pfSense

Connecting the pfSense

In order to connect the pfSense to the network:

  • Ensure the modem or other ISP provided equipment is in bridge mode. Anyone familiar with the local network setup will be able to assist with this.
  • Note: If the IP address is static, it will be necessary to load this information into the pfSense.
  • Connect the router to the modem provided by the ISP, ensuring that it is the only device connected. All other devices will connect to the router or a switch connected to the router.
  • In most cases the router can be accessed locally at 192.168.0.1 or 192.168.1.1.

Creating network address aliases

                The pfSense network appliances allow for the creation of an address aliases. This allows for multiple IP addresses or ranges to be managed in a single definition.

  • Navigate to Firewall Settings.
  • Navigate to Aliases.
  • Select New
  • Name the aliases Cytracom
  • Add the address range 209.105.249.192/26
  • Also add fw.cytracom.com/32, tftp.cytracom.net/32, and register.cytracom.net/32

aliases_udpated.png

Increasing System UDP Timeout

  • Navigate to System.
  • Navigate to Advanced.
  • Navigate to Firewall & NAT
  • Scroll down to the bottom of the page.
  • Update all UDP options to 180 (seconds).

firewall_advanced_settings.png

 

Outgoing Traffic Rule

  • Navigate to Firewall.
  • Navigate to Rules.
  • Select the LAN tab.
  • Select the Add button with upward arrow.

firewall_LAN_rule.png

 

  • Set the action to pass.
  • Set the interface to LAN.
  • Address Family will automatically set to IPv4.
  • Set the protocol to TCP/UDP.
  • Set source to Any.
  • Set destination to Single host or alias, then type in the name of the alias that was created earlier (Cytracom).
  • Check Log under extra options. (Note that logs will take up internal storage on device unless logs are sent to a remote syslog server.)

firewall_LAN_rule_detailed.png

Inbound Traffic Rule

  • Navigate to Firewall.
  • Navigate to Rules.
  • Select the WAN tab.
  • Select the Add button with upward arrow.

firewall_WAN_rule.png

  • Set the action to pass.
  • Set the interface to WAN.
  • Address Family will automatically set to IPv4.
  • Set the protocol to TCP/UDP.
  • Set source to Single host or alias, then type in the name of the alias that was created earlier (Cytracom).
  • Set destination to Any and destination port range to Any
  • Check Log under extra options. (Note that logs will take up internal storage on device unless logs are sent to a remote syslog server.)

firewall_WAN_rule_detailed_.png

 

Creating Traffic Shaping

  • Navigate to Firewall
  • Navigate to Traffic Shaper
  • Navigate to Wizards
  • Select Dedicated Links Wizard

traffic_shaping_1.png

  • Enter the number of WAN links.
  • Select Next

 traffic_shaping_2.png

  • On the first Local interface select LAN.
  • On the second Local Interface select HFSC.
  • On the first WAN interface select WAN.
  • On the second WAN interface select HFSC.
  • Configure the upload/download bandwidth based upon tested speeds.

(HFSC is the type of traffic shaper that will be used, We highly suggest using HFSC due to it having a hierarchy of queues and is capable of real-time traffic guarantees.)

  • Select Next

traffic_shaping_3.png

  • Check the box for “Prioritize Voice over IP traffic”.
  • Set Provider to Generic (lowdelay)
  • Set Upstream SIP Server to Cytracom. (Will have to manually type in Cytracom, this will tell it to use the alias that was created earlier.)
  • Set bandwidth upload/download limits for phone. The phones will normally use up to 90kbps on a call. (5 phones x 90kbps = 450kbps upload and download.)
  • Select Next.

traffic_shaping_4.png

  • Step three will allow you to set up a feature called Penalty Box, this allows for you to deprioritize traffic of devices that are using large amount or a specific threshold of bandwidth. It is recommended to ignore this step in regard to any IP's or services in relation to Cytracom.

traffic_shaping_6.png

  • The next few steps will allow to change prioritizes of well-known programs. In most cases you can leave these settings as they are and just select next. On the last page you will be alerted that after pressing finish it will create the new traffic shaper and enable it.

traffic_shaping_end.png

  • Lastly reboot all of the phones for the traffic shaper to take effect.
Was this article helpful?
1 out of 1 found this helpful
Have more questions? Submit a request