Visit the Forums
Register Now!

User Login


Forum Topic

Unified PFSense users... Pasok!!!!

  • ang masakit lang kasi sa youtube is CDN based sya so hindi mo sya ma lil-limit (technically you can but it will be very messy) with just pfsense only alone (no package reliance).

    one thing you can do to limit it is using squid proxy (no need for caching, just a regular proxy server). marami naman guide sa google how to bandwidth limit youtube using squid.

    -- edited by polka on Nov 11 2016, 07:51 AM
  • my recent experience with pfsense

    scenario: setup a local home network router using the spare parts that my client had

    * Intel D510MO Pinetrail based ATOM board
    * 4GB od DDR2 RAM
    * a slick case and pico PSU (all bought from lazada as my client said)
    * a 8GB USB Stick full install pfsense (with logging written on ram only and basic stock config, no proxy caching)
    * U.Fl to RP-SMA WiFi antenna adapter (bought from lazada as well, meron available locally pero sobrang mahal, 450 each wag na oi compating to lazada listing which is cheapest is 320pesos per pair).
    * Atheros 9285 mini pcie wireless card
    * Intel PRO 1000MT Dual port PCI land card

    - Assembled it within 10minutes all went good until I bump to these issues:

    * For some reason built-in realtek card doesnt work (even with system tunables that I set and disable TCP offloading), I also noticed that the card is not linking to gigabit link speed (randomly stuck at 10 or 100mbps link speed)

    Fix: I remembered with someone who said here in TPC that he was having issues with same motherboard with onboard LAN or vice versa? doesnt work on pfsense and setting the Storage controller from IDE to AHCI fixed it immediately. (who ever you are thanks!)

    * using the builtin mini PCI-e wireless card slot to fit in the Atheros wireless card, installed the antenna cables and whatsnot and encountered with a bunch of issues. 1 is some wifi devices cant connect through it and some do, I adjust the Key setting I think to Pre-Shared key or something and that fix the issue, 2 I get a lots of ath_wlan0 warning about ( ath0_wlan0: discard frame w/o leading ethernet header (len 6 pkt len 6)) 8 of this errors in syslog per 3-4 minutes, the fix is set the regulatory and country to default. (meh I just want to follow the Philippines regulation regarding wifi but this prevents me from doing it so meh).

    After that, all went smooth na.

    - Set up the Wireless card to have 2 SSID one for Private use and one for public use with captive portal. So lahat ng gustong maki gamit ng wifi nila kailangan nilang bumili ng coupon code sa kanila.

    - Average power consumption of the unit is 18watts at idle 24watts at full load. :)
  • Post deleted #11810657
  • normal ba na tumaas ang latency both LAN IP at Router IP pag may naka traffic shaping?
  • nope, traffic shaping #1 goal is to minimize latency packet loss between gateway and services, or maybe the ICMP is not in high priority kaya tumataas yung ping peero kung yung ping mo is mismog local LAN IP ng pfsense dapat <1ms lang yan unless naka wifi ka which is norm na yung 1-15ms with high jumps of 200-1k+ms.
  • nope, traffic shaping #1 goal is to minimize latency packet loss between gateway and services, or maybe the ICMP is not in high priority kaya tumataas yung ping peero kung yung ping mo is mismog local LAN IP ng pfsense dapat <1ms lang yan unless naka wifi ka which is norm na yung 1-15ms with high jumps of 200-1k+ms.

    un nga pinag tataka ko,
    tumataas yung ping ng local ip ni pfsense kasabay ng wan ip nya, kapag nag i internet,
    try ko i adjust yung ICMP nya,

    eto yung ping ko, 1ms idle lang yan, pero pag nag browse/download na nag iiba na.

    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=411ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=64ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=348ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=99ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=494ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=467ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=484ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=233ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=665ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=483ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=484ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=489ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=472ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=12ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=470ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=317ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=451ms TTL=64
    Reply from 192.168.1.1: bytes=32 time=114ms TTL=64

    -- edited by dawinsm on Nov 21 2016, 07:08 PM
  • pag ganyan na its either driver issue yan ng freebsd or defective NIC.
  • pag ganyan na its either driver issue yan ng freebsd or defective NIC.


    try ko palitan yung NIC, kinuha ko lang kasi yon sa mga spare parts

    pero yung system ko, base naman sa dashboard kayang kaya naman nya.

    <click here for link>
    Intel D945GCLF2 Essential Series Mini-ITX DDR2 667 Intel Graphics Integrated Atom Processor Desktop Board

    Mini-ITX /micro-ATX compatible (6.75 inches by 6.75 inches)
    Integrated dual-core Intel Atom processor 330 with a 533 MHz system bus
    One 240-pin DDR2 SDRAM Dual Inline Memory Module (DIMM) sockets
    Intel 945GC Express Chipset and Intel I/O Controller Hub 7 (ICH7)
    Intel Graphics Media Accelerator 950 & S-video output support

    -- edited by dawinsm on Nov 22 2016, 10:30 AM
  • guys good am to all. sino po user ng openvpn. Ask ko lang if ever connected kayo via vpn nakakapag-browse pa din kayo sa internet?
  • ^saan ba naka setup yung openvpn? sa mga client pc/gadgets ba or sa mismong pfsense firewall.

    pag sa mga pc/gadgets, yes openvpn still works as expected, and I dont see why it wont work, unless there a firewall rule that specifically block that kind of traffic.

    pag sa firewall mismo (pfsense) then it depends but by default, lets assume you sucessfully connected to a OpenVPN conenction, this doesnt mean routed na lahat automatically yung traffic mo sa vpn, all traffic is still routed to your wan, to reroute the traffic of your lan network to openvpn or maybe specific devices lang ang dadaan sa openvpn ,etc.... you need to create a rule for that under LAN tab or on a network you want it to implement to.

    -- edited by polka on Nov 23 2016, 12:12 PM
  • pfsense 2.3.2 at openvpn client sa pc...
  • ^if youre connected to VPN at bigla nawalang ng connection sa internet yung computer mo, wala na kinalaman yung pfsense dyan since ang nakikita lang ng pfsense is connected ka sa vpn connection mo.

    saka ko lang iisipin na pfsense ang issue kung hindi ka talaga maka connect sa VPN, but in your case your connected pero wala kang internet connection after you get connected to your VPN.

    with that case contact mo yung VPN provider mo since they were the one who is responsible for that kind of thing.
  • Sino po nag one on one tututorial dito pa pm naman. for net shop and captive portal. paki delete nalang po admin if bawal.
  • @polka

    nadali din boss.. meron pala option dun sa openvpn na block dns.

    ayun gumana na din...
  • Good day!

    Sino dito may hands on experience sa pag setup ng OpenVPN using PFsence na napagana??
    paturo naman, thanks!