Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    tinfoilmattT
    Here. I think. Referenced as "github.com: vendor-provided URL vendor-advisory" in your link.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @netboy said in is something wrong with pfBlockerNG?: After my post, I "changed" DNSBL -> DNSBL mode from "unbound python mode" to "unbound mode" and so far i have no issues. Terrible idea. Moving backwards in development history there.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    648 Posts
    C
    @mightykong Yes, my system also requires a restart after reboot, and what has worked for me is: service tailscaled stop && tailscale logout || true && service tailscaled start && tailscale up What has worked for updates included a [sysrc tailscaled_enable="YES"] that is supposed to handle tailscale restart after reboot, but it has not worked for me. I am looking into it, and others will be as well. In the meantime, this is my update one-liner command line: service tailscaled stop && tailscale logout || true && fetch https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6.pkg || exit 1 && IGNORE_OSVERSION=yes pkg-static add -f tailscale-1.90.6.pkg && rm -f tailscale-1.90.6.pkg && service tailscaled start && tailscale up Options: add && tailscale version && tailscale status to automate a first check; and, the "rm -f tailscale-1.90.6.pkg" is not needed, but once I saw the suggestion, I decided to keep it.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    A
    Hi everyone, This is a noob question but already tried multiple and I hope some one can help with this. I have a Wireguard Tunnel configured and handshake is successfully performed and I can ping the server from the laptop but can't do it otherwise. Already deactivate the NAT feature and all the rules and no luck. Pfsense and this server is located in a Proxmox Server, laptop is a local. Any ideas? Thank you.
  • Packages unavailable when using IPv6

    2
    0 Votes
    2 Posts
    2k Views
    ?
    Performed a new test with Prefer IPv4 disabled and enabled and captured DNS queries Prefer_IP_Disabled_Enabled_DNS_queries.txt
  • Can't access LAN from wireguard tunnel.

    2
    0 Votes
    2 Posts
    1k Views
    4
    @4rt PLEASE DETELE I figured it out. Thanks anyway.
  • Zabbix6 agent & proxy

    2
    0 Votes
    2 Posts
    2k Views
    M
    Looks like this was added! Thanks!
  • Package updates don't restart services

    5
    0 Votes
    5 Posts
    2k Views
    P
    Thanks all for the explanation!
  • 1 Votes
    20 Posts
    5k Views
    viktor_gV
    Redmine issue created: https://redmine.pfsense.org/issues/13002
  • System Patches update on 2.5.2

    5
    0 Votes
    5 Posts
    2k Views
    jimpJ
    There is an update for System Patches on Plus 21.05/CE 2.5.2, even if your update branch is set to stay on Plus 21.05/CE 2.5.2. We put an update there to add the recommended patches list populated with important security and stability fixes for people who couldn't upgrade to 2.6.0 right away.
  • DynDNS updates deprecated ipv6 addresses, resulting in service disruption

    3
    0 Votes
    3 Posts
    2k Views
    S
    @bob-dig yes. I consider it normal after a forced disconnect, being offline for a couple minutes until the new prefix has propagated downstream and every system chose it's new address. This is a design issue in ipv6 as a whole, amplified by fraudulent ISP's. Downtime due to this is definitely longer than we remember from ipv4/nat. But that's not at all part of my topic. This topic is all about the dyndns script not working for ipv6.
  • is it conceivable to arrange numerous standards in SQuidGuard?

    1
    0 Votes
    1 Posts
    833 Views
    No one has replied
  • No packages available on multiple CE 2.6 devices

    13
    1 Votes
    13 Posts
    3k Views
    GertjanG
    Instead of manipulating IPv6 settings and impacting all local networks, what about informing the 'package update' scripts from pfSense to prefer IPv4 ? Have a look at /usr/local/libexec/pfSense-upgrade - line 24 That's just what we need. To implement : Goto line 1415 and change unset force_ipv4 to force_ipv4=1 So, instead of "let the system decide if IPv4 or IPv6 is used" the calls to the pkg commands are now instructed to use IPv4. Later on, undo the change or just forget about it as an update will take care of undoing it anyway. Btw : I had a console open, implement the change and used option 13 : Update from console. It took seconds to sync up and finish.
  • Dear PF users, what happened to SquidGuard blacklists web pages?

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    There are not many people still maintaining lists for squidGuard. It's not so useful these days compared to other methods such as DNS based blacklists. Browsers are making it more and more difficult to safely and securely use a proxy for these kinds of tasks. The list at http://www.squidguard.org/blacklists.html used to have all of them, though I don't know how viable any of them are. It still lists Shalla even though that's gone, so the others may be questionable as well.
  • no menu updates after un-/installs of modules

    Moved
    1
    0 Votes
    1 Posts
    798 Views
    No one has replied
  • 0 Votes
    1 Posts
    724 Views
    No one has replied
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • FreeRadius, filter user with groups

    2
    0 Votes
    2 Posts
    3k Views
    E
    Some improuvment... It works but I am not satified! I put in the user filter (and desactivate the Group Membership part) : (&(uid=%{User-Name})(memberOf=cn=wifi,ou=group,dc=mydomain,dc=net)) => It work fine... only user in "wifi" group can be connected => I have to add the "menberOf" module in ladap I have know the following ldap/freeradius conf : ldap { server = "ldap.mydomain.net" port = "389" identity = "cn=admin,dc=mydomain,dc=net" password = 'xxxx base_dn = "dc=mydomain,dc=net" user { base_dn = "${..base_dn}" filter = "(&(uid=%{User-Name})(memberOf=cn=wifi,ou=group,dc=mydomain,dc=net))" } group { base_dn = "${..base_dn}" filter = '(objectClass=posixGroup)' } profile { filter = "(objectclass=radiusprofile)" } I think there is a better way... if some knows how ?
  • bind 9.16_13 - rndc delays

    1
    1 Votes
    1 Posts
    1k Views
    No one has replied
  • NMap scan GUI timeout fix

    1
    0 Votes
    1 Posts
    679 Views
    No one has replied
  • Cron-Package sort by time

    1
    0 Votes
    1 Posts
    626 Views
    No one has replied
  • squid / squidguard reliability

    6
    0 Votes
    6 Posts
    2k Views
    M
    @michmoor Thank you a lot for this clear answer, I will follow your advice for next questions.
  • FreeRadius - Mac addresses treated as Users

    3
    0 Votes
    3 Posts
    2k Views
    M
    Thats perfect... Will give it a try tonight. Thanks @NogBadTheBad
  • [Sovled]ntopng unable to start

    2
    0 Votes
    2 Posts
    1k Views
    S
    @scorpoin Solved . I removed the check ```Keep Data/Settings then uninstall the package and reinstalled it ,every thing works fine . But I lost all previous gathered data :( . Regards
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.