Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    A

    @wbmstr2000 : Thanks! I will investigate it, greetings

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Squid reverse - Dead Peer detection

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Enabling Transparent Proxy slows down internet speed

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    V

    The problem got resolved by uninstalling version 3 of squid and installing squid 2.

  • BUG: bacula-fd.sh service starter tries wrong config path (fix)

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R

    @marcelloc:

    I've pushed a fix for this, upadate to latest package version and test again.

    thank you… works on both version now as expected ;)

    (Problem was the the patch must applied every reboot/"crash" situation and not only once after install).

  • SquidGuard does not work after auto updating blacklist

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Installed Snort - how do I know it's working?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D

    @Deadringers:

    Morning all,

    I installed Snort and have it setup to run all the rules on the WAN interface…it looks like it's active but how do I know if it's working?

    I have been to the alerts page and the blocked hosts page on the snort part of the firewall interface but I can't see anything that has been blocked and no alerts?

    Which leads me to believe either:
    1 - It's not working properly and I've done something wrong

    or

    2 - it has detected nothing which needs to trigger a rule.

    I don't believe that it's number 2 for a second as I have tried to load some "dodgy" sites and downloaded some questionable material as a test into a VM of mine.

    Thoughts?

    Ahh right I have it up and running properly now! :)

    a reboot of the firewall sorted things out and now I can see the logs being generated.

  • Monitoring

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D

    @rajbps:

    Hi DigitalDeviant,

    Just want to be sure the server will be in the main office and the zabbix clients will be installed on the remote locations. All running pfsense.
    Linking the site to the main site, there is an openvpn site to site link, so each office comes back to the main site but none of them talk to each other.

    So if the vpn link goes down due to the service stopping on the remote site and the link dies, how will that link start again.

    is the agent clever and will it restart the link as during that time the server will not be able to contact the agent.

    Looking forward for your answer on this one.

    Cheers,

    raj

    I believe, in cases where the agent cannot contact the server, it's possible to run the Zabbix Proxy on the same machine. From there you can set the agent to run a custom command to run the start command as well as report that the link went down. Once the Zabbix server gets the information it can send out an email. You may need to give the Zabbix agent elevated permissions. I've never tried this and I don't have a test server to try it on.

  • Imspector-dev not logging users running Pidgin with Yahoo under Linux

    Locked
    1
    0 Votes
    1 Posts
    982 Views
    No one has replied
  • OpenBGPd

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D

    Thanks guys.

    I addressed the disconnecting problem, it was my hardware.

    I tried 2.0.3 32-bit and 2.1 beta 32-bit on 2 different J&W MINIX™ D2550-HD, same issue.

    When I replaced the motherboard with a Supermicro X9SCA-F, it's all working fine. No disconnection in 3 days.

  • CRITICAL: postfix fails to start after upgrade to 2.03 release [solved]

    Locked
    24
    0 Votes
    24 Posts
    5k Views
    marcellocM

    @hcoin:

    Talk about belt-and-suspenders.  Makes me wish each package that was a vm guest that was its own iso/appliance.  As hard as the open source world tries to deal with 'dependency hell' it just never seems to work out of the workbench environment.

    On 2.1 pbi packages will be much easier…

    I'm testing firmware upgrade on one of my 3 inbound smtp servers and I it's stuck on upgrade process.
    I found a mtree process that is "indexing" /usr dir with 60bg of dcc log from mailscanner package.
    For next 2 boxes upgrade I'll remove these folders before the update and remove all packages as well.

  • Squid caching website status messages

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N

    On squid-cache.org you probably find a description for nearly all config options. An example:
    http://www.squid-cache.org/Doc/config/negative_ttl/

    And you have the possibility to check the different values for the different squid versions.

  • Snort broken: whitelist

    Locked
    26
    0 Votes
    26 Posts
    11k Views
    C

    I can appreciate the difficulty in creating a dynamic whitelist for Snort.
    Perhaps in the interim a partial solution could be getting the whitelist to at least populate on startup all the IPs from an alias, including those from FQDNs.

  • SquidGuard blocking pages

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    K

    Actually firefox is configured to remember everything.

  • Snort stays online for a while, then fails to start again…

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    M

    So far so good. I'll let you know.

    Thanks!

  • Squidguard error page does not load on blocked URL

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G

    OK - I figured out most of my issues.  For anyone experiencing some of the same maybe this is helpful:

    Internal redirect issues:
    The error page is rendered from the same interface as the UI, I found out.  I have squid and squidguard on a few vlan interfaces so that I could isolate the UI and some other devices from what is basically my "mgmt" network subnet.  Because I have FW rules in place to block all traffic from the vlan'ed interfaces to this mgmt network, the page won't render.

    External URL's not working:
    While I was changing the settings I was not deleting the browser cache on my iphone between settings changes.  So, I was getting old webpages when hitting the same sites rather than the redirected pages.  So lesson learned is to always delete your cache when testing these different settings!

  • Quagga OSPF help for a beginner

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    R

    @rengiared:

    sorry for my late response, but i have figured out where my problem was
    on the site with the 2 wans i made a gateway-group and set this on the default-lan to everywhere rule as gateway, as soon as i changed it back to the default gateway preference all works

    then you can fix it easy

    we setup a "private" alias with all internal networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16) and set on each LAN a first "external" route:
    allow any any to !private any  over gateway group (with traffic limiter)

  • MOVED: Xenserver Tools for pfsense

    Locked
    1
    0 Votes
    1 Posts
    930 Views
    No one has replied
  • PfBlocker Lists question & Errors

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    marcellocM

    @rl2171:

    Strange, if I do Deny inbound it shows red, but if I deny both it shows as green.

    If you have no rules on wan interface, pfblocker will not create a rule as you already has an deny all traffic rule.

  • Monit on pfsense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    L

    Hi Raj,

    I did it the other day:

    http://forum.pfsense.org/index.php/topic,61602.0.html

    Hope that helps.

  • HAProxy Widget

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    P

    For your information, the widget is now included in the HAProxy-devel1.5-dev18 package.
    Made a few improvements to it to also:
    -Options configurable from the WebGUI.
    -Faster server enable/disable responses.
    -Dropped socat requirement.

    Check it out if you want 8)

  • Widescreen package in 2.1 breaks

    Locked
    13
    0 Votes
    13 Posts
    4k Views
    R

    Jim,
    N/M…  I found an odd character at the end of the widgets field in the xml file.  Deleted it, restored the file and its all well now.  Remnant of Widescreen?

    Thanks,
    Rick

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.