Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    H
    We installed haproxy on Netgate 8200 device 25.07.1-RELEASE (amd64) installed acme certificates and get certificate from letsencrypt, everything ok. checked ssl offload in frontend and selected the acme generated certificate under SSL Offloading. result after Apply Changes: Errors found while starting haproxy [NOTICE] (72045) : haproxy version is 2.9.14-7c591d5 [NOTICE] (72045) : path to executable is /usr/local/sbin/haproxy [ALERT] (72045) : config : Couldn't open the ca-file '/var/etc/haproxy_test/clientca_WAN_117.pem' (No such file or directory). [ALERT] (72045) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind x.x.x.x:443' in section 'frontend' : 'ca-file' : unable to load /var/etc/haproxy_test/clientca_WAN_117.pem [ALERT] (72045) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (72045) : config : Fatal errors found in configuration. also package _devel has the same issue. on other boxes where haproxy was configured on 24.11 - upgraded to 25.07.1 its working. BUG ?? so what can we do now -bolded text we need this function. thank you all in advance
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    B
    @Greyhat I think it's useful to work with what we've got and figure something out for the (i hope) edge cases later. So for the JSON I figured you can actually use an existing suricata integration by co-opting their pipelines.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N
    @netboy Most probaly a configuration regression. You really need to dig deeper. From which pf version did you upgrade? Have you tried removing and reinstalling pfblockerng? Looking to the moon for craters with naked eye doesn't show the one that the crashed spaceship created. Use a telescope instead. FWIW, I see quite a few pfblockerng instances on 25.07.1 running with no (apparent) issues τοο
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    johnpozJ
    @netboy do you have this docker available - this is actually pretty slick. I didn't think about monitoring the one connected to my nas.. It monitors it for shutdown of the nas, but it be nice to see such info off of it. I have one behind my tv I monitor with pi I have connected, that is my ntp server as well. I keep meaning to put another pi I have for the one in my av cab to monitor that one - just haven't gotten around to it. I have 4 total in the house of the cyberpower ones.. Be nice to throw them all into 1 place to monitor.. One I monitor on my pc, with misc network gear plugged into that, one my nas monitors for its own use, pretty sure the pfsense is on that ups along with my APs I think - but didn't think of turning on its server function and point pfsense to it. You have inspired me to to a better job of monitoring mine.. Mine are all cyber power 1500s, would have to double check models but I know at least 2 of them are the cCP1500PFCLCD I think your docker would be perfect for my use as well.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    92 Topics
    638 Posts
    L
    @Vad-B Interesting indeed! I just tried to fill the Pre-authentication Key with file:/dev/null. I get an crash in pfsense after some time, but when I login again is saved. For me this for after service restarts at least this solves it, including the issue with the routes not being advertised even set in the WebUI. Havent done an full restart of pfsense (yet)
  • Discussions about WireGuard

    712 Topics
    4k Posts
    D
    I feel like I’ve followed every guide there was. I was able to get nordvpn via wireguard on my pfsense but for the life of me I can’t get my own wireguard server working. I can’t even get a handshake. I have all the firewall rules mentioned, the gateway, interfaces. Etc. I got no clue what to do at this point. Can anyone please help? I’ll provide any information required I just don’t even know where to start I’ve tried every YouTube video possible and guide it’s strange. I was able to get nordvpn working but I can’t get my own.
  • Snort alerts - surely there's more?

    14
    0 Votes
    14 Posts
    6k Views
    bmeeksB
    @fearnothing: OK, posts since last noob question just got reset back to zero  :-[. Now it's beginning to make sense. Tutorials are very good at saying "Do A, then B, then C" but when you ask them why they tend to just go quiet. [/quote] Don't despair.  There are lots of knowledgeable folks here ready to help.  None of us know it all.  I read just today a quote that is appropriate – "everyone you meet knows something you do not".  A corollary would be "all of us are noobs about lots of stuff"… ;).  The whole IDS/IPS world can be a confusing maze to navigate.  Add to that all the wonderful open source options out there and it can be daunting.  One downside of open source software is most developers are happier writing and tweaking code than producing usable documentation.  I include myself in that characterization... :-[ That last comment reminds me to mention that an update to the documentation for Snort and Suricata on the pfSense Doc Wiki is needed.  I started some updates for Snort a month or two back, but have not gotten anything posted for Suricata yet.  If there is a willing user out there, any help would be welcomed.  You can contact the pfSense guys to get a Wiki account that allows updating. Bill
  • IMSpector 20111108 pkg v 0.3.2 MySQL Logging Problem

    6
    0 Votes
    6 Posts
    1k Views
    N
    Install Imspector from package, and then install it from shell with pkg_add . depend on your Mysql Server , you need to install the proper version of mysql_client. pkg_add will not change version of package, just install it manually with freeBSD Package manager.
  • Snort not restarting after rules update - 2.1.3- 2.9.6.0 pkg v3.0.8

    4
    0 Votes
    4 Posts
    1k Views
    BBcan177B
    I have intermittent issues with Snort Interfaces Exiting on Error, usually following a Rules Update. When it happens it happens to several boxes at a time. But the logs don't show very much information to help diagnose why its failing. I think it would be good to have a "debug" option where more details logs could be used as required to help diagnose issues better. All of my boxes are on Static so they don't renew their addresses.
  • Pfblocker and emails

    7
    0 Votes
    7 Posts
    2k Views
    BBcan177B
    @foresthus: How many lists can be added to pfblocker? Whre is the limit? I haven't seen any information to state that it has a limit on the number of Lists? I have a box with about 30 main lists (on the "List" Tab) and within the lists, I have multiple lists per. Only thing you need to watch for is the max number of IPs in the Tables. Advanced:Firewall:Firewall/NAT - Firewall Maximum Table Entries Maximum number of table entries for systems such as aliases, sshlockout, snort, etc,        combined. Note: Leave this blank for the default.
  • [Suricata 1.4.6 v1.0.2] Streaming Content issues

    5
    0 Votes
    5 Posts
    15k Views
    ?
    Those rules were evaluated as false positives on "closed" networks (limited number of users), all trusted. They mostly fired on wifi clients, hence the "wifi clients moving around" comment. That "category" of rules (weird traffic) was generally either caused by a wifi client moving from point A to point B and missing a couple of packets OR more rarely by suricata itself, that is after suricata has cleared the states for a blocked host. Technically the firewall has no record of an active connection, which triggers the "weird traffic" category. As I said, false positives. Disable. Note: By category I'm talking about my categories. There are 3 categories: 1)Rules that should have their creators exiled from earth, subcategories idiotic rules (simple http request), stupidly outdated rules (firefox 3.x rules). 2)Weird traffic rules, includes "unknown" traffic, or theoretically impossible traffic (in theory, theory and practice are equal. Practically they are not) and finally 3) Rules that their creators should be honored with nobel prices and generally thought of as humanity's $deities.
  • Help with stuck/botched Avahi install

    1
    0 Votes
    1 Posts
    700 Views
    No one has replied
  • New packages: Zabbix-2 Agent and Zabbix-2 Proxy

    10
    0 Votes
    10 Posts
    18k Views
    R
    I also want to pipe in and say Thank You! I also have it in a working environment. It works perfectly. Now if I can only get it to work on FreeNAS…....... :-\
  • NTLM Auth - Dansguardian broken package 2.12.0.3_2 pkg v.0.1.9 ?

    2
    0 Votes
    2 Posts
    1k Views
    E
    I give up to use Dansguardian on PFsense since the actual package don't work the NTLM plugin that is a requisite to my implementation. I'm using squidguard now.
  • Stopping NTOP

    2
    0 Votes
    2 Posts
    707 Views
    M
    Ok, I've resolved cd /usr/local/etc/rc.d/ touch ztop.sh chmod +x ztop.sh vi ztop.sh put this line in the file: /usr/local/etc/rc.d/ntop.sh stop save and reboot
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid3-dev + pfsense 2.1.3 release

    1
    0 Votes
    1 Posts
    732 Views
    No one has replied
  • 0 Votes
    4 Posts
    2k Views
    T
    Thx finalcut, that runs like a charm  :)
  • I cannot install package in pfsense how i can solve this problem

    1
    0 Votes
    1 Posts
    644 Views
    No one has replied
  • Lightsquid Cron problems

    3
    0 Votes
    3 Posts
    1k Views
    F
    I guess the problem happends when users like me disable the Hard disk cache system (value null instead of ufs) I dont don't use squid for caching things , only keep record of activity. If I dont want a hard disk cache what shall I do to remove the warnings?
  • PfBlocker in Alias Only Mode - Help

    7
    0 Votes
    7 Posts
    2k Views
    W
    Thanks Rick.
  • NUT + APC Back-UPS CS 350 not working

    3
    0 Votes
    3 Posts
    2k Views
    M
    Hi, thx for answer. I try all APC combinations settings, nothing work. my NUT settings (i want use only local usb ups): [image: Sn%C3%ADmka.JPG_thumb] [image: Sn%C3%ADmka.JPG]
  • Reverse-squid OWA,activesync attachement problem

    1
    0 Votes
    1 Posts
    896 Views
    No one has replied
  • Tincd and nat

    4
    0 Votes
    4 Posts
    2k Views
    P
    well this worked.  thanks.  I forgot about the interface assign page…
  • Brain-dead postfix postscreen function

    6
    0 Votes
    6 Posts
    2k Views
    B
    If anyone is running postfix and doesn't find this too fugly ;) I found this about how to whitelist Google servers: Comparing the list of subnets to one seen in another thread (now lost) it seems they haven't changed in over a year.  Not too surprising, since they are pretty big subnets. Paste the following into Services > Postfix Forwarder > Access Lists > Client Access Lists > CIDR: # Google IPv4 addresses 64.18.0.0/20 permit 64.233.160.0/19 permit 66.102.0.0/20 permit 66.249.80.0/20 permit 72.14.192.0/18 permit 74.125.0.0/16 permit 173.194.0.0/16 permit 207.126.144.0/20 permit 209.85.128.0/17 permit 216.239.32.0/19 permit # Google IPv6 addresses 2001:4860:4000::/36 permit 2404:6800:4000::/36 permit 2607:f8b0:4000::/36 permit 2800:3f0:4000::/36 permit 2a00:1450:4000::/36 permit 2c0f:fb50:4000::/36 permit Haven't been able to find anything similar for HotMail but no one I know uses it anyway  :)
  • Lightsquid reports via email

    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    I've seen it done with mailreports before. You can use "/usr/bin/fetch -o - https://[…]" to include the contents of the page in the report, though I seem to remember that having a formatting issue of some sort.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.