• Resolver log seems to never be up to date.

    4
    0 Votes
    4 Posts
    603 Views
    stephenw10S

    Level 1 is the default. Logging queries can produce a lot of logs of your network is at all busy. It's usually unnecessary. I only set that logging level when trying to diagnose something.

    Steve

  • self-paced PfSense courses?

    4
    0 Votes
    4 Posts
    625 Views
    stephenw10S

    Our own training is now also online and self-paced: https://www.netgate.com/training

    Steve

  • Potential dns error when I open my website on same server Internet t

    Moved
    9
    0 Votes
    9 Posts
    1k Views
    stephenw10S

    No I can't do that here. We have commercial support if you need it.

    Post screenshots showing how are accessing it and from where. (the source IP address)

    Steve

  • My pfsense LAN clients cannot ping the wan inteface

    2
    0 Votes
    2 Posts
    411 Views
    stephenw10S

    You should be able to ping the pfSense WAN interface at 70.70.70.2 from the Win7 VM in the LAN with only the default rules.
    The only reason you might not be is if the VM has no default route or a bad default route. Or something in the hypervisor is blocking it.

    You will not be able to ping from the server to anything on the LAN without firewall rules to pass it and a route to reach that subnet.

    Steve

  • 2.6.0 - Installed Pkgs - Unable to retrieve package information.

    21
  • Verify FQDN alias entries?

    7
    0 Votes
    7 Posts
    912 Views
    valnarV

    @bingo600
    That's it! Thanks.

  • Disabling one part of radvd Logs

    1
    0 Votes
    1 Posts
    125 Views
    No one has replied
  • Unable to access SSH / Webmin locally with pfsense v2.6

    14
    0 Votes
    14 Posts
    2k Views
    V

    Okay. Finally solved this for the friend.

    She had SimpleWall installed and it was blocking everything! I did not know it until I found we couldn't ping websites then investigated further and wallah!

    Thank you all!

  • How to enable ssh and remote web UI access from the console?

    Moved
    10
    0 Votes
    10 Posts
    4k Views
    rcfaR

    @rcfa said in How to enable ssh and remote web UI access from the console?:

    @stephenw10 Just one more question, which I can't seem to find answered: what sort of wildcards does easyrule accept?
    e.g.

    easyrule pass wan any any any any

    because I don't mind opening up the system completely, since it's only going for the time until the configuration backup is uploaded, so the chance of someone hacking the system in those 90 seconds is pretty low.

    OK, I tested it somewhere:
    the "any" wildcards work.

    Might be nice to mention that in the documentation...

  • WoL issues

    1
    0 Votes
    1 Posts
    206 Views
    No one has replied
  • Correct SMTP Settings for O365 w/ pfSense

    6
    0 Votes
    6 Posts
    4k Views
    S

    @adrianoebm See that link I posted above, https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-office-3. Microsoft has turned off SMTP AUTH (option 1 on the page) for new accounts and those with Security Defaults enabled.

  • Zoom Blocked, Completely Stumped.

    34
    0 Votes
    34 Posts
    4k Views
    johnpozJ

    @dma_pf here are some tests you might want to do to see if your isp is intercepting your dns..

    so query a specific authoritative NS for a record - say www.google.com to one of the actual google ns.. You should see aa in the response field showing that it was an authoritative response..

    aa.jpg

    Notice when I just ask some other NS for www.google.com I do not see the aa in the flags.. This means was not an authoritative response.. This points to dns being intercepted if you don't see the aa when doing a directed query to specific authoritative name server.

    Another simple test to see if all dns is being intercepted is just do a query to some IP you know for sure isn't actually running dns.

    So for example 1.2.3.4 sure and the hell is not providing dns.. But if its being redirected - sure looks like it is. So a quick test to see if all dns is being redirected is to just do a directed query to some IP you know for sure is not providing dns services - if you get a response, then your dns is being intercepted.

    redirect.jpg

    another sign of interception is when you query an authoritative ns for a record it is authoritative for.. You would get back the full TTL.. Notice I got a 300 back when I asked ns1.google.com for www.google.com, but when I asked another ns I got back some odd ttl.. That was something lower than the actual ttl - since it was from cache and not from the actual authoritative NS..

    Another possible hint of dns shenanigans is odd response times. Lets say 1.2.3.4 was actually some dns I could talk too.. But look at the response time I got back, 0 (since my redirection is local).. But if through some vpn while a query to maybe 1.2.3.4 might take 40ms, if your seeing much lower response time than what would be normal - that points to dns interception as well.

    There are many clues to look for to see if your isp or vpn is messing with your dns..

  • Multiple LANs versus VLANS?

    11
    0 Votes
    11 Posts
    1k Views
    D

    Now that I actually have a little free time, I'm starting to play with my pfsense box like this:

    -10.1.1.1/24=management LAN

    -10.20.30.0/24=LAB env., have a few poweredge servers with vsphere 7, TrueNAS Scale, unRAID, might get lucky and learn something configuring Microsoft server 2022 ADDNS/DHCP within vSphere on this LAN.

    -172.16.1.1/24=Personal, or basic home network for laptops, etc.

    -192.168.20.1/24=IOT devices I guess

    May try to figure out using the other two ports for the home and lab LANS.....future endeavor maybe.

    Directing traffic via firewall rules.
    Management LAN will have access to ALLOW ALL and ofcourse pfsense GUI
    All other networks, BLOCKED from each other and also blocked to pfsense GUI

    I dunno.......it all sounds right in my head. I'm sure I'm missing some things. You guys foresee any issues?
    Is all this needed? I dunno....
    Will I break something? All signs point to yes.....
    Will I learn something? Fosho!!
    Will the kids if and when I shut this mother down with some jacked up configs? Ofcourse but.......I grew up without internet, they can go without on it occasion.

  • Snort: Block but don't show alert?

    3
    0 Votes
    3 Posts
    1k Views
    L

    @bmeeks : Bummer. But I understand now. Thanks!

  • 0 Votes
    2 Posts
    806 Views
    stephenw10S

    It's because of the new RSC support in the updated hn(4) driver which is apparently broken.
    It only supports TCP to when you use OpenVPN (UDP) the traffic is unaffected.
    See: https://forum.netgate.com/topic/169884/after-upgrade-inter-v-lan-communication-is-very-slow-on-hyper-v

    Steve

  • DDNS doesn't update after Opt1(WAN2) recovery

    7
    0 Votes
    7 Posts
    948 Views
    stephenw10S

    Mmm, OK looks like that bug then. Updates will be on the report as they are found/patched.

  • Pfense/Openwrt : bridge interface > no network on the wireless wifi

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S

    If you don't need to filter between them then it's better to just have one interface as VLAN10 in pfSense and connect both those things to the vswitch with VLAN10 trunked directly.

    You usually can bridge VLAN interfaces like that but when you add ESXi that complicates things. You could also try bringing that traffic in untagged to pfSense and bridging those interfaces directly if you need bridging.

    Steve

  • Wifi interface -> NAS interface for video streaming?

    4
    0 Votes
    4 Posts
    691 Views
    stephenw10S

    In some situations that's all that is required. I have done exactly that on a system with a 'Smart' TV DNLA client and a NAS on different VLANs and it connected immediately.

    Steve

  • Identify traffic from MAC address or IP?

    2
    0 Votes
    2 Posts
    430 Views
    Z

    All good. Found a way. SSH into pfSense and run pftop -f 'src host 192.168.0.XXX'

  • Pfsense / Windows 10 Pro / File sharing with Iphone.

    13
    0 Votes
    13 Posts
    1k Views
    M

    @johnpoz

    I finally got it to work. Believe it or not, I experimented quite a bit and finally changed the format from exFAT to NTFS and it started working fine. Goes against everything I read on Google. Who knew you couldn’t trust the internet. 🤷🏻‍♂️

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.