Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Asterisk not working

    6
    0 Votes
    6 Posts
    3k Views
    S
    TheCook, I've used Asterisk and have sold and supported Asterisk platforms for several years now.  Look at the PbxInAFlash distros.  They have one (I think it's labeled "Green") that is just a straight ISO you can boot as a VM in VirtualBox.  Works really well and I think is Asterisk 10 or 11.  All you need to get it up and running is to set an IP to the VM and set up the sip.conf localnet and extip and you should be good to go.  All the dial patterns and stuff is already done and you get a FreePBX which makes life a lot easier.  I wouldn't put Asterisk on your firewall, especially with timing and jitter.  You don't want your PBX to have any unneeded load. Having said that, if you can get into the Asterisk CLI (which it appears you can) run a "sip show peers", "sip show registry", and "sip show channels".  That should give you an indication if your devices are registering with the PBX and if your trunks are connected.  Also, I see you have your localnet set, but do you have your external IP set in the sip.conf?  That would stop traffic. Good Luck!
  • [bug since 2.1.2] Unable to communicate with https://packages.pfsense.org

    Locked
    28
    0 Votes
    28 Posts
    29k Views
    C
    @msmith9xr4: confirmed works disabling ipv6 on 2.1.5 and 2.2.4 for me, 2 different WAN providers. You have IPv6 problems in that case. Start a new thread describing your IPv6 config, what you see when trying to traceroute6 to packages.pfsense.org (or google.com or anything else IPv6-enabled, guessing nothing will work in that case). Locking thread since it's been hijacked by a handful of completely unrelated things.
  • Pfflowd remnants

    3
    0 Votes
    3 Posts
    1k Views
    D
    Like rm -f /usr/local/etc/rc.d/pfflowd.sh ?
  • How to rotate dansguardian logs

    1
    0 Votes
    1 Posts
    669 Views
    No one has replied
  • MOVED: Squid and Squidgard not working in 2.2.4

    Locked
    1
    0 Votes
    1 Posts
    588 Views
    No one has replied
  • PfBlockerng issues with removing IPv4 lists

    3
    0 Votes
    3 Posts
    1k Views
    L
    Worked perfect!  Thanks for the quick response.  Love pfblockerng, keep up the great work!
  • NUT & APCUPSD shutdown signal?

    7
    0 Votes
    7 Posts
    3k Views
    E
    Thank you so much, dennypage.  You answered my question. Thanks for the link, doktornotor.  I'll check it out.  Much appreciated as always.
  • Packages fail to install, or install with files missing

    6
    0 Votes
    6 Posts
    2k Views
    T
    No more package problems.  I’d made no changes since the last package download failures of about a week ago, and had downloaded a copy of Wireshark and started a packet capture.  pfBlockerNG and Suricata both installed fine, to include all subordinate downloads.  I installed pfBlockerNG  on my other pfSense installation, which had also been failing, and it installed with the same success.  It seems that the package download problem I’ve been having for the past few weeks just went away.
  • Dhcp and dns package

    4
    0 Votes
    4 Posts
    1k Views
    johnpozJ
    Why would a client need to lookup spam server? So are you running Active Directory or not.. You mention ldap server..  So your using ldap to auth, but not AD from MS? Yes bind is a good name server.. How many IPs are you talking about?  You can use either dnsmasq or unbound that are both part of pfsense without any packages added.  Do you need a full blown authoritative name server? Your clients need to talk to the dhcp server at some point, but normally a worse case is /2 of your lease because if your dhcp just happen to fail you could have clients that were like 1 minute away of renew of their lease at the 50% mark, etc. I don't see the advantage of moving dns away from pfsense unless your going to setup redundancy on that system.  Or your just moving it to a system that could also just fail..  Unless you need some specific feature of dns that is not supported in dnsmasq or unbound or even the bind package for pfsense not sure moving it off buys you anything unless the other system is AD where all members of the AD should use AD dns and dhcp since it makes it easier to work with, etc..  If your reason for moving it off is you want dns if pfsense fails - the other system could fail as well..  Just because internet goes down does not mean pfsense stops providing local name services or dhcp even, etc. You could always setup carp for pfsense if your worried about the system failing, etc.
  • Syslog-ng: 500 - Internal Server Error

    1
    0 Votes
    1 Posts
    511 Views
    No one has replied
  • Uninstalling bind removes nsupdate

    8
    0 Votes
    8 Posts
    1k Views
    D
    Sorry, NFC. File a bug at Redmine, would need PBI rebuild anyway, not fixable with the package code.
  • MOVED: squid3 not starting with ssl interception enabled

    Locked
    1
    0 Votes
    1 Posts
    508 Views
    No one has replied
  • MOVED: How to give access to a user to view realtime of squid3

    Locked
    1
    0 Votes
    1 Posts
    426 Views
    No one has replied
  • Root: IP-blocklist was found not running

    2
    0 Votes
    2 Posts
    449 Views
    D
    No, not with this amount of info.
  • 0 Votes
    2 Posts
    658 Views
    C
    Packages are no longer supported on 1.x versions. You're 15 releases and 6 years behind, upgrade.
  • Bug in package "Bind" for pfSense causing it not to start.

    7
    0 Votes
    7 Posts
    4k Views
    RuddimasterR
    This bug is still here in version 2.2.4,  09.2015
  • MOVED: Version 2.1.5 Snort Missing from Available Packages

    Locked
    1
    0 Votes
    1 Posts
    535 Views
    No one has replied
  • MOVED: NtopNG Lua errors

    Locked
    1
    0 Votes
    1 Posts
    539 Views
    No one has replied
  • 0 Votes
    3 Posts
    1k Views
    C
    Ok, this Makel sense!  :- So I will reinstall the Firewall Cheers Christian
  • Unable to install any packages

    5
    0 Votes
    5 Posts
    1k Views
    T
    I'm searching the forums for solutions.  No harm intended.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.