Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    D
    Retested on 24.11-RELEASE (amd64) all seems to work. So it seems right to file a bug for this issue.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC
    @rlrobs Yes it’s still working fine here.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K
    @pulsartiger The database name is vnstat.db and its location is under /var/db/vnstat. With "Backup Files/Dir" we are able to do backup or also with a cron.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    M
    I resolved this by accepting the T+Cs via https://www.maxmind.com/en/accounts/1205389/geolite2/eula
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG
    @EChondo What's your pfSense version ? The instructions are shown here : [image: 1753262126227-1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png] A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate. @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy: I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess. No need to wait x days. You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    J
    @div444 i'm finding the same - did you find a solution or did reverting fix it? Hoping there is a patch fix or something to get it working! Rather not rollback if i can avoid it
  • Discussions about the Tailscale package

    90 Topics
    578 Posts
    T
    Re: How to update to the latest Tailscale version? I am on latest released Netgate 6100 pfSense PLUS v24 ( pfSense_plus-v24_11_amd64-pfSense_plus_v24_11 ) pkg config abi FreeBSD:15:amd64 pkg -vv | grep -A 3 "pfSense:" pfSense: { url : "pkg+https://pfsense-plus-pkg.netgate.com/pfSense_plus-v24_11_amd64-pfSense_plus_v24_11", enabled : yes, priority : 0, cat /usr/local/etc/pkg.conf ABI=FreeBSD:15:amd64 ALTABI=freebsd:15:x86:64 PKG_ENV { SSL_CA_CERT_FILE=/etc/ssl/netgate-ca.pem SSL_CLIENT_CERT_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0001-cert.pem SSL_CLIENT_KEY_FILE=/usr/local/etc/pfSense/pkg/repos/pfSense-repo-0001-key.pem } This firewall is obviously running on FreeBSD 15 no longer on 14. But can I use the freshports link for FreeBSD 14 amd64 quarterly which is at tailscale 1.86.2 or can I only go up to version tailscale 1.84.2_1, and need to wait until they have a version of tailscale 1.86.2 or higher for the FreeBSD 15? Would it be good enough to tell it to ignore the OSVERSION? export IGNORE_OSVERSION=yes Note: use of 14 and not 15 ? pkg add https://pkg.freebsd.org/FreeBSD:14:amd64/quarterly/All/tailscale-1.86.2.pkg service tailscaled restart tailscale up
  • Discussions about WireGuard

    690 Topics
    4k Posts
    J
    I've read through some other posts about this, but they either didn't say whether the proposed solution worked or they were very convoluted and difficult to understand. Here is our scenario: We have 6 locations--Las Cruces (LC), Sunland Park (SP), El Paso (EP), Abilene (ABI), Fort Worth (FW), and Plano (PL). LC and ABI have software that is accessed by the other 4 locations via VPN. There are WireGuard VPNs set up between LC and those 4 locations (SP, EP, FW, PL), and ABI and those 4 locations (SP, EP, FW, PL). There is also a WireGuard VPN connection between LC and ABI. LC and ABI have 2 internet connections. SP, EP, FW, and PL each have one internet connection. If the primary internet connection goes down at either LC or ABI and failover occurs to the secondary internet connection, is there a way to set up the WireGuard VPN connections so that they also failover without purchasing some 3rd party application? Thanks.
  • Is there a Bacula howto?

    5
    0 Votes
    5 Posts
    510 Views
    V
    So sorry, I asked in the wrong forum.
  • Zabbix Proxy?

    1
    0 Votes
    1 Posts
    403 Views
    No one has replied
  • After the last update pfsense 2.4.4 p3

    Locked
    12
    0 Votes
    12 Posts
    1k Views
    johnpozJ
    @jimp said in After the last update pfsense 2.4.4 p3: pf2ad Maybe he didn't pay his 60.00 € the guy wants for that package... That site is OLD... shoot it still says pfsense is owned by Electric Sheep Fencing ;)
  • This topic is deleted!

    0
    0 Votes
    0 Posts
    12 Views
    No one has replied
  • softflowd: multiple collectors

    1
    1 Votes
    1 Posts
    259 Views
    No one has replied
  • Snort and SquidGuard issues

    1
    0 Votes
    1 Posts
    314 Views
    No one has replied
  • 0 Votes
    9 Posts
    668 Views
    K
    I think I figured this out by installing pfsense in virtualbox VM, configuring it and then comparing pkg info commands between it and my live system. The live system always had a warning about pkg version 35 is newer than installed database 34 at the top, and there were a few other packages that were newer versions than the stock 2.4.4p3 system. The pkg version warning did not sit pretty with me so thats when I decided to blow away this new install and start over. After I wiped the drive and did a reinstall, I reapplied my config file. The interfaces were different from the old system (re0, igb0). Therefore until I got to the physical console and fixed it, the packages never installed because it could not contact the internet. The second time around I edited my xml config file in notepad++ and altered the WAN and LAN with the proper igb0 and igb1 designations as they are on the new box. Next wipe I got it back up and restored config. This time since the interfaces were correct, when it restarted it had internet access and the system was able to automatically reach out and download all of the packages. At the top of the web ui in a yellow banner it said to hold off on any changes while packages are reinstalled from the internet. (This is the behavior I noticed in my VirtualBox install test). The only one I had to manually install was bandwidthd (it was in the menu but the package wasn't installed). But after giving the system time installing all of these packages, I was able to install the Unifi controller using the github script. I then pkg lock these three packages: boost-libs-1.71.0_2 icu-65.1,1 mongodb34-3.4.23 I then installed the command line packages for lsof and nano, and they installed and work without issue. Nothing was downgraded or removed. System is running smoother than it ever has. I think the pkg database got messed up in the original install after importing the config, since the system was not able to contact the internet and complete the package install. There was no button in the UI to "retry" and reloading the config and just choosing package database did not seem to do anything. A clean install fixed it.
  • Pfsense 2.4.3 Freeradius 3.x ldap problem

    2
    0 Votes
    2 Posts
    630 Views
    M
    @magokbas said in Pfsense 2.4.3 Freeradius 3.x ldap problem: With the same settings as FreeRadius2, FreeRadius 3 ldap (active directory) don't work. when activate ldap is did not work sql. sql started to work after last update but ldap still does not work. This problem still persists.
  • FreeRadius - Wifi auth with PWD and TTLS

    1
    0 Votes
    1 Posts
    901 Views
    No one has replied
  • SIProxd registrations not releasing.

    1
    0 Votes
    1 Posts
    249 Views
    No one has replied
  • Snort 4.0_8

    2
    0 Votes
    2 Posts
    415 Views
    bmeeksB
    @cdx304 said in Snort 4.0_8: Snort does not want to start again .Was working fine ? Pfsense is latest 2.5 build . I assume you mean Snort 4.0_8 has been working for you and then just suddenly started not working. If so, then read on. This is almost always caused by a rule syntax error (or could be a required preprocessor is not enabled). Look in the pfSense system log and you should see a Snort error message that will tell you what's wrong. When the rules update (usually twice each week) it is entirely possible for either a rule to be published or updated and have a syntax error in it, or a rule that was previously default-disabled by the Snort team might have been changed to default-enabled by an update. If that particular rule need a preprocessor enabled that you have disabled, that can result in a startup failure. So check the pfSense system log to see why Snort is not starting. Post back here if are not able to identify the cause.
  • Antivirus on pfsense

    1
    0 Votes
    1 Posts
    336 Views
    No one has replied
  • Freeradius with remote mariadb server

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • What is the status of ARPWATCH package?

    10
    1 Votes
    10 Posts
    2k Views
    G
    @vw-kombi said in What is the status of ARPWATCH package?: I recently had to delete and re-create a vpn ouotbound connection, and arpwatch did not like this. In addition to the usual mesages, I am getting this with every cron execution - the interface mentioned in the email I get below does not exist anymore. It is not mentioned in the xml if I do a backup and edit either - I assume its in some sort of arpwatch database, but no amount of uninstalling and re-installing seem to rectify this email every 5 minutes : X-Cron-Env: <SHELL=/bin/sh> X-Cron-Env: <PATH=/etc:/bin:/sbin:/usr/bin:/usr/sbin> X-Cron-Env: <HOME=/root> X-Cron-Env: <LOGNAME=root> X-Cron-Env: <USER=root> Error: Unable to get interface "ovpnc3" statistics. I don't know anything about the inner workings of pfSense, but is it possible that this is causing an interface to become visible/invisible, and arpwatch is "just doing it's job" in alerting that a "device" has appeared on the network (and not been marked as an allowed device), disappeared, and then reappeared. Every tine the device comes back, it generates an alert, and unless there is some way to mark the MAC address as "allowed" this behaviour will never stop. Just a thought, I don't know if it has any merit.
  • [SOLVED] Bug while updating System_Patches

    7
    0 Votes
    7 Posts
    2k Views
    EveningStarNME
    @jimp Thank you, and to everyone else who replied here, too. I uninstalled v1.2_2 and installed v1..2_3, and everything worked as expected.
  • Adding to the user fields in Freeradius

    1
    0 Votes
    1 Posts
    308 Views
    No one has replied
  • Snort Rules in pfsense always failed

    4
    0 Votes
    4 Posts
    614 Views
    bmeeksB
    Not that it really should matter in terms of starting up, but you apparently have no rules selected for your LAN interface. That means Snort would not be really doing anything for you even if it started. At 10:11:19 in the log is a warning about "no text rules or IPS Policy selected for: LAN". Your Snort Subscriber Rules are also failing to download. Notice the "Server returned error code 505" message in the log at 10:10:28. The most likely cause of that is a trailing space in your Oinkcode. Retype or paste in your Oinkcode again and be sure that is no trailing space at the end and that every character is correct. So from the log, Snort appears to have started successfully. Does it still not show as running? Open a CLI (command line interface) session on the firewall either directly on the console or via an SSH connection and see what the output of this command is -- ps -ax | grep snort Do you see any running Snort processes in the output of that command? I also see a Gateway Alarm message in the log. If that happens often and if the gateway monitoring logs a "gateway down" message, that will trigger pfSense to issue a "restart all packages" command. If more than one instance of that happens in rapid succession it can result in the Snort process either getting clobbered, or sometimes, two duplicate Snort processes getting started.
  • Iperf version

    Moved
    12
    0 Votes
    12 Posts
    1k Views
    jimpJ
    That was just a cosmetic issue and is corrected in the repo, so when the next build happens, it will be fixed.
  • SquidGuard on pfSense 2.4.4: Segmentation Fault (core dumped)

    2
    0 Votes
    2 Posts
    592 Views
    KOMK
    Remove squidguard and then try to get squid working alone first. If it still dies, check the System log for anything related.
  • Possibly a broken pkg database

    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.