[pfSense] Please update the pfSense Wiki with the attached note
Hi Jim (or anyone with editing rights on the Wiki): Coud you please update https://doc.pfsense.org/index.php/VirtIO_Driver_Support by adding a note at the bottom of the Loading Kernel Modules section: With the current (2014-06-11) state of virtio network drivers in FreeBSD, it is necessary to check the Disable hardware checksum offload box on /system_advanced_network.php '''and to manually reboot pfSense after saving the setting, even though there is no prompt telling you to do so''' if you want to be able to reach systems (at least other VM guests, not sure if it also affects real hardware) protected by pfSense directly from the VM host. The whole issue seems to be related to https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=165059 -Stefan ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
[pfSense] Dependencies on older packages?
I went to install wget on a pfsense ( *2.1-RELEASE*) box, and I got this: # pkg_add -r wget Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/Latest/wget.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/pkg-config-0.25_1.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/libidn-1.22.tbz... Done. pkg_add: warning: package 'libidn-1.22' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'libidn-1.22' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed It seems that the wget package is out of date, as it depends on older versions of packages than the ones already installed. Is this to be expected? The only other package I had installed was iperf (via the GUI). Thanks, Brian. ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Please update the pfSense Wiki with the attached note
On 6/11/2014 4:40 AM, Stefan Baur wrote: Hi Jim (or anyone with editing rights on the Wiki): I added that text (with some minor edits) to the page. Jim ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Weird routing issue with pfSense-2.1.3-RELEASE-i386, Debian Wheezy, kvm and virtio
On Jun 10, 2014, at 5:37 PM, Stefan Baur newsgroups.ma...@stefanbaur.de wrote: Am 10.06.2014 22:52, schrieb Karsten Gorling: * Stefan Baur newsgroups.ma...@stefanbaur.de [140610 17:59]: This works all fine and dandy as long as I'm not using virtio: I had the same Problem. Essentially the VirtIO Network Drivers of FreeBSD are broken, you have to use another virtual Network Card. https://groups.google.com/forum/#!msg/mailing.freebsd.bugs/gw42Il1AX0o/3zj-gnRKgHIJ Browsing through the pfSense forum and the FreeBSD Bugtracker, I found that checking the Disable hardware checksum offload box on /system_advanced_network.php *and manually rebooting after saving* solved the problem for me. Haven't done any performance comparisons yet, though. Maybe you want to try the same? Again, it seems to be important to reboot pfSense manually after the change - there's no prompt telling you you should (all it says is The changes have been applied successfully. - but they don't come to life until you reboot). I've had problems using pf under KVM with the virtio driver, as reported in this thread: http://lists.freebsd.org/pipermail/freebsd-stable/2013-August/074637.html In my case, it would provoke abrt crash reports on the KVM host. I subsequently discovered that this did not happen when using the e1000 driver in the FreeBSD guest, so it seems that pf in general is not a problem for FreeBSD guests under KVM, just the pf+virtio (vnetX) combination. IIRC, I didn't notice a severe performance degradation when switching temporarily to the e1000 driver. It isn't too big an issue for me right now because I do firewalling at the pfSense gateway and not on the guests. It would be nice for the pf + virtio combination to work harmoniously, though, so I'd have the option of firewalling on the guests, too, if needed at some point. Cheers, Paul. ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
[pfSense] Fan Control
Hi everyone. I got two Sophos UTM 220 for my home lab and sucessfully installed pfSense in each one. The problem is that they make LOUD NOISE, and when I say loudy, I have to leave the room haha They start their fans in high velocity and don't change it anymore. Is there any fan control in pfSense (even in console)? Best regards. ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Fan Control
Hi. This feature could be very good, I think that this is the freebsd issue. Because when the air conditioning fail and server temperatures starts be high and fans are on 100% after fixing the air conditioning it never come back to the normal and reboot is required. We have some HP DL380 G4 and G5, yes these servers are very old but as router are working very well ☺ Thanks and best regards. Martin From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jonatas Baldin Sent: 11. června 2014 16:16 To: pfSense support and discussion Subject: [pfSense] Fan Control Hi everyone. I got two Sophos UTM 220 for my home lab and sucessfully installed pfSense in each one. The problem is that they make LOUD NOISE, and when I say loudy, I have to leave the room haha They start their fans in high velocity and don't change it anymore. Is there any fan control in pfSense (even in console)? Best regards. This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security and assessment of internal compliance with Accenture policy. __ www.accenture.com ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Fan Control
My UTM start on 100% and stay the same all the time. On the BIOS setup there's no configuration for fan control too. It's getting annoying :( Em 11/06/2014 11:38, martin.krali...@accenture.com escreveu: Hi. This feature could be very good, I think that this is the freebsd issue. Because when the air conditioning fail and server temperatures starts be high and fans are on 100% after fixing the air conditioning it never come back to the normal and reboot is required. We have some HP DL380 G4 and G5, yes these servers are very old but as router are working very well J Thanks and best regards. Martin *From:* List [mailto:list-boun...@lists.pfsense.org] *On Behalf Of *Jonatas Baldin *Sent:* 11. června 2014 16:16 *To:* pfSense support and discussion *Subject:* [pfSense] Fan Control Hi everyone. I got two Sophos UTM 220 for my home lab and sucessfully installed pfSense in each one. The problem is that they make LOUD NOISE, and when I say loudy, I have to leave the room haha They start their fans in high velocity and don't change it anymore. Is there any fan control in pfSense (even in console)? Best regards. -- This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security and assessment of internal compliance with Accenture policy. __ www.accenture.com ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
[pfSense] lots of problem with squid3-dev and squidguard-squid3
Dear all experts, i install only packages in my pfsense firewall one of squid3-dev then squidguard-squid3 and i alos properly configured it with transparent proxy because i do not need to go client pc and change to proxy settings on any browser. squid and squid guard services are properly started at status -- services but when i try to check internet at client pc some times it works fine and main problem is google and gmail is not opening other all sites are open properly then i block the https facebook and https youtube its only block http facebook or youtube. https facebook or https youtube are properly works. please give any idea where i m wrong. thanks A Mohan Rao Network Administrator IPS ACADEMY INDORE MADHYA PRADESH +91 98260 61122 ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] lots of problem with squid3-dev and squidguard-squid3
How are you blocking websites ? Use blacklist option for the websites you want blocked . HTH Faisal Gillani Pakistan Sent from my Verizon Wireless 4G LTE Smartphone - Reply message - From: A Mohan Rao mohanra...@gmail.com To: pfSense Support and Discussion Mailing List List@lists.pfsense.org Subject: [pfSense] lots of problem with squid3-dev and squidguard-squid3 Date: Wed, Jun 11, 2014 9:54 PM Dear all experts, i install only packages in my pfsense firewall one of squid3-dev then squidguard-squid3 and i alos properly configured it with transparent proxy because i do not need to go client pc and change to proxy settings on any browser. squid and squid guard services are properly started at status -- services but when i try to check internet at client pc some times it works fine and main problem is google and gmail is not opening other all sites are open properly then i block the https facebook and https youtube its only block http facebook or youtube. https facebook or https youtube are properly works. please give any idea where i m wrong. thanks A Mohan Rao Network Administrator IPS ACADEMY INDORE MADHYA PRADESH +91 98260 61122___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] lots of problem with squid3-dev and squidguard-squid3
First thanks for reply my email. for sites blocking i m using proxy filter http://www.shallalist.de/Downloads/shallalist.tar.gz Blacklist options Blacklist Check this option to enable blacklistBlacklist proxy Blacklist upload proxy - enter here, or leave blank. Format: host:[port login:pass] . Default proxy port 1080. Example: '192.168.0.1:8080 user:pass'Blacklist URL Enter the path to the blacklist (blacklist.tar.gz) here. You can use FTP, HTTP or LOCAL URL blacklist archive or leave blank. The LOCAL path could be your pfsense (/tmp/blacklist.tar.gz). On Wed, Jun 11, 2014 at 10:42 PM, faisal.gill...@akesp.org faisal.gill...@akesp.org wrote: How are you blocking websites ? Use blacklist option for the websites you want blocked . HTH Faisal Gillani Pakistan Sent from my Verizon Wireless 4G LTE Smartphone - Reply message - From: A Mohan Rao mohanra...@gmail.com To: pfSense Support and Discussion Mailing List List@lists.pfsense.org Subject: [pfSense] lots of problem with squid3-dev and squidguard-squid3 Date: Wed, Jun 11, 2014 9:54 PM Dear all experts, i install only packages in my pfsense firewall one of squid3-dev then squidguard-squid3 and i alos properly configured it with transparent proxy because i do not need to go client pc and change to proxy settings on any browser. squid and squid guard services are properly started at status -- services but when i try to check internet at client pc some times it works fine and main problem is google and gmail is not opening other all sites are open properly then i block the https facebook and https youtube its only block http facebook or youtube. https facebook or https youtube are properly works. please give any idea where i m wrong. thanks A Mohan Rao Network Administrator IPS ACADEMY INDORE MADHYA PRADESH +91 98260 61122 ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Dependencies on older packages?
On Wed, Jun 11, 2014 at 6:41 AM, Brian Candler b.cand...@pobox.com wrote: I went to install wget on a pfsense ( *2.1-RELEASE*) box, and I got this: # pkg_add -r wget Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/Latest/wget.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/pkg-config-0.25_1.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/libidn-1.22.tbz... Done. pkg_add: warning: package 'libidn-1.22' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'libidn-1.22' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed It seems that the wget package is out of date, as it depends on older versions of packages than the ones already installed. Is this to be expected? The only other package I had installed was iperf (via the GUI). Thanks, Brian. I'm not sure that it's a big deal, at least for wget. On my pfSense test machine which is currently running 2.1, I get those warnings, but wget works just fine afterwards despite them. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] Dependencies on older packages?
On Jun 11, 2014, at 7:41, Brian Candler b.cand...@pobox.com wrote: I went to install wget on a pfsense ( 2.1-RELEASE) box, and I got this: # pkg_add -r wget Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/Latest/wget.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/pkg-config-0.25_1.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/libidn-1.22.tbz... Done. pkg_add: warning: package 'libidn-1.22' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'libidn-1.22' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed It seems that the wget package is out of date, as it depends on older versions of packages than the ones already installed. Is this to be expected? The only other package I had installed was iperf (via the GUI). Yes, it’s expected. You are using a FreeBSD repo made when 8.3 was released, after that, ports tree received tons of updates. You can try to set PACKAGESITE env var pointing to 8.4-release packages or even to 8-stable and see if it helps. It’s just good to remember that it’s not an officially way to install things on pfSense. -- Renato Botelho http://people.freebsd.org/~garga/pubkey.asc ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] [pfSenseyd] Dependencies on older packagesd. Ccc?
Kmkokhuhhj b Sent from my BlackBerry 10 smartphone. Original Message From: Renato Botelho Sent: Wednesday, June 11, 2014 17:53 To: pfSense Support and Discussion Mailing List Reply To: pfSense Support and Discussion Mailing List Subject: Re: [pfSense] Dependencies on older packages? On Jun 11, 2014, at 7:41, Brian Candler b.cand...@pobox.com wrote: I went to install wget on a pfsense ( 2.1-RELEASE) box, and I got this: # pkg_add -r wget Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/Latest/wget.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/pkg-config-0.25_1.tbz... Done. Fetching ftp://ftp.freebsd.org/pub/FreeBSD/ports/amd64/packages-8.3-release/All/libidn-1.22.tbz... Done. pkg_add: warning: package 'libidn-1.22' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'libidn-1.22' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'libiconv-1.13.1_2', but 'libiconv-1.14_1' is installed pkg_add: warning: package 'wget-1.13.4_1' requires 'gettext-0.18.1.1', but 'gettext-0.18.3' is installed It seems that the wget package is out of date, as it depends on older versions of packages than the ones already installed. Is this to be expected? The only other package I had installed was iperf (via the GUI). Yes, it’s expected. You are using a FreeBSD repo made when 8.3 was released, after that, ports tree received tons of updates. You can try to set PACKAGESITE env var pointing to 8.4-release packages or even to 8-stable and see if it helps. It’s just good to remember that it’s not an officially way to install things on pfSense. -- Renato Botelho http://people.freebsd.org/~garga/pubkey.asc ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list
Re: [pfSense] lots of problem with squid3-dev and squidguard-squid3
still i m not get any success no body can still help... On Wed, Jun 11, 2014 at 10:45 PM, A Mohan Rao mohanra...@gmail.com wrote: First thanks for reply my email. for sites blocking i m using proxy filter http://www.shallalist.de/Downloads/shallalist.tar.gz Blacklist options Blacklist Check this option to enable blacklist Blacklist proxy Blacklist upload proxy - enter here, or leave blank. Format: host:[port login:pass] . Default proxy port 1080. Example: '192.168.0.1:8080 user:pass' Blacklist URL Enter the path to the blacklist (blacklist.tar.gz) here. You can use FTP, HTTP or LOCAL URL blacklist archive or leave blank. The LOCAL path could be your pfsense (/tmp/blacklist.tar.gz). On Wed, Jun 11, 2014 at 10:42 PM, faisal.gill...@akesp.org faisal.gill...@akesp.org wrote: How are you blocking websites ? Use blacklist option for the websites you want blocked . HTH Faisal Gillani Pakistan Sent from my Verizon Wireless 4G LTE Smartphone - Reply message - From: A Mohan Rao mohanra...@gmail.com To: pfSense Support and Discussion Mailing List List@lists.pfsense.org Subject: [pfSense] lots of problem with squid3-dev and squidguard-squid3 Date: Wed, Jun 11, 2014 9:54 PM Dear all experts, i install only packages in my pfsense firewall one of squid3-dev then squidguard-squid3 and i alos properly configured it with transparent proxy because i do not need to go client pc and change to proxy settings on any browser. squid and squid guard services are properly started at status -- services but when i try to check internet at client pc some times it works fine and main problem is google and gmail is not opening other all sites are open properly then i block the https facebook and https youtube its only block http facebook or youtube. https facebook or https youtube are properly works. please give any idea where i m wrong. thanks A Mohan Rao Network Administrator IPS ACADEMY INDORE MADHYA PRADESH +91 98260 61122 ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list