Re: [pfSense] Have you set up a system with "no" default route?

2015-03-10 Thread Shannon Gernyi
Hi Espen - thanks for the response. It's becoming evident that I didn't include enough information first up. I'm not planning to run full tables, just default announcement from provider if we can. EDIT: I clicked save earlier not send. I've since found out that removing the "" line using vic

Re: [pfSense] Follow-Up -- VIPs : CARP vs IP Alias

2015-03-10 Thread Bryan D.
So switching the CARP VIPs to IP Alias VIPs, in my config, does work (as I had originally expected by the "all about VIPs" WiKi page) -- it just takes an hour or so (in our case) for the up-stream equipment to "cache in" on those changes ... as was suggested by a couple of responders. I've sent

[pfSense] How to troubleshoot

2015-03-10 Thread Bryan D .
I have a v2.2 64-bit config running on a Core2 Duo system. The config uses a number of aliases (including aliases that include other aliases, etc.). Rules are based upon the aliases (du-oh!). PROBLEM: if I change the name of 1 of the IP aliases, the name of the corresponding table doesn't cha

Re: [pfSense] pfSense FreeBSD Version

2015-03-10 Thread Walter Parker
To do this, you will have to grab the sources for pfsense, then grab the build tools, and then try building a custom version of pfSense using a snapshot from https://www.freebsd.org/snapshots/ as the base OS rather than FreeBSD 10.1 as the base OS. You should also check if the person was suggestin

Re: [pfSense] pfSense FreeBSD Version

2015-03-10 Thread Vick Khera
On Tue, Mar 10, 2015 at 12:53 PM, WebDawg wrote: > Where is this tracked. I remember I used to be able to install the next > version of pfSense, can I still do this? > What you're saying you want to try is debugging, not a production solution. pfSense 2.2 already runs the most recent released f

Re: [pfSense] Pfsense 2.2 CPU 100%

2015-03-10 Thread Manojav Sridhar
If you have Device polling enabled it will use the "idle" cycles to poll the Ethernet devices for traffic instead of interrupts as I understand it. Disable it and you should see a top also a top -Sa on your console will show all process including the process that is hogging the CPU On Tue, Mar

[pfSense] pfSense FreeBSD Version

2015-03-10 Thread WebDawg
I have an issue with the version of BSD used in pfSense and my hardware. I was given the following advice to fix some hardware I use with pfSense and I would like to try it: Please try a snapshot of HEAD. It should try to allocate a PCI bus number for your second device which is currently failin

Re: [pfSense] Issue with OpenVPN certificate depth validation and long certificate subjects

2015-03-10 Thread Jim Pingle
On 03/07/2015 04:32 PM, David Durrleman wrote: > There seems to be an issue in pfsense's custom certificate depth > verification for OpenVPN connections. When long certificate subjects are > used, the validation fails. Here is how to repro: Probably this (already fixed in 2.2.1): https://redmine.p

Re: [pfSense] Issue with OpenVPN certificate depth validation and long certificate subjects

2015-03-10 Thread WebDawg
On Sat, Mar 7, 2015 at 2:32 PM, David Durrleman < david.durrle...@shift-technology.com> wrote: > [I am not subscribed to this list; please kindly copy me on any answer] > > Hi, > > I believe I have found a bug in pfsense. I am reporting it here per > https://doc.pfsense.org/index.php/Bug_reporting

Re: [pfSense] Pfsense 2.2 CPU 100%

2015-03-10 Thread Erik Anderson
What process is consuming your CPU? On Tue, Mar 10, 2015 at 8:52 AM, Guillaume JULLIEN wrote: > Hello, > > Since I upgraded my pfsenses to version 2.2, they more than often display > 100% cpu load. > I'm testing an installation on an Alix APU1D. > no extra addon installed > only one service def

Re: [pfSense] Pfsense 2.2 CPU 100%

2015-03-10 Thread Freund, Ingo
Hi, I’ve upgraded a virtual pfSense on an ESXi 5.5 installed on a HP Microserver and have the same issue. - Ingo From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Guillaume JULLIEN Sent: Tuesday, March 10, 2015 2:52 PM To: list@lists.pfsense.org Subject: [pfSense] Pfsense 2.2

[pfSense] Pfsense 2.2 CPU 100%

2015-03-10 Thread Guillaume JULLIEN
Hello, Since I upgraded my pfsenses to version 2.2, they more than often display 100% cpu load. I'm testing an installation on an Alix APU1D. no extra addon installed only one service defined : DHCP only my laptop connected on lan interface If I plug WAN interface to my LAN CPU load can be 100%

[pfSense] Issue with OpenVPN certificate depth validation and long certificate subjects

2015-03-10 Thread David Durrleman
[I am not subscribed to this list; please kindly copy me on any answer] Hi, I believe I have found a bug in pfsense. I am reporting it here per https://doc.pfsense.org/index.php/Bug_reporting Please let me know if this is the wrong channel. There seems to be an issue in pfsense's custom certific

Re: [pfSense] Have you set up a system with "no" default route?

2015-03-10 Thread Espen Johansen
Are you going to load a full internet BGP routing table? Is that why you do not want a default? Remember that even if you have a default route any route that is more specific will take preference. I dont see the problem? And if you want to prevent any unknown IP destination being routed to your upl

Re: [pfSense] Have you set up a system with "no" default route?

2015-03-10 Thread Shannon Gernyi
Hi Mark - this is exactly what I'm seeing - and it would be fine if there were a way to not set a static default. Unfortunately, when unchecking the "Default gateway" box in the system> routing menu, this selection isn't honoured. Cheers, Shannon https://www.linkedin.com/in/shannongernyi

Re: [pfSense] Have you set up a system with "no" default route?

2015-03-10 Thread Mark Tinka
On 10/Mar/15 10:21, Shannon Gernyi wrote: Hi Guys, First time poster to the list - I've spent some time searching without too much luck. Could be ambiguity in my search queries. I'm putting out some new firewalls shortly, and like many already in place, I'll be using openBGPd to interface

[pfSense] Have you set up a system with "no" default route?

2015-03-10 Thread Shannon Gernyi
Hi Guys, First time poster to the list - I've spent some time searching without too much luck. Could be ambiguity in my search queries. I'm putting out some new firewalls shortly, and like many already in place, I'll be using openBGPd to interface with our provider. I'd like to also make us