<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>stephenyeong&#039;s blog &#187; pfsense</title>
	<atom:link href="http://www.stephenyeong.idv.hk/wp/category/pfsense/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stephenyeong.idv.hk/wp</link>
	<description>Blog about my IT life</description>
	<lastBuildDate>Mon, 06 Feb 2012 13:41:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>OpenWrt (2 SSID) + pfSense + ESXi</title>
		<link>http://www.stephenyeong.idv.hk/wp/2012/01/openwrt2ssid-pfsense-esxi/</link>
		<comments>http://www.stephenyeong.idv.hk/wp/2012/01/openwrt2ssid-pfsense-esxi/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 20:17:48 +0000</pubDate>
		<dc:creator>stephenyeong</dc:creator>
				<category><![CDATA[ESXi]]></category>
		<category><![CDATA[pfsense]]></category>
		<category><![CDATA[其他]]></category>
		<category><![CDATA[網絡]]></category>
		<category><![CDATA[OpenWrt]]></category>
		<category><![CDATA[Wireless Guest Zone]]></category>

		<guid isPermaLink="false">http://www.stephenyeong.idv.hk/wp/?p=989</guid>
		<description><![CDATA[因為手上的Wireless LAN 卡可以開幾個SSID，所以決定玩多一樣  ﹣Guest Zone。 先在ESXi 內開多一個VMNetwork &#8211; Guest 並且設定好Security ﹣Promiscuous Mode＝Accept。 並且在現有的pfSense VM及OpenWrt VM各加多一個e1000 Network Interface 並連接到Guest Zone。 OpenWrt 設定好新增的e1000界面及開多一個Bridge Interface  br-Guest Wireless 加多一個SSID叫OpenWrtGuest，設定好一個易記的WPA Preshared Key 並開橋接到br-guest。 由於是Guest Zone，使用者不可以進入OpenWrt Web管理界面，所以Interface Protocol設定為Unmanaged pfSense方面，同樣設定好Interface。IP、DHCP Server、Proxy Server。 最後設定Firewall Rules ，Guest Network 除了不能進入LAN Network、Management界面外，其他Traffic 就Accept。 &#160; &#160; &#160;]]></description>
			<content:encoded><![CDATA[<fb:like href='http://www.stephenyeong.idv.hk/wp/2012/01/openwrt2ssid-pfsense-esxi/' send='false' layout='standard' show_faces='true' width='450' height='65' action='like' colorscheme='light' font='lucida+grande'></fb:like><p>因為手上的Wireless LAN 卡可以開幾個SSID，所以決定玩多一樣  ﹣Guest Zone。</p>
<p>先在ESXi 內開多一個VMNetwork &#8211; Guest 並且設定好Security ﹣Promiscuous Mode＝Accept。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/vSwitch3-and-Guest-Zone.png" rel="lightbox[989]" title="vSwitch3 and Guest Zone"><img class="alignnone size-full wp-image-994" title="vSwitch3 and Guest Zone" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/vSwitch3-and-Guest-Zone.png" alt="" width="378" height="121" /></a></p>
<p>並且在現有的pfSense VM及OpenWrt VM各加多一個e1000 Network Interface 並連接到Guest Zone。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/VM-pfSense.png" rel="lightbox[989]" title="VM pfSense"><img class="alignnone  wp-image-995" title="VM pfSense" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/VM-pfSense.png" alt="" width="452" height="241" /></a></p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/VM-OpenWrt.png" rel="lightbox[989]" title="VM OpenWrt"><img class="alignnone  wp-image-996" title="VM OpenWrt" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/VM-OpenWrt.png" alt="" width="456" height="222" /></a></p>
<p>OpenWrt 設定好新增的e1000界面及開多一個Bridge Interface  br-Guest</p>
<p><img class="alignnone  wp-image-992" title="OpenWrt LAN Interfaces" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/OpenWrt-LAN-Interfaces.png" alt="" width="594" height="444" /></p>
<p>Wireless 加多一個SSID叫OpenWrtGuest，設定好一個易記的WPA Preshared Key 並開橋接到br-guest。</p>
<p><img class="alignnone  wp-image-991" title="OpenWrt Wireless" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/OpenWrt-Wireless.png" alt="" width="594" height="444" /></p>
<p>由於是Guest Zone，使用者不可以進入OpenWrt Web管理界面，所以Interface Protocol設定為Unmanaged</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/OpenWrt-Interface-Guest.png" rel="lightbox[989]" title="OpenWrt Interface Guest"><img class="wp-image-997  alignnone" title="OpenWrt Interface Guest" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/OpenWrt-Interface-Guest.png" alt="" width="479" height="215" /></a></p>
<p>pfSense方面，同樣設定好Interface。IP、DHCP Server、Proxy Server。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/pfSense-Interfaces.png" rel="lightbox[989]" title="pfSense Interfaces"><img class="alignnone  wp-image-993" title="pfSense Interfaces" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/pfSense-Interfaces.png" alt="" width="673" height="442" /></a></p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/Screen-Shot-2012-01-12-at-3.57.10-AM.png" rel="lightbox[989]" title="DHCP Server Settings"><img class="alignnone  wp-image-998" title="DHCP Server Settings" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/Screen-Shot-2012-01-12-at-3.57.10-AM.png" alt="" width="654" height="407" /></a></p>
<p>最後設定Firewall Rules ，Guest Network 除了不能進入LAN Network、Management界面外，其他Traffic 就Accept。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/Screen-Shot-2012-01-12-at-4.13.03-AM.png" rel="lightbox[989]" title="pfSense Firewall"><img class="alignnone  wp-image-999" title="pfSense Firewall" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2012/01/Screen-Shot-2012-01-12-at-4.13.03-AM.png" alt="" width="571" height="261" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stephenyeong.idv.hk/wp/2012/01/openwrt2ssid-pfsense-esxi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pfSense 2.0 Released</title>
		<link>http://www.stephenyeong.idv.hk/wp/2011/09/pfsense-2-0-released/</link>
		<comments>http://www.stephenyeong.idv.hk/wp/2011/09/pfsense-2-0-released/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 01:00:09 +0000</pubDate>
		<dc:creator>stephenyeong</dc:creator>
				<category><![CDATA[pfsense]]></category>

		<guid isPermaLink="false">http://www.stephenyeong.idv.hk/wp/?p=753</guid>
		<description><![CDATA[等了1年零9個月, pfSense 2.0 終於出了正式版。回顧這兩年多, 由試vyatta轉用pfSense、ClearOS最後再轉返pfSense。 pfSense給我的印像是介面最好的Router。 簡潔的Dashboard, 似乎預設的擺位為了Multi WAN + Multi LAN 設定方面，由淺入深。 最基本想做到NAT功能只需設定好LAN和WAN的IP 深入少少可以睇睇Firewall/NAT 有Session Limit (Firewall Maximum States, 預設22,000)、Clear DF bit、Route/NAT 相關設定。 最深入可以去到System Tunables，直接設定Kernel/module parameter (應該沒有機會使用吧)。 報表雖然未有 per firewall policy 的 RRD Graph，但預設的Interface Graph 設計幾有心思. 其他 IPSEC VPN &#8211; 可以用Overlapped range，VPN返公司可以用埋公司做Hub-and-Spoke (這個是ClearOS沒有的) PPTP &#8211; 雖然設定怪怪的，但應用上沒有大問題 UPNP &#8211; eMule/MSN可以經UPNP開incoming NAT rule, 省了不少時間 &#160;]]></description>
			<content:encoded><![CDATA[<fb:like href='http://www.stephenyeong.idv.hk/wp/2011/09/pfsense-2-0-released/' send='false' layout='standard' show_faces='true' width='450' height='65' action='like' colorscheme='light' font='lucida+grande'></fb:like><p>等了1年零9個月, pfSense 2.0 終於出了正式版。回顧這兩年多, 由試vyatta轉用pfSense、ClearOS最後再轉返pfSense。</p>
<p>pfSense給我的印像是介面最好的Router。</p>
<p>簡潔的Dashboard, 似乎預設的擺位為了Multi WAN + Multi LAN</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_dashboard.png" rel="lightbox[753]" title="pfsense_dashboard"><img class="alignnone size-medium wp-image-754" title="pfsense_dashboard" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_dashboard-300x293.png" alt="" width="300" height="293" /></a></p>
<p>設定方面，由淺入深。<br />
最基本想做到NAT功能只需設定好LAN和WAN的IP<br />
深入少少可以睇睇Firewall/NAT</p>
<p>有Session Limit (Firewall Maximum States, 預設22,000)、Clear DF bit、Route/NAT 相關設定。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_firewall_NAT.png" rel="lightbox[753]" title="pfsense_firewall_NAT"><img class="alignnone size-medium wp-image-757" title="pfsense_firewall_NAT" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_firewall_NAT-195x300.png" alt="" width="195" height="300" /></a></p>
<p>最深入可以去到System Tunables，直接設定Kernel/module parameter (應該沒有機會使用吧)。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_system_turnables.png" rel="lightbox[753]" title="pfsense_system_turnables"><img class="alignnone size-medium wp-image-758" title="pfsense_system_turnables" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/pfsense_system_turnables-300x206.png" alt="" width="300" height="206" /></a></p>
<p>報表雖然未有 per firewall policy 的 RRD Graph，但預設的Interface Graph 設計幾有心思.</p>
<p><a><img class="alignnone size-medium wp-image-759" title="WAN 8 hour traffic (1 minutes average)" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/WAN-8hr-1min-300x151.png" alt="" width="300" height="151" /></a></p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/WAN-quality.png" rel="lightbox[753]" title="WAN quality"><img class="alignnone size-medium wp-image-760" title="WAN quality" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2011/09/WAN-quality-300x163.png" alt="" width="300" height="163" /></a></p>
<p>其他</p>
<p>IPSEC VPN &#8211; 可以用Overlapped range，VPN返公司可以用埋公司做Hub-and-Spoke (這個是ClearOS沒有的)<br />
PPTP &#8211; 雖然設定怪怪的，但應用上沒有大問題<br />
UPNP &#8211; eMule/MSN可以經UPNP開incoming NAT rule, 省了不少時間</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.stephenyeong.idv.hk/wp/2011/09/pfsense-2-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows 7 Network Location &amp; pfSense Bridged LAN IF</title>
		<link>http://www.stephenyeong.idv.hk/wp/2010/04/win7_nla_pfsense_bridge/</link>
		<comments>http://www.stephenyeong.idv.hk/wp/2010/04/win7_nla_pfsense_bridge/#comments</comments>
		<pubDate>Sat, 03 Apr 2010 16:28:32 +0000</pubDate>
		<dc:creator>stephenyeong</dc:creator>
				<category><![CDATA[pfsense]]></category>
		<category><![CDATA[Windows;Network Location Awareness;Windows]]></category>

		<guid isPermaLink="false">http://www.stephenyeong.idv.hk/wp/?p=574</guid>
		<description><![CDATA[自從pfSense轉了用 Bridged GE+WLAN LAN, 每逢Router reboot，Windows 7 就會話網絡位置改變了。 Windows 7 的網絡位置會變回最安全的 Public, 開啟Firewall 並關閉檔案分享。 今日終於下決心解決它。 原來Windows 7 個 Network Location 用 Default Gateway 個MAC Address來認出位置，剛好pfSense個Network Bridge 又會隨機選一個MAC Address。每逢Restart Router, Windows會收到一個全新的Gateway MAC Address。 解決方法就是在pfSense裏設定Bridged LAN interface 用固定的MAC Address。]]></description>
			<content:encoded><![CDATA[<fb:like href='http://www.stephenyeong.idv.hk/wp/2010/04/win7_nla_pfsense_bridge/' send='false' layout='standard' show_faces='true' width='450' height='65' action='like' colorscheme='light' font='lucida+grande'></fb:like><p>自從pfSense轉了用 Bridged GE+WLAN LAN, 每逢Router reboot，Windows 7 就會話網絡位置改變了。 Windows 7 的網絡位置會變回最安全的 Public, 開啟Firewall 並關閉檔案分享。</p>
<p>今日終於下決心解決它。</p>
<p>原來Windows 7 個 Network Location 用 Default Gateway 個MAC Address來認出位置，剛好pfSense個Network Bridge 又會隨機選一個MAC Address。每逢Restart Router, Windows會收到一個全新的Gateway MAC Address。</p>
<p>解決方法就是在pfSense裏設定Bridged LAN interface 用固定的MAC Address。</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/04/NLA-Default-Gateway-IP-pfsense-Bridged-LAN-interface.png" rel="lightbox[574]" title="NLA Default Gateway IP &amp; pfsense Bridged LAN  interface"><img class="alignnone size-medium wp-image-575" title="NLA Default Gateway IP &amp; pfsense Bridged LAN  interface" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/04/NLA-Default-Gateway-IP-pfsense-Bridged-LAN-interface-300x265.png" alt="" width="300" height="265" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.stephenyeong.idv.hk/wp/2010/04/win7_nla_pfsense_bridge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finally pfsense wireless bridge working</title>
		<link>http://www.stephenyeong.idv.hk/wp/2010/03/pfsense-wireless-bridge-working/</link>
		<comments>http://www.stephenyeong.idv.hk/wp/2010/03/pfsense-wireless-bridge-working/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 17:28:36 +0000</pubDate>
		<dc:creator>stephenyeong</dc:creator>
				<category><![CDATA[pfsense]]></category>
		<category><![CDATA[wireless lan]]></category>

		<guid isPermaLink="false">http://www.stephenyeong.idv.hk/wp/?p=519</guid>
		<description><![CDATA[Finally, pfSense  2.0 router with AP working. The tweak is, make both WLAN and LAN as opt  interface, bridge them and make bridged interface as LAN interface to network port assignment bridge interface members]]></description>
			<content:encoded><![CDATA[<fb:like href='http://www.stephenyeong.idv.hk/wp/2010/03/pfsense-wireless-bridge-working/' send='false' layout='standard' show_faces='true' width='450' height='65' action='like' colorscheme='light' font='lucida+grande'></fb:like><p>Finally, pfSense  2.0 router with AP working.</p>
<p>The tweak is, make both WLAN and LAN as opt  interface, bridge them and make bridged interface as LAN</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_1.png" rel="lightbox[519]" title="pfsense-lan-wlan-bridge_1"><img class="alignnone size-full  wp-image-523" title="pfsense-lan-wlan-bridge_1" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_1.png" alt="" width="771" height="386" /></a></p>
<p>interface to network port assignment</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_2.png" rel="lightbox[519]" title="pfsense-lan-wlan-bridge_2"><img class="alignnone size-full wp-image-521" title="pfsense-lan-wlan-bridge_2" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_2.png" alt="" width="731" height="159" /></a></p>
<p>bridge interface members</p>
<p><a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_3.png" rel="lightbox[519]" title="pfsense-lan-wlan-bridge_3"><img class="alignnone size-full wp-image-522" title="pfsense-lan-wlan-bridge_3" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/03/pfsense-lan-wlan-bridge_3.png" alt="" width="739" height="110" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.stephenyeong.idv.hk/wp/2010/03/pfsense-wireless-bridge-working/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>pfSense 2.0 Beta1 Cont.</title>
		<link>http://www.stephenyeong.idv.hk/wp/2010/01/pfsense-2-0-beta1-cont/</link>
		<comments>http://www.stephenyeong.idv.hk/wp/2010/01/pfsense-2-0-beta1-cont/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 04:23:37 +0000</pubDate>
		<dc:creator>stephenyeong</dc:creator>
				<category><![CDATA[pfsense]]></category>
		<category><![CDATA[網絡]]></category>
		<category><![CDATA[軟件]]></category>
		<category><![CDATA[firewall]]></category>

		<guid isPermaLink="false">http://www.stephenyeong.idv.hk/wp/?p=333</guid>
		<description><![CDATA[今日終於有時間做下載測試 用Vuze BT 19.70GB, 9:25開始, 到12:13已完成51.7%. Broadband: HGC 10M Router Hardware: 致銘ITX-M4S2GAP w/2GB DDR2, 4GB CF Router Software: pfSense 2.0 Beta1 snapshot 2009-12-31 Modified: kern.polling.idle_poll=0 Processor Usage, current 5% Session Table, current 2200 sessions, 25.4 state changes per second Traffic, current DL 9.59Mbps, UL 5.42Mbps]]></description>
			<content:encoded><![CDATA[<fb:like href='http://www.stephenyeong.idv.hk/wp/2010/01/pfsense-2-0-beta1-cont/' send='false' layout='standard' show_faces='true' width='450' height='65' action='like' colorscheme='light' font='lucida+grande'></fb:like><p>今日終於有時間做下載測試</p>
<p>用Vuze BT 19.70GB, 9:25開始, 到12:13已完成51.7%.</p>
<p>Broadband: HGC 10M<br />
Router Hardware: <em>致銘ITX</em>-M4S2GAP w/2GB DDR2, 4GB CF<br />
Router Software: pfSense 2.0 Beta1 snapshot 2009-12-31<br />
Modified: kern.polling.idle_poll=0</p>
<p>Processor Usage, current 5%<br />
<a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/Processor-2010-01-05.png" rel="lightbox[333]" title="Processor 2010-01-05"><img class="alignnone size-full wp-image-334" title="Processor 2010-01-05" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/Processor-2010-01-05.png" alt="" width="655" height="400" /></a></p>
<p>Session Table, current 2200 sessions, 25.4 state changes per second<br />
<a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/States-2010-01-05.png" rel="lightbox[333]" title="States 2010-01-05"><img class="alignnone size-full wp-image-335" title="States 2010-01-05" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/States-2010-01-05.png" alt="" width="655" height="390" /></a></p>
<p>Traffic, current DL 9.59Mbps, UL 5.42Mbps<br />
<a href="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/traffic-WAN-2010-01-05.png" rel="lightbox[333]" title="traffic WAN 2010-01-05"><img class="alignnone size-full wp-image-336" title="traffic WAN 2010-01-05" src="http://www.stephenyeong.idv.hk/wp/wp-content/uploads/2010/01/traffic-WAN-2010-01-05.png" alt="" width="663" height="376" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.stephenyeong.idv.hk/wp/2010/01/pfsense-2-0-beta1-cont/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

