• SG-2440 Gigabit WAN

    5
    0 Votes
    5 Posts
    770 Views
    chrismacmahonC

    It depends on the switches, cables, network load, etc. No you shouldn't lose that amount in your switches.

  • Removing Varnish Server, Routing Directly?

    4
    0 Votes
    4 Posts
    416 Views
    johnpozJ

    There is a whole section of the forum related to using the proxy if you have questions
    https://forum.netgate.com/category/52/cache-proxy

    It includes squid proxy and such but any questions you have about haproxy would go there as well.

    Here is some more info on the package
    https://www.netgate.com/docs/pfsense/packages/haproxy-package.html

  • Reset States not working for me [solved]

    6
    0 Votes
    6 Posts
    2k Views
    stephenw10S

    I edited the title. Not sure if you can or not, I think that might be time limited.

    Anyway glad I could help.

    Steve

  • Pfsense use Open DNS

    5
    0 Votes
    5 Posts
    930 Views
    P

    working now
    I have DNS Forwarder enabled not DNS resolver

    I removed 10.4.0.1 from DHCP Server DNS, and in general / system setup I kept adding the open dns thee under dNS Servers but changing the interface to AirVPN_WAN - opt2 . When I removed this and left both interfaces as WAN the Open DNS works

  • PPPoE authentication & Static IP on WAN

    4
    0 Votes
    4 Posts
    1k Views
    stephenw10S

    They don't give you any sort of gateway IP at all?

    In a point to point connection technically they don't have to but it would be very unusual.

    So do they give you the expected static IP via PPP or something random? Who are your ISP? Someone else must have hit this is they are reasonably big.

    You can try just setting any gateway IP and see what happens. As long as it's outside the WAN subnet it won't try to ARP for it.

    Steve

  • PfSense 2.4.x auto boot problem info

    1
    1 Votes
    1 Posts
    308 Views
    No one has replied
  • pfSense Home/Business Setup - Best Practices/Design for Installation?

    6
    0 Votes
    6 Posts
    3k Views
    stephenw10S

    Ok, well at 100Mbps a VPN can potentially completely saturate that without huge processing power. Our SG-3100 will pass close to that with OpenVPN and much more than that with IPSec. The SG-5100 would give you plenty in hand for a WAN upgrade later. Both will pass 1Gbps between internal interfaces.

    One thing you can do here is just try it on any random hardware you might have with two NICs. Just use all VLANs internally. That will give you a good feel for what is required before you purchase dedicated hardware.

    Steve

  • Boot stuck at Updating Configuration

    5
    0 Votes
    5 Posts
    718 Views
    S

    @jimp It's there, just 0 bytes. Looking in /conf/backup I see backups from the day it went down and the previous day. All the backups are 244K up until the reboot it seems.

    9:00 244K
    10:00 244K
    10:35 128K
    10:35 0B

    Edit. I copied the last full config file into place and the unit booted up normally so it's running. I'm just concerned about what would cause that. This is the second device at this site that has had a corrupted config file. Once last summer and now this time. 2 different pieces of hardware and there's really nothing spectacular about them. WAN is DHCP. LAN is just 192.168.1.1 with a DHCP pool of 100-150. pfBlocker, Suricata and Squid are running. That's about it. Last device was 2.3.2. This one is 2.4.4 (which I'll update before putting it back into production). It's a little concerning.

  • PfSense 2.3.3-RELEASE-p1 will not Autoboot

    Locked
    7
    0 Votes
    7 Posts
    1k Views
    johnpozJ

    If they did it would be irreverent to your issue since 2.3 is no longer supported.. So your having said issue on 2.4.x? 2.4.4p1? Please create your own thread and document your exact issue your seeing.

    Locking thread.

  • 0 Votes
    8 Posts
    7k Views
    stephenw10S

    Let's just say that if anyone is imagining:

    #Switch to layer 7 filtering - firewall_layer=3 + firewall_layer=7

    ...then unfortunately they are very very wrong! 😜

    Steve

  • 0 Votes
    5 Posts
    813 Views
    U

    Yes, absolutely. Thank you for pointing that out.

    From the reference:
    https://www.netgate.com/docs/pfsense/monitoring/filter-log-format-for-pfsense-2-2.html

    In a remote log, the fifth field is:
    <tracker> ::= <integer> -- Unique ID per rule, tracker ID is stored with the rule in config.xml for user added rules, or check /tmp/rules.debug

    I need to figure out how to use that number from my syslog server, to lookup the rule description. So far, I'm closer, now using splunk to run a script:

    | script pfsenselookup 1000000105

    where pfsenselookup.py is

    import sys import os matchstring=str(' '.join(sys.argv[1:])) os.system("ssh user@192.168.1.1 pfctl -vvsr | grep '^@' | grep '{matchstring}'".format(matchstring=matchstring))

    For example, results :

    @11(1000000105) block drop in log inet6 all label "Default deny rule IPv6"
  • can you import configuration file from console

    8
    0 Votes
    8 Posts
    2k Views
    C

    oh ok cool.. ill give that a shot too well ill tell her or ill practice it when she gives me her faulty hard drive... I did the conf folder and copied my older pfsense setup so hard drive is ready for her just to slide in the hot swap... but ill defently try that step too... I really appreciate the help great stuff (:

  • Pass specific IP through to LAN, port forwarding, firewall rules

    24
    0 Votes
    24 Posts
    3k Views
    A

    @konstanti said in Pass specific IP through to LAN, port forwarding, firewall rules:

    @akjim
    64.4.23.126 !!!!!!! - port forwarding rule
    64.4.231.126 - block !!!!!

    I am an idiot!!! I see that now, and after making the address correction it is working properly.
    THANK YOU so much for your guidance and assistance!!!

  • disable on boot check of config.xml

    4
    0 Votes
    4 Posts
    325 Views
    stephenw10S

    USB Ethernet devices are renamed ue0, ue1 etc, yes.

    It's not desirable to stop checking for them though. That is a physical interface. If it is assigned in the config and not present on the system the firewall should stop and ask the user how to proceed. Not doing so ends up in an unknown situation or potentially something worse like if you had multiple ue interfaces and one is unplugged you could start sending private traffic out of the remaining one if that became a different interface.

    The other interfaces in that list are those that built on top of a different physical NIC and may not have been created yet at the time of the check like ppp or vpns.

    There is no good way to handle this unfortunately. If the modem is in Ethernet mode you have to do something like this to avoid boot failure. If it's in PPP mode pfSense has no problem with the interface or device disappearing but the speed is limited to 3.5G (ish).

    It would be great to be able to use one of the other methods like MBIM but there is no driver in FreeBSD, yet.
    https://man.openbsd.org/umb.4

    Steve

  • FTP Client problem

    33
    0 Votes
    33 Posts
    5k Views
    stephenw10S

    Um... yeah that would not have helped at all in this case. Traffic to any ftp server was already allowed and passing.

    Steve

  • pfSense for Squid with only one interface

    4
    0 Votes
    4 Posts
    342 Views
    stephenw10S

    Because the proxy allows traffic on those ports?

    You can always block it on the firewall.

    Steve

  • pfSense problems tonight with access

    7
    0 Votes
    7 Posts
    950 Views
    M

    @jashaw30 that's all you've ever needed since that changed that you no longer need to use their kit.

    dhcp-client-identifier "woteveryouwanr@skydsl|woteveryouwant"

  • Is connecting a factory defaulted router a potential vulnerability?

    7
    0 Votes
    7 Posts
    824 Views
    GrimsonG

    For connecting new devices I have separated two ports on my switch into a single dedicated VLAN. So I connect the new devices to one of these ports and patch the Ethernet connection of one PC to the other port, this way they are in their own L2 and can't impact the network.

    Another solution is to use a Laptop and connect a new device there first for setup purposes. Just don't connect a device with unknown/conflicting settings to your production network.

  • Need to enable Rules to allow UniFi based Captive Portal Page?

    12
    0 Votes
    12 Posts
    5k Views
    C

    @gertjan said in Need to enable Rules to allow UniFi based Captive Portal Page?:

    If you pass some time with the acme package you could learn it to obtain a free of cost (that is money, not your time) wild card cert.

    Hey thank you for this info will look at the package for sure.

  • Load Balancer and reflection.

    2
    0 Votes
    2 Posts
    299 Views
    stephenw10S

    It's possible to workarounbd this using outbound NAT on the internal interface but it's ugly:

    https://www.netgate.com/docs/pfsense/book/loadbalancing/troubleshooting-server-load-balancing.html#unable-to-reach-a-virtual-server-from-a-client-in-the-same-subnet-as-the-pool-server

    Steve

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.