pfsense:about_pfsense
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pfsense:about_pfsense [2020/11/27 14:29] – [VPN] peter | pfsense:about_pfsense [2020/11/27 19:34] (current) – peter | ||
---|---|---|---|
Line 39: | Line 39: | ||
* NAT Reflection – in some configurations, | * NAT Reflection – in some configurations, | ||
- | ---- | ||
- | ===== NAT Limitation | + | <WRAP info> |
+ | **NAT Limitation** | ||
PPTP / GRE Limitation – The state tracking code in pf for the GRE protocol can only track a single session per public IP per external server. | PPTP / GRE Limitation – The state tracking code in pf for the GRE protocol can only track a single session per public IP per external server. | ||
- | This means if you use PPTP VPN connections, | + | This means if you use [[http:// |
A thousand machines can connect simultaneously to a thousand different PPTP servers, but only one simultaneously to a single server. | A thousand machines can connect simultaneously to a thousand different PPTP servers, but only one simultaneously to a single server. | ||
Line 54: | Line 54: | ||
A solution for this is currently under development. | A solution for this is currently under development. | ||
+ | |||
+ | </ | ||
---- | ---- | ||
Line 99: | Line 101: | ||
==== IPsec ==== | ==== IPsec ==== | ||
- | IPsec allows connectivity with any device supporting standard IPsec. | + | IPsec allows connectivity with any device supporting standard IPsec. |
+ | |||
+ | This is most commonly used for site to site connectivity to other pfSense installations, | ||
+ | |||
+ | It can also be used for mobile client connectivity. | ||
==== OpenVPN ==== | ==== OpenVPN ==== | ||
- | OpenVPN is a flexible, powerful SSL VPN solution supporting a wide range of client operating systems. | + | OpenVPN is a flexible, powerful SSL VPN solution supporting a wide range of client operating systems. |
+ | |||
+ | See the [[http:// | ||
==== PPTP Server ==== | ==== PPTP Server ==== | ||
- | PPTP is a popular VPN option because nearly every OS has a built in PPTP client, including every Windows release since Windows 95 OSR2. See this [[http:// | + | PPTP is a popular VPN option because nearly every OS has a built in PPTP client, including every Windows release since Windows 95 OSR2. |
+ | |||
+ | See this [[http:// | ||
---- | ---- | ||
Line 115: | Line 125: | ||
===== PPPoE Server ===== | ===== PPPoE Server ===== | ||
- | pfSense offers a PPPoE server. | + | pfSense offers a [[http:// |
- | For more information on the PPPoE protocol, see this [[http:// | + | A local user database can be used for authentication, |
---- | ---- | ||
Line 137: | Line 147: | ||
===== Real Time Information ===== | ===== Real Time Information ===== | ||
- | Historical information is important, but sometimes it’s more important to see real time information. | + | Historical information is important, but sometimes it’s more important to see real time information. |
+ | |||
+ | SVG graphs are available that show real time throughput for each interface. | ||
+ | |||
+ | For traffic shaper users, the **Status -> Queues** screen provides a real time display of queue usage using AJAX updated gauges. | ||
+ | |||
+ | The front page includes AJAX gauges for display of real time CPU, memory, swap and disk usage, and state table size. | ||
---- | ---- | ||
Line 163: | Line 179: | ||
===== Captive Portal ===== | ===== Captive Portal ===== | ||
- | Captive portal allows you to force authentication, | + | [[https:// |
+ | |||
+ | This is commonly used on hot spot networks, but is also widely used in corporate networks for an additional layer of security on wireless or Internet access. | ||
+ | |||
+ | The following is a list of features in the pfSense Captive Portal: | ||
* Maximum concurrent connections – Limit the number of connections to the portal itself per client IP. This feature prevents a denial of service from client PCs sending network traffic repeatedly without authenticating or clicking through the splash page. | * Maximum concurrent connections – Limit the number of connections to the portal itself per client IP. This feature prevents a denial of service from client PCs sending network traffic repeatedly without authenticating or clicking through the splash page. | ||
Line 170: | Line 190: | ||
* Logon pop up window – Option to pop up a window with a log off button. | * Logon pop up window – Option to pop up a window with a log off button. | ||
* URL Redirection – after authenticating or clicking through the captive portal, users can be forcefully redirected to the defined URL. | * URL Redirection – after authenticating or clicking through the captive portal, users can be forcefully redirected to the defined URL. | ||
- | * MAC filtering – by default, | + | * MAC filtering – by default, |
* Authentication options – There are three authentication options available | * Authentication options – There are three authentication options available | ||
* No authentication – This means the user just clicks through your portal page without entering credentials | * No authentication – This means the user just clicks through your portal page without entering credentials | ||
Line 190: | Line 210: | ||
pfSense includes both DHCP Server and Relay functionality. | pfSense includes both DHCP Server and Relay functionality. | ||
+ | |||
+ | ---- | ||
+ | |||
+ | ===== References ===== | ||
+ | |||
+ | https:// | ||
pfsense/about_pfsense.1606487340.txt.gz · Last modified: 2020/11/27 14:29 by peter