Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Lighsquid not updating

    3
    0 Votes
    3 Posts
    743 Views
    K

    I seem to remember that lightsquid was sort of flakey with the latest greatest version 3 squid, So I tended to use the older more stable squid.  Not sure what you are using.

  • Suricata 2.0.3 Package Preview

    121
    0 Votes
    121 Posts
    36k Views
    bmeeksB

    @bonkas:

    Has this issue been resolved?

    I am also running a PPPoE Connection and trying to get Suricata configured but my logs are flooded with "SC_ERR_DATALINK_UNIMPLEMENTED" errors.

    Suricata will not start automatically after a pfsense restart, is this by design or caused by these errors?

    Regards,

    No, not resolved and can't be really resolved until there is an upstream patch to Suricata so it recognizes the DLT_NULL data link type that FreeBSD assigns to PPPoE interfaces.  This is a problem in the Suricata binary that comes from upstream.

    You can make it partially work by hand-editing the suricata.yaml file and telling it the interface is an Ethernet physical link (by using the real physical NIC driver name), but you will still get occasional errors due to the PPPoE frame headers since Suricata does not expect to see them on a physical Ethernet interface.  Also, I can't guarantee you that all the detection signatures will work properly.  In short, this kind of hack is unsupported and you would be on your own.

    If you have a PPPoE interface and want IDS/IPS on it, then you should use Snort instead of Suricata.  The Snort binary fully supports the DLT_NULL data link type that FreeBSD uses.

    Bill

  • Dansguardian 2.12.0.3-i386 Will not start

    3
    0 Votes
    3 Posts
    821 Views
    R

    sounds like you are missing blacklists… try downloading them.

  • Squid and Squid Guard Logs

    3
    0 Votes
    3 Posts
    2k Views
    T

    Squidguard rotates logs daily when enabled.
    Squidguard itself maintains 3 log files.

    /var/squidGuard/log/block.log /var/squidGuard/log/sg_configurator.log /var/squidGuard/log/squidGuard.log

    There is no setting in the GUI for days of number of kb in size.
    Maybe "dvserg" can add this option into Squidguard gui/package.

  • Squidguard Blacklist

    6
    0 Votes
    6 Posts
    2k Views
    D

    @rjcrowder:

    @dvserg:

    No, its not suppurted.

    You could obviously write a shell script to download multiple and combine them…

    Hand-made way possible if you know how it may work. But many users know only GUI way.

  • Snort interfaces not starting after rule update/service restart

    7
    0 Votes
    7 Posts
    2k Views
    bmeeksB

    @adiadasman:

    Bill,

    The UUID issue does appear to be my problem. Please check your PMs as I have replied back to your original message.

    Got your PM reply and answered.  We can communicate back and forth in PM land.

    Bill

  • How to fix these Squid-3dev logs? i386 2.1.5 please help

    1
    0 Votes
    1 Posts
    825 Views
    No one has replied
  • Some RRD Graphs not working

    2
    0 Votes
    2 Posts
    745 Views
    S

    I reset the data and it all came back.

  • Apcupsd – need shutdown (not kill)

    2
    0 Votes
    2 Posts
    1k Views
    K

    I don't know your UPS, but my experience with other UPSes is:

    Upon line power loss, the system monitoring the UPS is informed about that event. The monitoring box remains running for the grace period (fpr example, 10 minutes).

    If line power has not returned within the grace period, machines get shut down (that may include the monitoring machine). There will be a preset time to allow all machines to shut down (for example, 5 minutes).

    At this point there a two options:

    1. If line power remains offline, the UPS will eventually gt to the point where the battery runs flat and it will shutdown the output. When line power returns, the UPS will eventually restart the output and the machines will reboot-sfter-power-loss (as configured in the BIOS).
    2. The line power returns before the UPS has shut down, this are a bit more interesting. Machines have been shut down already, but as they see no power loss, they will not reboot-after-power-loss. Ideally, the UPS would wait for the shutdown time period (5 minutes in my example), power cycle the outputs and everything is fine again.

    Regardless: I let the pfSense box run until the UPS power fails (no automatic shutdown or anything). Same for the modem, PBX, switches and even a few of the WLAN APs. I am aware that this causes additional drain on the battery of the UPS even after the server machines have shut down, but what the heck? Plus, with a communication infrastructure left online until the very last second, all remaining systems can continue to yell for help.

  • PFBlocker List for IPV6

    2
    0 Votes
    2 Posts
    2k Views
    ?

    I have seen a couple of IPv6 lists floating around, but can't remember where. My honest opinion is IPv6 lists are useless, unless they are used to ban entire subnets. The ease with which you can jump from IP to IP on IPv6 renders a single bad host in a list useless.

    My recommendation is to use snort/suricata to keep track of bad hosts in IPv6, and based on repeated offenders in a subnet, ban the entire subnet in a list of your own. Bad IPv6 traffic is low, it's the perfect time to experiment and tweak your security systems.

  • SNORT FATAL ERROR: (998) Unknown rule option: 'sip_header'.

    9
    0 Votes
    9 Posts
    5k Views
    bmeeksB

    @MilesDeep:

    At first, enabling the SIP Detection works.  The daemon starts.  After awhile, it the daemon stops and SIP detection is disabled.

    Does this have anything to do with fact that the update, which occurred last night, failed?

    No, a rules update will not disable nor enable a preprocessor.  I will check and be sure the default is enabled for future updates, but for now just look at the PREPROCESSORS tab and check all the preprocessors in the GENERAL section down towards the bottom of the page, then click SAVE.  You usually don't need the two SCADA preprocessors, but it hurts nothing to enable them as well.

    Bill

  • Show user name in squid

    1
    0 Votes
    1 Posts
    481 Views
    No one has replied
  • 0 Votes
    2 Posts
    2k Views
    N

    Ok I found 2 solutions:

    1. the good one is to simply add the following line in PfSense web configuration, Services, Proxy server, General, Custom Settings, Custom Options:

    ignore_expect_100 on

    yes, it works also for the REVERSE proxy.

    2. the bad one (just to know it exists) is to modify the source code of the web services' CLIENT SIDEs, in C#, by adding this line:

    System.Net.ServicePointManager.Expect100Continue = false;

    before instantiating the SoapClient object: MySoapClient My_WS_Client = new MySoapClient(); .

  • No squid.conf (squid3) on pfsense 2.1

    8
    0 Votes
    8 Posts
    6k Views
    C

    I do have a local website (owncloud) that I do not want to be cached. Was thinking of adding an "include" in the squid.inc file so everytime the package gets reloaded / changed by pfsense the cache deny all will kick in for that specific site. Where can I set that up?

    So, in sum it the squid.inc will always overwrite the squid.conf, so in the squid.inc add an include cache_exceptions.conf with cache deny all for the sites I don't want cache enabled. How can that be accomplished?

  • Adding a new secure port to Proxy Server Squid 3

    1
    0 Votes
    1 Posts
    601 Views
    No one has replied
  • Squid exited due to repeated failures

    5
    0 Votes
    5 Posts
    8k Views
    KOMK

    I saw that initially but wasn't sure it was the root cause of your problem.  You could try checking your ACLs for obvious problems (like being blank or empty) and then recreating them.

  • Replicating Dansguardian configuration

    3
    0 Votes
    3 Posts
    1k Views
    R

    Thanks, have done that for the initial config, but is there a method to keep things synchronised thereafter?

  • Squid3 3.1 not found. Squid 3.3 development service not starting.

    2
    0 Votes
    2 Posts
    880 Views
    C

    did you forget to search? https://forum.pfsense.org/index.php?topic=81118.0

    check out the 2.2 board.. there is a workaround

    https://forum.pfsense.org/index.php?topic=82232.0

  • Kernel: Bump flowset buckets to 256 (was 0)

    3
    0 Votes
    3 Posts
    3k Views
    F

    thank you and Cino

    (great answer)Cino
    That is from Limter being enabled… Goto Traffic Shaper, Limter tab.. Click on first limter you created, Show Advance Options; change Bucket Size to 256. Do this to the rest of them and you shouldn't see that message anymore

  • Color changing package pfsense?

    3
    0 Votes
    3 Posts
    866 Views
    S

    HAHAHAHAHA

    We just want to have fun :D

    @BBcan177:

    … You know that its a proven fact that Men are color blind... Or thats what the Women are telling us.... lol..

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.