Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    W

    @qinn
    Sent him an email Dan an email to the address on his site.. Not sure what is happening, my Teams stopped working. Disable it/turn it off and the problem went away.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • HTTP Sniffer

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC

    Have you actually tried the suggestion mrsense made?  It may not tell you right now who's connected to what site, but if you can live with a short lag (15 minutes) it'll work.

    AFAIK there is no way, short of running a "tail -f" on the squid log file, to watch who's connecting to what site in real time.

  • Ntop 3.3

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • IMspector questions

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    B

    that is a good point (already did that a while back)

    however, i think i realized the issue

    everyone else is using the new version of AIM (i use gaim/whatever)
    :D

  • Bandwidthd Question

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Imspector delete logs ..

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    J

    Thanks ! i will try this ..

  • SLBD config problem

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    T

    I can't get sticky connections to work with 1.2-RC3 . I have 2 pfsense boxes in failover configuration, and the > connections don't sticky. My 2 pfsense boxes are plugged into a switch that has 2 HSRP connections from the > provider.

    Turns out that sticky-address is working just fine. I mis-interpreted the meaning of sticky-address, which means that as long as a TCP connection is active (not broken down properly) the server will stick.
    I was hoping to have some sort of persistent time-limited server in the pool that would last for an hour.

    Sorry about the confusion.

  • Installing packages behind proxy

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    C

    I was asking if you can do a local install of the packages since I can't connect from behind my proxy to the pfsense.com site.  In other words, I pull down the packages from pfsense.com and point my pfsense box to my local web server (http://mylocalserver.com/packages) and install from there.  Thanks.

  • Where is SPAMD for pfsense 1.0.1

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    T

    Hi,

    thanks for your very fast answer.
    Bad to hear this, but I'm hopefully that it will be back sometime because it was a great package.

  • Squid and pfSense

    Locked
    2
    0 Votes
    2 Posts
    22k Views
    ?

    This has been asked and answers MANY MANY times on the forum and on the mailing lists.  Please check the available sources next time first.

  • Embedded systems & packages ???

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    ?

    Aside from excessive reads/writes to media, the packages generally require far more memory and CPU than is found on your typical embedded device.  Thus they are inappropriate for use on the embedded platform.

  • Bandwidthd output issue

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • IMSpector listening on WAN?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • [SOLVED] NUT 2.0.5_1 package on pfsense 1.2-RC2 not installing

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    C

    Perfect! The new package showed up in the list, downloaded, installed, and I have it up and running without any problems. Thank you! :)

    chartek

  • Keeping squidGuard after Updates/Reboot Sync

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D

    @4brats:

    If I re-install, will I pick up all the changes you made that I saw in the cvstrac?

    Near time nope. You have instllation from different source.
    Now i make publication this package. Will need wait some time.

  • Bandwidthd ip addresses

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid not working

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H

    hi

    what did you do to get the 2.5 MB/s down, i have squid up and running, i keep getting the same seed on downloads 80 kb/s i even monitored the traffic graph, if i download 2 files, one previously downloaded and a new one from the internet the download speed splits in 2 meaning i getting the previously download file from the internet and not from the cache.

    my squid settings as follows:

    general settings:
    proxy interface: lan
    allow users on interface: checked
    transparent proxy: checked
    do not proxy private …: checked
    enabled logging: checked

    cache management:
    hard disk cache size: 50,000
    memory cache size: 512 (my physical memory is 1 gig)
    minimum object size: 0
    maximum object size: 40000
    memory replacement policy: Heap GDSF
    cache replacement: Heap LFUDA
    enable offline mode: checked

    help really appreciated

    hadi57

  • Snort and Backdoor Rules not working

    Locked
    6
    0 Votes
    6 Posts
    10k Views
    T

    sql rules also are a problem…

    in lowmem mode it works fine without sql...

  • Snort blocking the *internal* IP when bittorrent is detected?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    U

    Pretty sure it doesn't, even WITH the internal IP whitelisted… >_<

  • Proxy_monitor.sh freezes at bootup

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    I

    hello again,

    i downloaded and installed pfsense 1.2 RC3 from the link that cmb posted… dhcpd, squid, imspector, and lightsquid works now :) many thanx... right now im exploring the firewall rulings, im having trouble with SMTP and POP3 but i guess that's for another post ;)

    again, many thanx guys... :)

    allison

  • Squid proxy installation

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    Cry HavokC

    If you'd used the search function on the forum you'd have found a number of others with similar package install problems, and advise on resolving them :)

    In short, check your DNS and connectivity.  If you have a firewall or proxy in the way then that may be the source of your problem.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.