• Cable Modem Hack - Cable Haunt pfSense rule?

    15
    0 Votes
    15 Posts
    2k Views
    S
    Hello! https://docs.netgate.com/pfsense/en/latest/firewall/preventing-rfc1918-traffic-from-exiting-a-wan-interface.html https://github.com/pfsense/docs/blob/master/source/firewall/preventing-rfc1918-traffic-from-exiting-a-wan-interface.rst ? And because someone, like me, might ask/wonder... https://forum.netgate.com/topic/119431/block-private-networks-what-does-that-do-what-is-it-used-for John
  • black arrow in the logs in interface column

    1
    0 Votes
    1 Posts
    120 Views
    No one has replied
  • Config firewall

    2
    0 Votes
    2 Posts
    243 Views
    fireodoF
    @humaxoid said in Config firewall: What kind of firewall is used in pfsense? Iptables or ...? Where does the firewall store the config? This will help you: Pfsense Documentation The config is under /config/config.xml Regards!
  • How to block itunes from pfsense

    3
    0 Votes
    3 Posts
    252 Views
    NogBadTheBadN
    ^^ this with openappid-streaming_media.rules or openappid-mobile.rules
  • Allow OPT to connect only to WAN, not LAN

    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    on your opt, then sure..
  • FQDN Alias update

    3
    0 Votes
    3 Posts
    494 Views
    F
    Thank you for the answer
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • Azure Multiple NICS

    1
    0 Votes
    1 Posts
    201 Views
    No one has replied
  • HOW CAN I PREVENT MY IP ADDRESS FROM BEING BLACKLISTED USING PFSENSE

    23
    0 Votes
    23 Posts
    3k Views
    bmeeksB
    @Mats said in HOW CAN I PREVENT MY IP ADDRESS FROM BEING BLACKLISTED USING PFSENSE: @johnpoz simple fix, just implement https://www.ietf.org/rfc/rfc3514.txt :D Wow! This rates right up there with the invention of the wheel and sliced bread ... . Now thousands of Snort/Suricata rules and millions of IP addresses on pfBlocker IP lists can all be replaced with a single firewall rule looking for and dropping packets with the evil bit set. So simple even a child can do it.
  • Traffic using disabled rules?

    2
    0 Votes
    2 Posts
    175 Views
    S
    It turns out that it was just pure coincidence that my change was made on the voice_network rules and that the root cause of this was a gateway being down on the secondary device and XMLRPC triggering the filter reload flushed states as this is what I have enabled.
  • Rules for allowing limited ICMP on IPv4/v6 from WAN

    6
    0 Votes
    6 Posts
    624 Views
    provelsP
    @IsaacFL Thanks. Now that you mention it, I believe the the RFC was where I had found the info I used as well but had forgotten (buffer overflow, I guess...). Thanks again, all.
  • Can the SG-3100 work as a hand off firewall to the same WAN?

    5
    0 Votes
    5 Posts
    429 Views
    T
    Yeah, I offered to pay a bit more. Their concern was unintended consequences that might affect other customers doing VOIP or video chat or what not. I'll pick up an SG-3100 and hope it will do the trick.
  • How to block "tiktok"(social media) on pfsense

    1
    1 Votes
    1 Posts
    2k Views
    No one has replied
  • Access ISP router

    6
    0 Votes
    6 Posts
    592 Views
    S
    Hm, then it should work by typing the LAN IP of the ISP router. We have a similar setup at several clients and at my home. Perhaps in Status/System Logs/Settings check "Log packets matched from the default block rules in the ruleset" temporarily to see if pfSense is blocking you but as long as the outbound is allowed it should work.
  • Firewall blocks legimate traffic like port443

    4
    0 Votes
    4 Posts
    445 Views
    johnpozJ
    If you want help with your rules, you going to have to show them.
  • 0 Votes
    2 Posts
    388 Views
    P
    I noticed that when it stops passing the private traffic there is no indication in the system logs that the traffic is being blocked and the watch I put on traffic when it passes, no longer indicates any of this private traffic is passing.
  • Hiding management from everyone

    8
    0 Votes
    8 Posts
    1k Views
    jimpJ
    When you setup your internal block rules make sure to use rules like this: Pass from <management addresses> to This Firewall (self) on <management ports> Reject from any to This Firewall (self) on <management ports> There are other (and better) ways to do it depending on which services must be accessible to local clients, but the key is you should be using This Firewall (self) as the target to make sure that any addressable interface on the firewall is covered. Otherwise if you have a rule like: Block from LAN subnet to LAN address Pass from LAN subnet to any (for the Internet) You'll find that local clients can reach the firewall GUI and SSH using the external address or addresses on other connected interfaces.
  • What does this mean , I do not have this ip#

    4
    0 Votes
    4 Posts
    1k Views
    rtoledo2002R
    @bmeeks that's it. it's Spectrum's modem . thanks
  • OpenVPN, NAT and FW from WAN inbound cannot ping

    2
    0 Votes
    2 Posts
    146 Views
    No one has replied
  • No default gateway shown

    6
    0 Votes
    6 Posts
    3k Views
    JKnottJ
    I just fired up my ThinkPad into Window 10. Both Wifi and Ethernet are on the same network and both show the same default gateway. Since you don't have a gateway on your Ethernet connection, you have some problem. Do a packet capture for DHCP and see what's on the wire for both interfaces.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.