Re: [pfSense] successor to ALIX is here

2014-04-02 Thread Jim Thompson
On Apr 2, 2014, at 3:17 PM, Thinker Rix wrote: > On 2014-04-02 17:35, Eugen Leitl wrote: >> Apu.1c >> http://www.heise.de/newsticker/meldung/Embeddded-Mainboard-mit-x86-CPU-und-Coreboot-2160404.html >> >> http://www.pcengines.ch/apu1c.htm >> >> in stock, €105.13 > > Unfortunately again only

Re: [pfSense] successor to ALIX is here

2014-04-02 Thread Jim Thompson
On Apr 2, 2014, at 3:24 PM, Ryan Coleman wrote: > Wouldn’t a layer-3 switch be a good investment in this situation? Put the > load on another device instead of, what is for all intents and (definitely) > purpose a thin, light-weight piece of hardware? It doesn’t even need to be a layer-3 swit

Re: [pfSense] successor to ALIX is here

2014-04-02 Thread Jim Thompson
On Apr 2, 2014, at 5:01 PM, Chris Bagnall wrote: > On 2/4/14 9:17 pm, Thinker Rix wrote: >> Unfortunately again only 3 NICs... and Realteks with bad performance. >> I would love to see such a board one day with at least 4-8 NICs. > > On that subject, we've recently been experimenting with these

Re: [pfSense] successor to ALIX is here

2014-04-03 Thread Jim Thompson
On Apr 3, 2014, at 2:38 PM, Bob Gustafson wrote: > > On 04/02/2014 04:55 PM, Jim Thompson wrote: >> This would enable multiples of 10G performance for load-balancing, packet >> filtering, and even NAT (with the right switch hardware). > > Dreamer - from my Chicago fr

Re: [pfSense] successor to ALIX is here

2014-04-03 Thread Jim Thompson
On Apr 3, 2014, at 3:35 PM, Dave Riesz wrote: > On Wed, Apr 2, 2014 at 3:44 PM, Jim Thompson wrote: > > > Yeah, we carried those for a while, then they started coming back, so we > carrying it in the store, and are moving the remaining inventory on Amazon. > I think we cal

[pfSense] pfSense version 2.1.1 has been released

2014-04-04 Thread Jim Thompson
Please see the blog post https://blog.pfsense.org/?p=1238 or changelog https://doc.pfsense.org/index.php/2.1.1_New_Features_and_Changes for details. Happy upgrading. Jim ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman

Re: [pfSense] successor to ALIX is here

2014-04-05 Thread Jim Thompson
On Apr 5, 2014, at 8:53 AM, Thinker Rix wrote: > On 2014-04-05 07:00, Ryan Coleman wrote: >> And you cannot eliminate three of this with a switch? > > I don't know any method how a network switch could replace the NICs of my > firewall - other than by operating with VLANs. > > But I do not tr

Re: [pfSense] New intel atom board

2014-04-05 Thread Jim Thompson
On Apr 5, 2014, at 12:48 PM, Ugo Bellavance wrote: > http://techcrunch.com/2014/04/03/intel-releases-99-minnowboard-max-an-open-source-single-board-computer/?utm_campaign=fb&ncid=fb > > An interesting platform for pfSense? > > It looks like it only has 1 NIC though. I looked at this earlier i

Re: [pfSense] 2.1 can't auto-update anymore?

2014-04-05 Thread Jim Thompson
Kevin, Glad you like the update. You won’t get ‘mutlicore’ PF until pfSense 2.2 (which is based on FreeBSD 10). Snapshots are available now. Rangely hardware, you say? http://store.netgate.com/Firewall/C2758.aspx Also available “real soon now" at the pfSense store. We believe in the C2000,

Re: [pfSense] New intel atom board

2014-04-05 Thread Jim Thompson
On Apr 5, 2014, at 5:06 PM, Adam Thompson wrote: > On 14-04-05 02:02 PM, Jim Thompson wrote: >>> http://techcrunch.com/2014/04/03/intel-releases-99-minnowboard-max-an-open-source-single-board-computer/?utm_campaign=fb&ncid=fb >>> An interesting platform for pfSense?

Re: [pfSense] The Heartbleed Bug, CVE-2014-0160

2014-04-08 Thread Jim Thompson
Well, that’s the point, Paul. (You hit the nail on the head.) If you don’t have an openssl service exposed, the problem doesn’t affect you. Since normally the web GUI isn’t exposed to the WAN, the attack surface is minimized. We are working at cutting a new release. Jim On Apr 8, 2014, at 1

Re: [pfSense] The Heartbleed Bug, CVE-2014-0160

2014-04-08 Thread Jim Thompson
On Apr 8, 2014, at 12:34 PM, Paul Heinlein wrote: > On Tue, 8 Apr 2014, b...@todoo.biz wrote: > >> This might not be enough as there are two versions of openssl installed… One >> in /usr/bin/openssl and one in /usr/local/bin/openssl >> >> Both should be ok. > > Not on 2.1: > > [2.1-RELEASE]

Re: [pfSense] The Heartbleed Bug, CVE-2014-0160

2014-04-08 Thread Jim Thompson
On Apr 8, 2014, at 3:39 PM, Rainer Duffner wrote: > > Am 08.04.2014 um 21:04 schrieb Jim Thompson : > >> >> Well, that’s the point, Paul. (You hit the nail on the head.) >> >> If you don’t have an openssl service exposed, the problem doesn’t affect you.

Re: [pfSense] The Heartbleed Bug, CVE-2014-0160

2014-04-09 Thread Jim Thompson
Sense 2.2 snapshots. -- Jim > On Apr 8, 2014, at 21:05, Paul Mather wrote: > >> On Apr 8, 2014, at 9:35 PM, Paul Mather wrote: >> >>> On Apr 8, 2014, at 3:04 PM, Jim Thompson wrote: >>> >>> >>> Well, that’s the point, Paul. (You h

Re: [pfSense] The Heartbleed Bug, CVE-2014-0160

2014-04-09 Thread Jim Thompson
2.1.2 wasn’t “UP”. Chris cut a version of something he called “2.1.2” that he indicated *might* become 2.1.2, but it was incomplete. So I asked him to pull it back down. Jim On Apr 9, 2014, at 4:59 PM, Ryan Coleman wrote: > There was a post to the list at 0400 central US today that 2.1.2 was

Re: [pfSense] 2.1.2-RELEASE up for testing

2014-04-10 Thread Jim Thompson
The final testing (testing updates against the real update servers, which can’t be effectively simulated) is happening now. jim On Apr 10, 2014, at 12:50 PM, k_o_l wrote: > Any update to when the fix will be released?! > > -Original Message- > From: List [mailto:list-boun...@lists

[pfSense] pfSense 2.1.2 is released

2014-04-10 Thread Jim Thompson
https://blog.pfsense.org/?p=1253 pfSense release 2.1.2 is now available. pfSense release 2.1.2 follows less than a week after pfSense release 2.1.1, and is primarily a security release. The Heartbleed OpenSSL bug and another OpenSSL bug which enables a side-channel attack are both covered by

Re: [pfSense] pfSense 2.1.2 is released

2014-04-10 Thread Jim Thompson
On Apr 10, 2014, at 4:10 PM, Volker Kuhlmann wrote: > On Fri 11 Apr 2014 07:23:52 NZST +1200, Jim Thompson wrote: > >> pfSense release 2.1.2 is now available. > > Thank you for all the quick work! > > May I ask though why this isn't simultaneously posted on &

Re: [pfSense] pfSense 2.1.2 is released

2014-04-10 Thread Jim Thompson
On Apr 10, 2014, at 4:25 PM, Dimitri Rodis wrote: > Can we also get information as to which versions of pfSense are affected > aside from 2.1.1? Or is 2.1.1 the only affected version? https://pfsense.org/security/advisories/pfSense-SA-14_04.openssl.asc ___

Re: [pfSense] pfSense 2.1.2 is released

2014-04-11 Thread Jim Thompson
They're built; we're waiting on Amazon. -- Jim > On Apr 11, 2014, at 22:41, linbloke wrote: > > >> On 11/04/2014 5:23 am, Jim Thompson wrote: >> https://blog.pfsense.org/?p=1253 >> >> pfSense release 2.1.2 is now available. pfSense release 2.1.2

Re: [pfSense] pfSense 2.1.2 is released

2014-04-12 Thread Jim Thompson
> On Apr 12, 2014, at 18:55, Volker Kuhlmann wrote: > >> On Fri 11 Apr 2014 18:43:18 NZST +1200, Ryan Coleman wrote: >> >> He gave you an option to subscribe to the list. > > You seem to have missed the point I was making: critical security fixes > (the 2.1.2 release in this case, unless I am

Re: [pfSense] pfSense Book (Buechler / Pingle)

2014-04-13 Thread Jim Thompson
> On Apr 13, 2014, at 5:11, Thinker Rix wrote: > > Hi, > > I own a hard copy of the pfSense book by Chris and Jim and have two questions > about it: > > 1. As a buyer of the hard copy, am I eligible to receive a gratis PDF-version > of the book, too? No. > 2. Is there any ETA for the har

Re: [pfSense] pfSense Book (Buechler / Pingle)

2014-04-13 Thread Jim Thompson
> On Apr 13, 2014, at 6:09, Volker Kuhlmann wrote: > >> On Sun 13 Apr 2014 22:11:41 NZST +1200, Thinker Rix wrote: >> >> I own a hard copy of the pfSense book by Chris and Jim and have two >> questions about it: >> >> 1. As a buyer of the hard copy, am I eligible to receive a gratis >> PDF-ve

Re: [pfSense] pfSense Book (Buechler / Pingle)

2014-04-13 Thread Jim Thompson
> On Apr 13, 2014, at 11:28, Kevin Tollison wrote: > > Even easier. I have a support subscription. I just uploaded the epub to my > Google Drive. As long as you don't share it, this is fine. ___ List mailing list List@lists.pfsense.org https://list

Re: [pfSense] pfSense 2.1.2 is released

2014-04-15 Thread Jim Thompson
ibrary. Can you post the AMI IDs here or to the security announce list when > they're available please? > > Kind regards, > lb > > >> On 12/04/2014 4:19 pm, Jim Thompson wrote: >> They're built; we're waiting on Amazon. >> >> -- Jim >&

Re: [pfSense] pfSense 2.1.2 is released

2014-04-16 Thread Jim Thompson
On Apr 16, 2014, at 4:34 PM, Brian Candler wrote: > On 15/04/2014 20:12, Jim Thompson wrote: >> We dropped the price, too. >> >> -- Jim > Which price are you referring to? On the EC2 instance(s). > I see that a support subscription is now $200 for 2 hours plus $2

Re: [pfSense] Interface options for pfsense

2014-04-22 Thread Jim Thompson
> On Apr 22, 2014, at 7:26, Stefan Baur wrote: > > Am 22.04.2014 14:19, schrieb Vick Khera: >> I disagree that is a sufficient condition, unless you restrict this >> statement to hme interfaces. > > From his previous posts, I think it's pretty obvious that that is what > he meant. :-) Hardly.

Re: [pfSense] Interface options for pfsense

2014-04-22 Thread Jim Thompson
> On Apr 22, 2014, at 10:39, Stefan Baur wrote: > > In fact, I'd be petty disappointed, too, if a newer pfSense release > stopped working on my hardware and it the whole issue appeared out of the > blue (== no "hwe driver no longer supported" or similar notice in the release > notes). Your po

Re: [pfSense] Interface options for pfsense

2014-04-22 Thread Jim Thompson
On Apr 20, 2014, at 5:32 PM, Volker Kuhlmann wrote: > I've been running pfsense for many years (and been very happy with it) > on scrapped PCs with a Sun 4-port Ethernet PCI card because I need 5 > Ethernet ports. > > Now freebsd dieing on the hme driver effectively turns those cards into > scr

Re: [pfSense] Interface options for pfsense

2014-04-22 Thread Jim Thompson
On Apr 22, 2014, at 12:27 PM, Stefan Baur wrote: > Am 22.04.2014 18:29, schrieb Jim Thompson: > >> It's not like we disabled the hme driver. > > Nobody accused you of intentionally disabling it. Manure happens. :-) Relax. > > >> We have no ability to

Re: [pfSense] Interface options for pfsense

2014-04-22 Thread Jim Thompson
On Apr 22, 2014, at 3:42 PM, Volker Kuhlmann wrote: > On Wed 23 Apr 2014 05:02:59 NZST +1200, Jim Thompson wrote: > >>> Are there any USB Ethernet adapters that actually work with pfsense? >>> Reliably? I am looking for reports from those who have tried, not the >&

Re: [pfSense] Upgrading Alix 2d13

2014-05-03 Thread Jim Thompson
> On May 2, 2014, at 23:42, David Newman wrote: > > It's possible this is related to this being 4G Sandisk CF cards, and > modern 2G and 4G Sandisk cards producing alignment errors. Unlikely. ___ List mailing list List@lists.pfsense.org https://lists

Re: [pfSense] upgrade dual ALIX netgate box?

2014-05-08 Thread Jim Thompson
On May 8, 2014, at 12:04 PM, b...@todoo.biz wrote: > Hi we are french resellers of Alix / APU > > > Le 6 mai 2014 à 21:16, Vick Khera a écrit : > >> I have the dual ALIX RM1U box from netgate which is a bit over 2 years old >> now (and an older one too!) >> >> Has anyone attempted replacing

Re: [pfSense] Giant lock is still there?

2014-05-17 Thread Jim Thompson
On May 17, 2014, at 5:16 PM, Leon Volfson wrote: > Hi guys, > > I had lots of issues in the past with the performance > and as I understood then - one of the biggest problems was > the Giant lock in pf. > > Since the 2.2 version is going to be FreeBSD 10 based I looked it up and > saw that the

Re: [pfSense] Poweredge 2850

2014-05-20 Thread Jim Thompson
On May 20, 2014, at 9:30 AM, Giles Coochey wrote: > On 20/05/2014 12:28, Ryan Coleman wrote: >> On May 20, 2014, at 1:59, Giles Coochey wrote: >> >>> >>> s >>> Not to mention that if I ran a PE 2850 at home there would probably be >>> complaints about the noise!!! Those things *scream* in th

Re: [pfSense] Poweredge 2850

2014-05-20 Thread Jim Thompson
If you had purchased something more modern, (even an APU, which uses 5-10% of your 2850, and is completely silent) bhyve would be an option. Which is the general direction I'm headed with pfSense for being able to run a media center or NAS on top. Refurb c1100s are < $600 on fleabay with 8 cor

Re: [pfSense] pfsense performance

2014-05-21 Thread Jim Thompson
On May 21, 2014, at 8:44 PM, Adam Thompson wrote: > On 14-05-21 08:27 PM, Joseph H wrote: >> Hi Everyone, >> >> I was having a debate with a new network engineer we have and we were >> discussing how pfSense performs and how it would handle 10G network >> connections, setup as a transparent f

Re: [pfSense] Report Errors

2014-06-02 Thread Jim Thompson
> On Jun 2, 2014, at 13:18, Brian Caouette wrote: > > As much as I like pfSense it > and packages are really prone to glitches and over all bugs. PfSense has bugs, and packages have bugs, but it is a mistake to conflate the two. ___ List mailing lis

Re: [pfSense] Report Errors

2014-06-02 Thread Jim Thompson
> On Jun 2, 2014, at 10:02 PM, Ryan Coleman wrote: > > It’s also a mistake to not report them to the maintainers. :) That’s true, and the maintainers for Squid, Snort and Silicata are very good about fixing said bugs. Jim ___ List mailing list List

Re: [pfSense] apu.4c silently dies

2014-06-04 Thread Jim Thompson
On Jun 4, 2014, at 2:29 PM, mayak wrote: > i really want to love this board, but, it it is simply a heater -- my > problems are thermal. > > i have now completely removed the the board from the case and put a huge > copper heat sync on it -- i'll take a picture -- i placed it next to a switch

Re: [pfSense] 802.11ac Mini PCI Express adapter for pfSense

2014-07-20 Thread Jim Thompson
there is no 802.11ac support in FreeBSD (and thus pfSense) as yet. 802.11n support is in FreeBSD 10 (and thus pfSense 2.2) > On Jul 20, 2014, at 11:08 PM, Ryan Coleman wrote: > > The compatibility is strictly up to the software drivers. Is the driver for > the card you’re looking at listed in t

Re: [pfSense] 802.11ac Mini PCI Express adapter for pfSense

2014-07-21 Thread Jim Thompson
> On Jul 21, 2014, at 8:18 AM, Nickolai Leschov wrote: > > What is the status of pfSense 2.2? alpha snapshots ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
> On Jul 22, 2014, at 10:56, Eugen Leitl wrote: > >> On Tue, Jul 22, 2014 at 02:40:44PM +, Ryan Coleman wrote: >> Is there a difference between the 4 and the 1C4? Is Netgate just trying to >> fleece people for an extra $200 by packaging the entire thing together built >> and tested? >> htt

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
> On Jul 22, 2014, at 10:58, Ryan Coleman wrote: > > I asked the differences in the two line items from netgate. Perhaps you should ask sa...@netgate.com Jim ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
> On Jul 22, 2014, at 17:19, Nickolai Leschov wrote: > > I wonder why they wouldn't just build the board with some appropriate Atom > CPU? :-) > And maybe even more performant, to boot? E3815, probably? Bay Trail? Why? That's for tablets. C2xx8 more likely. IJS...__

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
On Jul 22, 2014, at 17:19, Nickolai Leschov wrote: >> Just like the others: dissipation through the aluminum case > How does the CPU connect to the aluminum case? Is there some thermal > interface involved? Maybe an interface between CPU heatsink and aluminum case? Yes, there is a transfer "p

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
Very little if this thread is related to pfSense. Please stay on topic. -- Jim > On Jul 22, 2014, at 17:32, Chris Bagnall wrote: > >> On 22/7/14 11:17 pm, Nickolai Leschov wrote: >> I didn't notice this page. So it looks like it's some kind of thermal paste >> allows for adequate thermal co

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
Ryan, Profanity and personal attacks have no place on this list. -- Jim > On Jul 22, 2014, at 20:12, Ryan Coleman wrote: > > Look fuck nut: branded and shipped hardware is 100% on topic. Thank you. > > >> On Jul 22, 2014, at 20:10, Jim Thompson wrote: >> >&

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
On Jul 22, 2014, at 16:30, Nickolai Leschov wrote: >> Bay Trail? Why? That's for tablets. > What's the difference, in practical terms? First: Rangeley has an integrated i354 10/100/1000 quad Ethernet MAC. Bay Trail requires one to add Ethernet Second: Rangeley has a high-speed crypto co

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
ded and shipped hardware is 100% on topic. Thank you. >> >> >>> On Jul 22, 2014, at 20:10, Jim Thompson wrote: >>> >>> Very little if this thread is related to pfSense. >>> >>> Please stay on topic. >>> >>> -- Jim

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-22 Thread Jim Thompson
;> that assume that because a company wants to make a profit that they are >> fleecing people? The $6 margin on a $299 product hardly seem like a rip off >> (my time is worth a lot more than that). >> >> And you get a tested system with a warranty. >> >> Loo

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-27 Thread Jim Thompson
> On Jul 27, 2014, at 13:06, Matthias May wrote: > > Am 27.07.2014 18:32, schrieb Kenward Vaughan: >> On 07/22/2014 02:19 PM, Rainer Duffner wrote: >>> >>> Am 22.07.2014 um 21:29 schrieb Nickolai Leschov >> >: >>> The difference is not $200, but about $100 with

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-27 Thread Jim Thompson
> On Jul 22, 2014, at 16:19, Rainer Duffner wrote: > > >> Am 22.07.2014 um 21:29 schrieb Nickolai Leschov : >> >> The difference is not $200, but about $100 with 8GB Sandisk Extreme Secure >> [sic!] SDHC card included. >> >> 1. What's secure about this card? I suppose it's a regular SDHC on

[pfSense] Seeking ipfw & pf rulesets for performance work

2014-07-27 Thread Jim Thompson
We're doing some performance work with pf, and have issued a call for pf and ipfw rule sets. http://lists.freebsd.org/pipermail/freebsd-net/2014-July/039373.html If you wish to help, please get in-touch with George. -- Jim ___ List mailing list Lis

Re: [pfSense] Difference between APU4 and APU1C4

2014-07-27 Thread Jim Thompson
Ryan, Your point is entirely lost, I’ve already shown where your words are false by any measure. Time to close this thread. Jim > On Jul 27, 2014, at 9:08 PM, Ryan Coleman wrote: > > Nickolai, > > I don’t know about you but I get my 8GB SDHC Class 10 cards for between $5 > and $15. > >

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Jim Thompson
> On Jul 30, 2014, at 3:21 PM, Stefan Baur > wrote: > > Am 30.07.2014 um 22:09 schrieb Espen Johansen: >> ZFS = FS+LVM. Its efficient in many ways. Its highly resillient to >> things like silent data corruption ( disk FW bugs, power spikes). It has >> on the fly checking and repair. Copy on wri

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Jim Thompson
> On Jul 30, 2014, at 4:40 PM, Stefan Baur > wrote: > > Am 30.07.2014 um 23:34 schrieb Jim Thompson: >> tl;dr: I wouldn’t run ZFS… yet. >> >> I didn’t see the error message, you’re barking up a tree attempting to use >> it right now. > > Again, I

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Jim Thompson
Well, you could use it for that (pfSense on pfSense), but there will be unnecessary overhead. > On Jul 30, 2014, at 4:38 PM, Josh Reynolds wrote: > > Sounds like the mikrotik metarouter feature. > > Josh Reynolds, CIO > SPITwSPOTS > www.spitwspots.com > >

Re: [pfSense] ZFS warning message on local console during boot

2014-07-30 Thread Jim Thompson
> On Jul 30, 2014, at 7:20 PM, Paul Mather wrote: > > Despite all that FreeBSD ZFS love, I still would not recommend it on > FreeBSD/i386-based installations (as the OP said he was using). It is > much more of a headache to use in that milieu, and, IMHO, doesn't get > the testing and general ca

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
Ryan, Don't troll. > On Aug 27, 2014, at 7:33 AM, Ryan Coleman wrote: > > Wait, so the SDHC slot on this board is simply for show? > >> On Aug 26, 2014, at 13:56, Sergii Cherkashyn >> wrote: >> >> Thank you Espen, >> >> Squid is for filtering purpose only, not to save bandwidth. >> On

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
to carry two different SKUs (one with, one without). Jim > On Aug 27, 2014, at 7:57 AM, Ryan Coleman wrote: > > Why not answer the question? > > > On Aug 27, 2014, at 7:56, Jim Thompson <mailto:j...@netgate.com>> wrote: > >> Ryan, >> >> Don&#

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
n the features page it can be > booted off the SD slot - is that true? If so I have to change a few quotes I > have in play as they will need to get mSATA SSDs instead. > > On Aug 27, 2014, at 9:20, Jim Thompson <mailto:j...@smallworks.com>> wrote: > >> >> T

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
> > -- > Ryan Coleman > ryanjc...@me.com > m. 651.373.5015 > o. 612.568.2749 > >> On Aug 27, 2014, at 9:24, Jim Thompson wrote: >> >> >> Yes, the system can be booted from an SD (or SDHC) card. Or from USB, or >> from the m-SATA. >

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
an Coleman > ryanjc...@me.com > m. 651.373.5015 > o. 612.568.2749 > > On Aug 27, 2014, at 9:24, Jim Thompson wrote: > >> >> Yes, the system can be booted from an SD (or SDHC) card. Or from USB, or >> from the m-SATA. >> >> All of these require proper

Re: [pfSense] Netgate APU2 SSD module question

2014-08-27 Thread Jim Thompson
h USB. > > -- > Ryan Coleman > ryanjc...@me.com <mailto:ryanjc...@me.com> > m. 651.373.5015 > o. 612.568.2749 > > On Aug 27, 2014, at 9:24, Jim Thompson <mailto:j...@netgate.com>> wrote: > >> >> Yes, the system can be booted from an

Re: [pfSense] Netgate APU2 SSD module question

2014-08-28 Thread Jim Thompson
easy one based on what the OP asked. > There is allways better cheaper and faster tech just around the corner. > > 27. aug. 2014 21:26 skrev "Jim Thompson" følgende: >> SD cards are storage, but not “disks” nor “drives”. >> >> Beyond m-SATA, eMMC is your best

Re: [pfSense] Fwd: [Announce] 2.1.5 Release

2014-08-29 Thread Jim Thompson
again, the CSS changed, and the browsers love to cache that stuff. On Fri, Aug 29, 2014 at 8:47 AM, Peder Rovelstad wrote: > >>> I did note the "Code Red" color scheme wraps the page header bar, putting >>> "Help" under "System". I have such problems... > > It did this for me a well, but holdin

Re: [pfSense] menu bar in safari on 2.1.5

2014-08-29 Thread Jim Thompson
Have you reloaded (the CSS changed) and/or cleared the browser cache? (I use Safari, too.) On Fri, Aug 29, 2014 at 10:15 AM, Vick Khera wrote: > In 2.1.5 pfsense_ng theme, you added a new menu bar item for the Gold > support subscription. > > What this does in Safari is make the "system" menu

Re: [pfSense] pfSense hardware with comersial support.

2014-08-29 Thread Jim Thompson
> On Aug 29, 2014, at 10:19 AM, Vick Khera wrote: > > On Thu, Aug 28, 2014 at 3:37 AM, Ulrik Lunddahl wrote: >> Is there a difference in the software (firmware image) >> >> Is there a difference in the bundled support. > > From what I can tell, the difference between the Netgate products and

Re: [pfSense] pfSense hardware with comersial support.

2014-08-29 Thread Jim Thompson
Not ‘DBAs’. (Technically ‘Netgate’ is a DBA on “Rubicon Communications, LLC”, and pfSense is really “Electric Sheep Fencing, LLC”. There is no “pfSense” DBA (though I’ve considered it.) > On Aug 29, 2014, at 10:23 AM, Ryan Coleman wrote: > > It is the same product - they are just two diffe

Re: [pfSense] Develop Applications for pfseu

2014-09-10 Thread Jim Thompson
> On Sep 9, 2014, at 9:37 PM, Ryan Coleman wrote: > > Hi Tom! > > You would be better suited contacting Electric Sheep Fencing > (http://www.electricsheepfencing.com/) directly for your how-to but you can > start with a few basic concepts: > 1) This system is running FreeBSD 8.3 at present (f

Re: [pfSense] menu bar in safari on 2.1.5

2014-09-10 Thread Jim Thompson
gt; >>> De: "Vick Khera" <mailto:vi...@khera.org> >>> Para: "pfSense Support and Discussion Mailing List" >>> <mailto:list@lists.pfsense.org> >>> Enviados: Viernes, 29 de Agosto 2014 17:24:43 >>> Asunto: Re: [pfSens

Re: [pfSense] CVE-2004-0230

2014-09-18 Thread Jim Thompson
Maybe a blog post about this? -- Jim > On Sep 18, 2014, at 10:01, Jim Pingle wrote: > >> On 9/18/2014 8:55 AM, Martin Fuchs wrote: >> Does CVE-2004-0230 affect pfSense 2.1.5 ? > > As Vick mentions, practically the answer is 'no'. > > There are some rare cases when it might, however. It would

Re: [pfSense] OT: Good network switch for 10 machines?

2014-09-25 Thread Jim Thompson
All of pfSense (ESF & Netgate, including the collocation sites) runs on a combination of Dell PowerEdge 5524P (PoE), 5548, and 8924F switches. -- Jim > On Sep 23, 2014, at 12:56 PM, Chris Bagnall wrote: > >> On 23/9/14 6:46 pm, RB wrote: >> I'd suggest at least a managed switch that can do LAC

Re: [pfSense] bogon networks

2014-09-28 Thread Jim Thompson
Perhaps if you specified your block? > On Sep 28, 2014, at 5:59 AM, Andrew Mitchell > wrote: > > My company has just recently been assigned it's own block from ARIN. We have > a handful of pfSense boxes we need to connect to from that block. I have > noticed we can't when Block bogon networ

Re: [pfSense] upgrade from 1.2.3

2014-10-07 Thread Jim Thompson
Yer router, it’s 5 years out of date. https://blog.pfsense.org/?p=531 Best option is to replace it, likely. We have professional services to help with the upgrade if you need them. Jim > On Oct 7, 2014, at 8:38 AM, Nick Upson wrote: > > Hi > > I have a fi

Re: [pfSense] upgrade from 1.2.3

2014-10-07 Thread Jim Thompson
from 1.2.3 to 2.1.5. -- Jim > On Oct 7, 2014, at 8:57 AM, Chris Bagnall wrote: > >> On 7/10/14 2:41 pm, Jim Thompson wrote: >> Best option is to replace it, likely. > > This. > > Or at least install a recent pfSense on an unused device you have kicking > ar

Re: [pfSense] NIC support

2014-10-14 Thread Jim Thompson
> Will A SMB without L3 capable switches, that needs routing between 3-4 local > subnets (LAN, SERVERS, WIRELESS/GUEST, OTHER/DMZ) as close to wirespeed as > possible, be happy with a C2758. ? Very. Is a dual socket Xeon a bit faster? Yes. Does your application need that speed? Unlikely.

Re: [pfSense] NIC support

2014-10-15 Thread Jim Thompson
> On Oct 14, 2014, at 5:15 PM, compdoc wrote: > > >as close to wirespeed as possible, be happy with a C2758. ? > > > >Very > > > That C2758 has nice specs and should be able to keep up, however there seems > to be a throughput problem on at least one brand of board running the C2758. Whe

Re: [pfSense] NIC support

2014-10-15 Thread Jim Thompson
-- Jim > On Oct 15, 2014, at 10:06 AM, compdoc wrote: > > > When I speak of the C2758, I speak of the product sold at the pfSense store, > > as sold by the pfSense store, not the generic pfsense release running on > > "some > >brand of board@. > > I was speaking of a C2758 board that was test

Re: [pfSense] NIC support

2014-10-15 Thread Jim Thompson
> On Oct 15, 2014, at 4:06 PM, compdoc wrote: > > > There has been some testing using BSDRP, but it is not "a tool to test > > hardware". > > I used it as a tool to benchmark my hardware. There are several examples on > their website of using it for just that purpose. I am well-aware of Oli

Re: [pfSense] NIC support

2014-10-15 Thread Jim Thompson
> On Oct 15, 2014, at 5:01 PM, compdoc wrote: > > > I am well-aware of Olivier’s work in this area, as are many in the FreeBSD > > community. > > You’ve failed to disprove anything I've said, even the part about tools. I'm not going to argue with an individual who defines terms to suit h

Re: [pfSense] NIC support

2014-10-16 Thread Jim Thompson
> On Oct 16, 2014, at 2:06 AM, compdoc wrote: > > > I am well-aware of Olivier’s work in this area, as are many in the FreeBSD > > community. > > There is no proof, except that which is documented and reproducible. We're > > doing something like science here. > > Hmm, proof. Well, maybe a

Re: [pfSense] NIC support

2014-10-16 Thread Jim Thompson
> On Oct 16, 2014, at 11:14 AM, compdoc wrote: > > > The difference between Olivier's setup and ours (assuming pfsense 2.1.1+), > > is tuning > > The only way to prove what you say is with numbers. Tuning pfSense won't fix > this hardware problem, *if* it exists in your boards. Your assumpt

Re: [pfSense] NIC support

2014-10-16 Thread Jim Thompson
> On Oct 16, 2014, at 12:45 PM, compdoc wrote: > > > do you realize who you’re arguing with compdoc? > > Yeah, I'm arguing with a guy that not only attacked me for suggesting a > person be careful about buying certain hardware, he also attacked the work of > Olivier from BSDRP. > I neve

Re: [pfSense] NIC support

2014-10-17 Thread Jim Thompson
So, The only people getting a google fiber connection *today* live in Provo, UT or Kansas City. Google Funer is being built out in Austin, but won't be available until early 2015. My neighborhood will get it in the second pass, but I have a Grande 1Gbps/1Gbps connection to my house today, an

Re: [pfSense] NIC support

2014-10-17 Thread Jim Thompson
Corrections inline. I blame beer. -- Jim > On Oct 18, 2014, at 1:21 AM, Jim Thompson wrote: > > So, > > The only people getting a google fiber connection *today* live in Provo, UT > or Kansas City. > > Google Funer Fiber. > is being built out in Austin, b

Re: [pfSense] pfsense h/w

2014-10-22 Thread Jim Thompson
Talk to onset.eu. -- Jim > On Oct 22, 2014, at 9:32 AM, Nick Upson wrote: > > > I'm suffering in my efforts to install 2.1.5 onto my box, so can I change the > box? > > A proven hardware platform, available in the UK with at least 6 physical > network ports, I can probably justify buying.

Re: [pfSense] pfsense h/w

2014-10-22 Thread Jim Thompson
set.eu/ <http://onset.eu/> might be temporarily down > or it may have moved permanently to a new web address. > Error code: ERR_NAME_RESOLUTION_FAILED > > > Nick Upson, Telensa Ltd, Senior Operations Network Engineer > direct +44 (0) 1799 533252, support hotline +44 (0) 1799 39

Re: [pfSense] pfsense h/w

2014-10-22 Thread Jim Thompson
> On Oct 22, 2014, at 12:10 PM, Chris Buechler wrote: > > On Wed, Oct 22, 2014 at 11:29 AM, Jim Thompson wrote: >> Seems up now. I’ve let Gregory know that there may have been an issue. >> >> http://www.osnet.eu/en/products/FWA >> > > Pretty sure

Re: [pfSense] pfsense h/w

2014-10-23 Thread Jim Thompson
> On Oct 23, 2014, at 5:18 AM, Zia Nayamuth wrote: > > Lots of suggestions on the hardware, but I see nobody mention anything based > around the new and much more powerful Avoton platform. The platform is > officially supported, and the pfSense store has hardware based on it (looks > to be t

Re: [pfSense] pfsense h/w

2014-10-23 Thread Jim Thompson
ported and tested and optimized, I don't know why I would *sell* anything > else. > I'll continue to install pfSense in VMs and on existing repurposed hardware, > but that's an entirely different market segment anyway, and all I'm selling > is my time. > > -Ad

Re: [pfSense] pfsense h/w

2014-10-23 Thread Jim Thompson
people are waiting for “the other shoe to drop”. For us to take the pfSense project in a direction similar to what happened with Vyatta. This is not happening, but everyone seems to love chatting up conspiracy theories. Fluoride in the water and chemtrails overhead are evidence of gover

Re: [pfSense] pfsense h/w

2014-10-23 Thread Jim Thompson
> On Oct 23, 2014, at 7:48 PM, Adam Thompson wrote: > > [Hmm... half of this doesn't need to be on-list. Sorry if I'm polluting. > -Adam] > > > On 14-10-23 05:57 PM, Jim Thompson wrote: >>> I get that Jim rubs a lot of people the wrong way (mys

Re: [pfSense] pfsense h/w

2014-10-24 Thread Jim Thompson
ce industry as well as high capacity wifi) and >> I'd be curious to get some pros/cons from those who know... so please email >> me off list (so as not to offend the other Thompson on the list... he might >> molt on me anyway). >> >> Sliante! >>

Re: [pfSense] pfsense h/w

2014-10-24 Thread Jim Thompson
.pfsense.org/pipermail/dev/2013-November/000448.html > <http://lists.pfsense.org/pipermail/dev/2013-November/000448.html> > Josh Reynolds, Chief Information Officer > SPITwSPOTS, www.spitwspots.com <http://www.spitwspots.com/>On 10/24/2014 > 10:14 AM, Jim Thompson wrote: >>

Re: [pfSense] cheapest netgate/esf h/w with wireless?

2014-10-26 Thread Jim Thompson
> On Oct 26, 2014, at 12:51 PM, athompso wrote: > > Jim, I have three related h/w questions: > 1. what's the cheapest h/w currently available from ESF or Netgate that has > (or at least supports) being an AP? Technically, the Alix, when we can get them. Not that you want an Alix. > 2. I

Re: [pfSense] Revisiting PCIe LTE/4G modems

2014-10-28 Thread Jim Thompson
> On Oct 28, 2014, at 3:49 PM, Ryan Coleman wrote: > > So this project at my place of employment... the firewall selected (Sierra > Wireless GX440) doesn't seem to be passing UDP traffic over the link despite > having the device listed as the DMZ... > > So I'm hoping to get a possible alterna

Re: [pfSense] APU and SSD: full install or NanoBSD

2014-10-30 Thread Jim Thompson
3 year old Kingston SSDs are not like new Kingston SSDs. UFS is not ideal for SSD, but the pfSense store ships solutions with (Intel) SSD and UFS. So many people are confused by what it takes to make field equipment ‘live’ with an SSD, or SSD-like (eMMC) solution. I’ve mentioned ZFS before a

Re: [pfSense] APU and SSD: full install or NanoBSD

2014-10-30 Thread Jim Thompson
On Oct 30, 2014, at 7:14 AM, Jason Pyeron wrote: >> -Original Message- >> From: Jeppe Øland >> Sent: Wednesday, October 29, 2014 18:46 >> >> I've been on an Atom board with a Kingston SSD for like 3 >> years now ... >> In that time I've gone through 3 dead SSDs (which Kingston replace

<    1   2   3   >