Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    I
    @andrew_cb said in haproxy 0.63_2 weird behavior, edits not working: @iSagen @TheCyborgWeasel The issue is likely the same as in https://forum.netgate.com/topic/178348/haproxy-backend-port-changes-are-not-applied/ Try adding load-server-state-from-file none to the Advanced Settings > Backend pass thru section of each backend. Great! I will do this.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    @NRgia said in Suricata on Pfsense: @bmeeks Thank you for what you did for Snort or Suricata. I'm not sure what you want me to do on Redmine, due to is a bug tracker. My question is for Product Management, which I will ask it here to be public: What is the plan for these 2 packages, Suricata and Snort? Thank you Yes, Redmine is for both bug reports and feature requests. Asking for the Suricata binary to be updated to the latest 7.0.11 version from upstream is a legitimate Redmine request. I would suggest simply asking for the binary version update instead of asking about future Netgate strategy (such as the support plans for the packages). Strategy discussions typically don't get very far because they deal with proprietary information or plans that a company may not want to publicly discuss. Redmine is where the Netgate developer team tracks all the code changes they make for pfSense. They will see Redmine reports much quicker than a forum post.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    dennypageD
    @Leon-Straathof Data retention settings are handled inside of ntopng. Documentation here. Pay attention to the RRD note. Also, if you've turned on some of the slice and dice time series information (is off by default), I'd suggest turning them back off. These balloon the storage requirements and are of little actual use.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    J
    @keyser That is normal - the download of the GeoIP asn data is randomized (once when the system is setup) Why it runs at different times on different boxes. When you schedule pfblocker to run at 2:00 all the ASN files are then already local and not downloaded again. Put it another way, the older version would download every ASN file, every time, pfblocker ran an update via cron. so if you ran pfblocker hourly, you would be downloading ASN data file for your selected ASNs every time it ran the cron job ran. Now the download only happens once (at the preselected randomized time) and you get every ASN available ) You can run the pfblolcker cron updates as many times as you like and they will not download anything (Geo /ASN) related. it will just update those lists from the local data. You can even add a "new" ASN to your selection, and it will already be available. on a 2100 this ASN database download (as you noted is logged in the extras.log) takes all of 15 seconds here. I would likely never see a CPU hit specifically related to this download. Download Process Starting [ 08/14/25 07:45:01 ] /usr/local/share/GeoIP/asn.mmdb 200 OK /usr/local/share/GeoIP/asn.csv.gz 200 OK ASN Lookup Table has been updated [ 08/14/25 07:45:05 ] Download Process Ended [ 08/14/25 07:45:16 ]
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    495 Topics
    3k Posts
    M
    @jimp said in updating to acme 1.0 breaks system beyond repair: need to restore from backup: While we do not deliberately break such configurations, if you install a package from unsupported repositories and they replace or mess with base system dependencies, then there is no telling what will break over time like this. Understood - thank you very much for the clarification. I need crowdsec though... and there are no official support yet. I don't mind reinstalling the system, it takes reasonable amount of time, unless I found netinstaller fails to connect to my pppoe which tripled the time of restoration. For that I have no explanation and it is obviously not related to the dependencies, but that's offtopic in this thread.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    595 Posts
    E
    Updated CE 2.7.2 to 1.86.2_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.2_1.pkg Freshports
  • Discussions about WireGuard

    693 Topics
    4k Posts
    lvrmscL
    Strangely enough, checking the system 4 days later, I now see that Wireguard service is reported running! The last thing I did 4 days ago was to disable Wireguard service monitoring by the Service Watchdog. Anyway, even when it was reported stopped at first, 4 days ago, the tunnels were working flawlessly. Very strange. I will keep an eye on it.
  • Is there a Bacula howto?

    5
    0 Votes
    5 Posts
    517 Views
    V
    So sorry, I asked in the wrong forum.
  • Zabbix Proxy?

    1
    0 Votes
    1 Posts
    405 Views
    No one has replied
  • After the last update pfsense 2.4.4 p3

    Locked
    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    @jimp said in After the last update pfsense 2.4.4 p3: pf2ad Maybe he didn't pay his 60.00 € the guy wants for that package... That site is OLD... shoot it still says pfsense is owned by Electric Sheep Fencing ;)
  • This topic is deleted!

    0
    0 Votes
    0 Posts
    12 Views
    No one has replied
  • softflowd: multiple collectors

    1
    1 Votes
    1 Posts
    259 Views
    No one has replied
  • Snort and SquidGuard issues

    1
    0 Votes
    1 Posts
    316 Views
    No one has replied
  • 0 Votes
    9 Posts
    675 Views
    K
    I think I figured this out by installing pfsense in virtualbox VM, configuring it and then comparing pkg info commands between it and my live system. The live system always had a warning about pkg version 35 is newer than installed database 34 at the top, and there were a few other packages that were newer versions than the stock 2.4.4p3 system. The pkg version warning did not sit pretty with me so thats when I decided to blow away this new install and start over. After I wiped the drive and did a reinstall, I reapplied my config file. The interfaces were different from the old system (re0, igb0). Therefore until I got to the physical console and fixed it, the packages never installed because it could not contact the internet. The second time around I edited my xml config file in notepad++ and altered the WAN and LAN with the proper igb0 and igb1 designations as they are on the new box. Next wipe I got it back up and restored config. This time since the interfaces were correct, when it restarted it had internet access and the system was able to automatically reach out and download all of the packages. At the top of the web ui in a yellow banner it said to hold off on any changes while packages are reinstalled from the internet. (This is the behavior I noticed in my VirtualBox install test). The only one I had to manually install was bandwidthd (it was in the menu but the package wasn't installed). But after giving the system time installing all of these packages, I was able to install the Unifi controller using the github script. I then pkg lock these three packages: boost-libs-1.71.0_2 icu-65.1,1 mongodb34-3.4.23 I then installed the command line packages for lsof and nano, and they installed and work without issue. Nothing was downgraded or removed. System is running smoother than it ever has. I think the pkg database got messed up in the original install after importing the config, since the system was not able to contact the internet and complete the package install. There was no button in the UI to "retry" and reloading the config and just choosing package database did not seem to do anything. A clean install fixed it.
  • Pfsense 2.4.3 Freeradius 3.x ldap problem

    2
    0 Votes
    2 Posts
    633 Views
    M
    @magokbas said in Pfsense 2.4.3 Freeradius 3.x ldap problem: With the same settings as FreeRadius2, FreeRadius 3 ldap (active directory) don't work. when activate ldap is did not work sql. sql started to work after last update but ldap still does not work. This problem still persists.
  • FreeRadius - Wifi auth with PWD and TTLS

    1
    0 Votes
    1 Posts
    903 Views
    No one has replied
  • SIProxd registrations not releasing.

    1
    0 Votes
    1 Posts
    250 Views
    No one has replied
  • Snort 4.0_8

    2
    0 Votes
    2 Posts
    415 Views
    bmeeksB
    @cdx304 said in Snort 4.0_8: Snort does not want to start again .Was working fine ? Pfsense is latest 2.5 build . I assume you mean Snort 4.0_8 has been working for you and then just suddenly started not working. If so, then read on. This is almost always caused by a rule syntax error (or could be a required preprocessor is not enabled). Look in the pfSense system log and you should see a Snort error message that will tell you what's wrong. When the rules update (usually twice each week) it is entirely possible for either a rule to be published or updated and have a syntax error in it, or a rule that was previously default-disabled by the Snort team might have been changed to default-enabled by an update. If that particular rule need a preprocessor enabled that you have disabled, that can result in a startup failure. So check the pfSense system log to see why Snort is not starting. Post back here if are not able to identify the cause.
  • Antivirus on pfsense

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • Freeradius with remote mariadb server

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • What is the status of ARPWATCH package?

    10
    1 Votes
    10 Posts
    2k Views
    G
    @vw-kombi said in What is the status of ARPWATCH package?: I recently had to delete and re-create a vpn ouotbound connection, and arpwatch did not like this. In addition to the usual mesages, I am getting this with every cron execution - the interface mentioned in the email I get below does not exist anymore. It is not mentioned in the xml if I do a backup and edit either - I assume its in some sort of arpwatch database, but no amount of uninstalling and re-installing seem to rectify this email every 5 minutes : X-Cron-Env: <SHELL=/bin/sh> X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin> X-Cron-Env: <HOME=/root> X-Cron-Env: <LOGNAME=root> X-Cron-Env: <USER=root> Error: Unable to get interface "ovpnc3" statistics. I don't know anything about the inner workings of pfSense, but is it possible that this is causing an interface to become visible/invisible, and arpwatch is "just doing it's job" in alerting that a "device" has appeared on the network (and not been marked as an allowed device), disappeared, and then reappeared. Every tine the device comes back, it generates an alert, and unless there is some way to mark the MAC address as "allowed" this behaviour will never stop. Just a thought, I don't know if it has any merit.
  • [SOLVED] Bug while updating System_Patches

    7
    0 Votes
    7 Posts
    2k Views
    EveningStarNME
    @jimp Thank you, and to everyone else who replied here, too. I uninstalled v1.2_2 and installed v1..2_3, and everything worked as expected.
  • Adding to the user fields in Freeradius

    1
    0 Votes
    1 Posts
    310 Views
    No one has replied
  • Snort Rules in pfsense always failed

    4
    0 Votes
    4 Posts
    627 Views
    bmeeksB
    Not that it really should matter in terms of starting up, but you apparently have no rules selected for your LAN interface. That means Snort would not be really doing anything for you even if it started. At 10:11:19 in the log is a warning about "no text rules or IPS Policy selected for: LAN". Your Snort Subscriber Rules are also failing to download. Notice the "Server returned error code 505" message in the log at 10:10:28. The most likely cause of that is a trailing space in your Oinkcode. Retype or paste in your Oinkcode again and be sure that is no trailing space at the end and that every character is correct. So from the log, Snort appears to have started successfully. Does it still not show as running? Open a CLI (command line interface) session on the firewall either directly on the console or via an SSH connection and see what the output of this command is -- ps -ax | grep snort Do you see any running Snort processes in the output of that command? I also see a Gateway Alarm message in the log. If that happens often and if the gateway monitoring logs a "gateway down" message, that will trigger pfSense to issue a "restart all packages" command. If more than one instance of that happens in rapid succession it can result in the Snort process either getting clobbered, or sometimes, two duplicate Snort processes getting started.
  • Iperf version

    Moved
    12
    0 Votes
    12 Posts
    1k Views
    jimpJ
    That was just a cosmetic issue and is corrected in the repo, so when the next build happens, it will be fixed.
  • SquidGuard on pfSense 2.4.4: Segmentation Fault (core dumped)

    2
    0 Votes
    2 Posts
    599 Views
    KOMK
    Remove squidguard and then try to get squid working alone first. If it still dies, check the System log for anything related.
  • Possibly a broken pkg database

    1
    0 Votes
    1 Posts
    239 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.