Re: [pfSense Support] There were error(s) loading the rules

2005-08-21 Thread Scott Ullrich
Bill found this problem and commited a fix.  Please let me know if it
continues to be an issue.

Scott


On 8/19/05, alan walters [EMAIL PROTECTED] wrote:
 Backup the xml file and find the ipsec section and replace with the below code
 
 Replace the ipsec section with:
 
 ipsec
 /ipsec
 
 -Original Message-
 From: Bastian Schern [mailto:[EMAIL PROTECTED]
 Sent: 19 August 2005 23:02
 To: Scott Ullrich
 Cc: alan walters; [EMAIL PROTECTED]
 Subject: Re: [pfSense Support] There were error(s) loading the rules
 
 I think I did nothing with the IPSec rule. But is there a way to get the
 FW back to work?
 
 Bastian
 
 Scott Ullrich schrieb:
  On 8/19/05, alan walters [EMAIL PROTECTED] wrote:
 
 There are two ways to remake the error that I found.
 
 
 (1) create a new firewall rule and apply it.
 
 
  [click to toggle enabled/disabled status]  *   *   *   *
 *   TestRule
 
  I added the rule above.  No issues.
 
 
 (2) to save the ipsec configuration (DOES NOT MATTER WHEATHER THERE IS 
 ANYTHING IN IT OR NOT)
 
 
  I just changed my ipsec.  Again, no issues.  The problem is either
  fixed on recent versions or this is not how to reliably reproduce it.
 
  Scott
 
  -
  To unsubscribe, e-mail: [EMAIL PROTECTED]
  For additional commands, e-mail: [EMAIL PROTECTED]
 
 
 
 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]
 
 
 --
 No virus found in this incoming message.
 Checked by AVG Anti-Virus.
 Version: 7.0.338 / Virus Database: 267.10.13/78 - Release Date: 19/08/2005
 
 
 --
 No virus found in this outgoing message.
 Checked by AVG Anti-Virus.
 Version: 7.0.338 / Virus Database: 267.10.13/78 - Release Date: 19/08/2005
 
 
 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]
 


-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



[pfSense Support] There were error(s) loading the rules

2005-08-19 Thread Bastian Schern

Hello,

I have some problems with pfSense 0.77. I got this message:

php: : There were error(s) loading the rules: /tmp/rules.debug:110: 
syntax error /tmp/rules.debug:111: syntax error /tmp/rules.debug:112: 
syntax error /tmp/rules.debug:113: syntax error /tmp/rules.debug:114: 
syntax error /tmp/rules.debug:115: syntax error /tmp/rules.debug:116: 
syntax error pfctl: Syntax error in config file: pf rules not loaded - 
The line in question reads [110]: pass quick on rl0 proto esp from 
172.16.0.72 to keep state label IPSEC: esp proto


The Problem is now: The pfSense will nor route anylonger!
From the LAN side it is possible to ping the WAN interface of the FW 
(172.16.0.72) but it is not possible to ping any other host (e.g. 
172.16.0.71) in front of the WAN interface.
Directly from the FW (via webinterface) it is possible to ping hosts in 
front of the WAN interface.


What is going wrong?

Regards
Bastian

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



RE: [pfSense Support] There were error(s) loading the rules

2005-08-19 Thread alan walters
I agree this is still an issue in 0.77.
It happens when you change the firewall rules.

It does not matter what is in the ipsec setup. Wheather it is empty or
you are using it

-Original Message-
From: Bastian Schern [mailto:[EMAIL PROTECTED] 
Sent: 19 August 2005 18:56
To: support@pfsense.com
Subject: [pfSense Support] There were error(s) loading the rules

Hello,

I have some problems with pfSense 0.77. I got this message:

php: : There were error(s) loading the rules: /tmp/rules.debug:110: 
syntax error /tmp/rules.debug:111: syntax error /tmp/rules.debug:112: 
syntax error /tmp/rules.debug:113: syntax error /tmp/rules.debug:114: 
syntax error /tmp/rules.debug:115: syntax error /tmp/rules.debug:116: 
syntax error pfctl: Syntax error in config file: pf rules not loaded - 
The line in question reads [110]: pass quick on rl0 proto esp from 
172.16.0.72 to keep state label IPSEC: esp proto

The Problem is now: The pfSense will nor route anylonger!
 From the LAN side it is possible to ping the WAN interface of the FW 
(172.16.0.72) but it is not possible to ping any other host (e.g. 
172.16.0.71) in front of the WAN interface.
Directly from the FW (via webinterface) it is possible to ping hosts in 
front of the WAN interface.

What is going wrong?

Regards
Bastian

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



RE: [pfSense Support] There were error(s) loading the rules

2005-08-19 Thread alan walters
There are two ways to remake the error that I found.


(1) create a new firewall rule and apply it.
(2) to save the ipsec configuration (DOES NOT MATTER WHEATHER THERE IS ANYTHING 
IN IT OR NOT)

this happened on at least 8 installs.

Yes I agree you can clear the ipsec and reload the xml but if you do any of the 
above after that the issue comes back

-Original Message-
From: Scott Ullrich [mailto:[EMAIL PROTECTED] 
Sent: 19 August 2005 19:40
To: alan walters
Cc: Bastian Schern; support@pfsense.com
Subject: Re: [pfSense Support] There were error(s) loading the rules

On 8/19/05, alan walters [EMAIL PROTECTED] wrote:
 I agree this is still an issue in 0.77.
 It happens when you change the firewall rules.
 
 It does not matter what is in the ipsec setup. Wheather it is empty or
 you are using it

I disagree.   I just changed a rule on my firewall at home and then
REBOOTED it.   All 5 of my tunnels are STILL fine.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]


-- 
Internal Virus Database is out-of-date.
Checked by AVG Anti-Virus.
Version: 7.0.338 / Virus Database: 267.10.4/66 - Release Date: 09/08/2005
 

-- 
Internal Virus Database is out-of-date.
Checked by AVG Anti-Virus.
Version: 7.0.338 / Virus Database: 267.10.4/66 - Release Date: 09/08/2005
 

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] There were error(s) loading the rules

2005-08-19 Thread Scott Ullrich
On 8/19/05, alan walters [EMAIL PROTECTED] wrote:
 There are two ways to remake the error that I found.
 
 
 (1) create a new firewall rule and apply it.

[click to toggle enabled/disabled status]*   *   *   *  
 *   TestRule 

I added the rule above.  No issues.

 (2) to save the ipsec configuration (DOES NOT MATTER WHEATHER THERE IS 
 ANYTHING IN IT OR NOT)

I just changed my ipsec.  Again, no issues.  The problem is either
fixed on recent versions or this is not how to reliably reproduce it.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]