Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Adding havp lightsquid no longer logs*SOLVED*

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    F

    I'm having same issues with getting client ip address to show up on lightsquid. I'd tried the setting on the very bottom of this page http://doc.pfsense.org/index.php/HAVP_Package_for_HTTP_Anti-Virus_Scanning still no dice… anyone figured this one out yet?

    My current scheme: {inet} - [Squid] - [havp] - {clients}

  • Can't install snort 2.0 beta 4 amd64

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Clamav problem

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    N

    thanks, i will try and tell u.
    thanks

  • HAVP Dashboard widget for HAVP alerts

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    H

    index.php

    Status: Dashboard

    Right under Status

  • SquidGuard upgrade

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    D

    @dvserg:

    @rhiannon:

    Sorry, sorry

    1.2.3-RELEASE

    Thanks for you report. I check this bug.

    Thanks, fixed it for mine as well.  Running 1.2.3-RELEASE.  I like the changes to read the logs..

  • Squidguard reinstall error

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort wont update

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    ?

    The snort servers may have your ip blocked if you have updated to many times .

  • Snort interface GUI not displaying correctly

    Locked
    19
    0 Votes
    19 Posts
    7k Views
    ?

    @cdx304:

    Some tell us all if snort is fix in the lastest snapshot .Because i am not updating till it is fixed .Does not take long to reinstall just a pain !!!!

    Why is it so hard to get an answer to question in this forum .

  • Ether-wake

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    Does the built in Wake On LAN functionality not work for you?

    Services > Wake On LAN

  • Fixing Squid Transparent Proxy on 2.0

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ

    Squid+Transparent proxy should be fixed with current snapshots. It had nothing to do with that setting, but a different bug.

    That may have made it work, but not for the right reasons.

  • IMspector

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid Installation Failure

    Locked
    21
    0 Votes
    21 Posts
    8k Views
    imcdonaI

    That did it! Thank you!

  • Snort Streams5 Issue

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    Ahh now I see the issue, I kept changing the "Max Queued" thinking it was related to memcap. There is no option for changing memcap in the gui, I guess it needs to be changed by hand in the config file. I am surprised no one else has ran into this issue as well?

  • Reminder: Squid slowdown still present

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    M

    I have two boxes running at near 100% bandwidth through Squid, one is 1.2.3/Squid 2.7.8_1, the other is 1.2.3/Squid 2.7.9_4.

  • HowTo: Installing Munin-Node on pfsense 2.0

    Locked
    5
    0 Votes
    5 Posts
    11k Views
    jimpJ

    Most of the differences aren't really documented. In FreeBSD you don't need to end your scripts in *.sh, but in pfSense you do. It's just one of the many subtle differences.

  • Squidguard destination name bug

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D

    Fixed

  • From the Beginning

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D

    @DigitalJer:

    No indicator.  Just leave it alone for 10 - 20 minutes (I think that's about how long it took for my config, anyway).

    Default (tab), click the green arrow to Show Rules, and the categories will all appear when the list has finished loading.  Then just pick what category you want to deny.

    For the indicator, there are certain difficulties, but I hope to solve
    this task.

  • Downadup/Conficker-C + Pfsense

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    Cry HavokC

    Answer: No - only Windows systems can (and only then if it isn't patched or running decent AV).

    What you need to do is to read the alert - it will tell you what the source IP of the alert is.  If that IP address is the WAN IP of your pfSense host, and snort is running on the WAN interface, then it is possible the infection is on one of the 6 systems.  It is also entirely possible it is a false positive, but with so little to go on it is really hard to say.

  • OpenBGPD

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • VHOST ? Stopped with info that it`s runnning :X

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.