Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Jim Pingle
Ryan wrote: Without seeing the CP screen, automatically logging them in with Windows credentials, no. You can authenticate them on. the CP screen with RADIUS using their Windows credentials to IAS on a Windows Server DC (if you're using AD). I kinda thought that was the case. Thank you

Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Jim Pingle
Integrita Systems LLC http://www.integritasystems.com -Original Message- From: Jim Pingle [mailto:li...@pingle.org] Sent: Tuesday, April 21, 2009 1:18 PM To: support@pfsense.com Subject: Re: [pfSense Support] Can captive portal authenticate based on windows login Ryan wrote: Without

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-19 Thread Jim Pingle
Jean Carlos Coelho wrote: It is possible to install postfix in pfsense 1.2.2 only for mail relay ? how can i install into it ? (I am a newbie), thank's!! While it may be _possible_, it would not be _recommended_ or even _wise_ to run a full MTA on your firewall. Can you do it? Maybe. Should

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-20 Thread Jim Pingle
Paul Mansfield wrote: has anyone considered a transparent redirection of SMTP to a specific SMTP relay, so that (e.g.) captive portal clients on wifi hotspot can't send email without some level of control. this might also solve the OPs problem of providign an smtp relay without actually

Re: [pfSense Support] PFSense 1.2.3RC1 / Problems with IPSEC and AES256

2009-05-31 Thread Jim Pingle
Benjamin Fromme wrote: Hi List, we have several tunnels between some pfsense 1.2.2 boxes. For phase 2 we have configured AES256 as the only encryption algorithm and everything works fine. Now we upgrade one of the boxes to pfsense 1.2.3RC1 and all tunnels on this box are broken. The

Re: [pfSense Support] dhcp and arp list errors

2009-06-09 Thread Jim Pingle
and...@fiberby.dk wrote: Hi Does anyone have an explanation/solution to these errors: When choosing DHCP leases I get the following error: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/diag_dhcp_leases.php on line 74 When

Re: SV: [pfSense Support] dhcp and arp list errors

2009-06-09 Thread Jim Pingle
and...@fiberby.dk wrote: Potentionally 1000-1200 clients. I have another running 1.2.2 Super PDSMi+ (http://www.supermicro.com/products/system/1U/5015/SYS-5015M-MR+.cfm) P4 single core 1Gb ram 2Gb Flash on module At the moment it has 1033 dhcp-clients and has none of the listed

Re: SV: SV: [pfSense Support] dhcp and arp list errors

2009-06-09 Thread Jim Pingle
and...@fiberby.dk wrote: This is from the broken system: -rw-r--r-- 1 dhcpd _dhcp 39935156 Jun 9 21:30 /var/dhcpd/var/db/dhcpd.leases 15 minutes later: -rw-r--r-- 1 dhcpd _dhcp 77714885 Jun 9 21:45 /var/dhcpd/var/db/dhcpd.leases I've found one malfunctioning device that was

Re: [pfSense Support] CARP and Bridging

2009-06-26 Thread Jim Pingle
Joseph Hardeman wrote: One other question now that I think of it. Does CARP work between two firewalls that are running in full Bridge mode, no NATing done at all, just port blocking on the WAN interface? We have two firewalls and I want to make sure any states are kept intact on the chance

Re: [pfSense Support] trying to boot embedded image fails

2009-08-03 Thread Jim Pingle
Joseph L. Casale wrote: I have an HP DL120 G5 I am trying to use pfSense-1.2.3-RC1-Embedded on and it just hangs on the bootloader. I am using a 4gig USB key that I wrote the img to. Are there any particular bios requirements for this to work or other setup requirements? I have seen some

Re: [pfSense Support] trying to boot embedded image fails

2009-08-03 Thread Jim Pingle
Joseph L. Casale wrote: Are you speaking of these: http://snapshots.pfsense.org/FreeBSD_RELENG_7_2/pfSense_RELENG_1_2/nanobsd/ The pfSense-1.2.3-512mb-20090723-1908-nanobsd.img image didn’t hang the server but it just sat at a blinking cursor:) Sorry, spoke to soon! Same result. I wait

Re: [pfSense Support] no job control

2009-08-05 Thread Jim Pingle
David Burgess wrote: http://www.mail-archive.com/support@pfsense.com/msg05025.html After about 4 months on pfsense I'm now seeing this message in the console, Warning: no access to tty (Inappropriate ioctl for device). Thus no job control in this shell. The above-linked thread is over three

Re: [pfSense Support] no job control

2009-08-05 Thread Jim Pingle
David Burgess wrote: On Wed, Aug 5, 2009 at 6:10 AM, Jim Pingleli...@pingle.org wrote: IIRC it was due to something trying to mute the video console while it is really using serial. It is fixed (mostly?) on the 1.2.3-RC2 nanobsd snapshots, and doesn't seem to happen on 2.0 either. I'm

Re: [pfSense Support] pfSense Blocking some traffic

2009-08-16 Thread Jim Pingle
Joseph Hardeman wrote: However I am seeing entries captured in my firewall logs where visitors are being denied per the Default deny rule at the very bottom of the pf rules. My question is why are my explicit rules not capturing the entries before it gets to the last rule? And also, how can

Re: [pfSense Support] dynamic load balancing

2009-08-20 Thread Jim Pingle
Michel Servaes wrote: I am wondering, if the following would be possible - and how to start with it. I have this SDSL and ADSL connection - in where our ADSL has a download limit of 25GB/month If one bypasses the 25GB - the connection drops from 10mbits to 64kbits ! How can I make pfSense

Re: [pfSense Support] potential pfsense hardware

2009-08-27 Thread Jim Pingle
Ryan wrote: I'm thinking about picking up a Supermicro Atom based system for use with pfSense: http://www.supermicro.com/products/system/1U/5015/SYS-5015A-H. cfm?typ=H Any thoughts on potential issues with running pfSense on this hardware? The realtek nics they use are not the best.

Re: [pfSense Support] raccon message: racoon: ERROR: libipsec failed pfkey align (Invalid sadb message)

2009-09-02 Thread Jim Pingle
luismi wrote: Is there anyone here with experience with this message racoon: ERROR: libipsec failed pfkey align (Invalid sadb message)? Pfsense version is 1.2.2 and the remote side is a cisco router. Everything seems to be ok, but we have some connectivity problems with some servers and I

Re: [pfSense Support] Hardware dimensioning: Alix boards

2009-09-09 Thread Jim Pingle
Chris Bagnall wrote: We've been using Alix boards (2C1 initially, now 2D1 - 400Mhz Geode, 128MB RAM) for a few years with pfSense. One of our clients, whose network is normally about 50 users, is running an event this weekend which will see the number of connected devices rise to about

Re: [pfSense Support] SNMP oid's for bandwidth

2009-09-29 Thread Jim Pingle
Ståle Johnsen wrote: Hi, I'm trying to monitor in / out bandwidth in bits on wan interface but are having some problems finding the right SNMP oid. I found this one: http://cvstrac.pfsense.com/tktview?tn=257 but the OID i'm trying doesn't return anything. Does anyone have any better

Re: [pfSense Support] squid clobbering performance

2009-10-01 Thread Jim Pingle
mayak chunder-qwern wrote: hi all, any reason (or what can i look at) to see why squid transparent proxying is heavily slowing web access ... (w/out proxy, dell.fr takes 3-5 secs, with proxy, dell.fr takes 20+ or more) running latest stable version in a vmware virtual machine with nice

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
Curtis LaMasters wrote: I've searched around and read about others with this issue. Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast setting. Does anybody have a solution to this that would prevent me from having

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
Chris Buechler wrote: On Thu, Oct 1, 2009 at 4:10 PM, Curtis LaMasters curtislamast...@gmail.com wrote: I've searched around and read about others with this issue. Basically I have 5 different Vista laptops that cannot get a DHCP address unless I modify the registry and disable a broadcast

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
apiase...@midatlanticbb.com wrote: In one situation we had a HP procurve switch installed. We had tons of complaints that vista would not work but XP would. We replaced it with a Cisco 2950 and the complaints stopped. I have no idea why that would cause it to work. I have just come to believe

Re: [pfSense Support] Vista DHCP Issue

2009-10-01 Thread Jim Pingle
apiase...@midatlanticbb.com wrote: I'm wondering if a patch was added to windows update at some point to fix the problem. Is your Vista totally updated? Just this week I've had my hands on several fully patched Vista machines (including my laptop) as well as two other laptops -- one with Vista

Re: [pfSense Support] CARP switchover to backup because of high traffic

2009-10-08 Thread Jim Pingle
Evgeny Yurchenko wrote: Yesterday it happened twice on one of my production firewalls. CPU load was less than 10%. Did not pay attention at the moment but accoring to RRD number of states was not unusual - 4-5k. I reproduced it in my lab - only test connection, so number of states was less

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during the DHCP lease cleanup routine. Your /var/dhcpd/var/db/dhcpd.leases file must be huge. It doesn't typically grow that

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during the DHCP lease cleanup routine. Your /var/dhcpd/var/db

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during

Re: [pfSense Support] potential pfsense hardware

2009-10-15 Thread Jim Pingle
Ryan wrote: Does anyone make an atom board with intel onboard. I'd rather intel if i had my choice. I have seen a couple of flexatx atom boards that look real promising, but they don't have intel nics. MSI has a board with 2x1GB Intel NICs, the IM-945GSE

Re: [pfSense Support] potential pfsense hardware

2009-10-16 Thread Jim Pingle
Curtis Maurand wrote: Check this one out. It should work just fine. Very inexpensive. http://www.newegg.com/Product/Product.aspx?Item=N82E16816101262 I mentioned that one elsewhere in the thread. Three of them just arrived in my office and I'm getting ready to test them out. :-) First

Re: [pfSense Support] potential pfsense hardware

2009-10-16 Thread Jim Pingle
Paul Mansfield wrote: On 16/10/09 17:27, Curtis Maurand wrote: Check this one out. It should work just fine. Very inexpensive. http://www.newegg.com/Product/Product.aspx?Item=N82E16816101262 pretty good box at the price; I guess it would be a bit noisy for a home or office environment,

Re: [pfSense Support] potential pfsense hardware

2009-10-16 Thread Jim Pingle
Nathan Eisenberg wrote: Newegg says the board only has a PCI-Ex8 slot. I'm not sure which board that would be, as all the Atom boards I've seen are PCI-only. It has 2 PCI-E x8 and a PCI, but it looks like only the PCI-E x8 would be usable with the riser. Here's a pic I took of the mainboard

Re: [pfSense Support] potential pfsense hardware

2009-10-16 Thread Jim Pingle
Jim Pingle wrote: Curtis Maurand wrote: Check this one out. It should work just fine. Very inexpensive. http://www.newegg.com/Product/Product.aspx?Item=N82E16816101262 I mentioned that one elsewhere in the thread. Three of them just arrived in my office and I'm getting ready to test

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-20 Thread Jim Pingle
Andreas Fuchs wrote: I upgraded to 1.2.3 RC3 today. I'm now able to crate an interface on my tun1 for the OpenVPN, after a reboot the coneection is working. But the filter rules don't work. Based on the description i set the interface to a bridging interface to my LAN, but that way the

Re: [pfSense Support] little offtopic - using cron to monitor ipsec tunnels

2009-10-29 Thread Jim Pingle
Michel Servaes wrote: I was wondering, if there would be a way (by not installing third party software) to monitor the uptime of your ipsec VPN tunnels. Sure, I can ping every LAN printer that is in the other subnet - or install third party software... but some kind of cronjob checking this

Re: [pfSense Support] pfsense package system down ?

2009-11-20 Thread Jim Pingle
Indrajaya Pitra Perdana wrote: php: /pkg_mgr.php: XMLRPC request failed with error 2: Invalid return payload: enable debugging to examine incoming payload There was a missing on a tag in the xml, It's possible that was causing the error. Can you try it again? I committed a fix about 45

Re: [pfSense Support] pfsense 1.23 rc3 - ipsec VPN dies randomly, but stays active in the overview

2009-11-24 Thread Jim Pingle
Michel Servaes wrote: Since I have added two IPSEC tunnels to both Linksys' RV042 - my VPN connections start to die randomy, but stay active in both the webgui's overview (both, I mean pfSense and the DLINK's) - but either way is impossible to ping each other !! Have you tried checking the

Re: [pfSense Support] Split DNS Setup

2009-11-27 Thread Jim Pingle
Bruce Walker wrote: Oh! Here's a thought: I noticed that adding dns-forwarder overrides doesn't restart dnsmasq, so it doesn't necessarily see them. Either restart the service (from the Status - Services) or just click the Save button on the DNS Forwarder menu page. This should not be

Re: [pfSense Support] boot failure on alix with pfSense 1.2.3-RC3 (or more recent snapshots)

2009-12-03 Thread Jim Pingle
Hans Maes wrote: Thanks for the suggestion, although I didn't try it in the end. A working fix was posted on the forum yesterday ( http://forum.pfsense.org/index.php/topic,20405.msg107813.html#msg107813 ) - You need to set the bios power management mode to APM on the alix boards with VGA to

Re: [pfSense Support] Monitor traffic through vpn

2009-12-04 Thread Jim Pingle
Joseph L. Casale wrote: I have been asked to monitor traffic, per user through our openvpn pfsense setup, as its setup for filtering (Therefor I know what ip each user uses), I presume this can easily be done by looking at traffic between the opt int and the lan int. Are there provisions

Re: [pfSense Support] 1.2.3-RC3 PPPoE

2009-12-09 Thread Jim Pingle
On 12/9/2009 9:01 AM, RB wrote: On Wed, Dec 9, 2009 at 01:34, Ermal Luçi ermal.l...@gmail.com wrote: Please provide logs of mpd and explain more what you are trying to do and how you are trying to achive it! What I'm trying to achieve is awfully simple - with a fresh install of 1.2.3-RC3,

Re: [pfSense Support] 1.2.3-RC3 PPPoE

2009-12-10 Thread Jim Pingle
On 12/10/2009 6:56 PM, Scott Ullrich wrote: On Thu, Dec 10, 2009 at 6:54 PM, RB aoz@gmail.com wrote: Well, for posterity's sake then: if you have trouble in pfSense/FreeBSD with traffic not passing through an Intel 10/100 NIC (fxp), particularly when return/inbound packets aren't showing

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-10 Thread Jim Pingle
On 12/10/2009 7:10 PM, John Mitchell wrote: I don't suppose there is any way to backup the RRD Graph data is there? (More specifiically the Traffic portion). Trying to get a years worth of data going ;) You can install the Backup package and grab the data from there, or you could mount the CF

Re: [pfSense Support] Squid Guard with Alix box 1.2.3 embedded

2009-12-11 Thread Jim Pingle
On 12/11/2009 5:21 AM, bsd wrote: I wanted to know if It was Ok to install SquidGuard package with an embedded version of pfSense working on NanoBSD ? I plan to deploy It on Alix board… As the system is mounted RO… I am not certain this will be the best settings. Will this still be ok -

Re: [pfSense Support] hybrid storage?

2009-12-11 Thread Jim Pingle
On 12/11/2009 10:50 AM, David Burgess wrote: I've been happily using 1.2.3-RC1 for many months now on a Soekris net5501 and a 100GB 2.5 SATA drive. I like the idea of an embedded system on a CF card, but that's not possible or advisable for me as I'm running the squid and freeswitch packages.

Re: [pfSense Support] hybrid storage?

2009-12-11 Thread Jim Pingle
On 12/11/2009 12:22 PM, Paul Mansfield wrote: can you do overlay file systems on freeBSD, so that the base OS and config is read-only and you overlay a read-write file system at a very late stage in booting IF that overlay is uncorrupted? when you've made changes to config, if the worst

Re: [pfSense Support] hybrid storage?

2009-12-11 Thread Jim Pingle
On 12/11/2009 12:33 PM, David Burgess wrote: On Fri, Dec 11, 2009 at 10:30 AM, Jim Pingle li...@pingle.org wrote: On 12/11/2009 12:22 PM, Paul Mansfield wrote: can you do overlay file systems on freeBSD, so that the base OS and config is read-only and you overlay a read-write file system

Re: [pfSense Support] Squid Cache management does'nt save config

2009-12-11 Thread Jim Pingle
On 12/11/2009 5:52 PM, Nathaniel Simch de Morais wrote: Hi all I have a problem with my pfsense and already changed my machine but the problem still. Well, i can make any changes in squid, but in the tab Cache management just don't save. I put all info about cache i want and when i click

Re: [pfSense Support] Re: NanoBSD on WRAP

2009-12-15 Thread Jim Pingle
On 12/15/2009 6:31 AM, Rainer Duffner wrote: Ugo Bellavance schrieb: I like this answer, and there are really 2 facts that are highlighted here: - Users will always complain - The better your product and product history, the less users will read the warnings. PfSense has always had a good

Re: [pfSense Support] NAS/SAN

2009-12-19 Thread Jim Pingle
On 12/19/2009 7:05 PM, Seth Mos wrote: Op 19 dec 2009, om 22:34 heeft Glenn Kelley het volgende geschreven: is there a simple way to add an ISCSI or NAS storage to this system? For systems with limited storage - I do not see a way of doing this out of the box I am missing the context

[pfSense Support] FLOSS Weekly 101: pfSense

2009-12-24 Thread Jim Pingle
For those of you who didn't catch the video when it aired, FLOSS Weekly episode 101 about pfSense has been posted. http://twit.tv/floss101 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands,

Re: [pfSense Support] embedded install on a Pentium III system

2009-12-28 Thread Jim Pingle
On 12/28/2009 10:28 AM, Kurt Buff wrote: My big question - how would I tell which network interface will be the LAN, to run the WebGUI wizard on... (on an Alix, it's the first one - but how can I tell on this P3-600 (old compaq) board, which would be the first one ?) Or won't it run at all ?

Re: [pfSense Support] ntop is dumped

2009-12-31 Thread Jim Pingle
On 12/31/2009 2:12 AM, Koray AGAYA wrote: Hi, I use pfsense *1.2.3-RELEASE* and I installed ntop v.3.3.8. but Ntop working 5 minutes and then stop logs is below kernel: pid 49342 (ntop), uid 0: exited on signal 11 (core dumped) How can I resolve my problem ? [snip] Dec 31 09:00:27

Re: [pfSense Support] About promiscuous mode

2010-01-22 Thread Jim Pingle
On 1/22/2010 8:38 AM, Koray AGAYA wrote: Hi, I use 1.2.3-RELEASE Pfsense, System log have a error, I dont understand What is problem ? Jan 22 15:29:01 kernel: vge0: promiscuous mode disabled This is a part of how the Rate package operates. In that scenario, it's harmless log spam,

Re: [pfSense Support] Plugins

2010-01-22 Thread Jim Pingle
On 1/22/2010 7:41 PM, Fabian Abplanalp wrote: [snip - I don't use siproxd or spamd so I can't comment there] OpenVPN is also a lot that should be improved asap, for testing purposes I've installed an endian box (which has other ugly limitations), but at least SIP and OpenVPN work as expected

Re: AW: [pfSense Support] Password reset

2010-01-26 Thread Jim Pingle
On 1/26/2010 4:05 PM, Michel Herzog wrote: Remko Lodder wrote: As mentioned by Aarno, Did you password protect your console? Hello Yes. Problem is that there is no documentation. Also i have not set up the system myself so that's why i am vague :) Its like very important

Re: [pfSense Support] Ability to summarize # of states/IP

2010-02-03 Thread Jim Pingle
On 2/3/2010 2:35 PM, Nathan Eisenberg wrote: It would be incredibly handy to build a report that summarizes the number of states open, groups by IP. That way, one could easily identify a DOS origin. For example, I just had an attacker attempt to open 40,000 simultaneously HTTP sessions on

Re: [pfSense Support] Ability to summarize # of states/IP

2010-02-03 Thread Jim Pingle
On 2/3/2010 7:57 PM, Jim Pingle wrote: On 2/3/2010 2:35 PM, Nathan Eisenberg wrote: It would be incredibly handy to build a report that summarizes the number of states open, groups by IP. That way, one could easily identify a DOS origin. For example, I just had an attacker attempt to open

Re: [pfSense Support] How to forward protocol 41

2010-02-11 Thread Jim Pingle
On 2/11/2010 4:54 PM, Jan Zorz wrote: 2. Bang the bell very hard to wake up PfSense developers, so they finally deploy IPv6 mechanisms at last. I liked PfSense a lot, but I moved to Mikrotik devices. They have IPv6 (and a lot of v6 mechanisms, like ospf-v3 and others) fully deployed. Many

Re: [pfSense Support] FreeRADIUS users

2010-03-07 Thread Jim Pingle
On 3/7/2010 12:45 PM, Rich Johnson wrote: I am unable to edit the OpenVPN status entry. I am getting No Management Daemon. I reinstalled the package. My platform is 1.2.3 Read the note on the bottom of the page, it tells you what needs to be added to the custom options for your OpenVPN server

Re: [pfSense Support] FreeRADIUS users

2010-03-07 Thread Jim Pingle
On 3/7/2010 2:49 PM, Joseph L. Casale wrote: Not that I know of. Could you tell us the error message ? Hey, Well, I have a couple installs I tried it on, each on their openvpn server config have: management 127.0.0.1 7050; (port varies between installs etc...) and yet I get: [error]

Re: [pfSense Support] Low-cost VPN endpoint compatible with pfSense

2010-03-17 Thread Jim Pingle
On 3/17/2010 8:02 AM, Chris Bagnall wrote: Greetings list, One of our clients has a requirement for a low-cost ADSL modem/router that'll act as a VPN endpoint (IPSec or OpenVPN) to a central pfSense node (at their head office). Ordinarily I'd just recommend small pfSense nodes like the

Re: [pfSense Support] help -- policy routing problem

2010-03-18 Thread Jim Pingle
On 3/18/2010 4:11 PM, Chris Buechler wrote: On Thu, Mar 18, 2010 at 4:04 PM, mayak-cq ma...@australsat.com wrote: hi all, i've got a serious policy routing problem that i cannot seem to overcome. the pfsense box has three interfaces: two are wan ports and one is lan -- both wan ports share

Re: [pfSense Support] CPU Throttle

2010-04-01 Thread Jim Pingle
On 4/1/2010 12:38 PM, J.D. Bronson wrote: I have noticed when I boot up pfsense 1.2.3, I see stuff like this on dmesg: kernel: acpi_throttle0: ACPI CPU Throttling on cpu0 I have an Intel Core 2 Quad and have disabled IntelSpeedStep in the BIOS but want to make sure nothing in pfsense

Re: [pfSense Support] Microsoft Server 2008 DHCP relay

2010-04-17 Thread Jim Pingle
On 4/17/2010 2:17 PM, Karl Fife wrote: [...]As I see it, I don't mind if Microsoft 2K8 server runs the Windows parts of the network but not the whole network. Has anyone actually tried this? Thanks in advance! I haven't tried the DHCP parts, but I have set one up for DNS thusly: Pass the

Re: [pfSense Support] policy routing openvpn -- how to select interface/gateway for openvpn

2010-04-19 Thread Jim Pingle
On 4/19/2010 5:40 AM, mayak-cq wrote: i have a pfsense box with two interfaces (not sharing the same media or gateway). i need for openvpn to use a specific interface/gateway to bind to. as packets are internally generated, standard policy routing won't work here -- i tried the openvpn

Re: [pfSense Support] no packages for 2.0

2010-04-19 Thread Jim Pingle
On 4/19/2010 1:57 PM, David Burgess wrote: The Available Packages page for 2.0 beta x86_64 full snapshot from Friday shows no packages, with the warning Unable to communicate with www.pfsense.com. Please verify DNS and interface configuration, and that pfSense has functional Internet

Re: [pfSense Support] L2TP

2010-04-21 Thread Jim Pingle
On 4/21/2010 8:03 AM, Paolo Supino wrote: I've installed PFSense 1.2.3 on a computer that I want to put as a gateway (instead of my crappy ADSL modem). I use L2TP protocol to authenticate to my ISP and connect to the Internet. Going through the menus in the WebConfigurator I can see that

Re: [pfSense Support] L2TP

2010-04-21 Thread Jim Pingle
On 4/21/2010 9:01 AM, Paolo Supino wrote: How do I bypass the webConfigurator to do it with mpd? That is beyond the scope of this mailing list. I meant that someone familiar with pfSense internals and mpd's config file format could probably add a WAN type for L2TP if there were enough

Re: [pfSense Support] I forgot the login password

2010-04-28 Thread Jim Pingle
On 4/28/2010 4:16 AM, Barkat ali wrote: how to reset the password for login ? Try one of the many options listed here: http://doc.pfsense.org/index.php/I_locked_myself_out_of_the_WebGUI,_help! Jim - To unsubscribe, e-mail:

Re: [pfSense Support] Firewall not blocking ip after adding it to rules

2010-04-28 Thread Jim Pingle
On 4/27/2010 6:37 PM, Chris Flugstad wrote: I block an ip in the fw rules on lan and wan, and then reset states, but traffic is still being passed to and from that ip did i miss something? These problems boil down to one of a few issues: 1. IP has an existing state. Clearing states or

Re: [pfSense Support] /boot/loader.conf.local

2010-04-30 Thread Jim Pingle
On 4/30/2010 10:01 PM, Volker Kuhlmann wrote: I have an AMD K6 mobo which requires ACPI to be off, or network interfaces don't work. (Which I had to find out again a few weeks ago upgrading to 1.2.3, having to take the box out to connect monitor and keyboard.) /boot/loader.conf was overwritten

Re: [pfSense Support] upgrading wrap to alix

2010-05-01 Thread Jim Pingle
On 5/1/2010 6:18 PM, Vick Khera wrote: Given that running on the WRAP requires some hackery, and does not support the dual firmware partitions, I'm planning to replace my current WRAP motherboard with the new ALIX board. I have the 2-ethernet, 2 miniPCI version of WRAP. Do I need a new

Re: [pfSense Support] Can't activate dhcp on 2.0 snapshot

2010-05-04 Thread Jim Pingle
On 5/4/2010 8:15 AM, Matias wrote: I'm trying on a virtual machine 2.0 snapshot 20100429 and I'm not able to activate the dhcp on the LAN interface. The interface address is 192.168.56.10, and when activating the DHCP service in the Available range field I can see: 192.168.56.1 -

Re: [pfSense Support] Re: Can't activate dhcp on 2.0 snapshot

2010-05-04 Thread Jim Pingle
On 5/4/2010 8:25 AM, Matias wrote: El 04/05/10 14:19, Jim Pingle escribió: On 5/4/2010 8:15 AM, Matias wrote: I'm trying on a virtual machine 2.0 snapshot 20100429 and I'm not able to activate the dhcp on the LAN interface. The interface address is 192.168.56.10, and when activating the DHCP

Re: [pfSense Support] Re: Can't activate dhcp on 2.0 snapshot

2010-05-04 Thread Jim Pingle
On 5/4/2010 8:37 AM, Matias wrote: There are some known issues with IP comparison functions on 64-bit snapshots. This is probably just one of those issues. Unfortunately, it seems to be a 64-bit PHP bug that we need to find a good workaround for. Well, this is good news for me. At least I

Re: [pfSense Support] Bug in pfsense 2.0 BETA1 20100506 (loadbalancer)

2010-05-09 Thread Jim Pingle
On 5/9/2010 8:39 PM, Chris Buechler wrote: On Fri, May 7, 2010 at 6:40 AM, Kai Szymanski kszyman...@it-partner-nord.de wrote: Hi! If i try to configure the loadbalancer (Services - Load balancer) i get Fatal error: Cannot redeclare killbypid() (previously declared in /etc/inc/util.inc:40)

Re: [pfSense Support] Does 123 Show Internal LAN Traffic Speeds?

2010-05-30 Thread Jim Pingle
On 5/30/2010 2:39 PM, mehma sarja wrote: While cloning a laptop to a samba file server across my internal LAN, The Traffic Graph on the LAN interface shows no activity. I have a simple home setup with one WAN and one LAN interface. Am I thinking about this the wrong way? That traffic never

Re: [pfSense Support] PFsense 2.0 SMTP notifications.

2010-06-04 Thread Jim Pingle
On 6/4/2010 3:19 PM, Ryan wrote: Sorry if this gets sent twice, I forgot to put a subject smacks self in head I finally got a chance t play with the new version 2.0 beta. I must say, I like what I see so far. Thanks I see there is a place under Advanced Notifications for an smtp server

Re: [pfSense Support] New blocked traffic

2010-06-09 Thread Jim Pingle
I have another soekris running 2.0-BETA2 and seeing the following in the logs from it(it's not logging source or destination). Be nice to have the source ip address... Lyle Giese LCR Computer Services, Inc. Jun 8 21:47:21 proxy pf: 00:00:00.000350 rule 2/0(match): block in on sis0:

Re: [pfSense Support] New blocked traffic

2010-06-09 Thread Jim Pingle
On 6/9/2010 9:35 AM, Lyle Giese wrote: On 2.0 the pf logs are split into two lines. You need the line after this to see the remainder of the log info. That bytes! How does a simple syslog parser handle that to match the two lines together? How can you guarentee that the next line is the

Re: [pfSense Support] Bandwdith usage since start of month?

2010-06-18 Thread Jim Pingle
On 6/18/2010 12:04 PM, Adam Thompson wrote: Is there a way to get this information? Try this command at the CLI, do the values look right when compared to the graph? My awk-fu isn't that good, there's probably a better way to do this: (This should all be one single line) rrdtool fetch

Re: [pfSense Support] Bandwdith usage since start of month?

2010-06-18 Thread Jim Pingle
On 6/18/2010 1:28 PM, Adam Thompson wrote: Thank you very much! I never know how to extract the raw data from rrdlogs, now I know it's actually not that hard. (BTW: the AWK is fine, although you can omit the cut(1) stage in the pipe simply by having awk add up $2 and $3 instead of $1 and

Re: [pfSense Support] Bandwdith usage since start of month?

2010-06-18 Thread Jim Pingle
On 6/18/2010 1:40 PM, Adam Thompson wrote: It wouldn't be too difficult to add this to the GUI if we can confirm that the results are indeed accurate. Well, I can tell you that the numbers returned matched up exactly with what my ISP wants to bill me for :-) That's certainly a good

Re: [pfSense Support] Bandwdith usage since start of month?

2010-06-24 Thread Jim Pingle
On 6/18/2010 1:44 PM, Jim Pingle wrote: On 6/18/2010 1:40 PM, Adam Thompson wrote: It wouldn't be too difficult to add this to the GUI if we can confirm that the results are indeed accurate. Well, I can tell you that the numbers returned matched up exactly with what my ISP wants to bill

Re: [pfSense Support] upgrade failure from Beta2 to Beta3

2010-06-30 Thread Jim Pingle
On 6/30/2010 10:16 AM, Lyle Giese wrote: I am playing with 2.0 Beta and saw Beta3 was availible. I am running the nanobsd version on a Soekris Net4801 on a 2g SanDisk CF card. The orginal load was by putting the Beta2 image on the CF card with dd. I downloaded the latest snapshot of Beta3

Re: [pfSense Support] blocking https:facebook.com via squidguard pfsense gui

2010-06-30 Thread Jim Pingle
On 6/30/2010 4:00 PM, Luke Jaeger wrote: I decided to enable transparent proxy on my school firewall because I was getting a million requests a day to configure proxy settings on student laptops. But now that I turned on transparent proxy, students have discovered that they can get to

Re: [pfSense Support] Create larger embedded images

2010-07-01 Thread Jim Pingle
On 7/1/2010 3:45 PM, Trevor Benson wrote: We have a few devices with sad drives we would like to use packages with and configure extra steps into the shutdown to backup additional log data an some small configurations to the /cfg partition. It would be useful to use the rest of the 32G. We

Re: [pfSense Support] blocking https:facebook.com via squidguard pfsense gui

2010-07-01 Thread Jim Pingle
On 6/30/2010 4:29 PM, Luke Jaeger wrote: thanks Jim - I got the impression from reading the pfsense forum that there is a way to block https for specific domains by denying the connect method - am I understanding this wrong? That would still require they be routed through squid. Denying a

Re: [pfSense Support] Re: Potential DNS rebind attack detected

2010-07-06 Thread Jim Pingle
On 7/6/2010 10:57 AM, David Burgess wrote: On Tue, Jul 6, 2010 at 8:50 AM, David Burgess apt@gmail.com wrote: Any idea what's going on here? I see a thread is already active in the forum. I'll recall this post in favour of that thread.

Re: [pfSense Support] Bandwdith usage since start of month?

2010-07-13 Thread Jim Pingle
On 7/13/2010 3:21 PM, Adam Thompson wrote: Aha! In /usr/local/www/status_rrd_summary.php, on line 38, the requested resolution for $lastmonth is 86400, but the RRD file in question doesn't have anything larger than 720*60=43200 (according to rrdtool info, anyway) and defaults to

Re: [pfSense Support] Bandwdith usage since start of month?

2010-07-13 Thread Jim Pingle
On 7/13/2010 6:20 PM, David Burgess wrote: On Tue, Jul 13, 2010 at 4:06 PM, Jim Pingle li...@pingle.org wrote: I committed a fix and updated the package. It should be up shortly. Parse error: syntax error, unexpected '(' in /usr/local/www/status_rrd_summary.php on line 38 That's

Re: [pfSense Support] Writing a 4gb version from windows.

2010-07-14 Thread Jim Pingle
On 7/14/2010 9:51 AM, Laurentiu STEFAN wrote: I have try to write on a dvd the last version of the pfSense from a PC whit Windows 7. I recive an error:The image file is invalid Can some one send me a link to an image file whit the last full version of the PFsense and instruction to write

Re: [pfSense Support] Re: FTP Server or samba server for PFSense

2010-07-14 Thread Jim Pingle
On 7/14/2010 11:18 AM, Laurentiu STEFAN wrote: Can some one help me whit this problem too? 2010/7/14 Laurentiu STEFAN laurentiu.ste...@gmail.com mailto:laurentiu.ste...@gmail.com I have an IBM Inellystation whith 2 Pentium 2 - 350Mhz processor, 512 RAM and 150 GB Hdd. I want

Re: [pfSense Support] Minimal configuration for pfSense.

2010-07-14 Thread Jim Pingle
On 7/14/2010 3:17 PM, Laurentiu STEFAN wrote: It's OKa to use an IBM Pentium MMX 200MHZ, 64MB Ram, 3GB SCSI, 3X LAN for pfSense (Mask, firewall load balancing whith 10 PC behind)? That's not very much RAM. If it doesn't use any packages, and no VPNs, it might work. Barely. But it will

Re: [pfSense Support] 2.0 beta1 embedded to beta3 upgrade

2010-07-28 Thread Jim Pingle
On 7/28/2010 2:12 PM, stephen at stephenjc wrote: I have tried from the terminal to upgrade from beta1 to beta3. It says everything is ok and reboots but always comes backup as beta1. From a snap that old you will probably have to do a GUI firmware update. Both the console upgrade and auto

Re: [pfSense Support] USB Keyboard - Boot Hangs

2010-08-04 Thread Jim Pingle
On 8/4/2010 1:24 PM, Tim Nelson wrote: Greetings (again) fellow pfSense'rs- I'm also having issues with booting a system with a USB keyboard. The keyboard works perfectly fine, but when pfSense attempts to initialize all devices, there are problems and the system hangs: Starting device

Re: [pfSense Support] /boot/loader.conf vs /system_advanced_sysctl.php in 2.0

2010-08-12 Thread Jim Pingle
On 8/12/2010 1:54 PM, David Burgess wrote: In 1.2.3 I had very good results adding the following lines to /boot/loader.conf while using the squid package in transparent mode: hint.apic.0.disabled=1 kern.ipc.nmbclusters=32768 kern.maxfiles=65536 kern.maxfilesperproc=32768

Re: [pfSense Support] Large Aliases

2010-08-23 Thread Jim Pingle
On 8/23/2010 3:12 PM, Seth Mos wrote: Hi, Op 23 aug 2010, om 21:08 heeft Jim Cheetham het volgende geschreven: Perhaps there's another way; what are you doing this for? Instead of basing rules on a large set of aliases that you have to update regularly, is there some other characteristic

Re: [pfSense Support] Large Aliases

2010-08-23 Thread Jim Pingle
On 8/23/2010 6:20 PM, Joseph L. Casale wrote: Also, in 2.0 we have support for nested aliases. What you can do with this is pretty straightforward ofcourse. You can then update 1 specific alias which is part of the parent alias. This should make management a lot easier, the chances of error

  1   2   >