• Best Way How To: Block Lan machine from accessing internet?

    Locked
    8
    0 Votes
    8 Posts
    14k Views
    jimpJ
    Captive portal can also help in a Hotel/Airport/Hotspot environment as well
  • Dshield pfsense log parser now available

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    C
    I had it installed on my pfsense box to begin with, but if I remember correctly it, it did not work as expected because of the way the log file exists on the firewall. Since it is fixed at 512k, I was losing entries as well. My recommendation would be to setup a remote syslog server. It is a trivial task.
  • Feature ideas: rule grouping, changelogs / notes

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    GruensFroeschliG
    btw: this is thread about tracking changes: http://forum.pfsense.org/index.php/topic,9119.0.html
  • ARP (?) Requests do not pass WLAN (Bridge) -> LAN

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    GruensFroeschliG
    Are you really sure you allow everything? I mean a * in the protocol field and not TCP or TCP/UDP. Anyway i would update to 1.2.3 –> http://blog.pfsense.org/?p=377
  • Windows Messenger File Transfer and Remote Assistance

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    R
    here's the screenshot of my LAN and WAN rules ![LAN rules.jpg](/public/imported_attachments/1/LAN rules.jpg) ![LAN rules.jpg_thumb](/public/imported_attachments/1/LAN rules.jpg_thumb) ![WAN Rules.jpg](/public/imported_attachments/1/WAN Rules.jpg) ![WAN Rules.jpg_thumb](/public/imported_attachments/1/WAN Rules.jpg_thumb)
  • Allocating LAN and WIFI connections in 1 PC ?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: Logging Connections / Firewall States on HDD with date and time

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Internal IP not hidden from OPT ?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    T
    Here is the picture of the 1:1 NAT. Is it correct ? Outbound is set to "Manual Outbound NAT", and there is NO rule created (I erased the only one auto-generated). [image: 11NAT.jpg] [image: 11NAT.jpg_thumb]
  • UPnP mappings bypass firewall rules?

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    B
    @xcrustwadx: I also was unable to find records of upnp traffic in pftop either…  I didn't think it was possible to bypass pf. You aren't, the rules go into the upnp anchor, which is probably above your normal rules, hence the reason you can't override it.  I think we'd be willing to see a patch that moves it below user rules and doesn't regress anything ;)  In the meantime, I run upnp on ONLY a trusted interface with very little else on it (that poor xbox is quite lonely, but it does have the Wii and my torrent machine for company at least). –Bill
  • Basic IP blocking rule

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    Z
    got it… apparently it had to be TC/UDP not just TCP.
  • MOVED: problem with firewall

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Using an alias with ipfw command

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    ?
    You should only be making rules with the webGUI Do not mix firewall setups.  pf is the firewall used for 99% of everything, you absolutely can and will goof up things if you mix ipfw in.
  • Help me fix my ruleset

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N
    AFIK though, OpenDNS only has two IP addresses.
  • Odd FW logging inconsistency

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    0
    @Perry: you could try @http://forum.pfsense.org/index.php/topic: What a tcpdump on my Lan nic shows when i try from a outside connection tcpdump -t -i vr0 port 3333 and maybe search in http://192.168.1.1/status.php Thanks for the tip, that was a good page. I don't recognize the URL, it is not linked to in the GUI is it? And I think I finally found the problem - my bad - I have a complex setup of mail servers internally that routes mail back and forth and I have 3 non-standard ports exported for some of those SMTP purposes. I think I may have fooled myself into enabling logging on the wrong rule, I was looking at 25 but the internal target for that NAT was another port.. Thanks,
  • To access pfsense

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    0
    @GruensFroeschli: Your attampt should work. But dont set a source (i assume nn.nn.nn.nn/22 is your WAN subnet) otherwise you would have to be in this subnet to access the webgui. Yes I know, I have access enabled for one specific location and if I'm elsewhere I have to use VPN or RDP to another internal server first. Cheers,
  • Rule clean up question

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R
    time to reinstall your PFsense :)
  • Can i block specific ip or mac address accessing internet

    Locked
    2
    0 Votes
    2 Posts
    6k Views
    B
    Create an alias with the adresses that you either want or dont want to be able to acess. Probably the don't want access as I assume this will be smaller. Then create a single rule Lan Pass Source !BlockedIPList Destination any Port HTTP to HTTP Create a second rule covering HTTPS You need to remove the rule allowing the entire internal lan out This should work.. Regards Mark
  • How pass NFS LAN ->DMZ with scrub enabled?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Embedded PFS to forward all Http to SQUID Server

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: how to block messangers

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.