• PPPoE Server

    Locked
    13
    0 Votes
    13 Posts
    9k Views
    F

    dah d coba d cross terus smentara ga d pasang dl k modem adsl

    test remote pfsense aja d web lambat skali sampai drop kl lg
    mulai buka service apalagi kl mw nge-save settingan.
    ping dari 200ms, 2000ms, 3000ms sampai RTO.

    apa ethernetnya yg bermasalah coba tuker ethernet onboard jd
    lan dan begitu jg sbaliknya yg ethernet pci merk intel mash sama.

    terima kasih

  • URGENT –- Network kena virus Microsoft-ds

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    K

    Coba check port apa aka yang di serang dan dari mna serangan tersebut berasal.. setelah keteu block degan menggunakan firewall rule :D

  • [help] pfsense ku bermasalah dengan Yahoo Msgr

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    K

    untuk topologi udah bener.. apakah anda menggunakan squid / mengaktifkan squid :D
    kalau iya coba maukan port yahoo di Squid.comf anda :D

    kambeeng

  • Firewall

    Locked
    10
    0 Votes
    10 Posts
    5k Views
    G

    firewall itu kalo dalam bahasa jawa artinya tembok geni  ::)

  • PERTAMAX

    Locked
    16
    0 Votes
    16 Posts
    7k Views
    M

    Good Lunk buat om kambeeng… ;D

  • Step By Step Buat Web Server behind pfsense

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    1

    @bfsense:

    @111ichael:

    @bfsense:

    Udah omz… kalo di forward
    tapi webserver diakses dari luar lelet banget :D

    sebagai contoh :
    http://arie.smanda-bdl.sch.id <<== cuma index to' ( lumayan cepat )
    http://lms.smanda-bdl.sch.id <<== nah ini yang bermasalah..

    padaha keduanya berada dalam 1 server omz...
    mohon pencerahannya :D

    Notice :
    Mudah mudahan ga mati lampu ato dimatiin listriknya sama yang jaga sekalohannya :D

    Bandwidth Link Upload nya brapa bro?

    pake speedy bro,
    Untuk set upload bw di speedy ane lom paham

    Speedy yang multi speed yah… ?? klo mau buat web server, dll bagusnya link uploadnya 512kbps spy akses ke web server lancar... apalagi klo speedy link uploadnya kecil... klo buka yang .html lumayan cepat... tapi klo sudah berbasis php apalgi yg CMS... wah bisa berabe....

  • Billing hotspot dengan pfsense

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    A

    Coba di pfsense 2.0 beta,  di 1.2.3 belum support

  • [ASK] bandwith shaper per IP

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    A

    Kalau per IP itu BW-bya sama semua tinggal dari captive portal. Kalau beda2 ga bisa …

  • Cleaning Squid Cache

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    G

    delete cache,

    sarat : services squid di stop, bisa lewat webgui, tunggu 1 menitan setelah stop, br delete
    rm -rf /directory-cache/*
    squid -z

    kemudian start lagi services squid nya

  • [tanya] Tool Remote GUI

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    G

    makasih om atas infonya,,
    tetep menuntut ilmu dech disini :D

  • (tanya) memanfaatkan 2 isp dalam 1 jaringan

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    O

    untuk solusi nya baca postingan saya di page 2 dengan judul: untuk yang belum berhasil setting load balance

    disana sudah lengkap saya terangkan.trims

  • Package - Squidguard

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    D

    Kalau saya lebih suka menggunakan DNS Filtering, saya pakai DNSnya Nawala project.
    Alasan :

    Dari dulu belum pernah sukses configure squidguard di pfsense (bener bener sudah males, mungkin coba lagi ah…) Download shalalist yang kadang sering terputus di tengah jalan (ada yang punya mirror shalalist di indo/iix?)

    Solusi jika user mutusin pake dns lain, saya pakai rules di LAN untuk hanya mempermit Server di LAN saja untuk akses DNS (port 53) ke DNS server list yang saya bikin.

    ![dns block.JPG](/public/imported_attachments/1/dns block.JPG)
    ![dns block.JPG_thumb](/public/imported_attachments/1/dns block.JPG_thumb)

  • Cara blok aplikasi ultra surf

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    1

    klo squidnya transparent gimana cara ngaturnya??

  • 0 Votes
    2 Posts
    3k Views
    G

    @bfsense:

    mohon pencerahanya….
    kok ane tak bisa download paket ya..
    pesen errornya ini
    Unable to communicate to pfSense.com. Please check DNS, default gateway, etc.
    kalo liat di interface dahbener semua :(

    mohon pencerahan dari sob semua

    itu ada kesalahan di DNs chek kembali seting awal pfsense-nya….

  • PANDUAN TS DENGAN ALTQ

    Locked
    10
    0 Votes
    10 Posts
    9k Views
    G

    @kambeeng:

    Maaf bro lom sempat ana terjemaahkan  ;D semoga bermanfaat

    Notes on HFSC and its syntax within PF+ALTQ

    * realtime

    1. method: guaranteed rate
       2. designed for traffic which has precise latency or throughput requirements
       3. all realtime values take from total of root queue. (no inhereting from parent queues)
       4. maximum value is 75% of total bandwidth in root queue

    * linkshare

    1. method: best-effort dequeuing (inactive if there are no queued packets waiting)
       2. works with the bandwidth left over after realtime rates have been met.
       3. all linkshare values take from total of parent queue
       4. maximum bandwidth is 100%

    * bandwidth

    1.
       2. pf-specific variable, redundant for linkshare
       3. recommend matching this value to your linkshare value
       4. if you use this value but omit linkshare, it might use it as the linkshare value (I have not tested this)
       5. if you omit this value PF will complain of syntax errors

    ( explaination of this redundancy is quoted below from the mailing list)

    "q: Who needs two config parameters to control one variable"?

    "a: HFSC has 2 distinct bandwidth parameters; one for the realtime scheduling and the other for the linksharing scheduling. So, the bandwidth parameter is redundant but the current implementation is less surprising for those who don't understand hfsc. (I agree that it's confusing for those who knows hfsc, though.)"

    * qlimit

    1. the amount of packets that will be queued before PF begins to drop packets.
       2. default is 50
       3. recommend higher values for traffic in which reliability is more important than delay
       4. for p2p traffic, best results are achieved through trial and error tweaking of this value. You want packets to drop when other queues are competing bandwidth, as this allows for quicker response for the non-p2p queues, but do not want to drop packets when this queue is the only bandwidth consumer.

    * priority

    1. queues with a higher priority are preferred in the case of overload. (ie: this affects the order in which packets are dequeued, when packets are awaiting dequeue)

    Recommedations

    * realtime

    1. use this to specify the minimum bandwidth a queue should be guaranteed in a worst case scenario in order to function reasonably.

    * linkshare

    1. use this to specify the amount of bandwidth a queue will receive when attempting to dequeue packets. (I believe this is relative to what bandwidth is available)

    * upperlimit

    1. use this to specify that maximum bandwidth a queue will receive. It will never go beyond this.

    (note: upperlimit is not part of the original HFSC and I do not recommend using it except for your root queue)
    Notes

    * Assignments of linkshare and realtime are cumulative. Any traffic which exceeds the assignedrealtime threshhold will be dequeued using the assigned linkshare values.

    Tips/Ideas

    * Assigning a zero linkshare value

    1. You can assign a linkshare of 0Kb and still assign realtime value.
       2. If traffic in queue exceeds realtime value no linkshare would be used to dequeue those backlogged packets

    * Reducing or increasing bandwidth values over time

    Realtime and Linkshare can be adjusted automaticly based on a timed delay.

    Reducing rate over time

    example: hfsc(realtime (192Kb 5000 64Kb))

    1. 192Kbit of bandwidth is guaranteed for the first 5000ms
       2. After 5000ms the throughput guarantee is dropped to 64Kbit
       3. When using this method, the first and second bandwidth value can be anything you want, keeping in mind that the first value must be higher than the second

    Increasing rate over time

    example: hfsc(realtime (0Kb 300 128Kb))

    1. 0Kbit of bandwidth guaranteed for the first 300ms
       2. After 300ms 128Kbit of bandwidth is provided
       3. When using this method, the first value must be 0.

    Examples

    1. I like to assign an upperlimit to match the bandwidth/linkshare value.
       2. This ensures hfsc is receiving exactly as much bandwidth as you are telling it to work with.

    altq on $ext_if bandwidth 1216Kb hfsc(linkshare 1216Kb upperlimit 1216Kb) queue { o_def, o_intr, o_crit }

    1. Here i've given 640Kb of linkshare to the o_def queue.
       2. No traffic is being assigned to this queue, but child queues under it will take from this value.
       3. Priority is lower than the other queues because this traffic is not critical.

    queue o_def bandwidth 640Kb priority 7 hfsc(linkshare 640Kb) { o_brst, o_other, o_tput }

    1. Here i've given 32Kb of realtime, to ensure a smooth flow at low speed.
       2. I've also given 128Kb of linkshare, so that any queues packets can be dequeued quickly.

    queue o_other bandwidth 128Kb qlimit 50 hfsc(realtime 32Kb linkshare 128Kb default)

    1. Same as above.

    queue o_brst  bandwidth 128Kb qlimit 50 hfsc(realtime 32Kb linkshare 128Kb)

    1. Here i've given 384Kb of linkshare to distribute between the two child queues.
       2. No realtime is given here because bulk traffic is the least important of all.
       3. (ie: p2p applications and file transfers. traffic which is know to cause the slowdowns you wanted to use ALTQ for in the first place).

    queue o_tput  bandwidth 384Kb qlimit 30 hfsc(linkshare 384Kb) { o_tp1, o_tp2 }

    1. Here I assign two subqueues for bulk traffic.
       2. Each one is given 192Kb of linkshare.
       3. If bulk in each of these queues is fighting over bandwidth, they will both get 50% of the total available to them.

    queue o_tp1 bandwidth 192Kb qlimit 30 hfsc(linkshare 192Kb)                                               
    queue o_tp2 bandwidth 192Kb qlimit 30 hfsc(linkshare 192Kb)

    1. Here i've given 384Kb of linkshare to the o_intr queue.
       2. No traffic is being assigned to this queue, but child queues under it will take from this value
       3. Priority is higher than o_def because this traffic require low delays and steady throughput (games, ssh, im, vpn, etc).

    queue o_intr bandwidth 384Kb priority 8 hfsc(linkshare 384Kb) { o_gme, o_dly, o_vpn }

    1. Here I give realtime of 256Kb and linkshare of 128Kb.
       2. This ensures my gaming queue receives a guaranteed rate of 256Kbit.
       3. The linkshare value is to dequeue anything which exceeds the realtime value.

    queue o_gme bandwidth 128Kb qlimit 50 hfsc(realtime 256Kb  linkshare 128Kb)

    1. Essentialy the same as above but different values.

    queue o_dly bandwidth 128Kb qlimit 100 hfsc(realtime 192Kb linkshare 128Kb)

    1. Essentialy the same as above but different values.

    queue o_vpn bandwidth 128Kb qlimit 150 hfsc(realtime 192Kb linkshare 128Kb)

    1. Here i've given 192Kb of linkshare to the o_crit queue.
       2. No traffic is being assigned to this queue, but child queues under it will take from this value
       3. Priority is higher than o_def and o_intr because this traffic requires low delays and steady throughput. (dns, icmp, voip, etc)

    queue o_crit bandwidth 192Kb priority 9 hfsc(linkshare 192Kb) { o_voip, o_ctl, o_ack }

    1. Here I've given a guarantee of 120Kb with my realtime value.
       2. Notice I've given 0kb of linkshare because this traffic will never exceed 120Kbit/s and there is no concern about dequeuing because of this.
       3. I also use a qlimit of 500 to ensure no packets are ever dropped in this queue.

    queue o_voip bandwidth 0Kb qlimit 500 hfsc(realtime 120Kb)

    1. Here i've given a realtime of 48Kb to ensure smooth flow of dns and icmp traffic.
       2. I've given 64Kb of linkshare to ensure any overflow is dequeued quickly.

    queue o_ctl  bandwidth 64Kb qlimit 150 hfsc(realtime 48Kb linkshare 64Kb)

    1. Here i've given a realtime of 92Kb to ensure my ack packets are always flowing quickly.
       2. I have allocated 128Kb of linkshare to ensure any overflow, no mater how unlikely, is dequeued quickly.

    queue o_ack  bandwidth 128Kb qlimit 500 hfsc(realtime 92Kb    linkshare 128Kb)

    ?

    Kalo kita menggunakankan internet sebagai fokus utamnya, maka setting-an diatas.. akan mengakibatkan overlimit di koneksi internya.. Oleh karena itu perlu disesuaikan lagi dengan fokus utama company yg kita jalankan. :)

  • Ternyata masih ada yang bermain dengan squid-2.4.STABLE1 heheh

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    G

    kalo bendwitnya sih antara  3-6Mbs dengan client 600-an

    utk ideal cache HIT segitu ya kurang utk kelayakan brosing client

    nemu link itu asalnya saya kaget cachemgr.cgi saya ke crawl oleh indexnya google,
    akhirnya taruh file norobot di server squid, baru tidak di index lagi oleh google
    coba

    nah link itu salah satu yang ke crawl oleh index nya google

    enaknya menggunakan cachemgr, mrtg dan calamaris, kita bisa tahu performance sebenarnya tanpa harus concole ke server :D

  • PfSense update Squid 2.7.7 [official]

    Locked
    26
    0 Votes
    26 Posts
    21k Views
    G

    @ipoelnet:

    Perasaan Q g' penah nemuin hal spt ini?

    2009/11/30 00:47:08|         0 Objects expired.
    2009/11/30 00:47:08|         
    2009/11/30 00:47:08|         5846 Duplicate URLs purged.

    kok tiba-tiba muncul ini OM, pengaruh yach jika keluar itu?? apa ada yang perlu di tambahkan.

    65800 Objects cancelled
    ada duakemungkinana
    1. client mengabort/cancle browsing karena emang pengen di abbort
    2. client mengabort karena terjadi bottleneck, bisa jadi dari perfomance squidnya / performance jaringan
    3. solusi : cek configurasi squidnya, bottlnecknya di config squid (cache_dir, spindel hardisk, ram, dns dll) / kualitas jaringan yang penuh dengan broadcast virus

    5846 Duplicate URLs purged.

    proses ini akan mengclearkan cache swap dari duplikasi url yang sudah di cache, tapi kok banyak banget ya, kalo saya amati punya saya sendiri paling banyak cuma 20

  • Membelokkan rapidshare ke salah satu WAN address pada multi wan

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    D

    Di kantor, situs2 download/filehosting-an saya atur supaya lewat ISP yang paling lambat ( Ada 3 ISP) . Step2 yang saya ambil kalau mau membuat rules:
    1. Cari IP adresss ( misal rapidshare.com) dari website www.robtex.com. Biasanya yang saya masukkan alias adalah satu network block-nya
    2. Bikin ALIAS, supaya lebih terorganisir database IP-nya & bisa di pakai ulang di rules lain.
    3. Bikin Rules di LAN persis seperti yang dicontohkan bung Grage. Letakkan rules di atas rules DMZ & Load Balancing, karena pfsense memproses filternya dari atas ke bawah.
    Semoga membantu

  • Squid

    Locked
    85
    0 Votes
    85 Posts
    61k Views
    I

    Hasil dari: squidclient mgr:delay

    HTTP/1.0 200 OK
    Server: Lusca/LUSCA_HEAD
    Date: Thu, 26 Nov 2009 01:46:15 GMT
    Content-Type: text/plain
    Expires: Thu, 26 Nov 2009 01:46:15 GMT
    X-Cache: MISS from xx.xx.xx
    Via: 1.0 proxy.pfsense:80 (Lusca/LUSCA_HEAD)
    Connection: close

    Delay pools configured: 2

    Pool: 1
    Class: 2

    Aggregate:
    Disabled.

    Individual:
    Disabled.

    Pool: 2
    Class: 2

    Aggregate:
    Disabled.

    Individual:
    Max: 10000
    Rate: 10000
    Current: 12:-57987 4:10000

    Memory Used: 6792 bytes

    Apa yg menyebabkan hingga delay pool trsebut mendapat nilai min(-)….???

    itu menngunalan berapa pools?????
    kalau memang satu g' dipakai buang aja..

  • Newbie Ask: Gimana cara block website tertentu di pfsense

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    I

    tambahkan di /usr/local/pkg/squid.inc letakkan bawah sendiri sebelum http_access deny all
    atau search aja
    $conf .= "http_access deny all\n";

    acl ipuser src /var/squid/acl/ipuser.acl
    acl urlblock url_regex -i /var/squid/acl/urlblock.acl
    http_access deny urlblock ipuser

    isi /var/squid/acl/ipuser.acl
    192.xxx.xxx.xxx
    192.xxx.xxx.xxx

    isi /var/squid/acl/urlblock.acl
    facebook.com
    atau_kata_kunci

    atau jika pakai range dalam acl dan satuan url

    acl ipuser src 192.xxx.xxx.xxx-192.xxx.xxx.xxx/255.255.255.0
    acl urlblock url_regex -i facebook.com
    acl urlblock url_regex -i friendster.com

    http_access deny urlblock ipuser

    silahkan dicoba.

    lengkapnya contoh 1:

    $conf .= "acl ipuser src /var/squid/acl/ipuser.acl\n";
    $conf .= "acl urlblock url_regex -i /var/squid/acl/urlblock.acl\n";
    $conf .= "http_access deny urlblock ipuser\n";

    $conf .= "http_access deny all\n";

    lengkapnya contoh 2:

    $conf .= "acl ipuser src 192.xxx.xxx.xxx-192.xxx.xxx.xxx/255.255.255.0\n";
    $conf .= "acl urlblock url_regex -i facebook.com\n";
    $conf .= "acl urlblock url_regex -i friendster.com\n";
    $conf .= "http_access deny urlblock ipuser\n";

    $conf .= "http_access deny all\n";

    lebih enak pakai yang no 1. supaya squid.inc g' panjang.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.