pfsense:install_pfsense:pfsense_configuration
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:install_pfsense:pfsense_configuration [2021/01/05 13:20] – [DNS Server Settings] peter | pfsense:install_pfsense:pfsense_configuration [2023/04/22 08:31] (current) – peter | ||
---|---|---|---|
Line 7: | Line 7: | ||
In **DNS Server Settings**: | In **DNS Server Settings**: | ||
- | * DNS servers: | + | * DNS servers: |
- | * Use Gateway: | + | * Use Gateway: |
* DNS Server Override: | * DNS Server Override: | ||
- | * Disable DNS Forwarder: | + | * Disable DNS Forwarder: |
- | * Click **Save**. | + | |
<WRAP info> | <WRAP info> | ||
Line 21: | Line 20: | ||
{{: | {{: | ||
+ | |||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 31: | Line 32: | ||
* Dashboard Columns: | * Dashboard Columns: | ||
- | * Click **Save**. | ||
<WRAP info> | <WRAP info> | ||
**NOTE: | **NOTE: | ||
</ | </ | ||
+ | |||
+ | {{: | ||
+ | |||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 49: | Line 53: | ||
* Allow Agent Forwarding: | * Allow Agent Forwarding: | ||
* SSH Port: **22**. | * SSH Port: **22**. | ||
- | * Click **Save**. | ||
{{: | {{: | ||
+ | |||
+ | * Click **Save**. | ||
<WRAP info> | <WRAP info> | ||
Line 61: | Line 66: | ||
</ | </ | ||
+ | |||
+ | |||
---- | ---- | ||
Line 73: | Line 80: | ||
* Firewall Maximum States: | * Firewall Maximum States: | ||
* Firewall maximum table entries: | * Firewall maximum table entries: | ||
+ | |||
+ | {{: | ||
In **Bogon Networks**: | In **Bogon Networks**: | ||
* Update Frequency: | * Update Frequency: | ||
- | * Click **Save**. | ||
<WRAP info> | <WRAP info> | ||
Line 89: | Line 97: | ||
</ | </ | ||
+ | |||
+ | {{: | ||
+ | |||
+ | |||
+ | * Click **Save**. | ||
+ | |||
Line 105: | Line 119: | ||
</ | </ | ||
+ | {{: | ||
In **Network Interfaces**: | In **Network Interfaces**: | ||
Line 113: | Line 128: | ||
* Suppress ARP handling: | * Suppress ARP handling: | ||
* Reset All States: | * Reset All States: | ||
+ | |||
+ | {{: | ||
* Click **Save**. | * Click **Save**. | ||
Line 128: | Line 145: | ||
* Battery Power: | * Battery Power: | ||
* Unknown Power: | * Unknown Power: | ||
+ | |||
+ | {{: | ||
In **Cryptographic & Thermal Hardware**: | In **Cryptographic & Thermal Hardware**: | ||
Line 137: | Line 156: | ||
**NOTE: | **NOTE: | ||
</ | </ | ||
+ | |||
+ | {{: | ||
In **Gateway monitoring**: | In **Gateway monitoring**: | ||
* State Killing on Gateway Failure: | * State Killing on Gateway Failure: | ||
- | * Skip rules when gateway is down: **Checked**. | + | * Skip rules when gateway is down: **Not Checked**. |
+ | |||
+ | <WRAP alert> | ||
+ | **ALERT: | ||
+ | |||
+ | One might think that with the check mark unchecked, means that it skips rules when the gateway is down. But no, it means just the opposite! | ||
+ | |||
+ | * By default, when a rule has a specific gateway set, and this gateway is down, a rule is created and traffic is sent to default gateway. | ||
+ | * This option overrides that behavior and the rule is not created when gateway is down. | ||
+ | |||
+ | The end result is that if the rules are routing your private traffic over a VPN, but then the VPN goes down for some reason, the system silently routes your traffic to the default network. | ||
+ | |||
+ | * Not even the firewall logs provide an alert. | ||
+ | * They even show the defined gateway rules still executing properly! | ||
+ | |||
+ | If there is a need to still allow a computer to access the internet anytime (even when VPN is down) then a rule will be needed in **Firewall -> Rules -> LAN** to allow the internal IP address there. | ||
+ | |||
+ | * If this access if only needed when the VPN is down, then put it in the LAN firewall rules list after the normal policy-routing rule for VPN traffic. | ||
+ | * That way it only comes into play when the VPN is down. | ||
+ | |||
+ | </ | ||
<WRAP info> | <WRAP info> | ||
**NOTE: | **NOTE: | ||
</ | </ | ||
+ | |||
+ | {{: | ||
+ | |||
* Click **Save**. | * Click **Save**. |
pfsense/install_pfsense/pfsense_configuration.1609852836.txt.gz · Last modified: 2021/01/05 13:20 by peter