• User Manager using LDAP but OU with spaces not working ?

    6
    0 Votes
    6 Posts
    2k Views
    H

    @BeerCan:

    try

    User naming attribute = samAccountName
    Group naming attribute = cn
    Group member attribute = memberOf

    There is more but I am late for a meeting :)

    perfect thank you, that works under Diagnostics - Authenication and with the space in the OU name (no need for %20 etc).

    Now how do I allow this to log on to pfsense for report monitoring ?

  • Percent normally normal range right around

    2
    0 Votes
    2 Posts
    523 Views
    DerelictD

    What would be cool would be if SMF would automatically suspend posting privileges for accounts with < 5 posts with a 1:5 or greater posts:smites ratio.  That way we could just crowd-moderate these fuckers.

  • [Solved] DNS Rebinding Attack. No access to Server inside DMZ from LAN.

    13
    0 Votes
    13 Posts
    5k Views
    W

    @cmb:

    @kejianshi:

    Is it a 2.1.5 problem also?  Thats what those pfsense I was talking about are on.

    No, that problem never existed in 2.1.x, that was a regression in 2.2 only that I fixed a couple days ago. Guessing it is the cause of OP's issue if that's on a snapshot that's more than 1-2 days old.

    It worked! :D

    Current build is  Fri Nov 07 00:00:15 CST 2014, FreeBSD 10.1-RC4-p1.

    Unchecked

    Firewall -> NAT -> 1:1 -> Edit -> NAT reflection = use system default

    Services -> DNS forwarder ->

    Register DHCP leases in DNS forwarder
    and
    Register DHCP static mappings in DNS forwarder

    Unchecked.

    And of course the settings for DNS Split in Services -> DNS forwarder -> Host Override.

    Only thing is. When having multiple websites on one machine that you can access via different subdomaines like
    site1.mydomain.com
    site2.mydomain.com
    etc.
    Host Overrides only gives you the default website since I can not assign a specific directory to a subdomain.

    But I guess we will figure something out. It is not as important as the mailserver was.

    So thank you very much!

    –---------------------------------------

    //Edit: Just a little update for all the googlers that might come here later. To solve the website issue, we setup our own bind DNS on an extra machine.
    This DNS handles all requests from IPFire. Directs requests to sub.domain.com to the internal IP of that server.
    And in case that IP is a Webserver, Apache with Vhosts handles it and forward that to the specific directory.
    So thats it :)

  • Squid and Squidguard Service stops at 7:55am every morning

    7
    0 Votes
    7 Posts
    1k Views
    J

    FreeBSD-based.  Going to look at upgrading in the first instance.  Thanks for your help

  • Canot access https from pfsense box

    1
    0 Votes
    1 Posts
    491 Views
    No one has replied
  • After editing, Pfsense dooesn´t boot

    1
    0 Votes
    1 Posts
    522 Views
    No one has replied
  • Ftp Proxy on PFSense

    2
    0 Votes
    2 Posts
    1k Views
    X

    up!

  • PfSense, ALIX & Cisco Router Guidance

    1
    0 Votes
    1 Posts
    943 Views
    No one has replied
  • Web interface down, barely routing, dns failures, etc

    2
    0 Votes
    2 Posts
    746 Views
    K

    Sounds like either your pfsense is seriously hosed or the computer you are using to access it is.  Not sure if a switch could cause this, but I'd direct connect to the pfsense to test.

  • LAN pings and External IP

    11
    0 Votes
    11 Posts
    2k Views
    K

    haha - well take comfort in knowing that your simple mistakes are the only mistakes I could spot (-;

  • Bandwidth use details

    7
    0 Votes
    7 Posts
    2k Views
    johnpozJ

    Well that is easy enough to fix - why would those ports be open, only thing outbound from a work network should be the proxy ;)

  • VPN - Routing Issue - Only Linux Hosts

    40
    0 Votes
    40 Posts
    6k Views
    P

    Basically in the DNS forwarder where you can specify a domain override, I had to also specify the LAN IP of pfSense (172.26.10.254 in my case) as the "Source IP" on the domain override configuration.

    You usually have to do that when the DNS server that services the domain in question is over a VPN, because otherwise the source IP of the request (from the pfSense, across the VPN to the DNS server) will be some IP address of a VPN tunnel endpoint, or some internal tunnel address. The remote DNS server typically won't have a route back to that and so the reply to those DNS queries would never make it back.

  • 2.1.5 32bit - what is running on ssh?

    9
    0 Votes
    9 Posts
    1k Views
    ?

    Cable attached, yepp, both ends…

  • How to avoid rebooting firebox if WAN goes down?

    1
    0 Votes
    1 Posts
    516 Views
    No one has replied
  • HomeHub wireless access point

    2
    0 Votes
    2 Posts
    914 Views
    T

    If I am understanding correctly, you basically want the pfsense box to be the modem and your homehub just to provide wifi?

    if so you just set one of your interfaces up as WAN, IP and DHCP, connection as PPPoE and username and password as you say.

    I have done that for my infinity without issue. Then you can setup one other interface on a separate VLAN and plug the WAN port of the homehub into that pfsense port. Place rules on the guest vlan to deny traffic to your other main interface, deny ports 22 and 443 (so they cant SSH or get to the router management pages) and allow other traffic. Theres plenty of tutorials on the subject just google "pfsense guest vlan"

    HTH.

  • Cant Ping LAN…

    7
    0 Votes
    7 Posts
    2k Views
    E

    I went back to the provider with the information we had obtained through this test, and they 'have identified an issue with the host node' my VPSs are on.

    Thank you for your help, at least I could go to them with some idea of what I was talking about.

    Per your signature, I'll be buying some Nepalese children a Christmas party.

    Thanks again.

  • Pfsense lusca 2.1.3

    19
    0 Votes
    19 Posts
    11k Views
    E

    @cmb:

    @cabnet:

    so i better switch to the lower version which lusca cache is supported ..

    Hell no. Use Squid. There is absolutely no reasonable reason to use Lusca.

    you always say to use Squid but there is no noob step by step tutorial to make it work like lusca does.
    lusca caches everything and there is a lot of step by step guide to make it happen. and that satisfies our needs.
    I tried to install Squid many times  and try to follow every procedure in the net but still fail to cache everything
    that i browse like webpages, patches for games, specially videos from the net, etc. i guess some of us are maintaining
    5 or more pc's that is why pfsense lusca is very handy. hope you get what i mean and why we still insist to use lusca.

  • RAMDisk usage

    7
    0 Votes
    7 Posts
    3k Views
    stephenw10S

    In Nano it's in the same place as the /var and /tmp ramdisk options, in System: Advanced: Miscellaneous: Originally that option was in Diagnostics: NanoBSD: which obviously doesn't appear on the standard 'full install' type. I don't have a full install to check that.

    As Phil has said those options are there to make things more like Nano rather than for speed advantage. Though obviously a ram drive will be much faster than any standard drive type. If you were running a full install from a Disk On Module device you might want to move /var and /tmp to ram to reduce writes to the device.

    In pfSense things mostly run in RAM anyway. I doubt you'll see much improvement in performance unless you have something custom going on.

    Steve

  • Locked myself out of webGUI

    9
    0 Votes
    9 Posts
    2k Views
    P

    I would definitely go down the path of getting a serial cable - you really want one for the day when the system is power-cycled and nothing seems to come up. Being able to see the real console output is a must.
    I bought 1 of these serial cables for every site a few years ago: http://www.amazon.com/Tripp-Lite-Modem-Serial-P450-006/dp/B000067SCH/ref=pd_sim_sbs_indust_1?ie=UTF8&refRID=07T1K2VK31YGRK09HC5Z and they have all worked fine.
    and you need a client (laptop, desktop whatever) that has a serial DB9 port, or a USB to serial device.

    If you do re-flash, then make sure to use an image from Netgate. The Netgate images have whatever special parameters need to be set to get a successful boot the first time (e.g. boot_delay …). I have no idea if the FW-7551 needs anything special like that, but by using the Netgate image you should have no trouble.
    But don't do that - wait for a serial cable!

  • Dns forwarder issue

    9
    0 Votes
    9 Posts
    3k Views
    johnpozJ

    @esampathj:

    Never heard it before. Any idea how to disable it ?

    Under dhcpv6 on the services tab - see attachement

    Windows is going to prefer ipv6 out of the box..  If your not using ipv6 on windows, just disable it would be my suggestion.  Security 101 - if your not using the protocol, then the protocol should not be active.  Simple as a elevated prompt in windows

    reg add hklm\system\currentcontrolset\services\tcpip6\parameters /v DisabledComponents /t REG_DWORD /d 255

    No more ipv6 to worry about..

    underdhcpv6.png
    underdhcpv6.png_thumb

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.