Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Server's Traffic that i permitted getting limitted

    Scheduled Pinned Locked Moved Traffic Shaping
    26 Posts 4 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Look at the diagram again.

      I didn't look at it the first time  ;D

      OK, disregard what I said about that.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Probably still has a gateway set on it.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • A
          Arief
          last edited by

          @Derelict:

          Why are all your rules TCP-only?

          i just want to make rules for 192.168.200.x
          what did i do wrong? can you give me some example for create pfsense correctly? because if i deleted all of that rules and transfer data to my another server i just have 300-400KB/s but without pfSense i can have 7-8MB/s speed.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            TCP is just one protocol. You probably also want UDP and ICMP. Change the TCPs to any unless you know you are dealing with TCP ports.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              @Arief:

              @Derelict:

              Why are all your rules TCP-only?

              i just want to make rules for 192.168.200.x
              what did i do wrong? can you give me some example for create pfsense correctly? because if i deleted all of that rules and transfer data to my another server i just have 300-400KB/s but without pfSense i can have 7-8MB/s speed.

              I suggest you blow out the config and start over. Make WAN to interface going to your upstream, and make LAN for your LAN.  Get everything routing how you want THEN add OPT1 for the other segment.  Get everything routing how you want THEN worry about the limiters.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • A
                Arief
                last edited by

                @Derelict:

                I suggest you blow out the config and start over. Make WAN to interface going to your upstream, and make LAN for your LAN.  Get everything routing how you want THEN add OPT1 for the other segment.  Get everything routing how you want THEN worry about the limiters.

                Wait, i got a little confused. So i need to provide 3 NIC and the wan ip is 192.168.0.1?

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  According to your diagram the WAN IP should be 192.168.0.x and the gateway should be 192.168.0.1 but we only know what you have posted.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • A
                    Arief
                    last edited by

                    @Derelict:

                    According to your diagram the WAN IP should be 192.168.0.x and the gateway should be 192.168.0.1 but we only know what you have posted.

                    Oh yes, i fill in the upstream gateway for wan is 192.168.0.1 but the WAN IP is 192.168.0.254

                    1 Reply Last reply Reply Quote 0
                    • A
                      Arief
                      last edited by

                      So i should build configuration like this?

                      should.png
                      should.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Yes that makes a lot more sense.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • A
                          Arief
                          last edited by

                          @Derelict:

                          Yes that makes a lot more sense.

                          Wait, 192.168.0.1 is my gateway. will it conflict if i put WAN ip address 192.168.0.1?

                          1 Reply Last reply Reply Quote 0
                          • DerelictD
                            Derelict LAYER 8 Netgate
                            last edited by

                            Of course. You said WAN IP was .254

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • A
                              Arief
                              last edited by

                              @Derelict:

                              Of course. You said WAN IP was .254

                              Sorry i don't understand, so when i set interface(s) ip address, i should put 192.168.0.1 in WAN IPv4 Address?
                              will it affect my current gateway?

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                Your WAN IP address should be something other than your gateway IP address.

                                IP addresses on a subnet must be unique.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • A
                                  Arief
                                  last edited by

                                  @Derelict:

                                  Your WAN IP address should be something other than your gateway IP address.

                                  IP addresses on a subnet must be unique.

                                  oh i just got it, the reason i build that confusing configuration because the upstream gateway(192.168.0.1) is internet gateway in my office.
                                  and if i want to built configuration like u suggested, how do i can connect to internet, should i put the upstream gateway anyway?

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Arief
                                    last edited by

                                    Sorry, how about this? i think my pfsense right now is more like this

                                    a.png
                                    a.png_thumb

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      Arief
                                      last edited by

                                      @Derelict:

                                      Your WAN IP address should be something other than your gateway IP address.

                                      IP addresses on a subnet must be unique.

                                      i have edited my first post, perhaps its clearer than before.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.