[pfSense] Automated updates to firewall rules

2013-03-29 Thread Jason Pyeron
, but ssh commands would work too. Any suggestions? -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10

Re: [pfSense] Automated updates to firewall rules

2013-03-29 Thread Jason Pyeron
editing /cf/conf/config.xml and then /etc/rc.reload_all would be too disruptive. -Jason -- Michael D. Wood www.itsecuritypros.org -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jason Pyeron Sent: Friday, March 29, 2013

Re: [pfSense] Automated updates to firewall rules

2013-03-31 Thread Jason Pyeron
Does anyone know why the alias code is hard limited at 4999 aliases? See firewall_aliases_edit.php:line 251: for($x=0; $x4999; $x++) { -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron

[pfSense] Watchdog timer?

2013-04-12 Thread Jason Pyeron
-and-hardwaresoftware-watchdogs/, where should I go to learn more about setting a watchdog timer up? -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us

[pfSense] Packet capture

2013-04-28 Thread Jason Pyeron
? -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

Re: [pfSense] Packet capture

2013-04-28 Thread Jason Pyeron
to examine more closely in wireshark. As for traffic denied by the firewall have you tried looking at the firewall logs? Trevor On Apr 28, 2013 5:47 AM, Jason Pyeron jpye...@pdinc.us wrote: I am looking to capture all the packets that are traversing and attempting to traverse the firewall. If I

Re: [pfSense] Packet capture

2013-04-28 Thread Jason Pyeron
data. _ From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jason Pyeron Sent: Sunday, April 28, 2013 12:47 To: 'pfSense support and discussion' Subject: Re: [pfSense] Packet capture Yes the interface for packet capture is nice for a interactive

Re: [pfSense] Packet capture

2013-04-28 Thread Jason Pyeron
://www.northshoresoftware.com/ https://mail.google.com/mail/u/0/?ui=2ik=3456340655view=attth=13ab8f806fccb0 7eattid=0.2disp=inlinerealattid=f_h8z0yrka2safe=1zwsaduie=AG9B_P_0HvEbIe6v cnhsenP3ZJizsadet=1352854635474sads=QIpOFwfaK2xnZX61g1WsD4mNl08 On Sun, Apr 28, 2013 at 9:46 AM, Jason Pyeron jpye...@pdinc.us wrote

Re: [pfSense] Packet capture

2013-04-28 Thread Jason Pyeron
=13ab8f806fccb0 7eattid=0.2disp=inlinerealattid=f_h8z0yrka2safe=1zwsaduie=AG9B_P_0HvEbIe6v cnhsenP3ZJizsadet=1352854635474sads=QIpOFwfaK2xnZX61g1WsD4mNl08 On Sun, Apr 28, 2013 at 1:21 PM, Jason Pyeron jpye...@pdinc.us wrote: Nice. I did not now about that. When a packet is logged by PF

[pfSense] Filter rule and bridge confusion

2013-05-01 Thread Jason Pyeron
-- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

Re: [pfSense] Packet capture

2013-05-01 Thread Jason Pyeron
:21 PM, Jason Pyeron jpye...@pdinc.us wrote: Nice. I did not now about that. When a packet is logged by PF, a copy of the packet header is sent to a pflog(4) http://www.openbsd.org/cgi-bin/man.cgi?query=pflogsektion=4manpath=OpenBSD+5. 2 interface along with some additional data

Re: [pfSense] Bandwith Management

2013-05-01 Thread Jason Pyeron
.. Thank You with google: http://lmgtfy.com/?q=How+to+Configure+Bandwidth+Management+rules+in+pfSense Do you have a more specific question? -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron

[pfSense] Best configuration for redundant transparent firewall operation?

2013-05-12 Thread Jason Pyeron
#pfsyncop 3: http://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_(CARP) 4: http://www.seattlecentral.edu/~dmartin/docs/bridge.html -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason

[pfSense] pfSense and the Firewall Security Technical Implementation Guide (STIG)

2013-05-26 Thread Jason Pyeron
://iase.disa.mil/stigs/net_perimeter/network_infra/u_network_firewall_v8r14_ stig_20130426.zip -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal

Re: [pfSense] lock-ups

2013-06-08 Thread Jason Pyeron
. -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us http://www.pdinc.us/ - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

Re: [pfSense] psSense stops working

2014-01-22 Thread Jason Pyeron
@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us http://www.pdinc.us

Re: [pfSense] Poweredge 2850

2014-05-20 Thread Jason Pyeron
!!! -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

[pfSense] Alerts on bandwidth conditions

2014-06-09 Thread Jason Pyeron
? -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

Re: [pfSense] Alerts on bandwidth conditions

2014-06-10 Thread Jason Pyeron
://doc.pfsense.org/index.php/Setup_Snort_Package This is going to take a few weeks to experiment with. Thanks. On Mon, Jun 9, 2014 at 12:16 PM, Jason Pyeron jpye...@pdinc.us wrote: We are trying to enhance our (D)DOS detection and response. Can pfSense create alerts when the bandwith goes over X

Re: [pfSense] skype 29 minute fail

2014-06-16 Thread Jason Pyeron
List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us

[pfSense] Any experience with http://www.aliexpress.com/store/product/Compact-1U-router-server-firewall-server-with-MINI-ITX-Six-Gigabit-LANs-motherboard/908909_583033075.html

2014-09-09 Thread Jason Pyeron
-- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland

[pfSense] Small network sensor tool (Java on pfSense?)

2014-10-07 Thread Jason Pyeron
concerns (such as CPU usage, etc.) -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street

[pfSense] a notification is not sent when a gateway is down [https://redmine.pfsense.org/issues/3306]

2014-10-08 Thread Jason Pyeron
resources. Any suggestions? -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100

Re: [pfSense] a notification is not sent when a gateway is down[https://redmine.pfsense.org/issues/3306]

2014-10-08 Thread Jason Pyeron
-Original Message- From: Brian Caouette Sent: Wednesday, October 08, 2014 11:59 On 10/8/2014 11:39 AM, Jason Pyeron wrote: I think I am being hit by the same issue. Here is what I tried: Version: 2.0.2-RELEASE (i386) built on Fri Dec 7 16:30:25 EST 2012 FreeBSD 8.1

Re: [pfSense] a notification is not sent when a gatewayis down[https://redmine.pfsense.org/issues/3306]

2014-10-08 Thread Jason Pyeron
-Original Message- From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of compdoc Sent: Wednesday, October 08, 2014 12:46 To: 'pfSense Support and Discussion Mailing List' Subject: Re: [pfSense] a notification is not sent when a gatewayis

[pfSense] Trying to debug check_reload_status using too much CPU [https://redmine.pfsense.org/issues/2555]

2014-10-09 Thread Jason Pyeron
0:00.02 /bin/tcsh root 57023 0.0 0.3 3456 1236 0 R+ 11:52AM 0:00.00 ps auxwww -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us

Re: [pfSense] Trying to debug check_reload_status using too much CPU[https://redmine.pfsense.org/issues/2555]

2014-10-09 Thread Jason Pyeron
-Original Message- From: Jason Pyeron Sent: Thursday, October 09, 2014 12:06 A transparent firewall is showing the same problem as ticket 2555, I am unable to diagnose the issues without help. I have tried rebooting, the problem comes back at boot time. Killing the process

[pfSense] Pflog undocumented rule (https://forum.pfsense.org/index.php?topic=52887.0)

2014-10-24 Thread Jason Pyeron
02 04 17 00 00 00 00 F.. ..@. 0050 e0 00 00 01 94 04 00 00 11 64 ee 9b 00 00 00 00 .d.. -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc

Re: [pfSense] APU and SSD: full install or NanoBSD

2014-10-30 Thread Jason Pyeron
-- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333Baltimore, Maryland 21218

Re: [pfSense] https filtering

2014-11-21 Thread Jason Pyeron
in? -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269-1555 x333

[pfSense] Blocking non-SSL mysql traffic?

2016-06-06 Thread Jason Pyeron
e? -Jason -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- - - - Jason Pyeron PD Inc. http://www.pdinc.us - - Principal Consultant 10 West 24th Street #100- - +1 (443) 269

Re: [pfSense] Turning UDP broadcast into a unicast onanotherinterface

2016-06-01 Thread Jason Pyeron
> -Original Message- > From: Chris Buechler > Sent: Wednesday, June 01, 2016 14:54 > > On Wed, Jun 1, 2016 at 8:00 AM, Jason Pyeron <jpye...@pdinc.us> wrote: > >> -Original Message- > >> From: On Behalf Of Jim Thompson > >> Se

Re: [pfSense] Turning UDP broadcast into a unicast on anotherinterface

2016-06-01 Thread Jason Pyeron
> -Original Message- > From: On Behalf Of Jim Thompson > Sent: Tuesday, October 02, 2012 19:24 > Subject: [pfSense] Turning UDP broadcast into a unicast on another interface > > Without writing a small program? No, I can't think of a way. Before I go a write such a program, does

Re: [pfSense] passwordless console access

2016-05-03 Thread Jason Pyeron
> -Original Message- > From: j...@use.startmail.com > Sent: Tuesday, May 03, 2016 1:06 PM > > Greetings, > > I wonder if it is possible to configure passwordless ssh > access via ssl keys like done is regular unix via ssh-copy-id command. Yes. Googling the correct terminology: