[pfSense Support] captive portal webgui prob

2006-04-13 Thread barney gumbo
I'm having a problem with making changes to the captive portal webgui page. If I attempt to change the idle or hard timeout settings, then hit the save button, I then get a page cannot be displayed. I can disable/enable captive portal without getting that error.I don't see anything obvious in the log files, and rebootingdoesn't help. I'm running 
1.0 beta 2. Any help or pointers will be appreciated.



[pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
Hi.

How can I do Raid with pfSense without vinum, gmirror or ccd ?
Is there some package to install ?

Thanks in advance.

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Bill Marquette
On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
 Hi.

 How can I do Raid with pfSense without vinum, gmirror or ccd ?
 Is there some package to install ?

 Thanks in advance.

Hardware RAID controllers are supported.  If you really want software
RAID, you'll have to roll your own image.

--Bill

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
Well, I'll do it but I don't know how can pfSense be used in corporate
environments if it can't do RAID. And I don't know a better place of a
firewall other than a corporation.

This raid support was simply erased from the FreeBSD code base.

It's only a suggestion.

Thanks again.
[]'s

On 4/13/06, Bill Marquette [EMAIL PROTECTED] wrote:
 On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
  Hi.
 
  How can I do Raid with pfSense without vinum, gmirror or ccd ?
  Is there some package to install ?
 
  Thanks in advance.

 Hardware RAID controllers are supported.  If you really want software
 RAID, you'll have to roll your own image.

 --Bill

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
Hi again.

It's an IBM xSeries 226 with an Adaptec SCSI 7902.
FreeBSD/pfSense doesn't have the driver. Ok, it's not FreeBSD or pfSense fault.

So the next step is to use gmirror or vinum to do the raid.
Well, it's here that I saw there isn't these executables in pfSense.
They were not integrated.

I think this is a major problem for companies that want a reliable
firewall and is my opinion that pfSense must have gmirror or vinum in
their core. Even if is by a package.

As I said it's only a suggestion.

Thanks for the help.


On 4/13/06, Rainer Duffner [EMAIL PROTECTED] wrote:
 Guilherme Oliveira wrote:
  Well, I'll do it but I don't know how can pfSense be used in corporate
  environments if it can't do RAID. And I don't know a better place of a
  firewall other than a corporation.
 
  This raid support was simply erased from the FreeBSD code base.
 
  It's only a suggestion.
 


 You use a hardware RAID-controller.
 twe/twa or one of the SCSI-ones.
 Even some of the host-RAID-controllers are still supported.
 If it isn't supported, it's either useless or too new (think SAS).

 *Which* RAID-controller are you complaining about?



 cheers,
 Rainer

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
I will explain in other words:

My homework is not to rely in drivers that are external to FreeBSD
core, as pfSense too.

What I did as pfSense recommends is to compare to this list:
http://www.pfsense.com/index.php?id=37
As you can see the card is listed ;-)

So how can pfSense do an raid !? This is my point :-)

About your comment about carp is good, but don't forget that big
companies don't want cheap machines. They want reliable machines.





On 4/13/06, Scott Ullrich [EMAIL PROTECTED] wrote:
 I think if companies want a reliable raid array they should spec
 first, buy later.  Not the other way around.  Just because you did not
 do your homework and pick up a hardware raid card doesnt mean we
 should integrate a software raid.

 Besides, with CARP allowing for cheap firewall clusters, whats the point!?

 On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
  Hi again.
 
  It's an IBM xSeries 226 with an Adaptec SCSI 7902.
  FreeBSD/pfSense doesn't have the driver. Ok, it's not FreeBSD or pfSense 
  fault.
 
  So the next step is to use gmirror or vinum to do the raid.
  Well, it's here that I saw there isn't these executables in pfSense.
  They were not integrated.
 
  I think this is a major problem for companies that want a reliable
  firewall and is my opinion that pfSense must have gmirror or vinum in
  their core. Even if is by a package.
 
  As I said it's only a suggestion.
 
  Thanks for the help.
 
 
  On 4/13/06, Rainer Duffner [EMAIL PROTECTED] wrote:
   Guilherme Oliveira wrote:
Well, I'll do it but I don't know how can pfSense be used in corporate
environments if it can't do RAID. And I don't know a better place of a
firewall other than a corporation.
   
This raid support was simply erased from the FreeBSD code base.
   
It's only a suggestion.
   
  
  
   You use a hardware RAID-controller.
   twe/twa or one of the SCSI-ones.
   Even some of the host-RAID-controllers are still supported.
   If it isn't supported, it's either useless or too new (think SAS).
  
   *Which* RAID-controller are you complaining about?
  
  
  
   cheers,
   Rainer
  
   -
   To unsubscribe, e-mail: [EMAIL PROTECTED]
   For additional commands, e-mail: [EMAIL PROTECTED]
  
  
 
  -
  To unsubscribe, e-mail: [EMAIL PROTECTED]
  For additional commands, e-mail: [EMAIL PROTECTED]
 
 

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Scott Ullrich
On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
 I will explain in other words:

 My homework is not to rely in drivers that are external to FreeBSD
 core, as pfSense too.

 What I did as pfSense recommends is to compare to this list:
 http://www.pfsense.com/index.php?id=37
 As you can see the card is listed ;-)

 So how can pfSense do an raid !? This is my point :-)

 About your comment about carp is good, but don't forget that big
 companies don't want cheap machines. They want reliable machines.

These are all valid points but I personally would not trust a software
raid.  I would go with a hardware raid that is supported by FreeBSD
and known to work well.  SCSI, 3ware, etc.

I've seen a LOT of stories on the lists about Software raid woes.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
Thanks.
Next I have this in account.

[]'s

On 4/13/06, Scott Ullrich [EMAIL PROTECTED] wrote:
 On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
  I will explain in other words:
 
  My homework is not to rely in drivers that are external to FreeBSD
  core, as pfSense too.
 
  What I did as pfSense recommends is to compare to this list:
  http://www.pfsense.com/index.php?id=37
  As you can see the card is listed ;-)
 
  So how can pfSense do an raid !? This is my point :-)
 
  About your comment about carp is good, but don't forget that big
  companies don't want cheap machines. They want reliable machines.

 These are all valid points but I personally would not trust a software
 raid.  I would go with a hardware raid that is supported by FreeBSD
 and known to work well.  SCSI, 3ware, etc.

 I've seen a LOT of stories on the lists about Software raid woes.

 Scott

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Bill Marquette
On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
 Well, I'll do it but I don't know how can pfSense be used in corporate
 environments if it can't do RAID. And I don't know a better place of a
 firewall other than a corporation.

I would expect the decision to utilize RAID to be followed with a
quote for RAID capable hardware.

 This raid support was simply erased from the FreeBSD code base.

Correct, it's not needed for pfSense, we recommend hardware RAID, it's
more reliable.

 It's only a suggestion.

Understood.

--Bill

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Scott Ullrich
One thing that I just noticed is that software raid tools are included
in the developer edition.  You could use this to get up and running
but of course this is not supported from our end.  Hope this helps,

Scott

On 4/13/06, Bill Marquette [EMAIL PROTECTED] wrote:
 On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
  Well, I'll do it but I don't know how can pfSense be used in corporate
  environments if it can't do RAID. And I don't know a better place of a
  firewall other than a corporation.

 I would expect the decision to utilize RAID to be followed with a
 quote for RAID capable hardware.

  This raid support was simply erased from the FreeBSD code base.

 Correct, it's not needed for pfSense, we recommend hardware RAID, it's
 more reliable.

  It's only a suggestion.

 Understood.

 --Bill

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Guilherme Oliveira
That's it !!!

Thanks :-)

On 4/13/06, Scott Ullrich [EMAIL PROTECTED] wrote:
 One thing that I just noticed is that software raid tools are included
 in the developer edition.  You could use this to get up and running
 but of course this is not supported from our end.  Hope this helps,

 Scott

 On 4/13/06, Bill Marquette [EMAIL PROTECTED] wrote:
  On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
   Well, I'll do it but I don't know how can pfSense be used in corporate
   environments if it can't do RAID. And I don't know a better place of a
   firewall other than a corporation.
 
  I would expect the decision to utilize RAID to be followed with a
  quote for RAID capable hardware.
 
   This raid support was simply erased from the FreeBSD code base.
 
  Correct, it's not needed for pfSense, we recommend hardware RAID, it's
  more reliable.
 
   It's only a suggestion.
 
  Understood.
 
  --Bill
 
  -
  To unsubscribe, e-mail: [EMAIL PROTECTED]
  For additional commands, e-mail: [EMAIL PROTECTED]
 
 

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Scott Ullrich
Good deal.  Let me know if anything is missing and I'll fix it up.

This will be our standard solution for people wanting above and beyond
normal items in pfSense :)

Scott


On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
 That's it !!!

 Thanks :-)

 On 4/13/06, Scott Ullrich [EMAIL PROTECTED] wrote:
  One thing that I just noticed is that software raid tools are included
  in the developer edition.  You could use this to get up and running
  but of course this is not supported from our end.  Hope this helps,
 
  Scott
 
  On 4/13/06, Bill Marquette [EMAIL PROTECTED] wrote:
   On 4/13/06, Guilherme Oliveira [EMAIL PROTECTED] wrote:
Well, I'll do it but I don't know how can pfSense be used in corporate
environments if it can't do RAID. And I don't know a better place of a
firewall other than a corporation.
  
   I would expect the decision to utilize RAID to be followed with a
   quote for RAID capable hardware.
  
This raid support was simply erased from the FreeBSD code base.
  
   Correct, it's not needed for pfSense, we recommend hardware RAID, it's
   more reliable.
  
It's only a suggestion.
  
   Understood.
  
   --Bill
  
   -
   To unsubscribe, e-mail: [EMAIL PROTECTED]
   For additional commands, e-mail: [EMAIL PROTECTED]
  
  
 
  -
  To unsubscribe, e-mail: [EMAIL PROTECTED]
  For additional commands, e-mail: [EMAIL PROTECTED]
 
 

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



[pfSense Support] Vlan problems

2006-04-13 Thread tele

Hi,

I running Pfsense-Beta2 and this is my setup:

WAN83.214.128.169/26
LAN 192.168.100.1/24
SERVICE 83.214.162.0/24

SERVICE it's vlan0 with vid 162

i've activated Advanced Outbound NAT with the following rules:

Interface   Source Destination
WAN  192.168.100.0/24*
SERVICE   192.168.100.0/2483.214.162.0/24

the firewall rules are set to permit ALL in all interfaces

ok now i have the LAN port connected to a cisco catalyst
with a trunk configured in that port and some other port tagged.

so if i connect a pc to the port tagged with default 1 vlan i can exit 
to internet and ping

any interface.
if i connect a pc to the port tagged with the vlan 162 and configure the 
network for subnet 83.214.162.0/24 with gw 83.214.162.1 i can ping any 
interface of the fw but i can't ping out!


i don't know where is the problem i think that the catalyst config it's ok.
maybe i missing something in the pfsense configuration.

thank you for any help

:tele

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



RE: [pfSense Support] Vlan problems

2006-04-13 Thread Amorim, Nuno Alexandre \(ext\)

In the trunk port configure the native vlan to vlan 1. 

-Original Message-
From: tele [mailto:[EMAIL PROTECTED] 
Sent: quinta-feira, 13 de Abril de 2006 17:03
To: support@pfsense.com
Subject: [pfSense Support] Vlan problems

Hi,

I running Pfsense-Beta2 and this is my setup:

WAN83.214.128.169/26
LAN 192.168.100.1/24
SERVICE 83.214.162.0/24

SERVICE it's vlan0 with vid 162

i've activated Advanced Outbound NAT with the following rules:

Interface   Source Destination
WAN  192.168.100.0/24*
SERVICE   192.168.100.0/2483.214.162.0/24

the firewall rules are set to permit ALL in all interfaces

ok now i have the LAN port connected to a cisco catalyst
with a trunk configured in that port and some other port tagged.

so if i connect a pc to the port tagged with default 1 vlan i can exit 
to internet and ping
any interface.
if i connect a pc to the port tagged with the vlan 162 and configure the

network for subnet 83.214.162.0/24 with gw 83.214.162.1 i can ping any 
interface of the fw but i can't ping out!

i don't know where is the problem i think that the catalyst config it's
ok.
maybe i missing something in the pfsense configuration.

thank you for any help

:tele

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]


-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



[pfSense Support] NAT vs DCHP of external IP's

2006-04-13 Thread Bart Fisher



The main problem I have is allowing 1:1 NAT 
Internal IP's to connect to NAT services such as mail server.
I've already been told it can't be done with 1:1 
NAT.

However, if I change my method to use my External 
IP's (32) in DHCP, would this solve my problem?

TIA

Bart


[pfSense Support] Free IPsec client software, suggestions?

2006-04-13 Thread Jonathan Woodard
Is there a free IPsec VPN client I can use with Windows 2000/XP to 
connect to pfsense through IPsec. I have been using PPTP but I 
understand it's not as secure and I'm having trouble getting connected 
with it on my Linux desktop. I realize this is a bit off topic for 
Pfsense, but someone else might use this discussion later. Thank you 
very much for any help and please keep up the outstanding work on this 
project. It's coming along great and I see it really making a name for 
itself.


-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Free IPsec client software, suggestions?

2006-04-13 Thread Scott Ullrich
Look in http://www.pfsense.com/index.php?id=33


On 4/13/06, Jonathan Woodard [EMAIL PROTECTED] wrote:
 Is there a free IPsec VPN client I can use with Windows 2000/XP to
 connect to pfsense through IPsec. I have been using PPTP but I
 understand it's not as secure and I'm having trouble getting connected
 with it on my Linux desktop. I realize this is a bit off topic for
 Pfsense, but someone else might use this discussion later. Thank you
 very much for any help and please keep up the outstanding work on this
 project. It's coming along great and I see it really making a name for
 itself.

 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] Raid disks

2006-04-13 Thread Randy B
Day late, dollar short, and only an opinion:I'll spare you the boring details, but I know  understand enterprise redundancy. Software RAID has it's place, but at the enterprise level it's ridiculous to waste valuable CPU cycles on something a $300 add-on card can do much more efficiently and with much more of a guarantee. That even extends to firewalls  routers, an attitude I'm working on changing, but we have yet to find a system based on general-purpose hardware that can handle our throughput.
RBOn 4/13/06, Scott Ullrich [EMAIL PROTECTED] wrote:
Good deal.Let me know if anything is missing and I'll fix it up.This will be our standard solution for people wanting above and beyondnormal items in pfSense :)ScottOn 4/13/06, Guilherme Oliveira 
[EMAIL PROTECTED] wrote: That's it !!! Thanks :-) On 4/13/06, Scott Ullrich 
[EMAIL PROTECTED] wrote:  One thing that I just noticed is that software raid tools are included  in the developer edition.You could use this to get up and running  but of course this is not supported from our end.Hope this helps,
   Scott   On 4/13/06, Bill Marquette [EMAIL PROTECTED] wrote:   On 4/13/06, Guilherme Oliveira 
[EMAIL PROTECTED] wrote:Well, I'll do it but I don't know how can pfSense be used in corporateenvironments if it can't do RAID. And I don't know a better place of a
firewall other than a corporation. I would expect the decision to utilize RAID to be followed with a   quote for RAID capable hardware.  
This raid support was simply erased from the FreeBSD code base. Correct, it's not needed for pfSense, we recommend hardware RAID, it's   more reliable.
  It's only a suggestion. Understood. --Bill -
   To unsubscribe, e-mail: [EMAIL PROTECTED]   For additional commands, e-mail: 
[EMAIL PROTECTED]   -  To unsubscribe, e-mail: 
[EMAIL PROTECTED]  For additional commands, e-mail: [EMAIL PROTECTED]   -
 To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]
-To unsubscribe, e-mail: [EMAIL PROTECTED]For additional commands, e-mail: 
[EMAIL PROTECTED]