[pfSense Support] HEADS UP: this mailing list has moved

2011-09-08 Thread Chris Buechler
The mailing list has moved to l...@lists.pfsense.org. This list server is being decommissioned. Your email address on this list has been subscribed to the new list, and you will receive a welcome message on that list shortly. The old support@ and discussion@ emails will bounce. Feel free to

Re: [pfSense Support] how to block the bit torrent

2011-09-02 Thread Chris Buechler
On Fri, Sep 2, 2011 at 12:23 PM, Glenn Kelley gl...@typo3usa.com wrote: There is a PFSense 2 book available for the Kindle or paperback - in Amazon Store - just search for PFSENSE Not official, and poorly done. Wouldn't recommend it, our 1.2.x book is more helpful with 2.0.

Re: [pfSense Support] Block Website

2011-09-01 Thread Chris Buechler
On Thu, Sep 1, 2011 at 1:02 PM, suresh suresh suresh.notion...@gmail.com wrote: Hi All, How to block the website in pfsense 1.2.3 http://lmgtfy.com/?q=block+website+site%3Adoc.pfsense.org Please, before you bombard over 1000 people on this mailing list with the most basic of FAQs, much less

Re: [pfSense Support] PPTP not working after update on Tuesday

2011-09-01 Thread Chris Buechler
On Thu, Sep 1, 2011 at 1:31 PM, Vick Khera vi...@khera.org wrote: Office firewall has been running 2.0-RC2 from some time in May.  PPTP was working fine and dandy from iOS devices.  Just click the vpn on and off you went. Yesterday I updated the firewall to the latest snapshot of RC3 (Aug 30

Re: [pfSense Support] ntop crashes

2011-08-31 Thread Chris Buechler
On Wed, Aug 31, 2011 at 6:38 AM, Nick Upson n...@telensa.com wrote: Hi, running pfsense 1.2.3, ntop 3.3.8. after a few mins ntop crashes with the following message in syslog  kernel: pid 43126 (ntop), uid 0: exited on signal 11 (core dumped) Welcome to the wonderful world of ntop. It has

Re: [pfSense Support] Subnets in same NIC

2011-08-30 Thread Chris Buechler
On Tue, Aug 30, 2011 at 8:39 PM, Ivanildo Galvão - IT Services ivani...@itservices.com.br wrote: Yeah, I know it works with VLAN, but wanted to implement something simpler, the problem is that the customer had this scenario before working with Proxywith Linux and pfSense he wants to have the

Re: [pfSense Support] DHCP scope,

2011-08-29 Thread Chris Buechler
On Mon, Aug 29, 2011 at 4:04 PM, greg whynott greg.whyn...@gmail.com wrote: Hi, Is it possible to have the pfSence fw provide DHCP services to a network which lives one hop beyond the pfsence's INSIDE directly connected network?   On the router i configured an ip-helper address,  i then went

Re: [pfSense Support] syslog messages

2011-08-26 Thread Chris Buechler
On Fri, Aug 26, 2011 at 11:56 AM, k_o_l k_...@hotmail.com wrote: My syslog server is being filled with the following generated by pfsense-2.0-RC3  169.254.1.213.56971  169.254.1.255.5000: UDP, length 12 Some device on your LAN with that autoconfigured 169.254.1.213 (which, unless that's your

Re: [pfSense Support] Happy Birthday Chris

2011-08-18 Thread Chris Buechler
On Thu, Aug 18, 2011 at 1:18 AM, Glenn Kelley gl...@typo3usa.com wrote: Happy Birthday Chris Thanks! - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com

Re: [pfSense Support] Restrict bandwidth for a virtual ip

2011-08-18 Thread Chris Buechler
On Thu, Aug 18, 2011 at 6:35 AM, Shibashish shi...@gmail.com wrote: Hi, I have pfSense Version2.0-RC1 (i386) which runs multiple websites and acts as a load balancer too. I have a website which is eating up all my bandwidth. I want to restrict that ip to use 10Mbps of my bandwidth and keep

Re: [pfSense Support] PPTP Broken in latest AMD 2.0 Snapshots

2011-08-17 Thread Chris Buechler
On Wed, Aug 17, 2011 at 3:38 PM, Adam Piasecki apiase...@midatlanticbb.com wrote: Same config works with i386, does not work with AMD.. PPTP clients on AMD can not send traffic over IPSEC Tunnels or traffic out to the internet. PPTP to the local LAN works fine with AMD. I386 works with

Re: [pfSense Support] PPTP Broken in latest AMD 2.0 Snapshots

2011-08-17 Thread Chris Buechler
On Wed, Aug 17, 2011 at 3:54 PM, David Burgess apt@gmail.com wrote: On Wed, Aug 17, 2011 at 1:49 PM, Chris Buechler cbuech...@gmail.com wrote: http://redmine.pfsense.org/issues/1107 Fixing that broke PPPoE entirely on AMD64, doubt if that gets fixed for 2.0. Can you please clarify

Re: [pfSense Support] Monitor IP in gateway, strange behavior

2011-08-17 Thread Chris Buechler
On Wed, Aug 17, 2011 at 5:45 PM, Diego Barrios s...@techsystem.com.br wrote: Hi folks, I`m not sure if this could be a bug, but i`ve just installed a new PFSense 2.0RC3 (latest snapshop) with 3 NICs, 1 LAN + 2 WAN When i use the same monitor IP on both WANs You can't do that. The GUI

Re: [pfSense Support] Imspector

2011-08-16 Thread Chris Buechler
On Tue, Aug 16, 2011 at 6:22 PM, Cleber L. Medina clebermed...@gmail.com wrote: If I install a freebsd mysql package on pfsense It can work.. its is possible? You don't need it, and don't want to do that regardless. - To

Re: [pfSense Support] VPN Failover Backup

2011-08-14 Thread Chris Buechler
On Sat, Aug 13, 2011 at 11:04 PM, David Miller davi...@gmail.com wrote: I may have spoken too quickly last time as what I said made a lot, probably too may, assumptions about your network.  So lets start over and say as with most networking things it depends.  You've mentioned that the wireless

Re: [pfSense Support] policy routing issue : stumped : more

2011-08-12 Thread Chris Buechler
On Fri, Aug 12, 2011 at 9:54 AM, mayak-cq ma...@australsat.com wrote: hi again, i am now wondering why it is necessary to have gateway defined in the WAN interface ... Because that's what determines for NAT purposes whether something is treated as a WAN. if in the gateway definition, a

Re: [pfSense Support] BGP support in 2.0

2011-08-11 Thread Chris Buechler
On Tue, Aug 9, 2011 at 8:02 AM, Dan Candea dan.can...@quah.ro wrote: On 04.08.2011 00:11, Chris Buechler wrote: On Wed, Aug 3, 2011 at 7:43 AM, Adam Thompson athom...@athompso.net wrote: I've been accepting ~ 13k routes inbound  advertising nothing.  So that part works, too. Now you just

Re: [pfSense Support] Cannot access the http://forum.pfsense.org/

2011-08-11 Thread Chris Buechler
On Tue, Aug 9, 2011 at 7:16 AM, TKOAK liugann...@gmail.com wrote: Right, the *.pfsense.org is not blocked by the Chinese GFW. At present, I can visit any sub-domain at pfsense.org directly(without proxy), except the forum.pfsense.org. Your account hasn't triggered any bans on the forum in

Re: [pfSense Support] Cannot access the http://forum.pfsense.org/

2011-08-09 Thread Chris Buechler
On Tue, Aug 9, 2011 at 1:55 AM, Bart Grefte b...@ravenslair.nl wrote: You need a proxy just to open websites like pfSense.org and YouTube? They do block quite a few things, but not any of our sites currently (they used to block our blog when it was hosted on blogspot, but *.pfsense.org sites

Re: [pfSense Support] Cannot access the http://forum.pfsense.org/

2011-08-08 Thread Chris Buechler
On Mon, Aug 8, 2011 at 9:24 AM, TKOAK liugann...@gmail.com wrote: I got the Sorry Guest, you are banned from using this forum! message often... Can somebody help me to solve this problem! I don't see an account under this email address so not sure. It probably means you have an IP that a

Re: [pfSense Support] Fwd: Squid uninstall/install problem

2011-08-07 Thread Chris Buechler
On Sun, Aug 7, 2011 at 11:20 AM, Carlos Vicente cjpvice...@gmail.com wrote: Hi again, this problem is on a production pfSense. Is there a way of removing any reference of squid on GUI? I think it's uninstalled from system. I need to reinstall the package. Backup the config, manually remove

Re: [pfSense Support] BGP support in 2.0

2011-08-03 Thread Chris Buechler
On Wed, Aug 3, 2011 at 2:20 AM, Typo3 on Gmail gl...@typo3usa.com wrote: Does 2.x have BGP support ? Yes, and considerably improved from 1.2.3 where you have a full Internet routing table or two as we've done some tweaks there to prevent PHP from running out of memory with very large routing

Re: [pfSense Support] BGP support in 2.0

2011-08-03 Thread Chris Buechler
On Wed, Aug 3, 2011 at 7:43 AM, Adam Thompson athom...@athompso.net wrote: I've been accepting ~ 13k routes inbound  advertising nothing.  So that part works, too. Now you just need confirmation from someone who does both! I setup one that does both last week, gets full Internet routing

Re: [pfSense Support] php: : Could not open /usr/local/etc/snort/suppress/ for writing.

2011-08-03 Thread Chris Buechler
On Wed, Aug 3, 2011 at 1:11 PM, Ernst den Broeder erns...@gmail.com wrote: I am seeing this message in the system logs: php: : Could not open /usr/local/etc/snort/suppress/ for writing. Here's the version info: pfsense 2.0-RC3 (i386)   (hard disk installation) snort 2.8.6.1 pkg v. 1.34

Re: [pfSense Support] BGP support in 2.0

2011-08-03 Thread Chris Buechler
On Wed, Aug 3, 2011 at 6:19 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: I setup one that does both last week, gets full Internet routing table, ~360K routes each, from two providers. And advertises their AS. What about IPv6? ;) Should work on the 2.1 branch with manual bgpd.conf

Re: [pfSense Support] Dual WAN with cable modem (dhcp) and ADSL (pppoe) with static IP (and IPv6)

2011-08-02 Thread Chris Buechler
On Mon, Aug 1, 2011 at 10:06 AM, Eugen Leitl eu...@leitl.org wrote: I'm running a pfSense 2.0RC3 (with 4 physical NICs) at home with cable modem on WAN assigned by DHCP. Works well -- unless it's down. I'm thinking about adding an ADSL line and run dual-WAN for redundancy and load-leveling.

Re: [pfSense Support] which version

2011-07-28 Thread Chris Buechler
On Fri, Jul 29, 2011 at 1:08 AM, Vick Khera vi...@khera.org wrote: Loading the 1.2.3 backup mostly works.  We had to manually copy the bits for the OpenVPN certificates -- for some reason they did not load in properly.  I think one other thing had to be manually reconfigured, but it was easy

Re: [pfSense Support] Routed SSH Sessions are killed After 15 Minutes Whether Active or Not

2011-07-26 Thread Chris Buechler
On Tue, Jul 26, 2011 at 4:15 PM, Paul Kunicki pkuni...@sproutloud.com wrote: Routed SSH Sessions are killed After 15 Minutes Whether Active or Not Hi everyone. I am running 1.2.3-RELEASE on two Dell Poweredge R300s with CARP configured for redundancy. Each node has four interfaces: em0:

Re: [pfSense Support] PHP error when generating RRD graphs

2011-07-25 Thread Chris Buechler
On Mon, Jul 25, 2011 at 8:40 PM, William Jimenez wjime...@appdynamics.com wrote: Will this be fixed in the latest release candidate you think? Should I maybe do a fresh install of pfsense and restore my config instead? Haven't seen that aside from scenarios where people manually restore their

Re: [pfSense Support] PHP error when generating RRD graphs

2011-07-25 Thread Chris Buechler
On Mon, Jul 25, 2011 at 9:19 PM, William Jimenez wjime...@appdynamics.com wrote: I actually don't care much about the old RRD data at this point, I would just like it to start recording data this point on Disable and enable RRD under StatusRRD, Settings tab and that should fix it.

Re: [pfSense Support] Disabling the GUI?

2011-07-23 Thread Chris Buechler
On Sat, Jul 23, 2011 at 4:07 PM, William Jimenez wjime...@appdynamics.com wrote: Is there a way to disable to GUI on pfsense to increase performance, and then re-enable it when needed? It has 0 impact on performance as it uses nothing other than a few MB RAM if you aren't using it. Even when

Re: [pfSense Support] Static Routes

2011-07-19 Thread Chris Buechler
On Tue, Jul 19, 2011 at 2:15 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: Afternoon all. We am running pfsense 1.2.3-RELEASE and having issues with a couple remote sites. We have a few static route statements.  Each of them are actually part of the same subnet and go to the same

Re: [pfSense Support] Logout button - captive portal

2011-07-16 Thread Chris Buechler
On Fri, Jul 15, 2011 at 2:59 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: Good afternoon all. We use the following version and it has been rather stable. 1.2.3-RELEASE built on Sun Dec 6 23:21:36 EST 2009 My issue is when authenticate, you can do whatever you have been authorized.

Re: [pfSense Support] if possible to use radius and vouchers together?

2011-07-13 Thread Chris Buechler
2011/7/11 梁富宏 lian...@supcon.com: my network has 300 users and some guests.guests need to temperary access internet. now i want to use pfsense's captiveportal to control the users and guests to access internet: 1. users use account to login captiveportal 2. guests use voucher to login

Re: [pfSense Support] Incorrect System Log Order/Logging Bug?

2011-07-08 Thread Chris Buechler
On Fri, Jul 8, 2011 at 4:26 PM, Vick Khera vi...@khera.org wrote: On Fri, Jul 8, 2011 at 1:06 PM, Dimitri Rodis dimit...@integritasystems.com wrote: I have my log set to show newest on top, and the log is “mostly” in order, but notice how there are some entries that are in the middle of this

Re: [pfSense Support] Can't connect to cvs.bsdinstaller.org

2011-07-08 Thread Chris Buechler
On Fri, Jul 8, 2011 at 1:13 PM, Bao Ha b...@hacom.net wrote: Hello, We are trying to build the pfSense 2.0. However, the process hangs around the following message: Fetching BSDInstaller using CVSUP... It seems that cvs.bsdinstaller.org keeps timeout. The work-around is to patch the

Re: [pfSense Support] Problems getting PFSync to run properly, starting the Backup server produces Packet Loss on WAN

2011-07-07 Thread Chris Buechler
On Wed, Jul 6, 2011 at 9:45 AM, Raimund Sacherer raimund.sache...@logitravel.com wrote: Hello, I have the same problem if I deactivate CARP on the Backup server, it tells me than that all CARP Interfaces are down, but the packet loss is still there, so I have to shutdown the Backup server.

Re: [pfSense Support] Problems getting PFSync to run properly, starting the Backup server produces Packet Loss on WAN

2011-07-05 Thread Chris Buechler
On Tue, Jul 5, 2011 at 9:13 AM, Raimund Sacherer raimund.sache...@logitravel.com wrote: Hello, Short Problem Description: Starting the Backup Server results in 50% (or more) packet loss on the WAN facing Interfaces. I saw in the states table that it seems that the Backup server is sending

Re: [pfSense Support] Carp failover time

2011-07-02 Thread Chris Buechler
On Sat, Jul 2, 2011 at 4:34 AM, Shibashish shi...@gmail.com wrote: Hi, What is the average time for the carp failover to kick in... i.e. how much time does it take for the backup to become master and start serving requests and vice versa? Immediate if it's expected (i.e. you reboot the

Re: [pfSense Support] Strange TCP connection behavior 2.0 RC2 (+3)

2011-06-28 Thread Chris Buechler
On Tue, Jun 28, 2011 at 3:03 AM, William Salt williamejs...@googlemail.com wrote: Hi All,          For the last couple of months i have been pulling my hair out trying to solve this problem. We have a 1Gbps transatlantic link from the UK to the US, which has successfully passed the RFC2544

Re: [pfSense Support] init process... starting non-pfsense package

2011-06-28 Thread Chris Buechler
On Tue, Jun 28, 2011 at 5:38 PM, Alberto Mijares amijar...@gmail.com wrote: Hi, as you may guess, I need to start a package I just installed with # pkg_add -r and if I try to start it, it doesn't (start, onestart, CLI, web interface... nothing works). I cannot write a rc.conf either. See

Re: [pfSense Support] supported auth protocols

2011-06-22 Thread Chris Buechler
On Wed, Jun 22, 2011 at 3:19 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Ok, thank you. Now I have a couple of important tasks that will take me off from this, but I hope I'll be back here in three-four weeks. There will also be a developer mailing list available in the near future,

Re: [pfSense Support] need reboot after changing firewall rules?

2011-06-21 Thread Chris Buechler
On Mon, Jun 20, 2011 at 11:04 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Hi. Mr Router wrote: Just upgraded to RC 2 will check this now and update my findings Could you replicate the problem? Today I upgrade to RC3 and now the problem seems solved. There were a couple days of

Re: [pfSense Support] supported auth protocols

2011-06-21 Thread Chris Buechler
On Tue, Jun 21, 2011 at 8:51 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Roberto Nunnari wrote: Roberto Nunnari wrote: Roberto Nunnari wrote: Chris Buechler wrote: On Thu, Jun 9, 2011 at 5:49 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Hi all. We now face a problem

Re: [pfSense Support] Current Production Version

2011-06-19 Thread Chris Buechler
On Sun, Jun 19, 2011 at 5:02 AM, Eugen Leitl eu...@leitl.org wrote: On Sat, Jun 18, 2011 at 08:35:56PM -0600, David Burgess wrote: On Sat, Jun 18, 2011 at 7:22 PM, Volker Kuhlmann hid...@paradise.net.nz wrote: Well, this is a little annoying. I have RC1 too, and I had checked only about a

Re: [pfSense Support] Current Production Version

2011-06-18 Thread Chris Buechler
On Sat, Jun 18, 2011 at 7:30 AM, Eugen Leitl eu...@leitl.org wrote: Strange, my 2.0-RC1-IPv6 (i386) is still at RC1. You haven't synced in weeks then. What's the fate of IPv6 development branch, then? http://forum.pfsense.org/index.php/topic,37895.msg195593.html#msg195593

Re: [pfSense Support] Current Production Version

2011-06-17 Thread Chris Buechler
On Fri, Jun 17, 2011 at 1:58 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Apologies for the dumb question...  Is the general consensus that 2.0-RC1 is production ready, or is 1.2.3 still recommended for production deployments? Latest snapshot is your best bet over RC1. RC3 comes this

Re: [pfSense Support] Current Production Version

2011-06-17 Thread Chris Buechler
On Fri, Jun 17, 2011 at 4:53 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Latest snapshot is your best bet over RC1. RC3 comes this weekend, release soon after. There are less than half as many tickets open on 2.0 as there were on 1.2.3 when it was released, latest 2.0 has far fewer

Re: [pfSense Support] supported auth protocols

2011-06-10 Thread Chris Buechler
On Thu, Jun 9, 2011 at 5:49 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Hi all. We now face a problem.. the captive portal, will need to authenticate users via a radius server. Unfortunately, that radius server doesn't support PAP, and pfSense seems to be using right that.. on the web

Re: [pfSense Support] multiple captive networks setup

2011-06-09 Thread Chris Buechler
On Thu, Jun 9, 2011 at 5:23 AM, Roberto Nunnari roberto.nunn...@supsi.ch wrote: Just need to add a firewall rule to allow that. Ok. I remember I read somewhere that pfSense uses openbsd pf as firewall even though it is based on FreeBSD. In any case I guess it's possible to do it via the web

Re: [pfSense Support] pfsense as a centralized antivirus update to multiple hosts

2011-06-02 Thread Chris Buechler
On Wed, Jun 1, 2011 at 8:24 PM, Joseph Rotan joseph.ro...@gmail.com wrote: Hi, I would like to confirm if pfsense can act as a centralized PC to update anti-virus to multiple host PC's connected on the same LAN. In general, no that's not possible. That depends on how the antivirus updates

Re: [pfSense Support] naive prioritization of VoIP?

2011-06-02 Thread Chris Buechler
On Thu, Jun 2, 2011 at 6:12 PM, Adam Thompson athom...@athompso.net wrote: This begs the question of what, exactly  do all those other firewalls DO when I set priority. It varies, but generally there's more to it than setting priority. You need link speed as well as you need the firewall do to

Re: [pfSense Support] 2.0 restore config partially?

2011-06-01 Thread Chris Buechler
On Wed, Jun 1, 2011 at 5:00 PM, Volker Kuhlmann hid...@paradise.net.nz wrote: When restoring the config on 2.0RC1 only partially from a full config backup nothing is restored. The config must contain only the part being restored when doing a partial restore.

Re: [pfSense Support] RE: Snort and pfsense

2011-05-25 Thread Chris Buechler
On Wed, May 25, 2011 at 3:12 AM, A Mohan Rao mohanra...@gmail.com hijacked yet another thread: You've been asked several times now, when you post, you must start a new message with a new subject. What you keep doing is called thread hijacking, you're sending a completely different question on

Re: [pfSense Support] DHCP Server with virtual IP (subnets)

2011-05-25 Thread Chris Buechler
On Wed, May 25, 2011 at 11:43 AM, Alberto Mijares amijar...@gmail.com wrote: DHCP server only supports the primary subnet, no way to do that without hacking the source. Ok. I guess you mean through webConfigurator. If I modify /var/dhcpd/etc/dhcpd.conf, could achieve my goal? May I write

Re: [pfSense Support] DHCP Server with virtual IP (subnets)

2011-05-24 Thread Chris Buechler
On Tue, May 24, 2011 at 4:24 PM, Alberto Mijares amijar...@gmail.com wrote: Hi, I'm trying to include static IP's in DHCP server. LAN interface has IP 10.10.0.1/24 I added an IP alias for the interface with 10.10.1.1/24, so I include the MAC address of a host for 10.10.1.2 It doesn't

Re: [pfSense Support] pfSense Git resources

2011-05-18 Thread Chris Buechler
On Wed, May 18, 2011 at 10:57 PM, Yehuda Katz yeh...@ymkatz.net wrote: If there any chance the documentation on http://devwiki.pfsense.org/ about the Git setup will be updated to include how to connect to the mainline on GitHub instead of rcs? Pages are updated but not really anything to it

Re: [pfSense Support] L7 queue seems not to work

2011-04-29 Thread Chris Buechler
On Fri, Apr 29, 2011 at 4:49 PM, bsd b...@todoo.biz wrote: No one has any feedback on L7 that and v.2.0.RC1 ? It doesn't work. At least apparently unless manually compiled. There is a ticket open on it. - To unsubscribe,

Re: [pfSense Support] A REALLY Simple Question, Really

2011-04-29 Thread Chris Buechler
On Fri, Apr 29, 2011 at 9:00 PM, Bruce B bruceb...@gmail.com wrote: Next time, when you change the LAN interface subnet just don't press APPLY. It actually gives you a RED notice to go ahead and change DHCP server range as well and then come back and press APPLY. Still the same.

Re: [pfSense Support] 802.11 b/g/n radio on Soekris Net5501

2011-04-21 Thread Chris Buechler
On Wed, Apr 20, 2011 at 12:38 PM, Karl Fife karlf...@gmail.com wrote: Can anyone make a recommendation for a pfSense-compatible Mini PCI Wi-Fi radio that is suitable/compatible for a Soekris 5501.  I'm looking for something that supports 802.11b/g/n on 2.4 GHz.  I'll be building this on

Re: [pfSense Support] IPSEC and static routes?

2011-04-19 Thread Chris Buechler
On Tue, Apr 19, 2011 at 11:53 AM, Adam Thompson athom...@athompso.net wrote: I know this has come up more than once in the past, but I can’t find it in the archives (i.e. can’t figure out the right keywords). If my pfSense box is the endpoint of an IPSec tunnel, all the devices routing

Re: [pfSense Support] IPSEC and static routes?

2011-04-19 Thread Chris Buechler
On Tue, Apr 19, 2011 at 9:12 PM, Adam Thompson athom...@athompso.net wrote: I know this has come up more than once in the past, but I can't find it in the archives (i.e. can't figure out the right keywords). [...] http://doc.pfsense.org/index.php/Why_can%27t_I_query_SNMP,_use

Re: [pfSense Support] Symmetrically routing connection with Multi-WAN and NAT

2011-04-18 Thread Chris Buechler
On Mon, Apr 18, 2011 at 6:14 AM, Per von Zweigbergk p...@itassistans.se wrote: I have the following set up in a lab: [WinXP](LAN)[edgefw](WAN1)(Link1)[mock- ](WAN)[to my real LAN]                [      ](WAN2)(Link2)[router](LAN)[Win7] The WinXP box has a chargen server

Re: [pfSense Support] PPPoE connection still doesn't establish

2011-04-15 Thread Chris Buechler
On Fri, Apr 15, 2011 at 3:17 AM, Maik Heinelt m...@vegasystems.com wrote: Hi, Today, I have installed latest pfSense v2.0 RC1 build on our Alix board. It seems not to work, even with this version. (I already posted about this problem with a younger pfSense 2.0 build). PPPoE was setup like

Re: [pfSense Support] Question on vlan

2011-04-14 Thread Chris Buechler
On Thu, Apr 14, 2011 at 4:01 AM, Dave LaLong dalal...@gmail.com wrote: Hello List! I setup a vlan and am using dhcp-relay on my pfsense box. I cannot seem to setup a rule that will block the dhcp request. You can't, short of manually hacking the source. On interfaces where the DHCP server or

Re: [pfSense Support] WAN DHCP does not pull DNS server info on 2.0-RC1 build Apr 8 2011?

2011-04-14 Thread Chris Buechler
On Tue, Apr 12, 2011 at 12:46 PM, Josh Karli josh.ka...@gmail.com wrote: On 4/11/2011 6:13 PM, Chris Buechler wrote: On Mon, Apr 11, 2011 at 6:11 PM, Josh Karlijosh.ka...@gmail.com  wrote: Hello all I updated to the Friday April 8 2011 build via auto update. My WAN is connected to my

Re: [pfSense Support] PPTP password issue

2011-04-13 Thread Chris Buechler
On Wed, Apr 13, 2011 at 10:32 AM, Ernst den Broeder erns...@gmail.com wrote: Hi. We are running 2.0-RC1 on our systems.  I recently assigned a PPTP user the following password: x2758A6g924B mpd quotes user passwords so the in there is probably breaking it. The only other character

Re: [pfSense Support] WAN DHCP does not pull DNS server info on 2.0-RC1 build Apr 8 2011?

2011-04-11 Thread Chris Buechler
On Mon, Apr 11, 2011 at 6:11 PM, Josh Karli josh.ka...@gmail.com wrote: Hello all I updated to the Friday April 8 2011 build via auto update. My WAN is connected to my internet modem and is configured by DHCP, and I am not part of a domain. After the update DNS name resolution did not work

Re: [pfSense Support] 2.0RC1 - PPTP client disconnect kills all IPsec VPNs

2011-04-06 Thread Chris Buechler
On Wed, Apr 6, 2011 at 9:12 PM, Leon Strong leon.str...@smx.co.nz wrote: On this subject, i'm also noticing whenever a rules update happens, our openvpn connections all drop. possibly something related to resetting the rules, and therefore any established tcp/udp connections? Changing

Re: [pfSense Support] 2.0RC1 - PPTP client disconnect kills all IPsec VPNs

2011-04-02 Thread Chris Buechler
On Thu, Mar 31, 2011 at 5:05 PM, David Rees dree...@gmail.com wrote: I posted this on the forum[1] but didn't get any responses, so am trying here. On 2.0-RC1 (amd64) built on Tue Mar 22 21:02:19 EDT 2011 When a PPTP user connects and then disconnects, all IPsec VPNs go down shortly

[pfSense Support] HP 1800s - was: Re: [pfSense Support] www.pfsense.org down?

2011-04-01 Thread Chris Buechler
On Sat, Mar 26, 2011 at 7:23 PM, Adam Thompson athom...@athompso.net wrote: The one that failed is a 1800-24G, cheapest managed 24 port gig switch they make. I bought a E2510G-24 to replace it, will use the 1800- 24G replacement somewhere less critical. Though I know our customers have at

Re: [pfSense Support] Some minor issues after upgrade

2011-03-30 Thread Chris Buechler
On Wed, Mar 30, 2011 at 1:11 PM, - Dickie Bradford - dbradf...@never-enuff.net wrote: On 3/26/2011 9:53 PM, - Dickie Bradford - wrote: Today I installed a New 2.0 RC1 pfsense build  and then installed my backup config from 1.2.3.   It went pretty well with minor issues that were easily fixed.

Re: [pfSense Support] Is the PPTP/GRE Limitation fixed in 2.0?

2011-03-28 Thread Chris Buechler
On Mon, Mar 28, 2011 at 3:45 PM, Adam Piasecki apiase...@midatlanticbb.com wrote: I found a thread on the message board stating this was fixed in 2.0. I'm testing it right now and can only get 1 client connected at a time. It used to be, caused panics in edge cases and was reverted, won't make

Re: [pfSense Support] www.pfsense.org down?

2011-03-26 Thread Chris Buechler
On Sat, Mar 26, 2011 at 8:50 AM, Nebojsa Djordjevic djn...@gmail.com wrote: I'm constantly getting connection reset errors trying to access http://www.pfsense.org/ -- anyone else having the same problem? Was earlier, switch flaked out. Go figure we replace an ancient Cat2924 which are ticking

Re: [pfSense Support] www.pfsense.org down?

2011-03-26 Thread Chris Buechler
On Sat, Mar 26, 2011 at 6:40 PM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Was earlier, switch flaked out. Go figure we replace an ancient Cat2924 which are ticking timebombs to fail with a brand new HP managed gigabit switch and it flakes out within a month.. At least the HP has a

Re: [pfSense Support] Spoofed wan mac issues in 2.0-RC1

2011-03-26 Thread Chris Buechler
On Fri, Mar 25, 2011 at 1:38 PM, Joseph L. Casale jcas...@activenetwerx.com wrote: It appears as if the wan int can only acquire a dynamic ip when its spoofed from a fresh boot. If you down it from the gui interfaces page, it cannot re-acquire an ip when you up it again. Works fine for

Re: [pfSense Support] RE: Release all unused DHCP leases.

2011-03-24 Thread Chris Buechler
On Wed, Mar 23, 2011 at 2:18 PM, Adam Thompson athom...@athompso.net wrote: Offline leases in the pfSense interface are, I believe, merely a visual guide to show you who last got that IP address.  The “offline” part is what I’m not 100% sure about – if it just means the expiry date is past, or

Re: [pfSense Support] can't block https://facebook.com via firefox

2011-03-22 Thread Chris Buechler
On Tue, Mar 22, 2011 at 5:22 PM, Adam Thompson athom...@athompso.net wrote: Some commercial firewalls (Fortigate, most notably) claim to filter HTTPS, I'm still a bit unclear on how they manage to break SSL that thoroughly even with what amounts to a MitM attack... The way those in general

Re: [pfSense Support] Cisco AnyConnect

2011-03-21 Thread Chris Buechler
On Mon, Mar 21, 2011 at 11:19 AM, David Burgess apt@gmail.com wrote: On Sun, Dec 5, 2010 at 12:10 AM, Chris Buechler cbuech...@gmail.com wrote: On Sun, Dec 5, 2010 at 2:02 AM, David Burgess apt@gmail.com wrote: But openconnect works, at least for me on Linux, and from what I gather

Re: [pfSense Support] 2.0 Web UI Unresponsive

2011-03-18 Thread Chris Buechler
On Thu, Mar 17, 2011 at 11:44 AM, Jim Riggs freebsd-li...@christianserving.org wrote: I have been having an issue with 2.0 for a few months (beta snapshots and RC1) that is driving me mad.  I'm hoping someone can shed some light on this. The server is a Dell PowerEdge R610 with bce0-bce3.  It

Re: [pfSense Support] pfSense network throughput issues

2011-03-18 Thread Chris Buechler
On Fri, Mar 18, 2011 at 3:39 AM, Shibashish shi...@gmail.com wrote: snip igb0@pci0:3:0:0:        class=0x02 card=0x34f28086 chip=0x10c98086 rev=0x01 hdr=0x00     class      = network     subclass   = ethernet igb1@pci0:3:0:1:        class=0x02 card=0x34f28086 chip=0x10c98086 The igb

Re: [pfSense Support] 3G NIC compatible with pfSense ?

2011-03-18 Thread Chris Buechler
On Fri, Mar 18, 2011 at 11:39 AM, bsd b...@todoo.biz wrote: Hi, I wanted to know if you had any idea about 3G / GSM NIC that would be compatible with pfSense ? How is 3G supposed to work with pfSense ? info here: http://doc.pfsense.org/index.php/Configuring_3G_modems

Re: [pfSense Support] 2.0 Web UI Unresponsive

2011-03-18 Thread Chris Buechler
On Fri, Mar 18, 2011 at 2:19 PM, Jim Riggs freebsd-li...@christianserving.org wrote: I had wondered if it was just a promiscuous mode thing, but just setting promiscuous on the IF doesn't seem to do it.  (Let me do some more testing, though.)  If it does work, what's the best way to make

Re: [pfSense Support] AW: update bogons

2011-03-18 Thread Chris Buechler
On Sat, Mar 19, 2011 at 12:35 AM, Jim Cheetham j...@inode.co.nz wrote: On 18/03/11 23:47, Fuchs, Martin wrote: Just one question remains: how are updates scheduled in 1.2.3 and how is it done in 2.0, even though this is nearly obsolete ? Same way in both, once a month. I'd add a question to

Re: [pfSense Support] RE: DHCP server settings

2011-03-15 Thread Chris Buechler
On Tue, Mar 15, 2011 at 2:40 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: Thank you, Adam.  We had the DHCP default lease time set to 4 hours and the Maximum lease time was set to the default of 24 hours.  So we lowered the default lease to 2 hours and left the maximum lease at 24 hours. 

Re: [pfSense Support] unwanted reboots

2011-03-14 Thread Chris Buechler
On Mon, Mar 14, 2011 at 7:07 AM, Nick Upson nick.up...@gmail.com wrote: Hi, my pfsense has started rebooting at (possibly random) intervals, I have it set to syslog to another box in the hope of catching more info but all I get is the that it's running fine and then the messages associated

Re: [pfSense Support] IP Routing

2011-03-11 Thread Chris Buechler
On Thu, Mar 10, 2011 at 8:44 PM, Anthony Saenz anth...@consumertrack.com wrote: Hi, I'm new to pfsense and so far haven't found a way to do the following: I'm trying to route traffic on ports 80/443 going to a public IP (in this case let's say 74.125.224.214) to a box we have internally here

Re: [pfSense Support] FreeBSD Lost Track of Drive During Upgrade [WAS: Re: pfSense Support] Re: List Posting Etiquette [WAS: Re: [pfSense Support] Re: Intel Gigabit - em0: Watchdog Timeout]

2011-03-10 Thread Chris Buechler
On Thu, Mar 10, 2011 at 12:14 AM, Mehma Sarja mehmasa...@gmail.com wrote: The - Motherboard is Super X7SPA-HF I switched the TORQX SSD with a regular drive - they both get stuck at the same point, see screenshot. Root mount fails is a panic Here is a link to what I think is the cause:

Re: [pfSense Support] FreeBSD Lost Track of Drive During Upgrade [WAS: Re: pfSense Support] Re: List Posting Etiquette [WAS: Re: [pfSense Support] Re: Intel Gigabit - em0: Watchdog Timeout]

2011-03-10 Thread Chris Buechler
On Thursday, March 10, 2011, Mehma Sarja mehmasa...@gmail.com wrote: On 3/10/11 11:33 AM, Chris Buechler wrote: Based on your screenshot, that has no relevance. The screenshot shows you're booting from CD, likely a USB CD drive, which is slow initializing and you need to pick the boot from

Re: [pfSense Support] Traceroute repeating itself

2011-03-09 Thread Chris Buechler
On Wed, Mar 9, 2011 at 10:20 AM, Shibashish shi...@gmail.com wrote: 114.113.93.41 is a ip from the Routed segment/Server Segment alotted to me by my ISP. If you have a routed subnet that isn't assigned on a local interface, and that doesn't have traceroute directed to another host via NAT,

Re: [pfSense Support] Multiple WAN subnets

2011-03-01 Thread Chris Buechler
On Tue, Mar 1, 2011 at 12:02 PM, JASON JAMES jam...@milton.k12.wi.us wrote: We currently use PFSense as a perimeter firewall it does all of our NAT as well. We recently ran out of public ip's and had another subnet issued to us. The problem is whether I add a new interface or set it up as a

Re: [pfSense Support] DNS forwarding log? Finding which machine is accessing what site.

2011-03-01 Thread Chris Buechler
On Tue, Mar 1, 2011 at 7:26 AM, Andy Graybeal andy.grayb...@casanueva.com wrote: Greetings, I'm wondering if there is a DNS forwarding log?  I don't have a DNS server installed here at the site, I use OpenDNS for my name servers. I have a machine that is requesting a website that supposedly

Re: [pfSense Support] Traffic that is explicitly allowed occasionally blocked

2011-02-28 Thread Chris Buechler
On Mon, Feb 28, 2011 at 12:51 PM, Dimitri Rodis dimit...@integritasystems.com wrote: *2.0-BETA5 *(i386) built on Mon Feb 21 15:43:32 EST 2011 I am seeing the above occur maybe once a day or once every other day, but the source IP address is in an alias that is a list of aliases (and

Re: [pfSense Support] OpenNTP

2011-02-28 Thread Chris Buechler
On Thu, Feb 24, 2011 at 3:22 PM, Fabian Abplanalp fabian.abplan...@bug.ch wrote: Sawadeekap Is it possible to connect a serial DCF or GPS clock to a pfSense box, or are the drivers missing in the OpenNTP package? Is it possible to set the parameters manually in a config File? Haven't tried

[pfSense Support] 2.0-RC1 now available!

2011-02-28 Thread Chris Buechler
http://blog.pfsense.org/?p=585 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] pfsense 1.2.3 ipsec stopping to work after too many unsuccessful connects

2011-02-11 Thread Chris Buechler
On Fri, Feb 11, 2011 at 5:31 PM, David Rees dree...@gmail.com wrote: Ah, now I see my confusion.  You can't create an alias or firewall rule with a hostname in 1.2.3 You can do that too. :) doesn't update automatically though, have to cron a ruleset reload. 2.0 handles it very nicely.

Re: [pfSense Support] pfsense 1.2.3 ipsec stopping to work after too many unsuccessful connects

2011-02-10 Thread Chris Buechler
On Thu, Feb 10, 2011 at 5:36 PM, Fuchs, Martin martin.fu...@trendchiller.com wrote: Hi ! I run pfsense 1.2.3 and use 4 ipsec tunnels with dynamic endpoints. Everything works fine, but when one endpoint continuously gets a new WAN-IP due to numerous reconnects, raccoon stops working and has

Re: [pfSense Support] pfsense 1.2.3 ipsec stopping to work after too many unsuccessful connects

2011-02-10 Thread Chris Buechler
On Thu, Feb 10, 2011 at 8:11 PM, David Rees dree...@gmail.com wrote: On Thu, Feb 10, 2011 at 2:57 PM, Chris Buechler cbuech...@gmail.com wrote: On Thu, Feb 10, 2011 at 5:36 PM, Fuchs, Martin martin.fu...@trendchiller.com wrote: I run pfsense 1.2.3 and use 4 ipsec tunnels with dynamic

Re: [pfSense Support] Buttons or menu options

2011-02-09 Thread Chris Buechler
On Tue, Feb 1, 2011 at 4:07 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: When I click on certain buttons or options, I will get the source code instead of results. The latest was http://10.10.10.10/reboot.php.  I clicked on the reboot menu option and it gave me source code. Is there a

Re: [pfSense Support] CARP IP Not Registering MAC Address or Switch Disregarding CARP MAC Address -- Maybe???

2011-02-09 Thread Chris Buechler
On Wed, Feb 9, 2011 at 8:51 PM, Vaughn L. Reid III vaughn_reid_...@elitemail.org wrote: My understanding of forwarding also was that address learning is a normal part of switch operation.  But, I find it odd that turning that off lets the fail-over box ping the CARP IP on the primary box, with

  1   2   3   4   5   6   7   8   9   10   >