• 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Alix Install on ide hd, why does it fail? (updated)

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    T
    I've currently given up on my ide connection, I have no idea as to why it stopped working… now it doesn't even identify the laptop drive in bios... I wonder if there was hardware besides the resistor missing on the board (I soldered on the ide connector & added a resistor to select master (as mentioned in the alix documentation), but that went really smoothly...other than the not working bit ;) )... Onto the current problem. I would love to use a cf to just boot from a notebook drive that's connected via usb, but I can't get the default freebsd boot-loader to see the drive and I haven't been able to try with grub, as it just fails to install grub on the cf while hooked up to a desktop. (if anyone could offer ideas as to how to get grub working, it would be appreciated) Not being able to get grub working, I decided to just mount the usb drive at boot, and run the more disk intensive stuff from it (squid definitely doable...would be possible to send all logging there?) But...of course... it still fails to find the drive (this early in the boot process)... Welcome to pfSense 1.2.2 on the 'pfSense' platGform... EMounting filesysOtems...M_LABEL: Label ufs/pfSense removed. mount: /dev/da0s1 : No such file or directory done. Creating symlinks......done. Launching PHP init system...umass0: <western 0="" digital="" external="" hdd,="" class="" 0,="" r1<br="">da0 at umass-sim0 bus 0 target 0 lun 0 da0: <wdc wd60="" 0ve-00hdt0="" 0000=""> Fixed Direct Access SCSI-0 device da0: 40.000MB/s transfers da0: 57231MB (117210240 512 byte sectors: 255H 63S/T 7296C) done.</wdc></western> Running mount /mnt works fine once its started up. Here's my fstab: Device        Mountpoint      FStype  Options         Dump    Pass# /dev/ad0s1a     /               ufs     rw,noatime      1       1 /dev/ad0s1b     none            swap    sw              0       0 /dev/da0s1      /mnt            ufs     rw              1       1 If I can't even get this working on bootup… what would be the easiest way to run mount /mnt later during the bootup process. Any thoughts/ideas/suggestions at this point would be greatly appreciated.
  • {BUG SUBMISSION} Change of NIC (KVM)

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    F
    Issue may have been related to KVM/VM, but solution would be by re-scanning for changes in interfaces. Seems somewhat OK in standard standalone box -J
  • Installing pfDNS Problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    I
    Assuming you've already tried another download in case it was just a bad ISO file?
  • WebGUI not available after clean install.

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • PLEASE help with installation on Proliant DL360 G3

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    E
    1.2-Release works perfectly at DL360/DL380.
  • Transparent Bridge Firewall with multiple VLANs

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Upgrade from pfsense 1.2 -rel to 1.2.2 rel particulary failed

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    Ok, just reinstalled system. not really way, but works…  ::)
  • Is pfsense my solution?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M
    By 5. I mean being able to assign URL/Port/Protocol policies to groups of users based on, as your suggestion was, RADIUS user groups. I'll look into the package combo and do some more reading. Thanks.
  • 2.0 alpha doesn't see my newly formated IDE HDD

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M
    N/M tried a different HDD, the first was bad
  • Missing RAM!

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    G
    OK - thanks. I'll try a manual firmware upload on Friday and also check out the BIOS. loader.conf contains: utoboot_delay="1" vm.kmem_size="435544320" vm.kmem_size_max="535544320" kern.ipc.nmbclusters="0"
  • PLZ HELP ME WITH THE INSTALLATION !!! HELP ME SOMEONE!!

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    Cry HavokC
    Once more with feeling… pfSense uses FreeBSD - FreeBSD is NOT Linux. Once more, again, with feeling… just because your hardware meets the minimal requirements doesn't mean it'll work.
  • No Internet on LAN

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    Cry HavokC
    I'd start with a fresh install - it sounds like you either have some broken hardware, or you changed settings you don't understand.
  • FreeBSD chroot

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Cry HavokC
    It might work, but: a) It isn't supported b) Running your gateway and firewall as a virtual host isn't a good choice for security (see the Virtualisation forum)
  • Pfsense box behind a pfsense box

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    M
    ** Quick update at the bottom ** Thanks for your reply mhab12.  I didn't intend make it more difficult.  Partly, my pfsense boxes are not the most robust machines and I've noticed that there are limits to what I can have running on one box at a time.  For instance I have had to limit what rules are running on snort using one box and compensate the snort on the other box, kind of splitting the load in a sense, so that one box covers certain rules and the other box the rest.  There are some rules in snort that cause my service to stop if I have too many selected.  I don't have the best boxes with the up to date components, but I wanted to make it still secure enough and not overwhelm one boxes resources. Thanks for the heads up on the reverse proxy, I may give that a shot since my web box is not that great either and it would be less for it to deal with if one of the pfsense boxes to could handle a little of the load.  I think what I was finding is too much on one machine slows things down, but sharing resposibilities between boxes will lower the load on the computer and also give me more security on my home network as a perk.  I hope I didn't sound psycho about having two pfsense for security, I'm just better at visualizing things and this made sense for troubleshooting and, for some reason, give me a quick way to get the internet back up if one box goes down. @mhab12: Couple of thoughts: 1 - You mention binding squid to WAN.  This will not do what you're thinking and cache the outbound data from a 'slow' web server.  Doing this will require something called reverse proxy.  The squid package in pfSense will do it, yes, but it requires additional configuration beyond the included GUI. 2 - It sounds to me like what you're explaining could be accomplished by just adding an extra NIC to the first pfSense box.  By creating an OPT interface (likely OPT1), you can effectively have two LANs, LAN and OPT1, one will be 1.1 and one 2.1  You can setup firewall rules to prevent/limit access between them, setup bridges, anything you need.  If you do not trust the firewall rules well enough and chose to have two boxes for that reason, that's another issue. ** Update for my setup ** Just letting everyone know that I now have 1.1 running snort with rules split between it and 1.2 network pfsense boxes.  This is the main reason I wanted to set things up in this way, because I don't have the newest boxes and only 512mb ram in each.  I guess if I had a nice firewall box then it would be unnecessary for my setup, but I'm using what I've got…  my ram usage on 1.1 is at 62% with snort and squid running, and my ram usage on 1.2 is 68% with snort running 2 main rules and 2 empty rules.  I may end up swapping rules on the machines and see if I can balance them a little better, but for now I have backdoor and netbios running with the largest rules and then the two empty ones local and experimental.  The rest of the rules are running on the 1.1 pfsense box, but since it has a faster processor I may end up squeezing more out of these rules if I swap the rules between the two boxes.  We'll see how things go. Just FYI.
  • WAN to DMZ totally dead

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    V
    It turns out that there was a configuration error upstream, so nothing was getting to the firewall from the outside at all. I'm sure there's some tuning to do, but I'm extremely happy with the job that pfSense is doing now. Van
  • Newbie - suggestion/recommendation for initial setup for Satellite (HX50)

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    M
    I would bind squid to any interface that is going to have users doing browsing.  I think for you that is all except WAN.  Make sure you've switched your GUI to run on HTTPS so there are no port conflicts on port 80. As for caching windows update, there is nothing special to do.  Just make sure you set the 'Maximum Object Size' to something like 262144 (256Mb) if you want to grab items like windows update.  I've noticed this helps a lot across the board with any updates, not just MS (think AOL, AIM, P2P programs).  That said, I was having some issues with the most recent version of Squid not serving anything from cache, but that's another issue.
  • Cannot find hdd after upgrade

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    A
    No I didn't actually because there was a time pressure and i had to put it again in production as soon as possible so didn't made more tests…but i will try again when i will have time ;) thank you
  • Vmware virtual and "connection interrupted" error bizzareness!! (help!)

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    P
    :( [SOLVED!] right i've fixed it! I moved the virtual onto another PC that had dual onboard nics. One a Marvell tech nic and the other an Nvidia Nic (see where I'm going here?). I disabled the Nvidia Nic in the bios and slapped a spare  3Com card I had lying around into a PCI slot and presto worked first time! Looks like the forcedeth driver doesn't play well will vmware on ubuntu 8.04.2, I'm kicking myself as I usually make sure the hardware is solid because I know how twitchy vmware is with network hardware…It worked fist time so I'll be switiching out the 3scom for 2x netgear at some point!!!!
  • Embedded vs full hard drive install

    Locked
    9
    0 Votes
    9 Posts
    12k Views
    J
    Read/Write throughput isn't the end-all-be-all of performance.  Access time is VERY important when working with tiny bits of data and on that front an SLC SSD (be it Compact Flash, DoM, 2.5" SATA) will destroy a normal disk.  I'd say you'll be fine as long as your device supports DMA (PIO4 is still 20MB/s but it comes with high CPU usage). To osopolis:  I'm not sure that a single core Pentium 4 will be able to deal with 400Mbit/s, though I'll admit that I've never tried to route that much traffic through anything but an actual hardware router (not to mention that that chip is going to run hot as hell, what is that, TDP of 120W?).  You'd probably be better off with something newer like a Intel E7400 or the Xeon equivalent.  Also, make sure you get Server network cards (or at least Intel Desktop cards) as cheap Realtek parts (or anything similar) aren't going to be able to keep up.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.