• Dup-to custom rule

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: (portscan) UDP Filtered Portscan

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • MOVED: DynDNS firewall Rule

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Everyday people try to hack in with ssh.

    Locked
    18
    0 Votes
    18 Posts
    13k Views
    jimpJ
    Changing to an alternate port does help cut down on log spam though, and if your logs are more relevant it's easier to spot a potential security issue or targeted breach when you don't have to sort through a bazillion automated attacks.
  • Preventing traffic from reaching LAN from DMZ, but not to WAN

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    A
    Excellent, thank you both very much.
  • Transparent pfsense Firewall

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    2 Posts
    2k Views
    ?
    Blocking based on MAC addresses is not supported in 1.2.3 and is trivial to bypass so you're not actually adding security.  You can, of course, create firewall rules to block IP addresses, that's the point.  If you absolutely must only allow access based on MAC address, consider using the captive portal feature.
  • Stress test Tool

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    M
    Ow sorry i didn't called that. Bandwidth for sure, and the firewall ports.
  • Ports being blocked even though they are open

    Locked
    13
    0 Votes
    13 Posts
    5k Views
    V
    oh, crap, didn't see that, ok, will try it again and watch the logs and report back. Thanks, I'll be back!  :P
  • "ping host" menu command bypasses firewall rules for DMZ/LAN ?

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C
    Everything you describe is the way things should work.
  • State Type "none" not working as expected in 2.0RC1

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    you can't use no state like that, or at all in this circumstance. As long as your source uses random source ports (which is generally always the case, you may need to fix something in your specific case) and a new one every time it opens a new connection, you won't have any issues with opening new connections to the same port.
  • How does the firewall works?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    read these http://doc.pfsense.org/index.php/Firewall_Rule_Basics http://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting
  • Firewall

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Cry HavokC
    Without much more information nobody can help you. Please start with screenshots of your firewall rules (and any aliases) and details of the downloads (URLs etc) that aren't being blocked.
  • Blocking KProxy

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    jimpJ
    If you blocked those IPs, you wouldn't be able to get there if the rule was setup right. A block rule like that should be on the LAN, and at the top of the list.
  • 0 Votes
    2 Posts
    4k Views
    K
    I found that I had to put WAN and brigde this to the LAN connection. I have turned off DHCP server. I have enable DHCP Relay - and put in the dhcp server ip. No my computer, connected to the LAN port, gets an IP,DNS etc… but I cannot ping/dig cnn.com etc.. :-/ I'm connected to my network, but I cannot see outside world..
  • System load on WAN interface on two pfSence VM's

    Locked
    13
    0 Votes
    13 Posts
    6k Views
    I
    Just ran into this for the first time here as well with two physical boxes running v1.2.1 w/CARP and having separate switches for each private/public subnet.  Interestingly, the only difference between this network and any of quite a few others we've worked on with pfSense was the presence of a number of new Windows 7 machines which had bad keys and all suddenly started looking for KMM servers at the same time, (with lots of NBT broadcasts in the process).  Confoundingly, it's a multi-WAN and we had just added the second link (on a separate switch of course) and thought maybe we had configured something wrong in the LB by accident.  Fortunately we have an identically configured setup at another location and after doing a line-by-line comparison between all the configs determined it had to be a bug in pfSense.  A quick search came across this thread and we have implemented jjponce suggestion of restricting traffic between the two WAN interfaces to pfsync and nothing else.  (This was only performed on the public-facing NICs as they were the only interfaces exhibiting the problem, his reference to CARP interfaces may still apply under some circumstances). To clarify a bit further for anyone else seeing this, the traffic only appears on the public side and completely saturates the external NICs.  If you do a packet capture all the packets are NetBIOS addressed from/to 169.254.x.x (actual IP varies of course) and run up to the maximum bandwidth of the WAN link.   To reiterate that last, the bandwidth utilization we observed was the physical limits of the dedicated lines coming in, NOT the limits of the local hardware.  This implies that pfSense is routing the broadcast packets out and they are getting reflected back by upstream devices(?)  The multi-WAN in this case has lines coming from two different ISPs, both lines having bandwidth caps set by the ISPs, one at 35Mb and the other at 100Mb.  All local hardware is Gb but the traffic load was never more than what the lines were (externally) capped at. We'll post again if jjponce's solution does not help, otherwise consider it the answer for now.
  • Block Gtalk and other messengers

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    N
    To block gtalk and chat from gmail.com, I have setup DNS forwarding for talk.google.com, talk.x.google.com and chatenabled.mail.google.com and forwarded all the three domains to my local IP. This has disabled Gtalk from both web and messenger.
  • Logging outgoing mails

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    L
    Thanks for fast answer. Helped me a lot.
  • Can't get Internet speed over 380Mbit with 1.2.3 release

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    C
    A relatively slow box with cheap NICs isn't going to do much more than that. Atoms with Intel gig cards can hit about 500 Mb. 2.0 may be a bit faster, but you're trying to accomplish more than your hardware can do. Normally I would expect the CPU to be maxed out, but you may be hitting bus speed limits or other limits of your hardware.
  • Dual Wan firewall rule issue

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    L
    Hi Managed to get it sorted, user error and new with pfsense = not work lol
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.