Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Set this inside of custom options like Example: [image: 1760709794107-screenshot-2025-10-17-at-07.01.42.png] (ignore ssl_engine) After run Squid -k parse and you should see this within the tests if you have no errors and it moves to the next time you have the work around. 2025/10/17 07:02:07| Processing: ssl_engine devcrypto 2025/10/17 07:02:07| Processing: email_err_data off
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    You show a VLAN configured on the LAN physical interface. VLANs and netmap (the underlying FreeBSD kernel device used to support inline IPS mode operation) are not great friends . While it can work, a VLAN interface requires the use of an emulated netmap adapter which is a software construct that is much less efficient than the hardware adapter netmap interfaces. Another thing that limits IPS performance on pfSense is the fact IPS mode uses the host rings netmap interface. That interface is virtual and is much slower than the hardware rings associated with the NIC. Another issue that can severely affect throughput is the number of enabled rules. More rules means more CPU work and less throughput. Lastly, you may need to fine-tune settings for the NIC adapter using sysctl variables. You would need to perform your own research for that. I have no experience with that and thus no tips to offer. Legacy Mode uses the PCAP library to simply grab copies of packets traversing an interface. Suricata is then fed those copied packets to digest while the original packets continue on to the host. That means Legacy Mode will leak the initial packets and let the connection be made. Then, after Suricata has time to compare the packet or packets to the signatures and if there is a match, a pfctl firewall API call is made to place the offending IP address into a pf table for subsequent blocking. Another API call is then made to flush any active states that are associated with the blocked IP. Also noticed that you posted this same issue on the upstream Suricata forum. That will not help. The Suricata package on pfSense is highly customized and the developers upstream are not privy to the inner workings of the Suricata setup used in pfSense (nor in OPNsense, for that matter). Both *Sense products use a GUI front-end for managing Suricata. Suricata itself (the binary used to do the actual inspecting of traffic) has no GUI. It is managed completely at the command line level. But that is not true on pfSense as the GUI code manages the underlying binary and controls the creation of the suricata.yaml file. If you want optimum wire-speed IPS performance with Suricata, then you should install it on a separate hardware platform with at least three NIC ports running Linux. Suricata is optimized for Linux and no so much for FreeBSD. Three NIC ports allow one for a management address and then the other two for a netmap or AF_PACKET bridge handled by Suricata. You would need to install the binary package for the Linux distro you chose and configure Suricata by hand using the CLI. In your use case, this new hardware box would go inline between the LAN port of your 8200 MAX and the LAN switch in your network.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    J
    @mull0r Thanks for the clear instructions to fix this issue. I am on pfsense+ 25.07.1 and pfBlockerNG 3.2.7.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @netboy said in Docker container for nut server?: I am NOT installing docker in pfsense - offcourse this is a big security risk - I agree !!! My apologies. I interpreted your earlier question I think i need to explain what i am asking for. I am fully aware if your netgate router is attached to an UPS you can configure netgate. Let us say you 5 UPS's in your home and you want nut server to read all the UPS's and show me a dasboard about the status of all the UPS's ? - Is there a ready made docker container for client server nut with dashboard functionality? as a request to have something running on pfSense, which is why I responded I believe most people would say that the type of thing you are asking for isn't something you want to run on your firewall. I recommend using a general purpose operating system behind the firewall instead. Mutual misunderstanding I guess. If you want to explore general NUT monitoring, and not something particular to pfSense, I would recommend the NUT Users list as a better place to seek information.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    502 Topics
    3k Posts
    GertjanG
    @BerndHu said in BUG: ACME, Method "Hetzner DNS": Can please someone update this method? You mean this (from 2023) : "Hetzner => Automating SSL Certificate Issuance with acme.sh through DNS" isn't valid anymore ? If so, acme.sh will get (needs to be) updated first. See here to check who/when/what. For example, the "Issues" list. After acme.sh itself (yet another open source project) is updated, it will get pulled into the pfSense-acme.sh package and a newer version is build. You'll be asked to update that package.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    92 Topics
    625 Posts
    M
    @left4apple Basicaslly - Yes. The key on the UI is no longer relevant (once you go with the oauth route) I'm on version 1.88.3 of tailscale, after several reboots (due to power outages...) - TS still connected and authenticated :-)
  • Discussions about WireGuard

    707 Topics
    4k Posts
    planedropP
    I have a production setup with a good number (30) of WireGuard tunnels, and for some reason the WireGuard package fails to stop upon reboots now so I have to force reset both units in order to do a reboot. We had a (non-related I think) CARP issue with our setup today where our backup unit decided it was Master for our WAN (which is super bizarre given it could see the VRRP advertisements and has been fine for 5 years). When this happened, it took over WireGuard for some clients, causing routing issues. I figured I'd reboot it to see if CARP resumed properly, when doing this it got stuck and the WebGUI crashed. I decided to reboot from the console and it got stuck for 10 minutes on Stopping WireGuard, and this is not the first time this has happened. The first time was about a month ago and I left the units for 30 minutes and the package never stopped. Both firewalls are Netgate 1541's and both are on 25.07.1 so I'm thinking there is some bug either with the latest version of pfSense Plus or with the WireGuard package itself. Anyone else seen something like this?
  • System Patches Package v2.2.23

    Pinned
    1
    7 Votes
    1 Posts
    3k Views
    No one has replied
  • DNS Broken for pkg.pfsense.org

    Pinned Locked
    3
    0 Votes
    3 Posts
    18k Views
    jimpJ
    https://forum.netgate.com/topic/115789/pkg-pfsense-org-appears-to-be-dead/2
  • Packages wishlist?

    Pinned
    661
    0 Votes
    661 Posts
    2m Views
    O
    PRTG
  • mdns-bridge one-way reflection

    12
    0 Votes
    12 Posts
    380 Views
    dennypageD
    @kesawi mDNS isn't like firewall rules, where you are controlling pathways between discrete interfaces. The way to think about this is that mDNS represents a common pool of services (I.E. DNS entries). The filter rules allow you to control what service names from each segment are added to the pool (inbound filters), and what service names from the pool are advertised to each segment (outbound filters). Do keep in mind that the ability to see that the service exists in mDNS does not mean that you can connect to it. Standard firewall rules for TCP/UCP still govern the ability to connect to a service. One other note: as indicated in the documentation, it is not necessary (or useful) to include _tcp or local labels in filters as these are redundant.
  • snort 4.1.6_27 crashing with php error

    2
    0 Votes
    2 Posts
    45 Views
    fireodoF
    @SomeoneOnTheInternet Same here too ... EDIT: for the moment (until @jimp overview the code) you can edit the /usr/local/www/snort/snort_rules.php. Go to line 178 and put a ";" (without quota) in the end of this statement: $currentruleset = basename($currentruleset) so it looks like this: $currentruleset = basename($currentruleset); it helped here.
  • Need urgent support with HAProxy setup will pay

    1
    0 Votes
    1 Posts
    23 Views
    No one has replied
  • Advantages of mDNS-Bridge vs UDPBroadcastRelay

    7
    0 Votes
    7 Posts
    155 Views
    keyserK
    @dennypage And thank you SO much to @dennypage for maintaining the package - and so selflessly spending time supporting it and us users. Especially when we ask stupid questions or are so selfcentered we find ourselves important enough to outright complain over volunteer work like this. All package maintainers should really have a HERO badge here on this forum.
  • HAProxy - Files

    3
    4
    0 Votes
    3 Posts
    303 Views
    patient0P
    @AnthonySalamone preface: I don't use HA Proxy but did use the power of searching the internet. If you want to use pfSense with Authelia, which seems to use these exact three files, someone written a blog post about how to do it: https://kovasky.me/blogs/pfsense_haproxy_authelia/
  • LLDP Package disappeared

    3
    0 Votes
    3 Posts
    65 Views
    P
    @keyser Thanks for the info, I just rebooted and the LLDP packaged reppeared and reinstalled. Its now running. Thanks again.
  • Problem with Net-SNMP - not starting

    4
    0 Votes
    4 Posts
    3k Views
    kmpK
    @barnettd Hey there, thanks! I haven't really worked with FreeBSD for many years, and I've forgotten all of the package management stuff... your solution worked fine for me, though, and as with you I was able to then start Net-SNMP and I'm back to fully operational. Thanks again. I'd just like to summarize (for those following as well) what I understand: without really knowing what the pfSense-repo and pfSense-upgrade packages offer, it appears that the bottom line is that the pkg utility had to be downgraded from 2.2.2_2 to 1.21.3_5 [pfSense]. Do I have that right? I'm guessing that somehow I hit the update server at the right (wrong) moment and got an incompatible configuration. Strange, though, that I've (intentionally) never opted for anything other than the STABLE branch. Very much appreciate your help!
  • Prometheus Node Exporter gives log errors - fix or suppress in log

    7
    0 Votes
    7 Posts
    6k Views
    A
    @nws thanks for the consistent fix - I completely overlooked that for a while. And @credulous yes, it's still a mystery why the collectors seemingly trigger and gives errors, and also why they don't appear at the collector list. It seems the Prometheus Node Exporter package on FreeBSD has very low priority perhaps? Else you would imagine something like this could be fixed.
  • HAProxy / ACME + external webhost?

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FreeRadius or something else, for MFA without a PIN code?

    9
    0 Votes
    9 Posts
    3k Views
    N
    @Codefighter Thanks @Codefighter, you’ve nailed it. I totally agree that for home use, OTP can feel like overkill. But when it comes to small, medium, and large businesses, we’ve got a real responsibility to keep networks and systems secure. We can’t afford to be casual or underestimate the risks out there. Honestly, I’d much rather hear a few grumbles from employees about typing in an OTP every time they hop on the VPN than have to sit in a meeting with the board explaining why we didn’t do enough to prevent and mitigate a cyberattack.
  • 0 Votes
    1 Posts
    111 Views
    No one has replied
  • net-snmp on Netgate 7100 cluster - firmware 25.07.1-RELEASE

    3
    0 Votes
    3 Posts
    3k Views
    S
    see https://forum.netgate.com/topic/198800/solved-pkg-upgrade-not-found-required-by-pkg running on ssh this command fixed my problem. pkg-static clean -ay; pkg-static install -fy pkg pfSense-repo pfSense-upgrade for me the problem is solved.uuu
  • iperf3 on 25.07.1-RELEASE

    5
    0 Votes
    5 Posts
    3k Views
    E
    you're right, I'm still confused about where to find it. The red flag remains, probably just a minor bug
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    505 Views
    No one has replied
  • crowdsec

    36
    0 Votes
    36 Posts
    10k Views
    Z
    @keyser My "security engine" which is the server that receives all the logs and makes decisions, can be run on a separate server. That is my exact setup so I can run my own web/php front end. As per the the url block list, or EDL since I'm entrenched in Palo terminology, doesn't do the log analysis and crowdsec reporting. Different strokes for different folks I guess.
  • Arpwatch - flip flop notifications not suppressed

    1
    3
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • 0 Votes
    11 Posts
    8k Views
    fireodoF
    @jimp said in LCDproc Looses Connection - Restarting service Fixes but goes down again shortly after: and I can never reproduce it in the lab. Hi, if you go to Diagnostics -> States and kill all states you get the "running wild" and flooding syslog lcdproc-client. (Maybe also of interest: LcdProc) Regards, fireodo
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.