Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    D
    I recently start have trouble saving my HAProxy configuration due to a error. It keeps adding clientca_ in front of the SSL offload certificate name. On file level this file does not exist! I tested with both HA Proxy plugins, the regular and dev version. I tried to regenerate the SSL (Lets Encrypt) but this keeps happening. [ALERT] (45623) : config : Couldn't open the ca-file '/var/etc/haproxy_test/clientca_shared-frontend.pem' (No such file or directory). [ALERT] (45623) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:28] : 'bind 0.0.0.0:443' in section 'frontend' : 'ca-file' : unable to load /var/etc/haproxy_test/clientca_shared-frontend.pem Does anybody have the same behaviour? to be clear I have the 25.07-RC running. The relevant part of /var/etc/haproxy_test/haproxy.cfg frontend shared-frontend bind 0.0.0.0:443 name 0.0.0.0:443 ssl crt-list /var/etc/haproxy_test/shared-frontend.crt_list ca-file /var/etc/haproxy_test/**clientca_**shared-frontend.pem verify required crl-file /var/etc/haproxy_test/**clientcrl_**shared-frontend.pem
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC
    @rlrobs Yes it’s still working fine here.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K
    @pulsartiger The database name is vnstat.db and its location is under /var/db/vnstat. With "Backup Files/Dir" we are able to do backup or also with a cron.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    M
    I resolved this by accepting the T+Cs via https://www.maxmind.com/en/accounts/1205389/geolite2/eula
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG
    @EChondo What's your pfSense version ? The instructions are shown here : [image: 1753262126227-1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png] A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate. @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy: I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess. No need to wait x days. You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    J
    @div444 i'm finding the same - did you find a solution or did reverting fix it? Hoping there is a patch fix or something to get it working! Rather not rollback if i can avoid it
  • Discussions about the Tailscale package

    90 Topics
    578 Posts
    T
    Re: How to update to the latest Tailscale version? I am on latest released Netgate 6100 pfSense PLUS v24 ( pfSense_plus-v24_11_amd64-pfSense_plus_v24_11 ) pkg config abi FreeBSD:15:amd64 pkg -vv | grep -A 3 "pfSense:" pfSense: { url : "pkg+https://pfsense-plus-pkg.netgate.com/pfSense_plus-v24_11_amd64-pfSense_plus_v24_11", enabled : yes, priority : 0, cat /usr/local/etc/pkg.conf ABI=FreeBSD:15:amd64 ALTABI=freebsd:15:x86:64 PKG_ENV { SSL_CA_CERT_FILE=/etc/ssl/netgate-ca.pem SSL_CLIENT_CERT_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0001-cert.pem SSL_CLIENT_KEY_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0001-key.pem } This firewall is obviously running on FreeBSD 15 no longer on 14. But can I use the freshports link for FreeBSD 14 amd64 quarterly which is at tailscale 1.86.2 or can I only go up to version tailscale 1.84.2_1, and need to wait until they have a version of tailscale 1.86.2 or higher for the FreeBSD 15? Would it be good enough to tell it to ignore the OSVERSION? export IGNORE_OSVERSION=yes Note: use of 14 and not 15 ? pkg add https://pkg.freebsd.org/FreeBSD:14:amd64/quarterly/All/tailscale-1.86.2.pkg service tailscaled restart tailscale up
  • Discussions about WireGuard

    690 Topics
    4k Posts
    J
    I've read through some other posts about this, but they either didn't say whether the proposed solution worked or they were very convoluted and difficult to understand. Here is our scenario: We have 6 locations--Las Cruces (LC), Sunland Park (SP), El Paso (EP), Abilene (ABI), Fort Worth (FW), and Plano (PL). LC and ABI have software that is accessed by the other 4 locations via VPN. There are WireGuard VPNs set up between LC and those 4 locations (SP, EP, FW, PL), and ABI and those 4 locations (SP, EP, FW, PL). There is also a WireGuard VPN connection between LC and ABI. LC and ABI have 2 internet connections. SP, EP, FW, and PL each have one internet connection. If the primary internet connection goes down at either LC or ABI and failover occurs to the secondary internet connection, is there a way to set up the WireGuard VPN connections so that they also failover without purchasing some 3rd party application? Thanks.
  • PfSense 1.2.3 nano & Snort 2.8.5.3 pkg v. 1.21

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    J
    @jamesdean: Why is snort doing that to you? Why am I not seeing this error? ssh to your box and restart the webconfiguator. ( '11)  Restart webConfigurator '). Something like this happened to my instalation also. I was messing around with Snort memory settings and accidenly chose AC in a quite low resources system. Snort ate practicly all my resources (could not eaven log into pfsense gui). In my case this was solved by ssh connection to the box and stopping snort process.
  • Regarding Squid (pfSense_Lusca packages by Chudy)

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    P
    Hai Mr Chudy and topic moderator… i just want to ask,,,if my Harddrive 80GB and i using 1GB of RAM in Intel Atom Machine 1,6GHZ.... please give me a best advice to configure my cache management in webGUI... i;m using your LUSCA give me some explanation about this : tail -f /var/squid/log/cache.log 2010/04/09 07:53:27|        0 Duplicate URLs purged. 2010/04/09 07:53:27|        0 Swapfile clashes avoided. 2010/04/09 07:53:27|  Took 1.4 seconds (  0.7 objects/sec). 2010/04/09 07:53:27| Beginning Validation Procedure 2010/04/09 07:53:27|  Completed Validation Procedure 2010/04/09 07:53:27|  Validated 1 Entries 2010/04/09 07:53:27|  store_swap_size = 2k 2010/04/09 07:53:28| storeLateRelease: released 0 objects 2010/04/09 08:08:35| CACHEMGR: <unknown>@127.0.0.1 requesting 'info' 2010/04/09 08:20:30| squidaio_queue_request: WARNING - Queue congestion</unknown> and this : squidclient mgr:info HTTP/1.0 200 OK Server: Lusca/LUSCA_HEAD r14499 patched by chudy r11 Date: Fri, 09 Apr 2010 00:54:50 GMT Content-Type: text/plain Expires: Fri, 09 Apr 2010 00:54:50 GMT X-Cache: MISS from localhost Via: 1.0 localhost:3128 (Lusca/LUSCA_HEAD r14499 patched by chudy r11) Connection: close Squid Object Cache: Version LUSCA_HEAD r14499 patched by chudy r11 Start Time:    Thu, 08 Apr 2010 23:53:26 GMT Current Time:  Fri, 09 Apr 2010 00:54:50 GMT Connection information for squid:         Number of clients accessing cache:      0         Number of HTTP requests received:      6058         Number of ICP messages received:        0         Number of ICP messages sent:    0         Number of queued ICP replies:  0         Request failure ratio:  0.00         Average HTTP requests per minute since start:  98.7         Average ICP messages per minute since start:    0.0         Select loop called: 471925 times, 7.807 ms avg Cache information for squid:         Request Hit Ratios:    5min: 12.2%, 60min: 11.0%         Byte Hit Ratios:        5min: 1.5%, 60min: 23.0%         Request Memory Hit Ratios:      5min: 28.3%, 60min: 70.5%         Request Disk Hit Ratios:        5min: 3.8%, 60min: 12.7%         Storage Swap size:      154334 KB         Storage Mem size:      20300 KB         Mean Object Size:      42.62 KB         Requests given to unlinkd:      0 Median Service Times (seconds)  5 min    60 min:         HTTP Requests (All):  0.85130  1.00114         Cache Misses:          0.94847  1.17732         Cache Hits:            0.00379  0.00286         Near Hits:            0.76407  0.72387         Not-Modified Replies:  0.00379  0.00179         DNS Lookups:          0.00000  0.00000         ICP Queries:          0.00000  0.00000 Resource usage for squid:         UP Time:        3684.226 seconds         CPU Time:      91.372 seconds         CPU Usage:      2.48%         CPU Usage, 5 minute avg:        2.32%         CPU Usage, 60 minute avg:      2.52%         Process Data Segment Size via sbrk(): 0 KB         Maximum Resident Size: 53392 KB         Page faults with physical i/o: 3 Memory accounted for:         Total accounted:        23852 KB         memPoolAlloc calls: 1154184         memPoolFree calls: 1063451 File descriptor usage for squid:         Maximum number of file descriptors:  14745         Largest file desc currently in use:    49         Number of file desc currently in use:  34         Files queued for open:                  0         Available number of file descriptors: 14711         Reserved number of file descriptors:  100         Store Disk files open:                  2         IO loop method:                    kqueue Internal Data Structures:           3676 StoreEntries           3478 StoreEntries with MemObjects           3470 Hot Object Cache Items           3621 on-disk objects Thanks Mr. Chudy
  • Snort 2.8.5.3 pkg v. 1.21 not detecting portscans

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    J
    @LostInIgnorance: I am having a problem with snort not recognizing portscans done from an outside source.  They are not being blocked, detected, or logged. Check to see if snort is running. ps -aux | grep snort. If your on nanobsd snort will kill it self if you load to many rules. Error out of swap space…..... Make sure you are listening on the wan if you want to see portscans and attacks that get blocked by the firewall. James
  • Snort not applying threshold.conf settings

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    J
    @jaysonr: Ok, I went ahead and updated to the newest version (lost all my settings again) and now I see the pass through settings. I will start rebuilding my settings and post the results :) You can save your setting using the pfsense backup config thing.
  • Snort-dev has been released. old snort has been renamed snort-old

    Locked
    50
    0 Votes
    50 Posts
    19k Views
    J
    @tester_02: Snort 1.20 install went great, no issues  on my 1.2.3.release install. I had no issues on my firefox and getting new rules. Can others comment if they do an upgrade from the old releases (2.8.4 v1.7) that their installs do work?  Also, if you deinstalled, and then installed the new package, or just did a reinstall to upgrade? In my case (runnig pfsense 1.2.3 and the old snort version was 2.8.4 v1.7). I did deinstall the old version first and then installed the new 1.20 package.  Worked fine that way Just in case for those that are doing upgrade, or new with snort : Also remeber tho check the preprocessors settings when activating new rules. Snort wont start if you activate rules that require for example http preprocessor and the needed preprocessor is not selected (snort logs are good for finding what is wrong).
  • Squid cache Antivirus Update

    Locked
    9
    0 Votes
    9 Posts
    14k Views
    jimpJ
    Actually it should probably be: refresh_pattern avgate.net/.*\.gz 720 100% 10080 reload-into-ims; Since the regex isn't achored, that will match the same as .*avgate.net, and the . in .gz should probably have the \ before it so it's really considered a period. It still would have worked, but really either one of those should match the pattern you were trying to make.
  • Strange problem with Squid (pfSense_Lusca packages by Chudy)

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    P
    use squidclient command e.g @ console type #squidclient -p 3128 cache_object://localhost/info you can change 3128 with your squid listen port and localhost with your proxy ip or use only squidclient mgr:info http://forum.pfsense.org/index.php/topic,19251.msg124919.html#msg124919
  • Does stunnel work in 1.2.3?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    As an addition, it looks to be accepting connections on the port I configure but then immediately terminating them.  If I disable stunnel and try to telnet to the port I get a long timeout.  If I enable it, the telnet session immediately ends.
  • Squid and Active Directoy Auth with NTLM

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Running PHP, external database server connection

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    N
    solved it using ozanus recommendation..http://forum.pfsense.org/index.php/topic,21885.msg112854.html#msg112854 the important line is.. pkg_add -r http://files.pfsense.org/packages/7/All/php4-mysql-4.4.8.tbz ln -s /usr/local/lib/php/20020429/mysql.so /usr/local/lib/php/extensions/no-debug-non-zts-20020429/mysql.so now im capturing user details like mac address via arp and squidquard..
  • Resolve Names from LAN IPs in Darkstat and BandwidthD?

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    T
    All my internal IPs are given out by DHCP. Let me know if I'm on the right track: in pfSense, under the DHCP Server service, there is a Dynamic DNS field; is that what I should be using to try and get pfSense's DHCP to update my DNS server?
  • Havp eating up memory spawning new childs

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    D
    Test different settings (+/-) for 'HVDEF_HAVP_MINSRV', 'HVDEF_HAVP_MAXSRV' May be you found the best values.
  • Pfsense behind a web proxy, problem to download packages

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid access denied from Allowed subnet?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    Try tinkering with the box on the front page of the Squid/Proxy GUI called 'Allow users on interface'.  This has, in the past, overridden the allowed subnets box you are using.  Tick it, save, test, untick, save, test.  Hope it helps.
  • Problems with NTOP - New user.

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    P
    I have 3 sites with PFSense & monitoring with NTOP. 2 hold in there for a long time many days, 1 drops out the same as you get, same error within 1 to 12 hours. I don't know why. THey are running on similar systems, may even be exact clones (I just used a couple spare HP PC's for this task)
  • Snort uninstalling itself pfsense 1.2.3

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    G
    Seems to be hanging on running deinstall commands.
  • [ASK] client: ERROR: Cannot connect to localhost:3128: Connection refused

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Naieve Config Ques: Why not enable all?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    Well you generally pick what kinds of traffic you want to be on the lookout for. Services you run are one rule to follow, but you also need to be aware of services you do not ever want to see on your network as well, plus attacks of varying kinds (spyware, etc) For example, if you're only running a web server, you may want to run some of the rules that apply to https, and you may also want to be sure that the web server never has something like IRC traffic coming from it – that could be a sign it has been compromised. Running an IDS and doing it well will take some tuning. If you have the spare RAM and the spare CPU cycles, load 'em all up and see what gets triggered. If "good" traffic is triggering a rule, disable it or disable that set. It really is all up to the admin of a network to make these choices - only the admin of that network will know what should and should not be present there.
  • OpenOSPFD

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    C
    Thanks for the info, I downgraded the package to 4.3 for the time being.
  • [Fixed] Squid installed twice, shows up twice in status/services

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    Thanks, fixed it.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.