• Packet loss

    4
    0 Votes
    4 Posts
    561 Views
    JKnottJ

    One thing I learned a long time ago is, if you're prepared to watch for a failure, it won't happen.  ;)

  • 0 Votes
    3 Posts
    324 Views
    F

    Thanks, ok that does make sense. I need to use source hash so I guess I'll just use a portion of the subnet.
    Would be nice if we could use source hash with alias. Sticky round robin just doesnt do it for us.

    Thanks for clearing that up!

  • Pfsense blocks LAN VPN traffic

    4
    0 Votes
    4 Posts
    465 Views
    stephenw10S

    Ok, so 10.0.0.4 is not in the 192.168.3.0/24 subnet.

    Is the VPN server actually at 10.0.0.4? How is that subnet connected?

    If the client and server really are both in the 192.168.3.0 subnet that that's the wrong IP address the client is using. In that instance the traffic would go directly between them so pfSense would never see it.

    However running a VPN between two devices on the same subnet seems… unusual at best.  ;)

    Steve

  • 0 Votes
    4 Posts
    720 Views
    D

    Thank you, SammyWoo.

    I've had the traffic shaper run in different configurations since you suggested it, but the first couple of days the connection kept crashing every couple of hours despite the traffic shaper being up and running.
    Then I changed the port for torrents to use to one outside of the normal P2P range of ports that my ISP didn't seem to be messing with.
    That seems to have solved the problem.

  • NAT Source Hash - /24 subnet needs to exclude some addresses

    4
    0 Votes
    4 Posts
    337 Views
    F

    I went with NAT source hash subnet 3.3.3.128/25

    But it looks like(at least it seems this way) that my pfsense is also giving out the Broadcast address 3.3.3.255 to some of my clients, they then obviously lose internet access. If I check the states for their private address I see this "3.3.3.255:5205 (172.16.49.160:61396) -> 8.8.8.8:53 SINGLE:NO_TRAFFIC"

    Now I'm not sure if it's showing the broadcast address on the outgoing interface because this IP is failing to get out onto the internet?

    So as a test I changed the NAT outbound source hash rule from subnet 3.3.3.128/25 to 3.3.3.128/26 which should give out IP's up until 3.3.3.190, and ip 3.3.3.191 is the broadcast….but after making this change and searching the states I can see that pfsense is giving out the IP 3.3.3.191, this shouldn't happen as this is the ranges broadcast address.

  • Change VPN user password

    3
    0 Votes
    3 Posts
    1k Views
    K

    Are you using PPTP?  If so change immediately!  Go with openvpn or IPSEC Mobile..  Personally I prefer Mobile ipsec as it supports windows 10 native built in client.

  • Pfsense hanged, Help me.

    10
    0 Votes
    10 Posts
    1k Views
    K

    Maybe try enabling syslog and pushing to syslog server and you might get some info regarding the last seconds prior to hanging system.

  • Help with putting PfSense in frount of 8 static IP (public)

    22
    0 Votes
    22 Posts
    1k Views
    DerelictD

    @detox:

    Derelict …..

    According to Suddenlink, all the static IP's I will be issued are class C  /24

    Thanks

    So on the interface itself in a larger subnet than your allocation.

    There is no good way to put those addresses directly on servers.

    I would 1:1 NAT in that case.

    Or I would ask for a routed subnet to an address on that /24.

  • Web GUI from WAN IP inside LAN is this normal?

    4
    0 Votes
    4 Posts
    247 Views
    johnpozJ

    Lets look at it this way… Lets say your wan IP is 1.2.3.4

    What is the default lan rules?  Any Any right!  So is 1.2.3.4 fall into ANY?  If so then yes the lan would be able to access it.

    Rules are evaluated as traffic enters that interface from the network its connected too, first rule to trigger wins no other rules are evaluated.  So when you have some client on 192.168.1.X for example on your lan wanting to go to 1.2.3.4:443 that falls in the rule any any - so yes it is allowed.

    If you do not want to be able to hit the wan IP from your lan - then put in a rule that blocks that on your lan... But seems kind of pointless since your allowing lan your web gui on the lan address via the anti lockout rule.

  • RV mobile PFsense box. (sanity check)

    6
    0 Votes
    6 Posts
    655 Views
    johnpozJ

    While pfsense has a wide range of uses..  I would think something like a cradlepoint or the http://www.netgear.com/landings/nighthawk-mr1100-mobile-router/

    The netgear going to be more home/user budget friendly..

    You could for sure build up a nice setup with pfsense at the core… But there are devices specifically designed for this exact sort of use case.  And sure you could use it as failover internet connected into your pfsense setup at home when your not travel in your RV..

  • Network set up/config advice needed

    10
    0 Votes
    10 Posts
    636 Views
    M

    Thanks all! I'll dive into this weekend.

  • Dynamic DNS IP caching problem ?

    2
    0 Votes
    2 Posts
    284 Views
    DerelictD

    In general you bind the dynamic DNS you want to update to the interface address/vip you want it to update from.

  • PFSense with Vulnerability Scanner / Openvas

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ

    That is definitely not something you want running on the firewall.

    Setup another system. Install Kali in a VM and you can use it very easily. But don't try to make that run on the firewall.

  • Trunking VLANs on interfaces II

    18
    0 Votes
    18 Posts
    1k Views
    B

    stephenw10; Thank you.

    johnpoz: If a person goes to the parent domain and sees that I have a blog that makes the article I linked to SPAM? Get real.

    You're making assumptions again without facts in evidence. The default VLAN is not the same on all my switches.

    I purposely limited where 20 and 30 can go, that is by design and is why they are isolated. 30 is high continuous traffic 24/7, 20 can be at times for hours at a time. The traffic on each is confined on each. I do not want either to adversely affect one another or 10 which has its own purpose besides being the default for the majority of the switches

    Look, I came to this forum to ask how to configure pfSense to do exactly what I have done. Instead of getting help all I got was hostility and telling me how stupid this configuration is and how stupid I am and many other personal attacks. And I had to figure it out myself in the end.

    In case you haven't realized it Mr. Hero Member, you were of no help in this case. Put aside your I know the best way and it's the only way and help people do what they want whether you like it or not. And if you don't like it and can't do that then for God's sake leave the peole alone!

    I've told you more and showed you more then you need to know. Once again I came here for help configuring pfSense to do what I want that's all you needed to know.

    IF YOU ARE NOT GOING TO HELP PLEASE JUST LEAVE ME AND THIS TOPIC ALONE!!!

    This is what I want to do. This is what I did. This will work for my environment. It will have all the performance and flexibility I will ever need.

  • Strange pfSense Notifications

    2
    0 Votes
    2 Posts
    577 Views
    DerelictD

    That has already been fixed. Upgrade.

    https://redmine.pfsense.org/issues/8360

  • Apps on different ports on ubuntu server - pls advice!

    5
    0 Votes
    5 Posts
    431 Views
    DerelictD

    plenty of google terms there.

  • Samsung Tab A slow internet browsing

    17
    0 Votes
    17 Posts
    1k Views
    L

    Hi there. Sorry to say that when I went back to my Tab to perform another packet capture, everything was working fine. I gave it 24 hrs and things are still fine with speedy  internet browsing on the Tab. I've been living with the terrible performance for about three weeks and have not made any changes to pfsense or the network hardware. I hate unsolved mysteries!!

    Thank you all for your help and suggestions. Looks like I'm good for now and will report back if things fall back to the previous conditions.

  • No internet after Virgin Modem disconnected/reconnected

    17
    0 Votes
    17 Posts
    2k Views
    R

    Thank you very much for taking the time to help with this, glad to say the problem is solved  ;D Your last post prompted me to try something.

    I powered off the modem and back on, once it came up I checked and had lost internet except for the ability to ping 8.8.8.8.

    I was pinging via IP address, and as I said before the only one that worked was 8.8.8.8 which was my gateway monitor IP address. So I changed the monitor IP for the gateway to 8.8.4.4 and could no longer ping 8.8.8.8 but could now ping 8.8.4.4.

    Whilst I was in Edit Gateway changing the monitor IP address I noticed a check box to make it the default gateway, ticking that fixed the issue once applied.

    Don't know if the behaviour I was seeing is expected behaviour or just some weirdness going on, either way I'm very pleased its sorted.

    Thanks to everyone that tried to help.

  • Random client IP's just stop working - No Internet

    11
    0 Votes
    11 Posts
    1k Views
    ccgllcC

    Let me summarize:

    The vast majority of functionality is just fine.  Thus layer 1 appears healthy.

    From a statically addressed PC:  Sometimes SOME Internet sites are unreachable, as described below, but most work just fine.  Thus DNS, DHCP, cabling, DNAT rules, etc. are unlikely a problem.

    From a  statically addressed linux box:  I've noticed intermittent access to zec.slushpool.com port 4444.  I have 100% access from St. Louis, and "sometimes" access, lasting minutes to days, from a linux box behind the PFSense firewall of concern.  A PC on a different port of that same concerning PFSense firewall also has "sometimes" access to zec.slushpool.com port 4444 - and access outages do not correlate between the PC and the linux box.  I don't think there is anything special about zec.slushpool.com - it just happens to be the site the linux box and PC are configured to use.

    From my 160+ DHCP addressed processing machines, all linux based, I've seen a couple of instances of not being able to reach their primary site oh1.kano.is and have confirmed with the operator of that site they were not experiencing any issues.  Their backup site, stratum.kano.is functions fine when needed, so I only loose about 5 minutes of failover time.  I'm stating this just because its likely related.

    DNS resolution works fine ALL the time.  Pinging of zec.slushpool.com fails when access stops.

    Access to both zec.slushpool.com and oh1.kano.is will randomly and independently toggle, without any administrative changes occurring on the PFSense box.  (Note that oh1.kano.is is AWS based and requires a TCP ping, not ICMP).  Normally access is stable for hours - but under a curve.  e.g.  I've seen access for as little as a few minutes to days.

    I have not specifically checked if the linux box can ping the firewall, but SSH sessions continue to work.  Clearly the PC can access the firewall since most web browsing functions.

    Rebooting the PFSense box will sometimes resolve the access issues although its become a guessing game as to any individual website working or not.  Most do.

    Changing my external static address resolved about 90% of the access issues, at least for now, but that only occurred a few days ago.

    ALL of these problems started when I upgraded recently.  Prior to that I had no problems accessing everything.

    ps.  I've disabled Snort blocking just to eliminate it from suspicion.  Snort is the only add-on package installed.  Also switched to 8.8.8.8 and 8.8.4.4 to minimize the chances of this being a DNS issue, although the PFSense DNS Resolver is enabled (provides effective caching for most of my machines).

    pps.  Basic firewall health stats: 

  • MOVED: openvpn blues

    Locked
    1
    0 Votes
    1 Posts
    282 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.