Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    M
    You have several choices depending on budget but none of them will be on your pfsense. Your options will be Replace pfsense with another vendor that can do content filtering Use another service while keeping pfsense in line .
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    RedDelPaPaR
    @bmeeks Understood. Thank for kindly for your help. I will likely be ordering a new unit soon.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N
    @Gertjan said in is something wrong with pfBlockerNG?: "is something wrong with my pfBlockerNG?". First off, thanks for the detail reply. After my post, I "changed" DNSBL -> DNSBL mode from "unbound python mode" to "unbound mode" and so far i have no issues. I understand what you are saying & hinting "maybe something is wrong with my settings" - my response is this: Everything was working before i upgraded the pfsense software to " 25.07.1-RELEASE (arm64)" -- Before the update my DNSBL Mode was set as "unbound python mode" and everything worked. Here is my "inference" - something broke in pfBlockerNG after the upgrade and I cannot 100% point to what that setting (my) is? I will observe for some days how this change in DNSBL mode works out and report the findings.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    644 Posts
    C
    @elvisimprsntr Thank you. I would not be surprised if I ended up with a lengthy solution that works but needs significant improvement. I am using a Netgate 6100 with pfSense+, starting with version 24.x. I had updated Tailscale without trouble per this discussion by using pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-x.y.z.pkg. This worked until pfSense+ version 25.0.07 (FreeBSD 15-CURRENT) and Tailscale upgrade 1.88.3. After several attempts and web searches, I was only able to install that upgrade by using: fetch https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.88.3.pkg, and then IGNORE_OSVERSION=yes pkg-static add -f tailscale-1.88.3.pkg. Then, I could not restart Tailscale, no matter what I tried, including the sequence: service tailscaled stop, tailscale logout, service tailscaled start, and then tailscale up.
  • Discussions about WireGuard

    714 Topics
    4k Posts
    R
    I was on PfSense version 23.xx (don't recall the xx) and was able to start the Wireguard service. I upgraded to the 25.11 beta version and now the Wireguard service will not even start. I am on Wireguard version 2.1, and I see that there are versions that go up to 2.9. How do I upgrade to a later version? The only version in the pfSense updater is 2.1. Thank you
  • Which package/packages best to monitor traffic and LOG IT

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    May be via .htaccess  .htpasswd ?
  • NTOP shutting down

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    Ntop threading bugs or FreeBSD threading bugs, depending on who you ask. I don't know the true cause, but it's a common ntop issue with no resolution in sight.
  • Trasparent proxy and corrupted download

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    You need to upgrade to at least 1.2 RC2, better than that would be the most recent snapshot.
  • How to install spamd package

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Blocking orkut

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    Forgives me for placing this topic. I already resolved this problem: http://forum.pfsense.org/index.php?PHPSESSID=e510624136cf75765d8f850c749483ae&topic=6117.0
  • Three questions about SQUID

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    W
    If I config directly in squid.conf it will work? Yes, but it wont stick. To make it stick edit /usr/local/pkg/squid.inc, then regenerate squid.conf by changing an option on the proxy config screen of the gui. Remember to back it up though, in case a jr. tech (or a forgetful you) upgrades the package.
  • Squid - acl Safe_ports

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    W
    Solved it. i added 81 to the line 589 of /usr/local/pkg/squid.inc acl sslports port 81 443 563 $webgui_port
  • Squid bind to CARP interface

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    On transparent mode squid can't access to 127.0.0.1 and without carp Perhaps may be create some rule for sovling this problem?
  • Lightsquid log rotate bug

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    M
    Log rotate function works perfect now..  ;D many thanks Michael
  • (bug?) Snort Advanced configuration pass through doesn't work

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Squid timebased access

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H
    Hi, and thanks for the link howto configure the alt package menu, but I don´t get it running. I read the howto attentive but I end up in a failure. I Installed alt_pkg.php so that i can find the menubutton "Alt Package" in Services. Then I download File pkg_config.xml and put it via WinSCP in the directory /usr/local/www/packages/ and change to the Webgui Alt Package and select "Local 'XML Base URL' (127.0.0.1)" If I then press load where I see the content of pkg_config.xml and press save. If I change to Packages in System, the List will not directly appear and I get this "Unable to retrieve package info from 127.0.0.1. Cached data will be used." I didn´t use copy and paste to bring content of the File to PfSense. any Idea? greetings Hoster :)
  • Snort package typo

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    B
    Thanks!
  • Squid content filtering rule

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort doesn't block all I ask it to

    Locked
    19
    0 Votes
    19 Posts
    12k Views
    C
    One way I have been able to successfully block P2P traffic on my networks is by explicitly denying any udp traffic outbound, and only allowing DNS traffic from servers outbound. Egress filtering is another method I use. turn off the default lan to any and allow only specific traffic outbound ie ftp (port 21 TCP and you will need to allow port 20/UDP outbound for data ) http https pop3 imap  Let me know if this helps
  • Minor Snort configuration change ?

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    D
    Something to change tho, would be adding "ac-bnfa", to the list of choices and possibly removing mwm due to security issues (according to snort community). At this time you can manually edit a configurationfile downloaded from diagnostics and replacing your method of choice there to "ac-bnfa" and reboot.
  • Ipsec widget shows only inactive tunnels

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    H
    Ah Ok, thanks for the answer, greetings heiko
  • Including pmacct in pfsense

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • PfSense v.1.2 RC2 packages

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    N
    Hi. Thanks for all answers. I have added now 100% on those packages that work with v.1.2 RC2 :) Hope it's work for me too, hehe
  • Manual installation of packages

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    Has already found. Thanks to me…  :) http://forum.pfsense.org/index.php/topic,986.0.html
  • Squid/2.6.STABLE5

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    R
    … I also face with other problem with some webpage (intranet) if i dont enable bypass proxy server for local address. example: if i browse to http://chronicles i could not be able to access it. ... What if you type the full name of "chronicles" ? Is pfSense at the same "TLD" of chronicles ?  I mean, is "pfSense-hostname" at the same domain / zone than "chronicles" ? Eg.: pfSense-hostname."internal-domain"                   chronicles."internal-domain"
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.