• Simple Firewall/OpenVPN/CARP/NAT/Hairpin/VLAN/Loopback question

    1
    0 Votes
    1 Posts
    286 Views
    No one has replied
  • ASK Configurariont Interface /29 prefix

    3
    0 Votes
    3 Posts
    383 Views
    J

    Thanks dotdash for the answer.

    My firewall is not yet in production, I will test your information and I will return it soon.

    Once again, thank you for your kindness.

  • How to limit UDP datagram size?

    6
    0 Votes
    6 Posts
    3k Views
    M

    Hello team.

    Short update: it looks like the "net.inet.udp.maxdgram" is actually doing what I expected it to do.
    I double checked my lab layout and I found a piece of incorrect configuration.
    With the lab correctly setup, I can see that

    in case "net.inet.udp.maxdgram" is larger than my 3.1kb made up record, the DNS response from the auth server is one large UDP frame in case "net.inet.udp.maxdgram" is smaller, the communications switch to TCP.

    So, net.inet.upd.dgram seems to be the way to go.

    Thank you all for your attention, my best wishes of a good weekend to you all.
    Manuel

  • want to add netgate sg1100 to network that already has a router

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S

    Yeah, you can't really do that.

    One solution here would be to put the SG-1100 on a different subnet on a different interface on the Watchguard.

    That way all clients in LAN trying to reach it (or coming from it) will send their traffic to the Watchguard as their default gateway and it will route the traffic to the SG-1100. The traffic takes the same route in both directions, there is no asymmetry. Effectively that is creating a transport subnet for the SG-1100 (and any other router) to reside on. As long as you only have routers and no hosts in the transport subnet you will probably be OK.

    Steve

  • Restart Captive Portal service from command Line Pfsense 2.4.4

    6
    0 Votes
    6 Posts
    1k Views
    L

    Thanks again.. the solution posted by @jimp worked for me!

  • WAN blocking rule alias change reload client OpenVPN tunnels

    2
    0 Votes
    2 Posts
    291 Views
    stephenw10S

    I would not expect that unless that alias is somehow in use somewhere else.

  • pfSense in AWS not working

    4
    0 Votes
    4 Posts
    533 Views
    stephenw10S

    It looks like the WAN might not be set to dhcp which every interface has to be in AWS.

    Can you connect from the LAN? From another VM in the LAN perhaps?

    What was the last change you made?

    Otherwise I would probably just remove it and re-deploy. It's likely to be quicker than anything else.

    Steve

  • [SOLVED] Avaya IP Office v9 remote site phone failing

    18
    0 Votes
    18 Posts
    3k Views
    L

    @stephenw10
    Based on the idea you had about why I needed that rule at all, I went ahead and disabled that rule. Everything seems to still be working just fine. Guess that's what happens when you follow some guides on how to do things. The guide I followed was accurate to get the forwarding to work properly, but it was also why I added that NAT rule. If you can, can you update the title of this thread to include [SOLVED] in it, just in case anyone else runs across this. Thanks again for help. :)

  • Dashboard Configuration

    2
    0 Votes
    2 Posts
    237 Views
    stephenw10S

    It lools like you have either a lot of columns on your dashboard or you're viewing it in a narrow window.

    Using less columns should make it wider.

    Steve

  • PPPoE session dropping intermittently

    8
    0 Votes
    8 Posts
    1k Views
    O

    4 days uptime. Looks like it was a fault in the ISP router!

  • how to check which user is browsing which web sites??

    9
    0 Votes
    9 Posts
    3k Views
    stephenw10S

    Squid is a package you install in pfSense to proxy and log http/s traffic.
    https://docs.netgate.com/pfsense/en/latest/cache-proxy/index.html#squid

    If you watch the video I linked above it walks through the entire process.

    Steve

  • 0 Votes
    7 Posts
    1k Views
    stephenw10S

    This could easily be something in your browser filling the credential fields when you switch back to page. I've hit similar things before though not on that page.

    Steve

  • Performance Tuning for 1.5gbit Internet and 10Gbit LAN

    26
    0 Votes
    26 Posts
    4k Views
    stephenw10S

    That looks like plenty in hand in performance terms. No cpu core is anywhere near 100%. The bxe processes are not at 100%. I would have to guess the limit is somewhere else.

    You might try running tests from the pfSense box itself. It's not a good way to show absolute values but you have CPU cycles to spare and it will allow you to test the WAN and LAN separately.

    So you could run iperf on pfSense and test to it from the client to be sure you're getting speeds on the LAN that are above 1Gbps. You won't see 10Gbps but if you see, say, 4Gbps you know that's not limiting.

    You can run the CLI speedtest client on pfSense to test only the WAN. That might show almost anything! My experience is that it usually shows low speeds on high bandwidth WANs but if it shows closer to 1200Mbps that would prove the WAN is good.

    Steve

  • Logs System, what could it be?

    4
    0 Votes
    4 Posts
    557 Views
    lean-on-heL

    @kiokoman
    Its a PFsense 2.4.4 P3 running on a Xen hypervisor, so yes it is a virtuel machine.

  • DISK USAGE ALLMOST FULL

    6
    0 Votes
    6 Posts
    800 Views
    DerelictD

    Based on the service status in his screenshot it's neither of those. But it looks like he went dark on us anyway.

  • 0 Votes
    8 Posts
    1k Views
    J

    @petreza yes, but we know about this thread. We will get back to you.

  • WAN upgrade from /29 to /28

    13
    0 Votes
    13 Posts
    989 Views
    K

    @jimp Thanks for the heads up, Im not aware of my /28 addresses yet so I will hold fire on adjusting anything.

  • Pfsense 2FA failed on Freeradius

    1
    0 Votes
    1 Posts
    147 Views
    No one has replied
  • Two Customers Using One Firewall

    7
    0 Votes
    7 Posts
    843 Views
    stephenw10S

    Yes, you can bridge a 2nd interface to your WAN and allow them to use a single public IP directly.
    You should also be able to apply Limiters to that traffic.
    Whether or not you should is a different question.

    Steve

  • setting up alert when public ip access to internal server via NAT

    4
    0 Votes
    4 Posts
    425 Views
    stephenw10S

    Yup, probably. Unless that rule has a restricted source.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.