Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Dashboard gone after deinstall of Snort

    Locked
    17
    0 Votes
    17 Posts
    5k Views
    bmeeksB

    Updated to reflect push of Snort Dashboard Widget ver 0.3.4

    A new version of the Snort Dashboard Widget will hopefully go out soon is now out.  The new version is 0.3.4.  If you have the Snort Dashboard Widget installed, you most definitely want to update it to this latest version!

    I just discovered a rather nasty little bug that causes the Snort Dashboard Widget to crash the package startup for Snort upon a reboot of the firewall.  It only shows up when the widget is installed.  I have tested the fix for this and it works.  I inadvertently "included" an incorrect include file as part of the uninstall routine I added for the widget… :-[

    Bill

  • Avahi not working as expected.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Lightsquid - Time spent on a website?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    N

    And perhaps SARG package can offer you some more specific information but you have to check this by yourself because I don't have any experience with SARG.

  • Radius user name case sensitive sensitivity

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    N

    There is some dialogue on freeradius mailing lists:
    http://lists.freeradius.org/pipermail/freeradius-users/2013-April/066212.html

    Alan Dekok is one of the developers of freeradius. He is an absolute expert in freeradius but - in my opinion - he is not very polite when posting on the list.

    As far as I understand him you could add something like the following in "../raddb/policy.conf"

    if (User-Password) { update request { User-Password := "%{tolower:%{User-Password}}" } }

    Perhaps you cann follow this conversation and test and if you found a solution post it here that we can implement this into GUI.

  • I have problems with sqlite3

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    The command you run only downloads the sqlite program/libraries, it does not update the PHP module.

    Give a 2.1 snapshot a try, it should have a more up-to-date PHP library for sqlite.

  • How to do unified reports?

    Locked
    1
    0 Votes
    1 Posts
    775 Views
    No one has replied
  • Pfsense embedded with snort and squid

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    bmeeksB

    @costasppc:

    Snort and Squid are not recommended in embedded installations. You will have memory hogs. Also Squid needs disk space for caching, which is not much in CF card installations.

    Best regards

    Kostas

    I agree for Snort.  It can easily consume more than 1 GB of RAM just by itself with a moderate rule set.  I've had some 1 GB RAM virtual machines used in my Snort testing start swapping out to disk with Snort and a full set of rules running.

  • SNORT WISH LIST!!

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    S

    Quoted Bill for the Open Issues.

    Wanted to seperate the two threads :)

    @bmeeks:

    Folks:

    I think we may be narrowing down the list of open issues in the current Snort package version 2.5.6.  Here are items that I am aware of still open.  Actually I think these are all holdovers from the 2.5.5 package.  I have working fixes for these in my current test environment.  I just want to be sure I've caught everything major before I push out a 2.5.7 package update.

    OPEN ISSUES

    1.  Snort not saving edits to the Rules Update and Remove Blocked Offenders cron jobs.

    2.  Snapshot updates on 2.1-BETA systems do not fully complete the Snort rules update post-upgrade and Snort does not start until a manual rules update is performed.

    3.  Snort not auto-starting after a package reinstall with prior saved settings.

    Did I miss any big ones in my list?  I wanted to double-check and see if anything else was lurking out there before pushing another update.

    Bill

  • PhpSysInfo

    Locked
    18
    0 Votes
    18 Posts
    7k Views
    T

    Same problem I just had.. Not sure why it failing.. Will look at something and get back to you later.

  • 20th april snaps, squid issue

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    X

    can some1 give me commands to run to output the firewall rules in normal condition and when traffic stops, mayb it will provide more info

  • Snort 2.9.4.1 pkg version 2.5.6 – Change Log

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D

    Again, thank you for all your hard work and bug fixing!
    Updating from old version to the new one worked (again) without any problems!

  • Squidguard Success on pfsense 2.01

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    F

    Thx alot for the tip, I'm going to try this. I was going crazy no being able to install squidguard without crashing pfsense.
    I just tried this and it works with 2.0.3 !

  • Siproxd Update

    Locked
    11
    0 Votes
    11 Posts
    4k Views
    R

    Hi!

    I have had big problems with my siproxd but your guide has helped alot. The problem I had were that the state between my firewall and my sip provider kept dropping. After I set the rule up that you suggested it worked much better and the state help up for some days. But this morning it was down when I came to work.

    I have 6 phones which are all registered in siproxd's interface. I have setup the rule as I think you did: on the Wan side the sip provider is set a source and my wan adress on the destination, port 5060 over TCP/UDP.

    Are there anything I can setup for forcing the state not to go down, much like a ping can keep an VPN connection up. As of now from what I can understand it keeps up as long as possible but nothing stops it from going down if the resources are needed elsewhere. Perhaps there is a way to get the state up again if it goes down? The only way that I found to get the state up again is to make an outgoing call from one of the phones.

    Hope for some help. Cheers!

    //Peter

  • Squid Filter

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    marcellocM

    @nathanpinotti:

    There's a VPN rule allowing all traffic to anywhere. Could it mess my LAN rule up?

    Not at all. Lan traffic pass by lan rules and floating tab, not vpn interface.

  • How to dansguardian auth with ldap

    Locked
    15
    0 Votes
    15 Posts
    6k Views
    marcellocM

    web request –> nat(80 redirect to 8080) = transparent proxy

  • Snort 2.9.4.1 pkg v. 2.5.5 Issue(s)

    Locked
    111
    0 Votes
    111 Posts
    30k Views
    K

    @sronsen:

    This error message almost always means you have mixed 32-bit and 64-bit libraries on the system.  These "unsupported layout" errors have happened before for many other packages besides just Snort, and each time it's caused by having a mix of 32-bit and 64-bit stuff on a system.  In particular this error can happen when 64-bit libs wind up on a 32-bit box.  I can't tell you how this might have happened, but I'm pretty sure that's what is wrong now.

    I had to reformat the drive and reinstall pfSense, but I finally got Snort working.  If I could only figure out why the pfSense installation won't work from a USB CDROM, I wouldn't be so put off, but the installation asks for a mount device and fails when a valid one is entered.  If I plug in a SATA CDROM drive with the same disc, it just installs to the proper drive without asking me anything.  This is on a rack-mounted PC w/o any external bays, so I have to unmount the PC and open it up to rerun the installation.  Ugh!  I think I'll pass on pfSebse and Snort updates for the next year.

    I installed my current config from usb. My 1u system has no optical and I didnt have a usb cdrom. Mine installed just fine using the usb install method.. Maybe try that instead of cdrom?

  • Bandwithd with windows DNS and DHCp

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    A

    After the revers zone issue was corrected, everything works fine now.

    Thanks for the help.

  • Multiple pfsenses and Snort updates?

    Locked
    13
    0 Votes
    13 Posts
    3k Views
    S

    It could be the load on the specific server if it located in two different places :)

  • Bandwidthd giving errror

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    A

    i have re-installed bandwidthd and it is working now. However, I ended up using ntop cause that is the only bandwidth monitoring that support multi-wan.

  • Help: Add External Cache

    Locked
    1
    0 Votes
    1 Posts
    775 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.