Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    D
    @BBcan177 Thank you for the kind reminder; I am so accustomed to ensuring Save Settings is checked that I didn't follow your instructions properly (thanks @tinfoilmatt for uploading and highlighting the screen shot). I've properly followed the instructions and the update did not report and db problems. Thank you again! drac
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    661 Posts
    L
    For me I might have fixed (without kinda complicated solution which I could find). Since it worked when I did an restart in the UI, and that the tailscale service in pfsense was actually running, I came to the conclusion, that maybe some other tailscale service was started at boot, so I tried below. I tried to reboot it after, and tailscale came up just fine. I haven't tested it further though. LIke power it down completely, or do multiple reboots. /usr/local/etc/rc.d/pfsense_tailscaled enable /usr/local/etc/rc.d/tailscaled disable
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • OpenBGPD

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • VHOST ? Stopped with info that it`s runnning :X

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    6 Posts
    3k Views
    D
    Last page LOG - squidGuard config.  :-[
  • Snort Question

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    T
    @LostInIgnorance: Just my wan ok , i thought you might monitoring  two interfaces although pid sowing the same any way i checked at our system using 1.34 snort package its the same as you mention , its monitoring only the LAN int. Dec 10 09:34:14 snort[32933]: +------------------------------------------------- Dec 10 09:34:14 snort[32933]: [ Number of null byte prefixed patterns trimmed: 2382 ] Dec 10 09:34:14 snort[32933]: [ Number of null byte prefixed patterns trimmed: 2382 ] Dec 10 09:34:14 snort[32933]: Dec 10 09:34:14 snort[32933]: Dec 10 09:34:14 snort[32933]: --== Initialization Complete ==-- Dec 10 09:34:14 snort[32933]: --== Initialization Complete ==-- Dec 10 09:34:14 snort[32933]: Snort initialization completed successfully (pid=32933) Dec 10 09:34:14 snort[32933]: Snort initialization completed successfully (pid=32933) Dec 10 09:34:14 snort[32933]: Not Using PCAP_FRAMES Dec 10 09:34:14 snort[32933]: Not Using PCAP_FRAMES
  • Squidguard log disabled

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    New SG log page will be created.
  • SquidGuard and redirects?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    I do not know an elegant solution to this https problem. If there are any interesting offers, I will gladly use them. But - SG analyse and use HTTP-GUI LAN IP:port (need Save & Apply on General page SG). You can use any httpGUI port.
  • VLAN isolation of ips on Snort Alerts

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Clamav update needed

    Locked
    23
    0 Votes
    23 Posts
    22k Views
    W
    The Ports tree now has ClamAV v0.96.5 (updated on the 4th of Dec).
  • Why?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    Look here. http://forum.pfsense.org/index.php/topic,26009.msg135215.html#msg135215
  • Squidguard base redirector url

    Locked
    6
    0 Votes
    6 Posts
    22k Views
    D
    Hm.. problem with LAN ip detection. Pleace email me you /usr/local/etc/squidGuard/squidguard_conf.xml file.
  • SQUID BIG PROBLEM

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    O
    yes i know :D thats the problem with reboot ;) my proxyconfig is so because i want antivirus function and squid. BUT antivirus (havp) dont understand ftp protocol and so i have to configure squid as normal proxy and havp with parent proxy to squid ip!!!  it gives no other way for alternative - only wihtout ftp support! therefore i need a loopback interface for squid!
  • Internet activity - saving events

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    ?
    Hi, The time is in unix format. And that be so, as I understand it. Log to another physical server. How this can be done eg on Windows server? If there is a possibility. In Proxy server: General settings >> Custom Options I have: redirect_program /usr/local/bin/squidGuard -c /usr/local/etc/squidGuard/squidGuard.conf;redirector_bypass on;redirect_children 3 What is this? Thank you for your reply. adminkg
  • Snort problem again !!!

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    ?
    @DigitalJer: Even so, keep in mind this is bleeding edge technology, it's under active and heavy development.  The usual developer of this package listens and makes every effort to reply to a problem.  Complaining with no facts doesn't help anyone. Hear, hear!  I would think this would be standard practice now, or at least common sense.  Thanks for saying it.
  • Squid CacheMgmt

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    M
    I believe you need to remove your 'custom option'.  This field should be left blank.  At the top of the page on the Cache Management tab, set 'Hard Disk Cache System' to null.  The cache location should not matter as no storage will actually be used.
  • [SOLVED] How to use ClamAV on port 3310 from LAN Network?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    U
    @dvserg: Try use portmapping on interface IfaceIP:3310 > 127.0.0.1:3310 It works, thanks! Configuration: Firewall/NAT Interface: LAN Protocol: TCP External port range: 30000 NAT IP: 127.0.0.1 Local port: 3310 Point servers to firewall LAN IP address on port 30000.
  • Is the file server for pfsense down? files.pfsense.org

    Locked
    15
    0 Votes
    15 Posts
    8k Views
    jimpJ
    Awesome. Not sure why, but on i386 it would not automatically make a neon package. I made it by hand. amd64 built and uploaded it automatically.
  • Snort with NanoBsd Problem - Problem Solved!

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    Problem solved! Thanx! My home network can't not live without pfsense anymore!
  • MOVED: Imspector installation problem

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Hardware for Transparent Web-Cache

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    S
    It will be more than enough….........
  • Snort : GUI

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    ?
    I know there will not an answer but is the gui still broke or is it fixed on the latest snapshot .
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.