Re: [pfSense Support] Roadmap for 2.0?

2009-10-19 Thread Seth Mos
Eugen Leitl schreef: On Mon, Oct 19, 2009 at 11:16:51PM +1100, Morgan Reed wrote: I remember reading that a 2.0 RC was planned for end 2009. Not sure what the current plans are, judging from 1.2RC3 I have the impression the schedule has slipped a bit. (No criticism implied whatsoever, I'm

Re: [pfSense Support] Roadmap for 2.0?

2009-10-19 Thread Seth Mos
Nenhum_de_Nos schreef: On Mon, October 19, 2009 11:12, Seth Mos wrote: I have a machine I run at home for DSL, and can help testing 2.0. Is there any way to upgrade from 1.2.3RC1 and not loose all my data ? (I mean, the traffic info, rules, package data). Upgrades should work for the better

Re: [pfSense Support] Support for EP80579 Intel Tolapai proc

2009-10-22 Thread Seth Mos
bsd schreef: Hello, We have been provided with an embedded appliance that includes the latest EP80579 (Tolapai) and the default tests we have made showed that the processor is not recognized yet by default kernel. Do you know if there is any plan to add this proc to the list of supported HW

Re: [pfSense Support] pfsense IBM x3100 boot problem

2009-10-22 Thread Seth Mos
ozan ucar schreef: Hello All, I install pfsense 1.2.2 and full update on IBM x3100 server. I use 3 day and 4 and 5 success rebooting, dont problem. Try to configure the bios to set the disk mode from ahci to compatible or IDE. Regards, Seth

Re: [pfSense Support] broken route :( can i relay it?

2009-10-23 Thread Seth Mos
Chris Flugstad schreef: I cant reach an endpoint from 1 location, but can reach it from somewhere farther up the stream. It's not dying on my end. The admin for the other end is scratching his head. So. anyone ever setup a relay or a way to bounce specific traffic(only traffic going to this

Re: [pfSense Support] DHCP Leases Not Displaying?

2009-10-26 Thread Seth Mos
Tim Nelson schreef: Greetings all- I apologize if this problem has been fixed in a later version and I've not seen it yet... I have a box running pfSense 1.2.2 (Full version) and whenever a DHCP leases is handed out, there is a 50/50 chance it will actually show up in the Statis--DHCP Leases

Re: [pfSense Support] Multiple Filenames for Diskless Boot On LAN

2009-10-27 Thread Seth Mos
tort...@paradise.net.nz schreef: Hi Can multiple file names be specified for diskless boot on LAN functionality in pfSense on the same LAN? (e.g. thin clients and fat clients from same or different servers on same LAN) No, this is not possible. Regards, Seth

Re: [pfSense Support] Multiple Filenames for Diskless Boot On LAN

2009-10-27 Thread Seth Mos
Tortise schreef: - Original Message - From: Seth Mos seth@xs4all.nl To: support@pfsense.com Sent: Tuesday, October 27, 2009 8:08 PM Mmm well one can still do it one per LAN. I wonder if using VLANs might give more scope? Yes, when you create vlans in pfSense they become

Re: [pfSense Support] Site to Site VPN Error

2009-11-01 Thread Seth Mos
Koray AGAYA schreef: I Use Pfsense 1.2.2 and Error is below Can you help me please ! Oct 28 09:55:28 racoon: WARNING: /var/etc/racoon.conf:3: 0660 admin port support not compiled in I don't believe this is 1.2.2-RELEASE, it does not have admin support compiled into racoon, neither

Re: [pfSense Support] throughput, haproxy

2009-11-03 Thread Seth Mos
Lenny schreef: But I would really like to ask again, as this is very important: will replacing the PCI-X NIC with PCI-e one give some boost in performance? Unlikely, there is little reason to switch. The theoretical bandwidth cases are not too helpful. The intel dual port pci-e cards are

Re: [pfSense Support] DHCP question

2009-11-06 Thread Seth Mos
Nathan Eisenberg schreef: Any easy way of telling how many DHCP leases are used/remaining in the pool? Depends on the situation, if on a carp setup with failover it is pretty hard to do. On a single install the diag dhcp leases page is your best indication. If you set a range from 50-100,

Re: [pfSense Support] throughput, haproxy

2009-11-19 Thread Seth Mos
No you should not worry with your level of traffic. But as soon as you cross 500Mb/s you should not trust RRD any more. I was gradually increasing bandwidh usage using iperf udp -b option: 300Mb/s - ok, 400Mb/s - ok, 500Mb/s - ok, 600Mb/s - ooops -( In pfSense 2.0 we use the 64 bit counters

Re: [pfSense Support] Viewing RRD Graphs causes system lock-up or reboot.

2009-11-30 Thread Seth Mos
darkf...@comcast.net schreef: Going to the RRD Graphs page will lock up the pfSense box (rare), or will cause it to reboot (typical). Sounds like you have a faulty cpu cooler or a bad stick of ram. for the last 6 months and 18 months. So perhaps during a power failure These are the

Re: [pfSense Support] Weird msg in pfsense logs

2009-11-30 Thread Seth Mos
Gabriel - IP Guys schreef: Dear All, kernel: arp: 19.19.19.19 is on le2 but got reply from 00:01:02:03:04:05 on le1 You have a system moving from one interface to another. That or you have a cable loop. Also possible is that somebody created a network bridge under windows XP between 2

Re: [pfSense Support] Weird msg in pfsense logs

2009-11-30 Thread Seth Mos
Gabriel - IP Guys schreef: suppress ARP messages when interfaces share the same physical network That surpresses the arp messages, just like it should. Will this mean that packets now get routed, or will they still get dropped? Dropped.

Re: [pfSense Support] Old Firebox question

2009-12-03 Thread Seth Mos
Hi, You mean the one they had on the front of the watchguard firebox 2 and 3 models? They replicated those in the wsm ui. In the Firebox X series they have a sort of star interpretation instead of the triangle. You could flip the role of the primary lan and wan interface on that one to show a

Re: [pfSense Support] ipsec vpn with overlapping LAN networks

2009-12-08 Thread Seth Mos
Hi, The quick and dirty answer is don't do it. It won't work. Why are you using the same /16 on both ends? You'll need to break it up into smaller parts, it will require renumbering any one of them. If you do it in a smart way you can still use a summary to refer to all your network.

Re: [pfSense Support] Issue upgrading from 1.2.3-RC3 to RELEASE

2009-12-11 Thread Seth Mos
John Mitchell schreef: No worries, thanks for your help, I don't suppose there is any way to backup the RRD Graph data is there? (More specifiically the Traffic portion). Trying to get a years worth of data going ;) Copy off the contents of /var/db/rrd Regards, Seth Many many thanks

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-11 Thread Seth Mos
Chris Buechler schreef: On Fri, Dec 11, 2009 at 11:27 AM, Eugen Leitl eu...@leitl.org wrote: On Fri, Dec 11, 2009 at 09:31:38AM -0600, J.D. Bronson wrote: I just did the upgrade via the web GUI.. it went down w/o a hitch... Same thing here. One thing that was a potential problem in the past

Re: [pfSense Support] hybrid storage?

2009-12-11 Thread Seth Mos
I might be missing the boat here, but what about using a 2.5 SSD instead of flash + normal HD? That way you get the benefit of solid state, plus you have the space performance for a regular file system so you can run all the packages you want. Granted, SSDs aren't the cheapest things around,

Re: [pfSense Support] hybrid storage?

2009-12-11 Thread Seth Mos
apt@gmail.com schreef: SSD woul definitely bring the power, speed sound benefits of flash. It only lacks the perfect recovery of a read-only root fs. A big improvement over spinning media nevertheless. The writes should be fine really, worst case is that it will fail to write at some

Re: [pfSense Support] 2 Wans Failover

2009-12-14 Thread Seth Mos
2.I connected the static IP to the ETH1 of the soekris and set it in the WAN interface,and it is working fine,but now I need to set a failover, let the pfsense prefers WAN2 when WAN fails. 3.I have set the PPPoe in the router,and it works,I connected the router the ETH2 interface in the

Re: [pfSense Support] LAN to DMZ through the public IP on NAT 1:1

2009-12-14 Thread Seth Mos
charlyc...@yahoo.com.ar schreef: Hi, I have this configuration: WAN --- 1.2.3.0/26 || --- DMZ 192.168.1.0/24 | pfsense V1.2.2 | WAN2 --- 3.2.1.0/25 || --- LAN 10.1.1.0/24 I have to be able to connect from the LAN to the DMZ through the

Re: [pfSense Support] potential pfsense hardware

2009-12-15 Thread Seth Mos
Paul Mansfield schreef: On 14/12/09 23:47, Jeppe Øland wrote: As for the PCIe wireless card: it's a MSI brand card, using a Ralink NIC. (MS-6894, Ralink chip: RTL8187SE) I guess thats a RealTek wireless card ... probably next to useless for pfSense or? realtek != ralink I've previously have

Re: [pfSense Support] Windows Network functionality/auto-sensing lacking.

2009-12-15 Thread Seth Mos
Op 15 dec 2009, om 22:03 heeft li...@mgreg.com het volgende geschreven: Got a small issue here. Basically, I replaced a DLINK router with a base pfSense setup. Now, although all of my machines can ping one another, they don't seem to be auto-sensing one another -- no machines show up in

Re: [pfSense Support] Watch Chris and myself on FLOSS Weekly Live at 4:30 PM EDT

2009-12-17 Thread Seth Mos
Cool! I caught the last 30 minutes. Thanks for the mention. is there how to download the whole video ? I searched the site but no luck for me ... It is Episode 101 for Floss Weekly and will be available on Christmass Eve. http://www.twit.tv/FLOSS Regards, Seth

Re: [pfSense Support] Advanced outbound NAT -- Auto firewall rules on or off?

2009-12-17 Thread Seth Mos
Gabriel - IP Guys schreef: If I enable Advanced outbound NAT -- which according to the guide Pfsense MultiWAN Howto, http://mirror.qubenet.net/mirror/pfsense/tutorials/policybased_multiwan/ policybased_multiwan.pdf I just looked at it. It's entirely correct. If I am adding rules, and I

Re: [pfSense Support] RC3 to RELEASE - Verify

2009-12-17 Thread Seth Mos
Op 17-12-2009 11:35, Paul Mansfield schreef: has anyone upgraded a pfsense cluster running 1.2.2-release to 1.2.3? Yes. am using many CARP addresses on WAN and LAN ports, IPSEC, OpenVPN, and advanced outbound nat. I am using multiple WAN connections, 380 IPsec vpn tunnels, roughly a

Re: [pfSense Support] NAS/SAN

2009-12-19 Thread Seth Mos
Op 19 dec 2009, om 22:34 heeft Glenn Kelley het volgende geschreven: is there a simple way to add an ISCSI or NAS storage to this system? For systems with limited storage - I do not see a way of doing this out of the box I am missing the context here, why would you need it? Regards,

Re: [pfSense Support] Wan interface Error

2009-12-22 Thread Seth Mos
Op 23-12-2009 8:19, Koray AGAYA schreef: I use dashboard Have a error WAN Interfaces Statistics. I analysed system log but I dont view anything What is the problem Where can I learn What is Problem Where can I look ? This refers to physical interface errors. Collisions on a duplex mismatch,

Re: [pfSense Support] Preload upgrade

2009-12-23 Thread Seth Mos
Op 23-12-2009 14:20, Atkins, Dwane P schreef: Is there a way to preload an upgrade on a device and then have it do it’s install and reboot later? In other words, can I copy the new release to a particular directory on a pfSense device and then ssh and execute script and then have it reboot with

Re: [pfSense Support] Re: embedded install on a Pentium III system

2009-12-28 Thread Seth Mos
Op 28-12-2009 16:18, Ugo Bellavance schreef: On 2009-12-28 04:18, Michel Servaes wrote: My big question - how would I tell which network interface will be the LAN, to run the WebGUI wizard on... (on an Alix, it's the first one - but how can I tell on this P3-600 (old compaq) board, which

Re: [pfSense Support] Mailserver on OPT1 Bridged with WAN - port 25 filtered

2009-12-29 Thread Seth Mos
Op 29 dec 2009, om 20:05 heeft Mark Street het volgende geschreven: Hi, I ran nmap from remote servers and sure enough port 25 is not accessible. I set rules on the WAN to allow SMTP to pass through to the external address on OPT1 and still no pass. Running netstat on the mail host

Re: [pfSense Support] Mailserver on OPT1 Bridged with WAN - port 25 filtered

2009-12-29 Thread Seth Mos
get confused and traffic will be dropped because it is not hitting the states. That's normally more of a issue on normal routed and NAT configs though. I recommend a dose of Chris. Cheers, Seth Thanks, - Chris Buechler c...@pfsense.org wrote: On Tue, Dec 29, 2009 at 2:26 PM, Seth

Re: [pfSense Support] which image?

2010-01-05 Thread Seth Mos
Op 5 jan 2010, om 17:02 heeft David Newman het volgende geschreven: For pfSense, I *think* I want the 512-Mbyte embedded image, but am unsure about what changes, if any, the installation requires. (The docs for installing/upgrading the embedded images seem oriented toward CF cards and I

Re: [pfSense Support] openvpn extra options loses EOL

2010-01-08 Thread Seth Mos
Op 8-1-2010 18:21, Paul Mansfield schreef: On 08/01/10 16:21, Tim Nelson wrote: - Paul Mansfieldit-admin-pfse...@taptu.com wrote: if you put multiple lines of configuration in an openvpn server config, all the end of lines are lost and the whole lot is run together on one line when you

Re: [pfSense Support] New pfsense developer

2010-02-08 Thread Seth Mos
Hi Vinod, If you are familiar with a unix based system, be that linux or something else, you should have no issue getting around to develop. The methods differ wildly though. I personally develop pretty much all of my code on the test box I have myself. I then create patches from that and

Re: [pfSense Support] 32-bit counter limitation

2010-02-11 Thread Seth Mos
Op 12-2-2010 6:47, David Burgess schreef: What would it take to get counters on the interface page to not roll over at 4GB? Is that something that will just happen when PFS moves to a 64-bit platform? If so, is that a change that will happen with 2.0? We use 64 bit counters in 2.0 for the

Re: [pfSense Support] Newbie questions

2010-02-12 Thread Seth Mos
Op 12-2-2010 11:05, Varga Levente schreef: Hello! How usable is the 2.0 beta version? I'm asking because I'm using 1.2.3 at the moment but there are a few things that are included (like XAuth for VPN) in the 2.0 version which I would love to use. It's pretty usable, just don't attempt to use

Re: [pfSense Support] hardware upgrade - keep all history data

2010-02-17 Thread Seth Mos
Op 17-2-2010 12:56, Hans Maes schreef: Hello, I remember reading about this somewhere but can't seem to find it anymore through google or the forum. There have been quite a number of posts on the forum with regards to this. And I've seen a few on the list as well. see the files in

Re: [pfSense Support] hardware upgrade - keep all history data

2010-02-17 Thread Seth Mos
Op 17-2-2010 13:47, Hans Maes schreef: Seth Mos wrote: Which is why I was wondering wheter copying over the entire /var directory would break things. Just don't copy the var/run etc, just the things you want. Tar is your friend here. Regards, Seth

Re: [pfSense Support] Block URLs with HTTPS

2010-02-24 Thread Seth Mos
Op 24-2-2010 10:48, Abdulrehman schreef: I have pfsense 1.2.2 with squid in transparent proxy mode. I have blocked facebook with squid ACLs. But facebook is accessible with https. I checked the logs and found that only port 80 is being redirected to my squid port which is 3128. Please tell me

Re: [pfSense Support] Low-cost VPN endpoint compatible with pfSense

2010-03-17 Thread Seth Mos
Op 17-3-2010 13:02, Chris Bagnall schreef: Greetings list, One of our clients has a requirement for a low-cost ADSL modem/router that'll act as a VPN endpoint (IPSec or OpenVPN) to a central pfSense node (at their head office). Ordinarily I'd just recommend small pfSense nodes like the ALIX

Re: [pfSense Support] Low-cost VPN endpoint compatible with pfSense

2010-03-17 Thread Seth Mos
Op 17-3-2010 13:34, Jim Pingle schreef: On 3/17/2010 8:02 AM, Chris Bagnall wrote: Greetings list, I have heard there are also some ADSL modem/routers that ATT is distributing to its business customers which can do IPsec, probably something from Efficient/Siemens or 2Wire. I've looked at a

Re: [pfSense Support] Crystalfontz CFA-635 USB LCD

2010-03-29 Thread Seth Mos
Op 26-3-2010 14:29, Philippe Lang schreef: Hi, I'm trying to install a Crystalfontz CFA-635 USB LCD, but apparently, I'm doing something wrong. I'm using pfSense 1.2.3, and lcdproc package v.0.5.2. When plugging the lcd to the USB port 5 (internal port), lcd is well recognized: Kernel:

Re: [pfSense Support] CPU Throttle

2010-04-01 Thread Seth Mos
The cpu will automatically throttle when the cooler fails to prevent a burnout. You should also see a message when it does. Regards, Seth Op 1-4-2010 18:38, J.D. Bronson schreef: I have noticed when I boot up pfsense 1.2.3, I see stuff like this on dmesg: kernel: acpi_throttle0: ACPI CPU

Re: [pfSense Support] 1.2.3-release rebooting

2010-04-12 Thread Seth Mos
Op 12-4-2010 17:56, Charles Goldsmith schreef: The computer its running on is about 2 years old, a Cyrix 1ghz with Oh noes, a Cyrix. I thought they all died in 1997. I've seen no end of problems with those with either windows or linux. But then again, intel chips and cheap SiS chipsets were

Re: [pfSense Support] XBOX live not working with public IPS on MY LAN

2010-05-12 Thread Seth Mos
Op 12-5-2010 3:13, Chris Flugstad schreef: Cool. I didnt think anything special would have to be done. Its prolly a personal problem that the client isn't hookin up with there freinds on xbox live. i havent a clue. never had a problem like this before Like Chris said, you should have a rule

Re: [pfSense Support] root not found on cold boot 2.0

2010-06-10 Thread Seth Mos
Op 10-6-2010 3:26, David Burgess schreef: Hardware is a Soekris net5501 bios 1.33c with a Lexar 2G CF and no added hardware. I suppose the issue is more software than hardware related though, since the boot loader is found and a reboot functions as expected. Intruiging, I have a Soekris

Re: [pfSense Support] root not found on cold boot 2.0

2010-06-10 Thread Seth Mos
Op 10-6-2010 9:29, David Burgess schreef: On Thu, Jun 10, 2010 at 1:21 AM, Seth Mosseth@dds.nl wrote: I just got mine back from a 7/8 repair, so I'm going to assume they did their job and that's not my issue at this point. What I was seeing before the repair was the disk light coming on

Re: [pfSense Support] Bandwdith usage since start of month?

2010-07-18 Thread Seth Mos
Hi, Op 18 jul 2010, om 09:14 heeft David Burgess het volgende geschreven: On Wed, Jul 14, 2010 at 1:06 AM, David Burgess apt@gmail.com wrote: July 23: Same thing, package will neither function nor delete. I see this at the bottom of the page when trying to remove the package, even

Re: [pfSense Support] Bandwdith usage since start of month?

2010-07-19 Thread Seth Mos
Op 19-7-2010 7:34, David Burgess schreef: On Sun, Jul 18, 2010 at 10:30 AM, Seth Mosseth@dds.nl wrote: So at first glance the RRD Summary could be reconcilable with my ISP's figures, while the RRD Graph numbers cannot be. Intruiging, I'll have to look into it. Interesting that RRD

Re: [pfSense Support] Bandwdith usage since start of month?

2010-07-19 Thread Seth Mos
Op 19-7-2010 8:42, David Burgess schreef: On Mon, Jul 19, 2010 at 12:34 AM, Seth Mosseth@dds.nl wrote: Except the monthly graph shows a gap from the previous week when looking at the current month. Screenshot in the forum: http://forum.pfsense.org/index.php/topic,26789.0.html No

Re: [pfSense Support] Finding patch rejects...

2010-07-25 Thread Seth Mos
no, if it finds any it will stop. Regards, Seth Op 25 jul 2010, om 03:01 heeft support-pfsense het volgende geschreven: Hi all when i follow the document http://devwiki.pfsense.org/DevelopersBootStrapAndDevIso install freebsd 8.1 , update source, etc then run #./set_version.sh

Re: [pfSense Support] problem with 2.0BETA[34] and usb

2010-08-04 Thread Seth Mos
Hi, Op 3-8-2010 20:16, Nenhum_de_Nos schreef: hail, all tests now are on BETA4. anyone has any clue ? this is a via mini itx crusoe based mobo. Have you considered a bios update? Regards, Seth - To unsubscribe,

Re: [pfSense Support] PFSENSE 2.0

2010-08-05 Thread Seth Mos
Hi, Op 4-8-2010 17:40, Curtis Maurand schreef: On 8/3/2010 11:15 AM, Eugen Leitl wrote: You could probably mitigate some of the writes to disk by having the logging sent to a syslog server elsewhere inside the house that is using traditional write media. That should lengthen the life of the

[pfSense Support] iPad ssl vpn client

2010-08-05 Thread Seth Mos
Hello, Just inquiring here, does anybody already know of a SSL vpn client that works on the Apple iPad devices? Viscosity on the Mac works great, but that doesn't apply to iOS. I see mentions of a Cisco and Juniper client, but no idea if these can be made to work with pfSense. Regards,

Re: [pfSense Support] Monitoring pfSense

2010-08-10 Thread Seth Mos
Hi, I still need to write some curl code to monitor my own pfSense 2.0 systems at work. Hopefully I'll get round to that tomorrow and i'll post some PHP curl code to do so. Regards, Seth Op 10 aug 2010, om 17:42 heeft Chris Buechler het volgende geschreven: On Tue, Aug 10, 2010 at 7:59

Re: [pfSense Support] Help with Wireless Setup

2010-08-11 Thread Seth Mos
Op 11-8-2010 6:12, Chris Buechler schreef: On Tue, Aug 10, 2010 at 11:10 AM, Chris TheEndch...@theendrecords.com wrote: Hi, You can try different settings on the card, like if you're using channel 'auto', try picking a specific channel and see if it persists. Also may want to try 2.0 as it

Re: [pfSense Support] Multi WAN - Failover doubts.

2010-08-11 Thread Seth Mos
Op 11-8-2010 7:09, Chris Buechler schreef: On Tue, Aug 10, 2010 at 5:08 PM, Fabricio Ferreiragu...@bol.com.br wrote: Thanks Everyone! Actually I made it work, but not using the same monitoring address on both interfaces. Yeah you can't do that, as the monitor IP always is forced out only

Re: [pfSense Support] IPSec dies after more reconnects

2010-08-11 Thread Seth Mos
Op 11-8-2010 9:17, Fuchs, Martin schreef: Hi ! I have 3 ipsec tunnels. One of these endpoints has bad wan-connectivity, so it connects some times day. This problem exists since a week. I had to restart my raccoon-service on the central firewall every day, because it is stopped there ? I

Re: [pfSense Support] FW: Issues after update to 1.2.3-RELEASE

2010-08-12 Thread Seth Mos
Hi, Do you have a firewall rule that allows traffic on the IPsec interface under firewall rules? Regards, Seth Op 12 aug 2010, om 20:17 heeft Austin G. Smith het volgende geschreven: I just performed an update on a 1.2.0-RELEASE-FULL firewall last night. Today we started having

Re: [pfSense Support] Large Aliases

2010-08-23 Thread Seth Mos
Hi, Op 23 aug 2010, om 21:08 heeft Jim Cheetham het volgende geschreven: Perhaps there's another way; what are you doing this for? Instead of basing rules on a large set of aliases that you have to update regularly, is there some other characteristic you can group your rules by? (AKA

Re: [pfSense Support] Appliance Recommendation for 100 Mbps (DOCSIS 3.0) Service

2010-09-01 Thread Seth Mos
Hi, Op 1-9-2010 17:00, Michael Riglin schreef: have enough CPU power to support 100 Mbps and above. (Quality and future-proofing is more important than cost.) Well, if you search the forum for the Lanner FW7535 you should be able to find the benchmarks. This firewall platform is sold with

Re: [pfSense Support] Benchmark tool

2010-09-08 Thread Seth Mos
Hi, Op 7 sep 2010, om 21:24 heeft bsd het volgende geschreven: Results are somewhat similar… My main question is why when filtering is enabled do we loose 75% of the throughput… When i benchmarked the atom D510 I got in the office last week with 6 intel nics I had 480mbit throughput

Re: [pfSense Support] BGP

2010-09-18 Thread Seth Mos
FYI, in pfSense 2.0 we stopped doing that and became a bit smarter about it. But hey, it was a version 1 product. Regards, Seth Op 18 sep 2010, om 17:21 heeft Nathan Eisenberg het volgende geschreven: The interface rebuilds was an absolute killer for me. I've had to move our shared

Re: [pfSense Support] Re: Allow Traffic Between Interfaces

2010-09-20 Thread Seth Mos
Op 20-9-2010 1:16, Dave Warren schreef: In message aanlktimhp=h08xsyt=bvkel4vhi_u2zroxp9xjxnm...@mail.gmail.com Chris Buechlercbuech...@gmail.com was claimed to have wrote: Firewall Aliases. You should really get a copy of the book. :) http://pfsense.org/book Kindle? I like my dead tree

Re: [pfSense Support] Proxy Question

2010-10-06 Thread Seth Mos
Op 5-10-2010 20:58, Anil Garg schreef: At my work, I have to enter: proxy.sucks.com:80 under the ToolsOptionsnetworkconnectionssettings I would suggest setting up a proxy wpad host at work that provides the clients with that information. Setup a wpad.sucks.com website that has a wpad.dat

Re: [pfSense Support] Dual WAN + Firewall Redundancy + UPS Redundancy (?) at entrance

2010-10-08 Thread Seth Mos
I'll have 2 firewalls, and 2 UPS's one for each firewall. As suggested before, cross the power supply cords between the 2 ups's. If you have the option of 2 power feeds in your DC then put each UPS on one specific. Alternatively there are great breaker strips that take 2 feeds and can

Re: [pfSense Support] Dual WAN + Firewall Redundancy + UPS Redundancy (?) at entrance

2010-10-11 Thread Seth Mos
Hi again, Op 11 okt 2010, om 20:23 heeft Andy Graybeal het volgende geschreven: Andrew, From reading the PFSense book, I have now gathered that, like you just said, having two ADSL providers is not a good way to go about redundancy. In my case, one ADSL connection is free.. and I'm

Re: [pfSense Support] Dual WAN + Firewall Redundancy + UPS Redundancy (?) at entrance

2010-10-11 Thread Seth Mos
Hi, Op 11 okt 2010, om 21:22 heeft Jim Cheetham het volgende geschreven: You'd be better off explicitly floating the idea of an RD test rig, where you can play with things in order to prove which will be best for production later ... -jim On that point, I rebuilt and duplicated my

Re: [pfSense Support] pfSense 2.0 and SpamAssassin

2010-10-14 Thread Seth Mos
Hi, Yeah if you can run VMware ESXi on the box and then run whatever VMs you need, that's a good solution. Or you can look at the jailctl package and run a full jail for spamassassin and whatever else you want to throw on it. This is in production at one site atleast, a all in one wonder with

Re: [pfSense Support] pfSense 2.0 and SpamAssassin

2010-10-14 Thread Seth Mos
Op 13-10-2010 23:55, James Bensley schreef: Thank you too all for your input. I think running two VMs on top of the host OS (although it would be nice) is too much overhead for my liking given the spec of the box. I like the sound of jailctl, I will give this a go and report back my findings ;)

Re: [pfSense Support] Enclosure recommendations for a Mini ITX Motherboard

2010-10-16 Thread Seth Mos
Hi, Op 16 okt 2010, om 03:49 heeft Mehma Sarja het volgende geschreven: This is getting interesting, someone on the list mentions that 2.5 drives are not reliable for 24x7x365 situations - so are you using a 3.5 drive? My setup is at home as well and it is just not fan noise - we see MUCH

Re: [pfSense Support] Simply Query: Custom Definitions in pfSense?

2010-10-21 Thread Seth Mos
Op 21-10-2010 15:20, James Bensley schreef: Hello All :D You are looking for aliases. Seth - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial

Re: [pfSense Support] Cannot achieve 100 mbps Full Duplex (C2D, Intel NICs)

2010-10-21 Thread Seth Mos
Hi, Op 21 okt 2010, om 20:06 heeft Christian Borchert het volgende geschreven: I have a Dell Optiplex 745 SFF (Core 2 Duo) with an Intel PRO/1000 MT Dual Port Server Adapter What might be happening here is the somewhat peculiar setup of the pci slot(s) on the Dell optiplex machines. For

[pfSense Support] IPv6 support

2010-10-31 Thread Seth Mos
Hello, I've been working on IPv6 support for pfSense over the past week and have some questions on the importance off certain bits. Ofcourse I can't do everything at once but I can certainly work in some order. What I have now does: native ipv6 static on wan and lan. Route announcement on LAN

Re: [pfSense Support] IPv6 support

2010-10-31 Thread Seth Mos
Op 31 okt 2010, om 21:16 heeft Nathan Eisenberg het volgende geschreven: That's all I need - interface addresses and firewall rules! Thank you! Thank you! Thank you! Come to Seattle, and I will buy you a beer! When can I have it? :D Right now, gitsync against my git repo and it should

Re: [pfSense Support] IPv6 support

2010-10-31 Thread Seth Mos
Op 31 okt 2010, om 21:16 heeft Nathan Eisenberg het volgende geschreven: That's all I need - interface addresses and firewall rules! Thank you! Thank you! Thank you! Come to Seattle, and I will buy you a beer! When can I have it? :D Right now, gitsync against my git repo and it should

Re: [pfSense Support] IPv6 support

2010-10-31 Thread Seth Mos
Oops, forgot. It's the thread, not the exact post. But that should get you started. http://forum.pfsense.org/index.php/topic,26469.0.html Regards, Seth Op 31 okt 2010, om 21:41 heeft Nathan Eisenberg het volgende geschreven: The entire instruction for getting my code are in the forum post,

Re: [pfSense Support] Assign custom Gateway

2010-11-05 Thread Seth Mos
Hi Ryan, Sorry, no, that is currently not possible. I doubt there is much demand for this feature. Regards, Seth Op 5 nov 2010, om 22:31 heeft Ryan Rodrigue het volgende geschreven: From: Ryan L. Rodrigue [mailto:radiote...@aaremail.com] Sent: Friday, November 05, 2010 9:16 AM To:

Re: [pfSense Support] LCD driver for TEAK 3035S

2010-11-10 Thread Seth Mos
Op 10-11-2010 10:39, bsd schreef: Hello, I am reselling hardwawre on my website http://www.osnet.eu/ One of my client has requested to have the ability to use the LCD display for this device. Hardware manufacturer has provided me an application in C which allows communication with the LCD

Re: [pfSense Support] how to manage 2 subnets for LAN ?

2010-11-18 Thread Seth Mos
Hi, As we use an Alix 2d3 board with 3 ethernet interfaces, there is one free at now : could we use this OPT interface to manage backbone network, with an address in its subnet 192.168.1.0/24, and put an address from 192.168.2.0/24 subnet on the LAN interface to serve clients, provided these

Re: [pfSense Support] RRD graphs / Quality - Shows 2 WANs

2010-11-22 Thread Seth Mos
Op 22-11-2010 9:03, Jeppe Øland schreef: $ ls -l /var/db/rrd/ total 5000 -rw-r--r-- 1 nobody wheel 47608 Nov 22 00:01 WAN-quality.rrd -rw-r--r-- 1 nobody wheel 194776 Nov 22 00:01 ipsec-packets.rrd -rw-r--r-- 1 nobody wheel 194776 Nov 22 00:01 ipsec-traffic.rrd -rw-r--r-- 1 nobody

Re: [pfSense Support] LCD driver for TEAK 3035S

2010-11-22 Thread Seth Mos
Op 22-11-2010 10:43, bsd schreef: Hello Gavin, From my point of view (and as far as I am informed) you will have to build your own LCD driver. As a reseller of this hardware, I was in touch with the manufacturer, and I think you will have to use the provided C program and example (provided

Re: [pfSense Support] MAC based Access Control

2010-11-29 Thread Seth Mos
Op 29-11-2010 10:51, James Bensley schreef: I think it would be an useful feature to have; if you have a pfsense box at the end of a leased line, private virtual circuit or vpn, it would be good to check the device at the other has x MAC address to try and rule out any security features like a

Re: [pfSense Support] Embedded hardware recommendation - Fan-less andmany NIC ports

2010-12-17 Thread Seth Mos
There are pictures and a thread of mine on the forum for the dual core 7535 unit with 6 ge ports. It's currently in production to full satisfaction. Regards, Seth Op 17 dec 2010, om 04:26 heeft Kevin Tollison het volgende geschreven: I had a quote for the 7535 a few months ago. $459 IIRC

Re: [pfSense Support] pfSense 2.0 BETA4 : IPv6?

2010-12-20 Thread Seth Mos
There is a post in the forum, to my git branch and instructions for support on 2.0 BETA http://iserv.nl/files/pfsense/ipv6/ I'm currently using it in production on a carp cluster and appears to work fine for basic firewalling. Regards, Seth Op 20 dec 2010, om 20:19 heeft Bart Grefte het

Re: [pfSense Support] pfSense 2.0 BETA4 : IPv6?

2010-12-21 Thread Seth Mos
Op 21-12-2010 1:52, Sean Cavanaugh schreef: after that, it asks if I want to sync with master which doesn’t do anything. It says press enter if done. Press enter. ;-) The procedure for entering custom urls is that you enter it the 1st time, accept and then press enter to signal it to start.

Re: [pfSense Support] IPsec tunnels and failover.

2010-12-22 Thread Seth Mos
Op 22-12-2010 11:22, Vincent Hoffman schreef: At work we've a couple of servers running a synced pfsense cluster with IPsec tunnels to 2 other pfsense firewalls. While I can see that CARP syncs the configs across within the cluster I cant find anything that specifically says that if the primary

Re: [pfSense Support] pfSense 2.0 BETA4 : IPv6?

2010-12-22 Thread Seth Mos
Op 21-12-2010 22:50, Sean Cavanaugh schreef: ?ok. I got past the gitsync by hitting enter and letting it actually continue. now after the sync I get the nice error Parse error: syntax error, unexpected T_SL in /etc/inc/vslb.inc on line 291 Oops my bad. I merged up with the current 2.0 code

Re: [pfSense Support] IPsec tunnels and failover.

2010-12-22 Thread Seth Mos
Op 22-12-2010 16:15, Vincent Hoffman schreef: I'm already using a CARP address as the VPN endpoint. So the failover will fire up racoon on the backup node, or do i need to have racoon started on the backup node already and it just wont negotiate until its master for that CARP interface? The

Re: [pfSense Support] pfSense 2.0 BETA4 : IPv6?

2010-12-23 Thread Seth Mos
Hi Sean, Op 23-12-2010 14:01, Sean Cavanaugh schreef: ?-Original Message- From: Sean Cavanaugh Sent: Wednesday, December 22, 2010 7:39 PM To: support@pfsense.com Subject: Re: [pfSense Support] pfSense 2.0 BETA4 : IPv6? Verified with wireshark that the DHCPv6 requests are going out

Re: [pfSense Support] Auto-update Check fails

2010-12-24 Thread Seth Mos
Op 24-12-2010 13:03, Eugen Leitl schreef: On Thu, Dec 23, 2010 at 10:42:34PM -0500, Jim Pingle wrote: This should be working again now. If it doesn't, let me know. There was an issue with the update server, but it should be fixed now. No 2.0 as Xmas present this year? I've been upgrade

Re: [pfSense Support] Blank RRD traffic graphs with VLANs in router mode

2011-01-11 Thread Seth Mos
Op 11-1-2011 18:00, Lan Tran schreef: ello, I'm running version 2.0-BETA5 (amd64) built on Fri Jan 7 02:54:00 EST 2011 and builtin RRD traffic graphs are blank when pfSense is acting as a router (Disable all packet filtering option is checked). The graphs work fine when I run it as firewall.

Re: [pfSense Support] ftphelper in 2.0-Beta5

2011-01-16 Thread Seth Mos
Hi, Op 16 jan 2011, om 18:16 heeft Christoph Hanle het volgende geschreven: On 16.01.2011 17:55 Seth Mos wrote: I do know that passive FTP on a router without NAT is currently a issue. Active works. Regards, Seth THX, changing to active ftp did the job, but this wuergaround

Re: [pfSense Support] MHz myth?

2011-01-17 Thread Seth Mos
Op 18-1-2011 4:32, David Burgess schreef: Putting encryption and the various pfsense packages aside, can anybody tell me (based on theory and/or experience) what kind of comparative routing throughput I could expect to see from say an Athlon X2, Athlon II X2, Phenom 2, Atom D510, Pentium D,

Re: [pfSense Support] pfSense routing

2011-01-21 Thread Seth Mos
Op 21-1-2011 13:19, Danny schreef: Yes. ip route 0.0.0.0 0.0.0.0 FasthEthernet 0/0 err, no, there should be route to the public netblock you are using on the LAN behind pfsense, pointing to the WAN of pfSense which will be in the Cisco LAN subnet. Also note that Ciscos have really long arp

Re: [pfSense Support] outgoing gw to be vip

2011-01-24 Thread Seth Mos
Op 24-1-2011 14:39, Shibashish schreef: Hi, I have a mail server running on a vip which is natted to a real-lan ip. I have added the VIP in load-balancer option and added my lan server as the virtual-server-pool. But now my outgoing traffic is taking the ip of firewall as the firewall is its

Re: [pfSense Support] Got ipv6 working

2011-01-26 Thread Seth Mos
Op 26 jan 2011, om 21:54 heeft Charles N Wyble het volgende geschreven: Now I want to utilize my /48 and do prefix delegation, multiple vlans etc. Anyone doing this with pfsense? Also is anyone doing firewalling of v6 in pfsense? Does the pfsense book cover any of this? I saw your post on

  1   2   >