• Firewall and transparent proxy

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Ping Prob

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • SSH Problems with DMZ

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    3 Posts
    22k Views
    R
    That makes sense, I at least have somewhere to start looking now Thanks for your help.
  • Hide VRRP logs

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    M
    Thx. To simple for me ;-) Works like a charm ….
  • 0 Votes
    3 Posts
    2k Views
    C
    @onhel: Did you explicitly setup the ICMP Type in the firewall rule?  Its right underneath the Protocol once you select ICMP.  You will need Any or at least Echo Reply. Correct, except Echo, not Echo Reply if you're allowing pings.
  • MOVED: passing traffic for two hosts on LAN

    Locked
    1
    0 Votes
    1 Posts
    816 Views
    No one has replied
  • Internal IP visible to net

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    P
    Issue Solved & Explained. Sill
  • Disabling firewall rules?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    valnarV
    Right…  I just wanted to know if one was less "backdoor hackable" than the other. Thanks!
  • How to Block mp3 and video downloads through firewall..?

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    C
    thanks a lot p0ddie… ;D
  • Bonjour/Multicast DNS flooding

    Locked
    9
    0 Votes
    9 Posts
    8k Views
    P
    16 gigs in 2 hours translates to roughly 2MB/s of traffic. This is well beyond what normal Bonjour multicast discovery is about. Check his machine (look at the network activity in activity monitor), it either shows constant 2MB/s of traffic on the lan port, or something else is really fishy. Anyway, this looks like a misconfigured client.
  • How to redirect ports on the same lan?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to block traffic over 2 sites

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    If you are on 1.2.3, see here: http://doc.pfsense.org/index.php/OpenVPN_Traffic_Filtering_on_1.2.3 If you are on 2.0, just add a block rule to the top of the OpenVPN tab under Firewall > Rules.
  • WAP and LAN on 2.0-RC1

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blocking constant hits from WAN port 67 to LAN 255.255.255.255 port 68

    Locked
    7
    0 Votes
    7 Posts
    12k Views
    G
    Hey thanks for that!!!!! I used reverse DNS and it came up blank:S  I didn't think to just run a whois–thanks again!
  • Pf 'reason'

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Routing certain machines through VPN

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    Hi, thanks for your reply. Here is what I tried so far: Firewall Rule -> LAN interface, from LAN subnet , to any, Gateway=WAN Firewall Rule -> LAN interface, from any, to any, Gateway=WAN Firewall Rule -> VPN interface, from LAN subnet, to any, Gateway=WAN Firewall Rule -> VPN interface, from any, to any, Gateway=WAN Then I made a Routing Group as you suggested. Routing Group -> created Group with WAN=Tier1, VPN=Never (I also tried Tier2) Then I tried the same rules as above but with Gateway=RoutingGroup I also tried a rule on VPN interface blocking all traffic from LAN subnet, but it still went through. I think I am either misunderstanding how to use these rules or they don't have any effect… The only thing I managed in the meantime was that no traffic at all went through. I hope you or someone else can give a few more tips. Thanks in advance.
  • Need help to access OPT1 from a PC on the WAN subnet

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T
    Good point. In either case, the issue is that pfsense isn't answering the requests for those IPs, because they're bound to a different interface. They're not "listening" on WAN. So either direct traffic locally that is for those IPs, to pfsense… or else configure pfsense to listen to something and forward that traffic (as in my example).
  • Layer 7 firewall rule empty

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    T
    You need to visit the Traffic Shaper, and create a Layer7 container. Here you create the block or queueing rules, and then you can apply this container to a firewall rule.
  • How to make "transparent" firewall?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T
    I believe using 1-1 NAT mappings on the external one should accomplish this. Map each of the external IPs to a virtual IP (of your choosing) on the segment between the two firewalls (the inner firewall would be listening on these virtual IPs). Then create firewalls rules on the outer one that passes all traffic directed to/from those IPs. Since your lines are of different sizes, you'll need to put the shaper on the external firewall to make much sense.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.