Re: [pfSense Support] Pass WAN IP to 2nd router

2010-04-18 Thread Chris Buechler
On Sun, Apr 18, 2010 at 9:35 PM, Paul Peziol wrote: > We have a block of static addresses from our ISP. In the PFsense currently I > have setup VIP and 1:1 NAT to several servers. The network only has 1 lan > subnet 192.168.2.x currently with the servers and a few office computers on > their. The

[pfSense Support] Pass WAN IP to 2nd router

2010-04-18 Thread Paul Peziol
We have a block of static addresses from our ISP. In the PFsense currently I have setup VIP and 1:1 NAT to several servers. The network only has 1 lan subnet 192.168.2.x currently with the servers and a few office computers on their. The client machines that connect are connected to a comcast netwo

Re: [pfSense Support] Snort 2.8.5.3 setup help

2010-04-18 Thread Chris Buechler
On Sun, Apr 18, 2010 at 12:10 AM, Paul Peziol wrote: > Upgrade from the older snort to the new version available running on pfsense > 1.2.3. > It seems like snort is not giving alerts like the old version did. Not sure > if I have it set up right or its just not made for this version of pfsense. >

Re: [pfSense Support] DHCP question - OpenDNS or dnsmasq

2010-04-18 Thread Tim Dressel
> > Doesn't this create a ton of DNS traffic traversing the firewall? >> > Why does it create any more DNS traffic than doing it any other way? > > I've actually got a decent sized block of public IP's to play with, so I will get started on this later in the week. The reason I am concerned about ad

Re: [pfSense Support] DHCP question - OpenDNS or dnsmasq

2010-04-18 Thread Moshe Katz
On Sun, Apr 18, 2010 at 2:06 PM, Tim Dressel wrote: > Because OpenDNS does their filtering based on the source IP address, you >> would have to have eat LAN have its own outgoing IP(s) using Outbound NAT >> rules. >> >> > I've never actually done outbound NAT. So lets say I've got multiple IP > a

Re: [pfSense Support] DHCP question - OpenDNS or dnsmasq

2010-04-18 Thread Tim Dressel
> > Because OpenDNS does their filtering based on the source IP address, you > would have to have eat LAN have its own outgoing IP(s) using Outbound NAT > rules. > > I've never actually done outbound NAT. So lets say I've got multiple IP addresses bound as virtual IP's onto the physical WAN interfa

Re: [pfSense Support] DHCP question - OpenDNS or dnsmasq

2010-04-18 Thread Moshe Katz
Because OpenDNS does their filtering based on the source IP address, you would have to have eat LAN have its own outgoing IP(s) using Outbound NAT rules. You can turn off the pfSense DNS altogether and just set the server to forward all requests it cannot resolve directly to OpenDNS.

[pfSense Support] DHCP question - OpenDNS or dnsmasq

2010-04-18 Thread Tim Dressel
Hi folks, Someone else just asked a question that I responded to, but it actually triggered a question in my head and rather than highjack the thread I thought I'd start a new one. If you use OpenDNS to filter content, it works pretty seamlessly. Lets say that you have 4 LAN connections on diffe

Re: [pfSense Support] Microsoft Server 2008 & DHCP relay

2010-04-18 Thread Tim Dressel
> > Can anyone say from experience whether it's 'within scope' to keep pfSense > as the DHCP/DNS? In other words, is it feasible to have 2K8 server turn to > pfSense via something like DHCP relay? Never played with DHCP relay. > > Hi Karl, We are doing exactly this. I have my Win2008 server acti

Re: [pfSense Support] Status ipv6

2010-04-18 Thread Beat Siegenthaler
On 16.04.10 20:48, R. Th. Boots wrote: > Hello, > > I known I have been asking this before, but as my provider has started > a pilot with native ipv6 over adsl, I was wondering what the current > status is regarding ipv6 support. Take a look over to m0n0wall http://m0n0.ch it has a new version fro