Recommended Posts

Right!

It looks like we are getting somewhere now.

I setup SquidGuard as your instructions above, stopped and restarted squidguard and now it appears everything is working.

At the bottom of the long BLOCKLIST i choose allow all for now until i can figure out how to apply a certain category to only 1 IP.

Your an amazing chap Bud :D Thanks again.

That would be an ACL, let me take a look at how you do that.

edit:

Here you go, create a group ACL, put in your kids IP as source, I used 192.168.1.40

post-14624-0-70605800-1300226076.jpg

Then I created a new category, kids - and put in yahoo.com

post-14624-0-36338200-1300226104.jpg

In the group ACL block your new custom cat or categories you want - and shazam

in my virtual machine that is on 192.168.1.40 can not access yahoo.com

But my host machine on .100 can.

post-14624-0-46501600-1300226175.jpg

  • Like 2

--Budman

Spent a while lat night looking at the different options in SQUIDGUARD and managed to get an ACL setup for 192.168.33.253 which worked, so after all your help i have finally got it working and i think i now know what i was doing wrong, when specifying to use the blocklist i wasn't telling it to use the LOCAL database also i hadn't setup any categories for it to block or deny so it looks like it was BLOCKING everything by default.

I am going to take the screenshots you posted above and make a reference guide for the future, i also noticed a CONFIG BACKUP package which i can install to backup the configuration of the firewall which may be worth doing.

Earlier on at the start of this thread you also mentioned in an edit so i didn't catch it until i was reading back over the thread but you said something about DNS and not using the ISP DNS and you also said something about installing UNBOUND which i can't find so i have either read something wrong done something wrong or need to do something i haven't done. -- I also notice that on the general settings page i have the box ticked which says something about getting DNS from the ISP.

Thanks again for all your help

:woot: :woot: :woot:

yeah you can run your own recursive nameserver, install the unbound package

post-14624-0-83209600-1300281644.jpg

So my clients never talk to my isp dns, or forward a dns request -- pfsense is the dns server. It talks to roots directly, etc. You can use dnssec this way.

maybe you play with what you got working for awhile - and we can move on to DNS at a later date ;)

Ok -- come on now.. Who rep'd a post that says in essence "Im using 2.0 RC1"

But the 3 pages of posts where I walk him through every step, tell him what he did wrong and post screenshots, etc. etc. Gets none??

Something wrong with this picture! ;)

  • Like 1

Ok -- come on now.. Who rep'd a post that says in essence "Im using 2.0 RC1"

But the 3 pages of posts where I walk him through every step, tell him what he did wrong and post screenshots, etc. etc. Gets none??

Something wrong with this picture! ;)

Ahaha thats actually kind of funny. Crazy world we live in eh Budman, what with earthquakes and Tsunamis and all.

Perhaps its PfSense developers trying to push their latest release :shiftyninja: :shiftyninja:

:p

Im not knocking you getting a rep - good for you(but did you earn it?), it just did not make sense to me - I got a PM that he rep'd me for the help I did which is great.. To be honest I could care less, just here to help people - I have gotten my fair share of rep around the forum - it feels good when people upvote you - don't get me wrong. But as long as the post help the OP or the next guy is what matters.

I just found it odd that someone rep'd a post that I had already posted he should do a few times - I agree the 2.0 line is more than stable enough to run in a home, or even a production environment to be sure. And quite a few +'s to doing so.. But the 1.2.3 line REALLY STABLE and great as well. But I like to be on the cutting edge myself - and 2.0 makes more sense with the ipv6 suff I have been playing with lately!!

But come on -- who stops by and reps a post like yours, which is a great kick in the ass for the OP mind you to move to the latest version - dont get me wrong.. But they clearly do not understand what the rep system is suppose to do.. You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem. And sorry but you run 2.0 does not fall into that area no way no how :)

Maybe you have great other posts? But to me I look at 631 posts in like 7 years = LURKER!! Not even part of the community at all. Sorry!

The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote, etc. But I do feel you should be able to click to see who rep'd -- can you???

  • Like 1

Im not knocking you getting a rep - good for you(but did you earn it?), it just did not make sense to me - I got a PM that he rep'd me for the help I did which is great.. To be honest I could care less, just here to help people - I have gotten my fair share of rep around the forum - it feels good when people upvote you - don't get me wrong. But as long as the post help the OP or the next guy is what matters.

I just found it odd that someone rep'd a post that I had already posted he should do a few times - I agree the 2.0 line is more than stable enough to run in a home, or even a production environment to be sure. And quite a few +'s to doing so.. But the 1.2.3 line REALLY STABLE and great as well. But I like to be on the cutting edge myself - and 2.0 makes more sense with the ipv6 suff I have been playing with lately!!

But come on -- who stops by and reps a post like yours, which is a great kick in the ass for the OP mind you to move to the latest version - dont get me wrong.. But they clearly do not understand what the rep system is suppose to do.. You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem. And sorry but you run 2.0 does not fall into that area no way no how :)

Maybe you have great other posts? But to me I look at 631 posts in like 7 years = LURKER!! Not even part of the community at all. Sorry!

The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote, etc. But I do feel you should be able to click to see who rep'd -- can you???

now you're making something out of nothing.. and now making this personal. You say you dont care, yet you make a post ALL about it, and NOW you target me, specifically the bold part.

I've always respected your knowledge of things Budman, but this is disrespectful to something I havnt done. Thanks for derailing this, and if you have a problem with my "post count" and calling me a lurker. PM NEXT TIME.

Insulted. You tend to do that a lot.

Ridiculous BudMan.

Also, stop being concerned about "message board rep" it means nothing in life. I'm not going to forget this next time I see you being targeted... which I have seen before in other posts. Why should I rep your posts now? When I have plenty of times in the past...

I might have worded that a bit harsh.. :blush:

I did not mean anything bad directed at you to be honest, but more at the person that rep'd you.. The lurker comment was uncalled for, sorry!!

This is more what should of stood out - and clearly not direct towards you since you can not rep your own posts.

"You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem"

"The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote,"

The beers and irish whisky I had been consuming since 2pm might have had a bit to do with my lurker comment? :blush:

I might have worded that a bit harsh.. :blush:

I did not mean anything bad directed at you to be honest, but more at the person that rep'd you.. The lurker comment was uncalled for, sorry!!

This is more what should of stood out - and clearly not direct towards you since you can not rep your own posts.

"You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem"

"The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote,"

The beers and irish whisky I had been consuming since 2pm might have had a bit to do with my lurker comment? :blush:

Apology accepted.

  • 1 month later...

Pfsense Rocks.. I am running 2.0 RC2 now.. Did the OP solve this issue in the end ?

And Glad you 2 kissed and made up ;-)

Seriously tho... got to see the funny side of all this..

Take care.

Phillip.

Yes he did get it worked out. His internet access problem was fixed when he turned his gateway device into just a modem - see earlier in the thread

"I changed the DG834G router into modem only mode which makes it into a modem only device"

Then to his accessing his modems private IP - that was fixed too, he had the wrong virtual IP set on his wan interface to allow talking to his modems internal private IP. He had set the virtual ip to the same as his modems IP 192.168.10.1 vs .2

we used teamviewer and I got on his box so I could look at his pfsense config - once he corrected that it worked just fine.

The link to the pfsense doc is earlier in the thread, but for quick reference here it is again

http://doc.pfsense.org/index.php/Accessing_modem_from_inside_firewall

I dont want to knock anyone or PFsense, but with all the trouble the OP had, I think he might of had an easier time going with smoothwall, compared to PFsense (at least to me), it may have been easier to configure OOB. Budman you sure do have a lot of patience :) Sometimes it can be difficult trying to explain stuff to people without being able to be physically there to show someone, I have to do it daily to people deployed overseas in hot zones.

The user most likely would of had issues with any router distro to be honest.. His "modem" was not a modem - it was a gateway (modem/router combo) doing NAT. And he setup his LAN network on pfsense to be the same as what his gateway was using as its private network 192.168.33/24 -- so he had the same network on both his lan and his wan of his pfsense box.

I have chatted with him quite a bit on PM, he is trying but his basic understanding of networking needs work ;)

But he is getting there - and last I heard very happy with his setup now that he got it figured out in his head what he was doing wrong.

Nothing wrong with smoothwall -- its a great firewall/router distro.. I have not played with it for quite some time. But sure it's a fantastic choice as well - there are many firewall/router distro's out there - they all have pluses and minuses.. For the last few years I have been a using pfsense, but ipcop, smoothwall, etc all work too.

lately have been running the development ipv6 stuff from pfsense, which is working out great. Not a lot of distro's out there will full tunnel/firewall support for ipv6 - and its not in the mainline for pfsense either yet, not til they start work on the 2.1 version.

How is smoothwalls ipv6 support? Is it in the mainline version - if it is a more mature implementation I might have to take another look at it.

The user most likely would of had issues with any router distro to be honest.. His "modem" was not a modem - it was a gateway (modem/router combo) doing NAT. And he setup his LAN network on pfsense to be the same as what his gateway was using as its private network 192.168.33/24 -- so he had the same network on both his lan and his wan of his pfsense box.

I have chatted with him quite a bit on PM, he is trying but his basic understanding of networking needs work ;)

But he is getting there - and last I heard very happy with his setup now that he got it figured out in his head what he was doing wrong.

Nothing wrong with smoothwall -- its a great firewall/router distro.. I have not played with it for quite some time. But sure it's a fantastic choice as well - there are many firewall/router distro's out there - they all have pluses and minuses.. For the last few years I have been a using pfsense, but ipcop, smoothwall, etc all work too.

lately have been running the development ipv6 stuff from pfsense, which is working out great. Not a lot of distro's out there will full tunnel/firewall support for ipv6 - and its not in the mainline for pfsense either yet, not til they start work on the 2.1 version.

How is smoothwalls ipv6 support? Is it in the mainline version - if it is a more mature implementation I might have to take another look at it.

Ipv6 is still in it's infant stages with smoothwall, with update 8 that was just pushed out they added kernel support, but I don't think it's ready for prime time. I touched pfsense briefly when setting up my firewall/router, but when i gave smoothwall a test 2 years ago, it just worked. I spent maybe 5 minutes out of the box with it's setup tool and it just launched. installing packages/mods requires a little more work (usually requires the terminal), but it's very robust, and if you're into caching/im filtering, that's already built into the box (imspector and squid). for those with multicore processors, SMP is now supported as well.

All of those features are available on pfsense - it works out of the box as well.. Its normally a 5 minute install to up and running.. The OP just for some strange reason setup his lan network to the same as his router he already had. That would of caused an issue with any router distro.

Understanding that he was already doing nat, or for that matter keeping the default lan ip range would of worked with a double nat, etc.

Squid is click to install no terminal access required to install packages like squid, squidguard, im inspector, etc.

Im glad your happy with smoothwall - its a good distro and all.. But with what the OP did smoothwall would of had the same issue.

Hard to route traffic and nat when your lan IP is the same IP as the gateway on your wan interface ;)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Amazon Prime Day slashes Samsung's newest Galaxy Watch Ultra by 45 percent by Karthik Mudaliar Samsung’s flagship Android smartwatch has received one of its steepest Prime Day cuts. Amazon has dropped the 2025 Samsung Galaxy Watch Ultra in Titanium Blue to $357.24, saving buyers around $292 from its $649.99 list price. That's a 45 percent discount (purchase link below). The 47mm Galaxy Watch Ultra uses a titanium casing and a 1.5-inch Super AMOLED display with a resolution of 480 x 480 and peak brightness of 3,000 nits. It includes LTE connectivity, Bluetooth 5.3, Wi-Fi, NFC, and dual-frequency L1+L5 GPS for more accurate outdoor route tracking. The 2025 model has 64GB of storage, a 590mAh battery, sapphire crystal glass, 10ATM water resistance, IP68 protection, and MIL-STD-810H durability testing. Its health and fitness tools include heart rate monitoring, sleep coaching, Energy Score, Running Coach, body composition analysis, temperature sensing, and ECG support, where available. This model is best suited to Android users who regularly run, hike, cycle, or train outdoors and want cellular access without carrying a phone. The larger battery, rugged construction, bright display, and dedicated Quick Button also make it a stronger option than Samsung’s regular Galaxy Watch models for extended workouts and demanding environments. Grab the Titanium Blue Galaxy Watch Ultra before the Prime Day price resets: Samsung Galaxy Watch Ultra (2025) [Sold and Shipped by Amazon] Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Google begins rolling out its post-Epic Play Store billing model next week by Karthik Mudaliar Google has confirmed that its redesigned Play Store billing and fee structure will take effect on June 30, 2026, in the United States, the United Kingdom, and the European Economic Area. The changes will let eligible developers offer their own payment systems or send users to an external website for purchases, while separating Google’s platform service fee from the cost of using Google Play Billing. The rollout puts concrete dates and detailed rate cards behind the broader Android policy overhaul Google announced in March. That announcement followed a proposed settlement with Epic Games intended to resolve their long-running disputes over app distribution and payments, although the U.S. portion of the agreement still requires court approval. Under the new billing choice program, developers selling digital content or services can display an alternative payment option alongside Google Play Billing. They may also direct users to their own websites to complete a purchase. Developers can use Google’s standard payment-choice screen or design one that complies with the company’s user-interface rules. Choosing another payment processor does not eliminate Google’s cut altogether. The company will continue charging a service fee for transactions associated with apps distributed through Google Play, regardless of whether payment is handled by Google, an alternative provider, or a developer’s website. Google argues that this fee covers the value and infrastructure provided by Android and the Play Store. For developers earning up to $1 million annually, the service fee will generally be 10 percent. That rate also applies to auto-renewing subscriptions. When Google Play Billing is used in the U.S., U.K., or EEA, Google will add a separate 5 percent billing fee, and developers processing payments elsewhere will not pay that additional charge. This means Google’s familiar flat 30 percent commission is disappearing, but developers will not necessarily see a dramatic reduction on every transaction. An in-app purchase from an existing user processed through Google Play Billing can still reach a combined 30 percent. The biggest savings are likely to come from subscriptions, smaller developers covered by the $1 million tier, and companies able to move customers to their own payment infrastructure. Google is also offering lower rates through its Apps Experience and revamped Games Level Up programs. Apps and games that satisfy the company’s requirements can qualify for 15 percent service fees on new-install transactions and 20 percent on existing-install transactions. The criteria include performance and reliability standards, support for additional Android device categories, and selected platform features. Those program rates are scheduled to become available in the initial markets and Australia on September 30. For consumers, the immediate effect will depend on whether developers adopt alternative payments and pass any savings on through lower prices. For developers, however, June 30 begins a more flexible but considerably more complicated Play Store economy in which distribution, billing, install dates, revenue thresholds, and program participation can each affect Google’s final cut. Google is also separately developing a Registered App Stores program designed to simplify the installation of qualifying third-party stores. That initiative is expected to arrive with a major Android release later in 2026 and will launch outside the U.S. first. Google says the rest of the world will receive the changes by September 30, 2027, although billing rates for markets outside the US, UK, and EEA have not yet been announced.
    • 38% off a super insane price is still an INSANE price.
    • 1TB Samsung T9 and Samsung 9100 PRO SSDs are now selling at great prices by Fiza Ali Amazon is now offering the 1TB variant of Samsung T9 and Samsung 9100 PRO SSD at great prices with limited-time 38% and 39% discounts, respectively, so you may want to check them out if you have been looking to upgrade your storage solution. The Samsung T9 connects via a USB 3.2 Gen 2x2 (20Gbps) interface and delivers sequential read speeds of up to 2,000MB/s and sequential write speeds of up to 1,950MB/s, making it suitable for transferring large files, backing up data, and handling high-resolution media content. When it comes to the security features, the SSD includes AES 256-bit hardware encryption to help protect sensitive data. Designed for portability, the drive is reportedly resistant to drops from heights of up to 3 metres. Furthermore, it operates within a temperature range of 0°C to 60°C and can be stored at temperatures between -40°C and 85°C. Samsung Magician Software is included for drive management, firmware updates, performance optimisation, and health monitoring. Finally, the T9 is certified to multiple international standards, including CE, FCC, UL, UKCA, and RoHS 2 compliance, and is backed by a five-year limited warranty as well. 1TB Samsung T9 SSD: $179.99 (Amazon US) - 38% off The Samsung 9100 PRO uses the M.2 2280 form factor and connects through a PCIe 5.0 x4 interface with NVMe 2.0 support. Built with Samsung V-NAND TLC flash memory, an in-house controller, and 1GB of low-power DDR4X cache memory, the 9100 PRO is engineered for high-performance computing and gaming workloads. Furthermore, the SSD delivers sequential read speeds of up to 14,700MB/s and sequential write speeds of up to 13,300MB/s. Random performance is rated at up to 1,850,000 IOPS for reads and up to 2,600,000 IOPS for writes, depending on system hardware and configuration. The drive supports TRIM, S.M.A.R.T monitoring, automatic garbage collection, and device sleep mode to help maintain performance and efficiency over time. In terms of security features, it includes AES 256-bit encryption, TCG Opal support, and IEEE 1667 compliance. The 9100 PRO operates within a temperature range of 0°C to 70°C, is rated for 1.5 million hours MTBF, and can reportedly withstand shocks of up to 1,500G for 0.5 milliseconds. Finally, Samsung Magician Software is also included for firmware updates, performance monitoring, drive management, and optimisation. 1TB Samsung 9100 PRO SSD: $206.99 (Amazon US) - 39% off Alternatively, you can also check out other SSD deals here. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      124
    4. 4
      Michael Scrip
      81
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!