• Blocking TCP with RST flag ???

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    D
    It might be possible to craft the right pf rule, but you'd have to invoke that in a script or something.  Can I ask what you are trying to accomplish?  Not meaning to offend, but folks here are basically providing free tech support, and I for one would rather not invest a significant amount of (unpaid) time trying to help someone massage pf in a way that makes no sense.
  • Firewall rules

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    T
    Correct.
  • Blocking ports on the pfsense computer

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    0
    @jimp: Squid puts in a pass rule for the proxy when transparent proxy is enabled, and no rule you enter manually can override this. Ok, that sounds like a pretty crucial note then, I'll put it in my pfS book somewhere.
  • Long time to start

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    jimpJ
    @flanandorj: 1.2.2 built on Thu Jan 8 22:30:24 EST 2009 Upgrade to 1.2.3-RELEASE and then try again. If you still have issues, then someone might be able to help you further.
  • My pfsense failed an audit by securitymetrics.com

    Locked
    46
    0 Votes
    46 Posts
    23k Views
    J
    Glad it is working now ;-)
  • SSH port forwarding

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    P
    It worked perfectly!!!!!! Thx a lot
  • How to access a DSL modem through pfSense?

    Locked
    21
    0 Votes
    21 Posts
    25k Views
    bmeeksB
    I have two settings different from the screenshots shown for Virtual IP and NAT.  First, on the Virtual IP page I have "Other" marked and not "Proxy ARP".  Second, on the NAT setup I have the radio button for "Manual Outbound NAT" clicked and not the "Automatic" button.  Don't know if that will fix you or not, but except for those two, your settings and mine look the same.  Mine is working as posted earlier in this thread. One other thing to double-check.  Under Interfaces..WAN, make sure "Block private networks" is unchecked.
  • Block rule with schedule just almost working

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    0
    UPDATE –----- I have now uninstalled Lightsquid (must be uninstalled before Squid otherwise there are errors and uninstall fails..) and Squid and after a few reboots it seems that my block rule is working as intended. Obviously Squid is in a number of situations a problem, I have to do some rethinking when it comes to if and how I should use the Squid package then. Any thoughts and comments welcome.
  • Rules help with no internet access

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    M
    Thank  You! You've been very helpful  :D
  • Multi Wan external Squid redirect on same Subnet?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    G
    OK, thanks for that. These are all ESXI VM's so i guess i will just have to add some more networking in. "you'd just need a port forward on LAN that redirected any port 80 traffic NOT going to the pfSense box's LAN IP' Is this right? Surely this would mean that the redirect would not redirect the HTTP traffic and it would continue on through the pfsense box. Or am i being dumb, which is more than possible!! Cheers Gareth
  • Virtualbox + pfSense + DMZ

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    T
    I have been running one in Xen Server for 3 months now with no issue. Just make sure to reset the states when you make firewall changes.
  • Problem with access between 2 bridged lans

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • PCI Compliance Port 53

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    S
    You do not fail PCI compliance for having an open port on your firewall.  Port 53 is DNS, and if you run your own DNS servers, you must have this port open inbound.  You need a real PCI assessment, not some free automated scan.
  • PPPoE subnet ….

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    B
    ok, i didn't know about the netmask in UK, im from mexico, and me neither be sure if the doc applies to wan but i try everything to resolve my situation, and seems that there are many people with your same problem in the forum, anyway, good luck
  • VLAN via LAN NIC

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blocking ports and other lans

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    D
    Thanks again Efonne. I've now got everything working the way I planed it. I don't think a have a use for scheduling yet, but I see how it could come in handy. Thanks for the help again and bye
  • Can I redirect somebody on my network to a different page?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    C
    The squidGuard package appears to offer this functionality, although I've never used it. I like squid though.
  • 0 Votes
    5 Posts
    5k Views
    G
    Hi, the dummy static route is, so it seems, the only working solution for that problem. Now there is a static supernet route that covers every subnet. Its not the best but a working solution. The thing is, I think I will stay at static routes on my pfSense because neither RIP nor OpenOSPFd are getting along with PPPoE resets :( Edit: The dummy static route has another major downside with it. It generates a routing loop whenever one of the supernet advertised subnets is down, because the next hop router has the pfSense as default gateway, which is correct because it is the internet gateway. The packets are bouncing from the pfSense to the next hop router and back again until the TTL is 0. If OSPF would be running, the network would have been eliminated out of the routing table and the request would get a "network is unreachable" or something similar. Or am I wrong? To OSFPd the second: The process is stuck after every PPPoE "redial" no matter it is caused by periodic pppoe resets or manual reconnect. After being stuck it start a new ospfd instance. When you remove the OpenOSPFd package, the other started processes are not killed and running until you kill them manually.
  • WLAN to LAN access issue

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    sweet!
  • Can't access my webserver

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    jimpJ
    You need both a port forward and a firewall rule. This troubleshooting page might be of use: http://doc.pfsense.org/index.php/Port_Forward_Troubleshooting As well as the Port Forwarding tutorial here: http://doc.pfsense.org/index.php/How_can_I_forward_ports_with_pfSense%3F
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.