Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Packages and XMLRPC Sync

    11
    0 Votes
    11 Posts
    16k Views
    D
    @marcelloc: Ever considered splitting this to a separate inc and getting it included into core? I find your code in lots of packages, fixing the same comment typos and code style everywhere. It's most completely identical otherwise, except for some customized log messages… Sounds really like a waste of time to maintain the code in loads of places. In some packages, most of the PHP code is the copy-paste of XMLRPC sync. Example - 2/3 of the actual code are XMLRPC sync.
  • Freeradius not starting automaticly when booting up PFSense

    5
    0 Votes
    5 Posts
    2k Views
    M
    Okay, clear. The package FreeRADIUS is not starting at boot, but is giving the error above, when I manually start it, it works.
  • Instructions for Asterisk package?

    1
    0 Votes
    1 Posts
    557 Views
    No one has replied
  • Zabbix 2 Proxy compatibility

    1
    0 Votes
    1 Posts
    747 Views
    No one has replied
  • MOVED: Filter correctly HTTPS sites using squid3

    Locked
    1
    0 Votes
    1 Posts
    434 Views
    No one has replied
  • Clamav not working in 2.2.4 - can it be fixed in setting?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: Snort Pass White List not working correctly?

    Locked
    1
    0 Votes
    1 Posts
    512 Views
    No one has replied
  • [solved]bacula - webgui config - bug?

    8
    0 Votes
    8 Posts
    2k Views
    P
    package upgraded thank you
  • [nanobsd] Not enough space

    2
    0 Votes
    2 Posts
    3k Views
    P
    System->Advanced, Miscellaneous tab, RAM Disk Settings. Increase the size of /var Keep in mind the amount of real memory you have in your system - do not increase /var so much that all your real memory is consumed.
  • Unable to install packages. Stop at extracting

    2
    0 Votes
    2 Posts
    731 Views
    D
    Go to Diagnostics - NanoBSD and make it permanently read-write.
  • MOVED: Reverse proxy limits session traffic for RDS Gateway

    Locked
    1
    0 Votes
    1 Posts
    478 Views
    No one has replied
  • MOVED: Transparent reverse proxy by HAProxy in 3-Legs scheme

    Locked
    1
    0 Votes
    1 Posts
    514 Views
    No one has replied
  • 0 Votes
    1 Posts
    379 Views
    No one has replied
  • Snort 3.2.6 not saving alert or block list when pfsense is rebooted

    3
    0 Votes
    3 Posts
    846 Views
    F
    Ok my bad then.
  • Snort feature request OPTx renamed to name assigned in the interface

    1
    0 Votes
    1 Posts
    505 Views
    No one has replied
  • Problem with Postfix forwarder

    13
    0 Votes
    13 Posts
    3k Views
    A
    @biggsy: Get rid of mailscanner/spamassassin to start.  Add back in once you have postfix working.  (You may find that you don't need anything more than postfix.) You didn't follow the Quick Start Guide exactly because you had LAN Net as the listen interface.  Now that postfix is listening on WAN Address, you need to have a way for remote mail servers to connect and send mail from the Internet through your WAN interface. Do you have a real domain?  Do you have a DNS MX record that points to your WAN Address?  Without those, it is going to be very difficult to help you. Please do not post in two threads.  That doesn't encourage people to try and help you. biggsy,  I have DNS MX, where I put the DNS MX?
  • Nagios/NRPE Monitoring of Internal Private Network Hosts [RESOLVED]

    3
    0 Votes
    3 Posts
    3k Views
    D
    Hi, Now resolved. There were quite a few things at play here. First was the use of SSL in the original check_nrpe from our external nagios server, and not in the second nrpe fired off from the firewall. Then there was the lack of the firewalls IP in allowed hosts. Then there was selinux on the private hosts that kept denying nrpe bind to our custom port. It also doesnt help that the private hosts do not have internet outbound for security purposes. So troubleshooting and downloading packages etc, very time consuming. Thanks.
  • 2.2.3 Avahi Exits after Reboot - Have to Hit "Save" to Get Running

    19
    0 Votes
    19 Posts
    3k Views
    cwagzC
    I went ahead and submitted a bug on this issue after testing again in a brand new clean VM. https://redmine.pfsense.org/issues/4932
  • Darkstat will not start

    12
    0 Votes
    12 Posts
    4k Views
    D
    Upgrade pfSense to 2.2.x to get maintained packages.
  • Postfix Forward have get crash report.

    2
    0 Votes
    2 Posts
    950 Views
    D
    There's about ~40 pages thread about postfix. Good morning. ;) https://forum.pfsense.org/index.php?topic=40622.0
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.