Re: [pfSense] user certs

2015-01-29 Thread A Mohan Rao
any bod help which version is use squid and squid guard in pfsense 2.2 amd 64 On Thu, Jan 29, 2015 at 11:25 PM, Chris Buechler wrote: > On Thu, Jan 29, 2015 at 9:12 AM, Randy Bush wrote: > >> Randy (and I, since I suggested it to him) was under the impression > >> that it was possible to use cl

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-29 10:56 GMT-03:00 Vinícius Zavam : > > > 2015-01-29 10:24 GMT-03:00 Vinícius Zavam : > > >> >> 2015-01-28 6:41 GMT-03:00 WolfSec-Support : >> >>> >>> 2015-01-27 22:13 GMT+01:00 Chris Buechler : >>> > we have general problems with v2.2 > > I tried to update 13 devices, and o

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread Márcio Merlone
On 29-01-2015 13:08, Doug Lytle wrote: The link I'm working with is: http://www.malwaredomainlist.com/hostslist/ip.txt Thanks for the tip. :) -- *Marcio Merlone* ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the pro

Re: [pfSense] user certs

2015-01-29 Thread Chris Buechler
On Thu, Jan 29, 2015 at 9:12 AM, Randy Bush wrote: >> Randy (and I, since I suggested it to him) was under the impression >> that it was possible to use client-side certificates to access the >> UI, since password authentication, however filtered, is not always >> good / secure enough. > > seems d

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread Doug Lytle
Chris L wrote: Pretty sure you can see that info in Diagnostics > Tables And that it did. Thanks, Doug -- Ben Franklin quote: "Those who would give up Essential Liberty to purchase a little Temporary Safety, deserve neither Liberty nor Safety." ___

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread Chris L
> On Jan 29, 2015, at 8:53 AM, compdoc wrote: > >> The link I'm working with is: > >> http://www.malwaredomainlist.com/hostslist/ip.txt > > > When an alias is created with this url, do you know where the list is stored > on pfSense? I just want to see if I've created the alias correctly and t

Re: [pfSense] 2.2-RELEASE Via Padlock

2015-01-29 Thread Hakisho Nukama
On Thu, Jan 29, 2015 at 7:07 AM, Chris Buechler wrote: > On Sun, Jan 25, 2015 at 7:59 PM, Peder Rovelstad > wrote: >> Hello. Has Via Padlock Hardware Crypto support been disabled in >> pfSense/FreeBSD 10? > > No, should still be there. Whether anyone's continually testing the > old drivers like

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread compdoc
> The link I'm working with is: >http://www.malwaredomainlist.com/hostslist/ip.txt When an alias is created with this url, do you know where the list is stored on pfSense? I just want to see if I've created the alias correctly and that the list matches the ip addresses in the url. Thanks __

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread Doug Lytle
Jim Pingle wrote: It's still there on all mine, on each tab at the bottom there is an up arrow ("^") and it opens the bulk import page. And there it is! Icon little different then the docs say, but to be honest, I must be blind as a >2.) When trying to create an alias that links to a

Re: [pfSense] New pfSense 2.2 install

2015-01-29 Thread Jim Pingle
On 01/29/2015 10:08 AM, Doug Lytle wrote: > I'm building a new 64bit pfSense 2.2, running under ESXi 5.5. > > I've noted 2 things. > > 1.) Bulk Alias imports button no longer exist on the main alias page. It's still there on all mine, on each tab at the bottom there is an up arrow ("^") and it

Re: [pfSense] user certs

2015-01-29 Thread Randy Bush
> Randy (and I, since I suggested it to him) was under the impression > that it was possible to use client-side certificates to access the > UI, since password authentication, however filtered, is not always > good / secure enough. seems downright quaint to have a security product that uses passwo

[pfSense] New pfSense 2.2 install

2015-01-29 Thread Doug Lytle
I'm building a new 64bit pfSense 2.2, running under ESXi 5.5. I've noted 2 things. 1.) Bulk Alias imports button no longer exist on the main alias page. 2.) When trying to create an alias that links to an online listing of blacklisted IP addresses, the alias that was just created disappears

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-29 10:24 GMT-03:00 Vinícius Zavam : > > > 2015-01-28 6:41 GMT-03:00 WolfSec-Support : > >> >> 2015-01-27 22:13 GMT+01:00 Chris Buechler : >> >>> > we have general problems with v2.2 >>> > >>> > I tried to update 13 devices, and only some worked fine (1 ALIX), >>> > and one virtual machine

Re: [pfSense] Release 2.2 - more problems than success by upgrades / looping packet installations / sshd is not working any more / crashes on X5550 CPU

2015-01-29 Thread Vinícius Zavam
2015-01-28 6:41 GMT-03:00 WolfSec-Support : > > 2015-01-27 22:13 GMT+01:00 Chris Buechler : > >> > we have general problems with v2.2 >> > >> > I tried to update 13 devices, and only some worked fine (1 ALIX), >> > and one virtual machine (afterwards crashes see below) >> > >> > Most we had proble

[pfSense] Multi-Wan question

2015-01-29 Thread Nenhum_de_Nos
Hail, I have a multi-wan connection, and this is a unknown behavior to me: I have two Wan links, 10Mbps and 3Mbps. This machine has a rule on LAN (there is only one lan side, and lan address) to use the 3Mbps link. Now I got two downloads in on this machine, and I see the total bandwidth for t

Re: [pfSense] 2.2-RELEASE Via Padlock

2015-01-29 Thread Peder Rovelstad
On Sun, Jan 25, 2015 at 7:59 PM, Peder Rovelstad wrote: >> Hello. Has Via Padlock Hardware Crypto support been disabled in >> pfSense/FreeBSD 10? > No, should still be there. Whether anyone's continually testing the old drivers like that is unknown, that's one I haven't personally tested. You s

[pfSense] pfsense 2.2 (i386) - Soekris 6501-70 - Crashing once a day or so

2015-01-29 Thread Giles Coochey
I was running pfsense 2.1.5 (i386) on my Soekris 6501-70 with an mSata disk drive without any problems. I recently upgraded to pfsense2.2 (i386) and it appears to be crashing once a day or so. Now that I've disabled read-only /var & /tmp it reports upon logging in whether I want to send the

[pfSense] STUNNEL Transparent forwarding to HAPROXY

2015-01-29 Thread Stefan Berger
Hello, because I haven't received any response on the forum I will ask the list - maybe someone on the list can help me I have to terminate POP3S,IMAPS,SMTPS on our Firewall (SSL Offloading) and Forward the unencrypted Sessions to our Loadbalancer. Everything is working fine when i don't use STUNN

Re: [pfSense] 2.2-RELEASE now available!

2015-01-29 Thread Doug Lytle
Chris Buechler wrote: what specifically do you mean? The limiters are gone from Firewall>Traffic Shaper, Limiters? Correct. It was as if I had never set it. Since it's my home firewall, wasn't a big deal, just thought I'd let someone know. Doug -- Ben Franklin quote: "Those who would giv

Re: [pfSense] 2.2-RELEASE now available!

2015-01-29 Thread A Mohan Rao
[pfSense] 2.2-RELEASE now available! with lots of problem like squid and squid guard not working properly. Thanks A Mohan Rao +91 98260 61122 On Sat, Jan 24, 2015 at 7:54 AM, Chris Buechler wrote: > Details on the blog: > https://blog.pfsense.org/?p=1546 > ___

Re: [pfSense] 2.2-RELEASE now available!

2015-01-29 Thread Chris Buechler
Hey Seth, On Mon, Jan 26, 2015 at 8:38 AM, Seth Mos wrote: > Sorry to reply to myself here, but 2.2 in combination with the Intel > X540-2 card isn't very stable. The card keeps dropping the Phy which is > fine on 2.1.5. > That's surprising, we've seen much better results on our systems with ix

[pfSense] opvnvpn confusion remote access vs peer to peer

2015-01-29 Thread Muhammad Yousuf Khan
Hi. We have 3 sites and we want openvpn solution as hub and spoke. while i tried remote access type vpn server in pfsense i notice one thing that only connected spoke to hub can connected all the subnets behind hub. however all computer behind spoke can not reach the hub nor behind it and same for

Re: [pfSense] user certs

2015-01-29 Thread Phil Regnauld
Chris Buechler (cmb) writes: > If you're using user certs generated elsewhere, no need to import the > certs into the user manager at all. There a requirement for that > somewhere that I'm missing? Randy (and I, since I suggested it to him) was under the impression that it was poss

Re: [pfSense] 2.2-RELEASE now available!

2015-01-29 Thread Chris Buechler
On Mon, Jan 26, 2015 at 6:26 AM, Doug Lytle wrote: > I've also noted this morning that the 3 systems I've upgraded, all of them > have lost their limiter rules. > > I've read the release notes, nothing that I saw stated they'd be removed. > Limiters won't be removed. Check your config history, D

Re: [pfSense] Problem upgrading pfSense on Sun Fire x4100

2015-01-29 Thread Chris Buechler
On Wed, Jan 28, 2015 at 6:37 AM, Toni Garcia wrote: > well, no kernel crash ? > > > no kernel crash after upgrade > > > answering myself, seems to be this problem: > > https://redmine.pfsense.org/issues/3749 > It's definitely not that problem, that was specific to 2.2 alpha snapshots 6+ months a