Questions tagged [pfsense]
pfSense is an open source firewall/router computer software distribution based on FreeBSD. It is installed on a computer to make a dedicated firewall/router for a network and is known for its reliability and high-grade features.
83 questions
0 votes
0 answers
100 views
ISC Bind9 with DNS over TLS (DOT) fails when strict tls auth is enabled
working I installed and setup Bind9 official package to test DNS forward zones based on source IP/subnets which unbound doesn't support I properly set NAT forwards, changed listening ports on Bind9 ...
0 votes
0 answers
122 views
pfSense routing issues
Ive got a routing issue on my pfSense box that shows the response to a ping request being routed to a IP in a separate subnet/vlan. 10:25:13.239238 IP 10.2.0.2 > 8.8.8.8: ICMP echo request, id 9374,...
0 votes
0 answers
64 views
How to Allow all NATed traffic from iptables firewall via pfsense (gateway)
I have an iptables firewall (machine 1) and a centos 7 based gateway (machine 2), which is having 2 interfaces (machine-2:int-1) from WAN [/30] and (machine-2:int-2) is LAN [/28] one of the static IP ...
2 votes
1 answer
808 views
pfSense (FreeBSD 14.0) - Prometheus Node Exporter gives log errors - fix or suppress in log
On pfSense, I've enabled Prometheus Node Exporter, but it gives the following log errors each 15 seconds: Feb 15 09:53:57 vault node_exporter[25559]: ts=2024-02-15T08:53:57.164Z caller=collector.go:...
1 vote
0 answers
39 views
pfSense (FreeBSD) - tail -f not showing entire log when filtering with cut or sed [duplicate]
I have a strange problem when trying to display logs on pfSense (and I can reproduce the same problem on Ubuntu server also). The problem is this (with examples): I'm trying to display a running dhcp ...
0 votes
0 answers
102 views
Need help with Wireguard allowedip/pre/post settings
I started playing with wireguard on a pfsense router to try to see if I could overcome a CG Nat on a hotspot I want to use when visiting my mother a couple hours from home. I stay in an RV when up ...
0 votes
0 answers
130 views
How is it possible that NAT doesn't back translate packets?
I have the following topology and from myhost I can ping router2 but can't ping router1. With tcpdump I can observe how my pings go and I see that both router1 and router2 reply. But only replies ...
1 vote
1 answer
3k views
UEFI HTTP Boot clarity?
I'm interested in learning more about UEFI HTTPBoot and setting it up for my LAN as a netboot option, but the details are notably sparse. The best docs I've found are Suse Docs for configuring an HTTP ...
1 vote
1 answer
1k views
IPSec tunnel works until rekeying, then gets NO_PROPOSAL_CHOSEN
Context I have set up a site-to-site IPSec tunnel between a Raspberry Pi located in an office and a pfSense firewall in the cloud. I am using Strongswan for the Raspberry Pi side. Issue My tunnel ...
0 votes
1 answer
52 views
What subsystem is responsible if I can connect via s2s VPN connection only in one direction?
I have configured the following s2s VPN (in pfSense) connection which is working in general. Unfortunately, I can connect (ping, netcat, ssh) only from client to the server, but not back. If I can ...
0 votes
1 answer
505 views
What hostname to put in main.cf for self-hosted postfix, behind HAProxy?
Pfsense (HAproxy as reverse proxy)—->Unraid I run postfix on Debian Bullseye VM (under Unraid) on my home server. It is up and running. I can send the mail out but can’t receive any incoming mail. ...
0 votes
1 answer
2k views
PXE boot problem using netboot.xyz "mounting tmpfs on /cdrom failed: Invalid argument"
I've set up my pfsense server with tftp to support PXE booting. I've configured it to boot the latest (as of posting) version of netboot.xyz. This works to a point, but I've tried loading a few Linux ...
2 votes
0 answers
590 views
Port Forwarding over VPN link cloud VPS (To bypass CG-NAT)
I have a radio setup on a 4G connection that utilises CG-NAT. This means I am unable to access the radio remotely using the supplied remote software. To get around this I have setup a cloud VPS ...
0 votes
0 answers
158 views
Access to pfsense wan interface by ip public
I have this diagram. I have a server(centos 7) with ip public and staic 1.2.3.4 on internet, I want when user send request to this public ip 1.2.3.4, this request pass my modem with not static ip ...
0 votes
1 answer
762 views
routing already in table when trying to add additional route to the same net
I have the following table $ netstat -r -4 | grep 33.0 192.168.33.0/24 192.168.29.4 UGS ovpns5 I would like to add additional route to the same network and get $ route add -net 192.168....