Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Squid no log.

    Locked
    1
    0 Votes
    1 Posts
    959 Views
    No one has replied
  • Squid and squidGuard problem

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    N
    @nassman: how to solve it?? Read this: http://www.squid-cache.org/Doc/config/redirector_bypass/ squid will crash if all redirectors are busy but does not allow anyone to bypass squid if it is set ton "on". if it is set to "off" then the users will bypass the squid proxy but it will not crash. Increase the redirect_children to a larger number - lets say 25 or 50. You can do this permanent in squidguard_configurator.inc file. Before this check the "cache.log" file of squid. The will be probably something called "all redirectors are busy" or something about the queue length. CVhecvk this, too: http://www.squid-cache.org/Doc/config/url_rewrite_children/
  • NUT - UPS model not listed

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    H
    Thanks for the tip.  The service wouldn't start for any of the CyberPower selections, but the APC Back-UPS USB worked perfectly.
  • Stunnel service stopped

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    I don't recall seeing anyone say that it worked on 2.0.x, but I recall a few people saying it didn't. The package was written for 1.2.x, it could probably use rewritten/updated for 2.x, but that would require someone that knows stunnel to do it. If it's important enough, you might consider starting a bounty to see if someone can try to fix it up.
  • How to add exception in Short?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM
    did you tried to search this packages section???? There are several topics on the subject, this recent one is an example: http://forum.pfsense.org/index.php/topic,56550.0.html
  • HAVP blocking whitelisted domains

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    X
    I guess that would make sense…
  • Snort - Suppression Tutorial - (How to get rid of annoying alerts)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M
    Yeah I noticed later that there's an option for suppression in the new package  :-[ but in general it add up to our knowledge as you said esp for newbies.  ;D
  • Squid Guard times of day for specific users.

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    T
    You can fix the IP with dhcp options (service /dhcp/mac adress) After create an acl under squidguard, and configure it to allow/deny. ACL can be an IP or a range of IP
  • Snort Fatal Error

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    A complete uninstall and reinstall "without keeping settings" solved the problem.
  • Snort whitelist

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Redrects to internal ip ip based on a domain name

    Locked
    21
    0 Votes
    21 Posts
    15k Views
    L
    guac is a proxy (much like squid) you simply point your browser at guac and you are confronted with a logon page. depending on how you have configured the mappings, depends on what you are confronted with. to point your browser at gauc from external, you will need to create a A record or use your public ip and open up either 80 or 443 and point it to the guac server. alternatively, you can use squid and map to guac.
  • Snort alert need some help to interpret the data correct

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S
    Its a normal home metwork at my parents house So some one probably visited a Shady website? I just wanted to make shure thats its not a pc that is Infected with malware. My dad is really gifted in getting malware/ virusses on his pc. Thanx again
  • 0 Votes
    5 Posts
    2k Views
    M
    oh shit lol I didn'tk now that, I have created a basic list with suppress command in the list. :D but that would also be useful to work on other snort GUI just in case the add option wasn't available.
  • Snort Quits when (spp_arpspoof) detected

    Locked
    1
    0 Votes
    1 Posts
    833 Views
    No one has replied
  • A newbie snort question

    Locked
    1
    0 Votes
    1 Posts
    947 Views
    No one has replied
  • Postfix package - relay access denied

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    D
    Thanks, that did the trick! :-)
  • Issue with the postfix package

    Locked
    5
    0 Votes
    5 Posts
    1k Views
    P
    This server has a high load too, around 10.000 messages per day. Tonight I'll undo my workaround and try to collect some logs for you (can't do it during workhours). I didn't find any clues on the log the last time. I verified the error using telnet: with postscreen enable I didn't get the helo message on the internal NIC and whit it disabled I didin't get the helo message on the external NIC.
  • Dansguardian LDAP groups from AD?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T
    Thanks, Will give it a bash tomorrow and see what happens.. Rob
  • 0 Votes
    23 Posts
    8k Views
    M
    I re installed and it worked but now I have another problem with the pfsense dashboard page it self :D I only have one column for widgets not two :( how to solve this?
  • Snort Setup.

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    M
    I removed the snort package. restarted PFsense then reinstalled the package and it worked for me ..
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.