• 0 Votes
    1 Posts
    193 Views
    No one has replied
  • Exclude VMware from Pfsense

    2
    0 Votes
    2 Posts
    416 Views
    jimpJ
    If you want the VMs to bypass pfSense then you would have to do that at L2 -- put them on the WAN segment. There is no way to have them connected through pfSense but also be excluded from passing through pfSense. You could pass all their traffic and disable NAT for them (Assuming you have routable addresses for the VMs) but they'd still be passing through pfSense and subject to things like state tracking. You need to describe your use case in a lot more detail, perhaps with a diagram, to determine if what you're asking is possible.
  • vpn pptp connection through pfsense

    5
    0 Votes
    5 Posts
    501 Views
    jimpJ
    It's a limitation of GRE state tracking in pf. It will never be solved. PPTP is dead. If someone "needs" PPTP, they "need" educating on why it's a bad idea, and how it should have been changed 10+ years ago.
  • NGFW-esque functionality with add-ons?

    2
    0 Votes
    2 Posts
    173 Views
    bmeeksB
    What do you ultimately expect to gain by such a setup other than a continual headache trying to figure out why app "X" suddenly quit working or never worked from its installation? With a home network, just block unsolicited inbound connections and you are 90% or more of the way towards "secure". Trying to control outbound can be a real headache because no apps do a good job of documenting what ports they use to connect with or connect to. If you have IoT devices you are concerned with, just put them on a VLAN by themselves and don't give that VLAN any access into your regular LAN or other sensitive VLANs except as stateful replies (meaning something in the secure VLAN or LAN started the conversation with a walled-off IoT device).
  • 0 Votes
    1 Posts
    619 Views
    No one has replied
  • configure NUT

    1
    0 Votes
    1 Posts
    173 Views
    No one has replied
  • Can't get packet filter to work on bridge member interfaces

    2
    0 Votes
    2 Posts
    370 Views
    A
    Anyone? Can anyone at least confirm that this should be working, despite the fact that it very much isn't working? Very much appreciate anything that can help point me in the right direction here. Everything I've found online suggests it should be working but I haven't found anything conclusive.
  • Ignore Checkpoint CCP in firewall rules

    7
    0 Votes
    7 Posts
    1k Views
    M
    This is what I did: First I took the current bogon list from the pfSense in the CLI with pfctl -t bogons -T show Then I changed to the web interface and created a Firewall Alias IP named handmade_bogon_list with just the first network. Back in the CLI I called viconfig and added the remaining networks from the list. This is faster for me than pasting it in the webinterface. Now I could add a blocking rule using handmade_bogon_list in the source that logs. In front of this rule I've put a special blocking rule for port 8116/udp that doesn't log. At last I unchecked the box for blocking bogons at Interfaces > WAN > Reserved Networks to make this work. This setup already showed me that there is a DHCP client in that network that needs to be tracked down. Thanks for all your input.
  • I need to Create routes for my VLAN interface.

    firewall
    7
    0 Votes
    7 Posts
    818 Views
    C
    I am also wondering about the same thing. If you found a fix then please do let me know. thanks in advance :)
  • Block all traffic on port 80 and 443 except legitamate web traffic

    1
    0 Votes
    1 Posts
    158 Views
    No one has replied
  • pfsense firewall source code path

    2
    0 Votes
    2 Posts
    434 Views
    kiokomanK
    @pf2040 said in pfsense firewall source code path: https://github.com/pfsene https://github.com/pfsense/pfsense git clone you need freebsd os script to build build/scripts not easy, not worth. If you have to ask, you’ll never know. If you know, you need only ask
  • Allow specific IP on IOT VLAN to access IP and port on LAN

    1
    0 Votes
    1 Posts
    170 Views
    No one has replied
  • Meraki Client VPN Problems

    1
    0 Votes
    1 Posts
    391 Views
    No one has replied
  • Unexpected Alias behavior with FQDN

    5
    0 Votes
    5 Posts
    357 Views
    JeGrJ
    As you can read in the Ticket mentioned above it is not resolved in _p3 but tested for 2.4.5 so either you can install the Release Candidate for 2.4.5 or wait for the release. Otherwise you could use the method near the end of the topic to patch the filterdns part.
  • PfSense HTTP/HTTPS firewall rules and Squid ...

    3
    0 Votes
    3 Posts
    648 Views
    K
    Hi "isolatedvirus" and thx a lot ! It makes sense. I configured [transparent mode] in order to avoid the configuration at every client side (Win or Linux) => no need to import PfSense selfsigned certificate and the SSL flow is not "broken" at the proxy level. If I understood, the solution would be to force the outbound web trafic going through Squid-proxy first and redirect it to the firewall after... both firewall and proxy applications should be "called" but I don't think that's possible... Regarding HTTP/S trafic flow, either I keep Squid in service (FW = useless) or I forgive Squid (and its proxy-cache for perf). On the other hand, a proxy is really usefull in a company IT network but at home...
  • Internet drops for 22-25 seconds and then gets back on.

    6
    0 Votes
    6 Posts
    531 Views
    uxmU
    @uxm Anyone?... This is my log of Internet Connection Drops (not LAN!) : [image: 1580373329909-6a6e837b-47d8-443e-98de-c7e0d6abf2d0-image.png]
  • Data loss prevention with pfsense

    4
    0 Votes
    4 Posts
    4k Views
    C
    Thank you for this, however my company only needs internal data control given the internet environment. It's nice that pfsense can do this. i'm from vietnam - 0919679920
  • alias use for IPv4+IPv6

    4
    0 Votes
    4 Posts
    478 Views
    L
    Here is a ping to my FQDN from pfSense using IPv4 [image: 1580265847033-654e556d-0edb-4aa6-8219-2787897ba8e7-image.png] Same FQDN using IPv6 [image: 1580265957101-c0b773f2-521c-47e8-b268-9f4120ef775f-image.png]
  • Exchange server sending but not receiving emails

    5
    0 Votes
    5 Posts
    247 Views
    ahking19A
    I'd think you you want to use port 587 instead of 25.
  • 0 Votes
    3 Posts
    976 Views
    S
    Do you mind sharing the firewall rules you got to work? I’m in a similar situation.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.