• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Suggestion: Two Improvements to Pfsense

Scheduled Pinned Locked Moved General pfSense Questions
7 Posts 6 Posters 544 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    Ryu945
    last edited by Jan 14, 2018, 10:20 PM

    1)  In the GUI where the anti-lock out rule is located.  You should be able to apply that safety feature to more then just the default LAN.  Allow it on all LANs and Bridges.

    2)  In terminal where your setting up your ports.  You should be able to set up more then one LAN port.  If you do choose to set up more then one LAN port, the setup will set it up as a bridge.  If you set up only one LAN port; the setup will set it up the LAN port the way it does now.

    You may also want to consider setting up the LAN as a bridge by default.  If you have only one LAN port, then the bridge will only have a LAN connection on it.  This will make it an order of magnitude faster to add LAN ports after the fact.

    1 Reply Last reply Reply Quote 0
    • G
      Grimson Banned
      last edited by Jan 14, 2018, 11:00 PM

      @Ryu945:

      You may also want to consider setting up the LAN as a bridge by default.  If you have only one LAN port, then the bridge will only have a LAN connection on it.  This will make it an order of magnitude faster to add LAN ports after the fact.

      Bridge in pfSense is discouraged, as it is software based and lacks performance in comparision to a switch. So making this a default is quite stupid.

      1 Reply Last reply Reply Quote 0
      • R
        Ryu945
        last edited by Jan 15, 2018, 4:38 AM

        @Grimson:

        @Ryu945:

        You may also want to consider setting up the LAN as a bridge by default.  If you have only one LAN port, then the bridge will only have a LAN connection on it.  This will make it an order of magnitude faster to add LAN ports after the fact.

        Bridge in pfSense is discouraged, as it is software based and lacks performance in comparision to a switch. So making this a default is quite stupid.

        There has to be some way for Pfsense to have the same performance as a switch when the equipment it is installed on has multiple ethernet ports.

        1 Reply Last reply Reply Quote 0
        • G
          GruensFroeschli
          last edited by Jan 15, 2018, 6:56 AM

          @Ryu945:

          @Grimson:

          @Ryu945:

          You may also want to consider setting up the LAN as a bridge by default.  If you have only one LAN port, then the bridge will only have a LAN connection on it.  This will make it an order of magnitude faster to add LAN ports after the fact.

          Bridge in pfSense is discouraged, as it is software based and lacks performance in comparision to a switch. So making this a default is quite stupid.

          There has to be some way for Pfsense to have the same performance as a switch when the equipment it is installed on has multiple ethernet ports.

          No.
          You're comparing apples with oranges.
          One is a general purpose PC.
          The other is an ASIC.

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • G
            Gertjan
            last edited by Jan 15, 2018, 7:06 AM

            The apple that tastes like an orange https://store.netgate.com/SG-3100.aspx ? (it has a switch on board)

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • J
              jahonix
              last edited by Jan 15, 2018, 11:36 AM Jan 15, 2018, 11:31 AM

              @Ryu945:

              1)  In the GUI where the anti-lock out rule is located.  You should be able to apply that safety feature to more then just the default LAN.  Allow it on all LANs and Bridges.

              You only have one LAN, other interfaces are called OPTx for a reason but can be renamed to your liking.
              Ruleset to those interfaces varies on usage which means that applying an anti-lockout rule to your firewall on a DMZ interface is … nonsense at least.
              You can copy these rules yourself to other interfaces if needed.

              Configuring a bridge is nothing you want to do in a software router regularly. Get rid of that idea quickly!
              Each packet has to travel from the incoming interface through the software stack down to the kernel and back up to the outgoing interface again. This is not the equivalent to a switch, never was, never will be.

              Having understood that, your 2) is irrelevant.

              @Ryu945:

              You may also want to consider setting up the LAN as a bridge by default.

              Maybe suggestions like these should only be made if you understand the mechanics behind it…

              @Ryu945:

              This will make it an order of magnitude faster to…

              …have a borked configuration.

              1 Reply Last reply Reply Quote 0
              • K
                kpa
                last edited by Jan 15, 2018, 12:26 PM

                PfSense was never designed to be a replacement for a proper switch so don't expect it to perform like one.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received