• Simple match on wan not working for inbound traffic

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    W
    Okay so after some more testing, this appears as though it is state related.  I will see a "in on vr1" only when a new connection arrives on the vr1 interface.
  • Port 3128 has been block in LAN…what happen?

    Locked
    20
    0 Votes
    20 Posts
    8k Views
    jimpJ
    Squid may be closing the connections early, and pf may be removing the states due to that. The blocks you are seeing are just traffic that arrives after the state has already been removed. Not really necessary for normal operation, people wouldn't even notice that in most cases.
  • VPN Passthrough

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S
    well that's a straight foward answer, thank you :) you can mark this as solved.
  • Firewall logging is logging things that aren't supposed to be logged

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    The ftp proxy logs allowed connections, that is likely what you are seeing in the log.
  • C Class Network Problem

    Locked
    16
    0 Votes
    16 Posts
    5k Views
    I
    ok thanks a lot. what an easy, read read read i hate myself ): a turkish says : perfection hide in simplicity.
  • Help with Firewall Rules

    Locked
    24
    0 Votes
    24 Posts
    7k Views
    N
    Hi, I do not use SNORT or HAVP. I know that snort isn't easy to configure and not so many people are using it because of its complexity. HAVP shouldn't be so hard to configure but I do not have any pfsense box here to test. So the best way would be that you create a new thread and asking for help to configure HAVP and then someone who knows HAVP can help you or you provide screenshots of the configration pages so that we can help you with this.
  • Vlan and kvm

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M
    Draw a picture, it would be better if you draw "what you have" and "what you want to achieve"
  • Auto Blocking / Threshold / Dynamic Rules

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    N
    whats about the package "spamd" ?
  • WAN ICMP ping

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    A
    Never mind. Found the culprit.. Had Snort ICMP rule set. Glad to see it's effective. :)
  • Blocking interface by time [solved]

    Locked
    8
    0 Votes
    8 Posts
    2k Views
    P
    thanks ;D that is what i want.
  • GRE packets dropped when accessing a VPN

    Locked
    16
    0 Votes
    16 Posts
    5k Views
    M
    I only tried to suggest that, change your modem to bridging and use only firewall in routing mode. that ease a bit to troubleshoot gre and other things also.
  • Share files and printers

    Locked
    13
    0 Votes
    13 Posts
    8k Views
    P
    @pcboarders: i got to get pfsense works in ingress in my head and i think i should be able to figure the rest of filtering out thanks Again created to alias nfsports with the 4 ports and created fileservers with the serverips hope this works got it setup and will try it, see what  happens seems to work for all printers and files that are ubuntu based (nfs) samba is having a canary re-configuring samba to see if that works
  • Routing rules between several VLANS

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Help : one machine bringing down the entire LAN subnet

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N
    If the machin is spamming to an suspect IP address cut it from the network, save all data on the mahcine, check them for viruses and trojans and then kill the machin and do a reinstallation. The problem ist not pfsense or your network - it is the maleware!
  • [SOLVED] Block OPT1 to Lan

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    M
    Good to hear
  • Help - rules,routing for 2 Lan setup.

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    C
    Hi, sorry for the delay, i've added an image of how we our network is at the moment. [image: 10993d1313072528-help-rules-routing-2-lan-setup-admin-curriculum-network-simplified-map.jpg]
  • [solved]The alias for network(s) not working

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    S
    OK, i'm testing it now….
  • 2.0.x firewall – Do rules support reverse hostname lookups?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    W
    Thx Jimp. http://forum.pfsense.org/index.php/topic,39627.0.html  (same topic discussed here also, Jimp response more thorough) @jimp: It isn't "reverse" lookups in that way. You can add hostnames to an alias. Periodically, these are resolved again to ensure the IPs are up to date. They are used like any other IP-based alias entry.
  • Is there a way to specify a fqdn instead of an ip address?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    W
    Thx Jimp! @jimp: You can, in aliases, in 2.0. They are re-resolved periodically. You can also do this in 1.2.3 but in a hackish way. It only works with the second or later value in an alias It only resolves when the filter ruleset is (re)loaded, so basically when you save/apply. You can cron a filter reload if you really want to hack it up.
  • How to used Port Alias in the Firewall rule? PfSense 2.0 RC3

    Locked
    8
    0 Votes
    8 Posts
    21k Views
    M
    Firewall is updated, yesterdays build has some clitch with the aliases. But todays doesn't have. Problem solved
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.