• Firewall - add a lot of rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    Hi Skart, Can you explain how you fixed it. It can be helpful for the other members on the board.  …Actually im pretty interested at your version of the solution ;-) -m4rcu5
  • Firewall to defend DDOS Attack

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    M
    Hi rwhawkes, What i use to block the crap out is the rate limiter on the rules. Why on earth would someone make 100 conns/s if he is just browsing on port 80? That usually blocks the big offenders. If you have something like slowloris going on then snort might be of help. Snort also does a nice job blocking any known malicious networks. Hope this helps a bit in blocking your attacks. -m4rcu5
  • Unblocking IPs from the Command Line

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Not at this time, not easily anyhow. If it's in a rule or alias, you could hand edit the config (using viconfig) and then run /etc/rc.filter_configure If it's in a table that is dynamic, like snort or the ssh lockout, you can clear it on the command line with pfctl like so: pfctl -t sshlockout -T flush That would clear all entries in the sshlockout table
  • MOVED: VPN unreliable?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Where are the ftp helper options within 2.0-RC1?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    R
    all you can do is enable or disable it.  search for: debug.pfftpproxy Roy…
  • Bypass firewall for lan to wan to lan

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    Cry HavokC
    Hardware update clients are notorious for being problematic - it all depends on how much effort the manufacturer put into making them work correctly and how they find out the WAN IP. One solution I've found to work reliably is to replace the firmware with the likes of DD-WRT, which has a well behaved update client built into it. Obviously that only works if your router is supported by DD-WRT.
  • Checkpoint VPN has troubles when going through a pfsense gateway

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0.0.0.0:68 all over my logs

    Locked
    10
    0 Votes
    10 Posts
    15k Views
    E
    @driek: Could you tell me what your firewall rule looks like? My logs contain a lot of these and I think I need to let them pass for my IPTV to work, but I can't figure it out.. If you're seeing them in your logs, then they're not being passed, so if your IPTV is working, it doesn't need them. They're usually just "chatter" you get being on a cable modem. It's a fairly straightforward rule to block them, without logging. Cheers.
  • At&t MicroCell & NAT can't connect.

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    R
    My microcell works perfectly under 2.0 and has worked perfectly under 1.2.3. I did not have to forward any ports at all.
  • 0 Votes
    5 Posts
    3k Views
    jimpJ
    Syslog is the only way to do it out of the box. I'm not sure if anyone has a package out there that does what you're after. You could write your own daemon that attached to the pflog device and reads the data (or pipe it through tcpdump, check out how the current log is taken with tcpdump.) and then work that into your database however you like.
  • Mobile clients no Connection in-house

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    GruensFroeschliG
    http://doc.pfsense.org/index.php/Why_can%27t_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F
  • Whatif you don't adjust the states?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    W
    Thanks for the response.  That makes perfect sense now.
  • Firewall Rule Question - Can someone help?

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    S
    It could be in the order of the rules. The top rule gets processes first, so if you have a block rule above your pass rule, that could be the problem.
  • Routing one LAN traffic through a specfic WAN link

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A
    For some reason I couldn't get 1:1 NAT to work properly. Kept messing up some other things… However, the second suggestion worked flawlessly. Thanks a lot guys, problem solved!
  • How can I permit messenger services

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC
    There is a package for proxying IM connections, or you could use the likes of Squid (with Squidguard) and only allow the destinations you want.
  • MOVED: How can I block Social Networking Sites

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • View real time downloading activity and download quota

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Policy based internet access

    Locked
    1
    0 Votes
    1 Posts
    886 Views
    No one has replied
  • Protect a Dns Server

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Cry HavokC
    Don't forget that your firewall (pfSense box) is the weak link here - there's nothing stopping somebody simply DDoSing it if you just protect your DNS server.
  • 0 Votes
    1 Posts
    775 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.