If you’ve had a VPS with Hetzner in Europe (very competitive hosting rates) and you’re a Tailscale aficionado you’ve probably used Tailscale and been unhappy with upload/download speeds in kilobytes when connected via Tailscale over SSH. It turns out one reason for the low throughput is that you use pfSense as your firewall, and it can be difficult for Tailscale to punch a hole through pfSense. As a result, it falls back to its DERP servers, which are shared resources for all Tailscale users and often have poor throughput. With that said, here’s a quick change to apply on pfSense to alleviate the problem.
Let’s face it. You’re supposed to do important work but want to listen to some music you remembered on youtube and then get carried away into watching something more interesting, forgetting you have a job at hand. Kids with homeworks due are the most vulnerable :).
Say you want to disable internet access on a specific computer in your LAN/wifi between 11 p.m. and 2 a.m. every day and you have the pfsense (https://pfsense.org) firewall properly set up. Here are the steps:
I’ve always heard of pfsense as a great opensource firewall with a nice list of features. We have an MR60 with two APs (MS60) for a total of three access points and its a great piece of hardware providing good wireless through the two stories. I wanted to control internet access and MR60 has a module to do that but only for a yearly subscription. I thought this was a perfect time to set up pfSense so this blog is about installing pfsense where there’s an existing Netgear MR60 with two MS60s.