Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    It was all CVE fixes in the PHP GUI part of the package. See the Redmine ticket here: https://redmine.pfsense.org/issues/16414.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    V
    @Gertjan Thanks for your reply – that’s also my impression. The point is: I don’t really see any lists right now that are actually “maintained” in the sense of being actively cleaned up, checked for dead domains, categorized, etc. That’s why my main interest is more about the demand: Would curated lists really be a game changer for admins? Would they be more helpful than what’s available today, or are most people already using other alternatives? If so, which ones? And from your perspective, what would be your expectation towards “community lists”? (e.g. reliability, update frequency, categories, fewer false positives?)
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    501 Topics
    3k Posts
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    610 Posts
    E
    Updated CE 2.7.2 to 1.86.4_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.4_1.pkg Freshports
  • Discussions about WireGuard

    700 Topics
    4k Posts
    Bob.DigB
    @HFADmin If it is no Site2Site-VPN then you don't need any gateways in the first place... If that is true but you want to monitor the connection then you could create dummy-gateways just to ping the remote ip-addresses.
  • Avast Updates Fail!

    Locked
    12
    0 Votes
    12 Posts
    8k Views
    R
    I live by the web interface and do not dig to deep into the config files! I have to have a "keep it simple stupid" policy! Because if I get hit by a truck there is NO ONE to keep the systems going! I am in Egypt and after 3 years here I now know that Aliens built the pyramids! Because there is now way in hell they got build by the Egyptian Minds and Egyptian Natives! So I did it the simple way and figured the naming convention for most of the primary virus protection companies and loaded it into a text file and maualy loaded it to all pfsense servers… Problem solved and all is quite! If wanted I can post the No Cache Virus Server Update List.... Let me know!
  • I don't see the packages menu

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C
    ntop is not going to work on a 4501 even if you did run a full install on a microdrive. It requires way too much RAM to function on a system with only 64 MB. pfSense technically isn't even supported on less than 128 MB, though for some purposes 64 MB will suffice.
  • Hobbitclient - monitoring (or installhowto ;-) )

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Openntpd doesn't work

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    K
    Will a fix for this be incorperated into 1.2 rc 3? im currently using 1.2 rc2 its yet to auto sync with the exception of first boot for 13 days now. Ive been logging in through ssh to force a sync the past two days
  • Possible problem in Snort package dealing with MicroSoft IE

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    Well - here is a fix to the issue with Microsoft IE vs other browsers…. In the /usr/local/www/snort_rules.php file there is a javascript function called 'go'. brackets to denote an array index but instead uses the () parans… and then only if there are more than one object of the same type (lousy implementation if you ask me!)... Anyway - the "fix" to allow the different browsers, including Microsoft's IE, to display the Category information properly is to detect if the browser is msie or a different one - then setup the go function assignements accordingly: function go() {     var agt=navigator.userAgent.toLowerCase(); if (agt.indexOf("msie") != -1) {         box = document.forms.selectbox;}     else         {box = document.forms[1].selectbox;} destination = box.options[box.selectedIndex].value;     if (destination) location.href = destination; } I have tested the above code using both Firefox and MSIE-7 and it works properly - if anyone else wants to test please feel free - hopefully this will end up in the snort package as a fix.. gm…
  • Darkstat cannot connect on 666

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    L
    No but I will do that now thanks :D
  • Dual wan and package install

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    Cry HavokC
    Set up an explicit route?
  • Package reload hangs

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to disable squid without removing it?? –RESLOVED--

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    N
    WORKS. THANKS
  • Frickin Question

    Locked
    17
    0 Votes
    17 Posts
    7k Views
    A
    Once again this has come up :) What have I tried meantime is that I installed Frickin 2.0 beta2 onto my FreeBSD-6.2. I also enabled scrub only for udp and tcp, but well.. still stuck on "Verifying username and password..". Looks like I forgot to MFC a few items.  Please try a snapshot about 2 hours from now. I didn't quite get what snapshot should one try - Frickin or pfSense or …? And I'm quite confused about PF and PPTP issue. Some people seem to claim that it's possible to use PPTP through PF, but all the guidlines end up somewhere.. Is there any hope to get it working with PF or should I just go back to IPFW (which to my mind had no such problems)?
  • Snort not working

    Locked
    2
    0 Votes
    2 Posts
    6k Views
    S
    Sep 19 15:47:54    snort[11015]: PID path stat checked out ok, PID path set to /var/run/ Sep 19 15:47:54    snort[11015]: PID path stat checked out ok, PID path set to /var/run/ Sep 19 15:47:54    snort[11015]: FATAL ERROR: Failed to Lock PID File "/var/run//snort_ng0.pid" for PID "11015" Sep 19 15:47:54    snort[11015]: FATAL ERROR: Failed to Lock PID File "/var/run//snort_ng0.pid" for PID "11015" Do you connect to the internet via PPoE? I am currently having the same error but on ath0 but I've set snort to listen on to bfe0 (WAN) Slam
  • RC2 doesn't list packages

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R
    Thanks  ;D i was searching for subversion pkg
  • Subversion(SVN)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    Thanks for the info, anyone has tryied to use pkg_add?? on a pfsense?
  • Ip on whitelist but snort is stil triggering/blocking

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort

    Locked
    9
    0 Votes
    9 Posts
    7k Views
    AhnHELA
    I see the same exact thing on a reboot.  Snort apparently takes some coaxing to run properly and yes I've seen that line 40 error as well as of late. This is not specific to just your system Slam, so no more clean installs, ok?  ;)
  • Proxy and load balancer

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A
    Correct usuarioforum, that's my understanding too
  • Squid - Transparent Proxy for ALL Web Traffic

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    @Seth: including traffic on unique ports and SSL.  Is this possible? Transparently intercepting SSL is not possible, that's part the design of SSL.  As for non-standard ports, just block them: this is standard enterprise filtering technique and all service operators are aware of this, and hence the invention of HTTP tunnelling. Sneakily I want to add my own question, as of 1.2-RC2 is it possible to install transparent Squid to HAVP+ClamAV proxy from packages without manual configuration file hacking?  Would this even remotely run on a WRAP device with 128MB system memory and 4GB CF microdrive?  I'm checking for convenient embedded alternatives.
  • UPNP service not working correctly on multiple interfaces

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    R
    My mistake, I use vim in windows to edit the files and didn't realize it wasn't in unix format. Whats interesting is I tested it on my pfSense box and it ran fine. Anyway I updated the file using dos2unix to make sure.
  • About IMSpector file transfer and wishlists

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R
    Not at this time. Visit the http://imspector.org/ page for contact information.
  • AC-bnfa

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    How about looking at the snort community? :)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.