Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • SquidGuard ACL

    3
    0 Votes
    3 Posts
    850 Views
    M

    You get a happy face karma for your efforts.  Thanks.  8)

  • Squid and Firewall Rules - FailOver(Help)

    1
    0 Votes
    1 Posts
    481 Views
    No one has replied
  • Snort Reinstall Failure!

    4
    0 Votes
    4 Posts
    941 Views
    bmeeksB

    @pfff:

    Hi

    Thank you so much Bill for all your great work on Snort and Suricata!

    I ran into a problem 1-2 months ago with Snort before I switched to Suricata and just never found the time to report it. I was updating Snort and the installation script proceeded as usual to remove the old package but then my internet connection failed and the new package couldn't be downloaded and the installation aborted leaving me with no Snort at all. Perhaps it would be better to download the package first and only then proceed with the actual installation. I'm not sure if this issue is still present or related to the above post because I can't see the screenshot but I thought I'd report it.

    Suricata is working great, thanks again.

    The process for downloading and installing packages is handled by the pfSense core code.  The packages themselves have no control over that.  There have been suggestions for improvements in this area posted on the pfSense Redmine Bug Tracking site.  One of those suggestions was to first download and verify the new package before removing the old one.

    Bill

  • Blinkled stops working since upgrading to 2.1

    5
    0 Votes
    5 Posts
    1k Views
    N

    Hi,

    Has anyone found a fix for the problem?.  I have pfsense 2.1.5-Release with Blinkled 0.4.3.  It installed without problems and run for a few days before the Led 2 or 3 will stopped working or blink continuously for no reason.

    I need to reboot the unit or go to the Blinkled interface page and click "Save" to get it working again.  This will fail again in a few days time.

  • Varnish on NanoBSD pfSense

    2
    0 Votes
    2 Posts
    557 Views
    N

    No one can answer this simple question? :-[

  • Snort not working

    5
    0 Votes
    5 Posts
    2k Views
    L

    @bmeeks:

    @laptopdude90:

    @bmeeks:

    @laptopdude90:

    Snort is only detecting http_inspect. It's always 'http_inspect: UNKNOWN METHOD' or 'http_inspect: NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE'. I've tried using IDSWakeup, which didn't trigger anything. I also tried an online port scanner, which didn't trigger anything. I have set snort up listening on the WAN port. I should probably note that my ISP requires me to set up a virtual WAN port on VLAN 35, and that is what snort is listening on.

    Screenshots: http://imgur.com/a/BtYoq

    Yes, I have updated the rules, and I have restarted Snort.

    Those are very common false positives.  Did you read the threads here in the Packages sub-forum about generating a Suppress List so that the known false positives don't trigger?  Search this forum for threads about Suppress List generation.

    Do you have blocking enabled on your interfaces?  You set this on the INTERFACE settings tab.

    Bill

    The problem isn't the false positives, it's the fact that they're the only things that trigger.

    What do you mean about this blocking interfaces thing? Where do I find it?

    1.  From the pfSense menu, choose Services…Snort.

    2.  When the Snort tabs appear, either double-click on a selected interface or click the "e" icon to edit that interface.

    3.  The action in #2 above will open a new set of tabs for that specific interface's configuration.  On the SETTINGS tab you will find checkboxes for enabling the blocking of offenders.

    You can see what blocks have been put in place by clicking the BLOCKED tab.

    Where do you have Snort configured? Is it on the WAN interface or another one?  And how specifically did you run the IDSWakeup test?  Did you run that from a remote machine and target the firewall interface where Snort was running?  Depending on where you browse to and the amount of traffic on your network, it is quite common to have few Snort alerts.  For instance, on my home LAN where Snort is configured on the WAN and LAN, I get maybe one LAN alert per week because there is just me and my wife surfing and we have only a few favorite sites we visit.  On the WAN side I get a number of alerts per hour from some IP blacklists using the IP REPUTATION preprocessor.

    Bill

    Blocking is turned off. Snort is configured on the WAN interface. I ran the test from my father's network on my linux laptop, directed toward my IP.

  • Squid3-dev SSL MITM Proxy Mode Not Working

    1
    0 Votes
    1 Posts
    830 Views
    No one has replied
  • Cron Package - Add label to scheduled command?

    1
    0 Votes
    1 Posts
    548 Views
    No one has replied
  • How do I get squid to work with OpenVPN clients

    1
    0 Votes
    1 Posts
    763 Views
    No one has replied
  • Slow speed on "some?" pages. SQUID

    3
    0 Votes
    3 Posts
    1k Views
    R

    Hi, thanks for your replay.

    I changed "Memory cache size" from 8 to 512, and after that it started loading pages at exceptional speed, then changed it back to 8 just to test and it kept loading the page fast.

    Weird behavior since i have the "Hard disk cache system" to null this whole time,

    Anyway its working fine and i have no idea why  :-X :-\

    Thanks for the help.

  • FreeRadius 2.X & OTP Authentication

    4
    0 Votes
    4 Posts
    2k Views
    R

    Sorry I can't remind what I've done to make it works. It was a misconfiguration very stupid…  Can you show me your configuration I will tell what's different with mine.

  • Add packages to pfs 2.1.5?

    4
    0 Votes
    4 Posts
    1k Views
    BBcan177B

    You should probably use the 8.3 link instead for future pkg adds. When you install a pkg, you might need to run the following command (your reboot also fixed it) after you install the pkg for the pkg to be accessible.

    rehash

  • Bacula-client service fails to start on boot

    4
    0 Votes
    4 Posts
    3k Views
    D

    My fix:

    mkdir /usr/local/bacula/
    chown bacula:bacula /usr/local/bacula

    Run vipw from the command line and adjust the home directory for bacula to be the above mentioned directory.

    That is insufficient to get the correct WorkingDirectory value in bacula-fd.conf file.

    The path, /var/db/bacula is hardcoded at https://packages.pfsense.org/packages/config/bacula-client/bacula-client.inc

    Is that the problem?  I believe so.  If I edit /usr/local/pkg/bacula-client.inc and put the new path in there, the correct configuration is saved.

    In addition, all instances of BACULA_LOCALBASE . /etc/bacula-fd.conf in /usr/local/pkg/bacula-client.inc needs to be BACULA_LOCALBASE . /etc/bacula/bacula-fd.conf

    NOW it runs:

    [2.1.5-RELEASE][admin@pfsense.unixathome.org]/cf(110): ps auwx | grep bacula
    root    6659  0.0  0.3 28864  5756  ??  Is  12:56PM  0:00.00 /usr/pbi/bacula-amd64/sbin/bacula-fd -u root -g wheel -v -c /usr/pbi/bacula-amd64/etc/bacula/bacula-fd.conf
    root    9672  0.0  0.1  6088  1400  1  R+  12:56PM  0:00.00 grep bacula

    In addition, the code seems to append -dir to the Director Name via pkg_edit.php?xml=bacula-client.xml&act=edit&id=0

    Hope this helps to fix this bug.

  • Snort 2.9.6.2 update 3.1.2 stopped working

    18
    0 Votes
    18 Posts
    2k Views
    G

    Hi,

    I don't know how, but it took a while, now is working fine as I had it before.

    Solved!

  • New package submitted for OSSEC server

    8
    0 Votes
    8 Posts
    5k Views
    E

    hello all, that's good news, I'm waiting to test this package
    where I can download ?

  • Youtube Dyanamic and Update Caching breaks caching

    1
    0 Votes
    1 Posts
    758 Views
    No one has replied
  • [help] lightsquid package in pfsense error in running

    8
    0 Votes
    8 Posts
    2k Views
    A

    Hi, Thanks for the answer,,,,,but it does not solve my problem,…i dont want to use sarg report or maybe i will try it later but for now im looking for a solution of this error,thanks a lot...

  • Snort not holding settings

    7
    0 Votes
    7 Posts
    1k Views
    BBcan177B

    @wbennett77:

    Thanks BBcan177,
    Once last question re snort. If I have the IPS policy set to Connectivity or Balanced and "Block Offenders" disabled does that make Snort just a logger or is it still protecting against the IPS policy chosen?
    Thanks!

    You have to enable "Blocking" for it to actually Protect your network. or its just going to Alert only.

    I suggest "Block Offenders", "Kill States" and "Block Both"

  • Snort 2.9.6.2 pkg v3.1.2 Update – Release Notes

    21
    0 Votes
    21 Posts
    3k Views
    A

    As an update… thanks for the replies guys.  I finished the HA cluster upgrade from 2.0.3 to 2.1.5 this morning (everything went perfectly).  I definitely didn't want to customize the installation by trying to get snort to work on 2.0.3.

  • Pfsense 2.1.5 haproxy-devel install issue + fix

    4
    0 Votes
    4 Posts
    1k Views
    P

    Hi pjkenned,

    Thanks.

    I never thought a config that small (basically nothing configured yet, no frontends / no backends) would cause such a big problem (php process 'crashes' in the background).. Even though while when haproxy configuration is completely absent there apparently is no problem..

    Send a pull-request https://github.com/pfsense/pfsense-packages/pull/720 to fix this issue. It will probably get pulled later today.

    Thanks for reporting the issue & providing the info required to fix it.

    Kind regards PiBa-NL

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.