• PPOE SERVER - INBOUND TRAFFIC TO PPOE CLIENTS

    1
    0 Votes
    1 Posts
    535 Views
    No one has replied
  • Now rebooting daily

    10
    0 Votes
    10 Posts
    2k Views
    C
    Do you have a proper default route under Diag>Routes at the time? Can you ping that gateway IP? If so, what does a traceroute to something on the Internet look like when it's an issue?
  • Advice Needed Regarding pfSense with DMZ interface and Public IPs

    4
    0 Votes
    4 Posts
    1k Views
    KOMK
    pfSense is no different than any other router at the network level.  If your DMZ subnet is 172.16.0.0/24 then your other servers should also be in that same subnet.  Then you can use firewall rules to cordon off the DMZ from other network segments.
  • PfSense 2.5.1 - How to load balance two DSL connections?

    2
    0 Votes
    2 Posts
    1k Views
    P
    System->Routing, Groups Add a gateway group with WAN-A and WAN-B both at Tier1. (e.g. call it LoadBalance) On LAN add rules to match whatever traffic you want load-balanced. In the Advanced section of the rule, Gateeway - select the LoadBalance gateway group. Now the traffic is feed into the gateway group. As states are created they are round-robined between whichever WANs are up. And I see you are running a very advanced version of pfSense - 2.5.1 - what are all the new features that we will get in a few years?  ;)
  • How to prioritize OpenVPN tunnel data?

    4
    0 Votes
    4 Posts
    1k Views
    J
    @torontob: Thanks, is there anyway to do this without traffic shaping? I have used traffic shaping before and queues tend to full really quickly rendering the whole system useless. I find traffic shaping to be the weakest link in pfSense. Not as far as I know…
  • How to connect external RDP server through pfsense

    15
    0 Votes
    15 Posts
    3k Views
    K
    Cool - Glad its up.
  • SquidGuard blocked websites are cached in browsers

    2
    0 Votes
    2 Posts
    704 Views
    S
    Hi there, I was wondering if you ever managed to sort this out. I can't find any other posts on this subject and i have the exact same issue. Thanks!
  • Web filter - what can I do with pfsense?

    2
    0 Votes
    2 Posts
    966 Views
    J
    @tobiascapin: Log http and https connection storing transfer length, destination hostname and local ip or mac address Filter hostname from a list of denied hostname or by regex rule Do not use a connection configuration (transparent) Do not decrypt https content and do not alter certificate exchange (man-in-the middle) Optionally can be usefult to cache the http content. Hi, Squid and SquidGuard will cover all of the points above. The SSL Interception is optional. As long as you leave the SSL Part disabled, there is no modification (and interception) of SSL traffic. SquidGuard is optional but nice to have if you want to use complex rules (e.g. complex Regex) and logging. Speaking of logging: All users should agree that you log there sessions. Due to the law in many countries. As an example: I'm from Germany and the German/EU law doesn't allow the logging of accessed URLs and other personal data. this is due to privacy protection. A valid workaround is to log the MAC Address and mask it in your reports.
  • Webserver for single HTML page on pfsense

    2
    0 Votes
    2 Posts
    870 Views
    J
    @Mikeyb!: To caveat this first, this is a bad idea, but it's just for testing on a test network. Watch out for the vHosts Package. It works out of the box. Yes it have PHP, but if you really want to get rid of PHP just modify the Package defaults and you have a very light weight Web Server.
  • Help needed for Wireless Router Set up Behind pfSense Box

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    @kiekar: all worked fine even without changing any LAN and WAN settings on the wireless router. If you do that at the very least you must disable the DHCP server on the wireless router. It may be working fine now but sooner or later a device is going to get an IP address from the wireless router and it will be in the wrong subnet with the wrong gateway. Going the way you originally had it configured is generally frowned upon because of the double NAT, as Derellict said, but in many situations it will work fine. I'm writing this from behind double NAT and have experienced no issues with day to day stuff. Things get complicated if you have to forward ports though and some things (VoIP) really hate double NAT.  ;) Steve
  • WAN interface going down

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Authpf - feature request

    1
    0 Votes
    1 Posts
    622 Views
    No one has replied
  • Names in Rules and logs etc

    10
    0 Votes
    10 Posts
    2k Views
    C
    The logs show what rule matched, and you want to see the specific source IP, you don't want the alias name there. You can tell from the rule it shows which alias it hit. There is reverse DNS lookup support there as well.
  • Ssh on port 443… not working

    14
    0 Votes
    14 Posts
    3k Views
    stephenw10S
    No problem. Easily done.  ;) Steve
  • Http 1.0 protocol is not supported

    6
    0 Votes
    6 Posts
    3k Views
    M
    @stephenw10: Have you tried disabling Squid as a test? If that works you could exclude the bank site from the proxy. Steve YES!!!! This problem was in Squid, when i entered my IP in "Bypass proxy for these source IPs" site wil work fine! Thanks a lot. P.S. I'm trying to stop squidguard but it is not take effect. Why squid blocking? My rules are allow all traffic.
  • AD Group names with spaces or longer than 16 characters

    4
    0 Votes
    4 Posts
    3k Views
    B
    Are you using extended queries? You should post a screenshot of your config page.  Blank out anything you might feel is sensitive but do it in a way we can see all the strings. you can also try and escape the space with \20 and see if that works so ou=OU WithSpace becomes ou=OU\20WithSpace Or might  be %20 as escape for space. so would be ou=OU%20WithSpace if you need multiple groups to be searched the authentication container string should look similar to this CN=Users,DC=domain,DC=com;OU=DifferentUsers,DC=domain,DC=com I use extended queries for my vpn access and it looks like this memberOf=CN=VPNusers,CN=Users,DC=domain,DC=com
  • More VPN problems/questions

    9
    0 Votes
    9 Posts
    2k Views
    K
    Yeah - I have my server side on unlimited fiber internet.  So my VPN is much faster than my connection here in Asia.  I get about 5/5 here but about 60/60 in the USA. Sorry to hear that.  I will tell you this though.  The USA doesn't have a such thing as a anonymous / private VPN service.  They all comply with requests for info from law/government (or pretty much anyone who asks).  They all keep records.  Not one is "private". So, don't get too hung up on the ubber private vpn claims.  Its all disinformation, misrepresentation or blatant lies. I would go so far as to say that VPN providers are probably considered one-stop-shopping for law/government etc. For sure you would be better off on a VPN server you set up yourself. Its not that I condone illegal activity.  Its just that I don't think EVERYTHING should be read to make sure its legal…
  • Strange problem, no internet yet outbound vpn connection working

    2
    0 Votes
    2 Posts
    669 Views
    W
    Note to self, when you think you've checked everything make sure that Snort is not blocking access to your gateway  :o
  • 0 Votes
    4 Posts
    1k Views
    Z
    Has anyone found a solution for this? It's a real problem, sa sometimes ppp connection will fail, after days of working fine, and pfSense just won't reconnect…
  • Best Open Source Netflow Monitoring

    2
    0 Votes
    2 Posts
    870 Views
    C
    nfsen is my preferred option there. Best open source one I've seen. Scrutinizer is definitely nice, but very costly.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.