Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • What happened to unbound?

    Locked
    17
    0 Votes
    17 Posts
    7k Views
    T

    just try the normal url to your current running 2.1 pfsense.. and then add    /services_unbound.php

  • Snort in transparent mode

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    C

    Snort listens on network interface(s). It doesn't matter if they're bridged, routed, NATed, or just a span port from a switch that isn't involved in moving/filtering the traffic of the network at all. It's all the same.

  • SNORT: do i have to activate rules one by one ???

    Locked
    1
    0 Votes
    1 Posts
    881 Views
    No one has replied
  • Sarg Realtime Report Error

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM

    check all sarg config options, reports to generate and create a schedule to run.

    Default sarg options has (yes) after it's description. Select all to create a default config.

    http://forum.pfsense.org/index.php/topic,47765.msg290819.html#msg290819

  • LightSquid and sqstat

    Locked
    14
    0 Votes
    14 Posts
    7k Views
    J

    So, sorry! I am only able to answer now…  ;D

    Log rotation is set under Squid (i.e. Proxy Server). Go to Services->Proxy Server->General->Log rotate.

  • Squid and http 1.1 support

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    marcellocM

    Squid 3.2 isn't ported yet to freebsd/pfsense. As soon it's ported, we can create the package.

  • Squidgaurd and Squid 2.0, only blocking sites for some computers

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    N

    Facebook can be reached via httpS and this will not be filtered by a transparent running squid proxy ans so squidguard cannot detect this traffic.

  • Squid, Multiwan, Firewall Rules Problem

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort instance using up 100% of one core at 80-85Mbps

    Locked
    8
    0 Votes
    8 Posts
    10k Views
    A

    @tester_02:

    What version of pfsense.  Also 32 or 64 bit?

    Thanks for your reply, tester_02!

    I am running 2.1-BETA0. 64-bit (amd64).

  • Snort - digital bond rules/preprocessors

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    V

    That's a fair call, thanks for replying.

    I tried the patches they had on their site with little success after compiling snort from source on a *nix build.

    That being said I'm in the same boat as you, very little time to spare and need to come up with a proof of concept to protect SCADA networks/devices.

    Would i be able to get a copy of the 'private' or 'deprecated' build to prepare a paper? Just need to do a real basic inside/outside design to show mitigation strategies.. Its either that or i look at getting an ASA with the SCADA rules.  :-\

    Specifically interested in the Ethernet/IP and CIP rules/attacks

    Thanks again for your time

  • Inpect SSL?

    Locked
    1
    0 Votes
    1 Posts
    805 Views
    No one has replied
  • OpenBGPD 0.5.6 + RIP = BGP routes disappearing

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    E

    @Gloom:

    Probably a silly question but you've not got them both active on the same interface have you?

    No: BGP was running on the WAN interface, RIP on the LAN one.

    I've also tried to customize the /etc/gateways file with no luck: now I'm unable to supply the ones I've tested with.

  • Squid service not srating

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K

    version of pfsense 2.1
    version of squid - squid2

  • Sarg: Use Captive Portal logins (MS AD)?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    Only when squid can auth users using a "captive portal plugin"

  • Allow .exe through squid proxy

    Locked
    14
    0 Votes
    14 Posts
    6k Views
    M

    Upgraded to 2.7.9 pkg v.4.3.1 and added the IP DESTINATION bypass.

    All seems to be working now.

    Thanks!

  • Imspector-dev - new gui options and msn2011 support

    Locked
    12
    0 Votes
    12 Posts
    3k Views
    marcellocM

    maybe this post from haproxy can help you.

    http://forum.pfsense.org/index.php/topic,42852.msg221708.html#msg221708

  • 0 Votes
    2 Posts
    1k Views
    marcellocM

    Allow access to squid port and block all traffic on users interface.

  • Squid in transparent mode and dmz..

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    Wah so simple and it just work…

    /Michael

  • Snort Memory Usage

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    D

    From my experience, yes this is normal. Use AC-BNFA for memory performance.

  • Snort Alert Logs

    Locked
    1
    0 Votes
    1 Posts
    934 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.