Netgate SG-1000 microFirewall

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Topics - Gil

Pages: [1] 2
OpenVPN / Android client routes all traffic via VPN
« on: Yesterday at 05:56:06 am »
After performing client exports for windows and for Android,
I find that Windows allows internet browsing whilst an OpenVPN connection to the Server is active,
but the Android client does not.
Do I need to add something to the ovpn config file for Android?

OpenVPN / Tap restrictions
« on: Yesterday at 05:26:56 am »
I have a Bridge between an OpenVPN (Tap) and the Lan ports (for multicast purposes).
I would like to block the OpenVPN Tap clients from the pfSense server's web page.
Is that possible?

OpenVPN / WAN modem nat
« on: February 17, 2018, 04:34:31 am »
Is there a convenient way to view the settings / web page of the remote 4g or Adsl modem via OpenVPN?
I can do via a Nat if I am directly connected to remote pfsense router;
However I don't always have a publicly accessible IP address on 4g.
These routers run a client to call in to the centre & I want to get to the 4g modem to see rssi details.
Perhaps SNMP?

OpenVPN / OpenVPN Status Latency
« on: January 23, 2018, 09:13:54 pm »
Is there a setting to tune the OpenVPN status reporting?
I would like to when an OpenVPN connection has dropped out within 10 seconds or less; through the GUI Dashboard.

General Discussion / Platform Pie Chart - Poll
« on: January 10, 2018, 07:40:21 pm »
Wondering what is percentage of users are on each variety of paltforms?

a) Netgate appliances
b) Old hardware
c) Purpose built Hardware
d) Virtual
e) Other SBC
f) Other

General Questions / Backups without certificates
« on: January 02, 2018, 04:55:13 pm »
Is it possible to create backups without the certificates included.
Thinking about sharing configs with a work colleague, and keeping security.

The obvious thing to do seems to be to manually edit the xml file.


Official pfSense Hardware / Purchasing Support
« on: December 15, 2017, 06:11:51 am »
I like to think I am paying my dues to a fantastic system.
But paying double for a single fail_over solution because it has two Netgate ID's is a bit rich.
I bought a SG-4860-2000-PF to provide a High Availability fail-over and supported Netgate by purchasing their hardware.
At the end of the day, it is a single end server, sold as such - but requires 2 subscriptions to enable support?
Perhaps each unit can be separated and re-purposed, is that the issue?

Hardware / Modem Reset
« on: December 12, 2017, 03:14:30 am »
Has anyone developed a power reset switch to automatically reset a 4G modem (or ADSL) on ping fail?
My thoughts are to have a pfSense router (eg: SG-1000 or APU) which runs a Cron Ping and latching power switch on the ISP Modem supply.
I have had a situation where the 4G Modem froze and so did it's internal Ping reset facility. The APU router was happily doing what it could - but of course I could't contact it (remotely)


Firewalling / NAT through to Webdav FreeNAS
« on: December 10, 2017, 03:47:34 pm »
I have an IoT device that can only deliver secure files via Webdav.
I intend on setting up a FreeNAS Box with Webdav shares and I am curious as to the most secure way to push through my pfSense Firewall to the FreeNAS.
Is it advisable to push a NAT on a single port and enable Webdav directly through?


OpenVPN / OpenVPN Logs & Verbosity
« on: December 06, 2017, 05:37:36 pm »
I have set verbosity at 3 (recommended), but have the OpenVPN Logs filled with:

Dec 7 10:18:12   openvpn   8767   MANAGEMENT: Client disconnected
Dec 7 10:18:12   openvpn   8767   MANAGEMENT: CMD 'status 2'
Dec 7 10:18:12   openvpn   8767   MANAGEMENT: Client connected from /var/etc/openvpn/server1.sock

which is unhelpful when fault finding through the last 50 logs.

Is there a way to omit  this without setting verbosity to 1?

Installation and Upgrades / SG-1000 fail after 2.4.2 upgrade
« on: December 05, 2017, 03:42:52 pm »
I have an SG-1000 that has failed after 2.4.2 upgrade.

I have tried to reflash it with the recovery drive via the OTG port, but I don't get the option prompt at the console.
The console shows attempts to rebuild, and stops at:
"ERROR: Impossible to mount filesystem, use interactive shell to attempt to recover it"

The only option I get is to hit any key to stop autoboot

I can issue basic commands such as reboot.

Any ideas?

webGUI / Typo error
« on: November 28, 2017, 07:42:14 pm »
Little Typo error in 2.4.2 OpenVPN Server DH Parameter Length - More info message:

"new or stronger paramater sets."

OpenVPN / Routed Error: - impossibly lacks ifp
« on: November 23, 2017, 06:47:19 am »
I have several OpenVPN services on my server.
The latest one I am attemping to configure will not route to the client correctly.

I have a Peer2Peer Tunnel (tun tcp) Network between my server ( and client (

I can route from the client to the server (to, but I can NOT route from the server to client (
However; I can get to the client from the server on - which is the address allocated in the "CSC" Client Specific Overrides.

The route is not being added correctly even though it is in the OpenVPN server "Custom Options" - as follows:
When I add this route; the assigned OpenVPN Gateway goes offline.

The System Logs / System / Routing show the following:

routed   89460   static route (mask 0xffffff00) --> impossibly lacks ifp

Firewall rules are: Everything open under LAN, and everything open under OpenVPN .

Official pfSense Hardware / SG-1000 <--> SG-3100 ..... Gap
« on: November 11, 2017, 06:09:03 am »
Are there any plans for a 3 or 4 port device more akin to the APU devices.
I want to replace multiple APU routers for the future 2.5 roll out.
I have specific size restrictions and the SG-3100 is to large.

Should I look at Protectli 4 Port E3845 devices? (or similar)
Would like to buy Netgate and support the project.

webGUI / Traffic Graphs
« on: November 06, 2017, 10:56:31 pm »
Error: SyntaxError: Unexpected token < in JSON at position 0

I get this error after a few minutes (V2.4.1)

Pages: [1] 2