Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    stephenw10S
    I assume you have tried reinstalling both?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    M
    Hi, I had a problem with my home network today, so I checked pfsense and discovered that suricata had blocked the wan ip. After some tests and triggering some suricata alerts, the wan ip was blocked. I restarted pfsense and ran some more tests, but the problem no longer occurred. I then checked the wan interface settings and indeed the ip list does not include the wan ip, both now that it's working and before, when it was blocked. I'm using pfsense 2.8.0 and suricata 7.0.8_2. I use PPPoE to access the Internet.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    dennypageD
    @Leon-Straathof Data retention settings are handled inside of ntopng. Documentation here. Pay attention to the RRD note. Also, if you've turned on some of the slice and dice time series information (is off by default), I'd suggest turning them back off. These balloon the storage requirements and are of little actual use.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    J
    @LowKnee Just out of curiosity are you referring to the Database Sanity Check reporting that "these two counts should match" it the count is off by 1 (which I suspect is your case) there was a fix (manual code change) to change masterfile to mastercat in pfblolckerng.sh you want to change this change the line from s1="$(grep -cv ^${ip_placeholder2}$ ${masterfile})" to s1="$(grep -cv ^${ip_placeholder2}$ ${mastercat})" There is also an edge case if the count is greater than one, here is how that goes if in the deny directory you have say two flies (because of the list / file selection you have and they have repeat addresses file 1 has say 100 lines file 2 has say 10 lines (but those 10 lines are also in file 1, file 2 is a subset) you get two uniquely named deny files and then when the "count" is calculated on the deny directory it sees 110 entries when the "count:" is calculated on the "mastercat" file it only contains 100 entries the count doesn't match in my case the issue was caused by full list I had selected, also having an available subset lists (I had inadvertently selected one of) this causing two deny files with some of the same (overlapping data) I unselected the subset and bingo matched again, was a "my bad" selection. Edit: this applied to 25.07 (and 25.07.1) and pfblockerng 3.2.7 as it is labelled on those versions of pfSense
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    496 Topics
    3k Posts
    R
    @provels said in updating to acme 1.0 breaks system beyond repair: need to restore from backup: This same mess happened to me, even w/o Acme, going from 25.07 to *.1. Blew, reinstalled w/ Crowdsec, blew again, reinstalled, clipped all the Crowdsec info from config.xml, restored config, back to normal. Crowdsec is a great concept, but I think I'm out. I never had this issue with Crowdec before the ACME update, even with updating from 2.7 to 2.8 there was no issues. In fact after restoring from a backup after the ACME update, Crowdsec reinstalled just fine, and this was before the recent release a couple days ago that contained a fix.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    603 Posts
    W
    @totalimpact in my case I dsid not reboot the router, after I copied the new key tailscale went online.
  • Discussions about WireGuard

    697 Topics
    4k Posts
    H
    I have Wireguard setup with 3 peers. The peers are now receiving good handshakes and I looked over everything and everything looks good. However, from a laptop connected to the main FW I can take over items in the other LANs and I can get into pfSense by using the local IP instead of the public IP except for 1. Even though it looks good I cannot access anything on that LAN. I can ping the public IP but not the local. I have checked over everything I can think of and it just will not allow the traffic across. I have no idea what else to try?
  • LightSquid Issue - lightsquid_web services won't start

    1
    0 Votes
    1 Posts
    526 Views
    No one has replied
  • FreeRADIUS 3 with Active Directory Authentication and Authorization?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • SquidGuard: Blocking youtube on the Andriod app

    8
    0 Votes
    8 Posts
    11k Views
    GertjanG
    @rodgomesc: google.com -> 216.239.38.120 google.com resolves to more then one IPv4 : dig TXT +short _netblocks{,2,3}.google.com | tr ' ' '\n' | grep '^ip4:' ip4:64.233.160.0/19 ip4:66.102.0.0/20 ip4:66.249.80.0/20 ip4:72.14.192.0/18 ip4:74.125.0.0/16 ip4:108.177.8.0/21 ip4:173.194.0.0/16 ip4:209.85.128.0/17 ip4:216.58.192.0/19 ip4:216.239.32.0/19 ip4:172.217.0.0/19 ip4:172.217.32.0/20 ip4:172.217.128.0/19 ip4:172.217.160.0/20 ip4:172.217.192.0/19 ip4:108.177.96.0/19 ......
  • LCDproc: no nexcom.so ?? (pfs 2.3.5)

    3
    0 Votes
    3 Posts
    785 Views
    F
    After looking around some more, it looks like support for the Nexcom devices was added to the "generic" hd44780 driver after all: ConnectionType=lcm162 Code change: https://github.com/lcdproc/lcdproc/commit/9e80b177ffb1755e27109dd284ad568319fe4e6a#diff-b5b7491d509ceae9b603712026311903 Documentation change: https://github.com/lcdproc/lcdproc/commit/4a50059b81910d7a6f9a70791766dfd12c61bb99#diff-056b4c550c4f9828ca095124588909ed So, these Nexcom devices are supported by the base lcdproc project code. Not sure the pfSense integration package was updated, though…
  • Cannot Access NTOP

    2
    0 Votes
    2 Posts
    656 Views
    johnpozJ
    did you actually configure it and enable it?  Via the ntop settings under diag menu.
  • More Information on Package Development

    4
    0 Votes
    4 Posts
    726 Views
    P
    Well.. if you want to block/inspect traffic packets passing through pfSense, then that is not something that php will do. if you take the basic concept of pfSense it is just the php 'glue' that makes all parts work together with a nice webgui. Changing or adding new parts of that 'glue' is relatively easy. The packet processing is mostly being done by FreeBSD (the OS) and PF (the firewall). Or perhaps you would like to do something more like Snort and Suricata, and maybe create a custom 'ruleset' for one of those two with your packet inspection rules as far as they can support your intended case.. But developing on any those software parts is a entirely different thing than the usual 'pfSense package' which takes a existing binary application and wraps in into a easy to use php webgui without actually changing the binary code of the application or changing the internal flow of network packets, well a package like 'tinc' does add mesh vpn capabilities, but the 'pfSense package' just installs and configures that existing piece of software.. If your intending to go make changes in those parts then a little knowledge about script writing wont really help much. Would need some good general programming knowledge preferably in C or C++ .. its imho not something that can be learned by reading a single wiki page..
  • Mailreport and outlook.com

    3
    0 Votes
    3 Posts
    731 Views
    M
    Gertjan, thank you for your answer. Current situation is : Sending test email works with Outlook.com Alert emails (e.g. UPS events or Gateway events) are sent Mail reports are not sent Unfortunately I cannot use Postfix any more (I am leaving the company), therefore I am forced to switch to outlook.com. Furthermore : I am in China and this limits the selection of email providers I can use (Google does not work here and I already tried with pfSense, but no success). I will try to switch back to Postfix and confirm that the issue lies in the switch between the two systems.
  • Ntopng fails to restart

    1
    0 Votes
    1 Posts
    597 Views
    No one has replied
  • Zabbix log monitoring

    2
    0 Votes
    2 Posts
    1k Views
    D
    I suggest you send the logs elsewhere, the zabbix user won't have access to them locally. Regards.
  • Zabbix Proxy not starting

    3
    0 Votes
    3 Posts
    2k Views
    D
    @Beni: Hi, Have you tried to delete the pid file and the sqlite. rm /var/run/zabbix-proxy/zabbix_proxy.pid /var/db/zabbix-proxy/proxy.db Regards Beni Do this and show the proxy log, please.
  • Zabbix agent does not start after reboot

    2
    0 Votes
    2 Posts
    1k Views
    D
    Is this still happening? zabbix_agentd.sh is the rc script from pfSense. zabbix_agentd is the rc installed with the FreeBSD port.
  • Zabbix Proxy VMware Support

    2
    0 Votes
    2 Posts
    756 Views
    D
    It's all enabled now. https://github.com/pfsense/pfsense/blob/master/tools/conf/pfPorts/make.conf#L144-L162
  • Package Zabbix Proxy 3.4

    10
    0 Votes
    10 Posts
    4k Views
    D
    This was fixed with 1.0.1 version of proxy
  • HAProxy ssl verify and Android/Chrome issue

    2
    0 Votes
    2 Posts
    947 Views
    P
    https://redmine.pfsense.org/issues/8228#note-5 "Leave all these options empty"
  • Want to BLOCK IDM & uTorrent

    1
    0 Votes
    1 Posts
    735 Views
    No one has replied
  • Haproxy + Change Host Request Value

    3
    0 Votes
    3 Posts
    3k Views
    A
    Hello, thank you for your reply. I test hdr without success but this line working : sni ssl_fc_sni check-sni vhost.yourdomain.local Thank you
  • Syslog-ng stops working after logroate run

    1
    0 Votes
    1 Posts
    450 Views
    No one has replied
  • Glances

    2
    0 Votes
    2 Posts
    989 Views
    GertjanG
    Did you check how many times the word "Glances" was mentioned on this forum ? The answer is a start of a possible answer. pfSense can be instructed to make cafe, launch nukes, or sprinkle your lawn. Al you need is some time, PHP knowledge and some pfSense knowledge, and a (new) need for something. If you're missing one of more of those, you need to find someone. Did you see this forum : https://forum.pfsense.org/index.php?board=34.0
  • [SOLVED] freeradius stopped working and it won't restart

    8
    0 Votes
    8 Posts
    4k Views
    A
    radiusd -X }   # Loading module "datacounterforever" from file /usr/local/etc/raddb/mods-enabled/datacounter_acct   exec datacounterforever {         wait = yes         program = "/bin/sh /usr/local/etc/raddb/scripts/datacounter_acct.sh %{request:User-Name} forever %{request:Acct-Input-Octets} %{request:Acct-Output-Octets} %{request:Acct-Status-Type} %{request:Acct-Session-Id}"         shell_escape = yes   } /usr/local/etc/raddb/mods-enabled/counter[2]: Failed to link to module 'rlm_counter': Shared object "libgdbm.so.4" not found, required by "rlm_counter.so" error, radius not start. (freeradius3) help me please
  • Squid, pfSense 2.4.2p1 and unable to configure SSL Filtering

    3
    0 Votes
    3 Posts
    1k Views
    ChrisLynchC
    Yes, I see that X under the Internal column.  And that would make sense as the firewall needs to create the certificate for the SSL/TLS endpoint in order to filter SSL/TLS traffic.  Sorry for the confusion on my part.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.