Re: Performance 1.3b16 - Problems
| Newsgroups | gmane.comp.security.firewalls.m0n0wall |
|---|---|
| Message-ID | <[email protected]> |
P.S. here I joined the last two configs - of course a little bit modified of the private stuff... I hope that the attachments are going through...? Ralf Zitat von [email protected]: > Hi Neil, > > thanks for Your reply! - NO i didnt change anything on NAT but I > enabled the "captive-portal" > > I generated some tickets and stopped some sites I didnt want that my > daugther surfes on it. > > I am sorry because I cant make to much tests, because in the moment > Internet ist down I have the whole family on the neck...;-) > > Bye Ralf > > > Zitat von "Neil A. Hillard" <[email protected]>: > >> Hi, >> >> [email protected] wrote: >>> This is a compaq 2000 with 64 MB RAM on a PPOE line with not more than 1 >>> Mbit since the line seems with 43, db "Dämpfung" very old. But it works >>> very well with the actual 1.235 version. >>> >>> After changing there were really no surfing possible. It was worse like >>> a 56 Kbit Modem... >>> >>> I especially tried to jump on the beta using the new >>> "ticketing"-features for... >> >> If you are using advanced NAT then it could be the same issue that hit me: >> >> http://forum.m0n0.ch/index.php?topic=2596 >> >> I wanted to move to 1.3 for the ability to filter incoming VPN traffic! >> In lieu of being able to filter the VPN on m0n0wall I now terminate the >> VPN on my Cisco router and then I can filter the traffic in m0n0wall! >> >> HTH, >> >> >> Neil. >> >>> Zitat von Chris Buechler <[email protected]>: >>> >>>> On Sun, Jun 28, 2009 at 4:47 PM, <[email protected]> wrote: >>>>> Hi freaks, >>>>> >>>>> I installed as required the last beta, upgrading from 1.235 to 1.3b7 and >>>>> than to the b16 Release. >>>>> >>>>> But the result some hours later was remarked as an strong >>>>> bandwith-decrease. >>>>> No reboot helped and I went back to the 1.235. >>>>> >>>>> I am using a simple compaq PC with a 500 MB CF-Card >>>>> >>>> >>>> What CPU? What bandwidth are you expecting to get through it? >> >> >> >> --------------------------------------------------------------------- >> To unsubscribe, e-mail: [email protected] >> For additional commands, e-mail: [email protected] >> >> > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
konfig-20090518005956.xml
(text/xml, 8.4 KB)
<?xml version="1.0"?> <m0n0wall> <version>1.6</version> <lastchange>1242512585</lastchange> <system> <hostname>rochelle</hostname> <domain>ringall.hier</domain> <dnsallowoverride/> <username>admin</username> <password></password> <timezone>Europe/Berlin</timezone> <time-update-interval>300</time-update-interval> <timeservers>pool.ntp.org</timeservers> <webgui> <protocol>https</protocol> <port/> <certificate/> <private-key/> <expanddiags/> </webgui> <dnsserver>145.253.2.11</dnsserver> <dnsserver>195.50.140.114</dnsserver> <dnsserver>145.253.2.171</dnsserver> <group> <name>admin</name> <description>Administratoren</description> <pages>index.php</pages> <pages>system_usermanager.php</pages> <pages>diag_arp.php</pages> <pages>diag_backup.php</pages> <pages>graph_cpu.php</pages> <pages>diag_dhcp_leases.php</pages> <pages>diag_defaults.php</pages> <pages>diag_ipfstat.php</pages> <pages>diag_ipsec_sad.php</pages> <pages>diag_ipsec_spd.php</pages> <pages>graph.php</pages> <pages>diag_logs_portal.php</pages> <pages>diag_logs_dhcp.php</pages> <pages>diag_logs_filter.php</pages> <pages>diag_logs_vpn.php</pages> <pages>diag_logs_settings.php</pages> <pages>diag_logs.php</pages> <pages>diag_ping.php</pages> <pages>reboot.php</pages> <pages>diag_resetstate.php</pages> <pages>diag_traceroute.php</pages> <pages>firewall_aliases.php</pages> <pages>firewall_aliases_edit.php</pages> <pages>firewall_nat_1to1.php</pages> <pages>firewall_nat_edit.php</pages> <pages>firewall_nat_1to1_edit.php</pages> <pages>firewall_nat_server_edit.php</pages> <pages>firewall_nat_out_edit.php</pages> <pages>firewall_nat.php</pages> <pages>firewall_nat_out.php</pages> <pages>firewall_nat_server.php</pages> <pages>firewall_rules.php</pages> <pages>firewall_rules_edit.php</pages> <pages>firewall_shaper_pipes_edit.php</pages> <pages>firewall_shaper_queues_edit.php</pages> <pages>firewall_shaper_edit.php</pages> <pages>firewall_shaper_magic.php</pages> <pages>firewall_shaper_pipes.php</pages> <pages>firewall_shaper_queues.php</pages> <pages>firewall_shaper.php</pages> <pages>status.php</pages> <pages>exec.php</pages> <pages>exec_raw.php</pages> <pages>uploadconfig.php</pages> <pages>interfaces_vlan.php</pages> <pages>interfaces_assign.php</pages> <pages>interfaces_vlan_edit.php</pages> <pages>interfaces_lan.php</pages> <pages>interfaces_opt.php</pages> <pages>interfaces_wan.php</pages> <pages>license.php</pages> <pages>services_captiveportal.php</pages> <pages>services_captiveportal_ip.php</pages> <pages>services_captiveportal_ip_edit.php</pages> <pages>services_captiveportal_mac_edit.php</pages> <pages>services_captiveportal_users_edit.php</pages> <pages>services_captiveportal_filemanager.php</pages> <pages>services_captiveportal_mac.php</pages> <pages>services_captiveportal_users.php</pages> <pages>services_dhcp_relay.php</pages> <pages>services_dhcp.php</pages> <pages>services_dhcp_edit.php</pages> <pages>services_dnsmasq.php</pages> <pages>services_dnsmasq_domainoverride_edit.php</pages> <pages>services_dnsmasq_edit.php</pages> <pages>services_dyndns.php</pages> <pages>services_proxyarp.php</pages> <pages>services_proxyarp_edit.php</pages> <pages>services_snmp.php</pages> <pages>services_wol.php</pages> <pages>services_wol_edit.php</pages> <pages>status_graph_cpu.php</pages> <pages>status_captiveportal.php</pages> <pages>status_interfaces.php</pages> <pages>status_graph.php</pages> <pages>status_wireless.php</pages> <pages>system_advanced.php</pages> <pages>system_firmware.php</pages> <pages>system.php</pages> <pages>system_groupmanager.php</pages> <pages>system_routes.php</pages> <pages>system_routes_edit.php</pages> <pages>vpn_ipsec_ca.php</pages> <pages>vpn_ipsec_ca_edit.php</pages> <pages>vpn_ipsec_keys_edit.php</pages> <pages>vpn_ipsec_edit.php</pages> <pages>vpn_ipsec_mobile.php</pages> <pages>vpn_ipsec_keys.php</pages> <pages>vpn_ipsec.php</pages> <pages>vpn_pptp.php</pages> <pages>vpn_pptp_users_edit.php</pages> <pages>vpn_pptp_users.php</pages> </group> <group> <name>Info</name> <description>Informationen_klein</description> <pages>graph_cpu.php</pages> <pages>diag_ipfstat.php</pages> <pages>diag_ping.php</pages> <pages>license.php</pages> <pages>status_graph_cpu.php</pages> <pages>status_captiveportal.php</pages> <pages>status_interfaces.php</pages> <pages>status_graph.php</pages> <pages>status_wireless.php</pages> <pages>system_routes.php</pages> </group> <group> <name>internetcafe</name> <description>Ticket-Users</description> <pages>index.php</pages> <pages>license.php</pages> </group> <user> <name>Aua</name> <fullname>Aua se</fullname> <groupname>internetcafe</groupname> <password></password> </user> <user> <name>hesse</name> <fullname>Ralf se</fullname> <groupname>admin</groupname> <password></password> </user> <user> <name>Pascale</name> <fullname>Pale se</fullname> <groupname>internetcafe</groupname> <password></password> </user> <user> <name>rhesse</name> <fullname>Ralf se</fullname> <groupname>internetcafe</groupname> <password></password> </user> <harddiskstandby/> </system> <interfaces> <lan> <if>vr1</if> <ipaddr>192.168.1.10</ipaddr> <subnet>24</subnet> <media/> <mediaopt/> </lan> <wan> <if>vr0</if> <mtu/> <blockpriv/> <media/> <mediaopt/> <ipaddr>pppoe</ipaddr> <spoofmac/> </wan> </interfaces> <staticroutes/> <pppoe> <username></username> <password></password> <provider/> <ondemand/> <timeout>0</timeout> </pppoe> <pptp/> <bigpond/> <dyndns> <type>dyndns</type> <username/> <password/> <host/> <mx/> <server/> <port/> </dyndns> <dnsupdate/> <dhcpd> <lan> <enable/> <range> <from>192.168..16</from> <to>192.168..24</to> </range> <staticmap> <mac>00::cf</mac> <ipaddr>192.168..3</ipaddr> <descr>Sao-</descr> </staticmap> </lan> </dhcpd> <pptpd> <mode/> <redir/> <localip/> <remoteip/> </pptpd> <dnsmasq> <enable/> <regdhcp/> </dnsmasq> <snmpd> <syslocation/> <syscontact/> <rocommunity>public</rocommunity> </snmpd> <diag> <ipv6nat> <ipaddr/> </ipv6nat> <ipfstatentries>500</ipfstatentries> </diag> <bridge/> <syslog> <reverse/> <nentries>150</nentries> <remoteserver/> <resolve/> </syslog> <nat> <portrange-low/> <portrange-high/> </nat> <filter> <rule> <type>reject</type> <interface>wan</interface> <protocol>tcp</protocol> <source> <address>205.188.251.118</address> </source> <destination> <any/> </destination> <descr>ICQ-1</descr> </rule> <rule> <type>reject</type> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <address>85.236.198.250</address> </destination> <log/> <descr>Kwick.com-sperren</descr> </rule> <rule> <type>reject</type> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <address>205.188.251.118</address> </destination> <descr>ICQ-2</descr> </rule> <rule> <type>block</type> <interface>lan</interface> <source> <address>64.12.164.247</address> </source> <destination> <address>64.12.164.247</address> </destination> <descr>ICQ-3</descr> </rule> <rule> <type>pass</type> <descr>Default LAN -> any</descr> <interface>lan</interface> <source> <network>lan</network> </source> <destination> <any/> </destination> </rule> <tcpidletimeout/> </filter> <shaper> <enable/> <pipe> <bandwidth>10</bandwidth> <mask>destination</mask> <descr>test-destination</descr> </pipe> <rule> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <any/> </destination> <direction/> <iplen/> <iptos/> <tcpflags/> <descr>test-destination</descr> <targetpipe>0</targetpipe> </rule> <queue> <targetpipe>0</targetpipe> <weight>1</weight> <mask>destination</mask> <descr>test-destination</descr> </queue> </shaper> <ipsec/> <aliases/> <proxyarp/> <wol/> </m0n0wall>
konfig-20090518214102.xml
(text/xml, 10.6 KB)
<?xml version="1.0"?> <m0n0wall> <version>1.8</version> <lastchange>1242613669</lastchange> <system> <hostname>rochelle</hostname> <domain>ringall.hier</domain> <dnsallowoverride/> <username>admin</username> <password></password> <timezone>Europe/Berlin</timezone> <time-update-interval>300</time-update-interval> <timeservers>1.m0n0wall.pool.ntp.org</timeservers> <webgui> <protocol>https</protocol> <port/> <certificate/> <private-key/> <expanddiags/> </webgui> <dnsserver>145.253.2.11</dnsserver> <dnsserver>195.50.140.114</dnsserver> <dnsserver>145.253.2.171</dnsserver> <group> <name>admin</name> <description>Administratoren</description> <pages>index.php</pages> <pages>system_usermanager.php</pages> <pages>diag_arp.php</pages> <pages>diag_backup.php</pages> <pages>graph_cpu.php</pages> <pages>diag_dhcp_leases.php</pages> <pages>diag_defaults.php</pages> <pages>diag_ipfstat.php</pages> <pages>diag_ipsec_sad.php</pages> <pages>diag_ipsec_spd.php</pages> <pages>graph.php</pages> <pages>diag_logs_portal.php</pages> <pages>diag_logs_dhcp.php</pages> <pages>diag_logs_filter.php</pages> <pages>diag_logs_vpn.php</pages> <pages>diag_logs_settings.php</pages> <pages>diag_logs.php</pages> <pages>diag_ping.php</pages> <pages>reboot.php</pages> <pages>diag_resetstate.php</pages> <pages>diag_traceroute.php</pages> <pages>firewall_aliases.php</pages> <pages>firewall_aliases_edit.php</pages> <pages>firewall_nat_1to1.php</pages> <pages>firewall_nat_edit.php</pages> <pages>firewall_nat_1to1_edit.php</pages> <pages>firewall_nat_server_edit.php</pages> <pages>firewall_nat_out_edit.php</pages> <pages>firewall_nat.php</pages> <pages>firewall_nat_out.php</pages> <pages>firewall_nat_server.php</pages> <pages>firewall_rules.php</pages> <pages>firewall_rules_edit.php</pages> <pages>firewall_shaper_pipes_edit.php</pages> <pages>firewall_shaper_queues_edit.php</pages> <pages>firewall_shaper_edit.php</pages> <pages>firewall_shaper_magic.php</pages> <pages>firewall_shaper_pipes.php</pages> <pages>firewall_shaper_queues.php</pages> <pages>firewall_shaper.php</pages> <pages>status.php</pages> <pages>exec.php</pages> <pages>exec_raw.php</pages> <pages>uploadconfig.php</pages> <pages>interfaces_vlan.php</pages> <pages>interfaces_assign.php</pages> <pages>interfaces_vlan_edit.php</pages> <pages>interfaces_lan.php</pages> <pages>interfaces_opt.php</pages> <pages>interfaces_wan.php</pages> <pages>license.php</pages> <pages>services_captiveportal.php</pages> <pages>services_captiveportal_ip.php</pages> <pages>services_captiveportal_ip_edit.php</pages> <pages>services_captiveportal_mac_edit.php</pages> <pages>services_captiveportal_users_edit.php</pages> <pages>services_captiveportal_filemanager.php</pages> <pages>services_captiveportal_mac.php</pages> <pages>services_captiveportal_users.php</pages> <pages>services_dhcp_relay.php</pages> <pages>services_dhcp.php</pages> <pages>services_dhcp_edit.php</pages> <pages>services_dnsmasq.php</pages> <pages>services_dnsmasq_domainoverride_edit.php</pages> <pages>services_dnsmasq_edit.php</pages> <pages>services_dyndns.php</pages> <pages>services_proxyarp.php</pages> <pages>services_proxyarp_edit.php</pages> <pages>services_snmp.php</pages> <pages>services_wol.php</pages> <pages>services_wol_edit.php</pages> <pages>status_graph_cpu.php</pages> <pages>status_captiveportal.php</pages> <pages>status_interfaces.php</pages> <pages>status_graph.php</pages> <pages>status_wireless.php</pages> <pages>system_advanced.php</pages> <pages>system_firmware.php</pages> <pages>system.php</pages> <pages>system_groupmanager.php</pages> <pages>system_routes.php</pages> <pages>system_routes_edit.php</pages> <pages>vpn_ipsec_ca.php</pages> <pages>vpn_ipsec_ca_edit.php</pages> <pages>vpn_ipsec_keys_edit.php</pages> <pages>vpn_ipsec_edit.php</pages> <pages>vpn_ipsec_mobile.php</pages> <pages>vpn_ipsec_keys.php</pages> <pages>vpn_ipsec.php</pages> <pages>vpn_pptp.php</pages> <pages>vpn_pptp_users_edit.php</pages> <pages>vpn_pptp_users.php</pages> </group> <group> <name>Info</name> <description>Informationen_klein</description> <pages>graph_cpu.php</pages> <pages>diag_ipfstat.php</pages> <pages>diag_ping.php</pages> <pages>license.php</pages> <pages>status_graph_cpu.php</pages> <pages>status_captiveportal.php</pages> <pages>status_interfaces.php</pages> <pages>status_graph.php</pages> <pages>status_wireless.php</pages> <pages>system_routes.php</pages> </group> <group> <name>internetcafe</name> <description>Ticket-Users</description> <pages>index.php</pages> <pages>license.php</pages> </group> <user> <name>Aurelia</name> <fullname>Aua se</fullname> <groupname>internetcafe</groupname> <password></password> </user> <user> <name>hesse</name> <fullname>Ralf</fullname> <groupname>admin</groupname> <password></password> </user> <user> <name>Pascale</name> <fullname>se</fullname> <groupname>internetcafe</groupname> <password></password> </user> <user> <name>rhesse</name> <fullname>Ralf</fullname> <groupname>internetcafe</groupname> <password></password> </user> <harddiskstandby/> </system> <interfaces> <lan> <if>vr1</if> <ipaddr>192.168..10</ipaddr> <subnet>24</subnet> <media/> <mediaopt/> </lan> <wan> <if>vr0</if> <mtu/> <blockpriv/> <media/> <mediaopt/> <ipaddr>pppoe</ipaddr> <spoofmac/> </wan> </interfaces> <staticroutes/> <pppoe> <username></username> <password></password> <provider/> <ondemand/> <timeout>0</timeout> </pppoe> <pptp/> <bigpond/> <dyndns> <type>dyndns</type> <username/> <password/> <host/> <mx/> <server/> <port/> </dyndns> <dnsupdate/> <dhcpd> <lan> <enable/> <range> <from>192.168..10</from> <to>192.168..24</to> </range> <staticmap> <mac>00:fe</mac> <ipaddr>192.168..15</ipaddr> <descr>pir</descr> </staticmap> <staticmap> <mac>00:cf</mac> <ipaddr>192.168..3</ipaddr> <descr>Sao</descr> </staticmap> <staticmap> <mac>00::4f</mac> <ipaddr>192.168..3</ipaddr> <descr>plo</descr> </staticmap> <defaultleasetime/> <maxleasetime/> </lan> </dhcpd> <pptpd> <mode/> <redir/> <localip/> <remoteip/> </pptpd> <dnsmasq> <enable/> <regdhcp/> </dnsmasq> <snmpd> <syslocation/> <syscontact/> <rocommunity>public</rocommunity> </snmpd> <diag> <ipv6nat> <ipaddr/> </ipv6nat> <ipfstatentries>500</ipfstatentries> </diag> <bridge/> <syslog> <reverse/> <nentries>150</nentries> <remoteserver/> <resolve/> </syslog> <nat> <portrange-low/> <portrange-high/> </nat> <filter> <rule> <type>reject</type> <interface>wan</interface> <protocol>tcp</protocol> <source> <address>205.188.251.118</address> </source> <destination> <any/> </destination> <descr>ICQ-1</descr> </rule> <rule> <type>reject</type> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <address>85.236.198.250</address> </destination> <log/> <descr>Kwick.com-sperren</descr> </rule> <rule> <type>reject</type> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <address>205.188.251.118</address> </destination> <descr>ICQ-2</descr> </rule> <rule> <type>block</type> <interface>lan</interface> <source> <address>64.12.164.247</address> </source> <destination> <address>64.12.164.247</address> </destination> <descr>ICQ-3</descr> </rule> <rule> <type>pass</type> <descr>Default LAN -> any</descr> <interface>lan</interface> <source> <network>lan</network> </source> <destination> <any/> </destination> </rule> <rule> <type>pass</type> <descr>Default IPsec VPN</descr> <interface>ipsec</interface> <source> <any/> </source> <destination> <any/> </destination> </rule> <tcpidletimeout/> </filter> <shaper> <enable/> <pipe> <bandwidth>10</bandwidth> <mask>destination</mask> <descr>test-destination</descr> </pipe> <rule> <interface>lan</interface> <protocol>tcp</protocol> <source> <any/> </source> <destination> <any/> </destination> <direction/> <iplen/> <iptos/> <tcpflags/> <descr>test-destination</descr> <targetpipe>0</targetpipe> </rule> <queue> <targetpipe>0</targetpipe> <weight>1</weight> <mask>destination</mask> <descr>test-destination</descr> </queue> </shaper> <ipsec/> <aliases/> <proxyarp/> <wol/> <captiveportal> <passthrumac> <mac>00::fe</mac> <descr>pdar</descr> </passthrumac> <passthrumac> <mac>00::4f</mac> <descr>plato</descr> </passthrumac> <user> <name>Aua</name> <fullname>se</fullname> <expirationdate/> <password></password> </user> <interface>lan</interface> <maxproc/> <timeout/> <idletimeout/> <auth_method>local</auth_method> <reauthenticateacct/> <httpsname/> <certificate/> <private-key/> <bwdefaultdn/> <bwdefaultup/> <redirurl/> <radiusip/> <radiusip2/> <radiusport/> <radiusport2/> <radiusacctport/> <radiuskey/> <radiuskey2/> <radiusvendor>default</radiusvendor> <radmac_format>default</radmac_format> <logoutwin_enable/> </captiveportal> <voucher> <charset>2345678abcdefhijkmnpqrstuvwxyzABCDEFGHJKLMNPQRSTUVWXYZ</charset> <rollbits>16</rollbits> <ticketbits>10</ticketbits> <saveinterval>300</saveinterval> <checksumbits>5</checksumbits> <magic>1951606442</magic> <publickey>LS0tLS1CRUdJTiBQVUJMSUMgS0VZLS0tLS0NCk1DUXdEUVlKS29aSWh2Y05BUUVCQlFBREV3QXdFQUlKQU5QUnFHa1poazNwQWdNQkFBRT0NCi0tLS0tRU5EIFBVQkxJQyBLRVktLS0tLQ0K</publickey> <privatekey>LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ0KTUQ4Q0FRQUNDUURUMGFocEdZWk42UUlEQVFBQkFnaEJQRmo1TmdieFlRSUZBT3lQdEhNQ0JRRGxPWGt6QWdVQQ0KeU52ajNRSUZBTXNYRmRNQ0JBMmd5Tk09DQotLS0tLUVORCBSU0EgUFJJVkFURSBLRVktLS0tLQ0K</privatekey> <msgnoaccess>Voucher invalid</msgnoaccess> <msgexpired>Voucher expired</msgexpired> <enable/> <roll> <number>001</number> <minutes>15</minutes> <comment>Für Aurelia</comment> <count>1000</count> <used>AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA</used> </roll> </voucher> </m0n0wall>