Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    D
    @BBcan177 Thank you for the kind reminder; I am so accustomed to ensuring Save Settings is checked that I didn't follow your instructions properly (thanks @tinfoilmatt for uploading and highlighting the screen shot). I've properly followed the instructions and the update did not report and db problems. Thank you again! drac
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    663 Posts
    C
    For what it’s worth, we may have had the same issue but for different reasons. I checked, and my system has the duplicate two files. Therefore, I asked Grok.ai about “/usr/local/etc/rc.d/pfsense_tailscaled enable /usr/local/etc/rc.d/tailscaled disable” versus the solution it had provided me yesterday. See the answer below. (Grok.ai used sources that included this Netgate forum, Lawrence Systems Forums – Networking & Firewalls, and https://forum.tailscale.com/.) The Two Service Files: Quick Breakdown Before diving into the relation, let’s clarify what those files are (based on standard pfSense Tailscale package behavior on 25.07.x/FreeBSD 15-CURRENT): • /usr/local/etc/rc.d/tailscaled: This is the generic FreeBSD/Tailscale rc.d script. It originates from the underlying tailscale package (the one you manually installed via' pkg add' for version 1.90.6). It’s a basic daemon starter/stopper that just runs /usr/local/bin/tailscaled without any pfSense-specific smarts (e.g., no auto-auth, no route advertising, no GUI integration). • /usr/local/etc/rc.d/pfsense_tailscaled: This is the pfSense-specific wrapper script. It’s installed by the official pfSense-pkg-Tailscale package. It wraps the generic tailscaled binary but adds pfSense magic: it reads your GUI config (auth key, advertised routes, exit node flags), writes them to /usr/local/etc/rc.conf.d/pfsense_tailscaled (e.g., pfsense_tailscaled_authkey="yourkey"), and handles the full tailscale up with flags on boot. It’s what makes the service “pfSense-aware.” In a stock official package install (without your manual binary upgrade), only pfsense_tailscaled exists and runs everything. When you force-installed the newer tailscale pkg on top, it added the generic tailscaled script as a side effect—but your fixed script (the one we pasted into /usr/local/etc/rc.d/tailscaled) overrode it to behave correctly.
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • Postfix with Carp

    Locked
    33
    0 Votes
    33 Posts
    8k Views
    marcellocM
    Nice! sorry for the typo on that post  :) You could set update frequency to 1h if you have a huge domain with many changes. att, Marcello Coutinho
  • Snort dying on multiple interfaces

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    not quite, I can get snort to run on all the interfaces but, after some time and a few automatic updates, snort stops running on some interfaces I can manually start snort without problems
  • Snort not running when setup on 2 interfaces

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    T
    @ermal: Can you please state your pfSense version? less /etc/version ```gives me a``` 2.0.1-RELEASE less /etc/platform ```shows``` pfsense Best regards T
  • PfSense and Snort VRT Subscription

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    M
    Thank you Jamesdean for clarifying how the pfsense snort package handles Sourcefire VRT/premium rules subscriptions.
  • Fusionpbx/freeswitch package is missing

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    S
    I can try a fresh install later tonight. I really need to find a way to clone a UDMA CF card…using a CF2IDE adapter on a nano-itx motherboard's IDE primary port. Trying to keep the hardware down to zero moving parts. Having a number of CF cards to cycle through would make it a bit easier to test various packages.
  • Freeradius2 not at list package

    Locked
    8
    0 Votes
    8 Posts
    2k Views
    N
    @neewbie: I use the hard drive. I might have to reinstall my pfsense machine. You should reinstall your machine. freeradius2 is available for HDD install on amd64 and i386 :)
  • SquidGuard old version install howto

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    Blacklist rebuild can take time from 10 min up to 1.5 hour (depends on the speed of you system) Is it possible if the blacklist rebuild does not fully complete Only if it had been interrupted manually or reboot.
  • OpenNTPD timing out when performing queries

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    @biggsy: I was curious about this, having tried ntpq myself with the same timeout. I did some searching and found this thread http://www.monkey.org/openbsd/archive/misc/0408/msg00448.html It seems, from the first few responses in the very long thread, that openntpd doesn't respond to ntpq and probably never will. Do you know/suspect your LAN clients aren't sync'ing to pfSense? I expected " ntpq -p " to work, but never bothered to use anything else to check if the ntp server is working. I just performed ntpdate on one of my computers and got some positive feedback: ntpdate 10.119.97.61 29 Jan 11:38:06 ntpdate[15951]: adjust time server 10.119.97.61 offset -0.004357 sec I guess this thread can be closed. Would be nice to see what servers the pfSense box is sync'ed to, but I suppose this would suffice. Thanks for having me .. think outside the box :)
  • What is going on with Snort package?

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    C
    I just donated a bit. Thanks guys!
  • Freeswitch- process is not starting

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A
    now its working fine …thanks  ;)
  • Pfsense 2.0.1 and freeswitch

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    marcellocM
    Another hit http://forum.pfsense.org/index.php/topic,45593.msg238114.html#msg238114 Are you searching the forum? ???
  • Jail (PfJailCtl pkg) on pfsense 2

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    R
    I still use pfJailCtl GUI on 2.0.1 and it's capable to start my jail on boot. Of course it needed additional work to make it run smoothly: 1.  Turn on the debug in the GUI. 2. Configure jail and push Create which of course would not work, just copy script from debug output. 3. Replace sysinstall installed by the packet (from FreeBSD 7) with FreeBSD 8.1 version. 4. Modify script from §3 according to your needs, remember to change FreeBSD release to something 8-tish ie I used 8.2, turn ssh if you wish - remember to change port because otherwise pfSense and jail ssh would not be distinguishable. 5. Run your script from shell. 6. Boot jail from GUI. I successfully share SMB from jail, which I know is not too great idea on firewall, but it save me one box @home and it's a bit safer than sharing directly from pfsense. I also managed to run vnc to xfce4 on xvbf in the jail. If someone would need such functionality I shall share this result.
  • Snort stops working after snort update (newest 2.0 RELEASE)

    Locked
    113
    0 Votes
    113 Posts
    68k Views
    J
    @antilog: @Cino: i've always had a space, at least for the last 2 years: suppress gen_id 119, sig_id 2 suppress gen_id 120, sig_id 3 suppress gen_id 122, sig_id 22 This was in response to johnybe, who did not have a space.  :) Sorry, it was a typo.  :)
  • Snort 2.9.2.1 Upgrade?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort 2.9.1 pkg v. 2.1.1 update broke my Snort

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    @mentalhemroids: ***UPDATE *** BTW, I didn't have to restart the system.  Just uninstall and reinstall. usually you dont need to reboot but i throw that out there to be safe
  • Proxy Server package (squid3) bandwidth limits not working(?)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    marcellocM
    Squid3 is not fully updated, test this feature with squid 2 package.
  • Squidguard bypassed by facebook android app

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    Last time I sniffed the traffic from my tablet it looked like the Facebook app just used standard HTTPS, so as marcelloc said, transparent proxying wouldn't catch it. You'd have to set the proxy settings on the phone/tablet if it's supported.
  • Snort not starting error

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    i love how no one searches anymore…
  • Can squidguard merge permission from Group ACL?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    You clients will use first-mach rule only.
  • Squid stops from working

    Locked
    6
    0 Votes
    6 Posts
    11k Views
    P
    ok. rebooting pfsense resolves the issue. I don't know what could be the issue but what I'm sure is WAN got an issue but it was restored but it seems pfsense needs to reboot. I can now ping google.com and no more No route to host issue
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.