[pfSense] Backup/Restore to another router

2015-10-26 Thread Edward Holcroft
Hello list

I am setting up my second pfSense box, with a view to eventually replacing
20 Pelink Balance routers on my network.

The first one works great and I have IPSec tunnels working between it and
all the Peplink sites. Now since I am lazy, I was hoping to be able to
backup the IPSec tunnels on the first one and simply restore it on the
second and subsequent routers, to save myself some effort. Naturally I
edited the content of the xml file to match the new router. However, I have
now noticed that there is an entry for each tunnel called  which
is, well, unique.

Does this mean I have to create each and every tunnel manually? Or can I
use the existing backup with that same uniqid on a different router? Or is
there some way to generate uniqid's if that's what it requires?

cheers
ed

-- 
Edward Holcroft | Madsen Kneppers & Associates Inc.
11695 Johns Creek Parkway, Suite 250 | Johns Creek, GA 30097
O (770) 446-9606 | M (770) 630-0949

-- 
MADSEN, KNEPPERS & ASSOCIATES USA, MKA Canada Inc. WARNING/CONFIDENTIALITY 
NOTICE: This message may be confidential and/or privileged. If you are not 
the intended recipient, please notify the sender immediately then delete it 
- you should not copy or use it for any purpose or disclose its content to 
any other person. Internet communications are not secure. You should scan 
this message and any attachments for viruses. Any unauthorized use or 
interception of this e-mail is illegal.
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] Backup/Restore to another router

2015-10-26 Thread Chris Buechler
On Mon, Oct 26, 2015 at 12:26 PM, Edward Holcroft  wrote:
> Hello list
>
> I am setting up my second pfSense box, with a view to eventually replacing
> 20 Pelink Balance routers on my network.
>
> The first one works great and I have IPSec tunnels working between it and
> all the Peplink sites. Now since I am lazy, I was hoping to be able to
> backup the IPSec tunnels on the first one and simply restore it on the
> second and subsequent routers, to save myself some effort. Naturally I
> edited the content of the xml file to match the new router. However, I have
> now noticed that there is an entry for each tunnel called  which
> is, well, unique.
>
> Does this mean I have to create each and every tunnel manually? Or can I
> use the existing backup with that same uniqid on a different router?

That's an identifier that only has to be unique to the system it's
running on, so you can use the same ones on different systems. Just
make sure not to duplicate them on the same system.


> Or is
> there some way to generate uniqid's if that's what it requires?
>

It's just the output of PHP's uniqid() if you want to generate them.
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


Re: [pfSense] Backup/Restore to another router

2015-10-26 Thread WebDawg
On Mon, Oct 26, 2015 at 12:26 PM, Edward Holcroft 
wrote:

> Hello list
>
> I am setting up my second pfSense box, with a view to eventually replacing
> 20 Pelink Balance routers on my network.
>
> The first one works great and I have IPSec tunnels working between it and
> all the Peplink sites. Now since I am lazy, I was hoping to be able to
> backup the IPSec tunnels on the first one and simply restore it on the
> second and subsequent routers, to save myself some effort. Naturally I
> edited the content of the xml file to match the new router. However, I have
> now noticed that there is an entry for each tunnel called  which
> is, well, unique.
>
> Does this mean I have to create each and every tunnel manually? Or can I
> use the existing backup with that same uniqid on a different router? Or is
> there some way to generate uniqid's if that's what it requires?
>
> cheers
> ed
>
> --
> Edward Holcroft | Madsen Kneppers & Associates Inc.
> 11695 Johns Creek Parkway, Suite 250 | Johns Creek, GA 30097
> O (770) 446-9606 | M (770) 630-0949
>
>
>
Did you figure out what that uniquid id was for?  is it just a ref for the
web interface/pfsense code?
___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold


[pfSense] pfBlocker and Suricata

2015-10-26 Thread mayak

Hi All,

I have both pfBlocker and Suricata installed on a 2.2.4 pfSense.

I am noticing that Suricata block rules are evaluated  before pfBlocker. Is 
there a way to change that behavior?

I am grabbing the blocked IPs from Suricata and placing them into persistent 
pfBlocker lists, however, Suricata keeps filling up its lists again.

Many Thanks!

Mayak


___
pfSense mailing list
https://lists.pfsense.org/mailman/listinfo/list
Support the project with Gold! https://pfsense.org/gold