• Blocking sites on a alix board pfsense

    2
    0 Votes
    2 Posts
    1k Views
    W

    @glennbtn:

    I have 1 or 2 lan ip's I want to block access to certain websites. Can anyone advise the best way

    Firewall rules on the LAN interface.

  • FQDN instead of IP

    3
    0 Votes
    3 Posts
    2k Views
    L

    Is there a way to put a FQDN into PFsense DNS without registering a domain name externally?  Almost like an lmhosts file in Windows?  Looks like you can add a DNS "Host Override" under advanced in DNS forwarder?  Is it a good idea to do this?  For example, the FQDN for the pub is an external hosted website, but could add wifi.puburl.com into the hosts override and assign this to the captive portal ip?

    Still not really sure what that call to the function does mentioned above?

    Looks like it would only be useful if you had more than one interface using the Captive Portal.  It seems to look at the interfaces in use for the portal, get the IP/Subnet for those interfaces, look to see which the clientIP 'matches', and then assigns the IP address for the captive portal according to which interface the client is on?

    So if using just one interface, you could opt to loose the call to this function, as you are always going to get the same result from the call.

    Is there a reason to NOT use the hostname of the pfsense server?

  • Youtube block

    Locked
    5
    0 Votes
    5 Posts
    14k Views
    C

    You can just assign those machines the open dns ip addresses the rest could reach another dns server, skipping the policy's. Ok its not the best professional option, but it would still work?

  • Cross platform restore?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    R

    @stephenw10:

    It's in the drop down menu on the updater settings tab. Probably safest to just select it from there but they are, for current release:
    For 32bit

    Steve

    OK, now I feel like an idiot…  of course thats where they are.  Duly noted, changed and backed up.
    Thanks again,
    Rick

  • Monitoring few pfsense boxes

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    C

    Cheers Steve!

  • What's the use of MAC spoofing on PPPoE interface?

    Locked
    13
    0 Votes
    13 Posts
    6k Views
    K

    If you want to retain em0's original address but still use spoofing for PPPoE, I guess a workaround would be to create a bridge interface first with the desired MAC address and then create a new PPPoE connection over that (if pfSense allows it).

    Otherwise just changing em0's address works.

  • Multi LAN problem

    Locked
    9
    0 Votes
    9 Posts
    2k Views
    stephenw10S

    @riversr54:

    The one thing that has me stumped though is why I can't even ping it…does that make sense for the default configuration for the second LAN default settings?

    That's normal. By default everything is blocked. That includes ICMP. The only exception to this is DHCP traffic if you have it enabled on the interface.

    Steve

  • Pfsense User Manager Page

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    jimpJ

    It is not a vulnerability, it's a limitation in the user manager. If you don't want someone to change another user's password, don't give them the ability to manage users.

  • Open router

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    C

    Lol what Steve said

  • User Access to change squid local password

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    I could be wrong! And correct me someone please. But personally the easiest way to do what your doing is introducing Ldap so users can auth to active directly and change their passwords in there own windows environment

  • Port forwarding (Remote desktop) hangs pfsense

    Locked
    22
    0 Votes
    22 Posts
    16k Views
    C

    Sorry if iv miss read. Are you using VMware workstation? What version? Id personally say its something to do with the virtual machine. Can you try maybe installing open vm tools as a 3rd party package? Just an idea….

  • Installation 2.0.3 i386 hang up at 38%

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    C

    Can i also add pfsense works amazing on VMware. And as a virtual machine you can chop the 1tb down and its amazing!

  • [Solved] Cronjob / Script not working for update of A-record

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to block http & https freelance websites?

    Locked
    3
    0 Votes
    3 Posts
    901 Views
    C

    Squid and Squid Guard are amazing! But the easiest stress free option is to use OpenDNS.com! Go on that! your love it!

  • PPPOE Connection up, run a script

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Pfsense as Firewall and router,dd-wrt router as AP need some help

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    stephenw10S

    You should have your DD-wrt box setup as an access point only so:
    Disable DHCP on the dd-wrt box.
    Enable DHCP on the pfSense OPT1 interface.
    Set the dd-wrt box to a static IP in the OPT1 subnet so you can access it later.
    Connect the ethernet cable from the pfSense OPT1 interface to one of the dd-wrt LAN ports.
    Add firewall rules to the pfSense OPT1 interface to allow traffic from the wireless clients to your server.

    Steve

  • VLAN not working (except DHCP)

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    M

    resolved by doing the following, create vlan, and then adds the vlan vlan physical interface that was craiada, eg RE0, re0_vlan1 a bridge, then asymp interface creates another interface, opt2 eg, ai the interface will be connected to interface bridge0 eg, there went all the normal traffic.

    ![Sem título.jpg_thumb](/public/imported_attachments/1/Sem título.jpg_thumb)
    ![Sem título.jpg](/public/imported_attachments/1/Sem título.jpg)

  • Rule banned my IP, how/where to unban?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    That actually lands you in a special table. The place you'd need to clear is under Diagnostics > Tables, "virusprot" I believe.

    Remove the record from that table and you should be able to send packets again, or just wait for the entry to timeout (takes a couple hours)

  • Firewall Log Shows My WAN IP keeps changing, AND I am on a STATIC IP

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    I

    Thank-You very much Jimp for the very prompt reply. You relieved a lot of stress. Briefly I built a server and mail system mostly for my children on the East Coast and I was using a WRT54G router with DD-WRT and a pgm called WallWatcher to monitor port probes and the like. Someone turned me on to pfSense and I am just starting to learn this stuff for an old man in my mid 60's.
        Again, thanks an awful lot for the help.

  • Can VLANs do that? Some advanced stuff…

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    ?

    QinQ sounds interesting, can't clearly tell if it will work.

    I'm running Supermicro X7SPA-HF in a M350 chassis,
    I haven't see a compatible riser card / IO Panel so a third nic isn't in the cards.
    Currently have em0/em1 dedicated to the modems and LAN via a USB adapter which is very dirty.

    wallabybob's #2 looks to be the only solid option at this point.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.