• Need some help on LAN IP blocking

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R
    Hi everybody! I used ALIASES in assigning a group of LAN IP addresses: 1. List of LAN IP Addresses blocked in accessing the internet and 2. List of LAN IP Addresses with time restrictions in accessing the internet And used SCHEDULES in assigning time restrictions in some LAN IP Addresses as listed in no. 2. After which I used them in making FIREWALL RULES and placed them before the default rule. After that I reboot the system but it hanged during Configuring firewall….. Please help!
  • FTP Server > pfSense returning WAN IP instead of Virtual IP

    Locked
    10
    0 Votes
    10 Posts
    5k Views
    K
    Yeah, only outgoing connections originating from 192.168.1.5 will be mapped to the VIP. You'll still need to add port forwards for incoming connections. Btw static port means exactly what the documentation states: "do not randomize source port on the outgoing connections", nothing else. The redirection is really done with the selection of the NAT address in the outbound rule and static port is just an extra option that is normally not needed. In your case it's better to turn it on since (active) ftp data connection originates from port 20 and you want it to originate from the same port on the VIP.
  • MOVED: Problem with SMTP in PFSENSE.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to divide 2 network in interface LAN

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    GruensFroeschliG
    http://forum.pfsense.org/index.php/topic,19862.msg102193.html
  • How to block free anonymous proxy http ?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    thanks sir..  ;D
  • Definition of 'any' for protocol?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • ICMP best practice?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    6 Posts
    3k Views
    Cry HavokC
    I've already mentioned other possible problems - search my previous reply for NetBIOS ;) Did you put rule (1) on the 192.168.2.x network interface?  Is it before any other rules?
  • VOIP - SIP registration timeout issue

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    M
    I think I know what is happening, not sure how to fix it yet. There are 2 sets of trunks, 3 trunks with one provider and 1 trunk with a second provider.  If I disable either trunk set, the other set will register and work fine.  Its when both trunk sets are enabled that the single trunk set will drop.  It should be noted that when the trunk drops, tcpdump shows no outgoing traffic to the provider of that trunk on the wan interface; however the lan interface shows the traffic coming into the box. So at least I can replicate the issue by enabling/disabling the asterisk trunks without rebooting the pfsense box each time. I suspect that this vanished trunk registration traffic is being incorrectly routed to the other provider and thats why I don't see it.  I also have no idea why it would work initially for a bit when the trunks are all enabled and then it dies with no trace.
  • Please check my Firewall:Rules and tell me if they are ok.

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • PfSense –> Web Server

    Locked
    8
    0 Votes
    8 Posts
    17k Views
    F
    @dotdash: To just address the last question, if you need the server to have a static IP, you could create a DMZ bridged to WAN. Another solution is to make the firewall transparent. Search around, there is a lot of information on these options. Followed this guide: http://202.143.130.99/files/transparent_firewall.pdf Worked like a charm!  Thanks for pointing me in the right direction :)
  • Firewall rule not blocks ip

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Different Default deny problem

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    B
    Anyone have any ideas?
  • [Solved] Allow web interface WAN access

    Locked
    7
    0 Votes
    7 Posts
    11k Views
    D
    Glad it's working.  I've had a glitch or two where rebooting cleared up whatever stale state/entry was causing issues.
  • Pfsense is accessible from the web

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G
    Sorry for the delayed response! Apparently, I had a rule allowing all the ports forwarded from my VM, this appears to have been added by default.  Does anybody know why?  The description is "Default allow all on WAN in VM." In any case, disabling the rule has fixed my issue.  Thanks!
  • Where should a Radius server sit ? DMZ or WIFI ??

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Block web access

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    S
    Why dont use Captive portal??
  • Comply with CALEA ?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    Cry HavokC
    Try searching the forum and read the answers to the other threads ;) In short, by itself it won't provide you with CALEA compliance but it also doesn't stop you achieving it.  You should talk to a lawyer about what you have to do, but it may be that simply providing a network tap is sufficient.
  • Bridge not work in pfsense?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    B
    No one can help or know in issue??
  • US Cert Vulnerability Note #464113 - TCP SYN (FIN)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.