• Allow traffic

    3
    0 Votes
    3 Posts
    925 Views
    R

    @akinori said in Allow traffic:

    going to let traffic coming from LAN interface going out to WAN and vice versa?

    By default pfSense will pass all traffic out and in on the LAN interface. WAN blocks all inbound traffic by default and will allow all outbound traffic without any special rules.

  • Pfsense

    12
    0 Votes
    12 Posts
    2k Views
    M

    Issue with the flux capacitor?

  • Strange Speed Issue with 5gbit AT&T Fiber Upload

    7
    0 Votes
    7 Posts
    904 Views
    stephenw10S

    I would definitely test enabling (or disabling) flow control at the link level on the NIC.

    Some connections absolutely require that.

  • Responding to port 80 on WAN side

    17
    0 Votes
    17 Posts
    2k Views
    L

    @johnpoz, I've done nothing for you to act so childish in this question and have provided what ever information I can but you just keep on making assumptions and even saying my info is BS.

    There is nothing mysterious here, it's just something where I cannot share the customers technology. They are doing something that's proprietary and that's that.

    The only thing I can share is my mention of UDP and that's where it doesn't work with a host, it has to be bare metal.

    Again, thank you for your help.

  • metronet fiber, internet goes down roughly every 24 hours

    45
    0 Votes
    45 Posts
    10k Views
    stephenw10S

    Yes, that sounds very much like you're hitting that issue. Try setting the supersede option and see if it returns.

  • USB MFA Key and Pfsense Login?

    3
    1 Votes
    3 Posts
    654 Views
    JonathanLeeJ

    @stephenw10

    Thanks for the reply!!

  • Mail server rejecting connections

    16
    0 Votes
    16 Posts
    2k Views
    L

    The SIP server is on the same LAN as the phones. It used to be external but it's local now.

    Different lines use different ports, 5060, 5061, 5062, 5064 on 4 line phones for example but there's also just one phone.

  • Auto Configuration Backup (ACB) is down

    7
    1 Votes
    7 Posts
    847 Views
    geminateG

    Perfect, thanks! Everything appears to be working again.

  • How to create a static NDP entry

    5
    0 Votes
    5 Posts
    874 Views
    E

    @johnpoz Ok, that is great anyway.

    Really thank you.

  • need help on pfsense setup on virtualbox

    6
    0 Votes
    6 Posts
    2k Views
    stephenw10S

    @bengregory said in need help on pfsense setup on virtualbox:

    now i can't access gui from pc3 and 4 and can't ping pfsense and can only access the pfsense gui from pc in the virtualbox

    That's good. That's what I expect to happen unless you have added firewall rules to allow it on WAN and routes to the LAN subnet so PCs 3/4 know how to reach it.
    They should be able to access the pfSense GUI on the WAN IP if the WAN firewall rules are passing that.

    Anything you do to make PCs 3 & 4 send their traffic via pfSense is going to be a hack with that network topology. You should have them on a separate layer 2 segment.

    However to do that you would need to set the pfSense WAN as the default gateway on PCs 3 & 4 dircetly. Then you need firewall rules in pfSense to allow traffic from them into the WAN. And you need a custom outbound NAT rule in pfSense to NAT traffic from the WAN subnet to the WAN address. Otherwise you will have asymmetric routing. This would be a really horrible setup! 😉

    Steve

  • new pfsense firewall blocks many websites

    20
    0 Votes
    20 Posts
    3k Views
    johnpozJ

    @pirod said in new pfsense firewall blocks many websites:

    was on static ipv4 I guess. Not sure why.

    Well if it was static you would of had to have set the IP, etc It defaults to dhcp that is for sure.

    BTW - still waiting for where you see all the complaints with no answers ;)

    I see many people complaining the same and no real answers are given.

  • TAC Lite Disassociated with Device

    3
    0 Votes
    3 Posts
    506 Views
    G

    thanks.... Netgate Support got me sorted 👍

  • 0 Votes
    5 Posts
    1k Views
    johnpozJ

    @stepinsky you would need to edit the subject (ie your first post) then you can edit that and add a tag of solved, etc.

  • Slow to NO Internet-Unless using VPN

    6
    0 Votes
    6 Posts
    836 Views
    J

    Now that Frontier has resolved the corruption on their end, my problem is now resolved.

    Thank you everyone.

  • Problems restoring my config

    Moved
    4
    0 Votes
    4 Posts
    425 Views
    R

    @thedragon said in Problems restoring my config:

    Is there anything in particular that causes the second set of tags to be added?

    Yes, the specific software-related bug I linked to caused it. In the next release the double-tag will be ignored.

  • 0 Votes
    7 Posts
    744 Views
    N

    @stephenw10
    hi Steve,
    the version I use is the 2.6.0.
    In the file config.xml I have tried only to modify the "username"
    On friday I will test the alternative format in the field "URL" in the config.xml file
    I will update you
    thank you for now!

    regards
    sblack

  • PROXIES

    5
    0 Votes
    5 Posts
    595 Views
    V

    @natethegreat21
    Even if you post the same screenshots multiple times, it gets not more clear, what you have configured actually, since the pics are still missing comments.

    And also the questions stay the same:
    Did you import the SSL certificates into pfSense?
    Obviously you didn't. However, this is necessary for HAproxy allowing to read the host header.
    I mentioned this already in the other thread, I think.

    You have the ACLs configured on host name basis. So HAproxy must be able to get it. But the client only send the host name after he got an SSL certificate from the server. So that requires that HAproxy has SSL certificates assigned in the frontends.

    Without importing the certificates you can only use TCP mode frontends and configure the ACLs to read the SNI.

  • Add bacula-client to pfsense repo

    5
    0 Votes
    5 Posts
    781 Views
    stephenw10S

    Mmm, there was a bacula package at one time (way back in pbi times). I don't see any feature requests open for that.
    It doesn't have any additional dependencies:

    [2.6.0-RELEASE][admin@cedev-4.stevew.lan]/root: pkg add https://pkg.freebsd.org/FreeBSD:12:amd64/latest/All/bacula13-client-13.0.1.pkg Fetching bacula13-client-13.0.1.pkg: 100% 427 KiB 436.8kB/s 00:01 Installing bacula13-client-13.0.1... ===> Creating groups. Creating group 'bacula' with gid '910'. ===> Creating users Creating user 'bacula' with uid '910'. ===> Creating homedir(s) Extracting bacula13-client-13.0.1: 100% ===== Message from bacula13-client-13.0.1: -- NOTE: Sample files are installed in /usr/local/etc/bacula: bconsole.conf.sample, bacula-fd.conf.sample

    There is no front end for it though. And pfSense doesn't use the FreeBSD init system so you might need to start it using another method.
    If you really need it.

    Steve

  • FreeBSD Ping

    18
    0 Votes
    18 Posts
    3k Views
    G

    @mdearman I’m just having some fun. There have already been like 10 threads on this same subject over the past few days that were answered. This has been the more entertaining one of them.

  • NAT Port Forwards not working after restoring settings on new install.

    Moved
    4
    0 Votes
    4 Posts
    535 Views
    stephenw10S

    Hmm, not really sure what you mean by that. When you backup the config the complete config is backed up every time. It's not incremental.

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.