NAT / Re: Intermittent NAT failures
« on: February 16, 2018, 05:51:24 pm »
We're dealing with many thousands of states; I can't seem to find a count anywhere in the UI...

It's on the Dashboard, look again.

Here comes the issue... I cannot have 2 default gateways.

That's not an issue, that is normal. If you have more than one gateway for an address family you need to do policy based routing.

General Discussion / Re: New to Pfsense and pfblockerng
« on: February 15, 2018, 12:35:14 pm »
Read the tooltip of the green arrow.

Traffic Shaping / Re: Netflix bypassing traffic limiters?
« on: February 15, 2018, 10:23:47 am »
You need to understand how traffic shaping/limiting works:

There is no real way for pfSense to tell a remote server at what speed it should sent data. Instead once the transfer hits the limit pfSense will start dropping packets, in the hope that the remote server will notice it and slow down. As this is normal behaviour it works most of the time. But this entirely depends on the cooperation of the remote server, if that doesn't care for dropped packets it will simply continue to sent as much data as fast as possible.

So check that the data from Netflix goes through the right limiter. If it is and is and it's still pushing over the limits there is not much else you can do with pfSense. In that case the traffic would have to be limited on the other side of the DSL connection to prevent it from choking, and that means your provider has to configure a limiter on their side.

Installation and Upgrades / Re: Upgrade 2.2.6 to 2.3.5
« on: February 15, 2018, 09:45:43 am »
As it looks now the installation is already hosed, so a fresh install is the fastest and safest way to get back to a consistent system that won't barf on the next upgrade attempt.

Hardware / Re: Advise for storage on sg-4860
« on: February 15, 2018, 09:38:25 am »
I'm using pfBlockerNG for about 3 months now, with some IP and DNSBL lists and the cronjob runs hourly. All the pfBNG logs together are around 2 Mbyte in size. So I don't think you have to worry about that.

Code: [Select]
/var/log/pfblockerng: ls -l
total 491
-rw-r--r--  1 root  wheel   994321 Feb 15 16:35 dnsbl.log
-rw-r--r--  1 root  wheel     1736 Feb 15 16:35 dnsbl_error.log
-rw-r--r--  1 root  wheel     2002 Feb 15 16:00 extras.log
-rw-r--r--  1 root  wheel      161 Feb  6 23:00 maxmind_ver
-rw-r--r--  1 root  wheel  1036363 Feb 15 16:00 pfblockerng.log

Hardware / Re: Newbie to pfsence and need advice
« on: February 15, 2018, 08:39:50 am »
I was asking about a preconfigured box for my VPN. I need one that can handle at least 100Mbps. Thanks!

As has already been said, the only legal hardware with pfSense already installed comes from Netgate:

The configuration has to be done by yourself. If you are incapable or unwilling to learn how to do it you're simply in the wrong place here. Paid support might be willing to do it, but that's going to cost a lot of money.

Installation and Upgrades / Re: Kernel Panic error while installing
« on: February 15, 2018, 08:32:56 am »
Any ideas of what it could be will be appreciated.

It's just crappy hardware, replace it.

pfBlockerNG / Re: pfBlocker moving firewall rules to the top on interfaces
« on: February 15, 2018, 05:01:57 am » it's even still on the first page of this board.

General Questions / Re: SMTP notifications not working with gmail
« on: February 14, 2018, 11:21:34 am »
SMTP Port of E-Mail server: Tried both 465 and 587
Secure SMTP Connection: I leave it checked.

Set the port to 587 and uncheck "Secure SMTP Connection" it will then use StartTLS.

Deutsch / Re: DHCP und 2 Mac Adressen
« on: February 14, 2018, 09:07:17 am »
Folgende Problematik: Es geht um ein WLAN Netz welches 2,4 und 5GHz anbietet. Je nachdem was empfangstechnisch guenstiger ist, verbindet sich der Client entweder mit 2.4Ghz oder 5Ghz. 2 Netze heißt aber auch 2 Mac-Adressen beim Client.

Hat der Klient 2 WLAN Karten/Adapter, oder warum hat der unterschiedliche MACs bei den zwei Bändern? Alle mir bekannten Endgeräte benutzen die gleiche MAC unabhängig vom verwendeten Frequenzband.

webGUI / Re: GUI LAGG Configuration page issue
« on: February 11, 2018, 01:15:26 pm »
They do show up under the Interface Groups page...

Then they are assigned.

