Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • How do I use the "IP Range Aliases" package?

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    RonpfSR

    I m using 1.2.3

    Installed IP Ranges, seems to work fine , then it start behaving strange … range collapsing etc
    (I was trying to define a 10.0 range minus 3 subnet of 256 hosts, maybe I was doing wrong)

    so I re installed the package (without removing it)

    That broke the config file, could not do anything in the https or at the console.

    I reinstalled and start from scratch again (its a new setup anyway)

  • Squid don't open some sites

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    E

    Sorry pal, but that site was REALLY SLOW TO HELL on my connection even WITHOUT squid, it takes YEARS to open up, maybe you could try something else not so dawn slow to test it.

  • Squid and squidGuard simply aren't usable

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    D

    SquidGuard updated:

    Removed extra columns in Dest table Fixed support IP addresses in Dest-Domains.

    *Note: Now 'Not use IP options' not affected for 'whitelist'.

  • APCUPSD Installation

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    M

    on witch version 1.2.3 or 2.0 ?

  • SNORT - ignore packets sent on specific port from specific local machine

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Missing lightsquid package in 1.2.3

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D

    OK. Here I can not help.. :-[

  • Squid transparent fail with captive portal

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    Block traffic to the squid port from hosts on that subnet.

    You may need to disable the anti-lockout rule for that to have any effect.

  • [exclude_hosts] let me try again

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J

    thanks for the reply.

    unfortunately a fresh install is not an option since our proxy needs to be up 24/7 so serve 100+ client machines (large hospital).

    do you think there might be another way to edit a (xml?) file to simply include the missing lines (refer your attached screenshot).

    regards.

  • Snort Auto Block feature Prob/possible Enhancement?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CountryBlock email don't work

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    K

    Hi Bernard,
    You may want to post your question here
    http://forum.pfsense.org/index.php/topic,25732.0.html

    TB watches this thread and is very responsive to questions and issues. It is the main CB thread.

    I dont think he implemented the ability to have the username info blank. I think all fields for the most part need data. I could be wrong.

  • Installed Squid and Squidguard but it's not filtering.

    Locked
    14
    0 Votes
    14 Posts
    11k Views
    D

    @nambi:

    I also set the port you specified, can you use any port or is 3128 what is recommend?

    Default port is 3128

  • Snort rules upload

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Live logs-endian

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    D

    Yes i mean something like sqstat!
    Ok i dont always check live logs mate  8) but if a user is downloading a big file or enter games.com etc i have to know it.
    Many thanks though

  • PfSense 1.2.3-RELEASE nanobsd + Squid + SquidGaurd remote logging

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    Not likely, at least not easily.

  • Vhosts plugin blocking filter reload

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How do I reset BandwidthD's Figures?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    M

    http://devwiki.pfsense.org/BandwidthD

  • MOVED: cannot install imspector under [2.0B4]

    Locked
    1
    0 Votes
    1 Posts
    953 Views
    No one has replied
  • MOVED: snort remove blocked list after reboot? [2.0B4]

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid & QuidGuard - Update webinterface after manual modifications

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    B

    This my script :

    update_whitelist.sh

    while read ligne
    do
    newchaine=$newchaine$ligne' '

    done < /var/db/squidGuard/listeblanche/domains
    echo New Chain : $newchaine

    sed "s/(<domains>)[^<]*/\1$newchaine/" /cf/conf/config.xml > /cf/conf/result
    mv -f /cf/conf/result /cf/conf/config.xml

    /usr/local/bin/squidGuard -C domains
    /usr/local/etc/rc.d/squid.sh restart</domains>

    1. In /var/db/squidGuard/listeblanche/domains I add new URL (one per line) on my main pfsense
    2. Every day, I synchronize my file "domains" with cronjob (From my main pfsense to others pfsense)
    3. Every day, after this synchronization, I launch the same script on others pfsense with a cronjob.

    It's okey on one pfsense. I have to test with others.

    One problem stays.
    I hope it will be possible to improve this process to do a bidirectional synchronization.

  • Package Configuration Understanding?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.