Re: [pfSense] DNS over TLS config for pfSense 2.2.6

2018-04-05 Thread Dave Warren
On 2018-04-06 00:09, Bryan D. wrote: On 2018-Apr-05, at 10:47 PM, Dave Warren wrote: Cloudflare has pushed an update, and things seem to be working from here. For those having issues, try again now? Thanks for the "heads up." Works for me, also (i.e., on pfSense 2.2.6 con

Re: [pfSense] DNS over TLS config for pfSense 2.2.6

2018-04-05 Thread Dave Warren
On 2018-04-05 01:25, Bryan D. wrote: On 2018-Apr-04, at 10:05 PM, Dave Warren wrote: I can also confirm that 9.9.9.9@853 does work here which re-enforces that this is a Cloudflare specific issue. - So it looks like the following config works on pfSense 2.2.6's unbound/DNS Resolve

Re: [pfSense] DNS over TLS config for pfSense 2.2.6

2018-04-04 Thread Dave Warren
I'm running 2.4.3-RELEASE (amd64). I can't get it working here either after a couple hours of poking at it on and off, it now looks like this is actually a Cloudflare issue: https://community.cloudflare.com/t/1-1-1-1-was-working-but-not-anymore/15136/4 "Thanks for the report! This is going to

[pfSense] Firewall by ASN

2018-01-06 Thread Dave Warren
Howdy! Is there a way to firewall traffic based on the ASN? The underlying reason is that we've recently enabled HE's tunnelbroker which, for the most part, works great. However we've run into certain services *cough*Netflix*cough* which reject traffic sent through a HE tunnel. I'd like to r

[pfSense] acme standalone HTTP server verification fails in test environment

2017-11-24 Thread Dave Warren
There is an upcoming issue with Let's Encrypt using the standalone HTTP server, and in fact it is already broken on the Let's Encrypt Test environment. In the near future Let's Encrypt will start performing multiple HTTP verification calls from different origins to complete the validation. However

Re: [pfSense] acme package: wrong agreement URL

2017-11-24 Thread Dave Warren
For anyone else still having issues, it looks like the package was updated November 16th. On Sat, Nov 18, 2017, at 20:39, WebDawg wrote: > Did you report this as a bug? > > On Thu, Nov 16, 2017 at 4:36 AM, Brian Candler > wrote: > > Trying to use the acme package with pfsense 2.4.1 and the LetsE

Re: [pfSense] pfsense upgrade problems?

2017-02-22 Thread Dave Warren
On Wed, Feb 22, 2017, at 10:23, Eero Volotinen wrote: > The process will require 14 MiB more space. > > 73 MiB to be downloaded. > > Fetching php56-5.6.30.txz: .. done > > pkg: php56-5.6.30 failed checksum from repository > > something wrong with the packages? I upgraded a couple pfSen

Re: [pfSense] Lightning strike

2016-10-13 Thread Dave Warren
On Thu, Oct 13, 2016, at 20:41, Jim Thompson wrote: > What should pfSense do in this instance? Point taken about all the possible things that can go wrong and various permutations from pfSense's perspective. As a starting point for a generalized solution, isn't it possible to read the hardware M

[pfSense] Any side effects or negative impact to reassigning ports?

2016-08-30 Thread Dave Warren
Howdy! I'm building out a new pfSense box, but the NICs have not yet arrived and I'm wondering how much configuration I can do in advance. My configuration will be a quad port Intel NIC, two ports will be WAN ports directly connected to a pair of modems, and the other two will be a LACP LAGG group

Re: [pfSense] looking for perfect pfsense box for home?

2016-08-21 Thread Dave Warren
100CAD on a 1U server from eBay that will probably do more than I'll need for the immediate future. I'll probably just buy Gold and call it a day. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense

Re: [pfSense] looking for perfect pfsense box for home?

2016-08-20 Thread Dave Warren
On 2016-08-20 04:02, Jim Thompson wrote: On Aug 20, 2016, at 3:10 AM, Dave Warren wrote: On 2016-08-03 08:43, Steve Yates wrote: I'm being serious but what is your rationale for not using pfSense's/NetGate's? https://www.pfsense.org/products/ The "cheap" part (&l

Re: [pfSense] looking for perfect pfsense box for home?

2016-08-20 Thread Dave Warren
ckage. Any old PC will do just fine if one adds an SSD but as someone pointed out that may use far more power in the long run. For me, it's the fact that I want to rackmount my gear, but $1,799.00 is the cheapest option offered on pfSense.org that can rackmount. -- Dave Warren ht

Re: [pfSense] Restoring DHCP table from 2.2.x into 2.3.x

2016-05-29 Thread Dave Warren
e XML right now, although if the data appears similar, it may be worth considering. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project w

[pfSense] Restoring DHCP table from 2.2.x into 2.3.x

2016-05-29 Thread Dave Warren
be convenient if IP assignments didn't need to change as this makes it easier to bring the new firewall up side by side with the old one and transfer over relatively seamlessly. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejw

Re: [pfSense] Port mapping like reverse proxy

2016-05-11 Thread Dave Warren
rname and proxy the session forward if needed, or use a SSH tunnel to tunnel through to the eventual destination. This would obviously involve a lot more complexity than is available from pfSense. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com

Re: [pfSense] Fw: new message

2016-04-27 Thread Dave Warren
een spam) But maybe that's just me. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] Disable DHCP domain-name request

2015-11-24 Thread Dave Warren
ll make a difference, and it only causes issues on specific hardware, but if you capture and analyze the packets, you'll see correct data was sent by the DHCP server. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren

Re: [pfSense] postfix+mailscanner on 2.2.4

2015-07-30 Thread Dave Warren
maintained, and does not work on any modern version of pfSense. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https

Re: [pfSense] Access Point Recommendations?

2015-07-24 Thread Dave Warren
making it configurable, nor should it be enabled by default unless the guest network is enabled. Ultimately I'm not unhappy with the overall performance of the unit, but it's still not one I'd wholeheartedly recommend, mostly because of the support experience. -- Dave Warren http

Re: [pfSense] Access Point Recommendations?

2015-07-23 Thread Dave Warren
concerns me that support doesn't understand how it's a potential issue. If you use it for NAT/routing/anything, does it listen on the WAN interface, or only the LAN side? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren __

Re: [pfSense] QoS for fairness usage

2015-07-14 Thread Dave Warren
rably, both upstream and downstream, but it did help. Ultimately we just brought in a second pipe from the ISP and now we route high-bandwidth users to that pipe and let them fight it out amongst themselves. That has worked quite reliably. -- Dave Warren http://www.hireahit.com/

Re: [pfSense] testing email

2015-04-08 Thread Dave Warren
y that actually applies that extension block list wasn't enabled. It is now. Thanks! -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support t

Re: [pfSense] Enforcing policy routing gateway

2015-01-11 Thread Dave Warren
duplicate every rule with a "Or else just reject the above..." It's functional, but a hassle. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ pfSense mailing list https://lists.pfsense.org/mailman/lis

Re: [pfSense] APU and SSD: full install or NanoBSD

2014-10-30 Thread Dave Warren
On 2014-10-30 17:15, Jim Thompson wrote: On Oct 30, 2014, at 3:39 PM, Dave Warren wrote: Buy quality instead of junk? <...> Even a cheapo 30GB/60GB/whatever SSD is more than enough for pfSense and makes a far more reliable solution than external flash. I strongly disagree.SSDs h

Re: [pfSense] APU and SSD: full install or NanoBSD

2014-10-30 Thread Dave Warren
se and makes a far more reliable solution than external flash. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Fwd: [Announce] 2.1.5 Release

2014-08-29 Thread Dave Warren
On 2014-08-29 07:47, Jim Thompson wrote: again, the CSS changed, and the browsers love to cache that stuff. Not if the HTML that calls the CSS throws a version into the filename or query, in which case there is no caching issues at all when the version is incremented. -- Dave Warren http

[pfSense] pfSense DHCP PTR registration

2014-08-26 Thread Dave Warren
o be clear, I'm wanting pfSense's DHCP server to register the IPs in the appropriate upstream DNS server, not in the DNS forwarder as in my configuration the DNS forwarder is not authoritative or in a position to intercept queries) -- Dave Warren http://www.hireahit.co

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Dave Warren
t zfs would give me a lot more resiliency here (but possibly not, perhaps squid simply can't ever recover gracefully) -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Dave Warren
other messages in this thread, it appears that it's harmless and can be ignored since no zfs partitions are actually mounted, but the error still appears. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing

Re: [pfSense] Squid Problem and DNS?

2014-07-17 Thread Dave Warren
xy level cache these days. Or at least that was my experience when our office was stuck on a 3Mb pipe instead of our usual dual 100Mb for a few months. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List m

Re: [pfSense] Unbound vs stock

2014-07-11 Thread Dave Warren
without a DNS server, then it will find itself unable to find pfsense.org to download packages. Ultimately the fix will be for pfSense to recognize unbound as a local DNS server and add it to resolv.conf by default, similar to dnsmasq. -- Dave Warren http://www.hireahit.com/ http://

Re: [pfSense] skype 29 minute fail

2014-06-16 Thread Dave Warren
peer-supernodes-for-scalability-not-surveillance-717215/ it doesn't sound like Skype uses Supernodes anymore anyway, so that probably isn't relevant. (Also not a Skype expert, I just remember reading about it and went Googling :) -- Dave Warren http://www.hireahit.com/ http://ca.li

Re: [pfSense] Report Errors

2014-06-02 Thread Dave Warren
r a set of "One size fits some" defaults, with only a handful of the most common options directly exposed to the user. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org ht

Re: [pfSense] RRD 1-month vs 3-month

2014-05-30 Thread Dave Warren
ite nicely. I'll check it out, thanks for the pointer. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] RRD 1-month vs 3-month

2014-05-30 Thread Dave Warren
On 2014-05-30 09:54, Michael Hardrick wrote: Graphs are usually rounded off to the 90th percentile (or similar). Graphs of one-day, one-week, one-month, one-year will reflect more of a relative percentage of the total bandwidth for the period. A bit of rounding is fine, but we're not talking ab

[pfSense] RRD 1-month vs 3-month

2014-05-30 Thread Dave Warren
th.php.png -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Bogon List

2014-05-23 Thread Dave Warren
want to stay there), so it makes me wonder if other lists could be subject to the same "phantom" entries? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://li

Re: [pfSense] Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet

2014-05-13 Thread Dave Warren
is what makes pfSense awesome, and again, I really appreciate all the feedback. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet

2014-05-09 Thread Dave Warren
On 2014-05-09 15:13, Jason McClung wrote: On 5/9/2014 3:02 PM, Dave Warren wrote: Anyone have experience with a Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet Server Adapter EXP19404PT on pfSense? From wandering the forums it looks like it should be supported in pfSense 2, but I can&#

[pfSense] Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet

2014-05-09 Thread Dave Warren
else recommend a quad port that's available at a reasonable price for a small deployment? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Some packages not reinstalled after upgrade

2014-05-03 Thread Dave Warren
doesn't come back up automatically. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Change MAC address on one VLAN of the same NIC.

2014-05-03 Thread Dave Warren
On 2014-05-03 00:49, Ermal Luçi wrote: On Sat, May 3, 2014 at 12:14 AM, Dave Warren <mailto:da...@hireahit.com>> wrote: Howdy! A quick question, is it possible for one NIC to use a different MAC address on a different VLANs? Well FreeBSD supports this if ng_vlan

[pfSense] Change MAC address on one VLAN of the same NIC.

2014-05-02 Thread Dave Warren
#3, or if I connect #3 to a DHCP-assigned bridge on a different ISP, everything works. The IPs on all three ranges are in different subnets, so there's no gateway conflicts, as far as I can tell it's just the MAC address conflict. Is there a better approach? -- Dave Warren

Re: [pfSense] apinger not noticing good connection

2014-04-22 Thread Dave Warren
modem is down completely. *None meaning less than 1%, per RRD and a normal ping from a workstation. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org

Re: [pfSense] pfSense version 2.1.1 has been released

2014-04-04 Thread Dave Warren
On 2014-04-04 19:29, Chris Buechler wrote: On Fri, Apr 4, 2014 at 9:13 PM, Peder Rovelstad wrote: Worked for me on my home FW, but didn't reboot on own (I did receive mail message that it would reboot in 10 sec). Power cycle brought it back on the right slice. Looking good! Did you inadverte

[pfSense] unbound using ipv6 in ipv4-only environment

2014-03-10 Thread Dave Warren
sfully unbound attempts to connect. Is there any harm in flipping unbound's IPv6 support off in the package? Is there any reason to leave it on? Is it doing any harm? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren __

Re: [pfSense] Netgate's customized pfSense release

2014-02-13 Thread Dave Warren
their hardware. This seems like a good thing to me, and arguably the whole point of being open source and BSD licensed. Reading the other messages on the list, this arrangement definitely seems mutually beneficial for both pfSense and Netgate. -- Dave Warren http://www.hireahit.com/ http://

Re: [pfSense] issue Downloading package from Pfsense.com

2014-02-13 Thread Dave Warren
S DNS resolution settings rather than (potentially) using it's own. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren On 2014-02-13 12:03, Muhammad Yousuf Khan wrote: Yes i can ping, here is the result from web console Diagnostics>ping Ping output: PING 8.8.8.8

[pfSense] MultiWAN vs unbound

2014-01-23 Thread Dave Warren
switch (and of course puts us back to forwarding, rather than resolving locally, which is less than ideal) -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren 1832-Curling is introduced to the U.S., giving Americans a sport combining the surface of hockey with the

Re: [pfSense] OpenVPN client bug? "An IPv4 protocol was selected, but the selected interface has no IPv4 address" error

2013-12-24 Thread Dave Warren
, so I read up and found some directions that suggested setting it to the OpenVPN tunnel itself. I'll experiment once I'm back in the office and see what happens if I change it to a WAN. Thanks. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren Light tra

Re: [pfSense] OpenVPN client bug? "An IPv4 protocol was selected, but the selected interface has no IPv4 address" error

2013-12-22 Thread Dave Warren
orking again since I commented out this validation in the PHP code, thereby allowing the parameters to be saved and the connection to be updated. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren Men are from Earth. Women are from

Re: [pfSense] Cannot get data about interface em0_vlan4

2013-11-28 Thread Dave Warren
On 2013-11-28 14:23, Dave Warren wrote: This is an issue again in 2.1... ? Same scenario as before, I reconfigured an interface, rebooted, now I'm getting "Cannot get data about interface em0_vlan4" on an unrelated interface. And here we are, got forced into another reboot

[pfSense] OpenVPN client bug? "An IPv4 protocol was selected, but the selected interface has no IPv4 address" error

2013-11-28 Thread Dave Warren
me to save changes and successfully connect to the VPN. While this code likely makes sense when setting up and OpenVPN server, it should not apply when setting up an OpenVPN client. Am I missing something or is this a bug? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/da

Re: [pfSense] Traffic Graph: Not reflecting reality?

2013-11-28 Thread Dave Warren
show nearly mirror images for the 2 interfaces. I don't use SNMP here, but I see the same, RRDs appear to be accurate. Oddly it's only some interfaces that double in the traffic graphs, but not all. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com

Re: [pfSense] Cannot get data about interface em0_vlan4

2013-11-28 Thread Dave Warren
On 2013-03-05 17:14, Dave Warren wrote: On 3/5/2013 04:27, Jim Pingle wrote: That's a known issue on 2.0.2, fixed on 2.0.3. Check the forum. Thanks, I appreciate the info. This is an issue again in 2.1... ? Same scenario as before, I reconfigured an interface, rebooted, now I'

Re: [pfSense] Traffic Graph: Not reflecting reality?

2013-11-06 Thread Dave Warren
appened on all of my interfaces, but I'm 100% VLAN'd here, my entire box runs on one single port. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.

Re: [pfSense] Traffic Graph: Not reflecting reality?

2013-11-06 Thread Dave Warren
arent proxy on port 80) and it happens with NNTP connections which are not proxied. RRD graphs look closer to being possible, and the WAN and LAN seem to match roughly what I'd expect. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/d

[pfSense] Traffic Graph: Not reflecting reality?

2013-11-06 Thread Dave Warren
hen we're under load. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

[pfSense] unbound not starting

2013-09-28 Thread Dave Warren
e were only using it because it did a better job of splitting load across the two WANs, otherwise unbound looks like a far better solution. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@li

Re: [pfSense] possible DNS-rebind attack detected

2013-05-10 Thread Dave Warren
on the net, or 2) You were just protected against an attack. Either way, everything worked the way it's supposed to. There's absolutely no upside to disabling DNS rebinding attack detection unless your networks are supposed to be interconnected and you are supposed to be able to access eac

Re: [pfSense] Conditional Routing question

2013-04-29 Thread Dave Warren
of a way to do this using layer7 filtering, at least at this time, but someone else might chime in with a suggestion. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://li

Re: [pfSense] Conditional Routing question

2013-04-29 Thread Dave Warren
ffic from that machine out via your VPN. This may still be somewhat problematic as BitTorrent really does need an inbound port opened as well, but that's between you and your VPN provider. An external seedbox might be a better approach, along with the VPN to handle other traffic. -- D

Re: [pfSense] Prevailing wisdom on Hyperthreading?

2013-04-12 Thread Dave Warren
it. pfSense is rarely CPU-bound (unless you do a lot of high speed VPN connections or proxying), but pfSense is latency sensitive and Hyperthreading might actually increase latency very slightly. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com

Re: [pfSense] Legit HTTP Requests, lots... IP Spoof? Any way to shut it down?

2013-03-19 Thread Dave Warren
the URL bar. It's a longshot, but it's not outside the realm of possibility. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Microsoft Outlook Blocked

2013-03-17 Thread Dave Warren
traffic to the specific destination IP, are you able to confirm that Outlook is attempting a connection at all or could this be an issue on Outlook's side of things? -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___

[pfSense] Load balancer vs dynamic IPs

2013-03-15 Thread Dave Warren
great deal of success. The only catch is that when one of the WAN interfaces' undergoes an IP change, someone needs to manually update the pfSense load balancer. Is there any way to specify an interface IP rather than hard-coding the external IP for each interface? -- Dave W

Re: [pfSense] Cannot get data about interface em0_vlan4

2013-03-05 Thread Dave Warren
On 3/5/2013 04:27, Jim Pingle wrote: That's a known issue on 2.0.2, fixed on 2.0.3. Check the forum. Thanks, I appreciate the info. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list

[pfSense] Cannot get data about interface em0_vlan4

2013-03-04 Thread Dave Warren
;s not entirely consistent, I'm in a multi-WAN environment, initially my main WAN wasn't working, today it is and my second WAN (named "DSL") isn't working. Any pointers? Chrome: 25.0.1364.97 m pfSense: 2.0.2-RELEASE (i386) -- Dave Warren http://www.hireahit.co

[pfSense] Restoring XML file

2012-06-29 Thread Dave Warren
but the new system will have a different NIC driver, so at a minimum, it will rename the interfaces. Can I search/replace the references in the XML file and/or are there any other options? -- Dave Warren http://www.hireahit.com/ http://ca.linkedi

Re: [pfSense] Low(ish) cost pfSense platforms

2012-06-08 Thread Dave Warren
ck with the P4 until something better shows up. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] does pfsense block XML traffic

2012-05-24 Thread Dave Warren
other pfSense members if you're using CARP. If you don't know what CARP is and only have one firewall, ignore the setting completely, it does absolutely nothing. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren ___

Re: [pfSense] Alias based on the PTR record

2012-03-14 Thread Dave Warren
On 3/14/2012 1:10 PM, Ugo Bellavance wrote: I know it is less secure and creates load on the firewall and DNS servers, but is it possible to create an alias to create rules, that would allow one to deny traffic for hosts that has a PTR that contains a string? The short answer is no, at least

[pfSense] OpenVPN vs MultiWAN

2012-02-09 Thread Dave Warren
ot sure if I've understood the logic or not, am I in the right place? -- Dave Warren, CEO Hire A Hit Consulting Services http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] OpenVPN and saved username/password credentials

2011-12-29 Thread Dave Warren
nt part of the holidays banging my head against it and the remote site was always reporting that my client sent no username/password at all. Oh well, it works now, thanks! -- Dave Warren, CEO Hire A Hit Consulting Services http://ca.linkedin.com/in/d

Re: [pfSense] OpenVPN and saved username/password credentials

2011-12-27 Thread Dave Warren
AM, Andrew Mitchell wrote: Perhaps I am misunderstanding but could you setup a separate tunnel? Peer to peer shared key as an example? Andrew On Tue, Dec 27, 2011 at 4:16 AM, Dave Warren <mailto:li...@hireahit.com>> wrote: Does anyone happen to know if pfSense (2.x)'s OpenVPN

[pfSense] OpenVPN and saved username/password credentials

2011-12-27 Thread Dave Warren
his requirement, and I'd like to move the VPN connection from the desktop to the firewall level if feasible. -- Dave Warren, CEO Hire A Hit Consulting Services http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http

Re: [pfSense] NAT reflection and SIP registration

2011-12-07 Thread Dave Warren
the network. It's not perfect since some applications still cache IP addresses internally (and don't respect TTLs) but most well-written applications rely on the OS cache instead, so it works more than it doesn't. -- Dave Warren, CEO Hire A Hit Consulting S

Re: [pfSense] Proxy server not working properly

2011-12-01 Thread Dave Warren
your original message, you said "If I block some websites..." How are you attempting to block some sites? What else did you do to set this up? If you aren't attempting to block "some websites" does everything work as expected? -- Dave Warren, CEO Hire A Hit Consu

Re: [pfSense] Load Balancer: Virtual Servers vs DHCP assigned dynamic IP addresses

2011-11-23 Thread Dave Warren
On 11/22/2011 5:11 PM, Jim Pingle wrote: On 11/22/2011 7:45 PM, Dave Warren wrote: Is there any way to tell pfSense that these entries should represent interface IPs rather than hardcoding specific IPs? I don't recall if we reject the syntax in the GUI, but I believe relayd supports us

[pfSense] Load Balancer: Virtual Servers vs DHCP assigned dynamic IP addresses

2011-11-22 Thread Dave Warren
ies should represent interface IPs rather than hardcoding specific IPs? -- Dave Warren, CEO Hire A Hit Consulting Services http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] SIP client fails after a few days

2011-11-01 Thread Dave Warren
EASE since the week it came out without difficulties. -- Dave Warren, CEO Hire A Hit Consulting Services http://ca.linkedin.com/in/davejwarren ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list