[pfSense] FRR restart prevention

2017-11-30 Thread Daniel
Hi there, is there anyway to prevent the whole restart of FRR when the config has changed? Problem is durin a restart the connectivity gets lost and when you do this a couple of time it could be that you network is flapping and maybe some providers user damping. Cheers Daniel __

[pfSense] FRR restart prevention

2017-11-30 Thread Daniel
Hi there, anyone know how to prevent FRR to restart every time when the config has chaned? Problem can be dampeing for example are network unreachability. Just as an Idea, use only somethink like that: vtysh -e "sh ip bgp sum" vtysh -e "clear ip bgp *" And so on. In this case you

Re: [pfSense] pfsense 2.3 -> 2.4 upgrade?

2017-11-30 Thread Steve Yates
It would help if someone updated the pfSense doc page to clarify that, then, since I asked that question on this list in July and got a different answer than yours. https://doc.pfsense.org/index.php/Upgrade_Guide#Packages -- Steve Yates ITS, Inc. -Original Message- From: List [mailto:l

[pfSense] pfSense can get to Internet but LAN cannot

2017-11-30 Thread Steve Yates
Short version: a PC on the LAN cannot ping the router's gateway, though the router can ping it and get to the Internet. Routing table looks OK, default firewall rule isn't blocking packets (rule to allow LAN to any is in place), and it's not a private IP address. Looking for suggestion

Re: [pfSense] pfSense can get to Internet but LAN cannot

2017-11-30 Thread Holger Bauer
Hi Steve, Any chance outbound nat got messed up, when setting up carp? Check the settings there and check diag>states if nat works. Holger Am 30.11.2017 10:43 nachm. schrieb "Steve Yates" : Short version: a PC on the LAN cannot ping the router's gateway, though the router can ping it an

Re: [pfSense] pfSense can get to Internet but LAN cannot

2017-11-30 Thread Steve Yates
A couple clarifications...the ping from LAN to the WAN gateway is timing out, not saying "unreachable" or something like that. I can ping the router's WAN IP (and CARP WAN IP) from the LAN, as allowed by firewall rule. -- Steve Yates ITS, Inc. -Original Message- From: List [mailto:lis

Re: [pfSense] pfSense can get to Internet but LAN cannot

2017-11-30 Thread Steve Yates
1) we're not using NAT 2) ...which means this is the answer because the router on the WAN side doesn't know to route that subnet back to the pfSense. D'oh! Adding a manual NAT rule lets it work. -- Steve Yates ITS, Inc. -Original Message- From: List [mailto:list-boun...@lists.pfsense.

[pfSense] SquidGuard Allow facebook/company url only?

2017-11-30 Thread Alberto Moreno
Hi. I'm trying to figure out how to allow our users just access Facebook company site: www.facebook.com/My-Company/ I add in Target Categories the url above, I select the Target as whitelist in our users, but SG is not accepting my url, I have try different inputs like: www, .facebook differen