• Heavy drive activity on standby firewall

    2
    0 Votes
    2 Posts
    523 Views
    K
    Activating the RAM disk options for /var and /tmp under System > Advanced on the Miscellaneous tab will reduce the amount of writes.  This is extremely effective on standby members of a two-node cluster on heavily-utilize internet connections!  Disk writes went from up to 100MB/s to nearly zero on the standby firewall in the HA carp cluster.  Since the firewalls are servers with plenty of ram, I set the ram disk sizes to 1 GB for /var and 500MB  for /tmp .
  • Any pfSense guru to help me choosing a setup for a small network ?

    17
    0 Votes
    17 Posts
    3k Views
    DerelictD
    That iTel looks like a pretty good service if the use case is right.
  • Could this be working? PfSense on the same subnet - Transparent Proxy

    4
    0 Votes
    4 Posts
    588 Views
    KOMK
    Why do you want to specifically use pfSense here when all you seem to need is a proxy server?  Any *BSD or *nix box could do that for you. I've never heard of a single-NIC config where the NIC is WAN.  I also haven't had the need to actually configure like this, so I don't have direct experience.
  • VLAN Config/Bridging on one interface

    5
    0 Votes
    5 Posts
    2k Views
    C
    Once the VLANS have been configured on the physical interface they should be listed in the drop down menu at the bottom of the interface selection with "ADD" to the right (I've attached pic from my home unit) Once added you can then configure the IP addresses / etc of them and should be able to bridge them from there. ![pfsense add int.PNG](/public/imported_attachments/1/pfsense add int.PNG) ![pfsense add int.PNG_thumb](/public/imported_attachments/1/pfsense add int.PNG_thumb)
  • Watchdog?

    8
    0 Votes
    8 Posts
    2k Views
    C
    @hypernative: Dial on demand.. that's new information for me. The line is fiber.. Why i want it to be restarted compeltely: The router is running is a VPN-client, all traffic is routed via the external vpn source. If the VPN provider has problems, and later when the VPN service is UP again there can be scenarios when the router has to be restarted.. Well I was referring to reauthorizing PPOE (if you were using it), and again, can't you build an IPSEC tunnel on the pfsense directly to the remote end, that would bring the tunnel up when it sees interesting traffic instead of involving another random bit of hardware running it's own VPN client?
  • 0 Votes
    4 Posts
    883 Views
    DerelictD
    There is a recent hangout explaining how to use OpenVPN as a WAN (PIA, etc). It goes into detail regarding policy routing. Yes, Gold Membership gets you access there. October 2016 pfSense Hangout on OpenVPN as a WAN with pfSense March 2016 was Multi-WAN: https://portal.pfsense.org/webcasts/index.php?video=160624666
  • [solved] significant problem with throughput through our pfsense

    8
    0 Votes
    8 Posts
    3k Views
    U
    So… it seems to be the LRO that is decreasing the throughput. I'll keep you informed. *edit: i think that and some performancetuning helped.
  • Ddns + port forwarding

    6
    0 Votes
    6 Posts
    2k Views
    B
    Ok. Found my miracle. One firewall rules block this.
  • Iperf perfomance

    10
    0 Votes
    10 Posts
    2k Views
    H
    i would stop trying to measure from/to the firewall. This is pointless & incorrect. try this & report back: iperf-server<->routerWAN | routerLAN <–> iperf-client
  • New user :) Setup Wizard - Sufficient for security to start with?

    3
    0 Votes
    3 Posts
    658 Views
    B
    Thank you very much hda!
  • Dpinger and virtual ips

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: Squid Certificate https

    Locked
    1
    0 Votes
    1 Posts
    316 Views
    No one has replied
  • 0 Votes
    1 Posts
    269 Views
    No one has replied
  • PFSense machine stops responding (temporarily) when restarting DHCPD

    1
    0 Votes
    1 Posts
    371 Views
    No one has replied
  • PXE boot arch linux ISO

    1
    0 Votes
    1 Posts
    910 Views
    No one has replied
  • Which DNS server to use on multiple vlans?

    9
    0 Votes
    9 Posts
    8k Views
    C
    @johnpoz: You do not need to put anything in there if you just want to have the dhcp clients point to IP the dhcp server is running on for dns..  Its right there in the text below the dns boxes.. Leave blank to use the system default DNS servers: this interface's IP if DNS Forwarder or Resolver is enabled, otherwise the servers configured on the System / General Setup page. Thanks, apparently I've read way too much in the past few days and my brain is melted. Thank you for your patience, I got it :D
  • SG-1000 No WAN Access

    3
    0 Votes
    3 Posts
    550 Views
    A
    The wan is a 10.0.x.x /16 and the LAN side is the default 192.168.1.x /24.
  • Getting Into PfSense

    3
    0 Votes
    3 Posts
    705 Views
    chpalmerC
    Try the WAN NIC.  They might be swapped.
  • WSUS

    6
    0 Votes
    6 Posts
    2k Views
    jahonixJ
    @vitoreiter: …and for security purposes I can't really give exact IP's. For example lets say that WSUS is on x.x.x.45 and other systems are on the same subnet ... Do you use public IPs internally? Then use RFC5737 Test-Net addresses for documentation, that's what they are there for. But usually RFC1918 are misunderstood. I'm currently dealing with a university that does just that, use public IPv4 addresses internally. And only internally…
  • Zotac CI323 Crashing pfSense 2.3.2 - WAN interface says up but no IP??

    26
    0 Votes
    26 Posts
    4k Views
    PippinP
    So, driver issue, who`s responsible for that ;)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.