Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    It was all CVE fixes in the PHP GUI part of the package. See the Redmine ticket here: https://redmine.pfsense.org/issues/16414.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    V
    @Gertjan Thanks for your reply – that’s also my impression. The point is: I don’t really see any lists right now that are actually “maintained” in the sense of being actively cleaned up, checked for dead domains, categorized, etc. That’s why my main interest is more about the demand: Would curated lists really be a game changer for admins? Would they be more helpful than what’s available today, or are most people already using other alternatives? If so, which ones? And from your perspective, what would be your expectation towards “community lists”? (e.g. reliability, update frequency, categories, fewer false positives?)
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    501 Topics
    3k Posts
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Discussions about the FRR Dynamic Routing package on pfSense

    295 Topics
    1k Posts
    J
    Anyone else happen to notice that when configuring BFD, if you create a peer and select a profile - after save, re-edit the peer and the Profile is not represented. It appears as "None". You have to check the raw config to determine if the profile was actually assigned to the peer. This is on 2.8.1 (all packages up to date as of the date/time of this post). UPDATE: if re-edit and save (without re-configuring the profile none to what you want) - the save will strip the profile from the peer.
  • Discussions about the Tailscale package

    90 Topics
    610 Posts
    E
    Updated CE 2.7.2 to 1.86.4_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.4_1.pkg Freshports
  • Discussions about WireGuard

    700 Topics
    4k Posts
    Bob.DigB
    @HFADmin If it is no Site2Site-VPN then you don't need any gateways in the first place... If that is true but you want to monitor the connection then you could create dummy-gateways just to ping the remote ip-addresses.
  • PfBlocker disabled pf when router was booted with no internet

    8
    0 Votes
    8 Posts
    2k Views
    T
    I was able to reproduce this on a test router, and I have posted this at: http://forum.pfsense.org/index.php/topic,42543.msg340581.html#msg340581
  • OpenVPN Client Export Settings

    5
    0 Votes
    5 Posts
    2k Views
    B
    Thank you, found it.
  • Snort update page & footer div

    6
    0 Votes
    6 Posts
    2k Views
    T
    Thanks.
  • Tuning Dan's Guadian

    3
    0 Votes
    3 Posts
    1k Views
    R
    @SoFlo1: I'm having a few of problems with DG and wondered if there wasn't a tweaking/tuning guide somewhere that works through all these issues. First, the Japanese porn weighted phrase list was triggering on all kinds of random crap - like shopping for shelves at homedepot.com. So I turn that off only to find other weighted lists that keep triggering on completely random stuff. Are there better weighted lists than what the DG package for pfSense ships with are are they just generally known to be pretty useless? Anyway, the other problem is with weighted phrases turned on, certain sites like reddit get all munged - reduced to a simple links-only kind of rendering, some graphics but no layout. The other, other problem I'm having is inline JPEGs stripped out, but not other MIME types. I'm sure this is a setting somewhere but it doesn't seem to be as obvious to find as I would have thought. I'm sure everyone's run across these and more so maybe you could just point me to a "living with dansguardian" link before I give up? Thanks. I'm fairly confident this is something to do with your configuration… been using it for years with none of these issues.
  • Squid 3.1 transparent proxy omits HTTP exceptions (PEBKAC?)

    3
    0 Votes
    3 Posts
    2k Views
    N
    MatSim, you coul have a look at the "bypass proxy" options on squid. In my environment I bypass proxy for all internal communication. If you bypass the proxy for some source/destination IPs then the pfsense firewall rules need to do the job for port 80 (http). If you do not bypass the proxy for that traffic then you must configure ACLs on squid which allow/deny that traffic on port 80 (http).
  • Snort with CARP sync

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    bmeeksB
    @jflsakfja: I see that snort sync has been added back in 2.5.8. Thank you, you just saved me a couple of months work. Many many many thanks! ;D Those thanks go to Marcelloc. ;D  He contributed the main Snort CARP Sync code.  I will be posting a Change Log with some screen shots of new stuff this weekend for the Snort 2.5.8 package. Bill
  • Varnish keeps crashing on 2.0.3-RELEASE (nanobsd)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort blocks IP despite disabled rule!

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    S
    2.5.7. I havent had the time to load the 2.5.8 yet since I am fooking busy at work! Get back to you soon Bill when I get to do that. But problems are on 2.5.7!
  • Squid

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K
    While trying to retrieve the URL: http://www.domain.com/ The following error was encountered: •Read Error The system returned: (54) Connection reset by peer …... .... For this  error you can just exclude the domain from caching it works fine..
  • Cannot get cronjob to work - scripts work when entred manually into shell

    Locked
    15
    0 Votes
    15 Posts
    6k Views
    B
    Alright!! Phil you were correct. That worked for the first script. The second one I managed to get working (somehow with the tee command). I ended up using: #!/bin/sh /usr/local/bin/curl ifconfig.me/ip|tee /tmp/vpn_external Now I am on to the final command, I have tinkered with it for about 2 hours, and I can get it to output a file, but the file only contains  {}  , usually it would have the port inside the brackets, ex. {45000}. Currently I am using the following command (the X's represent my username and password. If I enter the command into shell, it does work) I tried using the full path to both cat commands (and without) but no go: #!/bin/sh /usr/local/bin/curl -o /tmp/portforwardlist -d "user=XXXXX&pass=XXXXX&client_id=$(/bin/cat ~/.pia_config)&local_ip=$(/bin/cat /tmp/vpn_ip)" https://www.privateinternetaccess.com/vpninfo/port_forward_assignment ALMOST THERE
  • Postfix slow email delivery

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    A
    Thanks for that information. And thanks for the tip. I added that custom main.cf options. I will continue testing and see if things improve.
  • Undefined symbol error when trying to run ClamScan?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Mailreport - never sent a rrd report

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D
    @drzoidberg33: I have a similar issue - automated report never send. I am trying to do a daily report with a few rrd graphs. It works fine if I click send now but the automation doesn't work. I have also tried selecting the blank option in the "Day of the week" field but it always reverts to Sunday when I save, maybe this is the issue? Here is a screengrab of the settings for this report: [image: Screenshot%20from%202013-05-29%2016%3A53%3A25.png] Nevermind, I see where I went wrong. The hour wasn't set, I mistakenly assumed it would just send at midnight.
  • Bandwidth monitoring package

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    A
    You can install Pfflowd and have it send data to another server. Prtg is free on windows for 20 sensors/users. If you stick there add banner on your site I think you can get 20 or 30 more free sensors. The full version runs free for 30 days. Lots of data. Nfsen I think is one for linux. Look up flow collector and you will find several for linux.
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Email Report Only, No Need for System Notifications

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J
    Thanks for the information, I can't wait for that feature in 2.2.  ;D Since my email provider doesn't use the SSL authentication for the SMTP, I check the "Enable SSL/TLS Authentication" so that the box cannot send the notifications and only uncheck it if I want to send the RRD. It is like a manual sending of the graphs. But much better than manually copying each graph to paint/word processor. :D
  • Avahi install failed - Missing additional files

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    P
    Thank you jim. Everything seems to be in place and I'm installing it now.
  • Port scan blocking?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Barnyard2 wont start pfsense 2.1RC0

    Locked
    1
    0 Votes
    1 Posts
    882 Views
    No one has replied
  • HAVP Antivirus -> scan via GUI failed

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    A
    sorry for the necro post, but this issue still is around and I wanted to post my workaround. It seems pfsense is setting up clamav with a non-default location for its socks and pid file (/var/run).  The default location is /var/run/clamav.  But when the scanning program is called by the gui, it's not given the path of the config file and doesn't know about the location of the sock file.  This creates a symlink as a work around. I'm not sure if the pid file is needed, but I linked it anyway. mkdir /var/run/clamav ln -s /var/run/clamd.pid /var/run/clamav/clamd.pid ln -s /var/run/clamd.sock /var/run/clamav/clamd.sock And it now works. 2013.05.28 02:08:31 Starting scan file '/var/db'. ----------- SCAN SUMMARY ----------- Infected files: 0 Time: 4.963 sec (0 m 4 s)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.