Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Running additional internet applications on pfsense

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mare
      last edited by

      I am running some cloud service software on my pfsense installation. I start it using special user on system startup.

      Is it safe? As far as I figured out, this application is not firewalled in any way and is connected to internet and LAN regardless of my firewall rules.

      NollipfSenseN provelsP 2 Replies Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @mare
        last edited by

        @mare Are you saying your pfSense is a virtual installation? That's what most folks do in such case. If not, most folks would say no other application should be on a firewall that's not an approved package.

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        1 Reply Last reply Reply Quote 0
        • M
          mare
          last edited by

          It's not a virtual installation, it runs on a router HW.

          NollipfSenseN 1 Reply Last reply Reply Quote 0
          • NollipfSenseN
            NollipfSense @mare
            last edited by

            @mare Well from a firewall sense, your set up doesn't sound safe especially bypassing the firewall completely yet attaches to your computer inner structure. Remember though, it's your setup, if you determined that it's safe, so be it.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            1 Reply Last reply Reply Quote 1
            • provelsP
              provels @mare
              last edited by

              @mare Might as well turn off pfSense.

              Peder

              MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
              BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

              1 Reply Last reply Reply Quote 0
              • M
                mare
                last edited by mare

                ...at least user privilleges are obeyed and it can read/write only to user's home address.

                So is there a way to run additional applications in safe way? It is very handy to use my router HW for some additional 24/7 tasks.

                provelsP 1 Reply Last reply Reply Quote 0
                • provelsP
                  provels @mare
                  last edited by

                  @mare Run vetted applications installed from the Package Manager.

                  Peder

                  MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                  BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    There's no 100% safe way to do this, whatever you choose to run is untested and might have introduced issues. Only you will be able to test and fix that. Installing pkgs from other repos may replace a package we modify for pfSense with unexpected results.
                    If you really have to do this the safest way is probably to use bhyve.

                    Otherwise run pfSense and whatever else you need both as VMs in some other hypervisor.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.