Re: [pfSense Support] Load Balanced Passive FTP?

2009-10-01 Thread Chris Buechler
On Thu, Oct 1, 2009 at 7:02 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: -Original Message- From: Chris Buechler [mailto:cbuech...@gmail.com] Sent: Thursday, October 01, 2009 2:58 PM To: support@pfsense.com Subject: Re: [pfSense Support] Load Balanced Passive FTP? On Thu

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Chris Buechler
On Fri, Oct 2, 2009 at 1:06 AM, Jim Pingle li...@pingle.org wrote: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{GUID} DhcpConnForceBroadcastFlag=dword: On my laptop this is set to 1, and it still works for me. I've even plugged directly into my

Re: [pfSense Support] Vista DHCP Issue

2009-10-02 Thread Chris Buechler
On Fri, Oct 2, 2009 at 8:03 AM, Curtis LaMasters curtislamast...@gmail.com wrote: I won't be at that client today, but I should be there this weekend or early next week and will get that for you. Great, I'm curious. In my case, I have 5 Vista machines all with different patch levels and

Re: [pfSense Support] Transparent squid box on same subnet

2009-10-04 Thread Chris Buechler
On Sun, Oct 4, 2009 at 2:59 PM, Apostolis Sotiropoulos m0rphys2...@gmail.com wrote: Hi to all, I want to have a transparent squid proxy on a box which is in the same subnet with the pf lan. So i'm adding a nat to forward all traffic to 80 in the squids port but that makes a loop for the

Re: [pfSense Support] Pfsense 1.2.3 alix 2d13 IDE disk installation problem

2009-10-04 Thread Chris Buechler
2009/10/4 ozan ucar m...@ozanucar.com: Hi everyone, I have a alix 2d13 onboard.I need installation pfsense 1.2.3 on ide disk. http://forum.pfsense.org/index.php/topic,13509.0.html I'm installation change config.xml for nic lanvr0 wan vr1 and edit /etc/fstap  and replace all disk name ad0 .

Re: [pfSense Support] possible bug

2009-10-04 Thread Chris Buechler
On Fri, Oct 2, 2009 at 3:43 PM, Borowicz, Paul pborow...@behaviorcorp.org wrote: I am 1.2.3-RC3 built on Mon Sep 14 02:04:35 UTC 2009 I have a DMZ, WAN, and LAN on this box.  I have been getting bleed through from the DMZ to the LAN and vice versa. I have a WAN rule, all stars except

Re: [pfSense Support] streaming video (rtsp, mms)

2009-10-04 Thread Chris Buechler
On Fri, Oct 2, 2009 at 9:25 AM, Jure Pečar pega...@nerv.eu.org wrote: If anyone is going to dig this in the archives, here is the simplest way: * download http://docs.real.com/docs/proxykit/osrtspproxy_2_0.tar.gz * patch with patches from

Re: [pfSense Support] VLAN Capable switch

2009-10-04 Thread Chris Buechler
On Sun, Oct 4, 2009 at 2:15 PM, Anil Garg garg_art2...@yahoo.com wrote: I have a pfsense with two 10/100 PCI cards (acting as LAN WAN router). I have a 4 port (quad) 10/100 PCI (ZNYX ZX374) card. If I were to add this card into the box and then add those ports and bridge them with each other

Re: [pfSense Support] One check-box is missing in Rules-Edit-Advanced of 1.2.3-RC3 snapshot

2009-10-06 Thread Chris Buechler
On Tue, Oct 6, 2009 at 9:57 AM, Evgeny Yurchenko evg.yu...@rogers.com wrote: Sorry to bring old thread back but I yesterday was helping friend of mine on his pfSense box 1.2.2 built on Thu Jan 8 22:30:24 EST 2009 FreeBSD 7.0-RELEASE-p8 i386 and allow-opts WAS in his box!

Re: [pfSense Support] bug in DHCP client

2009-10-06 Thread Chris Buechler
On Tue, Oct 6, 2009 at 7:05 PM, bryanmeds...@akalc.org wrote: I've discovered a bug in the way pfSense (or FreeBSD) handles DHCP. In my simple setup, my pfSense box receives a dynamic IP from its upstream router on the WAN side.  As expected, it creates a route from its assigned IP to

Re: [pfSense Support] pfsense 1.2-RELEASE and OpenBGP

2009-10-06 Thread Chris Buechler
On Tue, Oct 6, 2009 at 10:42 PM, Agi Subagio a...@mbs.co.id wrote: I have pf 1.2-RELEASE and OpenBGP 0.5 installed. I have configure bgpd.conf using webGUI like this: # This file was created by the pfSense package manager.  Do not edit! AS 65001 holdtime 60 listen on 172.16.1.252/16

Re: [pfSense Support] Block rule creates syntax error

2009-10-08 Thread Chris Buechler
On Thu, Oct 8, 2009 at 7:09 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: Please switch to raw logs and show us the entry text and syntax error from the alert. Sanitize before-hand if you want. I am not sure if this is what you want, but: php: : There were error(s) loading the rules:

Re: [pfSense Support] FTP proxy

2009-10-08 Thread Chris Buechler
On Thu, Oct 8, 2009 at 9:23 PM, Nathan Eisenberg nat...@atlasnetworks.uswrote: Been banging my head on the FTP proxy for a little while on a box that has a lot of 1:1 NAT – finally did a dump of the PF ruleset, and saw this little gem. What’s goin on? ;) How can I… not have this rule?

Re: [pfSense Support] Dell R200 Working Setup?

2009-10-08 Thread Chris Buechler
On Fri, Oct 9, 2009 at 12:52 AM, Curtis LaMasters curtislamast...@gmail.com wrote: Anyone know what version of OS I need to install to get a Dell R200 working properly?  I have 1.2.3-RC3 installed right now and I'm getting the bad hdr length messages in the logs and it's keeping me from

Re: [pfSense Support] Dell R200 Working Setup?

2009-10-08 Thread Chris Buechler
On Fri, Oct 9, 2009 at 1:10 AM, Curtis LaMasters curtislamast...@gmail.com wrote: Still getting them with that setting enabled.  Do I need to reboot? No. Strange this would come up again, last time was about a year ago and I don't recall what the cause was. I know there are a lot of people

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 2:01 PM, Andreas Fuchs f...@tcnet.ch wrote: i'm running on 1.2.2, might this be my problem? as it is a production environment i don't think it's smart to upgrade to 1.2.3-RC3 Yes that's your problem, and it's fine to upgrade to RC3, the final release won't be much

Re: [pfSense Support] Routing Seperate Gateways, but the Gateway is the same IP, on different WAN's

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 7:01 PM, Chris Flugstad ch...@cascadelink.com wrote: I have multiple DSL lines, but they all have the same GW.  I am not load balancing, but just want to route VOIP over one, and Internet traffic over the other. When I try to select FW rules to route voip ports out

Re: [pfSense Support] Snort Whitelist still blocking

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 10:59 PM, Indrajaya Pitra Perdana viet...@indo.net.id wrote: dear support, I try to whitelist all of google site that have IP address 216.239.32.0/19 , and then i restarted the snort services, but somehow it keeps blocking them, is there anything that i should do to

Re: [pfSense Support] Switching to serial console during the boot

2009-10-15 Thread Chris Buechler
On Thu, Oct 15, 2009 at 3:03 AM, bsd b...@todoo.biz wrote: Hello, I am working on setting up couple of high end firewall based on Advantech Hardware. http://www.osnet.eu/en/content/opensource-firewall-fwa-3140 Everything goes well if we use the embedded version of the OS = infos are

Re: [pfSense Support] potential pfsense hardware

2009-10-15 Thread Chris Buechler
On Thu, Oct 15, 2009 at 11:32 AM, Joseph L. Casale jcas...@activenetwerx.com wrote: Anybody else? I don't have any experience with Marvell other than in my Laptop. I assume they are better than Realtek... I have a myriad of Intel, Broadcom, 1 marvell now and several realtek nics on various

Re: [pfSense Support] potential pfsense hardware

2009-10-15 Thread Chris Buechler
On Thu, Oct 15, 2009 at 6:50 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: I'd rather have neither. Won't argue that:) All of this has me concerned, I am waiting on some other issues but was about to order a 3 nic Alix board and saw it uses Via VT6105M 10/100 nics? I haven't used Via

Re: [pfSense Support] svg errors in chrom(ium) browser?

2009-10-18 Thread Chris Buechler
On Mon, Oct 19, 2009 at 1:01 AM, David Burgess apt@gmail.com wrote: I'm using the chromium browser on Ubuntu and when I try to view PFSense's traffic graphs I don't see the graph, just a box with the following error: This page contains the following errors: error on line 2 at column 1:

Re: [pfSense Support] 1.2.3-RC3 using slbd ?

2009-10-24 Thread Chris Buechler
On Sat, Oct 24, 2009 at 6:06 AM, Josep Pujadas i Jubany jo...@bellera.cat wrote: Hello! I migrated one pfSense today from 1.2-BETA-1-PRERELEASE-SNAPSHOT-04-23-07 embedded to 1.2.3-RC3 built on Thu Oct 22 05:53:52 UTC 2009 nanobsd I changed de CF and I loaded my config.xml backup.

Re: [pfSense Support] Outgoing PPTP

2009-10-26 Thread Chris Buechler
On Mon, Oct 26, 2009 at 5:37 PM, Adam Van Ornum greatb...@hotmail.com wrote: I'm really sorry if this has been answered in other places, I tried searching but couldn't find anything.  We have a Windows 2003 server that handles the PPTP so I have pfSense configured to redirect PPTP to the

Re: [pfSense Support] do we support ipsec-nat ?

2009-10-26 Thread Chris Buechler
On Mon, Oct 26, 2009 at 9:31 AM, Fuchs, Martin martin.fu...@trendchiller.com wrote: Hi ! Do we support IPsec-NAT ? No, PF can't do it. See a recent thread on freebsd-net for details. - To unsubscribe, e-mail:

Re: [pfSense Support] do we support ipsec-nat ?

2009-10-27 Thread Chris Buechler
On Tue, Oct 27, 2009 at 3:56 AM, Fuchs, Martin martin.fu...@trendchiller.com wrote: Hmmm, thats bad... So i really have to take a cisco device for this one gateway :-( but our main firewall stays pfsense ;-) Are there any planst o ever support this ? If the underlying software does, yes.

Re: [pfSense Support] Site to Site VPN Error

2009-10-28 Thread Chris Buechler
On Wed, Oct 28, 2009 at 4:11 AM, Koray AGAYA insanad...@gmail.com wrote: I Use Pfsense 1.2.2 and Error is below Can you help me please ! Oct 28 09:55:28     racoon: ERROR: such policy already exists. anyway replace it: 10.0.1.0/24[0] 10.0.0.0/24[0] proto=any dir=in Oct 28 09:55:28    

Re: [pfSense Support] Re: {Disarmed} Re: [pfSense Support] Site to Site VPN Error

2009-10-28 Thread Chris Buechler
2009/10/28 Johan Hendriks j.hendr...@schavemaker.com: Do not ping to the pfsense routers itself for the keep alive ping. It will not work, do not use it or use a machine behind the pfsense box. As long as you use an IP that's reachable using the VPN (i.e. LAN, not WAN), it will work fine.

Re: [pfSense Support] Site to Site VPN Error

2009-10-28 Thread Chris Buechler
2009/10/28 Koray AGAYA insanad...@gmail.com: Both pfsense change to cable ( I use to both site crosover cable ) But same error Again, that's not showing any actual errors. It doesn't show it even attempting to negotiate. That's because you're trying to connect 10.0.1.0/24 to 10.0.1.1/32. Those

Re: [pfSense Support] Site to Site VPN Error

2009-10-28 Thread Chris Buechler
On Wed, Oct 28, 2009 at 12:58 PM, Johan Hendriks j.hendr...@schavemaker.com wrote: You are right, but there was a time that the pfsense box itself could not ping the other pfsense box on the other side, or was it with monowall?  well i always assumed that it still was that way. That's true

Re: [pfSense Support] Hardware upgrade recommendation

2009-10-31 Thread Chris Buechler
On Sat, Oct 31, 2009 at 10:39 AM, Ugo Bellavance u...@lubik.ca wrote: Hi list,        We're currently running PfSense 1.2 on a white-box PC, that costed nothing...  P4 1., 1G RAM, HDD install.  Nics: vr (WAN), fxe (3 vlan LAN).  Very robust up to now. Even the lowest end P4 can push over

Re: [pfSense Support] Re: Hardware upgrade recommendation

2009-10-31 Thread Chris Buechler
On Sat, Oct 31, 2009 at 10:13 PM, Tim Dressel tjdres...@gmail.com wrote: PRO 100's have serious problems in BSD7. That's not true. I know there are issues in combination with some Adaptec RAID cards but other than that they work fine. Is the Pro/1000 better than the Pro/100? Is the em

Re: [pfSense Support] Re: Hardware upgrade recommendation

2009-10-31 Thread Chris Buechler
On Sat, Oct 31, 2009 at 10:57 PM, Tim Dressel tjdres...@gmail.com wrote: This is the exact issue I had with the PRO100's. I never tried disabling TSO or applying the patch. http://security.freebsd.org/advisories/FreeBSD-EN-09:03.fxp.asc That was a regression in 7.2. It's not applicable to

Re: [pfSense Support] IPSEC Doesnt Work

2009-10-31 Thread Chris Buechler
On Sat, Oct 31, 2009 at 11:22 AM, Koray AGAYA insanad...@gmail.com wrote: I Use Pfsense (1.2.2   built on Sat Jan 17 17:24:57 EST 2009  FreeBSD 7.0-RELEASE-p8 i386 ) Error is below Can you help me please ! Ipsec doens't work Why ? NOTE: I use to both site crosover cable and use same switch,

Re: [pfSense Support] Re: Hardware upgrade recommendation

2009-11-01 Thread Chris Buechler
On Sun, Nov 1, 2009 at 9:06 PM, Ugo Bellavance u...@lubik.ca wrote: Chris Buechler wrote: On Sat, Oct 31, 2009 at 10:57 PM, Tim Dressel tjdres...@gmail.com wrote: This is the exact issue I had with the PRO100's. I never tried disabling TSO or applying the patch. http://security.freebsd.org

Re: [pfSense Support] PFSense

2009-11-01 Thread Chris Buechler
On Mon, Nov 2, 2009 at 1:13 AM, Glenn Kelley gl...@typo3usa.com wrote: I suddenly cannot log into our PFSENSE system. I reset the password console via ssh - however it still does not show up. Any ideas? You're not really logging into the firewall? Maybe a port forward and you're trying to

Re: [pfSense Support] Sending traffic out a 2nd WAN interface

2009-11-02 Thread Chris Buechler
On Mon, Nov 2, 2009 at 8:10 PM, Ron Lemon rjle...@gmail.com wrote: Do I create this rule on the WAN or OPT tab under Firewall rules? Where ever the traffic is initiated (LAN probably). Do I need to enable AON or should I leave automatic? Automatic.

Re: [pfSense Support] pfSense book now available!

2009-11-05 Thread Chris Buechler
On Thu, Nov 5, 2009 at 4:35 PM, Michael Riglin michael.rig...@shaw.ca wrote: Just placed the order for my copy. I don't know where you found the time to put this book together, but I'm sure glad you did. My thanks to the author's for their efforts to get this highly anticipated book out to us.

Re: [pfSense Support] pfSense book now available!

2009-11-05 Thread Chris Buechler
On Thu, Nov 5, 2009 at 9:07 PM, Perkins, Jerry je...@jperkins.us wrote:  Thank you very much.   Only 5 left on Amazon.  I (the wife really) got number 6. Thank you! Actually that's not the number left, that's the number of places where you can buy it (if you click on that, it links to other

Re: [pfSense Support] Sticky Connections

2009-11-08 Thread Chris Buechler
On Mon, Nov 9, 2009 at 1:48 AM, Dave Warren dave-use...@djwcomputers.com wrote: I'm running 1.2.3-rc3, load balancing two connections (MultiWAN, NAT mode) shortly after enabling Sticky Connections I notice problems making connections. Looking through the lists this appears to be a known

Re: [pfSense Support] Port forward beyond local internal subnet.

2009-11-10 Thread Chris Buechler
On Tue, Nov 10, 2009 at 8:04 PM, Matt mnaism...@gmail.com wrote: Hi, I have a router behind pfsense with multiple internal subnets behind that. Will a pfsense  port forward from the WAN to any of my internal subnets work ?  Assuming pfsense can route to the internal subnets the port forward

Re: [pfSense Support] anyone proxying to an anonymizing vpn service

2009-11-11 Thread Chris Buechler
On Wed, Nov 11, 2009 at 3:29 PM, Vick Khera vi...@khera.org wrote: I'm looking into some privacy VPN services like PublicVPN or StrongVPN.  They offer OpenVPN based tunneling from the desktop or from your home router. Not using either of them or anything like it personally, but you can do

Re: [pfSense Support] anyone proxying to an anonymizing vpn service

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 11:02 AM, Vick Khera vi...@khera.org wrote: On Wed, Nov 11, 2009 at 11:23 PM, Chris Buechler cbuech...@gmail.com wrote: On Wed, Nov 11, 2009 at 3:29 PM, Vick Khera vi...@khera.org wrote: I'm looking into some privacy VPN services like PublicVPN or StrongVPN.  They offer

Re: [pfSense Support] pkg_add and openvpn-auth-ldap in 1.2.3-RC1

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 4:05 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: Searching the forum showed others who received the Shared object libgssapi.so.9 not found, required by libldap-2.4.so.6 error but the solution was to use 1.2.3-RC1. I have a fresh install lab'ed up but still

Re: [pfSense Support] pkg_add and openvpn-auth-ldap in 1.2.3-RC1

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 4:34 PM, Chris Buechler cbuech...@gmail.com wrote: On Thu, Nov 12, 2009 at 4:05 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: Searching the forum showed others who received the Shared object libgssapi.so.9 not found, required by libldap-2.4.so.6 error

Re: [pfSense Support] pkg_add and openvpn-auth-ldap in 1.2.3-RC1

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 4:46 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: If you're going to do this, upgrade to RC3 and start from there, then at least you can upgrade to the final 1.2.3 release (no FreeBSD version change). Chris, I greatly appreciate the guidance there. If it's not

Re: [pfSense Support] where is the support? is bank holiday in usa?

2009-11-12 Thread Chris Buechler
Not sure what you're talking about? - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] pkg_add and openvpn-auth-ldap in 1.2.3-RC1

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 4:54 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I don't want to jump in front of Chris on this but the forums has a sticky on setting up PAM auth for OpenVPN to back end to RADIUS.  It may not even be an option anymore but something to look at. Yeah it's out

Re: [pfSense Support] where is the support? is bank holiday in usa?

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 5:22 PM, luismi asturlui...@gmail.com wrote: I called several times this around two hours ago, no reply, nice IVR, but no reply. online support at the web was also offline :P Two of us have been on chat all day long. Not sure what's up with the phone, as far as I know

Re: [pfSense Support] where is the support? is bank holiday in usa?

2009-11-12 Thread Chris Buechler
On Thu, Nov 12, 2009 at 6:08 PM, luismi asturlui...@gmail.com wrote: As far as I see right now in the web: live support is offline Shows online for me and I tried several PCs in different locations. Several people have joined chat this afternoon, you must have a browser problem of some sort.

Re: [pfSense Support] CARP switchover to backup because of high traffic

2009-11-13 Thread Chris Buechler
On Fri, Nov 13, 2009 at 4:31 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: If I pay for support would somebody be able to login and see what is going on here? Sure, absolutely. - To unsubscribe, e-mail:

Re: [pfSense Support] CARP and BGP

2009-11-13 Thread Chris Buechler
On Fri, Nov 13, 2009 at 9:13 PM, Glenn Kelley gl...@typo3usa.com wrote: Am I correct in assuming that CARP and BGP cannot work together - as CARP pushes private ip addresses ? CARP doesn't push private IPs, not sure what you mean by that, but it can work just the same as anything with public

Re: [pfSense Support] TFTP Request through NAT

2009-11-14 Thread Chris Buechler
On Sat, Nov 14, 2009 at 10:58 AM, Aloysius Thevarajah Lloyd lloyd.aloys...@gmail.com wrote: HI All, I am running the pfsense 1.2.3-RC1 .The following question ask by several time. My SIP phones are behind the NAT but TFTP server on the WAN side. The phones cannot get the information from

Re: [pfSense Support] pfSense 2.0 / FreeBSD 8.0-RC3 : ftp freeze the box

2009-11-20 Thread Chris Buechler
On Fri, Nov 20, 2009 at 3:26 AM, Xavier Beaudouin k...@oav.net wrote: Hi there, I have upgraded my pfsense box at home, and fixed by the way the ipsec tunnel between my m0n0wall in my datacenter. But it seems there is a bug, I dunno if someone saw that, if I do some ftp passive, the pfsense

Re: [pfSense Support] Migrate from Embedded

2009-11-24 Thread Chris Buechler
On Tue, Nov 24, 2009 at 6:59 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: I have a machine that was setup as embedded but now we need packages functional so I need to migrate it to install based. Given it's the very same server, can I simply restore the xml config from the embedded

Re: [pfSense Support] Install w/o cdrom

2009-11-25 Thread Chris Buechler
On Wed, Nov 25, 2009 at 10:08 AM, Gabriel - IP Guys gabr...@impactteachers.com wrote: Required ingredients; 1: Google for something called 'unetbootin' 2: A USB stick 3: Your ISO 4: Half an hour of your time (x2) It's a lot easier to install with the drive in another machine that has a

Re: [pfSense Support] WAN + OpenVPN - Failover

2009-11-25 Thread Chris Buechler
On Wed, Nov 25, 2009 at 4:01 PM, Dominic vamp...@vortex.co.za wrote: Hi, I currently have two sites running pfSense, connected with a direct telecoms link. In addition to the direct telecoms link, each site has its own Internet connection. At present I route all traffic between the sites

Re: [pfSense Support] Bogons file overwritten w/ bad data

2009-11-25 Thread Chris Buechler
On Wed, Nov 25, 2009 at 4:51 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: Check out the rc_updatebogons.sh script in /etc.  That's how the file is updated. I kind of figured it updated on its own... Given that the WAN mac is not rewritten until the config is restored, I figured that's

Re: [pfSense Support] Split DNS Setup

2009-11-27 Thread Chris Buechler
On Fri, Nov 27, 2009 at 10:10 AM, Ron Lemon r...@maplewood.com wrote: Good Morning, I have a pfSense box that needs to resolve real world IP addresses (www.google.ca) and also internal office IPs for real world IPs (www.mydomain.com as 192.168.1.1).  This way people in the building can use

Re: [pfSense Support] Shaping Bridge

2009-11-28 Thread Chris Buechler
On Sat, Nov 28, 2009 at 3:04 PM, Dave Warren dave-use...@djwcomputers.com wrote: I'm looking at making a shaping bridge, hopefully using a single port using VLANs (although this isn't a strict requirement) Is pfSense a good choice for this role? It'll work fine, potentially with one caveat -

Re: [pfSense Support] Power Question for pfsense

2009-11-29 Thread Chris Buechler
On Sun, Nov 29, 2009 at 3:25 PM, Anil Garg garg_art2...@yahoo.com wrote: I have a headless pfsense 1.23 box powering my home network with a wired setup. We had a power glitch after which it was stuck and not booking with the sonic pleasure of clear boot sound and neither were internet

Re: [pfSense Support] PHP Process consuming 100% CPU

2009-11-30 Thread Chris Buechler
On Mon, Nov 30, 2009 at 5:27 AM, darkf...@comcast.net wrote: Well, I uninstalled the Snort plugin after reading your mail.  That may have been the cause. I guess a pentium III 900MHz just can't handle snort + PHP. That's more than enough, must be some sort of problem with the Snort package.

Re: [pfSense Support] Wake On LAN

2009-11-30 Thread Chris Buechler
On Tue, Dec 1, 2009 at 2:53 AM, Tortise tort...@paradise.net.nz wrote: Somehow I cannot get magic packets to awaken any PC on a pfSense LAN.  I don't get it. Some motherboard BIOS seem to have WOL and others don't.  Even the ones I have that are said to have it cannot be awoken as best I can

Re: [pfSense Support] Split DNS Setup

2009-12-01 Thread Chris Buechler
On Fri, Nov 27, 2009 at 3:29 PM, Bruce Walker bruce.wal...@gmail.com wrote: Yeah, I take that back. :-)  I rechecked my notes, and what I really found is that when you add an override *domain*, dnsmasq isn't restarted by that action. You need to either Save on the DNS forwarder page or restart

Re: [pfSense Support] How to ensure packets go out of the IP they came I on?

2009-12-03 Thread Chris Buechler
On Thu, Dec 3, 2009 at 7:42 PM, Gabriel - IP Guys gabr...@impactteachers.com wrote: Dear All, I have multiple ISP’s connected to my pfSense box, but only the ISP that is configured as the WAN seems to be able to route traffic. Attempts to come into ISP configured on OPT1 seem to make it to

Re: [pfSense Support] PFsense + Load Balance + Squid

2009-12-04 Thread Chris Buechler
On Fri, Dec 4, 2009 at 6:14 AM, Rafael Cristian rcristia...@gmail.com wrote: Hi, I have problem in configuration the load balance in pfsense. I am configure, but not get work the squid. My clients in Squid not balance, but In clients out squid get balance normally. Anybody know why???

Re: [pfSense Support] How to ensure packets go out of the IP they came I on?

2009-12-04 Thread Chris Buechler
On Fri, Dec 4, 2009 at 12:00 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: By the way last time I checked UDP OpenVpn it did not work this way. Incoming packet comes on OPTx outgoing comes out of WAN. There was no such problem with TCP. Is it known issue? Works fine when configured

Re: [pfSense Support] How to ensure packets go out of the IP they came I on?

2009-12-04 Thread Chris Buechler
On Fri, Dec 4, 2009 at 6:02 AM, Gabriel - IP Guys gabr...@impactteachers.com wrote: Basically, what I want to do is have traffic come in on my secondary ISP, and return packets return out the correct interface, instead of being blocked. Is that possible? Yes, and that's how it works by

Re: [pfSense Support] Re: PFsense + Load Balance + Squid

2009-12-04 Thread Chris Buechler
On Fri, Dec 4, 2009 at 2:46 PM, Dave Warren dave-use...@djwcomputers.com wrote: In message d64aa1760912041123v2e92448fi3bc780947235c...@mail.gmail.com Chris Buechler c...@pfsense.org was claimed to have wrote: On Fri, Dec 4, 2009 at 6:14 AM, Rafael Cristian rcristia...@gmail.com wrote: Hi

Re: [pfSense Support] Re: PFsense + Load Balance + Squid

2009-12-04 Thread Chris Buechler
On Fri, Dec 4, 2009 at 4:02 PM, Scott Ullrich sullr...@gmail.com wrote: On Fri, Dec 4, 2009 at 3:58 PM, Rafael Cristian rcristia...@gmail.com wrote: Thank you. But is version 2.0 now is available Yes, but it is alpha-alpha (soon to be alpha): In other words - unless you can fix

Re: [pfSense Support] Is your embedded pfsense stable?

2009-12-04 Thread Chris Buechler
On Thu, Dec 3, 2009 at 1:35 AM, mehma sarja mehmasa...@gmail.com wrote: 1.2.3-RC3, nanobsd on a Netgate Alix board with 256 MB RAM and a 8GB CF card. The firmware and all have been updated. Have been playing around with this box as a firewall for the last couple of weeks. Then I did the

Re: [pfSense Support] Is your embedded pfsense stable?

2009-12-05 Thread Chris Buechler
On Sat, Dec 5, 2009 at 3:50 PM, Eugen Leitl eu...@leitl.org wrote: On Fri, Dec 04, 2009 at 09:47:30PM -0500, Chris Buechler wrote: Even Snort with a lighter config is probably doable. But yeah if you push it past its limits, which isn't hard to do when you're running Snort, you can easily

Re: [pfSense Support] Second Gateway Problem

2009-12-06 Thread Chris Buechler
On Sun, Dec 6, 2009 at 3:48 PM, Koray AGAYA insanad...@gmail.com wrote: Can you help me please ? http://forum.pfsense.org/index.php/topic,21063.0.html Please do not post forum threads here unless it's gone unanswered for 24 hours.

Re: [pfSense Support] How to ensure packets go out of the IP they came I on?

2009-12-07 Thread Chris Buechler
On Mon, Dec 7, 2009 at 5:27 AM, Gabriel - IP Guys gabr...@impactteachers.com wrote: -Original Message- From: cbuech...@gmail.com [mailto:cbuech...@gmail.com] On Behalf Of Chris Buechler Sent: 04 December 2009 19:39 To: support@pfsense.com Subject: Re: [pfSense Support] How

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-10 Thread Chris Buechler
On Thu, Dec 10, 2009 at 6:43 PM, John Mitchell mitche...@gmail.com wrote: Hiya, Wondering if someone can point me in the right direciton, I'm trying to upgrade a RC3 to RELEASE on my alix box.  I'm using a 4G Flash card and the update file I'm trying to use is

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-10 Thread Chris Buechler
On Thu, Dec 10, 2009 at 6:47 PM, John Mitchell mitche...@gmail.com wrote: Console upgrade. Web interface upgrade work any differently? I tried both and they worked. - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-10 Thread Chris Buechler
On Thu, Dec 10, 2009 at 7:08 PM, Scott Ullrich sullr...@gmail.com wrote: On Thu, Dec 10, 2009 at 7:04 PM, mitch mitche...@gmail.com wrote: Same error I'm afraid, status at top says something went wrong updating the fstab entry, Log still reports same error message. Please see my response

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-10 Thread Chris Buechler
On Thu, Dec 10, 2009 at 7:14 PM, J.D. Bronson jd_bron...@sbcglobal.net wrote: I did a web based RC3 to RELEASE upgrade. Once the machine rebooted I refreshed the screen and all LOOKS ok. Is there any way to verify a successful upgrade? If you didn't get any errors, and the front page shows

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-10 Thread Chris Buechler
On Thu, Dec 10, 2009 at 7:27 PM, Jim Pingle li...@pingle.org wrote: On 12/10/2009 7:10 PM, John Mitchell wrote: I don't suppose there is any way to backup the RRD Graph data is there? (More specifiically the Traffic portion). Trying to get a years worth of data going ;) You can install the

[pfSense Support] pfSense 1.2.3 release now available!

2009-12-10 Thread Chris Buechler
Details here: http://blog.pfsense.org/?p=531 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-11 Thread Chris Buechler
On Fri, Dec 11, 2009 at 11:27 AM, Eugen Leitl eu...@leitl.org wrote: On Fri, Dec 11, 2009 at 09:31:38AM -0600, J.D. Bronson wrote: I just did the upgrade via the web GUI.. it went down w/o a hitch... Same thing here. One thing that was a potential problem in the past was https. Shouldn't be

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-11 Thread Chris Buechler
On Fri, Dec 11, 2009 at 4:41 AM, Tom Müller-Kortkamp tmu...@kommunity.net wrote: Am 11.12.2009 um 01:25 schrieb Scott Ullrich: On Thu, Dec 10, 2009 at 7:12 PM, Chris Buechler cbuech...@gmail.com wrote: I don't believe there were any changes between RC3 and release though?  It's been a while

Re: [pfSense Support] Wake On LAN - Now Works on 1.2.3 Embedded!

2009-12-11 Thread Chris Buechler
On Sat, Dec 12, 2009 at 1:21 AM, Tortise tort...@paradise.net.nz wrote: Well I had already done all that and it still didn't work, that was using 1.2.3 RC1 embedded.  (3 NIC's, one WAN, two LAN)  I now wish I had set up a sniffer to see if magic packets were actually going out I just

Re: [pfSense Support] syslog on 1.2.3

2009-12-12 Thread Chris Buechler
On Sat, Dec 12, 2009 at 4:44 PM, J.D. Bronson jd_bron...@sbcglobal.net wrote: I noticed this when I 1st started using pfSense at 1.2.3-RC, so I am not sure if its a new issue or not. Using the web interface: Status...then system logs then system..and then press CLEAR LOG clears the screen

Re: [pfSense Support] syslog on 1.2.3

2009-12-12 Thread Chris Buechler
On Sat, Dec 12, 2009 at 6:40 PM, J.D. Bronson jd_bron...@sbcglobal.net wrote: well my ISP DHCP lease is only 10mins, even though it never has changed in 2yrs... and as such, there is 'noise' on the system log indicating the renew every 10mins...piles of them. Once I clear the system log, I

Re: [pfSense Support] syslog on 1.2.3

2009-12-12 Thread Chris Buechler
On Sat, Dec 12, 2009 at 7:19 PM, J.D. Bronson jd_bron...@sbcglobal.net wrote: On 12/12/09 6:09 PM, Chris Buechler wrote: I just tried 3 different boxes and they all continue to log just fine. Including when kicking off dhclient. Try to edit and save a firewall rule and apply changes

Re: [pfSense Support] Virtual IP ProxyARP vs. CARP

2009-12-16 Thread Chris Buechler
On Wed, Dec 16, 2009 at 7:14 PM, Trevor Benson tben...@a-1networks.com wrote: I noticed that when creating a CARP virtual that it requires it to be attached to an interface with the same network.  However when creating a proxy arp, it does not have this requirement.  Wouldn't it be logical to

Re: [pfSense Support] Virtual IP ProxyARP vs. CARP

2009-12-17 Thread Chris Buechler
On Thu, Dec 17, 2009 at 4:09 PM, Trevor Benson tben...@a-1networks.com wrote: On Dec 16, 2009, at 5:41 PM, Chris Buechler wrote: On Wed, Dec 16, 2009 at 7:14 PM, Trevor Benson tben...@a-1networks.com wrote: I noticed that when creating a CARP virtual that it requires it to be attached

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-17 Thread Chris Buechler
On Thu, Dec 17, 2009 at 5:35 AM, Paul Mansfield it-admin-pfse...@taptu.com wrote: has anyone upgraded a pfsense cluster running 1.2.2-release to 1.2.3? am using many CARP addresses on WAN and LAN ports, IPSEC, OpenVPN, and advanced outbound nat. Yeah, I have a few. No problems. The

Re: [pfSense Support] Source NAT

2009-12-17 Thread Chris Buechler
On Fri, Dec 18, 2009 at 2:09 AM, Tapani Tarvainen pfse...@tapanitarvainen.fi wrote: Hi, I'm new to pfSense, trying to evaluate its suitability for my needs, to replace an old custom freebsd firewall, and while it looks very nice otherwise, there's one feature I can't find: Source NAT, i.e.,

Re: [pfSense Support] pfsense embedded installed on an Alix 2D3

2009-12-21 Thread Chris Buechler
On Mon, Dec 21, 2009 at 7:09 PM, Michel Servaes mic...@mcmc.be wrote: This seems to work fine... But, is it normal that I can install packages if I want to ? Yes, see embedded switched to nanobsd here: http://blog.pfsense.org/?p=531 Only the ones that can reasonably run from CF are available,

Re: [pfSense Support] sshlockout in 2.0

2009-12-22 Thread Chris Buechler
On Wed, Dec 23, 2009 at 12:00 AM, Evgeny Yurchenko evg.yu...@rogers.com wrote: Hello, # uname -a FreeBSD 2.0-alpha-alpha 7.2-RELEASE-p3 FreeBSD 7.2-RELEASE-p3 #0: Wed Aug  5 16:55:16 UTC 2009

Re: [pfSense Support] Preload upgrade

2009-12-23 Thread Chris Buechler
On Wed, Dec 23, 2009 at 9:27 AM, Seth Mos seth@xs4all.nl wrote: Op 23-12-2009 14:20, Atkins, Dwane P schreef: Is there a way to preload an upgrade on a device and then have it do it’s install and reboot later? In other words, can I copy the new release to a particular directory on a

Re: [pfSense Support] FLOSS Weekly 101: pfSense

2009-12-24 Thread Chris Buechler
On Thu, Dec 24, 2009 at 5:03 PM, Nenhum_de_Nos matheus...@gmail.com wrote: On Thu, 24 Dec 2009 15:45:30 -0500 Jim Pingle li...@pingle.org wrote: For those of you who didn't catch the video when it aired, FLOSS Weekly episode 101 about pfSense has been posted. http://twit.tv/floss101 is

Re: [pfSense Support] Mailserver on OPT1 Bridged with WAN - port 25 filtered

2009-12-29 Thread Chris Buechler
On Tue, Dec 29, 2009 at 4:19 PM, Mark Street mstr...@alliancemed.org wrote: Hi, This was my thought as stated in my original post.  I thought I read something in the book about setting the gateway on the bridged machine to the pfsense box instead of the ISP gateway because the traffic from

Re: [pfSense Support] 1:1 NAT - bind actual external IP to an optional interface?

2009-12-31 Thread Chris Buechler
On Thu, Dec 31, 2009 at 9:52 AM, Karl Fife karlf...@gmail.com wrote: Like many, I use 1:1 NAT to give one of my public IP address to an internal host.  This works great for certain applicatons where the host (such as Asterisk) is 'smart' and can be made aware of the fact that the IP address

Re: [pfSense Support] Disabling Services

2010-01-06 Thread Chris Buechler
On Wed, Jan 6, 2010 at 5:59 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: How do I correctly set the default state for a service of an installed package like ntop or pfflowd to stopped? Varies by package. Many can be disabled in their configuration. Some may have to be uninstalled.

Re: [pfSense Support] Disabling Services

2010-01-06 Thread Chris Buechler
On Wed, Jan 6, 2010 at 6:26 PM, Kurt Buff kurt.b...@gmail.com wrote: On Wed, Jan 6, 2010 at 14:59, Joseph L. Casale jcas...@activenetwerx.com wrote: How do I correctly set the default state for a service of an installed package like ntop or pfflowd to stopped? Thanks! jlc If there's a

Re: [pfSense Support] 1:1 NAT - bind actual external IP to an optional interface?

2010-01-06 Thread Chris Buechler
On Wed, Jan 6, 2010 at 1:26 PM, Karl Fife karlf...@gmail.com wrote: Thanks for the ideas!  It's working with the exception of a traffic shaping problem. What I did to set this up is 1. Bridged the OPT interface with WAN, leaving all other fields blank 2. Created a rule on the tab of the OPT

Re: [pfSense Support] DHCP custom options?

2010-01-07 Thread Chris Buechler
On Thu, Jan 7, 2010 at 2:47 AM, Jonathan Dieter jdie...@gmail.com wrote: In our school, we are currently using the ISC dhcp server on a CentOS server, with the BIND DNS server running on the same server.  We give the computers in the school static addresses handed out over DHCP, and unknown

<    6   7   8   9   10   11   12   13   14   15   >