• Site-to-site OpenVPN not routing (and other errors)

    Locked
    15
    0 Votes
    15 Posts
    13k Views
    M

    Hi thank you for the clarification.. I will start a new thread regarding those other questions.

  • Missing Dashboard drop down link on some pages

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    Snort installs its own copy of fbegin.inc - it should really not do this on 2.0, as it will cause all kinds of issues, including breaking the link to OpenVPN (which has an open ticket)

    I don't recall why the package maintainer chose to do that, though.

  • Openvpn status on server

    Locked
    16
    0 Votes
    16 Posts
    7k Views
    S

    ur right i ll check config.

    "peer to peer (ssl/tls)"  is 1:1 connection

    "remote access (ssl/tls)"  is 1:n connection, so u need to use remote access for 3 sites and more i think, i ll test it.

    good night.

    thx for replies

  • Dashboard Traffic Graphs

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    Each graph has a different interval for each step. Because of that, the newest step of the lower graphs may not have enough data to put on the graph for that interval.

  • Multi-WAN with Squid

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R

    CMB,

    Thank you by responses. I'll test PfSense 2 here.

    @cmb:

    @raragao:

    The pfSense 2.0 Beta 3 can now make the squid to work with multi-wan?

    Yes

    @raragao:

    Another thing, what improvements were made in the load balancing multi-WAN?

    mostly listed here.
    http://doc.pfsense.org/index.php/2.0_New_Features_and_Changes

  • [Solved] unable to connect to OPT1 ftp server from LAN

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    HI,

    i just create a NAT rule:

    If Proto Src. addr Src. ports Dest. addr              Dest. ports            NAT IP       NAT Ports Description
    LAN TCP      *      * 123.123.123.123(ext ip)      21 (FTP)         192.168.1.2 21 (FTP)      FTP

    and it works fine now.

    Is my NAT seems correct for my configuration?

    Thanks,

  • 0 Votes
    1 Posts
    2k Views
    No one has replied
  • WLAN/WiFi PCI Linksys WMP600n on pfSense 2 with FreeBSD 8.1 RC1

    Locked
    6
    0 Votes
    6 Posts
    7k Views
    C

    Should I not try to install the driver? Or it might be that it is supported in the release?

    EDIT:
    Ok, how do I install a git package on pfSense 8.1-R1? I want install this driver.
    http://repo.or.cz/w/ralink_drivers.git

  • Is a large drop count in qDefault on LAN normal?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    G

    I'm seeing the same thing. LAN interface set to 100Mb, child queue qInternet set to 22Mb (ISP speed) and dDefault with bandwidth %. Downloads come in at around 12-14Mb with shaping turned on, 22Mb with it turned off.

    I see drops also incrementing on the queues page. Where would the queue length be adjusted?

  • Openvpn - ssl/tls + user auth (ldap)

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    B

    Ok, now I understand.

  • Atheros (AR5416) wireless issues

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • OpenVPN in latest snapshots

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    @jimp:

    I haven't seen any such behavior and I've been using and working with OpenVPN a lot on 2.0. I don't think I've tried that one scenario, though.

    I'll need to know exactly how you have your server instance setup, any client-specific config entries you may have, etc.

    Rebooted the user on this one.  I was certain when I'd tested this before it had worked fine.  Ends up I inadvertantly added a duplicate secondary IP a few weeks ago between testing and final rollout that was causing the problem.

  • How to get SquidGuard 1.4.2 working on 2.0 Beta3

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    jimpJ

    pkg_delete squid* will match squidguard. Just don't use the *, use the full package name as shown in pkg_info.

    If that doesn't work, I don't know. I wouldn't recommend using lusca, as that changes your package repository to pull from their repo and not the official package repo, so there is no telling what you are getting.

  • BLOCK WAN to OPT1 using Schedule but ALWAYS ALLOW Captive Portal on OPT1?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    A couple things:

    1. There is a firewall rule which always exists, and which you do not see in the UI, that allows all packets that are part of an existing state.
    2. User-created firewall rules operate only on connections entering an interface, never leaving.

    So, when a client on OPT1 is able to use the internet, it is because you have created a firewall rule on OPT1 allowing packets to pass from the client to the internet. Rule 1 above takes care of the return packets.

    If you want to use the firewall to block OPT1 clients access to the internet, then you must do it using block rules on OPT1. I expect you should be able to create a rule explicitly allowing clients on OPT1 to access the address of the CP server (i.e., pfsense) and place it at the top. Below that, create your rule to pass packets from OPT1 hosts to anywhere (or !LAN, as the case may be), and use the scheduler to activate and deactivate this rule according to your desired schedule.

    Note that if you disable your pass rule at 15h00 on a schedule, any states existing at that time will continue to pass. You can use CP timeouts to kill these.

  • Squid Traffic mgmt/Throttle binary files

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    jimpJ

    Not sure offhand, but you might be able to pull it off with squidguard if not in squid alone, or just put your line in the custom options box if it will work there.

  • Correct webgui SSL cert management techniques

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    1.2.x and before, like m0n0wall, don't generate certs, they use a single hard coded one.

    Not sure offhand what you're seeing there.

  • OpenVPN

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C

    You already have a server certificate, just add that to the client configuration. That'll be added to the client export before release.

  • UNABLE TO COMMUNICATE WITH chudy.0fees.net

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    jimpJ

    That is not a standard package server. You may have installed a package from someone else (like Lusca) which modified your pfSense install to get your packages from them only, which can be dangerous.

  • Panic=page fault

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    Is the error always on "rl0"? (See the current process)

    You might have a flaky network card, or some other faulty hardware.

  • Setting link speed on mlppp member interfaces

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.