• Firewall Lanecy traffic issue

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    D
    Your OP said "going up and down".  What is the pfsense sending back?  Unless you are running some kind of open service they can access, they should not be using anything like 2mb/sec.
  • Firewall blocks traffic from dmz/lan to wan address

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    D
    because specifying "wan address" means: "filter if the destination is the WAN address".  in this case, the wan address is the gateway, not the destination.  nothing strange about this.
  • Bulk import of IP to aliases

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    J
    That would fit in with this question too.
  • Remove port forward from pfSense Shell

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    Cry HavokC
    Possibly, but if it all goes wrong and you break your box you're on your own.
  • Firewall Pfsense - Redirect Traffic 80 to 3128 squid machine

    Locked
    9
    0 Votes
    9 Posts
    56k Views
    J
    You can refer here: http://doc.pfsense.org/index.php/Setup_Squid_as_a_Transparent_Proxy
  • Problem with Squd transparent mode

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    J
    Please refer to this link: http://doc.pfsense.org/index.php/Setup_Squid_as_a_Transparent_Proxy
  • Security IN the Peoples Republic

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    P
    Blocking typical traffic in and out that I would do for a pbx in America. just use a strict firewall policy. do not put a permit any to any rule in there. only permit what is needed. are you hosting a website or any other services? Using Snort to try and determine possible intrusions. there is a package in pfsense for this. install it and take a look. Using very complicated passwords on all AP's (including hidden SSID, password with random spaces in it, non-sensical SSID if discovered, and MAC filtering)as well as non-descript computer names, network drives, etc, hidden SSID's and mac filtering isn't going to buy you much if any at all. security by obscurity is a very bad practice. ssid's can still be sniffed and mac filtering is easily spoofed. what you need to be sure is that your using the strongest encryption available. you need WPA2 with AES. anything less is vulnerable.
  • Pf + dup-to = i can?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    i read this topic http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html but i didnt get results…
  • How to release websites for specific ips?

    Locked
    1
    0 Votes
    1 Posts
    896 Views
    No one has replied
  • Allow specific ports on LAN2

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    I
    hello, thank for your reply… no, i havent allowed 53 on the initial alias, but i did so upon reading ur reply.. but still NO GO... is there any other port that needs to be opened? thanks again :) isonski UPDATE: i altered the alias and defined first port 53 (DNS) before port 80 (HTTP) and otehr ports... not it works :D thanks a lot blak :)
  • Firewall Blocking paticular lan request

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    I'm guessing maybe it is a retransmitted FIN segment.  Since the original FIN got through, the connection has been removed from the state table, so seeing a FIN segment is illegal and pfsense drops it (this is just a guess, mind you.)
  • Firewall Optimization Options

    Locked
    7
    0 Votes
    7 Posts
    8k Views
    P
    yeah, i've figured out that it's the "pfctl" command that sucks up all the cpu.
  • Changing the gateway has no effect

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    E
    In what way do you perform switching? Usually it is automatic process if you use loadbalancer in failover mode.
  • Blocking access to all unneeded sites - a firewall or Squidguard?

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    P
    @smbsmb god am i happy i don't work for you.
  • Internet Access Blocking by IP Problem

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    J
    Just unplug the rj45 and your done.
  • Block all of China!!??

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    J
    Thanks jjj - i dont see any intruders /var/log/filter.log :) I noticed that i disabled the firewall default rule :) you should try to disable too maybe it can help :) jigp
  • VLAN <–> Cisco 2900xl

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FTP and some weird things…..

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Block DMZ network from accessing LAN - not working

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    J
    Wow… a reboot made it all better. Can someone explain why that was? Even when there were no states it was still allowed.....?
  • Specific Access based on MAC or other criteria?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Cry HavokC
    Best approach is to add a separate network for these visitors and lock that down.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.