• ISP Modem Mode Reverted - Question.

    3
    0 Votes
    3 Posts
    417 Views
    B

    @motific:

    your ISP probably updated the firmware on their kit and reset it back their defaults.  Some do that.

    You know what is causing the situation, it’s up to you.  I’d ignore them, but others might disagree.

    Thank you motific - Much appreciate the response.

  • Noddos project

    3
    0 Votes
    3 Posts
    576 Views
    F

    Hi BlueKobold. Yes, I know that pfSense if FreeBSD based. In fact what I ask is the equivalent of nf_conntrack in pfSense (FreeBSD), where I can see  network flows in real time. I have never programmed packages for pfSense, this is something to look at later (for now it is essential to analyze network flows).

  • VLAN traffic problem

    11
    0 Votes
    11 Posts
    850 Views
    R

    Ok , I'll try

  • Migrate LAN to VLANs

    7
    1 Votes
    7 Posts
    3k Views
    ?

    FYI, the Foundry X448 I bought is actually full PREM version with L2, L3-Base & L3-Full.

    So let the switch route between all the VLANs or the entire network to free up the load from the pfsense
    box able to realize more for you, might be then also a way able to march on or am I wrong with that!?

  • Hardening Pfsense, with Snort

    7
    0 Votes
    7 Posts
    3k Views
    ?

    New to this forum, but have been using pfsense for a while, but no expert..

    It doesn´t matter at all, but that said, like mentioned before, snort and suricata are not set it up and forget it packets!
    It´ll be more on the need to fine tune more and more and also get new rules for that will be a work for itself.

    I'm just looking for best practice regarding hardening pfsense and snort, without using all my time on false positives.

    We all do! But again it is not a plug and play packet, it can help much and bringing you to running wild too,
    if there is a DMZ with opened ports and forwarded protocols it might be the best bet to positioning it there,
    if you are not really sure how to use it, I suggest you to get a small amount of books about your favorite
    IDS/IPS system such snort and suricata are. That will narrow down the entire time you spend on it.

  • Security patches for 2.3.4_1 ?

    2
    0 Votes
    2 Posts
    416 Views
    jimpJ

    We have a 2.3.5 release coming in the next couple days that has security and other fixes.

  • Trying to configure Lan and Wireless as one network

    2
    0 Votes
    2 Posts
    331 Views
    johnpozJ

    Would not suggest bridge unless you have no possible other recourse.

    Devices do not need to be on the same layer 2 to use plex..  I access my plex server from any vlan/network I want to allow it from by opening up 32400 from that network to the plex servers IP.. Then just access your plex server direct via its local name or IP.

    If you just want your wireless to be on your lan network - just plug your AP into your switch that your lan is connected to.

  • SQUID+DANSGUARDIAN with WPAD/PAC

    6
    0 Votes
    6 Posts
    807 Views
    KOMK

    i used pfsense version 2.2.1.

    :o

    https://doc.pfsense.org/index.php/WPAD_Autoconfigure_for_Squid

  • VLAN not working

    3
    0 Votes
    3 Posts
    631 Views
    P

    Once again I seem to have found an answer:

    https://www.linuxquestions.org/questions/linux-networking-3/server-on-multiple-vlans-server-not-responding-to-pings-from-non-local-subnets-819880/

    Now I just need to understand it.

    It has to do with traffic being dropped when leaving on a different interface than they arrive at.  I tried to work around a router on a LAN segment issue - but this will also not work.  I will need a dedicated router to make this work :S

  • Problems after clean 2.4 install on ESXi 5.1

    12
    0 Votes
    12 Posts
    1k Views
    V

    So I have noticed mine crashing too, and then vmware thinks its down, but its kind of up? This is with a new install too, and if I power off via esxi gui, and then unregister it and re register it, and remove the SATA host in the edit options, it seems fine…for a bit. I gave it 4 cpu, and 4gb memory.... still happened a few times before I gave up. This was all in one night :s.

    Heeeey, this is related: https://forum.pfsense.org/index.php?topic=137628.15
    TLDR: 2.4.1 fixes it.

  • SIP Phones

    9
    0 Votes
    9 Posts
    1k Views
    T

    Hi.
    Anyone any ideas on this ?

    Thanks

  • Assemblyline - CSE

    1
    0 Votes
    1 Posts
    478 Views
    No one has replied
  • PfSense via pppoe passthrough (no NAT) page load slow issue

    2
    0 Votes
    2 Posts
    725 Views
    S

    Sloved.
    Nothing to do with pfSense setup.
    It is the SG300 managed switch setup, change to an access port with default vlan1. Speed back to normal.

  • Problems Accessing Gmail

    1
    0 Votes
    1 Posts
    317 Views
    No one has replied
  • Gateway IP Address Disabled

    4
    0 Votes
    4 Posts
    612 Views
    J

    Yes, in the WAN Interface.
    The changes you made there interfere with the Gateway.

  • Bad -c option

    11
    0 Votes
    11 Posts
    2k Views
    H

    That makes sense.

    Thanks all!

  • DNS config on pfsense

    1
    0 Votes
    1 Posts
    332 Views
    No one has replied
  • Internal certificate issues without SubjectAlternativeName on pfSense 2.4

    Locked
    3
    0 Votes
    3 Posts
    536 Views
    M

    Thank you for the confirmation. Will wait for the next patch(es).

  • How to configure pfSense with ISP router (no bridge mode)

    22
    0 Votes
    22 Posts
    6k Views
    D

    Guy, like I already said I did a factory reset and used almost all default options except for a few (seemingly) inconsequential options like timezone etc…

    I also said that there was an issue with port labels on the device and interface numbering not matching which meant I was using the wrong ports (LAN and WAN reversed) at first but now I swapped them to the correct position but still had some issues.

    I dont find it a challenge to change LAN address or many other options, but blindly changing options when you dont know how they work is a bad idea. I was confused with some of the options worked like DHCP on LAN. I didnt see seperate DHCP option, that makes sense to me now. Thanks @Grimson for the DHCP explanation.

    Te reason it did work with laptop connected irectl but not over network was bit silly, laptop was connecting to wifi from ISP router before firewall an desktop I tried had static ip (192.168.0.50) when pfsense used 192.168.1.1, so no wonder it didnt work.

    Will try changing the ISP router ip next so my static ip's dont have to change when used with pfsense.

  • Firewall Rule Block Internet Access

    11
    0 Votes
    11 Posts
    6k Views
    L

    Hey.. thx for the picture. Great hint with the defined alias for the rfc1918 area.

    Let me get a bit offtopic:
    I have some virtual machines on my ESXI. One of them is for indexing my documents and to provide a search engine,
    I were finally able to get searchdaimon running. Searchdaimon is unfortunately quite outdated and it seems,
    that the devs are not working on this project anymore. The forum has been taken by bots.
    I dont know any powerful opensource/lightweight alternative for this purpose.
    Even i update centos to 6.9 in the VM and tried to get a clean system, so it will a good thing, to block any traffic to the 'WAN' (any) in this described way..

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.