Re: [pfSense Support] upgrade failure

2009-07-19 Thread Scott Ullrich
On Sun, Jul 19, 2009 at 9:57 PM, k_o_lk_...@hotmail.com wrote: This evening I attempted to upgrade to “pfSense-Full-Update-1.2.3-20090718-1920.tgz “  but failed with the following alert “Something went wrong when trying to update the fstab entry. Aborting upgrade.” Any ideas? If you are

Re: [pfSense Support] Re: Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-14 Thread Scott Ullrich
On Tue, Jul 14, 2009 at 6:08 PM, Tim A.pfse...@lists.goldenpath.org wrote: Chris Buechler wrote: On Sun, Jul 5, 2009 at 4:23 PM, Tim A.pfse...@lists.goldenpath.org wrote: Attached a patch against 1.2.3-rc2 adding support for auto configuring interfaces. That's definitely a nice feature,

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-07-13 Thread Scott Ullrich
On Mon, Jul 13, 2009 at 2:33 AM, Caroline Stekkecaroline.ste...@univ-rennes1.fr wrote: I know, but I use Firewall Builder for other work. In fact, I have to translate a Cisco config to my PfSense. And for this, I use Firewall Builder. The only problem that I have is to make this new Firewall

Re: [pfSense Support] virusprot question

2009-07-07 Thread Scott Ullrich
On Tue, Jul 7, 2009 at 5:49 AM, Earl Lapusearl.la...@gmail.com wrote: hi all, (Newbie question) I just want to ask, why isn't the virusprot table declared with the `persist` keyword like snort2c and sshlockout? In case there are no rules referring to the table: persist - causes the kernel to

Re: [pfSense Support] Understanding 2.0

2009-07-07 Thread Scott Ullrich
On Tue, Jul 7, 2009 at 12:27 PM, Tim A.pfse...@lists.goldenpath.org wrote: I don't get it. Sure there's a lot of features people want to add. And the answer is typically, 2.0. But what is the major platform difference for this major revision? I just built HEAD (2.0 on 7_2) and... umm... I like

Re: [pfSense Support] OpenBGPd raw config edit

2009-07-02 Thread Scott Ullrich
On Thu, Jul 2, 2009 at 7:44 AM, Aarno Aukiaaarnoau...@gmail.com wrote: $tab_array[] = array(gettext(Status), false, /openbgpd_status.php); Thanks, commited! Scott - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For

Re: [pfSense Support] OpenOSPFd

2009-07-02 Thread Scott Ullrich
On Thu, Jul 2, 2009 at 8:35 AM, Aarno Aukiaaarnoau...@gmail.com wrote: I did, but didn't find out how  service    namebgpd/name    rcfilebgpd.sh/rcfile    executablebgpd/executable  /service translates to a binary in /usr/local/sbin/... Ahh, take a look at pkg_config.7.xml pkg_config.8.xml

Re: [pfSense Support] OpenBGPd raw config edit

2009-07-01 Thread Scott Ullrich
On Wed, Jul 1, 2009 at 6:41 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Corrected patch (with correct highlighting of the selected tab) attached. Patch was already applied. You need to submit a change on top of what is commited: sullrich$ patch ~/Downloads/pfsense-openbgpd-rawconfig.diff

Re: [pfSense Support] OpenOSPFd

2009-07-01 Thread Scott Ullrich
On Wed, Jul 1, 2009 at 6:46 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hello, From what I saw in the forums (http://forum.pfsense.org/index.php?topic=11603.0) adding an openospfd package shouldn't be such a challenge. I can try to write an appropriate openospfd.xml, but how/where are the

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:39 AM, Curtis Maurandcmaur...@xyonet.com wrote: [snip] Unless I can get good communication going today, vyatta gets the nod at 5:00 pm. If you are under those types of time constraints then you really should consider our commercial support offering. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:46 AM, Curtis Maurandcmaur...@xyonet.com wrote: It works OK in 1.2.X. It works even better in 2.0. It really does work in 1.2.X using parallel tunnels. Scott - To unsubscribe, e-mail:

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:58 AM, Curtis Maurandcmaur...@xyonet.com wrote: [snip] I'm pretty frustrated. Even more of a reason to consider our offering. The offering is there to help eliminate frustration and to offer the best support possible. Scott

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 12:15 PM, Curtis Maurandcmaur...@xyonet.com wrote: I'm not sure $600.00 for a one time thing is worth it. The time leftover can be used for other situations. But it appears your mind is already made up. Scott

Re: [pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 11:58 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hello, Attached is a patch to allow the more experienced BGP admin to edit the raw bgpd.conf in the WebConfigurator. This is against

Re: [pfSense Support] OpenBGPd raw config edit

2009-06-30 Thread Scott Ullrich
On Tue, Jun 30, 2009 at 3:12 PM, Aarno Aukiaaarnoau...@gmail.com wrote: As noted on the Raw config site itself, the GUI-configuration is ignored as long as there is raw config present. One can empty out the raw config and then start using the gui again. Thanks, that is perfect. I have to

Re: [pfSense Support] log entries

2009-06-27 Thread Scott Ullrich
On Sat, Jun 27, 2009 at 9:01 AM, Lyle Giesel...@lcrcomputer.net wrote: I recently installed pfSense 1.2.3-RC1 on a Soekris NET4801 box. 1) Is there any documentation on the syslog entries like below?  These are not the same as the entries from a mOnOwall router. 2) Can someone enlighten me

Re: [pfSense Support] openVPN to OPT1 interface

2009-06-27 Thread Scott Ullrich
On Sat, Jun 27, 2009 at 6:22 AM, jose thomastk.j...@gmail.com wrote: Hi there, In our data center, we have two pfsense 1.2.2 boxes with two subnets behind the NAT. The OPT1 interfaces are been using for the inter communication between the two lan subnets owned by the two pfsense boxes. We

Re: [pfSense Support] blocking RFC1918 and bogons on 2nd WAN

2009-06-26 Thread Scott Ullrich
On Fri, Jun 26, 2009 at 7:19 AM, Paul Mansfieldit-admin-pfse...@taptu.com wrote: I did notice in the config file for the WAN there's a bogons attribute, if pondered copying it to WAN2, but was worried it would destroy the universe or break pfSense? Not recommended. Scott

Re: [pfSense Support] pfsense lighttp and php services

2009-06-26 Thread Scott Ullrich
2009/6/26 ozan ucar m...@ozanucar.com: Hi Dear All, I need run a php file with zend guard 5 encode. Install zend optimize and change php.ini but reboot pfSense my configuration deleted : ( What should I do ? Don't do that. You will probably want to install another web server to use for

Re: [pfSense Support] Inbound load balancer performance under heavy load.

2009-06-26 Thread Scott Ullrich
On Fri, Jun 26, 2009 at 11:25 AM, Scott Ullrichsullr...@gmail.com wrote: On Fri, Jun 26, 2009 at 8:07 AM, Paul Mansfieldit-admin-pfse...@taptu.com wrote: we've also had problems with inbound load balancing which we thought was just crappy ISP - a small number of http connections would quietly

Re: [pfSense Support] Cvstrac-Bug 1932 patch

2009-06-24 Thread Scott Ullrich
On Wed, Jun 24, 2009 at 8:22 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hi, Attached a patch against 1.2.3-rc1 fixing http://cvstrac.pfsense.com/tktview?tn=1932, which was opened by a co-worker of mine while I was on vacation. Let me know if de patch fails against cvs/git. I'll have to

Re: [pfSense Support] pfSense tinydns package question

2009-06-19 Thread Scott Ullrich
On Fri, Jun 19, 2009 at 6:18 AM, Matias Surdimatiassu...@gmail.com wrote: I've installed the TinyDNS package. It's listening on 127.0.0.1. Then I've setup the DNS forwarder to resolve a certain domain against the authoritative name server 127.0.0.1. This doesn't work when making queries from

Re: [pfSense Support] SpamD Broken Behavior Fixed, see attached patch.

2009-06-18 Thread Scott Ullrich
On Thu, Jun 18, 2009 at 10:25 AM, Tim A. pfse...@lists.goldenpath.org wrote: filter.inc.patch:      necessary for the correct operation of spamd Table whitelist exists but was never populated or used. Fixed. Table blacklist exists but was never populated. Fixed. Broken rule logic for

Re: [pfSense Support] SpamD Broken Behavior Fixed, see attached patch.

2009-06-18 Thread Scott Ullrich
On Thu, Jun 18, 2009 at 9:24 PM, Tim A.pfse...@lists.goldenpath.org wrote: Scott Ullrich wrote: Can you please do a diff -rub you want a recursive diff of the whole system? No, sorry I was not more clear. Just a diff -rub of filter.inc Scott

Re: [pfSense Support] SpamD Broken Behavior Fixed, see attached patch.

2009-06-18 Thread Scott Ullrich
On Thu, Jun 18, 2009 at 9:53 PM, Tim A.pfse...@lists.goldenpath.org wrote: No, no, I'm unfamiliar with the process. I'm sure you were perfectly clear. Ok, but I'll have to clean up first. A diff -rub in my current setup is messy. I guess I'm working a bit bass ackwards here. I copied the

Re: [pfSense Support] shellcmd package

2009-06-13 Thread Scott Ullrich
On Fri, Jun 12, 2009 at 10:19 AM, Aarno Aukiam...@arska.ch wrote: Hello list, I was editing config.xml by hand to add system/shellcmd and system/earlyshellcmd until I noticed the Shellcmd package. When I started using that on pfSense 1.2.3-rc1 all shellcmds stopped working, because the

Re: [pfSense Support] Issue building an ISO

2009-06-08 Thread Scott Ullrich
On Mon, Jun 8, 2009 at 4:33 PM, Alexsander Loulaalex.lo...@gmail.com wrote: Hi Folks, I'm trying to build a custom pfSense image following this procedure http://devwiki.pfsense.org/DevelopersBootStrapAndDevIso, but the process is stucking right after (on miniobj.h): # ./cvsup_current .

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Scott Ullrich
On Tue, Jun 2, 2009 at 6:14 PM, Victor Padro vpa...@gmail.com wrote: Excuse me Chris, I know that, but here in Mexico I had to do that a couple times with Telmex(ADSL ISP), and didn't know the reason of that behaviour. Even my old Pentium II has that boxes unchecked in other to surf the net.

Re: [pfSense Support] snort update problem

2009-05-29 Thread Scott Ullrich
2009/5/29 ozan ucar m...@ozanucar.com: Hello, I have pfsense 1.2.2.I'm install snort but dont update rule.Error: snort rules: md5 signature of rules mismatch. I have oinkmaster code, entered snort page but dont update snort :( What is my problem and how to manual update snort rule. Thanks

Re: [pfSense Support] QoS with no ingress interface

2009-05-29 Thread Scott Ullrich
On Fri, May 29, 2009 at 1:35 PM, David Burgess apt@gmail.com wrote: I asked this on the forum but didn't get any info: http://forum.pfsense.org/index.php/topic,16361.0.html Basically I want to filter traffic that originates from pfsense itself. The traffic shaper GUI requires that I

Re: [pfSense Support] arm arch?

2009-05-27 Thread Scott Ullrich
On Wed, May 27, 2009 at 4:25 PM, David Burgess apt@gmail.com wrote: That's a good reason. What about using a NetBSD base? I suppose that would be another big job? More than you can imagine. Scott - To unsubscribe, e-mail:

Re: [pfSense Support] dyndns on multiWAN

2009-05-26 Thread Scott Ullrich
On Tue, May 26, 2009 at 12:45 AM, David Burgess apt@gmail.com wrote: On Mon, May 25, 2009 at 10:38 PM, Chris Buechler c...@pfsense.org wrote: You can't until 2.0. Only WAN is supported. Thanks for the quick response. Not even by editing a file somewhere? Not without modify a number of

Re: [pfSense Support] openssh flaw

2009-05-21 Thread Scott Ullrich
On Thu, May 21, 2009 at 3:37 PM, David Burgess apt@gmail.com wrote: http://linux.slashdot.org/article.pl?sid=09/05/21/1824220from=rss What versions run in pfsense? Is this something we should be concerned about? http://openssh.com/txt/cbc.adv In a nutshell: not a problem. If you are

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-05-13 Thread Scott Ullrich
On Wed, May 13, 2009 at 10:21 AM, Rainer Duffner rai...@ultra-secure.de wrote: AFAIK, SUN still provides eval-systems for free. I would evaluate one of the new X2270 with the Nehalem Xeons. This should provide a 50% boost even on 5400-series Xeons. Also, they use Intel NICs, IIRC. The

Re: [pfSense Support] RE: T1 Saturating - Windows update kills the connection... ??

2009-05-13 Thread Scott Ullrich
On Wed, May 13, 2009 at 11:55 AM, Chris Buechler c...@pfsense.org wrote: Slowing down considerably when under full load is normal, slowing to the point that sites don't load anymore when you're just running a few Windows updates is definitely not. Sounds like there's something wrong with the

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-05-13 Thread Scott Ullrich
On Wed, May 13, 2009 at 8:36 PM, Dimitri Rodis dimit...@integritasystems.com wrote: My understanding is that Giant lock is gone from the FreeBSD network stack in 8: http://unix.derkeiler.com/Mailing-Lists/FreeBSD/arch/2009-04/msg00075.html PF is still protected by one giant lock and does not

Re: [pfSense Support] No IP over DHCP

2009-04-24 Thread Scott Ullrich
On Fri, Apr 24, 2009 at 5:27 PM, Michael Schmitt stiff...@linuxnoob.net wrote: Hello List, I try the new 1.2.3-RC1-Embedded release on an ALix board. WAN -- sis0, dhcp LAN -- sis1, 10.0.0.1/24 WLAN -- ath0 bridged with LAN (atheros 5212 chipset) dhcp-server is enabled for LAN. the first

Re: [pfSense Support] pfSense based on -STABLE or -CURRENT

2009-04-22 Thread Scott Ullrich
On Wed, Apr 22, 2009 at 9:42 AM, Cristiano Deana cristiano.de...@gmail.com wrote: Hi, i need a pfSense based on 7-STABLE (better) or -CURRENT, to have working usb support for apple usb2ethernet device. Is it possible to do? Or can i make a patchetd and personalized kernel on pfSense? I will

Re: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-18 Thread Scott Ullrich
On Sat, Apr 18, 2009 at 7:25 PM, Tim Nelson tnel...@fudnet.net wrote: [snip BTW, any release date on the horizon for 1.2.3? When it's done. Scott - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional

Re: [pfSense Support] feature request: VPNC

2009-04-11 Thread Scott Ullrich
On Sat, Apr 11, 2009 at 6:53 AM, Mikel Jimenez Fernandez mi...@irontec.com wrote: Hello I found that is a port for freebsd of vpnc cisco client. http://www.freebsdsoftware.org/security/vpnc.html http://www.unix-ag.uni-kl.de/~massar/vpnc/ This is usefull when you want to connect your

Re: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Scott Ullrich
On Wed, Apr 8, 2009 at 11:31 PM, Dimitri Rodis dimit...@integritasystems.com wrote: Currently running: 1.2.3-RC1 built on Wed Apr 1 16:59:10 EDT 2009 Changed the CARP config-- had a redundant member that I removed, so I shut pfsync off. However, I kept getting messages along the top that

Re: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Scott Ullrich
On Thu, Apr 9, 2009 at 12:37 PM, Dimitri Rodis dimit...@integritasystems.com wrote: I think this is more obscure than you think-- this is on a snapshot build, so how many people have 1) run a 1.2.3 snapshot, 2) _had_ a redundant CARP config, and then 3) removed the redundant member and 4) added

Re: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Scott Ullrich
On Thu, Apr 9, 2009 at 1:57 PM, Dimitri Rodis dimit...@integritasystems.com wrote: The snapshot I'm using is dated April 1.. that's a couple of days after the hackathon, I believe. Any idea when the xmlparse.inc from HEAD was removed? You where affected then. It was removed for causing

Re: [pfSense Support] Intel Atom Install Trouble

2009-03-30 Thread Scott Ullrich
On Mon, Mar 30, 2009 at 4:58 PM, Vaughn L. Reid III vaughn_reid_...@elitemail.org wrote: I have a Intel Atom based board that I'm trying to get pfsense to install on.  I can boot fine into safe mode but I get a panic message when I try the default boot config.  I can reproduce this from both

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-03-23 Thread Scott Ullrich
On Mon, Mar 23, 2009 at 8:30 AM, Lenny five2one.le...@gmail.com wrote: I got offered a Sun Fire X2200 with Opteron Dual Core 2210(that's 1.8GHz). Will that do it? (for ~150kpps) Stick with boxes that feature EM (Intel) NICS. Scott

Re: [pfSense Support] Web User interface gone ?

2009-03-19 Thread Scott Ullrich
On Thu, Mar 19, 2009 at 7:56 AM, Michel Servaes mic...@mcmc.be wrote: I just updated my pfSense 1.2.3 prerelease version through a webupdate. Which just seems to be working fine, allthough I cannot access the webinterface anymore ?? I already restarted the webconfigurator through telnetting

Re: [pfSense Support] Web User interface gone ?

2009-03-19 Thread Scott Ullrich
On Thu, Mar 19, 2009 at 11:43 AM, Michel Servaes mic...@mcmc.be wrote: This is a brilliant response... ROTFL !!! I guess I can safely downgrade to 1.22 using SSH/Telnet ? Yes. It is an option on the console menu. Scott - To

Re: [pfSense Support] packet loss question

2009-03-19 Thread Scott Ullrich
On Thu, Mar 19, 2009 at 6:09 PM, Mikel Jimenez Fernandez mi...@irontec.com wrote: Hello I have a firewall with 2 interfaces. WAN and AN and CARP LAN = 10.10.0.99 CARP=10.10.0.100 Is this normal from lan host? backup:~# ping -f 10.10.0.99 PING 10.10.0.99 (10.10.0.99) 56(84) bytes of

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-03-16 Thread Scott Ullrich
On Mon, Mar 16, 2009 at 7:14 AM, Lenny five2one.le...@gmail.com wrote: Hi again, So I did replace the server, I have an IBM x336 now instead of the x335. The NIC is the identical, but not the same. First of all, Chris, you were absolutely right - it was some sort of a glitch with the

Re: [pfSense Support] Nat traversal and Asterisk

2009-03-16 Thread Scott Ullrich
On Mon, Mar 16, 2009 at 7:50 PM, k_o_l k_...@hotmail.com wrote: Hello, Is there a known issue between Pfsense, Asterisk,  and Nat traversal? The reason I ask is, I’ve noticed a one-way-audio problem when using Pfsense and no problem when using different product namely FortiGate. Common

Re: [pfSense Support] LCDProc Package on Embedded

2009-03-06 Thread Scott Ullrich
On Fri, Mar 6, 2009 at 3:17 PM, Jeppe Øland jol...@gmail.com wrote: Actually, LCDProc would be a pretty cool feature to have as standard in the embedded version of pfSense. If there are problems with the embedded boxes, it's virtually impossible to figure out whats going on. The LCD could

Re: [pfSense Support] Re: Not resolving external addresses

2009-02-21 Thread Scott Ullrich
On Sat, Feb 21, 2009 at 1:08 PM, Victor Padro vpa...@gmail.com wrote: Actually I did that, TinyDNS is enabled without DNS fowarder and the results are the same, no external resolution I have to restart the DNS service in order to surf the web. any other pointer? What does TinyDNS have to do

Re: [pfSense Support] pfsync vs contrackd

2009-02-19 Thread Scott Ullrich
On Thu, Feb 19, 2009 at 1:26 PM, mikel mi...@irontec.com wrote: I ask this question, because I am favour ogf *BSD, and one friend discuss me that what pfsync+carp does, is possible with contrackd. I have read that contrackd only syncs tcp states, and is a user space daemon, not kernel level.

Re: [pfSense Support] Re: policy rules with proxy and multiwan

2009-02-16 Thread Scott Ullrich
On Mon, Feb 16, 2009 at 9:57 AM, Federico Konig chamiko...@gmail.com wrote: Nobody answer? 2009/2/12 Federico Konig chamiko...@gmail.com I setup multiwan with 4 links, and i have a proxy service. Then, the machines on lan navigate trough the proxy. The proxy request a page trough the

Re: [pfSense Support] Issues with upgrade to pfsense version 1.2.2

2009-02-12 Thread Scott Ullrich
On Thu, Feb 12, 2009 at 2:05 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: We upgraded to pfSense version 1.2.2 today around 0530. It seems to have upgraded just fine and personnel started logging into the CaptivePortal and I tested it as well and it worked as expected. However, around 11:30

Re: [pfSense Support] Issues with upgrade to pfsense version 1.2.2

2009-02-12 Thread Scott Ullrich
On Thu, Feb 12, 2009 at 2:57 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: The captive portal page was locked up. It appears that there was a php issue around 11:00 or so. Scott, where would I find the 1.2.3 release? http://snapshots.pfsense.org/FreeBSD7/RELENG_1_2/?C=M;O=D It has been

Re: [pfSense Support] Problem when rebooting... Embedded on ALIX

2009-01-31 Thread Scott Ullrich
On Sat, Jan 31, 2009 at 8:31 PM, Chuck Mariotti cmario...@xunity.com wrote: I have managed (thanks to help on this list) to get my ALIX board running a full install of pfSense on 8GB CF card, so that I could enable Snort service (default install with embedded kernel). I ran into the problem

Re: [pfSense Support] (v2.0-ALPHA-ALPHA) Issue with IPSec VPN, PSK + Xauth and pfSense Users...

2009-01-30 Thread Scott Ullrich
On Fri, Jan 30, 2009 at 9:00 AM, Gavin Spurgeon gspurg...@dageek.co.uk wrote: Hi All, Have been on #pfsense and asked about this issue, but as yet nobody has come up with an answer/suggestion... This is my situation:- I have the pfsense box setup as a IPSec VPN Server (+Mobile hosts) my

Re: [pfSense Support] problems trying to sftp/scp pfSense router

2009-01-30 Thread Scott Ullrich
On Fri, Jan 30, 2009 at 2:32 PM, Vick Khera vi...@khera.org wrote: On Fri, Jan 30, 2009 at 8:41 AM, Jorge Marques Pelizzoni jorge.pelizz...@gmail.com wrote: First of all, congratulations on the great work you've been doing on pfSense! Here is my problem: I've enabled ssh on my pfSense 1.2.2

Re: [pfSense Support] 1.2.2 TCP Disconnects (sessions)

2009-01-29 Thread Scott Ullrich
On Thu, Jan 29, 2009 at 11:45 PM, Curtis LaMasters curtislamast...@gmail.com wrote: At my company we host a large number of dotnet sites and have now been plagued with an issue in our hosting environment. Nearly all of our sites are now report periodic disconnects where users viewing the sites

Re: [pfSense Support] Error While Mounting fd0 when trying to save config

2009-01-27 Thread Scott Ullrich
On Tue, Jan 27, 2009 at 10:35 AM, Marty Nelson mnel...@transdyn.com wrote: When trying to upgrade using a 1.2.3 livecd, here's the error message I received. Warning: filesize(): Stat failed for /conf/config.xml (errno=2 - No such file or directory) in /etc/inc/config.inc on line 218

Re: [pfSense Support] 1.2.2

2009-01-27 Thread Scott Ullrich
On Tue, Jan 27, 2009 at 2:58 PM, Paul Cockings p...@cytringan.co.uk wrote: Fresh install of 1.2.2 (LiveCD installed to HDD) System Advanced Enable filtering bridge There is no checkbox to enable this option. I'm trying to setup a 'transparent' firewall (trendchiller instructions) as i've

Re: [pfSense Support] Error While Mounting fd0 when trying to save config

2009-01-26 Thread Scott Ullrich
On Mon, Jan 26, 2009 at 3:04 PM, Marty Nelson mnel...@transdyn.com wrote: Greetings all. I'd imagine I'm doing something utterly stupid, but why in the heck can't I save my config to floppy? When selecting 98 it shows fd0 as an available device but when I say, ok go ahead and save to fd0 it

Re: [pfSense Support] Odd boot behavior

2009-01-23 Thread Scott Ullrich
On Fri, Jan 23, 2009 at 4:25 PM, tehp...@gmail.com wrote: Good afternoon everyone, I'm currently trying to get my old Soekris 4801 running as a router again. I never had a single problem with the thing running m0n0wall, and I figured since development has slowed on m0n0wall i'd give pfSense

Re: [pfSense Support] Intermediate CA issue

2009-01-14 Thread Scott Ullrich
On Wed, Jan 14, 2009 at 9:34 AM, Atkins, Dwane P atki...@uthscsa.edu wrote: Awhile we had an issue where we had to modify the system.inc so that we could add the line $lighty_config .= ssl.ca-file = \/path/to/my/cert/mycert.pem\\n\n; Did this get fixed in recent releases? If not, are there

Re: [pfSense Support] dnsmasq 2.46? in 1.2.2??

2009-01-13 Thread Scott Ullrich
On Tue, Jan 13, 2009 at 3:32 PM, apiase...@midatlanticbb.com apiase...@midatlanticbb.com wrote: Is there any reason why dnsmasq 2.46 wasn't added to 1.2.2 releases? We tried upgrading our 1.2.2 box but were getting some errors for missing library's. Yes, there is a BIG reason:

Re: [pfSense Support] Iface combo not showing lagg interfaces for vlan association.

2009-01-13 Thread Scott Ullrich
On Tue, Jan 13, 2009 at 7:13 PM, Aliet Santiesteban Sifontes alietsantieste...@gmail.com wrote: Testing 20090112 2.0 Alpha I have found that the lagg interfaces are not listed in the combo for vlan parent interface, any workaraound for this???. Best regards Kindly, this list is for

Re: [pfSense Support] bogons - was pfsense 1.2.1 wizard bug

2009-01-08 Thread Scott Ullrich
On Thu, Jan 8, 2009 at 6:50 AM, Paul Mansfield it-admin-pfse...@taptu.com wrote: Chris Buechler wrote: The list is auto updated monthly if your firewall can get to the Internet. Clean installs aren't immediately updated. should the part of the page with the bogon enable/disable have the

Re: [pfSense Support] SquidGuard error on upgrade from RC2 to 1.2.1

2009-01-08 Thread Scott Ullrich
On Thu, Jan 8, 2009 at 10:37 AM, Jostein Elvaker Haande jehaa...@gmail.com wrote: Hello dear pfSense users. I just upgraded my installation of pfSense, and noticed this error after all the packages were reinstalled: [snip] Warning: fopen(/usr/local/etc/squidGuard/squidguard_conf.xml):

Re: [pfSense Support] Couple OpenNTPd Ticket Comments Fix

2009-01-08 Thread Scott Ullrich
On Wed, Jan 7, 2009 at 11:24 PM, David Rees dree...@gmail.com OK, here's a tested fix. Seems to work on my system. Looks like you applied the other fix already, this patch should apply over it. Thanks. I committed a slightly changed version of your patch (to stop ntpd correctly). Scott

Re: [pfSense Support] Couple OpenNTPd Ticket Comments Fix

2009-01-08 Thread Scott Ullrich
On Thu, Jan 8, 2009 at 8:46 PM, JJB onephat...@earthlink.net wrote: So does OpenVPN on pfsense have a known vulnerability, and if so, can we patch the pfsense servers (running 1.2) as described in the advisory? 1.2.2 will be released in the next couple of days. It is undergoing testing now.

Re: [pfSense Support] 1.2.1-RC4 failover supposed to be stateful? OpenVPN config sync?

2008-12-26 Thread Scott Ullrich
On Fri, Dec 26, 2008 at 5:28 PM, Jason Lixfeld jason-lists.pfse...@lixfeld.ca wrote: [snip] Well, kinda. As far as the OS is concerned it's a dedicated NIC. It's running inside an ESXi VM so it's a VLAN on a trunk as far as VMWare is concerned. You need to turn on promiscuous mode on the

Re: [pfSense Support] 1.2.1-RC4 failover supposed to be stateful? OpenVPN config sync?

2008-12-26 Thread Scott Ullrich
On Fri, Dec 26, 2008 at 6:06 PM, Jason Lixfeld jason-lists.pfse...@lixfeld.ca wrote: Ok, so just so I'm not chasing a wild good, the failover is supposed to be stateful, right? Sessions in or out of a pfSense cluster shouldn't be disconnected or need to be reconnected, right? I don't think

Re: [pfSense Support] issue with too big alias blocks solved

2008-12-20 Thread Scott Ullrich
2008/12/20 Claus Marxmeier cl...@marxmeier.de: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi there! I had problems with too big alias blocks in the past. After splitting every alias into 200entry and numbering aliasnames with parts#no it works fine now. The only thing left: pfsense

Re: [pfSense Support] Looks like someone out there is busy working on the freenas package...

2008-12-20 Thread Scott Ullrich
On Sat, Dec 20, 2008 at 7:39 PM, Josh McAllister josh...@gmail.com wrote: Let me preface this by saying I know all the reasons why one should not combine freenas/firewall. Armed with that knowledge, I'd like to do it anyways. Google shows me someone is busy at work:

Re: [pfSense Support] /cf: filesystem full

2008-12-13 Thread Scott Ullrich
On Thu, Dec 11, 2008 at 7:45 PM, David Rees dree...@gmail.com wrote: Your problem sounds different than ours. We finally ran out of space because our config files kept on getting bigger, not because something is filling up the partition behind our backs. After a reboot, there still seems to

Re: [pfSense Support] regulary checks of config.xml through md5

2008-12-05 Thread Scott Ullrich
On Fri, Dec 5, 2008 at 3:10 PM, [EMAIL PROTECTED] wrote: Hi, as i am investigating monitoring solutions at the moment i came up with an idea, somebody has already implemented: what about regulary getting the config.xml (not bad as backup as well) and checking it against a former - good

Re: [pfSense Support] Memory Detection Problem in 1.2.1-RC2?

2008-12-03 Thread Scott Ullrich
On Wed, Dec 3, 2008 at 10:34 PM, Tim Nelson [EMAIL PROTECTED] wrote: Good evening all- I've just booted the latest 1.2.1-RC2 LiveCD on an old 1U network appliance. The embedded board is made by Force computing and has a fanless 600mhz Celeron onboard with 320MB RAM (2x 128 + 1x 64). The

Re: [pfSense Support] Reflective routing broken in newest 1.2.1-RC2 SNAP

2008-11-27 Thread Scott Ullrich
On Thu, Nov 27, 2008 at 2:01 PM, Scott Ullrich [EMAIL PROTECTED] wrote: On Thu, Nov 27, 2008 at 11:57 AM, DLStrout [EMAIL PROTECTED] wrote: If I back down (using the console UG method - 13) to the image below (from mirror) and restore the backed-up configuration (interfaces portion only

Re: Re: [pfSense Support] Reflective routing broken in newest 1.2.1-RC2 SNAP

2008-11-27 Thread Scott Ullrich
On Thu, Nov 27, 2008 at 6:16 PM, DLStrout [EMAIL PROTECTED] wrote: Let me know if I can provide anything else. I want to see the working rule(s). Scott - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands,

Re: [pfSense Support] Reflective routing broken in newest 1.2.1-RC2 SNAP

2008-11-27 Thread Scott Ullrich
On Thu, Nov 27, 2008 at 9:49 PM, DLStrout [EMAIL PROTECTED] wrote: It looks like it is getting hung up on the way back out of the virtual (test) environment Nov 27 21:41:55 LAN 192.168.22.22:5900 192.168.1.2:33150 TCP The rule that triggered this action is:

Re: [pfSense Support] manual pf rules

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 2:18 PM, mikel [EMAIL PROTECTED] wrote: I have configurate manually tun0 to my ISP(ppp0 interface) and I want to do NAT in this interface See http://devwiki.pfsense.org/OpenVPNasWAN which does something similar. Scott

Re: [pfSense Support] manual pf rules

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 2:34 PM, mikel [EMAIL PROTECTED] wrote: Please Scott The origin of this probelms is that i can´t configure pptp client with my ISP in pfsense. Please help me Believe it or not, I did read your original message. See the URL I posted. Scott

Re: [pfSense Support] manual pf rules

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 2:38 PM, mikel [EMAIL PROTECTED] wrote: But this is using openvpn, and I need pptp Yes, and openvpn is no different in using a dynamic interface just like mpd does. This has been discussed quite a bit in the past on this mailing list and in the forum. Do some google

Re: Re: [pfSense Support] pptp help!!

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 4:09 PM, mikel [EMAIL PROTECTED] wrote: Sorry, there are some mistakes, this are resolved: Is simply, my ISP requires pptp client configuration to have non-dynamic ip address. If Pfsense can´t do that, i don´t know what is the purpose of pptp type connection in WAN

Re: Re: [pfSense Support] pptp help!!

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 4:22 PM, mikel [EMAIL PROTECTED] wrote: OK so explain me please the purpose off pptp wan interface. In practical/reallife scenario please Exactly what you want it to be, but it expects the IP address to be handed out via DHCP. Scott

Re: Re: [pfSense Support] pptp help!!

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 5:32 PM, Curtis LaMasters [EMAIL PROTECTED] wrote: Scott/Chris - Would the Centipede Networks or BSD Perimeter teams be able to help with this buy buying a support package? I think direct contact is going to be the only solution to this... No. He wants to be able to

Re: Re: [pfSense Support] pptp help!!

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 5:39 PM, mikel [EMAIL PROTECTED] wrote: I can´t believe how it can be so defficult... when you buy a common house router, and ii fyou have to have non-dynamic ip addres, you ask to your isp, and it gives you some info. In my case username, password and one i, the

Re: Re: [pfSense Support] pptp help!!

2008-11-25 Thread Scott Ullrich
On Tue, Nov 25, 2008 at 6:45 PM, mikel [EMAIL PROTECTED] wrote: Dear Crish/Scot/Developers I t will be possible modify this patch to adapt to 1.2RCx and 2.0? http://www.mail-archive.com/[EMAIL PROTECTED]/msg01766.html thanks, I wait your response This patch will not solve your problem.

Re: [pfSense Support] pfSense and dynamic routing

2008-11-19 Thread Scott Ullrich
On Wed, Nov 19, 2008 at 9:07 AM, Veiko Kukk [EMAIL PROTECTED] wrote: Erwan David wrote: OpenBGPD is in the packages. Thank you, but is it stable enought (ALPHA)? Are there any plans to make Quagga package for pfSense? # uptime 3:50PM up 196 days, 16:46, 2 users, load averages: 0.00, 0.00,

Re: [pfSense Support] pfSense and dynamic routing

2008-11-19 Thread Scott Ullrich
On Wed, Nov 19, 2008 at 6:29 PM, Bill Marquette [EMAIL PROTECTED] wrote: [snip] At this point we should probably move it to stable as it's been around a while and has had no bug reports. Done. Scott - To unsubscribe, e-mail:

Re: [pfSense Support] NAT Reflection States

2008-11-18 Thread Scott Ullrich
On Tue, Nov 18, 2008 at 6:32 PM, Dimitri Rodis [EMAIL PROTECTED] wrote: How long will pfSense hold onto the states required to maintain a tcp connection/udp session, and can this be changed? It seems like connections on my network that are utilizing NAT reflection are timing out extremely

Re: [pfSense Support] NAT Reflection States

2008-11-18 Thread Scott Ullrich
On Tue, Nov 18, 2008 at 6:40 PM, Dimitri Rodis [EMAIL PROTECTED] wrote: That's milliseconds, correct? I believe that is seconds, actually (whatever the default nc uses -- netcat). Scott - To unsubscribe, e-mail: [EMAIL

Re: [pfSense Support] NAT Reflection States

2008-11-18 Thread Scott Ullrich
On Tue, Nov 18, 2008 at 7:04 PM, digger [EMAIL PROTECTED] wrote: I have the same issue with reflection and SSH. The session closes after about 20 seconds. I am using* *1.2.1-RC1 built on Thu Oct 16 07:20:59 EDT 2008 Not a huge issue as I can connect directly to the internal IP in the DMZ but

Re: [pfSense Support] NAT Reflection States

2008-11-18 Thread Scott Ullrich
On Tue, Nov 18, 2008 at 7:10 PM, Dimitri Rodis [EMAIL PROTECTED] wrote: There are a ton of lines that look like this: 19004 stream tcp nowait/0nobody /usr/bin/nc nc -w 20 I guess we found the culprit then? Why is it using 20 as opposed to 2000? It was a mistake / code

Re: [pfSense Support] Directed Broadcast for WOL

2008-11-14 Thread Scott Ullrich
On Thu, Nov 13, 2008 at 5:02 PM, Heinrich Pechtold [EMAIL PROTECTED] wrote: Hi, is there a possibility to enable directed Broadcasts (redirecting them in the remote subnet) for WOL purposes in Freebsd? I would like to turn on some PCs in a remote Vlan. Not that I know of. Only direct

Re: [pfSense Support] Reflective routing ?

2008-11-12 Thread Scott Ullrich
On Wed, Nov 12, 2008 at 6:50 AM, DLStrout [EMAIL PROTECTED] wrote: All seems well on 1.2.1, but when testing 2.0Ax2 I noticed one of the start up scripts hangs and produces the below output. Not real sure how to debug it and had to CTRL-C to get it to finally finish booting up. I appears to

Re: Re: [pfSense Support] Reflective routing ?

2008-11-12 Thread Scott Ullrich
On Wed, Nov 12, 2008 at 1:11 PM, DLStrout [EMAIL PROTECTED] wrote: Absolutely NOT disappointed at all, just pointing out an issue ... quite the contrary in fact, and I am as anxious as any to see some of the fantastic new features of 2.0 in a STABLE release. Really just try to provide some

Re: [pfSense Support] lighttpd bug in 1.2

2008-11-11 Thread Scott Ullrich
On Tue, Nov 11, 2008 at 11:33 AM, rgreiner [EMAIL PROTECTED] wrote: Hi, I've been getting some problems with the web pages on our pfSense server (version 1.2), and after some digging I found the following message in /var/log/lighttpd.error.log (repeated quite a few times): 2008-11-11

Re: [pfSense Support] Syncing DHCP configs

2008-11-11 Thread Scott Ullrich
On 11/11/08, Ian Levesque [EMAIL PROTECTED] wrote: Before I go through the process of trying to hack into the sync backend on pfsense, I just wanted to put this out there one last time... Anybody with inside info willing to shed some light on the future plans for this issue? Cheers, Ian

<    1   2   3   4   5   6   7   8   9   10   >