Re: [pfSense] DNS over TLS config for pfSense 2.2.6

2018-04-04 Thread James
Yeah, I ran into this as well. It just caused my to not be able to resolve anything :( On Thu, 5 Apr 2018, at 11:01 AM, Bryan D. wrote: > Re: https://www.netgate.com/blog/dns-over-tls-with-pfsense.html > --- > Applying the suggested "Custom Options" to the Unbound/DNS Resolver > configuration

Re: [pfSense] DNS over TLS config for pfSense 2.2.6

2018-04-04 Thread James
Sorry, mine was indeed on 2.4.X. The daemon appeared to start up but any queries returned no records. On Thu, 5 Apr 2018, at 11:20 AM, Steve Yates wrote: > Wild guess, but did you try it in 2.4.x? > > -- > > Steve Yates > ITS, Inc. > > -Original Message- > From: List On Behalf Of Br

[pfSense] Traffic Shaping per client port?

2011-12-15 Thread James Perry
Hello, I've got a REST API based application sitting behind a pfSense Load Balancer (works great!). I want to perform some scaleability testing using pfSense's traffic shaping capabilities. I was able to configure pfSense to limit total throughput for a given interface but what I really want

Re: [pfSense] Carp locking up routers.

2012-01-06 Thread JASON JAMES
Jason James is no longer with the School District of Milton. If you need to email the Technology Department please correct your contact list to hol...@mail.milton.k12.wi.us If you need to contact Jason James directly his contact email is jja...@janesville.k12.wi.us

Re: [pfSense] DynDNS/No-IP question, cascaded NAT

2012-01-06 Thread JASON JAMES
Jason James is no longer with the School District of Milton. If you need to email the Technology Department please correct your contact list to hol...@mail.milton.k12.wi.us If you need to contact Jason James directly his contact email is jja...@janesville.k12.wi.us

Re: [pfSense] [pfsense] dansguardian

2012-04-26 Thread James Caldwell
I've been part of the pfsense lists for months but have never really spoken up about anything. I tried to implement dansguardian in v2.0.1 but failed aswell. Has anyone found a reliable best practice or guide for this? James From: list-boun...@lists.pfsense.org [mailto:list

Re: [pfSense] pfSense vs JunOS

2012-07-03 Thread James Caldwell
Absolutely, some of the best support I've had for a software solution to date. James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of bsd Sent: July-03-12 3:24 PM To: pfSense support and discussion Subject: Re: [pf

[pfSense] IP Alias and IPSec

2012-07-28 Thread James Bland
s I'm missing some rule somewhere that I might need but I've tried fiddling and come up empty. Can anyone give me some advice on this? Cheers, James ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] IP Alias and IPSec

2012-07-30 Thread James Bland
face. I'm happy with the config as I have it now but maybe this is a bug or it cannot work and the documentation might want to mention this? Cheers, James On 30 Jul 2012, at 19:17, Moshe Katz wrote: > Moshe ___ List mailing list List@list

Re: [pfSense] FYI: MS-CHAPv2 (used in PPTP) considered totally insecure

2012-07-31 Thread James Caldwell
How difficult would it be to replace PPTP implementations with OpenVPN for mobile users? James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jim Pingle Sent: July-31-12 7:20 AM To: pfSense support and discussion Subject

Re: [pfSense] IP Alias and IPSec

2012-07-31 Thread James Bland
Hi Gavin, I've 2 IPSec tunnels and both of the other ends are Cisco ASA devices so OpenVPN wouldn't be an option. It is working fine with how I've configured it now, not using PPPoE. Must just be that it's not possible with PPPoE currently with multiple IP's. Cheers,

Re: [pfSense] FYI: MS-CHAPv2 (used in PPTP) considered totally insecure

2012-07-31 Thread James Caldwell
What would this look like connecting from a windows xp/7 client. Would it still use the PPTP protocol or would it be setup differently? James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Jim Pingle Sent: July-31-12 9:31

[pfSense] Building Reports and Content Filters

2012-11-20 Thread James Caldwell
Firewalls' and their ability to better manage your network traffic. I'd hate to think that they have anything the open source community has not already had for some time :). Regardless, any insight would be really appreciated. Thanks guys! James

Re: [pfSense] Building Reports and Content Filters

2012-11-20 Thread James Caldwell
y bad situation, merely trying to provide an intelligent response to someone else's inquiry. The second bit I was looking to see is a breakdown of where the traffic is coming from, such as HTTP, P2P, etc, and what IP ranges are the primary culprits as they have several VLANS. Chee

Re: [pfSense] Building Reports and Content Filters

2012-11-20 Thread James Caldwell
https://www.untangle.com/store/policy-manager-conf.html https://www.untangle.com/store/reports.html A couple of links that I came across that prompted the question this morning. James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On

Re: [pfSense] 2.0.2 release now available

2012-12-21 Thread James Caldwell
Awesome work guys, looking forward to 2.1! Regards, James Sent from my BlackBerry - Original Message - From: Chris Buechler [mailto:c...@pfsense.org] Sent: Friday, December 21, 2012 08:39 AM To: pfSense support and discussion Subject: [pfSense] 2.0.2 release now available info here

Re: [pfSense] 2.0.2 release now available

2012-12-21 Thread James Caldwell
I'm always a little leary of the 'beta' term. Once you guys stamp it as a release quality build I'll move up to it no problem. James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Eugen Leitl Sent: Decem

Re: [pfSense] 2.0.2 release now available

2012-12-21 Thread James Caldwell
That's great to know it's been thoroughly tested out in the wild already and still considered in beta. If it's already stable enough to run as your primary version, what's left before 2.1 goes release? James -Original Message- From: list-boun...@lists.pfsense.o

Re: [pfSense] SIP traffic not forwarding reliably

2013-02-06 Thread James Records
I had a similar situation that I resolved using nprev2 package and nagios, I sent a ping from the pfsense box to my sip providers ip, we charted the latency and found that it was in the neighborhood of 80ms on average, that prompted us to switch up to a different ISP at the location and once that w

[pfSense] Open Source WAN Optimization

2013-04-12 Thread James Caldwell
Has anyone had any kind of success running an open source or commercial alternative to riverbed for WAN optimization? It would be great if some of solution like this was available and even better if we could run it inside of pfsense. Cheers. James

Re: [pfSense] Open Source WAN Optimization

2013-04-12 Thread James Caldwell
Hi Jim, That’s very interesting. If not directly integrated into pfsense how do you envision it might take shape? What do you think of Glenn Kelley’s comment about the very impressive numbers he’s been getting using Traffic Squeezer? James From: list-boun...@lists.pfsense.org [mailto:list

[pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-13 Thread James Bensley
and one when it goes up. (Also, given my first query, all my TCP connections will stop working again!). Many thanks, James. ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-15 Thread James Bensley
the exact same hardware) seems to the running very slow. I have shell access via a serial cable and I can see with the 'top' command that CPU usage is low, but browsing the web interface is very slow especially for pages relating to CARP and Virtual IP setting

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-15 Thread James Bensley
On 15 April 2013 15:29, James Bensley wrote: > Although my tests > aren' proving successful so far. I meant to say; I am pulling a file via SCP from a host in the LAN to a host on the WAN. If I disable CARP on the master to force a fail over to the backup, there is a pause, and th

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-16 Thread James Bensley
backup to fail. Otherwise we have two outages. Cheers, James. ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-16 Thread James Bensley
ut I can't. I think I will leave it. Cheers, James. ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Packet capture

2013-04-28 Thread James Records
Jason, I think what you want is the pflog0 interface. -- James Records | Principle Network Engineer M 425.984.4349 E ja...@northshoresoftware.com W www.northshoresoftware.com On Sun, Apr 28, 2013 at 9:46 AM, Jason Pyeron wrote: > ** > Yes the interface for packet capture is nice

Re: [pfSense] Packet capture

2013-04-28 Thread James Records
Jason, Take a look at this: http://www.openbsd.org/faq/pf/logging.html Should help you out a bit. -- James Records | Principle Network Engineer M 425.984.4349 E ja...@northshoresoftware.com W www.northshoresoftware.com On Sun, Apr 28, 2013 at 1:21 PM, Jason Pyeron wrote: > ** >

Re: [pfSense] Packet capture

2013-05-01 Thread James Records
l on Pfsense, though I've never done this, but with some tweaking, you can probably get this to do what you want without the need for remote ssh access. -- James Records | Principle Network Engineer M 425.984.4349 E ja...@northshoresoftware.com W www.northshoresoftware.com On Sun, Apr

Re: [pfSense] Full Backup/Restore for pfSense

2013-05-04 Thread James Records
ect that is going to need ~35, so a templatized image is a much better solution for me than normal configs. -- James Records | Principle Network Engineer M 425.984.4349 E ja...@northshoresoftware.com W www.northshoresoftware.com On Sat, May 4, 2013 at 9:32 AM, Odhiambo Washington wrote: > Wh

Re: [pfSense] Full Backup/Restore for pfSense

2013-05-04 Thread James Records
some of this in the UI, but I'm doing fine with ssh access to these commands for now. -- James Records | Principle Network Engineer M 425.984.4349 E ja...@northshoresoftware.com W www.northshoresoftware.com On Sat, May 4, 2013 at 11:18 AM, Mehma Sarja wrote: > dd is fine unle

Re: [pfSense] pfsense cannot find suitable hard drive to install on

2013-06-11 Thread James Caldwell
This may be a stupid question but are you looking in the motherboard bios or the raid card bios? Regards, James Sent from my BlackBerry From: pfu...@hushmail.com [mailto:pfu...@hushmail.com] Sent: Tuesday, June 11, 2013 10:43 PM To: pfSense support and discussion Subject: Re: [pfSense

Re: [pfSense] pfSense 2.1-RELEASE and Gold Subscription Now Available!

2013-09-15 Thread James Caldwell
Fantastic job all, keep up the great work! My team and I are extremely appreciative as always. James -Original Message- From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Chris Buechler Sent: September-15-13 2:50 AM To: pfSense support and

Re: [pfSense] rrd error

2013-10-15 Thread James Gorman
nd click Execute include("shaper.inc"); include("upgrade_config.inc"); include("rrd.inc"); upgrade_080_to_081(); -Done James ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

[pfSense] OpenVPN Dropping Connection

2013-10-17 Thread James Caldwell
I have one particular firewall that keeps dropping its connection to its partner. It's a client node connecting to a server. The error seen on the dashboard is 'No Management Daemon'. If anyone has experience with this your insight would be appr

Re: [pfSense] Possible MTU/PMTU/MSS issue with HE IPv6 tunnel over PPPoE DSL connection

2014-02-11 Thread James Conner
Check again. I found that the new servers that google deployed were not working properly. They would receive the PMTU packet² packet to big² and would not scale down. They had over 200 servers that had a problem. ___ List mailing list List@lists.pfsens

[pfSense] Freezing Entering NAT Rules

2014-02-23 Thread James Caldwell
Has anyone ever experienced the gui hang or get very sluggish entering NAT rules and subsequently applying changes afterwards? James ___ List mailing list List@lists.pfsense.org http://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Freezing Entering NAT Rules

2014-02-28 Thread James Caldwell
Turned out to be bad/dieing hardware. Replaced the firewall with a new Dell server and everything is back to normal. Thanks, James From: list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] On Behalf Of Chris Buechler Sent: February-23-14 6:16 PM To: pfSense support and

[pfSense] Network Traffic Monitoring w/o Webgui

2014-04-07 Thread James Caldwell
remain outside the web interface as much as possible due to the load that it puts on the system. Any thoughts or experience is appreciated. James <>___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] Network Traffic Monitoring w/o Webgui

2014-04-08 Thread James Caldwell
og type solution so that we're not only gathering network data but also logs/health from the routers themselves? Any tips here before I dive headlong into this? Thanks, James From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Chuck Mariotti Sent: April-07-14 1:04 PM To: pfS

Re: [pfSense] Poweredge 2850

2014-05-19 Thread James Caldwell
Amd64 is the 64 bit version that you would want to use on that proc. I386 is 32 bit. James -Original Message- From: List [mailto:list-boun...@lists.pfsense.org] On Behalf Of Brian Caouette Sent: May-19-14 4:37 PM To: pfSense support and discussion Subject: [pfSense] Poweredge 2850

Re: [pfSense] Enumerating NAT Hops - Information Disclosure - TTL++ mangle.

2014-07-10 Thread James Bensley
Further to what Walter has said - Double NATB! ___ List mailing list List@lists.pfsense.org https://lists.pfsense.org/mailman/listinfo/list

Re: [pfSense] polling pfsense status for a combined dashboard

2015-01-27 Thread James Records
Not sure if this is exactly what your asking but I have a dashboard setup for pf logs, I made a reddit post about it a while back: http://www.reddit.com/r/PFSENSE/comments/2rlm8h/pfsense_docker_elk/ I also use nagios (which i was going to try to package in docker as well when I get around to it)

Re: [pfSense] Notification about soon-to-expire certificates

2015-06-19 Thread James Records
This would be useful, I've made a monitoring tool (still unofficial until i figure out how to get it in the proper package repo) here that I might play with and see if I can get an alert setup for this by simply loading the cert page and parsing the expire date. http://www.reddit.com/r/PFSENSE/com

[pfSense] Recipe to safely allow remote SIP phones to connect a local asterisk PBX?

2015-12-23 Thread James Ronald
Is anyone aware of a pfSense config/recipe to safely allow remote SIP phones to connect a local asterisk PBX? Regards, *James Ronald* <http://www.drewtech.com> ___ pfSense mailing list https://lists.pfsense.org/mailman/listinfo/list Support the p

Re: [pfSense] Port forwards don't work on one machine

2018-02-12 Thread James Ronald
What is the default gateway of the destination (is there a route back to pfSense)? - Jim On Mon, Feb 12, 2018 at 1:46 PM, Marco wrote: > On Mon, 12 Feb 2018 11:59:09 -0600 > Steven Spencer wrote: > > > On 02/12/2018 11:43 AM, Marco wrote: > > > On Mon, 12 Feb 2018 10:21:08 -0600 > > > Steven S

Re: [pfSense] Nat between vlans

2018-03-30 Thread James Ronald
Yılmaz, Sorry, but why not attach the Airprint to both VLANs? - Jim Regards, *James Ronald* Drew Technologies, Inc. 3915 Research Park Dr Ste 10A Ann Arbor, MI 48108 734-222-5228 x617 www.drewtech.com On Fri, Mar 30, 2018 at 1:58 PM, Raphaël RIGNIER wrote: > Le 30/03/2018 à 19:03, Yıl

[pfSense] cipher suites and NIST

2013-10-11 Thread James A. Donald
There is a smoking gun on one of random number generators. There is strong circumstantial evidence, reason for suspicion, on suggested Suite B. AES and SHA look to be fine, but using them gives the appearance to end users that you might be playing footsie with NIST. Cryptographer Jon Callas