Questions tagged [pfsense]

pfsense is a customized FreeBSD+pf distribution designed for use as a firewall. It wraps many of the features of the pf firewall code in an easy-to-use web interface.

pfSense is an open-source firewall product built on top of FreeBSD and the OpenBSD pf firewall.
It provides a graphical (web-based) interface for configuring and managing firewall rules, as well as viewing traffic and firewall decisions (accept/reject).

pfsense is available as a pre-built applicance (such as OPNSense or StrongBochs) or as installable software directly from the pfSense project's site.

pfsense is similar in concept to m0n0wall, however as of this writing m0n0wall uses the ipfilter packet filter.

838 questions
3
votes
4 answers

Slow upload speed for VMWare virtual machines working via pfSense

We have ProLiant DL360 Gen8 and Gen9 servers running VMWare ESXi 6.0 with virtual machines under various versions of Windows that are routed via pfSense 2.3.4-RELEASE (64-bit) with Open-VM-Tools package 10.1.0,1. The virtual machines that work via…
3
votes
0 answers

PFSense IPv4 TCP/UDP connections from LAN not connecting

I have a PFSense firewall sitting as a gateway for a group of VM's sitting on top of a Xen hypervisor (all machines except for the host are virtual). I have PFSense acting as a waypoint for me to be able to route traffic out to the Internet as my…
Francis Booth
  • 83
  • 1
  • 5
3
votes
2 answers

PFSense DNS Not working

I replaced a Dell tower running PFSense 2.2 that kept needing to be rebooted with a Nokia (Nokia Checkpoint IP390 8 Gigabit Ethernet GbE 4GB CF 1GB RAM) rack mount appliance running the newest PFSense 2.3 that I got off eBay. Things seemed to go…
Alan
  • 543
  • 2
  • 6
  • 18
3
votes
2 answers

pfSense and Disabling SURICATA UDPv4 invalid checksum

We have a pfSense router running with packet inspection. Our logs are filling up with these requests: SURICATA UDPv4 invalid checksum Research shows that we should do the following: Disable the stream-events.rules via SID Mgmt. (Yeah, I mean the…
Jason
  • 3,931
  • 19
  • 66
  • 107
3
votes
1 answer

How to configure PFSense firewall with external transparent Squid proxy?

I am using PFSense 2.0 and trying to get transparent proxy to work. As the internal Squid won't work with loadbalancing and dual-wan (and it seems Squid doesn't work at all on the latest build), I installed Squid on one of the Linux servers I have…
Raynet
  • 511
  • 2
  • 4
  • 11
3
votes
1 answer

Is it possible for a router misconfiguration to cause a telephone line fault/issue?

I apologise if this is posted in the wrong stackexchange but I am currently in the process of building and testing a router running pfSense. Having recently had a line fault, the BT Openreach engineer that did the repair told me of the huge cost…
James W
  • 33
  • 3
3
votes
3 answers

Routing between pfSense Subnets and IPSec VPN

I have a pfSense Router, which is the endpoint of a site-to-site IPSec VPN. In the pfSense the main LAN Interface is 10.0.2.1/24 and it has a virtual IP 10.0.125.1/24 The IPSec Phase 2 connects the 10.172.0.0/16 (from the other side) to the…
W4rlock
  • 968
  • 1
  • 7
  • 10
3
votes
0 answers

Redirect network traffic to Proxy with Pfsense

I have a network with 9 clients: 192.168.1.0/24 I need to redirect all traffic from 192.168.1.208 and 192.168.1.209 to an outside proxy server. --------------- |192.168.1.201|--------| --------------- | |192.168.1.202|-----| …
netrangermike
  • 31
  • 1
  • 4
3
votes
1 answer

Use Framed-IP-Address RADIUS attribute for IP allocation with DHCP on Windows Server 2012R2

I have configured a DHCP server on Windows Server with an NPS Policy, connected to a FreeRADIUS2 server running on pfSense. Authentication is based on MAC address. If MAC address is not present in FreeRADIUS, Windows does not deliver an address, and…
ju71
  • 31
  • 1
  • 2
3
votes
4 answers

PFsense https connections unusably slow

I have a very strange issue with PFsense as router running in KVM with CentOS 7. https connections are incredibly slow (10KB/s or less), and uploads over https simply don't work; for example using https://imgur.com over https loads, but uploading an…
Alex
  • 389
  • 9
  • 23
3
votes
1 answer

1 Public IP 1 NIC ESXi to multipule VMs (with external access)

So I have purchased a Server from https://www.kimsufi.com/fr/index.xml, KS-5A to be exact. Kimsufi only give you 1 Public IP address and 1 NIC to work with, and you cannot purchase more. I have installed ESXi to the Server and I am attempting to…
Lero
  • 41
  • 1
  • 5
3
votes
1 answer

Do all captive portal solutions work the same way? (cookie, vs MAC address, vs other?)

While traveling and having to interact with a number of broken captive portal implementations I've overheard other passengers having usability issues with iPads, Phones, computers depending on the captive portal technology being used. E.g. Captive…
makerofthings7
  • 8,911
  • 34
  • 121
  • 197
3
votes
1 answer

QoS settings for Wi-Fi calling on pfSense firewall/gateway?

The new version of iOS 8 as well as Android supports Wi-Fi Calling with multiple cellular providers including T-Mobile in the US. I am currently running pfSense as the primary Internet gateway for several commercial clients. On my pfSense gateway,…
reedog117
  • 183
  • 1
  • 3
  • 12
3
votes
1 answer

pfSense Cluster not working with Manual NAT

I have two pfSense clusters, one is 2.1.4 and one is 2.1.3. The directions suggest that Manual Outbound NAT is required, but the 2.1.3 cluster is working just fine using Automatic NAT, servers and all (including SSH and OpenVPN). The 2.1.4 cluster…
Mei
  • 4,590
  • 8
  • 45
  • 53
3
votes
2 answers

pfSense OpenVPN DNS Resolution

It seems that my problem is a common issue, and I've read several answers on Server Fault, but I can't seem to get my issue figured out. One of my clients is running pfSense 2.1.4, at an internal IP address of 10.1.10.1. The local network is…
David W
  • 3,453
  • 5
  • 36
  • 62