Re: [pfSense Support] Statically-defined DHCP clients with dynamic addressing not entered into DNS

2009-06-30 Thread Chris Buechler
On Mon, Jun 29, 2009 at 3:57 PM, Ian Levesquei...@crystal.harvard.edu wrote: On Jun 26, 2009, at 2:00 PM, Ian Levesque wrote: We're running DHCP and DNS on a pair of CARPed pfSense 1.2.1 boxen. Other than the fact that they don't sync DCHP entries, it's been working OK for us. However, we've

Re: [pfSense Support] Traffic Shapping : High priority on particular port

2009-06-30 Thread Simon Nayan
Thanks for your answer. We are currently running many application through the VPN. There is a particular one running on port 5000 that I would like to prioritize. Simon Nayan Systems Network Administrator Advans Savings Loans Limited Phone : 021 251322 Mobile :0244480642 email

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread jose thomas
Thank you Scott, it solves my problem with routing. Thanks again for your time -Jose On Sat, Jun 27, 2009 at 10:14 PM, Scott Ullrich sullr...@gmail.com wrote: On Sat, Jun 27, 2009 at 6:22 AM, jose thomastk.j...@gmail.com wrote: Hi there, In our data center, we have two pfsense 1.2.2

RE: [pfSense Support] Traffic Shapping : High priority on particular port

2009-06-30 Thread Bastien DARMON
Thanks Chris, The architecture is as follow: One pfsense main router at our Head Office, and some pfsense routers at our remote branches. A VPN is connecting our branches to our Head Office, and many applications are running through it: Among all the traffic, we'd only like to prioritize the

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
Interesting. I had wished I could make that scenario work w/ipsec. Alas, no joy. I had to set up a vyatta to do it and it worked flawlessly out of the box. I didn't need a third NIC port to do it, either. My thinking is that BSD doesn't handle virtual interfaces very well. *sigh* I

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Michael Schuh
2009/6/30 Curtis Maurand cmaur...@xyonet.com: Interesting.  I had wished I could make that scenario work w/ipsec. Alas, no joy.  I had to set up a vyatta to do it and it worked flawlessly out of the box.  I didn't need a third NIC port to do it, either.  My thinking is that BSD doesn't handle

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
I have configured 2 IPSEC-VPN-Tunnels between 2 Boxes for such a scenario. Works like a charm. michael I had two subnets. I had machines on both subnets. The opt1 interface could not be pinged and was generally dropping packets. If I can't communicate locally with some sort of

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:39 AM, Curtis Maurandcmaur...@xyonet.com wrote: [snip] Unless I can get good communication going today, vyatta gets the nod at 5:00 pm. If you are under those types of time constraints then you really should consider our commercial support offering. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
Scott Ullrich wrote: On Tue, Jun 30, 2009 at 11:04 AM, Curtis Maurandcmaur...@xyonet.com wrote: Interesting. I had wished I could make that scenario work w/ipsec. Alas, no joy. I had to set up a vyatta to do it and it worked flawlessly out of the box. I didn't need a third NIC port to do

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:46 AM, Curtis Maurandcmaur...@xyonet.com wrote: It works OK in 1.2.X. It works even better in 2.0. It really does work in 1.2.X using parallel tunnels. Scott - To unsubscribe, e-mail:

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Michael Schuh
2009/6/30 Scott Ullrich sullr...@gmail.com: On Tue, Jun 30, 2009 at 11:46 AM, Curtis Maurandcmaur...@xyonet.com wrote: It works OK in 1.2.X.   It works even better in 2.0. It really does work in 1.2.X using parallel tunnels. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Michael Schuh
2009/6/30 Michael Schuh michael.sc...@gmail.com: 2009/6/30 Scott Ullrich sullr...@gmail.com: On Tue, Jun 30, 2009 at 11:46 AM, Curtis Maurandcmaur...@xyonet.com wrote: It works OK in 1.2.X.   It works even better in 2.0. It really does work in 1.2.X using parallel tunnels. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
Scott Ullrich wrote: [snip] If you are under those types of time constraints then you really should consider our commercial support offering. This shouldn't be that difficult. I've been doing this configuration on an OpenRoute GT900 for over a year. I set it up in a couple of hours. I

[pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Aarno Aukia
Hello, Attached is a patch to allow the more experienced BGP admin to edit the raw bgpd.conf in the WebConfigurator. This is against https://rcs.pfsense.org/projects/pfsense-packages/repos/mainline/trees/master/config/openbgpd/. Regards, Aarno -- Aarno Aukia Atrila GmbH Switzerland

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
[snip] yes, exactly this way, 2 identical tunnels with different local/remote subnets... Other settings are identical a really impotant thing is, that the remote nets are different from the liocal nets. otherwise it get routing problems Why do I need parallel tunnels when all I

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Michael Schuh
2009/6/30 Curtis Maurand cmaur...@xyonet.com: [snip] yes, exactly this way, 2 identical tunnels with different local/remote subnets... Other settings are identical a really impotant thing is, that the remote nets are different from the liocal nets. otherwise it get routing problems

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:58 AM, Curtis Maurandcmaur...@xyonet.com wrote: [snip] I'm pretty frustrated. Even more of a reason to consider our offering. The offering is there to help eliminate frustration and to offer the best support possible. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Curtis Maurand
[snip] Even more of a reason to consider our offering. The offering is there to help eliminate frustration and to offer the best support possible. Scott I'm not sure $600.00 for a one time thing is worth it. - To

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 12:15 PM, Curtis Maurandcmaur...@xyonet.com wrote: I'm not sure $600.00 for a one time thing is worth it. The time leftover can be used for other situations. But it appears your mind is already made up. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Eugen Leitl
On Tue, Jun 30, 2009 at 12:17:39PM -0400, Curtis Maurand wrote: [snip] you need only 2 tunnels for passing 2 subnets from one side to the other I'm only passing one. and this dinky little config shouldn't need paid support to happen. Folks, please try to quote

Re: [pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:58 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hello, Attached is a patch to allow the more experienced BGP admin to edit the raw bgpd.conf in the WebConfigurator. This is against

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread apiase...@midatlanticbb.com
Curtis Maurand wrote: [snip] you need only 2 tunnels for passing 2 subnets from one side to the other I'm only passing one. and this dinky little config shouldn't need paid support to happen. __ Information from ESET NOD32 Antivirus, version of virus signature database

Re: [pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Aarno Aukia
Hi Scott, On Tue, Jun 30, 2009 at 18:21, Scott Ullrichsullr...@gmail.com wrote: On Tue, Jun 30, 2009 at 11:58 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hello, Attached is a patch to allow the more experienced BGP admin to edit the raw bgpd.conf in the WebConfigurator. This is against

Re: [pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 3:12 PM, Aarno Aukiaaarnoau...@gmail.com wrote: As noted on the Raw config site itself, the GUI-configuration is ignored as long as there is raw config present. One can empty out the raw config and then start using the gui again. Thanks, that is perfect. I have to