Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    I
    @andrew_cb said in haproxy 0.63_2 weird behavior, edits not working: @iSagen @TheCyborgWeasel The issue is likely the same as in https://forum.netgate.com/topic/178348/haproxy-backend-port-changes-are-not-applied/ Try adding load-server-state-from-file none to the Advanced Settings > Backend pass thru section of each backend. Great! I will do this.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    @NRgia said in Suricata on Pfsense: @bmeeks Thank you for what you did for Snort or Suricata. I'm not sure what you want me to do on Redmine, due to is a bug tracker. My question is for Product Management, which I will ask it here to be public: What is the plan for these 2 packages, Suricata and Snort? Thank you Yes, Redmine is for both bug reports and feature requests. Asking for the Suricata binary to be updated to the latest 7.0.11 version from upstream is a legitimate Redmine request. I would suggest simply asking for the binary version update instead of asking about future Netgate strategy (such as the support plans for the packages). Strategy discussions typically don't get very far because they deal with proprietary information or plans that a company may not want to publicly discuss. Redmine is where the Netgate developer team tracks all the code changes they make for pfSense. They will see Redmine reports much quicker than a forum post.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    dennypageD
    @Leon-Straathof Data retention settings are handled inside of ntopng. Documentation here. Pay attention to the RRD note. Also, if you've turned on some of the slice and dice time series information (is off by default), I'd suggest turning them back off. These balloon the storage requirements and are of little actual use.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG
    @jeremyc311 said in pfBlockerNG-devel 3.2.8 service pfb_dnsbl don't start: I’m surprised to see in my logs only one blocked IP, which is related to my TrueNAS I'll decode this one : @jeremyc311 said in pfBlockerNG-devel 3.2.8 service pfb_dnsbl don't start: Aug 5 09:01:14,1770008712,bxe1,LAN,block,4,17,UDP,192.168.2.13,116.147.64.181,51765,51413,out,Unk,pfB_PRI1_v4,116.146.0.0/15,ET_Block_v4,Unknown,truenasr740,null,+ Traffic, coming into LAN, from a LAN device (192.168.2.13 = your TrueNAS) going to a Chinise ( 116.147.64.181 ) Brazilian ( 177.72.195.114 - = next line ) was blocked by the "pfB_PRI1_v4" list. That's probably good thing ? ( ! ). Up to you to discover why your NAS should initiate connections to these countries. A NAS can go outside for maintenance purposes, for example to look for updates of it's system. These could be located anywhere of course. The GeoIP IP created a rule for you. How and where do you use that this rule ?
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    495 Topics
    3k Posts
    M
    @jwt said in updating to acme 1.0 breaks system beyond repair: need to restore from backup: installed or upgraded? 2.7.2 was installed first from iso then upgraded to 2.8 then config restored - that resolved the issue. @jwt said in updating to acme 1.0 breaks system beyond repair: need to restore from backup: more details here would be good. no details - unfortunately installer doesn't provide any logs or troubleshooting info, except "unable to contact netgate servers" during install. Despite same PPPoE username and password specified in the initial prompt as used during normal operations.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    595 Posts
    E
    Updated CE 2.7.2 to 1.86.2_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.2_1.pkg Freshports
  • Discussions about WireGuard

    693 Topics
    4k Posts
    lvrmscL
    Since my upgrade to 25.07-RELEASE (amd64) built on Tue Jul 22 22:24:00 CEST 2025 FreeBSD 15.0-CURRENT, on one end of my most important tunnel, the tunnel still works fine, but the pfSense GUI keeps reporting the service as stopped. I had to remove its monitoring from the Service Watchdog which was also trying to start it, without success. Yet the trafic flows correctly. I'm holding off upgrading my other boxes. Is there something I could do to help diagnose?
  • Dansguardian access to /var/log

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    L
    well, my /var/log/dansguardian directory is owned by clamav and in group nobody same for the access.log file.. Check dansguardian is running as clamav I guess.
  • Squid2 old bug not resolve

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Z
    –BUMP-- Does anyone know how to fix this?
  • Dashboard gone after deinstall of Snort

    Locked
    17
    0 Votes
    17 Posts
    5k Views
    bmeeksB
    Updated to reflect push of Snort Dashboard Widget ver 0.3.4 A new version of the Snort Dashboard Widget will hopefully go out soon is now out.  The new version is 0.3.4.  If you have the Snort Dashboard Widget installed, you most definitely want to update it to this latest version! I just discovered a rather nasty little bug that causes the Snort Dashboard Widget to crash the package startup for Snort upon a reboot of the firewall.  It only shows up when the widget is installed.  I have tested the fix for this and it works.  I inadvertently "included" an incorrect include file as part of the uninstall routine I added for the widget… :-[ Bill
  • Avahi not working as expected.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Lightsquid - Time spent on a website?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    N
    And perhaps SARG package can offer you some more specific information but you have to check this by yourself because I don't have any experience with SARG.
  • Radius user name case sensitive sensitivity

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    N
    There is some dialogue on freeradius mailing lists: http://lists.freeradius.org/pipermail/freeradius-users/2013-April/066212.html Alan Dekok is one of the developers of freeradius. He is an absolute expert in freeradius but - in my opinion - he is not very polite when posting on the list. As far as I understand him you could add something like the following in "../raddb/policy.conf" if (User-Password) { update request { User-Password := "%{tolower:%{User-Password}}" } } Perhaps you cann follow this conversation and test and if you found a solution post it here that we can implement this into GUI.
  • I have problems with sqlite3

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    The command you run only downloads the sqlite program/libraries, it does not update the PHP module. Give a 2.1 snapshot a try, it should have a more up-to-date PHP library for sqlite.
  • How to do unified reports?

    Locked
    1
    0 Votes
    1 Posts
    779 Views
    No one has replied
  • Pfsense embedded with snort and squid

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    bmeeksB
    @costasppc: Snort and Squid are not recommended in embedded installations. You will have memory hogs. Also Squid needs disk space for caching, which is not much in CF card installations. Best regards Kostas I agree for Snort.  It can easily consume more than 1 GB of RAM just by itself with a moderate rule set.  I've had some 1 GB RAM virtual machines used in my Snort testing start swapping out to disk with Snort and a full set of rules running.
  • SNORT WISH LIST!!

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    S
    Quoted Bill for the Open Issues. Wanted to seperate the two threads :) @bmeeks: Folks: I think we may be narrowing down the list of open issues in the current Snort package version 2.5.6.  Here are items that I am aware of still open.  Actually I think these are all holdovers from the 2.5.5 package.  I have working fixes for these in my current test environment.  I just want to be sure I've caught everything major before I push out a 2.5.7 package update. OPEN ISSUES 1.  Snort not saving edits to the Rules Update and Remove Blocked Offenders cron jobs. 2.  Snapshot updates on 2.1-BETA systems do not fully complete the Snort rules update post-upgrade and Snort does not start until a manual rules update is performed. 3.  Snort not auto-starting after a package reinstall with prior saved settings. Did I miss any big ones in my list?  I wanted to double-check and see if anything else was lurking out there before pushing another update. Bill
  • PhpSysInfo

    Locked
    18
    0 Votes
    18 Posts
    7k Views
    T
    Same problem I just had.. Not sure why it failing.. Will look at something and get back to you later.
  • 20th april snaps, squid issue

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    X
    can some1 give me commands to run to output the firewall rules in normal condition and when traffic stops, mayb it will provide more info
  • Snort 2.9.4.1 pkg version 2.5.6 – Change Log

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    Again, thank you for all your hard work and bug fixing! Updating from old version to the new one worked (again) without any problems!
  • Squidguard Success on pfsense 2.01

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    F
    Thx alot for the tip, I'm going to try this. I was going crazy no being able to install squidguard without crashing pfsense. I just tried this and it works with 2.0.3 !
  • Siproxd Update

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    R
    Hi! I have had big problems with my siproxd but your guide has helped alot. The problem I had were that the state between my firewall and my sip provider kept dropping. After I set the rule up that you suggested it worked much better and the state help up for some days. But this morning it was down when I came to work. I have 6 phones which are all registered in siproxd's interface. I have setup the rule as I think you did: on the Wan side the sip provider is set a source and my wan adress on the destination, port 5060 over TCP/UDP. Are there anything I can setup for forcing the state not to go down, much like a ping can keep an VPN connection up. As of now from what I can understand it keeps up as long as possible but nothing stops it from going down if the resources are needed elsewhere. Perhaps there is a way to get the state up again if it goes down? The only way that I found to get the state up again is to make an outgoing call from one of the phones. Hope for some help. Cheers! //Peter
  • Squid Filter

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    marcellocM
    @nathanpinotti: There's a VPN rule allowing all traffic to anywhere. Could it mess my LAN rule up? Not at all. Lan traffic pass by lan rules and floating tab, not vpn interface.
  • How to dansguardian auth with ldap

    Locked
    15
    0 Votes
    15 Posts
    6k Views
    marcellocM
    web request –> nat(80 redirect to 8080) = transparent proxy
  • Snort 2.9.4.1 pkg v. 2.5.5 Issue(s)

    Locked
    111
    0 Votes
    111 Posts
    30k Views
    K
    @sronsen: This error message almost always means you have mixed 32-bit and 64-bit libraries on the system.  These "unsupported layout" errors have happened before for many other packages besides just Snort, and each time it's caused by having a mix of 32-bit and 64-bit stuff on a system.  In particular this error can happen when 64-bit libs wind up on a 32-bit box.  I can't tell you how this might have happened, but I'm pretty sure that's what is wrong now. I had to reformat the drive and reinstall pfSense, but I finally got Snort working.  If I could only figure out why the pfSense installation won't work from a USB CDROM, I wouldn't be so put off, but the installation asks for a mount device and fails when a valid one is entered.  If I plug in a SATA CDROM drive with the same disc, it just installs to the proper drive without asking me anything.  This is on a rack-mounted PC w/o any external bays, so I have to unmount the PC and open it up to rerun the installation.  Ugh!  I think I'll pass on pfSebse and Snort updates for the next year. I installed my current config from usb. My 1u system has no optical and I didnt have a usb cdrom. Mine installed just fine using the usb install method.. Maybe try that instead of cdrom?
  • Bandwithd with windows DNS and DHCp

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    A
    After the revers zone issue was corrected, everything works fine now. Thanks for the help.
  • Multiple pfsenses and Snort updates?

    Locked
    13
    0 Votes
    13 Posts
    3k Views
    S
    It could be the load on the specific server if it located in two different places :)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.