Recommended Posts

Right!

It looks like we are getting somewhere now.

I setup SquidGuard as your instructions above, stopped and restarted squidguard and now it appears everything is working.

At the bottom of the long BLOCKLIST i choose allow all for now until i can figure out how to apply a certain category to only 1 IP.

Your an amazing chap Bud :D Thanks again.

That would be an ACL, let me take a look at how you do that.

edit:

Here you go, create a group ACL, put in your kids IP as source, I used 192.168.1.40

post-14624-0-70605800-1300226076.jpg

Then I created a new category, kids - and put in yahoo.com

post-14624-0-36338200-1300226104.jpg

In the group ACL block your new custom cat or categories you want - and shazam

in my virtual machine that is on 192.168.1.40 can not access yahoo.com

But my host machine on .100 can.

post-14624-0-46501600-1300226175.jpg

  • Like 2

--Budman

Spent a while lat night looking at the different options in SQUIDGUARD and managed to get an ACL setup for 192.168.33.253 which worked, so after all your help i have finally got it working and i think i now know what i was doing wrong, when specifying to use the blocklist i wasn't telling it to use the LOCAL database also i hadn't setup any categories for it to block or deny so it looks like it was BLOCKING everything by default.

I am going to take the screenshots you posted above and make a reference guide for the future, i also noticed a CONFIG BACKUP package which i can install to backup the configuration of the firewall which may be worth doing.

Earlier on at the start of this thread you also mentioned in an edit so i didn't catch it until i was reading back over the thread but you said something about DNS and not using the ISP DNS and you also said something about installing UNBOUND which i can't find so i have either read something wrong done something wrong or need to do something i haven't done. -- I also notice that on the general settings page i have the box ticked which says something about getting DNS from the ISP.

Thanks again for all your help

:woot: :woot: :woot:

yeah you can run your own recursive nameserver, install the unbound package

post-14624-0-83209600-1300281644.jpg

So my clients never talk to my isp dns, or forward a dns request -- pfsense is the dns server. It talks to roots directly, etc. You can use dnssec this way.

maybe you play with what you got working for awhile - and we can move on to DNS at a later date ;)

Ok -- come on now.. Who rep'd a post that says in essence "Im using 2.0 RC1"

But the 3 pages of posts where I walk him through every step, tell him what he did wrong and post screenshots, etc. etc. Gets none??

Something wrong with this picture! ;)

  • Like 1

Ok -- come on now.. Who rep'd a post that says in essence "Im using 2.0 RC1"

But the 3 pages of posts where I walk him through every step, tell him what he did wrong and post screenshots, etc. etc. Gets none??

Something wrong with this picture! ;)

Ahaha thats actually kind of funny. Crazy world we live in eh Budman, what with earthquakes and Tsunamis and all.

Perhaps its PfSense developers trying to push their latest release :shiftyninja: :shiftyninja:

:p

Im not knocking you getting a rep - good for you(but did you earn it?), it just did not make sense to me - I got a PM that he rep'd me for the help I did which is great.. To be honest I could care less, just here to help people - I have gotten my fair share of rep around the forum - it feels good when people upvote you - don't get me wrong. But as long as the post help the OP or the next guy is what matters.

I just found it odd that someone rep'd a post that I had already posted he should do a few times - I agree the 2.0 line is more than stable enough to run in a home, or even a production environment to be sure. And quite a few +'s to doing so.. But the 1.2.3 line REALLY STABLE and great as well. But I like to be on the cutting edge myself - and 2.0 makes more sense with the ipv6 suff I have been playing with lately!!

But come on -- who stops by and reps a post like yours, which is a great kick in the ass for the OP mind you to move to the latest version - dont get me wrong.. But they clearly do not understand what the rep system is suppose to do.. You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem. And sorry but you run 2.0 does not fall into that area no way no how :)

Maybe you have great other posts? But to me I look at 631 posts in like 7 years = LURKER!! Not even part of the community at all. Sorry!

The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote, etc. But I do feel you should be able to click to see who rep'd -- can you???

  • Like 1

Im not knocking you getting a rep - good for you(but did you earn it?), it just did not make sense to me - I got a PM that he rep'd me for the help I did which is great.. To be honest I could care less, just here to help people - I have gotten my fair share of rep around the forum - it feels good when people upvote you - don't get me wrong. But as long as the post help the OP or the next guy is what matters.

I just found it odd that someone rep'd a post that I had already posted he should do a few times - I agree the 2.0 line is more than stable enough to run in a home, or even a production environment to be sure. And quite a few +'s to doing so.. But the 1.2.3 line REALLY STABLE and great as well. But I like to be on the cutting edge myself - and 2.0 makes more sense with the ipv6 suff I have been playing with lately!!

But come on -- who stops by and reps a post like yours, which is a great kick in the ass for the OP mind you to move to the latest version - dont get me wrong.. But they clearly do not understand what the rep system is suppose to do.. You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem. And sorry but you run 2.0 does not fall into that area no way no how :)

Maybe you have great other posts? But to me I look at 631 posts in like 7 years = LURKER!! Not even part of the community at all. Sorry!

The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote, etc. But I do feel you should be able to click to see who rep'd -- can you???

now you're making something out of nothing.. and now making this personal. You say you dont care, yet you make a post ALL about it, and NOW you target me, specifically the bold part.

I've always respected your knowledge of things Budman, but this is disrespectful to something I havnt done. Thanks for derailing this, and if you have a problem with my "post count" and calling me a lurker. PM NEXT TIME.

Insulted. You tend to do that a lot.

Ridiculous BudMan.

Also, stop being concerned about "message board rep" it means nothing in life. I'm not going to forget this next time I see you being targeted... which I have seen before in other posts. Why should I rep your posts now? When I have plenty of times in the past...

I might have worded that a bit harsh.. :blush:

I did not mean anything bad directed at you to be honest, but more at the person that rep'd you.. The lurker comment was uncalled for, sorry!!

This is more what should of stood out - and clearly not direct towards you since you can not rep your own posts.

"You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem"

"The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote,"

The beers and irish whisky I had been consuming since 2pm might have had a bit to do with my lurker comment? :blush:

I might have worded that a bit harsh.. :blush:

I did not mean anything bad directed at you to be honest, but more at the person that rep'd you.. The lurker comment was uncalled for, sorry!!

This is more what should of stood out - and clearly not direct towards you since you can not rep your own posts.

"You don't rep +1 type posts, you don't rep "me too" type posts, you don't rep "yeah I agree with that" type posts -- its suppose to be for posts that HELPED/SOLVED the users problem"

"The rep system is not meant to be a 'like" type system - atleast from my take of it. Its not reddit clicking upvote,"

The beers and irish whisky I had been consuming since 2pm might have had a bit to do with my lurker comment? :blush:

Apology accepted.

  • 1 month later...

Pfsense Rocks.. I am running 2.0 RC2 now.. Did the OP solve this issue in the end ?

And Glad you 2 kissed and made up ;-)

Seriously tho... got to see the funny side of all this..

Take care.

Phillip.

Yes he did get it worked out. His internet access problem was fixed when he turned his gateway device into just a modem - see earlier in the thread

"I changed the DG834G router into modem only mode which makes it into a modem only device"

Then to his accessing his modems private IP - that was fixed too, he had the wrong virtual IP set on his wan interface to allow talking to his modems internal private IP. He had set the virtual ip to the same as his modems IP 192.168.10.1 vs .2

we used teamviewer and I got on his box so I could look at his pfsense config - once he corrected that it worked just fine.

The link to the pfsense doc is earlier in the thread, but for quick reference here it is again

http://doc.pfsense.org/index.php/Accessing_modem_from_inside_firewall

I dont want to knock anyone or PFsense, but with all the trouble the OP had, I think he might of had an easier time going with smoothwall, compared to PFsense (at least to me), it may have been easier to configure OOB. Budman you sure do have a lot of patience :) Sometimes it can be difficult trying to explain stuff to people without being able to be physically there to show someone, I have to do it daily to people deployed overseas in hot zones.

The user most likely would of had issues with any router distro to be honest.. His "modem" was not a modem - it was a gateway (modem/router combo) doing NAT. And he setup his LAN network on pfsense to be the same as what his gateway was using as its private network 192.168.33/24 -- so he had the same network on both his lan and his wan of his pfsense box.

I have chatted with him quite a bit on PM, he is trying but his basic understanding of networking needs work ;)

But he is getting there - and last I heard very happy with his setup now that he got it figured out in his head what he was doing wrong.

Nothing wrong with smoothwall -- its a great firewall/router distro.. I have not played with it for quite some time. But sure it's a fantastic choice as well - there are many firewall/router distro's out there - they all have pluses and minuses.. For the last few years I have been a using pfsense, but ipcop, smoothwall, etc all work too.

lately have been running the development ipv6 stuff from pfsense, which is working out great. Not a lot of distro's out there will full tunnel/firewall support for ipv6 - and its not in the mainline for pfsense either yet, not til they start work on the 2.1 version.

How is smoothwalls ipv6 support? Is it in the mainline version - if it is a more mature implementation I might have to take another look at it.

The user most likely would of had issues with any router distro to be honest.. His "modem" was not a modem - it was a gateway (modem/router combo) doing NAT. And he setup his LAN network on pfsense to be the same as what his gateway was using as its private network 192.168.33/24 -- so he had the same network on both his lan and his wan of his pfsense box.

I have chatted with him quite a bit on PM, he is trying but his basic understanding of networking needs work ;)

But he is getting there - and last I heard very happy with his setup now that he got it figured out in his head what he was doing wrong.

Nothing wrong with smoothwall -- its a great firewall/router distro.. I have not played with it for quite some time. But sure it's a fantastic choice as well - there are many firewall/router distro's out there - they all have pluses and minuses.. For the last few years I have been a using pfsense, but ipcop, smoothwall, etc all work too.

lately have been running the development ipv6 stuff from pfsense, which is working out great. Not a lot of distro's out there will full tunnel/firewall support for ipv6 - and its not in the mainline for pfsense either yet, not til they start work on the 2.1 version.

How is smoothwalls ipv6 support? Is it in the mainline version - if it is a more mature implementation I might have to take another look at it.

Ipv6 is still in it's infant stages with smoothwall, with update 8 that was just pushed out they added kernel support, but I don't think it's ready for prime time. I touched pfsense briefly when setting up my firewall/router, but when i gave smoothwall a test 2 years ago, it just worked. I spent maybe 5 minutes out of the box with it's setup tool and it just launched. installing packages/mods requires a little more work (usually requires the terminal), but it's very robust, and if you're into caching/im filtering, that's already built into the box (imspector and squid). for those with multicore processors, SMP is now supported as well.

All of those features are available on pfsense - it works out of the box as well.. Its normally a 5 minute install to up and running.. The OP just for some strange reason setup his lan network to the same as his router he already had. That would of caused an issue with any router distro.

Understanding that he was already doing nat, or for that matter keeping the default lan ip range would of worked with a double nat, etc.

Squid is click to install no terminal access required to install packages like squid, squidguard, im inspector, etc.

Im glad your happy with smoothwall - its a good distro and all.. But with what the OP did smoothwall would of had the same issue.

Hard to route traffic and nat when your lan IP is the same IP as the gateway on your wan interface ;)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Exactly, this is just the beginning. I hope that by that time, our inept politicians devise something like a Universal Basic Income, because unemployment and poverty rates will skyrocket otherwise. And believe me, robots that perform physical work aren't a matter of IF, but WHEN. No career is truly safe from AI/robots, it's just a matter of time.
    • Subtitle Edit 5.0.0 by Razvan Serea Subtitle Edit is a powerful, free, and user-friendly subtitle editing tool designed for creating, editing, and converting subtitles for videos. It supports a wide range of subtitle formats, including SRT, ****, and SUB, allowing users to easily modify and adjust subtitles for accurate timing and formatting. With its intuitive interface, Subtitle Edit provides a variety of features such as waveform audio display, spell-check, subtitle synchronization, and real-time video preview, making it an ideal choice for both beginners and professionals. The software also includes powerful tools for batch processing, translating subtitles, and converting between different subtitle formats. Subtitle Edit features: Create/adjust/sync/translate subtitle lines Convert between SubRib, MicroDVD, Advanced Sub Station Alpha, Sub Station Alpha, D-Cinema, SAMI, youtube sbv, and many more (300+ different formats!) Cool audio visualizer control - can display wave form and/or spectrogram Video player uses mpv, DirectShow, or VLC media player Visually sync/adjust a subtitle (start/end position and speed) Audio to text (speech recognition) via Whisper or Vosk/Kaldi Auto Translation via Google translate Rip subtitles from a (decrypted) dvd Import and OCR VobSub sub/idx binary subtitles Import and OCR Blu-ray .sup files - bd sup reading is based on Java code from BDSup2Sub Can open subtitles embedded inside Matroska files Can open subtitles (text, closed captions, VobSub) embedded inside mp4/mv4 files Can open/OCR XSub subtitles embedded inside divx/avi files Can open/OCR DVB and teletext subtitles embedded inside .ts/.m2ts (Transport Stream) files Can open/OCR Blu-ray subtitles embedded inside .m2ts (Transport Stream) files Merge/split subtitles Adjust display time Fix common errors wizard....and more. Subtitle Edit 5.0.0 changelog: Subtitle Edit 5 is a major new release and a big step for the project. For the first time, Subtitle Edit runs natively on Windows, macOS, and Linux from a single, modern, cross-platform codebase. The builds are self-contained, so no separate .NET installation is required, and on macOS and Linux the needed media components (mpv/ffmpeg) are bundled in. Please read before upgrading: Subtitle Edit 5 is a new application, not just an update of Subtitle Edit 4. It has been rebuilt from the ground up to be cross-platform, so: It is not 100% the same app. The look, layout, and some workflows have changed. Some things are in different places, and a few behave differently than in SE4. Not every SE4 feature exists in SE5 yet. SE5 covers all the core editing, conversion, sync, video playback, OCR, and online services, but some of the more specialized SE4 tools are not available yet. Features will continue to be added. If you rely on a specific SE4 feature that is missing, please keep SE4 installed alongside SE5. The easiest way to run both side by side is to use the Portable versions of SE4 and SE5, which keep their settings separate and do not interfere with each other. Which version should I use? Subtitle Edit 5: recommended for most users on Windows 10 (22H2) or newer, macOS 12+, and Linux. Subtitle Edit 4: please continue to use SE4 if you are on an older Windows version (Windows 7/8), or on older / slower computers where SE5 may not run well. SE4 remains available and is the right choice in those cases. To run SE4 and SE5 at the same time, use the Portable versions - you can try SE5 while keeping SE4 as a fallback. Download: Subtitle Edit 5.0.0 | ARM64 | ~60.0 MB (Open Source) Download: Subtitle Edit Portable | 103.0 MB View: Subtitle Edit Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Google Pixel 11 series: Here's what to expect by Hamid Ganji Google Pixel 10 series In recent years, Google has successfully turned its Pixel devices into worthy contenders in the smartphone market. The search giant is now preparing to launch the Pixel 11 series in just a few months, and many Pixel fans are likely wondering what Google has in store for them this year. The next lineup of Google smartphones includes four devices: the Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, and Pixel 11 Pro Fold. This year, we don’t expect Google to bring revolutionary upgrades to its handsets, and the Pixel 11 series is likely to receive modest hardware improvements alongside a slew of AI-powered features. Here are the rumored specifications of the Google Pixel 11 series ahead of its official debut: When will the new Pixel phones be unveiled? The last two generations of Google Pixel phones (Pixel 9 series and Pixel 10 series) were launched in August, unlike the previous three generations that debuted in October. With that in mind, we expect Google to unveil the Pixel 11 series sometime in August 2026. The exact launch date has yet to be confirmed. Google Pixel 11 CAD renders - Image via AndroidHeadlines How much will the Pixel 11 series cost? Predicting the final price of upcoming smartphones has become increasingly difficult. As you may know, RAM and memory prices are rising sharply, leading to significant increases in the cost of consumer electronics. Recently, Apple CEO Tim Cook said that price increases for some future Apple products are unavoidable, suggesting that the iPhone 18 series could become more expensive. Google has remained tight-lipped about any potential price increases for the Pixel 11 series. If the company manages to maintain last year’s pricing structure, here’s what the lineup could cost: Pixel 11: $799 Pixel 11 Pro: $999 Pixel 11 Pro XL: $1,199 Pixel 11 Pro Fold: $1,799 Given current market conditions, it may be difficult for Google to avoid raising prices unless it adopts cost-saving measures, such as equipping the base model with 8GB of RAM. Google Pixel 11 series anticipated specs: We expect the Google Pixel 11 series to debut with a new Tensor G6 processor as well as an upgraded camera system. The overall design, however, is expected to remain largely unchanged across the lineup. Specifications Pixel 11 Pixel 11 Pro Pixel 11 Pro XL Pixel 11 Pro Fold Display 6.3-inch LTPO AMOLED / 120Hz refresh rate / up to 3100 nits of brightness 6.3-inch Super Actua LTPO OLED, 120Hz refresh rate, up to 3600 nits of brightness 6.8-inch Super Actua LTPO OLED, 120Hz refresh rate, up to 3600 nits of brightness 8-inch inner screen and 6.4-inch outer display, 120Hz refresh rate, up to 3600 nits of brightness RAM & Processor Tensor G6 / 8-12GB of RAM Tensor G6 / 12-16GB of RAM Tensor G6 / 12-16GB of RAM Tensor G6 / 16GB of RAM Storage options 128GB or 256GB 256GB, 512GB, 1TB 256GB, 512GB, 1TB 256GB, 512GB, 1TB Camera 50MP main sensor, 13MP ultra-wide, 10.8MP 5x telephoto, 10.5MP front camera 50MP main camera, 48MP ultra-wide, 48MP telephoto with 5x optical zoom, 42MP selfie camera 50MP main camera, 48MP ultra-wide, 48MP telephoto with 5x optical zoom, 42MP selfie camera 50MP main camera, 10.5MP ultra-wide camera, 10.8MP telephoto camera, 10MP front camera, 10MP inner camera Battery 4,840 mAh 4,707 mAh 5,000 mAh 4,658 mAh Software Android 17 Android 17 Android 17 Android 17 The Pixel 11 series won’t be a major departure from its predecessor, with Google instead focusing on subtle improvements and AI additions such as Gemini Intelligence. However, a patent filed by Google suggests the company is working on a removable battery for its smartphones, and we could see this feature make its way to the Pixel 11 Pro Fold. Given that nearly all smartphones today lack removable batteries, such a feature would be a welcome addition to future Pixel devices. That said, it may not arrive with this year’s lineup after all, and the final decision is yet to be made by Google. The Pixel 11 series could also face an uphill battle in the market. In the Android segment, Samsung is performing well with the Galaxy S26 series, while the Galaxy Z Fold 8 lineup is also expected to launch next month. On the other hand, Apple is preparing to unveil the iPhone 18 Pro and iPhone 18 Pro Max in September alongside its first foldable iPhone.
    • At least AMD is still taking Windows 10 seriously (after the oops) before it consumer extended support ends. @WaltC - Memories, 2x Voodoo in SLI with a Riva TNT with an Aureal A3D soundcard.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      475
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      105
    4. 4
      Michael Scrip
      88
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!