Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    P
    Hi Andrew, thanks for the tip. I forgot reply here. In our case, the problem was the hardware. Since 2013 I use the same hardware an Athlon LE-1620(1 Core) with 2GB. Some months ago, we created an app with many HAProxy rules and the access is growing. We bought one fanless with Intel J6426 and 8GB and now it´s work fine.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    @NRgia said in Suricata on Pfsense: @bmeeks Thank you for what you did for Snort or Suricata. I'm not sure what you want me to do on Redmine, due to is a bug tracker. My question is for Product Management, which I will ask it here to be public: What is the plan for these 2 packages, Suricata and Snort? Thank you Yes, Redmine is for both bug reports and feature requests. Asking for the Suricata binary to be updated to the latest 7.0.11 version from upstream is a legitimate Redmine request. I would suggest simply asking for the binary version update instead of asking about future Netgate strategy (such as the support plans for the packages). Strategy discussions typically don't get very far because they deal with proprietary information or plans that a company may not want to publicly discuss. Redmine is where the Netgate developer team tracks all the code changes they make for pfSense. They will see Redmine reports much quicker than a forum post.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    dennypageD
    @Leon-Straathof Data retention settings are handled inside of ntopng. Documentation here. Pay attention to the RRD note. Also, if you've turned on some of the slice and dice time series information (is off by default), I'd suggest turning them back off. These balloon the storage requirements and are of little actual use.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG
    @jeremyc311 said in pfBlockerNG-devel 3.2.8 service pfb_dnsbl don't start: I’m surprised to see in my logs only one blocked IP, which is related to my TrueNAS I'll decode this one : @jeremyc311 said in pfBlockerNG-devel 3.2.8 service pfb_dnsbl don't start: Aug 5 09:01:14,1770008712,bxe1,LAN,block,4,17,UDP,192.168.2.13,116.147.64.181,51765,51413,out,Unk,pfB_PRI1_v4,116.146.0.0/15,ET_Block_v4,Unknown,truenasr740,null,+ Traffic, coming into LAN, from a LAN device (192.168.2.13 = your TrueNAS) going to a Chinise ( 116.147.64.181 ) Brazilian ( 177.72.195.114 - = next line ) was blocked by the "pfB_PRI1_v4" list. That's probably good thing ? ( ! ). Up to you to discover why your NAS should initiate connections to these countries. A NAS can go outside for maintenance purposes, for example to look for updates of it's system. These could be located anywhere of course. The GeoIP IP created a rule for you. How and where do you use that this rule ?
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    494 Topics
    3k Posts
    jimpJ
    ACME pkg v1.0 is rolling out shortly for pfSense Plus 25.07, 24.11, and CE 2.8.0. It may be a while before it shows up depending on build times. Bug fixes/changes: Synchronized with upstream acme.sh version 3.1.2 (master branch) Various upstream bug fixes for DNS providers Removed deprecated OCSP stapling options https://redmine.pfsense.org/issues/16195 Fixed a bug with nsupdate and challenge aliases https://redmine.pfsense.org/issues/15061 Added initial support for custom ACME servers Add servers on the General Settings tab. Note: This feature has undergone basic testing, however, there is no way to know if it will work against any custom ACME server, and there is no way for the package to know which validation methods are supported by an ACME server. Use at own risk. Test before deployment. https://redmine.pfsense.org/issues/9833 Existing Provider Changes: Gandi LiveDNS has deprecated API keys and now uses a Personal Access Token (PAT). Configure the new PAT option to ensure future updates work. https://redmine.pfsense.org/issues/16294 Active24 changed from a single Token to an API Key + API Secret and must be reconfigured before use. Selectel API version v1 is deprecated, but still available as a new option, along with new API v2 options. Must be reconfigured before use. New DNS Providers: Beget.com EdgeCenter.ru FreeMyIP.com HE.net DDNS Mijn.host OpenProvider via REST API Spaceship Technitium ZoneEdit Note: The change from 0.9 to 1.0 does not reflect any particular significant change in the package, but it has been stable for so long that keeping its version number below zero no longer made sense.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    595 Posts
    E
    Updated CE 2.7.2 to 1.86.2_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.2_1.pkg Freshports
  • Discussions about WireGuard

    693 Topics
    4k Posts
    lvrmscL
    Since my upgrade to 25.07-RELEASE (amd64) built on Tue Jul 22 22:24:00 CEST 2025 FreeBSD 15.0-CURRENT, on one end of my most important tunnel, the tunnel still works fine, but the pfSense GUI keeps reporting the service as stopped. I had to remove its monitoring from the Service Watchdog which was also trying to start it, without success. Yet the trafic flows correctly. I'm holding off upgrading my other boxes. Is there something I could do to help diagnose?
  • NUT Driver DummyUPS Device File

    1
    0 Votes
    1 Posts
    154 Views
    No one has replied
  • FreeRadius + Captive Portal "Amount of Time" Problem

    17
    0 Votes
    17 Posts
    3k Views
    GertjanG
    @mustafa-azzam said in FreeRadius + Captive Portal "Amount of Time" Problem: But I have another question now .. when radius is running, the command (radius -X) will not run? Radius is a process you can see as a "server process". Golden rule : on one and the same system, you can have on ONE server process that listens to a determined port. So, if you launch "FreeRadius" using the pfSense GUI, you have a radius process runnin. Example, right now, on my pfSense : [2.4.4-RELEASE][admin@pfsense.brit-hotel-fumel.net]/root: ps ax | grep radius 83839 - Is 0:18.74 /usr/local/sbin/radiusd 21455 0 S+ 0:00.00 grep radius As you know, it's easy to check what ports it's using. When I launch another, second radius process, it will bail out.
  • gwled using high amounts of CPU on APU2

    1
    1 Votes
    1 Posts
    313 Views
    No one has replied
  • Squid & Squid Guard block pages

    2
    0 Votes
    2 Posts
    345 Views
    KOMK
    No. This is just how it is for https connections.
  • Python client library for FauxAPI available on PyPi

    1
    0 Votes
    1 Posts
    447 Views
    No one has replied
  • Avahi - OpenVPN missing from deny interfaces

    7
    0 Votes
    7 Posts
    1k Views
    J
    @grimson Thanks! Didn't know about that widget... I've added it to my dashboard :) Some sort of built-in alerting would be good though. I just found this custom script another user wrote to alert on available system and package updates https://forum.netgate.com/topic/137707/auto-update-check-checks-for-updates-to-base-system-packages-and-sends-email-alerts
  • OpenBGPd not able to use prefix-set

    4
    0 Votes
    4 Posts
    577 Views
    Y
    @jimp said in OpenBGPd not able to use prefix-set: I can't remember if support for that is in FRR, but OpenBGPD is pretty much a dead end these days on FreeBSD (and especially pfSense). More than likely what you want to do can be done without much more effort on FRR. Thanks for the suggestions, I am new to FRR and looks really interesting, will for sure explore this in testing and see if we can make the transition. @biggsy said in OpenBGPd not able to use prefix-set: From what I can find prefix-set was introduced with OpenBSD 6.3 (released in April 2018). The FreeBSD version is old compared to the one in OpenBSD. Seem you are correct and that OpenBGPd on freebsd is far outdated and without the new prefix-set features :(
  • i need something like fail2ban do on linux on pfsense or backend servers

    6
    0 Votes
    6 Posts
    761 Views
    L
    @nogbadthebad said in i need something like fail2ban do on linux on pfsense or backend servers: e the backend servers running any form of BSD, look here if they are:- thanks for reply!
  • How to specify a non-standard mysql-Port in the Banyard2 configuration?

    1
    0 Votes
    1 Posts
    136 Views
    No one has replied
  • Package unavailable

    3
    0 Votes
    3 Posts
    637 Views
    jimpJ
    The doc I'm linking is for upgrade troubleshooting but since upgrades and packages both use the same mechanism to pull info, this section is relevant to figuring out why you can't see packages, too: https://docs.netgate.com/pfsense/en/latest/install/upgrade-troubleshooting.html#force-pkg-metadata-update
  • What is the status of ARPWATCH package?

    1
    0 Votes
    1 Posts
    150 Views
    No one has replied
  • [arpwatch package] Ignore VRRP/CARP traffic

    1
    2 Votes
    1 Posts
    352 Views
    No one has replied
  • LCDProc multiple instances after packages restart

    10
    0 Votes
    10 Posts
    1k Views
    fabricioguzzyF
    @stephenw10 said in LCDProc multiple instances after packages restart: Steve I will give it a try.. Thanks Much Steve!! Fabricio.
  • Mailscanner + spamassassin + clamav package

    313
    0 Votes
    313 Posts
    309k Views
    D
    @marcelloc Hi Marcelloc, i have postfix and mailscanner running on pfsense 2.4.4-p1, i got the following warnings: MailScanner[64731]: Clamd::ERROR:: UNKNOWN CLAMD RETURN ./lstat() failed: Permission denied. ERROR :: /var/spool/MailScanner/incoming/64731 Permissions looks fine, i did chown -R postfix:postfix /var/spool/MailScanner/incoming/, also chmod -R 6666 to the same folder. Runas user on MailScanner.conf and clamd.conf is postfix. Also mailscanner logs display syntax errors: Mar 6 16:09:51 pfsense2 MailScanner[56749]: Syntax error(s) in configuration file: Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "deliversuspiciouspdf" at line 93 Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "pdfidcommand" at line 84 Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "pdfidtimeout" at line 87 Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "scanpdf" at line 90 Mar 6 16:09:51 pfsense2 MailScanner[56749]: Warning: syntax errors in /usr/local/etc/MailScanner/MailScanner.conf. Please Help.
  • Sarg package for pfsense

    467
    0 Votes
    467 Posts
    573k Views
    Y
    @marcelloc Hello, Marcelo: Do you know how to install SARG in Hello, Marcelo: Do you know how to install SARG in pfsense 2.4.4, FreeBSD 11.2-RELEASE-p3 ? Thanks, Yosvany
  • Not able to download Snort Signature on Pfsense

    6
    0 Votes
    6 Posts
    1k Views
    bmeeksB
    You must have a valid Oinkcode subscription code. You can have either a free registered code or a paid subscription code. You must obtain the code from the Snort.org web site. Next, if you are running any type of RAM disk configuration on your firewall, make sure you have at least 256 MB of free space in the /tmp directory (and preferably up to 512 MB free). Snort needs available free disk space to download the rules tarballs and unpack them during the update process. Running out of space on /tmp will cause all kinds of weird errors. Look at the pfSense system log to see if any errors show up there related to disk space. P.S. -- the only way to tell if disk space was an issue is to review the system log. When the update process finishes (either successfully or with a failure), it will clean up behind itself and delete the files and sub-directories it created in /tmp. So simply looking at the dashboard disk space widget will not reveal the problem.
  • Secure logging to external server

    3
    0 Votes
    3 Posts
    527 Views
    bmeeksB
    @pipetennathan said in Secure logging to external server: Incase anyone else is stuck on this, I found the solution. Posted it here: https://forum.netgate.com/topic/136998/how-to-send-snort-alert-logs-to-graylog-without-barnyard2/6 This is a great solution as Barnyard2 has not been well supported in recent years by its developer. You could almost call it "dead" in a manner of speaking. It is likely that at some point down the road Barnyard2 will be pulled from the Snort and Suricata packages.
  • Snort blocking all torrents

    10
    0 Votes
    10 Posts
    4k Views
    bmeeksB
    @rango said in Snort blocking all torrents: I can try to disable Auto flow bit rule. Is it as easy as disable by the rule itself? My hardware has nothing to do with it. It's 2.4Ghz Quad core intel i5 processor with 4gb of ram able to run encryption at ~300Mbps. Without snort package it runs correct. It's snort component do it but since p2p and policy is not enabled i'm puzzled what rule or which component is doing this. If an additional auto-flowbit rule is alerting, it will show up on the ALERTS tab. But note that when in blocking mode, every Snort alert results in a corresponding block of the IP address unless that IP is in a Pass List. And a block will not "slow down" traffic, it will completely stop it. So I continue to be puzzled by your statement that Snort "slows down bandwidth to a few kb/sec". If Snort rule blocks are the issue, the traffic would completely stop: not just slow down.
  • Snort stop working

    snort
    7
    0 Votes
    7 Posts
    3k Views
    Frequency295F
    I was confused on how to do this so after I figured it out I thought I would share. Click Services, Snort Edit the non functional snort interface e Click %Interface% Rules Click the drop down for Category: and choose GPLv2_community.rules Wait for it to load and disable x Sid: 49090 SERVER-SAMBA at the bottom of the page Save & Apply Then back on the Snort Interfaces tab you should now be able to start x snort on the Interface
  • Is it possible to combine OTP and LDAP authentication with FreeRadius ?

    1
    0 Votes
    1 Posts
    241 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.