Re: [pfSense Support] potential pfsense hardware

2009-10-14 Thread Jeppe Øland
> I'm thinking about picking up a Supermicro Atom based system > for use with pfSense: >> >> Has anybody tried pfSense with a board like this? >> http://www.avalue.com.tw/products/ECM-945GSE.cfm > > those seem good :) > jsut couldn't find anywhere to sell (thus no price tag). If you have an

RE: [pfSense Support] potential pfsense hardware

2009-10-14 Thread Joseph L. Casale
>Has anybody tried pfSense with a board like this? >http://www.avalue.com.tw/products/ECM-945GSE.cfm I don't know about FreeBSD's support of Marvell nics, but based on my experience with them in Solaris and RHEL I won't even let one in my site without calling the janitor and his garbage cart. Jus

Re: [pfSense Support] Snort Whitelist still blocking

2009-10-14 Thread Indrajaya Pitra Perdana
Thanks Chris i gonna upgrade it first Regards ~Indrajaya Pitra Perdana~ Chris Buechler wrote: On Wed, Oct 14, 2009 at 10:59 PM, Indrajaya Pitra Perdana wrote: dear support, I try to whitelist all of google site that have IP address 216.239.32.0/19 , and then i restarted the snort services,

Re: [pfSense Support] Snort Whitelist still blocking

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 10:59 PM, Indrajaya Pitra Perdana wrote: > dear support, > > I try to whitelist all of google site that have IP address 216.239.32.0/19 , > and then i restarted the snort services, but somehow it keeps blocking them, > is there anything that i should do to make this whiteli

[pfSense Support] Snort Whitelist still blocking

2009-10-14 Thread Indrajaya Pitra Perdana
dear support, I try to whitelist all of google site that have IP address 216.239.32.0/19 , and then i restarted the snort services, but somehow it keeps blocking them, is there anything that i should do to make this whitelist work ? thx in advance My snort package is 2.8.2.6_1 Ppsense 1.2.2

Re: [pfSense Support] potential pfsense hardware

2009-10-14 Thread Nenhum_de_Nos
On Wed, October 14, 2009 21:52, Jeppe Øland wrote: > On Thu, Aug 27, 2009 at 1:27 PM, Jim Pingle wrote: >> Ryan wrote: I'm thinking about picking up a Supermicro Atom based system for use with pfSense: > > Has anybody tried pfSense with a board like this? > http://www.avalue.com.tw/pro

Re: [pfSense Support] LAN->WAN block out on carp0

2009-10-14 Thread Evgeny Yurchenko
Evgeny Yurchenko wrote: Chris Buechler wrote: On Wed, Oct 14, 2009 at 11:37 AM, Evgeny Yurchenko wrote: Hello all! There must be something simple here. Please explain! Nothing is coming from LAN to WAN. *1.2.3-RC1* built on Wed Apr 22 15:45:47 EDT 2009 with carp on lan and wan. LAN=em1

RE: [pfSense Support] potential pfsense hardware

2009-10-14 Thread Nathan Eisenberg
The D945 chipset works with PFSense - I see no reason why it wouldn't work. Best Regards, Nathan Eisenberg Sr. Systems Administrator - Atlas Networks, LLC office: 206.577.3078 | suncadia: 206.210.5450 www.atlasnetworks.us | www.suncadianet.com > -Original Message- > From: Jeppe Øland [ma

Re: [pfSense Support] potential pfsense hardware

2009-10-14 Thread Jeppe Øland
On Thu, Aug 27, 2009 at 1:27 PM, Jim Pingle wrote: > Ryan wrote: >>> I'm thinking about picking up a Supermicro Atom based system >>> for use with pfSense: Has anybody tried pfSense with a board like this? http://www.avalue.com.tw/products/ECM-945GSE.cfm Regards, -Jeppe

Re: [pfSense Support] LAN->WAN block out on carp0

2009-10-14 Thread Evgeny Yurchenko
Chris Buechler wrote: On Wed, Oct 14, 2009 at 11:37 AM, Evgeny Yurchenko wrote: Hello all! There must be something simple here. Please explain! Nothing is coming from LAN to WAN. *1.2.3-RC1* built on Wed Apr 22 15:45:47 EDT 2009 with carp on lan and wan. LAN=em1 pass in quick on em1 all fla

Re: [pfSense Support] Routing Seperate Gateways, but the Gateway is the same IP, on different WAN's

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 7:01 PM, Chris Flugstad wrote: > I have multiple DSL lines, but they all have the same GW.  I am not load > balancing, but just want to route VOIP over one, and Internet traffic over > the other. > > When I try to select FW rules to route voip ports out over 1 of the GW's,

[pfSense Support] Routing Seperate Gateways, but the Gateway is the same IP, on different WAN's

2009-10-14 Thread Chris Flugstad
I have multiple DSL lines, but they all have the same GW. I am not load balancing, but just want to route VOIP over one, and Internet traffic over the other. When I try to select FW rules to route voip ports out over 1 of the GW's, it always selects the primary GW. Any way to resolve this wi

Re: [pfSense Support] LAN->WAN block out on carp0

2009-10-14 Thread Evgeny Yurchenko
Chris Buechler wrote: Upgrade. We removed rules for CARP interfaces because the OpenBSD documentation says they shouldn't be there, but it actually does need to be. It's been added back in RC3. O thanks that explains everything... I will upgrade... I was wondering where are all rules for c

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 2:01 PM, Andreas Fuchs wrote: > i'm running on 1.2.2, might this be my problem? as it is a production > environment i don't think it's smart to upgrade to 1.2.3-RC3 > Yes that's your problem, and it's fine to upgrade to RC3, the final release won't be much different.

Re: [pfSense Support] LAN->WAN block out on carp0

2009-10-14 Thread Chris Buechler
On Wed, Oct 14, 2009 at 11:37 AM, Evgeny Yurchenko wrote: > Hello all! > There must be something simple here. Please explain! Nothing is coming from > LAN to WAN. > > *1.2.3-RC1* built on Wed Apr 22 15:45:47 EDT 2009 with carp on lan and wan. > LAN=em1 > pass in quick on em1 all flags S/SA keep st

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Roberto Greiner
Keenan Tims wrote: Quoting Roberto Greiner : Could it be something mwith the fact that my box is a Xen virtual server? Perhaps posting the generated leases file (or an excerpt of it) would be helpful? I don't see how this would be directly related to your use of Xen, though I suppose if you

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Andreas Fuchs
sorry forgot to mention that i see this in the logs: openvpn[5850]: /etc/rc.filter_configure tun1 1500 1542 192.168.1.1 192.168.1.2 init openvpn[5850]: /sbin/ifconfig tun1 192.168.1.1 192.168.1.2 mtu 1500 netmask 255.255.255.255 up openvpn[5850]: TUN/TAP device /dev/tun1 opened so i assume t

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Andreas Fuchs
Thats what i tryed before asking :-) and it was not working But now i saw this in the pfsense doc: /Filtering OpenVPN Traffic/ /As of pfSense 1.2.3-RC1 and newer, you can filter incoming OpenVPN traffic. To do so, browse to Interfaces -> Assign and assign the appropriate tun interface to an O

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Keenan Tims
Quoting Roberto Greiner : Could it be something mwith the fact that my box is a Xen virtual server? Perhaps posting the generated leases file (or an excerpt of it) would be helpful? I don't see how this would be directly related to your use of Xen, though I suppose if your network configur

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: > Jim Pingle wrote: >> Roberto Greiner wrote: >>> Jim Pingle wrote: Roberto Greiner wrote: >> Roberto Greiner wrote: >>> Fatal error: Allowed memory size of 33554432 bytes exhausted >>> (tried to >>> allocate 35 bytes) in /usr/local/www/services_dhcp.php

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Roberto Greiner
Jim Pingle wrote: Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhc

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: > Jim Pingle wrote: >> Roberto Greiner wrote: >> >>> Jim Pingle wrote: >>> Roberto Greiner wrote: > Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to > allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48

RE: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Joseph L. Casale
>How can i create an OPT interface assigned to a tun interface? I knew that reply I wrote was a bit sloppy:) Make the OpenVPN config first specifying the Custom Opt as tun0. Save it. Then go back to your Interface Assignments and the Network port selection will now have a tun0 interface. jlc --

[pfSense Support] LAN->WAN block out on carp0

2009-10-14 Thread Evgeny Yurchenko
Hello all! There must be something simple here. Please explain! Nothing is coming from LAN to WAN. *1.2.3-RC1* built on Wed Apr 22 15:45:47 EDT 2009 with carp on lan and wan. LAN=em1 pass in quick on em1 all flags S/SA keep state label "USER_RULE: " In logs I have: pf: 1. 000562 rule 112/0(mat

Re: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Andreas Fuchs
Hi Joseph Thans for the fast reply, i think i undertand the idea, but: How can i create an OPT interface assigned to a tun interface? If i do: Interfaces -> assign -> add interface i can create an OPT interface, but i the dropdown i have my phisical interfaces an a plip0 What am i doing wrong

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Roberto Greiner
Jim Pingle wrote: Roberto Greiner wrote: Jim Pingle wrote: Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during the DHCP lease cleanup routi

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: > Jim Pingle wrote: >> Roberto Greiner wrote: >> >>> Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to >>> allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 >>> >> >> That is during the DHCP lease cleanup routine. Your >> /var/dhcpd

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Roberto Greiner
Jim Pingle wrote: Roberto Greiner wrote: Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during the DHCP lease cleanup routine. Your /var/dhcpd/var/db/dhcpd.leases file must be huge. It do

RE: [pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Joseph L. Casale
>We have several Road Warrior stile open VPN Users. Today they are >directly routed to the LAN interface without any Filter Rules. >New security policies request that we restrict some of the OpenVPN Users. > >It's a bit unclear to me how this can be done. Create an OPT interface (do not assign thi

Re: [pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Jim Pingle
Roberto Greiner wrote: > Fatal error: Allowed memory size of 33554432 bytes exhausted (tried to > allocate 35 bytes) in /usr/local/www/services_dhcp.php on line 48 That is during the DHCP lease cleanup routine. Your /var/dhcpd/var/db/dhcpd.leases file must be huge. It doesn't typically grow that

RE: [pfSense Support] SIP syslog messages

2009-10-14 Thread k_o_l
From: k_o_l [mailto:k_...@hotmail.com] Sent: Monday, October 12, 2009 2:31 PM To: support@pfsense.com Subject: [pfSense Support] SIP syslog messages Hi Everyone, Does anyone know why SIP syslog messages are showing in unreadable format? Here is an example: Oct 12 14:26:37 pf: From: ta

[pfSense Support] DHCP fatal error in services_dhcp.php line 48

2009-10-14 Thread Roberto Greiner
Hi, I was configuring CARP, and as a final touch, I chose to enable, inside the DHCP server, the NTP servers option. When I activated it, pointing NTP to the LAN-CARP address (in this case 172.16.0.1. The physical LAN address is 172.16.0.2), I got a blank page with only the following line: F

[pfSense Support] Filter Rules for OpenVPN connections

2009-10-14 Thread Andreas Fuchs
Hi all We have several Road Warrior stile open VPN Users. Today they are directly routed to the LAN interface without any Filter Rules. New security policies request that we restrict some of the OpenVPN Users. It's a bit unclear to me how this can be done. - Based on their CN we assign them f