Clarification for use of sticky-address in pf.conf

2009-09-14 Thread David Harrison
Hi misc, I'm looking at how to apply the use of the stick-address option. Can someone confirm for me that I only need to use the option for the first pool based rule, and that any subsequent rule utilising that same pool spec will also have the option applied ? IE. I have 2 rules as follows: p

address pools and macros

2009-09-08 Thread David Harrison
Hi misc, I'm interested to know if it's possible to abstract address pools such that I could do something like one of the following: -- table { ($ext_if1 $ext_gw1), ($ext_if2 $ext_gw2) } ... pass in log on $int_if \ route-to { ($ext_if1 $ext_gw1), ($ext_if2 $ext_gw2) } round-robin \

Re: ifstated not honouring my if clauses ?

2009-09-06 Thread David Harrison
2009/9/3 David Harrison : > Hi all, > > I'm setting up a firewall with 2 load-balanced redundant Internet > links. To ensure the host itself can load balance its outbound > connections (and fail-over correctly if one of those links dies) I'm > configuring ifstated to

ifstated not honouring my if clauses ?

2009-09-02 Thread David Harrison
Hi all, I'm setting up a firewall with 2 load-balanced redundant Internet links. To ensure the host itself can load balance its outbound connections (and fail-over correctly if one of those links dies) I'm configuring ifstated to handle updating the default routes for the host based on a simple p

Re: Physical IFs, CARP, and arp overwrite warnings

2008-08-18 Thread David Harrison
2008/8/19 Aaron Glenn <[EMAIL PROTECTED]>: > On Sun, Aug 17, 2008 at 6:42 PM, David Harrison > <[EMAIL PROTECTED]> wrote: >> >> I'm currently theorizing that this is because I have two distinct >> interfaces (carp1, em1) both with IPs on the same subnet

Physical IFs, CARP, and arp overwrite warnings

2008-08-17 Thread David Harrison
Hey all, I've got a CARP rig setup to balance an IP between my 2 firewall hosts (192.168.0.100), with each firewall also having an IP on their physical interface (em1) so I can hit each machine individually (192.168.0.11, 192.168.0.12) no matter who is currently carp master. Config for the intern

Upgrade to 3.7 and VPN no longer works

2005-06-18 Thread David Harrison
I just upgraded my firewall to 3.7, but I've found my VPN is now not working. I keep seeing "NAT detected" messages, but both machines have real IPs so it doesn't make sense. The client machine is a 3.6 install, and the server machine was a 3.4 machine which I used the media CD to upgrade. I