software:pfsense
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
software:pfsense [2015/08/29 18:42] – superwizard | software:pfsense [2018/01/06 04:12] (current) – superwizard | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== | + | ====== |
+ | |||
+ | |||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | # This python (2.7) script provides a function to query the pfsense (v2.3) dhcp leases status page and | ||
+ | store the results for # ip, hostname, and mac as lists. A second function is also provided to export | ||
+ | the results in json to the file / | ||
+ | </ | ||
+ | |||
+ | ====== Firewall Rule Basics ====== | ||
+ | |||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | any - 0.0.0.0 to 255.255.255.255, | ||
+ | |||
+ | Single host or alias - Select this and enter one IP address (1.2.3.4, aa: | ||
+ | |||
+ | Network - Select this and enter a network and mask (10.99.0.0/ | ||
+ | |||
+ | LAN net - The subnet configured on the LAN interface under Interfaces > LAN. On pfSense 2.2+, this also includes IP alias networks on that interface. | ||
+ | |||
+ | LAN address - The IP address configured on the LAN interface under Interfaces > LAN | ||
+ | |||
+ | zzz Net / zzz address - Works the same as LAN above but for other interfaces (WAN, OPT1, OPT2, etc.) | ||
+ | |||
+ | PPTP clients - Automatically locate and use the addresses of PPTP clients | ||
+ | |||
+ | L2TP clients - Automatically locate and use the addresses of L2TP clients | ||
+ | |||
+ | This Firewall (self) - Any IP address assigned to any interface on this firewall (pfSense 2.2+) | ||
+ | </ | ||
+ | |||
+ | ====== Installing the Ubiquiti UniFi Controller Software on pfSense 2.2 ====== | ||
+ | |||
+ | From: http:// | ||
+ | |||
+ | < | ||
+ | Note: I am leaving this here for the reference and posterity, but for a variety of reasons, | ||
+ | I no longer recommend doing this. It is a neat hack, but tends to be a bit of a pain to live | ||
+ | with as you end up having to troubleshoot or reinstall it every time you update pfSense or | ||
+ | Unifi. When you can install it on a Raspberry Pi for less than $50, there' | ||
+ | to do this. | ||
+ | </ | ||
+ | |||
+ | |||
+ | ====== Automatically backup Pfsense | ||
+ | |||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | The script is secure and will only connect via SSH using SSH key authentication instead of passwords. | ||
+ | We use pfMb on Mac and Linux but it should work on any *nix under bash. | ||
+ | </ | ||
+ | |||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | It is very lightweight and easy to use this tool. It requires the Microsoft .NET framework 2.0 to be | ||
+ | installed on the machine from which you are running it. Extract the executable in the ZIP and run it | ||
+ | without parameters to see the help text which explains the options you have to run it:</ | ||
+ | |||
+ | |||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | pfSense keeps its configuration in one convenient XML document. A backup of this document can be saved | ||
+ | by going to Diagnostics > Backup/ | ||
+ | Before downloading, | ||
+ | RRD data from the backup file. | ||
+ | Restoring a configuration is just as easy, click Browse, locate the backup configuration file, then click | ||
+ | Restore Configuration | ||
+ | </ | ||
+ | |||
+ | From: https:// | ||
+ | |||
+ | |||
+ | From: http:// | ||
From: | From: | ||
+ | ====== PFSENSE BEHIND A ROUTER ====== | ||
+ | |||
+ | From: http:// | ||
+ | |||
+ | |||
+ | < | ||
+ | Trouble shooting: | ||
+ | Can pfsense ping router – NO WAN config error | ||
+ | Can pfsense ping pfsense client – NO – LAN config error / Client firewall | ||
+ | Can pfsense client ping pfsense – NO – LAN config error / Client firewall | ||
+ | Can pfsense ping 8.8.8.8 – NO – ASDL/CABLE router config error | ||
+ | Can pfsense client ping router – NO – NAT error | ||
+ | Can pfsense client ping 8.8.8.8 – NO – NAT error / ADSL / CABLE config error | ||
+ | Can pfsense client ping 8.8.8.8 – YES – All good | ||
+ | Can pfsense client load a website – NO – DNS Error – Check everything above is OK | ||
+ | Can pfsense client load a website – YES – Everything is working | ||
+ | </ | ||
+ | |||
+ | ====== PFsense System Advanced Notification SMTP configuration ====== | ||
+ | |||
+ | From: https:// | ||
+ | |||
+ | |||
+ | < | ||
+ | Now - guess what ... Exchange does support plaintext-logins when configured correctly, | ||
+ | but only using the method " | ||
+ | Re: Cannot send mails using office365 smtp server | ||
+ | « Reply #14 on: November 22, 2014, 10:05:07 pm » | ||
+ | Got it working! Issue was STARTTLS (and save before Test). | ||
+ | Thanks! | ||
+ | </ | ||
{{ : | {{ : | ||
Line 10: | Line 121: | ||
====== pfsense ipv6 with comcast ====== | ====== pfsense ipv6 with comcast ====== | ||
+ | |||
+ | From: http:// | ||
From: https:// | From: https:// | ||
Line 24: | Line 137: | ||
</ | </ | ||
+ | From: https:// | ||
+ | |||
+ | < | ||
+ | Comcast will let you request no more than a /60. 16 /64 subnets on a personal network should be | ||
+ | more than enough for most people. | ||
+ | |||
+ | Business class service may be able to request larger allocations, | ||
+ | anything from /64 to /60 only, depending on how many subnets you need (1 to 16, based on number of bits). | ||
+ | |||
+ | Because of pfSense' | ||
+ | IPv6 address for your router on your LAN. You set up "Track Interface", | ||
+ | you want to use (which will only be 0 if you request a /64, could be 0-F if you request a /60). The LAN | ||
+ | interface gets a SLAAC address based on the interface' | ||
+ | </ | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | |||
+ | {{ : | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | {{ : | ||
+ | |||
+ | {{ : | ||
====== CONFIGURING DHCP SERVER AND DYNAMIC DNS SERVICES ====== | ====== CONFIGURING DHCP SERVER AND DYNAMIC DNS SERVICES ====== | ||
Line 125: | Line 263: | ||
http:// | http:// | ||
====== Squid Configuration ====== | ====== Squid Configuration ====== | ||
- | |||
=== Cache management page === | === Cache management page === |
software/pfsense.1440873727.txt.gz · Last modified: 2015/08/29 18:42 by superwizard