Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Problem with configuring the Netgate 1100

    Scheduled Pinned Locked Moved General pfSense Questions
    18 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      SteveITS Galactic Empire @stephenw10
      last edited by

      Duh, I apparently misread all of OP's message. Still in vacation mode I guess.

      @Netgate1100guy
      I am way more confused now.

      Snort AND Suricata? That seems...absurd. They do the same thing.

      Outside hackers can't "get into" your computer over the Internet unless you've allowed the inbound connection and/or have weak passwords. It's far easier to get a victim to run a program, connect to a web page, etc. and infect themselves.

      If unexpected changes are being made to network settings on your PC (??) it sounds more like they have already gotten into your PC, thus trying to block external connections is kind of irrelevant.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • F
        Firewalldude89 @stephenw10
        last edited by

        @stephenw10 Okay.

        I believe the hacker could be inside and wonder if there are tools/packages on pfsense
        that can detect this. Yes, a hacker is using VPN to attack me.
        VPN is encrypted and you can seem to be anywhere in the world which could
        maybe confuse user of firewall or firewall itself.

        Not sure what to do.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          At a basic level what are you seeing that makes you think you are seeing attacks?

          When I say an attacker inside your network what I mean is if you are running, for example, a public wifi network and an attack is coming from that subnet inside the firewall.

          Steve

          1 Reply Last reply Reply Quote 0
          • F
            Firewalldude89
            last edited by

            Hi, I wonder why I dont see the Squid certificate in the padlock icon by clicking on it on websites in web browser. If you dont see it, then it can mean it doesnt work.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              You would only see that if you implemented a 'full bump' MITM style Squid install where it's intercepting all traffic.

              F 1 Reply Last reply Reply Quote 0
              • F
                Firewalldude89 @stephenw10
                last edited by

                @stephenw10 you mean "splice whitelist, bump otherwise"?

                I also wonder why I dont see the IPv4 address from my netgate router in system settings on computer.

                F 1 Reply Last reply Reply Quote 0
                • F
                  Firewalldude89 @Firewalldude89
                  last edited by

                  @netgate1100guy I can see IPv4 adress now, fixed it. Still wonder about the padlock icon and Squid in webbrowser.

                  F 1 Reply Last reply Reply Quote 0
                  • F
                    Firewalldude89 @Firewalldude89
                    last edited by

                    @netgate1100guy And wonder how to fix "ICAP protocol error" when I try to visit websites

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      You should see the Netgate LAN IP as the gateway on a client behind it. Assuming you're using DHCP.

                      F 1 Reply Last reply Reply Quote 0
                      • F
                        Firewalldude89 @stephenw10
                        last edited by

                        @stephenw10 Now I get the error message "ERR_CONNECTION_TIMED_OUT" when try to view the default admin site with 192.168.1.1 IP adress, how do I fix this?

                        Am running Squid with MITM mode..

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Undo whatever you last did?

                          If you have console access you can roll back the config there.

                          I would disable Squid though.

                          F 1 Reply Last reply Reply Quote 0
                          • F
                            Firewalldude89 @stephenw10
                            last edited by

                            @stephenw10 Hi thanks, got Squid enabled but have it on just "splice all" with HTTP proxy active, works much better. I wonder about something:

                            If a hacker somehow blocks downloads from the internet (happens often) and there is a hacker (numerous unknown IP addresses), does that mean the hacker is inside my local network?
                            Can a hacker block and interfere with downloads by hitting the internet modem/central or maybe even WAN port on Netgate 1100, but without getting inside and into my computer?

                            stephenw10S 1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator @Firewalldude89
                              last edited by

                              @netgate1100guy said in Problem with configuring the Netgate 1100:

                              If a hacker somehow blocks downloads from the internet (happens often) and there is a hacker (numerous unknown IP addresses)

                              What exactly are you seeing that makes you think this is happening?

                              It's far more likely to be a compromise on your local client if it really is malicious activity.

                              However simply being unable to download is probably a config issue.

                              Either way Squid won't help you at all here. And on an 1100 could well be causing more problems.

                              Steve

                              1 Reply Last reply Reply Quote 0
                              • S SteveITS referenced this topic on
                              • S SteveITS referenced this topic on
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.