Re: [pfSense Support] DNS forwarder or proxy question

2009-02-03 Thread Steve Spencer
RB, Thanks for that. It was necessary to keep DNS resolution on the box outside of the ssh process, but your post /did/ help me accomplish this. All up and doing well. Thanks again, Steve RB wrote: On Mon, Feb 2, 2009 at 15:15, Steve Spencer sspen...@kdsi.net wrote: The only problem I had

[pfSense Support] Problems with 2nd phase IPsec between Openswan and pfSense racoon

2009-02-03 Thread Xesc Arbona
Hi, I'm trying to set a VPN tunnel between a Debian GNU/Linux machine with Openswan 2.4.6 and a box with pfSense 1.2.2. I'm using X.509 certificates and my configuration is: linux: conn pfsense2linux left=192.168.251.3 leftnexthop=192.168.1.1 leftid=@pfsense.foo.bar

RE: [pfSense Support] Configuration Questions

2009-02-03 Thread Austin G. Smith
When I setup my bridge a few weeks ago, I noticed that the bridge interfaces have STP enabled by default. This created a temporary headache until I figured it out ;) For note, the stp protocol will have to be enabled/disabled on the individual interfaces, not the bridge interface itself. Also

RE: Re: [pfSense Support] Problems with 2nd phase IPsec between Openswan and pfSense racoon

2009-02-03 Thread Xesc Arbona
Thanks! But it was not a certificate issue. At some point in time I changed the rightsubnet to 10.0.0.0/16 on the Linux box, but not on pfSense, that make the SA IPsec not working. Now the configuration works, both with a certificate and with a PSK. ;) Thanks anyway, I finally have a tunnel

[pfSense Support] openvpn suggestion - copy description into the config file

2009-02-03 Thread Paul Mansfield
maye I humbly suggest that the openvpn config generator take the description field and put it as a comment into the /var/etc/openvpnXX.conf file? this would make it easier to tell the different config files apart when you have lots of them. thanks.

Re: [pfSense Support] Problems with 2nd phase IPsec between Openswan and pfSense racoon

2009-02-03 Thread Curtis LaMasters
I don't use certs on ipsec but from the sounds of it, pfSense cant find the certificate, it's in the wrong format or a permissions issue. Curtis LaMasters http://www.curtis-lamasters.com http://www.builtnetworks.com On Tue, Feb 3, 2009 at 4:38 AM, Xesc Arbona x.arb...@topdesk.com wrote: Hi,

[pfSense Support] Traffic shaping of Transmission bittorrent

2009-02-03 Thread Thomas Elsgaard
Hi Guys I have just configured pf sense to do traffic shaping in our network, and i hoped that the p2pcatch all could detect the p2p traffic from the linux transmission p2p client, but unfortunately this traffic is going into the default que.. By looking i the wireshark traces, it's really hard

Re: [pfSense Support] Traffic shaping of Transmission bittorrent

2009-02-03 Thread Daniel Lloyd
Make sure that its not using UPnP, as that bypasses shaping, or did last time I used it. On Tue, Feb 3, 2009 at 3:35 PM, Thomas Elsgaard thomas.elsga...@gmail.comwrote: Hi Guys I have just configured pf sense to do traffic shaping in our network, and i hoped that the p2pcatch all could

Re: [pfSense Support] Traffic shaping of Transmission bittorrent

2009-02-03 Thread RB
On Tue, Feb 3, 2009 at 16:35, Thomas Elsgaard thomas.elsga...@gmail.com wrote: I have just configured pf sense to do traffic shaping in our network, and i hoped that the p2pcatch all could detect the p2p traffic from the linux transmission p2p client, but unfortunately this traffic is going

[pfSense Support] WAN configuration without router

2009-02-03 Thread Bennett Lee
I'm helping a buddy get his pfSense (v1.2) setup with a new higher capacity connection and keep his old connection as a dual-WAN. He got some IP assignments from his ISP, the gist of which is: WAN Block: x.x.x.132/30 WAN Subnet Mask: 255.255.255.252 Network Side: x.x.x.133