• OpenVPN config question…

    3
    0 Votes
    3 Posts
    939 Views
    N

    Thanks guys!  I ended up upgrading to the latest version of pfsense and re-installing the new exported client and it works fine!

  • Bandwidthd using 100% CPU

    1
    0 Votes
    1 Posts
    949 Views
    No one has replied
  • Speed graph on main login page

    7
    0 Votes
    7 Posts
    2k Views
    ?

    @stephenw10:

    You will see traffic passing between two internal interfaces vlan or not.
    The only way you wouldn't see that is if your switch is layer 3 and is setup to route between the vlans.

    Steve

    thanks.  that does make sense.

  • Pfsense Passive ftp with ftpproxyhelper

    1
    0 Votes
    1 Posts
    865 Views
    No one has replied
  • Pfsense não conecta ne interne por nenhum dos dois links

    4
    0 Votes
    4 Posts
    1k Views
    J

    Thank you all very much …

    The way I found to solve it was back a backup that ha had done a month ago ...

    Being that I have not changed anything in the settings ...

    Very Strange ...

    Given as solved then ...

  • Unable to ping traffic between VLANs on interfaces

    8
    0 Votes
    8 Posts
    2k Views
    stephenw10S

    It's not a private IP address. Do you own that IP?

    Steve

  • Default State of Managed Switch - Secure or Insecure

    3
    0 Votes
    3 Posts
    1k Views
    stephenw10S

    Exactly.

    1. All switches default to one VLAN across all ports, almost (?) always VLAN1.

    2. Nope but this is the reason some people don't trust VLANs for separating network segments especially, say, WAN and LAN. That and the possibility that your switch firmware has some exploitable bug allowing packets to change VLAN, never seen that either.

    3. Some switches have an unmanaged mode they default to that is indicated somehow. The Dell PowerConnect range, for example, have a managed mode LED on the front that tells you the switch has been configured away from it's default state. If it did default back to unmanaged mode the LED would go out, you would know.

    Steve

  • Notification Settings

    1
    0 Votes
    1 Posts
    571 Views
    No one has replied
  • Changed configuration settings log

    2
    0 Votes
    2 Posts
    564 Views
    jimpJ

    Not quite sure what you're asking for since it's a little vague, but perhaps this?

    Diagnostics > Backup/Restore, Config History tab

  • Apinger - Email when alarm is cancelled

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    There isn't a way to do that currently because what tends to happen is less that apinger sees it recover and more than apinger is restarted and it is assumed that the gateway is up. If you received an e-mail whenever it assumed a gateway was up, you would not be happy. :-)

    That is likely to improve in the future especially now that we restart apinger less frequently.

  • Default Dev Languages Available?

    5
    0 Votes
    5 Posts
    1k Views
    jimpJ

    It isn't used for anything post-install, but there is also a Lua interpreter included ( /usr/local/bin/lua50 ) and of course you can run shell scripts or install your own packages as cmb described.

    PHP is the best choice for most things, as that's what most of the other code uses.

  • Which VPN for Windows 7 native client & IOS

    9
    0 Votes
    9 Posts
    2k Views
    jimpJ

    At the moment, yes, but it looks like that will be better on 2.2

  • MOVED: Dansguardian - Squid Issue?

    Locked
    1
    0 Votes
    1 Posts
    650 Views
    No one has replied
  • How to aggregate many internet connection

    4
    0 Votes
    4 Posts
    2k Views
    J

    @stephenw10:

    Exactly, ML-PPP is the best you can do.
    I don't see how this could be done with multiple VPN connections as they're too high up the OSI model. I would think you need something below layer3. Do you have a link to anything explaining this?

    Steve

    I'd think OpenVPN TAP would get you to the level you'd need.

    Jimp made some comments about a feature like this being on the roadmap but being way down on the list unless someone sponsored the development. He also said something about possibly using Kickstarter for larger features like this.

  • What is my bandwidth being used by?

    4
    0 Votes
    4 Posts
    1k Views
    P

    Am I correct in assuming that "WAN in" is traffic coming from the internet into the WAN interface, and that LAN "out" is traffic leaving the LAN segment?

    All "In/Out" on the Traffic Graph and table of bandwidth In/Out by IP are relative to the interface or client being reported.
    A download from the internet comes In to WAN, Out of LAN and In to the end client system on LAN.
    An upload comes Out of the end client system, In to LAN and Out of WAN.

  • Two gateways, how to split smtp.

    1
    0 Votes
    1 Posts
    690 Views
    No one has replied
  • Asterisk behind PFsense, problem after WAN down

    8
    0 Votes
    8 Posts
    3k Views
    D

    <started another="" thread="" with="" details="" of="" my="" issue="">Hopefully someone will respond there…hopefully.</started>

  • Does PFSense modify TCP window sizes?

    2
    0 Votes
    2 Posts
    1k Views
    P

    TCP window size is a parameter at a higher layer that end-systems use to work out how much data to have outstanding in the pipeline before waiting/expecting ACKs to have come back. I played with this many years ago tuning continuous flows of a data acquisition process across a long link. TCP window size needs to be adjusted on the end-systems.

  • SSH Login Options

    11
    0 Votes
    11 Posts
    4k Views
    A

    Steve,

    I'd noticed that checkbox previously, but had misinterpreted its likely behaviour and steered well clear.

    But, with it enabled, I'm certainly getting a bit closer to where I wanted to be, though it still leaves PermitRootLogin enabled globally.  I had intended to disable Root from the WAN.
    (It may well be that KeyAuthenticationOnly, when no-one has the key, is as hacker-proof as a total prohibition on RootLogin would be anyway).

    I am, however, beginning to suspect that pfSense may not be correctly honouring MATHES of host addresses when given in the form "192.168.1.0/24" (as specified in the man pages you pointed me at) whilst it does accept "192.168.1.*".  This may explain some, if not most, of my earlier confusion.

    More news when I've done some more testing…

  • Network switch sought

    20
    0 Votes
    20 Posts
    4k Views
    V

    Have you looked at Dell PowerConnect?  Can get 24-port, Gb, layer 3 switches for under $2k.
    Have older 6224 running on SAN duty for over two years with no problems.

    http://www.dell.com/us/business/p/powerconnect-6200-series/pd?refid=powerconnect-6200-series&baynote_bnrank=0&baynote_irrank=0&~ck=baynoteSearch&isredir=true

    Vince

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.