Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. help
    Log in to post
    • All categories
    • E

      Should I invest into a PFSense setup and How?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions pfsense help newbie proxmox port forwarding
      7
      0 Votes
      7 Posts
      444 Views
      stephenw10S

      If you're asking can you run pfSense as a VM in proxmox then the answer is yes. But there are some caveats! It's a more complex setup to be sure the traffic is all passing through the VM. If you have to reboot proxmox you lose your router/firewall. There are lots of users doing exactly that though.

    • R

      Update Problem pfSense 2.7.2

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions update help error
      10
      0 Votes
      10 Posts
      641 Views
      stephenw10S

      I would guess it's because you are policy routing traffic from LAN clients to a specific gateway. So that works even when the firewall has no default route.

    • V

      Haproxy Layer6 Issues - Intermittent Logging

      Watching Ignoring Scheduled Pinned Locked Moved Cache/Proxy help haproxy ssl letsencrypt
      1
      0 Votes
      1 Posts
      260 Views
      No one has replied
    • P

      OpenVPN site to site not working both ways

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions pfsense openvpn help
      10
      0 Votes
      10 Posts
      1k Views
      V

      @Pablomdli said in OpenVPN site to site not working both ways:

      The only weird things is that it gives the ip 10.0.8.0 to de office#2 openvpn client

      So I'd suspect, that you stated this IP in the CSO.
      You should enter an IP out of the tunnel network there, but it have to be one from the second upwards.

    • P

      NAT Reflection on a multiwan system - need help debugging my problem getting it to work.

      Watching Ignoring Scheduled Pinned Locked Moved NAT nat reflection help
      2
      0 Votes
      2 Posts
      475 Views
      V

      @pdwalkerhk said in NAT Reflection on a multiwan system - need help debugging my problem getting it to work.:

      is there any way to debug why the traffic from the local lan to the public ip of the port forwarded ports is not going through?

      Sniff the traffic with the packet capture tool on the LAN.

      does that reflection firewall rule look correct for my situation?

      I would expect it to work.

      the default route for the LAN traffic is a gateway group composed of the 4 lan connections. Could this be causing a problem, preventing the nat reflection from working?

      You may mean an interface group. This is not a problem, however, ensure that a rule on LAN allows the traffic from LAN IP to LAN destination IP.
      The rule must not be a policy routing rule (gateway (group) stated)!

      could I use the / Diagnostics / Packet Capture / somehow to find out what is or is not happening?

      Yes. You should see packets from the source IP to the public going to pfSense and packets leaving with source = LAN IP and local destination IP.

    • R

      Port Forward does not work..

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling help nat nat rules firewall firewall rules
      71
      1 Votes
      71 Posts
      14k Views
      V

      @johnpoz said in Port Forward does not work..:

      But completely agree with you - in my multiple statements that nat reflection is an abomination

      That's the way I know you. 😊

      As I mentioned, I didn't read all posts and I missed the reason for doing NAT reflection.

    • O

      TCP Streams Drop between Proxmox VLANS Routed via Virtual PFSense

      Watching Ignoring Scheduled Pinned Locked Moved L2/Switching/VLANs help vlans proxmox pfsense
      1
      0 Votes
      1 Posts
      354 Views
      No one has replied
    • R

      Can someone explain to me how i can do this ?

      Watching Ignoring Scheduled Pinned Locked Moved Virtualization help proxmox networking vlans vlan
      12
      0 Votes
      12 Posts
      2k Views
      NollipfSenseN

      @root1ng said in Can someone explain to me how i can do this ?:

      the network card of the motherboard is disabled in the bios

      Most of us who use Proxmox reserve that port for Proxmox...makes it a lot easy, and once you passthrough the PCIe NIC in your setup, Proxmox won't have a gateway. Please visit here: https://docs.netgate.com/pfsense/en/latest/recipes/virtualize-proxmox-ve.html

    • S

      How do I route outgoing email over WireGuard Tunnel?

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN wireguard tunnels routiing help gateway
      29
      0 Votes
      29 Posts
      4k Views
      Bob.DigB

      @Gertjan said in How do I route outgoing email over WireGuard Tunnel?:

      Of course I use have DANE available and set up :

      I just noticed I had to recreate the TLSA records, something with Let's Encrypt must have changed. I hope I am good now for some time...

    • M

      No connection on WAN port

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions help wan vlan pppoe
      9
      0 Votes
      9 Posts
      1k Views
      M

      @stephenw10 I guess there is VLAN configured because I didn't need to set it on the pfsense

    • E

      DDoS protection with pfSense

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling ddos games server help desperate
      12
      0 Votes
      12 Posts
      4k Views
      Cool_CoronaC

      @erick51 You can. But it takes experience and knowledge.

      And you need hardware with dual Xeon proc. to cope.

    • S

      (2100) Some links to documentation in the admin GUI point to incorrect location.

      Watching Ignoring Scheduled Pinned Locked Moved Documentation help gui 22.01
      5
      0 Votes
      5 Posts
      2k Views
      S

      @steveits Done, thanks for pointing me in the right direction. :)

    • AtariA

      Netgate 6100 MAX (Help installing firmware)

      Watching Ignoring Scheduled Pinned Locked Moved Official Netgate® Hardware help router newbie
      11
      0 Votes
      11 Posts
      2k Views
      stephenw10S

      Yeah, I reviewed it with the support agent and we agreed it was an issue that required further testing of the hardware.

      Steve

    • C

      AUTH_FAILED

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN help openvpn log openvpn
      1
      0 Votes
      1 Posts
      589 Views
      No one has replied
    • N

      Help Understanding a Crash [kernel panic]

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions crash kernel panic pfsense help log
      31
      0 Votes
      31 Posts
      5k Views
      N

      Hello,

      Just to update about the crashs: they didn't happen again.
      Also, I've being using Suricata 6.0.3 release since than, and no netmap issues 😸

      So, I changed my RAM, and tested the old ones:
      24H of MemTest86+ and at least 5hrs of GoldMemory (not the best tests, but still), resulted in not a single red flag for them (tested individually), AND I'm using them on other Win machines withouth BSOD or anything in the logs.

      I already saw RAM tests failing to detect problems, so based on what you explained, I'm assuming that both 1 - the issue with Suricata's Multithreading ring access, and 2 - darkstat, were hitting some intermittent problem, that I could not with tests and other OS.

      Anyway, thank you for helping me out solving this. Really appreciate @stephenw10 and @bmeeks !

    • M

      OpenVPN connect but no internet on iOS and Mac Pls help

      Watching Ignoring Scheduled Pinned Locked Moved OpenVPN open vpn help openvpn
      1
      0 Votes
      1 Posts
      442 Views
      No one has replied
    • P

      Is my pfSense dying?

      Watching Ignoring Scheduled Pinned Locked Moved webGUI web gui error fail help file system che
      1
      0 Votes
      1 Posts
      582 Views
      No one has replied
    • M

      Proxy services stop unexpectedly

      Watching Ignoring Scheduled Pinned Locked Moved Cache/Proxy pfsense squid squidguard help
      2
      0 Votes
      2 Posts
      871 Views
      ?

      @mhmz

      does it make any sense sitting on proxy server with deactivated aes-ni ?

    • R

      Wan not coming up, fresh install.

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software wan gateway comcast help
      4
      0 Votes
      4 Posts
      1k Views
      GertjanG

      @cfbcfb said in Wan not coming up, fresh install.:

      Connected to the router via wifi and my phone, got a "this network wants you to sign in" and when I clicked that, it brought up the comcast login

      That's your OS / brower playing the captive portal detection mode !
      That means your WAN is using a RFC1918 IP, and when you start your bowser it hits the GUI web server of the modem, because it's router part is redirecting the browser requests to it's internal Web GUI, where you have to login.

      What about playing with these option on the WAN interface :

      37b478df-9583-49cc-9cf0-9fd448fc633f-image.png

      See manual - Advanced Configuration.

    • D

      pfSense not recognized on boot drive after successful (?) installation

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software help
      2
      0 Votes
      2 Posts
      2k Views
      CybermazeC

      These kinds of installation issues are quite rare.

      I'm not sure we have enough information to precisely tell you the problem or how to fix it, but maybe we can start to work it out.

      FreeBSD (and thus pfSense) can boot using UEFI since FreeBSD 10.1, however, depending on the BIOS/UEFI in your laptop it might help to enable CSM (Compatibility Support Module) to allow booting in legacy BIOS mode. CSM enabled should generally be the most safe option (my experience).

      Regarding AHCI or IDE this is mostly to do with your SATA ports, but may affect USB drives aswell. AHCI mode should be default, IDE being legacy mode for very many years now.

      Installation to USB drives is generally a bad idea, since the controllers and NAND chips on USB drives are not really geared for that kind of workload. You should REALLY consider installation to a small SSD or even a Harddrive. At least to work out if the issue is related to the one or more USB drives, that you have attempted to use.