[pfSense] OpenVPN: offsite configuration

2012-04-25 Thread runinva
I'm new to pfSense and OpenVPN but my questions cross both products. Is it conceivable to ship a pfSense system to a remote office location and have the onsite systems tech set the public IP address using some simple instructions? Can OpenVPN be configured in such a way that the same shipped

Re: [pfSense] OpenVPN: offsite configuration

2012-04-25 Thread Gavin Will
I have shipped pfSense boxes before. What I do is setup remote access to the web configurator (only allowing the source address of our main office) and then post the box. If the WAN is dhcp then you are all set, get a person at remote office to do a what is my ip or

Re: [pfSense] OpenVPN: offsite configuration

2012-04-25 Thread Seth Mos
Hi, To make sure things stay working as it is. I have a hostname in the remote access list so that even if the main office needs to relocate (DR) i can still access the remote machine. I also ship routers with a dyndns name that every now and then will turn up a rfc1918 ip but i can still see

[pfSense] Quick Thanks from a Happy user

2012-04-25 Thread Christian Neumann
Hi everybody, I just wanted to share how glad we are that pfSense exists. Usually people mostly share problems, but this time I just wanted to highlight what we have been able to achieve with a little bit of customization. Please let me know if this isn't the right forum for this and point to

[pfSense] Open VPN client access and forcing clients through tunnel / Outbound NAT issue?

2012-04-25 Thread Gavin Will
Hi I have tested with a pfSense VM located at home an open-vpn dial in for remote users (TLS +User Auth - Local Auth). I check the redirect gateway to force all traffic through the tunnel and test by going to http://pfsense.org/ip.php This shows my IP as the remote PF sense box / home. All

Re: [pfSense] Open VPN client access and forcing clients through tunnel / Outbound NAT issue?

2012-04-25 Thread Gavin Will
Ignore this... Answered it myself.. It was todo with the Outbound NAT. Thing was I did not disconnect / reconnect from the client side after applying the NAT rule. All working now thanks Gavin -Original Message- From: list-boun...@lists.pfsense.org

[pfSense] THREAD HIJACK

2012-04-25 Thread Giles Coochey
Just a note - When starting a new thread or question can you please not reply to an existing email and modify the subject. Some of us with threaded mail readers might be ignoring the existing thread you hijack, and therefore not see your query and not be able to help you out. If you need

Re: [pfSense] THREAD HIJACK

2012-04-25 Thread Ian Bowers
Serves them right for hijacking! On Wed, Apr 25, 2012 at 9:26 AM, Giles Coochey gi...@coochey.net wrote: Just a note - When starting a new thread or question can you please not reply to an existing email and modify the subject. Some of us with threaded mail readers might be ignoring the

Re: [pfSense] THREAD HIJACK

2012-04-25 Thread Ryan Rodrigue
-Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Giles Coochey Sent: Wednesday, April 25, 2012 8:26 AM To: list@lists.pfsense.org Subject: [pfSense] THREAD HIJACK Just a note - When starting a new thread or question can you

Re: [pfSense] Quick Thanks from a Happy user

2012-04-25 Thread Mehma Sarja
On 4/25/12 4:29 AM, Christian Neumann wrote: Hi everybody, I just wanted to share how glad we are that pfSense exists. Usually people mostly share problems, but this time I just wanted to highlight what we have been able to achieve with a little bit of customization. Please let me know if

[pfSense] DNS internal, caching external forwarding requests to upstream servers. What's the best practice on pfsense 2.0.1?

2012-04-25 Thread Ray
Hi there, I'm running four pfSense 2.0.1s. Each of them serves 1 different LAN, 192.168.{1,2,3,4}.0/24 There are layer 3 OpenVPN tunnels between them. I had the hope of setting up internal DNS subdomains for each site site1.intra.mysite.com site2.intra.mysite.com site3.intra.mysite.com

[pfSense] Can anyone please tell me the step by step to integrate Freeradiuse to authenticate users from Window Active directory?

2012-04-25 Thread steel max
Can anyone please tell me the step by step to integrate Freeradiuse to authenticate users from Window Active directory? I have Successfully Setup: 1- Captive portal FreeRadius. 2- Local PFsesnce Users can Login authenticate from Captive-portal. *BUT I really want is to Authenticate AD

Re: [pfSense] Can anyone please tell me the step by step to integrate Freeradiuse to authenticate users from Window Active directory?

2012-04-25 Thread Chris Buechler
On Wed, Apr 25, 2012 at 11:54 PM, steel max steelmax11...@gmail.com wrote: Can anyone please tell me the step by step to integrate Freeradiuse to authenticate users from Window Active directory? Why? Use RADIUS on your Windows server instead, no sense in complicating things with some other

Re: [pfSense] Can anyone please tell me the step by step to integrate Freeradiuse to authenticate users from Window Active directory?

2012-04-25 Thread Brian Henson
You could use Windows Internet Authorization server to provide the users/groups. It is a radius server and could do what your wanting to do. On Wed, Apr 25, 2012 at 11:54 PM, steel max steelmax11...@gmail.com wrote: Can anyone please tell me the step by step to integrate Freeradiuse to

Re: [pfSense] Quick Thanks from a Happy user

2012-04-25 Thread Christian Neumann
On Apr 25, 2012, at 6:00 PM, list-requ...@lists.pfsense.org list-requ...@lists.pfsense.org wrote: On 4/25/12 4:29 AM, Christian Neumann wrote: Hi everybody, I just wanted to share how glad we are that pfSense exists. Usually people mostly share problems, but this time I just wanted to