Re: [pfSense-discussion] pfsense on a flash drive

2011-05-12 Thread Scott Ullrich
On Thu, May 12, 2011 at 8:38 PM, Muhammad Panji sumodi...@gmail.com wrote: Dear All, Anyone has experience installing and using pfsens from a flash drive / thumb drive? how is the performance comparing to using hard drive? Thank you regards, For the most part there is no difference in

Re: [pfSense-discussion] And so it ends...

2011-02-03 Thread Scott Ullrich
On Thu, Feb 3, 2011 at 9:54 AM, Eugen Leitl eu...@leitl.org wrote: I have a hunch IPv6 deployment will pick up considerably 1-2 years from now. - Forwarded message from Scott Howard sc...@doc.net.au - From: Scott Howard sc...@doc.net.au Date: Thu, 3 Feb 2011 06:35:57 -0800 To:

Re: [pfSense-discussion] PfSense localization

2011-01-04 Thread Scott Ullrich
On Tue, Jan 4, 2011 at 5:07 AM, William David Armstrong biosyst...@gmail.com wrote: I can help for  translate  in Brazilian Portuguese http://pootle.pfsense.org.br:8080/docs/resources.html Scott - To unsubscribe, e-mail:

Re: [pfSense-discussion] PfSense localization

2011-01-04 Thread Scott Ullrich
On Tue, Jan 4, 2011 at 10:40 AM, st41...@st41ker.net wrote: Thank you. It's good to know that. But is there is some prognosis on the 2.0 release date? Yep, when it's done. Scott - To unsubscribe, e-mail:

Re: [pfSense-discussion] Re: Low end, cool CPE.

2010-11-12 Thread Scott Ullrich
On Fri, Nov 12, 2010 at 5:51 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: [snip] But still - no IPv6 support (though a 3rd-party patch is now available to beat it in, it's not up to par yet, and it's not in 'stable').  :( The work Seth is doing will be in 2.1 sometime next year. He has

Re: [pfSense-discussion] pfSense router/firewall in a Vmware ESXi guest for other guests

2010-10-02 Thread Scott Ullrich
On Sat, Oct 2, 2010 at 2:27 PM, Adam Thompson athom...@c3a.ca wrote: It works, but performance is, in my experience, poor.  Don't use trunking (802.3ad / LACP) and VLANs together, or inter-vlan routing slows down drastically.  This appears to be a VMWare problem, not a pfSense problem. I

Re: [pfSense-discussion] pfSense 2.0 will do FreeBSD 8.1?

2010-07-28 Thread Scott Ullrich
On Wed, Jul 28, 2010 at 10:11 AM, Eugen Leitl eu...@leitl.org wrote: Thanks. Is boot from zfs root an install option? No, the installer does not have ZFS support and we will not see ZFS support into 2.1 at the earliest when work on the new installer picks up steam. Scott

Re: [pfSense-discussion] port to freescale 8349e

2010-06-18 Thread Scott Ullrich
On Fri, Jun 18, 2010 at 12:42 PM, Zied Fakhfakh zyd...@gnet.tn wrote: On 06/07/2010 05:07 PM, Zied Fakhfakh wrote: Hi, I'm planning to port/build pfsense on freescale 8349e powerpc based system. http://www.freescale.com/webapp/sps/site/prod_summary.jsp?code=MPC8349E It holds the e300

Re: [pfSense-discussion] any chances to see pfsense on GuruPlug Plus?

2010-02-25 Thread Scott Ullrich
On Thu, Feb 25, 2010 at 1:05 PM, Paul Mansfield it-admin-pfse...@taptu.comwrote: I asked them if there was a UK distributor, and they responded promptly with http://www.newit.co.uk/shop/products.php?cat=11 dual ethernet for less than £100 (US$150) seems quite a good deal. For about the

Re: [pfSense-discussion] pfSense book now available for purchase

2009-11-04 Thread Scott Ullrich
On Wed, Nov 4, 2009 at 12:13 PM, cl...@pfsense pfse...@mail-fwd.archie.dk wrote: Can't wait for the electronic version  :-) I believe only commercial support customers will have access to the electronic version. And folks, please respect the authors and do not pirate it. kthanks Scott

Re: [pfSense-discussion] IPsec and OPT

2009-11-03 Thread Scott Ullrich
On Tue, Nov 3, 2009 at 7:45 AM, Eugen Leitl eu...@leitl.org wrote: Anyone has a working IPsec config with a virtual OPT device (VIP or similar) you could share? I've made a tunnel (one end is transparent bridge, terminated on WAN), but can't route between networks. I'll move on to OpenVPN

Re: [pfSense-discussion] BGP to get Internet

2009-10-29 Thread Scott Ullrich
On Thu, Oct 29, 2009 at 9:32 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: I thought you corrected .php to exclude Gateway input field. So I just modify config.xml and never go to gui to modify WAN interface, right? Yep, that boxes WAN IP never changes. Scott

Re: [pfSense-discussion] Is there a 1.2.2 change log?

2009-10-16 Thread Scott Ullrich
On Fri, Oct 16, 2009 at 4:38 PM, Marty Nelson mnel...@transdyn.com wrote: Hey everyone.  I’m running 1.2.1 and was wondering if there was a change log available?  I poked around the pfSense site as well as the forums and I either blindly missed it, or it’s not obvious.  J Please see

Re: [pfSense-discussion] fully redundant dual-WAN setup

2009-08-11 Thread Scott Ullrich
On Tue, Aug 11, 2009 at 5:03 AM, Veiko Kukkveiko.k...@krediidipank.ee wrote: I have tried dual wan and dual machine setup with no success. Dual wan pfsense only works with single machine. carp also works, but both carp *and* dual wan together does not work! And seems there are very few who

Re: [pfSense-discussion] xen aware pfsense.

2009-01-27 Thread Scott Ullrich
On Tue, Jan 27, 2009 at 10:15 PM, pfsense sense pfse...@kavadas.org wrote: i'm not suggesting pfsense be run inside a VM, i am suggesting pfsense provide VM functionality i'm fully aware the VM's shortcomings, i manage a 14TB ESX cluster let me say that again... i am suggesting pfsense

Re: [pfSense-discussion] pfSense as VDSL Router

2008-11-03 Thread Scott Ullrich
On Mon, Nov 3, 2008 at 11:41 AM, Eugen Leitl [EMAIL PROTECTED] wrote: FYI: http://www.heise.de/netze/pfSense-als-VDSL-Router--/artikel/116739 /kraut (Notice that IP-TV needs IGMP support which is apparently not in pfSense kernel? Here's a thread, which says the problem is an IGMP proxy

Re: [pfSense-discussion] We have received your email and someone will be responding shortly.

2008-09-11 Thread Scott Ullrich
[EMAIL PROTECTED] removed from mailing list discussion@pfsense.com Sorry about the noise folks! Scott On Thu, Sep 11, 2008 at 10:45 AM, [EMAIL PROTECTED] wrote: We have received your email and someone will be responding shortly. Please do not respond to this email -- it is automatically

Re: [pfSense-discussion] DNS resolver test

2008-07-22 Thread Scott Ullrich
On Tue, Jul 22, 2008 at 2:32 PM, Eugen Leitl [EMAIL PROTECTED] wrote: http://www.provos.org/index.php?/pages/dnstest.html DNS Resolver Test For secure name resolution, it is important that your DNS resolver uses random source ports. The box below will tell you if there is something you

[pfSense-discussion] 1.2.1-BETA snapshots now available!

2008-07-06 Thread Scott Ullrich
Please see http://blog.pfsense.org/?p=207 for more information. Thanks!

Re: [pfSense-discussion] Used ALIX or Soekris?

2008-06-27 Thread Scott Ullrich
On Fri, Jun 27, 2008 at 3:37 PM, Andrew Burnette [EMAIL PROTECTED] wrote: I had similar thoughts a while back. doesn't always work out the way you think. (e.g. toyota prius, while a politically and technologically needed car, actually saves no energy over it's lifespan due to the enormous

Re: [pfSense-discussion] clog size

2008-04-14 Thread Scott Ullrich
On 4/14/08, Paul M [EMAIL PROTECTED] wrote: RB wrote: I've had a request to increase logging duration on systems that have no access to an external syslog server, so am making the necessary changes to maintain much larger ring-log files. Incredibly larger - what we've done is to make

Re: [pfSense-discussion] BUG? Access to bandwidhtd without password

2008-03-18 Thread Scott Ullrich
On 3/18/08, Cristiano Deana [EMAIL PROTECTED] wrote: Hi, pfsense 1.2, I installed hte package of bandwitdhd. If I access to https://my.pfsense/bandwithd/ there is no request for password Do you thing is it right? That is correct. Firewall off the port to only trusted hosts. Scott

Re: [pfSense-discussion] freebsd 6.2 ports archive

2008-03-13 Thread Scott Ullrich
On 3/13/08, Paul M [EMAIL PROTECTED] wrote: Hi, I was looking for the syslog-ng package to install on my pfsense boxes, and discovered that the main freebsd site no longer has the ports for that release - only 6.3. I found the ftp.de.freebsd.org site still had it, so I did an evil hack

[pfSense-discussion] Mirror finder

2008-03-13 Thread Scott Ullrich
Thanks everyone (20+) of you for notifying us of the mirror problems. It is now resolved. Scott

Re: [pfSense-discussion] 1.2RC5 or release

2008-02-11 Thread Scott Ullrich
On Feb 11, 2008 9:15 AM, Chris Buechler [EMAIL PROTECTED] wrote: We'll probably skip RC5 as an official release even though the snapshots are labeled as such right now. Yeah. no plans to release 1.2-RC5 except in its current snapshot form. I changed the version so we can identify new issues

Re: [pfSense-discussion] bogons update issue

2008-02-03 Thread Scott Ullrich
On 2/3/08, Jan Hoevers [EMAIL PROTECTED] wrote: I'm running the embedded version of pfSense on a Soekris 4801. Today (3 Feb 2008) I upgraded to 1.2-RC4 and it caught my eye that the bogons file (/etc/bogons) dated back to October 2007. I consider bogons filtering important, so I decided not

Re: [pfSense-discussion] lagg + carp: carp not sending multicast via lagg interface

2008-01-23 Thread Scott Ullrich
On 1/23/08, Fabio C Flores [EMAIL PROTECTED] wrote: And how can I find out if 1.2-RC4 uses that freebsd fix? http://pfsense.com/cgi-bin/cvsweb.cgi/tools/patches/RELENG_6_2/if_lagg.diff ... Is what we use. Feel free to send a new patch if it does not include the needed bits. Scott

Re: [pfSense-discussion] (DUP!) duplicated packets when pinging internal server

2008-01-22 Thread Scott Ullrich
I bet it is being caused by your usage of LAGG. Unfortunately you are on your own on this one as LAGG is not supported as of yet. On Jan 22, 2008 2:03 PM, Fabio C Flores [EMAIL PROTECTED] wrote: # ping 10.0.2.10 PING 10.0.2.10 (10.0.2.10): 56 data bytes 64 bytes from 10.0.2.10: icmp_seq=0

[pfSense-discussion] #pfSensechat has been opened

2008-01-10 Thread Scott Ullrich
All, We have opened a new FreeNode pfSense chat room that is meant for off topic discussions for like minded people (pfSensers). Please join us and chat with like minded folks! #pfSenseCHAT on FreeNode. Scott

Re: [pfSense-discussion] Dynamic remote endpoints (IPsec)

2008-01-02 Thread Scott Ullrich
On Jan 2, 2008 6:10 PM, Dennis Karlsson [EMAIL PROTECTED] wrote: Hi In the current beta of m0n0wall they've included the possibility to use a host name as destination gateway address. Will this be included in the 1.2 release? No. 1.2 is frozen. It is already in RELENG_1 and HEAD so should

Re: [pfSense-discussion] Looking for a push in the right direction for VoIP/Cisco 7971 phones

2008-01-02 Thread Scott Ullrich
On 1/2/08, patrickm [EMAIL PROTECTED] wrote: Hi all, I'm in charge of replacing our Cisco PIX firewall with one that will allow us to use VPN, and a bunch of my other sysadmin friends have suggested using pfsense. Everything was super easy to set up initially, and now I want to get our

Re: [pfSense-discussion] Simple patch for Dynamic DNS.

2007-12-05 Thread Scott Ullrich
On 12/5/07, Ben Timby [EMAIL PROTECTED] wrote: I have attached two patches. dyndns-HEAD.patch dyndns-RELENG_1.patch both patch two files: usr/local/www/services_dyndns.php etc/inc/services.inc Thanks! I will check into these this evening. Scott

Re: [pfSense-discussion] Support NTLM

2007-12-05 Thread Scott Ullrich
On 12/5/07, Jose Augusto [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, I need help. I have a firewall running on Linux, and the most faster possible the change the firewall for PFSense, but, in pfsense is possible authentication on NTML (Active Directory)

Re: [pfSense-discussion] Simple patch for Dynamic DNS.

2007-12-01 Thread Scott Ullrich
On 11/27/07, Ben Timby [EMAIL PROTECTED] wrote: I set up the Dynamic DNS feature today, however, I needed to be able to specify my DNS server address. The attached patch adds a field to the services_dyndns.php form. This field if provided will be written to the nscommands file (in

Re: [pfSense-discussion] multiwan ftp proxy

2007-11-19 Thread Scott Ullrich
On Nov 19, 2007 1:50 PM, Bill Marquette [EMAIL PROTECTED] wrote: Assuming I ftp at home (don't recall the last time I intentionally did that!) then ftp works just fine via the primary wan as Chris mentions. I think I did have to create a rule for traffic destined to 127.0.0.1 to use the

Re: [pfSense-discussion] php: : Not installing nat reflection rules for a port range 500 (1.2-RC2)

2007-11-09 Thread Scott Ullrich
You most likely have a port range defined. Scott On Nov 9, 2007 2:26 AM, Tortise [EMAIL PROTECTED] wrote: Hi Team I added a rule for MS TS access to 3389, I get logged php: : Not installing nat reflection rules for a port range 500 and the connection does not seem to be created. I

Re: [pfSense-discussion] Captive portal could not deterimine clients MAC address

2007-09-05 Thread Scott Ullrich
On 9/5/07, Nick Buraglio [EMAIL PROTECTED] wrote: What wireless AP are you using? nb I answered him here: http://forum.pfsense.org/index.php/topic,5999.msg35459.html#msg35459 Tunge2, please stop cross posting between the forum and the mailing list. Scott

Re: [pfSense-discussion] Firmware

2007-08-25 Thread Scott Ullrich
No. Nothing will change from this perspective. Please visit our blog where we describe how this wilkl help the project. Scott On 8/25/07, Mike [EMAIL PROTECTED] wrote: With the recent move to paid support for pfsense and monowall, will this signify the end of the firmware upgrades, package

Re: [pfSense-discussion] 1.2-RC2 released

2007-08-21 Thread Scott Ullrich
On mar, 21 aoû 2007 17:48:24 +0200, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Just one question, from a pfsense newbie where i can download 1.2RC2 update ? Best regards http://www.pfsense.com/mirror.php?section=updates/pfSense-Full-And-Embedded-Update-1.2-RC2.tgz Scott

Re: [pfSense-discussion] atmel avr port of pfsense?

2007-07-31 Thread Scott Ullrich
On 7/31/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: [snip] This looks like a job for NetBSD! Good luck porting pfSense to Net! :) Scott

Re: [pfSense-discussion] atmel avr port of pfsense?

2007-07-31 Thread Scott Ullrich
On 7/31/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Most of the steps should be the same for NetBSD as they are for FreeBSD since they share a lot of commonalities. Not quite. You will find a lot of items that rely on netgraph such as PPTP, PPPoE, etc. Scott

Re: [pfSense-discussion] Package installation / removal problem ?

2007-07-17 Thread Scott Ullrich
Dashboard is still very much a work in progress and has a few issues. Scott On 7/17/07, Daniele Guazzoni [EMAIL PROTECTED] wrote: Small correction: only dashboard stalls Daniele Guazzoni wrote: I'm running 1.2-BETA-2-TESTING-SNAPSHOT-07-05-2007 and it stalls on adding and removing

Re: [pfSense-discussion] Sun Fire X2100 M2 questions

2007-06-21 Thread Scott Ullrich
On 6/21/07, Bill Marquette [EMAIL PROTECTED] wrote: On 6/20/07, Eugen Leitl [EMAIL PROTECTED] wrote: nfe won't be there in 1.3, correct? I can survive with just two interfaces (WAN and LAN) for a while, but I do need at least DMZ rather soon. When they say I should stay away from

Re: [pfSense-discussion] Problems mit DynDNS Update

2007-06-20 Thread Scott Ullrich
Try a recent snapshot. On 6/20/07, Fabian Steiner [EMAIL PROTECTED] wrote: Hello! We are using PfSense 1.2_BETA and are experiencing some serious problems concerning DynDNS updates. Sometimes they are performed (obviously without adding additional options, e.g. wildcard=ON) and sometimes they

Re: [pfSense-discussion] RAID

2007-06-15 Thread Scott Ullrich
On 6/15/07, Eugen Leitl [EMAIL PROTECTED] wrote: There's no SATA soft-RAID support planned in the pfsense install, right? RAID 1 is supported if two disks are present.

Re: [pfSense-discussion] openbsd 10gb stuff

2007-06-04 Thread Scott Ullrich
One of the 10% patches have already been ported and in our tree. We are seeing up to a 33% improvement in performance on some machines such as Soekris 266. Stay tuned, Chris plans on blogging about the improvements soon. Scott On 6/4/07, Jure Pečar [EMAIL PROTECTED] wrote: Just saw this

Re: [pfSense-discussion] MiniUPnPd security risks

2007-04-25 Thread Scott Ullrich
On 4/25/07, DarkFoon [EMAIL PROTECTED] wrote: I'm considering installing the UPnP daemon on some home/home office boxes, and I'm curious what the security issues are. From my own (simple) analysis, the worst that could happen is a malicious application could ask for many, many (almost all?) of

Re: [pfSense-discussion] Patch submittal deadline?

2007-04-22 Thread Scott Ullrich
RELENG_1 and -HEAD would be fine. We are past RELENG_1_2 deadline. Scott On 4/22/07, Kyle Mott [EMAIL PROTECTED] wrote: Do you care if the diff's/patches are from a February 1.0.1 snapshot, or would you prefer it from a 1.2-BETA snapshot? -Kyle Scott Ullrich wrote: On 4/15/07, Kyle Mott

Re: [pfSense-discussion] Patch submittal deadline?

2007-04-15 Thread Scott Ullrich
On 4/15/07, Kyle Mott [EMAIL PROTECTED] wrote: Is there a deadline for submitting a patch to be included in the base release? I'm still working on my EtherChannel port, but I've still got a few things to work out. Will I still be able to get it in to the next release (I assume 1.2), and/or 1.0.1

Re: [pfSense-discussion] 16 instance of Snort running ???

2007-04-10 Thread Scott Ullrich
On 4/10/07, Daniele Guazzoni [EMAIL PROTECTED] wrote: I upgraded to 1.0.1-SNAPSHOT-03-27-2007, running with the snort package installed. Before the upgrade everything was ok, now I have 16 instances of snort running and crashing regularly. Known problem ? Yes. Uninstall and reinstall the

Re: [pfSense-discussion] routing everything though an IPsec tunnel

2007-03-30 Thread Scott Ullrich
On 3/30/07, Eugen Leitl [EMAIL PROTECTED] wrote: What I really like about pfsense/m0n0 is that it allows you to build IPsec tunnels between firewalls. This is rather important, because I happen to live in a country where ISPs are required to spy on their customers by law (storing all connection

Re: [pfSense-discussion] Box hangs because of PHP ?

2007-03-22 Thread Scott Ullrich
Technically now that the images are 128 megabytes its possible. We just never spent the time to make it work correctly. On 3/22/07, Eugen Leitl [EMAIL PROTECTED] wrote: On Thu, Mar 22, 2007 at 12:20:12PM -0400, Scott Ullrich wrote: Is there a way to upgrade 1.0.1 embedded remotely

Re: [pfSense-discussion] freebsd ports vs pfsense ports

2007-02-28 Thread Scott Ullrich
On 2/28/07, Paul [EMAIL PROTECTED] wrote: Working on mpd, I saw that there's a pfSense ports directory in /home/pfsense/tools I need to port some custom packages to pfSense, so how do I tell the build scripts to use my own port instead of the freebsd ones, or shall I just copy them to

Re: [pfSense-discussion] m0n0wall to PFSense

2007-02-15 Thread Scott Ullrich
On 2/15/07, Salcido, Cesar [EMAIL PROTECTED] wrote: If I were to install PFSense on my Nokia P020 m0n0wall currently installed could I use my existing config.xml with PFSense? Please see http://faq.pfsense.com/index.php?action=artikelcat=4id=89artlang=enhighlight=m0n0wall%20config

Re: [pfSense-discussion] Searched Google but nada

2007-02-14 Thread Scott Ullrich
On 2/14/07, Chris Godwin [EMAIL PROTECTED] wrote: I'm getting a sync error. Both boxes are running 1.0.1 on a hacomm i386 box. I have added additional code to the XMLRPC sync area to hopefully tell us what is going on. Upgrade to a new snapshot an hour from now (around 9pm EST).

Re: [pfSense-discussion] about manage a lot of pfsense in one console interface

2007-01-18 Thread Scott Ullrich
No, this unfortunately will not work like this is outlined PF and IPF are a little too different. But you can use one of our anchors in the rules file to insert and remove rules from cron easier than IPF. On 1/18/07, Sjaak Nabuurs [EMAIL PROTECTED] wrote: Cristian Maybe this is a sugestion

Re: [pfSense-discussion] about manage a lot of pfsense in one console interface

2007-01-18 Thread Scott Ullrich
On 1/18/07, Cristian Mata [EMAIL PROTECTED] wrote: Thks Scoot, wich is the name of the rules file? Because en my freebsd y have pf.conf but in pfsense... the rules are in the xml file? Thanks in advance. Look at /tmp/rules.debug Scott

Re: [pfSense-discussion] Source based redirection

2007-01-16 Thread Scott Ullrich
Nobody is working on it to my knowledge. Scott On 1/16/07, Adam Van Ornum [EMAIL PROTECTED] wrote: Is anyone working on source based redirection? I checked in the forums and one guy had been working on it supposedly but apparently he disappeared. Its a feature I need and I might try doing

Re: [pfSense-discussion] VideoConference problems

2007-01-08 Thread Scott Ullrich
Same situation that VOIP folks run into. Create an advanced outbound NAT rule for this particular port, move it to the top and be sure to enable the static pot option for the rule in question. Also search the forum for static port, it's discussed about once a week at least. Scott On 1/8/07,

Re: [pfSense-discussion] VideoConference problems

2007-01-08 Thread Scott Ullrich
netmeeting machine behind Pfsense don't have video and sound yet. I was reading the forum but said the same below -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Monday, January 08, 2007 12:19 PM To: discussion@pfsense.com Subject: Re: [pfSense-discussion

Re: [pfSense-discussion] VideoConference problems

2007-01-08 Thread Scott Ullrich
You need to define the port in question as well. Scott On 1/8/07, Carlos Julio Sánchez [ACC-SIS] [EMAIL PROTECTED] wrote: Here I send the screenshots, please inform me if I have configured anything wrong Thansks! -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent

Re: [pfSense-discussion] VideoConference problems

2007-01-08 Thread Scott Ullrich
No, you do not want source port, you want destination port. On 1/8/07, Carlos Julio Sánchez [ACC-SIS] [EMAIL PROTECTED] wrote: Hi, i send the screen shots with the port 1720 of netmeeting -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Monday, January 08, 2007 3

Re: [pfSense-discussion] Memory issue

2006-12-28 Thread Scott Ullrich
FreeBSD will buffer as much ram as you give it IIRC. What you really should monitor is top from a shell if you are this worried. I would not be worried at all until memory is in the 90+. Scott On 12/28/06, Jack Mayhew [EMAIL PROTECTED] wrote: I'm seeing the same thing (ver 1.0.1 - though I

Re: [pfSense-discussion] Known PFsense Limits?

2006-12-15 Thread Scott Ullrich
On 12/15/06, Odette [EMAIL PROTECTED] wrote: FYI, I've successfully substituted Linux-iptables with PFsense on Soekris net4801 using 5 eth ports and everything have been running fine for more than 30 days. About the rule translation nightmare: aliases and rules optimization permitted me to

Re: [pfSense-discussion] FTP Server Logging

2006-12-13 Thread Scott Ullrich
The only way to do this is turn off the FTP helper and port forward 21 and the dynamic port range defined on the FTP server. Scott On 12/13/06, Ben Flores [EMAIL PROTECTED] wrote: Is there a way to pass the original external source IP to the internal server? The only IP that shows in the

Re: [pfSense-discussion] help me

2006-11-23 Thread Scott Ullrich
You need to reinstall. Scott On 11/23/06, Carlos Julio Sánchez [ACC-SIS] [EMAIL PROTECTED] wrote: Hi! I upgrades pfsense RC2 to Release 1.0.1 and i have an error in the banner that say [filter load] there were error(s) loading the rules: pfctl: DIOCSETSTATUSIF the line in question reads

Re: [pfSense-discussion] NAT on tun0 used with OpenVPN

2006-11-14 Thread Scott Ullrich
On 11/13/06, Stefan Tunsch [EMAIL PROTECTED] wrote: The problem is that push route options need to be established on both sides of the tunnel. If I establish them only on one side, routing does not happen. Can you please confirm me that there is no way to route traffic from a local network

Re: [pfSense-discussion] NAT on tun0 used with OpenVPN

2006-11-13 Thread Scott Ullrich
On 11/13/06, Stefan Tunsch [EMAIL PROTECTED] wrote: I have seen several posts in the forum stating that tun or tap interfaces should not be assigned to an interface of pfSense. That any/any firewall rules are automatically created when openvpn client establishes connection. And that no traffic

Re: [pfSense-discussion] purpose of VLAN on LAN interface?

2006-11-08 Thread Scott Ullrich
http://en.wikipedia.org/wiki/Vlan On 11/8/06, Jonathan Horne [EMAIL PROTECTED] wrote: i was wondering, what exactly is the purpose of the VLAN support on the LAN interface? can someone give me a quick example of how, why or where this might be used? thanks, jonathan

Re: [pfSense-discussion] Hotspot accounting software

2006-11-08 Thread Scott Ullrich
On 11/8/06, Jason Brunk [EMAIL PROTECTED] wrote: I built something awhile back. This was my setup. 1. multiple captive portals at different locations 2. a freeradius server for authentication 3. mod to freeradius to use mysql for storing info instead of flat text files 4. an entry into the

Re: [pfSense-discussion] Hotspot accounting software

2006-11-08 Thread Scott Ullrich
On 11/8/06, Jason Brunk [EMAIL PROTECTED] wrote: Never used one before. Could be done I suppose. Any suggestions on a good one? I will give it a shot. Give http://asp2php.naken.cc/ a try. Scott

Re: [pfSense-discussion] dnsmasq config file support

2006-10-18 Thread Scott Ullrich
On 10/18/06, Josh Stompro [EMAIL PROTECTED] wrote: I have come across a few situations where I have wanted to be able to add wildcard dns entries to a pfsense box. Dnsmasq does support this through it's config file, dnsmasq.conf with an entry like this. address=/proxy.dns.net/192.168.1.1 or on

Re: [pfSense-discussion] IDS yet?

2006-10-05 Thread Scott Ullrich
On 10/5/06, Chris Godwin [EMAIL PROTECTED] wrote: Am I correct about Snort being able to block as well as detect? Isn't this IDS/IPS, not just IDS. It is a delayed IDS. Generally an IPS hooks into the network stack directly and does not allow the traffic to pass through until its scanned.

Re: [pfSense-discussion] IDS yet?

2006-10-05 Thread Scott Ullrich
On 10/5/06, Jason J. Ellingson [EMAIL PROTECTED] wrote: Snort is kicking some great arse! I'm really loving it. Any way to get it to syslog? I see a lot of MS-SQL worms and such and would (for giggles) like to see all the snort alerts. System logs only shows the attacking IP and not what

Re: [pfSense-discussion] IDS yet?

2006-10-04 Thread Scott Ullrich
Snort requires 1.0-RC3. On 10/4/06, Donald Pulsipher [EMAIL PROTECTED] wrote: I tried to install the snort package but get an error. This was on my Soekris embedded box with the embedded version 1.0-RC1a. Here is the output : - Installation of snort FAILED! Downloading package

Re: [pfSense-discussion] IDS yet?

2006-10-04 Thread Scott Ullrich
SH. Don't tell anyone this. ;) Scott On 10/4/06, Donald Pulsipher [EMAIL PROTECTED] wrote: The /pkg_mgr.php and related files are still in the www directory, I just pointed to them in my url. If I upgrade to RC3, is there an easy way to change the embedded image to support packages

Re: [pfSense-discussion] add support for per-user bandwidth limitation

2006-10-04 Thread Scott Ullrich
This is not feasible. Dummynet (which is what is used on the CP) is not compatible with PF due to a rdr bug of some sort. The problem has been brought up on the FreeBSD lists but nobody is interested in fixing it. Scott On 10/4/06, Jan-Patrick Perisse [EMAIL PROTECTED] wrote: Jonathan De

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-03 Thread Scott Ullrich
On 10/3/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Am Dienstag, den 03.10.2006, 09:09 -0400 schrieb Scott Ullrich: I am telling you how to solve your problem now, not long term. I agree that the FTP system is a mess. Ok, fine, how? At the moment I start the ftpsesame per hand after booting

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-03 Thread Scott Ullrich
On 10/3/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Hi Scott, hi Bill! Am Dienstag, den 03.10.2006, 10:05 -0400 schrieb Scott Ullrich: With the afterfilterchangeshellcmd command. It is run every time a filter change occurs as the last item. So you can override *ANYTHING* the system does

Re: [pfSense-discussion] IDS yet?

2006-10-03 Thread Scott Ullrich
On 9/20/06, Scott Ullrich [EMAIL PROTECTED] wrote: There is no IDS package with no intention on creating one. We are waiting for you all to step up to the plate. I somewhat lied about this. For some reason after seeing your post something clicked in my head and I spent a good 35 hours

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-02 Thread Scott Ullrich
You want to use: o afterfilterchangeshellcmd http://pfsense.blogspot.com/2005/06/new-xml-system-tag-introduced.html Scott On 10/2/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Am Sonntag, den 01.10.2006, 19:33 -0400 schrieb Scott Ullrich: We already run ftp-sesame for bridged

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-01 Thread Scott Ullrich
On 10/1/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Hi all! I do know of that problem since RC1 (possibly the first version I tried it). It hasn't been fixed in 1.0-SNAPSHOT-09-27-06. Since there are some tweaks with it I wanted to discuss about it before writing a bug report. The main problem

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-01 Thread Scott Ullrich
Use CARP. On 10/1/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Hi Scott! Am Sonntag, den 01.10.2006, 21:09 +0200 schrieb Peter Allgeyer: But that only works with port forwarding, right? What about an FTP server listening on 62.13.14.55 instead of 10.0.0.180? Ok, I can try to configure a

Re: [pfSense-discussion] FTP Helper on WAN - bug?

2006-10-01 Thread Scott Ullrich
We already run ftp-sesame for bridged interfaces. Scott On 10/1/06, Peter Allgeyer [EMAIL PROTECTED] wrote: Hi Scott! No, CARP isn't the answer (I saw your posting in the FAQ already). We are using CARP for HA already (and that IMHO should be the only reason for anyone to use CARP at all).

Re: [pfSense-discussion] Tutorial - configuring the captive portal with the integrated user manager

2006-09-28 Thread Scott Ullrich
On 9/28/06, Richard Davis [EMAIL PROTECTED] wrote: I was looking at the pfSense tutorial section and tried to connect to configuring the captive portal with the integrated user manager . All I got was dead links. Does anybody know if this is a good tutorial and if it is where can I get it?

Re: [pfSense-discussion] Nat reflection

2006-09-20 Thread Scott Ullrich
On 9/20/06, Chris Godwin [EMAIL PROTECTED] wrote: I have several 1:1 nat mappings (replacing a pix). How do I get nat reflection to work. There's a check box that disables it but I do not have it checked. Also I've noticed that there is a note under the checkbox that say it only works for

Re: [pfSense-discussion] Proxy arp

2006-09-18 Thread Scott Ullrich
On 9/18/06, Chris Godwin [EMAIL PROTECTED] wrote: I cannot get proxy arp to work, nor can I get VIP's to work as type other. Carp vip's work but when I add more than a few I get a kernel panic. Can anyone point me in the right direction to posts either here or in the forum on this issue so that

Re: [pfSense-discussion] Proxy arp

2006-09-18 Thread Scott Ullrich
On 9/18/06, Chris Godwin [EMAIL PROTECTED] wrote: Really? I just downloaded the newest RC2 today. I'll try it. What constitutes a invalid configuration? No, you need a newer snapshot: http://www.pfsense.com/~sullrich/1.0-SNAPSHOT-09-12-06/ Not reusing the vhid, adding an ip that is outside

Re: [pfSense-discussion] Proxy arp

2006-09-18 Thread Scott Ullrich
On 9/18/06, Chris Godwin [EMAIL PROTECTED] wrote: Still get a panic after trying to add more than 4 vips. Then my box gets thrown into an infinite fsck and panic. Took single user mode to recover. It really shouldn't. What are the IP's that you are adding and what adv skew, vhid, did you use?

Re: [pfSense-discussion] OpenVPN auth-ldap plugin?

2006-09-07 Thread Scott Ullrich
On 9/7/06, Nathan Osborne [EMAIL PROTECTED] wrote: The auth-ldap plugin for OpenVPN looks very interesting. Has anyone taken a look at this for inclusion in pfSense? Authentication against Active Directory seems like a key feature that could help OpenVPN to replace PPTP once and for all.

Re: [pfSense-discussion] Dynamic DNS - no password encryption

2006-08-29 Thread Scott Ullrich
On 8/29/06, DarkFoon [EMAIL PROTECTED] wrote: I was looking through my XML configuration recently, and I noticed that my Dynamic DNS password is not encrypted like the PFsense password is. It seems to me that this is a rather important password and should be encrypted (if possible).

Re: [pfSense-discussion] FreeBSD LSI Logic fixes for VMware

2006-08-18 Thread Scott Ullrich
On 8/16/06, Dmitry Sorokin [EMAIL PROTECTED] wrote: I'm not sure how you did that, but ESX Server doesn't support IDE Hard Drives (neither physical nor virtual). So your VM with IDE Virtual disk just wouldn't run on ESX Server (it's not FreeBSD related, just any OS). Maybe you moved the VM to

Re: [pfSense-discussion] Hamachi and PFSense

2006-08-18 Thread Scott Ullrich
On 8/18/06, Chris Godwin [EMAIL PROTECTED] wrote: Hello All, My name is Chris. I use Hamachi which is supposed to be a zero conf vpn solution. I am having this problem: when creating a 1:1 bimap from my wan's interface to my local pc I can use hamachi fine… I can connect to the hamachi

Re: [pfSense-discussion] source-hash and sticky-address in pf pools

2006-08-17 Thread Scott Ullrich
On 8/17/06, Raja Subramanian [EMAIL PROTECTED] wrote: Hi, I have a pfSense box with 5 wan links, 1 wan and 1 dmz and the load balancing and policy based routing in pfSense is simply fantastic. The one missing feature that I would like to see, is the ability to specify the source-hash or

Re: [pfSense-discussion] source-hash and sticky-address in pf pools

2006-08-17 Thread Scott Ullrich
On 8/17/06, Bill Marquette [EMAIL PROTECTED] wrote: slbd isn't used for gateway balancing, just for monitoring the gateways. The sticky patches that Scott committed (not me) were for server load balancing. My apologies, I thought he was talking about incoming load balancing.

Re: [pfSense-discussion] source-hash and sticky-address in pf pools

2006-08-17 Thread Scott Ullrich
On 8/17/06, Heath Henderson [EMAIL PROTECTED] wrote: Thanks, I might hit you up for that script when I get to it. I have a DSL/Cable modem setup(2 WAN) 1 DMZ and 1 LAN. I am getting ready to setup. I haven't worked with this before, and the routing tables are a bit confusing the first time

Re: [pfSense-discussion] Problem with ipsec

2006-08-09 Thread Scott Ullrich
On 8/9/06, Carlos Julio Sánchez [ACC-SIS] [EMAIL PROTECTED] wrote: Hello! anybody can help me please? I have an error when I set up vpn with ipsec, my computer A have pfsense and my computer B have Centos(Linux) In the ipsec logs I have: racoon: ERROR: failed to get sainfo. racoon:

Re: [pfSense-discussion] ipv6 stuff

2006-08-07 Thread Scott Ullrich
On 8/3/06, Nick Buraglio [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is there an easy way to get the pfsense gui to see a gif interface that I create manually? I'm working on some v6 stuff via a public v6 delegation (and a tunnel) and want to be able to use the gui

Re: [pfSense-discussion] xorp

2006-08-02 Thread Scott Ullrich
On 3/6/06, Scott Ullrich [EMAIL PROTECTED] wrote: You would need to start from ground 0 with this. Its meant to be a router and does not have PF, etc. Nor does it have CARP, nor does it have insert another feature here. XORP is a great project but to integrate it would mean to start

Re: [pfSense-discussion] Limiting access through table virusprot

2006-07-27 Thread Scott Ullrich
On 7/26/06, Peter Allgeyer [EMAIL PROTECTED] wrote: [snip] There's another table for sshlockout, but it's not referenced anywhere in a ruleset. Don't know, if useful for anything, nor if it's a stub already for a general solution to SSH brute force attacks. This works with our ssh lockout

  1   2   3   >