Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Snort no tabs Rule, Categorie and Serveur

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid in transparent mode + PPTP Issue

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid log rotation. Basic infos

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C

    Thanks for your help guys

  • IMSpector V2

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    Anyone ?

  • Igmpproxy noworking

    Locked
    67
    0 Votes
    67 Posts
    58k Views
    E

    The first packet indeed looks weird.
    Can you send me off-list:

    packet captures from downstream and upstream for the same time frame. what you see in System->Logs for the same time frame.
    Regarding 2.0 - several people reported that igmpproxy worked for 2.0 though I've never tested it.
  • How i install nod32,avg,avira on pfsense?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    Cry HavokC

    To what end?  What do you want to do with them?

    Oh, and you'd install them by following the instructions that came with them.

  • Proxy filter

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ntop 4

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    I don't know, I'm not sure I've heard of anyone trying. If it works on FreeBSD, the chances are good that it would work on pfSense, so long as you don't need GUI integration.

  • Bock URL ????

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    cyber7C

    Hi vinhk20119
    the short answer, YES…

    The long answer:
    Install SQUID/SQUIDGUARD and do it though this.

    Kind regards
    Aubrey Kloppers

  • Squid - Dynamics CRM client blocked

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    R

    sorry, this actually started again - if anyone has any ideas on what it could be please post up

    Thanks

  • Debian proxy + pfsense Squid guard is it possible ?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D

    1. Install & configure pfSense.
    2. Install configure & Squid, setup you debian proxy as parent for Squid.
    3. Install configure & squidGuard

    All examples exists in the forum and FAQ.

  • Bandwidthd Day changing

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid - How to stop loggin a single ip? - SOLVED!

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to make a crontab for backup aliases, rules everyday?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    B

    This pretty much outlines your options:

    http://doc.pfsense.org/index.php/Remote_Config_Backup

  • Squid - reverse proxy?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    L

    well, after a while i give up as time was precious. i then spotted the apache server with mod security package (reverse proxy etc) and decided to have a go at this.
    out went squid and in came apache (this is on an alix 2d3 with cf)
    i had this horrible feeling that it was too much for the poor old alix and this was confirmed by the amount of packages etc that it installed with it.
    the alix started to creak and i couldn't access the web config. it became so unresponsive, i couldn't hardly do anything with it.
    so, from the shell….. lots of pkg_delete -f -a with lots of /etc/rc.conf_mount_rw
    after about 7 runs, i finally clear everything out so no packages. i even delete the remaining traces of them.
    i'm on the net but no web configurator. a check of the logs reveals missing dependancies. no prob's, i have another pfsense and i copy the missing shared files over.
    but still, no web configurator. it's starting to beat me now. i have a config backup etc so i keep ploding away.
    everything is working fine but the web configurator. ummm, check the config and i can't see any port under webgui so i add a <port>443 in front of</port> thinking that's why i couldn't get onto it.
    crash.... now i'm really stuffed, no web either now. i'm off the net with a few choice words. i now remember, i tried an upgrade to v2 and had that on the other slice (silly me, why didn't i duplicate it back to 1.2.3 before all of this? lesson learnt! won't happen again!)
    maybe time to upgrade to v2 as i have this other slice....... no, i get the usual probs with it not remembering vlans etc.
    no prob's, i will configure it with minimal lan and from there, install backup config. no, it's beat me again with "a scalar value error" and just won't let any lan be configured under v2.
    shock horror..... i don't want to remove the cf card and reinstall etc. i'm not on the internet at this time and i haven't got a copy of pfsense with me.
    so, now i'm back into the config and removing the <port>443 and pfsense is back up but still no web config.
    and then it hit me.......
    try an upgrade with v1.2.3 on the v2 slice that doesn't work. so i upgrade this slice to 1.2.3 and voila...... pfsense is backup and running with web config. phew!

    moral of the story?
    1. have a working opposite slice & config backup before adding any packages
    2. don't go against your better judgement (me by loading apache etc on an alix) unless you have time to spare
    3. don't panic. sit back and think it out and you can get there in the end. you learn a bit too!

    now.... how can i waste my next sunday?</port>

  • Snort update issue

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    B

    Is nobody else seeing this, I notice another post relating to this but for pfSense V1.2.3, the common factor is the Snort package version.

    I had to manually install the rules but this isn't my first choice of ways to pass the time.

    I'd appreciate it if anyone running V1.35 could try to update and post the result (PS although my version says 1.35 on the package page the package reports v1.34 - and yes I have re-installed three times).

  • Snort, Help Blocking Anonymous Proxy Usage

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    L

    have you also tried using opendns as your forwarders? then just set a firewall rule that only opendns can be used.
    i find opendns quite effective and it's another layer for them to try and overcome.

  • Squid/squidguard kills connexion client

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    C

    @brcisna:

    clutch68,
    I don't like having this teachers workstation "outside" of the firewall for sure as we have so may possibilities of viruses in a school setting. Kids are just 'trying' to kill every system on the lan, it goes without saying.
    At least the connexion client is usable with this cludge,,,:).

    Hi Barry, glad to be of help. I could certainly be wrong here, but simply bypassing the proxy should not further expose the client PC. Although a local firewall is prudent, your staff client should also still be "behind" the firewall protection of the pfsense box, just as it was before the proxy bypass. In other words, a squid bypass doesn't necessarily = firewall bypass. The client is simply not routing outbound web traffic through squid.

    This post is begging for correction if anyone has further thoughts on this.

  • How modify snort rules

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    I

    I found that disabling the 'snort_web-client.rules' #15306 (WEB-CLIENT Portable Executable binary file transfer) worked for me.  Cleared out the blocked and all seems to be working again.

    Suspect there's another little gremlin in there as well.  Hell of an 'all-inclusive' rule to break Windows Updates  ::)

  • How to block certain websites

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    If you read the forum and doc wiki you will find complete howtos that go over everything necessary. It's been asked and answered dozens if not hundreds of times.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.