pfsense:install_pfsense:pfsense_configuration
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:install_pfsense:pfsense_configuration [2021/01/05 13:39] – [DNS Server Settings] peter | pfsense:install_pfsense:pfsense_configuration [2023/04/22 08:31] (current) – peter | ||
---|---|---|---|
Line 7: | Line 7: | ||
In **DNS Server Settings**: | In **DNS Server Settings**: | ||
- | * DNS servers: | + | * DNS servers: |
- | * Use Gateway: | + | * Use Gateway: |
* DNS Server Override: | * DNS Server Override: | ||
- | * Disable DNS Forwarder: | + | * Disable DNS Forwarder: |
<WRAP info> | <WRAP info> | ||
Line 32: | Line 32: | ||
* Dashboard Columns: | * Dashboard Columns: | ||
- | * Click **Save**. | ||
<WRAP info> | <WRAP info> | ||
Line 39: | Line 38: | ||
{{: | {{: | ||
+ | |||
+ | * Click **Save**. | ||
---- | ---- | ||
Line 52: | Line 53: | ||
* Allow Agent Forwarding: | * Allow Agent Forwarding: | ||
* SSH Port: **22**. | * SSH Port: **22**. | ||
+ | |||
+ | {{: | ||
+ | |||
+ | * Click **Save**. | ||
<WRAP info> | <WRAP info> | ||
Line 62: | Line 67: | ||
</ | </ | ||
- | {{: | ||
- | |||
- | * Click **Save**. | ||
Line 144: | Line 146: | ||
* Unknown Power: | * Unknown Power: | ||
- | {{: | + | {{: |
In **Cryptographic & Thermal Hardware**: | In **Cryptographic & Thermal Hardware**: | ||
Line 160: | Line 162: | ||
* State Killing on Gateway Failure: | * State Killing on Gateway Failure: | ||
- | * Skip rules when gateway is down: **Checked**. | + | * Skip rules when gateway is down: **Not Checked**. |
+ | |||
+ | <WRAP alert> | ||
+ | **ALERT: | ||
+ | |||
+ | One might think that with the check mark unchecked, means that it skips rules when the gateway is down. But no, it means just the opposite! | ||
+ | |||
+ | * By default, when a rule has a specific gateway set, and this gateway is down, a rule is created and traffic is sent to default gateway. | ||
+ | * This option overrides that behavior and the rule is not created when gateway is down. | ||
+ | |||
+ | The end result is that if the rules are routing your private traffic over a VPN, but then the VPN goes down for some reason, the system silently routes your traffic to the default network. | ||
+ | |||
+ | * Not even the firewall logs provide an alert. | ||
+ | * They even show the defined gateway rules still executing properly! | ||
+ | |||
+ | If there is a need to still allow a computer to access the internet anytime (even when VPN is down) then a rule will be needed in **Firewall -> Rules -> LAN** to allow the internal IP address there. | ||
+ | |||
+ | * If this access if only needed when the VPN is down, then put it in the LAN firewall rules list after the normal policy-routing rule for VPN traffic. | ||
+ | * That way it only comes into play when the VPN is down. | ||
+ | |||
+ | </ | ||
<WRAP info> | <WRAP info> |
pfsense/install_pfsense/pfsense_configuration.1609853997.txt.gz · Last modified: 2021/01/05 13:39 by peter