[pfSense Support] forum vs mailing list

2009-06-17 Thread JJB
Hello, I didn't realize there is also a pfsense forum and that they are not connected. Which is the best place to post technical questions about configuration? - Joel - To unsubscribe, e-mail:

Re: [pfSense Support] Outbound mail multi-wan

2009-06-17 Thread JJB
We've tried this 10 different ways, so far it has not worked. Current Config is two pfsense 1.22 firewalls with CARP two WAN connections (not load balanced or failover) (covad att), with a DMZ interface where our mail and other internet servers live. I want the mail server to only make SMTP

Re: [pfSense Support] Outbound mail multi-wan

2009-06-16 Thread JJB
Yes, setup your rules on the interface with the mail server accordingly. I don't know how to set up pfsense to bind the mail server to the ATT network interface instead of the Covad, can someone provide me with details of how this would be done? It doesn't look like static routes would work

[pfSense Support] Outbound mail multi-wan

2009-06-13 Thread JJB
Hello, pfsense 1.22 we have a mail server: mail.domain.com We have two wan links WAN_ATT (T1) and WAN (covad DSL) reverse DNS is configured for the ATT link for mail.domain.com and for the covad link as mail01.domain.com is there some way to enable the mail server to open smtp

Re: [pfSense Support] Outbound mail multi-wan

2009-06-13 Thread JJB
Chris Buechler wrote: On Sat, Jun 13, 2009 at 3:07 PM, JJBonephat...@earthlink.net wrote: Hello, pfsense 1.22 we have a mail server: mail.domain.com We have two wan links WAN_ATT (T1) and WAN (covad DSL) reverse DNS is configured for the ATT link for mail.domain.com and for the covad

Re: [pfSense Support] pfsense 1.2.3 problem with vpn ipsec (can ping, but nothing else ?)

2009-02-02 Thread JJB
Ermal Luçi wrote: look at this http://forum.pfsense.org/index.php/topic,13847.0.html Just out of sheer curiosity - what the heck does this do, why does solve his problems, and what makes those particular values the correct ones to put there? - Joel In /etc/rc.bootup add there near the

Re: [pfSense Support] Couple OpenNTPd Ticket Comments Fix

2009-01-08 Thread JJB
So does OpenVPN on pfsense have a known vulnerability, and if so, can we patch the pfsense servers (running 1.2) as described in the advisory? - Joel today's FreeBSD security advisories. The OpenSSL one is potentially applicable with OpenVPN, so it's being rebuilt with the updates.

[pfSense Support] sudden ssh problems with 1.2.1 rc1

2008-12-18 Thread JJB
Today our company is doing one of our most important software releases todate and suddenly this morning for no apparant reason (no changes were made to pfsense) we started having trouble opening new ssh connections to our web server. We have ssh tunnels going by which we do mysql replication,

Re: [pfSense Support] sudden ssh problems with 1.2.1 rc1

2008-12-18 Thread JJB
Also, more info: we are able to any internet host but our www server without problem, and to ssh from any internet host TO our www sever with no problem, just ssh to www from the office behind pfsense is not working correctly. - Joel

Re: [pfSense Support] sudden ssh problems with 1.2.1 rc1

2008-12-18 Thread JJB
Rockbochs Inc. (218)727-4332 x105 - JJB onephat...@earthlink.net wrote: Also, more info: we are able to any internet host but our www server without problem, and to ssh from any internet host TO our www sever with no problem, just ssh to www from the office behind pfsense is not working

Re: [pfSense Support] OpenVPN issues...

2008-12-08 Thread JJB
Chris Buechler wrote: 2 . We want our VPN users to use the 3mb link. After we configured this, VPN with proto udp stopped working - since the DSL is now the WAN link it appears that what happens is the firewall responds to an incoming udp packet on the T1 line by sending a response over the WAN

Re: [pfSense Support] load balancing non-http services?

2008-11-24 Thread JJB
Tom Müller-Kortkamp wrote: Am 22.11.2008 um 00:22 schrieb JJB: Is it possible with the pfsense load balancing to load balance between two database servers on port 3306? it should work with every tcp service - To unsubscribe

[pfSense Support] load balancing non-http services?

2008-11-21 Thread JJB
Is it possible with the pfsense load balancing to load balance between two database servers on port 3306? - Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] Commercial

[pfSense Support] vrrp.mcast.net?

2008-11-10 Thread JJB
This shows up in darkstat on our fw, as CARP. I haven't found any useful information on this host, does anyone have an idea? - Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] OpenVPN super-slow upload speeds

2008-11-10 Thread JJB
JJB wrote: I, and some of our users are getting very slow, modem like upload speeds on OpenVPN from home - using Tunnelblick on my DSL (6mbit down 768 up). Download speed is OK - about 560kbps. The WAN link I am connected to is 3mbit in both directions. This might be a mac-only issue

Re: [pfSense Support] find my openvpn ip address?

2008-11-07 Thread JJB
Nevermind. Found it... - Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED] Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] Throttling/Shaping anomaly

2008-10-29 Thread JJB
Karl Fife wrote: On Wed, 29 Oct 2008 10:01:31 +, Paul Mansfield I think you mean asymmetric rather than half duplex. Hi Paul. I do make mistakes, but I did in fact mean to say BOTH asymmetric AND half-duplex. In other words: ADSL is Asymetric AND ALSO half-duplex SDSL

Re: [pfSense Support] pfsense 1.2.1 dude

2008-10-28 Thread JJB
Chris Buechler wrote: On Mon, Oct 20, 2008 at 6:08 AM, Mikel Jimenez [EMAIL PROTECTED] wrote: Hello Is secure to put pfsense 1.2.1 in production enviroment? I think the others who replied may have misunderstood your intent, it appears you aren't a native English speaker, and may have

Re: [pfSense Support] syslogd stuck at 100% cpu

2008-10-28 Thread JJB
BSD Wiz wrote: Not that this helps but I have seen what you describe only while running in a VM Ware environment. -Phil G On Oct 28, 2008, at 10:45 AM, Ian Levesque [EMAIL PROTECTED] wrote: Hello, I'm running 1.2.1-RC1 (built on Sat Sep 13 03:53:42 EDT 2008). After about 10 days of

Re: [pfSense Support] OpenVPN super-slow upload speeds

2008-10-26 Thread JJB
Scott Ullrich wrote: On Sat, Oct 25, 2008 at 6:57 PM, BSD Wiz [EMAIL PROTECTED] wrote: To bad it's for v10.5 only. Coming into this thread late, please forgive me if this has been asked but can this Viscosity import a configuration file? With 1.3 we can generate a windows openvpn

[pfSense Support] OpenVPN super-slow upload speeds

2008-10-24 Thread JJB
I, and some of our users are getting very slow, modem like upload speeds on OpenVPN from home - using Tunnelblick on my DSL (6mbit down 768 up). Download speed is OK - about 560kbps. The WAN link I am connected to is 3mbit in both directions. This might be a mac-only issue, not sure, I haven't

Re: [pfSense Support] OpenVPN super-slow upload speeds

2008-10-24 Thread JJB
Paul Mansfield wrote: JJB wrote: I, and some of our users are getting very slow, modem like upload speeds on OpenVPN from home - using Tunnelblick on my DSL (6mbit down 768 up). Download speed is OK - about 560kbps. The WAN link I am connected to is 3mbit in both directions. This might

Re: [pfSense Support] OpenVPN super-slow upload speeds

2008-10-24 Thread JJB
Paul Mansfield wrote: JJB wrote: I, and some of our users are getting very slow, modem like upload speeds on OpenVPN from home - using Tunnelblick on my DSL (6mbit down 768 up). Download speed is OK - about 560kbps. The WAN link I am connected to is 3mbit in both directions. This might

Re: [pfSense Support] OpenVPN super-slow upload speeds

2008-10-24 Thread JJB
Your architecture is somewhat unclear - do I correctly surmise that you have a pfSense server *somewhere* on a 3/3 connection, and that several users connect to it via OpenVPN? two pfsense servers using CARP for failover with a shared vip connected to 3/3 pipe (two t1 lines bonded) Also a

Re: [pfSense Support] jerky network streaming?

2008-10-23 Thread JJB
Craig Drown wrote: On Wed, 22 Oct 2008 13:23:18 -0700, JJB did say: Video streaming over the network from the internet, including youtube (especially in high quality mode) is still choppy, even though we have upgraded the DSL connection from 3mbit to 10mbit. Has anyone experienced choppy

[pfSense Support] tcp tuning for pfsense?

2008-10-23 Thread JJB
http://www.psc.edu/networking/projects/tcptune/ I'm wondering if any of this freebsd tuning info is relevant to pfsense, has it already been done, are there any benefits to setting any of these things (some of which are missing - there seems to be no /etc/rc.conf on pfsense - where is it?).

[pfSense Support] OpenVPN issues...

2008-10-10 Thread JJB
Hello, We just migrated our vpn users to our pf sense firewall. We have dual firewalls (CARP) and dual wan links - a 3mbit bonded t1 link and a 10mb dsl link. (not load balanced - a LAN router is determining what is going to which link) 1. How do we disable a vpn client? Clicking block

[pfSense Support] ntop still not installing

2008-09-26 Thread JJB
There does not seem to be any stuck processes. Also, as I understand it the install process seems to use the local web browser to do the download and install, if you navigate away from the page the install will not complete. Other packages install just fine. Could there be a problem with

Re: [pfSense Support] ntop still not installing

2008-09-26 Thread JJB
Thanks! - Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

[pfSense Support] darkstat - reverse dns lookups?

2008-09-26 Thread JJB
Since ntop isn't working, I installed darkstat, which seems to pretty much do the job that I wanted ntop to do. I set it to track the LAN interface. For some reason I'm getting DNS resolution for all the external websites, but not for internal ip addresses. Is there any way to get dns names

[pfSense Support] darkstat - nevermind.

2008-09-26 Thread JJB
Actually it is working... My apologies. Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] multi-wan / ha

2008-09-18 Thread JJB
cassio lima wrote: its support muli- wan traffic shaping version 1.3 On Thu, Sep 18, 2008 at 12:31 AM, JJB [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] wrote: On Sep 17, 2008, at 6:11 PM, cassio lima wrote: you using version 1.3 ? On Wed, Sep 17, 2008 at 7:41 PM, JJB [EMAIL

[pfSense Support] CARP not working...

2008-09-18 Thread JJB
Hello, we just brought up a secondary pfsense firewall, fw02. We are getting the following error on fw01: [sync_settings]An error code was received while attempting XMLRPC sync with username admin http://172.16.4.6:80 - Code 2: Invalid return payload: enable debugging to examine incoming

[pfSense Support] multi-wan / ha

2008-09-17 Thread JJB
Any issues to look out for when configuring dual redundant pf firewalls load balancing to multiple wan connections? In our case a 3mb line and a 3mb dsl line. We have LAN, WAN and DMZ interfaces on the pf firewall. We were attempting to use QOS until someone on the list hipped us that QOS

Re: [pfSense Support] multi-wan / ha

2008-09-17 Thread JJB
On Sep 17, 2008, at 6:11 PM, cassio lima wrote: you using version 1.3 ? On Wed, Sep 17, 2008 at 7:41 PM, JJB [EMAIL PROTECTED] wrote: Any issues to look out for when configuring dual redundant pf firewalls load balancing to multiple wan connections? In our case a 3mb line and a 3mb dsl

[pfSense Support] install of ntop from packages page fails

2008-09-10 Thread JJB
Hello, This is a repost. I go to the packages page on our firewall, and click the install button for ntop. The download of ntop and dependencies dies every time, sometimes at 2%, sometimes at 7 % sometimes at 20%, but it always dies. other packages we have installed (such as bandwidthd)

[pfSense Support] ntop package install fails

2008-09-05 Thread JJB
I've tried to install the ntop package numerous times. It always stalls out, sometimes at 2% sometimes at 20% download and never completes. Any suggestions? - Thanks - Joel - To unsubscribe, e-mail: [EMAIL PROTECTED] For

[pfSense Support] Traffic shaping WAN-DMZ ?

2008-09-03 Thread JJB
Hello, We have servers on our SHARED_DMZ interface and we would like to give priority to http requests to those servers from our web server over all other traffic. The bandwidth usage is tiny, a few kbits every few minutes. These series of http requests execute within 15 -20 seconds during