Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    M

    @Laxarus This worked for me as well. Though I had to search the web how to edit the file (the easiest way).

    Therefore:

    Addition for anyone struggling to find where to edit files on your pfsense system.

    Go to Diagnostics --> Edit File --> insert the location of the file:

    /usr/local/pkg/pfblockerng/pfblockerng.sh

    Go to line number 1232 by filling it in the Go to line field.

    That line should read:

    s1="$(grep -cv ^${ip_placeholder2}$ ${masterfile})"

    replace only (leave the rest intact):

    masterfile

    to

    mastercat

    Then follow the above instructions from @Laxarus https://forum.netgate.com/post/1219635

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Snort Bug: HOME_NET line being mis-written. Comma at string end.

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    N

    Bug opened, but closed.  Thanks for that. :)  Now if only I could figure out why /var/db/whitelist winds up being such a mess for me. :(  It doesn't work right at all unless I manually clean it up after each reboot.  It appears to keep dumping duplicates into the file, and unless I sort network large to small, it's no good.

    That, and I have a network, x.x.x.0/24 for I have in /var/db/whitelist, but snort keeps adding x.x.x.11 to the blocklist.  Unless I put x.x.x.11/32 in there as well, it keeps getting blocked.

  • Package that block ports

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H

    You can see pen connections at diagnostics>states if that helps.

  • Idea for New Package: PBNJ

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    @mrquintopolous:

    I just started using pfSense on an internal firewall where I work, and it works pretty nice. Good work guys!

    So I had an idea to extend pfSense with the capabilities of PBNJ (http://pbnj.sourceforge.net/). Basically, I think it would be a cool feature to be able to automatically scan your LAN machines with nmap and see changes over time and maybe even be alerted when a machine has a new port open. That way, an admin can jump on figuring out why this happened.

    In an attempt to figure out the internals of pfSense and waste time, I have been fiddling with getting PBNJ installed on the pfSense box. Without the ports system, it requires the following steps:

    pkg_add -r perl pkg_add -r <various 6="" perl="" modules,="" around="">3) One of the dependencies, p5-Nmap-Parser is not in the packages, so it requires downloading the tarball, extracting, installing etc. This requires a pkg_add -r gmake extract PBNJ, perl Makefile.pl, gmake, gmake install, gmake test Maye more that I subsequently forgot.

    Pretty involved, maybe installing ports and going from there would have been smarter. Anyways, I was wondering:

    Do people on this forum think that this would be a useful thing to have in a pfSense box? If so, is installing perl too much? i.e., would it be better to rewrite something similar in php? Would anyone be interested in making a package / ui frontend for it with me?

    I hope to hear your thoughts.</various>

    Not as involved as you would think.  Check out the squid package which in turns install perl.  Theres a number of packages that install multiple dependencies and then setup the package.  I don't see anything that would change this situation for this package.

    Check out http://pfsense.com/cgi-bin/cvsweb.cgi/tools/pkg_config.xml?rev=1.407 and http://pfsense.com/cgi-bin/cvsweb.cgi/tools/packages/

  • Are there any "packet sniffers" available?

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    S

    Recent snapshots have a tcpdump GUI component.

  • Squid Proxy Sever Blacklist

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    ?

    Please be a LOT more specific about what you're talking about.

  • Iperf Installation problem

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    M

    Working for me, thanks a lot!

  • MiniUPnPd and My Network Places

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    H

    I vote him for package maintainer of the year!  ;D

  • Pure-FTPD

    Locked
    21
    0 Votes
    21 Posts
    10k Views
    M

    thank you very much!

  • Bleeding Threats Support in SNORT

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Gateway AV and Snort

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B

    Yes, that is true. I'm out of work right now, but if I was working I'd offer $50 and then possibly more once it was done. $30-$50 for me is my starting place for things. However I have to work though and hopefully by the end of Feb I can start a new job. If there's not a gateway AV for pfsense when I am back to work then I will be offering a bounty for it. At least I hope I can afford to do that.

    You guys who work on pfsense really do a good job on the UI and stuff.

  • No packages work for me

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    B

    Everything is working good. The issue was I guess you had to select LAN/WAN in that window. I don't remember what area that is. Like settings area for the package or something. I had to fiddle with it a while untill I understood it better since there is no documentation for anything.

    I also did upgrade to the latest snapstop as suggested and it's good so far.
    Thank you!!

  • Squid does´nt start

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D

    I think I finaly fixed this today in version p15

  • Packages offline

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J

    Double check your boxes by sending a ping to google or yahoo in the terminal.  I haven't ever had a problem with the package system that didn't involve me forgettting about something.

  • SQUID Problem.

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    D

    See the other 10 page long squid thread.
    set a space in the unrestricted and banned fields and it should work then.
    Commited version p9 just now.

  • Pfsense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    The packages that exist for this are not finished/working atm. If you have some knowledge feel free to fix/finish them.

  • Squid help

    Locked
    12
    0 Votes
    12 Posts
    4k Views
    J

    I'm guessing there is a language barrier, try your forum language and post there if it is listed, you should have more luck, but all in all this is NOT setup to work correctly yet

  • Squid Whitelist URL Capacity

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D

    The current squid whitelisting and blacklisting should work starting from version p8.

    So you can try what size the limit is now :-)

  • Squid log to a remote server

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    B

    I found a command who can do the job :
    tail -f /log/squid/access.log | logger -p "local4.info" &
    To work syslog must be configured tu send "local4.info" to the remote server.

  • Snort Alert Question?

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    S

    Yep I just noticed that as I went to reconfigure!

    Thanks for your help guys.  ;D

    [Edit:] In fact, it would appear that Snort does not like to run on multiple interfaces; a bug perhaps?

  • Squid and Traffic Shaping possible work around?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    U

    I had a quick look at what you did, so I don't know what causing squid to crash, but what I said before, squid has been changed for transparent proxying.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.