Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Haproxy-devel external address option (pfsense 2.2)

    3
    0 Votes
    3 Posts
    1k Views
    N

    Hi, thank you for your answer.

    Nicolas

  • Bypass ssl-bump on squid3-dev

    37
    0 Votes
    37 Posts
    18k Views
    marcellocM

    @webstor:

    He has to generate a certificate for the required domain when bumping server-side first, it is a wildcard generated for the correct domain and not the ip.

    I know it is for the site.

    the question is, in transparent mode, how could squid know without intercepting that connection from 192.168.1.1 to 64.54.10.10 is a request to microsoft windows update?

    Squid will only know the domain after interception, so acl will take no effect.

    Also there are some notes about fast and slow acls that not work on this or that squid option.

  • Need the best squid caching policy for a slow connection

    4
    0 Votes
    4 Posts
    1k Views
    T

    I had a similar network in size, and the cache hit ratio was around 15-20%. YMMV. That would likely increase if SSL interception was enabled but that bring it's own set of problems.
    Try it, it isn't too difficult to setup, especially if you use the pfsense package.

  • Suricata 2.0.6 pkg v2.1.4 Release Notes (pfSense 2.2 only)

    8
    0 Votes
    8 Posts
    1k Views
    C

    Your welcome Bill! Good call on how you programmed this.

  • Smokeping on pfSense

    22
    1 Votes
    22 Posts
    7k Views
    D

    So you mean - killbyname in case something happened to pid file?
    I wouldn't do it like that, but I am not developing pfSense. If developers need to killbyname, they should be using link with different name themselves :)

    I am not here to judge this. If that's how it is done currently, we'll use workaround, I just don't like that many workarounds around pfSense :(

  • Squid + SquidGuard + AD

    12
    0 Votes
    12 Posts
    12k Views
    A

    @Luiz Gustavo , there is now other repositories working ???????

  • Mailreport Problems

    4
    0 Votes
    4 Posts
    2k Views
    P

    This is in Mail Report 2.3, available now. Along with fixes here also: https://forum.pfsense.org/index.php?topic=83668.msg488777#msg488777

  • Bacula Client Package doesn't work on 2.2-rc

    6
    0 Votes
    6 Posts
    2k Views
    jimpJ

    Bacula should be OK now on 2.2, as of package version 1.0.6.

  • Sarg + dansguardian

    2
    0 Votes
    2 Posts
    875 Views
    R

    @markusxyz:

    Is there any conflict with sarg+dansguardian? Should I use squidguard instead?

    There is no incompatibility between Sarg and dansguardian. However, you will have to set the log format for dans to output in the squid format for Sarg to parse it. BTW, there are much better options for dansguardian reporting… you could install webmin and the DG reporting package - or see this thread https://forum.pfsense.org/index.php?topic=69003.msg377440#msg377440

    The question on squidguard has nothing to do with Sarg… squidguard and dansguardian are not the same thing. Squidguard does blacklist based filtering. Dans does both blacklist and content based filtering.

  • Simple set-up Squid3 and Clam with Failover

    3
    0 Votes
    3 Posts
    892 Views
    O

    Well, I got Failover working. Ticking the "default gateway switching" box did the trick. I did not need to add a floating rule like many trying to do this in 2.1.5.

  • Snort Rule Fatal Error

    3
    0 Votes
    3 Posts
    958 Views
    K

    Thanks BBcan177, I'll disable the rule.

  • Ntopng won't load

    3
    0 Votes
    3 Posts
    1k Views
    E

    Thanks for the response.  Looking at the PFsense dashboard, it's sitting at 20% memory usage of the 2GB of memory being used.  I've got other fish to fry with my network, so ntopng is more of a luxury.  Alas, it was wonderful when it worked.

  • 2.2 and bind package: libz.so.5

    8
    0 Votes
    8 Posts
    2k Views
    D

    @knebb:

    Just wondering as there is now no symlink libz.so.5 nor libz.so anywhere…

    Well yes, that is the point! It does NOT need libz.so.5. It gets moaning about that one since the linker symlink under /usr/lib points to the non-existent deprecated library version. (If you look into /usr/pbi, the PBI thing somehow creates its own directory structure for each package under /usr/pbi/<packagename-$arch>/local, and redirects the calls and produces its own symlinks copies there. So, just removing/fixing the broken symlink under /usr/lib is not enough. You need to nuke and reinstall the package as well.

    At least that's my understanding of these stupid issues, I hate the PBI thing with passion and pretty sure at least some of the few remaining package maintainers are of the same opinion.</packagename-$arch>

  • 0 Votes
    2 Posts
    3k Views
    marcellocM

    While intercepting port 443, on http protocol will work.

    Skype uses port 443 but it's protocol is not http.

    That's why it's not working

  • Freeradius authentication over IPSEC

    5
    0 Votes
    5 Posts
    2k Views
    D

    This won't work out of the box with IPSec for reasons documented here: Why can't I query SNMP, use syslog, NTP, or other services initiated by the firewall itself over IPsec VPN

  • Ezjail package?

    1
    0 Votes
    1 Posts
    906 Views
    No one has replied
  • Squid3 Input Errors

    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    Fix all issues pinted by config alert and it will save.

    Are you on nanobsd or cf images?

  • Firebox LCDProc

    1
    0 Votes
    1 Posts
    638 Views
    No one has replied
  • Snort and pfsense firewall - order of processing?

    8
    0 Votes
    8 Posts
    3k Views
    bmeeksB

    You don't need to do that.  When you define the OpenVPN server setup, you specify what net blocks o the firewall VPN clients will have access to.  So long as a Snort instance is listening on those net blocks (interfaces), your VPN traffic will be inspected.  Typically the LAN is the net block VPN clients have access to.

    By the way, I fixed my typo in the VPN UDP port in my original post.

    Bill

  • Snort + squid3 (transparent http/https) - inspect ssl traffic?

    4
    0 Votes
    4 Posts
    2k Views
    N

    Hmm,

    wanted to click "Thanks" for both posts but just works for one.
    So thank you for your feedback. Would be a nice feature if it works but it is probably not that easy.

    Thanky you!

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.