Re: [pfSense] Low(ish) cost pfSense platforms

2012-06-25 Thread Moshe Katz
throughput at any speed). I would be extremely hesitant to use these devices in a production system. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Possible bug in gateway monitoring in 2.1 snapshot (Sat Jun 16 08:16:08 EDT 2012)

2012-06-21 Thread Moshe Katz
the gateway monitor and the static route, and submit it. I opened an issue in the pfSense Redmine to track this: http://redmine.pfsense.com/issues/2513 Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Slightly OT: Accessing pfSense webinterface via reverse proxy

2012-06-18 Thread Moshe Katz
; > Cheers > > ** ** > > Gavin > > > ** > Hello, pfSense uses absolute path URLs (i.e. starting with a slash but without the domain name; view the source of the page to see this), you would need your proxy to rewrite lin

Re: [pfSense] Low(ish) cost pfSense platforms

2012-06-08 Thread Moshe Katz
previously using home-grade wireless routers (Linksys, Belkin, etc). All of them had fiber (range 15mbit to 100mbit), so I know these boxes can handle that load. Two of them were running Squid and Squidguard. If you do go this route, stay away from Dell machines older than the Optiplex GX280. The

Re: [pfSense] [SPAM] Help in port Forwarding configuration

2012-05-25 Thread Moshe Katz
> > *open socket2* > > *Connect to server* > > *error: 10060* > > *error: 10060* > > *error: 10060* > > *error: 10060* > > > Note that my firewall WAN address is 201.65.126.240, could be my firewall > settings wrong. > > Thanks > > Joseph. &

Re: [pfSense] [SPAM] Help in port Forwarding configuration

2012-05-24 Thread Moshe Katz
gt; WAN >>> >>> TCP >>> >>> any >>> >>> any >>> >>>200.6.14.60 >>> >>> 3001 >>> >>> 192.168.9.10 >>> >>> 5001 >>> >>> >>> >&g

Re: [pfSense] Multiple port ranges in alias

2012-05-13 Thread Moshe Katz
those ports. It seemed to work just fine. Are you trying to put the alias in the "End Port" box on the rule page? AFAIK, you only need to put it in the "Start Port" box (though pfSense will copy it to the other box after you save the rule). What version of pfSense are you runni

Re: [pfSense] Outbound NAT

2012-05-07 Thread Moshe Katz
tter which computer sent the request. Without the Outbound NAT rules, any computer that has 1-to-1 NAT set up for it will send traffic to this destination on its regular address and be blocked by their firewall. To answer your new question, here is a quote from the Outbound NAT

Re: [pfSense] vmware appliance

2012-05-01 Thread Moshe Katz
build logs on the snapshot server, you will also see the VMWare builds there. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Tue, May 1, 2012 at 12:05 PM, David Burgess wrote: > The docs (http://doc.pfsense.org/index.php/VMwareAppliance) state that > there is no longer a c

Re: [pfSense] port forwarding LAN to LAN

2012-05-01 Thread Moshe Katz
NS records but it simplifies configuration and improves response times from the server. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Tue, May 1, 2012 at 10:30 AM, Nelson Serafica wrote: > I've pfsense with port forwarding running fine if the rules is WAN to > LAN bu

Re: [pfSense] lagg

2012-04-04 Thread Moshe Katz
as any open ports, you run this risk. In one school where I volunteer, they have students playing with the cables create a loop and bring down the whole network at least one a month. (I have almost convinced them to buy boxes with locks for the network switches instead of leaving t

Re: [pfSense] icmp best practices

2012-03-20 Thread Moshe Katz
On Tue, Mar 20, 2012 at 8:05 AM, Ugo Bellavance wrote: > On 2012-03-20 07:25, Chris Bagnall wrote: > >> On 19/3/12 11:54 pm, Moshe Katz wrote: >> >>> I have ICMP blanket allowed on both pfSense installations that I have >>> (home >>> and work). >&

Re: [pfSense] icmp best practices

2012-03-19 Thread Moshe Katz
. I have heard that the reason Google keeps ICMP open is for marketing. If you know that you can ping Google to help troubleshoot your internet connectivity, you just remember Google for one more thing they can help you with. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 ___

Re: [pfSense] creating a 1:1 NAT WAN to DMZ

2012-02-20 Thread Moshe Katz
mething else in your configuration that is doing that. Try rebooting the box if you can so it will reload all the configs from disk. -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Mon, Feb 20, 2012 at 11:42 AM, Jason T. Slack-Moehrle < slackmoeh...@gmail.com> wrote: > Hi Guys,

Re: [pfSense] creating a 1:1 NAT WAN to DMZ

2012-02-15 Thread Moshe Katz
Is this the setup you have right now (or have you plugged in some other router/firewall for now) because I can get to the web site at the address in the screenshots. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Wed, Feb 15, 2012 at 8:04 PM, Jason

Re: [pfSense] creating a 1:1 NAT WAN to DMZ

2012-02-13 Thread Moshe Katz
ve. Moshe ------ Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Sun, Feb 12, 2012 at 10:57 PM, Jason T. Slack-Moehrle < slackmoeh...@gmail.com> wrote: > Hi Moshe, > > > I created an alias with the INTERNAL addresses of all web servers. The >

Re: [pfSense] pfSense help with creating rules

2012-02-10 Thread Moshe Katz
/28 from our Verizon FiOS. We created Virtual IPs for alll of the addresses and we are using 1:1 NAT for all of our servers which themselves have private IPs. It works just fine. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 _

Re: [pfSense] Request for help: Seeking pfSense user with access to 6RD IPv6 WAN

2012-02-01 Thread Moshe Katz
IPv6 implementation, we'd (as an industry) be a lot further on than we are. > > Kind regards, > > Chris > -- > This email is made from 100% recycled electrons > ___ > List mailing list > List@lists.pfsense.org > htt

Re: [pfSense] Block Rule doesnt work

2012-01-25 Thread Moshe Katz
On Wed, Jan 25, 2012 at 2:08 PM, David Burgess wrote: > 2012/1/25 Jürgen Echter : > > You're using Reject rather than Block, which operates only on TCP/UDP. > Any other packet type will not match that rule. > > db > ___ > List mailing list > List@lists.

Re: [pfSense] Block Rule doesnt work

2012-01-25 Thread Moshe Katz
r rules are actually "block" rules (red icons) and that they are enabled. I'm sorry if this sounds like a stupid question but did you make sure your IP address is not the one that is allowed through in the first rules? Moshe -- Moshe Katz -- mo...@ymkatz.

Re: [pfSense] Unable to check for updates.

2011-12-25 Thread Moshe Katz
Information widget, I see "Unable to check for updates". This is with Nano > i386 2.0.1 and I saw the same thing with 2.0. Do I need to tell it where to > look for updates or do I need to create a rule to allow it to look for > updates or do I just ignore that message? > &

Re: [pfSense] Unable to check for updates.

2011-12-24 Thread Moshe Katz
Here's what I have: http://updates.pfsense.org/_updaters Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 2011/12/24 Przemysław Pawełczyk > On Sat, 24 Dec 2011 11:46:04 +0100 > Eugen Leitl wrote: > > > You people with i386 2.0.1,

Re: [pfSense] Silly question - using a PC + pfsense + dual ethernet NIC + wlan PCI card as wifi router

2011-12-07 Thread Moshe Katz
house, this will likely not make a difference. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Wed, Dec 7, 2011 at 7:15 PM, Air Zonk wrote: > Hi, > > Before I go buy a Linksys from Best Buy, > > Can I use a Pentium III class PC, plus

Re: [pfSense] Survey of pfSense users and developers

2011-11-13 Thread Moshe Katz
Thank you very much to everyone who completed the survey. - Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Sat, Nov 5, 2011 at 11:25 PM, Moshe Katz wrote: > Hello All, > > I am a long-time pfSense user and currently a student studying

[pfSense] Survey of pfSense users and developers

2011-11-05 Thread Moshe Katz
few minutes to fill out my survey. It's at http://opencs.umd.edu/survey/index.php?sid=69279&lang=en. Thank you all again, Moshe ------ Moshe Katz -- mo...@ymkatz.net -- mmk...@umd.edu -- +1(301)867-3732 ___ List mailing

Re: [pfSense] IP330

2011-11-02 Thread Moshe Katz
says: 266mhz will get you 10-20Mbps 866mhz will get you 50-200Mbps I have not found any benchmarks of pfSense on Nokia IP___. Moshe -- Moshe Katz -- mo...@ymkatz.net -- +1(301)867-3732 On Wed, Nov 2, 2011 at 10:55 AM, Patrick Coppens wrote: > On 2/11/2011 14:05, Mo

Re: [pfSense] IP330

2011-11-02 Thread Moshe Katz
I just finished researching pfSense on the similar IP380. From what I have seen, it works well. You have to install the hard drive in a different computer first in order to do the installation because the IPxxx cannot boot from CD. After pfSense is installed, you put the drive back in the firewa

Re: [pfSense] X86 to X64 Question

2011-10-12 Thread Moshe Katz
On Wed, Oct 12, 2011 at 12:16 PM, Adam Thompson wrote: > > Thanks for the thoughts on these questions. A few more related: > > > > Is there a listing of the addon-package differences between x86 and > > x64? In particular, I'm curious if squid, squidguard, and notes > > are available for x64 bec

<    1   2