Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @netboy said in is something wrong with pfBlockerNG?: After my post, I "changed" DNSBL -> DNSBL mode from "unbound python mode" to "unbound mode" and so far i have no issues. Terrible idea. Moving backwards in development history there.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    S
    @LaUs3r Yeah, I added those IPs, but after restarting pfSense, the WireGuard status says “handshake failed.” Also, when I do nslookup us-bos.prod.surfshark.com, I get two different sets of IPs. For example: • The first time I get 43.225.189.108 and 43.225.189.118 • The next time I get 149.40.50.216 and 149.40.50.290 So I was wondering can I add both sets of IPs, and put a “0” at the end of each, and use /24 for both IPs? I reached out to Surfshark support, and they sent me their official pfSense WireGuard setup guide see the guide here in the guide they mention 10.14.0.2 for static routes
  • HAProxy stable in 2.2?

    3
    0 Votes
    3 Posts
    1k Views
    N
    All right. Thank you. Nicolas
  • Haproxy-devel external address option (pfsense 2.2)

    3
    0 Votes
    3 Posts
    1k Views
    N
    Hi, thank you for your answer. Nicolas
  • Bypass ssl-bump on squid3-dev

    37
    0 Votes
    37 Posts
    20k Views
    marcellocM
    @webstor: He has to generate a certificate for the required domain when bumping server-side first, it is a wildcard generated for the correct domain and not the ip. I know it is for the site. the question is, in transparent mode, how could squid know without intercepting that connection from 192.168.1.1 to 64.54.10.10 is a request to microsoft windows update? Squid will only know the domain after interception, so acl will take no effect. Also there are some notes about fast and slow acls that not work on this or that squid option.
  • Need the best squid caching policy for a slow connection

    4
    0 Votes
    4 Posts
    1k Views
    T
    I had a similar network in size, and the cache hit ratio was around 15-20%. YMMV. That would likely increase if SSL interception was enabled but that bring it's own set of problems. Try it, it isn't too difficult to setup, especially if you use the pfsense package.
  • Suricata 2.0.6 pkg v2.1.4 Release Notes (pfSense 2.2 only)

    8
    0 Votes
    8 Posts
    1k Views
    C
    Your welcome Bill! Good call on how you programmed this.
  • Smokeping on pfSense

    22
    1 Votes
    22 Posts
    7k Views
    D
    So you mean - killbyname in case something happened to pid file? I wouldn't do it like that, but I am not developing pfSense. If developers need to killbyname, they should be using link with different name themselves :) I am not here to judge this. If that's how it is done currently, we'll use workaround, I just don't like that many workarounds around pfSense :(
  • Squid + SquidGuard + AD

    12
    0 Votes
    12 Posts
    12k Views
    A
    @Luiz Gustavo , there is now other repositories working ???????
  • Mailreport Problems

    4
    0 Votes
    4 Posts
    2k Views
    P
    This is in Mail Report 2.3, available now. Along with fixes here also: https://forum.pfsense.org/index.php?topic=83668.msg488777#msg488777
  • Bacula Client Package doesn't work on 2.2-rc

    6
    0 Votes
    6 Posts
    2k Views
    jimpJ
    Bacula should be OK now on 2.2, as of package version 1.0.6.
  • Sarg + dansguardian

    2
    0 Votes
    2 Posts
    947 Views
    R
    @markusxyz: Is there any conflict with sarg+dansguardian? Should I use squidguard instead? There is no incompatibility between Sarg and dansguardian. However, you will have to set the log format for dans to output in the squid format for Sarg to parse it. BTW, there are much better options for dansguardian reporting… you could install webmin and the DG reporting package - or see this thread https://forum.pfsense.org/index.php?topic=69003.msg377440#msg377440 The question on squidguard has nothing to do with Sarg… squidguard and dansguardian are not the same thing. Squidguard does blacklist based filtering. Dans does both blacklist and content based filtering.
  • Simple set-up Squid3 and Clam with Failover

    3
    0 Votes
    3 Posts
    1k Views
    O
    Well, I got Failover working. Ticking the "default gateway switching" box did the trick. I did not need to add a floating rule like many trying to do this in 2.1.5.
  • Snort Rule Fatal Error

    3
    0 Votes
    3 Posts
    1k Views
    K
    Thanks BBcan177, I'll disable the rule.
  • Ntopng won't load

    3
    0 Votes
    3 Posts
    1k Views
    E
    Thanks for the response.  Looking at the PFsense dashboard, it's sitting at 20% memory usage of the 2GB of memory being used.  I've got other fish to fry with my network, so ntopng is more of a luxury.  Alas, it was wonderful when it worked.
  • 2.2 and bind package: libz.so.5

    8
    0 Votes
    8 Posts
    2k Views
    D
    @knebb: Just wondering as there is now no symlink libz.so.5 nor libz.so anywhere… Well yes, that is the point! It does NOT need libz.so.5. It gets moaning about that one since the linker symlink under /usr/lib points to the non-existent deprecated library version. (If you look into /usr/pbi, the PBI thing somehow creates its own directory structure for each package under /usr/pbi/<packagename-$arch>/local, and redirects the calls and produces its own symlinks copies there. So, just removing/fixing the broken symlink under /usr/lib is not enough. You need to nuke and reinstall the package as well. At least that's my understanding of these stupid issues, I hate the PBI thing with passion and pretty sure at least some of the few remaining package maintainers are of the same opinion.</packagename-$arch>
  • 0 Votes
    2 Posts
    3k Views
    marcellocM
    While intercepting port 443, on http protocol will work. Skype uses port 443 but it's protocol is not http. That's why it's not working
  • Freeradius authentication over IPSEC

    5
    0 Votes
    5 Posts
    2k Views
    D
    This won't work out of the box with IPSec for reasons documented here: Why can't I query SNMP, use syslog, NTP, or other services initiated by the firewall itself over IPsec VPN
  • Ezjail package?

    1
    0 Votes
    1 Posts
    918 Views
    No one has replied
  • Squid3 Input Errors

    2
    0 Votes
    2 Posts
    1k Views
    marcellocM
    Fix all issues pinted by config alert and it will save. Are you on nanobsd or cf images?
  • Firebox LCDProc

    1
    0 Votes
    1 Posts
    641 Views
    No one has replied
  • Snort and pfsense firewall - order of processing?

    8
    0 Votes
    8 Posts
    3k Views
    bmeeksB
    You don't need to do that.  When you define the OpenVPN server setup, you specify what net blocks o the firewall VPN clients will have access to.  So long as a Snort instance is listening on those net blocks (interfaces), your VPN traffic will be inspected.  Typically the LAN is the net block VPN clients have access to. By the way, I fixed my typo in the VPN UDP port in my original post. Bill
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.