• Multiple LANs to WAN on a local subnet - firewall rules

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    marcellocM
    my mistake, the deny rule does not has the not in dst action Proto        Source              Port        Destination        Port          Gateway deny any          LAN subnet        *              my_nets          *              * allow TCP          LAN subnet        *              !my_nets          80              *
  • Need Help With Firewall rules and VLAN

    Locked
    8
    0 Votes
    8 Posts
    11k Views
    R
    This guide has screenshots about firewalling your VLANS. This is what I have used in the past. http://networktechnical.blogspot.com/2007/04/pfsense-how-to-setup-vlans.html
  • Problem to add an network-range to an Firewall rule.

    Locked
    5
    0 Votes
    5 Posts
    1k Views
    W
    OK thank you for help. It was a double ".00" at the end. Don't know why I don't noticed this  ;D
  • Printing to other network segment

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    D
    Automatic outbound NAT rule generation
  • MOVED: xbox on the network

    Locked
    1
    0 Votes
    1 Posts
    924 Views
    No one has replied
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: Firewall and Squid

    Locked
    1
    0 Votes
    1 Posts
    945 Views
    No one has replied
  • Issue with Firewall and NFS.

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    C
    It's likely NAT that's breaking it rather than the firewall. Static port is generally necessary to not break NFS.
  • Facebook pings my pfsense

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    C
    Digging a little closer, got a packet capture of the DNS request they're sending. It's just a NS root query, which is used at times in DNS amplification DDoS attacks (when hosts actually respond). So my guess is they're checking if the host is likely to be one that's taking part in a DDoS attack because it's configured poorly answering to the world. What relation that has to the iPhone app and apparently nothing else, I don't know.
  • Using static route filtering, still having some lag issues

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    W
    Ok good point.  Ill do some tests as you suggest. The point to points are 3.0mbps up/down. Thanks. @cmb: How fast are the point to point connections, and how loaded are they? Windows file sharing performance is very poor over anything with > ~20 ms latency by the design the protocol. You can take the firewall out of the equation completely by adding a static route to one of the test hosts, and I expect you'll see the same behavior. It's most likely latency induced from the sounds of it.
  • VLAN to VLAN

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    C
    If you're blocking traffic destined to VLAN2, then yes you want out. In on VLAN2 would be traffic initiated on VLAN2.
  • Routing Between Subnets - Just Doesnt work :(

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    P
    You can add a route to the server to test.
  • Block client with wrong ip

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    @marcelloc: mac addresses can be spoffed/changed too and it's quite easy to do this. one extra 'protection' may be static arp entries on pfsense to fix mac -> ip. I know about arp spoofing, but my users don't. ;-) Enableing "Static ARP" on pfsense "DHCP Server" is exactly what I want, but the problem is that I should turn on pfsense dhcp server while i have another dhcp server on my network. i want  pfsense dhcp server to be on so I can enable static arp feature, but in the meantime block any dhcp request from lan to pfsense . (or block answers) I believe the long description in the first post made it difficult to read ;-) Anyway thanks for your attention.
  • Opendns as monitor ip

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    Last I heard from others, that was working as a monitor IP. You just need to make sure that if you have two WANs, you don't set up a conflicting situation where under System > General a DNS server is set to WAN1 and then used as a monitor IP for WAN2, that wouldn't work.
  • IPs matter on transparent bridge?

    Locked
    12
    0 Votes
    12 Posts
    4k Views
    C
    What did you do to get it working? I have a transparent bridge with Ips on the interfaces and want to remove the ips for security. What trickery do I need to get it to work smoothly? Thanks.
  • Builtin SIP and RTP ports [SOLVED]

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K
    Thanks. That's what I needed to know.  Looks like I can use the SIP one, but not the RTP one.
  • Neither SRC nor DST are my network

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    A
    I am pretty sure it was an internal VPN client communicating with an external network.  Sorry I missed you reply!
  • MOVED: ssp_ssl: Invalid Client HELLO after Server HELLO Detected

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Blocking facebook integrated with skype

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    marcellocM
    Create a firewall alias with apps.Facebook.com and then apply it on rules
  • Redirect to a ip address

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    G
    @Cry: Note that you should do everything via the web interface, not on the command line (at least until you fully understand the differences between pfSense and a standard FreeBSD install). Well, that's why i'm doing this, just for fun and learning  ;D Now, another question related, i know that if i do: fwd 10.1.0.1 ip from 10.0.0.100 to any in this will redirect, but it will not change the header in the packets, so i can't redirect to a external website (i.e. google). In that case ¿did i need to use natd? ¿can i do it from the webgui? (i've tried with nat options but with no luck) Thanks for your answers!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.