• Does NameCheap dyndns work for anyone?

    15
    0 Votes
    15 Posts
    7k Views
    T
    BANG ON! darn it. What a waste of time. The pass from NameCheap portal was suffixing a white space. It seems like all the code update I did is waste now :( Thanks a lot though everyone!
  • What are some of the things you do when you install pfSense?

    14
    0 Votes
    14 Posts
    7k Views
    T
    Set System > Firmware > Update Settings to either Stable or Developmental firmware. I would set it to developmental having learned my lesson of seeing broken features in stable versions but working in developmental version - many vouch for dev version to be stable in production.
  • Some web sites request timeout through pfSense

    8
    0 Votes
    8 Posts
    3k Views
    K
    browsershots.org doesn't like that site either. Ends up stopped at  can not load krungsri.com/robots.txt Totally not a pfsense issue.
  • Best upgrade to Alix boards for pfSenes?

    7
    0 Votes
    7 Posts
    2k Views
    jimpJ
    @torontob: In production is the FW-7541 as reliable as Alix? I have Alix that have been running 24/7 for the past 4-5 years without any issues. Well they haven't existed quite that long so I can't really say. :-) They do quite well from what I've heard. Lots of customers have them and they're happy…
  • [SOLVED] Internal NIC dies, lights off att "Configuring firewall"

    3
    0 Votes
    3 Posts
    1k Views
    D
    @tim.mcmanus: Try installing 2.1.  There is broader chipset support in it. I've tried 2.1 RC0 without success. Just so you don't misinterpret me - pfSense has worked flawlessly since April - and only now started acting up. Or maybe it's my NIC. Anyway, I ordered a new one and hope it'll help.
  • Edit pfsense from CLI and not show in webGUI

    4
    0 Votes
    4 Posts
    1k Views
    jimpJ
    yes. It shows up there.
  • Specific PC net monitoring.

    4
    0 Votes
    4 Posts
    1k Views
    M
    Off the top of my head, I believe this can be done with PFsense and the BandwidthD package.  Others can chime in on a more polished package if one exists. If you're looking for something that installs on the PC, I'd say Google your needs… e.g. "free bandwidth monitor", "free traffic monitor", etc.... there's a bunch of them out there... none that I've tried unfortunately.
  • MOVED: Tracabilité dans PfSense !!!

    Locked
    1
    0 Votes
    1 Posts
    697 Views
    No one has replied
  • Skype not working properly

    20
    0 Votes
    20 Posts
    11k Views
    K
    Well - Like I said, the effectiveness of this will also depend on you getting things like "ultrasurf" off your network. I did have a little conversation with some very smart people on that subject here: http://forum.pfsense.org/index.php/topic,64432.msg349171.html#msg349171 Pay special attention to one post by phil.davis and how he handles port 53 with this solution. Basically, you want to only allow access to port 53 to your pfsense box and the DNS servers at dyndns from the LAN. You can set up your DYNdns filters at https://account.dyn.com/labs/dyn-internet-guide/              (log in to dyndns first) Then click defense plan or default defense.  Modify it to block whatever you need blocked in the office) You will need to also set up your dynamic DNS service in pfsense so that dyndns always knows your network's IP. Then follow instruction I gave in the thread above.
  • Is this setup Feasible? Medium Sized-Biz

    1
    0 Votes
    1 Posts
    983 Views
    No one has replied
  • System log quit working after a panic reboot

    5
    0 Votes
    5 Posts
    2k Views
    B
    Thank You to the suggestoins made to the syslog problem. After looking a second time,,I noticed this time in the syslog it was showing something about" kernel/boot was a binary files".( one line of logging) I done a "Clear log" as suggested. This got rid of 'the binary file ' thing',,and system log is working again now. This machine actually panic rebooted ,again last night ,overnight,,,drove to the remote location where this pfSense machine resides to find one of the  case cooling fans had quit and the second case fan is barley turning so,,I'm sure it is overheating,,,not an pfSense/OS problem at all. Take Care, Barry
  • Access AP behind pfsense

    6
    0 Votes
    6 Posts
    2k Views
    K
    I think its smarter to put an extra NIC card in the pfsense so that you have WAN  (assigned by ISP DHCP)  Plugged directly into modem LAN (for you)        -  10.15.20.0/24 OPT (for visitors)  -  10.15.21.0/24 Then plug an AP into OPT1 port for visitors.  Bind Captive portal to OPT1 If the AP gets a STATIC IP on the OPT1, you can allow just that 1 IP to LAN net (10.15.20.0/24) in Firewall Rules.  Then: In firewall rules for interface OPT1 block any with DESTINATION LAN net  (10.15.20.0/24)  (Before the pass everything rule) The AP interface should be available to you.
  • Content filtering on systems without use of squid or dansguardian

    15
    0 Votes
    15 Posts
    7k Views
    P
    Your solution still works - it sometimes might work for an even wider audience than planned. My real office users have desktops in the domain, or laptops for which they do not have admin privilege. So they can't change their allocated DNS server and can't add 1,000 naughty name/address pairs to their hosts file. All DHCP for allowed/known devices are static mapped. General devices in the DHCP pool get addresses in a range that has internet access blocked. When someone arrives with a new allowed device they have to get the WiFi password, connect, then we find them in the DHCP pool and static map them to their proper allocated address. Of course, someone can connect by cable to a real wall socket, set at suitable IP address and get access - but these days most people want to get their mobile device onto the WiFi, so they are stuck at step 1 getting the WiFi password. I block any TCP+UDP to port 53 !LANaddress - then people with personal devices can set whatever DNS server they like, all the ones other than the one provided on the pfSense will simply not respond/work. These people with personal devices could still load up a hosts file with a list of naughty site names and IP addresses that they get from somewhere, but they know the organisation policy and that there would be big trouble if they were caught going to those lengths to access prohibited material. For me, the DNS provider filtering option is quite effective, simple to use and cheap!
  • ALERTS on RRD Categories

    3
    0 Votes
    3 Posts
    2k Views
    P
    Thank you sir.  Will have to wait for 2.1.  I've got 1.2.3 as the rock solid ones in production.
  • PFSense - Kernel Panic on 2.0.3 - Redundant Firewalls

    3
    0 Votes
    3 Posts
    1k Views
    D
    Looks like I have the double-whammy with both igb interfaces (Intel expansion slot) as well as Broadcom on board. Thanks for the quick response, I'll deploy this on the two firewalls I'm building for the local office. I'll definitely let you know if this fixes the issue. Thanks
  • SD Card encryption

    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    We don't officially have any support for disk encryption, but FreeBSD does. It does require manually entering the password, otherwise as doktornotor said it would be pretty worthless. You can have security, or you can have convenience, you can almost never have both. http://www.freebsd.org/doc/en/books/handbook/disks-encrypting.html You need an unencrypted section of the disk in addition to the encrypted section (or two separate disks), I don't believe it supports booting from an encrypted disk for some obvious reasons. If you're that worried about someone stealing the CF, then you either need to not keep such sensitive data on it, or invest in some good physical security measures to keep it physically safe and locked up.
  • XMLRPC sync without CARP/pfsync

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    Sure, XMLRPC works with or without CARP. Some people use it just to sync aliases and such.
  • Bandwidth test = fine, browsing = impossible

    2
    0 Votes
    2 Posts
    910 Views
    S
    I should note that this is 2.1 because of RADIUS/IPSec
  • A new vulnerability was discovered in Haproxy !!!

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    The haproxy package on pfSense 2.x is already on 1.4.24. Just reinstall the package and you'll be OK.
  • Routing of the public ip to the switch in pfsense.

    6
    0 Votes
    6 Posts
    2k Views
    M
    Or I use the option virtual ips? http://doc.pfsense.org/index.php/What_are_Virtual_IP_Addresses%3F
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.