Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    V
    Ah, I changed the action to deny both and now I also have a wan firewall rule, which I also had on OPNsense. With this wan rule I can see the blocks already coming now! Is it a bad idea to have the action set to deny both instead of inbound only?
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    S
    @LaUs3r Yeah, I added those IPs, but after restarting pfSense, the WireGuard status says “handshake failed.” Also, when I do nslookup us-bos.prod.surfshark.com, I get two different sets of IPs. For example: • The first time I get 43.225.189.108 and 43.225.189.118 • The next time I get 149.40.50.216 and 149.40.50.290 So I was wondering can I add both sets of IPs, and put a “0” at the end of each, and use /24 for both IPs? I reached out to Surfshark support, and they sent me their official pfSense WireGuard setup guide see the guide here in the guide they mention 10.14.0.2 for static routes
  • Squid 3 SSl transparent options

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    N
    Thank you, very usefull info, i haven't found it searching in the forum.
  • Squid reverse - Dead Peer detection

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Enabling Transparent Proxy slows down internet speed

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    V
    The problem got resolved by uninstalling version 3 of squid and installing squid 2.
  • BUG: bacula-fd.sh service starter tries wrong config path (fix)

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R
    @marcelloc: I've pushed a fix for this, upadate to latest package version and test again. thank you… works on both version now as expected ;) (Problem was the the patch must applied every reboot/"crash" situation and not only once after install).
  • SquidGuard does not work after auto updating blacklist

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Installed Snort - how do I know it's working?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    @Deadringers: Morning all, I installed Snort and have it setup to run all the rules on the WAN interface…it looks like it's active but how do I know if it's working? I have been to the alerts page and the blocked hosts page on the snort part of the firewall interface but I can't see anything that has been blocked and no alerts? Which leads me to believe either: 1 - It's not working properly and I've done something wrong or 2 - it has detected nothing which needs to trigger a rule. I don't believe that it's number 2 for a second as I have tried to load some "dodgy" sites and downloaded some questionable material as a test into a VM of mine. Thoughts? Ahh right I have it up and running properly now! :) a reboot of the firewall sorted things out and now I can see the logs being generated.
  • Monitoring

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D
    @rajbps: Hi DigitalDeviant, Just want to be sure the server will be in the main office and the zabbix clients will be installed on the remote locations. All running pfsense. Linking the site to the main site, there is an openvpn site to site link, so each office comes back to the main site but none of them talk to each other. So if the vpn link goes down due to the service stopping on the remote site and the link dies, how will that link start again. is the agent clever and will it restart the link as during that time the server will not be able to contact the agent. Looking forward for your answer on this one. Cheers, raj I believe, in cases where the agent cannot contact the server, it's possible to run the Zabbix Proxy on the same machine. From there you can set the agent to run a custom command to run the start command as well as report that the link went down. Once the Zabbix server gets the information it can send out an email. You may need to give the Zabbix agent elevated permissions. I've never tried this and I don't have a test server to try it on.
  • Imspector-dev not logging users running Pidgin with Yahoo under Linux

    Locked
    1
    0 Votes
    1 Posts
    987 Views
    No one has replied
  • OpenBGPd

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    Thanks guys. I addressed the disconnecting problem, it was my hardware. I tried 2.0.3 32-bit and 2.1 beta 32-bit on 2 different J&W MINIX D2550-HD, same issue. When I replaced the motherboard with a Supermicro X9SCA-F, it's all working fine. No disconnection in 3 days.
  • CRITICAL: postfix fails to start after upgrade to 2.03 release [solved]

    Locked
    24
    0 Votes
    24 Posts
    5k Views
    marcellocM
    @hcoin: Talk about belt-and-suspenders.  Makes me wish each package that was a vm guest that was its own iso/appliance.  As hard as the open source world tries to deal with 'dependency hell' it just never seems to work out of the workbench environment. On 2.1 pbi packages will be much easier… I'm testing firmware upgrade on one of my 3 inbound smtp servers and I it's stuck on upgrade process. I found a mtree process that is "indexing" /usr dir with 60bg of dcc log from mailscanner package. For next 2 boxes upgrade I'll remove these folders before the update and remove all packages as well.
  • Squid caching website status messages

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    N
    On squid-cache.org you probably find a description for nearly all config options. An example: http://www.squid-cache.org/Doc/config/negative_ttl/ And you have the possibility to check the different values for the different squid versions.
  • Snort broken: whitelist

    Locked
    26
    0 Votes
    26 Posts
    11k Views
    C
    I can appreciate the difficulty in creating a dynamic whitelist for Snort. Perhaps in the interim a partial solution could be getting the whitelist to at least populate on startup all the IPs from an alias, including those from FQDNs.
  • SquidGuard blocking pages

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    K
    Actually firefox is configured to remember everything.
  • Snort stays online for a while, then fails to start again…

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    M
    So far so good. I'll let you know. Thanks!
  • Squidguard error page does not load on blocked URL

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    OK - I figured out most of my issues.  For anyone experiencing some of the same maybe this is helpful: Internal redirect issues: The error page is rendered from the same interface as the UI, I found out.  I have squid and squidguard on a few vlan interfaces so that I could isolate the UI and some other devices from what is basically my "mgmt" network subnet.  Because I have FW rules in place to block all traffic from the vlan'ed interfaces to this mgmt network, the page won't render. External URL's not working: While I was changing the settings I was not deleting the browser cache on my iphone between settings changes.  So, I was getting old webpages when hitting the same sites rather than the redirected pages.  So lesson learned is to always delete your cache when testing these different settings!
  • Quagga OSPF help for a beginner

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    R
    @rengiared: sorry for my late response, but i have figured out where my problem was on the site with the 2 wans i made a gateway-group and set this on the default-lan to everywhere rule as gateway, as soon as i changed it back to the default gateway preference all works then you can fix it easy we setup a "private" alias with all internal networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16) and set on each LAN a first "external" route: allow any any to !private any  over gateway group (with traffic limiter)
  • MOVED: Xenserver Tools for pfsense

    Locked
    1
    0 Votes
    1 Posts
    937 Views
    No one has replied
  • PfBlocker Lists question & Errors

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    marcellocM
    @rl2171: Strange, if I do Deny inbound it shows red, but if I deny both it shows as green. If you have no rules on wan interface, pfblocker will not create a rule as you already has an deny all traffic rule.
  • Monit on pfsense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    L
    Hi Raj, I did it the other day: http://forum.pfsense.org/index.php/topic,61602.0.html Hope that helps.
  • HAProxy Widget

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    P
    For your information, the widget is now included in the HAProxy-devel1.5-dev18 package. Made a few improvements to it to also: -Options configurable from the WebGUI. -Faster server enable/disable responses. -Dropped socat requirement. Check it out if you want 8)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.