Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 pfsense unifi ?

views
     
TSMoogle Stiltzkin
post Jul 1 2019, 02:00 AM, updated 5y ago

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
searched the forum but info is stale or when i tried couldn't get to work. is there an updated guide for setting up pfsense to work with tmnut unifi confused.gif

Tried this but didn't seem to work icon_question.gif
https://highsecurity.blogspot.com/2011/08/p...d-tm-unifi.html

https://forum.lowyat.net/index.php?showtopi...=0&p=82418857&#



This post has been edited by Moogle Stiltzkin: Jul 1 2019, 12:28 PM
linkinstreet
post Jul 1 2019, 08:35 PM

Red Bull Addict
Group Icon
Moderator
9,275 posts

Joined: Jan 2005
From: KL. Best place in Malaysia. Nuff said

I presume the VLAN tagging is not working correctly? In any case, you can use this guide instead: https://www.blacktubi.com/guide/make-any-ro...-work-on-unifi/

It uses a TP Link switch (cost less than RM100) that you can use to separate the VLAN's beforehand. Hence you don't need to configure the VLAN in PFSense anymore
TSMoogle Stiltzkin
post Jul 2 2019, 10:46 AM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(linkinstreet @ Jul 1 2019, 08:35 PM)
I presume the VLAN tagging is not working correctly? In any case, you can use this guide instead: https://www.blacktubi.com/guide/make-any-ro...-work-on-unifi/

It uses a TP Link switch (cost less than RM100) that you can use to separate the VLAN's beforehand. Hence you don't need to configure the VLAN in PFSense anymore
*
ty for the reply notworthy.gif

actually i'm using pfsense on a QNAP TS-877



using virtual station, u install the pfsense with their img file.
https://www.qnap.com/solution/pfsense/en/


I tried following the instructions but didn't work. To be more precise, i got pfsense installed and i can login to the pfsense admin web UI to change settings. But cannot connect to WAN.


@9:10 , @20:40







The issue is either

1. i did not enter the tmnut ISP settings properly in pfsense
2. i did not setup virtual switches properly. Based on the video guide, they mentioned for the virtual switch for the WAN, to not give it a IP. they did not explain for the LAN virtual switch, but i followed the same instruction as mentioned.


I think a regular pfsense running on a NON nas hardware in NON vm would be much easier to setup. less complication. in fact i was considering this at one point for a pfsense router

QUOTE
Qotom Barebone PC Q355G4 with Intel Core i5 5200U Processor up to 2.2 GHz 4 Intel Gigabit NIC Mini PC Pfsense Firewall Router (if you opt for this route, make sure to reinstall pfsense from usb stick. don't trust the default install  :S )

$233

Crucial 8GB Single DDR3/DDR3L 1600 MT/S (PC3-12800) Unbuffered SODIMM 204-Pin Memory - CT102464BF160B

$49 ish


Samsung SSD 860 EVO 250GB mSATA Internal SSD (MZ-M6E250BW)

$79 ish
For now i just wanted to check that i at least did the ISP settings for pfsense correctly, to rule that out as the problem.


This is roughly the setting i did

user posted image

user posted image

user posted image


For dns i did it differently. i did 1.1.1.1 and 1.0.0.1 I also ticked for dns server over ride, and untick for dns forwarder. the gayeway i left blank and not touch that. Not sure if this is the correct setup. I was just following another guys video for the pfsense setup

user posted image




user posted image



In assignments, i went to vlan, added a VLAN 500 and assign that to the WAN port. I did not do a v600, because i don't intend to use the hypptv, also i'm not sure it would work on the QNAP. based on the QNAP guide, they mention 1 WAN and 1 LAN, nothing else. thats why i omitted the iptv vlan.

This post has been edited by Moogle Stiltzkin: Jul 2 2019, 03:34 PM
TSMoogle Stiltzkin
post Jul 2 2019, 11:39 AM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(linkinstreet @ Jul 1 2019, 08:35 PM)
I presume the VLAN tagging is not working correctly? In any case, you can use this guide instead: https://www.blacktubi.com/guide/make-any-ro...-work-on-unifi/

It uses a TP Link switch (cost less than RM100) that you can use to separate the VLAN's beforehand. Hence you don't need to configure the VLAN in PFSense anymore
*
i checked it out

QUOTE
In layman terms, using the Easy Smart Switch from TP-Link allow you to use any router in the market even those without Unifi mode in the firmware.


QUOTE
With the configuration, your TM Unifi modem (Fibre ONU) should be connected to port 1. Your wireless router should be connected to Port 3 and HyppTV should be connected to Port 5. I wouldn’t go in on how to setup your wireless router but you can setup your wireless router as usual with the PPPOE mode using your Unifi PPPOE ID and Password. Do not select any Unifi profile if available! Nothing need to be done on the HyppTV, it should work properly immediately.
that does sound amazing nod.gif

but it shows the switch is connected direct to the modem. is that safe ?

i use a switch, but i keep that behind my router. So it's not directly connected to the modem. Only the router is connected to the modem physically via ethernet.

in pfsense there is already a setting for adding a vlan.


This post has been edited by Moogle Stiltzkin: Jul 2 2019, 11:49 AM
linkinstreet
post Jul 2 2019, 12:56 PM

Red Bull Addict
Group Icon
Moderator
9,275 posts

Joined: Jan 2005
From: KL. Best place in Malaysia. Nuff said

QUOTE(Moogle Stiltzkin @ Jul 2 2019, 11:39 AM)
i checked it out
that does sound amazing  nod.gif

but it shows the switch is connected direct to the modem. is that safe ?

i use a switch, but i keep that behind my router. So it's not directly connected to the modem. Only the router is connected to the modem physically via ethernet.

in pfsense there is already a setting for adding a vlan.
*
I know that there is an option to tag VLAN in PFSense, but honestly it's not really intuitive. Mostly for my PFSense configuration, I let my switch handle the VLAN and just use PFSense for routing/firewall
th3game
post May 25 2020, 09:59 PM

Getting Started
**
Junior Member
235 posts

Joined: Sep 2014


hi guys...need help to setup unifi PPPoe with pfSense

i run the pfsense in VM fyi

below is my setup but the WAN_unifi failed to connect to PPPoE

anything i did is wrong here?

for hypptv i already tackle it using blacktubi guide here

Blacktubi guide

user posted image

user posted image

user posted image

user posted image

user posted image

user posted image

user posted image


Appreciate if anyone can help
th3game
post May 26 2020, 12:46 PM

Getting Started
**
Junior Member
235 posts

Joined: Sep 2014


done configured pfSense for tm unifi and it's so easy actually. Also got working hypptv as well

long way transition from default tm router —> asus —> mikrotik —> and now pfSense!

running pfSense as VM with proxmox host on bare metal server. running together are pihole,unifi controller, Home Assistant, netdata to monitor and heimdall as unified homepage

next time wanna try to configure pfblockerNG/pihole, ntopg and openVPN

biggrin.gif
TSMoogle Stiltzkin
post May 28 2020, 03:06 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(th3game @ May 26 2020, 12:46 PM)
done configured pfSense for tm unifi and it's so easy actually. Also got working hypptv as well

long way transition from default tm router —> asus —> mikrotik —> and now pfSense!

running pfSense as VM with proxmox host on bare metal server. running together are pihole,unifi controller, Home Assistant, netdata to monitor and heimdall as unified homepage

next time wanna try to configure pfblockerNG/pihole, ntopg and openVPN

biggrin.gif
*
how?? confused.gif

earlier you just said you tried a config (kudos for the pics), but you didn't mentioned what you changed to get it to work sad.gif

This post has been edited by Moogle Stiltzkin: May 28 2020, 03:07 PM
th3game
post May 28 2020, 09:37 PM

Getting Started
**
Junior Member
235 posts

Joined: Sep 2014


QUOTE(Moogle Stiltzkin @ May 28 2020, 03:06 PM)
how??  confused.gif

earlier you just said you tried a config (kudos for the pics), but you didn't mentioned what you changed to get it to work  sad.gif
*
create vlan 500 & user port WAN ( in my case vtne1)
look like this

user posted image

port assignment WAN (use the VLAN 500 u just created)
edit WAN port to use PPPoe, then put username & password there
then it will look like this

user posted image

go to PPP tab change the Interface(s)/Port(s) to ur WAN port (my case vtnet1)
it will look like this

user posted image

then u should get the unifi connect!

user posted image

enjoy pfSense..so powerful!

TSMoogle Stiltzkin
post May 30 2020, 01:53 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(th3game @ May 28 2020, 09:37 PM)
create vlan 500 & user port WAN  ( in my case vtne1)
look like this

user posted image

port assignment WAN (use the VLAN 500 u just created)
edit WAN port to use PPPoe, then put username & password there
then it will look like this

user posted image

go to PPP tab change the Interface(s)/Port(s) to ur WAN port (my case vtnet1)
it will look like this

user posted image

then u should get the unifi connect!

user posted image

enjoy pfSense..so powerful!
*
ty so much sir notworthy.gif appreciate the help.

by the way, any recommendations for pfsense router hardware?

i understand that you would want an intel nic right? for it to work proper for pfsense. but other than that i'm not quite sure.

I've kinda narrowed choices down to something like a Qotom ? because it's compact and is prebuilt. And it's cheaper than the netgate official pfsense routers. Unless you have a better suggestion?

I want to use VPN for 100mbps to 500 mbps internet connection hmm.gif with stuff like Suricata, pf snort, and possibly VM.

TSMoogle Stiltzkin
post Jun 12 2020, 04:33 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(th3game @ May 28 2020, 09:37 PM)
...
sorry to bother, i ran into trouble.

internet works but i noticed a lot of PPPOE disconnect, try, cannot connect, repeat spaming in pfsense logs.


I suspect the issue is how i configured the wan config and the vlan.

i'm using this to get internet working. not sure how to fix hmm.gif
user posted image

when i create this, i selected both the wan and vlan interfaces hmm.gif
user posted image

when i created the PPPOE

i'm using pfsense vm on a qnap nas fyi.


i spotted this

QUOTE
PfSense 2.3.2 with TM Unifi Installation & Configuration
by NOOR AMLI SAID·
NOVEMBER 8, 2016

This article will guide you through the basic installations on how to install and configure pfSense version 2.3.2 in a home network with working HyppTV on TM UNIFI

My Hardware
Pentium 4 2.8Ghz Processor, 2GB RAM, 80GB of HDD, CD-ROM
2 PCI Ethernet cards + 1 onboard ethernet port, and a pfsense ISO file available from http://nyifiles.pfsense.org/mirror/downloa...ASE-i386.iso.gz

Internet Connection i'm using.

TM UNIFI Advanced 30mb with HyppTV active. We'll setup VLAN 500 for PPPoE and VLAN 600 for HyppTV


Setup Summary
Onboard Ethernet (rl2) - LAN - 192.168.1.1/24. Connect to your home network
PCI Ethernet NIC1 (rl0)- WAN - VLAN500 & VLAN600. Connect your TM BTU here
PCI Ethernect NIC2 (rl1) - IPTV - Connect your HyppTV set top box here 


pfSense Installation
1- Download the image from pfSense download page. Here i am using i386 platform.
2- unzip downloaded gz file using 7zip then burn the ISO image on to CD using imgburn.
3- Now reboot target machine and set BIOS boot option to boot CDROM first.
4- Once boot into CD, select 1 to "Boot Multi User" then press Enter
5- Then press "I" to launch the installer
6- on Configure Console, choose "Accept these Settings"
7- on Select Task, choose "Custom Install"
8- Select disk to install pfSense
9- Choose This Disk
10- Then choose "Use this Geometry" and Format this disk.
11- Partition Disk then choose "Accept and Create"
12- Yes, partition ada0
13- Accept and Install Bootblocks
14- Choose the partition on top for Bootblock. Let it finish partition.
15- on Select Subpartition. Choose "Accept and Create"
16- Install Kernel menu, choose "Standard Kernel"
17- Reboot your machine

pfSense Configuration
1- Once boot up, on "Assign Interfaces" menu choose "y" on "Should VLANs be set up now?"
2- Our first PCI NIC (rl0) will be used as WAN, so type rl0 here
3- Enter VLAN tag : 500
4- Then select rl0 again and Enter VLAN tag :600
5- Press enter to proceed.
6- Enter WAN interface name: rl0
7- Enter LAN interface name: rl2

8- Enter Optional 1 interface name: rl1
9- Press Enter to proceed. Choose 'y' to proceed

VLAN Setup for TM UNIFI
By default IP address is set to 192.168.1.1, username:admin, password:pfsense
10- Login to your pfSense using another laptop. Set laptop IP address to be in 192.168.1.0 range
11- using web browser, type http://192.168.1.1 to access to pfSense login page.
12- Click into Interfaces / then VLANs. Make sure the setup is as below
13- Parent Interface: rl0
14- VLAN Tag : 500
15- then click Save

16- Then another VLAN
17- Parent Interface: rl0
18- VLAN Tag : 600

Interface Assignments PPPoE
20- Browse to Interface / Interface Assignments
20- From "available network ports" choose rl0_vlan500. Then click add
21- On "General Configuration"  Tick Enable interface, and set IPv4 Configuration type to PPPoE 
22- On PPPoE Configuration put in your TM UNIFI account username and password. Please contact TM Support Center for these details.
23- Then Click Save.


Interface Assignments HyppTV
24- Browse to Interface / Interface Assignments
25- Edit OPT1 Interface, change description to IPTV. Then click Save
26- From "available network ports" choose VLAN 600 in rl0
27- Click Add
28- Then browse to Interfaces / Bridges / Edit
29- Member Interfaces. Choose IPTV and VLAN600. Change description to IPTV-Bridge
30- Click Save

Firewall Setup
Now plug everything accordingly rl0-to TM Unifi BTU, rl1- to HyppTV Set top Box and rl2- to your home network switch
31- Browse to Firewall / Rules / LAN.
32- Make sure LAN Action=Pass, Protocol=Any
33- Browse to Firewall / Rules / IPTV
34- Set to IPTV Action=Pass, Protocol=Any
35- Set on IPTV Extra Options / Advanced Options. Tick Allow IP Options to pass.
36- Browse to Firewall / Rules / PPPoE
37- Set to PPPoE Action=Pass, Protocol=Any
38- Browse to Firewall / Rules / VLAN600
39- Set to VLAN600 Action=Pass, Protocol=Any
40- Set on VLAN600 Extra Options / Advanced Options. Tick Allow IP Options to pass.
41- Click save.
Enjoy PfSense with TM Unifi
https://www.facebook.com/notes/noor-amli-sa...11000716993320/



can the pfsense config be skipped? and jump straight to the setup in red highlight instructions instead? because the only thing i set at this part was set wan, lan and to enable dhcp for lan (begining to -end ip ranges for dhcp).
QUOTE
3- Enter VLAN tag : 500
4- Then select rl0 again and Enter VLAN tag :600

hmm.gif

This post has been edited by Moogle Stiltzkin: Jun 12 2020, 05:28 PM
TSMoogle Stiltzkin
post Jun 14 2020, 04:00 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
just an update, i figured out the solution. this worked for me, and i no longer get any pppoe errors in pfsense logs.

user posted image

QUOTE
okay i deleted my old config for this, then re-did it based on this guide. had to go back and forth until i got something that worked close enuff to the instructions.

instead of add interface for pppoe, that part i just edit the existing wan, and edited the general config for it, and added pppoe and the isp credentials save. then i check interface assignments, that this is now the wan which it should be.

so in interface assignments, i only have a wan and lan.


in vlan i only have that one vlan tag 500 entry bound to the wan port.

then i go to interface, wan, then edit it to PPPOe and add isp credentials, save.

Now in interface assignments there is a pppoe is bound to vtnet0.500 , this i replace the original wan interface "vnet0" with the new pppoe vtnet0.500 entry.


i then wipe logs and then i rebooted the router via cmd "5" normal reboot.

i confirm that the wan logs into isp, i have broadband access, and no pppoe spam so far.


This post has been edited by Moogle Stiltzkin: Jun 14 2020, 04:02 PM
Drian
post Jun 21 2020, 12:02 AM

Look at all my stars!!
*******
Senior Member
4,999 posts

Joined: Jan 2003


Question why pfsense and not opnsense?

TSMoogle Stiltzkin
post Jun 21 2020, 01:29 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(Drian @ Jun 21 2020, 12:02 AM)
Question why pfsense and not opnsense?
*
never looked at opnsense. is it better confused.gif



This post has been edited by Moogle Stiltzkin: Jun 21 2020, 01:30 PM
Drian
post Jun 21 2020, 01:52 PM

Look at all my stars!!
*******
Senior Member
4,999 posts

Joined: Jan 2003


QUOTE(Moogle Stiltzkin @ Jun 21 2020, 01:29 PM)
never looked at opnsense. is it better confused.gif


*
It seems simpler,cleaner looking UI and probably 98% similar to pfsense.
TSMoogle Stiltzkin
post Jun 21 2020, 03:33 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(Drian @ Jun 21 2020, 01:52 PM)
It seems simpler,cleaner looking UI and probably 98% similar to pfsense.
*
well the way people frame it, sounds like pfsense is more stable. i'm quite content with pfsense for now.

using pfblocker atm, but plan to add suricata soon nod.gif
maxguy
post Jul 24 2020, 01:19 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 24 2020, 01:21 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 24 2020, 01:22 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 24 2020, 01:23 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 24 2020, 01:25 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


the setup was on an apu4d4 = 4 i211AT LAN / AMD GX-412TC CPU / 4 GB DRAM / dual SIM by pc engines

https://www.pcengines.ch/apu4d4.htm
TSMoogle Stiltzkin
post Jul 25 2020, 03:12 AM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(maxguy @ Jul 24 2020, 01:19 PM)
user posted image
*
y google dns? i recommend you try 1.1.1.1 with 1.0.0.1 for cloudflare. You can then configure dot (dns over tls) and cloudflare claims no logging policy. this is better than what google promises.

That said cloudflare vpn policy is rather worrisome hmm.gif

QUOTE
the setup was on an apu4d4 = 4 i211AT LAN / AMD GX-412TC CPU / 4 GB DRAM / dual SIM by pc engines
oo what chasis you put it in confused.gif

This post has been edited by Moogle Stiltzkin: Jul 25 2020, 03:13 AM
maxguy
post Jul 25 2020, 12:01 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 25 2020, 12:03 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
maxguy
post Jul 25 2020, 12:30 PM

Enthusiast
*****
Senior Member
822 posts

Joined: Jan 2003


user posted image
syahbi
post Jan 20 2021, 05:41 PM

Getting Started
**
Junior Member
218 posts

Joined: Feb 2008
QUOTE(th3game @ May 26 2020, 12:46 PM)
done configured pfSense for tm unifi and it's so easy actually. Also got working hypptv as well

long way transition from default tm router —> asus —> mikrotik —> and now pfSense!

running pfSense as VM with proxmox host on bare metal server. running together are pihole,unifi controller, Home Assistant, netdata to monitor and heimdall as unified homepage

next time wanna try to configure pfblockerNG/pihole, ntopg and openVPN

biggrin.gif
*
I would like try pfsense also.... Now on MikroTik.. Is it true pfsense way more better than mikrotik

TSMoogle Stiltzkin
post Jan 21 2021, 10:19 AM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(syahbi @ Jan 20 2021, 05:41 PM)
I would like try pfsense also.... Now on MikroTik.. Is it true pfsense way more better than mikrotik
*
i used microtik long time ago. seemed alrite.

what i like about pfsense though it's solid. got packages and u can update. also they will patch any security flaws, so again, just update.

for packages, if u want, you can opt for suricata and pfblocker. i only use pfblocker because suricata is a bit annoying to manage, also i don't host anything from my network, so no ports open, so less needed.

if u bought something like an asus etc, the firmware updates usually only a couple of years before it eol then they ask u to buy a new router model. with pfsense, u don't have such a downside brows.gif

that said, asus does get some third party support like rt merlin, who does regularly releases security patches regularly. but that said, even he has a EOL, at which point u have to update to a newer model at some point.

also for pfsense u don't necessarily have to go qotom. but price wise, it seems to be one of the better options for a compact pfsense box, also it has no cooling issues. my old asus ac68u had a major cooling issue..... this is why i don't want to bother with those kinds of routers again puke.gif tbf, maybe newer asus models don't have this issue hmm.gif

This post has been edited by Moogle Stiltzkin: Jan 21 2021, 10:42 AM
HuorEarfalas
post Mar 19 2021, 12:06 PM

Casual
***
Junior Member
382 posts

Joined: Sep 2006


Anyone upgraded to pfsense 2.5 from 2.4.5? Any issues?
nicks
post Mar 19 2021, 01:59 PM

TC
*******
Senior Member
2,070 posts

Joined: Sep 2005
From: Sungai Buloh



I used pfsense 2.45 previously (last year starting MCO to be exact). It's good however due I'm using thin client PC and using realtek chip for ethernet i just can get roughly 250~300 Mbps. with special kmod installed i can get it stable without any disconnected network.

However, i change the setup using OpenWRT this year and it's awesome. No problem to achieve 800Mbps (yes I'm on 800 unifi packages) with same hardware. With cake SQM now bufferbloat rating (dslreports) giving A for rating.
satanhead2003
post Mar 19 2021, 04:34 PM

On my way
****
Senior Member
551 posts

Joined: Dec 2005
Upgraded to 2.5. much more improvement on tcp. Running on esxi vm n passthrough dual nic. Before, my other vm will get 400-500mbps. After upgrading other vm can get 700-800mbps in speedtest
TSMoogle Stiltzkin
post Mar 20 2021, 04:05 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
i upgraded pfsense, no issues.

obviously keep backups BEFORE updating.

Also DO NOT update package UNTIL after you first update your pfsense first.

You can update pfsense and packages from UI, but in terms of reliable updates, using the command line for pfsense is a more surer way to perform the updates


Ah_Huat
post Mar 22 2021, 04:33 AM

Getting Started
**
Junior Member
249 posts

Joined: Jan 2003
From: SG. Jarom


Hi..
i just have unifi 100m few week ago, i use pfsense connect to ONU (Fiberhome HG6240A) via PPPOE, internet is fine, but i have some problem with IPv6 .
when i boot up pfsense, it get a IP from TM and the DHCP6 also working, but after days ( i not sure how long .. seem over 24 hours) the DHCP6 will go "offline" , just now i found out the DHCP6 is offline , so i restart the ONU and pfsense , but this time it won't work (before this i also have this problem but fix it after i restart the ONU and pfsense), i get a new IP address from TM , but DHCP6 still offline ...
i am not very good at networking.
any pfsense sifu can help ?

this is my setting:
WAN:
user posted image
LAN:
user posted image

this is the status:

user posted image

this is my DNS setting:

user posted image

and this is the Log with the error:

user posted image

is my setting correct?

thanks.
TSMoogle Stiltzkin
post Mar 24 2021, 03:38 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
hm... i did not configure the ipv6 portion for pfsense. because last i heard ipv6 is not quite good for vpn for most part due to leaks. ip4 just works (for now), so i did not have the need to setup ipv6 just yet.

do you actually need ipv6 running? your internet should be fine without it.


https://www.networkworld.com/article/344520...n-breakout.html

https://www.vpnuniversity.com/learn/should-...pn-support-ipv6

https://www.itproportal.com/features/ipv6-y...er-supports-it/

https://www.expressvpn.com/blog/disable-ipv...vpn-protection/



i see that you are using google dns. thats fine, but i think the cloudflare dns is better in the sense they claim no log policy, so they periodically wipe dns history. google makes no such policy whatsoever.

https://www.techradar.com/sg/reviews/cloudflare-dns


DNS Over TLS On pfSense 2.4.5
https://www.youtube.com/watch?v=5mygS-TiT9c




This post has been edited by Moogle Stiltzkin: Mar 24 2021, 03:41 PM
PRSXFENG
post Mar 24 2021, 05:04 PM

Look at all my stars!!
*******
Senior Member
2,608 posts

Joined: Nov 2020


QUOTE(Moogle Stiltzkin @ Mar 24 2021, 03:38 PM)
hm... i did not configure the ipv6 portion for pfsense. because last i heard ipv6 is not quite good for vpn for most part due to leaks. ip4 just works (for now), so i did not have the need to setup ipv6 just yet.

do you actually need ipv6 running? your internet should be fine without it.
https://www.networkworld.com/article/344520...n-breakout.html

https://www.vpnuniversity.com/learn/should-...pn-support-ipv6

https://www.itproportal.com/features/ipv6-y...er-supports-it/

https://www.expressvpn.com/blog/disable-ipv...vpn-protection/
i see that you are using google dns. thats fine, but i think the cloudflare dns is better in the sense they claim no log policy, so they periodically wipe dns history. google makes no such policy whatsoever.

https://www.techradar.com/sg/reviews/cloudflare-dns
DNS Over TLS On pfSense 2.4.5
https://www.youtube.com/watch?v=5mygS-TiT9c
*
Personally I prefer Quad9 DNS, they're (soon) Switzerland based, similar policy to Cloudflare but they block malware domains.
There's also a unfiltered one should you choose to use that.

Also, they have a Malaysia server, which is pretty nice
TSMoogle Stiltzkin
post Mar 24 2021, 08:30 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
QUOTE(PRSXFENG @ Mar 24 2021, 05:04 PM)
Personally I prefer Quad9 DNS, they're (soon) Switzerland based, similar policy to Cloudflare but they block malware domains.
There's also a unfiltered one should you choose to use that.

Also, they have a Malaysia server, which is pretty nice
*
tbh i did not yet try quad, but privacy (best as possible at least sad.gif ) and performance is important to me. right now i use pfblocker own dns with cloudflare as backup. according to the tests these offer the best result to me

https://www.grc.com/dns/benchmark.htm
https://www.grc.com/dns/dns.htm
https://www.cloudflare.com/ssl/encrypted-sni/#dns-info
https://ipleak.net/


https://www.youtube.com/watch?v=xizAeAqYde4
https://www.youtube.com/watch?v=5mygS-TiT9c

This post has been edited by Moogle Stiltzkin: Mar 24 2021, 08:32 PM
w00t
post Mar 28 2021, 01:16 AM

Casual
***
Junior Member
318 posts

Joined: Jan 2003


Anybody here running pfSense 2.5.0-RELEASE with working pfBlockerNG ? Cannot seems to make it work. Installed with default wizard config many times also still not working. My current setup is Huawei B525 4G Router (DMZ for WAN to pfSense) to my barebone pfSense box. Internet is from DiGi.
TSMoogle Stiltzkin
post Mar 28 2021, 09:16 PM

Look at all my stars!!
*******
Senior Member
4,474 posts

Joined: Jan 2003
pfblocker works on latest
https://www.youtube.com/watch?v=xizAeAqYde4

Ash55
post Jun 10 2021, 11:57 PM

Getting Started
**
Junior Member
104 posts

Joined: Dec 2014
From: Axis Federation


QUOTE(th3game @ May 26 2020, 12:46 PM)
done configured pfSense for tm unifi and it's so easy actually. Also got working hypptv as well

long way transition from default tm router —> asus —> mikrotik —> and now pfSense!

running pfSense as VM with proxmox host on bare metal server. running together are pihole,unifi controller, Home Assistant, netdata to monitor and heimdall as unified homepage

next time wanna try to configure pfblockerNG/pihole, ntopg and openVPN

biggrin.gif
*
have you try OPNsense On unifi

 

Change to:
| Lo-Fi Version
0.0276sec    0.38    5 queries    GZIP Disabled
Time is now: 14th December 2025 - 04:32 PM