Re: [pfSense Support] ping oddness

2007-11-16 Thread Chris Buechler
Scott Ullrich wrote: On 11/16/07, Joe Laffey <[EMAIL PROTECTED]> wrote: Did this issue occur ONLY with CARP ips? I have plugged my laptop directly into the cable modem, removing the pfsense box completely, and I still see the problem (but only on certain ips). Yes and no. I kept test

Re: [pfSense Support] Virtual addresses

2007-11-16 Thread Chris Buechler
RB wrote: I'm having trouble getting virtual addresses to behave as I expect; my expectations may be what's off, but I'll let you be the judge. I have a pair of systems set up as a virtual router - CARP IP on both WAN and LAN, and clients configured with that as their gateway. Try as I may, I c

[pfSense Support] Suggestions appreciated for unusual network setup

2007-11-19 Thread Chris Bagnall
to share the same subnet (with routers on .1 and .2 for example), but since they're from independent service providers, that isn't going to happen. Any suggestions gratefully appreciated (even if they're "it can't be done" - if I know it can't be done, I won'

[pfSense Support] Multiple WANs in same subnet

2007-11-19 Thread Chris Bagnall
with only 2 interfaces, i.e. LAN and WAN ? Thanks in advance. Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it This email is made from 100% recycled elec

Re: [pfSense Support] does pfSense cache?

2007-11-19 Thread Chris Buechler
Daniel Lloyd wrote: Depends on how they redirect, could be stale DNS caches. That would be my guess as well, but it depends on how the redirection is done. There is no other caching unless you have a package, like squid installed. --

Re: [pfSense Support] suggestion change to UI - locking pages on slave firewalls

2007-11-20 Thread Chris Buechler
Paul M wrote: two firewalls, fwa, fwb, fwa is the master and replicated to fwb I made the mistake of modifying something on fwb, and then of course had to go back and reproduce the changes on fwa. Could there be added in the UI (advanced options maybe) a flag to indicate that this FW is a slave

Re: [pfSense Support] 1.2RC3 update

2007-11-20 Thread Chris Buechler
Atkins, Dwane P wrote: We are confused as to which is the upgrade we need to do for the latest firmware. Is it the Full-and-embedded update or is it just the full update? Where are you seeing a Full-and-embedded file? There shouldn't be any of those around anymore for RC3, it's split in

Re: [pfSense Support] suggestion change to UI - locking pages on slave firewalls

2007-11-20 Thread Chris Buechler
Scott Ullrich wrote: On 11/20/07, Paul M <[EMAIL PROTECTED]> wrote: two firewalls, fwa, fwb, fwa is the master and replicated to fwb I made the mistake of modifying something on fwb, and then of course had to go back and reproduce the changes on fwa. Could there be added in the UI (advanced

RE: [pfSense Support] Suggestions appreciated for unusual network setup

2007-11-22 Thread Chris Bagnall
> You cannot do this! And this is really a very very short answer of why > it doesn't work. > I don't think you're interested on internals of this just the quick answer. Actually, I kind of am. I'd be very interested to know why it can't work, if you don&#

Re: [pfSense Support] Interesting issue with IPsec

2007-11-26 Thread Chris Buechler
Wade Blackwell wrote: Good morning sports fans, I am running PF 1.2-RC2. I have 22 IPsec tunnels running over a low bandwidth connection. CPU usage is below 30% and spikes to 90% when re-keying occurs. memory usage hovers around 25% The interesting issue I have is this; One of the directl

Re: [pfSense Support] Needed broadband speed OpenVPN

2007-11-26 Thread Chris Buechler
Leif Nilsson wrote: Hi all! I have a question what kind of speed you need for OpenVPN tunnels with clients. Total employees are on site A 15, site B 10 and site C 5, and approx. 15 employees on different locations with client access. Most of the traffic will be http, mail, fileserver o

Re: [pfSense Support] Ethernet Link Problem

2007-11-26 Thread Chris Buechler
Markus Helfrich wrote: Hello, i've got a nice Problem. I installed a Pfsense wall on a Jetway Board with two Gigabit Ethernet adapters from Realtek onboard. If i plug the WAN Cabel in, the Link goes up und i have connect but ... the CPU is 60% in use and i have terrible connect to the internet.

Re: [pfSense Support] Ethernet Link Problem

2007-11-26 Thread Chris Buechler
qoska kotfare wrote: Try forcing the speed duplex since the card may fail to negotiate properly with the switch But not until you verify there's actually a problem as I described in my last post, blindly forcing speed and duplex on any piece of equipment is more likely to cause problems th

Re: SV: [pfSense Support] Needed broadband speed OpenVPN

2007-11-26 Thread Chris Buechler
Leif Nilsson wrote: Thanks for your answer! Well the fileserver is domain server for all employees to log on to. So I think that this will generate some load on the broadband. To PfSense we will use 2Ghz with 2Gb RAM. But as I said I'm not sure what kind of speed on the broadband I need. O

Re: [pfSense Support] IPSec VPN problem with 1.2RC3

2007-11-26 Thread Chris Buechler
JBosco wrote: Hi all, Recently I updated my 1.2RC3(built on Sat Nov 24 13:51:31 EST 2007) and the IPSec VPN stopped working. what version did you upgrade from? What order are the logs in, newest on top or bottom? Can you paste more logs also? ---

Re: [pfSense Support] Need help on DNS Forwarder

2007-11-27 Thread Chris Buechler
Raleigh Guevarra wrote: Hi there, I have: pfSense version 1.2-RC3 DNS Forwarder enabled DNS Server disabled Everything's running ok until I tried to disable the DNS Forwarder, I lost internet connection. I enabled it again and when I tried to ping a computer by hostname, it returned a diff

Re: [pfSense Support] Attack aftermath

2007-11-27 Thread Chris Buechler
Wally Mono wrote: Can anybody make any sense out of this? I got 8 of these while running a yum update on a FC 5 xen partition. And (not coincidentally I suspect) immediately afterward got a 3 day distributed dictionary email attack (DHA?) that forced me to loopback a domain. It's exceptional

Re: [pfSense Support] Checkin 20231

2007-11-28 Thread Chris Buechler
Bill Marquette wrote: You might look at the code a little closer. It happens on the first day of the month at 2:01am. In fall the worst that would happen if it happens to fall on the same day is the code will run twice. In spring, we could potentially miss the run _if_ the time zone change occ

Re: [pfSense Support] Checkin 20231

2007-11-28 Thread Chris Buechler
Ron Rosson wrote: Bye setting the time to check the bogons file at 2am this will prevent the check from happening in the spring time and it will happen twice in the fall. For those wondering "wtf", daylight savings change. But only if the DST change falls on the 1st calendar day of the month

Re: [pfSense Support] Symlink gone after power outage

2007-11-28 Thread Chris Buechler
Paul M wrote: when I first started using pfsense with rc1, it was so unstable when either configuring CARP or expecting CARP to failover that the machine would crash or lockup and would nearly always lose the config.xml. even RC2 when changing carp interfaces can still crash pfsense, and I woul

Re: [pfSense Support] pfSense in firmware

2007-11-29 Thread Chris Buechler
Gabriel Green wrote: Hi All, I've heard much about these WRAP boards, which can store pfSense in firmware. What I need to know is the following: * We need something that can handle 51 IPSec tunnels (and up to a full T1 of bandwidth, occasionally; usually much less) without any trouble caus

Re: [pfSense Support] Symlink gone after power outage

2007-11-29 Thread Chris Buechler
Léo Goehrs wrote: I Agree, and specially on FreeBSD. In fact, we have pretty complex configurations with about 25 vlans per firewall and on top of these, we have Carp Interfaces. We used to have FreeBSD but when manipulating the carp interface, we would regularly face Kernel Panic. As lon

Re: [pfSense Support] RE: VIP/NAT Issues

2007-11-29 Thread Chris Buechler
Paul Brown wrote: I'm also having problems with Port Forwarding - both regular and 1:1. Firewall log shows the traffic passing but connection attempts just timeout. Is this a known issue? No, nothing related to this has changed in a long time. See http://doc.pfsense.org/index.php/Port_Forwa

Re: [pfSense Support] pfSense in firmware

2007-11-29 Thread Chris Buechler
Rainer Duffner wrote: BTW: What kind of case do you recommend? AFAICS, PCEngines doesn't really sell Mini-ITX-cases, which seem to be the form-factor for the ALIX-boards. They aren't mini ITX. Cases linked here: http://blog.pfsense.org/?p=155 PC Engines sells the same. --

Re: [pfSense Support] Upstream security issues

2007-11-30 Thread Chris Buechler
Linus Nordberg wrote: Hi, How are security issues in "upstream" software like the FreeBSD kernel handled by the pfSense project? As Bill said, we release point updates for any issues that affect the system. Since this is a local-only issue, and if you have local access on pfSense it's game

Re: [pfSense Support] Attack aftermath

2007-12-01 Thread Chris Buechler
Wally Mono wrote: Any clue as to what rule 66.423.11.0/0 means would be appreciated. If you click on the pass or block image in the web log display it'll show you exactly which rule caused the pass/drop. Actually that is blank: 'The rule that triggered this action is:' followed directly b

Re: [pfSense Support] Nokia IP130 Power Supply

2007-12-08 Thread Chris Patch
Mine is 12v 1250ma barrel connector and center hot. On Fri, 2007-12-07 at 17:21 -0600, Tim Nelson wrote: > I just came upon a Nokia IP130 firewall unit but do not have the power > supply. I know many people run monowall and pfsense on these units and was > hoping one of you could tell me the vol

Re: [pfSense Support] Nokia IP130 Power Supply

2007-12-10 Thread Chris Patch
t unit? > > Tim Nelson > Systems/Network Support > Rockbochs Inc. > (218)727-4332 > > - Original Message - > From: "Chris Patch" <[EMAIL PROTECTED]> > To: support@pfsense.com > Sent: Saturday, December 8, 2007 11:38:59 PM (GMT-0600) America/Chicag

Re: [pfSense Support] 1:1 at wits end

2007-12-11 Thread Chris Buechler
Russ Bennett wrote: Hello, I've setup a 1:1 nat and entered in the rules. Nothing was getting through so I looked at the log and I can see the rule getting hit properly except within the log I get the following message The rule that triggered this action is: @45 block drop in log quick all lab

Re: [pfSense Support] 1:1 at wits end

2007-12-12 Thread Chris Buechler
Russ Bennett wrote: I probably am over thinking this...I tend to do that often. Any how, I believe I am having success 1. I created the VIP with the /29 block I was given. 2. I created the 1:1 208.83.93.19/32 -> 10.0.1.14/32 3. I created the firewall rule Proto Source PortDestination

[pfSense Support] pfSense support for usb to serial converter

2007-12-13 Thread Chris Kuhn
Is there a driver in 1.2-RC3-embedded for USB-Serial converters? or a way to add it in? -- this is on an ALIX.2C3 board built with pfSense-1.2-RC3-Embedded.img -- so far everything else is working great! The converter does show up in the system.log as a generic device, but I can't seem to talk to

Re: [pfSense Support] Token Ring oltr(4) driver problem

2007-12-14 Thread Chris Buechler
Heinrich Pechtold wrote: Hi! we have some problems with Olicom Token Ring Hardware Free Bsd supports this hardware with the oltr(4) driver. Pfsense boots up, and shows the pci Tokenring Hardware while booting up correctly, but also tell "no driver attachd" at the same time (same Line). Token

Re: [pfSense Support] pfSense support for usb to serial converter

2007-12-15 Thread Chris Kuhn
ile and build my own image, but I suppose I can if needed. Thanks, -Chris On Dec 15, 2007, at 10:47 AM, sean nash wrote: Does this mean Serial to usb as in Vodaphone pcmcia crds? On Dec 13, 2007 8:43 PM, Chris Kuhn <[EMAIL PROTECTED]> wrote: Is there a driver in 1.2-RC3-embedded for USB-Se

Re: [pfSense Support] pfSense support for usb to serial converter

2007-12-15 Thread Chris Kuhn
it couldn't be that simple ;-) Thanks! -Chris On Dec 15, 2007, at 9:32 PM, Chris Kuhn wrote: I know nothing of any Vodaphone pcmcia cards. This is just "normal" off-the-shelf usb<->rs232 adapter that plugs into the USB port on the host machine to provide an RS232 port. On

Re: [pfSense Support] PPTP VPN

2007-12-17 Thread Chris Buechler
Giljam Koch wrote: Hello Richard, Thanks for your reply. No. It’s still default. I did however conclude the following: When I disable my own PPTP VPN server, the outbound VPN’s work again. Can anyone confirm this? Does this have something to do with this infamous “GRE connection tracking”

Re: [pfSense Support] pfSense support for usb to serial converter

2007-12-17 Thread Chris Buechler
Chris Kuhn wrote: small update: on my other (recently setup) BSD system, which is: FreeBSD 6.2-RELEASE #0: Fri Jan 12 10:40:27 UTC 2007 I see in /usr/src/sys/dev/usb that uftdi.c and "usbdevs" contain a definition for this device. I'm not sure exactly what kernel change wou

Re: [pfSense Support] PPTP VPN

2007-12-18 Thread Chris Buechler
Giljam Koch wrote: Hi Chris! Thanks for the reply! I've got a few IP-addresses left. How can I separate the PPTP connections from the normal traffic? I suppose I have to use the gateway and some rule, but do you have more details? Probably the easiest is to just NAT all outbound traff

Re: [pfSense Support] PPTP Server Oddity

2007-12-18 Thread Chris Buechler
Matt Hohman wrote: Hello all, We've been using our current pfSense install for a year now with no major problems, except one. Our pfsense box has a cable modem on the wan, a lan, a t1 line, and a dmz. The t1 and the dmz are bridged together. The cable modem is the wan for the lan users. I

Re: [pfSense Support] pfSense support for usb to serial converter

2007-12-18 Thread Chris Kuhn
me, as I was hoping to get this going fast and not need to rebuild the flash image or kernel ;-) "mount -uw /" is my best friend. Now I just need to do some crontab work... -Chris --- Vivek Khera <[EMAIL PROTECTED]> wrote: > On Dec 17, 2007, at 7:49 PM, Chris Buechler wrote:

Re: [pfSense Support] Setting up on Soekris NET5501-70 with all features

2007-12-18 Thread Chris Buechler
Christopher Iarocci wrote: None of the images I can download will work with my application. I’m setting up PFSense on a Soekris NET5501-70 with a hard drive and wish to have all the features. Is there a way to get the serial console working on the full version of PFSense? If so, is there a tu

Re: [pfSense Support] Setting up on Soekris NET5501-70 with all features

2007-12-19 Thread Chris Buechler
Christopher Iarocci wrote: Is there no way to default it to the serial console before putting the hard drive in the 5501 except this procedure? This means I have to have a piece of hardware with VGA, keyboard and 2 NIC cards that also will connect a SATA II drive. I don't have that sort of h

RE: [pfSense Support] Setting up on Soekris NET5501-70 with all features

2007-12-19 Thread Chris Bagnall
ly that'd resolve the issue the OP was trying to work around? Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it This email is made from 100% recycled electrons --

Re: [pfSense Support] Setting up on Soekris NET5501-70 with all features

2007-12-19 Thread Chris Buechler
Christopher Iarocci wrote: Or, make an image for the full version that is an image, not an iso, that also have the serial port enabled. This way it could be written to a hard drive bound for an embedded machine and just plopped in place with no fancy work arounds. We can't provide an image

Re: [pfSense Support] Setting up on Soekris NET5501-70 with all features

2007-12-19 Thread Chris Buechler
Christopher Iarocci wrote: Sean, Will the ISO allow me to install to a hard drive hung off a machine by a USB adapter, or will it only work if the hard drive is connected to the motherboard? I imagine I have to boot a machine off the CD created by the ISO and that will run me through an

Re: [pfSense Support] PPTP Server Oddity

2007-12-22 Thread Chris Buechler
Angelo Turetta wrote: Chris Buechler wrote: Matt Hohman wrote: Is is a know bug to only be able to receive them on the WAN interface, any ideas on what I'm missing if not? Services running locally don't work with OPT WANs at this time without static routes, this is a known

[pfSense Support] Interest in a training course?

2007-12-25 Thread Chris Buechler
http://blog.pfsense.org/?p=158 Feel free to discuss/offer your thoughts here on the list, in the comments there, or email me. - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] AA$T PPPOE OUT? What's the world comming to?

2007-12-28 Thread Chris Buechler
This is unbelievably frustrating. Bellsouth/AT&T's tech support (at least first level, I've had no luck getting further than that) are completely worthless, if the PPPoE on the modem works they can't help any further (even though they clearly broke *something*, our and m0n0wall's PPPoE works fo

Re: [pfSense Support] Running a jail under pfsense?

2008-01-04 Thread Chris Buechler
Jaye Mathisen wrote: Anybody done this? Seems like a fairly easy way to add stuff w/o having to figure out the pfsense package/init/etc system, while leaving pfsense to do the fw/routing and all that other icky stuff. (Other than getting the jail started the first time with jailer). I thin

Re: [pfSense Support] user interface bug with minimum font size set

2008-01-04 Thread Chris Buechler
Paul M wrote: is this a known feature/bug? using firefox on linux and setting minimum font size to 13, and the metallic theme on pfsense 1.2RC3, I find that the diagnostics "tab" wraps off the end and appears under the system tab, and then you can't access anything under the system tab any more.

Re: [pfSense Support] CP broken ??

2008-01-04 Thread Chris Buechler
DLStrout wrote: I upgraded a pfS box over vacation to SNAP: 1.2-RC3 built on Sat Dec 29 09:06:06 EST 2007 and I have several users that are complaining (well not complaining .. cheering actually) that they never get challenged for UN/PW. I just confirmed this with my WiFi laptop and sure enoug

Re: [pfSense Support] Port 80

2008-01-07 Thread Chris Buechler
Paul Cockings wrote: Bridging is possible (and it works for everything I tested except port 80), but I don't think many people are using this configuration. My reason to use this method is I hold a belief that NAT buggers about with things, and wanted to cut NAT out the loop. Just to use pfse

Re: [pfSense Support] Problem during dev_bootstrap and big sound when boot

2008-01-08 Thread Chris Buechler
Jian Zhang wrote: Dear all, I already installed the development edition of pfsense on Vmware workstation 6. It is almost well, but I still met two problems: 1. During the dev bootstrap process, the script reported the below errors: Unknown collection “tools” Unknown collection “www” Howev

Re: [pfSense Support] Hang on reboot after restore

2008-01-09 Thread Chris Buechler
Jason W. Allen wrote: At this point, I've let is wait since just about the same time I sent that email. That was about 45 minutes ago :-) Has it booted yet? You have to give it a while, it's only been ~3.5 hours. ;) The only time I've seen a system hang at that point, it's been caused

Re: [pfSense Support] Evenly share bandwidth

2008-01-10 Thread Chris Buechler
Jeroen wrote: On a side note; the reason I disabled shaping was it applied to all interfaces. For example; I have a 14Mb WAN connection, and shaped it accordingly (NNTP low, HTTP high etc etc etc). LAN <> WAN works perfectly (get's shaped) Wireless <> Wan works perfectly (get's shaped) LAN <

Re: [pfSense Support] connections LAN to LAN get dropped

2008-01-11 Thread Chris Buechler
Bill Marquette wrote: Your reply traffic from 192.168.12.0/24 is bypassing the pfsense box and returning directly to your PC. This breaks stateful inspection. You are better off moving 192.168.12.0 behind the pfsense box on another nic, or adding a static route on your PC tht points 192.168.12.0

Re: [pfSense Support] embedded version and flash drive in unexpected place?

2008-01-11 Thread Chris Buechler
John Sellens wrote: Hi - I've got a couple of embedded firewall boxes (older GB1000 Celeron, VIA chipset boxes from gta.com) but the stock pfSense-1.2-RC3-Embedded.img won't boot properly on them. The kernel starts up, sees devices, but fails to mount root. It looks like the compact flash card i

Re: [pfSense Support] PPPOE with static IP

2008-01-15 Thread Chris Buechler
Ryan Rodrigue wrote: i have a dsl account with a pppoe connection and a static ip address given by at&t. unfortunatly, the pppoe doesn't get the correct ip address. a ceap linksys router i have lets me put the ip address in and everything works as expected. Is there a way to do this in pfsense

[pfSense Support] 1.2-RC4 released!

2008-01-16 Thread Chris Buechler
The pfSense development team is happy to bring you the final release candidate in the 1.2 series! Info here: http://blog.pfsense.org/?p=164 - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PRO

Re: [pfSense Support] Flash UPNP attack

2008-01-17 Thread Chris Buechler
tester wrote: Hello, as subject, being worried I'd like to know if pfSense's UPNP implementation is also affected: I'm sure it most likely is, it's a protocol issue, not an implementation-specific issue. This is why we said for a long time "this is bad, no we won't implement it", but after it

Re: [pfSense Support] Dropped WAN connections

2008-01-17 Thread Chris Buechler
Ron Lemon wrote: Good Afternoon All, I have a satellite internet connection, both in and out, attached to a pfSense 1.2RC3 box. Lately I have been having a connection issue keeping my connection stable on the stat elite for some unknown reason. When the connection gets dropped it usually

Re: [pfSense Support] 1.2-RC2 beta1 -> 1.2-RC4 upgrade

2008-01-23 Thread Chris Buechler
Gabriel Green wrote: Hi all: I have 1.2RC2-beta1 on a PC installed to HD and want to upgrade to 1.2-RC2. However, after picking the appropriate interfaces, the LiveCD halts on "Configuring WAN interface..." - I try ALT+FunctionKeys to see debugging information; nothing. Then I also tried C

Re: [pfSense Support] PFSense VLAN Tagging on the WAN Port

2008-01-23 Thread Chris Buechler
Scott Williamson wrote: Devs, Can this be done now … should be able to, I know there are people running several WANs on VLANs for lack of physical ports. and if not can it be bought, and if it can be bought, would $1000 US cover it, If there is some issue that needs to be corrected, I w

Re: [pfSense Support] License

2008-01-24 Thread Chris Buechler
Scott Ullrich wrote: On 1/24/08, Richard Sperry <[EMAIL PROTECTED]> wrote: Since this is becoming more of a commercial project, do we have to worry about this becoming a pay software? Absolutely not. Never. Over my dead body. It will remain free forever. Absolutely. Under no c

[pfSense Support] commercial development services (was: Re: [pfSense Support] License)

2008-01-25 Thread Chris Buechler
ex.php?option=com_content&task=view&id=8&Itemid=25 Feel free to contact me (off or on list) if you would like to discuss further. Chris - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] Alternative Full Install Installation Methods

2008-01-28 Thread Chris Buechler
[EMAIL PROTECTED] wrote: Hello, I am trying to do a full install of pfSense onto a CF card. I have tested the card extensively and it works perfectly. I want a full install, not an embedded one, so I can utilize packages. When I boot the live CD in VMWare, it gets stuck while installing. I

Re: [pfSense Support] Re: IPv6

2008-01-28 Thread Chris Buechler
R. Th. Boots wrote: Graham Beneke wrote: R. Th. Boots wrote: I was wondering if pfsense was supporting ipv6 and ipv6-in-ipv4 tunnels? It is my understanding that the kernel that runs under pfsense has supported IPv6 fully for a long time. This is what I have noticed aswell. You can provide

Re: [pfSense Support] Upgrade 1.0.1 to 1.2 RC4 from console (2nd appeal)

2008-01-28 Thread Chris Buechler
Michael Richardson wrote: I was once given a command (or series of commands really) that fetched, unpacked, and installed (or coppied files anyway) that let me do an update from 1.0.1 to 1.2 RC4, but I’ve misplaced it. Could someone provide that again? As best I recall, the output of fetch wa

Re: [pfSense Support] Re: IPv6

2008-01-29 Thread Chris Buechler
R. Th. Boots wrote: Chris Buechler wrote: R. Th. Boots wrote: The problem is indeed that none of your configurations show up in the web interface of pfsense and that you are also not able to create any firewall rules on those interfaces. IPv6 support exists in the HEAD development tree

Re: [pfSense Support] Re: IPv6

2008-01-30 Thread Chris Buechler
R. Th. Boots wrote: Chris Buechler wrote: R. Th. Boots wrote: Chris Buechler wrote: R. Th. Boots wrote: The problem is indeed that none of your configurations show up in the web interface of pfsense and that you are also not able to create any firewall rules on those interfaces. IPv6

Re: [pfSense Support] nat labelling bug?

2008-01-30 Thread Chris Buechler
Paul M wrote: I was created a nat rule's equivalent filter rule and got the error below. Is this a known bug? There were error(s) loading the rules: /tmp/rules.debug:149: rule label too long (max 63 chars)pfctl: Syntax error in config file: pf rules not loaded - The line in question reads [149]:

Re: [pfSense Support] Manually configure (force) link-speed/duplex?

2008-01-30 Thread Chris Buechler
Michael Richardson wrote: I’ve got a Realtek nic that is not playing nice with a cable-modem. The System Log shows the interface is going up and down a couple times per minute. I intend to replace the NIC (when I’m not 200 miles away), but for now I’d like to try and for the speed/duplex to s

RE: [pfSense Support] pfsense and soekris 5501

2008-01-31 Thread Chris Bagnall
I've not tried an HD install, but we have about 15 net5501s out there in the wild running pfSense and there's been nary a problem with them. We're using 512MB compact flash cards made by Integral, if it's any help. Regards, Chris -- C.M. Bagnall, Director, Minotaur I

Re: [pfSense Support] minor fix/request: button positions on NAT page compared to rules

2008-01-31 Thread Chris Daniel
In my opinion, no, you're not being fussy ... UIs should be consistent wherever possible. pfSense (and probably m0n0wall, too) has some inconsistency issues in a few places; I've been meaning to make some suggestions / patches for some UI improvements and simplifications for some time. Maybe I'll g

[pfSense Support] pfSense and Compact Flash size

2008-02-04 Thread Chris Bagnall
t take the chance. Thanks in advance. Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it This email is made from 100% recycled electrons - To unsubscribe, e-ma

[pfSense Support] router failover

2008-02-05 Thread Chris Flugstad
Not to doubt pfsense, but i'd like to setup 2 pfsense routers so when 1 fails the 2nd will take over. I havent had pfsense fail yet, but i've had hardware(soekris) and powersupplies go out on me, and even though its a quick fix, its still a hassle, and not to mention downtime. is this a simpl

Re: [pfSense Support] router failover

2008-02-06 Thread Chris Flugstad
AIL PROTECTED] This is a small office, but still it cant go down. Im using soekris 5501 , 256 Ram 433mhz geode procs. prolly not the fastest, but small, low power, and price is right ;) I've used slower and had no problems, but am open to questions or concerns. -chris/topher ---

[pfSense Support] Spanning tree support

2008-02-06 Thread Chris Bagnall
age development on that front? :-) Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it This email is made from 100% recycled electrons - To unsubscribe,

Re: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Chris Buechler
Trave Harmon wrote: I am having a problem: I have multiple virtual mail servers behind a pfsense firewall. Now on each server, I have multiple domains. Now sending to the domain from google or yahoo is perfect and out again is perfect but when I send a message from one virtual server to a

RE: [pfSense Support] Spanning tree support

2008-02-07 Thread Chris Bagnall
connections to the switch), or to provide failover (into 2 separate switches), but if you want to combine the 2, STP was required on the switches? I'll freely admit this is way outside my normal areas of expertise, I'm learning as I go here :-) Regards, Chris -- C.M. Bagnal

Re: [pfSense Support] Spanning tree support

2008-02-07 Thread Chris Buechler
Chris Bagnall wrote: Greetings list, Does anyone know if pfSense includes support for failover between two LAN interfaces? For example, one can provide high availability using CARP to create a virtual router IP failing over between 2 pfSense boxes, but that's not going to solve the pr

Re: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Chris Buechler
I have a document that describes in detail the steps required to accomplish this, though not accessible right now. You're partially right, partially wrong. I'll put it online somewhere later. Bryan Derman wrote: After searching the archives, the forum and conferring with Mr. Google, I've not

Re: [pfSense Support] Strategy for Multiple-Subnet LAN on Single Port

2008-02-07 Thread Chris Buechler
Bryan Derman wrote: Thanks, but VLANs are not an option due to other hardware/switch limitations. Having only a basic understanding of VLANs, I'm also not sure how that would apply (but would be happy to learn) since the underlying objective is to have pfSense support multiple LAN subnets (in

Re: [pfSense Support] router failover

2008-02-08 Thread Chris Flugstad
Im not quite following. i only have 1 WAN connectino, at this time. and want to setup a router just to do basic tasks. I'd also like to setup a 2nd router, in case the 1st one stops or hangs up. I guess I'm not familiar with pfsense to take the simple instructions you gave. If there is mor

Re: [pfSense Support] router failover

2008-02-08 Thread Chris Flugstad
Thanks Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] router failover

2008-02-08 Thread Chris Flugstad
Thanks again for the tutorials/instructions After getting everything setup, I do notice it works fine until i pull the ethernet on one of the LAN of the routers, basically bringing it offline to my computer. i notice a period of time where it doesnt do anything, and then it works, but through

Re: [pfSense Support] enabling high performance tcp - freebsd

2008-02-13 Thread Chris Buechler
Paul M wrote: http://www.psc.edu/networking/projects/tcptune/#FreeBSD this has some recommendations for setting options in freebsd to improve network performance; I don't know whether it's current wisdom though. We do tweak some of that, but almost none of it is applicable to a firewall or

[pfSense Support] Traffic Useage

2008-02-20 Thread Chris Flugstad
I noticed that pfsense does not show the traffic used (in/out) by a user in the captive portal like m0n0 does. What are my options of tracking how much bandwidth is used over a set amount of time? Thanks, Chris - To

Re: [pfSense Support] Traffic Useage

2008-02-20 Thread Chris Flugstad
I just answered my own stupid question sorry, i was out of coffee today. i didnt even know there was a rrd tool on here DOH! -topher - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTEC

Re: [pfSense Support] pfsense crashed out

2008-02-22 Thread Chris Buechler
Paul M wrote: Ngawang Sangye wrote: There were error(s) loading the rules: /tmp/rules.debug:191: rule label too long (max 63 chars) pfctl: Syntax error in config file: pf rules not loaded - The line in question reads [191]: pass in quick on $wan proto { tcp udp } from any to { 192.168.2.58 }

Re: [pfSense Support] Does Captive Portal require Squid?

2008-02-22 Thread Chris Buechler
Radio Tech wrote: I just did a fresh install of 1.2-RC4 with the same results. I will try to find my disk of 1.2 RC3 and try that. Is there something I am possibly doing wrong. I can assure you that changing versions isn't going to fix it, there haven't been any CP issues in a long time.

Re: [pfSense Support] Does Captive Portal require Squid?

2008-02-22 Thread Chris Buechler
Radio Tech wrote: Hey Chris, Thanks for taking the time for this. When i say it doesn't work, i mean all internet traffic goes though without authorization. It skips the CP page. I was just trying to solve the problem. I tried it on a fresh install without blocking anything on the LAN

Re: [pfSense Support] 1.2 full version

2008-02-23 Thread Chris Buechler
Scott Ullrich wrote: On 2/23/08, Odd Kåre Qvam Trøen <[EMAIL PROTECTED]> wrote: Hi list! Does anyone know if I can consider v1.2 as fully released now? Look here: http://snapshots.pfsense.org/FreeBSD6/RELENG_1_2/updates/ and http://snapshots.pfsense.org/FreeBSD6/RELENG_1_2/updates/pfSens

Re: [pfSense Support] IPSEC error

2008-02-25 Thread Chris Flugstad
this where my tunnel hangs up -chris - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] Downloading/Uploading IP identification

2008-02-26 Thread Chris Buechler
Bosco wrote: Hi all, I am using pfSense solution for a while (about 6 months) - version 1.2 with 1 LAN + 3 WANs - and sometimes the Download or Upload traffic goes very high. How do I know who (the LAN IP address) is downloading or uploading - any package or command ? T

Re: [pfSense Support] upgrade woes ...

2008-02-26 Thread Chris Buechler
Jure Pečar wrote: Hello, I rushed to 1.2 as many others did I presume ;) Indeed, the one mirror out of 11 that I have checked stats on has seen 4,000 downloads in the first 24 hours. I'm running 1.0-RELEASE on my home fw (simple adsl and two subnets). And I am not able to upgrade it to

Re: [pfSense Support] upgrade woes ...

2008-02-26 Thread Chris Buechler
Scott Ullrich wrote: On 2/27/08, Chris Buechler <[EMAIL PROTECTED]> wrote: [snip] 1. fetch the upgrade file fetch http://files.pfsense.org/mirror/updates/pfSense-Full-Update-1.2-RELEASE.tgz 2. Run the upgrade command /etc/rc.firmware pfSenseupgrade pfSense-Full-Update-1.2-RELEA

Re: [pfSense Support] wrong email addresses on mail list page

2008-02-29 Thread Chris Buechler
Paul M wrote: http://www.pfsense.org/index.php?option=com_content&task=view&id=66&Itemid=71 the unsubscribe email address is incorrect in the href for support-unsubscribe, it's the same as the subscribe one! Fixed, thanks! --

Re: [pfSense Support] Help Get Games And SW Working Please

2008-03-01 Thread Chris Buechler
SD wrote: Looks like I figured it out (after 3 hours last night, and 4 hours tonight using the backup xml config files). We had the MAC address spoof/cloning turned on. Looks like that isn't working properly since when I turned it off, everything works like a charm (no static ports needed).

Re: [pfSense Support] IPSEC tunnel brings down traffic from lan to wan

2008-03-01 Thread Chris Buechler
Matt Hohman wrote: Hey All got a weird one for you all, We have a pfsense box with 4 interfaces Lan 192.168.0.1 Wan Static Public IP Wan2 Static Public IP Different ISP than Wan DMZ Wan2 and DMZ are bridged. Wan handles all traffic form the lan. We have 3 remote pfsense boxes that use ip

Re: [pfSense Support] After upgrade (1.2RC3 --> 1.2) No IPsec connection any more

2008-03-01 Thread Chris Buechler
Tunge2 wrote: Hello, After upgrading to release 1.2 of PFsense we are not able to set up any IPsec connection anymore. No errors in the logs of Pfsense. But wenn i put the upgrade (PFsense 1.2 RC3) over the not working 1.2 version, it all works again.? So why doesn't the IPsec tunnels w

<    1   2   3   4   5   6   7   8   9   10   >