Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    tinfoilmattT
    Here. I think. Referenced as "github.com: vendor-provided URL vendor-advisory" in your link.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @netboy said in is something wrong with pfBlockerNG?: After my post, I "changed" DNSBL -> DNSBL mode from "unbound python mode" to "unbound mode" and so far i have no issues. Terrible idea. Moving backwards in development history there.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    649 Posts
    luckman212L
    @mightykong @CarlMRoss Looks like you might be experiencing https://github.com/tailscale/tailscale/issues/17793 I also have a 6100 + Tailscale 1.90.6 so I will test mine now. update: I don't seem to be having this problem, which is odd because I'm usually that one guy in a thousand who has the strange bug that nobody else can reproduce. Have you tried deleting the contents of /usr/local/pkg/tailscale/state ?
  • Discussions about WireGuard

    715 Topics
    4k Posts
    A
    Hi everyone, This is a noob question but already tried multiple and I hope some one can help with this. I have a Wireguard Tunnel configured and handshake is successfully performed and I can ping the server from the laptop but can't do it otherwise. Already deactivate the NAT feature and all the rules and no luck. Pfsense and this server is located in a Proxmox Server, laptop is a local. Any ideas? Thank you.
  • Pfsense.com packages system seems to be down… or is it my eyes?

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    C
    Sorry, I hosed the packages in the process of moving the website. Working again now.
  • How to install Dashboard for 1.2RC4 embedded?

    Locked
    15
    0 Votes
    15 Posts
    5k Views
    Cry HavokC
    I used a Teac CD-210PU (5 years old) to install one of the very early 1.2 snapshots onto my FX5620.  I don't know whether my success is related to the Teac drive, the box or a combination.
  • Imspector monitor website chats?

    Locked
    13
    0 Votes
    13 Posts
    5k Views
    R
    Did you leave the IM client connected when you first started imspector? If so that's why. Imspector has to be started first so it can intercept the IM client connection.
  • Is the squidguard package stable at the moment…..

    Locked
    38
    0 Votes
    38 Posts
    19k Views
    H
    @dvserg: Rewrites work as replacer url or url-template to specified you url for example */porn.jpg - http://myweb.com/pornstop.jpg replace all pron.jpg to you pornstop.jpg if you can - place screenshots of error-names. I can't retry you error (test rc-4 and rc-2). ps where take rc-5? Best regards. Serg Ah, i will test it again with rewrites and here you can get rc5/release http://snapshots.pfsense.org/FreeBSD6/RELENG_1_2/updates/
  • Squidguard, problem and error.

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D
    Welcome  ;)
  • BUG: snort2c

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IMspector update

    Locked
    16
    0 Votes
    16 Posts
    6k Views
    V
    i testing in cyrillic! work normally, but logged only outgoing messages  ??? incoming messages not log. it really must work?
  • Squidguard Deny Default Access automatically

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    V
    I guess that makes sense given its a Default.  I realize now I tried to uncheck both of them, instead of just Deny . .
  • Squid showing blank page for certain sites

    Locked
    9
    0 Votes
    9 Posts
    8k Views
    H
    @mhab12: The new broken site is just one more reason to create a bounty to fix the squid package.  I'll work on the bounty post right now… http://forum.pfsense.org/index.php/topic,7911.0.html Good! wait and see…
  • Squidguard redirect

    Locked
    14
    0 Votes
    14 Posts
    7k Views
    D
    You can reinstall SG xml SG version showed for port only XML (gui) updates possible looking in http://cvstrac.pfsense.com/dirview?d=tools/packages/squidGuard&
  • DNS-SERVER Package

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    S
    No I am afraid not.  Check out the DJBDNS site for instructions on how it works.
  • Snort - Rules Update problem

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    O
    Sorry for the late reply. If the snort page says you have updated you do not need to modify the file.  The package maintainer probably updated the package.
  • SquidGuard destination groups

    Locked
    10
    0 Votes
    10 Posts
    7k Views
    D
    @aaron: I reinstalled the SG XML and it's working! Thank you  ;D Yahoooo!  :)
  • Password protect lightsquid and other cgi files

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    D
    @BaNoBi: Ok But in any case solved my problem. If developerd adding way, how this correctly change from package, i promise add this to lightsquid Pkg.  :)
  • IMspector log problem

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    N
    Found a logfile and delete it, it was empty. chmod is 0777 so it should be ok. But still imspector: Connect socket, connect() failed to /tmp/.imspectorlog imspector: Error: Unable to communicate with logging process
  • Dashboard

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    S
    Browser cache.
  • Imspector causes repeated disconnects from AIM?

    Locked
    13
    0 Votes
    13 Posts
    6k Views
    N
    Well I hope you get time to do this. You are doing a good job and have great knowledge.
  • Cannot install Asterisk on pfsense platform

    Locked
    23
    0 Votes
    23 Posts
    15k Views
    S
    dmz, why dont you go with the suggestion of running pfsense and any asterisk VM appliance as VMs on your server? From security point of view this is not good, but if you are OK with that then this is probably easiest to get working. asterisk is exceptionally difficult to compile, configure and run, and if you have not done it before then getting it to work on FreeBSD is not likely to happen.
  • Problems reaching imdb.com with Squid caching enabled

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    W
    Hmmm well I guess now is like when you take your car into a mechanic with a problem that magically disappears when you get there… seems to be no issues browsing IMDB now.  ???
  • How to install packages on an embedded system (wrap)

    Locked
    6
    0 Votes
    6 Posts
    15k Views
    ?
    I just stickied this topic since a whole bunch of people keep asking this question.  For, hopefully, the last time: Packages on embedded are NOT supported.  Not supported means we will not help you hack packages into an embedded installation. There are very good reasons why packages aren't supported on embedded, perhaps you should find out why.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.