• OpenVPN 2FA disconnects

    5
    0 Votes
    5 Posts
    662 Views
    M

    @the-other

    f2b8929a-3ac9-43ba-99a2-4e7d6fd6257d-image.png

    e6e9eced-0a1c-41e8-b66e-6752a70d1860-image.png

  • Questions about setting up a more secure home- and small business network

    6
    0 Votes
    6 Posts
    917 Views
    S

    @johnpoz said in Questions about setting up a more secure home- and small business network:

    @stef_r please tell you don’t have idrac exposed to public internet you vpn into the edge?

    I am aware that exposing the iDRAC interface to the public isn't a smart way to do it! :-)
    So yes, I have restricted access for only one trusted IP address and only through the VPN connection through the EdgeRouter.

  • 0 Votes
    19 Posts
    2k Views
    Dobby_D

    @jonathanlee

    As soon as cookies are cleaned it's gone.

    I would say you could install some privacy addons
    and say absolute no to cookies! And you only keep
    your cookies from your switches and routers or firewalls
    and use only that one (browser) for your internal tech equipment.

    Google Analytics I have never seen on it. I have seen
    cloudflare analytics also.

    pfBlocker-NG and/or Squid & SquidGuard may be sorted
    with some add blocker lists.

  • Basic firewall rules for interfaces

    13
    0 Votes
    13 Posts
    1k Views
    J

    @bumzag said in Basic firewall rules for interfaces:

    I want LAN to have access to every interface indiscriminately, and NET2 to have WAN access, but no LAN access.

    The block comes before the allow so LAN would be blocked

  • bad nginx errors in system logs

    9
    0 Votes
    9 Posts
    1k Views
    N

    @steveits fair enough, will just pivot to blocking all and only allowing ports that are confirmed in use, thank you for the confirmation

  • pfsense vs Fritzbox securety

    5
    0 Votes
    5 Posts
    2k Views
    C

    As the Fritzbox can be accessed and adjusted remotely by your ISP (similarly to most ISP supplied boxes) you can not guarantee your configuration as well as one can with a pfsense box. It is worthwhile with a Fritz!Box looking at the security tab to see what open ports exist and the services supported.
    Configuring pfsense to work with a Fritz!Box in modem mode is a whole other kettle of fish!

  • Migration several Netgate 7100 to 8200

    3
    0 Votes
    3 Posts
    570 Views
    L

    Ok perfect...

    I would like to keep all the configuration of ACLs, VPN, etc. redoing everything by hand, besides the waste of time would definitely cause errors.

    Thank you very much

  • Migrating from Mini Computer with pfsense to 6100

    Moved
    10
    0 Votes
    10 Posts
    975 Views
    stephenw10S

    I would not remove the switch if you have multiple devices on the same VLANs talking to each other. The 6100 ports are not a switch. If you have devices connected to them that need to be in the same subnet they would have to be bridged and that uses significant CPU cycles. An external switch can do that without loading the firewall.

    Steve

  • Upgrade to 23.01 - crash report

    29
    0 Votes
    29 Posts
    5k Views
    stephenw10S

    Ok, start a new thread for that then it seems unrelated to the notifications issue.

  • Pfsense Error

    2
    0 Votes
    2 Posts
    376 Views
    jimpJ

    That is the same error we saw from others who had an outdated Home Assistant pfSense integration installed. You will need to update the integration in Home Assistant (or disable it).

    The error isn't coming from code in pfSense, but code being sent by that pfSense integration, so there is nothing pfSense can do to alter that code.

    There are several threads for this already if you need more information.

  • Moving current network to pfsense

    6
    0 Votes
    6 Posts
    697 Views
    V

    @johnpoz
    Oh yeah. Go to correct it. Thanx.

  • Register custom hostname by MAC address

    4
    0 Votes
    4 Posts
    607 Views
    JKnottJ

    @sdugoten said in Register custom hostname by MAC address:

    Could you please point me to which screen that would do the static mapping? Thanks.

    Bottom of the DHCP server page.

    22781824-e8e8-47a2-a8b6-2d91a794a058-image.png

    Also, the easy way to make a static mapping is to connect the device and find it in Status / DHCP leases and convert it to static mapping, to add the desired address and host name.

  • Boot environment - cannot erase

    1
    0 Votes
    1 Posts
    463 Views
    No one has replied
  • Setup ISP Router Bridged with ISP VOIP

    1
    0 Votes
    1 Posts
    217 Views
    No one has replied
  • Network UPS tools (nut server) youtube video

    1
    0 Votes
    1 Posts
    200 Views
    No one has replied
  • crontab changes

    Moved
    8
    0 Votes
    8 Posts
    609 Views
    S

    @jrey I only looked because I was expecting it to comment out the periodic daily line but it didn’t. Then it rewrote the file at boot, still I commented, so I pulled up the patch details. no memory spike the next day so it must have worked.

    Perhaps crontab write triggers again at other criteria?

  • VPN routing broken afer upgrade to 23.01

    11
    0 Votes
    11 Posts
    2k Views
    B

    @derelict Thanks for pointing this out - we hadn't had a rule on the previous version but added it in before the gateway rule and all is working OK again.

  • 0 Votes
    5 Posts
    658 Views
    A

    @viragomann

    I found the culprit, why it only has been on this one unit, I cant explain. It was being blocked by Snort..

    140:20
    (spp_sip) Invite replay attack

    Disabled the rule and it has resolved fine. All 4 units run Snort, only this one has had an issue.

    Thank you for your help.

    John

  • PFsense with multiple lans and nighthawk mr60 with satellites

    3
    0 Votes
    3 Posts
    615 Views
    S

    @steveits thank you for the reply, I'll try finding the docs :)

  • Fatal trap 12: page fault while in kernel mode after upgrade to 23.01

    Moved
    6
    0 Votes
    6 Posts
    883 Views
    F

    @eddie-raydian said in Fatal trap 12: page fault while in kernel mode after upgrade to 23.01:

    @fsc830 first of all, this is not helpful and disrespectful to all users on the forum. If you cannot provide help or good feedback, I think we can all agree that it you should not post.

    Second of all, asking, if a backup (or in case of VMware a snapshot) is available is a legitimated question to think about further steps.

    Cant see, why this should be disrespectful.
    But as you desired: I will not post to any of your questions again. 😎

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.