[pfSense Support] Re: Firewall security compromised by auxillary programs?

2011-02-05 Thread Dave Warren
In message Kurt Buff was claimed to have wrote: >On Fri, Feb 4, 2011 at 20:21, Joseph L. Casale > wrote: >>>Well, I hear of people running pfSense in a VM, and I wonder how do you >>>avoid exposing the host OS to the network?  How can a firewall be run in a >>>VM and not leave the host OS hangin

Re: [pfSense Support] Firewall security compromised by auxillary programs?

2011-02-05 Thread Pandu Poluan
On Sat, Feb 5, 2011 at 02:54, Mark Jones wrote: > Well, I hear of people running pfSense in a VM, and I wonder how do you avoid > exposing the host OS to the network?  How can a firewall be run in a VM and > not leave the host OS hanging out to be attacked?  Or, go the otherway and > put the VM

[pfSense Support] 2.0 Openvpn questions

2011-02-05 Thread Joseph L. Casale
How comes the openvpn configuration forces a "client-cert-not-required" when using an LDAP auth backend in 2.0b5x64 (Sat Feb 5 snap)? I don't believe that's a mandatory limitation, we use certs _and_ secondary auth via ldap. jlc