• 401'd on assign interfaces after restore

    Locked
    15
    0 Votes
    15 Posts
    8k Views
    N

    Hello,

    @dotdash:

    I'm doing some more testing, but this seems to only happen when restoring a 1.2 config (with mis-matched interfaces) to 2.0AA.

    Oh, yes, I noticed that several times. Restoring 1.2 config to 2.0-AA triggers automatic config translation/upgrade(?) while booting but it sometimes forget something and I had to start again from the scratch, moving 2.0-AA around is okay though. Never mind, it's still -AA.

    cheers,

  • Oops built on Tue Dec 9 00:11:49

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    N

    Hello ermal,

    you quick! confirmed fix Tue Dec 9 03:19:14 EST 2008. thanks!  :)

    cheers,

  • CPU usage: Division by zero

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    N

    Hi,

    I have seen "Division by zero" several times but dunno what's the trigger is/was, and that is seen too intermittently so I really don't care but I'd rather say it's a software issue, indeed. How about to load up some new snaps and keep eyes on it for a bit?

    cheers,

  • CA installed and changed to HTTPS

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    D

    on a upgrade the certificate is not upgraded, the webui is accessible on the same port as before but only http. That confused me for a bit too.

  • PPTP Broken?

    Locked
    10
    0 Votes
    10 Posts
    8k Views
    E

    Try the latest build it actually should be solved with later snapshots.

  • Firewall rules in ipsec Vpn

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    O

    ok

    $ sysctl -a | grep enc
    kern.timecounter.tc.i8254.frequency: 1193182
    kern.timecounter.tc.ACPI-fast.frequency: 3579545
    kern.timecounter.tc.TSC.frequency: 997508645
    net.inet.ip.sendsourcequench: 0
    net.enc.out.ipsec_bpf_mask: 0000000000
    net.enc.out.ipsec_filter_mask: 0x00000002
    net.enc.in.ipsec_bpf_mask: 0000000000
    net.enc.in.ipsec_filter_mask: 0x00000001
    debug.dopersistence: 0
    dev.p4tcc.0.%desc: CPU Frequency Thermal Control

    $ sysctl -a | grep ipsec
    net.inet.ipsec.def_policy: 1
    net.inet.ipsec.esp_trans_deflev: 1
    net.inet.ipsec.esp_net_deflev: 1
    net.inet.ipsec.ah_trans_deflev: 1
    net.inet.ipsec.ah_net_deflev: 1
    net.inet.ipsec.ah_cleartos: 1
    net.inet.ipsec.ah_offsetmask: 0
    net.inet.ipsec.dfbit: 0
    net.inet.ipsec.ecn: 0
    net.inet.ipsec.debug: 0
    net.inet.ipsec.esp_randpad: -1
    net.inet.ipsec.crypto_support: 50331648
    net.inet6.ipsec6.def_policy: 1
    net.inet6.ipsec6.esp_trans_deflev: 1
    net.inet6.ipsec6.esp_net_deflev: 1
    net.inet6.ipsec6.ah_trans_deflev: 1
    net.inet6.ipsec6.ah_net_deflev: 1
    net.inet6.ipsec6.ecn: 0
    net.inet6.ipsec6.debug: 0
    net.inet6.ipsec6.esp_randpad: -1
    net.enc.out.ipsec_bpf_mask: 0000000000
    net.enc.out.ipsec_filter_mask: 0x00000002
    net.enc.in.ipsec_bpf_mask: 0000000000
    net.enc.in.ipsec_filter_mask: 0x00000001

  • Errror in gateway groups

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    D

    success, spaces are apparently evil

  • Solve–>ftp-proxy problem

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    A

    Dear ermal

    I upgrade pfsense version to Mon Dec 1 04:58:27 EST 2008.
        It's okay to use ftp

    Thanks ermal

  • PPPoE -> Clicking on disconnect removes the LAN IP (!)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    N

    Hi,

    It seems to be fixed in my environment with Sun Nov 30 21:11:20 EST 2008 build.

    @ArkAngel:

    Going to the console and refreshing the display shows the IP of the LAN is gone, while the one for PPPoE is still there. Setting the IP again allow me to enter back the Web Interface.

    That was ouch  ;D

    cheers,

  • 2.0 Quality graphs Broken? *Updated*

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Help to set up loadbalancing in 2.0 Alpha

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    Thanks for the info, I'll try this out.
    Better elaborations are welcome.

    Thanks

  • VLAN create error

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    E

    Fixed, thanks.

  • DHCP + PPPoe on the ONE WAN

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    @ermal:

    You can by assigning the same interface twice in pfSense.
    To allow this you have to modify interfaces_assign.php to show the plus sign even after all interfaces have been assigned.

    I try to modify
    interfaces_assign.php
    line 393

    and assign interface twice
    but there were other errors

  • Firewall problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    E

    Use the "Floating Rules" tab and just create a rule to block udp packets on port 67 incoming from not your lan ~~network to any.
    Do not specify the interface on the rule.

    That should get you up and running.~~

  • Reflective routing issues w/ 2.0

    Locked
    16
    0 Votes
    16 Posts
    11k Views
    D

    I just updated to the latest SNAP:

    2.0-ALPHA-ALPHA
    built on Tue Nov 25 14:59:09 EST 2008
    FreeBSD 7.1-PRERELEASE

    and the issue still exists.  As before tests one and two pass fine but then I get stopped dead at test three (SSH) and four (VNC test).

    Here's the logging output …..

    Nov 27 10:11:56     LAN     192.168.22.22:5900     192.168.1.20:18340     TCP

    The rule that triggered this action is:

    @3 block drop in log all label "Default deny rule"
    @30 anchor "spoofing" all
    @31 anchor "loopback" all
    @32 pass in on lo0 all flags S/SA keep state label "pass loopback"
    @33 pass out on lo0 all flags S/SA keep state label "pass loopback"
    @34 anchor "firewallout" all
    @35 pass out all flags S/SA keep state label "let out anything from firewall host itself"
    @36 anchor "anti-lockout" all
    @37 pass in quick on le0 from any to (le0:2) flags S/SA keep state label "anti-lockout rule"
    @38 anchor "packagelate" all
    @39 block drop in log quick proto tcp from sshlockout:0to any port = rsh-spx label "sshlockout"</sshlockout:0>

  • Traffic Shaping using Bridged Mode

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    F

    matt have you gotten your pfsense working properly now? and also can u use a broadband connection from a pc to connect to your internet?

  • Captive portal doesn't stick

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R

    I downloaded 1.2.1 RC2 tonight,,, I'll play with this until tomorrow, then I'll install the RC2 and give the same thing a try. The reason I went to 2 alpha was to get bsd 7 and support of my wireless card, but I understand RC2 is also 7, so I should be good to go.

    If anyone has any thoughts about where I can find logs relating to CP in 2 alpha before tomorrow morning please let me know and I'll post the log.

    Cheers,

    -tim

  • What is the correct way to setup a wireless access point on 2.0?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R

    I have same setup, on my wireless interface I set the type to static, then gave it a subnet different from the LAN (i.e. if LAN was 192.198.2.1/24, I set wireless to 10.10.10.1/24).

    Then I went to DHCP, setup scope to hand out in .50 to .100 (or whatever).

    Then I went to rules, created an everything rule identical to the one for LAN to WAN, and it just worked.

    Cheers,

    -tim

  • Ssh on embeded

    Locked
    12
    0 Votes
    12 Posts
    7k Views
    M

    @sullrich:

    Did you change the password in the user manager for the admin account?

    Yep, I can't use the auto upgrade facility as my CF card is to small. So I image the card, boot and then restore the config. Just to be sure I also opened the admin user in the user manager and re-entered the password for admin and saved it. The saved password works on the WebGUI just not SSH

  • Startup on 2.0AA

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D

    what sort of wan is this.

    The 127.0.0.2 dictates a down dynamic interface.

    The exiting 15 is from when I kill it when it reconfigures. This is normal.

    The touch filter_dirty is one I am still actively pursuing. It has to do with /tmp losing permissions.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.