[pfSense Support] squid clobbering performance

2009-10-01 Thread mayak chunder-qwern
hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+ or more) running latest stable version in a vmware virtual machine with nice hardware. thanks mcq

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread Abdulrehman
Simply bypass this website from squid..make your squid to do not cache any content of this site... On Thu, Oct 1, 2009 at 12:38 PM, mayak chunder-qwern ma...@australsat.comwrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread Morgan Reed
On Thu, Oct 1, 2009 at 17:38, mayak chunder-qwern ma...@australsat.com wrote: any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+ or more) Are you using Squid for caching?

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread mayak chunder-qwern
On Thu, 2009-10-01 at 10:33 +0100, Paul Mansfield wrote: On 01/10/09 08:38, mayak chunder-qwern wrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread Paul Mansfield
I assume you're retyping the config rather than giving us grep -v ^# squid.conf you sure the cache size 1500 is 1500MB and not 1500KB? is it using sufficient disk space? if the disk cache is too small it'll be pointless having it. also, have you turned logging level up too far, if you log

[pfSense Support] why delete captive portal accts on expiry?

2009-10-01 Thread Pete Boyd
Why are captive portal accounts automatically deleted when they expire? To my mind, it would be more useful if they were left in place, expired, so that to re-enable them for the admin person was an easy task of just choosing a new expiry date. As it is, when we have a user pay again for their

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread mayak chunder-qwern
On Thu, 2009-10-01 at 14:02 +0100, Paul Mansfield wrote: I assume you're retyping the config rather than giving us grep -v ^# squid.conf you sure the cache size 1500 is 1500MB and not 1500KB? is it using sufficient disk space? if the disk cache is too small it'll be pointless having it.

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread Jim Pingle
mayak chunder-qwern wrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+ or more) running latest stable version in a vmware virtual machine with nice

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread David Burgess
On Thu, Oct 1, 2009 at 7:57 AM, Jim Pingle li...@pingle.org wrote: mayak chunder-qwern wrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+ or more) My

[pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Vick Khera
I'm trying to figure out how to make my ftp service pass the PCI security compliance (we take credit cards, so need the compliance). I have pfSense 1.2.2 running the ftp proxy to my internal box, which is a FreeBSD 7.2 server running the stock ftpd. A probe from the outside looks like this:

Re: [pfSense Support] squid clobbering performance [solved]

2009-10-01 Thread mayak chunder-qwern
On Thu, 2009-10-01 at 08:18 -0600, David Burgess wrote: On Thu, Oct 1, 2009 at 7:57 AM, Jim Pingle li...@pingle.org wrote: mayak chunder-qwern wrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 10:41 AM, Vick Khera vi...@khera.org wrote: I'm trying to figure out how to make my ftp service pass the PCI security compliance (we take credit cards, so need the compliance).  I have pfSense 1.2.2 running the ftp proxy to my internal box, which is a FreeBSD 7.2 server

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Evgeny Yurchenko
Vick Khera wrote: I'm trying to figure out how to make my ftp service pass the PCI security compliance (we take credit cards, so need the compliance). I have pfSense 1.2.2 running the ftp proxy to my internal box, which is a FreeBSD 7.2 server running the stock ftpd. A probe from the outside

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Vick Khera
On Thu, Oct 1, 2009 at 1:25 PM, Chris Buechler cbuech...@gmail.com wrote: There's quite a bit of irony in using FTP yet wanting to be PCI compliant. I suppose to some extent. However, it is the ideal tool for the job of collecting large data files from arbitrary customers who do not have their

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Vick Khera
On Thu, Oct 1, 2009 at 1:41 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: I do not believe pftpx has setting this. I would disable ftp-helper on WAN and use NAT port-forwarding top you FreeBSD ftp-server (I use pfSense in this way). How portable is this to various ftp clients? I've done

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Keenan Tims
It works fine if you set everything up properly, but since many clients will use passive mode by default to get through NAT, you will need to forward a port range for passive mode use and configure your FTP server to use that port range. Unfortunately, as far as I know there's no (easy,

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Zaharioudakis Nikos
Hi I personally think that FTP could never pass the pci criteria as the transmission has no encryption and the anonymous does not comply anyway. (you always need that user authentication so as to log who tried/ succeeded etc) So sftp is perhaps your best alternative . Maybe you play with

[pfSense Support] Sorry for top posting

2009-10-01 Thread Zaharioudakis Nikos
I apologize top posting on my previous message. I was on the run with a mobile device. Regards, Nikos Walking with Zimbra mobile ...using iPhone Zaharioudakis Nikos +30 694 720 40 63 - To unsubscribe,

Re: [pfSense Support] PORT command in ftp proxy

2009-10-01 Thread Evgeny Yurchenko
Vick Khera wrote: On Thu, Oct 1, 2009 at 1:41 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: I do not believe pftpx has setting this. I would disable ftp-helper on WAN and use NAT port-forwarding top you FreeBSD ftp-server (I use pfSense in this way). How portable is this to various

[pfSense Support] Vista DHCP Issue

2009-10-01 Thread Curtis LaMasters
I've searched around and read about others with this issue. Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast setting. Does anybody have a solution to this that would prevent me from having to touch each workstation?

[pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Nathan Eisenberg
Is there a way to load balance a range of ports with one rule? For example, I have a 100 port passive FTP range defined. Do I have to create 100 load balancer rules? 1.2.3 Best Regards, Nathan Eisenberg Sr. Systems Administrator - Atlas Networks, LLC office: 206.577.3078 | suncadia:

Re: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Curtis LaMasters
On Thu, Oct 1, 2009 at 3:57 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Is there a way to load balance a range of ports with one rule?  For example, I have a 100 port passive FTP range defined.  Do I have to create 100 load balancer rules? 1.2.3 Best Regards, Nathan Eisenberg

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
Curtis LaMasters wrote: I've searched around and read about others with this issue. Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast setting. Does anybody have a solution to this that would prevent me from having

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue.  Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast setting.  Does anybody

Re: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 4:57 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Is there a way to load balance a range of ports with one rule? Same way you load balance one port. Create a rule that specifies the range. - To

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue. Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 6:07 PM, Jim Pingle li...@pingle.org wrote: Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue.  Basically I have 5 different Vista laptops that cannot get a

RE: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Nathan Eisenberg
-Original Message- From: Chris Buechler [mailto:cbuech...@gmail.com] Sent: Thursday, October 01, 2009 2:58 PM To: support@pfsense.com Subject: Re: [pfSense Support] Load Balanced Passive FTP? On Thu, Oct 1, 2009 at 4:57 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Is

Re: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 7:02 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: -Original Message- From: Chris Buechler [mailto:cbuech...@gmail.com] Sent: Thursday, October 01, 2009 2:58 PM To: support@pfsense.com Subject: Re: [pfSense Support] Load Balanced Passive FTP? On Thu,

Re: [pfSense Support] Quad NIC's?

2009-10-01 Thread Joshua Schmidlkofer
On 9/22/09 8:07 PM, Morgan Reed wrote: On Wed, Sep 23, 2009 at 10:26, Luke Jaegerad...@pvpa.org wrote: Are there any known issues with quad NIC cards on a pfSense box? Should be fine, your average (decent) quad NIC is a PCI(express) bridge on a card with what essentially amounts to

RE: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Nathan Eisenberg
-Original Message- From: Chris Buechler [mailto:cbuech...@gmail.com] Sent: Thursday, October 01, 2009 4:24 PM To: support@pfsense.com Subject: Re: [pfSense Support] Load Balanced Passive FTP? Oh, for inbound load balancing, I thought you meant outbound. No, no way to do that for a

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread apiase...@midatlanticbb.com
Chris Buechler wrote: On Thu, Oct 1, 2009 at 6:07 PM, Jim Pingle li...@pingle.org wrote: Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue. Basically I have 5

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
apiase...@midatlanticbb.com wrote: In one situation we had a HP procurve switch installed. We had tons of complaints that vista would not work but XP would. We replaced it with a Cisco 2950 and the complaints stopped. I have no idea why that would cause it to work. I have just come to believe

RE: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Tim Dickson
On Thu, Oct 1, 2009 at 6:07 PM, Jim Pingle li...@pingle.org wrote: Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue.  Basically I have 5 different Vista laptops that cannot get a

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread apiase...@midatlanticbb.com
Tim Dickson wrote: On Thu, Oct 1, 2009 at 6:07 PM, Jim Pingle li...@pingle.org wrote: Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue. Basically I have 5

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
apiase...@midatlanticbb.com wrote: I'm wondering if a patch was added to windows update at some point to fix the problem. Is your Vista totally updated? Just this week I've had my hands on several fully patched Vista machines (including my laptop) as well as two other laptops -- one with Vista

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Chris Buechler
On Fri, Oct 2, 2009 at 1:06 AM, Jim Pingle li...@pingle.org wrote: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{GUID} DhcpConnForceBroadcastFlag=dword: On my laptop this is set to 1, and it still works for me. I've even plugged directly into my

[pfSense Support] Wierd issue with 1:1 NAT

2009-10-01 Thread Nathan Eisenberg
Hey, I've not had this problem before - I have a PFSense firewall with a lot of 1:1 NATs. For almost every outbound connection, the traffic seems to originate from the correct IP. For example, if I SSH from behind the firewall to a server outside of the firewall, and then use 'last', I see