• Virtual IP not working in 2.2 like it did in 2.1.5

    5
    0 Votes
    5 Posts
    1k Views
    R
    I tried it this morning and it's working from that location now. Thank you for the ideas/explanation.
  • Voip ipv4 outbound nat.

    2
    0 Votes
    2 Posts
    814 Views
    J
    Here you go…this guide should help you.... http://www.3cx.com/blog/voip-howto/pfsense-firewall/
  • DNS Forwarder as a DNS server for the firewall

    3
    0 Votes
    3 Posts
    1k Views
    T
    Thank You
  • OpenVPN description in "Interfaces: Assign network ports" missing

    2
    0 Votes
    2 Posts
    691 Views
    P
    Fix turned out to be easy. Pull request https://github.com/pfsense/pfsense/pull/1341
  • Unbound domain overrides for local DNS across site-to-site VPNs

    2
    0 Votes
    2 Posts
    5k Views
    C
    Yeah there isn't a direct equivalent for the source IP per-domain override that's in dnsmasq. Ideally that won't be an issue because #1 will work, but that isn't the case at times and fixing that can be a significant undertaking. The best alternative I've seen is #2, picking only a single interface for the outgoing interface option. I don't think there are any caveats to that. Any queries that go to an Internet destination will have that IP source NATed. The only potential issue I can think of there is if you need one domain override to use one source IP, and a diff domain override to use a diff source IP. I've never seen anyone have such a requirement so it's likely exceptionally rare. Choosing only LAN for the outbound interface should be safe in most every scenario.
  • *HEADS UP* - careful with upgrades - zf kernel load unexpected EOF

    19
    0 Votes
    19 Posts
    4k Views
    C
    @cmb: I'm not sure what the issue was, and probably won't know until we can discuss on Monday. Any further info on what the problem was?
  • Install of Open-VM-Tools fails

    3
    0 Votes
    3 Posts
    2k Views
    C
    the root of that issue is this. https://redmine.pfsense.org/issues/4019 to work around, run the following at a command prompt before installing the package. mkdir /usr/local/etc/rc.d
  • Installation ALIX APU mSATA SSD not possible

    10
    0 Votes
    10 Posts
    7k Views
    jimpJ
    The "embedded" choice error is fixed in current snapshots now. Though there are still some issues (check redmine)
  • Ipv6 will not work with my setup or provider.

    1
    0 Votes
    1 Posts
    706 Views
    No one has replied
  • IPSEC RSA error no private key found

    11
    0 Votes
    11 Posts
    13k Views
    E
    Thanks for the logs. I fixed for new snapshots the certificates will be there now.
  • Can not get ipv4 voip to work. Tried nat forwarding to no avail.

    3
    0 Votes
    3 Posts
    1k Views
    P
    I already found this link but am not able to understand correctly what is written there. I could understand the parts with "Set Conservative state table optimization" and "Disable scrub". I installed siproxd but the  configuration is way to complicated to me. And I did not understand the part about "Disable source port rewriting". What I did was giving the Phone a static dhcp lease. Then I set up udp forwarding per the directions my provider is handing out. See: http://hilfe.telekom.de/hsp/cms/content/HSP/de/3378/FAQ/theme-45859561/Telefonie/theme-45859560/Anschluss-und-Tarife/theme-45859549/Telefonieren-und-Surfen/theme-82239611/IP-basierter-Anschluss/faq-350884716 In short: UDP (out): Ports 5060, 30000-31000, 40000-41000, 3478, 3479 UDP (in): Ports 5070, 5080, 30000-31000, 40000-41000 TCP (out): Port 80, 443 I only have one phone, so port forwarding should to the job. I still have not found how i could forward port ranges, if someone told my how to do this I would be glad. Because the wan voip adresses change frequently with my provider I can not use static adressing voip server wise. Any help would be appreciated.
  • 2.2 Outgoing FTP

    5
    0 Votes
    5 Posts
    1k Views
    C
    OK. But: 230 Guest login ok, access restrictions apply. ftp> ls 500 Illegal PORT rejected (address wrong).
  • IKEv2 Modes?

    3
    0 Votes
    3 Posts
    1k Views
    3
    That's what I was thinking! Thanks!
  • Multiple default gateways

    7
    0 Votes
    7 Posts
    2k Views
    C
    It's not two v6 gateways, it's one v4 and one v6. I fixed the description so it shows correctly. For gif and GRE it should only have either a v4 or a v6 gateway depending on which is in the tunnel network, but it doesn't hurt anything having both, one is just not going to do anything.
  • How is ipv6 handled? I need pppoe plus dhcp prefix delegation.

    1
    0 Votes
    1 Posts
    807 Views
    No one has replied
  • Unbound /resolver broke

    8
    0 Votes
    8 Posts
    3k Views
    C
    The code Phil referenced was a copy/paste from dnsmasq, which uses its advanced field differently since it needs those as command line arguments, not in a conf file. The problem was your advanced options were never used prior to a few days ago, and once that was fixed, they were put in wrong. That did need to be output differently. I just pushed a fix for that. gitsync or upgrade to a snapshot on the 16th or newer and you should be in good shape.
  • I am now creating new DansGuardian and Squid3 binaries.

    50
    0 Votes
    50 Posts
    18k Views
    E
    Thanks for explaining. I remember having seen other posts regarding the issue. Squidguard is indeed working. Cheers.
  • Syntax error /etc/inc/gwlb.inc

    2
    0 Votes
    2 Posts
    996 Views
    C
    There was a note on that linked commit internally that apparently got overlooked, I just now pushed a fix. Thanks for the report
  • 2.2 Nov. 13 Snapshot NanoBSD VGA switch to RO after install crash

    1
    0 Votes
    1 Posts
    799 Views
    No one has replied
  • PfSense 2.2 with Atheros AR9285 in 802.11n mode

    6
    0 Votes
    6 Posts
    3k Views
    ?
    Here is my current setup on Riverbed  Steelead 100 with mikrotik R52hn [image: pfwifi.jpg] [image: pfwifi.jpg_thumb]
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.