• pfSense as NTP authority

    9
    0 Votes
    9 Posts
    662 Views
    T2M5T
    @johnpoz I chose to use an NTP master on Linux CentOS and point pfsense to it to then distribute to network clients. It was actually much easier and quicker to configure, I tried a few times to synchronize with ad but there was always a problem somewhere, pfsense wouldn't synchronize or distribute, or vice versa. Not that it doesn't work, but I couldn't get it to work lol. But I will try to distribute the time through chroync in Linux to the pfSense and define it as Server and to point every client to the pfSense. Thank you very much for your help, you saved me a lot of headaches bro.
  • Firewall Rules States Details

    1
    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Limit connections per second from any host

    1
    0 Votes
    1 Posts
    136 Views
    No one has replied
  • Sonos setup with VLAN and Spotify Connect

    6
    8
    0 Votes
    6 Posts
    1k Views
    S
    Setting up Sonos with VLAN for enhanced security and Spotify Connect integration offers a seamless audio experience. However, ensure you're using official methods to access Spotify, steering clear of unauthorized avenues like the Spotify Premium APK. Enjoy your music setup with peace of mind and convenience.
  • 0 Votes
    3 Posts
    449 Views
    No one has replied
  • A "pass" rule with "invert match" blocks traffic

    4
    3
    0 Votes
    4 Posts
    504 Views
    johnpozJ
    @lindhe this has come up a few times already ;) I was just going to post to one of the other threads, but it was quicker to just point to the info in the docs ;)
  • Rules orders LAN and VPN

    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • Is effective blocking whole AS w/o Squid possible?

    1
    0 Votes
    1 Posts
    123 Views
    No one has replied
  • ET SCAN Potential SSH Scan OUTBOUND SSH

    3
    1
    0 Votes
    3 Posts
    474 Views
    X
    @mcury interesting I will have to look more. I do have usb backup but have had it for a while and this snort issue just recently started popping up. My backup still does work as far as I can tell.
  • Floating rule

    1
    1
    0 Votes
    1 Posts
    198 Views
    No one has replied
  • Floating rule

    1
    1
    0 Votes
    1 Posts
    124 Views
    No one has replied
  • per-port SYN cookies

    1
    0 Votes
    1 Posts
    167 Views
    No one has replied
  • 0 Votes
    5 Posts
    305 Views
    S
    @ddbnj It's probably in the docs somewhere. That one shows when adding a rule. There's an alias for each pfSense network/subnet plus This Firewall.
  • Forward 443/80 to upstream proxy?

    1
    4
    0 Votes
    1 Posts
    175 Views
    No one has replied
  • url blocking depending on client IP

    5
    0 Votes
    5 Posts
    328 Views
    M
    @Mr_JinX I agree with the possible security problems but i haven't found much negative information on it. Also they won me over because the dev worked on a few of my issues that were not working. So NXFilter has a built in net-flow collector. It wasn't working as i thought and they worked with me on fixing it. Its in the back of my mind of course that this app hasn't been vetted by anyone(as far as i know) but...so far....works as advertised. It has an updated categorization system, builtin netflow collector, and reporting (which isn't great). Fills the home requirement. The issue i have with the suggestion of external DNS services is that you cant track who is visiting what site as all source IP information will come from your WAN.
  • Proxmox web interface no longer avilable

    5
    0 Votes
    5 Posts
    623 Views
    W
    @viragomann thank you for your responses. I'm not sure I understand your questions fully. Can you break it down a little further? I'm new to all this
  • Suricatas "INDICATOR-SHELLCODE x86 setgid 0" Killing my VPN connection

    2
    1 Votes
    2 Posts
    556 Views
    S
    @unique_username Presumably you enabled those rules for a reason…? I would just say, try moving Suricata to LAN which will also avoid scanning all the packets that would normally be dropped by the firewall. Also if it’s just one IP being blocked you can suppress that alert for that IP.
  • Clear Firewall Logs only

    1
    0 Votes
    1 Posts
    201 Views
    No one has replied
  • Consolidating rules with NOT (invert) operator

    4
    2
    0 Votes
    4 Posts
    519 Views
    S
    @GPz1100 I would guess your floating rule is allowing it if/since you're not blocking those ports otherwise. But, you say FTP transfer didn't work? Passive FTP ports are controlled by the server. Some use all 1024 through 65535. FWIW I usually prefer two rules just for clarity. The floating vs interface rule order may be involved here, too: https://docs.netgate.com/pfsense/en/latest/nat/process-order.html
  • Unifi Controller Behind Netgate 6100

    8
    3
    0 Votes
    8 Posts
    648 Views
    N
    Yes, its right. VLANs are sub interface on the ix1, add under: Interfaces/Interface Assignments
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.