Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Whats wrong with my setup? Running since early 2021

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 4 Posters 978 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      usaevo7
      last edited by

      With both DNSBL Service and Firewall filter service disabled, I then ran "ipconfig /flushdns" and still have the same issue. Any other thoughts? Could it be a rules based issue? Maybe something to do with our domain? It seems like the issues are mainly related to security certs and encrypted connections because logging in with a brand new computer to O365 fails (i have to enable legacy support). Is it possible there is a pfsense firewall setup issue that is blocking certs or mishandling them?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @usaevo7
        last edited by

        @usaevo7 said in Whats wrong with my setup? Running since early 2021:

        Is it possible there is a pfsense firewall setup issue that is blocking certs or mishandling them?

        NO since pfsense has no clue to if your moving data or a cert

        suricata

        Now an IPS could mess with traffic that triggers some rule..

        When you say you turned off filtering? That doesn't seem like a good idea.. Your not natting with pfsense? There is no way to turn off pfsense firewall and still nat traffic. So your routing public IP space through pfsense?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        U 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Not by default. pfSense does nothing with https traffic unless you have installed Squid in full intercept mode. Usually when you see cert errors like that it's because traffic is being redirected to the wrong server. Like for example when something is resolved to the DNS-BL ad-replacement pixel server.

          U 1 Reply Last reply Reply Quote 0
          • U
            usaevo7 @johnpoz
            last edited by

            @johnpoz said in Whats wrong with my setup? Running since early 2021:

            When you say you turned off filtering? That doesn't seem like a good idea.. Your not natting with pfsense? There is no way to turn off pfsense firewall and still nat traffic. So your routing public IP space through pfsense?

            I mentioned this based on these two services running which I had stopped in order to test. We are not doing any NAT. The only rules there are there from DNSLB if any.
            pfb_dnsbl pfBlockerNG DNSBL service
            pfb_filter pfBlockerNG firewall filter service

            1 Reply Last reply Reply Quote 0
            • U
              usaevo7 @stephenw10
              last edited by

              @stephenw10
              Can you elaborate on how I confirm this is or is not the issue?

              johnpozJ stephenw10S 2 Replies Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @usaevo7
                last edited by johnpoz

                @usaevo7 did you setup squid, do you even have it installed? If not then its pretty confirmed..

                As to pfblocker - do you have any auto rules setup with it? remove them, turn off pfblocker - if you have no rules setup with pfblocker, and you don't have it enabled then its pretty confimed its not pfblocker.

                Uninstall if you want.. There is nothing in pfsense, other than a proxy setup to intercept ssl, that would do anything with ssl traffic. Other than some IPS that is tripping some rule you have enabled. pfblocker could block stuff either based of dns query you made returning the wrong IP (ie blocked) or via some firewall rule using it to prevent access to some IPs.. But its simple enough to disable all of that..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense @usaevo7
                  last edited by

                  @usaevo7 said in Whats wrong with my setup? Running since early 2021:

                  Firefox cant download updates either from https://addons.mozilla.org/en-US/firefox/.

                  Addons...did you enabled wildcard blocking?
                  Wildcard Blocking (TLD)Enable
                  This is an Advanced process to determine if all Sub-Domains should be wildcard blocked for each listed Domain.
                  Click infoblock before enabling this feature!

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator @usaevo7
                    last edited by

                    @usaevo7 said in Whats wrong with my setup? Running since early 2021:

                    @stephenw10
                    Can you elaborate on how I confirm this is or is not the issue?

                    Disable pfBlocker entirely, don't just stop the services, then retest.

                    1 Reply Last reply Reply Quote 0
                    • U
                      usaevo7
                      last edited by

                      Thanks to everyone for helping with possibilities. I found the culprit in this case was Comcasts hardware and their "security edge" setup was blocking "download" sites which somehow the few I mentioned above were included as. Not sure why Firefox.com is a download website but thats what was preventing connection in order to update. So yes, everyone was correct and it was not a pfSense issue so thanks. Im looking into putting the router into Bridge mode as Ive seen recommended elsewhere on this site to prevent any similar issues in the future.

                      1 Reply Last reply Reply Quote 1
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Ouch. Nice catch!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.