Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Cron package error!!

    2
    1
    0 Votes
    2 Posts
    510 Views
    kiokomanK
    require_once("/usr/local/pkg/cron.inc"); $a_cron = &$config['cron']['item']; <- line 25 if ($_GET['act'] == "del") { you have probably corrupted the config file, go to Diagnostics / Backup & Restore / Config History and restore to a working config [image: 1581857261466-immagine.jpg]
  • Arpwatch fails to download ethercodes.dat

    2
    0 Votes
    2 Posts
    666 Views
    E
    Here is a link to the bug report: https://redmine.pfsense.org/issues/10261
  • Service Watchdog Bug?

    2
    0 Votes
    2 Posts
    383 Views
    jimpJ
    That's the same as most any other page. Just click back or click away in the menu. Not a bug. There is no valid reason for anyone to add every service to the watchdog. It's illogical and highly likely to cause problems. Don't do that. Also not a bug since nobody should ever be in that situation.
  • Avahi-daemon choosing VIP instead of interface IP

    2
    0 Votes
    2 Posts
    552 Views
    C
    Based on feedback I've opened https://redmine.pfsense.org/issues/10253 to pfblockerng to move the default VIP bind to localhost instead of a user interface.
  • Syslog-ng not binding on multiple interfaces

    Moved
    1
    0 Votes
    1 Posts
    192 Views
    No one has replied
  • Unable to retrieve package info

    13
    0 Votes
    13 Posts
    2k Views
    GertjanG
    Don't know. And bye bye the security if it would be possible to change the URL being used for updates.
  • [solved] VPN Client Export Utility on 2.5.0-DEV

    3
    1 Votes
    3 Posts
    516 Views
    C
    Hello Hin4ik, thanks a lot for helping me here. I forgot to create a user certificate, after creating one I see also the config Kind Regards Robert
  • NTP PPS Jitter Question

    6
    0 Votes
    6 Posts
    2k Views
    C
    I have a Garmin 18x LVC wired and configured the same way (no LED though) and am also getting PPS jitter, see below [image: 1581011652491-capture.png]
  • DNS slave server ignoring updates from master

    3
    0 Votes
    3 Posts
    454 Views
    S
    Yeah, rndc doesn't work but it turns out it did eventually replicate. It just took hours and hours
  • HAProxy with thousand of additional certificates

    10
    0 Votes
    10 Posts
    1k Views
    C
    Sorry for weird word. Because of when I searching about memory_limit most of comments is to increase memory_limit configuration, and for pfsense I found to increase is in the file '/etc/inc/config.inc'. But after upgrade this file is override that the reason I said it's not a good idea ( not the right place ) to modify this file configuration. Thank you, If you want more information or any support from me don't hesitate to ask me.
  • Oracle Database Freeradius

    2
    0 Votes
    2 Posts
    402 Views
    kiokomanK
    it is not supported, you can ask a new feature here https://redmine.pfsense.org/ your only option is to install freeradius on another machine or convert the database the configuration files are overwritten every time you change something on the GUI consequently you lose what you entered manually
  • Random Failing Websites

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Testing Multicast using PIMD

    1
    0 Votes
    1 Posts
    484 Views
    No one has replied
  • New package: pimd

    Locked
    35
    11 Votes
    35 Posts
    15k Views
    jimpJ
    This seems to have strayed very far from the original intent of the thread. If you'd like to continue to discuss the merits of multicast routing in general, rather than issues directly related to the functionality of the package, start a new thread in an appropriate (non-packages) category. For those who have feedback about pimd, start a fresh thread for your individual issues. Please include details about your use case as well as current package settings. Ensure you are on pimd version 0.0.2. Locking this.
  • 0 Votes
    1 Posts
    430 Views
    No one has replied
  • [solved] Snort Registered User rules download fails

    13
    0 Votes
    13 Posts
    6k Views
    C
    I've been battling this as well. Be sure the Oinkcode is correct and without a leading space. Rookie mistake but it happens, drove me crazy for a week. Good luck!
  • HAProxy Listen On LAN - Pass Internal Traffic Through Proxy

    2
    0 Votes
    2 Posts
    643 Views
    B
    Did you figure this out? When I do, I'll post my response here.
  • Python 3 in pfsense

    28
    0 Votes
    28 Posts
    14k Views
    jwsiJ
    @guardian great! Look forward to hearing how you get on
  • 0 Votes
    6 Posts
    886 Views
    johnpozJ
    https://docs.netgate.com/pfsense/en/latest/general/can-i-sell-pfsense.html What can not be offered is a commercial redistribution of pfSense software, for example the guidelines do not permit someone to offer “Installation of pfSense software” as a service or to sell a device pre-loaded with pfSense software to customers without the prior express written permission of ESF pursuant to the trademark policy.
  • FreeRadius 0.15.7_8 and you are using a SQL database ?

    1
    1
    0 Votes
    1 Posts
    170 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.