experiencing situation 2 after the installation by my ISP of a device in my village to reduce my DSL line's length from 4700 m down to 700 m.

    My stats, today, are as follows:

    Modulation:ADSL2 PLUS

    Annex Mode:ANNEX_A

    Downstream Upstream
    SNR Margin: 17.3 7.8 db
    Line Attenuation: 14.2 7.9 db
    Data Rate: 10271 1022 kbps

    Note the enormous SNR margin of 17.3 decibels. I would gladly bet my modem could synchronise at the SNR margin of 6 db, which is the normal target for SNR Margin at the ADSL2plus modulation. This could result in a stable downstream data rate of around 20000 kbps (almost double the current 10271 rate). But my ISP throttles the bandwidth from its place and denies doing so, possibly for commercial reasons. If I consent to purchase an expensive contract with VoIP and pay-TV, they swear the bandwith will magically be liberated. Legally, this stands for a tie-in contract: plain illegal where I live.

    With such a line, with a VDSL modulation, which my line is now declared to be capable of, I could reach the 50000 kbps data rate. Worth doing something !

    It may even be possible that other ISPs play the same dirty tricks to their customers (tie-in contracts), who knows ?

    Rather that wasting my time in litigating, my desire is therefore accessing a good modem, ADSL and VDSL capable.

    Hence my question 1 (is a pfSense appliance a modem or able to become so with a package);

    Hence my question 2 is there an open source DSL modem project underway, capable of allowing a high level of security and capable of line-state-monitoring.

    TIA for suggestions, even speculative.  8) 8) 8)

  • Need help to configure VLAN in HA environment

    5
    0 Votes
    5 Posts
    703 Views
    P

    Thank you !
    I try to set up this.

  • Web based vpn like cisco webvpn and synology vpn plus

    1
    0 Votes
    1 Posts
    514 Views
    No one has replied
  • Firewall logs entries only display the last minute

    9
    0 Votes
    9 Posts
    1k Views
    G

    Well I started with the filter issue, and moved on to other issues, and now figured it out.

    Looks like there was a small configuration issue on VMWare.
    https://doc.pfsense.org/index.php/CARP_Configuration_Troubleshooting

    Needed to make sure the Net.ReversePathFwdCheckPromisc was changed.

    The VMWare Hosts all have multiple trunk ports to the switch, so that was causing a layer 2 loop for the CARP advertisement traffic.

    After changing that setting and bouncing the promiscuous mode on each vswitch, all is well.

    Thank you for the help, and if anyone else is seeing the same, ther is a trail, from missing log filter entries to the actual root cause.

    And a reminder for others, sometime we do read the manual and just need a little help from our fellow gurus on the web.

  • Admin Login via RADIUS using Active Directory Accounts

    7
    0 Votes
    7 Posts
    2k Views
    U

    This was sorted out. I found out my issue. On my RADIUS server I was was trying to use the same network policy but just add in different ip address of my pfsense in the network policy Conditions

    Removing the other IP address and adding its own network policy seems to fix that  ;D 8)

  • Some websites are just non-navigable

    10
    0 Votes
    10 Posts
    953 Views
    RonpfSR

    Why don't you simply whitelist "fncstatic.com" ?

  • How to assign statis ip for certain OpenVPN users?

    2
    0 Votes
    2 Posts
    376 Views
    KOMK

    You were close.  You were missing the proper subnet mask.

    Leave IPv4 Local Networks(s) blank and add your custom stuff under IPv4 Tunnel Network like this:

    a.b.c.d/30

    For example, one of my users is set to 192.168.2.4/30 which means (I think) .4 for the network address, .5 for the gateway address, .6 for the actual IP address and .7 for the broadcast address.  My next user is 192.168.2.8/30 which gives him an IP address of 192.168.2.10.  Separate each user by 4.

  • Blank pfSense dashboard issue; Might be that the drive is full…. help?

    2
    0 Votes
    2 Posts
    540 Views
    GertjanG

    Hi,

    What about asking your drive, or more precis : the file systems ?
    Enter console - go option 8 and type the max word :

    df

    If you can't understand the output of df, post it here, like :

    [2.4.2-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: df Filesystem                  1K-blocks    Used    Avail Capacity  Mounted on /dev/ufsid/54ca20c41b3d50b0 298695208 1143932 273655660    0%    / devfs                              1      1        0  100%    /dev /dev/md0                        3484    180      3028    6%    /var/run /usr/local/lib/python2.7    298695208 1143932 273655660    0%    /var/unbound/usr/local/lib/python2.7 devfs                              1      1        0  100%    /var/dhcpd/dev procfs                              4      4        0  100%    /proc procfs                              4      4        0  100%    /proc

    In my case : close to 0% and 6 % - the 100 % lines are special cases.

    Btw : log files are circular and can't fill up the file system.
    And a pfSense which a huge set op parameters (config) won't use more then a couple of Mega ….

    So, no, if the dashboard isn't showing up, it must be something else.

  • Best practice rules/setup for icmp and NTP?

    18
    0 Votes
    18 Posts
    5k Views
    NogBadTheBadN

    @V3lcr0:

    How would I do a "…host time.apple.com does it come back with 17.253.24.253 ?" where do I go for this?

    Would a port forward as you provided: https://doc.pfsense.org/index.php/Redirecting_all_DNS_Requests_to_pfSense enhance my DNS security?

    On the pfSense router, connect via ssh or via Diagnostics -> Command Prompt

    Some devices could be hard coded for google, my Panasonic TV is, if I wanted to force my TV to use my pfSense box this would be the only method.

  • Template for syslog

    1
    0 Votes
    1 Posts
    465 Views
    No one has replied
  • Client OpenVPN cant see other subnets

    3
    0 Votes
    3 Posts
    422 Views
    H

    Got it working.. Thnx..

  • NTP, leap 11 (Leap not in sync)

    4
    0 Votes
    4 Posts
    3k Views
    johnpozJ

    Well clearly from your output pfsense ntpd which is not ntpdate is not able to talk outbound.. Did you mess with outbound nat?  Do you have any floating rules..

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.