• Schedules breaks captive portal?

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H

    Ah, nice to know.

  • Access webgui from outside (public ip)?

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    S

    yes, this always worked; I never tryied ssh the wan because it was behind an adsl modem; now I'm using a frame relay circuit and do not have anything between me and internet.

  • Filtering Bridge to OPT1: Non-primary IP addresses invisible to pfSense

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J

    @cmb:

    You can use as many IP's as you want on your OPT1 hosts, I've had deployments exactly as you describe and they work fine. You do not want it as a VIP since that IP is directly assigned on a system. That will likely break it, take that out.

    What do you mean by "totally ignored"? What are you trying to do that doesn't work?

    The VIP was only temporary in an attempt to make it work. Forget I ever mentioned it.

    Quite simply, I have no access whatsoever from the WAN to those IP addresses on the (Filtered Bridge) OPT1 interface that are not the primary IP address on the host's Ethernet interface. Rules to the primary IP work perfectly; no rules to additional IPs (pass or deny, port or any) have any effect whatsoever, nor is there any corresponding entry in the log. It's as if the IP addresses were totally invisible to pfS.

  • File of pf rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    W

    /tmp/rules.debug

  • Question about IP forwarding SMTP and using SPAMD

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC

    Embedded is designed for installing onto solid state memory (compact flash etc).  There used to be a good primer, but it seems to be gone :(

  • High load cable network

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C

    As long as you're using new server class hardware you'll be fine at those numbers.

  • Blocking with ipfilter.dat

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    GruensFroeschliG

    I dont think so.
    pfSense loads the xml at startup and after that runs from RAM. it only access the "slow" storage when you change something in the configuration.

    (I think you would need REALLY REALLY many aliases to slow pfSense down)

  • Allow program based on UUID or executable name

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    Thanks for the quick help.  :)

  • Downloading broken. Troubleshoot or Reinstall?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    dotdashD

    This should work on a stock setup. It sounds like you may be hosting ftp servers, which will add to the complexity. Try the standard ftp troubleshooting steps and see if that helps: http://devwiki.pfsense.org/FTPTroubleShooting

  • Blocking orkut

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    G

    It works with OpenDNS. thanks cdsu.

  • No connection LAN -> DMZ after some time

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    I

    Nothing is working, not even ping LAN -> DMZ. WAN -> DMZ is working.

    So i should upgrade you think? I'm unsure which package to use from ftp://reflection.ncsa.uiuc.edu/pub/pfSense/updates :-)
    This one using the WEB Gui Upgrade function? pfSense-Full-And-Embedded-Update-1.2-BETA-2.tgz? Never upgraded before…

    icanton

  • Disable routing between VLANs

    Locked
    17
    0 Votes
    17 Posts
    12k Views
    M

    That's really good to know.  I'm almost positive I was a victim of that very scenario.  Thanks for the tip.

  • Some help with a firewall rule

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    Great.  Looks like I got the rules correct.  Thank you!

  • Import an alias list?

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    F

    Thanks for the replies.  I did some digging and I do see that the config.xml file has the alias lists.  I see that the address section is pretty straight forward, but do I need to put information in the corresponding <detail>section?

    Since this information would be right in the config.xml file, I'm a bit concerned about putting in too many aliases for fear this will slow down bootup and general operation of my pfSense box.  The list I might want to import may have hundreds or thousands of IPs.  Would such a large alias list negatively impact the performance of pfSense?</detail>

  • Firewall rules by hostname/domain name

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    T

    Good to know. That's been one of the only areas of weakness, as far as I'm concerned.

  • Aliases

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG

    you dont see the name of the alias in any list.
    you just write the name of the alias directly into the field with red background.

    (i'm using this without problem in 1.2RC2)

  • [Transparant] Snort doesn't work

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • White list as Content filtering

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC

    You could go with Squid, though I'm not sure if it supports a default block.  You also can't (that I know of) do a selective block on what a DNS name would resolve to.

  • Nat reflection

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    But I am not using any SSH… I can't even get to my WWW server from LAN through WAN IP and formwarded port.. 80.. nor 85...

    in 1.0.1 it worked fine :( :( :(

  • What's default value for firewall->rule->edit->Advanced Options

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    dotdashD

    There is no default value on most of those. eg- there is no simultaneous client conection limit unless you set one. The pf default on state timeout is 10 sec and it appears pfSense does not change this. (pfctl shows interval=10s)

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.