Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NGNIX Errors?

    Scheduled Pinned Locked Moved General pfSense Questions
    28 Posts 3 Posters 3.1k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jsmiddleton4 @stephenw10
      last edited by

      @stephenw10

      I don't recall doing so. I'll hit that document now.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        The source in those outbound NAT rules should be internal private IPs. There's no real need to obscure those.

        J 1 Reply Last reply Reply Quote 1
        • J Offline
          jsmiddleton4 @stephenw10
          last edited by jsmiddleton4

          @stephenw10

          I did not do anything with System Tunables when making the bridge. Can do so now, booting might have to wait. Wife watching Thursday Night Football via streaming on Fubo.TV.......

          These are the current entries:

          net.link.bridge.pfil_onlyip Only pass IP packets when pfil is enabled 0
          net.link.bridge.pfil_member Packet filter on the member interface 1
          net.link.bridge.pfil_bridge Packet filter on the bridge interface 0

          "At least one of these must be set to 1"

          One of them is set to 1 already????

          All of them to "1"?

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            It depends where you want to filter but usually in that sort of setup where you're effectively wanting to use the NICs as switch ports you would set filtering to the bridge interface and not the member interfaces. You can filter in both places if you need to. But wherever you have filtering enabled you will need appropriate firewall rules to pass the traffic.

            Steve

            J 1 Reply Last reply Reply Quote 1
            • J Offline
              jsmiddleton4 @stephenw10
              last edited by jsmiddleton4

              @stephenw10

              I understand that A+B=C. The Firewall Rules I figured out are okay, even if I change Tunables, the Bridge would need a Firewall rule.

              What do I set the Tunables to? All of them to 1?

              The document says at least one of them. I already have one of them set to 1.

              Do I change the member filter that is “1” to “0” and the ones that are “0” to “1”?

              Is that what is meant by at least one of them has to be “1”? Whichever you set to “1”, set the other to “0”?

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                You should leave net.link.bridge.pfil_onlyip set to 0.

                Then either net.link.bridge.pfil_member or net.link.bridge.pfil_bridge (or both) should be set to 1 depending on where you want to filter traffic.

                J 2 Replies Last reply Reply Quote 1
                • J Offline
                  jsmiddleton4 @stephenw10
                  last edited by

                  @stephenw10

                  I tested and answered my own question as well.

                  Member one set to 1 still need my NAT Rules.

                  It set to 0 and the bridge one set to 1, don’t need them, just need the Bridge/LAN NAT rule.

                  I figured the IP one leave at 0. If to 1 guessed it would cut off TCP/UDP, etc.

                  Not to lose track of where this started.

                  No more NGNIX error messages.

                  Getting a bunch of WAN blocked in Firewall Log now.

                  stephenw10S 1 Reply Last reply Reply Quote 1
                  • J Offline
                    jsmiddleton4 @stephenw10
                    last edited by

                    @stephenw10
                    Thanks for all your help.

                    Merry Christmas.

                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      programmer131113 @jsmiddleton4
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator @jsmiddleton4
                        last edited by

                        @jsmiddleton4 said in NGNIX Errors?:

                        Member one set to 1 still need my NAT Rules.
                        It set to 0 and the bridge one set to 1, don’t need them, just need the Bridge/LAN NAT rule.

                        I think you mean firewall rules here. 😉 The NAT rules should not change.

                        @jsmiddleton4 said in NGNIX Errors?:

                        I figured the IP one leave at 0. If to 1 guessed it would cut off TCP/UDP, etc.

                        Yeah leave that as 0. It wouldn't block TCP/UDP, because that runs over IP, but it would block netbios, appletalk etc, non-IP protocols. You are probably not using any but if you are that will be blocked and troubleshooting it is..... challenging!

                        Steve

                        J 1 Reply Last reply Reply Quote 1
                        • J Offline
                          jsmiddleton4 @stephenw10
                          last edited by jsmiddleton4

                          @stephenw10

                          Yes Firewall Rules.

                          I don’t think my AppleTV’s, iPAD or iPHONES use Apple Talk. Might.

                          Now on to other questions. Thanks again. Cleaned up some of the network routing and was able to eliminate both Netgear switches in two person office.

                          Added UPS’s to each work station and to the “Internet” station, the router, modem, wireless AP.

                          Power rarely goes out here but it does once and awhile.

                          Employer gets a tad annoyed when everyone disappears.

                          Thanks again. NOW my Firewall is doing what its supposed to do for WAN side. Lots of blocking going on.

                          I've installed and configured the UPS package. Need to figure it out though.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.