Re: [pfSense Support] Source NAT

2009-12-17 Thread Chris Buechler
On Fri, Dec 18, 2009 at 2:09 AM, Tapani Tarvainen wrote: > Hi, > > I'm new to pfSense, trying to evaluate its suitability for > my needs, to replace an old custom freebsd firewall, > and while it looks very nice otherwise, there's one > feature I can't find: Source NAT, i.e., redirection > dependi

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-17 Thread Seth Mos
Op 17-12-2009 11:35, Paul Mansfield schreef: has anyone upgraded a pfsense cluster running 1.2.2-release to 1.2.3? Yes. am using many CARP addresses on WAN and LAN ports, IPSEC, OpenVPN, and advanced outbound nat. I am using multiple WAN connections, 380 IPsec vpn tunnels, roughly a hundre

[pfSense Support] Source NAT

2009-12-17 Thread Tapani Tarvainen
Hi, I'm new to pfSense, trying to evaluate its suitability for my needs, to replace an old custom freebsd firewall, and while it looks very nice otherwise, there's one feature I can't find: Source NAT, i.e., redirection depending on source IP. Here's a sample pf.conf entry from the old box to cla

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-17 Thread Chris Buechler
On Thu, Dec 17, 2009 at 5:35 AM, Paul Mansfield wrote: > has anyone upgraded a pfsense cluster running 1.2.2-release to 1.2.3? > > am using many CARP addresses on WAN and LAN ports, IPSEC, OpenVPN, and > advanced outbound nat. > Yeah, I have a few. No problems. The auto-update from 1.2.2 to 1.2.3

Re: [pfSense Support] Virtual IP ProxyARP vs. CARP

2009-12-17 Thread Chris Buechler
On Thu, Dec 17, 2009 at 4:09 PM, Trevor Benson wrote: > On Dec 16, 2009, at 5:41 PM, Chris Buechler wrote: > >> On Wed, Dec 16, 2009 at 7:14 PM, Trevor Benson >> wrote: >>> I noticed that when creating a CARP virtual that it requires it to be >>> attached to an interface with the same network.

Re: [pfSense Support] Virtual IP ProxyARP vs. CARP

2009-12-17 Thread Trevor Benson
On Dec 16, 2009, at 5:41 PM, Chris Buechler wrote: > On Wed, Dec 16, 2009 at 7:14 PM, Trevor Benson > wrote: >> I noticed that when creating a CARP virtual that it requires it to be >> attached to an interface with the same network. However when creating a >> proxy arp, it does not have this r

Re: [pfSense Support] ALIX 'idle' CPU utilization

2009-12-17 Thread David Burgess
On Thu, Dec 17, 2009 at 11:22 AM, Keenan Tims wrote: > I have an ALIX 2d3 running a full install of 1.2.3-RC2 on some industrial > CF. When it's passing very little traffic (~150pps, ~600kbps) I'm seeing an > average of about 15% CPU usage. That doesn't look out of line to me. I have a net5501 (

[pfSense Support] ALIX 'idle' CPU utilization

2009-12-17 Thread Keenan Tims
Has anyone seen what appears to be excessive CPU utilization on the ALIX hardware when it's virtually idle? I have an ALIX 2d3 running a full install of 1.2.3-RC2 on some industrial CF. When it's passing very little traffic (~150pps, ~600kbps) I'm seeing an average of about 15% CPU usage. T

[pfSense Support] Same Gateway Adresses

2009-12-17 Thread Koray AGAYA
Hi Everybody I have two " WAN " interface OPT1 and OPT2 and both gateway ip is same. I didnt write a NAT rule because same gateway adresses into combo box How can I resolve this problem ? Please Help me ? Thank you for your help

[pfSense Support] (connections) Traffic which comes in on OPT1 being blocked on way back out?

2009-12-17 Thread Gabriel - IP Guys
I can telnet to my main ISP IP, (tested from internet based linux box) and get a conversation going with any of my internal servers no problem, (bacula, IMAP, smtp, ssh) all work When I telnet into my OPT1 IP address from the same system, the traffic makes it in, but in the logs I noticed the foll

RE: [pfSense Support] Advanced outbound NAT -- Auto firewall rules on or off?

2009-12-17 Thread Gabriel - IP Guys
-Original Message- From: Seth Mos [mailto:seth@xs4all.nl] Sent: 17 December 2009 12:07 To: support@pfsense.com Subject: Re: [pfSense Support] Advanced outbound NAT -- Auto firewall rules on or off? Gabriel - IP Guys schreef: > If I enable Advanced outbound NAT -- which according to

Re: [pfSense Support] Advanced outbound NAT -- Auto firewall rules on or off?

2009-12-17 Thread Seth Mos
Gabriel - IP Guys schreef: If I enable Advanced outbound NAT -- which according to the guide Pfsense MultiWAN Howto, http://mirror.qubenet.net/mirror/pfsense/tutorials/policybased_multiwan/ policybased_multiwan.pdf I just looked at it. It's entirely correct. If I am adding rules, and I check

[pfSense Support] Advanced outbound NAT -- Auto firewall rules on or off?

2009-12-17 Thread Gabriel - IP Guys
If I enable Advanced outbound NAT -- which according to the guide Pfsense MultiWAN Howto, http://mirror.qubenet.net/mirror/pfsense/tutorials/policybased_multiwan/ policybased_multiwan.pdf If I am adding rules, and I check auto add firewall rule for NAT rules, I am assuming that I will not have to

[pfSense Support] Internal Virtual IP passing traffic outside??

2009-12-17 Thread Gabriel - IP Guys
I have configured a virtual IP with the address of 10.0.0.100. When I do a traceroute to this IP from inside my network, first hop is the gateway, then after that is gets passed out to my ISP? Something isn't quite right here! I want to use this IP in a 1:1 NAT set - Any assistance?

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-17 Thread Paul Mansfield
has anyone upgraded a pfsense cluster running 1.2.2-release to 1.2.3? am using many CARP addresses on WAN and LAN ports, IPSEC, OpenVPN, and advanced outbound nat. am just being uber cautios! - To unsubscribe, e-mail: support-un

Re: [pfSense Support] Watch Chris and myself on FLOSS Weekly Live at 4:30 PM EDT

2009-12-17 Thread Seth Mos
Cool! I caught the last 30 minutes. Thanks for the mention. is there how to download the whole video ? I searched the site but no luck for me ... It is Episode 101 for Floss Weekly and will be available on Christmass Eve. http://www.twit.tv/FLOSS Regards, Seth