• MOVED: freeradius question

    Locked
    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
  • Get max performance from fiberlink with Pfsense possible?

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    stephenw10S

    Doesn't actually help provide an explanation either way!
    The 'ethernet extentions' product is routed via their fibre network, which is presumably shared with other traffic, where as the extensions+ product is swiched ethernet.
    Plenty of people complaining about virgin media in general though.  ::)

    Steve

  • Interface bridging

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    jimpJ

    There is also

    http://doc.pfsense.org/index.php/What_is_a_bridged_interface_and_how_would_one_be_used%3F

    If you clicked the category at the bottom of the link you posted (for "Bridging") that shows up.

    I just added a "See also" link to the page so it's a little more obvious.

  • SIP phone behind pfSense wall

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    No.

  • Telnet on Pfsense

    Locked
    7
    0 Votes
    7 Posts
    7k Views
    K

    @XIII:

    @k6usy:

    To many bots out there trying to crack simple passwords I would rather not have the traffic going to my router.

    Thats why you use key based SSH authentication, cuts down on the exposure drastically.

    That works too.

  • Fowarding connections based on subdomain

    Locked
    1
    0 Votes
    1 Posts
    983 Views
    No one has replied
  • PFsense not passing/routing traffic between WAN/LAN

    Locked
    6
    0 Votes
    6 Posts
    22k Views
    S

    Thank you Wallybob for walking me through routing troubleshooting. It was a routing problem all along. I thought the AP was acting as a bridge, but it was actually a DHCP server and didn't know where to forward 192.168.2.0/24 traffic. FACEPALM In my defense, it's my first week on the job…  :P

    Lessons learned:
    PFSense does not randomly drop traffic.
    If you can't reach something because of routing, you do not always get Destination Host Unreachable when pinging.
    Have faith in the system logs.

    Thanks,
    Seanny

  • Setting up Pfsense with C class through ADSL modem

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    E

    If you can get them to route those addresses to a separate static IP in a different subnet (like maybe your existing static IP, for example), you could do this with routing instead of bridging and your DHCP server could directly hand out public IP addresses on the local side.

  • Routing entries - is there any limit? [ANSWERED]

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    The limit would be at what point the XML gets so big it causes performance degradation. That's so high that it's WAY beyond what any sane network would have in static routes, I've seen systems with hundreds of static routes on slow hardware with no impact, could easily do many thousands. Beyond a few hundred you probably aren't routing very optimally, or should be using a dynamic routing protocol. People run the BGP package with multiple full Internet routing table feeds, that's over 350,000 routes in the routing table, and 2-3+ times that in BGP.

  • How to stop downloads from YTD YouTube Downloader software

    Locked
    11
    0 Votes
    11 Posts
    19k Views
    N

    @dreamslacker:

    @nearones:

    Can some one guide me how to make rule for mime type in pfsense, i had gon through many docs, but all r on SQUID

    You don't.  You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well.  That's that.  No buts.

    Short of actually sniffing traffic and writing your own layer7 patterns to block YTD, you're out of luck.
    Even so, I believe that YTD, like most download software can spoof normal browser traffic so you would be out of luck there as well.

    What you have isn't a network policy problem.  It's a system policy problem.
    If you want to stop YTD, get on the systems and actually amend the GPs to prevent it from installing or running to begin with.  Alternatively, use a software firewall on the system that simply drops traffic originating from the YTD software.

    You use the MIME blocking for Squid installed as a package in pfSense.  However, this will block normal browsers from viewing youtube as well.

    What u said is also the good method to block some other websites like onlinegames, porn websites. But how can i do that in pfsense.

  • Need a little help

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    B

    @SGTR:

    Hi,

    For your case you should check out link http://doc.pfsense.org/index.php/FreeRADIUS_2.x_package#Accounting_with_Captive_Portal You might be put your printer different VLAN. You should check your switch conf. or port. Have you done nat rules for your clients ports? What is your nat rules? You can use traffic shapping for this.

    SGTR

    Hi SGTR,

    I fixed everything by just changing my setup a little. It now looks like this:

    Clients –-- switch ---- pfsense ---- switch ---- router ---- internet
                                                        |
                                                      server
                                                        |
                                                      printer

    This setup also allows me to apply stronger security on our clients.

    Now the only thing is trying to get daloRadius to read the FreeRadius sql hidden somewhere in pfsense, hope your link can help with that.

  • PPPoE Idle Timeout

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M

    http://forum.pfsense.org/index.php/topic,47594.0.html

  • PPPoE Disconnects

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    N

    There appears to be a bug in my version of PfSense.  On the WAN interface, set for PPPoE, it does not allow you to save a "0" setting for "Idle timeout."  You can save such a setting if you enter the value via the Setup Wizard, however, editing the WAN page appears to dump the setting.  One can imagine what kind of problems this bug creates.

    :(

  • MOVED: Basic question

    Locked
    1
    0 Votes
    1 Posts
    687 Views
    No one has replied
  • Firewall syslog logging - who can explain the pf logs?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S

    Thanks for your feedback.
    If we do change things anyway, it would also make sense to send a hostname or IP address within the syslog header to make it more RFC compliant.
    Would you like to add that to your feature request?

  • Md5sum's

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    You have decompressed the image. The md5 is generated from the original compressed version present on the server.

  • Relayd sends traffic to a host that is down in 2.0-RC1

    Locked
    8
    0 Votes
    8 Posts
    2k Views
    jimpJ

    Yes we do, the patches are all in the tools repo.

  • PFSense as firewall for Cloud hosting provider (500 VMs)

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    That type of deployment is amongst the most common we do. We've done in excess of 100 datacenter setups similar to that for customers, and there are probably thousands of others out there that we've had no involvement in.

  • Bing.com

    Locked
    2
    0 Votes
    2 Posts
    986 Views
    C

    It's a feature, we're not fans of Microsoft.  ;D

    No seriously, sounds like it's not a firewall-related issue. You're getting to some web server since you're getting a 404, and unless you put in an override in the DNS forwarder, it's sending you to whatever IP your configured DNS servers are responding with. What IP does bing.com resolve to?

  • Some clients getting IP from strange source..

    Locked
    17
    0 Votes
    17 Posts
    5k Views
    pttP

    i'll give that a shot.. what exactly does that do?

    "If" i'm not wrong (i'm not a networking expert)

    DHCP server "BOOTPS" have as src port 67, then if you block ANY (0.0.0.0/0) traffic coming from your Clients to the WLAN interface of your AP,  from port 67, then you are Blocking ANY external DHCP server.

    About MikroTik, i can't help you. We are only using it as "Access Concentrator" (fancy name for a PPPoE server) and giving our customers "Static IPs", so i have no experience with MT and DHCP server / DHCP Relay  :-[

    Also we are planning to take out the MikroTik PPPoE Server from our network (due the fact that Ubiquiti cant do QoS on encrypted traffic) and use Static IPs on the CPEs (in Router mode), and connect our APs (in Bridge mode) directly to the  pfSense server.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.