Re: [pfSense] NAT reflection and SIP registration

2011-11-25 Thread Gavin Will
I am in the same situation as you, I put a request up a while back but there was no replies to it. Im using 2.0-Release upgraded from 2.0 something a while back. I have not done a clean install of 2.0-Release. Nat reflection is enabled for the couple of https NAT forward rules we have and

[pfSense] CARP: Promote backup to master/master to backup without halting master

2011-11-25 Thread Danny
Hi, I´ve got a cluster of pfsense 1.2.3 firewalls, but I´m having troubles to install packages on backup firewall. I need to promote backup firewall to master without switching off the master (reason is that squid is only in master firewall and cannot halt the system to force backup promotion)

[pfSense] Layer 3 OpenVPN (tun) server: several site networks as clients possible?

2011-11-25 Thread Ray
Hi, I have set up an OpenVPN server in a network 192.168.1.0/24 and a client in a network 192.168.10.0/24. Both are connected through a tunnel network whose interfaces (tun0 at both ends) have the POINTOPOINT interface flag set. I've set up both tun0's as dhcp and they get 10.0.8.1/24 at the

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-25 Thread Ugo Bellavance
On 2011-11-23 23:43, Daniel Davis wrote: We are thinking about running a redundant (CARP) setup with one pfSense on our VMWare cluster, and one on a physical, separate machine. I would not recommend a hybrid physical/virtual CARP cluster as CARP is entirely network reliant. In a physical

[pfSense] NAT advice

2011-11-25 Thread Ugo Bellavance
Hi, I'd like to use pfSense for a proof-of-concept to link two networks together for a SIP trunk. After discussing with the other network admin, we concluded that we'd use NAT because we don't want the traffic to go through core switches, which are the only L3 devices available. I know NAT

Re: [pfSense] Replacing CheckPoint Firewall-1 with pfSense

2011-11-25 Thread Fuchs, Martin
Hi ! It's meant as more than 500 ports ;-) Am 25.11.2011 um 14:51 schrieb Ugo Bellavance u...@lubik.ca: On 2011-11-23 23:43, Daniel Davis wrote: We are thinking about running a redundant (CARP) setup with one pfSense on our VMWare cluster, and one on a physical, separate machine. I