Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Snort and SQL Injection (Microsoft SQL Server + IIS): SOLVED!

    Locked
    8
    0 Votes
    8 Posts
    9k Views
    M

    Well, I tried the "custom.rules" feature.

    It really does what it's supposed to do, changes on that rules are saved in the config.xml file and are recreated during the rule update.
    Just, it's quite slow when you save the rules, I don't know what actions are made on that post, but anyway to apply the changes I need to restart-snort manually.

    Ciao,
    Michele

  • Proxy Filter + LDAP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HAVP after Squid deletion

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blank Spaces in Menus w/ Widescreen and Firefox Dev

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    B

    I have the issue with the menu's appearing under the traffic graphs with the widescreen addon.

  • Dansguardian fails to start

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K

    I don't know how to do that (where would I enter that command and what is SysV?). But what I did was uninstall, reboot, reinstall. Still error persists.

  • 0 Votes
    8 Posts
    2k Views
    jimpJ

    it should, yes, make a new interface, a proxy vm, and a vswitch to connect them (on their own subnet) and then you should be able to make that work.

  • Get Snort Alerts out of pfSense for email alerting?

    Locked
    7
    0 Votes
    7 Posts
    8k Views
    M

    @kevross33:

    Use unified2 and barnyard in Snort package to write it off to an external database and use snorby (snorby.org) to email you reports.

    I tried this, but I could never get anything to populate in Snorby. I'll research it again.

    You wouldn't happen to know of a good how-to on the web would you?

  • Snort Active Checker

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J

    Oh thank you ever so much for that, probably me being lazy as per usual to actually go back in and keep re-enabling it (or usually when I forget to check if its running) ;D

    Thank you ever so much and I will give that a whirl!

  • 0 Votes
    3 Posts
    3k Views
    N

    I'm having issues with the HTTPS reverse proxy as well, however the HTTP reverse proxy works fine.

    Currently I'm getting a squid error page saying Access Denied. Access control configuration prevents your request from being allowed at this time.

    Also I believe I found a bug in the HTTPS reverse proxy settings, you need to manually put in the listen port 443. By default it listens on 80 even though it says 443, just manually put it in there.

  • SquidGuard 1.4_2 pkg v.1.9.1: error message during updating

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    Maybe blacklist too long, more that '/tmp' size

    The black list was the "shallalist", where 300 MB should still be plenty. Explicitly executing squidGuard_blacklist_update.sh from the tmp dir does not give any error message.

  • Varnish3 package quite broken (fixed July-27-2012)

    Locked
    20
    0 Votes
    20 Posts
    4k Views
    marcellocM

    @blundar:

    Forgot patches!!!

    I'll merge a multi daemon varnish soon, I've applied the cdata fix on my updated files and varnish started fine.

    Thanks for your tests and feedback

  • Snort - reverse DNS on blocked IPs?

    Locked
    1
    0 Votes
    1 Posts
    899 Views
    No one has replied
  • SquidGuard not work on vlan interfaces

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    E

    Finally i managed to get it work BUT when there is a redirection to error page (e.g. for a denied host) the system tries to redirect to parent interface IP address…Furthermore, ont only this but it tries to redirect to the old IP address of parent interface (I have changed it..). Does anyone have any idea?

  • Lightsquid reporting - Am stuck, are there lightsquid logs I can look at?

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    T

    Hi marcelloc,

    Sorry for the delay replying - I had never used/installed sarg before so wanted to play with it a bit before commenting.  SARG worked fine as it happens.  I got the realtime reports straight away.  After playing with it a bit I got the scheduled reports too.  I can see plenty of output in /usr/local/sarg-reports.  I'm not 100% sure I understand all the SARG options on the GUI, but I'm sure if I played with it a bit I would get used to it.

    I "could" switch over to using SARG, but if it's possible I'd like to continue using lightsquid.  Does the fact that SARG works tell me anything (other than the fact the SQUID is logging away correctly and that SARG is an option for me now!)??

  • Avahi suddenly hates me

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Manually Installing packages with NO internet connection

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    There isn't a way to install them manually over SSH.

    You could clone the package repo and setup your own local copy (check the doc wiki) and install them from a local server instead.

  • Snort stopped working again (last update)

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    M

    @Gradius:

    Sigh.

    Fixed.

    It is working for me on a test box I have. Snort Auto updates enabled every 6 hours no problems.
    Snort not snort-dev

    intel atom 8 gig memory 64 gig ssd.
    2.1-BETA0 (amd64)
    built on Wed Jul 25 09:38:52 EDT 2012

  • Snort 2.9.2.3 pkg v. 2.5.1 - Completely fresh installation error

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    E

    Sorry fixed.

  • HAVP new install - am I missing something?

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    jimpJ

    fixed
    https://github.com/bsdperimeter/pfsense-packages/commit/50d8ce945282aff349149de3a4fd590e364b54c7

  • Fail to install a pkg

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    W

    Oh yes…
    a short view in fstab... I had seen this in a second....

    Other Distries said... Permission denied that were usefull for me...

    All fine now ;)

    Thank you!

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.