Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    W

    @qinn
    Sent him an email Dan an email to the address on his site.. Not sure what is happening, my Teams stopped working. Disable it/turn it off and the problem went away.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Snort and SQL Injection (Microsoft SQL Server + IIS): SOLVED!

    Locked
    8
    0 Votes
    8 Posts
    9k Views
    M

    Well, I tried the "custom.rules" feature.

    It really does what it's supposed to do, changes on that rules are saved in the config.xml file and are recreated during the rule update.
    Just, it's quite slow when you save the rules, I don't know what actions are made on that post, but anyway to apply the changes I need to restart-snort manually.

    Ciao,
    Michele

  • Proxy Filter + LDAP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HAVP after Squid deletion

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Blank Spaces in Menus w/ Widescreen and Firefox Dev

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    B

    I have the issue with the menu's appearing under the traffic graphs with the widescreen addon.

  • Dansguardian fails to start

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K

    I don't know how to do that (where would I enter that command and what is SysV?). But what I did was uninstall, reboot, reinstall. Still error persists.

  • 0 Votes
    8 Posts
    2k Views
    jimpJ

    it should, yes, make a new interface, a proxy vm, and a vswitch to connect them (on their own subnet) and then you should be able to make that work.

  • Get Snort Alerts out of pfSense for email alerting?

    Locked
    7
    0 Votes
    7 Posts
    8k Views
    M

    @kevross33:

    Use unified2 and barnyard in Snort package to write it off to an external database and use snorby (snorby.org) to email you reports.

    I tried this, but I could never get anything to populate in Snorby. I'll research it again.

    You wouldn't happen to know of a good how-to on the web would you?

  • Snort Active Checker

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J

    Oh thank you ever so much for that, probably me being lazy as per usual to actually go back in and keep re-enabling it (or usually when I forget to check if its running) ;D

    Thank you ever so much and I will give that a whirl!

  • 0 Votes
    3 Posts
    3k Views
    N

    I'm having issues with the HTTPS reverse proxy as well, however the HTTP reverse proxy works fine.

    Currently I'm getting a squid error page saying Access Denied. Access control configuration prevents your request from being allowed at this time.

    Also I believe I found a bug in the HTTPS reverse proxy settings, you need to manually put in the listen port 443. By default it listens on 80 even though it says 443, just manually put it in there.

  • SquidGuard 1.4_2 pkg v.1.9.1: error message during updating

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    Maybe blacklist too long, more that '/tmp' size

    The black list was the "shallalist", where 300 MB should still be plenty. Explicitly executing squidGuard_blacklist_update.sh from the tmp dir does not give any error message.

  • Varnish3 package quite broken (fixed July-27-2012)

    Locked
    20
    0 Votes
    20 Posts
    4k Views
    marcellocM

    @blundar:

    Forgot patches!!!

    I'll merge a multi daemon varnish soon, I've applied the cdata fix on my updated files and varnish started fine.

    Thanks for your tests and feedback

  • Snort - reverse DNS on blocked IPs?

    Locked
    1
    0 Votes
    1 Posts
    899 Views
    No one has replied
  • SquidGuard not work on vlan interfaces

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    E

    Finally i managed to get it work BUT when there is a redirection to error page (e.g. for a denied host) the system tries to redirect to parent interface IP address…Furthermore, ont only this but it tries to redirect to the old IP address of parent interface (I have changed it..). Does anyone have any idea?

  • Lightsquid reporting - Am stuck, are there lightsquid logs I can look at?

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    T

    Hi marcelloc,

    Sorry for the delay replying - I had never used/installed sarg before so wanted to play with it a bit before commenting.  SARG worked fine as it happens.  I got the realtime reports straight away.  After playing with it a bit I got the scheduled reports too.  I can see plenty of output in /usr/local/sarg-reports.  I'm not 100% sure I understand all the SARG options on the GUI, but I'm sure if I played with it a bit I would get used to it.

    I "could" switch over to using SARG, but if it's possible I'd like to continue using lightsquid.  Does the fact that SARG works tell me anything (other than the fact the SQUID is logging away correctly and that SARG is an option for me now!)??

  • Avahi suddenly hates me

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Manually Installing packages with NO internet connection

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    There isn't a way to install them manually over SSH.

    You could clone the package repo and setup your own local copy (check the doc wiki) and install them from a local server instead.

  • Snort stopped working again (last update)

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    M

    @Gradius:

    Sigh.

    Fixed.

    It is working for me on a test box I have. Snort Auto updates enabled every 6 hours no problems.
    Snort not snort-dev

    intel atom 8 gig memory 64 gig ssd.
    2.1-BETA0 (amd64)
    built on Wed Jul 25 09:38:52 EDT 2012

  • Snort 2.9.2.3 pkg v. 2.5.1 - Completely fresh installation error

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    E

    Sorry fixed.

  • HAVP new install - am I missing something?

    Locked
    14
    0 Votes
    14 Posts
    5k Views
    jimpJ

    fixed
    https://github.com/bsdperimeter/pfsense-packages/commit/50d8ce945282aff349149de3a4fd590e364b54c7

  • Fail to install a pkg

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    W

    Oh yes…
    a short view in fstab... I had seen this in a second....

    Other Distries said... Permission denied that were usefull for me...

    All fine now ;)

    Thank you!

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.