• Blocked packed even if rules allow traffic?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    F
    Thanks for the explaination. Could rasising the state size reduce this noise or does it not matter?
  • MOVED: Unable to delete or reinstall the squid and squidgurad

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Configure PFsense firewall from CLI

    Locked
    6
    0 Votes
    6 Posts
    11k Views
    jimpJ
    It's just PHP. It's in the pfSense code repo, it's part of 2.0.
  • Basic Home Firewall Setup

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    R
    Any error aside, it sounds to me like you are where I was a two or three months ago.  Please review this post, which contains what I learned: http://forum.pfsense.org/index.php/topic,25548.0.html Regarding having only a few machines and so keeping a tight netmask, why bother?  Use /24, it is easier to think about.  Use a different number for each LAN if you have several.
  • Multi-Site BGP and firewall rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    E
    For BGP to work you do not need anything in rules other than TCP port 179 allowed.
  • Log LAN Rule but I don't have any rule to Log

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    A
    Thanks Jimp
  • Block All Ports and Only Allow HTTP(S)

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    P
    Yes, after viewing the advanced options in skype I just realized this. I would like to view my squid cache logs. How do I view my logs to ensure that traffic is going through squid as well. I am able to view my squid lightreport though.
  • WAN type - DHCP vs StaticIP

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    W
    Thanks!!! Default subnet was 32 - which was the problem. Thanks!
  • Completely open, but traffic gets blocked by "Default deny rule"

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    W
    Update: SOLVED! Stupid mistake! - it was working all along - just on the server soft-firewall was in the way.
  • MOVED: how can block sites over name?. travian, heroes, amazon etc

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Not able to access public WAN IP from internal LAN

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    F
    This may help. http://doc.pfsense.org/index.php/Why_can't_I_access_forwarded_ports_on_my_WAN_IP_from_my_LAN/OPTx_networks%3F
  • Blocking Hotspot Shield

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    jimpJ
    Since it relies on connecting to their remote servers to make a VPN connection, you might be able to look up whatever IP space they own and block it that way. Depending on the protocol they use, an L7 filter might work, but it may also catch traffic you want.
  • Only allow US Ips?

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    jimpJ
    The URL Table Alias package will let you do this, too. But you need to be on 1.2.3 to use it.
  • M$ activesync errors

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    F
    There is an option in the Advanced State section of the firewall rules to specify the timeout length in seconds. You could try adding a value to that field to keep the state from closing earlier than MS wants.
  • Multiple Static Voip

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • DNS Issues

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    In order to properly offer suggestions, we'll need a lot more information. For starters, the exact contents (preferably screencaps) of your firewall rules and NAT rules. You can block out any public IPs but if you do so, at least leave the last octet. Before gathering that info, first have a look here: http://doc.pfsense.org/index.php/Port_Forward_Troubleshooting
  • MOVED: load balancig problem. cant log in to website! (CPANEL)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Port-forwarding LAN:X to LAN:Y

    Locked
    8
    0 Votes
    8 Posts
    9k Views
    R
    New idea on how to get another "apparent" interface so that I can achieve my desired forwarding.  I have been reading about VLANs.  I am really extrapolating here so please bear with me if I am way off base. If I created VLANs on my LAN, would I be able to forward LAN:80 to VLAN:8080, having VLAN:80 open to go to the internet?  If so, I have some other questions too. When a machine does a DHCP request, it knows nothing of VLANs, so I assume that the request is picked up by the DHCP server and that the DHCP server assigns it an IP and associates it with a VLAN.  How does it choose?  The only differentiator would be the MAC address, so this would have to be manually configured, analogous to a static IP.  Am I on the right track?  I suppose there could be more boxes appearing under the DHCP Server configuration that appear after I make the VLANs, but I don't want to mess up my working configuration until I know that I am barking up a valid tree. There seems to be an assumption of a managed switch to route VLANS.  From what I have read, I don't see anything preventing a cheap layer 2 switch from routing based on MAC address, as long as I cut down the MTU by 4 bytes to make room for the VLAN stuff.  1500 bytes is hardly a power of two anyway, so I would expect the impact on throughput due to fragmenting and assembling 1496 vs. 1500 byte packets would be minimal.  Is this good reasoning? Do I have to have all other traffic on the physical LAN interface be on VLANs too, or can the "base" lan be "normal", with VLANs running on top? Thanks.
  • VOIP registration

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    P
    I can't thank you enough.  I had the AON but without the static route selected.  Racked my brain for days with this. THANKS!
  • External Traffic Blocked - Even with NAT rules and Nat Reflection Setup

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    A
    i may have found the issue, standby ** UPDATE ** I may have fixed it i dont know. I can access the services from the ip address but it seems the dmain names arnt working.  Might be something to do with the dns server. i am investigating now
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.