Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    H
    We installed haproxy on Netgate 8200 device 25.07.1-RELEASE (amd64) installed acme certificates and get certificate from letsencrypt, everything ok. checked ssl offload in frontend and selected the acme generated certificate under SSL Offloading. result after Apply Changes: Errors found while starting haproxy [NOTICE] (72045) : haproxy version is 2.9.14-7c591d5 [NOTICE] (72045) : path to executable is /usr/local/sbin/haproxy [ALERT] (72045) : config : Couldn't open the ca-file '/var/etc/haproxy_test/clientca_WAN_117.pem' (No such file or directory). [ALERT] (72045) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind x.x.x.x:443' in section 'frontend' : 'ca-file' : unable to load /var/etc/haproxy_test/clientca_WAN_117.pem [ALERT] (72045) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (72045) : config : Fatal errors found in configuration. also package _devel has the same issue. on other boxes where haproxy was configured on 24.11 - upgraded to 25.07.1 its working. BUG ?? so what can we do now -bolded text we need this function. thank you all in advance
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    B
    @Greyhat I think it's useful to work with what we've got and figure something out for the (i hope) edge cases later. So for the JSON I figured you can actually use an existing suricata integration by co-opting their pipelines.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @netboy Well then it would seem that you've successfully resolved your root issue. Nice work.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    johnpozJ
    @netboy do you have this docker available - this is actually pretty slick. I didn't think about monitoring the one connected to my nas.. It monitors it for shutdown of the nas, but it be nice to see such info off of it. I have one behind my tv I monitor with pi I have connected, that is my ntp server as well. I keep meaning to put another pi I have for the one in my av cab to monitor that one - just haven't gotten around to it. I have 4 total in the house of the cyberpower ones.. Be nice to throw them all into 1 place to monitor.. One I monitor on my pc, with misc network gear plugged into that, one my nas monitors for its own use, pretty sure the pfsense is on that ups along with my APs I think - but didn't think of turning on its server function and point pfsense to it. You have inspired me to to a better job of monitoring mine.. Mine are all cyber power 1500s, would have to double check models but I know at least 2 of them are the cCP1500PFCLCD I think your docker would be perfect for my use as well.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    92 Topics
    638 Posts
    L
    @Vad-B Interesting indeed! I just tried to fill the Pre-authentication Key with file:/dev/null. I get an crash in pfsense after some time, but when I login again is saved. For me this for after service restarts at least this solves it, including the issue with the routes not being advertised even set in the WebUI. Havent done an full restart of pfsense (yet)
  • Discussions about WireGuard

    712 Topics
    4k Posts
    D
    I feel like I’ve followed every guide there was. I was able to get nordvpn via wireguard on my pfsense but for the life of me I can’t get my own wireguard server working. I can’t even get a handshake. I have all the firewall rules mentioned, the gateway, interfaces. Etc. I got no clue what to do at this point. Can anyone please help? I’ll provide any information required I just don’t even know where to start I’ve tried every YouTube video possible and guide it’s strange. I was able to get nordvpn working but I can’t get my own.
  • OpenVPN Multihop Package

    6
    3
    2 Votes
    6 Posts
    2k Views
    A
    @John2893ax Hello, can you update pkg for 24.03?
  • Thoughts on CrowdSec

    2
    0 Votes
    2 Posts
    472 Views
    A
    @beloc I have tried him, looks working. Can be integrated with Suricata. They are making update for pfSense, but still not in official repo. If will support official will have to test again)))
  • Requesting help setting up Bind9 on SG1100

    1
    0 Votes
    1 Posts
    136 Views
    No one has replied
  • Bind config window blank - Error Msg on nslookup

    1
    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • Howto enable DNSSEC for a domain configured in Bind

    5
    1
    0 Votes
    5 Posts
    1k Views
    A
    @megapearl said in Howto enable DNSSEC for a domain configured in Bind: Now finding a way to save the keys in the config xml or write them to a different location to make them persistent upon reboot Also looking for a way to save my slave zone. After reboot my slave zone is empty, if there is no master. https://forum.netgate.com/topic/188369/slave-zone-in-bind-9-17/3
  • CloudFlare WARP, WARP+ and WireGuard working setup?

    1
    0 Votes
    1 Posts
    407 Views
    No one has replied
  • Problem with Avahi mdns after upgrade.

    4
    0 Votes
    4 Posts
    760 Views
    GertjanG
    @trautmann Avahi doesn't know if traffic goes over wires only, or if a part of the path is over Wifi ....
  • System Patches Package v2.2.11

    1
    5 Votes
    1 Posts
    953 Views
    No one has replied
  • New 2.7.2 Install. Packages are displaying in triplicates.

    4
    1
    0 Votes
    4 Posts
    518 Views
    J
    @SteveITS Looks good now... That was weird. Thanks.....
  • arpwatch database edit

    2
    0 Votes
    2 Posts
    913 Views
    johnpozJ
    @jester95 had a sim thread recently - the db files are here /usr/local/arpwatch https://forum.netgate.com/post/1163611 the dat files seem to be just text files, so you should be able to edit them I would think.
  • Please Consider Netbird Support | The Truly Free Tailscale Alternative

    1
    5 Votes
    1 Posts
    2k Views
    No one has replied
  • pfSense 2.7 and UDP Broadcast Relay

    9
    1
    1 Votes
    9 Posts
    2k Views
    S
    @Nyxtorm Yes, I had the same feeling; perhaps the best thing is to have the TVs in the same VLAN. In the end, I switched to OpenWRT; I find it better for home use.
  • arpwatch and voluminous amounts of SPAM

    9
    0 Votes
    9 Posts
    744 Views
    J
    Nice! Enjoy!
  • help with ntopng

    4
    0 Votes
    4 Posts
    673 Views
    dennypageD
    @detox To be clear, what I meant was that I don't know if the new pfSense-pkg-ntopng version is in the pfSense community repo yet. You should check in System / Package Manager. GeoIP will not work until a new version of pfSense-pkg-ntopng is installed because the old version does not provide the Login ID. [MaxMind now requires a Login ID as well as the License Key. There are several posts discussing this in the forum.]
  • 23.09.1 from 23.05.1 freeRadius broke

    9
    0 Votes
    9 Posts
    1k Views
    P
    @vanwinkle-rip, thanks for posting this! The log suggested to make that change but didn't specify where. You pointed in the right direction. Do you or anyone else know how to make this change permanent? Any changes in the GUI revert the changes. Maybe we can create an eap.local file or something like this?
  • Configuring UDP Broadcast Relay

    25
    0 Votes
    25 Posts
    7k Views
    R
    @iptvcld i'm sure there's a more eloquent and effective way to find out but I've actually just googled and messaged various companies to ask them what the udp forwarding port the app uses and been moderately successful. Can't get the the printer to reliably talk across the vlans but that could be a "printers are terrible" thing
  • System Patches Package v2.2.10_1

    3
    8 Votes
    3 Posts
    2k Views
    jimpJ
    They can't be in the release notes immediately along with the release since the issues are marked private until after the release is out, but they'll be added shortly.
  • Netmap root directory

    Moved
    1
    0 Votes
    1 Posts
    163 Views
    No one has replied
  • Rebooting pfsense on wan gateway failure

    2
    0 Votes
    2 Posts
    886 Views
    styxlS
    @ipfftw Try this link text
  • FreeRADIUS

    2
    1
    0 Votes
    2 Posts
    370 Views
    P
    The screenshot I posted above got removed somehow so I'm posting in text sshguard 14637 Blocking "192.168.4.103/32" for 480 secs (1 attacks in 0 secs, after 3 abuses over 693 secs.)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.