Re: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Angelo Turetta
Trave Harmon wrote: Mine is on but it still doesn't work. Is there a way to verifiy at the command prompt level if it is working? -Original Message- From: Dimitri Rodis [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 06, 2008 8:10 PM Maybe I'm off the mark by saying this, but I

[pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Bryan Derman
After searching the archives, the forum and conferring with Mr. Google, I've not found anything about the best/correct strategy to use to support multiple LAN subnets on a single LAN port. The Questions = - is using address aliases the correct/optimal/best way to create the WAN aliases

Re: [pfSense Support] "Read error" when booting pfsense from cf.

2008-02-07 Thread Gary Buckmaster
Carl Lischke wrote: Hi. When i'm trying to install Pfsense from a CF-card i get the message "Read error", and i can't go around it, i'm stuck. What can i do to fix it? I'm in great need of a good router, so i really need help. Cry Greetings, Carl Carl, I believe this link ans

Re: [pfSense Support] "Read error" when booting pfsense from cf.

2008-02-07 Thread Carl Lischke
I ahve tried that, but can't get it to work. 2008/2/7, Gary Buckmaster <[EMAIL PROTECTED]>: > > Carl Lischke wrote: > > Hi. > > > > When i'm trying to install Pfsense from a CF-card i get the message > > "Read error", and i can't go around it, i'm stuck. > > > > What can i do to fix it? I'm in gre

Re: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Chris Buechler
Trave Harmon wrote: I am having a problem: I have multiple virtual mail servers behind a pfsense firewall. Now on each server, I have multiple domains. Now sending to the domain from google or yahoo is perfect and out again is perfect but when I send a message from one virtual server to a

RE: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Bryan Derman
Thanks, but VLANs are not an option due to other hardware/switch limitations. Having only a basic understanding of VLANs, I'm also not sure how that would apply (but would be happy to learn) since the underlying objective is to have pfSense support multiple LAN subnets (in this case, 3) on a singl

RE: [pfSense Support] SSL configuration with Captive Portal

2008-02-07 Thread Atkins, Dwane P
No, I added it correctly. From: Dziuk, Fred J [mailto:[EMAIL PROTECTED] Sent: Thursday, February 07, 2008 1:49 PM To: support@pfsense.com Subject: RE: [pfSense Support] SSL configuration with Captive Portal Dwane, Did you add "blah.crt" instead of

RE: [pfSense Support] Spanning tree support

2008-02-07 Thread Chris Bagnall
> You don't need spanning tree support on the router to accomplish this. > You just need NIC 'teaming' support in the OS. Yep, hence I suppose I should have phrased the question along the lines of "whether it'd be possible to team vr0 and vr1 together on the LAN interface". I'd imagine it's more

RE: [pfSense Support] SSL configuration with Captive Portal

2008-02-07 Thread Dziuk, Fred J
Dwane, Did you add "blah.crt" instead of "ca-cert.crt??? This could be a problem. Fred From: Atkins, Dwane P [mailto:[EMAIL PROTECTED] Sent: Thursday, February 07, 2008 1:46 PM To: support@pfsense.com Subject: [pfSense Support] SSL configuration with C

Re: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Bryan Derman
Thanks Chris, I'd appreciate that. If you want ping me via http://www.derman.com/Contact/AboutUs-Contacts.jsp I'll send you an email address, if that would make it easier. Narrower version of original diagram included, below ... so it doesn't wrap 'n jumble [du-oh!] __

[pfSense Support] SSL configuration with Captive Portal

2008-02-07 Thread Atkins, Dwane P
I was looking at a couple of links on the website about this. http://forum.pfsense.org/index.php/topic,2966.0.html http://forum.pfsense.org/index.php?topic=7146.msg40522 We created a file called ca-cert.crt I copied the file to /var/etc I have edited the /var/etc/lighty-CaptivePo

Re: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Ronald L. Rosson Jr.
I could be wrong here but I will throw this out there any ways. When he goes by IP it works. When he goes by domain name it doesn't. This might be an issue where split DNS is needed or some DNS trickery. -Ron On Feb 6, 2008, at 7:10 PM, Dimitri Rodis wrote: Maybe I'm off the mark by saying

Re: [pfSense Support] Spanning tree support

2008-02-07 Thread Chris Buechler
Chris Bagnall wrote: Greetings list, Does anyone know if pfSense includes support for failover between two LAN interfaces? For example, one can provide high availability using CARP to create a virtual router IP failing over between 2 pfSense boxes, but that's not going to solve the problem o

[pfSense Support] "Read error" when booting pfsense from cf.

2008-02-07 Thread Carl Lischke
Hi. When i'm trying to install Pfsense from a CF-card i get the message "Read error", and i can't go around it, i'm stuck. What can i do to fix it? I'm in great need of a good router, so i really need help. [image: Cry] Greetings, Carl

Re: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Paul M
I'm not 100% sure, but I've noticed that if you create a new CARP entry on the WAN, the nat reflection doesn't get set up until you make some other change. - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-m

Re: [pfSense Support] Bandwidthd to listen on more than one interface

2008-02-07 Thread Scott Ullrich
On Feb 7, 2008 9:30 AM, Ugo Bellavance <[EMAIL PROTECTED]> wrote: > Hi, > > Would it be possible to make bandwidthd listen on more than one > interface, like darkstats? No. Check the known bugs section on source forge. Last time I checked this was a known issue. Scott -

RE: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Dimitri Rodis
Angelo, pfSense specifically has a feature known as NAT reflection which allows this to be possible, mainly because split horizon DNS is not always a reasonable solution. In the case of the person who started this thread, he has approx 700 email domains across various servers behind a NAT-- so whe

Re: [pfSense Support] Spanning tree support

2008-02-07 Thread Adam Armstrong
Gary Buckmaster wrote: Chris Bagnall wrote: Greetings list, Does anyone know if pfSense includes support for failover between two LAN interfaces? For example, one can provide high availability using CARP to create a virtual router IP failing over between 2 pfSense boxes, but that's not goi

Re: [pfSense Support] Spanning tree support

2008-02-07 Thread Gary Buckmaster
Chris Bagnall wrote: Greetings list, Does anyone know if pfSense includes support for failover between two LAN interfaces? For example, one can provide high availability using CARP to create a virtual router IP failing over between 2 pfSense boxes, but that's not going to solve the problem o

RE: [pfSense Support] SSL configuration with Captive Portal

2008-02-07 Thread Atkins, Dwane P
My apologies. At the bottom of the /var/etc/lighty-CaptivePortal-SSL.conf file, I input the following command, ssl.ca-file = "/var/etc/ca-cert.crt". Thanks Dwane From: Atkins, Dwane P [mailto:[EMAIL PROTECTED] Sent: Thursday, February 07, 2008 1:46 PM

Re: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Chris Buechler
I have a document that describes in detail the steps required to accomplish this, though not accessible right now. You're partially right, partially wrong. I'll put it online somewhere later. Bryan Derman wrote: After searching the archives, the forum and conferring with Mr. Google, I've not

Re: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Chris Buechler
Bryan Derman wrote: Thanks, but VLANs are not an option due to other hardware/switch limitations. Having only a basic understanding of VLANs, I'm also not sure how that would apply (but would be happy to learn) since the underlying objective is to have pfSense support multiple LAN subnets (in

RE: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Sean Cavanaugh
set the LAN interface to use VLANs? -Sean > Date: Thu, 7 Feb 2008 04:36:40 -0800> To: support@pfsense.com> From: [EMAIL > PROTECTED]> Subject: [pfSense Support] Strategy for Multiple-Subnet LAN on > Single Port> > After searching the archives, the forum and conferring with > Mr. Google,> I'

Re: [pfSense Support] OpenVPN Client

2008-02-07 Thread Jeppe Øland
I'm not sure if by "client" you mean a mobile person, or a client office. At any rate, this one describes both scenarios: http://pfsense.untouchable.net/tutorials/openvpn/pfsense-ovpn.pdf I had the extra requirement that the mobile clients needed internet access via the OpenVPN tunnel as well. For

Re: [pfSense Support] OpenVPN Client

2008-02-07 Thread graham
Could someone please point me towards a sample of how to set up a client to server connection which all the clients network can access the servers network in openVPN and pfsense. It is great that everything is automated etc etc but its really easier to set manual firewall rules in a config file.

[pfSense Support] Bandwidthd to listen on more than one interface

2008-02-07 Thread Ugo Bellavance
Hi, Would it be possible to make bandwidthd listen on more than one interface, like darkstats? Regards, Ugo - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

[pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Trave Harmon
Actually, the split DNS would be the best solution for me. Changing the DNS per server is easy compared to changing the routes in the entire network. I found a product that would auto create a private MX only record when I create a private record for a domain. This is the only solution that I f

[pfSense Support] Traffic Shaper on a new config

2008-02-07 Thread tester
Hello, I am building a new system with new hardware and I think the better thing is to trash the old config and do a new one. I'd like to try Traffic Shaper, but I get little information and I've lots of doubts, especially regarding its limits and possible side effects on daily usage. I'd really ap

[pfSense Support] pcAnywhere "network/Cable/DSL" scan with IPSEC VPN?

2008-02-07 Thread Gabe Green
Hi all: With PPTP, I was able to launch the "Network/Cable/DSL" host from PCAnywhere remotely and it'd scan the LAN (remote LAN) for machines running PCAW and display them. Doesn't seem to work with site to site IPSEC VPN; what firewall rule do I need to enable? I tried allowing TCP/UDP to