Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N

    @SteveITS ...got it, I should have looked in the docs... I do too use Quad9 and have DNSSEC disabled, so I guess my question is pointless..

    Thank you for all the help.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    690 Topics
    4k Posts
    J

    I've read through some other posts about this, but they either didn't say whether the proposed solution worked or they were very convoluted and difficult to understand. Here is our scenario: We have 6 locations--Las Cruces (LC), Sunland Park (SP), El Paso (EP), Abilene (ABI), Fort Worth (FW), and Plano (PL). LC and ABI have software that is accessed by the other 4 locations via VPN. There are WireGuard VPNs set up between LC and those 4 locations (SP, EP, FW, PL), and ABI and those 4 locations (SP, EP, FW, PL). There is also a WireGuard VPN connection between LC and ABI. LC and ABI have 2 internet connections. SP, EP, FW, and PL each have one internet connection.

    If the primary internet connection goes down at either LC or ABI and failover occurs to the secondary internet connection, is there a way to set up the WireGuard VPN connections so that they also failover without purchasing some 3rd party application?

    Thanks.

  • Snort Netlist for IPv6 subnets

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    I don't expect this being fix until IP6v6 is fully implemented in pfSense. But wanted it to be known, that snort is ignoring IPV6 addresses and/or subnets when they are added to NETLIST and WHITELIST it seems. I'm thinking this is probably a snort issue and not pfSense since it is in the conf file looks right… Still re-searching tho..

  • Squid with upstream proxy on same lan

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    marcellocM

    Did you monitored the traffic using tcpdump on console to be sure nothing was been redirected to opt proxy server?

  • HAVP Antivirus Explanation?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D

    HAVP explore http traffic only.

  • SSL proxy server in pfsense squid package, how to

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    N

    I am not sure if everyone is understanding your question.
    with squid3 package it is possible to run squid as proxy and as reverse-proxy.

  • Snort-2.9.2.3.tbz hasnt build yet, please revert last commit

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T

    Thank you for explanation an I wonder if snort 2.9.3 will bring update packages

  • Darkstat

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid & SquidGuard

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    N

    squid2 and squidguard is working stable.
    squid3 and squidguard is probably working stable, too but you need to first intall squidguard and after that squid3.

    Blocking facebook.com:
    Remember that squid in transparent mode is only filtering http traffic. If someone uses https://www.facebook.com this will not be filtered and so squidguard cannot block this.

    To filter and block https traffic your squid needs to run in non-transparent mode.

    Another possibility would be to create a host-alias and put facebook.com in this alias. Then pfsense will regularly check and resolve the IPs to this DNS entry. Now create a firewall rule and put this alias as destination ip and select "block" for this rule. you have to place this rule on top of all other firewall rules.

  • Can't Change Squid Cache Size

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    Q

    Thanks for the info! I copied and pasted the info over the existing file (not sure if there is a better method to for this) and it appears to be working now. Tried restarting the service = worked. Tried stopping and then starting = works.

    I believe that did it. :)

    Cheers!

  • Squid3 & Squidguard

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    E

    Marcelloc,

    tried it but failed. Strange, because found that solution to in other posts.
    Like stated above. Only solution for me was installing the normal squid via the packages and then "upgrading" o Squid3!

    Do mind that I indeed did a manual install of the Perl package.

    Thx a lot for the support!

  • User Activity Monitoring on Sarg fo PFSense 2.0.1

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    what did you configured on sarg?

  • Mail Report: Sending report mail to multiple recipient

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    i have tried the following with no luck:
    xxx@gxxx.com;yyy@gyyy.com
    xxx@gxxx.com,yyy@gyyy.com

    The system log shows that mail is being sent to:
    php: /system_advanced_notifications.php: Message sent to xxxx@xxxx.com,yyyy@yyyy OK

    Any other suggestions?

  • Squid Unrestricted IPs gave acess to all class ?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Ntop: Missing host / IP?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Updated Avahi daemon?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D

    Thanks for the reply.

    Two questions, ps aux is not returning the command line params for the avahi daemon. Is there something I'm missing? This is all I see in the ps output.

    avahi  58773 100.0  0.3  6112  2948  ??  RNs  24May12 15368:26.33 avahi-daemon: running [rooter.local] (avahi-daemon)

    Another thing I noticed is that the rooter name is not correct. In the ps output it is showing rooter.local (default for pf) but it is not what is there in the configuration. In some of the issues related to the "Invalid query packet" error they mention that the .local domain may be the cause.

    I'm assuming that the browse domain and deny interfaces are passed as arguments? Is it possible that these are written to a config file and it is not being read/passed correctly on service startup?

    I'll keep poking around, I just thought I'd put this here first. Thanks again.

  • BUG: Dashboard Widget: HAVP & Antivirus Status broken for pfSense 2.1

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D

    The problem adopted

  • [SOLVED] Squid - A Few Questions

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    N

    Figured it Out.

    Exclude domain/URL from blacklist

    In the squidGuard GUI (Services > Proxy Filter):

    Open Target categories page
        Click + to add a new item
        Enter a name for the category - 'myWhitelist' for example.
        Add domains and/or URL's to the lists as needed. Entries should be separated by a space. The examples on the page show how entries should be formatted.
        As with the Common ACL discussed previously, you may set redirect and logging options specific to this category.
        Save
        Open Common ACL or Groups ACL page (where you want to make an exclusion).
        Click Target Rule List to expand the list of categories. The newly created category should show alphabetically in the list, above any blacklist categories. Find the MyWhiteList entry in the list and select white.
        Save
        Return to the General Settings tab and press Apply.

  • Package repository and nanobsd

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    D

    I cannot disconnect our WAN interfaces to test this, sorry.

    You didn't mention whether the pfSense test links work on your repository host. Did you try those URLs? I would also ensure that error_reporting in PHP is disabled as some of the deprecation warnings for the ereg functions may cause issues with the retrieval of package information.

  • New NTOP Install

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    G

    Runs fine on two HP DL360 servers here. Just install and off you go after minimal setup

  • Block With Dansguardian

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    K

    No one can help me!?
      I read somewhere that the DG favors the exception list in relation to banned list, it is impossible to block a host eg "chatenabled.mail.google.com" with proxy? I can lock in squidGuard but my problem is that i work with AD groups with names over 16 characters and squidGuard does not accept the name of the ACL more than that.

  • Redirection to custom url every 30 minutes or every 10 urls.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.