Re: [pfSense Support] four port network card

2005-07-15 Thread Scott Ullrich
I have started a supported hardware list (adapted from the freebsd list): http://www.pfsense.com/index.php?id=37 On 7/15/05, alan walters [EMAIL PROTECTED] wrote: D-Link DFE-580TX Quad NIC PCI Card Sorry I have't been following some thread very well there has been some

[pfSense Support] Multi WAN dhclient

2005-07-18 Thread Scott Ullrich
Support for multiple WAN dhclient has been available for 2-3 weeks. Has anyone tried this yet? I need some feedback on if this works or not Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands,

Re: [pfSense Support] pfSense 70.1 dhclient and unexpected character

2005-07-19 Thread Scott Ullrich
(/etc/dhclient-script, ...): No such file or directory -Kyle Mott Scott Ullrich wrote: Couple of things: 1. rm -rf /usr/local/pkg/pf/* 2. Reinstall all packages 3. vipw from a shell prompt and add: _dhcp:*:65:65::0:0:dhcp programs:/var/empty:/usr/sbin

Re: FW: [pfSense Support] round robin on inbound nat

2005-07-22 Thread Scott Ullrich
not mean to send it -Original Message- From: alan walters Sent: 22 July 2005 15:11 To: 'Bill Marquette'; Scott Ullrich Cc: support@pfsense.com Subject: RE: [pfSense Support] round robin on inbound nat I have done some testing today with inbound NAT and carp And round robin

Re: [pfSense Support] CARP and backup firewall

2005-07-25 Thread Scott Ullrich
I have 2 boxes at home, both on carp. Works fine. You sure your outbound rules are setup correctly? Scott On 7/25/05, alan walters [EMAIL PROTECTED] wrote: On version 0.70.8 I had sync working and backup lan operational when the master was down. On veriosn 0.71 the sync works

Re: [pfSense Support] round robin on inbound nat

2005-07-25 Thread Scott Ullrich
On 7/25/05, alan walters [EMAIL PROTECTED] wrote: I know this discussion is going on a bit. But I was wondering If we really think it is practical using the method we are trying. With a basic round robin configured on the firewall. The web servers can be configured to use there own software

Re: [pfSense Support] squid diskd 70.10

2005-07-25 Thread Scott Ullrich
squid? Is this going to make the kernel use more memory? --Bill On 7/24/05, Scott Ullrich [EMAIL PROTECTED] wrote: Alright, I'll recompile the kernel with: options MSGMNB=8192 # max # of bytes in a queue options MSGMNI=40 # number of message

Re: [pfSense Support] PHP error on PPTP Loggin page

2005-07-28 Thread Scott Ullrich
Its a known problem. Thanks, Scott On 7/28/05, David Strout [EMAIL PROTECTED] wrote: Everyone, I get the following line above the table when I click on the PPTP tab on the Diagnostics: System logs: PPTP VPN page. /usr/sbin/clog: ERROR: log_file argument must be specified. usage:

Re: [pfSense Support] captive portal

2005-07-29 Thread Scott Ullrich
They are kept in pf tables. The table in question is captiveportal. Try this command at a command prompt after you have some ppl auth'd: pfctl -t captiveportal -T show Scott On 7/29/05, alan walters [EMAIL PROTECTED] wrote: Just was reviewing the captive portal implementation.

Re: [pfSense Support] captive portal

2005-07-29 Thread Scott Ullrich
On 7/29/05, alan walters [EMAIL PROTECTED] wrote: ok thanks it looks ok for allowed IP's, is the rule the same for captive portal clients that are being authenticated through the captive portal or are they authenticated on there mac address Yes

Re: [pfSense Support] Securing CARP

2005-07-31 Thread Scott Ullrich
Use a dedicated carp / pfsync interface. Scott On 7/31/05, Randy B [EMAIL PROTECTED] wrote: I know that CARP encrypts it's messages, but I'm using it to provide a virtual IP on a network that I'd rather consider actively hostile. As such, I'd like to eliminate any non-essential

Re: [pfSense Support] pppoe

2005-08-01 Thread Scott Ullrich
HRM. Interesting. I'll check it out. May not be able to support radius for PPPoE since its config is no different than PPTP. On 8/1/05, alan walters [EMAIL PROTECTED] wrote: Pppoe hangs on registing computer on network with radius enabled. Nothing weird is in my radius server

Re: [pfSense Support] services startup

2005-08-01 Thread Scott Ullrich
All are planned changes for this coming weekend (hackathon). Scott On 8/1/05, alan walters [EMAIL PROTECTED] wrote: It would be good to have packages installed but not running for example ntop. Can these be configured on boot or to be started when you want them

Re: [pfSense Support] pfSense Development...

2005-08-01 Thread Scott Ullrich
On 8/1/05, Paul Taylor [EMAIL PROTECTED] wrote: We have a monowall development system... (A FreeBSD VM)... We used the excellent guide in the Monowall docs about how to build your own monowall images to create it... We've since added a SSH server that only allows access via keys set in the

Re: [pfSense Support] vpn ipsec

2005-08-01 Thread Scott Ullrich
I have 10+ vpn's nailed up with 0 issues. I seriously doubt there is a bug. Scott On 8/1/05, alan walters [EMAIL PROTECTED] wrote: I'm still having problems with my vpns I have sad and spd entries at each end on the tunnel but I cannot traceroute or use any other protocol . does

Re: [pfSense Support] pfSense Development...

2005-08-01 Thread Scott Ullrich
On 8/1/05, Paul Taylor [EMAIL PROTECTED] wrote: Comments below: -Original Message- Why not use a remote radius server that only the user can control? We are trying to do this with as few boxes (and lowest $$) as possible. We also thought the simple web interface of Monowall

Re: [pfSense Support] Multiple WAN IP addresses .....

2005-08-01 Thread Scott Ullrich
Use the virtual IP function to add more addresses to any interface, including WAN. Scott On 8/1/05, DLStrout [EMAIL PROTECTED] wrote: Are there any plans for assigning multiple IP addresses to the WAN interface? - To

Re: [pfSense Support] Remote Shutdown

2005-08-02 Thread Scott Ullrich
Use execraw.php to issues shutdown -h now Scott On 8/2/05, analyzerx [EMAIL PROTECTED] wrote: halt system in the web admin? o_O? On 8/2/05, Roger Miranda (Digital Relay) [EMAIL PROTECTED] wrote: Hey, I have a PfSense Version Firewall in place but due to energy prices in it's

Re: [pfSense Support] Question on UPDATES

2005-08-02 Thread Scott Ullrich
On 8/2/05, David Strout [EMAIL PROTECTED] wrote: Are the updates posted to the mirrors static or are they updated based upon changes throughout the day/multiday timeline. They update throughout the day. Check the md5's. A little clarity if I grabbed the 0.73.2 update last night and

Re: [pfSense Support] concurrent captive portal users

2005-08-02 Thread Scott Ullrich
If you can make this an option this would be a great addition. A unified diff with the m0n0wall code changes should be enough for me to integrate the code into pfSense. Scott On 8/2/05, Paul Taylor [EMAIL PROTECTED] wrote: By default, captive portal will allow multiple logins using the

Re: [pfSense Support] concurrent captive portal users

2005-08-02 Thread Scott Ullrich
On 8/2/05, Paul Taylor [EMAIL PROTECTED] wrote: I am planning to make it an option - Either log them out, or allow concurrency I hadn't thought of having it ask. I've also had another suggestion to redirect them to a page that indicates their password may have been

Re: [pfSense Support] ipsec more info

2005-08-03 Thread Scott Ullrich
I would to help with this but I have to admit that this is a new prospect for me. Let me know how it turns out and it would be nice if we could document this behavior. On 8/3/05, alan walters [EMAIL PROTECTED] wrote: Ok I have made a bit of progress with this one. I have setup a vpn by

Re: [pfSense Support] Multi-WAN capabilities...

2005-08-03 Thread Scott Ullrich
On 8/3/05, Paul Taylor [EMAIL PROTECTED] wrote: I've seen somewhere the multi-WAN works with DHCP on both WANs now, but will it work with PPPoe on one interface and DHCP on the other? If so, is this a failover situation by default (where one interface can be designated as a primary), or for

Re: [pfSense Support] Problem with pfSense on EPIA with DiskOnModule

2005-08-03 Thread Scott Ullrich
The embedded images do not have VGA :) Install from the ISO to the DoC. Scott On 8/3/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Hi all, I'm trying to get pfSense working on my EPIA setup with the following configuration: * EPIA PD1 (C3 1Ghz Nehemiah, dual LAN connection,

Re: [pfSense Support] Two ISP configuration

2005-08-03 Thread Scott Ullrich
On 8/3/05, Charrua [EMAIL PROTECTED] wrote: Hi I have two Internet connections from two different ISPs. Connection A is ADSL, connection B is another kind of broadband connection (LMDS). In the ADSL link I have 1 public ip which changes dynamically, and in the B connection I have 28

Re: [pfSense Support] vpn ipsec

2005-08-03 Thread Scott Ullrich
Or you could think of this as self tuning. From everything I can gather it seems normal. Scott On 8/4/05, Chris Buechler [EMAIL PROTECTED] wrote: On 8/1/05, Scott Ullrich [EMAIL PROTECTED] wrote: [kernel: tl0: tx underrun -- increasing tx threshold to 512 bytes] [kernel: tl0: tx

Re: [pfSense Support] 0.73.6-WRAP board

2005-08-04 Thread Scott Ullrich
Fixed in CVS. Thanks. On 8/4/05, Giorgio Ducci [EMAIL PROTECTED] wrote: Hi, I'm testing 0.73.6 on a Wrap board with an Atheros mPCI and when I enable interface OPT1 (ath0) and I click on SAVE I get a new page with this on the header: Warning: fopen(/tmp//sbin/ifconfig_wireless): failed

Re: [pfSense Support] SSH Access with pfSense

2005-08-04 Thread Scott Ullrich
Thats bizarre because I just logged into my primary firewall with WinSCP without any modifications. In fact I remember spending many days working on this exact problem! Scott On 8/4/05, Paul Taylor [EMAIL PROTECTED] wrote: I've got pfSense installed and working today, but the SSH access it

Re: [pfSense Support] USB Keyboard on 73.2

2005-08-04 Thread Scott Ullrich
Here's an update on the usb keyboard status. In a nutshell, known problem: http://www.freebsd.org/releases/5.3R/errata.html 31 Oct 2004, updated on 5 Nov 2004) For FreeBSD/i386 and FreeBSD/amd64, when installing FreeBSD 5.3 using an USB keyboard the keyboard will stop working once the kernel

Re: [pfSense Support] USB Keyboard on 73.2

2005-08-04 Thread Scott Ullrich
I have started a booting wiki page at: http://wiki.pfsense.com/wikka.php?wakka=BootOptions Please feel free to expand it. Scott On 8/4/05, Chris Buechler [EMAIL PROTECTED] wrote: On 8/4/05, Paul Taylor [EMAIL PROTECTED] wrote: Success! Nice! We added the hint to the

Re: [pfSense Support] USB Keyboard on 73.2

2005-08-04 Thread Scott Ullrich
All that is required (supposed to be) for USB is usbd which is running. On 8/4/05, Paul Taylor [EMAIL PROTECTED] wrote: We're actually wondering if there is something that starts after the interface assignments are complete that brings the keyboard support back. Since we modified our

Re: [pfSense Support] USB Keyboard on 73.2

2005-08-04 Thread Scott Ullrich
assignment script again... Keyboard doesn't work.. I'm guessing that something is starting after that script completes that causes the USB keyboard to start working... Paul -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Thursday, August 04, 2005 1:54 PM

Re: [pfSense Support] USB Keyboard on 73.2

2005-08-04 Thread Scott Ullrich
0.73.6 is the latest On 8/4/05, Paul Taylor [EMAIL PROTECTED] wrote: 0.73.4.1 -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Thursday, August 04, 2005 2:09 PM To: Paul Taylor Cc: support@pfsense.com Subject: Re: [pfSense Support] USB Keyboard on 73.2

Re: [pfSense Support] IOS image problems .....CORRECTION

2005-08-04 Thread Scott Ullrich
Are you configuring the networking and its able to talk to the network before installing? On 8/4/05, David Strout [EMAIL PROTECTED] wrote: Everyone, Reported earlier that the /FreeSBIE/scripts/install.sh loads fine. As the first few lines pass by it states that the Backend is Loading, but

Re: [pfSense Support] FreeRadius Package - slight security issue

2005-08-05 Thread Scott Ullrich
Contact the authors of freeradius then. This setup would be no different from freebsd in the back of your room running the same configuration! On 8/5/05, Paul Taylor [EMAIL PROTECTED] wrote: While looking through the config.xml file to see if I could spot anything unusual (to

Re: [pfSense Support] Captive Portal Problems 0.73.6

2005-08-05 Thread Scott Ullrich
If this is happening then your hitting some big giant locked area of the freebsd kernel. I haven't personally seen this issue but I have noticed that sometimes during filter reload operations the console keyboard stops responding which reminds me of your issue. Just a complete guess. Scott On

Re: [pfSense Support] FreeRadius Package - slight security issue

2005-08-05 Thread Scott Ullrich
Not to mention I have to stress that this is no different from running free-radius in a non pfSense environment. Your real beef is with the freeradius authors, not us. Scott On 8/5/05, Bill Marquette [EMAIL PROTECTED] wrote: On 8/5/05, Paul Taylor [EMAIL PROTECTED] wrote: Bill,

Re: [pfSense Support] FreeRadius Package - slight security issue

2005-08-05 Thread Scott Ullrich
This whole argument is pointless. If this is really this big of a problem you have these choices: 1. Dont use freeradius and use a seperate server where you will be entering these configs in _PLAIN TEXT_ as well. 2. Dont use pfSense Scott On 8/5/05, Paul Taylor [EMAIL PROTECTED] wrote:

[pfSense Support] Hackathon time!

2005-08-05 Thread Scott Ullrich
Sorry for cross posting but I wanted to make everyone aware that the lists will be going offline for the weekend as the developers hackathon is starting today. Please hold all bug reports, etc until after monday of next week. Would also like to thank everyone that has donated to the hackathon.

Re: [pfSense Support] Re: usb eth not working?

2005-08-08 Thread Scott Ullrich
Found one more issue. Look for the fixes in the next version. Not sure when it will be out however. On 8/8/05, denny halim [EMAIL PROTECTED] wrote: i just tried the latest 0.73.8 pfsense. still same error. ?? On 8/4/05, Scott Ullrich [EMAIL PROTECTED] wrote: Fixed in CVS

Re: [pfSense Support] upgrade problems ...

2005-08-08 Thread Scott Ullrich
On 8/8/05, David Strout [EMAIL PROTECTED] wrote: [useless stuff snipped] I also notice scrolling ALERTS about an error parsing the /tmp/rules.debug What line in /tmp/rules.debug and what does the line say? Thats the culprit.

Re: [pfSense Support] vpn trouble 0.74

2005-08-08 Thread Scott Ullrich
What does line 248 of /cf/conf/config.xml show? On 8/8/05, alan walters [EMAIL PROTECTED] wrote: following error occurs when trying to add a new ipsec tunnel version 0.74 XML error: not well-formed (invalid token) at line 248

Re: [pfSense Support] Outbound NAT

2005-08-08 Thread Scott Ullrich
Please open a ticket for this item at http://cvstrac.pfsense.com/tktnew and include as much info as possible. On 8/8/05, Marcin Jessa [EMAIL PROTECTED] wrote: Hi. Enabling your custom NAT rules and then chosing Save for Enable advanced outbound NAT will reenable default NATing rules.

Re: [pfSense Support] Some GUI minor problems

2005-08-08 Thread Scott Ullrich
Please open a ticket for this at http://cvstrac.pfsense.com/tktnew and include as much info as possible. On 8/8/05, Giorgio Ducci [EMAIL PROTECTED] wrote: Hi to all, I'm testing 0.74-embedded on a WRAP 1E board. In INTERFACES: OPT1 when I set the SSID name and I desactive the hide SSID option

Re: [pfSense Support] general congrats on all that hard work

2005-08-08 Thread Scott Ullrich
Thank us in a week when all the bugs are worked out. Scott On 8/8/05, alan walters [EMAIL PROTECTED] wrote: Well just thought to say thanks to the fine work you all achieved in the weekend while we sat in the sun and supped martinis' Big pats on the back, even though they

[pfSense Support] Runing 0.74?

2005-08-09 Thread Scott Ullrich
If you are running 0.74 I would highly suggest to 0.74.2. There was a really interesting XML parser bug that was really wrecking the pf rules file in certain cases. Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For

Re: [pfSense Support] ppp over gre or ptp tunnel

2005-08-09 Thread Scott Ullrich
I have a Mitel 5020IP phone that I run over IPSEC to work. It works fine. I honestly cannot speak of the other things you mention. Scott On 8/8/05, alan walters [EMAIL PROTECTED] wrote: I know this is a difficult question but I would like to know wheaether there is any Native support

Re: [pfSense Support] Re: [pfSense-discussion] Security problem while loading rules?

2005-08-10 Thread Scott Ullrich
On 8/10/05, alan walters [EMAIL PROTECTED] wrote: I feel that it is the same bug or very similar to the one that was in 0.74 when it first came out. When you create an ipsec tunnel it trashes it also when you add a block rule to the firewall on an optional interface the rules crash. I will

Re: [pfSense Support] error on pf rules on opt 1 interface with pppoe enabled on wrap.

2005-08-10 Thread Scott Ullrich
Send me your /tmp/rules.debug file to [EMAIL PROTECTED] Scott On 8/10/05, alan walters [EMAIL PROTECTED] wrote: The this that the pope server is not working on the optional interfaces on 0.74.6 on a wrap board. But it think it is to do with the rules errors we have discussed and not

[pfSense Support] Re: CORRECTION -- ISO problems ... still

2005-08-10 Thread Scott Ullrich
Not sure what to tell you. It works fine for me. Scott On 8/10/05, David Strout [EMAIL PROTECTED] wrote: My fat finger ... yes it is the 0.74.4 ISO that I tried I tried all of the 0.73.x versions prior to this. Sorry for the mis-communication. - Original Message - Subject:

Re: [pfSense Support] pfSense 0.73.8 and Traffic Shaper Wizzard

2005-08-11 Thread Scott Ullrich
That version had bugs. Upgrade to the latest. Scott On 8/11/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Hi, Am having some problems with the Traffic Shaper Wizzard on 0.73.8. At the final stage of the wizzard when the changes are applied we see a page of PHP error message which is

Re: [pfSense Support] Installation Problem

2005-08-11 Thread Scott Ullrich
This has been reported before but I have not been able to reproduce the problem. Scott On 8/11/05, Yves Fortin [EMAIL PROTECTED] wrote: Hello, I seem to be having some issues installing pfsense with at least the 4 last iso images. After typing installer, there is a brief blue screen (not

[pfSense Support] Re: 0.74.6-WRAP board-bugs

2005-08-11 Thread Scott Ullrich
On 8/10/05, Giorgio Ducci [EMAIL PROTECTED] wrote: Hi to all, I installed 0.74.6 on a 1E Wrap board. Some minor bugs: - on Interfaces==OPT1(Atheros wireless) the Hide SSID option is missed?! Option was removed. It hides the SSID from the end user and does not hide the SSID from wireless

Re: [pfSense Support] ISO problems ... still

2005-08-11 Thread Scott Ullrich
We are working on this. Everyone please be patient. The installer is a tricky piece to get right for such a broad range of hardware and such. Scott On 8/11/05, Wesley Joyce [EMAIL PROTECTED] wrote: I'm in the same boat as well on Dell GX 110's. I have followed the 'upgrade solution' of

Re: [pfSense Support] ISO problems ... still

2005-08-11 Thread Scott Ullrich
All, are you using SCSI by chance? Scott On 8/11/05, Wesley Joyce [EMAIL PROTECTED] wrote: I'm in the same boat as well on Dell GX 110's. I have followed the 'upgrade solution' of installing 0.68.x and upgrading from there. -Original Message- From: William Pflaumer

Re: Re: [pfSense Support] ISO problems ... still

2005-08-11 Thread Scott Ullrich
Try running: /usr/local/bin/lua50c51 /usr/local/share/dfuibe_lua/main.lua \ dir.root=/FreeSBIE/ \ option.booted_from_install_media=true ... From a shell prompt. Do you get a lua error? Scott On 8/11/05, David Strout [EMAIL PROTECTED] wrote: I just tried a fresh 0.74.6 install

Re: [pfSense Support] ISO problems ... still

2005-08-11 Thread Scott Ullrich
] wrote: I am going to try the latest ISO with a GX110 using the IDE HD and then SCSI and let you guys know. -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Thursday, August 11, 2005 3:00 PM To: David Strout Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]; support

Re: [pfSense Support] ISO problems ... still on 0.75 / 0.75.1 iso version error?

2005-08-12 Thread Scott Ullrich
On 8/12/05, Wesley Joyce [EMAIL PROTECTED] wrote: I am now only getting as far as 63% during the install when the CDROM is on the secondary bus. This is using pfSense-LiveCD-0.75.1 which for some strange reason still boots and display 0.75 as the version. Should I download this from a

Re: [pfSense Support] 0.75.1 ISO ..... Problems

2005-08-12 Thread Scott Ullrich
On 8/12/05, David Strout [EMAIL PROTECTED] wrote: All, It hangs STILL on the Waiting for Backend screen and I tried running the lua cammand that Scott had me try last night and get a different set of messages, but it still hangs and I have to CTRL-C out (twice). Send me the messages. Scott

Re: [pfSense Support] Alert about pf rules syntax errors... again...

2005-08-12 Thread Scott Ullrich
This is not the correct fix. Try this /etc/inc/vpn.inc. http://pfsense.com/cgi-bin/cvsweb.cgi/pfSense/etc/inc/vpn.inc?rev=1.69;content-type=text%2Fplain On 8/12/05, M. Kohn [EMAIL PROTECTED] wrote: Hi, small hint abut IPSec bug (I hope...): (pfSense 0.75) The function

Re: [pfSense Support] ISO problems ... still on 0.75 / 0.75.1 iso version error?

2005-08-12 Thread Scott Ullrich
? To: Scott Ullrich [EMAIL PROTECTED] Cc: support@pfsense.com During the cpdup command processing after the partitioning, formatting, it faults at the 63% progress indicator during the installation. -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: Friday, August 12

[pfSense Support] Re: 0.75.1 - php: There were error(s) loading the rules

2005-08-12 Thread Scott Ullrich
Same problem as reported a few hours ago. Try the vpn.inc that I asked the other person to try. On 8/12/05, Wesley Joyce [EMAIL PROTECTED] wrote: After disabling the default LAN rule I immediately got this notice. System log from web gui Aug 12 12:13:41 php: There were

Re: [pfSense Support] Packages

2005-08-12 Thread Scott Ullrich
Check your DNS? It works fine here. Scott On 8/12/05, Mike Sr [EMAIL PROTECTED] wrote: I am running version 0.75 upgraded from 0.74.8 and in either version I am unable to see any packages. It says Unable to retrieve package info from www.pfesnse.com. Cached data will be used.

Re: [pfSense Support] pfSense 0.76.2: No rdr rule for Squid Transparent Proxy

2005-08-16 Thread Scott Ullrich
The solution here is to set the filter dirty flag in the squid startup script. This will force the rules to be reloaded and then squid will be running. I'll take care of it shortly. Scott On 8/16/05, Bill Marquette [EMAIL PROTECTED] wrote: Albert, can you file a ticket on this at

Re: [pfSense Support] Alert about pf rules syntax errors... again...

2005-08-17 Thread Scott Ullrich
rather hard to enforce, no? Scott On 8/17/05, Randy B [EMAIL PROTECTED] wrote: Scott Ullrich wrote: I just tested the latest vpn.inc with my home firewall that has 4+ ipsec links and it works fine.I'll be releasing a new version soon. Please be on the lookout for it and give it a try

Re: [pfSense Support] pfSense 0.76.2: No rdr rule for Squid Transparent Proxy

2005-08-17 Thread Scott Ullrich
concerned of the Squid process dying for any reason and the rdr rule for transparent proxying is still in effect. This will block http traffic to the internet. Any solution for this? Thanks again. Miles --- Scott Ullrich [EMAIL PROTECTED] wrote: The solution here is to set the filter

Re: [pfSense Support] pfSense 0.76.2: No rdr rule for Squid Transparent Proxy

2005-08-17 Thread Scott Ullrich
... /bkw On 8/17/05, Scott Ullrich [EMAIL PROTECTED] wrote: SQUID should not be dying. If it is then I need to deactivate the package until a new one is released on the freebsd site. Scott On 8/16/05, Albert Miles Enabe [EMAIL PROTECTED] wrote: No need to file a ticket. Thanks

Re: [pfSense Support] Firewall is blocking traffic it shouldn't

2005-08-17 Thread Scott Ullrich
pfctl -vvvsr from a command prompt (or status.php) lists the rules with rule numbers. On 8/17/05, Roy Walker [EMAIL PROTECTED] wrote: Running pfsense 0.77. Getting messages like the following: pf: 140737 rule 111/0(match): block in on fxp2: yyy.yyy.yyy.yyy.4685

Re: [pfSense Support] ipsec and 0.77

2005-08-18 Thread Scott Ullrich
Is this a fresh configuration? On 8/18/05, alan walters [EMAIL PROTECTED] wrote: I don't know about this I still am seeing problems with ipsec Auto generated rules being wrong and an empty tunnel still being made with 0.77. I know this is nothing to do with the above problem but 0.77 is

Re: [pfSense Support] ipsec and 0.77

2005-08-18 Thread Scott Ullrich
it adds a blank tunnel again. And creates rubbish rules. -Original Message- From: Scott Ullrich [mailto:[EMAIL PROTECTED] Sent: 18 August 2005 20:42 To: alan walters Cc: support@pfsense.com Subject: Re: [pfSense Support] ipsec and 0.77 Is this a fresh configuration? On 8/18

Re: [pfSense Support] Trying to setup pfsense with 3 WAN connections

2005-08-19 Thread Scott Ullrich
Outgoing load balancing is not ready yet. On 8/19/05, Moacyr Leite da Silva [EMAIL PROTECTED] wrote: Hi there, Need tips for outgoing load balance and source routing with pfsense and 2 and 3 WAN connections. I tryed to config this scenario com with 2 pfsense box and with 1

Re: [pfSense Support] pfsense on flash

2005-08-19 Thread Scott Ullrich
The embedded images lack video, keyboard and mouse support. Perhaps the best solution is to install using the cdrom installer to the compact flash directly then editing /etc/platform to read wrap. Scott On 8/19/05, Jamy Klein [EMAIL PROTECTED] wrote: I noticed there are images for running

Re: [pfSense Support] There were error(s) loading the rules

2005-08-19 Thread Scott Ullrich
On 8/19/05, alan walters [EMAIL PROTECTED] wrote: There are two ways to remake the error that I found. (1) create a new firewall rule and apply it. [click to toggle enabled/disabled status]* * * * * TestRule I added the rule above. No issues. (2)

[pfSense Support] Avoid 0.78!

2005-08-19 Thread Scott Ullrich
Firmware upgrade bug lurks from within. I would avoid it at all costs. 0.79 will be published soon. Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] Error with squid on .79

2005-08-21 Thread Scott Ullrich
Squid is being worked on right now. I would avoid it. On 8/21/05, Jason Landry [EMAIL PROTECTED] wrote: I get the following error trying to install squid: Parse error: parse error, unexpected T_VARIABLE in /etc/inc/pkg-utils.inc(424) : eval()'d code on line 1 Fatal error: Call to

Re: [pfSense Support] There were error(s) loading the rules

2005-08-21 Thread Scott Ullrich
-Original Message- From: Bastian Schern [mailto:[EMAIL PROTECTED] Sent: 19 August 2005 23:02 To: Scott Ullrich Cc: alan walters; [EMAIL PROTECTED] Subject: Re: [pfSense Support] There were error(s) loading the rules I think I did nothing with the IPSec rule. But is there a way to get the FW

Re: [pfSense Support] Virtual IPs not working

2005-08-22 Thread Scott Ullrich
You cannot ping proxy-arp'd ips unless there are 1:1 NAT setup. Is this how your forwarding or using port forward? Scott On 8/22/05, Bastian Schern [EMAIL PROTECTED] wrote: Hi, I'm using pfSense Version 0.79.2 and my Virtual IPs are not functional. --- snip --- virtualip

Re: [pfSense Support] wireless card on lan

2005-08-23 Thread Scott Ullrich
I'll check it out. I really need to rip out the interfaces crap and redo it completely. But no time and a feature freeze. GRR. On 8/23/05, alan walters [EMAIL PROTECTED] wrote: Seems that if you put a wireless card in the lan there is no option to make it a hostap only bss and ibss.

Re: [pfSense Support] captive portal

2005-08-23 Thread Scott Ullrich
On 8/23/05, Tobias Frank [EMAIL PROTECTED] wrote: Hello, when trying to use the captive portal on 0.79 there is a strange thing. Following ports work without authentication: MySQL, smtp, ping, ssh, name. Others I didn´t check. m0n0wall (1.2b9) doesn´t show this behaviour. Is this a bug or

[pfSense Support] Anyone using failover DHCP?

2005-08-23 Thread Scott Ullrich
If so, you need to do an update for a file I just commited. From the shell type: update_file.sh /etc/inc/services.inc Now reboot each firewall. Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands,

[pfSense Support] Attention users with ISO installation problems

2005-08-23 Thread Scott Ullrich
Please try 0.79.4 and report back if you have had problems with previous LiveCD's. Thanks! - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: [pfSense Support] VLAN problem

2005-08-24 Thread Scott Ullrich
Thats strange. The wizard should not reappear unless you change interface assignments. Im curious why the interface assignment screen is being tripped on reboot. Does it happen every time? If so I'll need to somehow duplicate your configuration and figure out what logic to ignore when

[pfSense Support] Anyone having installer issues

2005-08-24 Thread Scott Ullrich
Please try 0.80 which is making its way to the mirrors. If this fails, please try: http://wiki.pfsense.com/wikka.php?wakka=BootTroubleShooting Thanks! - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands,

Re: [pfSense Support] captive portal question?

2005-08-24 Thread Scott Ullrich
The interface must be enabled and configured to show up. Scott On 8/24/05, Dan Swartzendruber [EMAIL PROTECTED] wrote: I was looking at the setup screen, and it doesn't look like it will let me pick the OPT1 interface (which is where my guest WLAN will come in on...)

Re: [pfSense Support] Sweet!

2005-08-25 Thread Scott Ullrich
On 8/25/05, Dan Swartzendruber [EMAIL PROTECTED] wrote: I don't know if this is something I'm doing wrong. Using the default pfsense captive portal page, I defined a test user and password. Unfortunately, even if I deliberately enter something wrong, I get no error indication, and my

Re: [pfSense Support] Captive portal broken?

2005-08-25 Thread Scott Ullrich
I have just commited a change for this. Please test on 0.80.4 On 8/25/05, Dan Swartzendruber [EMAIL PROTECTED] wrote: Well, it doesn't seem to work at all. Here's what I'm seeing: 1. I'm allowed to pass whatever traffic I feel like before being authenticated. 2. When I launch the

Re: [pfSense Support] Slow Boot - Hanging on OPT interfaces.

2005-08-26 Thread Scott Ullrich
What kind of NICS? On 8/26/05, Ted Crow [EMAIL PROTECTED] wrote: Ok, versions 0.80-0.80.2 installed without *too* much trouble, and my remote network can now see the WAN and OPT interfaces. One thing I did notice with 0.80 and 0.80.2 is that my firewall hangs for about 5 minutes during

Re: [pfSense Support] Anyone having installer issues

2005-08-26 Thread Scott Ullrich
0.71? Thats OLD. Please download a 0.80 series iso. On 8/26/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: At 11:47 AM 8/26/2005, Dimitri Rodis wrote: This wouldn't happen to be a repeat of the cdrom on the same channel issue, is it? Well, it's a virtual CDROM, but it happens to be on a

Re: [pfSense Support] Anyone having installer issues

2005-08-26 Thread Scott Ullrich
. At 12:05 PM 8/26/2005, Scott Ullrich wrote: How much ram do you have? 128 is the recommended minimum. On 8/26/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: At 11:53 AM 8/26/2005, Scott Ullrich wrote: 0.71? Thats OLD. Please download a 0.80 series iso. No, .71

Re: [pfSense Support] Anyone having installer issues

2005-08-26 Thread Scott Ullrich
On 8/26/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: The only LiveCD's that I found on 4 different sites were pfSense-LiveCD-0.80.iso, with no minor version appended. After looking at 4 sites, I stopped trying to find any more versions. According to my System:Firmware:AutoUpdate page:

Re: [pfSense Support] Anyone having installer issues

2005-08-26 Thread Scott Ullrich
Please send me the contents of /tmp/ after a failed install attempt. [EMAIL PROTECTED] Thanks On 8/26/05, Simon SZE-To [EMAIL PROTECTED] wrote: Hello, I've tried the latest ISO installer, but my problem still here as I send to this list a week ago. Below is my mail has been sent

Re: [pfSense Support] Captive portal update

2005-08-26 Thread Scott Ullrich
On 8/26/05, Chris Buechler [EMAIL PROTECTED] wrote: yeah, if that's the controls you want applied to authenticated clients. Sounds like that's a bug though. Scott or someone will have to comment there. Chris is absolutely correct. I'll drag all the equipment back out tomorrow and retest

Re: [pfSense Support] traffic shaper

2005-08-27 Thread Scott Ullrich
On 8/27/05, Robo.K. [EMAIL PROTECTED] wrote: Hi, i have a question. Where in settings of traffic shaper can i set up the bandwidth ?? A don`t want use a EZshaperWizard, where is able set up only one item for upload and one item for download. I wan to create various pipes as in Monowall.

Re: [pfSense Support] WARNING: R/W mount of denied. Filesystem is not clean - run fsck

2005-08-30 Thread Scott Ullrich
On 8/30/05, Tomas Hodan [EMAIL PROTECTED] wrote: it looks like it's not. such situations are very common, that firewall for what every reason will loose power. Yes, thats pretty obvious, isn't it? If it is not, then this is a bug. Scott

Re: [pfSense Support] WARNING: R/W mount of denied. File system is not clean - run fsck

2005-08-30 Thread Scott Ullrich
On 8/30/05, Bill Marquette [EMAIL PROTECTED] wrote: Interestingly the WRAP image is supposed to be mounted read-only anyway. Only /cf should normally get mounted r/w and then only for changes. Actually it writes RW during boot giving a chance for any now defunct packages to readjust the

Re: [pfSense Support] 81.4 load balance + carp

2005-08-31 Thread Scott Ullrich
On 8/31/05, Rodolfo Vardelli [EMAIL PROTECTED] wrote: Bill Marquette ha scritto: standard soekris 4801 + 2 lan traffic? in that moment zero and it happens only with carp+load balance with two boards When you say load balancing do you mean arp balancing? Scott

Re: [pfSense Support] 81.4 load balance + carp

2005-08-31 Thread Scott Ullrich
There was a bug in previous versions that would send the machine into a interrupt storm due to a route bug. Your on a later version than this so I really dont know what to say here. Scott On 8/31/05, Rodolfo Vardelli [EMAIL PROTECTED] wrote: Scott Ullrich ha scritto: sorry, I meant

Re: [pfSense Support] 81.4 load balance + carp

2005-08-31 Thread Scott Ullrich
Perhaps block this rule on the LAN interface before the ALL all? On 8/31/05, Rodolfo Vardelli [EMAIL PROTECTED] wrote: Scott Ullrich ha scritto: What was generating the traffic? it was a normal broadcast to port 137-138 in network 9.0 that for some strange reason pass to other network

Re: [pfSense Support] ftp support?

2005-09-02 Thread Scott Ullrich
Pureftpd is not intended for a firewall installation. It was created because I run a number of FTP servers and I want a clear and easy way to get them setup. Scott On 9/2/05, Dan Swartzendruber [EMAIL PROTECTED] wrote: Maybe I'm doing something wrong. I have the ftp proxy active, since if

Re: [pfSense Support] time zone of firewall log

2005-09-02 Thread Scott Ullrich
Does /etc/localtime exist? This is strange since we haven't made any changes to the TZ code since importing m0n0wall. On 9/1/05, Simon SZE-To [EMAIL PROTECTED] wrote: Hello, Seems that the time of System logs: Firewall is not following the time zone settings. I have tried config. time

  1   2   3   4   5   6   7   8   9   10   >