• Security IN the Peoples Republic

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    P
    Blocking typical traffic in and out that I would do for a pbx in America. just use a strict firewall policy. do not put a permit any to any rule in there. only permit what is needed. are you hosting a website or any other services? Using Snort to try and determine possible intrusions. there is a package in pfsense for this. install it and take a look. Using very complicated passwords on all AP's (including hidden SSID, password with random spaces in it, non-sensical SSID if discovered, and MAC filtering)as well as non-descript computer names, network drives, etc, hidden SSID's and mac filtering isn't going to buy you much if any at all. security by obscurity is a very bad practice. ssid's can still be sniffed and mac filtering is easily spoofed. what you need to be sure is that your using the strongest encryption available. you need WPA2 with AES. anything less is vulnerable.
  • Pf + dup-to = i can?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    i read this topic http://taosecurity.blogspot.com/2005/07/distributed-traffic-collection-with-pf.html but i didnt get results…
  • How to release websites for specific ips?

    Locked
    1
    0 Votes
    1 Posts
    904 Views
    No one has replied
  • Allow specific ports on LAN2

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    I
    hello, thank for your reply… no, i havent allowed 53 on the initial alias, but i did so upon reading ur reply.. but still NO GO... is there any other port that needs to be opened? thanks again :) isonski UPDATE: i altered the alias and defined first port 53 (DNS) before port 80 (HTTP) and otehr ports... not it works :D thanks a lot blak :)
  • Firewall Blocking paticular lan request

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    I'm guessing maybe it is a retransmitted FIN segment.  Since the original FIN got through, the connection has been removed from the state table, so seeing a FIN segment is illegal and pfsense drops it (this is just a guess, mind you.)
  • Firewall Optimization Options

    Locked
    7
    0 Votes
    7 Posts
    8k Views
    P
    yeah, i've figured out that it's the "pfctl" command that sucks up all the cpu.
  • Changing the gateway has no effect

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    E
    In what way do you perform switching? Usually it is automatic process if you use loadbalancer in failover mode.
  • Blocking access to all unneeded sites - a firewall or Squidguard?

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    P
    @smbsmb god am i happy i don't work for you.
  • Internet Access Blocking by IP Problem

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    J
    Just unplug the rj45 and your done.
  • Block all of China!!??

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    J
    Thanks jjj - i dont see any intruders /var/log/filter.log :) I noticed that i disabled the firewall default rule :) you should try to disable too maybe it can help :) jigp
  • VLAN <–> Cisco 2900xl

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FTP and some weird things…..

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Block DMZ network from accessing LAN - not working

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    J
    Wow… a reboot made it all better. Can someone explain why that was? Even when there were no states it was still allowed.....?
  • Specific Access based on MAC or other criteria?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Cry HavokC
    Best approach is to add a separate network for these visitors and lock that down.
  • Default LAN Rule

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    J
    kpa, thanks for your reply. Yes, the traffic is actually blocked by the pfsense router: i've tracked the packets using tcpdump, from the client to the pfsense to the web server (Zimbra mailserver) and back to the client through the pfsense router. This is were the packets are stopped. I have several applications (database and a Freecom file server) accessed by remote clients  and the connection to the Zimbra mailserver is the only one blocked on its way back. Thanks for your help.
  • DHCP on WAN Blocked?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T
    Well, ripping everything apart, trying various pci network cards, and putting it back together, allowed me to determine that putting it back exactly how it was fixed my problem.  Not sure exactly why (maybe just having the modem unplugged for a while) it is now fixed, but it is. What I was able to find out, is that the jetway case I bought to go with my intel motherboard is a pain to work with, and I cannot get the pci riser working reliably with the atom motherboard (I can see the network card, but it isn't able to get any traffic flowing through it, and I get a bunch of watchdog errors).  But that is a problem for another day ;)
  • Allow traffic from dynamic IP address

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G
    I find that using a voip phone over an IPSEC VPN tunnel affects the call quality quite seriously. I guess it is the overhead of the encryption. I have the same problem with a couple of home workers. Will try out the Alias hostname. Thanks
  • [howto] Getting native IPv6 to work.

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J
    I tried to change the number 64 into 24 but no luck.. Configure the interfaces ifconfig $IFOUT inet6 alias 2001:4cb8:a95:1::2 prefixlen 64 changed to 24 ifconfig $IFIN inet6 alias 2001:4cb8:b95:1::1 prefixlen 64 changed to 24 …. I use "ipconfig on windows workstations but i dont see this kind of ipv6 ips.. jigp 1.2.2
  • Maximum new connections / per second

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    Hi can you tell me how to know who brute force the box and also how to set limit of connections on ssh? Thanks jigp 1.2.2
  • Pfsense rewriting my LAN IPs

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    GruensFroeschliG
    Firewall –> NAT --> outbound Enable manual outbound NAT rules. Delete the autocreated rule and nothing should be rewritten anymore. Make sure you have the correct static routes on the upstream devices set.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.