Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Other packages in pfsense

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    K

    Many Thanks dvserg!
    i will try that tomorrow on our test box.

  • Packages Offline availble?

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    marcellocM

    You will need to do it under the roof.

    Backup packages tgz install and all xml files.

    After that a manual restore (via console) of config.XML

    Maybe there is another way that I don't know.

  • Missing libraries for amd64 version of cyrus-sasl-2.1.25_1

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    marcellocM

    They are part of freebsd install, that's why it's not included on port package build.

    Some time ago core team asked to do not include binaries/libs on package repo and not everyone that uses postfix need sasl.

  • Problem whit OpenVPN

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Package(s) install/uninstall - previous configuration remains…

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    marcellocM

    @phil.davis:

    It would be impossible for a generic package cleanup interface to reliably know which sections belonged to which package. Packages would have to declare these somewhere, and I don't think they do a present.

    Or include this option on package gui, just like snort does.

    "remove all config on package uninstall"

  • How to delete 400 GB in /usr/local/sarg-reports/ ?

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    U

    Ok, after 3 days files are deleted…
    @jimp: I tried multiple SSH sessions but I just want to find some magic hack and delete like NTFS - just mark file as deleted and space is free. But now I know - just wait  ;)

  • Spamd Package - set up to handle multiple smtp host domains

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Unable to upload file to TFTP server…

    Locked
    2
    0 Votes
    2 Posts
    2k Views
  • SQUID3 HTTPS fixed but WAN PPPOE problem with SQUID3

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    N

    Make you squid only listening on LAN interface. Not on any other.
    Check "Allow users on interfaces" and check "Transparent proxy".
    check "use DNS v4 first" and do NOT enable "cache dynamic content"

    Do not use any other custom options. Squid will run and start with the default settings very well.

    I am sure your problem is not PPPoE but something wrong on squid config.

    Perhaps you can post screenshots of your squid GUI configs.

    Further - if you run squid you can rund squidguard or dansguardian and use predifines blacklists for porn. Then you do not need to do that with openDNS.
    You can also try to use some other DNS like 8.8.8.8 or 8.8.4.4 instead of OpenDNS - just for testing.

  • Packages vanishes after reboot

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    K

    Thankyou phil jee.
    I was nearly getting MAD.
    Thanks

  • 0 Votes
    11 Posts
    4k Views
    marcellocM

    Thanks for the feedback, this patch was applied to squid3 install.

  • As soon as I install Squid3, https does not work anymore

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    marcellocM

    @quetzalcoatl:

    If wan is a pppoe connection squid still does not work.

    I have squid3 with pfsense 2.0.2 and pppoe working without issues.  ???

    @quetzalcoatl:

    Also if i want squid to start caching for real, i have to disable caching for dynamic content.

    It's a Know issue. The dynamic content acls was implemented based on squid3 wiki page, it needs fixes/improvements.

  • Packages Server down? (SOLVED)

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    M

    Thank you.

    I can access normally too now.

    I will keep the above URL handy!  :)

  • Package list

    Locked
    3
    0 Votes
    3 Posts
    987 Views
    jimpJ

    Split this off into its own thread and sent a warning, but since the linked site doesn't contain any ads it isn't really "spam" in the traditional sense, just a lot of self-promotion.

    Someone may find these blog post(s) helpful, but they should only be posted in relevant places, and with only 1-2 links to articles that are specifically relevant to a given topic.

  • Suggestion for SNORT package…

    Locked
    1
    0 Votes
    1 Posts
    725 Views
    No one has replied
  • SNORT is driving me crazy…...!!

    Locked
    21
    0 Votes
    21 Posts
    9k Views
    S

    After the table increase, then I upped memory to 4GB and rebooted.

    IT WORKS!! No issues at all and even snort started without complaints :D

    Thx mate! Really appreciated!

  • SquidGuard XMLRPC Sync - has anybody done that ?

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    marcellocM

    @Nachtfalke:

    Hehe, "where" is the Apply-function ? php, html and java is not my friend ;-))

    I think that a good place(just a fast look, not a deep look ;) ) to put it is in squidguard_configurator.inc file at function sg_reconfigure()

    or include it before sg_reconfigure and exec sg_reconfigure after update.

  • Barnyard2 thinks snort spool logs are empty

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort crashing after adding any rules

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    N

    you were right.  I have been messing with the preprocessor rules and the various categories.  It's working now, but i noticed the "Sensisitive data searches for CC or SS# in data" make it crash with no rule sets enabled. weird.  thanks for your help. Are the ET rules better than the snort rules?  What is a desired combination that isn't too restrictive, but blocks incoming attacks. I am not as much worried about outgoing issues.

  • Ospfd summary route

    Locked
    1
    0 Votes
    1 Posts
    925 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.