• [SOLVED] IPv6 Address not working in Alias

    12
    0 Votes
    12 Posts
    1k Views
    C
    Thank you all very much for your help. I rebooted the firewall and until now (uptime 20h) the aliases are working as expected.
  • VoIP no audio for 5 to 30 seconds and internet time out

    3
    0 Votes
    3 Posts
    357 Views
    G
    I resolve the issue with BIG HELP from Infecticide!!!! I did call my ISP and they told me they saw timeout on the gateway. I plug the modem directly in pfsense and I had no timeout. So it is the gateway. By repluging everything, it worked. Thanks
  • Pfsense blocking network access on pc but not on phone?

    pfsense
    3
    0 Votes
    3 Posts
    685 Views
    W
    @akuma1x Cheers for getting back to me and sorry about the delay in reply. It turns out it was nordvpn in the background. I had it set to "NOT" auto-start with windows, which it wasn't and there was no icon in the app tray but when I went into task manager there was some part of it that was running in the background blocking all Lan traffic but not wan traffic. Really weird, and hard to diagnose! I turned on nord's auto-start with windows feature and turned it off again, rebooted and everything was back on. Really annoying, not happy with Nord.
  • Block outgoing connections ?

    15
    0 Votes
    15 Posts
    2k Views
    JeGrJ
    It's a bit tricky at first but just think about the pfSense Box as some sort of blackbox with lines going into it. WAN being one, LAN being another. Filtering is done "inbound" so whereever a packet "touches" the blackbox first, that's where you should filter it (pass/block etc.) :)
  • Interface subnet misconfigured /32 and firewall default allow rule

    7
    0 Votes
    7 Posts
    1k Views
    B
    Yes, is from Virtual IP - 192.168.10.7/24 is an IP alias - the pfsense router has replaced two single wan routers - 192.168.10.2/24 and 192.168.10.7/24 some years ago. I tested on an pfsense VM and replicated the double allow rule. Thanks for help, good to know that pfsense is reliable and is a user error.
  • [Solved]Is Aliases can block?

    7
    0 Votes
    7 Posts
    612 Views
    V
    Thanks for the info.
  • Tables and Persistency ...

    5
    0 Votes
    5 Posts
    644 Views
    C
    Nice :) I'll have a look at that, since it's probably better than the pfctl approach, performance-wise ..
  • Consulting of snort

    2
    0 Votes
    2 Posts
    198 Views
    bmeeksB
    Snort has the capability for creating a Pass List (on the PASS LISTS tab). You can create a list and include an alias. You would define that alias within pfSense under FIREWALL > ALIASES. Once you have your custom Pass List created, go to the Snort interface's settings edit tab and select your custom Pass List by name in the Pass List drop-down selector on that tab. You can also use Snort's IP Reputation tab to import a plaintext file of IP addresses or networks (using the standard Snort syntax) and assign those to an IP REP whitelist. Any IP address or network defined on that list will then bypass Snort inspection completely.
  • States detail reset

    3
    0 Votes
    3 Posts
    336 Views
    H
    Thanks for the info, I was under the impression that it was not the case.
  • Netflix blocked

    Locked
    7
    0 Votes
    7 Posts
    1k Views
    GertjanG
    Added to what @bmeeks said : I guess that a 'good and honest' VPN supplier has a FAQ or clearly states before you buy ; "Netflix will not streamin-traffic to us".
  • SSH Port forwarding

    1
    0 Votes
    1 Posts
    153 Views
    No one has replied
  • Ring video doorbell behind PFsense firewall?

    28
    0 Votes
    28 Posts
    16k Views
    T
    FYI, I was able to get this to work by disabling my DNS Resolver and enabling the DNS Forwarder service instead. I didn't need to add any additional Firewall rules or NAT/PAT rules since all of the connections are initiated outbound. I don't have a good idea what about the DNS Resolver the Ring was incompatible with, but wanted to put this out there so if others want, they can track down the cause.
  • Best practice to block traffic between local interfaces

    4
    0 Votes
    4 Posts
    483 Views
    NogBadTheBadN
    Something like this:- [image: 1573813807706-screenshot-2019-11-15-at-10.28.31.png]
  • Peer to Peer OpenVPN - Can't access remote router.

    1
    0 Votes
    1 Posts
    117 Views
    No one has replied
  • 0 Votes
    5 Posts
    619 Views
    O
    Thanks Jimp. Indeed this also does the job but there seems to be a place for both solutions depending on the situation. Much appreciated!
  • FTP passive port on demand opening

    32
    0 Votes
    32 Posts
    3k Views
    O
    @johnpoz I denote a certain polemical vein
  • Can't connect to an external vpn inside network

    3
    1 Votes
    3 Posts
    369 Views
    P
    I had to: Delete site to site vpn configuration on both pfSense AND the remote device. Even though both were disabled. Delete all Nat rules and set it back to auto on pfSense. Reboot. For Windows there is a registry update you may need to do but I can’t remember what it was, sorry.
  • DNS Leak OpenVPN-Client Solution

    1
    0 Votes
    1 Posts
    185 Views
    No one has replied
  • How to close Port 23, 53 and 80 on WAN?

    48
    0 Votes
    48 Posts
    9k Views
    johnpozJ
    Dude you seem to be just over your head is all... As derelict stated those are outbound.. Your seeing your own connection to the site your using to test canyouseeme.org [52.202.215.126] with would be my guess. That port for the 52 address is 443, that is the dest port of your test.. Yeah when you GO to that site you will see traffic to that site on the port you go too, ie https would be 443.. Then you have a 10 address.. Which your hiding? Why??? Its rfc1918 address..
  • Create firewall rules by script

    5
    0 Votes
    5 Posts
    911 Views
    jimpJ
    There is no API for this (yet), though there is the easyrule script which may not help directly, but you could copy its code to potentially setup something. Having an IDS inject rules is a fine idea in general, though. We have demonstrated this working in TNSR using its API combined with ERSPAN to feed packets to the IDS: https://github.com/Netgate/TNSR_IDS/
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.