Re: [pfSense] SG-1000 and VPN

2017-01-24 Thread A Mohan Rao
better u can use site to site vpn is best solution. On Wed, Jan 25, 2017 at 11:08 AM, WebDawg wrote: > On Tue, Jan 17, 2017 at 10:16 AM, Steve Yates wrote: > > > We have a client who wants to set up one remote user (in a fixed > > location) with a

Re: [pfSense] SG-1000 and VPN

2017-01-24 Thread WebDawg
On Tue, Jan 17, 2017 at 10:16 AM, Steve Yates wrote: > We have a client who wants to set up one remote user (in a fixed > location) with a hardware VPN connection back to the office. The office > has about 5 active PCs at any given time. This would be the only VPN

Re: [pfSense] Fake OpenVPN / IPSec IP

2017-01-24 Thread WebDawg
On Sun, Jan 15, 2017 at 7:57 AM, Chris wrote: > All, > > is a client able to change his assigned OpenVPN or IPSec IP? > > Are packets still routed to him, if he chooses an arbitrary address? > > - Chris > > ___ > >

Re: [pfSense] PFsense 2.3.2-P1 dies

2017-01-24 Thread WebDawg
On Fri, Jan 13, 2017 at 7:06 AM, Roy Hocknull wrote: > Hi, > > I recently updated to 2.3.2-P1 and now when the system logs reach 500k, the > firewall dies and everything stops, like OpenVPN. I tried resetting the > values in the log settings, but it still happens. Is

Re: [pfSense] Is this list still active?

2017-01-24 Thread Gé Weijers
Google's spam filter is complaining about a DMARC failure. On Tue, Jan 24, 2017 at 2:33 PM, Gé Weijers wrote: > Gmail seems to mark most messages from this list as spam. I have a rule > that prevents gmail from moving messages to the spam folder, otherwise I > would have seen

Re: [pfSense] Is this list still active?

2017-01-24 Thread Gé Weijers
Gmail seems to mark most messages from this list as spam. I have a rule that prevents gmail from moving messages to the spam folder, otherwise I would have seen the same thing. On Tue, Jan 24, 2017 at 1:15 PM, Sherwood McGowan < sherwood.mcgo...@gmail.com> wrote: > Hey, nice last name! I've got

[pfSense] system CA certificate generator change

2017-01-24 Thread Vick Khera
I just made a new certificate using my own CA with the UI in pfsense 2.3.2-p1 for one of my firewalls. It appears that how it is generated does not allow Chrome or Firefox to recognize it by the CN, only the aliases. A certificate I generated using the UI in 2014 does however, work with the

Re: [pfSense] Is this list still active?

2017-01-24 Thread Sherwood McGowan
Hey, nice last name! I've got the same as a first! Yes, the list is still active, just not all the time. ⁣Sherwood McGowan VOIP Engineer &  Consultant This email was sent via a mobile device. Please pardon misspellings, strange syntax, and other possible issues arising from using a mobile

Re: [pfSense] IPSec Bug?

2017-01-24 Thread Jim Thompson
On Tue, Jan 24, 2017 at 12:16 PM, Eero Volotinen wrote: > What hardware is other side running? Why you are trying to use 3des? > > Eero > > 2017-01-17 16:36 GMT+02:00 Roland Giesler : > >> We've battled all afternoon to establish an IPSec

Re: [pfSense] IPSec Bug?

2017-01-24 Thread Eero Volotinen
What hardware is other side running? Why you are trying to use 3des? Eero 2017-01-17 16:36 GMT+02:00 Roland Giesler : > We've battled all afternoon to establish an IPSec site-to-site connection. > Here's what happens: > > TimeProcessPIDMessage > Jan 17 15:58:53

Re: [pfSense] Is this list still active?

2017-01-24 Thread Benjamin E. Nichols
Actually, I did just wake up, just respondin to checkin. What is this, a role call? LOL. Anyhow, Greetings from SBL. On 1/24/2017 11:48 AM, Kostas Backas wrote: Just received a bunch of messages from other people so I guess the listsrv woke up. Best regards Kostas Sent from my iPhone

Re: [pfSense] Is this list still active?

2017-01-24 Thread Victor Padro
+1 On Tue, Jan 24, 2017 at 11:48 AM, Kostas Backas wrote: > Just received a bunch of messages from other people so I guess the listsrv > woke up. > > Best regards > > Kostas > > Sent from my iPhone > > > From: List

Re: [pfSense] Hello World?

2017-01-24 Thread Victor Padro
I've just rescued all the emails from the spam folder, really don't what happened here. Very strange issue. On Sun, Jan 22, 2017 at 12:12 PM, Peder Rovelstad wrote: > Is the list constipated? I haven't received anything all month. > > > > If just me, sorry for the

Re: [pfSense] Is this list still active?

2017-01-24 Thread Kostas Backas
Just received a bunch of messages from other people so I guess the listsrv woke up. Best regards Kostas Sent from my iPhone From: List on behalf of Steven Sherwood Sent: Monday, January 16, 2017 4:23:19 PM To:

[pfSense] Hello World?

2017-01-24 Thread Peder Rovelstad
Is the list constipated? I haven't received anything all month. If just me, sorry for the annoyance. Peder ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold

Re: [pfSense] IPSec Bug?

2017-01-24 Thread Roland Giesler
Am I still on this list? I'm not getting any mail from there. Could someone just tell me if you see my mail please? On Tue, Jan 17, 2017 at 4:36 PM, Roland Giesler wrote: > We've battled all afternoon to establish an IPSec site-to-site > connection. Here's what

[pfSense] SG-1000 and VPN

2017-01-24 Thread Steve Yates
We have a client who wants to set up one remote user (in a fixed location) with a hardware VPN connection back to the office. The office has about 5 active PCs at any given time. This would be the only VPN user. Has anyone used one of the new micro SG-1000 units with a VPN

[pfSense] IPSec Bug?

2017-01-24 Thread Roland Giesler
We've battled all afternoon to establish an IPSec site-to-site connection. Here's what happens: TimeProcessPIDMessage Jan 17 15:58:53 charon 05[NET] <197> sending packet: from 129.232.232.130[500] to 105.27.116.62[500] (56 bytes) Jan 17 15:58:53 charon 05[ENC] <197> generating INFORMATIONAL_V1

[pfSense] Is this list still active?

2017-01-24 Thread Steven Sherwood
Just sending this out as a test message as I've stopped receiving the list as of December 8... ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold! https://pfsense.org/gold

[pfSense] Fake OpenVPN / IPSec IP

2017-01-24 Thread Chris
All, is a client able to change his assigned OpenVPN or IPSec IP? Are packets still routed to him, if he chooses an arbitrary address? - Chris ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the project with Gold!

[pfSense] PFsense 2.3.2-P1 dies

2017-01-24 Thread Roy Hocknull
Hi, I recently updated to 2.3.2-P1 and now when the system logs reach 500k, the firewall dies and everything stops, like OpenVPN. I tried resetting the values in the log settings, but it still happens. Is this a known issue? Thanks, Roy Hocknull ___

[pfSense] Man in the middle not working

2017-01-24 Thread Getzan Avila
HI list, I will appreciate your help. I has Man in the middle operational in my Pfsense box, but after an update it stop working. I'll recreate again all the configurations, restart the Pfsense defaults factory and nothing. There is something that I'm forgetting? My version is

[pfSense] CAS or Shibboleth authentication?

2017-01-24 Thread Paul Mather
Does anyone know whether CAS or Shibboleth is supported as an authentication method by pfSense 2.3.2? CAS is the preferred authentication method for Web applications at our organisation and so it would be great if pfSense could use it---at least with the WebGUI. Is there anyone on the list

Re: [pfSense] Aliases grouping

2017-01-24 Thread David STIEVENARD
Hi Luc, here's my basic naming convention names are composed with this pattern {optional prefix}*{nature}-{relevant information that depends on the nature}-{sequence number}*-{optional_suffix} for the alias in pfSense I use the same convention and - the "net" nature for a network - the

Re: [pfSense] Port forward => load balancer

2017-01-24 Thread Ugo Bellavance
On 2016-12-02 03:47 PM, Jim Pingle wrote: On 12/02/2016 06:04 AM, Ugo Bellavance wrote: I'd like to know if there is a way to switch from a port forward to a server load balancer configuration without downtime. Can I create everything in the load balancer config and then remove the port