[pfSense Support] problem with ipsec

2008-02-28 Thread Christos Pelekis
Hi, i have 2 pfsense installs (both have 1.2 release) I have setup in aggressive mode a vpn channel and work fine. But if i change this to main (only this change, all the remain config is the same) then i have this errors: ** racoon: ERROR: phase1 negotiation failed. racoon:

Re: [pfSense Support] problem with ipsec

2008-02-28 Thread Vivek Khera
On Feb 28, 2008, at 4:07 AM, Christos Pelekis wrote: Hi, i have 2 pfsense installs (both have 1.2 release) I have setup in aggressive mode a vpn channel and work fine. But if i change this to main (only this change, all the remain config is the same) then i have this errors: What kind of

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Anil Garg
Thanks for your response Martin - Rev 1.3 might be some time away... I'd like to do an Open VPN site-2-site. Do you have a link or two to point to me as I am a Newb on computers Best Anil Garg Fuchs, Martin [EMAIL PROTECTED] wrote:So then go on and use OpenVPN

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Jeppe Øland
Try this one: http://pfsense.untouchable.net/tutorials/openvpn/pfsense-ovpn.pdf Regards, -Jeppe On Thu, Feb 28, 2008 at 8:04 AM, Anil Garg [EMAIL PROTECTED] wrote: Thanks for your response Martin - Rev 1.3 might be some time away... I'd like to do an Open VPN site-2-site. Do you have a link

[pfSense Support] Load kernel error

2008-02-28 Thread Mike Lever
While trying to upgrade to 1.2 using the webgui update I received an error during the next bootup Loading /boot/defaults/loader.conf Unable to load a kernel ! - Cant load 'kernel' It freezes there.. I've tried to reinstall from scratch, the setup runs fine but freezes at the same point in

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Heiko Garbe
with 1.2 you needn´t static ips on both sides, one side dynamic pfsense and one side static pfsense and it works greetings heiko Jeppe Øland schrieb: Try this one: http://pfsense.untouchable.net/tutorials/openvpn/pfsense-ovpn.pdf Regards, -Jeppe On Thu, Feb 28, 2008 at 8:04 AM, Anil Garg

Re: [pfSense Support] Load kernel error

2008-02-28 Thread Gary Buckmaster
Can I assume that this is an embedded device you're trying to upgrade? If so, this is a reported issue and has been discussed several times on this mailing list. Use the shell upgrade method provided or re-flash your CF card. Mike Lever wrote: While trying to upgrade to 1.2 using the

Re: [pfSense Support] Load kernel error

2008-02-28 Thread Scott Ullrich
On 2/28/08, Mike Lever [EMAIL PROTECTED] wrote: Hi Gary, Thanks for that info. I am using a standard installation not an embedded device (I think, I'm working off a standard desktop, HDD, no CF) I also tried a fresh re-install and it installs fine, then boots up. I noticed the problem.

RE: [pfSense Support] Dual-wan Setup issue (Yes, I've read a few Dual-Wan HOWTO docs)

2008-02-28 Thread Michael Richardson
Reinstall from scratch -- Still safe to export/import my config or do you really mean from scratch ? -Original Message- From: sai [mailto:[EMAIL PROTECTED] Sent: Thursday, February 28, 2008 12:12 AM To: support@pfsense.com Subject: Re: [pfSense Support] Dual-wan Setup issue (Yes, I've

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Ryan Neily
Return Receipt Your Re: AW: [pfSense Support] IPSEC document:

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Anil Garg
Heiko This is an amazing news. Let me try some guidance from you. One Machine A(PFSENSE), I have to create a rule and in that I use the public IP of the remote gateway. And for my identifier I will use [EMAIL PROTECTED] Then on Machine B(PFSENSE), I have to create a corresponding rule and

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Heiko Garbe
Hello, you need: PFSENSE A (dynamic) -- PFSENSE B (static) On the Pfsense B you must enabled allow mobile Clients and define at the PSK -tab- an identifier and a passwort. Then you must fill out the other fields lifetimes and so on the mobile client page On the Pfsense A you need the same

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread Ryan Neily
Return Receipt Your Re: AW: [pfSense Support] IPSEC document:

RE: [pfSense Support] Load kernel error

2008-02-28 Thread Sean Cavanaugh
pfSense will run the CD as a LiveCD. it doesn not do an automated installer. When the system is fully up, select Option 99 on the console to initialte the HDD installer which will step you thru the partitioning and formating of the HDD. make sure to use the GRUB loader as it avoids some other

[pfSense Support] DHCPDISCOVER

2008-02-28 Thread Mike Lever
Looking at my system log I see repeated messages “dhclient[12649]: DHCPDISCOVER on rl0 to 255.255.255.255 port 67 interval 13” Now rl0 is statically configured and should be needing any form of DHCP, where is this coming from ? and how do I stop it ? Regards, Mike Lever Tenacity Films

[pfSense Support] IPSEC tunnel brings down traffic from lan to wan

2008-02-28 Thread Matt Hohman
Hey All got a weird one for you all, We have a pfsense box with 4 interfaces Lan 192.168.0.1 Wan Static Public IP Wan2 Static Public IP Different ISP than Wan DMZ Wan2 and DMZ are bridged. Wan handles all traffic form the lan. We have 3 remote pfsense boxes that use ipsec to connect

Re: [pfSense Support] DHCPDISCOVER

2008-02-28 Thread Scott Ullrich
On 2/28/08, Mike Lever [EMAIL PROTECTED] wrote: Looking at my system log I see repeated messages dhclient[12649]: DHCPDISCOVER on rl0 to 255.255.255.255 port 67 interval 13 Now rl0 is statically configured and should be needing any form of DHCP, where is this coming from ? and how do I

[pfSense Support] Ping

2008-02-28 Thread Anil Garg
My ISP has created a CLAN for me with the following public address: xxx.xxx.xxx.64/27 Gateway for my pfsense is xxx.xxx.xxx.65 I have configured the pfsense to static IP of xxx.xxx.xxx.66/27 and given an gateway of xxx.xxx.xxx65 Everything works fine and I can VPN into xxx.xxx.xxx.66 But my

Re: [pfSense Support] Ping

2008-02-28 Thread Vaughn L. Reid III
Try creating a firewall rule on the Wan interface to allow ICMP packets. Vaughn Anil Garg wrote: My ISP has created a CLAN for me with the following public address: xxx.xxx.xxx.64/27 Gateway for my pfsense is xxx.xxx.xxx.65 I have configured the pfsense to static IP of xxx.xxx.xxx.66/27 and

Re: [pfSense Support] Ping

2008-02-28 Thread Anil Garg
Thanks - I will try this... After the first rule that says block RFC 1918 networks and is automatically created by the WAN setting, If I put a rule on the WAN saying like following: TAB Selected : WAN Proto/Source/Port/Dest/Port/Gateway/Schedule/Description Pass

[pfSense Support] Ping

2008-02-28 Thread Anil Garg
In my pass-through for PPTP and IPSEC, I had a rule that allowed any...all..any for only TCP IP protocol. I have now changed that to any protocol all the way to the end any. Is this ok on the VPN interfaces like PPTP and IPSEC? Anil Garg Anil Garg [EMAIL PROTECTED] wrote: My ISP has created

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread drovalev
Return Receipt Your Re: AW: [pfSense Support] IPSEC document:

Re: AW: [pfSense Support] IPSEC

2008-02-28 Thread wayne
Hi I don't think this will solve your problem, There is a huge difference between a Dynamic IP and a private IP as you have, I solved this problem like this::: I have two Private IP's , so I rented a vserver with root access (SOMEWHERE on the planet)something small only to handle redirects,