Questions tagged [pfsense]
pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a computer to make a dedicated firewall/router for a network and is known for its reliability and high-grade features.
83 questions
0
votes
0
answers
86
views
ISC Bind9 with DNS over TLS (DOT) fails when strict tls auth is enabled
working I installed and setup Bind9 official package to test DNS forward zones based on source IP/subnets which unbound doesn't support
I properly set NAT forwards, changed listening ports on Bind9 ...
0
votes
0
answers
112
views
pfSense routing issues
Ive got a routing issue on my pfSense box that shows the response to a ping request being routed to a IP in a separate subnet/vlan.
10:25:13.239238 IP 10.2.0.2 > 8.8.8.8: ICMP echo request, id 9374,...
0
votes
0
answers
59
views
How to Allow all NATed traffic from iptables firewall via pfsense (gateway)
I have an iptables firewall (machine 1) and a centos 7 based gateway (machine 2), which is having 2 interfaces (machine-2:int-1) from WAN [/30] and (machine-2:int-2) is LAN [/28] one of the static IP ...
2
votes
1
answer
786
views
pfSense (FreeBSD 14.0) - Prometheus Node Exporter gives log errors - fix or suppress in log
On pfSense, I've enabled Prometheus Node Exporter, but it gives the following log errors each 15 seconds:
Feb 15 09:53:57 vault node_exporter[25559]: ts=2024-02-15T08:53:57.164Z caller=collector.go:...
1
vote
0
answers
37
views
pfSense (FreeBSD) - tail -f not showing entire log when filtering with cut or sed [duplicate]
I have a strange problem when trying to display logs on pfSense (and I can reproduce the same problem on Ubuntu server also).
The problem is this (with examples):
I'm trying to display a running dhcp ...
0
votes
0
answers
93
views
Need help with Wireguard allowedip/pre/post settings
I started playing with wireguard on a pfsense router to try to see if I could overcome a CG Nat on a hotspot I want to use when visiting my mother a couple hours from home. I stay in an RV when up ...
0
votes
0
answers
121
views
How is it possible that NAT doesn't back translate packets?
I have the following topology
and from myhost I can ping router2 but can't ping router1.
With tcpdump I can observe how my pings go and I see that both router1 and router2 reply. But only replies ...
1
vote
1
answer
3k
views
UEFI HTTP Boot clarity?
I'm interested in learning more about UEFI HTTPBoot and setting it up for my
LAN as a netboot option, but the details are notably sparse. The best docs I've
found are Suse Docs for
configuring an HTTP ...
1
vote
1
answer
1k
views
IPSec tunnel works until rekeying, then gets NO_PROPOSAL_CHOSEN
Context
I have set up a site-to-site IPSec tunnel between a Raspberry Pi located in an office and a pfSense firewall in the cloud. I am using Strongswan for the Raspberry Pi side.
Issue
My tunnel ...
0
votes
1
answer
46
views
What subsystem is responsible if I can connect via s2s VPN connection only in one direction?
I have configured the following s2s VPN (in pfSense) connection which is working in general.
Unfortunately, I can connect (ping, netcat, ssh) only from client to the server, but not back.
If I can ...
0
votes
1
answer
496
views
What hostname to put in main.cf for self-hosted postfix, behind HAProxy?
Pfsense (HAproxy as reverse proxy)—->Unraid
I run postfix on Debian Bullseye VM (under Unraid) on my home server. It is up and running. I can send the mail out but can’t receive any incoming mail. ...
0
votes
1
answer
2k
views
PXE boot problem using netboot.xyz "mounting tmpfs on /cdrom failed: Invalid argument"
I've set up my pfsense server with tftp to support PXE booting. I've configured it to boot the latest (as of posting) version of netboot.xyz. This works to a point, but I've tried loading a few Linux ...
2
votes
0
answers
582
views
Port Forwarding over VPN link cloud VPS (To bypass CG-NAT)
I have a radio setup on a 4G connection that utilises CG-NAT. This means I am unable to access the radio remotely using the supplied remote software.
To get around this I have setup a cloud VPS ...
0
votes
0
answers
157
views
Access to pfsense wan interface by ip public
I have this diagram.
I have a server(centos 7) with ip public and staic 1.2.3.4 on internet, I want when user send request to this public ip 1.2.3.4, this request pass my modem with not static ip ...
0
votes
1
answer
749
views
routing already in table when trying to add additional route to the same net
I have the following table
$ netstat -r -4 | grep 33.0
192.168.33.0/24 192.168.29.4 UGS ovpns5
I would like to add additional route to the same network and get
$ route add -net 192.168....