Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Squid 3 SSl transparent options

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    N
    Thank you, very usefull info, i haven't found it searching in the forum.
  • Squid reverse - Dead Peer detection

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Enabling Transparent Proxy slows down internet speed

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    V
    The problem got resolved by uninstalling version 3 of squid and installing squid 2.
  • BUG: bacula-fd.sh service starter tries wrong config path (fix)

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R
    @marcelloc: I've pushed a fix for this, upadate to latest package version and test again. thank you… works on both version now as expected ;) (Problem was the the patch must applied every reboot/"crash" situation and not only once after install).
  • SquidGuard does not work after auto updating blacklist

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Installed Snort - how do I know it's working?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    @Deadringers: Morning all, I installed Snort and have it setup to run all the rules on the WAN interface…it looks like it's active but how do I know if it's working? I have been to the alerts page and the blocked hosts page on the snort part of the firewall interface but I can't see anything that has been blocked and no alerts? Which leads me to believe either: 1 - It's not working properly and I've done something wrong or 2 - it has detected nothing which needs to trigger a rule. I don't believe that it's number 2 for a second as I have tried to load some "dodgy" sites and downloaded some questionable material as a test into a VM of mine. Thoughts? Ahh right I have it up and running properly now! :) a reboot of the firewall sorted things out and now I can see the logs being generated.
  • Monitoring

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D
    @rajbps: Hi DigitalDeviant, Just want to be sure the server will be in the main office and the zabbix clients will be installed on the remote locations. All running pfsense. Linking the site to the main site, there is an openvpn site to site link, so each office comes back to the main site but none of them talk to each other. So if the vpn link goes down due to the service stopping on the remote site and the link dies, how will that link start again. is the agent clever and will it restart the link as during that time the server will not be able to contact the agent. Looking forward for your answer on this one. Cheers, raj I believe, in cases where the agent cannot contact the server, it's possible to run the Zabbix Proxy on the same machine. From there you can set the agent to run a custom command to run the start command as well as report that the link went down. Once the Zabbix server gets the information it can send out an email. You may need to give the Zabbix agent elevated permissions. I've never tried this and I don't have a test server to try it on.
  • Imspector-dev not logging users running Pidgin with Yahoo under Linux

    Locked
    1
    0 Votes
    1 Posts
    988 Views
    No one has replied
  • OpenBGPd

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    Thanks guys. I addressed the disconnecting problem, it was my hardware. I tried 2.0.3 32-bit and 2.1 beta 32-bit on 2 different J&W MINIX D2550-HD, same issue. When I replaced the motherboard with a Supermicro X9SCA-F, it's all working fine. No disconnection in 3 days.
  • CRITICAL: postfix fails to start after upgrade to 2.03 release [solved]

    Locked
    24
    0 Votes
    24 Posts
    5k Views
    marcellocM
    @hcoin: Talk about belt-and-suspenders.  Makes me wish each package that was a vm guest that was its own iso/appliance.  As hard as the open source world tries to deal with 'dependency hell' it just never seems to work out of the workbench environment. On 2.1 pbi packages will be much easier… I'm testing firmware upgrade on one of my 3 inbound smtp servers and I it's stuck on upgrade process. I found a mtree process that is "indexing" /usr dir with 60bg of dcc log from mailscanner package. For next 2 boxes upgrade I'll remove these folders before the update and remove all packages as well.
  • Squid caching website status messages

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N
    On squid-cache.org you probably find a description for nearly all config options. An example: http://www.squid-cache.org/Doc/config/negative_ttl/ And you have the possibility to check the different values for the different squid versions.
  • Snort broken: whitelist

    Locked
    26
    0 Votes
    26 Posts
    11k Views
    C
    I can appreciate the difficulty in creating a dynamic whitelist for Snort. Perhaps in the interim a partial solution could be getting the whitelist to at least populate on startup all the IPs from an alias, including those from FQDNs.
  • SquidGuard blocking pages

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    K
    Actually firefox is configured to remember everything.
  • Snort stays online for a while, then fails to start again…

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    M
    So far so good. I'll let you know. Thanks!
  • Squidguard error page does not load on blocked URL

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    OK - I figured out most of my issues.  For anyone experiencing some of the same maybe this is helpful: Internal redirect issues: The error page is rendered from the same interface as the UI, I found out.  I have squid and squidguard on a few vlan interfaces so that I could isolate the UI and some other devices from what is basically my "mgmt" network subnet.  Because I have FW rules in place to block all traffic from the vlan'ed interfaces to this mgmt network, the page won't render. External URL's not working: While I was changing the settings I was not deleting the browser cache on my iphone between settings changes.  So, I was getting old webpages when hitting the same sites rather than the redirected pages.  So lesson learned is to always delete your cache when testing these different settings!
  • Quagga OSPF help for a beginner

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    R
    @rengiared: sorry for my late response, but i have figured out where my problem was on the site with the 2 wans i made a gateway-group and set this on the default-lan to everywhere rule as gateway, as soon as i changed it back to the default gateway preference all works then you can fix it easy we setup a "private" alias with all internal networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16) and set on each LAN a first "external" route: allow any any to !private any  over gateway group (with traffic limiter)
  • MOVED: Xenserver Tools for pfsense

    Locked
    1
    0 Votes
    1 Posts
    938 Views
    No one has replied
  • PfBlocker Lists question & Errors

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    marcellocM
    @rl2171: Strange, if I do Deny inbound it shows red, but if I deny both it shows as green. If you have no rules on wan interface, pfblocker will not create a rule as you already has an deny all traffic rule.
  • Monit on pfsense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    L
    Hi Raj, I did it the other day: http://forum.pfsense.org/index.php/topic,61602.0.html Hope that helps.
  • HAProxy Widget

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    P
    For your information, the widget is now included in the HAProxy-devel1.5-dev18 package. Made a few improvements to it to also: -Options configurable from the WebGUI. -Faster server enable/disable responses. -Dropped socat requirement. Check it out if you want 8)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.