Re: [pfSense] Design Best Practice Question

2015-03-07 Thread ED Fochler
Set your servername in apache/whatever, you’re all good. The servername needs to match the cert, the IP doesn’t matter and shouldn’t be handed out anywhere. On 2015, Mar 7, at 8:44 AM, Tim Hogan t...@hoganzoo.com wrote: Ed, I like your idea with using 1:1 NAT but just one question; If

Re: [pfSense] Design Best Practice Question

2015-03-07 Thread Tim Hogan
Ed, I like your idea with using 1:1 NAT but just one question; If you use SSL with the certificate on the web server, will the 1:1 NAT mess with that? Regards, Tim On 3/6/2015 9:52 PM, ED Fochler wrote: Bridging will disable firewall and DHCP on modem, this should be expected. If it

Re: [pfSense] Design Best Practice Question

2015-03-07 Thread Tim Hogan
Yes, I guess I want to know if the bridge is set up correctly when one of the interfaces in the bridge has an IP address that is being used for the NAT address for my internal LAN. Regards, Tim On 3/6/2015 3:07 PM, WebDawg wrote: On Fri, Mar 6, 2015 at 2:16 PM, Tim Hogan t...@hoganzoo.com

Re: [pfSense] PF 2.15 Release (AMD64) Gateway Monitoring with OSPF

2015-03-07 Thread Wade Blackwell
Anyone? Bueler? Wade Blackwell Solutions Architect (D) 805.457.8825 (C) 805.400.8485 (S) coc.wadeblackwell On 6 March 2015 at 10:44, Wade Blackwell wa...@bablam.com wrote: Good morning all, I currently have a PF VM being used as my core L3 device for a small site. No static

Re: [pfSense] PF 2.15 Release (AMD64) Gateway Monitoring with OSPF

2015-03-07 Thread Espen Johansen
Based on what you described I'm pretty sure you missed the part that pfsense does not support ECMP and thus will only accept a single default kernel route. In other words it cant be done and to be honest a single pfsense receiving 2 default routes does not give you any redundancy except 2

Re: [pfSense] Design Best Practice Question

2015-03-07 Thread Volker Kuhlmann
On Sun 08 Mar 2015 02:44:45 NZDT +1300, Tim Hogan wrote: I like your idea with using 1:1 NAT but just one question; If you use SSL with the certificate on the web server, will the 1:1 NAT mess with that? No. Volker -- Volker Kuhlmann is list0570 with the domain in header.