• 0 Votes
    4 Posts
    3k Views
    chpalmerC
    Works well! My kids hate it…    [image: grin.gif]
  • How/why is port 443 allowed by default?

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    O
    hi @ all, Not sure why the firewall is allowing HTTPS through. –> hmmm, ssl login to gmx f.e. or ebay Also, I cannot block ICMP. I have tried to "block all" and "block icmp" and nothing can block ICMP. –> you cant block, i can ;) Block ICMP LAN net * * * *   Block LAN Ping
  • WTF is OCSP.MIA1.VERISIGN.COM

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    O
    aaaahhhhh is verisign from pfsense firewall ??????? http://www.verisign.com/static/005296.pdf –-------- RESULT is not a risk!!! its for security :D http://www.soft-ware.net/tipps/tipp27/Verbindung-zu-crlverisigncom-sicher.asp dont panic! CLOSED
  • Blocking log entry no working?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    That's common to see on Cable networks. It's just DHCP traffic from your provider. That will always be logged unless you (a) disable the "block private networks" rule under Interfaces > WAN, and (b) add a rule at the top of your WAN firewall rules that blocks UDP from any port 67 to 255.255.255.255 port 68
  • [SOLVED] Periodic update of URL based Aliases

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    C
    Thanks for the heads up, I'll stuck to URL Tables then. Cheers
  • FTP TCP-S How To Allow It?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    O
    ok sorry! it was a server problem … I CAN DOWNLOAD and now iam happy! THANKS CLOSED
  • Firewall block all rules

    Locked
    11
    0 Votes
    11 Posts
    11k Views
    C
    The rules take a priority from the TOP to the bottom, so Block * WAN * will refuse any allows that appear after it to fix this, move your block statement to the very bottom of your list, and all will be fixed. Change your rules to look like this. TCP/UDP * * * 6666 *   OpenVPN  TCP/UDP * * * 3333 *   NAT Squid Port Forward  TCP/UDP * * * 110 *   Allow WAN POP  TCP/UDP * * * 995 *   Allow WAN POP SSL  TCP/UDP * * * 143     *   Allow WAN IMAP  TCP/UDP * * * 993  *   Allow WAN IMAP SSL  TCP/UDP * * * 25  *   Allow WAN SMTP  TCP/UDP * * * 465  *   Allow WAN SMTP SSL  TCP/UDP * * * 587 *   Allow WAN SMTP TLS  TCP/UDP * * * 21 *   Allow WAN FTP  UDP      * * * 123  *   Allow WAN NTP  ICMP    * * * * *   Allow Ping  TCP      * * * 4804 *   Allow BunkerTV Radio  TCP/UDP 192.168.10.25 * * * *   Allow Only Lafoffice01        * * * * * *   Block WAN ALL
  • VLAN DHCP Working - No Internet Access

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    B
    Do you have squid (and) squidGuard packages installed by chance? If not do this: Click "Diagnostics,>Ping,>Select the LAN interface,> try google.com copy/paste the output of this back here,,, You will no doubt get 100% drops but the return values may help to determine what is dying. If you do in fact get replies on the pfSense box you know your routing is jabber wokied somewhere to the vlan… BC
  • MOVED: SquidGuard

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PfSense newbie -MAC filtering - how to ?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    G
    DHCP Server and Captive portal
  • [SOLVED] ICMP, HTTPS managment from WAN, correct WAN FW rules?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    Thank you that you are so supportive!  :'( 1.) I figured out how to do this by myself. So thanks anyone who helping me! ;) 2.)I did this using PORT forwarding and one WAN rule.
  • PfSense and TTL=1

    Locked
    7
    0 Votes
    7 Posts
    12k Views
    U
    It did work for me! Thanks a lot mate !   8)
  • [solved] DMZ via VLAN - would this work?

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    G
    @ghm: Questions: Do I actually have to tag LAN or is it good enough to tag DMZ? I think I need to tag LAN as well but am not certain. Do I under the DMZ tab actually have to state the Source? Why not just the destination given that the Firewall work inbound and the tab describes the IF anyway? Does anything else here look clearly bad? solved this using "pfSense - The Definitive Guide". Now I know that one should neither use PVID 1 nor the parent interface of a VLAN. Have LAN on PVID 2 now and DMZ on PVID 11. WiFi is unbridged now, even though bridged did not cause visible issues. Works :-)
  • Only one domain

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    chpalmerC
    A counterpart of mine does this using Wampserver using virtual hosts on the same machine. Using No-IP.com he only has to update the service to one IP address.
  • MOVED: Allow only one WEB site and Block others

    Locked
    1
    0 Votes
    1 Posts
    994 Views
    No one has replied
  • Firewall Rules for second network

    Locked
    15
    0 Votes
    15 Posts
    8k Views
    C
    I have to allow OpenVPN even though I'm using the PPTP on pfSense and not OpenVPN?  Also, I can't seem to make an ftp connection to any ftp.  I tried ports 21, 20, 1023, 1026, 1027.  Should I just remove the block on the LAN and move it to the WAN?
  • Time Based Rule

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to block a complete AS (autonomous system)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Firewall blocking allowed RTP packets

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    T
    Thanks Perry, that got me in the right direction. Doing Manual Outbound NAT did the trick - although I cannot figure out why 2 providers worked fine, and one didnt.
  • Prevent TCP Zero Window DDNS (Sockstress) Attacks

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    S
    PF (the packet filter in pfSense) has packet scrubbing for this which is enabled by default. See here.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.