Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Newbie question

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      scarr
      last edited by

      Hi all,

      I Installed smoothwall about a week ago and to be honest I'm not impressed here is my wish list.

      1. have DHCP with static IP's (if I'm saying this correctly)
      2. Have timed access so I can block IP's at certain times (my son)
      3. Port forwarding and if possible to multiple devices (a game and the knidle want port 443 forwarding to them)
      4. Usage charts by IP
      5. web proxy so I can trace where people have been
      6. I have a wifi router, this has build in SSID and passwords this will be part of my network
      7. virgin media cable router -> pfSense -> switch, hanging off this switch downstairs will be wifi router
      8. Web interface

      I know i have probably said a lot of things that are "Doh" but didn't want to miss anything, so will pfSense do all this?

      Thanks

      Steve

      1 Reply Last reply Reply Quote 0
      • M
        milanojs
        last edited by

        Hi scar

        1. have DHCP with static IP's (if I'm saying this correctly)
          yes, have to put mac address and reserve the static ip
        2. Have timed access so I can block IP's at certain times (my son)
          squid acl time based rule
        3. Port forwarding and if possible to multiple devices (a game and the knidle want port 443 forwarding to them)
          Yes, Nat rules could it be nat 1:1 or port forwarding
        4. Usage charts by IP
          squid with sarg, pftop
        5. web proxy so I can trace where people have been
          squid again doing the job
        6. I have a wifi router, this has build in SSID and passwords this will be part of my network
          connect direct to wan port or lan port will do the job in companion with squid
        7. virgin media cable router -> pfSense -> switch, hanging off this switch downstairs will be wifi router
          Web interface
          dont ge it! but pfsense has a web interface to work with it
        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Additionally:

          1. You could also use scheduled firewall rules.

          2. Yes but you can't forward incoming port 443 requests to two places. Are you sure they want, the very common and already used for HTTPS, port 443?

          Steve

          1 Reply Last reply Reply Quote 0
          • R
            rjcrowder
            last edited by

            Just to add a little bit…

            1. have DHCP with static IP's (if I'm saying this correctly)
              yes, have to put mac address and reserve the static ip
              RJC - if necessary, you can also startup IPFW and create rules to make sure that no tries to manually switch their IP address (layer 2/3 rules). Good idea if anyone on your network is smart enough to figure out how to change their IP (for example - to one that doesn't have time restrictions or filtering).
            2. Have timed access so I can block IP's at certain times (my son)
              squid acl time based rule
              RJC - Time based firewall rules work great for this.
            3. Port forwarding and if possible to multiple devices (a game and the knidle want port 443 forwarding to them)
              Yes, Nat rules could it be nat 1:1 or port forwarding
            4. Usage charts by IP
              squid with sarg, pftop
            5. web proxy so I can trace where people have been
              squid again doing the job
              RJC - Highly recommend Dansguardian in conjunction with Squid if you have children accessing the internet. It will give you content based filtering and nice logging features. There's no great reporting package for it, but Webmin can be added and it works well. Also consider using the OpenDNS servers for DNS. Then configure the dynamic DNS update within pfSense.
            6. I have a wifi router, this has build in SSID and passwords this will be part of my network
              connect direct to wan port or lan port will do the job in companion with squid
            7. virgin media cable router -> pfSense -> switch, hanging off this switch downstairs will be wifi router
              Web interface
              RJC - Sounds like exactly what I have: modem -> pfsense -> switch -> wifi router configured as access point.
            1 Reply Last reply Reply Quote 0
            • S
              scarr
              last edited by

              WOW, thanks a lot guys really helpfull, will install at the weekend and keep you all posted, thanks again.

              Steve

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.