• Dshield pfsense log parser now available

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    C
    I had it installed on my pfsense box to begin with, but if I remember correctly it, it did not work as expected because of the way the log file exists on the firewall. Since it is fixed at 512k, I was losing entries as well. My recommendation would be to setup a remote syslog server. It is a trivial task.
  • Feature ideas: rule grouping, changelogs / notes

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    GruensFroeschliG
    btw: this is thread about tracking changes: http://forum.pfsense.org/index.php/topic,9119.0.html
  • ARP (?) Requests do not pass WLAN (Bridge) -> LAN

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    GruensFroeschliG
    Are you really sure you allow everything? I mean a * in the protocol field and not TCP or TCP/UDP. Anyway i would update to 1.2.3 –> http://blog.pfsense.org/?p=377
  • Windows Messenger File Transfer and Remote Assistance

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    R
    here's the screenshot of my LAN and WAN rules ![LAN rules.jpg](/public/imported_attachments/1/LAN rules.jpg) ![LAN rules.jpg_thumb](/public/imported_attachments/1/LAN rules.jpg_thumb) ![WAN Rules.jpg](/public/imported_attachments/1/WAN Rules.jpg) ![WAN Rules.jpg_thumb](/public/imported_attachments/1/WAN Rules.jpg_thumb)
  • Allocating LAN and WIFI connections in 1 PC ?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: Logging Connections / Firewall States on HDD with date and time

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Internal IP not hidden from OPT ?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    T
    Here is the picture of the 1:1 NAT. Is it correct ? Outbound is set to "Manual Outbound NAT", and there is NO rule created (I erased the only one auto-generated). [image: 11NAT.jpg] [image: 11NAT.jpg_thumb]
  • UPnP mappings bypass firewall rules?

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    B
    @xcrustwadx: I also was unable to find records of upnp traffic in pftop either…  I didn't think it was possible to bypass pf. You aren't, the rules go into the upnp anchor, which is probably above your normal rules, hence the reason you can't override it.  I think we'd be willing to see a patch that moves it below user rules and doesn't regress anything ;)  In the meantime, I run upnp on ONLY a trusted interface with very little else on it (that poor xbox is quite lonely, but it does have the Wii and my torrent machine for company at least). –Bill
  • Basic IP blocking rule

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    Z
    got it… apparently it had to be TC/UDP not just TCP.
  • MOVED: problem with firewall

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Using an alias with ipfw command

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    ?
    You should only be making rules with the webGUI Do not mix firewall setups.  pf is the firewall used for 99% of everything, you absolutely can and will goof up things if you mix ipfw in.
  • Help me fix my ruleset

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N
    AFIK though, OpenDNS only has two IP addresses.
  • Odd FW logging inconsistency

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    0
    @Perry: you could try @http://forum.pfsense.org/index.php/topic: What a tcpdump on my Lan nic shows when i try from a outside connection tcpdump -t -i vr0 port 3333 and maybe search in http://192.168.1.1/status.php Thanks for the tip, that was a good page. I don't recognize the URL, it is not linked to in the GUI is it? And I think I finally found the problem - my bad - I have a complex setup of mail servers internally that routes mail back and forth and I have 3 non-standard ports exported for some of those SMTP purposes. I think I may have fooled myself into enabling logging on the wrong rule, I was looking at 25 but the internal target for that NAT was another port.. Thanks,
  • To access pfsense

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    0
    @GruensFroeschli: Your attampt should work. But dont set a source (i assume nn.nn.nn.nn/22 is your WAN subnet) otherwise you would have to be in this subnet to access the webgui. Yes I know, I have access enabled for one specific location and if I'm elsewhere I have to use VPN or RDP to another internal server first. Cheers,
  • Rule clean up question

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R
    time to reinstall your PFsense :)
  • Can i block specific ip or mac address accessing internet

    Locked
    2
    0 Votes
    2 Posts
    6k Views
    B
    Create an alias with the adresses that you either want or dont want to be able to acess. Probably the don't want access as I assume this will be smaller. Then create a single rule Lan Pass Source !BlockedIPList Destination any Port HTTP to HTTP Create a second rule covering HTTPS You need to remove the rule allowing the entire internal lan out This should work.. Regards Mark
  • How pass NFS LAN ->DMZ with scrub enabled?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Embedded PFS to forward all Http to SQUID Server

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: how to block messangers

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Problem with outside firewall

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    E
    @Monoecus: You have chosen (any) in the NAT Port Forwarding window. Try to use “interface address” so that the rule does not get confused with LAN. switched it, still no change :( at this point i've also tried a reinstall, i get a notable error trying to install grub, but i just skipped it instead, but far as i can tell, the rules are being written out, what file would the rules be written to? nvm, found it, looked like all the rules were fine
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.