• PfSense as VPN Concentrator/Server

    2
    0 Votes
    2 Posts
    1k Views
    D
    My first instinct would be to suggest that you simply replace the SonicWall with pfsense….. 8) I understand that may be an ambitious start, and while I'm no expert at SonicWall, I seem to recall you can create a DMZ port in SonicWall. You should be able to present that port to the WAN port on pfsense much as you would to an internet facing Web server. That should let you create an IPSec tunnel to the pfsense box.  The LAN side of pfsense will have to "merge" with your existing LAN subnet, unless you're willing to dedicate a new subnet just for the pfsense IPSec. If you can give some more details (and/or diagrams) about what you envision this setup to look like, maybe we can help you arrive at a solution.
  • 503 - Service not available in Dashboard

    4
    0 Votes
    4 Posts
    1k Views
    M
    Reset to factory defaults got me going here.  couldn't find anything less invasive …. :(
  • Daily (or weekly, or monthly) quotas per user?

    5
    0 Votes
    5 Posts
    2k Views
    T
    @jimp: You'd have to use Captive Portal + RADIUS accounting and then the RADIUS setup would handle the bandwidth tracking and long-term decisions. Well, that sound complicated!
  • Limiter works sporadically, works after states reset

    1
    0 Votes
    1 Posts
    664 Views
    No one has replied
  • Access control at the network level

    6
    0 Votes
    6 Posts
    4k Views
    jimpJ
    Correct.
  • PfSense as a stratum 1 time server

    6
    0 Votes
    6 Posts
    2k Views
    mcdonnjdM
    @stephenw10: Conversely I would be less likely to do it on a work box just because the consequences of some yet undiscovered NTPd exploit would be so much worse. If my home firewall goes down for whatever reason I get grief but I'm unlikely to find the locks have changed when I get back. If a firewall I'm managing for a business goes down (or worse gets owned) because I opened NTPd to WAN as a public service that's a different matter. You could see this as simply increasing the attack surface of a the firewall which is never a good thing. If you want to run a public NTP server the firewall should not be your first choice.  ;) Or there's always the possibility some company could make a consumer router and hard code your IP address in the firmware and set a ridiculous refresh rate when it can't reach the server and end up having you be flooded by tons of NTP traffic, bringing your network to a grinding halt. (This actually happened to the University of Wisconsin, courtesy of Netgear: http://pages.cs.wisc.edu/~plonka/netgear-sntp/) But as mentioned, at work, I would not be running this on the firewall. (We run an ASA at work, though I've mentioned switching to pfSense when the discussion of replacing it has come up. Though I believe the last word on it was simply increasing the memory on it instead, though I don't believe that has happened yet.) My FreeRADIUS (on FreeBSD) server would be the most likely candidate for being a stratum 1 server (currently I believe it's a stratum 3) unless I special built a machine specifically for NTP.
  • Will this be Fixed?

    6
    0 Votes
    6 Posts
    1k Views
    stephenw10S
    That's unlikely to work because the pfSense box will not route the traffic with only one IP. You could do it if you don't have Squid in transparent mode. Steve
  • Bandwidthd Package Services Not Running

    3
    0 Votes
    3 Posts
    756 Views
    A
    thanks for the reply, but sorry i was not able to understand what to do? please let me know how to do that briefly. Thanks.
  • Newbie Question: How to gain root?

    5
    0 Votes
    5 Posts
    7k Views
    J
    @MindfulCoyote - admin and root are there by default, however… @JeGr - The point of this exercise is to not memorize and distribute the admin password :] @stephenw10 - Doh! Completely missed this in the list of packages. Thank you!
  • Webgui not working

    8
    0 Votes
    8 Posts
    3k Views
    stephenw10S
    Right but as divsys said have you proved that the server isn't using http (non-encrypted) on port 443. That can make connection difficult because browsers try to be helpful by automatically using https as soon as you specify port 443 and vice versa. You could try re-assigning the LAN interface IP in the console menu via option 2. You can assign it the same address so that nothing changes but it should ask you 'do you want to revert to http?' or something similar to which you can answer yes. It doesn't on my 2.2 alpha test box I have here though. The config file is /conf/config.xml. If you SCP that off the box you can reset it to factory defaults or look through it for a config error (such as http on port 443). Yopu can try editing the file whilst on the box: ee /conf/config.xml Look in the <webgui>section. Change back to http on port 80 and then reboot. Obviously manually editing the config file is open to error.  ;) Steve</webgui>
  • Routing Loop?

    7
    0 Votes
    7 Posts
    3k Views
    stephenw10S
    @evano666: I should also mention I already have a rule in place for ICMP… IPv4 ICMP * * * * * none Where is that rule? As others have said, what sort of NAT arrangement to you have on these virtual IPs? It would be common to use 1:1 NAT to your internal servers but if you're not doing that then have you NAT'd ICMP? Steve
  • Configure pfsense inside the lan

    3
    0 Votes
    3 Posts
    882 Views
    johnpozJ
    Um that is not a wan IP, that is a rfc1918 address that you would use on our lan.  Why do you need to control bandwidth on your lan?  To your 2k8 server?  If you go into more details of your perceived issue and what you would like to do to fix it. We can either agree this is best solution, or maybe point you in better direction.  Maybe pfsense can solve your problem, maybe not - but without understanding what your wanting to do exactly??
  • Bandwidthd not working on new install of pfsense 2.1.3

    5
    0 Votes
    5 Posts
    1k Views
    P
    For other readers, bandwidthd defaults to writing stats at 2.5 minute intervals. As long as there is more than the minimum traffic seen (about 1MB from memory) then there should be data and graphs generated within 5 minutes of enabling it.
  • Help with rules, schedules, traffic shaper

    2
    0 Votes
    2 Posts
    710 Views
    P
    You should be able to put a pass rule for traffic from the alias, select the limiters you want and schedule you want. Then after that put a deny rule for traffic from the same alias. Then at schedule times the pass rule will apply first and be effective. Out-of-schedule-hours the deny will be hit.
  • Routing between OPTs

    2
    0 Votes
    2 Posts
    781 Views
    P
    Routing between directly-connected networks "just happens" once you put firewall rule/s on each interface to allow the traffic - e.g. on OPT1 put a rule that allows source OPT1net destination LANnet. No need to do any port forwarding or other tricky stuff. To access a server that has a public name that is port-forwarded back inside your own network you can use NAT reflection. But actually it is easier to do "split-DNS". In pfSense DNS forwarder add a host override for that public name, pointing to the local/private IP of the server. Then LAN-side clients that ask for the name to be resolved, will get an answer that is the local/private IP of the server, and they will successfully connect locally to it.
  • Pf sense firewall

    16
    0 Votes
    16 Posts
    3k Views
    J
    Abandoning this project didn't get it work Thx everyone for ther help
  • Weird php error, firewall is down

    2
    0 Votes
    2 Posts
    801 Views
    S
    [SOLVED]  -  It was the USB disk that went bad.  I put in a new one and restored the config and were back in  business.
  • PfSense squid proxy error.

    1
    0 Votes
    1 Posts
    504 Views
    No one has replied
  • Description fields stripped of characters when synced?

    1
    0 Votes
    1 Posts
    558 Views
    No one has replied
  • Apinger weirdness

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD
    Restarted apinger (killed it then saved the gateway config and applied) and now it's back to 0%.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.