Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    BBcan177B
    @Draco try to goto the General Tab, first ensure that the Keep Settings option is checked. Then unchecked Enable pfBlockerNG so that its disabled. Hit save. Force Update. Then reenable pfBlockerNG and Force update.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    A
    @GPz1100 I ran into this same exact issue. I don't have the Prefer IPv4 over IPv6 box checked, but I do have IPv6 enabled. I think the real issue is that Let's Encrypt's server seems to respond with "Recv failure: Connection reset by peer" on almost every request when using IPv6. I tested this by using the command curl -v https://acme-v02.api.letsencrypt.org/directory from pfsense's shell. To work around it, I modified the ACME script as you described. In the file /usr/local/pkg/acme/acme.sh, I updated line 1887 from: _ACME_CURL="curl --silent --dump-header $HTTP_HEADER " to: _ACME_CURL="curl -4 --silent --dump-header $HTTP_HEADER " After forcing curl to use IPv4, both certificate registration and renewal from the acme package started working again without issue.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    656 Posts
    C
    @elvisimprsntr Updated 25.07.1 to 1.90.6_1, copied and pasted from @elvisimprsntr's post: pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6_1.pkg (Why it worked this time and not on previous updates: Over the last couple of days, I ran into the "Shared object "libutil.so.10, not found..." error that triggered the version 25.07.1 update issues some of us have been having. After I fixed that error, I decided to go back to the usual update method, and it worked.)
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • PfSense 1.2.3 nano & Snort 2.8.5.3 pkg v. 1.21

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    J
    @jamesdean: Why is snort doing that to you? Why am I not seeing this error? ssh to your box and restart the webconfiguator. ( '11)  Restart webConfigurator '). Something like this happened to my instalation also. I was messing around with Snort memory settings and accidenly chose AC in a quite low resources system. Snort ate practicly all my resources (could not eaven log into pfsense gui). In my case this was solved by ssh connection to the box and stopping snort process.
  • Regarding Squid (pfSense_Lusca packages by Chudy)

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    P
    Hai Mr Chudy and topic moderator… i just want to ask,,,if my Harddrive 80GB and i using 1GB of RAM in Intel Atom Machine 1,6GHZ.... please give me a best advice to configure my cache management in webGUI... i;m using your LUSCA give me some explanation about this : tail -f /var/squid/log/cache.log 2010/04/09 07:53:27|        0 Duplicate URLs purged. 2010/04/09 07:53:27|        0 Swapfile clashes avoided. 2010/04/09 07:53:27|  Took 1.4 seconds (  0.7 objects/sec). 2010/04/09 07:53:27| Beginning Validation Procedure 2010/04/09 07:53:27|  Completed Validation Procedure 2010/04/09 07:53:27|  Validated 1 Entries 2010/04/09 07:53:27|  store_swap_size = 2k 2010/04/09 07:53:28| storeLateRelease: released 0 objects 2010/04/09 08:08:35| CACHEMGR: <unknown>@127.0.0.1 requesting 'info' 2010/04/09 08:20:30| squidaio_queue_request: WARNING - Queue congestion</unknown> and this : squidclient mgr:info HTTP/1.0 200 OK Server: Lusca/LUSCA_HEAD r14499 patched by chudy r11 Date: Fri, 09 Apr 2010 00:54:50 GMT Content-Type: text/plain Expires: Fri, 09 Apr 2010 00:54:50 GMT X-Cache: MISS from localhost Via: 1.0 localhost:3128 (Lusca/LUSCA_HEAD r14499 patched by chudy r11) Connection: close Squid Object Cache: Version LUSCA_HEAD r14499 patched by chudy r11 Start Time:    Thu, 08 Apr 2010 23:53:26 GMT Current Time:  Fri, 09 Apr 2010 00:54:50 GMT Connection information for squid:         Number of clients accessing cache:      0         Number of HTTP requests received:      6058         Number of ICP messages received:        0         Number of ICP messages sent:    0         Number of queued ICP replies:  0         Request failure ratio:  0.00         Average HTTP requests per minute since start:  98.7         Average ICP messages per minute since start:    0.0         Select loop called: 471925 times, 7.807 ms avg Cache information for squid:         Request Hit Ratios:    5min: 12.2%, 60min: 11.0%         Byte Hit Ratios:        5min: 1.5%, 60min: 23.0%         Request Memory Hit Ratios:      5min: 28.3%, 60min: 70.5%         Request Disk Hit Ratios:        5min: 3.8%, 60min: 12.7%         Storage Swap size:      154334 KB         Storage Mem size:      20300 KB         Mean Object Size:      42.62 KB         Requests given to unlinkd:      0 Median Service Times (seconds)  5 min    60 min:         HTTP Requests (All):  0.85130  1.00114         Cache Misses:          0.94847  1.17732         Cache Hits:            0.00379  0.00286         Near Hits:            0.76407  0.72387         Not-Modified Replies:  0.00379  0.00179         DNS Lookups:          0.00000  0.00000         ICP Queries:          0.00000  0.00000 Resource usage for squid:         UP Time:        3684.226 seconds         CPU Time:      91.372 seconds         CPU Usage:      2.48%         CPU Usage, 5 minute avg:        2.32%         CPU Usage, 60 minute avg:      2.52%         Process Data Segment Size via sbrk(): 0 KB         Maximum Resident Size: 53392 KB         Page faults with physical i/o: 3 Memory accounted for:         Total accounted:        23852 KB         memPoolAlloc calls: 1154184         memPoolFree calls: 1063451 File descriptor usage for squid:         Maximum number of file descriptors:  14745         Largest file desc currently in use:    49         Number of file desc currently in use:  34         Files queued for open:                  0         Available number of file descriptors: 14711         Reserved number of file descriptors:  100         Store Disk files open:                  2         IO loop method:                    kqueue Internal Data Structures:           3676 StoreEntries           3478 StoreEntries with MemObjects           3470 Hot Object Cache Items           3621 on-disk objects Thanks Mr. Chudy
  • Snort 2.8.5.3 pkg v. 1.21 not detecting portscans

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    J
    @LostInIgnorance: I am having a problem with snort not recognizing portscans done from an outside source.  They are not being blocked, detected, or logged. Check to see if snort is running. ps -aux | grep snort. If your on nanobsd snort will kill it self if you load to many rules. Error out of swap space…..... Make sure you are listening on the wan if you want to see portscans and attacks that get blocked by the firewall. James
  • Snort not applying threshold.conf settings

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    J
    @jaysonr: Ok, I went ahead and updated to the newest version (lost all my settings again) and now I see the pass through settings. I will start rebuilding my settings and post the results :) You can save your setting using the pfsense backup config thing.
  • Snort-dev has been released. old snort has been renamed snort-old

    Locked
    50
    0 Votes
    50 Posts
    19k Views
    J
    @tester_02: Snort 1.20 install went great, no issues  on my 1.2.3.release install. I had no issues on my firefox and getting new rules. Can others comment if they do an upgrade from the old releases (2.8.4 v1.7) that their installs do work?  Also, if you deinstalled, and then installed the new package, or just did a reinstall to upgrade? In my case (runnig pfsense 1.2.3 and the old snort version was 2.8.4 v1.7). I did deinstall the old version first and then installed the new 1.20 package.  Worked fine that way Just in case for those that are doing upgrade, or new with snort : Also remeber tho check the preprocessors settings when activating new rules. Snort wont start if you activate rules that require for example http preprocessor and the needed preprocessor is not selected (snort logs are good for finding what is wrong).
  • Squid cache Antivirus Update

    Locked
    9
    0 Votes
    9 Posts
    14k Views
    jimpJ
    Actually it should probably be: refresh_pattern avgate.net/.*\.gz 720 100% 10080 reload-into-ims; Since the regex isn't achored, that will match the same as .*avgate.net, and the . in .gz should probably have the \ before it so it's really considered a period. It still would have worked, but really either one of those should match the pattern you were trying to make.
  • Strange problem with Squid (pfSense_Lusca packages by Chudy)

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    P
    use squidclient command e.g @ console type #squidclient -p 3128 cache_object://localhost/info you can change 3128 with your squid listen port and localhost with your proxy ip or use only squidclient mgr:info http://forum.pfsense.org/index.php/topic,19251.msg124919.html#msg124919
  • Does stunnel work in 1.2.3?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    As an addition, it looks to be accepting connections on the port I configure but then immediately terminating them.  If I disable stunnel and try to telnet to the port I get a long timeout.  If I enable it, the telnet session immediately ends.
  • Squid and Active Directoy Auth with NTLM

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Running PHP, external database server connection

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    N
    solved it using ozanus recommendation..http://forum.pfsense.org/index.php/topic,21885.msg112854.html#msg112854 the important line is.. pkg_add -r http://files.pfsense.org/packages/7/All/php4-mysql-4.4.8.tbz ln -s /usr/local/lib/php/20020429/mysql.so /usr/local/lib/php/extensions/no-debug-non-zts-20020429/mysql.so now im capturing user details like mac address via arp and squidquard..
  • Resolve Names from LAN IPs in Darkstat and BandwidthD?

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    T
    All my internal IPs are given out by DHCP. Let me know if I'm on the right track: in pfSense, under the DHCP Server service, there is a Dynamic DNS field; is that what I should be using to try and get pfSense's DHCP to update my DNS server?
  • Havp eating up memory spawning new childs

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    D
    Test different settings (+/-) for 'HVDEF_HAVP_MINSRV', 'HVDEF_HAVP_MAXSRV' May be you found the best values.
  • Pfsense behind a web proxy, problem to download packages

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid access denied from Allowed subnet?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    Try tinkering with the box on the front page of the Squid/Proxy GUI called 'Allow users on interface'.  This has, in the past, overridden the allowed subnets box you are using.  Tick it, save, test, untick, save, test.  Hope it helps.
  • Problems with NTOP - New user.

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    P
    I have 3 sites with PFSense & monitoring with NTOP. 2 hold in there for a long time many days, 1 drops out the same as you get, same error within 1 to 12 hours. I don't know why. THey are running on similar systems, may even be exact clones (I just used a couple spare HP PC's for this task)
  • Snort uninstalling itself pfsense 1.2.3

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    G
    Seems to be hanging on running deinstall commands.
  • [ASK] client: ERROR: Cannot connect to localhost:3128: Connection refused

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Naieve Config Ques: Why not enable all?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    Well you generally pick what kinds of traffic you want to be on the lookout for. Services you run are one rule to follow, but you also need to be aware of services you do not ever want to see on your network as well, plus attacks of varying kinds (spyware, etc) For example, if you're only running a web server, you may want to run some of the rules that apply to https, and you may also want to be sure that the web server never has something like IRC traffic coming from it – that could be a sign it has been compromised. Running an IDS and doing it well will take some tuning. If you have the spare RAM and the spare CPU cycles, load 'em all up and see what gets triggered. If "good" traffic is triggering a rule, disable it or disable that set. It really is all up to the admin of a network to make these choices - only the admin of that network will know what should and should not be present there.
  • OpenOSPFD

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    C
    Thanks for the info, I downgraded the package to 4.3 for the time being.
  • [Fixed] Squid installed twice, shows up twice in status/services

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    Thanks, fixed it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.