Re: [pfSense Support] IPSEC tunnel up but no traffic being passed...

2008-03-01 Thread Chris Buechler
Tim Nelson wrote: Hello! I have an IPSEC tunnel configured between a mobile client running TheGreenBow and a fresh installation of pfSense 1.2-RELEASE. The tunnel comes up as expected yet I am unable to ping any devices on the remote subnet. There is not a firewall tab for rules on IPsec tunnels.

Re: [pfSense Support] IP Aliases

2008-03-03 Thread Chris Buechler
Paulo Almeida wrote: Hi, We have a Watchguard Firebox X700 as a Firewall/Gateway for a 10Mb Synchronous link to internet. We want to substitute this equipment and we are investigating the open source solutions. Our Firefox system have one public ip (195.22.21.218) and our ISP give us a 14 block

Re: [pfSense Support] Trouble installing on old Dell 6450

2008-03-06 Thread Chris Buechler
Sean Cavanaugh wrote: Has anyone else attempted to install pfsense on a Dell 6450? booting from the CD in normal mode it will freeze durring hardware lookup and booting with ACPI turned off it gets a kernel trap 12 error almost immediately. Google found a suggestion from someone to enable "OS

Re: [pfSense Support] Message repeating in System Log, can't find the reason

2008-03-06 Thread Chris Buechler
RB wrote: I may be mistaken but I though pfSense only supported 1 DHCP connection on the WAN It was my understanding that only the interface designated 'WAN' could do PPPoE, but the others in a multi-WAN setup could do DHCP or static. That is correct. There are at least a couple people

Re: [pfSense Support] Message repeating in System Log, can't find the reason

2008-03-06 Thread Chris Buechler
Anil Garg wrote: Now that the broadband is very reliable, why would anyone use more than one WAN at home. What are the benefits you have seen or desired in multiple dhcp wan at home. "Very reliable" depends on your provider, your definition of reliable, and even more, your tolerance for down

Re: [pfSense Support] Message repeating in System Log, can't find the reason

2008-03-06 Thread Chris Buechler
Michael Richardson wrote: My reasons are two-fold. One is as Chris said, I work from home AND have servers in the home that need to remain accessible to my hosted servers. The 2nd is because I do a significant amount of off-site backups in 2 directions so a 2nd line allows me to saturate one

Re: [pfSense Support] Message repeating in System Log, can't find the reason

2008-03-06 Thread Chris Buechler
Bryan Derman wrote: I see how multiple WANs from different providers (assuming they use different link-level sources and/or technology) can provide backup for outgoing access, but I haven't figured out how this can help for incoming access to servers. I.E., let's say I have 2 WAN connections wit

Re: [pfSense Support] Message repeating in System Log, can't find the reason

2008-03-06 Thread Chris Buechler
Michael Richardson wrote: I'm hoping the log entries below will help because I'm not familiar with tcpdump yet (spoiled GUI user where packet-capturing is concerned). go to a command line (enable SSH if you haven't already or do it at the actual console), and run: tcpdump -i fxp0 -s 1515

Re: [pfSense Support] Re: routing unreliable

2008-03-06 Thread Chris Buechler
Ngawang Sangye wrote: I would try that but if you have an upper limit set on all traffic - I assume that LAN to LAN will be limted to that speed (2 Mbit for us). Thats what I experience, and slower because of all the internet traffic competing to the point of unusable connections to local serv

Re: [pfSense Support] pfSense VPN X Nortel Contivity

2008-03-06 Thread Chris Buechler
Bill Marquette wrote: Not sure on hardware, but I wouldn't be the least bit surprised if boards as low powered as the new pcengines ALIX boards could do 14mbit encrypted (that's really not alot of traffic). I've heard from people who have tested ALIX hardware to max out at about 10 Mbps IPse

Re: [pfSense Support] pfSense VPN X Nortel Contivity

2008-03-07 Thread Chris Daniel
Chris Buechler wrote: Bill Marquette wrote: Not sure on hardware, but I wouldn't be the least bit surprised if boards as low powered as the new pcengines ALIX boards could do 14mbit encrypted (that's really not alot of traffic). I've heard from people who have tested ALIX

Re: [pfSense Support] Trouble installing on old Dell 6450

2008-03-08 Thread Chris Buechler
Sean Cavanaugh wrote: I can install FreeBSD on it with zero issue. don't even have to disable ACPI. pfsense freezes right after it sees the raid array as a viable HDD. Interesting, not what I would have suspected. Can you try booting FreeSBIE 2.0.1 on that box? http://www.freesbie.org/downlo

Re: [pfSense Support] Dumb VPN question

2008-03-11 Thread Chris Buechler
Scott Ullrich wrote: On 3/11/08, Jeremy Bennett <[EMAIL PROTECTED]> wrote: Hello all, I think this has been asked in the past, but I'm looking for current (1.2) info. If I am sitting behind a PFsense firewall (which happens to be running its own PPTP server), can I connect to another PF

[pfSense Support] Using pfSense to redirect traffic from a dead server

2008-03-12 Thread Chris Bagnall
that reverts to the offsite server when the local server is offline? If not possible with pfSense, does anyone know anything else that might achieve this? Thanks in advance. Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it Th

RE: [pfSense Support] Using pfSense to redirect traffic from a dead server

2008-03-12 Thread Chris Bagnall
this. Thanks for your reply Scott. I was under the impression the load balancer was CARP-based, and CARP required a dedicated interface for heartbeating between the servers? One of the servers will not be on the LAN, and may have a latency of ~30ms as opposed to the sub-1ms one would expect

RE: [pfSense Support] Using pfSense to redirect traffic from a dead server

2008-03-12 Thread Chris Bagnall
purpose of this exercise is to provide disaster recovery for devices on the LAN rather than the WAN) Thanks in advance. Regards, Chris -- C.M. Bagnall, Director, Minotaur I.T. Limited For full contact details visit http://www.minotaur.it This email is made from 100% recycle

Re: [pfSense Support] Dumb VPN question

2008-03-13 Thread Chris Buechler
Angelo Turetta wrote: But by now, only ipfilter can take advantage of this nonstandard extension when doing NAT (don't know about Linux's iptables). It does exist, but apparently doesn't work in ipfilter. Manuel tried it for inclusion in m0n0wall and said it didn't work, and if anybody could

Re: [pfSense Support] Web Console Quits responding

2008-03-17 Thread Chris Buechler
Neal Lawson wrote: ok, it seems that web console will only work if you have a machine on the same subnet, even tho there are routes for the other networks on my lan side.. That's not true, I have a number of deployments that are accessible from behind routers on the inside. Out of the box i

Re: [pfSense Support] Multiple VPN compatible with Micro$oft

2008-03-17 Thread Chris Buechler
Radio Tech wrote: Hello all. I am looking for some information. I need to implement a wireless connection using VPN access. I am kinda green on VPN and really dont know the way to go. The kicker is, it need to be able to support up to 300 user and have the ability to intergrate with Microsof

Re: [pfSense Support] Multiple VPN compatible with Micro$oft

2008-03-18 Thread Chris Buechler
Ryan Rodrigue wrote: Chris, Thanks for the reply. Will PPTP work with MS Active Directory? I was kinda thinking it would using radius. Yes, with IAS. - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e

Re: [pfSense Support] Any chance of pfsense being a port?

2008-03-19 Thread Chris Buechler
Scott Ullrich wrote: None of us have the time and or patience to maintain a freebsd port. Since we replace the /etc/rc system with PHP that would hardly be a good idea. Plus a few kernel patches, a custom kernel config, and it would have to install numerous other ports. It would be a huge e

Re: [pfSense Support] DHCP Server Issues

2008-03-19 Thread Chris Buechler
Dimitri Rodis wrote: Two things I’ve noticed in pfSense 1.2 release: 1. The subnet mask in the scope settings for DHCP keeps reverting back to “32”. At one point, the DHCP server would not start until I went through all of my DHCP scopes (3 interfaces) and reset the subnet masks appropriatel

Re: [pfSense Support] DHCP Server Issues

2008-03-19 Thread Chris Buechler
Dimitri Rodis wrote: The ticket is 1679. I don't know if I classified it correctly-- I don't know if you guys wanted to consider it a bug or a feature req, but really it's both. I wanted to point this out so one of the dev gods can look at it with this in mind and change it if necessary. Th

Re: [pfSense Support] Server NAT

2008-03-21 Thread Chris Buechler
Anil Garg wrote: I am reading the m0n0wall documentation (its so well written - kudos to the author) What, you specifically buttering me up to get a response? ;) There is a pointer that for many public addresses to be mapped to servers inside, m0nowall specifies that "Server NAT should

Re: [pfSense Support] Trouble installing on old Dell 6450

2008-03-21 Thread Chris Buechler
Sean Cavanaugh wrote: ** > Date: Wed, 19 Mar 2008 16:35:11 -0400 > From: [EMAIL PROTECTED] > To: support@pfsense.com > Subject: Re: [pfSense Support] Trouble installing on old Dell 6450 > > On 3/19/08, Sean Cavanaugh <[EMAIL PROTECTED]> wrote: > > > I ju

Re: [pfSense Support] unexpected network throughput

2008-03-22 Thread Chris Buechler
Eric Baenen wrote: As I said before - all is working fine - except: when doing rsync's over ssh/scp from the lab machines to the services core, I'm seeing a maximum sustained throughput of around 60Mbps. With gigabit end to end - even with the AES encryption overhead of the OpenVPN connection

Re: [pfSense Support] Captive Portal

2008-03-22 Thread Chris Buechler
Dimitri Rodis wrote: If I wanted to display a user’s IP address AND MAC address on the captive portal page, does anyone have a code snippet that would do that on the pfSense captive portal page? Is this possible? I suggest opening a feature request ticket on cvstrac.pfsense.org, and/or st

Re: [pfSense Support] Single Captive Portal Login Triggers Dual Accounting Sessions

2008-03-22 Thread Chris Buechler
Kelvin Chiang wrote: Hi, I am seeing a phenomenon, that a single captive portal login triggered 2 accounting sessions, did anyone see this before? Not that I've heard of. If it's something you can consistently replicate, please open a ticket at cvstrac.pfsense.org. --

[pfSense Support] Registration open for pfSense training at BSDCan!

2008-03-22 Thread Chris Buechler
Please see the following post for more information. http://blog.pfsense.org/?p=182 Hope to see you there! Chris - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] Constant reboots in 1.2-RC4

2008-03-23 Thread Chris Buechler
Andy Dills wrote: On Sun, 23 Mar 2008, Scott Ullrich wrote: On 3/23/08, Andy Dills <[EMAIL PROTECTED]> wrote: rl2: discard oversize frame (ether type 0 flags 3 len 29807 > max 1514) That is a rather large packet?Jumbo frames? Nope, that's what has me confused. This

Re: [pfSense Support] Captive Portal

2008-03-23 Thread Chris Buechler
Dimitri Rodis wrote: If I made the modifications to display the mac/client IP on the "default" captive portal page, would you commit it and make it the default captive portal page? I would just throw a couple of lines right beneath the login button that say: Client MAC: xx:xx:xx:xx:xx:xx

Re: [pfSense Support] Watchdog timeouts on 1.2-RELEASE full installation but not on 1.2-RELEASE embedded?!?

2008-03-25 Thread Chris Buechler
Tim Nelson wrote: Thank you for the tip, I'll give it a shot. If that doesn't work, which kernel are you using on the full install when getting the watchdog timeouts? - To unsubscribe, e-mail: [EMAIL PROTECTED] For addit

Re: [pfSense Support] Watchdog timeouts on 1.2-RELEASE full installation but not on 1.2-RELEASE embedded?!?

2008-03-25 Thread Chris Buechler
Tim Nelson wrote: I have not tried the full install without ACPI yet. However, I did use the Uniprocessor kernel when I tried a full install previously. You might want to try the SMP kernel if disabling ACPI doesn't work, though IIRC the embedded kernel is uniprocessor so I somewhat doubt

Re: [pfSense Support] WRAP Bandwidth

2008-03-27 Thread Chris Buechler
Ask Bjørn Hansen wrote: On Mar 26, 2008, at 16:54, Dimitri Rodis wrote: Would a WRAP board be capable of NATting and Shaping a 10 megabit symmetric connection without choking? As Adam said - it should. It depends on the specifics of your traffic though. We had an installation that was

Re: [pfSense Support] WRAP Bandwidth

2008-03-27 Thread Chris Buechler
Eugen Leitl wrote: On Thu, Mar 27, 2008 at 12:21:13PM -0400, Chris Buechler wrote: The pfSense box (1.0-RC3 still) in front of the colo servers that host the project's websites is a WRAP. It pushes around 2-8 Mb at around 10-25% utilization, we can push it up over 20 Mbps out

Re: [pfSense Support] Seagate Microdrive 8GB

2008-03-27 Thread Chris Buechler
Michel Servaes wrote: pfSense won't start... BSD itself starts just fine, but a little later on it asks for the boot device... BIOS senses the drive correctly, the BSD menu comes up, and then a little bit of text passes by (I am a n00b at BSD things), and further on asks me to supply boot devic

Re: [pfSense Support] PPP with Verizon USB Card

2008-03-28 Thread Chris Buechler
RB wrote: If you check the CVS timeline, you'll notice Scott has been quietly adding PPP support with direct references to using cellular links. I added it actually. But it's far from being finished. I'm guessing it won't be available as a supported option for 1.2, but it just might be in

Re: [pfSense Support] problem report with default routes

2008-03-31 Thread Chris Buechler
Randy Schultz wrote: Hey there, This is just a report of a minor problem I've noticed. It's easy to work around so this is more of a FWIW. I am currently toying with 1.2-RELEASE built on Sun Feb 24 17:04:58 EST 2008. We have a bit of a non-standard setup here where the default route on the p

Re: [pfSense Support] problem report with default routes

2008-04-01 Thread Chris Buechler
Randy Schultz wrote: Ah. Now I remember why I used the LAN i'face instead of the WAN i'face - because the WAN is DHCP only whereas with the LAN I can set the static address. You can configure a static IP on the WAN. In fact you have to configure the IP on the WAN in this case, because that's

[pfSense Support] openvpn tunnel using public ip's from 1 side

2008-04-01 Thread Chris Flugstad
So I have a scenario that I wanna run by all you gurus. In my colo, where I have lots of public IPs, and my openvpn server, id like to use these ip's at a remote location on the other end of a vpn tunnel. so basically, at the remote end, it would be as if they wer in my colo. has anyone done thi

Re: [pfSense Support] deleting ssh keys

2008-04-05 Thread Chris Buechler
Randy Schultz wrote: Oi lads and lasses, Does anybody know what is the preferred method to delete SSH keys? I have checked to make sure hosts cannot gain access via SSH, then added keys for a coupla hosts, clicked save, checked(yup, they can now access), removed the keys via the webUI, but

Re: [pfSense Support] Wanted: Tips for a VLAN capable switch (for home use)

2008-04-05 Thread Chris Buechler
Rainer Duffner wrote: Hi, can anybody recommend a switch (8 port or so) that is VLAN capable (and the VLANs actually work with pfSense)? Any switch that supports VLANs with 802.1q trunking (when properly configured) will work with pfSense. I've used multiple Cisco, HP, Netgear, 3Com and possi

Re: [pfSense Support] Routing MSN

2008-04-06 Thread Chris Buechler
Mike Lever wrote: Hi, Been having problems the last few days with users on my LAN not being able to login to MSN messenger. I have been fiddling around on my firewall but unsure what I affected to make this change. How can I route all mu MSN traffic through a specific wan port ? I have 5 vari

Re: [pfSense Support] ipsec tunnel between two lans with the same ip address space

2008-04-07 Thread Chris Buechler
lartc wrote: hi all, i have inherited two sites that need to be connected with an ipsec tunnel -- issue is that each lan on each side of the tunnel is identical rfc1918 address space (172.16.16.0/16). is there a way to overcome this with nat There will be in 1.3, but isn't now. Still I would

Re: [pfSense Support] Constant reboots in 1.2-RC4

2008-04-09 Thread Chris Buechler
Andy Dills wrote: Good news, it appears my assumption was correct. There exists a flaw in the realtek chipset (as quoted earlier in the thread), and it appears that a patch to the driver has been created: http://www.nabble.com/RELENG_7-panic-td16285669.html that is good news. Do you know

Re: [pfSense Support] Multimple WAN ftp server thing.

2008-04-11 Thread Chris Buechler
David Cavanaugh wrote: Thanks so far for all the info. But using WebDAV (port 80) instead of FTP would circumvent this limitation, correct? Correct. Using any file transfer mechanism other than the NAT-b0rk FTP will work around this, including SCP, WebDAV (though that makes me cringe a li

Re: [pfSense Support] blocking to destination ports

2008-04-11 Thread Chris Buechler
Ermal Luçi wrote: What's wrong with only in rules?! You can do the same blocking as you would do with out and just save your computer from blocking the packet after traversing the whole machine! The interface it's blocked on is relatively irrelevant. You can do anything with only in rules,

Re: [pfSense Support] DROP database

2008-04-14 Thread Chris Buechler
On Mon, Apr 14, 2008 at 2:46 AM, Eugen Leitl <[EMAIL PROTECTED]> wrote: > On Sun, Apr 13, 2008 at 06:29:23PM -0400, Scott Ullrich wrote: > > > Not currently. This is a feature in HEAD that will be back-ported at > > some point. 1.3 has an alias import feature where you can paste a > > C/R sep

Re: [pfSense Support] DROP database

2008-04-14 Thread Chris Buechler
On Mon, Apr 14, 2008 at 10:27 AM, Vivek Khera <[EMAIL PROTECTED]> wrote: > > > I know I've piped up many times regarding embedded upgrades... > You've had worse luck than anybody on this topic. :) > I've been using the FreeNAS software (also in "embedded" version), which is > also derived fro

Re: [pfSense Support] PPPoE gets disconnected on WAN port

2008-04-16 Thread Chris Buechler
On Wed, Apr 16, 2008 at 9:46 AM, Olivier Mueller <[EMAIL PROTECTED]> wrote: > Hello... > > Since the situation has not improved, I'm re-posting this :-( > If you have any idea what I could/should try, it would be very nice... > At the moment I have about 3-4 disconnects per day, and according to

Re: [pfSense Support] ipsec saying: racoon: INFO: unsupported PF_KEY message REGISTER

2008-04-16 Thread Chris Buechler
On Wed, Apr 16, 2008 at 4:41 PM, Fabio C Flores <[EMAIL PROTECTED]> wrote: > I havent got all settings for the other end (3rd party). Is there any > specific option I should look at? > Not really, you need to get all the configuration details from the other end, and make sure they aren't using any

Re: [pfSense Support] triple wan to triple lan

2008-04-16 Thread Chris Buechler
On Thu, Apr 17, 2008 at 2:03 AM, Anders Dahl <[EMAIL PROTECTED]> wrote: > > I have one machine and 3 xdsl-connections. I want each of them being a > gateway for it's own LAN. Shouldn't that be possible!? Sure. > I have succesfully created multiple WANs with one LAN, and thougt that it > would b

Re: [pfSense Support] 3-way CARP

2008-04-17 Thread Chris Buechler
On Thu, Apr 17, 2008 at 7:46 PM, Dimitri Rodis <[EMAIL PROTECTED]> wrote: > > Is it possible to have a 3-way CARP setup? I can't seem to find mention of > anyone having one up and running, so I just thought I would check to see if > there was any reason it wouldn't work… > Yeah, you can. The only

Re: [pfSense Support] 3-way CARP

2008-04-17 Thread Chris Buechler
On Thu, Apr 17, 2008 at 8:24 PM, Dimitri Rodis <[EMAIL PROTECTED]> wrote: > So really the peer IP option is there for folks who don't have a > dedicated interface, so that the pfsync traffic doesn't flood the > network, is that right? > No, it's more for networks with switches that don't play ni

Re: [pfSense Support] 3-way CARP

2008-04-17 Thread Chris Buechler
On Thu, Apr 17, 2008 at 8:50 PM, Dimitri Rodis <[EMAIL PROTECTED]> wrote: > One last thing: > > Is there currently any way to *not* assign an IP directly to the WAN > interface in a CARP config? > No, not at this time. > Since the IPs assigned directly to the WAN can't be used in a failover >

Re: [pfSense Support] Support NAT Tranversal with IPSec VPN

2008-04-20 Thread Chris Buechler
On Fri, Apr 18, 2008 at 2:36 PM, Sebastián Veloso Varas <[EMAIL PROTECTED]> wrote: > > I would like to know if some of you has had good experiences trying to > realize tunnels VPN IPSEC doing NAT-T (Transversal), since I was reading the > characteristics that the firewall supports and says that it

Re: [pfSense Support] Multiple SSID on single physical wireless interface

2008-04-20 Thread Chris Buechler
On Sun, Apr 20, 2008 at 10:04 PM, David C P Gray <[EMAIL PROTECTED]> wrote: > > Hi All, > > Apologies if this capability already exists and I have just missed it... > > Are there any plans to implement virtual wireless interfaces in pfSense, > thus allowing one to define multiple wireless networ

Re: [pfSense Support] CP Issue

2008-04-23 Thread Chris Buechler
On Wed, Apr 23, 2008 at 8:24 PM, Tim Dickson <[EMAIL PROTECTED]> wrote: > Finally deploying captive portal at one of our new sites. But am coming > across a redirect issue I'm hoping you can shed some light on. > > BACKGROUND: > I have 3 Wans setup - WAN, DSL, DSL2 > I have 3 Lans setup - LAN,

[pfSense Support] OpenVPN Client more/diff problem

2008-04-24 Thread Chris Flugstad
I have my client setup, server setup. I did however setup the client side to have an IP address of one from the server side, which has blocks of public ip's. I am trying to get the client side of the VPN to be able to use public IP's from the server side. I added a line in the xml file unde

Re: [pfSense Support] triple wan to triple lan

2008-04-26 Thread Chris Buechler
On Fri, Apr 25, 2008 at 6:41 AM, Anders Dahl <[EMAIL PROTECTED]> wrote: > Hi Chris or anyone who will help me... > > I have followed the instructions and have partly succeded. > > This is my setup: > fxp1 = Lan (this is used for management only) > fxp0 holds the

Re: [pfSense Support] CP Issue

2008-04-27 Thread Chris Buechler
On Sun, Apr 27, 2008 at 5:45 PM, RB <[EMAIL PROTECTED]> wrote: > On Sun, Apr 27, 2008 at 2:47 PM, Scott Ullrich <[EMAIL PROTECTED]> wrote: > [snip] > > Squid is not compatible with CP. This would have been helpful if you > > told this up front :) > > That's odd, I've been running it in trans

Re: [pfSense Support] CP Issue

2008-04-27 Thread Chris Buechler
On Sun, Apr 27, 2008 at 5:57 PM, RB <[EMAIL PROTECTED]> wrote: > > I think it does work, there might be some caveats though. Does it > > cause the portal to be bypassed? I've never tried it myself. > > Nope - typical behavior. Clients DHCP, hit the captive portal on the > CARP primary, and a

Re: [pfSense Support] Multiple SSID on single physical wireless interface

2008-04-28 Thread Chris Buechler
On Mon, Apr 28, 2008 at 3:45 AM, David C P Gray <[EMAIL PROTECTED]> wrote: > > I realise that this is looking 2 versions out so all the usual uncertainty > caveats apply, but in practical terms, how long *might* we be looking at > before the virtual WLAN thing could become a possibility in pfSense

Re: [pfSense Support] CP Issue

2008-04-28 Thread Chris Buechler
On Mon, Apr 28, 2008 at 12:48 PM, Tim Dickson <[EMAIL PROTECTED]> wrote: > I did state Squid was in there ;) > ... "I have squid setup with defaults (non transparent) on LAN ONLY I > > have lightsquid installed for reporting" > > So, anything else to try? I'm willing to help the cause if you have

Re: [pfSense Support] Anyone get Wii working with pfSense?

2008-04-28 Thread Chris Buechler
On Mon, Apr 28, 2008 at 9:16 PM, Tom <[EMAIL PROTECTED]> wrote: > I can connect to Worldwide and Regional events with Mario Kart, but I can't > connect to Friends. > Nintendo says they are different types of connections so connecting to > Worldwide and Regional events doesn't necessarily mean conn

Re: [pfSense Support] CP Issue

2008-04-29 Thread Chris Buechler
On Tue, Apr 29, 2008 at 7:04 PM, Tim Dickson <[EMAIL PROTECTED]> wrote: > Well I don't have squid running on the interface in question. > Squid is running on LAN and I want CP on LAN2.. does that make a difference? No, Squid really isn't relevant here, it's the route-to rules and their interactio

Re: [pfSense Support] PPPoE gets disconnected on WAN port

2008-04-29 Thread Chris Buechler
On Tue, Apr 29, 2008 at 8:44 AM, Olivier Mueller <[EMAIL PROTECTED]> wrote: > Short update about my issues: > > Thanks for your feedback (and also to David). I couldn't try the > commands yet because the device was remote and people were working, but > I will keep them around in case the proble

Re: [pfSense Support] Failover problem

2008-04-29 Thread Chris Buechler
On Wed, Apr 30, 2008 at 1:30 AM, Martin Kruse Jensen <[EMAIL PROTECTED]> wrote: > > I created Ticket #1706 regarding the load-balancing issue. Does anyone have > an estimate of how long time before bugs are fixed? Could I do a workarround > meanwhile? > Not sure on a work around, but no bugs will

Re: [pfSense Support] RRD graphs keep going NaN

2008-04-30 Thread Chris Buechler
On Wed, Apr 30, 2008 at 9:40 PM, Jeppe Øland <[EMAIL PROTECTED]> wrote: > I'm not pretty much convinced that the RRD graphs going all NAN is > coused by more than one instance of updaterrd.sh running at the same > time. > You're not convinced? Or was that a typo? > Now the big question is ho

Re: [pfSense Support] RRD graphs keep going NaN

2008-05-02 Thread Chris Buechler
On Wed, Apr 30, 2008 at 10:42 PM, Jeppe Øland <[EMAIL PROTECTED]> wrote: > >You're not convinced? Or was that a typo? > > Typo. I'm convinced. > > Last time it happened, I had just moved the pfSense box from one > location to another (did a shutdown and turned it on in the new > location) ...

Re: [pfSense Support] 1.2 package add-on missing

2008-05-05 Thread Chris Buechler
Paul Peziol wrote: I think I just found the problem. Version 1.2- Release but under Platform it says CD-ROM. I guess I assumed I installed it to the HD and didnt pay attention to it. Is there a way to move it to the hd without running the cd again and resetting up the config. or can I just do

Re: [pfSense Support] ping_hosts.sh in infinite loop

2008-05-06 Thread Chris Buechler
David Rees wrote: On Tue, May 6, 2008 at 6:12 AM, <[EMAIL PROTECTED]> wrote: Was it just me, or did [EMAIL PROTECTED]'s reply look empty? It was. - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands,

Re: [pfSense Support] ping_hosts.sh in infinite loop

2008-05-06 Thread Chris Buechler
David Rees wrote: On Tue, May 6, 2008 at 9:27 AM, Chris Buechler <[EMAIL PROTECTED]> wrote: David Rees wrote: Was it just me, or did [EMAIL PROTECTED]'s reply look empty? It was. Thought so. ;-) Anyone have any ideas on the ping_hosts.sh getting stuck and

Re: [pfSense Support] ping_hosts.sh in infinite loop

2008-05-06 Thread Chris Buechler
On Tue, May 6, 2008 at 5:30 PM, David Rees <[EMAIL PROTECTED]> wrote: > > OK, attached is a patch to /etc/config.inc that makes sure that the > config.xml and config.cache is updated atomically. The patch adds a > function function "write_safe_file" with 3 arguments: $file, $content, > $force_b

Re: [pfSense Support] boot usb wothout bios support

2008-05-06 Thread Chris Buechler
On Tue, May 6, 2008 at 9:26 PM, Tortise <[EMAIL PROTECTED]> wrote: > > It seems to me that a floppy could boot, load a USB driver and hand over to > the USB device on these old machines? Any reason not? (Floppy disk > required!) > I was thinking of that - I seem to recall some kind of boot loade

Re: [pfSense Support] boot usb wothout bios support

2008-05-06 Thread Chris Buechler
On Tue, May 6, 2008 at 10:35 PM, Tortise <[EMAIL PROTECTED]> wrote: > The older FreeBSD installations had a floppy boot disc, whether this could be > adapted I have wondered? Not in this fashion, no. - To unsubscribe, e-mail: [E

Re: [pfSense Support] Unable to install pfSense 1.2 LiveCD

2008-05-07 Thread Chris Buechler
Atkins, Dwane P wrote: I am attempting to install pfSense on a Dell PowerEdge RS200 server. This has a 64 bit ES4500 2.2 Ghz Processor with 1 GB memory and 80 gig SATA hard drive. The install goes so far and then I start getting ad4: and acd0 errors (errors that occur on ad4 seem to o

Re: [pfSense Support] Unable to install pfSense 1.2 LiveCD

2008-05-07 Thread Chris Buechler
Couple other suggestions: -Disable ACPI -make sure the BIOS is up to date. and other items here may help if all else fails. http://devwiki.pfsense.org/BootTroubleShooting Atkins, Dwane P wrote: Thank you, Chris. I could get to the point where it brought the reboot screen. I chose to

Re: [pfSense Support] Unable to install pfSense 1.2 LiveCD

2008-05-07 Thread Chris Buechler
Atkins, Dwane P wrote: Chris, My apologies. Which file should I download. I did the pfSense.iso.gz, however it would not allow me to unzip this using winzip. that's the right file. I just downloaded it and it opens and extracts fine with WinRAR, and it's the same file a numbe

Re: [pfSense Support] Re: "brilliant" advice from a security audit...

2008-05-07 Thread Chris Buechler
On Wed, May 7, 2008 at 7:49 PM, Ugo Bellavance <[EMAIL PROTECTED]> wrote: > > Ease of setup is usually the reason. The main reason of the warning is > that it is possible to use PPTP with no or very weak encryption. > Sure, the issue isn't the output itself, it's the suggestion you run PPTP over

[pfSense Support] 1:1 push WAN ip to VLAN interface?

2008-05-08 Thread Chris Flugstad
share the same subnet of the 192. on the inside. I want basically a 2nd, 3rd and so on public WAN ip to be directly hooked with a different vlan. how might i do this? -chris - To unsubscribe, e-mail: [EMAIL PROTECTED] For

Re: [pfSense Support] PPTP problem

2008-05-08 Thread Chris Buechler
On Thu, May 8, 2008 at 6:45 PM, Jeremy Bennett <[EMAIL PROTECTED]> wrote: > Thank you for the help. > > I've considered this, but once I've established a VPN connection, shouldn't > that put me on the LAN where the NAT firewall rules on the WAN don't apply? > Yes, it does. Only PPTP rules apply to

Re: [pfSense Support] panic on install of stable pfsense on latests Dell PE 1950 server

2008-05-08 Thread Chris Buechler
On Thu, May 8, 2008 at 12:26 PM, Christopher Iarocci <[EMAIL PROTECTED]> wrote: > I'll trade you that machine for one that works. ;-) > > > > Seriously though, disable the ACPI in the bios. There was just a thread on > a similar problem yesterday. See here: > > > > http://www.mail-archive.com/su

Re: [pfSense Support] nat on command line

2008-05-08 Thread Chris Buechler
On Fri, May 9, 2008 at 12:44 AM, Diego A. Gomez <[EMAIL PROTECTED]> wrote: > How I can to write a nat rule in command line? > you don't. you can manually edit config.xml, add the rule, remove the config.cache and reload the filter rules but that's not suggested since you could blow up your config

Re: [pfSense Support] nat on command line

2008-05-08 Thread Chris Buechler
On Fri, May 9, 2008 at 12:56 AM, Diego A. Gomez <[EMAIL PROTECTED]> wrote: > > I need to write a nat rule for tun0 (VPN) interfase > Can I do it through config.xml? > I don't believe that's possible without at least some minor code changes. 1.3 will allow NAT on OpenVPN interfaces but that's not a

Re: [pfSense Support] 1:1 push WAN ip to VLAN interface?

2008-05-09 Thread Chris Flugstad
did it NAT 1:1 to the entire subnet? i did that and it didnt really take i created the 2nd public IP 75.XXX.XXX.18 as "other" than i 1:1 75:XXX.XXX.18/32><192.168.10.0/32 did i miss something? - To unsubscribe, e-mail: [EM

[pfSense Support] How do i use different public IP's on different Vlans when I have only 1 WAN interface

2008-05-09 Thread Chris Flugstad
I wrote an earlier post, but didnt describe it too well. i have a few public ip's of of them is used for 4 vlans. Each of those vlans are on different subnets 192.168.1.1 192.168.2.1 192.168.3.1 192.168.4.1 they all have dchp and route out through public ip #1 now i have another vlan 192.1

Re: [pfSense Support] bsdperimeter.com down -- what is the state of commercial support for pfSense?

2008-05-09 Thread Chris Buechler
On Fri, May 9, 2008 at 5:32 AM, Timo Schoeler <[EMAIL PROTECTED]> wrote: > Hi there, > > I'm about to sell a bunch of pfSense-based Firewalls to a customer (who > wants to run a nice loadbalanced setup). > > What about commercial support? bsdperimeter.com is down, as it seems to > me... Thanks for

Re: [pfSense Support] panic on install of stable pfsense on latests Dell PE 1950 server

2008-05-09 Thread Chris Buechler
On Fri, May 9, 2008 at 11:18 AM, Harrie Bonenkamp (Colson) <[EMAIL PROTECTED]> wrote: > Which livecd should I download from development (pfsense1.2 –freebsd6.3) > http://cvs.pfsense.org/~sullrich/testing_images/6/FreeBSD_RELENG_6_3/pfSense_RELENG_1_2/ pfSense.iso.gz --

Re: [pfSense Support] setting time

2008-05-10 Thread Chris Buechler
On Sat, May 10, 2008 at 11:16 AM, Dean Larson <[EMAIL PROTECTED]> wrote: > > i have a cron job of 15 * * * * /usr/sbin/ntpdate -u -s tick.usno.navy.mil > > i did the command you said ntpdate pool.ntp.org. and yes it sets the time, > but it doesn't stay. for long. > > computer kept near perfect t

Re: [pfSense Support] setting time

2008-05-10 Thread Chris Buechler
On Sun, May 11, 2008 at 12:19 AM, Dean Larson <[EMAIL PROTECTED]> wrote: > > i did ysctl -w kern.timecounter.hardware=i8254 and after 33 minutes i was off > .04 seconds. better than 250 seconds.:) > Good to know! Thanks for reporting back. --

Re: [pfSense Support] multiple WAN load-balancing (aggregating/combining the speed)

2008-05-11 Thread Chris Buechler
2008/5/11 Michael Smirnov <[EMAIL PROTECTED]>: > Hello! > First of all, does pfSense support > - pptp vpn interfaces as WAN Yes > - more than one(I need 8) pptp vpn interface as WAN > No. > Is there a workaround to connect all 8 pptp connections > from pfSense simultaneously? > Not a go

Re: [pfSense Support] Re: Out of Office AutoReply: [pfSense Support] pfSense6 Dev

2008-05-12 Thread Chris Buechler
RB wrote: 1. If you MUST send an autoresponse, make sure you only send it if it is DIRECTLY to you. 2. NEVER attach one of the stupid "prove you are a human" milters to it. 3. Exchange just doesn't cut it. Top-posting, autoresponders, dim-witted filtering, HTML email... 4. And the [EMAIL

Re: [pfSense Support] RE: Atheros 5212 throwing tons of errors

2008-05-12 Thread Chris Buechler
On Mon, May 12, 2008 at 7:56 PM, tester <[EMAIL PROTECTED]> wrote: > Hello, > there is a special build of pfSense 1.2 based on > FreeBSD 6.3 instead of 6.2. A user in the forum said > that he experiences much less problem with wireless. Yeah try this: http://cvs.pfsense.org/~sullrich/testing_im

Re: [pfSense Support] ipsec woes

2008-05-13 Thread Chris Buechler
On Tue, May 13, 2008 at 6:47 AM, Jure Pečar <[EMAIL PROTECTED]> wrote: > > > I solved office1 to office2 with openvpn, now I want to figure out the > problem between office1 and servers. > > I monitored the ipsec logs on both pfsenses at the time when ssh session > freezes and nothing shows up

Re: [pfSense Support] Intel Pro 1000 VT

2008-05-13 Thread Chris Buechler
Only have time for a very quick reply, try: http://cvs.pfsense.org/~sullrich/testing_images/6/FreeBSD_RELENG_6_3/pfSense_RELENG_1_2/ On Tue, May 13, 2008 at 1:01 PM, Adam Costello <[EMAIL PROTECTED]> wrote: > > > > > Hi, > > > > I've got a Dell R300 with a Intel Pro 1000VT Quad Gigabit NIC. I've

Re: [pfSense Support] Feature request - take it with a grain of salt

2008-05-13 Thread Chris Buechler
On Tue, May 13, 2008 at 5:08 PM, Ruediger G. Biernat <[EMAIL PROTECTED]> wrote: > Hi there, > > I wonder how cool it would be to integrate my favorite WLAN meshing software > (www.open-mesh.com) into pfsense? > If you open a feature request ticket at http://cvstrac.pfsense.org we'll consider it.

Re: [pfSense Support] Intel Pro 1000 VT

2008-05-14 Thread Chris Buechler
On Wed, May 14, 2008 at 5:34 AM, Adam Costello <[EMAIL PROTECTED]> wrote: > There's good news and bad news. > > Good news: That install fixed the issue with the Intel Pro 1000VT and when I > stick the cable link status says UP > > Bad News: The onboard Broadcom NetXtreme Dual Gigabit NIC is not wor

Re: [pfSense Support] Virtualizing pfSense

2008-05-15 Thread Chris Buechler
On Thu, May 15, 2008 at 3:07 PM, Rainer Duffner <[EMAIL PROTECTED]> wrote: > > Am 15.05.2008 um 20:55 schrieb Sean Cavanaugh: > >> >> for the record, VMWare tools is included in the ports collection > open-vm-tools from ports is the way to go. I have packages built for pfSense, just need to put to

Re: [pfSense Support] Why DHCP and portal logs are limited to 65535 octets?

2008-05-16 Thread Chris Buechler
On Fri, May 16, 2008 at 3:44 AM, <[EMAIL PROTECTED]> wrote: > Hello, > > in /var/log/ the DHCP and portal auth logs are limited to 65535 octets. So I > can't read lot connections! Is it possible to bypass the limitation (without > syslog server) ? > That's the first I've heard of this. Can you

<    1   2   3   4   5   6   7   8   9   10   >