Re: [pfSense Support] RE: Load Balancer Using TCP

2009-04-04 Thread Chris Buechler
On Thu, Apr 2, 2009 at 12:22 AM, Nathan Eisenberg nat...@atlasnetworks.us wrote: Here's what ends up in slbd.conf when I save my config: servicename:\     :poolname=poolname:\     :vip=x.x.x.x:\     :vip-port=80:\     :sitedown=x.x.x.x:\     :sitedown-port=80:\

Re: [pfSense Support] RE: Load Balancer Using TCP

2009-04-06 Thread Chris Buechler
On Sat, Apr 4, 2009 at 9:06 PM, Chris Buechler c...@pfsense.org wrote: There is another issue where TCP is always selected when you edit an existing pool, haven't fixed that yet but will. Just fixed, diff here. https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits

Re: [pfSense Support] MultiWan , not quite sure whats wrong

2009-04-07 Thread Chris Buechler
On Tue, Apr 7, 2009 at 8:34 AM, Chris Flugstad ch...@cascadelink.com wrote: So i have 2 WANS 100.100.100.4   DSL 216.127.123.4   Wireless back to Colo When the Wireless backhaul is disconnected or down, anything else on its subnet is not accessible over the other WAN.  It's as if it only

Re: [pfSense Support] Possible Outbound NAT Bug in 1.2.3 Snapshot?

2009-04-08 Thread Chris Buechler
On Wed, Apr 8, 2009 at 11:12 PM, Dimitri Rodis dimit...@integritasystems.com wrote: Currently running: 1.2.3-RC1 built on Wed Apr 1 16:59:10 EDT 2009 In addition to a fiber connection at this particular location, there is also a second connection brought in via a cable modem. The fiber

Re: [pfSense Support] CARP Bug in 1.2.3

2009-04-09 Thread Chris Buechler
On Thu, Apr 9, 2009 at 7:00 PM, Dimitri Rodis dimit...@integritasystems.com wrote: Good deal. I'll go to a later snapshot then. Are upgrades between snapshots on embedded working at the moment, or should I just reflash? Yeah you got hit with the xmlparse.inc issue that was in snapshots for a

Re: [pfSense Support] upgrading a certain snapshot

2009-04-10 Thread Chris Buechler
On Fri, Apr 10, 2009 at 2:47 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: We are trying to do a test upgrade using the snapshot, pfSense-1.2.3-20090407-1035.img.gz.  It took over 1 hour and 10 minutes and the upgrade still had not completed.  The current version of the device is 1.2-RELEASE

Re: [pfSense Support] feature request: VPNC

2009-04-11 Thread Chris Buechler
On Sat, Apr 11, 2009 at 6:53 AM, Mikel Jimenez Fernandez mi...@irontec.com wrote: Hello I found that is a port for freebsd of vpnc cisco client. http://www.freebsdsoftware.org/security/vpnc.html http://www.unix-ag.uni-kl.de/~massar/vpnc/ This is usefull when you want to connect your

Re: [pfSense Support] First Embedded System

2009-04-12 Thread Chris Buechler
On Sun, Apr 12, 2009 at 4:12 PM, Rainer Duffner rai...@ultra-secure.de wrote: That's a bit of a problem. I always re-flash to update. That won't be necessary for much longer. The next generation of embedded (based on nanobsd) will be available in 1.2.x and 2.0 releases sometime in the next

Re: [pfSense Support] Re: Can't get more than 15kpps.

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 6:13 AM, Lenny five2one.le...@gmail.com wrote: Hi guys, first of all, thanks for all the support! Anyway, unfortunately, after all the hell I've been through with this, our CEO is not interested in buying a new server:( heh.. How about sorry, but there is no other

Re: [pfSense Support] Dell PRO/1000VT Quad port NIC

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 11:35 AM, Mikel Jimenez Fernandez mi...@irontec.com wrote: Hello TIm I have not good experiences good igb driver... My experience was with http://www.intel.com/Products/Server/Adapters/Gb-ET-Dual-Port/Gb-ET-Dual-Port-overview.htm that uses 82576. IMHO better choose

Re: [pfSense Support] upgrading a certain snapshot

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 12:16 PM, Atkins, Dwane P atki...@uthscsa.edu wrote: I am guessing I can do this with a firmware upgrade?  I am not going on about 10 minutes.  Can someone please give me an idea of how long this upgrade should take? Depends on the specifics of your hardware,

Re: [pfSense Support] RE: [SPAM] Re: [pfSense Support] website browsing

2009-04-13 Thread Chris Buechler
On Mon, Apr 13, 2009 at 1:28 PM, Gary Buckmaster g...@centipedenetworks.com wrote: This is not the way to do this as the configuration will not survive reboots.  You can set the MTU on the interface configuration page for your WAN interface in the webGUI.  I would encourage you to check that

Re: [pfSense Support] RE: [SPAM] [pfSense Support] RE: [SPAM] RE: [pfSense Support] RE: [SPAM] RE: [pfSense Support] RE: [SPAM] Re: [pfSense Support] RE: [SPAM] Re: [pfSense Support] website browsin

2009-04-16 Thread Chris Buechler
On Thu, Apr 16, 2009 at 7:50 AM, Juan Rivera jriv...@americancableco.com wrote: hey this is getting worse we can't even get to the home page now we have to hit refresh over and over so we can get to the home page its running really slow I think just like dial up lol well I don't know what else

Re: [pfSense Support] Reboot on virtual IP

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 12:42 AM, Tim Dressel tjdres...@gmail.com wrote: Hi folks, We've been playing around at work with binding multiple IP's to the WAN interface so that we can port forward the same ports from different IP's to different services on the LAN side. Has anyone ever seen

Re: [pfSense Support] Firewall rules keep failing

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 4:15 AM, Graeme Evans graeme.ev...@kcssolutions.co.uk wrote: Situation: I have a simple PFSense setup with a single PFsense 1.2.2 computer, 1 WAN interface, and 2 Local interfaces - one named LAN (10.0.0.0/24), and the other is Workshop (10.0.1.0/24).  We have

Re: [pfSense Support] Firewall rules keep failing

2009-04-17 Thread Chris Buechler
On Fri, Apr 17, 2009 at 4:15 AM, Graeme Evans graeme.ev...@kcssolutions.co.uk wrote: PS: anyone know why the registration system on the pfsense forum won’t send activation emails – so I can’t register? Oh, and I looked for your email address on the forum and it isn't there. If you let me know

Re: [pfSense Support] Reboot on virtual IP

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 1:07 PM, Tim Dressel tjdres...@gmail.com wrote: I had zero luck with this in the last few days. Here are some more details: Internet -- PFSense -- procurve managed switch I have tried three different computers, an old P3 based IBM desktop with 512MB on a flash disk

Re: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 2:17 PM, Dimitri Rodis dimit...@integritasystems.com wrote: Attention Firebox X500/700/1000 Users using pfSense: Glad to hear that looks like it fixes it. There's at least one thread on the forum reporting this issue as well, might want to post to those threads too to

Re: [pfSense Support] Reboot on virtual IP

2009-04-18 Thread Chris Buechler
On Sat, Apr 18, 2009 at 2:33 PM, Tim Dressel tjdres...@gmail.com wrote: There is definitely an upstream router, and I have physical access to it but not console. I can power it off and on again, but it tends to make the service provider unhappy. I do have a good working relationship with the

Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Chris Buechler
On Tue, Apr 21, 2009 at 1:27 PM, Ryan L. Rodrigue radiote...@aaremail.com wrote: First.  Thanks for making the best rouster software in the world. Second.   I'v searched, but i cant quite figure it out.  I would like to use captive portal.  What I want is to have certain users based on windows

Re: [pfSense Support] Can captive portal authenticate based on windows login

2009-04-21 Thread Chris Buechler
On Tue, Apr 21, 2009 at 3:46 PM, Dimitri Rodis dimit...@integritasystems.com wrote: Microsoft Internet Security and Acceleration Server (ISA Server), and you need to have AD. I've used it, but only in this particular case. I do not know of anything in the open source world that works reliably

[pfSense Support] 1.2.3-RC1 released!

2009-04-22 Thread Chris Buechler
Info here: http://blog.pfsense.org/?p=428 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available - https://portal.pfsense.org

Re: [pfSense Support] bridging 2 networks with pfsense+openvpn

2009-04-22 Thread Chris Buechler
You don't *have* to have two subnets, you can bridge OpenVPN, but it's a bit convoluted, not documented well (yet), and generally I don't recommend it. You rarely want broadcast traffic traversing a VPN. On Wed, Apr 22, 2009 at 6:22 PM, Brian Josefsen josef...@sjovedyr.dk wrote: Hi I have 2

Re: [pfSense Support] Attention Firebox X Series Users - Testing Needed

2009-04-24 Thread Chris Buechler
On Fri, Apr 24, 2009 at 10:32 AM, Andrew Cotter andrew.cot...@somersetcapital.com wrote: Is there an update path from 1.2.2 to 1.2.3-RC1 embedded? Not a guaranteed reliable one. You can grab an embedded update file off the snapshot server but it may blow up. That'll be resolved with the new

Re: [pfSense Support] PPTP Hangs at Verifying Username and Password

2009-05-01 Thread Chris Buechler
On Fri, May 1, 2009 at 5:16 PM, Marty Nelson mnel...@transdyn.com wrote: I'm sitting behind another pfSense box version 1.2.2 If you have the PPTP server enabled, you need to either: 1) disable it 2)

Re: [pfSense Support] draft 802.11n and pfsense

2009-05-05 Thread Chris Buechler
On Tue, May 5, 2009 at 2:22 PM, Markus Golser elmar...@googlemail.com wrote: Hi I'm wondering if there is a draft 802.11n mini pciE card that works nice on pfsense 1.2.2 http://doc.pfsense.org/index.php/Is_802.11n_wireless_supported

Re: [pfSense Support] gre tunnel support

2009-05-07 Thread Chris Buechler
On Thu, May 7, 2009 at 5:21 AM, Mikel Jimenez mi...@irontec.com wrote: Hi Is possible to make a GRE tunel between two Pfsenses without using IPsec? Not with nor without, until 2.0. - To unsubscribe, e-mail:

Re: [pfSense Support] network interface mismatch

2009-05-11 Thread Chris Buechler
On Mon, May 11, 2009 at 10:19 AM, Pete Boyd petes-li...@thegoldenear.org wrote: Is there anything that can be done instead of replacing one of the 3Com cards? Sounds like a driver issue of some sort, trying 1.2.3 which has a newer FreeBSD base may make it work.

Re: [pfSense Support] Problem with pftpx - device busy

2009-05-11 Thread Chris Buechler
On Tue, Apr 21, 2009 at 7:43 AM, Peter Allgeyer allge...@web.de wrote: Hi, I just encountered a problem with pftpx. We have a FTP-Server in the DMZ-Zone. Entering ftp://ftp.server.ip from inside in the browser (for example, command line ftp is the same) shows no listing. Reloading the

Re: [pfSense Support] RE: T1 Saturating - Windows update kills the connection... ??

2009-05-13 Thread Chris Buechler
On Wed, May 13, 2009 at 2:47 AM, Chuck Mariotti cmario...@xunity.com wrote: To clarify further... In this situation, we are downgrading to a T1 (1.5Mbit/1.5Mbit) connection from a new service provider. The current connection is 3Mbit/3Mbit, works, but is insanely expensive (way more than

Re: [pfSense Support] bsnmpd eating cpu

2009-05-16 Thread Chris Buechler
On Fri, May 15, 2009 at 9:53 AM, Jure Pečar pega...@nerv.eu.org wrote: On Mon, 9 Feb 2009 13:41:30 +0100 Jure Pečar pega...@nerv.eu.org wrote: On Mon, 9 Feb 2009 10:37:27 +0100 Jure Pečar pega...@nerv.eu.org wrote: Hello, On 1.2-release running on two machines in carp failover mode,

Re: [pfSense Support] pfSense 1.2-Release - 1.2.3-RC1 upgrade, FTP problem

2009-05-18 Thread Chris Buechler
On Mon, May 18, 2009 at 6:01 AM, Android Andrew[:] andr...@oberon.pfi.lt wrote: Sorry for previous letter with bad subject.. Hello all! We have faced the following problem: after the upgrade of pfSense from 1.2-Release to 1.2.3-RC1, the access from the internal LAN1 network to FTP-server,

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-19 Thread Chris Buechler
On Tue, May 19, 2009 at 10:56 AM, Jean Carlos Coelho jean.lis...@gmail.com wrote: Hi all.. a question..   It is possible to install postfix in pfsense 1.2.2 only for mail relay ? Not easily, I've tried before, there are a ton of libraries and other misc. things not included in pfSense that

Re: [pfSense Support] Pfsense + Postfix (Relay)

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 5:02 AM, Paul Mansfield it-admin-pfse...@taptu.com wrote: has anyone considered a transparent redirection of SMTP to a specific SMTP relay, so that (e.g.) captive portal clients on wifi hotspot can't send email without some level of control. You can do that now with a

Re: [pfSense Support] wrong boot device after generic install

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 8:54 PM, David Burgess apt@gmail.com wrote: Hi all, I'm new to pfsense and a real novice with FreeBSD, so go easy on me ;) I used the live CD of pfsense 1.2.3-RC1 to install to a hard drive for use in a soekris net5501. When I boot while attached to the serial

Re: [pfSense Support] Which pfSense version should I install?

2009-05-20 Thread Chris Buechler
On Wed, May 20, 2009 at 9:45 PM, Jonathan Wanak jlwa...@yahoo.com wrote: Hi everyone, I'm about to update a remote pfSense installation I last worked on back in version 1.0.2.  I'm using a PII desktop with 128MB RAM and 3 NICs.  The box runs 2 LANs (public and private), utilizes Captive

Re: [pfSense Support] openssh flaw

2009-05-21 Thread Chris Buechler
On Thu, May 21, 2009 at 3:37 PM, David Burgess apt@gmail.com wrote: http://linux.slashdot.org/article.pl?sid=09/05/21/1824220from=rss What versions run in pfsense? Is this something we should be concerned about? This is 6+ month old news, and it's lame, not sure why it's getting so much

Re: [pfSense Support] dyndns on multiWAN

2009-05-25 Thread Chris Buechler
On Tue, May 26, 2009 at 12:29 AM, David Burgess apt@gmail.com wrote: Hi, I see the question in the archives, but no answer. What would be the correct way to set up dynamic DNS on a multiwan setup? You can't until 2.0. Only WAN is supported.

Re: [pfSense Support] arm arch?

2009-05-28 Thread Chris Buechler
On Thu, May 28, 2009 at 1:40 PM, Tim Nelson tnel...@rockbochs.com wrote: In regards to alternate arch's, wouldn't something like ARM or MIPS provider better PPS rates than x86(_64)? No difference due to the architecture. There are some higher end MIPS platforms that are equivalent to big $

Re: [pfSense Support] Snort running and update problem

2009-05-30 Thread Chris Buechler
On Sat, May 30, 2009 at 7:30 AM, ozan ucar m...@ozanucar.com wrote: Hello All, I have pfsense 1.2.2 and install snort.Snort success installation but dont update. Oinkmaster code have, i go to snort update page an error Snort success installation but dont update. Snort changed around their

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-05-31 Thread Chris Buechler
On Sun, May 31, 2009 at 7:03 AM, Tebano epaminonda l_epa_m_ino...@hotmail.com wrote: Hi all. I've read that complete multiwan support will be available only with 2.0 version of pfsense, but I'd like to know if You've some suggestion for doing something similar, also using many pfsense instead

Re: [pfSense Support] Can I install packages if my Pfsense is offline

2009-06-01 Thread Chris Buechler
On Mon, Jun 1, 2009 at 10:24 PM, Rakthum_NetworkTelecom_IP#1 rakthu...@advanceagro.com wrote: Hello all My Pfsense is offline but I want install some packages .How can I do? You can't. It has to download the package list and the packages themselves.

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-01 Thread Chris Buechler
On Mon, Jun 1, 2009 at 3:59 AM, Tebano epaminonda l_epa_m_ino...@hotmail.com wrote: Sorry, Guys. I where discussing of limitation reported into the features of: Inbound Load Balancing What exactly are you referring to? - To

Re: [pfSense Support] Does it matter which interface I specify for static routes?

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 5:54 AM, Steve Harman steve.har...@envisional.com wrote: Hi! We have four internal NICs on our pfSense box; “LAN” , “LAN2”, “LAN3” and “LAN4”. I need to setup a static route for a remotely hosted network at our parent company’s office so any traffic destined for

Re: [pfSense Support] Does it matter which interface I specify for static routes?

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 4:24 PM, Evgeny Yurchenko evgeny.yurche...@frontline.ca wrote: May I ask why pfSense web-interface has this option? It needs to know for NAT rule generation and other purposes. It's a hold over from m0n0wall, it could figure it out without specifying.

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 5:50 PM, Joseph Wagner lawn.dart.de...@gmail.com wrote: Has anyone been able to get pfsense to run properly on a Soekris net5501 embedded pc? Lots of people. I've installed the embedded image into my board and everything work fine except I can't get any traffic to  

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 6:01 PM, Victor Padro vpa...@gmail.com wrote: Sometimes you have to uncheck the Block private networks and the Block bogon networks boxes on the WAN interface page, have you alredy done that? You never have to uncheck that for access out to the Internet. Those only

Re: [pfSense Support] running pfsense on soekris net5501

2009-06-02 Thread Chris Buechler
On Tue, Jun 2, 2009 at 7:02 PM, Tim Nelson tnel...@rockbochs.com wrote: Quickly looking at the previous posts, I don't see where you've specified what type of connection you're setting your WAN to. Is it PPPoE? Static? DHCP? Etc? And also, is it on a private subnet? Same subnet as your

Re: [pfSense Support] keep alive

2009-06-03 Thread Chris Buechler
On Wed, Jun 3, 2009 at 12:00 PM, Paul Cockings p...@cytringan.co.uk wrote: Hello list, I have an annoyance that is driving me bonkers.  I have a Windows XP client, a pfsense 1.2.2 configured as a transparent firewall, development webserver (FreeBSD 7.2) When I using SSH (Putty) or MySQL

Re: [pfSense Support] Does it matter which interface I specify forstatic routes?

2009-06-03 Thread Chris Buechler
On Wed, Jun 3, 2009 at 9:29 AM, Evgeny Yurchenko evgeny.yurche...@frontline.ca wrote: from my experience failover takes has higher priority than static route as it is implemented by means of pf rules. Yes, that is true. Static routes direct traffic initiated by the firewall to the

Re: [pfSense Support] Feature Requests

2009-06-05 Thread Chris Buechler
On Fri, Jun 5, 2009 at 4:33 PM, Curtis Maurand cmaur...@xyonet.com wrote: Where can we make feature requests? http://redmine.pfsense.org with many still at http://cvstrac.pfsense.org as we haven't converted everything over yet. I also can't seem to find any decent documentation on the

Re: [pfSense Support] Recommended pfSense Hardware ( UK ~£100) ?

2009-06-07 Thread Chris Buechler
On Sun, Jun 7, 2009 at 2:00 AM, Volker Kuhlmannhid...@paradise.net.nz wrote: On Tue 02 Jun 2009 02:35:55 NZST +1200, David Burgess wrote: Have a look at these. http://www.soekris.com/lan16x1.htm The 2-port card is low profile Yes, sure. But how do you connect one of those to an ALIX board?

Re: [pfSense Support] LAN Drivers RTL8111D on INTEL

2009-06-08 Thread Chris Buechler
On Mon, Jun 8, 2009 at 8:34 PM, Federico Castro A.fcastro1...@racsa.co.cr wrote: Hi everyone. I´m trying to setup an INTEL DG41TY board with 3 LAN cards.  One integrated RTL8111D and two D-Link 520 TX PCI. The D-Links are setup without a problem but the Realtek doesn´t come up when I boot

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-10 Thread Chris Buechler
On Wed, Jun 10, 2009 at 10:03 AM, Tebano epaminondal_epa_m_ino...@hotmail.com wrote: I've 2 isp with 2 different IP and routers. So I've configured 2 pfsense in load balance and with carp between them (internal and external, so I always has a single IP to manage with routes and nats). All

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-11 Thread Chris Buechler
On Thu, Jun 11, 2009 at 2:34 AM, Webmaster Megastarwebmas...@megastar.fr wrote: There is a bug when you want to setup multiwan + load balancing + carp. The development team is aware of this. Ermal committed a kernel patch to pf that should resolve this. It's only in 8 builds at the moment, it

Re: [pfSense Support] Multiwan suggestions before v. 2.0 ...

2009-06-12 Thread Chris Buechler
2009/6/11 Webmaster Megastar webmas...@megastar.fr: Can you give us an idea of when it will be available in snapshots released to public ? Anything from 20090612 and newer should work (there aren't any yet, they'll be there eventually). Please test and report back.

Re: [pfSense Support] blocking RFC1918 and bogons on 2nd WAN

2009-06-12 Thread Chris Buechler
On Fri, Jun 12, 2009 at 9:10 AM, Paul Mansfieldit-admin-pfse...@taptu.com wrote: suppose we have two WAN ports and have turned on the automatic RFC1918 and bogon blocking; you can see the grey-ed out rules on WAN1 interface. what's the best way to also do this on WAN2? in particular, how to

Re: [pfSense Support] Inbound load balancer performance under heavy load.

2009-06-12 Thread Chris Buechler
On Fri, Jun 12, 2009 at 5:29 AM, Jose Hernandezj...@vidzone.tv wrote: Hi, Yesterday we had a service launch, and pfSense inbound load balancer let me down big time… We have been using pfSense 1.2-release version installed on Dell PowerEdge R200 and CARP for redundancy for around a year now,

Re: [pfSense Support] Outbound mail multi-wan

2009-06-13 Thread Chris Buechler
On Sat, Jun 13, 2009 at 3:07 PM, JJBonephat...@earthlink.net wrote: Hello, pfsense 1.22 we have a mail server: mail.domain.com We have two wan links WAN_ATT (T1) and WAN (covad DSL) reverse DNS is configured for the ATT link for mail.domain.com and for the covad link as

Re: [pfSense Support] Outbound mail multi-wan

2009-06-16 Thread Chris Buechler
On Tue, Jun 16, 2009 at 1:37 PM, JJBonephat...@earthlink.net wrote: Yes, setup your rules on the interface with the mail server accordingly. I don't know how to set up pfsense to bind the mail server to the ATT network interface instead of the Covad, can someone provide me with details of how

Re: [pfSense Support] forum vs mailing list

2009-06-17 Thread Chris Buechler
On Wed, Jun 17, 2009 at 1:38 PM, JJBonephat...@earthlink.net wrote: Hello, I didn't realize there is also a pfsense forum and that they are not connected. Which is the best place to post technical questions about configuration? Which ever you prefer. Some people like the forum format better,

Re: [pfSense Support] Outbound mail multi-wan

2009-06-17 Thread Chris Buechler
On Wed, Jun 17, 2009 at 2:47 PM, JJBonephat...@earthlink.net wrote: We've tried this 10 different ways, so far it has not worked. Current Config is two pfsense 1.22 firewalls with CARP two WAN connections (not load balanced or failover) (covad att), with a DMZ interface where our mail and

Re: [pfSense Support] Nfsen - Netflow: 2 new possibly packages for pfsense?

2009-06-19 Thread Chris Buechler
On Fri, Jun 19, 2009 at 1:00 PM, Tebano epaminondal_epa_m_ino...@hotmail.com wrote: Hi all. I'm exploring features embedded into pfsense, and I was looking to interesting features as RRD graphics of system activityes. I've read on RRD also improvements introduced from the use of packages:

Re: [pfSense Support] Interface stops routing to WAN

2009-06-22 Thread Chris Buechler
On Mon, Jun 22, 2009 at 1:42 PM, Joe Laffeyj...@laffey.tv wrote: While I forgot to look when it happened, this was one of my thoughts, as well. But then I thought to myself, wouldn't this cause connections from the LAN to the WAN to fail as well? Or is the state table subdivided equally

Re: [pfSense Support] Dynamic DNS won't update

2009-06-22 Thread Chris Buechler
On Mon, Jun 22, 2009 at 5:33 PM, Bjoern Hellermailingli...@hellercom.de wrote: Hello, Im running pfSense 1.2.3 RC1 on standard PC hardware, and everything runs perfect exept the DynDNS updater. The new IP isnt sent to dyndns.org... If I manually click on the Save button in the Dynamic DNS

Re: [pfSense Support] Appliance support

2009-06-23 Thread Chris Buechler
On Tue, Jun 23, 2009 at 9:38 AM, Vick Kheravi...@khera.org wrote: Last time I set up an embedded (1.2.2 on my home router) I booted the device, reset the DHCP lease on my desktop and connected to 192.168.1.1 and configured it by reloading the config file. No serial port required, even though

Re: [pfSense Support] vpn pass thru problem

2009-06-24 Thread Chris Buechler
On Thu, Jun 25, 2009 at 1:39 AM, Guruprasad-Baysoftg...@baysoft.in wrote: i had pfsense 1.2.2 and vpn not configured. I was connecting outside vpn servers from my laptop thru vpn client and no issues. After upgrading pfsense to 1.2.3RC1, i am unable to connect to outside vpn servers from my

Re: [pfSense Support] Cvstrac-Bug 1932 patch

2009-06-25 Thread Chris Buechler
On Wed, Jun 24, 2009 at 8:22 AM, Aarno Aukiaaarnoau...@gmail.com wrote: Hi, Attached a patch against 1.2.3-rc1 fixing http://cvstrac.pfsense.com/tktview?tn=1932, which was opened by a co-worker of mine while I was on vacation. Let me know if de patch fails against cvs/git. I'll have to

Re: [pfSense Support] vpn pass thru problem

2009-06-25 Thread Chris Buechler
On Thu, Jun 25, 2009 at 1:59 AM, Guruprasad-Baysoftg...@baysoft.in wrote: I am using safenet softremote LT client software. My customer sent the security policy editor config file. So i just imported that in my safenet vpn client software and using. Hence i donot know what is the remote vpn

Re: [pfSense Support] PFSense 1.2.3RC1 / Problems with IPSEC and AES256

2009-06-25 Thread Chris Buechler
On Tue, May 26, 2009 at 5:42 AM, Benjamin Frommebenjamin.fro...@login-online.de wrote: Hi List, we have several tunnels between some pfsense 1.2.2 boxes. For phase 2 we have configured AES256 as the only encryption algorithm and everything works fine. Now we upgrade one of the boxes to

Re: [pfSense Support] Multiple WANs on a Single Bridge

2009-06-25 Thread Chris Buechler
On Thu, Jun 25, 2009 at 3:43 PM, Joseph Hardemanjharde...@colocube.com wrote: Hi Everyone, I have been trying to figure out how to setup multiple wan networks on a single bridge. For instance: 111.111.111.111/25  - em0/bridge0/opt1 - internal servers 222.222.222.222/25  - em0/bridge0/opt1 -

Re: [pfSense Support] PFSense 1.2.3RC1 / Problems with IPSEC and AES256

2009-06-29 Thread Chris Buechler
On Thu, Jun 25, 2009 at 6:27 AM, Ho Sy Tanhosy...@gmail.com wrote: I run pfSense-1.2.3-RC1 (FreeBSD 7.1), IPSec with IKE P2 AES 256, it work fine. That's with the older ipsec-tools version. The latest one wants different syntax.

Re: [pfSense Support] Traffic Shapping : High priority on particular port

2009-06-29 Thread Chris Buechler
On Mon, Jun 29, 2009 at 1:58 PM, Bastien DARMONbdar...@horus-df.com wrote: Hello, Is there a way, in pfsense, to give the highest priority over the rest of the traffic to an application running on a particular port? You can shape this just like anything else, with the caveat that it falls

Re: [pfSense Support] Statically-defined DHCP clients with dynamic addressing not entered into DNS

2009-06-30 Thread Chris Buechler
On Mon, Jun 29, 2009 at 3:57 PM, Ian Levesquei...@crystal.harvard.edu wrote: On Jun 26, 2009, at 2:00 PM, Ian Levesque wrote: We're running DHCP and DNS on a pair of CARPed pfSense 1.2.1 boxen. Other than the fact that they don't sync DCHP entries, it's been working OK for us. However, we've

Re: [pfSense Support] NAT+IPsec

2009-07-02 Thread Chris Buechler
On Thu, Jul 2, 2009 at 10:36 AM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: Hello. setup: my LAN---192.168.8.0/24 pfSense 1.1.1.1/242.2.2.2/24 FW 198.x.x.0/24---remote LAN I am asked to create Ipsec tunnel between 'my LAN' and 'remote LAN' but these remote guys say that

[pfSense Support] Re: Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-05 Thread Chris Buechler
On Sun, Jul 5, 2009 at 4:23 PM, Tim A.pfse...@lists.goldenpath.org wrote: Attached a patch against 1.2.3-rc2 adding support for auto configuring interfaces. That's definitely a nice feature, though only suitable for addition to 2.0, so we'll need a patch for 2.0. The only thing from your

Re: [pfSense Support] Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-06 Thread Chris Buechler
On Mon, Jul 6, 2009 at 8:47 AM, Ermal Luçiermal.l...@gmail.com wrote: To me this is a hack and not a feature. There is a better way to do this things than kludge things here and there in the code. The right fix was proposed once and not everybody liked the POLA breaking. I don't recall that

Re: [pfSense Support] Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-07 Thread Chris Buechler
On Tue, Jul 7, 2009 at 4:26 AM, Ermal Luçiermal.l...@gmail.com wrote: On Mon, Jul 6, 2009 at 8:39 PM, Chris Buechlerc...@pfsense.org wrote: On Mon, Jul 6, 2009 at 8:47 AM, Ermal Luçiermal.l...@gmail.com wrote: To me this is a hack and not a feature. There is a better way to do this things

Re: [pfSense Support] PPTP erro 619

2009-07-11 Thread Chris Buechler
On Fri, Jul 10, 2009 at 8:13 PM, Chris Flugstadch...@cascadelink.com wrote: False alarm Still broken :( Reset the state table on the firewall the client is behind and try again. - To unsubscribe, e-mail:

Re: [pfSense Support] 1.2.3RC1 embedded: wireless communication with Nokia N97 stops after a few KB but the connection desn't drop

2009-07-12 Thread Chris Buechler
On Sun, Jul 12, 2009 at 1:21 PM, Angelonglrossi...@gmail.com wrote: Hi, I have a weird wireless connection issue with my new Nokia N97, hope someone can help me. You won't find a solution here, it's a wireless driver issue of some sort and that would have to get fixed upstream in FreeBSD.

[pfSense Support] Fwd: [FreeBSD-Announce] Announcing EuroBSCon 2009

2009-07-13 Thread Chris Buechler
I will be presenting on pfSense at EuroBSDCon. info here: http://blog.pfsense.org/?p=481 and below -- Forwarded message -- From: Robert Watson rwat...@freebsd.org Date: Mon, Jul 13, 2009 at 9:18 AM Subject: [FreeBSD-Announce] Announcing EuroBSCon 2009 To: annou...@freebsd.org

Re: [pfSense Support] IGMP packet out of WAN

2009-07-13 Thread Chris Buechler
On Mon, Jul 13, 2009 at 9:43 AM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: Hi All! should the rule   pass out quick on bge1 all flags S/SA keep state label let out anything from firewall host itself allow IGMP packets out of WAN interface? Packets are generated by igmpproxy

Re: [pfSense Support] Re: Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-14 Thread Chris Buechler
On Tue, Jul 14, 2009 at 6:08 PM, Tim A.pfse...@lists.goldenpath.org wrote: I tried to push this to the repo but it keeps saying not allowed. Are you guys only using that internally? You can only push to your own clones unless you're an authorized committer, we don't let just anybody push

[pfSense Support] Next generation of pfSense embedded now available

2009-07-14 Thread Chris Buechler
For those who don't follow the blog: http://blog.pfsense.org/?p=472 - To unsubscribe, e-mail: support-unsubscr...@pfsense.com For additional commands, e-mail: support-h...@pfsense.com Commercial support available -

Re: [pfSense Support] Next generation of pfSense embedded now available

2009-07-14 Thread Chris Buechler
On Tue, Jul 14, 2009 at 9:51 PM, Nenhum_de_Nosmatheus...@gmail.com wrote: great news. just one question though. I use tinybsd for this embedded stuff, is there any way to shrink this image (any way I can do myself, not the project do for me) to fit 128MB cf I already have ? Not easily.

Re: [pfSense Support] Filtering streaming - peer to peer - instant messaging

2009-07-15 Thread Chris Buechler
On Wed, Jul 15, 2009 at 8:48 AM, bsdb...@todoo.biz wrote: Hello, I am about to answer a public tender and am looking for a reliable open-source filtering solution. I need to filter layer 3 and 4 of TCP/IP stack (TCP and Application layer) specially for stream such as Peer to Peer - IM -

Re: [pfSense Support] Re: Patch and ISO: New Feature -- Auto Configuring Interfaces

2009-07-15 Thread Chris Buechler
On Wed, Jul 15, 2009 at 3:39 AM, Ermal Luçiermal.l...@gmail.com wrote: Please pretty please do not make distinctions on lan/wan/optif i have invested too much time to clean this! I don't see anything that treats LAN/WAN/OPT improperly. When auto-assigning interfaces, you don't have a choice but

Re: [pfSense Support] Web Interface Pages - Save Button

2009-07-15 Thread Chris Buechler
On Wed, Jul 15, 2009 at 11:15 PM, Tim Nelsontnel...@fudnet.net wrote: Hello fellow pfSensers! I've been quietly annoyed with a minor 'issue' in pfSense for some time now and finally thought I'd bring it to light to see if it's just me or if anyone else has the same problem. I love my

Re: [pfSense Support] Web Interface Pages - Save Button

2009-07-15 Thread Chris Buechler
On Wed, Jul 15, 2009 at 11:25 PM, Tim Nelsontnel...@fudnet.net wrote: Chris Buechler wrote: On Wed, Jul 15, 2009 at 11:15 PM, Tim Nelsontnel...@fudnet.net wrote: Hello fellow pfSensers! I've been quietly annoyed with a minor 'issue' in pfSense for some time now and finally thought I'd bring

Re: [pfSense Support] 1.2.3RC1 embedded: wireless communication with Nokia N97 stops after a few KB but the connection desn't drop

2009-07-16 Thread Chris Buechler
On Thu, Jul 16, 2009 at 4:26 AM, Paul Mit-admin-pfse...@taptu.com wrote: Angelo wrote: I have a weird wireless connection issue with my new Nokia N97, hope ... Yesterday I bought a Nokia N97 and as soon as I came back home I started playing with it. I joined my wireless network and typed

Re: [pfSense Support] IGMP packet out of WAN

2009-07-18 Thread Chris Buechler
On Mon, Jul 13, 2009 at 6:59 PM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: No, I can not see in logs. But on LAN I have 18:55:24.602839 IP 192.168.1.2 224.0.0.22: igmp v2 report 239.142.1.1 It does not go out of WAN. And when I disable packet filtering it does go out of WAN.

Re: [pfSense Support] Hardware Configuration

2009-07-20 Thread Chris Buechler
On Mon, Jul 20, 2009 at 4:47 AM, Caroline Stekkecaroline.ste...@univ-rennes1.fr wrote: Hi ! I have installed PfSense on two servers DELL. I have on this servers a network card of 4 ports GBE. I have a problem with this card, because FreeBSD or PfSense, I don't know where is the problem can't

Re: [pfSense Support] Hardware Configuration

2009-07-20 Thread Chris Buechler
On Mon, Jul 20, 2009 at 5:09 AM, Caroline Stekkecaroline.ste...@univ-rennes1.fr wrote: Thank you for you attention But I have installed this version : 1.2.3-RC1  with FreeBSD 7.1 So for you my newer card, just can work with FreeBSD 7.2 ? I don't know, but it's possible.

Re: [pfSense Support] Hardware Configuration

2009-07-20 Thread Chris Buechler
On Mon, Jul 20, 2009 at 5:17 AM, Caroline Stekkecaroline.ste...@univ-rennes1.fr wrote: Ok, And did you know what is the procedure to compile the driver bge myself. The bge driver is there already. If the NICs aren't detected, they aren't supported by the bge driver in that particular FreeBSD

Re: [pfSense Support] Re: odd sip firewall issue

2009-07-21 Thread Chris Buechler
On Tue, Jul 21, 2009 at 11:25 AM, R. Th. Bootsvand...@gmail.com wrote: Chris Buechler wrote: On Sun, Jul 19, 2009 at 5:44 PM, R. Th. Bootsvand...@gmail.com wrote: Hello All, I have an asterisk server which is hooked up to 3 providers. With all 3 of them I have no problems connecting to my

Re: [pfSense Support] IGMP packet out of WAN

2009-07-22 Thread Chris Buechler
On Wed, Jul 22, 2009 at 9:37 PM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: Suddenly I discovered pfSense-development distribution which has compiler (yes, I was that stupid thad had not paid attention that there wer such thing). Now I'd like to play with igmpproxy package. Where

Re: [pfSense Support] IGMP packet out of WAN

2009-07-23 Thread Chris Buechler
On Thu, Jul 23, 2009 at 11:29 AM, Chris Buechlerc...@pfsense.org wrote: On Thu, Jul 23, 2009 at 10:02 AM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: Thanks for quick report Chris. I am completely new to this stuff please bear with me. Trying to accoomplish 'Clone the tools repo at

Re: [pfSense Support] IGMP packet out of WAN

2009-07-23 Thread Chris Buechler
On Thu, Jul 23, 2009 at 12:32 PM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: Well.. I installed http://files.pfsense.org/mirror/downloads/pfSense-Developers-1.2.2.iso.g z and it gave me 7.0. My systems run 1.2-RELEASE as I have some issues with 1.2.2 So you've been testing the

Re: [pfSense Support] IGMP packet out of WAN

2009-07-23 Thread Chris Buechler
On Thu, Jul 23, 2009 at 12:49 PM, Evgeny Yurchenkoevgeny.yurche...@frontline.ca wrote: No, I've been testing igmpproxy on 1.2.2 and if it will work I'll have to build one FW on 1.2.2. Oh, that binary I put up a URL for was built on 7.1, you should be trying at least 1.2.3-RC1 for that. One

Re: [pfSense Support] Version Clarification and Routing Issue

2009-07-23 Thread Chris Buechler
On Thu, Jul 23, 2009 at 1:24 PM, bsd...@gmail.combsd...@gmail.com wrote: hi, first, i am a little confused at the versions of pfsense. currently i'm running pfsense 1.2.3-RC1 built back in April of 09. it's not clear to me where the 1.2.3 branch stands or what is the latest version of 1.2.3

<    4   5   6   7   8   9   10   11   12   13   >