• Loopback? i think its called?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    dotdashD
    Go to Advanced and uncheck the box 'Disable NAT reflection' This is kind of a hack, but D-Link, Linksys, etc. use ugly hacks to do this. If you are hosting a web site/mail server, you really should use the internal DNS instead of the external DNS. IMO, If you are running public servers, you can handle running a DNS server.
  • Traffic passing with rules disabled

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    M
    yes it will  :D http://forum.pfsense.org/index.php/topic,6516.0.html
  • Traffic being blocked despite rules allowing

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    Nailed it. NATting on the WAN interface is enabled by default.  Switch NAT off (and remember to apply the changes because I did try switching NAT of earlier, but hadn't realised I hadn't applied it) God, I've spent ages trying to figure out why that was!
  • FTP problems

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    G
    Thanks for that- very helpful While i got you here, quick question - is there any way to we can get Nagios to monitor pfSense? I've looked around but the SNMP stuff seems mostly performance & stats related Thanks
  • Problem with log viewer

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    R
    I'd like to add that upgrading to 1.2 RC-3 has fixed all the log viewer issues I was previously having.  Six boxes fixed and counting…... :)
  • Hosts behind Transparent Bridge are displayed with Bridge IP as source IP

    Locked
    24
    0 Votes
    24 Posts
    22k Views
    C
    hi all! thanks to this post i also managed to get things working, but something i am still wondering about: i am loosing 2 of my official ip's on the pfsense machine. does this have to be this way or am i just having a configuration black out, but when i use private ip's on the machine nothing is going thru. best regards CC
  • Schedules breaks captive portal?

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    H
    Ah, nice to know.
  • Access webgui from outside (public ip)?

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    S
    yes, this always worked; I never tryied ssh the wan because it was behind an adsl modem; now I'm using a frame relay circuit and do not have anything between me and internet.
  • Filtering Bridge to OPT1: Non-primary IP addresses invisible to pfSense

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J
    @cmb: You can use as many IP's as you want on your OPT1 hosts, I've had deployments exactly as you describe and they work fine. You do not want it as a VIP since that IP is directly assigned on a system. That will likely break it, take that out. What do you mean by "totally ignored"? What are you trying to do that doesn't work? The VIP was only temporary in an attempt to make it work. Forget I ever mentioned it. Quite simply, I have no access whatsoever from the WAN to those IP addresses on the (Filtered Bridge) OPT1 interface that are not the primary IP address on the host's Ethernet interface. Rules to the primary IP work perfectly; no rules to additional IPs (pass or deny, port or any) have any effect whatsoever, nor is there any corresponding entry in the log. It's as if the IP addresses were totally invisible to pfS.
  • File of pf rules

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    W
    /tmp/rules.debug
  • Question about IP forwarding SMTP and using SPAMD

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC
    Embedded is designed for installing onto solid state memory (compact flash etc).  There used to be a good primer, but it seems to be gone :(
  • High load cable network

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C
    As long as you're using new server class hardware you'll be fine at those numbers.
  • Blocking with ipfilter.dat

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    GruensFroeschliG
    I dont think so. pfSense loads the xml at startup and after that runs from RAM. it only access the "slow" storage when you change something in the configuration. (I think you would need REALLY REALLY many aliases to slow pfSense down)
  • Allow program based on UUID or executable name

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F
    Thanks for the quick help.  :)
  • Downloading broken. Troubleshoot or Reinstall?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    dotdashD
    This should work on a stock setup. It sounds like you may be hosting ftp servers, which will add to the complexity. Try the standard ftp troubleshooting steps and see if that helps: http://devwiki.pfsense.org/FTPTroubleShooting
  • Blocking orkut

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    G
    It works with OpenDNS. thanks cdsu.
  • No connection LAN -> DMZ after some time

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    I
    Nothing is working, not even ping LAN -> DMZ. WAN -> DMZ is working. So i should upgrade you think? I'm unsure which package to use from ftp://reflection.ncsa.uiuc.edu/pub/pfSense/updates :-) This one using the WEB Gui Upgrade function? pfSense-Full-And-Embedded-Update-1.2-BETA-2.tgz? Never upgraded before… icanton
  • Disable routing between VLANs

    Locked
    17
    0 Votes
    17 Posts
    12k Views
    M
    That's really good to know.  I'm almost positive I was a victim of that very scenario.  Thanks for the tip.
  • Some help with a firewall rule

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F
    Great.  Looks like I got the rules correct.  Thank you!
  • Import an alias list?

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    F
    Thanks for the replies.  I did some digging and I do see that the config.xml file has the alias lists.  I see that the address section is pretty straight forward, but do I need to put information in the corresponding <detail>section? Since this information would be right in the config.xml file, I'm a bit concerned about putting in too many aliases for fear this will slow down bootup and general operation of my pfSense box.  The list I might want to import may have hundreds or thousands of IPs.  Would such a large alias list negatively impact the performance of pfSense?</detail>
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.