Netgate SG-1000 microFirewall

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - pbnet

Pages: [1] 2 3 4
1
Here comes the issue... I cannot have 2 default gateways.

That's not an issue, that is normal. If you have more than one gateway for an address family you need to do policy based routing.

Would static routing work ?

Thanks,
Andy

2
@kpa

Here comes the issue... I cannot have 2 default gateways.
If I follow the article https://doc.pfsense.org/index.php/Using_IPv6_with_a_Tunnel_Broker and put interface OPT as default gateway, the clients from VLAN1 won't be able to use my ISP's IPv6.



 OPT2_TUNNELV6  OPT2  2001:470:1f1a:699::1  2001:470:1f1a:699::1  Interface OPT2_TUNNELV6 Gateway      
 WAN_DHCP6 (default)    WAN  fe80::1  fe80::1  Interface WAN_DHCP6 Gateway      
   WAN_PPPOE (default)    WAN  10.0.0.1  10.0.0.1  Interface WAN_PPPOE Gateway

Thanks,
Andy

3
@Gertjan

I know how it is...
I have a /64 for about 3 years now, since Digi (the main ISP in Romania) provides it.
Sadly, the move to /56 will come sometimes this year (no timeline defined).

Now back to our sheep (revenons a nos moutons :) )...
I can't seem to find a way to assign the /64 from Hurricane Electric to the second VLAN I have.
I only have a LAN tab, that points to VLAN1 and I need to et HE's V6 to VLAN2 (that is on a different NIC Card).

If I can't figure it out, I'll probably send them an e-mail.

@Community: any ideas on how to assign a specific NIC to HE V6 ?

Thanks,
Andy

4
Thanks Gertjan.

Well, if I get a /48 or /56 from HE.NET it will probably work.
Why: because I have 2 VLANs and would like to have IPv6 on both VLANs, which I can't do with a /64 from my ISP.
I'm open to any suggestions.

Thanks,
Andy.

5
@johnpoz

Quick question:
I have the following setup:
- WAN over PPPoE that offers both IPv4 and IPv6 (::/64)
- LAN (IPV4 DHCP, IPv6 using track WAN)
- LAN2 (different VLAN) - IPv4 DHCP

I tried to setup an HE.NET IPv6 TunnelBroker, and when setting up the IPv6 static IP on LAN2 (following the article: https://doc.pfsense.org/index.php/Using_IPv6_with_a_Tunnel_Broker, I get IP address overlapping - a bit normal since both IP addresses in the guide are in the same /64 if I read correctly).
Any idea ? Is my scenario even supported ?

Thanks,
Andy.

6
Packages / Can we run Squid both as a proxy and as a reverse proxy ?
« on: January 31, 2018, 02:21:08 am »
I want to start configuring a reverse proxy on PFSense to replace my aging Microsoft TMG.
Can I run both Squid Proxy (forward proxy) and Squid Reverse Proxy ? Or do you guys recommend a different reverse proxy ?

Thanks,
Andy.

7
IPv6 / Monitoring IPv6 WAN logs
« on: January 14, 2018, 09:12:13 am »
Hello,

I have native IPv6 from my ISP assigned though PPPoE with Prefix Delegation (they assign a /64).
This week the ISP upgraded the firmware on the ONT providing the connection and so far I encounter the following issue:
- PFSense WAN interface periodically loses its IPv6 IP.
First I suspected a port flap or something, but the uptime of the interface is in the range of days.

Is there a way I can find in PFSense logs when the interface lost its IPv6 address ?

Thanks a lot,
Andy

8
pfBlockerNG / Re: DNS Whitelist
« on: January 09, 2018, 02:24:59 am »
Thanks.
Managed to do it and whitelist the domains.


9
pfBlockerNG / DNS Whitelist
« on: January 08, 2018, 02:58:42 am »
Hello,

I've configured PFBlockerNG on my PFSense box and just noticed that the ASUS Download page doesn't allow me to download drivers anymore.
If I look in the DNSBL logs, I see:
DNSBL Reject HTTPS,Jan 08 10:57:35,etrk.asus.com

is there a way I can whitelist this FQDN in DNSBL ?

Thanks a lot for all your help and support.

Best regards,
Andy

10
DHCP and DNS / Re: Limit AAAA name resolution for specific hosts
« on: December 27, 2017, 03:45:49 am »
Thanks a lot!!! (again :) )

11
Hardware / Re: Dell R710 Port Flapping
« on: December 26, 2017, 03:11:11 pm »
Thanks  a lot for every hint provided.
So far all looks good


 WAN      Uptime: 4d 12:23:21   

12
DHCP and DNS / Re: Limit AAAA name resolution for specific hosts
« on: December 26, 2017, 03:09:54 pm »
Sorry to re-open the thread.
I've switched to DNS Resolver and unbound.
How do I make the same settings with unbound (DNS Resolver) ?

Thanks.

13
Hardware / Re: Dell R710 Port Flapping
« on: December 23, 2017, 04:22:22 am »
Done that.
So far I have: Uptime: 1d 01:33:12
Weird, since there is permanent traffic on that NIC, so it should not go into any sort of Power Management.
So far it works... I'll keep an eye on it...

Thanks for the hint.

14
Hardware / Re: Dell R710 Port Flapping
« on: December 22, 2017, 01:25:46 am »
Same issue.
It works for hours, then suddenly the port shuts down.
For example I watched more than 12 hours of Netflix without any issue, then suddenly, it happened.
Is there any fix to this or even some logs I could see to try to identify the cause?

Thanks,
Andy

15
Hardware / Dell R710 Port Flapping
« on: December 21, 2017, 08:09:50 am »
Hello,

I have a DELL R710 server (with 4 Broadcom NICs) running PFSense 2.4.2-RELEASE-p1 and experience port flapping on the NIC port assigned to VLAN1.
The setup is the following:

- bce0 --> WAN over PPPoe
- bce1 --> unused
- bce2 --> LAN (VLAN1) --> connected to a cisco SG200-26 Switch
- bce3 --> LAN (VLAN10) --> connected to the same cisco switch.

Randomly, port bce2 starts flapping for a couple of seconds. Sometimes it doesn't even recognize the LAN cable that is plugged in.

I've followed this article: https://doc.pfsense.org/index.php/Tuning_and_Troubleshooting_Network_Cards and created the loader.conf.local file in /boot:

kern.ipc.nmbclusters="131072"
hw.bce.tso_enable=0
hw.pci.enable_msix=0

The issue is less frequent, but still occurs.

I've tried connecting the LAN to a 100Mbps cisco switch (Old Catalyst) and the problem doesn't seem to occur.

Can anyone give me some advice ?

Thanks,
Andy

Pages: [1] 2 3 4