Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    J
    @andrew_cb ChatGPT had the right idea but gave me 100 different places to put "load-server-state-from-file none". Your post was worth more than ChatGPT could ever offer!
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    JonathanLeeJ
    @bmeeks your work outclasses so many individuals and developers. Your stuff is amazing. Cheers
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N
    @jrey said When I checked the status of the service, the firewall returned, "does not exist". as in on the Status -> Services page? or where specifically ? and yet it shows on the dashboard services widget.. Please see below. I can see .sh files but not executables (suricata & syslog-ng have both). [25.07.1-RELEASE][suser@...]/root: ls /usr/local/etc/rc.d/ choparp dnsmasq isc-dhcrelay6 nginx php_fpm sshguard unbound dbus expiretable kea openvpn radvd strongswan uuidd dhcp6c igmpproxy lighttpd pcscd rrdcached suricata waagent dhcp6relay isc-dhcpd microcode_update pfb_dnsbl.sh rsyncd suricata.sh waagent.sh dhcp6s isc-dhcpd6 miniupnpd pfb_filter.sh scponlyc syslog-ng wireguardd dhcpcd isc-dhcrelay mpd5 pfnet-controller smartd syslog-ng.sh xinetd are there any errors in pfblockerNG 's error.log, dnsbl_parsed_error or py_error (Firewall -> pfBlockerNG -> Logs error.log contains a few lines on feeds failed to fetch entires py_error is empty dnsbl_parsed_error (see below) did not have any errors that prevent service execution ... 19:00:44,StevenBlack_ADs,ip6-loopback,::1 ip6-loopback ... 19:14:40,StevenBlack_ADs,ip6-loopback,::1 ip6-loopback ... 19:14:46,EasyList,admi2fib4exit,||admi2fib4exit^ ... 00:01:20,EasyList,admi2fib4exit,||admi2fib4exit^ ... 00:01:09,EasyList,admi2fib4exit,||admi2fib4exit^ ... 16:50:29,UT1_adult,xxx,xxx Keep settings is enabled, package uninstalled and reinstalled, code changed, feed updated and finally system rebooted. No change in the service status in dashboard's service widget. I found that except log (e.g., block, permit), the other functions are working. So, I will stop digging further on this regard and hope that future firewall upgrade will solve it. I need to identify, segregate and transfer logs to SIEM, which won't be a hassle. Thank you very much for your assistance. With appreciation Nanda, D.Sc. (Tech.)
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    501 Topics
    3k Posts
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Discussions about the FRR Dynamic Routing package on pfSense

    295 Topics
    1k Posts
    J
    Anyone else happen to notice that when configuring BFD, if you create a peer and select a profile - after save, re-edit the peer and the Profile is not represented. It appears as "None". You have to check the raw config to determine if the profile was actually assigned to the peer. This is on 2.8.1 (all packages up to date as of the date/time of this post). UPDATE: if re-edit and save (without re-configuring the profile none to what you want) - the save will strip the profile from the peer.
  • Discussions about the Tailscale package

    91 Topics
    611 Posts
    T
    Hi All, I use HAProxy to redirect to a range of https internal resources, this works really well at the moment through the WAN where I have source limits set up, and I can connect to the internal resources from limited external IP Addresses. Given I have tailscale I would like to basically be able to put custom dns entries in to point these hostnames to my pfsense tailscale IP4 address (100.89.148.118) but I am not having any luck getting this working. At the moment, I am just trying to connect to HAProxy using https://100.89.148.118 but it is getting blocked by the firewall. Sep 11 11:55:58 tailscale0 Default deny rule IPv4 (1000000103) 100.89.148.10:53148 100.89.148.118:443 TCP:S I have tried with and without NAT redirecting internally to 127.0.0.1, and I also have rules set up to allow any traffic to and from my tailnets (defined in an alias) but I still keep getting these connections from my other tailscale machines being blocked on the pfsense machine. Can someone give me some pointers on what I am missing because I can see the requests are coming through to the pfsense machine, and in theory the rules should allow it through but I cant see why they don't. I do have tailscale ACL in place, but clearly that is not an issue as the requests are making it through to the firewall. 0/0 B IPv4+6 TCP/UDP TailNets * TailNets * * none Allow across Tailnets 0/0 B IPv4+6 TCP/UDP * * * 443 (HTTPS) * none Allow Tailscale IP4 I also tried adding a EasyRule but because the tailscale0 interface doesn't exist in pfsense it throws an error and won't let me add that rule. Appreciate any help or tips, Cheers.
  • Discussions about WireGuard

    702 Topics
    4k Posts
    P
    Yes
  • Snort Update

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Installing IMSpector

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    N
    I have tried several reboots, slightly different settings and everything else I can think of, I have 'lan' selected, I have enable box checked and I have tried just 1, all 4 and variations of each for which service to log.  Nothing seems to work for it.  Bleh QQ
  • SquidGuard - Defining users

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F
    Many Thanks!
  • Squid slow Transfers

    Locked
    19
    0 Votes
    19 Posts
    26k Views
    M
    The change must be made to loader.conf in 1.2.2_RELEASE as well.  I was suffering from the exceptionally slow transfers until I commented out the #kern.ipc.nmbclusters="0" @Devs What are the advantages of this argument?  Why was this changed temporarily in the 1.2/FreeBSD 6.3 Release?  Any insight would be greatly appreciated.  Perhaps someone could also commit a change to the Squid packages so that the loader.conf gets updated upon package installation.
  • PfSense + FreeSWITCH + Digium TDM400P?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    J
    I put the card in my PBX in a Flash box for the time being. I got the card real cheap off of eBay so at least now I know it works. I'll just be patient and keep and eye out here for the drivers to become available.
  • Squid Cache on a external HD

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M
    "Incorrect superblock" means that the hard disk is not partitioned/formatted properly for use with pfSense. You'll need to partition it (e.g. using the pfSense installer or a FreeBSD computer) and then try mounting it again.
  • Snort 2.8.2.1_1 ignoring WhiteList & loading non checked categories

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    M
    fixed when snort update was completed
  • Problem with zabbix on 1.2.1

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Ntop configuration username/password?

    Locked
    1
    0 Votes
    1 Posts
    6k Views
    No one has replied
  • How to bypass squid and squidGuard

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    ?
    This is a question for the squid mailing list as it pertains specifically to the function of squid, not pfSense.
  • Squid 3 on 1.2.1 release; not logging anything

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Help me finnish PeerGuardian 2 like Package

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    L
    I wanted this too but not limited to one list (dshield, bluetack).  But the ability to add firewall dynamic pfilter tables hasn't been added yet.  This like the bogon rule would just be a hard coded static rule.    The "infrastructure" was supposed to be changes to use tables maybe ver 2.0 but that  was way back in ticket 1057 08/2006.  Ticket 185 even describes this same thing.  But its response was let squid do it. If it isn't wanted.  I had a outline on the modules needed to download a url to a file (schedules, decompress, conversion, cronjobs)  and add the fire wall rule.  But this is only possible if adding like the bogon rule. or some significant firewall rule module changes. Strange how the somethings are difficult to include in the scope of the firewall/router (WAP, UPNP) but appliances seem to be hot now.
  • Pfflowd generates somtetimes double records

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • NUT, Pfsense 1.2.0, FreeBSD 6.3, Alix 2c3

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FreeBSD Packages

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    I've never used 'dhis.' However I have experienced some of what you are going through when I built the FreeSWITCH package for pfSense. By default FreeSWITCH binds to the WAN IP.  I've also tried connecting to it un-successfully on 127.0.0.1. I did however connect to it on the WAN or the LAN. @JoP: "dhid: failed to open incoming udp socket on port 58800" By default on the LAN interface every port is open. But just for a test you might try a different port like 5880 or something. @JoP: (or am I violating the pfSense platform by doing this in the first place?) No violation. @JoP: Of course, the best solution would be if the DHID came as a pfSense-package or added under the dynDNS menu If you want to make a pfSense package out of it when you have it working you are free to do so.
  • IDS Intrusion detection system for pfSense

    Locked
    5
    0 Votes
    5 Posts
    8k Views
    S
    Hello, I am using Hacom version of 1.2.1-RC1 built on Mon Oct 27 00:06:07 EDT 2008
  • Pfsense 1.2.1 rc4 + squid 3 problem

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • LCDProc + Pyramid

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    ?
    Thanks!
  • Re: Where is Snort?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    At this time the standard embedded install does not have packages. Snort is a package for the full install. I have heard some people have put the fill install on their compact flash cards. You might search the forum for doing that.
  • Squid vs firewall rules

    Locked
    7
    0 Votes
    7 Posts
    7k Views
    E
    okey. i'm happy about this solution. but, i have figured the acl, the time, the destination…but still i cant work it out. 1. if i turn on the squid, do the firewall rules work? what should i do with the firewall rules? should i deny all or allow all in LAN and WAN? 2. in squid guard, what should i do with the default rules? should i deny all or allow all? i've made a rules for allowing the acl to the specified destination. i've tried to do this, but still the allowing rules seems depend on firewall rules... strange but true...
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.