Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. firewall
    Log in to post
    • All categories
    • M

      Error when adding network range to Firewall Alias

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall alias network range
      4
      0 Votes
      4 Posts
      829 Views
      bingo600B

      I just saw this
      https://forum.netgate.com/post/939135

      Seems like you can enter a range

      /Bingo

    • D

      Multiple Gateways on same subnet

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN multi-wan subnet gateway routing firewall
      26
      0 Votes
      26 Posts
      6k Views
      D

      @JeGr said in Multiple Gateways on same subnet:

      Why not simply reconfigure those routers

      Because some devices (not mine) directly connected to router 1 have in their routing table certain rules to redirect traffic through 10.1.0.4. Hence those routers need to be on the same subnet.

      These routers are shared by around 20 people, in 4 rooms on single floor. Hence I cannot change settings on those routers.

    • D

      Possible to block certain websites using URL ?

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall block website acl access control
      6
      0 Votes
      6 Posts
      2k Views
      DaddyGoD

      @dr_tech said in Possible to block certain websites using URL ?:

      Is such a provision available ?

      Yes, I thought pfBlockerNG would be a good solution. 😉
      See the answer to your question at the attached link:
      https://forum.netgate.com/topic/138029/acl-s-support

      In particular, focus on the recommendation of @BBcan177 (maintainer and creator of pfBlockerNG)

    • P

      PFSense throw looped back NS error

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall network problem error networking
      1
      0 Votes
      1 Posts
      940 Views
      No one has replied
    • W

      Restrição de acesso pelo túnel IPsec

      Watching Ignoring Scheduled Pinned Locked Moved Portuguese firewall firewall rules ipsec ipsec rules
      1
      0 Votes
      1 Posts
      453 Views
      No one has replied
    • D

      Solved: Cannot access beyond router via OpenVPN

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN routing firewall openvpn openvpn routing log
      9
      0 Votes
      9 Posts
      2k Views
      johnpozJ

      @ddbnj said in Cannot access beyond router via OpenVPN:

      10.8.0.0 0.0.0.0 255.255.255.0 U 0 0 0 tun0

      Yeah that would dick it up ;)

      Glad you got it sorted! Told you it wasn't pfsense ;) hehehehe

      The trick is getting the person to clearly see that themselves... Which is why the sniff proves to the user, hey pfsense is doing what its suppose to be doing... Have to look elsewhere..

    • Sergei_ShablovskyS

      Packages of Aliases (Port + IP's + company AC) for easy administrating

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions packages admin gui firewall alias
      13
      0 Votes
      13 Posts
      3k Views
      Sergei_ShablovskyS

      @viktor_g said in Packages of Aliases (Port + IP's + company AC) for easy administrating:

      @Sergei_Shablovsky said in Packages of Aliases (Port + IP's + company AC) for easy administrating:

      have a lot of Apple iOS devices in company/home and need to quickly add rules to pfSence after You buy new appliance from Netgate;
      company buy a software product that need to communicate with outside servers on a developer side;
      company buy a new hardware (servers (like IBM IMM service, Dell/HP have similar) , email antivirus DPI inspector, etc...), that need to communicate with outside servers on a developer side;

      Every appliance uses it own list of ports, that can be changed
      It is better to check this information with the vendor

      May be 5 or 7 years ago I was agree with You, because there are a huge bunch of SaaS services and the pool of IPs cannot able to be collected in reasonable timeslot.
      BUT now in 2020 exist only 30-100 SaaS services that used by MOST OF USERS: Amazon AWS, Google ~Servises, Apple, 5 email services (Google, Yahoo, ...), and around 10 most-usable hardware vendors (Dlink, TPlink, Amazon devices, Google devices, ...)

      Sorry, I need to repeat again:

      The main question are the most users just need "push button and all working well" solution. Just look at this NetGate forum - more than 80% are about something described in official doc, or more than one time appear on forum. But same questions popup again and again, again and again, countless.
      Even pinned on top of official pfBlockerNG part of this forum Bypassing DNSBL for specific IPs have words like CloudFlare. Rock... :)

      And from point of view of ordinary users if something goes wrong, each user clime the "NetGate pfSense router" rather himself for not setup pfSense correctly. You may see on this forum even sysadmins of small organization are to lazy to correctly setup the pfBlockerNG-devel. This is reality of our life.

      So at the bottom line are: if some solution exist on level "push button - and we do the rest" - more than 80% of users are happy with this. And buy more and more of pfSense devices, and recommend to others. NetGate are open source but not source of donation, this is "open source / business" balance.

      And my proposition also about increase the power of this "open source / business" balance.

      blocking using social networks (we all need that our stuff pay attention on work neither spent working hours on instagram, tinder, facebook, twitter...)

      You can block it with the pfBlockerNG-devel / DNSBL Category

      You can also find/add some specific DNSBL/IP lists there,
      Most cloud providers have these lists,
      check https://github.com/joetek/aws-ip-ranges-json
      https://forum.netgate.com/topic/147716/stun-public-email-providers-and-some-feeds-from-secops
      etc..

      Thank You for source! Appreciate Your attention and time!

    • H

      [Solved] Disable IP source routing

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall routing firewall rules
      4
      0 Votes
      4 Posts
      1k Views
      GertjanG

      No need tu put it off, because

      The style of routing described on that link won't work since pfSense doesn't enable the options for multiple routing tables

      So, what isn't implemented can't be switched off - neither on.

    • D

      FW Widgets on different IFs show the same entries

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall widget dashboard log
      1
      0 Votes
      1 Posts
      498 Views
      No one has replied
    • N

      Multiple gateways and what seems to be Asymmetric Traffic

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN routing routing opt1 firewall aysmmetric multi wan
      1
      1 Votes
      1 Posts
      508 Views
      No one has replied
    • mohkhalifaM

      Port Forward in Active CP

      Watching Ignoring Scheduled Pinned Locked Moved Captive Portal captive portal firewall firewall rules port forward port forwarding
      6
      0 Votes
      6 Posts
      1k Views
      F

      @Gertjan shodan.io is a service that scans the internet for known exposure and for vulnerabilities

      i remember you are french, so I link you here a video in French on the subject https://youtu.be/SxjmOFBtsvk

    • A

      I need to Create routes for my VLAN interface.

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall
      7
      0 Votes
      7 Posts
      803 Views
      C

      I am also wondering about the same thing. If you found a fix then please do let me know. thanks in advance :)

    • C

      does pfsense behind router make sense

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions pfsense firewall nas forwarding home
      8
      0 Votes
      8 Posts
      2k Views
      DerelictD

      Well it is up to the ISP device to provide reasonable support for a customer-owned firewall device while still providing the necessary IPTV, etc functionality.

    • F

      pfctl Anchor based approach possible?

      Watching Ignoring Scheduled Pinned Locked Moved Development firewall
      3
      0 Votes
      3 Posts
      358 Views
      F

      When I run an iperf UDP Test that involves pfsense as router and a filter reload is done there is packet loss while the filter is reloading. This is especially annoying if an IPv6 Gateway goes down, the filter is reloaded and this affects the IPv4 Link aswell. If pfsense could selectively reload ipv6 only if an IPv6 Gateway goes down that would make things a lot easier.

      This was not meant to be a "problem post" but rather a "couldn't we improve by splitting ipv4 and ipv6 rules in 2 anchors" though. My first idea was something that could be done in iptables but not pf: Have a list of rules we want and one with rules we have and issue the commands to make them match. The closest we could get to that is probably splitting up, comparing when we want to reload and only reload if last != current.

    • J

      Pfsense não consegue fechar mais de um túnel vpn

      Watching Ignoring Scheduled Pinned Locked Moved Portuguese vpn windows server rdp firewall
      1
      0 Votes
      1 Posts
      541 Views
      No one has replied
    • O

      Configuration of a Dedicated Management Interface on a SG-3100

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall sg-3100 mgmtaccess
      2
      0 Votes
      2 Posts
      703 Views
      RicoR

      Post your Rules (Screenshots).

      -Rico

    • G

      Restricting access to GUI from LAN - Still have access?

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall gui access alias
      8
      0 Votes
      8 Posts
      1k Views
      G

      @NogBadTheBad

      Hi,

      Sorry i should have mentioned, yeah my PC is on the 10.0.4.X network (just as a test PC) , the aim here was to loose connectivity to the GUI from my PC, then i have another one on the 10.0.7.X range that "should" get access to the GUI.

      After thinking about this last night I think I have sussed it out, we are going through a Proxy and this is the IP Address that accesses the Management GUI, hopefully I should be able to add some rules in our other proxy to avoid this Firewall bypassing it.

      Ill let you know if i have any more issues or if i need more help with this.

      Thanks for your help!

    • D

      Understanding Firewall Configuration

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling rules firewall interfaces
      1
      0 Votes
      1 Posts
      478 Views
      No one has replied
    • H

      How can I find out, why pfSense is blocking an internal IP?

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling firewall
      9
      0 Votes
      9 Posts
      2k Views
      johnpozJ

      NP - glad you got it sorted..

    • S

      Feature Request: Have IPSec listen on all members of a Gateway Group

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN multi wan ipsec firewall routing
      1
      0 Votes
      1 Posts
      339 Views
      No one has replied