Re: [pfSense] SIP through IKEv2-tunnel

2017-03-23 Thread Martin Fuchs
what's actually happening. Look in the SIP session description (SDP) and see what IP addresses the client is telling the other side to communicate with. Divide and conquer. On 3/21/2017 5:42 AM, Martin Fuchs wrote: > what really irritates me is the fact (tried it just now) that using

Re: [pfSense] SIP through IKEv2-tunnel

2017-03-21 Thread Martin Fuchs
what really irritates me is the fact (tried it just now) that using it over OpenVPN instead of IKEv2 it works... any idea ? i'm gonna look over it again... Von: List im Auftrag von Martin Fuchs Gesendet: Dienstag, 21. März 2017 10:45:34 An: pfSense Su

Re: [pfSense] SIP through IKEv2-tunnel

2017-03-21 Thread Martin Fuchs
no change with sipproxd installed... very strange... Von: List im Auftrag von Martin Fuchs Gesendet: Dienstag, 21. März 2017 10:44:36 An: pfSense Support and Discussion Mailing List Betreff: Re: [pfSense] SIP through IKEv2-tunnel since it's only one cli

Re: [pfSense] SIP through IKEv2-tunnel

2017-03-21 Thread Martin Fuchs
remotes -> pfSense VPN -> Switchvox I can't tell from the OP's original description how the connections are configured. On Mon, Mar 20, 2017 at 6:10 AM, Eero Volotinen wrote: > maybe you need something like this > https://doc.pfsense.org/index.php/Siproxd_package >

Re: [pfSense] SIP through IKEv2-tunnel

2017-03-21 Thread Martin Fuchs
nel maybe you need something like this https://doc.pfsense.org/index.php/Siproxd_package Eero 20.3.2017 11.56 ap. "Martin Fuchs" kirjoitti: > Hi ! > > I have a Fritz!Box (router) connected to the internet (no other > possibility). > > In i have NATted ESP, GRE

Re: [pfSense] SIP through IKEv2-tunnel

2017-03-21 Thread Martin Fuchs
the STUN support on your phone? Cheers, Rosen Martin Fuchs wrote on 3/20/2017 3:36 AM: > Hi ! > > I have a Fritz!Box (router) connected to the internet (no other possibility). > > In i have NATted ESP, GRE, 4500, 500, 1701, ... to a pfSense VM. > > This pfSense VM just oper

[pfSense] SIP through IKEv2-tunnel

2017-03-20 Thread Martin Fuchs
Hi ! I have a Fritz!Box (router) connected to the internet (no other possibility). In i have NATted ESP, GRE, 4500, 500, 1701, ... to a pfSense VM. This pfSense VM just operates as a VPN-Gateway. I have set up the routes in the Fritz!Box for the dial-in networks to the pfSense. I can connect

Re: [pfSense] firewall rules with fqdn-alias

2016-05-18 Thread Martin Fuchs
seeing errors in there > before... > > -- > > Steve Yates > ITS, Inc. > -Original Message- > From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Martin Fuchs > Sent: Wednesday, May 18, 2016 4:22 AM > To: 'pfSense Support and Discussion Mai

Re: [pfSense] firewall rules with fqdn-alias

2016-05-18 Thread Martin Fuchs
seeing errors in there > before... > > -- > > Steve Yates > ITS, Inc. > -Original Message- > From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Martin Fuchs > Sent: Wednesday, May 18, 2016 4:22 AM > To: 'pfSense Support and Discussion Mai

Re: [pfSense] firewall rules with fqdn-alias

2016-05-18 Thread Martin Fuchs
seeing errors in there > before... > > -- > > Steve Yates > ITS, Inc. > -Original Message- > From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Martin Fuchs > Sent: Wednesday, May 18, 2016 4:22 AM > To: 'pfSense Support and Discussion Mai

Re: [pfSense] firewall rules with fqdn-alias

2016-05-18 Thread Martin Fuchs
an Am 18.05.2016 00:12 schrieb "Martin Fuchs" : > Hi, Steve ! > No dots in the alias, yurt in the fqdn-address, the lookup works fine, > so the resolved fqdn are visible in the tables, but it seems as if the > rule is not applied. > But there is no error... > Any diagnostic hint

Re: [pfSense] firewall rules with fqdn-alias

2016-05-17 Thread Martin Fuchs
;t valid alias names... 'The name > of the alias may only > consist of the characters "a-z, A-Z, 0-9 and _".' > > -- > > Steve Yates > ITS, Inc. > > -Original Message- > From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Mar

[pfSense] firewall rules with fqdn-alias

2016-05-17 Thread Martin Fuchs
Hi ! We're using pfSense 2.3_1 here in a CARP-cluster. We are using rules with fqdn-aliases and those rules do not work. When i look under diagnostics -> tables i see the tables filled with the correct IPs. When I change the rule not to use the alias, but the IP instead, the rules works imme

Re: [pfSense] Quagga OSPF & VLAN

2015-09-03 Thread Martin Fuchs
OMG ! - SHAME ON ME ;-) Seems it was far too early without any coffee ;-) Just forgot to add the interface... Fetching a coffee now and configure it ;-) Regards, martin --- Hi ! I'm wondering if i'm missing something. I tried to configure Quagga OSPF today. I have set up a Vlan where OSP

[pfSense] Quagga OSPF & VLAN

2015-09-03 Thread Martin Fuchs
Hi ! I'm wondering if i'm missing something. I tried to configure Quagga OSPF today. I have set up a Vlan where OSPF is running in the backbone area, but i cannot configure quagga to use this vlan, it seems to only support physical interfaces. Does anyone know how to handle this - is there a

Re: [pfSense] best way to change WAN interface after migration

2015-06-01 Thread Martin Fuchs
ay to change WAN interface after migration On Tue, Apr 14, 2015 at 2:39 AM, Martin Fuchs wrote: > I also thought about this, but can you tell me if the tules are > attached tot he interface name or tot he interface port ? > Everything is attached to the interface identifier, , , . Nothi

Re: [pfSense] best way to change WAN interface after migration

2015-04-15 Thread Martin Fuchs
f: Re: [pfSense] best way to change WAN interface after migration On Tue, Apr 14, 2015 at 2:39 AM, Martin Fuchs wrote: > I also thought about this, but can you tell me if the tules are > attached tot he interface name or tot he interface port ? > Everything is attached to the interf

Re: [pfSense] best way to change WAN interface after migration

2015-04-14 Thread Martin Fuchs
Von: List [mailto:list-boun...@lists.pfsense.org] Im Auftrag von Chris Buechler Gesendet: Dienstag, 14. April 2015 03:38 An: pfSense Support and Discussion Mailing List Betreff: Re: [pfSense] best way to change WAN interface after migration On Sat, Apr 11, 2015 at 1:46 PM, Martin Fuchs wrote: >

Re: [pfSense] best way to change WAN interface after migration

2015-04-11 Thread Martin Fuchs
and discussion Betreff: Re: [pfSense] best way to change WAN interface after migration In the past I have edited a config backup and restored it. Maybe there are better ways, but find and replace in a editor does the trick :-) Brgds, Espen 11. apr. 2015 20:46 skrev "Martin Fuchs&quo

[pfSense] best way to change WAN interface after migration

2015-04-11 Thread Martin Fuchs
Hi ! Does anyone have any experience with changing WAN-interfaces ? We migrated out CARP-cluster from one provider to another. On em1 we have provider-old and On em7 we have provider-new. The old provider will switch off his connection soon. We changed the gateways and everything,

[pfSense] new user with console menu

2014-09-26 Thread Martin Fuchs
Hi ! When i add a new user to pfSense, this user does not have a menu when logging into the shell. What rights does the user need to have the console menu displayed ? Regards, martin ___ List mailing list List@lists.pfsense.org https://lists.pfsen

[pfSense] CARP-user

2014-09-23 Thread Martin Fuchs
Hi ! Does anyone have experience on CARP setup with a different user than "admin" ? Is there the possibility to create another user and use that for CARP ? I did not manage to get it working. Created user "CARPsync" with "admin" group-membership (and shell access) and set CARP up to us

Re: [pfSense] CVE-2004-0230

2014-09-18 Thread Martin Fuchs
he workaround is to turn on pf. > > Therefore, the answer to your question is technically "yes" but in > practice "no". > > > On Thu, Sep 18, 2014 at 8:55 AM, Martin Fuchs wrote: > > Hi ! >

[pfSense] CVE-2004-0230

2014-09-18 Thread Martin Fuchs
Hi ! Does CVE-2004-0230 affect pfSense 2.1.5 ? regards, Martin ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] IPSec Phase2 deflate

2014-08-31 Thread Martin Fuchs
deflate On Fri, Aug 22, 2014 at 7:32 AM, Martin Fuchs wrote: > Is there any possibility to disable the IPSec deflate option ? I wasn't aware that pfSense supported the deflate option for IPsec, what makes you think it does? -Dave ___ List mail

[pfSense] IPSec Phase2 deflate

2014-08-22 Thread Martin Fuchs
Hi ! Is there any possibility to disable the IPSec deflate option ? (It seems as if there are some problems with AVM-products and i would like to check this out) Regards, martin ___ List mailing list List@lists.pfsense.org https://lists.pfsense

Re: [pfSense] pkg_add

2014-07-10 Thread Martin Fuchs
Hi ! Hmmm, sad... so i have to find another way ;-) But thanks a lot fort he very good explained and documented links, regards, martin >Technically yes but not directly from the base OS, you'll need a FreeBSD >8.3 machine to build packages for. Remember that pfSense 2.1 is based on >8.3 and that

[pfSense] pkg_add

2014-07-09 Thread Martin Fuchs
Hi, Jim ! Is there a possibility to install a package from the ports tree for testing purposes ? Somethink like pkg_add or else ? Regards, martin ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] https transparent proxy project failed...

2014-06-26 Thread Martin Fuchs
It is also not legal everywhere ;-) -Ursprüngliche Nachricht- Von: List [mailto:list-boun...@lists.pfsense.org] Im Auftrag von Ryan Coleman Gesendet: Donnerstag, 26. Juni 2014 14:00 An: pfSense Support and Discussion Mailing List Betreff: Re: [pfSense] https transparent proxy project faile

Re: [pfSense] Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet

2014-05-12 Thread Martin Fuchs
On Fri, May 9, 2014 at 6:02 PM, Dave Warren mailto:da...@hireahit.com> > wrote: Anyone have experience with a Intel Pro/1000 PT Quad Port PCI-e Gigabit Ethernet Server Adapter EXP19404PT on pfSense? >From wandering the forums it looks like it should be supported in pfSense 2, >but I can't find

Re: [pfSense] package installed but not appearing in services\diagnostics\etc drop-down menus

2014-04-28 Thread Martin Fuchs
Did you try to reinstall the xml gui components ? Von: List [mailto:list-boun...@lists.pfsense.org] Im Auftrag von Naor Livne Gesendet: Montag, 28. April 2014 16:25 An: pfSense Support and Discussion Mailing List Betreff: [pfSense] package installed but not appearing in services\diagnostics\etc

Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-17 Thread Martin Fuchs
:59 An: pfSense Support and Discussion Mailing List Betreff: Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails On Fri, Apr 11, 2014 at 3:00 AM, Martin Fuchs mailto:mar...@fuchs-kiel.de> > wrote: Same un

Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-14 Thread Martin Fuchs
1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails On Sat, Apr 12, 2014 at 9:58 AM, Martin Fuchs wrote: > Hi ! > > It's very often that out CARP flaps. > > We have 5 Interfaces and it's about 10 times a day, but it's since the

Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-12 Thread Martin Fuchs
[pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails On Tue, Apr 8, 2014 at 9:26 AM, Martin Fuchs mailto:mar...@fuchs-kiel.de> > wrote: Hi ! We're running a clustered pfSense (2 Machines x86) and it runs f

Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-11 Thread Martin Fuchs
upport and Discussion Mailing List Betreff: Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails - "Martin Fuchs" wrote: > Same under pfSense 2.1.2 > > > > Any hints ? > > &

Re: [pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-11 Thread Martin Fuchs
Same under pfSense 2.1.2 Any hints ? Could it be helpful to play with the base ans skew values ? Von: List [mailto:list-boun...@lists.pfsense.org] Im Auftrag von Martin Fuchs Gesendet: Dienstag, 8. April 2014 16:27 An: list@lists.pfsense.org Betreff: [pfSense] after upgrade to 2.1.1

[pfSense] after upgrade to 2.1.1: never ending "Carp cluster member has resumed the state "BACKUP"" mails

2014-04-08 Thread Martin Fuchs
Hi ! We're running a clustered pfSense (2 Machines x86) and it runs fine. Yesterday i updated to the 2.1.1 release and since then i contstantly receive "Carp cluster member has resumed the state "BACKUP"" mails. This has never been an issue before. and the cluster does not change roles since

Re: [pfSense] pfSense routing and TCP sequence numbers

2013-09-14 Thread Martin Fuchs
ml Google is your friend ;-) On Fri, Sep 13, 2013 at 4:15 PM, Martin Fuchs mailto:mar...@fuchs-kiel.de> > wrote: Hi ! We use pfSense 2.0.1 and have a local LAN, a WAN and remote Offices connected by managed VPN-connections (pfsense does not need to stablish VPN tot he re

[pfSense] pfSense routing and TCP sequence numbers

2013-09-13 Thread Martin Fuchs
Hi ! We use pfSense 2.0.1 and have a local LAN, a WAN and remote Offices connected by managed VPN-connections (pfsense does not need to stablish VPN tot he remote offices). LAN -> pfSense -> remote office In the LAN we have a HiPath Communications system and in the remote offices one r