[pfSense Support] Re: [***SPAM*** Score/Req: 05.6/5.0] [pfSense Support] block a country (.com)

2010-02-01 Thread Víctor Pasten
Hi, You can get IP address by country from: ftp://ftp.ripe.net/pub/stats/ For example: ftp://ftp.ripe.net/pub/stats/lacnic/delegated-lacnic-latest More information: http://en.wikipedia.org/wiki/Regional_Internet_registry Mixed with anchors, scripts (for updates, filters) Good luck ---

Re: [pfSense Support] block a country (.com)

2010-02-01 Thread Curtis LaMasters
Best way that I could imagine would be to use the bogon's list. Either manually or figure out how to get pfSense to update it manually. In this case one of your bogon's would be network blocks from China. Not 100% fool proof but it's a good start I think. Maybe a snort rule would do as well. Cur

[pfSense Support] block a country (.com)

2010-02-01 Thread Michel Servaes
Would there be an easy option to block or allow a certain country to a pfSense box ? Let's assume that I don't want any Korean traffic on my pfSense... or China. As I see that most attempts to the firewall (blocked ones, so not really an issue) are from chinese ip's... I was wondering, if I cou

Re: [pfSense Support] how does one test for stability?

2010-02-01 Thread Vick Khera
On Mon, Feb 1, 2010 at 4:50 PM, mehma sarja wrote: > It would be neat to have a cron job reporting certain parameters conveying > how a pfsense is running. I use to work at a company managing a hundred and > a quarter FreeBSD appliances and we had a custom Control Center webpage > where we could t

Re: [pfSense Support] how does one test for stability?

2010-02-01 Thread mehma sarja
It would be neat to have a cron job reporting certain parameters conveying how a pfsense is running. I use to work at a company managing a hundred and a quarter FreeBSD appliances and we had a custom Control Center webpage where we could track all machines easily. As I recall, this is what it had:

Re: [pfSense Support] how does one test for stability?

2010-02-01 Thread Michel Servaes
How many walls do you have? Mehma === On Mon, Feb 1, 2010 at 2:13 AM, Michel Servaes > wrote: > > Web surfing happens on port 80 and tcp only. There should be no udp port 80 > traffic going out. I think I read it in the pfsense book which just came

Re: [pfSense Support] how does one test for stability?

2010-02-01 Thread mehma sarja
How many walls do you have? Mehma === On Mon, Feb 1, 2010 at 2:13 AM, Michel Servaes wrote: > > > > Web surfing happens on port 80 and tcp only. There should be no udp port > 80 > > traffic going out. I think I read it in the pfsense book which just came > > out. > > > > > > Didn't read it yet

Re: [pfSense Support] OpenBGPd package on 1.2.3-release

2010-02-01 Thread Aarno Aukia
Hello, On Sun, Jan 31, 2010 at 19:10, Scott Ullrich wrote: > On Fri, Jan 29, 2010 at 11:03 AM, Aarno Aukia wrote: >> Thanks for committing, > > Committed.  Thanks for submitting. Please also bump the packages version number, although this was not in my patch ;) Thanks, Aarno -- Aarno Aukia At

Re: [pfSense Support] OpenBGPd package on 1.2.3-release

2010-02-01 Thread Aarno Aukia
Hello Ermal, On Mon, Feb 1, 2010 at 09:35, Ermal Luçi wrote: > On Fri, Jan 29, 2010 at 5:03 PM, Aarno Aukia wrote: >> On Fri, Jan 29, 2010 at 00:06, Scott Ullrich wrote: >> > On Thu, Jan 28, 2010 at 10:57 AM, Aarno Aukia >> > wrote: >> >> bgpd is started twice when booting on 1.2.3-release wit

Re: [pfSense Support] how does one test for stability?

2010-02-01 Thread Michel Servaes
> > Web surfing happens on port 80 and tcp only. There should be no udp port 80 > traffic going out. I think I read it in the pfsense book which just came > out. > > Didn't read it yet (but, then again - I'm only at page 147 ;-) ) In the meanwhile, I blocked 80/udp on my firewalls :)

Re: [pfSense Support] OpenBGPd package on 1.2.3-release

2010-02-01 Thread Ermal Luçi
On Fri, Jan 29, 2010 at 5:03 PM, Aarno Aukia wrote: > Hello, > > On Fri, Jan 29, 2010 at 00:06, Scott Ullrich wrote: > > On Thu, Jan 28, 2010 at 10:57 AM, Aarno Aukia > wrote: > >> bgpd is started twice when booting on 1.2.3-release with the newest > >> package. I suspect once from /usr/local/p