Re: [pfSense] adding a dup-to rule?

2015-02-25 Thread Manojav Sridhar
I have come up w/ this pass in quick on pppoe0 dup-to ( re0_vlan201 192.168.100.2/32 ) inet proto udp from any port 5060 to any I have an ATA device making a sip connection from the LAN to IP on the internet port 5060 udp. I want to be able to duplicate packets that travel inbound on that conn

Re: [pfSense] serial port sadness

2015-02-25 Thread Chris L
> On Feb 25, 2015, at 12:12 PM, Volker Kuhlmann wrote: > > On Thu 26 Feb 2015 07:19:04 NZDT +1300, Jim Pingle wrote: > >> http://www.amazon.com/gp/product/B00AHYJWWG > > Yes useful for many occasions. > However as a first step having a two bucks gender bender and trying with > and without will

Re: [pfSense] serial port sadness

2015-02-25 Thread Jeremy Bennett
Thank you all for the suggestions. I put my own alix router in place for my client, and now that I have a little time, will go ahead and purchase a non-prolific USB to serial adapter, and the associated accessories. I have gotten into the habit of buying prebuilt Alix systems, and that has spoiled

Re: [pfSense] serial port sadness

2015-02-25 Thread Volker Kuhlmann
On Thu 26 Feb 2015 07:19:04 NZDT +1300, Jim Pingle wrote: > http://www.amazon.com/gp/product/B00AHYJWWG Yes useful for many occasions. However as a first step having a two bucks gender bender and trying with and without will put the straight/null issue to rest. You'll still need if if the flashin

[pfSense] another minor issue on upgrade to 2.2

2015-02-25 Thread Vick Khera
I use the service watchdog package. I had to delete racoon and add back the new ipsec process to the monitor. for a few days it just sat there trying to restart racoon over and over again :( Just another thing to keep in mind... ___ pfSense mailing list

Re: [pfSense] no stable ipsec connection after upgrade to 2.2

2015-02-25 Thread Chris Buechler
On Wed, Feb 25, 2015 at 9:02 AM, compdoc wrote: > > peer client ID returned doesn't match my proposal > > I have two ipsec tunnels and after the upgrade, for one tunnel I had to > change the 'Peer identifier' on my side to use the IP address it was > seeing. > Been working great since. > Especia

Re: [pfSense] serial port sadness

2015-02-25 Thread Jim Pingle
On 02/25/2015 12:03 PM, Bob Gustafson wrote: > Years ago I had problems with serial cables - I invested in a little > in-line gadget that had red and green LEDs for each line. The one I have > uses 25 pin connectors, so the cable is a mix of 9-25 pin adapters and > the LED viewer. > > You can shut

[pfSense] adding a dup-to rule?

2015-02-25 Thread Manojav Sridhar
pfS Gurus! I gather the UI has no ability to add dup-to rules for pf. I am happy to edit the filter.inc, but I am not sure where I should edit this to add my dupto rule. I am trying to replicate this iptables rule iptables -t mangle -A POSTROUTING -p udp -d 192.168.100.0/23 -m string --string "I

Re: [pfSense] serial port sadness

2015-02-25 Thread Bob Gustafson
Years ago I had problems with serial cables - I invested in a little in-line gadget that had red and green LEDs for each line. The one I have uses 25 pin connectors, so the cable is a mix of 9-25 pin adapters and the LED viewer. You can shut down/disconnect one end to see what lights remain li

Re: [pfSense] no stable ipsec connection after upgrade to 2.2

2015-02-25 Thread compdoc
> peer client ID returned doesn't match my proposal I have two ipsec tunnels and after the upgrade, for one tunnel I had to change the 'Peer identifier' on my side to use the IP address it was seeing. Been working great since. ___ pfSense mailing li

[pfSense] no stable ipsec connection after upgrade to 2.2

2015-02-25 Thread Thorsten Leiser
Hi, I got a serious problem with my ipsec connection since the upgrade from 2.1.4 to 2.2. the ipsec connection to the sophos utm 9.2 has always been stable, but now since the upgrade, the best I can get is a tunnel for a few minutes with a verly low throughput. To achieve this I have to restar

Re: [pfSense] serial port sadness

2015-02-25 Thread Dr. Peter Voigt
On Wed, 25 Feb 2015 01:26:04 -1000 Jeremy Bennett wrote: > I'm using a cable that came with a Cisco router, I googled the part > number and I'm pretty sure it came back with a Null modem cable. Not sure if I have read all about your issue. But my Cisco SG300 switches are operating with straight

Re: [pfSense] serial port sadness

2015-02-25 Thread Jeremy Bennett
I'm using a cable that came with a Cisco router, I googled the part number and I'm pretty sure it came back with a Null modem cable. The strangest thing is that I'm pretty sure I had this working at one point. I'll post back when I find the solution. On Mon, Feb 23, 2015 at 6:24 PM, Oliver Hansen

Re: [pfSense] pfsense 2.2 Strongswan rekeying issues

2015-02-25 Thread Brian Candler
On 24/02/2015 21:44, Brian Candler wrote: Many thanks. I've made that change now and I'll see over the next few days if it stays up. Unfortunately it didn't :-( 2015 Feb 25 06:07:30 Group = X.X.X.219, IP = X.X.X.219, Error: dynamic map SYSTEM_DEFAULT_CRYPTO_MAP: * to any not permitted. 2015 F