Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    S
    @Smeg.Head Have you tried saving the log settings page as is? Years ago IIRC there was a bug there also where it needed saving. If pfSense is set to compress logs (should not on ZFS or slow CPUs) I wonder if it might be trying and timing out.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    J
    @nanda said in pfb_filter and pfb_dnsbl services are not running Pfsense 25.07.1: When I checked the status of the service, the firewall returned, "does not exist". as in on the Status -> Services page? or where specifically ? and yet it shows on the dashboard services widget.. And you said this was a fresh install so ... are there any errors in pfblockerNG 's error.log, dnsbl_parsed_error or py_error (Firewall -> pfBlockerNG -> Logs on the pfblockerNG -> General. make sure the Keep Settings option is enabled then head over to packages and try to reinstall the package (you may remove and install or just reinstall) see if you spot any install errors during the install then when complete you will need to change the masterfile / mastercat line again and then check the update page at Firewall -> pfBlockerNG -> Update should have a status showing the next scheduled cron event (if that is within a few minutes just wait for it to run). if it is more than say 20 minutes away or says not scheduled (or similar) then on the same update screen force Cron hit run. when that is complete check the status then reboot check the status
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    500 Topics
    3k Posts
    G
    @Gertjan well..... finally i created a new user for inwx and just gave him dns_management role only AND without 2FA. So now all is fine, my PFSense has the LE Cert as it should be. Thanks and kr Mike
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    609 Posts
    luckman212L
    The bugaboo that was affecting the FreeBSD 15 pkg repos has cleared, and the new builds seem to be finished. So, 1.86.4 is now landed in FreeBSD:15:amd64/latest ABI: pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.86.4.pkg
  • Discussions about WireGuard

    699 Topics
    4k Posts
    S
    @Bob.Dig what's the right place?
  • HAVP + ClamAV: some thoughts on setting it up

    Locked
    5
    0 Votes
    5 Posts
    10k Views
    R
    Updated HAVP, works with current ClamAV package. Should hit CVS any time now. raj
  • Installing Packages..

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    @clamothe: wow..  i just realised that I forgot to install pfsense on my HD, and I was running it off livecd for the past two weeks lol, thanks tho update: Okay I have it installed on my HD now.  I'm looking at packages, but the list is limited.. how do I install lighttpd?  I don't see a package upload either.  I ssh'd in and did pkg_add -r http://pfsense.org/packages/All/lighttpd-1.4.11.tbz ala freebsd, and it installed fine, but there's no gui element installed. Lighttpd alredy installed - this system package - WebGUI worked in them type pkg_info - you see all installed FreeBSD packages. But this not some WebGui packages list. InWebGUI you can see users packages and can't see system packages.
  • Squid package questions

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • I don't know the antivirus has start?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    A
    Hi, When I go to "Service"–>"Clamav" The page show a follow error: Warning: Invalid argument supplied for foreach() in /usr/local/www/pkg_edit.php on line 326 How I to do? Thanks a lot.
  • Re: Transparent Squid and Traffic Shaping!!

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    ?
    http://forum.pfsense.org/index.php?topic=1352.0
  • Squid install problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    http://forum.pfsense.org/index.php?topic=1352.0
  • Updated packages

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    The installed package tab will show new versions.
  • Package installation

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    B
    OK, so that's the case thnx! I'll try BETA 4 :)
  • Unable to communicate to pfSense.com

    Locked
    3
    0 Votes
    3 Posts
    7k Views
    N
    I found out why it wasn't working. The "Allow DNS server list to be overridden by DHCP/PPP on WAN" option was enabled in the "System: General Setup" menu.
  • Freeradius

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    FreeRADIUS is marked as broken.  Surely you dont' expect something marked as broken to work!?
  • Pfflowd non correctly counts

    Locked
    12
    0 Votes
    12 Posts
    7k Views
    B
    @freeseacher: @billm: It's likely that pfflowd is only counting stuff that matches state.  Retransmits that got dropped for whatever reason likely don't add to the flow numbers it retains. pfflowd gets it's data from pfsync - I don't believe it maintains a table of inflight flows, I'm pretty sure it gets it's data from the state teardown messages.  So, the data comes directly from the PF state entry which means only data that pf forwarded itself. –Bill rules for pf was pass any in keep-state pass any out keep-state is there someting to miss ? Yes, my point ;) Not all packets in a given TCP flow will be considered "in state".  Consider out of window packets, out of sequence window packets (stuff that's been ack'd and had data past it acked, but was retransmitted all the same).  "normal" TCP communications do have packets that will get blocked.  I'm reasonably confident that those packets will not cound against the PF byte count for that flow.  The easiest way to determine that is to see if the PF byte count more closely matches that of the file(s) that were transferred.  If it's under, then there's a bug somewhere, if it's over, but over by less than the other accounting types (ng_netflow is going to get all packets regardless of whether pf blocks it) then it's not a bug per se, you just have to understand what/where you're monitoring. –Bill
  • Error when installing STUNNEL

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    L
    thanks a lot Sullrich, it's OK now  ;)
  • Antivirus for PFsense

    Locked
    2
    0 Votes
    2 Posts
    7k Views
    S
    Fernando is working on it but there is no ETA.
  • ClamAV

    Locked
    8
    0 Votes
    8 Posts
    8k Views
    R
    Hi, I have made a clamav package, it's not complete as yet and I have not added any web gui for starting or stopping or for other options in config files. As of now you can just test it from command line by running clamscan. The actual use for clamscan is for havp. As of now havp has experimental FreeBSD support and I am working on packaging it for FreeBSD. In the mean time pl test the clamav package. This is my first stab at packaging some thing for pfSense, so there will be lot's of things that can be improved. raj I am posting the clamav section from pkg_config.xml and the package configuration files.           <package><name>clamav</name>           <website>http://www.clamav.net/</website>           <descr>Opensource anti virus</descr>           <category>Services</category>           <config_file>http://agni.linuxense.com/packages/config/clamav.xml</config_file>           <depends_on_package_base_url>http://ftp13.freebsd.org/pub/FreeBSD/ports/i386/packages-6.0-release/All</depends_on_package_base_url>           <depends_on_package>clamav-0.87.tbz</depends_on_package>           <version>0.1</version>           <status>BETA</status>           <maintainer>raj@linuxense.com</maintainer>           <configurationfile>clamav.xml</configurationfile>           <logging><facilityname>clamav</facilityname>                 <logfilename>clamav.log</logfilename></logging></package> config.xml <packagegui><name>clamav</name>         <version>0.1</version>         <title>ClamAV: Settings</title>         <include_file>/usr/local/pkg/clamav.inc</include_file>         <service><name>clamav</name>                 <rcfile>/usr/local/etc/rc.d/clamav.sh</rcfile></service>         <additional_files_needed><prefix>/usr/local/pkg/</prefix>             <chmod>0755</chmod>             http://agni.linuxense.com/packages/config/clamav.inc</additional_files_needed>         <custom_php_install_command>clamav_install_command();</custom_php_install_command>         <custom_php_deinstall_command>clamav_deinstall_command();</custom_php_deinstall_command>         <custom_delete_php_command>sync_package_clamav();</custom_delete_php_command>         <custom_php_resync_config_command>sync_package_clamav();</custom_php_resync_config_command>         <custom_add_php_command>sync_package_clamav();</custom_add_php_command></packagegui> clamav.inc function sync_package_clamav() {         conf_mount_rw();         config_lock();         global $config;         $start = "/usr/local/sbin/clamd &\n";         $stop  = "/usr/bin/killall clamd\n" .         "sleep 2";         write_rcfile(array(                           "file" => "clamav.sh",                           "start" => $start,                           "stop" =>  $stop                           )                     );         conf_mount_ro();         config_unlock();         mwexec("killall -HUP cron");         mwexec("/usr/local/etc/rc.d/clamav.sh stop");         mwexec("/usr/local/etc/rc.d/clamav.sh start"); } function clamav_install_command() {         global $config, $g;         mwexec ("mkdir -p /var/db/clamav");         mwexec ("/usr/local/bin/freshclam");         sync_package_clamav(); } function clamav_deinstall_command() {         global $config, $g;         conf_mount_rw();         unlink_if_exists("/usr/local/etc/rc.d/clamav.sh");         unlink_if_exists("/var/db/clamav/daily.cvd");         unlink_if_exists("/var/db/clamav/main.cvd");         unlink_if_exists("/var/db/clamav");         conf_mount_ro(); } ?>
  • Command Line package installation

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    D
    and this command line wiil not work? php pkg_mgr_install.php?id=packagename
  • SpamD - add to whitelist working ?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    S
    Yep, thats about it in a nutshell.
  • Spamd - Add spam trap E-mail address: + nextMTA

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    @Aderium: Add spam trap E-mail address: if I add a spamtrap email called spamtrap@mydomain.com do I also need to create such user in my email server ? No, basically if a email address is the to: address then SpamD knowns to add this servers IP to the trapped database and then further connections from that mail server will be trapped in a great tarpit which looks like a 110 baud modem communication, wasting the cpu cycles of the mail server in question.  It's neat. @Aderium: nextMTA my internal ip address for mailserver is 10.1.10.10  is this the IP I would add to nextMTA ? Yep.
  • SpamD outlook button

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H
    Install http://pfsense.com/~sullrich/SpamDOutlookAlpha/SpamD.msi . It will add the outlook plugin. You also need to have SpamD package installed at your pfSense of course.
  • Might I suggest breaking out the packages to their own directories

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    B
    @ronnieredd: Excuse me? Why am I making you click dozens of forums? Did I do something wrong? If so, I'm sorry. Please do elaborate. 13 packages plus the existing dozen or so forums makes for dozens of forums.  I'm old enough to remember and use BBS's, yet I still prefer email - I can sort and filter my inbox based on what I choose to read.  Which means more time spent on email worth replying to.  More forums split the attention the developers (who are still the primary support - although a few souls have certainly stepped up and chipped in on the support from) leaving us with less time to write code.  Until a package becomes enough of a nuisance filling the existing packages forum, it's really not worth splitting it out. –Bill PS. wut sullrich and hoba said
  • Variables for spamd

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    S
    %A expands to the IP in the blacklist. Since each blacklist is added individually then you know what database url to insert for each response. I couldn't locate any other variables in http://www.openbsd.org/cgi-bin/man.cgi?query=spamd.conf&sektion=5 but if you come across any others, please let me know.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.