Re: [pfSense Support] Nat traversal and Asterisk

2009-03-16 Thread Chris Buechler
On Mon, Mar 16, 2009 at 7:52 PM, Scott Ullrich wrote: > >  Static port needs to be disabled Correct, but that's a typo - needs to be enabled. http://doc.pfsense.org/index.php/Static_Port - To unsubscribe, e-mail: support-unsubsc

Re: [pfSense Support] sip nat

2009-03-18 Thread Chris Buechler
Nearly always, rewriting source port on SIP breaks it so it's not done by default. Enable AON and it will be. On Wed, Mar 18, 2009 at 6:11 AM, wrote: > > Hi > > I know this issue have been raised before, but I haven't really found a > satisfying answer, so here I go again... > > My problem is r

Re: [pfSense Support] RE: 1:1 NAT - Outbound source IP?

2009-03-18 Thread Chris Buechler
On Wed, Mar 18, 2009 at 4:25 PM, Nathan Eisenberg wrote: > Just bumping this question up. > Gary answered it yesterday. The only way it doesn't work that way is if you have some sort of proxy running on the firewall. - To unsubs

Re: [pfSense Support] CARP over Serial?

2009-03-18 Thread Chris Buechler
On Wed, Mar 18, 2009 at 7:55 PM, Nathan Eisenberg wrote: > > Is there any provision for doing CARP over serial/SLIP, or do I have to have > a third Ethernet interface? No, because it wouldn't work unless you have a 512 Kb Internet pipe or slower. Serial is *way* too slow to sync states with any

Re: SV: [pfSense Support] sip nat

2009-03-18 Thread Chris Buechler
On Wed, Mar 18, 2009 at 9:44 PM, Chris Flugstad wrote: > Also forgot to note, that most phones will register on port 5060.  This > however behind a NAT wont work if you have more than 1 phone.  You will have > to statically configure the port different on each port OR someone phone > will have a "

Re: [pfSense Support] Fw: About bridge network interface and rc.conf

2009-03-18 Thread Chris Buechler
Did you not see my previous reply? Here: http://thread.gmane.org/gmane.comp.security.firewalls.pfsense.support/16723/focus=16726 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h

Re: [pfSense Support] Nat traversal and Asterisk

2009-03-19 Thread Chris Buechler
On Thu, Mar 19, 2009 at 7:51 AM, k_o_l wrote: > Actually I just noticed, it fixed the problem for the asterisk clients but > broke my Vonage service > Doesn't surprise me, you'll need to modify your outbound NAT to not rewrite source port for traffic going to Vonage.

Re: [pfSense Support] Declined:

2009-03-19 Thread Chris Buechler
What, nobody wanted to attend Bill's meeting he sent to the mailing list? :) We gave him some grief about it last night, he said he got click happy in gmail. - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For addition

Re: [pfSense Support] packet loss question

2009-03-19 Thread Chris Buechler
On Thu, Mar 19, 2009 at 7:17 PM, Mikel Jimenez Fernandez wrote: > Oh yeah!! thanks > > Is this  normal? > yes. google checksum offloading. - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mai

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-03-22 Thread Chris Buechler
On Sun, Mar 22, 2009 at 5:33 PM, Bill Marquette wrote: > I believe so.  The newer "Core" designs have lower Ghz ratings.  Any > chance you know the models?  I'm not seeing the VTX feature in your > dmesg, which makes me think it's not a 5xxx series CPU (which would > get you more throughput). > H

Re: [pfSense Support] ACPI/APIC in loader.conf - watchdog timeouts

2009-03-22 Thread Chris Buechler
On Mon, Mar 23, 2009 at 12:38 AM, Dimitri Rodis wrote: > > hint.apic.0.disabled=1? I thought it was hint.acpi.0.disabled=1 (see > http://doc.pfsense.org/index.php/Booting_Options, and also the forum posts > regarding firebox installs) > APIC and ACPI are entirely different things. APIC is another

Re: [pfSense Support] Multi-WAN with Fail Over

2009-03-23 Thread Chris Buechler
On Mon, Mar 23, 2009 at 11:04 AM, Alexsander Loula wrote: > This is my current setup: > > I'm not using CARP, only the Load Balance service (pools). > Are the gateways the same? If so, that won't work as it balances by gateway IP, you need an intermediate NAT device on one.

Re: [pfSense Support] ACPI/APIC in loader.conf - watchdog timeouts

2009-03-23 Thread Chris Buechler
On Mon, Mar 23, 2009 at 1:02 AM, Dimitri Rodis wrote: > Do you think this has any potential relevance to the firebox watchdog > timeouts? Obviously I am going to test it and simply observe the results-- > not too hard to reproduce the issue. > It could. > Also, there was a suggestion that using

Re: [pfSense Support] Multi-WAN with Fail Over

2009-03-23 Thread Chris Buechler
On Mon, Mar 23, 2009 at 10:13 PM, Chuck Mariotti wrote: > Alex, I share your pain. I’m not a pf guru, but I can’t seem to get this > working either… > > > > I have managed to get the Load Balancer Status to turn Green/Yellow/Red as > expected when I unplug a connection. But the internet get’s all

Re: [pfSense Support] Multi-WAN with Fail Over

2009-03-25 Thread Chris Buechler
On Wed, Mar 25, 2009 at 5:26 AM, Veiko Kukk wrote: > > No, with two identical machines, using CARP for hardware failover, the dual > WAN failover does not work with pfsense. > Works fine, I've setup a number of boxes like that. You have something setup wrong. ---

Re: [pfSense Support] WAN, VLANS on WAN, and RRD Graph Behavior Graph or Feature?

2009-03-25 Thread Chris Buechler
On Wed, Mar 25, 2009 at 9:16 AM, Vaughn L. Reid III wrote: > I have a pfsense router configured with the following WAN setup.  It's > running 1.2.2. > > Wan Physical Interface Contains: > WAN is mapped to the default untagged interface (I know this isn't a > completely normal setup with VLAN's als

Re: [pfSense Support] Multi-WAN with Fail Over

2009-03-25 Thread Chris Buechler
On Wed, Mar 25, 2009 at 4:15 PM, Alexsander Loula wrote: > > Could you please share your XML config? > The boxes don't belong to me, they're those of various support customers, so no I can't. If you post yours maybe someone will tell you what's wrong.

Re: [pfSense Support] Internet at the lake? Rogers Mobile Internet Stick (Rocket) with pfSense?

2009-03-26 Thread Chris Buechler
On Thu, Mar 26, 2009 at 10:09 AM, Vick Khera wrote: > > When we were at BSDCon in DC last month, the local wifi provided was > over a shared connection built this way by hand using an OpenBSD > laptop as the gateway to the verizon network via usb stick.  It worked > quite well for the first day :-

Re: [pfSense Support] Multi-WAN with Fail Over

2009-03-28 Thread Chris Buechler
On Wed, Mar 25, 2009 at 10:07 PM, Alexsander Loula wrote: > This is my config: > You're missing a static route for a DNS server on your second WAN, assuming you use the DNS forwarder on pfSense. You may be using a monitor IP that doesn't reliably respond to pings when the connection is up. Your L

Re: [pfSense Support] OT: PCI Slot Adapter for 2.5" HDD?

2009-03-29 Thread Chris Buechler
On Sun, Mar 29, 2009 at 10:24 AM, Tim Nelson wrote: > Greetings pfSense list! I do apologize in advance for the OT nature of this > post. Since many of you have great experience with > different hardware platforms, embedded systems, etc I'm hoping someone can > help me out. I have a 1U server fo

Re: [pfSense Support] multiWAN connection / BGP

2009-03-29 Thread Chris Buechler
On Sun, Mar 29, 2009 at 10:38 PM, Glenn Kelley wrote: > I am wondering if there is a way to load balance / and provide connectivity > via 2 or 3 ethernet connections using BGP with PFSense. > Sure, if your ISP allows it. Presuming you mean 2 or 3 Internet connections. ---

Re: [pfSense Support] Question about traffic graphing

2009-03-30 Thread Chris Buechler
On Mon, Mar 30, 2009 at 11:07 AM, Borowicz, Paul wrote: > I using Cacti to graph the interfaces on my Pfsense box.  Before I replaced > the PIX I was graphing, LAN, DMZ, and WAN.  WAN showed all traffic, so I > used that to estimate my 95th percentile cost. > > Now I am graphing, LAN, DMZ, enc0 (i

Re: [pfSense Support] FW: Help with dynamic routing configuration

2009-03-30 Thread Chris Buechler
2009/3/30 Elvis Palombizio : > > Bottom line is I need to modify the RIP engine to allow it to advertise the > tunnel interface. Any idea on how to do this? > You'll have to modify the source code. - To unsubscribe, e-mail: suppo

Re: [pfSense Support] Intel Atom Install Trouble

2009-03-30 Thread Chris Buechler
On Mon, Mar 30, 2009 at 4:58 PM, Vaughn L. Reid III wrote: > I have a Intel Atom based board that I'm trying to get pfsense to install > on.  I can boot fine into safe mode but I get a panic message when I try the > default boot config.  I can reproduce this from both the pfsense ISO and > after a

Re: [pfSense Support] FW: Help with dynamic routing configuration

2009-03-30 Thread Chris Buechler
On Mon, Mar 30, 2009 at 2:26 PM, Elvis Palombizio wrote: > Ok. I assume that the modifications would need to be in the routed.inc file > somehow so it could generate the correct GATEWAYS > file or is it more involved than that? > That should be it, but I haven't actually checked the code to veri

Re: [pfSense Support] Template to connect a Cisco router to PFSense using IPSec

2009-03-31 Thread Chris Buechler
On Tue, Mar 31, 2009 at 10:43 PM, Borowicz, Paul wrote: > I was just collaborating on this for the wiki, here is the link. > http://doc.pfsense.org/index.php/IPSec_between_pfSense_and_a_Cisco_PIX > He's running IOS though, which is different from PIX OS. (Luis is a support customer who opened a t

Re: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-03-31 Thread Chris Buechler
On Tue, Mar 31, 2009 at 11:37 PM, Tim Nelson wrote: > I've just acquired an X500 unit and after throwing boatloads of traffic > through it, I haven't seen a single watchdog timeout. Two ports are connected > to a switch and a third port to a workstation. I can send you any information > on my c

Re: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-04-01 Thread Chris Buechler
On Wed, Apr 1, 2009 at 12:17 AM, Tim Nelson wrote: > > D'oh! I performed my testing with (oddly enough) the latest 2.0-ALPHA-ALPHA > snapshot. For some reason I don't have the current > 1.2.2 > available. Well, that makes my previous post a bit useless... > Oh, 2.0 has the same patches, so the s

Re: [pfSense Support] Template to connect a Cisco router to PFSense using IPSec

2009-04-01 Thread Chris Buechler
On Wed, Apr 1, 2009 at 8:11 AM, luismi wrote: > We have PIX too, but the configuration we received from previous team > is well, I don't have words to tell you how bad is. :P > Hah. I can imagine. I've cleaned up some unbelievable messes when converting PIX configs to pfSense for customers.

Re: [pfSense Support] Wireless segregation and integration question

2009-04-01 Thread Chris Buechler
On Mon, Mar 30, 2009 at 11:32 PM, Tim Dressel wrote: > Hi folks, > > I have inherited about a dozen schools with internet connections > between 2Mbit and 10Mbit. Each school has a PFSense box (standard PC, > hard disk, 1GB ram, 3 nics). > > Each PFSense is configured as WAN, LAN, and OPT1 where OP

Re: [pfSense Support] Template to connect a Cisco router to PFSense using IPSec

2009-04-01 Thread Chris Buechler
On Mon, Mar 30, 2009 at 4:05 PM, luismi wrote: > Is there anyone here, in the list, with a template to configure a Cisco > router against a pfsense firewall using ipsec? > For anyone who runs across this in the archives, here are the instructions: http://doc.pfsense.org/index.php/IPsec_between_pf

Re: [pfSense Support] Inbound Source IP Busted

2009-04-03 Thread Chris Buechler
On Fri, Apr 3, 2009 at 12:39 PM, pfsense wrote: > I am using 1.2.2 on a box with only a few inbound NATs for > our mail system. The problem is (this is the case using > regular port forwarding or 1:1), the source IP shows up at > the mail system as the LAN IP of the PFSense server instead > of the

Re: [pfSense Support] IPsec VPN times out requires ping to restart

2009-04-04 Thread Chris Buechler
On Fri, Apr 3, 2009 at 3:29 PM, Borowicz, Paul wrote: > I have a problem with a vpn between my pfsense box and an ASA box.  I've > noticed the same problem between PIX and pfsense.  The VPN works fine, but > when there is no traffic for awhile it will stop receiving connections.  The > ASA side wi

Re: [pfSense Support] RE: Load Balancer Using TCP

2009-04-04 Thread Chris Buechler
On Thu, Apr 2, 2009 at 12:22 AM, Nathan Eisenberg wrote: > Here's what ends up in slbd.conf when I save my config: > > > > servicename:\ > >     :poolname=poolname:\ > >     :vip=x.x.x.x:\ > >     :vip-port=80:\ > >     :sitedown=x.x.x.x:\ > >     :sitedown-port=80:\ > >   

Re: [pfSense Support] RE: Load Balancer Using TCP

2009-04-06 Thread Chris Buechler
On Sat, Apr 4, 2009 at 9:06 PM, Chris Buechler wrote: > > There is another issue where TCP is always selected when you edit an > existing pool, haven't fixed that yet but will. > Just fixed, diff here. https://rcs.pfsense.org/projects/pfsense/repos

Re: [pfSense Support] MultiWan , not quite sure whats wrong

2009-04-07 Thread Chris Buechler
On Tue, Apr 7, 2009 at 8:34 AM, Chris Flugstad wrote: > So i have 2 WANS > 100.100.100.4   DSL > 216.127.123.4   Wireless back to Colo > > When the Wireless backhaul is disconnected or "down", anything else on its > subnet is not accessible over the other WAN.  It's as if it only things it > can a

Re: [pfSense Support] Possible Outbound NAT Bug in 1.2.3 Snapshot?

2009-04-08 Thread Chris Buechler
On Wed, Apr 8, 2009 at 11:12 PM, Dimitri Rodis wrote: > Currently running: > > 1.2.3-RC1 > built on Wed Apr 1 16:59:10 EDT 2009 > > > > > > In addition to a fiber connection at this particular location, there is also > a second connection brought in via a cable modem. The fiber connection is > int

Re: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Chris Buechler
On Thu, Apr 9, 2009 at 7:00 PM, Dimitri Rodis wrote: > Good deal. I'll go to a later snapshot then. > > Are upgrades between snapshots on embedded working at the moment, or should > I just reflash? > Yeah you got hit with the xmlparse.inc issue that was in snapshots for a couple days. I know CARP

Re: [pfSense Support] upgrading a certain snapshot

2009-04-10 Thread Chris Buechler
On Fri, Apr 10, 2009 at 2:47 PM, Atkins, Dwane P wrote: > We are trying to do a test upgrade using the snapshot, > pfSense-1.2.3-20090407-1035.img.gz.  It took over 1 hour and 10 minutes and > the upgrade still had not completed.  The current version of the device is > 1.2-RELEASE > built on Thu A

Re: [pfSense Support] feature request: VPNC

2009-04-11 Thread Chris Buechler
On Sat, Apr 11, 2009 at 6:53 AM, Mikel Jimenez Fernandez wrote: > Hello > > I found that is a port for freebsd of vpnc cisco client. > > http://www.freebsdsoftware.org/security/vpnc.html > http://www.unix-ag.uni-kl.de/~massar/vpnc/ > > This is usefull when you want to connect your firewall in clie

Re: [pfSense Support] First Embedded System

2009-04-12 Thread Chris Buechler
On Sun, Apr 12, 2009 at 4:12 PM, Rainer Duffner wrote: > > That's a bit of a problem. I always re-flash to update. That won't be necessary for much longer. The next generation of embedded (based on nanobsd) will be available in 1.2.x and 2.0 releases sometime in the next couple months. Primarily

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 6:13 AM, Lenny wrote: > Hi guys, > first of all, thanks for all the support! > > Anyway, unfortunately, after all the hell I've been through with this, our > CEO is not interested in buying a new server:( heh.. How about "sorry, but there is no other option"? Maybe quote

Re: [pfSense Support] Dell PRO/1000VT Quad port NIC

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 11:35 AM, Mikel Jimenez Fernandez wrote: > Hello TIm > > I have not good experiences good igb driver... > My experience was with > http://www.intel.com/Products/Server/Adapters/Gb-ET-Dual-Port/Gb-ET-Dual-Port-overview.htm > that uses 82576. > > IMHO better choose one taht i

Re: [pfSense Support] upgrading a certain snapshot

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 12:16 PM, Atkins, Dwane P wrote: > I am guessing I can do this with a firmware upgrade?  I am not going on about > 10 minutes.  Can someone please give me an idea of how long this upgrade > should take? > Depends on the specifics of your hardware, shouldn't take more tha

Re: [pfSense Support] RE: [SPAM] Re: [pfSense Support] website browsing

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 1:28 PM, Gary Buckmaster wrote: > This is not the way to do this as the configuration will not survive > reboots.  You can set the MTU on the interface configuration page for your > WAN interface in the webGUI.  I would encourage you to check that out. In addition, it won'

Re: [pfSense Support] RE: [SPAM] [pfSense Support] RE: [SPAM] RE: [pfSense Support] RE: [SPAM] RE: [pfSense Support] RE: [SPAM] Re: [pfSense Support] RE: [SPAM] Re: [pfSense Support] website browsin

2009-04-16 Thread Chris Buechler
On Thu, Apr 16, 2009 at 7:50 AM, Juan Rivera wrote: > hey this is getting worse we can't even get to the home page now we have > to hit refresh over and over so we can get to the home page its running > really slow I think just like dial up lol well I don't know what else to > do I called our prov

Re: [pfSense Support] Reboot on virtual IP

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 12:42 AM, Tim Dressel wrote: > Hi folks, > > We've been playing around at work with binding multiple IP's to the > WAN interface so that we can port forward the same ports from > different IP's to different services on the LAN side. > > Has anyone ever seen when you add a s

Re: [pfSense Support] Firewall rules keep failing

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 4:15 AM, Graeme Evans wrote: > > > Situation: > > I have a simple PFSense setup with a single PFsense 1.2.2 computer, 1 WAN > interface, and 2 Local interfaces - one named LAN (10.0.0.0/24), and the > other is Workshop (10.0.1.0/24).  We have allsorts of computers including

Re: [pfSense Support] Firewall rules keep failing

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 4:15 AM, Graeme Evans wrote: > > PS: anyone know why the registration system on the pfsense forum won’t send > activation emails – so I can’t register? > Oh, and I looked for your email address on the forum and it isn't there. If you let me know offlist what you registered

Re: [pfSense Support] Reboot on virtual IP

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 1:07 PM, Tim Dressel wrote: > I had zero luck with this in the last few days. Here are some more details: > > Internet <--> PFSense <--> procurve managed switch > > I have tried three different computers, an old P3 based IBM desktop > with 512MB on a flash disk and a hard d

Re: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 2:17 PM, Dimitri Rodis wrote: > Attention Firebox X500/700/1000 Users using pfSense: > Glad to hear that looks like it fixes it. There's at least one thread on the forum reporting this issue as well, might want to post to those threads too to give those folks a heads up.

Re: [pfSense Support] Reboot on virtual IP

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 2:33 PM, Tim Dressel wrote: > > > There is definitely an upstream router, and I have physical access to > it but not console. I can power it off and on again, but it tends to > make the service provider unhappy. I do have a good working > relationship with the service provi

Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Chris Buechler
On Tue, Apr 21, 2009 at 1:27 PM, Ryan L. Rodrigue wrote: > First.  Thanks for making the best rouster software in the world. > > Second.   I'v searched, but i cant quite figure it out.  I would like to use > captive portal.  What I want is to have certain users based on windows > username and pass

Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Chris Buechler
On Tue, Apr 21, 2009 at 3:46 PM, Dimitri Rodis wrote: > Microsoft Internet Security and Acceleration Server (ISA Server), and you > need to have AD. > > I've used it, but only in this particular case. I do not know of anything in > the open source world that works reliably specifically the way you

Re: [pfSense Support] sipproxd with pfSense on EMBEDDED.

2009-04-22 Thread Chris Buechler
On Wed, Apr 22, 2009 at 4:31 PM, Karl Fife wrote: > Has anyone here successfully run sipproxd on embedded pfSense? It's built into 1.2.3. - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail:

[pfSense Support] 1.2.3-RC1 released!

2009-04-22 Thread Chris Buechler
Info here: http://blog.pfsense.org/?p=428 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] bridging 2 networks with pfsense+openvpn

2009-04-22 Thread Chris Buechler
You don't *have* to have two subnets, you can bridge OpenVPN, but it's a bit convoluted, not documented well (yet), and generally I don't recommend it. You rarely want broadcast traffic traversing a VPN. On Wed, Apr 22, 2009 at 6:22 PM, Brian Josefsen wrote: > Hi > > I have 2 pfsense boxes, one e

Re: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-24 Thread Chris Buechler
On Fri, Apr 24, 2009 at 10:32 AM, Andrew Cotter wrote: > Is there an update path from 1.2.2 to 1.2.3-RC1 embedded? Not a guaranteed reliable one. You can grab an embedded update file off the snapshot server but it may blow up. That'll be resolved with the new embedded that's on the way, includin

Re: [pfSense Support] Temporarily blocking hosts

2009-04-25 Thread Chris Buechler
On Sat, Apr 25, 2009 at 5:04 PM, Joshua Schmidlkofer wrote: > Support, > >  I want to integrate pfSense, or rather, a series of pfSense boxen with > something like fail2ban.   Is there an interface for temporary rules?   Are > there faculties for timed operations?   I am thinking of getting a pyth

Re: [pfSense Support] pfSense based on -STABLE or -CURRENT

2009-04-26 Thread Chris Buechler
On Sun, Apr 26, 2009 at 1:11 PM, Nenhum_de_Nos wrote: > > On Wed, April 22, 2009 13:02, Scott Ullrich wrote: >> On Wed, Apr 22, 2009 at 9:42 AM, Cristiano Deana >> wrote: >>> Hi, >>> >>> i need a pfSense based on 7-STABLE (better) or -CURRENT, to have >>> working usb support for apple usb2etherne

Re: [pfSense Support] udp load balancing

2009-04-29 Thread Chris Buechler
On Mon, Apr 27, 2009 at 11:55 AM, Paul Mansfield wrote: > is this going to be feature of 1.2.3 or do we need to wait for 1.3? > No new features in 1.2.x releases (though a couple came by association with bug fixes). There isn't a 1.3 anymore, that's 2.0. At a glance, it doesn't seem to support UD

Re: [pfSense Support] PPTP Hangs at "Verifying Username and Password"

2009-05-01 Thread Chris Buechler
On Fri, May 1, 2009 at 5:16 PM, Marty Nelson wrote: > I'm sitting behind another pfSense box version 1.2.2 > If you have the PPTP server enabled, you need to either: 1) disable it 2) http://doc.pfsense.org/index.php/Connect_to_a_remote_PPTP_server_when_you_have_the_pfSense_PPTP_server_enabled -

Re: [pfSense Support] draft 802.11n and pfsense

2009-05-05 Thread Chris Buechler
On Tue, May 5, 2009 at 2:22 PM, Markus Golser wrote: > Hi I'm wondering if there is a draft 802.11n mini pciE card that works > nice on pfsense 1.2.2 http://doc.pfsense.org/index.php/Is_802.11n_wireless_supported - To unsubscrib

Re: [pfSense Support] gre tunnel support

2009-05-07 Thread Chris Buechler
On Thu, May 7, 2009 at 5:21 AM, Mikel Jimenez wrote: > Hi > > Is possible to make a GRE tunel between two Pfsenses without using IPsec? > Not with nor without, until 2.0. - To unsubscribe, e-mail: support-unsubscr...@pfsense.com

Re: [pfSense Support] network interface mismatch

2009-05-11 Thread Chris Buechler
On Mon, May 11, 2009 at 10:19 AM, Pete Boyd wrote: > Is there anything that can be done instead of replacing one of the 3Com > cards? > Sounds like a driver issue of some sort, trying 1.2.3 which has a newer FreeBSD base may make it work. -

Re: [pfSense Support] Problem with pftpx - device busy

2009-05-11 Thread Chris Buechler
On Tue, Apr 21, 2009 at 7:43 AM, Peter Allgeyer wrote: > Hi, > > I just encountered a problem with pftpx. We have a FTP-Server in the > DMZ-Zone. Entering ftp://ftp.server.ip from inside in the browser (for > example, command line ftp is the same) shows no listing. Reloading the > website several

Re: [pfSense Support] RE: T1 Saturating - Windows update kills the connection... ??

2009-05-13 Thread Chris Buechler
On Wed, May 13, 2009 at 2:47 AM, Chuck Mariotti wrote: > To clarify further... > > In this situation, we are downgrading to a T1 (1.5Mbit/1.5Mbit) connection > from a new service provider. The current connection is 3Mbit/3Mbit, works, > but is insanely expensive (way more than twice the price).

Re: [pfSense Support] bsnmpd eating cpu

2009-05-16 Thread Chris Buechler
On Fri, May 15, 2009 at 9:53 AM, Jure Pečar wrote: > On Mon, 9 Feb 2009 13:41:30 +0100 > Jure Pečar wrote: > >> On Mon, 9 Feb 2009 10:37:27 +0100 >> Jure Pečar wrote: >> >> > >> > Hello, >> > >> > On 1.2-release running on two machines in carp failover mode, we notice >> > bsnmpd eating all ava

Re: [pfSense Support] pfSense 1.2-Release -> 1.2.3-RC1 upgrade, FTP problem

2009-05-18 Thread Chris Buechler
On Mon, May 18, 2009 at 6:01 AM, Android Andrew[:] wrote: > Sorry for previous letter with bad subject.. > > Hello all! > > We have faced the following problem: > after the upgrade of pfSense from 1.2-Release to 1.2.3-RC1, the access from > the > internal LAN1 network to FTP-server, located in DMZ

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-19 Thread Chris Buechler
On Tue, May 19, 2009 at 10:56 AM, Jean Carlos Coelho wrote: > Hi all.. a question.. > > >   It is possible to install postfix in pfsense 1.2.2 only for mail relay ? > Not easily, I've tried before, there are a ton of libraries and other misc. things not included in pfSense that it wants. It was w

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 5:02 AM, Paul Mansfield wrote: > has anyone considered a transparent redirection of SMTP to a specific > SMTP relay, so that (e.g.) captive portal clients on wifi hotspot can't > send email without some level of control. > You can do that now with a port forward on any add

Re: [pfSense Support] wrong boot device after generic install

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 8:54 PM, David Burgess wrote: > Hi all, > > I'm new to pfsense and a real novice with FreeBSD, so go easy on me ;) > > I used the live CD of pfsense 1.2.3-RC1 to install to a hard drive for > use in a soekris net5501. When I boot while attached to the serial > console it ap

Re: [pfSense Support] Which pfSense version should I install?

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 9:45 PM, Jonathan Wanak wrote: > > Hi everyone, > > I'm about to update a remote pfSense installation I last worked on back in > version 1.0.2.  I'm using a PII desktop with 128MB RAM and 3 NICs.  The box > runs 2 LANs (public and private), utilizes Captive Portal, connec

Re: [pfSense Support] openssh flaw

2009-05-21 Thread Chris Buechler
On Thu, May 21, 2009 at 3:37 PM, David Burgess wrote: > http://linux.slashdot.org/article.pl?sid=09/05/21/1824220&from=rss > > What versions run in pfsense? Is this something we should be concerned about? > This is 6+ month old news, and it's lame, not sure why it's getting so much attention. It'

Re: [pfSense Support] dyndns on multiWAN

2009-05-25 Thread Chris Buechler
On Tue, May 26, 2009 at 12:29 AM, David Burgess wrote: > Hi, > > I see the question in the archives, but no answer. What would be the > correct way to set up dynamic DNS on a multiwan setup? You can't until 2.0. Only WAN is supported. -

Re: [pfSense Support] bsnmpd eating cpu

2009-05-26 Thread Chris Buechler
On Tue, May 26, 2009 at 4:34 AM, Jure Pečar wrote: > On Sat, 16 May 2009 21:20:13 -0400 > Chris Buechler wrote: > >> Never seen anything like that. Sounds like some sort of bsnmpd or >> FreeBSD problem. If you find a solution, let us know. > > Googling around re

Re: [pfSense Support] arm arch?

2009-05-28 Thread Chris Buechler
On Thu, May 28, 2009 at 1:40 PM, Tim Nelson wrote: > > In regards to alternate arch's, wouldn't something like ARM or MIPS provider > better PPS rates than x86(_64)? No difference due to the architecture. There are some higher end MIPS platforms that are equivalent to big $ gear from Cisco, Juni

Re: [pfSense Support] Snort running and update problem

2009-05-30 Thread Chris Buechler
On Sat, May 30, 2009 at 7:30 AM, ozan ucar wrote: > Hello All, > > I have pfsense 1.2.2 and install snort.Snort success installation but dont > update. > Oinkmaster code have, i go to snort update page an error "Snort success > installation but dont update." > Snort changed around their website e

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-05-31 Thread Chris Buechler
On Sun, May 31, 2009 at 7:03 AM, Tebano epaminonda wrote: > Hi all. > I've read that complete multiwan support will be available only with 2.0 > version of pfsense, but I'd like to know if You've some suggestion for doing > something similar, also using many pfsense instead of single one, or > som

Re: [pfSense Support] Can I install packages if my Pfsense is offline

2009-06-01 Thread Chris Buechler
On Mon, Jun 1, 2009 at 10:24 PM, Rakthum_Network&Telecom_IP#1 wrote: > Hello all > > My Pfsense is offline but I want install some packages .How can I > do? You can't. It has to download the package list and the packages themselves. ---

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-01 Thread Chris Buechler
On Mon, Jun 1, 2009 at 3:59 AM, Tebano epaminonda wrote: > Sorry, Guys. > I where discussing of limitation reported into the features of: > > Inbound Load Balancing > What exactly are you referring to? - To unsubscribe, e-mail:

Re: [pfSense Support] Does it matter which interface I specify for static routes?

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 5:54 AM, Steve Harman wrote: > Hi! > > > > We have four internal NICs on our pfSense box; “LAN” , “LAN2”, “LAN3” and > “LAN4”. > > > > I need to setup a static route for a remotely hosted network at our parent > company’s office so any traffic destined for that network is di

Re: [pfSense Support] Does it matter which interface I specify for static routes?

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 4:24 PM, Evgeny Yurchenko wrote: > May I ask why pfSense web-interface has this option? It needs to know for NAT rule generation and other purposes. It's a hold over from m0n0wall, it could figure it out without specifying. -

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 5:50 PM, Joseph Wagner wrote: > Has anyone been able to get pfsense to run properly on a Soekris net5501 > embedded pc? > Lots of people. > I've installed the embedded image into my board and everything work fine > except I can't get any traffic to  go through the WAN por

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 6:01 PM, Victor Padro wrote: > > Sometimes you have to uncheck the Block private networks and the Block bogon > networks boxes on the WAN interface page, have you alredy done that? > You never have to uncheck that for access out to the Internet. Those only affect traffic in

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 7:02 PM, Tim Nelson wrote: > > Quickly looking at the previous posts, I don't see where you've specified > what type of connection you're setting your WAN to. Is it PPPoE? Static? > DHCP? Etc? > And also, is it on a private subnet? Same subnet as your LAN? -

Re: [pfSense Support] keep alive

2009-06-03 Thread Chris Buechler
On Wed, Jun 3, 2009 at 12:00 PM, Paul Cockings wrote: > Hello list, > > I have an annoyance that is driving me bonkers.  I have a Windows XP client, > a pfsense 1.2.2 configured as a transparent firewall, development webserver > (FreeBSD 7.2) > > When I using SSH (Putty) or MySQL (SQLyog) to the w

Re: [pfSense Support] Does it matter which interface I specify forstatic routes?

2009-06-03 Thread Chris Buechler
On Wed, Jun 3, 2009 at 9:29 AM, Evgeny Yurchenko wrote: > > from my experience failover takes has higher > priority than static route as it is implemented by means of pf rules. > Yes, that is true. Static routes direct traffic initiated by the firewall to the appropriate WAN, and direct traffic

Re: [pfSense Support] Feature Requests

2009-06-05 Thread Chris Buechler
On Fri, Jun 5, 2009 at 4:33 PM, Curtis Maurand wrote: > Where can we make feature requests? http://redmine.pfsense.org with many still at http://cvstrac.pfsense.org as we haven't converted everything over yet. > I also can't seem to find any decent documentation on the atrocious way it > handl

Re: [pfSense Support] Recommended pfSense Hardware ( UK ~£100) ?

2009-06-06 Thread Chris Buechler
On Sun, Jun 7, 2009 at 2:00 AM, Volker Kuhlmann wrote: > On Tue 02 Jun 2009 02:35:55 NZST +1200, David Burgess wrote: > >> Have a look at these. The 2-port card >> is low profile > > Yes, sure. But how do you connect one of those to an ALIX board? > You can't o

Re: [pfSense Support] LAN Drivers RTL8111D on INTEL

2009-06-08 Thread Chris Buechler
On Mon, Jun 8, 2009 at 8:34 PM, Federico Castro A. wrote: > > Hi everyone. > > I´m trying to setup an INTEL DG41TY board with 3 LAN cards.  One integrated > RTL8111D and two D-Link 520 TX PCI. > > The D-Links are setup without a problem but the Realtek doesn´t come up when > I boot with the CD ver

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-10 Thread Chris Buechler
On Wed, Jun 10, 2009 at 10:03 AM, Tebano epaminonda wrote: > > > I've 2 isp with 2 different IP and routers. > So I've configured 2 pfsense in load balance and with carp between them > (internal and external, so I always has a single IP to manage with routes > and nats). > All works perfectly, if a

Re: [pfSense Support] pfsense related problem

2009-06-10 Thread Chris Buechler
On Thu, Jun 11, 2009 at 2:14 AM, Guruprasad-Baysoft wrote: > Hi > > I am using pfsense 1.2.2 version firewall connected to my broadband. I have > 2 problems as follows > > > > 1.   Any mail with attachment or big mail size is not able to be sent > from any system behind pfsense. > > 2.   Fe

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-10 Thread Chris Buechler
On Thu, Jun 11, 2009 at 2:34 AM, Webmaster Megastar wrote: > There is a bug when you want to setup multiwan + load balancing + carp. The > development team is aware of this. Ermal committed a kernel patch to pf that should resolve this. It's only in 8 builds at the moment, it will make its way int

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-12 Thread Chris Buechler
2009/6/11 Webmaster Megastar : > Can you give us an idea of when it will be available in snapshots released > to public ? > Anything from 20090612 and newer should work (there aren't any yet, they'll be there eventually). Please test and report back. --

Re: [pfSense Support] blocking RFC1918 and bogons on 2nd WAN

2009-06-12 Thread Chris Buechler
On Fri, Jun 12, 2009 at 9:10 AM, Paul Mansfield wrote: > suppose we have two WAN ports and have turned on the automatic RFC1918 > and bogon blocking; you can see the grey-ed out rules on WAN1 interface. > > what's the best way to also do this on WAN2? in particular, how to put > the list of RFC1918

Re: [pfSense Support] Inbound load balancer performance under heavy load.

2009-06-12 Thread Chris Buechler
On Fri, Jun 12, 2009 at 5:29 AM, Jose Hernandez wrote: > Hi, > > > > Yesterday we had a service launch, and pfSense inbound load balancer let me > down big time… We have been using pfSense 1.2-release version installed on > Dell PowerEdge R200 and CARP for redundancy for around a year now, it probe

Re: [pfSense Support] Outbound mail & multi-wan

2009-06-13 Thread Chris Buechler
On Sat, Jun 13, 2009 at 3:07 PM, JJB wrote: > Hello, > > pfsense 1.22 > > we have a mail server: > > mail.domain.com > > We have two wan links > > WAN_ATT (T1) and WAN (covad DSL) > > reverse DNS is configured for the ATT link for mail.domain.com and for the > covad link as mail01.domain.com > > is

Re: [pfSense Support] Outbound mail & multi-wan

2009-06-16 Thread Chris Buechler
On Tue, Jun 16, 2009 at 1:37 PM, JJB wrote: >> Yes, setup your rules on the interface with the mail server accordingly. > > I don't know how to set up pfsense to bind the mail server to the AT&T > network interface instead of the Covad, can someone provide me with details > of how this would be don

Re: [pfSense Support] forum vs mailing list

2009-06-17 Thread Chris Buechler
On Wed, Jun 17, 2009 at 1:38 PM, JJB wrote: > Hello, > > I didn't realize there is also a pfsense forum and that they are not > connected. Which is the best place to post technical questions about > configuration? Which ever you prefer. Some people like the forum format better, others mailing list

<    5   6   7   8   9   10   11   12   13   14   >