Re: [pfSense Support] pfsense 1.2.3 ipsec stopping to work after too many unsuccessful connects

2011-02-12 Thread David Rees
On Fri, Feb 11, 2011 at 7:10 PM, Chris Buechler cbuech...@gmail.com wrote:
 On Fri, Feb 11, 2011 at 5:31 PM, David Rees dree...@gmail.com wrote:
 Ah, now I see my confusion.  You can't create an alias or firewall
 rule with a hostname in 1.2.3

 You can do that too. :)  doesn't update automatically though, have to
 cron a ruleset reload. 2.0 handles it very nicely.

Hmm.. so what am I missing?  When trying to create an alias with a
host name, I get an error when I use either the Host(s) or Network(s)
type.

If I try to create a rule, set the source type to Single host or alias
and type in a hostname for the address, I get an error, too.

Good to know 2.0 will be able to handle this nicely, though as it does
come in handy on occasion...

Thanks

-Dave

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



[pfSense Support] install pfsense from usb stick

2011-02-12 Thread Hans Maes

Hello,

I've searched google and the forum but couldn't find a working answer, 
so I thought I'd ask here.
Is it possible to install the full version of pfsense from USB stick in 
stead of from a cdrom ?


I'm asking because I'm installing a fair share of pfsense boxes 
regularly, and I never have an empty CDR at hand. I normally do have 
plenty of USB sticks with me.
I usually install debian or ubuntu from usb stick by converting the 
install ISO to a usb stick by using the ubuntu startup disk creator tool.
However, that doesn't seem to work with the pfsense ISO. (not a real 
suprise but it didn't hurt trying)


Next, I tried UNetbootin, which gave me partial success. (It seems like 
a very nice usb boot disk creator tool for all kinds of purposes)
Simply converting the pfSense iso to usb stick didn't seem to boot, but 
creating a default FreeBSD 7.2 boot stick works and boots up to the 
freebsd installer.


Thinking I was almost there I copied the contents of the pfsense install 
ISO into the root of the working FreeBSD 7.2 usb boot stick (overwriting 
all existing files) hoping this would make the usb stick boot to the 
pfsense installer. However, no joy... it still boots the original 
FreeBSD 7.2 installer.


My first guess is there is a config file somewhere that tells the boot 
process which installer to start after setting up a minimalistic 
environment.
Being more of a linux guy myself, I don't have enough FreeBSD knowledge 
to know what I need to change to make it run the pfsense installer.


Could anybody tell me what would be the next step ?

I'm sure this would be a very useful entry in the pfsense online 
documentation as well, since I found quite a lot of people online asking 
the same question but never found a working procedure.


Thanks!

Regards,

Hans

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



Re: [pfSense Support] install pfsense from usb stick

2011-02-12 Thread David Burgess
The 2.0 snapshots include a usb image. Installing 1.2.3 from usb will be a
bit of a trick, as you have learned.

db


Re: [pfSense Support] install pfsense from usb stick

2011-02-12 Thread Jim Pingle
On 2/12/2011 5:43 PM, Hans Maes wrote:
[snip]
 I'm sure this would be a very useful entry in the pfsense online
 documentation as well, since I found quite a lot of people online asking
 the same question but never found a working procedure.

No need to make one yourself. 2.0 includes them already. I made one for
1.2.3. It's not official of course but it works.

http://cvs.pfsense.org/~jimp/pfSense-1.2.3-usbinstall.img.gz

Jim

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



[pfSense Support] Weird DHCP issue with multiple VLANS

2011-02-12 Thread Charles N Wyble
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hi all,

Got a weird DHCP issue.

I have several VLANs setup on my pfsense box. One is my desktop VLAN,
one is my guest wireless VLAN. These both hand out DHCP addresses just
fine (to physical hosts and virtual machines).

I am now trying to use DHCP on a third VLAN. Going to put my DMZ virtual
machines in this VLAN. DHCP traffic never gets to the firewall.
I see it in the VM and on the host. Bridging is setup correctly etc.
I don't even see ping traffic hitting the interface when I ping it.

# ifconfig vlan3
vlan3: flags=8843UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST metric 0 mtu 1500
options=3RXCSUM,TXCSUM
ether 00:1a:a0:5c:2e:87
inet6 fe80::21a:a0ff:fe5c:2e87%vlan3 prefixlen 64 scopeid 0xa
inet 10.10.7.1 netmask 0xff00 broadcast 10.10.7.255
media: Ethernet autoselect (100baseTX full-duplex)
status: active
vlan: 5 parent interface: bge0
#

Doing tcpdump -qni vlan3 and requesting a DHCP address or pinging the
interface, no traffic shows up. However the ping succeeds.

I have DHCP enabled for the interface, don't have deny unknown clients
enabled. Have a static mapping setup for the lease I want to hand out.

Any ideas? Let me know if any other info is needed.


- -- 
Charles N Wyble (char...@knownelement.com)
Systems craftsman for the stars
http://www.knownelement.com
Mobile: 626 539 4344
Office: 310 929 8793
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJNVwY5AAoJEMvvG/TyLEAtRH8P/ifaUGk8aR6EwnOoTF/a5JcU
L5so+DPfEOzcurJJARhuEGocX5PlySJ8lv/MZjeT8ju5tIKtTaLa0jynKovhn7Yh
jalSjLqlS+bS7GFrQoQmhZkamJ2wvqCsGIlHANpeRV8y+ckMocT6UxRoazdOAflm
SY2gQhOz1ArzAEzrGiKPDIpiKUbiYcu4d8DuvW8A4GZWXHlRdalvBpFlCqRlIBog
2xDffSHFaxhVryquMcGI/imGxOAOudKanB+h85ih+hkn3gnJEVTdND41qXjy1NWM
1WI59MNpX+fg3qNs9DVbolAB4RA4yb8snP6KjhG77o1qp9aCSKMNbD4AUPXMQg7V
cMhcOy+dVnw2acjtZNAcjO4Gkku2md9CueJ8TvaYIi8+kfUPjslipqqYJ9ae0kiP
MrY+yd01hCOnX+Qok+JLYVajobXwrPKhWeEjzhWizP6a5f79pTWPTrFKFWClrPY9
GTfV24b+GxKbBEkRZwfwpexqVPaRkaJy60gilVbxM0QMZVz7FkDHpVnKWZP+pgTq
IBsMYPDhNrEk2ahMcMQBnYG5S29Vwm2HT6bbrkazYqbR7TYYvqtv1iVxeXjKx9Yi
Row00uZrIY6rK+9W/H7vu0T0JKvtqS8ncstgqw86G4Gpi7JiLxHczDbRTwK50r7k
R6Omfc9IUlq1EcdRXPqa
=ecG6
-END PGP SIGNATURE-

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org