Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    @dauhee if the proxy is not set on the client the firewall rules come into play if you allow 443 and 80 no client will use the proxy they will bypass it. I also use a WPAD server that is outside of pfsense that directs clients to the proxy and to use that you have to have host overrides to point clients to that with the dns because clients will ask for wpad automatically if proxy is set to auto, I got tired of back and forth with windows 11 issues.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    S
    @Patch said in So why is Netflix hitting me with Dradis?: The information they are after on your device is screen fingerprinting (to identify content played not from them). And any thing else they can see on your network. The overall effect is a rather high price for a country. Clearly an individual can’t change this on their own but neither must an individual accept or support it. Interested in a source for the claims. I thought targeted advertising was frighteningly cheap?
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG
    edit : I found this post, created hours ago, not posted. So I finished it up and posted. Basically, what @SteveITS said above ^^ @cburbs said in PfBlocker and Paramount +: Like : when the device asks for host name to be resolved, like an add server, this host name will now be avaible ... for all your LAN devices, as it's now part of the resolver's cache. Ones a host name is white listed, it will be whitelist for all your LAN network devices. The "use the pfBlockng Python Group Policy" function (list with requesting IPs) will short circuit the DNSBL handling. Example : A device wants to resolve "horrible-add-server.com", so it sends a request to the upstream DNS, pfSense = unbound. Unbound will receive the requests, and checks its local cache if it wasn't already resolved = locally known. If it is, answer is returned straight away to the requesting LAN device. Take note : no DNS resolving was needed, a cache hit will return the answer direct. If the host name "horrible-add-server.com" isn't available locally, the resolve process kicks in. It's this process that first calls a local unbound plugin = our pfBlockerng script. The plugin interface doesn't use shell, PHP, LUA, or a binary, no, it uses Python. hence the name 'Python mode'. This Python script starts by checking if the requester is listed under "Python Group Policy", and if it is, "Ok" is returned right away : resolving starts and the answer is return to the requesting device. Take note : and the answer is placed in the local unbound cache. Now you understand that if a whitelisted "Python Group Policy" that will request "horrible-add-server.com" will make the resolved result avaible to all LAN networks. ... and this is why I wish a knew of a way to just do exclusions for a single device. I think there is. It's called "views". Go here : Services > DNS Resolver > General Settings and look at this page from top tho bottom. ( Have a look at the Advanced Settings page ) The good news is the bad news. Read this .... And now you know there are more possibilities - waaaay more possibilities. Probably most of the are accessible with this : [image: 1764832409373-d62cadd5-b3a4-4fa8-91c0-d67b73c498ee-image.png] Like the good old days : you have to create your own 'extended unbound config', and you'll need the manual. You'll discover that 'views' exist, so you can use these to have unbound work for differently on a network (LAN) level and even device level - never tested this myself though, but others did. Some examples are present here on this forum. So, you want special things 'just for you' : that's ok, but you have to go outside of what the pfSense (and pfBlockerng) GUI can do for you. A GUI can only offer a small percentage of all the available possibilities (of unbound).
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    94 Topics
    670 Posts
    P
    @elvisimprsntr This worked OK on 2.7.2 as well as on 2.8.1 just pasting in to the gui command prompt section. I found out it works by accident.
  • Discussions about WireGuard

    718 Topics
    4k Posts
    M
    Count me in! But considering replies seems like it never gonna happen
  • System Patches Package v2.2.23

    Pinned
    1
    7 Votes
    1 Posts
    3k Views
    No one has replied
  • DNS Broken for pkg.pfsense.org

    Pinned Locked
    3
    0 Votes
    3 Posts
    18k Views
    jimpJ
    https://forum.netgate.com/topic/115789/pkg-pfsense-org-appears-to-be-dead/2
  • Packages wishlist?

    Pinned
    661
    0 Votes
    661 Posts
    2m Views
    O
    PRTG
  • Unable to start FreeRADIUS service

    2
    0 Votes
    2 Posts
    14 Views
    GertjanG
    @scottastic86 You've showed why and where there error occurred .... We, here on the forum, can acces that file, but the pfSense admin = you, you can ?! Have a look at this file : /usr/local/etc/raddb/mods-config/files/authorize When you see the file, you'll think : where did I see this before ? It's the info you entered here : [image: 1764763153476-4474cf8a-c7dd-49a9-8891-f7fbc85c9470-image.png] Start by checking all the entries : remove accented chars, all ' " `` etc. Just plain ASCI text. To test radiusd in debug mode : On the command line : radiusd -X and you'll see where it fails. But you already know where. Ctrl-C to abort. @scottastic86 said in Unable to start FreeRADIUS service: I deleted and rebuilt the Captive Portal The portal isn't radius related. Your issue is 'radius', not the portal. @scottastic86 said in Unable to start FreeRADIUS service: uninstalled and reinstalled the FreeRADIUS package But you kept your freeradius settings with an error in place ^^
  • Is anyone working on a RustDesk package?

    3
    0 Votes
    3 Posts
    774 Views
    M
    Using rustdesk pro self-hosted If's fantastic except when a client machine is in a restrictive environment with only 80/443 outbound open. Apparently there's a working websocket config but I wanted to use PfSense/HAproxy and can't translate the setup from nginx I'm a bit surprised more people aren't trying to do this to avoid the crushing costs of Teamviewer these days, and the absurd limimtations or security risks of other solutions.
  • 23.09.1 from 23.05.1 freeRadius broke

    10
    0 Votes
    10 Posts
    2k Views
    V
    Note to self under the latest release I had to set decipher list to cipher_list = "DEFAULT@SECLEVEL=0"
  • udpbroadcastrelay vs mcast-bridge vs mdns-bridge

    4
    0 Votes
    4 Posts
    186 Views
    dennypageD
    @luckman212 said in udpbroadcastrelay vs mcast-bridge vs mdns-bridge: I'm reminded of xkcd 2347... LOL! Closer than you know... I used to be one of those random maintainers in Nebraska. There were actually a handful of us, but we all escaped the state before 2003.
  • LLDP Package disappeared

    6
    0 Votes
    6 Posts
    434 Views
    AMG A35A
    @dennypage Tried first option, did not fix. Then tried second which has fixed the problem, thanks for your help. I have a second unit on 25.07.1 found that had identical problem, again option two fixed.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    10 Views
    No one has replied
  • Problem with Net-SNMP - not starting

    5
    0 Votes
    5 Posts
    3k Views
    M
    @barnettd Thanks for the fix! I was running into the exact same issue. Like @kmp, the pkg utility also had to be downgraded: pkg: 2.2.2_2 → 1.21.3_5 [pfSense] The following packages were reinstalled: pfSense-repo-25.07.1 [pfSense] pfSense-upgrade-1.3.11 [pfSense] snmpd starts up and everything appears to be working after a reboot.
  • 0 Votes
    6 Posts
    474 Views
    GertjanG
    @rootCRO said in pfSense 2.8 Installation Fails, and 2.7.2 Cannot Fetch pkg Packages – Repository Unreachable”: services.netgate.com Where did you get that "services.netgate.com" host name from ? Here is the forum that handles the 'install' questions : Home > pfSense Software > Problems Installing or Upgrading pfSense Software. @rootCRO said in pfSense 2.8 Installation Fails, and 2.7.2 Cannot Fetch pkg Packages – Repository Unreachable”: I’d really like to know exactly where pfSense pulls its packages from FreeBSD: { enabled: no } pfSense-core: { url: "pkg+https://pfsense-plus-pkg.netgate.com/pfSense_plus-v25_07_1_amd64-core", mirror_type: "srv", signature_type: "fingerprints", fingerprints: "/usr/local/share/pfSense/keys/pkg", enabled: yes } pfSense: { url: "pkg+https://pfsense-plus-pkg.netgate.com/pfSense_plus-v25_07_1_amd64-pfSense_plus_v25_07_1", mirror_type: "srv", signature_type: "fingerprints", fingerprints: "/usr/local/share/pfSense/keys/pkg", enabled: yes } I'm using pfSense plus. Be ware : you can't point a web browser to URL like https://pfsense-plus-pkg.netgate.com/pfSense_plus-v25_07_1_amd64-pfSense_plus_v25_07_1, as it is not a web server.
  • mdns-bridge one-way reflection

    26
    0 Votes
    26 Posts
    2k Views
    M
    @keyser said in mdns-bridge one-way reflection: @marcg Yes, those ports are needed - in what we consider the wrong direction - when you are Airplaying Video/screen mirroring. For sound only Airplay they are not needed/used. @keyser @dennypage , thanks for the info and confirmation. Somewhat reminiscent of the well-known firewall issues with active FTP ... with the difference that Airplay was introduced 20+ years later.
  • zabbix 7.4 package

    1
    0 Votes
    1 Posts
    102 Views
    No one has replied
  • UDP Broadcast Relay and subnet-directed broadcasts

    2
    1
    0 Votes
    2 Posts
    403 Views
    keyserK
    While I'm not 100% sure it cannot be brought to relay subnet-directed broadcast, it would make little network sense if it did. Remember that any IP stack on the other side that follows IP guidelinies would still drop the packet even if the NIC picked up the L2 broadcast frame from the wire. The idea of the package is forwarding Class D (multicast) and proper global broadcast frames.
  • snort 4.1.6_27 crashing with php error

    4
    0 Votes
    4 Posts
    329 Views
    S
    yeah, it's fixed with _28
  • Need urgent support with HAProxy setup will pay

    1
    0 Votes
    1 Posts
    196 Views
    No one has replied
  • Advantages of mDNS-Bridge vs UDPBroadcastRelay

    7
    0 Votes
    7 Posts
    601 Views
    keyserK
    @dennypage And thank you SO much to @dennypage for maintaining the package - and so selflessly spending time supporting it and us users. Especially when we ask stupid questions or are so selfcentered we find ourselves important enough to outright complain over volunteer work like this. All package maintainers should really have a HERO badge here on this forum.
  • HAProxy - Files

    3
    4
    0 Votes
    3 Posts
    485 Views
    patient0P
    @AnthonySalamone preface: I don't use HA Proxy but did use the power of searching the internet. If you want to use pfSense with Authelia, which seems to use these exact three files, someone written a blog post about how to do it: https://kovasky.me/blogs/pfsense_haproxy_authelia/
  • Prometheus Node Exporter gives log errors - fix or suppress in log

    7
    0 Votes
    7 Posts
    6k Views
    A
    @nws thanks for the consistent fix - I completely overlooked that for a while. And @credulous yes, it's still a mystery why the collectors seemingly trigger and gives errors, and also why they don't appear at the collector list. It seems the Prometheus Node Exporter package on FreeBSD has very low priority perhaps? Else you would imagine something like this could be fixed.
  • HAProxy / ACME + external webhost?

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.