• Block lots of ip ranges

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J

    at interfaes/wan turn on

    Block bogon networks
    When set, this option blocks traffic from IP addresses that are reserved (but not RFC 1918) or not yet assigned by IANA.
    Bogons are prefixes that should never appear in the Internet routing table, and obviously should not appear as the source address in any packets you receive.

  • PROBLEMS WITH THE PORT 443

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    It's open from LAN by default and blocked on any other interface like WAN, OPT1,… If you want to simply open it up to the firewall at WAN for example create a rule at firewall>rules,WAN. If you want to forward it to an host on one of your internal subnets create a portforward at firewall>nat, portforward and let the firewall rule be autocreated (the box for this is enabled by default).

  • L7-filter kind app

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    S

    I know just a bit about layer-7 shaping abilities, and for know pfsense layer-4 scheme is working for me; but I'm sure that layer-7 in pfsense would bring the firewall into a new land where the most modern p2p programs change their ports to scape trafic shaping or the most commons firewalls that block well known p2p ports…

    But as I said, pfSense scheme is doing the job for me now, it saves more than 30% of my bandwitch that are being used by p2p programs in users boxes... it's amazing!

  • Wierd bug: MULTIPLE:SINGLE?

    Locked
    13
    0 Votes
    13 Posts
    6k Views
    S

    Already fixed in cvs.  Thanks.

  • Manualy edit pf

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    S

    Your changes will get overwritten each time.  Seriously, you really need to use something else if you want to have custom pf rules.  Sorry!

  • BUG? Source ports range as alias

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    T

    Ok, sad to hear it but I have to live with it.
    Cheers

  • HEEELp ping allow other deny

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D

    lowcypl,

    your config seems to be okay. But beside that it is kinda hard to understand …

    what you were trying to accomplish regarding your setup?

    what is/was your issue (i.e. what does not work)?

    Regards
    Daniel S. Haischt

  • Transparent firewall & DHCP

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    S

    1.0-RC3 is now out, you really should update.

  • Enabling Filtering Bridge

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    S

    Show a screen shot of your custom rules and then run cat /tmp/rules.debug | grep USER from a shell/command prompt.

  • Firewall Reload Problem Bridge

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    W

    sorry i didn't get round to answer yesterday. I changed the setup after having these annoying problems with the bridge i was in a hurry had a customer waiting for the firewall. When i have some time i will do some testing with the bridge setup and post my results.

  • Virtual DMZ

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Dns traffic blocked heavy load

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    S

    If you are running polling then the share of userland vs kerneland needs to be altered.

    On a really busy dns server that would mean that the split between kernel workload and userland workload needs to be about 50/50.

    I cannot recall what our defaults are but I would suggest as hoba did to not run polling unless you spend quite a bit of time "tunning" it for your workload.

  • Filtering Bridge with Spanning Tree problem?

    Locked
    7
    0 Votes
    7 Posts
    11k Views
    H

    I'll retest bridge this evening with latest snapshot but I bet it's something else (tested it not too long ago already).

  • Forward based on hostname

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    J

    Thank you for the quick reply.

    I think I will just install Pound (http://www.apsis.ch/pound/) at a central point and forward all web traffic to it for redistribution based on requested URL.

    Again - thank you for the quick reply :-)

    If I ever learn how to create packages I will attempt a pound package.

    Cheers,

    jk

  • Proxy server not working

    Locked
    11
    0 Votes
    11 Posts
    7k Views
    P

    hmmm I found the problem … It seemed to be dns.
    Sorry guys and thanks for the help :-[

    Thanks

  • SMTP Rules ?

    Locked
    12
    0 Votes
    12 Posts
    8k Views
    J

    :D  find the solution

    My modem is not ugly

    My provider is ugly ;D  (tele2)

    it refuses all connection to smtp server except for its smtp server (smtp.tele2.fr)  .

    Sorry for the problem.

    thanks all.

  • Difference between LAN and OPTx interfaces..?

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    H

    Firewallrules are first match wins from top down. You can't pass anything below that you already have blocked on the top. Just use your brain to evaluate your ruleset. Finally, if something is still blocked visit status>systemlogs. firewall and click on the small block icon in front of an undesired block to see what rule triggered the block.

  • Windows Vista with pfSense

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    B

    After some more digging, a lot more digging. It seems that the problem is related to our fiber provider. Sorry if i implied that there was anything wrong with pfSense, I've been using it for months now in our school system and love it.

    Brian

  • Firewall optimization=aggressive work with games/xbox?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    Z

    Somethings that you could do to speedup the gameplay.

    1. Make sure nothing is running on half-duplex
    2. If your using a hub, get a switch (gig is overkill for xbox)
    3. Adjust your MTU size
    4. start running ping/traceroute tests and see if there's anything messed up with your internet connection

    As fire as the firewall optimization goes unless your trying to run a bit torrent client while playing xbox adjusting the settingsd from normal to agressive probably won't show much of an improvement. Try it though, if you can run with aggressive and nothing starts acting up the better as the firewall needs to keep track of less connections in this mode.

  • Packet Lost / Latency

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    Z

    as hoba said, need more info. If you are running the traffic shaper make sure you set VOIP to the highest priority and make sure the rest is a lower priority.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.