Re: [pfSense] fast CF cards?

2012-11-07 Thread Chris Bagnall
On 6 Nov 2012, at 19:24, David Burgess apt@gmail.com wrote: With that in mind, can anybody recommend a CF card with good write speed and good reliability? We've used a mix of Sandisk, Transcend and Kingston cards over the years. Of those: - nearly all the Kingston cards have failed

Re: [pfSense] fast CF cards?

2012-11-07 Thread Jim Thompson
On Nov 7, 2012, at 1:59 AM, Chris Bagnall pfse...@lists.minotaur.cc wrote: On the other hand, Transcend cards are usually available for less than 10 GBP, which if you're ordering lots of them, is a consideration. We order a lot of CF (1,000 at a time), we don't buy Transcend or on price

Re: [pfSense] fast CF cards?

2012-11-07 Thread David Burgess
On Wed, Nov 7, 2012 at 9:46 AM, Jim Thompson j...@netgate.com wrote: We've also never had a Kingston CF fail that I know of. Thanks, everybody, for the feedback. I settled on a Sandisk 200x 8GB. There were some Kingston's available with much faster ratings, but after reading some reviews of

[pfSense] Question about accessing two pfSense boxes in Fail-over mode

2012-11-07 Thread j...@millican.us
Hello, I know this is a bit short on details but... I have 4 pfSense boxes in two fail-over sets, one set is my edge firewall and the other is inside of the first between LAN and a DB zone. I have remote access through OpenVPN that puts me in the LAN where I can get to interface IP's of

Re: [pfSense] Question about accessing two pfSense boxes in Fail-over mode

2012-11-07 Thread Jim Pingle
On 11/7/2012 12:33 PM, j...@millican.us wrote: The problem is that on the edge boxes I can only get to the primary, the slave is inaccessible. In this case, it's likely that your slave box has a route or IPsec phase 2 defined that covers your client subnet, so the slave thinks it knows the

Re: [pfSense] Question about accessing two pfSense boxes in Fail-over mode

2012-11-07 Thread j...@millican.us
On 11/7/2012 1:23 PM, Jim Pingle wrote: On 11/7/2012 12:33 PM, j...@millican.us wrote: The problem is that on the edge boxes I can only get to the primary, the slave is inaccessible. In this case, it's likely that your slave box has a route or IPsec phase 2 defined that covers your client

[pfSense] Bug in pfSense v2.1

2012-11-07 Thread Oliver Schad
Hi all, I've found a bug in the latest development version v2.1 If you use a carp device a NAT rule is generated which source nats any outgoing packet to the carp IP. You can do that if the device is in master mode but you shouldn't do this if the device is in the backup mode. The rule is

[pfSense] IPv6-Bug in pfSense v2.1

2012-11-07 Thread Oliver Schad
Hi all, if I use CARP-Devices with IPv6 I see the following notice: [ There were error(s) loading the rules: no IP address found for 2001:abcd:abcd:201::1...0/64/tmp/rules.debug:153: could not parse host specificationno IP address found for