Re: [pfSense Support] Multi WAN

2011-01-13 Thread David Burgess
On Thu, Jan 13, 2011 at 11:30 PM, Shali K.R. wrote: > Dear sir, > > How can i create rule for out going? i already created all allow rule for > OPT1 in firewal-> Rules When you create a firewall rule on an interface, that rule will govern only packets arriving on that interface, not leaving it. S

Re: [pfSense Support] Multi WAN

2011-01-13 Thread Shali K.R.
Dear sir, How can i create rule for out going? i already created all allow rule for OPT1 in firewal-> Rules On Fri, Jan 14, 2011 at 11:46 AM, Chris Buechler wrote: > On Fri, Jan 14, 2011 at 1:12 AM, Shali K.R. > wrote: > > OPT1 as wan (public IP and gateway ) i can ping from out side.first i >

Re: [pfSense Support] Multi WAN

2011-01-13 Thread Chris Buechler
On Fri, Jan 14, 2011 at 1:12 AM, Shali K.R. wrote: > OPT1 as wan (public IP and gateway ) i can ping from out side.first i need > to configure the connection right? then NAT ing and all these... > > i cant make any ping from GUI choosing OPT1 as interface Read the page - "Note: Multi-wan is not s

Re: [pfSense Support] Multi WAN

2011-01-13 Thread Shali K.R.
OPT1 as wan (public IP and gateway ) i can ping from out side.first i need to configure the connection right? then NAT ing and all these... i cant make any ping from GUI choosing OPT1 as interface On Fri, Jan 14, 2011 at 11:03 AM, David Burgess wrote: > On Thu, Jan 13, 2011 at 10:29 PM, Shali K

Re: [pfSense Support] Multi WAN

2011-01-13 Thread David Burgess
On Thu, Jan 13, 2011 at 10:29 PM, Shali K.R. wrote: > Dear all, > > I have 2 WAN ( Static and another PPPOE )connections and a LAN connection > > > i added PPPOE as WAN and static as OPT1 two connections are active and i > added a firewall rule for OPT1 allow all to all  then i check the > connect

[pfSense Support] Multi WAN

2011-01-13 Thread Shali K.R.
Dear all, I have 2 WAN ( Static and another PPPOE )connections and a LAN connection i added PPPOE as WAN and static as OPT1 two connections are active and i added a firewall rule for OPT1 allow all to all then i check the connectivity of OPT1, i can ping to OPT1 from out side but cant ping from

Re: [pfSense Support] autorollback?

2011-01-13 Thread Chris Buechler
On Thu, Jan 13, 2011 at 10:46 PM, Joseph L. Casale wrote: >>> So how does one do a restore from the cli in pfSense? >> >>cd /cf/conf/backup && cp config-xxx.xml ../config.xml && reboot >> >>replacing config-.xml with whichever one you want. > > Chris, > That's simple enough. So utilizi

RE: [pfSense Support] autorollback?

2011-01-13 Thread Joseph L. Casale
>> So how does one do a restore from the cli in pfSense? > >cd /cf/conf/backup && cp config-xxx.xml ../config.xml && reboot > >replacing config-.xml with whichever one you want. Chris, That's simple enough. So utilizing what comes stock, would you suggest a cron job be the best thing t

Re: [pfSense Support] autorollback?

2011-01-13 Thread Chris Buechler
On Thu, Jan 13, 2011 at 6:13 PM, Joseph L. Casale wrote: >>The feature on cisco/juniper is a two phase application process. >> >>Phase one applies the configuration. >> >>Phase two rolls it back if you don't confirm it. So if you did something >>that blocked you out of the device for example, it w

Re: [pfSense Support] pfsense 2.0 BETA5 Can't get PPPoE working!

2011-01-13 Thread Maik Heinelt
On 2011/01/14 2:50, Chris Buechler wrote: On Wed, Jan 12, 2011 at 8:07 PM, Maik Heinelt wrote: Well, if I can help We have a PPPoE line for developing& tests. I could setup a pfsense 2.0 Beta5 box and make you ssh login to it. Then you, or other pfsense developer can debug it. That would

RE: [pfSense Support] autorollback?

2011-01-13 Thread Joseph L. Casale
>The feature on cisco/juniper is a two phase application process. > >Phase one applies the configuration. > >Phase two rolls it back if you don't confirm it. So if you did something >that blocked you out of the device for example, it would auto roll back. > >I miss this feature on pfsense. It's on

RE: [pfSense Support] autorollback?

2011-01-13 Thread Chase Bolt
-Original Message- From: Pandu Poluan [mailto:pa...@poluan.info] Sent: Thursday, January 13, 2011 2:36 PM To: support@pfsense.com Subject: Re: [pfSense Support] autorollback? Although I never found myself in a situation where I need to have an auto-revert, I can see how this will be useful

Re: [pfSense Support] autorollback?

2011-01-13 Thread Pandu Poluan
Although I never found myself in a situation where I need to have an auto-revert, I can see how this will be useful for some. Or for myself, someday. Rgds, On 2011-01-14, David Burgess wrote: > On Thu, Jan 13, 2011 at 2:00 PM, Charles N Wyble > wrote: > >> Phase one applies the configuration.

Re: [pfSense Support] autorollback?

2011-01-13 Thread David Burgess
On Thu, Jan 13, 2011 at 2:00 PM, Charles N Wyble wrote: > Phase one applies the configuration. > > Phase two rolls it back if you don't confirm it. So if you did something > that blocked you out of the device for example, it would auto roll back. Ubiquiti's AirOS 5 has a "change" button which up

Re: [pfSense Support] autorollback?

2011-01-13 Thread Cristian Ionescu-Idbohrn
On Thu, 13 Jan 2011, Chris Buechler wrote: > On Thu, Jan 13, 2011 at 3:55 PM, Cristian Ionescu-Idbohrn > wrote: > > On Thu, 13 Jan 2011, Jim Pingle wrote: > >> > >> Even if you don't apply changes, the config has still been saved. > > > > So, what's the point with an "apply changes" then? > > Beca

Re: [pfSense Support] autorollback?

2011-01-13 Thread Francois-Alexandre St-Onge Aubut
would be easy, before applying changes make a local xml backup, and add an option to revert back to previous XML On 11-01-13 04:00 PM, Charles N Wyble wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The feature on cisco/juniper is a two phase application process. Phase one applies the con

Re: [pfSense Support] autorollback?

2011-01-13 Thread Charles N Wyble
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The feature on cisco/juniper is a two phase application process. Phase one applies the configuration. Phase two rolls it back if you don't confirm it. So if you did something that blocked you out of the device for example, it would auto roll back. I

Re: [pfSense Support] autorollback?

2011-01-13 Thread Chris Buechler
On Thu, Jan 13, 2011 at 3:55 PM, Cristian Ionescu-Idbohrn wrote: > On Thu, 13 Jan 2011, Jim Pingle wrote: >> On 1/13/2011 3:26 PM, Francois-Alexandre St-Onge Aubut wrote: >> > >> > dont apply changes? >> > >> > On 11-01-13 03:11 PM, Charles N Wyble wrote: >> > Does pfsense have a feature like cisc

Re: [pfSense Support] autorollback?

2011-01-13 Thread Cristian Ionescu-Idbohrn
On Thu, 13 Jan 2011, Jim Pingle wrote: > On 1/13/2011 3:26 PM, Francois-Alexandre St-Onge Aubut wrote: > > > > dont apply changes? > > > > On 11-01-13 03:11 PM, Charles N Wyble wrote: > > Does pfsense have a feature like cisco/juniper where if you don't > > confirm the change it rolls it back? > >

Re: [pfSense Support] autorollback?

2011-01-13 Thread Jim Pingle
On 1/13/2011 3:26 PM, Francois-Alexandre St-Onge Aubut wrote: > > dont apply changes? > > On 11-01-13 03:11 PM, Charles N Wyble wrote: > Does pfsense have a feature like cisco/juniper where if you don't > confirm the change it rolls it back? > > How difficult would something like this be to impl

Re: [pfSense Support] autorollback?

2011-01-13 Thread Francois-Alexandre St-Onge Aubut
dont apply changes? On 11-01-13 03:11 PM, Charles N Wyble wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Does pfsense have a feature like cisco/juniper where if you don't confirm the change it rolls it back? How difficult would something like this be to implement? Any estimates of the d

[pfSense Support] autorollback?

2011-01-13 Thread Charles N Wyble
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Does pfsense have a feature like cisco/juniper where if you don't confirm the change it rolls it back? How difficult would something like this be to implement? Any estimates of the developer time/cost to implement it? - -- Charles N Wyble (char...@

Re: [pfSense Support] Blank RRD traffic graphs with VLANs in router mode

2011-01-13 Thread Lan Tran
On 1/12/2011 2:57 AM, Seth Mos wrote: Op 11-1-2011 18:00, Lan Tran schreef: ello, I'm running version 2.0-BETA5 (amd64) built on Fri Jan 7 02:54:00 EST 2011 and builtin RRD traffic graphs are blank when pfSense is acting as a router ("Disable all packet filtering" option is checked). The graph

RE: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Chase Bolt
-Original Message- From: Jim Pingle [mailto:li...@pingle.org] Sent: Thursday, January 13, 2011 5:42 AM To: support@pfsense.com Subject: Re: [pfSense Support] Not able to add virtual carp ip on different subnet On 1/13/2011 8:15 AM, Shibashish wrote: [please don't top post] > On Thu, Jan 1

Re: [pfSense Support] pfsense 2.0 BETA5 Can't get PPPoE working!

2011-01-13 Thread Chris Buechler
On Wed, Jan 12, 2011 at 8:07 PM, Maik Heinelt wrote: > > Well, if I can help > We have a PPPoE line for developing & tests. > I could setup a pfsense 2.0 Beta5 box and make you ssh login to it. > Then you, or other pfsense developer can debug it. > That would be ideal, was going to ask for th

Re: [pfSense Support] How to set USB Wi-fi dongle as client to connect to another Wireless router?

2011-01-13 Thread Chris Buechler
On Wed, Jan 12, 2011 at 5:17 PM, Bruce B wrote: > Hi Everyone, > Good news for me that a Cisco/Linksys USB dongle WUSB54GC V3 was detected > within seconds of connecting to pfSense 2.0 Alix board. > However, having loaded pfSense 2.0 just today, I am not sure where to turn > for some documentation

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Jim Pingle
On 1/13/2011 8:15 AM, Shibashish wrote: [please don't top post] > On Thu, Jan 13, 2011 at 6:38 PM, Jim Pingle > wrote: > > On 1/13/2011 5:29 AM, Shibashish wrote: > > My WAN ip is xx.xx.87.44 > > > > I am trying to add a Virtual IP CARP as xx.xx.93.193, bu

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Shibashish
Thanks for explaining. I wanted to use haproxy and this was not starting. The reason as someone suggested is that the VIP must be a CARP ip. http://forum.pfsense.org/index.php?topic=21748.0 I'm on 1.2.3-RELEASE. ShiB. while ( ! ( succeed = try() )

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Jim Pingle
On 1/13/2011 5:29 AM, Shibashish wrote: > My WAN ip is xx.xx.87.44 > > I am trying to add a Virtual IP CARP as xx.xx.93.193, but i am not able to. > > Sorry, we could not locate an interface with a matching subnet for > xx.xx.93.193/27. Please add an ip in this subnet on a real interface. > > I

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Shibashish
My ISP has given xx.xx.93.192/27 (32 IPs – 30 Usable IPs excluding Network & Broadcast) ShiB. while ( ! ( succeed = try() ) ); On Thu, Jan 13, 2011 at 4:07 PM, Shibashish wrote: > xx.xx.87.40/29 > > ShiB. > while ( ! ( succeed = try() ) ); > > > > On Thu, Jan 13, 2011 at 4:06 PM, Warren Baker

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Shibashish
xx.xx.87.40/29 ShiB. while ( ! ( succeed = try() ) ); On Thu, Jan 13, 2011 at 4:06 PM, Warren Baker wrote: > > On Thu, Jan 13, 2011 at 12:29 PM, Shibashish wrote: > >> My WAN ip is xx.xx.87.44 >> >> I am trying to add a Virtual IP CARP as xx.xx.93.193, but i am not able >> to. >> >> Sorry, we

Re: [pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Warren Baker
On Thu, Jan 13, 2011 at 12:29 PM, Shibashish wrote: > My WAN ip is xx.xx.87.44 > > I am trying to add a Virtual IP CARP as xx.xx.93.193, but i am not able to. > > Sorry, we could not locate an interface with a matching subnet for > xx.xx.93.193/27. Please add an ip in this subnet on a real interf

[pfSense Support] Not able to add virtual carp ip on different subnet

2011-01-13 Thread Shibashish
My WAN ip is xx.xx.87.44 I am trying to add a Virtual IP CARP as xx.xx.93.193, but i am not able to. Sorry, we could not locate an interface with a matching subnet for xx.xx.93.193/27. Please add an ip in this subnet on a real interface. I want the carp ip to be used for haproxy without which ha

Re: [pfSense Support] NUT pfsense package rewrite

2011-01-13 Thread Ermal Luçi
On Wed, Jan 12, 2011 at 7:52 PM, Grant Joy wrote: > Hello, > > I am rewriting the pfsense NUT package to work with multiple UPSs. > Everything is working, except deleting UPSs. I am using pkg.php and the > XML tag to create the list of UPSs. What I really > need is for a PHP function to run when

Re: [pfSense Support] pfsense 2.0 BETA5 Can't get PPPoE working!

2011-01-13 Thread Ermal Luçi
On Thu, Jan 13, 2011 at 2:07 AM, Maik Heinelt wrote: > On 2011/01/13 9:20, Chris Buechler wrote: >> >> On Wed, Jan 12, 2011 at 1:43 PM, Charles N Wyble >>  wrote: >>> >>> Same here. No PPPOE support. >>> >> It works fine for the vast majority, there are some edge cases that >> don't work and we d