Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NGNIX Errors?

    Scheduled Pinned Locked Moved General pfSense Questions
    28 Posts 3 Posters 3.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      Ok, did you set the bridge sysctls to moved filtering the bridge interface?
      https://docs.netgate.com/pfsense/en/latest/bridges/firewall.html#bridging-and-firewalling

      Did you reboot after doing that?

      With those set you should only need rules on the bridge interface, LAN here. Otherwise, by default, the bridge filters on the member interfaces so you would need pass rules om all of them.

      Steve

      J 1 Reply Last reply Reply Quote 1
      • J Offline
        jsmiddleton4 @stephenw10
        last edited by

        @stephenw10

        I don't recall doing so. I'll hit that document now.

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          The source in those outbound NAT rules should be internal private IPs. There's no real need to obscure those.

          J 1 Reply Last reply Reply Quote 1
          • J Offline
            jsmiddleton4 @stephenw10
            last edited by jsmiddleton4

            @stephenw10

            I did not do anything with System Tunables when making the bridge. Can do so now, booting might have to wait. Wife watching Thursday Night Football via streaming on Fubo.TV.......

            These are the current entries:

            net.link.bridge.pfil_onlyip Only pass IP packets when pfil is enabled 0
            net.link.bridge.pfil_member Packet filter on the member interface 1
            net.link.bridge.pfil_bridge Packet filter on the bridge interface 0

            "At least one of these must be set to 1"

            One of them is set to 1 already????

            All of them to "1"?

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              It depends where you want to filter but usually in that sort of setup where you're effectively wanting to use the NICs as switch ports you would set filtering to the bridge interface and not the member interfaces. You can filter in both places if you need to. But wherever you have filtering enabled you will need appropriate firewall rules to pass the traffic.

              Steve

              J 1 Reply Last reply Reply Quote 1
              • J Offline
                jsmiddleton4 @stephenw10
                last edited by jsmiddleton4

                @stephenw10

                I understand that A+B=C. The Firewall Rules I figured out are okay, even if I change Tunables, the Bridge would need a Firewall rule.

                What do I set the Tunables to? All of them to 1?

                The document says at least one of them. I already have one of them set to 1.

                Do I change the member filter that is “1” to “0” and the ones that are “0” to “1”?

                Is that what is meant by at least one of them has to be “1”? Whichever you set to “1”, set the other to “0”?

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  You should leave net.link.bridge.pfil_onlyip set to 0.

                  Then either net.link.bridge.pfil_member or net.link.bridge.pfil_bridge (or both) should be set to 1 depending on where you want to filter traffic.

                  J 2 Replies Last reply Reply Quote 1
                  • J Offline
                    jsmiddleton4 @stephenw10
                    last edited by

                    @stephenw10

                    I tested and answered my own question as well.

                    Member one set to 1 still need my NAT Rules.

                    It set to 0 and the bridge one set to 1, don’t need them, just need the Bridge/LAN NAT rule.

                    I figured the IP one leave at 0. If to 1 guessed it would cut off TCP/UDP, etc.

                    Not to lose track of where this started.

                    No more NGNIX error messages.

                    Getting a bunch of WAN blocked in Firewall Log now.

                    stephenw10S 1 Reply Last reply Reply Quote 1
                    • J Offline
                      jsmiddleton4 @stephenw10
                      last edited by

                      @stephenw10
                      Thanks for all your help.

                      Merry Christmas.

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        programmer131113 @jsmiddleton4
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator @jsmiddleton4
                          last edited by

                          @jsmiddleton4 said in NGNIX Errors?:

                          Member one set to 1 still need my NAT Rules.
                          It set to 0 and the bridge one set to 1, don’t need them, just need the Bridge/LAN NAT rule.

                          I think you mean firewall rules here. 😉 The NAT rules should not change.

                          @jsmiddleton4 said in NGNIX Errors?:

                          I figured the IP one leave at 0. If to 1 guessed it would cut off TCP/UDP, etc.

                          Yeah leave that as 0. It wouldn't block TCP/UDP, because that runs over IP, but it would block netbios, appletalk etc, non-IP protocols. You are probably not using any but if you are that will be blocked and troubleshooting it is..... challenging!

                          Steve

                          J 1 Reply Last reply Reply Quote 1
                          • J Offline
                            jsmiddleton4 @stephenw10
                            last edited by jsmiddleton4

                            @stephenw10

                            Yes Firewall Rules.

                            I don’t think my AppleTV’s, iPAD or iPHONES use Apple Talk. Might.

                            Now on to other questions. Thanks again. Cleaned up some of the network routing and was able to eliminate both Netgear switches in two person office.

                            Added UPS’s to each work station and to the “Internet” station, the router, modem, wireless AP.

                            Power rarely goes out here but it does once and awhile.

                            Employer gets a tad annoyed when everyone disappears.

                            Thanks again. NOW my Firewall is doing what its supposed to do for WAN side. Lots of blocking going on.

                            I've installed and configured the UPS package. Need to figure it out though.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.