RE: [pfSense Support] Incorrect System Log Order/Logging Bug?

2011-07-13 Thread Dimitri Rodis
2011/7/13 Jim Pingle li...@pingle.orgmailto:li...@pingle.org On 7/9/2011 9:17 PM, Dimitri Rodis wrote: The system is and has been set to -8 (I am Pacific Daylight Time, USA), and hasn't been re/booted since the first boot on that build--and I have reported this issue back in RC1 and it still

[pfSense Support] Incorrect System Log Order/Logging Bug?

2011-07-08 Thread Dimitri Rodis
, but notice how there are some entries that are in the middle of this screenshot that are newer than everything else. (The problem is that Jul 8 15:12:29 has not yet happened in my time zone, it is only shortly after 10AM here..) [cid:image001.png@01CC3D56.B846EF00] Dimitri Rodis Integrita

[pfSense Support] NAT Reflection Broken in recent builds

2011-05-23 Thread Dimitri Rodis
for debugging/troubleshooting purposes if someone needs it since I have a spare unit that I can boot the CF on.. Thanks, Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com

RE: [pfSense Support] COM-port Watchguard Firebox X500 with 2.0-RC1

2011-05-08 Thread Dimitri Rodis
don't think the support for 8139C+ will ever be 100% (I'd take 99%) until this happens. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com - To unsubscribe, e-mail: support-unsubscr...@pfsense.com

RE: [pfSense Support] COM-port Watchguard Firebox X500 with 2.0-RC1

2011-05-07 Thread Dimitri Rodis
, or X2500) that is what it's going to take to fix the Realtek driver problem. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e

[pfSense Support] Incorrect Sort on 2.0-RC1

2011-04-11 Thread Dimitri Rodis
2.0-RC1 (i386) built on Mon Mar 14 17:33:11 EDT 2011 Log sorting is set to newest first, however, the log sort is randomly incorrect (see screen snippet). I didn't see anything in redmine, thought I would check here first.. [cid:image001.png@01CBF837.8BDBAAF0] Dimitri Rodis Integrita Systems

[pfSense Support] Traffic that is explicitly allowed occasionally blocked

2011-02-28 Thread Dimitri Rodis
, and then there is a rule right beneath that rule that explicitly blocks outbound SMTP from all IP addresses on the subnet, and I have logging turned on for that rule. So, the rule beneath the one that should be triggered is being triggered instead. Is there a Bug/Race condition in rule evaluation?? Dimitri

RE: [pfSense Support] Traffic that is explicitly allowed occasionally blocked

2011-02-28 Thread Dimitri Rodis
No, those are RSTs and FINs coming after the state is closed, expected behavior. http://doc.pfsense.org/index.php/Logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection,_why%3F Ok, but unless I'm misunderstanding, I am not logging packets blocked by the default rule, so why would this

RE: [pfSense Support] pfSense 2.0, upgrade to this morning's snap problem

2011-01-25 Thread Dimitri Rodis
On Mon, Jan 24, 2011 at 7:42 PM, Dimitri Rodis dimit...@integritasystems.com wrote: After an upgrade to this morning's snap, I received the following after the upgrade/reboot (it's what's on my PuTTY atm): Syncing OpenVPN settings...done. Starting syslog...done. Configuring firewall

[pfSense Support] Traffic Graph accurate--but not the host list

2011-01-24 Thread Dimitri Rodis
the file server's ip address at all. It almost looks like the host list is only looking at traffic directed to pfSense itself as opposed to through that particular interface. Anyone else confirm? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com

[pfSense Support] pfSense 2.0, upgrade to this morning's snap problem

2011-01-24 Thread Dimitri Rodis
After an upgrade to this morning's snap, I received the following after the upgrade/reboot (it's what's on my PuTTY atm): Syncing OpenVPN settings...done. Starting syslog...done. Configuring firewall..done. Starting PFLOG...done. Setting up gateway monitors...done. Synchronizing user

[pfSense Support] Bootup Complete - but no console

2011-01-22 Thread Dimitri Rodis
this might be? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com

[pfSense Support] Alias Renaming Issue

2011-01-21 Thread Dimitri Rodis
stuff doesn't work ;) Anyone else see this? Dimitri Rodis http://www.integritasystems.com - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support

[pfSense Support] 1:1 NAT Entry issue - Bug or mistake?

2011-01-20 Thread Dimitri Rodis
did not try using an Alias in the External Subnet IP field, although it is RED also. Anyone else see this? Dimitri Rodis http://www.integritasystems.com

RE: [pfSense Support] 1:1 NAT Entry issue - Bug or mistake?

2011-01-20 Thread Dimitri Rodis
On Thu, Jan 20, 2011 at 9:28 PM, Dimitri Rodis dimit...@integritasystems.com wrote: pfSense 2.0-BETA5 (i386) built on Wed Jan 19 12:45:14 EST 2011 When I try to use an alias in the Internal IP field (suppose the alias was ) I receive the following error upon saving (or trying to save

RE: [pfSense Support] Testing 2.0 - What is the upgrade and downgrade process for Daily snapshots?

2011-01-12 Thread Dimitri Rodis
Hi Everyone, Just loaded a nanobsd image of pfSense 2.0 onto a CF card for Alix board. I have only used v1.2.3 in the past and I never used the internet to upgrade it. In fact, I am under the impression that v1.2.3 is the latest and there are no upgrades to it. I am wondering if there is a

RE: [pfSense Support] CARP IP/Hyper-V/Hyper-V R2

2010-11-22 Thread Dimitri Rodis
On Mon, Nov 15, 2010 at 9:57 PM, Evgeny Yurchenko evg.yu...@rogers.com wrote: I do not know a lot about Hyper-v but in VMWare for instance you can block frames with 'faked' mac-addresses. Probably you hit the same problem as CARP-packets have MAC-addresses 'not real' but specifically

RE: [pfSense Support] CARP IP/Hyper-V/Hyper-V R2

2010-11-16 Thread Dimitri Rodis
On 10-11-15 09:22 PM, Dimitri Rodis wrote: I recently migrated a pfSense virtual machine (version 1.2.2) that was running flawlessly on Hyper-V (first release) with 2 additional CARP IP addresses on the WAN interface for about 16 months. Over the weekend, I migrated that virtual machine over

[pfSense Support] CARP IP/Hyper-V/Hyper-V R2

2010-11-15 Thread Dimitri Rodis
to the original Hyper-V (non-R2) host. Any ideas on why CARP IPs wouldn't work on Hyper-V R2? Is there something since 1.2.2 that might change this? Thanks, Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] CARP and NAT problems

2010-05-31 Thread Dimitri Rodis
If the port forwards are on the WAN addresses themselves, to my knowledge they will not fail over. My understanding is that all addresses (and port forwards) that you intend to survive a failover must be on CARP addresses. Dimitri Rodis Integrita Systems LLC -Original Message- From

RE: [pfSense Support] Wierd CARP problem

2010-04-23 Thread Dimitri Rodis
On Thu, Apr 22, 2010 at 7:51 PM, Dimitri Rodis dimit...@integritasystems.com wrote: I would really like to see this work reliably at some point. From what I can tell, this problem is not limited to just Fireboxes, it is on pretty much all NICs that have RTL8139C+ chips on them

RE: [pfSense Support] Wierd CARP problem

2010-04-22 Thread Dimitri Rodis
On Mon, Apr 19, 2010 at 6:56 PM, Hans Maes h...@bitnet.be wrote: Although it is definately related to the type of NIC's in the watchguard boards, I'm still not completely convinced this is 100% a hardware problem since the Watchguard Linux OS seems to work just fine on it. Sounds more like a

RE: [pfSense Support] Redirect to Captive Portal is not working

2009-06-11 Thread Dimitri Rodis
Stupid question--- the pfSense box is (still) the gateway address for your network, right? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: apiase...@midatlanticbb.com [mailto:apiase...@midatlanticbb.com] Sent: Thursday, June 11, 2009 5:42 PM

RE: [pfSense Support] Re: Can't get more than 15kpps.

2009-05-13 Thread Dimitri Rodis
My understanding is that Giant lock is gone from the FreeBSD network stack in 8: http://unix.derkeiler.com/Mailing-Lists/FreeBSD/arch/2009-04/msg00075.html Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Bill Marquette [mailto:bill.marque

RE: [pfSense Support] Captive Portal Question

2009-05-09 Thread Dimitri Rodis
I'm drafting a reply. Be done shortly. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Tim Dressel [mailto:tjdres...@gmail.com] Sent: Friday, May 08, 2009 11:11 PM To: support@pfsense.com Subject: Re: [pfSense Support] Captive Portal

RE: [pfSense Support] Captive Portal Question

2009-05-09 Thread Dimitri Rodis
Options box) to allow/limit/prevent internet access. Hopefully that made some sense. It's a bit tough to describe without seeing it! :) Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Tim Dressel [mailto:tjdres...@gmail.com] Sent: Friday, May 08

RE: [pfSense Support] Captive Portal Question

2009-05-08 Thread Dimitri Rodis
for about 15 months now--still running on 1.2-release. If you have some good managed switches, that's the way to do it IMHO. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: RB [mailto:aoz@gmail.com] Sent: Thursday, May 07, 2009 3:16 PM

RE: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-29 Thread Dimitri Rodis
,15669.0.html Thanks, Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Joshua Schmidlkofer [mailto:joshl...@gmail.com] Sent: Tuesday, April 28, 2009 8:23 PM To: support@pfsense.com; j...@pax2cargo.com Subject: Re: [pfSense Support] Attention

RE: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-23 Thread Dimitri Rodis
reported that 2.0 gives him timeouts (see http://forum.pfsense.org/index.php?topic=15669). I don't yet have an explanation as to why I get timeouts in 1.2.3 and not in 2.0, but I'm working on figuring out why. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original

RE: [pfSense Support] 1.2.3-RC1 released!

2009-04-22 Thread Dimitri Rodis
Tim, See http://forum.pfsense.org/index.php?topic=15669 if you have issues with the Firebox. I'm collecting as much data as I can from those that are having issues. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Tim Nelson [mailto:tnel

RE: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Dimitri Rodis
may not know about it). With respect to ISA, there is a client installation (aka Firewall Client) that is required to make the authentication transparent--without it, it would work just like pfSense would-- with RADIUS against AD, and the user would have to enter credentials manually. Dimitri Rodis

RE: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Dimitri Rodis
portal, and have the current windows logon credentials automatically pass to the captive portal, which is currently not possible with pfSense-- ISA Server is the only thing I know of that does this. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message

RE: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Dimitri Rodis
day of the week over ISA, even if it meant they had to use credential prompts. Bottom line: if eliminating credential prompts is an absolute must, ISA can do it for sure. pfSense, not yet ;) Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From

[pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-18 Thread Dimitri Rodis
can fix it. Thanks to all that have helped, and thanks to those that are willing to test! Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com http://www.integritasystems.com smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-18 Thread Dimitri Rodis
Forum link: http://forum.pfsense.org/index.php/topic,15669.0.html Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: cbuech...@gmail.com [mailto:cbuech...@gmail.com] On Behalf Of Chris Buechler Sent: Saturday, April 18, 2009 11:33 AM

RE: [pfSense Support] VMware ESXi - Protect all VM's with pfSense VM in Bridge Mode - HELP!

2009-04-16 Thread Dimitri Rodis
There is a promiscuous mode on the vSwitches. That setting might need to be adjusted. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Tim Nelson [mailto:tnel...@fudnet.net] Sent: Thursday, April 16, 2009 9:01 AM To: support@pfsense.com

RE: [pfSense Support] Possible Outbound NAT Bug in 1.2.3 Snapshot?

2009-04-10 Thread Dimitri Rodis
I put that in also-- like I said it didn't take effect until I rebooted. If the rule wasn't there, it wouldn't matter how many times I rebooted :) Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Kimmo Paasiala [mailto:kpaas...@gmail.com] Sent

RE: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Dimitri Rodis
didn't dupe the section myself. Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:sullr...@gmail.com] Sent: Thursday, April 09, 2009 8:15 AM To: support@pfsense.com Subject: Re: [pfSense Support] CARP Bug in 1.2.3 On Wed, Apr 8, 2009 at 11:31 PM

RE: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Dimitri Rodis
The snapshot I'm using is dated April 1.. that's a couple of days after the hackathon, I believe. Any idea when the xmlparse.inc from HEAD was removed? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Scott Ullrich [mailto:sullr...@gmail.com

RE: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Dimitri Rodis
Good deal. I'll go to a later snapshot then. Are upgrades between snapshots on embedded working at the moment, or should I just reflash? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Scott Ullrich [mailto:sullr...@gmail.com] Sent

[pfSense Support] Possible Outbound NAT Bug in 1.2.3 Snapshot?

2009-04-08 Thread Dimitri Rodis
? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com smime.p7s Description: S/MIME cryptographic signature

[pfSense Support] CARP Bug in 1.2.3

2009-04-08 Thread Dimitri Rodis
/installedpackages Shouldn't config/config only be in there once? Looks like it added another config/config section it each time I tried to change/save it, and it's only using the last one. Bug or user error? Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com smime.p7s

RE: [pfSense Support] Possible Outbound NAT Bug in 1.2.3 Snapshot?

2009-04-08 Thread Dimitri Rodis
Nope, using embedded. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: cbuech...@gmail.com [mailto:cbuech...@gmail.com] On Behalf Of Chris Buechler Sent: Wednesday, April 08, 2009 8:30 PM To: support@pfsense.com Subject: Re: [pfSense Support

RE: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-04-01 Thread Dimitri Rodis
! Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Dimitri Rodis [mailto:dimit...@integritasystems.com] Sent: Tuesday, March 31, 2009 9:55 PM To: support@pfsense.com Subject: RE: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue Woohoo

[pfSense Support] RE: Load Balancer Using TCP

2009-04-01 Thread Dimitri Rodis
version of pfSense you are using J Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com From: Nathan Eisenberg [mailto:nat...@atlasnetworks.us] Sent: Wednesday, April 01, 2009 9:10 PM To: support@pfsense.com Subject: [pfSense Support] Load Balancer Using TCP Hello, I

RE: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-03-31 Thread Dimitri Rodis
appear to really have any issues.. then I added a second LAN and a dedicated sync interface for CARP and threw it into production, and it lasted about 10 minutes before it melted down with watchdog timeouts. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original

RE: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-03-31 Thread Dimitri Rodis
Woohoo! Didn't know you guys got this put in.. I'll test tomorrow or Thursday as time permits. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: cbuech...@gmail.com [mailto:cbuech...@gmail.com] On Behalf Of Chris Buechler Sent: Tuesday, March

RE: [pfSense Support] ACPI/APIC in loader.conf - watchdog timeouts

2009-03-23 Thread Dimitri Rodis
testing tomorrow. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: cbuech...@gmail.com [mailto:cbuech...@gmail.com] On Behalf Of Chris Buechler Sent: Monday, March 23, 2009 6:05 PM To: support@pfsense.com Subject: Re: [pfSense Support] ACPI/APIC

[pfSense Support] ACPI/APIC in loader.conf - watchdog timeouts

2009-03-22 Thread Dimitri Rodis
(and a specially sized sticker than can cover up the Firebox X logo J) Dimitri Rodis Integrita Systems LLC smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] ACPI/APIC in loader.conf - watchdog timeouts

2009-03-22 Thread Dimitri Rodis
a full install on these fireboxes is pretty tough and requires some soldering (I believe) to get a keyboard header working, not to mention that you have to get the board completely out of the chassis to fit a video card on it. Thanks Chris.. Dimitri Rodis Integrita Systems LLC -Original

RE: [pfSense Support] AW: Firebox X series w/ 1.2 and 1.2.2 issue

2009-03-20 Thread Dimitri Rodis
Switched the cables a few times now. 3 different pre-fab cables (different colors even!). Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Andrew Cotter [mailto:andrew.cot...@somersetcapital.com] Sent: Friday, March 20, 2009 12:35 PM

RE: [pfSense Support] Existing pfSense 1.2.2, adding redundant member

2009-03-18 Thread Dimitri Rodis
It looked that easy-- just wanted to be sure before messing with a production set up! Thanks, Dimitri Rodis Integrita Systems LLC -Original Message- From: Paul Mansfield [mailto:it-admin-pfse...@taptu.com] Sent: Wednesday, March 18, 2009 4:45 AM To: support@pfsense.com Subject: Re

[pfSense Support] LCDProc Package on Embedded

2009-03-06 Thread Dimitri Rodis
; echo /dev/ufs/pfSenseCfg /cf ufs rw 1 1 /etc/fstab Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] Exchange RPC/HTTPS outbound client

2009-02-10 Thread Dimitri Rodis
also categorically never used squid in one of these setups either. Dimitri Rodis Integrita Systems LLC http://www.integritasystems.com -Original Message- From: RB [mailto:aoz@gmail.com] Sent: Monday, February 09, 2009 7:16 PM To: support@pfsense.com Subject: Re: [pfSense Support

RE: [pfSense Support] Packages with pfSense embedded not an option - very sad

2009-01-26 Thread Dimitri Rodis
Re-do what you did, but create a 2GB partition and try again. Leave the other 6GB unused. I had this problem with an older PC and an actual 20GB hard drive-- from what I understand, it has to do with the IDE--CF adapters and how well they support LBA/DMA modes, etc. Dimitri Rodis Integrita

RE: [pfSense Support] Outbound NAT to Virt. IP issues. Maybe it's the config, maybe it's VMWare ESXi?

2008-12-22 Thread Dimitri Rodis
What kind of Virtual IP are you using? If you are using CARP addresses (which is what I'm using), make sure your subnet mask actually matches your WAN interface subnet mask. Dimitri Rodis Integrita Systems LLC -Original Message- From: Jason Lixfeld [mailto:jason-lists.pfse

RE: [pfSense Support] Dell Hardware Monitoring - pfSense 1.2 Final

2008-12-09 Thread Dimitri Rodis
OpenManage Server Administrator is what you're looking for. Dimitri Rodis Integrita Systems LLC From: Curtis LaMasters [mailto:[EMAIL PROTECTED] Sent: Tuesday, December 09, 2008 11:16 AM To: support@pfsense.com Subject: Re: [pfSense Support] Dell Hardware Monitoring - pfSense 1.2 Final

[pfSense Support] DNS Forwarder/Authoritative DNS Server

2008-12-02 Thread Dimitri Rodis
detected: * A override already exists for this domain. Is there a way that I can specify multiple DNS servers for a particular domain suffix? You should be able to, IMO. Thanks, Dimitri Rodis Integrita Systems LLC inline: image001.gif

RE: [pfSense Support] Bridge + Captive Portal

2008-11-19 Thread Dimitri Rodis
interface to use the corresponding private IPs? That way, you can use all your public IPs, and each client will have one-- I've never used 1:1 in conjunction with captive portal, though, so what I just said may or may not work. Dimitri Rodis Integrita Systems LLC -Original Message- From

[pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
mail servers as well). Dimitri Rodis Integrita Systems LLC smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] Bridge + Captive Portal

2008-11-18 Thread Dimitri Rodis
to accomplish it. Is there a particular reason you are trying to do a captive portal using a bridge setup vs NAT? Dimitri Rodis Integrita Systems LLC -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Chris Buechler Sent: Tuesday, November 18, 2008 12:34 AM

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
Thanks, Scott. Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 3:36 PM To: support@pfsense.com Subject: Re: [pfSense Support] NAT Reflection States On Tue, Nov 18, 2008 at 6:32 PM, Dimitri Rodis

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
That's milliseconds, correct? Dimitri Rodis Integrita Systems LLC -Original Message- From: Dimitri Rodis [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 3:38 PM To: support@pfsense.com Subject: RE: [pfSense Support] NAT Reflection States Thanks, Scott. Dimitri Rodis

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
me last. Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 3:44 PM To: support@pfsense.com Subject: Re: [pfSense Support] NAT Reflection States On Tue, Nov 18, 2008 at 6:40 PM, Dimitri Rodis [EMAIL

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
the -w param is in seconds according to http://www.securityforest.com/wiki/index.php/Netcat_-_Basic_Overview Any other ideas as to why connections would be dropping/timing out like this? Dimitri Rodis Integrita Systems LLC -Original Message- From: Dimitri Rodis [mailto:[EMAIL

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
I am using 1.2-RELEASE built on Sun Feb 24 17:04:58 EST 2008 so it isn't an RC thing. Dimitri Rodis Integrita Systems LLC -Original Message- From: digger [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 4:04 PM To: support@pfsense.com Subject: Re: [pfSense Support] NAT

RE: [pfSense Support] NAT Reflection States

2008-11-18 Thread Dimitri Rodis
There are a ton of lines that look like this: 19004 stream tcp nowait/0nobody /usr/bin/nc nc -w 20 I guess we found the culprit then? Why is it using 20 as opposed to 2000? Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto

[pfSense Support] Force Speed/Duplex on NIC

2008-11-05 Thread Dimitri Rodis
). I would rather not have to go get some junk 8 port managed switch just to force a speed/duplex if it's possible to do in the pfSense config. Dimitri Rodis Integrita Systems LLC smime.p7s Description: S/MIME cryptographic signature

RE: [pfSense Support] Captive Portal enabling Ethernet Port Traffic

2008-09-11 Thread Dimitri Rodis
different places and it works quite well for us. Dimitri Rodis Integrita Systems LLC -Original Message- From: Tim Nelson [mailto:[EMAIL PROTECTED] Sent: Thursday, September 11, 2008 3:43 PM To: support@pfsense.com Subject: Re: [pfSense Support] Captive Portal enabling Ethernet Port Traffic

RE: [pfSense Support] pfSense 1.2-RELEASE: Performance Issue?

2008-07-30 Thread Dimitri Rodis
, I got barely over 2Mb. Using the Intel, I got 9.5Mb. What kind of NICs are in your pfSense box? Dimitri Rodis Integrita Systems LLC -Original Message- From: Ted Crow [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 30, 2008 1:03 PM To: support@pfsense.com Subject: [pfSense Support

RE: [pfSense Support] Intel Pro 1000 VT

2008-05-15 Thread Dimitri Rodis
Adam, This may sound strange, but you might want to load linux and vmware server on the machine, and run pfSense virtualized until the hardware support comes for your NICs. We run pfSense virtualized on Dell PE1800s, PE2900s, and PE2950 servers all the time. Dimitri Rodis Integrita

RE: [pfSense Support] 1.2 package add-on missing

2008-05-05 Thread Dimitri Rodis
1. Did you install pfSense to the hard drive? (You need to for packages) 2. Yes.. Go to the interfaces page and add it. Dimitri Rodis Integrita Systems LLC From: Paul Peziol [mailto:[EMAIL PROTECTED] Sent: Monday, May 05, 2008 8:41 AM To: support@pfsense.com Subject

[pfSense Support] 3-way CARP

2008-04-17 Thread Dimitri Rodis
appreciated! Thanks, Dimitri Rodis Integrita Systems LLC

RE: [pfSense Support] 3-way CARP

2008-04-17 Thread Dimitri Rodis
So really the peer IP option is there for folks who don't have a dedicated interface, so that the pfsync traffic doesn't flood the network, is that right? So, in a 3-way config, do you always have to make configuration changes on the master? Or can they be made on any of them? Dimitri Rodis

RE: [pfSense Support] 3-way CARP

2008-04-17 Thread Dimitri Rodis
be moot if there's a way to do it already.. Thanks guys.. Dimitri Rodis Integrita Systems LLC -Original Message- From: Chris Buechler [mailto:[EMAIL PROTECTED] Sent: Thursday, April 17, 2008 5:32 PM To: support@pfsense.com Subject: Re: [pfSense Support] 3-way CARP On Thu, Apr 17, 2008

[pfSense Support] pfsync/FreeRADIUS

2008-04-11 Thread Dimitri Rodis
(or both) of the above scenarios work using pfSense? If not, if someone can give me a bump in the right direction, maybe I can add it to the FreeRADIUS package and send that change to coreteam also. Thanks, Dimitri Rodis Integrita Systems LLC

[pfSense Support] DHCP on WAN

2008-03-26 Thread Dimitri Rodis
Any workaround for getting DHCP to work on the WAN interface? Dimitri Rodis Integrita Systems LLC

[pfSense Support] WRAP Bandwidth

2008-03-26 Thread Dimitri Rodis
Would a WRAP board be capable of NATting and Shaping a 10 megabit symmetric connection without choking? Dimitri Rodis Integrita Systems LLC

RE: [pfSense Support] Captive Portal

2008-03-22 Thread Dimitri Rodis
: xxx.xxx.xxx.xxx Dimitri Rodis Integrita Systems LLC -Original Message- From: Chris Buechler [mailto:[EMAIL PROTECTED] Sent: Saturday, March 22, 2008 6:41 PM To: support@pfsense.com Subject: Re: [pfSense Support] Captive Portal Dimitri Rodis wrote: If I wanted to display a user's IP

[pfSense Support] Captive Portal

2008-03-21 Thread Dimitri Rodis
, and if I am able to display that information on the Captive Portal, I can just have them read it to me as opposed to trying to step them through all of the hoops to get the mac address. Thanks, Dimitri Rodis Integrita Systems LLC

RE: [pfSense Support] DHCP Server Issues

2008-03-19 Thread Dimitri Rodis
the WAN tab to show up (and DHCP to work) on the WAN side? I will submit the feature request shortly. Dimitri Rodis Integrita Systems LLC -Original Message- From: Chris Buechler [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 19, 2008 10:42 AM To: support@pfsense.com Subject: Re: [pfSense

RE: [pfSense Support] DHCP Server Issues

2008-03-19 Thread Dimitri Rodis
if there's a quick workaround that anyone knows of, that would be great. Thanks, Dimitri Rodis Integrita Systems LLC -Original Message- From: Chris Buechler [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 19, 2008 10:42 AM To: support@pfsense.com Subject: Re: [pfSense Support] DHCP

RE: [pfSense Support] FreeRADIUS Package

2008-03-06 Thread Dimitri Rodis
Is there a better place to post/email this stuff? I don't seem to be getting much in the way of responses. I have some nice additions to the FreeRADIUS package that I want to submit, but I would like to add the logging support before I do. Trying to contribute! Thanks, Dimitri Rodis Integrita

RE: [pfSense Support] FreeRADIUS Package

2008-03-06 Thread Dimitri Rodis
The pfSense log viewer is broken? Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Thursday, March 06, 2008 1:02 PM To: support@pfsense.com Subject: Re: [pfSense Support] FreeRADIUS Package On 3/6/08, Dimitri Rodis [EMAIL

RE: [pfSense Support] Dual-wan Setup issue (Yes, I've read a few Dual-Wan HOWTO docs AND I've rebuilt the router)

2008-03-04 Thread Dimitri Rodis
You need to use Manual Outbound NAT, and add a rule above the default rule that has the source address of your machine, destination * *, and then select the address of your WAN2 interface. Dimitri Rodis Integrita Systems LLC From: Michael Richardson [mailto:[EMAIL PROTECTED] Sent

[pfSense Support] CARP Documentation

2008-03-04 Thread Dimitri Rodis
/Special:Search/Setting_up_CARP_with_pf Sense in other pages or edit this page http://doc.pfsense.org/index.php?title=Setting_up_CARP_with_pfSenseact ion=edit . Where'd the CARP doc go? Dimitri Rodis Integrita Systems LLC

[pfSense Support] Outbound NAT Problem, 1.2-RELEASE

2008-02-27 Thread Dimitri Rodis
something wrong? Congrats on a great release, by the way. :) Dimitri Rodis Integrita Systems LLC - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

RE: [pfSense Support] FreeRADIUS Package

2008-02-14 Thread Dimitri Rodis
changes so far? (I did the VLAN support already, figured I'd send that up now and then follow up with the logging stuff). Thanks, Dimitri Rodis Integrita Systems LLC 2990 S Durango Drive Las Vegas, NVĀ  89117 P: 702.896.7207 F: 702.228.0208 C: 702.296.4217 [EMAIL PROTECTED] -Original

[pfSense Support] FreeRADIUS Package

2008-02-11 Thread Dimitri Rodis
are the maintainer of that package? Dimitri Rodis Integrita Systems LLC [EMAIL PROTECTED] mailto:[EMAIL PROTECTED]

RE: [pfSense Support] FreeRADIUS Package

2008-02-11 Thread Dimitri Rodis
Once I have changes made, how should I go about getting these changes into a pfSense install to test before I send any patches up? Should I be using the dev iso? Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Monday, February

RE: [pfSense Support] FreeRADIUS Package

2008-02-11 Thread Dimitri Rodis
.) Does it take something more than just adding a reference to the location of the log in the .xml file somewhere? Dimitri Rodis Integrita Systems LLC -Original Message- From: Dimitri Rodis [mailto:[EMAIL PROTECTED] Sent: Monday, February 11, 2008 4:29 PM To: support@pfsense.com Subject

RE: [pfSense Support] FreeRADIUS Package

2008-02-11 Thread Dimitri Rodis
as expected. Once they do, I'll send them up. Thanks-- Dimitri Rodis Integrita Systems LLC -Original Message- From: Fuchs, Martin [mailto:[EMAIL PROTECTED] Sent: Monday, February 11, 2008 3:52 PM To: support@pfsense.com Subject: AW: [pfSense Support] FreeRADIUS Package Or just replace

RE: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-07 Thread Dimitri Rodis
with is probably 30-40 somewhere. So in these cases, what would you choose? ;) Dimitri Rodis Integrita Systems LLC -Original Message- From: Angelo Turetta [mailto:[EMAIL PROTECTED] Sent: Thursday, February 07, 2008 1:09 AM To: support@pfsense.com Subject: Re: [pfSense Support] Multiple

RE: [pfSense Support] Multiple servers behind NAT'd firewall

2008-02-06 Thread Dimitri Rodis
.. Dimitri Rodis Integrita Systems LLC -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 06, 2008 12:31 PM To: support@pfsense.com Subject: Re: [pfSense Support] Multiple servers behind NAT'd firewall On Feb 6, 2008 3:29 PM, Sean Cavanaugh [EMAIL

[pfSense Support] Rule Question

2007-11-29 Thread Dimitri Rodis
server isn't running on pfSense) is 192.168.99.100 thru 192.168.99.199. What I would like to do is block outbound SMTP on only the machines that have a dynamically assigned address. Is it possible to create a single rule in pfSense to accomplish this? Thanks-- Dimitri Rodis Integrita

RE: [pfSense Support] Rule Question

2007-11-29 Thread Dimitri Rodis
understanding correctly? Dimitri Rodis Integrita Systems LLC -Original Message- From: Bill Marquette [mailto:[EMAIL PROTECTED] Sent: Thursday, November 29, 2007 3:14 PM To: support@pfsense.com Subject: Re: [pfSense Support] Rule Question Yes. You'll need to create a subnet alias - say

RE: [pfSense Support] Traffic shaper, asterisk and IAX (port 4569)

2007-10-30 Thread Dimitri Rodis
The *wizard* doesn't include IAX traffic, but pfSense will still do what you want. All that you have to do is add rules to put the traffic into the appropriate queues on the shaper rules page. Dimitri Rodis Integrita Systems LLC -Original Message- From: news [mailto:[EMAIL PROTECTED

RE: [pfSense Support] Re: pfsense, procurve 2626 3 vlans

2007-10-25 Thread Dimitri Rodis
that is how you change a port's untagged membership to a VLAN. Then on an entirely separate page, you can set up the tagged ports. Very unfriendly and confusing compared to the HPs. Dimitri Rodis Integrita Systems LLC -Original Message- From: news [mailto:[EMAIL PROTECTED] On Behalf Of Ugo

RE: [pfSense Support] pfsense, procurve 2626 3 vlans

2007-10-23 Thread Dimitri Rodis
, the ports should be members of the appropriate VLAN, but *untagged*. Dimitri Rodis Integrita Systems LLC -Original Message- From: news [mailto:[EMAIL PROTECTED] On Behalf Of Ugo Bellavance Sent: Tuesday, October 23, 2007 12:52 PM To: support@pfsense.com Subject: [pfSense Support] pfsense

RE: [pfSense Support] Re: pfsense, procurve 2626 3 vlans

2007-10-23 Thread Dimitri Rodis
so, AND you have NICs that support it properly under FreeBSD), and all of the others should NOT be tagged (excluding any connections to VLAN capable switches). Dimitri Rodis Integrita Systems LLC -Original Message- From: news [mailto:[EMAIL PROTECTED] On Behalf Of Ugo Bellavance Sent

  1   2   >