[pfSense Support] Problems with dual wan and policy based routing

2005-11-18 Thread Daniel Solsona
Hi all, I've posted that on forums but I'll try here too with new info. We've 1 soekris 4501 + lan1621 (Two ethernet ports) We've 2 ADSL lines (static ip's both) one working with dhcp and the other with static. And we want to have 1 Lan (192.168.50.0/24) 1 Wan (DHCP adsl line) (aaa.bbb.ccc.ddd)

RE: [pfSense Support] vlans and altq

2005-11-18 Thread alan walters
Will await the next release and test again. Thanks for your comments -Original Message- From: Dan Swartzendruber [mailto:[EMAIL PROTECTED] Sent: Thursday, November 17, 2005 11:51 PM To: support@pfsense.com Subject: RE: [pfSense Support] vlans and altq At 06:04 PM 11/17/2005, you wrote:

Re: [pfSense Support] aliases and firewall rules

2005-11-18 Thread Scott Ullrich
This is now fixed. Scott On 11/18/05, alan walters [EMAIL PROTECTED] wrote: I have noticed that the firewall rules are not updated when aliases are changed. Is this design When an alais is edited the new rule does not seem to take effect. If you go into firewall rules and resave

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Scott Ullrich
On bootup or after initial setup of the tunnel, pfSense will ping across the tunnel to bring it up. Scott On 11/17/05, John Cianfarani [EMAIL PROTECTED] wrote: Does anyone have IPSec tunnels auto establish working? I can only seem to get the tunnels to come up when traffic is passing over

RE: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread John Cianfarani
Ah okay I was figuring it would always try to keep it up. Any thing I can do from within the pfsense box itself to keep the tunnel up? Is traffic shapping over Ipsec out of the question at the moment? Thanks John -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent:

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Jesse Norell
Ah okay I was figuring it would always try to keep it up. Any thing I can do from within the pfsense box itself to keep the tunnel up? As long as traffic is going through the tunnel, it should stay up. In my case I have a IP phone and never notice an issue. Does pfsense have cron? If

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Scott Ullrich
Yeah, we have cron. Scott On 11/18/05, Jesse Norell [EMAIL PROTECTED] wrote: Ah okay I was figuring it would always try to keep it up. Any thing I can do from within the pfsense box itself to keep the tunnel up? As long as traffic is going through the tunnel, it should stay up. In

RE: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread John Cianfarani
I've tried pinging from the shell/console to a remote ipsec endpoint but it doesn't cause the tunnel to come up. (a local machine will cause the tunnel to come up though). I though I read in an earlier message or the faq that freebsd kludges together ipsec tunnels so some routes aren't properly

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Scott Ullrich
Great!!! On 11/18/05, John Cianfarani [EMAIL PROTECTED] wrote: Awesome! You da man! Fixes up my issue :) Thanks John -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Friday, November 18, 2005 1:30 PM To: support@pfsense.com Subject: Re: [pfSense Support]

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Scott Ullrich
No, we do not want to invoke a php binary every minute. On 11/18/05, Holger Bauer [EMAIL PROTECTED] wrote: maybe we should make this a checkbox for a tunnel (pinging once in a minute to not let the tunnel go down)? Holger -Ursprüngliche Nachricht- Von: Scott Ullrich

Re: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Vivek Khera
what's the point of keeping the tunnel up? won't either endpoint force it to re-establish on demand anyhow? i know my mobile user IPsec vpn does so from my mac to pfSense. i'm fairly certain our remote office VPN also does so, but it is a LNG haul over an unreliable network, so it is

AW: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Holger Bauer
Just a real-life example: I have an IPSEC-Mesh between several locations. Each location has it's own VoIP PBX. The PBXs don't talk to each other unless there is a call. If the tunnel is down and you try to call a phone at the distant PBX you get a busy before the tunnel is up (tunnel needs

RE: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread John Cianfarani
Here is my somewhat potential setup for why I needed to keep the tunnel up. Lets say you have voip phones at a small remote site (1-2 users) which has a dynamic ip address. (Which uses the mobile ipsec client setup) Lets also assume the phones don't register with the call server (static

RE: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread John Cianfarani
LOL same example. In my potential setup there will be no server at the remote location. That's why I was looking for a way for pfsense to keep it up. John -Original Message- From: Holger Bauer [mailto:[EMAIL PROTECTED] Sent: Friday, November 18, 2005 3:39 PM To: support@pfsense.com

AW: [pfSense Support] IPsec Does Auto Establish work?

2005-11-18 Thread Holger Bauer
Heh, looks like this option should be called make voip happy [X] -Ursprüngliche Nachricht- Von: John Cianfarani [mailto:[EMAIL PROTECTED] Gesendet: Freitag, 18. November 2005 22:18 An: support@pfsense.com Betreff: RE: [pfSense Support] IPsec Does Auto Establish work? Here is my

Re: [pfSense Support] Solution: Re: [pfSense Support] VPN NAT Traversal (CISCO VPN Client)

2005-11-18 Thread Chris
I banged my head on this for a while before I realized our network admin probably had the Cisco PIX VPN config to only work with UDP, not TCP. Our default config is to use UDP, but that didn't work for me on pfsense v.86. After I read the e-mail below I stopped trying to connect over UDP.

Re: [pfSense Support] Solution: Re: [pfSense Support] VPN NAT Traversal (CISCO VPN Client)

2005-11-18 Thread Chris
It did not work with IPSec Passthrough disabled. I must have tested too quickly after disabling it. I tried again an hour later and I could not connect to the office. I enabled passthrough and I was fine. Sorry for any confusion. Chris wrote: I banged my head on this for a while before I