• GUI problem using several (more than 60) vlans

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    Y

    Our thoughts were to create one tab for VLANs. Once you click that tab there will be a dropdown box to select which VLAN you want to work with.

  • Frustrated: DMZ has no access to Internet

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T

    Setting up Virtual IP addresses for my public IP's seems to be the answer!

    Thanks for the help.

  • Pf / network traffic scanning

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    C

    Yeah, UTM (Unified Threat Management) is the marketing term. Though you could just as easily call pfsense a UTM device, it has firewall, VPN, IDS/IPS, and some content filtering, and we're working to fill more of the check boxes that make a UTM device. Not because we think it's great (I still like to split out things a lot more than any UTM would with everything turned on), but because that's what people want.

  • TFTP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FYI: Error msg when applying ICMPv6 block rule with GUI

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    S

    @cmb:

    It's probably a bug, and probably still a bug in 1.2b1. We removed IPv6 from the kernel entirely, this definitely isn't going to work (no need to allow/block IPv6 traffic, pfsense is going to completely ignore it all).

    Funny, my dutch linux/bsd magazine stated that their are real plans to push ipv6 into real action. :)
    I am aware that ipsense blocks by default -well done-, but it doesn't hurd to add a rule explicitly denying some traffic. (and by this trowing up a 2nd barrier ;D).

  • Help to config a dmz

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    P

    http://doc.m0n0.ch/handbook/examples.html

  • Block all ports leave only the "basic needs" Because of P2P

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R

    Thanks what i was thinking.
    I having a bit of problem enabling msn video conference ports i looked around and found they are dinamyc and Microsoft recomends a huge port range.

    The actual Real-time Transport Protocol (RTP) streams are sent using dynamically allocated UDP ports in the range of 5004–65535. Without a way to open these UDP ports on any firewall in the path dynamically, the streams fail to reach their destination.

    From: http://technet.microsoft.com/en-us/library/b9bd86b1-a604-d747-b219-bb2ac5473e87.aspx#EKAA

    It was better to say leave every thing open :P

  • Auto blocking SSH - sshlockout_pf

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    B

    @Gandalf:

    I don't know about sending syslog but personaly I have http://denyhosts.sourceforge.net/ on every box I own, I don't have any BSD box (except pfSense which has the ssh port closed so I didn't need to tried it) it works great on Linux boxes, maybe you can try it on pfSense?

    I'll check it out, I see its in the FreeBSD ports tree so I'm sure it will work.

  • Timebased rules

    Locked
    31
    0 Votes
    31 Posts
    12k Views
    K

    The rebuild from scratch took care of the problem. Apparently the config.xml file didn't make it through the upgrades in the past successfully.

    Thanks for the assistance and for the developers of this great piece of software. Keep up the good work!

  • Not installing nat reflection rules. Maximum 1,000 reached.??

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    G

    @cmb:

    I would recommend using a proper split DNS infrastructure and don't use reflection. It's ugly any way it's done, but it's really ugly how we currently do it.  :)  A replacement is in the works for a future (post-1.2) release.

    But if I turn reflection off, then whatever I try rsync won't work, did I miss something??

  • Block private & bogon networks

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    belleraB

    Ok!

    Thanks, Cry

  • Raw IP traffic

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Simultaneous client connection limit

    Locked
    9
    0 Votes
    9 Posts
    7k Views
    B

    pass in quick on $lan  route-to { ( rl2 firstfailoverip ) } from any to any keep state ( max-src-nodes 5 max-src-states 5 tcp.established 60 max-src-conn-rate 5 /1, overload <virusprot>flush global  )  label "USER_RULE: adsl fail airband"

    obviously replace firstfailoverip for my gateways ip address

    and with this rule being the only pass i can get 20 connections in my download manager

    thanks</virusprot>

  • Schedule Logic too Difficult for me

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HowTo Hardening PfSense firewall?

    Locked
    14
    0 Votes
    14 Posts
    25k Views
    J

    @Snailer:

    A fourth, lets call it a 'paranoid-idiot-fool-and-newbie-high-security's-firewall-proof' checkbox,  ;D would be for me like a wet boy's dream has come true.  :P :+

    so that checkbox will remove all rules on the wan port

    same as youre virgin pfsense  ;D

  • Newbie needs help - basic firewalling

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    F

    Thanks for clearing this up.

  • Userland FTP-proxy enabled by default on opt interfaces

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • How can i block sites or ip sites?

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    C

    if you just want to block IP's, do that with firewall rules. You could create an Alias for "Bad Site IP's" or something, then use it in a firewall rule (suggest a reject, not block, rule on LAN, make sure you move it above the default rule).

  • Solid monitoring and rule problem finding

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    C

    The dynamic refresh might not work quite right just yet. I'll take a closer look at it.

  • Multiple Bridged Interfaces

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    H

    Multiinterfacebridging is not possible and won't be possible for 1.2.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.