Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB
    It was all CVE fixes in the PHP GUI part of the package. See the Redmine ticket here: https://redmine.pfsense.org/issues/16414.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    V
    @Gertjan Thanks for your reply – that’s also my impression. The point is: I don’t really see any lists right now that are actually “maintained” in the sense of being actively cleaned up, checked for dead domains, categorized, etc. That’s why my main interest is more about the demand: Would curated lists really be a game changer for admins? Would they be more helpful than what’s available today, or are most people already using other alternatives? If so, which ones? And from your perspective, what would be your expectation towards “community lists”? (e.g. reliability, update frequency, categories, fewer false positives?)
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    501 Topics
    3k Posts
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    610 Posts
    E
    Updated CE 2.7.2 to 1.86.4_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.4_1.pkg Freshports
  • Discussions about WireGuard

    700 Topics
    4k Posts
    Bob.DigB
    @HFADmin If it is no Site2Site-VPN then you don't need any gateways in the first place... If that is true but you want to monitor the connection then you could create dummy-gateways just to ping the remote ip-addresses.
  • Access denied from Squid - Help

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    M
    @marcelloc: Are you sure this denied site is not also included on squid blacklist? OMG yes it is included in the squid blacklist and not in dansguardian blacklist! Ok need to figure out how to configure dansguardian than :S. Thanks
  • Squid3 in transparent mode

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    M
    Have you tried a different browser or client pc?  This seems like a software issue on the client side to me.
  • Update package (OpenVPN client export)

    Locked
    8
    0 Votes
    8 Posts
    2k Views
    S
    what parameters!? It's just export tool! If you're talking about the openVPN configurations, it'll be there! To be on the safer side, why don't you take openVPN backup from the dropdown under Diagnostics->Backup/Restore!
  • Load balancing with squid

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    S
    Can u post some screenshots! Btw what interface did you chose on the proxy interface on your squid settings!?
  • Dansguardian access to /var/log

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    L
    well, my /var/log/dansguardian directory is owned by clamav and in group nobody same for the access.log file.. Check dansguardian is running as clamav I guess.
  • Squid2 old bug not resolve

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    Z
    –BUMP-- Does anyone know how to fix this?
  • Dashboard gone after deinstall of Snort

    Locked
    17
    0 Votes
    17 Posts
    5k Views
    bmeeksB
    Updated to reflect push of Snort Dashboard Widget ver 0.3.4 A new version of the Snort Dashboard Widget will hopefully go out soon is now out.  The new version is 0.3.4.  If you have the Snort Dashboard Widget installed, you most definitely want to update it to this latest version! I just discovered a rather nasty little bug that causes the Snort Dashboard Widget to crash the package startup for Snort upon a reboot of the firewall.  It only shows up when the widget is installed.  I have tested the fix for this and it works.  I inadvertently "included" an incorrect include file as part of the uninstall routine I added for the widget… :-[ Bill
  • Avahi not working as expected.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Lightsquid - Time spent on a website?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    N
    And perhaps SARG package can offer you some more specific information but you have to check this by yourself because I don't have any experience with SARG.
  • Radius user name case sensitive sensitivity

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    N
    There is some dialogue on freeradius mailing lists: http://lists.freeradius.org/pipermail/freeradius-users/2013-April/066212.html Alan Dekok is one of the developers of freeradius. He is an absolute expert in freeradius but - in my opinion - he is not very polite when posting on the list. As far as I understand him you could add something like the following in "../raddb/policy.conf" if (User-Password) { update request { User-Password := "%{tolower:%{User-Password}}" } } Perhaps you cann follow this conversation and test and if you found a solution post it here that we can implement this into GUI.
  • I have problems with sqlite3

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    The command you run only downloads the sqlite program/libraries, it does not update the PHP module. Give a 2.1 snapshot a try, it should have a more up-to-date PHP library for sqlite.
  • How to do unified reports?

    Locked
    1
    0 Votes
    1 Posts
    783 Views
    No one has replied
  • Pfsense embedded with snort and squid

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    bmeeksB
    @costasppc: Snort and Squid are not recommended in embedded installations. You will have memory hogs. Also Squid needs disk space for caching, which is not much in CF card installations. Best regards Kostas I agree for Snort.  It can easily consume more than 1 GB of RAM just by itself with a moderate rule set.  I've had some 1 GB RAM virtual machines used in my Snort testing start swapping out to disk with Snort and a full set of rules running.
  • SNORT WISH LIST!!

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    S
    Quoted Bill for the Open Issues. Wanted to seperate the two threads :) @bmeeks: Folks: I think we may be narrowing down the list of open issues in the current Snort package version 2.5.6.  Here are items that I am aware of still open.  Actually I think these are all holdovers from the 2.5.5 package.  I have working fixes for these in my current test environment.  I just want to be sure I've caught everything major before I push out a 2.5.7 package update. OPEN ISSUES 1.  Snort not saving edits to the Rules Update and Remove Blocked Offenders cron jobs. 2.  Snapshot updates on 2.1-BETA systems do not fully complete the Snort rules update post-upgrade and Snort does not start until a manual rules update is performed. 3.  Snort not auto-starting after a package reinstall with prior saved settings. Did I miss any big ones in my list?  I wanted to double-check and see if anything else was lurking out there before pushing another update. Bill
  • PhpSysInfo

    Locked
    18
    0 Votes
    18 Posts
    7k Views
    T
    Same problem I just had.. Not sure why it failing.. Will look at something and get back to you later.
  • 20th april snaps, squid issue

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    X
    can some1 give me commands to run to output the firewall rules in normal condition and when traffic stops, mayb it will provide more info
  • Snort 2.9.4.1 pkg version 2.5.6 – Change Log

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    Again, thank you for all your hard work and bug fixing! Updating from old version to the new one worked (again) without any problems!
  • Squidguard Success on pfsense 2.01

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    F
    Thx alot for the tip, I'm going to try this. I was going crazy no being able to install squidguard without crashing pfsense. I just tried this and it works with 2.0.3 !
  • Siproxd Update

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    R
    Hi! I have had big problems with my siproxd but your guide has helped alot. The problem I had were that the state between my firewall and my sip provider kept dropping. After I set the rule up that you suggested it worked much better and the state help up for some days. But this morning it was down when I came to work. I have 6 phones which are all registered in siproxd's interface. I have setup the rule as I think you did: on the Wan side the sip provider is set a source and my wan adress on the destination, port 5060 over TCP/UDP. Are there anything I can setup for forcing the state not to go down, much like a ping can keep an VPN connection up. As of now from what I can understand it keeps up as long as possible but nothing stops it from going down if the resources are needed elsewhere. Perhaps there is a way to get the state up again if it goes down? The only way that I found to get the state up again is to make an outgoing call from one of the phones. Hope for some help. Cheers! //Peter
  • Squid Filter

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    marcellocM
    @nathanpinotti: There's a VPN rule allowing all traffic to anywhere. Could it mess my LAN rule up? Not at all. Lan traffic pass by lan rules and floating tab, not vpn interface.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.