• Amazon Cloud Drive Issue

    4
    0 Votes
    4 Posts
    1k Views
    M
    Are you sure the entire line is going down? After such a 'crash' have you tried attaching a separate device (laptop?) to your switch and pinging an outside address before restarting everything?
  • How to test your pfsense firewall for vulnerabilities

    14
    0 Votes
    14 Posts
    11k Views
    D
    Thanks guys this weekend when the internet at work is not in use I will try OPENVPN
  • Off site Wifi proxy

    1
    0 Votes
    1 Posts
    723 Views
    No one has replied
  • Loosing connection for all vlans on a LAGG after em-change

    6
    0 Votes
    6 Posts
    1k Views
    D
    I can reproduce this at will on embedded alix2d13 running 2.2.6-RELEASE (i386): lagg0: flags=8843 <up,broadcast,running,simplex,multicast>metric 0 mtu 1500         options=8280b <rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate>ether <removed>inet6 <removed>prefixlen 64 scopeid 0x8         inet <removed>netmask 0xffffff00 broadcast 192.168.17.255         nd6 options=21 <performnud,auto_linklocal>media: Ethernet autoselect         status: active         laggproto lacp lagghash l2,l3,l4         laggport: vr2 flags=1c <active,collecting,distributing>laggport: vr1 flags=1c <active,collecting,distributing>lagg0_vlan9: flags=8803 <up,broadcast,simplex,multicast>metric 0 mtu 1500         ether 00:00:00:00:00:00         inet6 <removed>prefixlen 64 scopeid 0xa         inet <removed>netmask 0xffffff00 broadcast 192.168.18.255         nd6 options=21 <performnud,auto_linklocal>vlan: 0 vlanpcp: 0 parent interface: <none>lagg0_vlan10: flags=8803 <up,broadcast,simplex,multicast>metric 0 mtu 1500         ether 00:00:00:00:00:00         inet6 <removed>prefixlen 64 scopeid 0x9         inet <removed>netmask 0xffffff00 broadcast 192.168.19.255         nd6 options=21 <performnud,auto_linklocal>vlan: 0 vlanpcp: 0 parent interface:</performnud,auto_linklocal></removed></removed></up,broadcast,simplex,multicast></none></performnud,auto_linklocal></removed></removed></up,broadcast,simplex,multicast></active,collecting,distributing></active,collecting,distributing></performnud,auto_linklocal></removed></removed></removed></rxcsum,txcsum,vlan_mtu,wol_ucast,wol_magic,linkstate></up,broadcast,running,simplex,multicast> the vlanid is 0 and interface is none in such cases. Sadly this happens on every reboot or alteration to the LAGG. This is the first time I'm using such a setup on pfsense, thus I don't know if this ever worked before on this platform. I left a comment in the related issue: https://redmine.pfsense.org/issues/3976 but I don't think I have permission to reopen the ticket.
  • Supressing "arp moved" messages on system logs

    7
    0 Votes
    7 Posts
    2k Views
    M
    I often encounter this problem arp,Finally I use forced dhcp resolved. client must re get new ip and obtain IP via DHCP,Secretly setting is can't use Internet.packets will not be sent to pfsense cisco switch–>Try cisco DAI+DHCP Snooping ruckus controller-->enable option:"Enable Force DHCP,disconnect client if client does not obtain valid IP in XX seconds"
  • Long term traffic capture with tcpdump over netcat

    7
    0 Votes
    7 Posts
    4k Views
    N
    plink, ssh , wireshark and tcpdump remote auto start. https://forum.pfsense.org/index.php?topic=89917.msg497700
  • Site to site VPN without using IPSec

    2
    0 Votes
    2 Posts
    2k Views
    ?
    I am having some difficulty creating a site to site VPN using IPSec. pfSense to Draytek IPSec VPN IPsec tunnel established but no traffic - SOLVED! IPSec VPN between pfSense 2.x and DrayTek Vigor 2910 Often made failures: On both sides must be different IP ranges or networks 192.168.1.0/24 - 192.168.2.0/24 (255.255.255.0) pfSense aggressive mode instead of main mode Less secure but mostly good working using MD5 and DES on both sides SHA1 was over long time failing on the DrayTek side
  • Calculate Internet usage per machine

    2
    0 Votes
    2 Posts
    723 Views
    ?
    You could try out Squid & SquidGuard & SARG plus setting up user authentication which would be able to add one device per user and then you will get a detailed report over that Internet access. The other thing is to install PRTG for monitoring for the entire network, to get this detailed informations about all PCs and or each single one.
  • Crash Report (on pfsense SG-2440)

    7
    0 Votes
    7 Posts
    1k Views
    ?
    I have a third site that I was planning on pushing the AES-NI to, and I think I will try that over the weekend - I will have to wait and see if it crashes that. The greater brother of yours SG-4860 will be able to push 500+ MBit/s over IPSec VPN tunnel and this stable as a rock, so perhaps it will be more pending then on the lower power or a miss configuration perhaps. If it doesn't, it's more than likely hardware related. Do you really think that the hardware is malformed or buggy because your IPSec VPN is failing? Hm, I am not really sure but you got two support calls for that actions like explained here in that case. Did you ever thought about that, to take one of this to solve that issues by professional support?
  • Firewall rules for open VPN users by LDAP Security Groups.

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    There isn't any mechanism for LDAP to give that info to pfSense. It does work for OpenVPN logins using RADIUS with the rules passed back in Cisco acl style using an avpair reply attribute (Search around, there are examples on the forum), but LDAP doesn't have a way to do that at this time. You could set that up in NPS, most likely.
  • An ISP and new to pfsense

    3
    0 Votes
    3 Posts
    773 Views
    chpalmerC
    I want pfsense to act like a normal router with a firewall that blocks any one from behind the wan to see whats in please Yes?  as it does by default… And?  ^What Divsys said^
  • PfSense Community installed accidentally on SG-2440

    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    If you register the unit and login to the portal, you can download a full installation image for the factory firmware. It's technically possible to switch using a firmware upgrade, but it's not recommended. You can backup the config and reinstall and be up and running in a few minutes in most cases.
  • 3129 Port, Transparent Proxy Only !

    1
    0 Votes
    1 Posts
    527 Views
    No one has replied
  • Unable to connect to package server

    3
    0 Votes
    3 Posts
    849 Views
    4
    I'm not sure what happened, but after I posted last night, I went and did some firewall and port scans. Just fooling around. After that, I checked the packages again and THEY WERE ALL THERE. So, all's well.  ;D
  • 2 network cards - can access WebGUI but not ping pfSense

    10
    0 Votes
    10 Posts
    2k Views
    johnpozJ
    Well yeah the default any any rule allows icmp, if your not going to use a any any rule and you want to ping you would have to have a rule that allows icmp. So my wireless guest segment is pretty locked down, but you can see I allow them to ping pfsense interface so they can validate connectivity.  Then any other IP of the firewall at all on any port is blocked.  I then allow them out to anything they want as long as not rfc1918 (local networks) - this allows them internet access.  Notice they can not even use pfsense for dns, I hand them public via dhcp for that. [image: allowicmp.png] [image: allowicmp.png_thumb]
  • Hugh packet loss via pfsense

    17
    0 Votes
    17 Posts
    5k Views
    S
    My question: who is "Hugh", and why is he worried about packet loss via pfSense?
  • Port forwarding problems - Probably an easy fix?

    4
    0 Votes
    4 Posts
    785 Views
    M
    Your "Filter rule association" shows "None", which means your port forward was created, but there's no associated firewall rule that is actually allowing the traffic thru the firewall.  Change the "Filter rule association" section to "Add associated filter rule". Should be good to go as far as PFsense is concerned.
  • Unexplained traffic drop

    3
    0 Votes
    3 Posts
    847 Views
    N
    no proxy. most of the storage is consumed by ntopng i presume.
  • Pfsense and Proxy

    3
    0 Votes
    3 Posts
    1k Views
    ?
    Hello, use a radius server for all internally employees and the captive portal for all guests only. Set them up in different VLANs and install Squid & SquidGuard & SARG to realize a proper logging for all actions you want. You could also setup static IP addresses and/or a user authentication for Squid. many ways are able to wake on.
  • Squid3 ssl inspection with Transparent mode

    6
    0 Votes
    6 Posts
    2k Views
    M
    i know what you mean, but if this is the point, so they should remove the feature and say it's not exist for security reasons or whatever, but they choose to put half of it, as you could enable it but you won't be able to bypass any sites with FQDN you must get all IPs and bypass it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.