Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • PfBlocker Lists

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • SARG Schedule Starting Multiple force refreshs at scheduled time

    17
    0 Votes
    17 Posts
    7k Views
    B

    @thestealth:

    I assume I was looking for this line:

    root  28032  0.0  0.3  3348  1332  ??  Ss    6:39PM  0:00.01 /usr/sbin/cron -s

    No more weirdness in my log either.

    Thank a lot it is much appreciated.

    Yes as you can see their were 6 running before and you are welcome!

  • Snort Barnyard2 MSSQL support

    8
    0 Votes
    8 Posts
    3k Views
    M

    Hmm… Let me look into it and I'll get back to you.

  • Web proxy

    2
    0 Votes
    2 Posts
    869 Views
    R

    Not sure if this is the config you are looking for or not, but any machine on the network could run squid and serve as a proxy. It would only need one NIC to do so… Likewise, you wouldn't need pfSense at all - just squid running on a server that had access to the internet and was accessible from the other network.

  • 0 Votes
    1 Posts
    627 Views
    No one has replied
  • Vnstat2 on 2.1 broken now that rc0

    20
    0 Votes
    20 Posts
    6k Views
    B

    I have updated package. Waiting on one of the devs to upload the new php_frontend file.  :-[

    https://forum.pfsense.org/index.php/topic,71553.0.html

    [quote author=marcusone link=topic=62708.msg390896#msg390896 date=1390242650]
    Sorry for waking an old thread… but the same issue is back :(

    Beginning package installation for vnstat2 .
    Downloading package configuration file… done.
    Saving updated package information... done.
    Downloading vnstat2 and its dependencies...
    Checking for package installation...
    Downloading http://files.pfsense.org/packages/8/All/vnstat-1.11_1-i386.pbi ...  (extracting)
    Loading package configuration... done.
    Configuring package components...
    Additional files… vnstat_php_frontend-1.5.1-updated.tar.gz failed.
    Backing up libraries…
    Removing package...
    Starting package deletion for vnstat-1.11_1-i386...done.
    Removing vnstat2 components...
    Tabs items... done.
    Menu items... done.
    Loading package instructions...
    Deinstall commands... done.
    Removing package instructions...done.
    Auxiliary files... done.
    Package XML... done.
    Configuration... done.
    Cleaning up... done.
    Failed to install package.

    Installation halted.

  • Snort "disable http alerts"

    4
    0 Votes
    4 Posts
    1k Views
    bmeeksB

    @newbieuser1234:

    If i am having problem with http slowness and inspect blocks is it correct to disable the alerts to make it faster?

    newbieuser1234:

    The way to solve your issues is by adding these alerts to the Suppress List.  Go to the Alerts tab, and for each HTTP Inspect block you think is bogus, click the plus icon (+) in the SID column.  That will automatically add that alert to the Suppress List and it won't cause further blocks.  Do this for all the HTTP Inspect alerts you don't want to cause blocks, then stop and restart Snort on that interface when you're done.

    Alternatively, run Snort in non-blocking mode for several days or weeks to get a feel for the traffic in your environment.  Look at the Alert logs and add Suppress Entries for things you believe are false positives.  Once you have a good Suppress List with few or no false positives showing up in the Alerts, then put Snort back into blocking mode.  You do this on the Interface Edit tab for the interface in Snort.

    Bill

  • Trigger a sync from the Pfsense-Config to the Squidquard-Config?

    1
    0 Votes
    1 Posts
    794 Views
    No one has replied
  • Squid data export

    1
    0 Votes
    1 Posts
    915 Views
    No one has replied
  • Missing Quagga BGP package?

    6
    0 Votes
    6 Posts
    2k Views
    B

    The PBI allows for the package to sit in its own directory with its dependencies. Though the package probably needs to be rewritten to make sure that it is not moving things out of the pbi directory etc. As long as they are encapsulated I think that would work but I do not have a working understanding of either package right now.

  • Snort 2.9.5.5 pkg v3.0.2 Update Released – Bug fixes only

    9
    0 Votes
    9 Posts
    3k Views
    C

    I noticed I was also getting update errors at some times during the day.

    I changed the 'Update Start Time' parameter to a non-standard value and it fixed the problems.

  • Snort http inspection

    7
    0 Votes
    7 Posts
    10k Views
    N

    Thanks Bill

  • No graphs in bandwidthd

    12
    0 Votes
    12 Posts
    5k Views
    W

    OK,

    Good to know. I have a spare firewall with the exact same specs which is configured the same way. I will do a complete wipe and fresh install on that one and after that do the same to this one.

    Thanks,

    Roger

  • VNstat2 и PF 2.1 calendar problem

    38
    0 Votes
    38 Posts
    6k Views
    B

    @DasTieRR:

    thank for your help, I really appreciate it :)

    Your welcome  ;)

  • Dglog2 for dansguardian log analysis

    8
    0 Votes
    8 Posts
    3k Views
    R

    Really haven't messed with lightsquid much… sorry.

  • Sarg and squidguard reports

    10
    0 Votes
    10 Posts
    4k Views
    S

    @periko:

    Have u try this with squid3+squidguard?

    I have and it works very well.

  • Transparent Proxy: Squid allow Chrome to open gmail.com when it's blocked

    5
    0 Votes
    5 Posts
    3k Views
    D

    To those intressted, I managed to archive my goal by setting up an Firewall rule to REJECT the following Network range: 74.125.0.0/16

  • Mailscanner clamav update

    1
    0 Votes
    1 Posts
    763 Views
    No one has replied
  • Use Squid for IPSec HTTP Traffic

    2
    0 Votes
    2 Posts
    2k Views
    ?

    I can't see the forest for the trees.

    Now I configured a Proxy in the VPN-Settings for the Client.
    Then I added a Rule on IPSec Interface that blocks all HTTP/HTTPS Traffic not going to the Proxy or the LAN Subnet.

    It seems to work fine now.

  • Squid Lograte not happening

    2
    0 Votes
    2 Posts
    948 Views
    J

    I have the same issue.

    My squid access.log log file size is growing up.  It never rotate since the first day I start running squid.

    Looking for the solution too.

    Thanks.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.