RE: [pfSense Support] Dhcp client Beta 3

2006-05-02 Thread Mailling
What is the purpose of the code rule: " VPN_IPSEC_CONFIGURE(TRUE); ", in /etc/rc.newwanip?? Is this rule used by the dhclient (see error below)? (can this be the reason of are failing dhclient?) The reason why I' am asking this is that when I remove the rule are IPSEC vpn tunnels are more stable

RE: [pfSense Support] Dhcp client Beta 3

2006-05-02 Thread Mailling
Thanks for the response! The strange thing is that it did not accrue with beta 2? Last night the dhcp client crashed again (version of PFsense: BETA3 built on Mon Apr 17 22:46:52 UTC 2006, same machine as the last time, see below) Are other two PFsense Beta 2 machines are still working fine (sam

Re: [pfSense Support] Need guidance before using a CF based appliance to run pfsense

2006-05-02 Thread Scott Ullrich
On 5/2/06, Wesley K. Joyce <[EMAIL PROTECTED]> wrote: Greetings list, I need some guidance before I use a CF based appliance to run pfsense and feeling comfortable with that setup. I have been running pfsense on hard drive based systems. How does one configure pfsense differerently if you only

[pfSense Support] Need guidance before using a CF based appliance to run pfsense

2006-05-02 Thread Wesley K. Joyce
Greetings list, I need some guidance before I use a CF based appliance to run pfsense and feeling comfortable with that setup.  I have been running pfsense on hard drive based systems.  How does one configure pfsense differerently if you only have 128MB - 512MB of flash storage?  I am thinking

Re: [pfSense Support] system firewall logs

2006-05-02 Thread Derrick MacPherson
there isn't one... set loginterface fxp0 set loginterface bge0 set loginterface em0 set loginterface em1 block in log proto tcp from to any port 22 label "sshlockout" On Tue, 2006-05-02 at 18:39 -0400, Scott Ullrich wrote: > On 5/2/06, Derrick MacPherson <[EMAIL PROTECTED]> wrote: > > How can

Re: [pfSense Support] system firewall logs

2006-05-02 Thread Scott Ullrich
On 5/2/06, Derrick MacPherson <[EMAIL PROTECTED]> wrote: How can I find how pass rules are being written the log, yet there's none turned on? Look in /tmp/rules.debug for the "log" keyword in the pass rules. Scott - To unsubs

Re: [pfSense Support] Port Forwarding

2006-05-02 Thread Scott Ullrich
On 5/2/06, Robert Mortimer <[EMAIL PROTECTED]> wrote: OK I set logging for the auto created rule and get the following pf: 18. 541834 rule 66/0(match): pass in on rl1: (tos 0x10, ttl 64, id 8719, offset 0, flags [DF], proto: TCP (6), length: 60) 80.176.108.59.1040 > 10.0.0.10.25: S 299957971:29

RE: [pfSense Support] Port Forwarding

2006-05-02 Thread Robert Mortimer
OK I set logging for the auto created rule and get the following pf: 18. 541834 rule 66/0(match): pass in on rl1: (tos 0x10, ttl 64, id 8719, offset 0, flags [DF], proto: TCP (6), length: 60) 80.176.108.59.1040 > 10.0.0.10.25: S 299957971:299957971(0) win 5840 I turn it off and get ZIP in the l

[pfSense Support] system firewall logs

2006-05-02 Thread Derrick MacPherson
How can I find how pass rules are being written the log, yet there's none turned on? - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

RE: [pfSense Support] Port Forwarding

2006-05-02 Thread Robert Mortimer
> Okay, do the reverse then, turn on logging and see what is ALLOWING it. > Where do I do that (do you mean the raw logging?) > On 5/2/06, Robert Mortimer <[EMAIL PROTECTED]> wrote: > > No TCP port 25 appears in the logs. I have a lot of UDP etc > > but no TCP/IP from my IP > > > > I have three in

Re: [pfSense Support] basic Q

2006-05-02 Thread Scott Ullrich
Leftover from m0n0wall days. If you are not familar with m0n0wall then you should check it out so you can understand what else we inherited. On 5/2/06, Derrick MacPherson <[EMAIL PROTECTED]> wrote: why are proxy arps used and not aliases on the interfaces?

[pfSense Support] basic Q

2006-05-02 Thread Derrick MacPherson
why are proxy arps used and not aliases on the interfaces? - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

[pfSense Support] Problem in appliance

2006-05-02 Thread Pedro Paulo de Magalhaes Oliveira Junior
I need some clue on how to recover config.xml using floppy disk   sometimes I’m losing the confing.xml in this appliance

Re: [pfSense Support] CARP setup problem

2006-05-02 Thread Ispánovits Imre
On Tue, 2 May 2006 11:53:51 -0400 "Scott Ullrich" <[EMAIL PROTECTED]> wrote: > > 1.) Since pfsense1 which is originally the master was down and pfsense2 > > (backup) > > took its role, both machines shows up in the carp status page as master. > > run cvs_sync.sh releng_1 from a shell if this is

Re: [pfSense Support] Suggested mini-itx solutions?

2006-05-02 Thread Scott Ullrich
Good point. Let me see if I can dig up one. On 5/2/06, Paul Haddad <[EMAIL PROTECTED]> wrote: On 5/2/06, Scott Ullrich <[EMAIL PROTECTED]> wrote: > Take a look at our vendors page: http://www.pfsense.com/index.php?id=40 > > We only display vendors that are known to work with pfSense and if > th

Re: [pfSense Support] Suggested mini-itx solutions?

2006-05-02 Thread Paul Haddad
On 5/2/06, Scott Ullrich <[EMAIL PROTECTED]> wrote: Take a look at our vendors page: http://www.pfsense.com/index.php?id=40 We only display vendors that are known to work with pfSense and if they have hip/excellent products. The vendor page seems to have a nice selection of WRAP hardware vendo

Re: [pfSense Support] Port Forwarding

2006-05-02 Thread Scott Ullrich
Okay, do the reverse then, turn on logging and see what is ALLOWING it. On 5/2/06, Robert Mortimer <[EMAIL PROTECTED]> wrote: No TCP port 25 appears in the logs. I have a lot of UDP etc but no TCP/IP from my IP I have three internal sub nets and have turned on advanced nat so I can add each sub

RE: [pfSense Support] Port Forwarding

2006-05-02 Thread Robert Mortimer
No TCP port 25 appears in the logs. I have a lot of UDP etc but no TCP/IP from my IP I have three internal sub nets and have turned on advanced nat so I can add each sub net. I have also added routing rules for the internal gateway but apart from that it is a vanilla setup > -Original Messag

Re: [pfSense Support] CARP setup problem

2006-05-02 Thread Scott Ullrich
On 5/2/06, Ispánovits Imre <[EMAIL PROTECTED]> wrote: Hi, CARP is now up and running :) It's great! I noticed though some phenomena that I at least don't understand. 1.) Since pfsense1 which is originally the master was down and pfsense2 (backup) took its role, both machines shows up in the carp

Re: [pfSense Support] Port Forwarding

2006-05-02 Thread Scott Ullrich
On 5/2/06, Robert Mortimer <[EMAIL PROTECTED]> wrote: I have a set of 6 public IP addresses I set up pfSense with an internal IP in the 10.0.0.x range and use an external IP All is good except I can not port forward to my mailserver or webserver. I have been to the Firewall: NAT: Port Forward ta

Re: [pfSense Support] Suggested mini-itx solutions?

2006-05-02 Thread Scott Ullrich
On 5/2/06, Paul Haddad <[EMAIL PROTECTED]> wrote: Hi All, There seems to be a near endless supply of almost identical mini-itx motherboards out there, half of which are either unavailable or out of stock. The case situation is maybe even worse with most of them seeming to focus on car installat

Re: [pfSense Support] Status line meaning

2006-05-02 Thread Scott Ullrich
I fixed a number of bridge bugs this weekend. Please wait for beta4. On 5/2/06, rabbtux rabbtux <[EMAIL PROTECTED]> wrote: All, My pfsense bridge on an embedded WRAP board give me a message I'm not sure what to do with. The bridge has 3 interfaces, 1 wireless(unconfigured),and 2 ethernet conf

Re: [pfSense Support] CARP setup problem

2006-05-02 Thread Ispánovits Imre
Hi, CARP is now up and running :) It's great! I noticed though some phenomena that I at least don't understand. 1.) Since pfsense1 which is originally the master was down and pfsense2 (backup) took its role, both machines shows up in the carp status page as master. 2.) The CARP virtual IP's show

[pfSense Support] Port Forwarding

2006-05-02 Thread Robert Mortimer
I have a set of 6 public IP addresses I set up pfSense with an internal IP in the 10.0.0.x range and use an external IP All is good except I can not port forward to my mailserver or webserver. I have been to the Firewall: NAT: Port Forward tab and set up the port forward (including the addition of

[pfSense Support] Suggested mini-itx solutions?

2006-05-02 Thread Paul Haddad
Hi All, There seems to be a near endless supply of almost identical mini-itx motherboards out there, half of which are either unavailable or out of stock. The case situation is maybe even worse with most of them seeming to focus on car installations. So any suggestions on pfSense compatible ~$3

[pfSense Support] Status line meaning

2006-05-02 Thread rabbtux rabbtux
All, My pfsense bridge on an embedded WRAP board give me a message I'm not sure what to do with. The bridge has 3 interfaces, 1 wireless(unconfigured),and 2 ethernet configured as LAN and OPT1. I'm using bridging between LAN and OPT1 and using the traffic shaper. The messag scrolling at the to

RE: [pfSense Support] CARP setup problem

2006-05-02 Thread Amorim, Nuno Alexandre \(ext\)
Do not use special caracters anywhere! -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: sexta-feira, 28 de Abril de 2006 18:17 To: support@pfsense.com Subject: Re: [pfSense Support] CARP setup problem That error sounds like username / password / http/https mismatch