Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    656 Posts
    C
    @elvisimprsntr Updated 25.07.1 to 1.90.6_1, copied and pasted from @elvisimprsntr's post: pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6_1.pkg (Why it worked this time and not on previous updates: Over the last couple of days, I ran into the "Shared object "libutil.so.10, not found..." error that triggered the version 25.07.1 update issues some of us have been having. After I fixed that error, I decided to go back to the usual update method, and it worked.)
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    Im trying to set up Fubo TV for my mother using AT&T Wireless.. problem is they keep showing her California news channels... She wants local. Even though the website asks for her zip code they seem to default to the IP location. I have tried several times to sit down with this but can never get the thing to even ping from the other side. Connected with Wireguard here successfully for helping troubleshoot things for her otherwise.. Fubo is a PITA and keeps reverting back so I am finished trying to deal with them. Anyone got any tips? or a good tutorial??
  • Postfix with Carp

    Locked
    33
    0 Votes
    33 Posts
    8k Views
    marcellocM
    Nice! sorry for the typo on that post  :) You could set update frequency to 1h if you have a huge domain with many changes. att, Marcello Coutinho
  • Snort dying on multiple interfaces

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    not quite, I can get snort to run on all the interfaces but, after some time and a few automatic updates, snort stops running on some interfaces I can manually start snort without problems
  • Snort not running when setup on 2 interfaces

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    T
    @ermal: Can you please state your pfSense version? less /etc/version ```gives me a``` 2.0.1-RELEASE less /etc/platform ```shows``` pfsense Best regards T
  • PfSense and Snort VRT Subscription

    Locked
    7
    0 Votes
    7 Posts
    6k Views
    M
    Thank you Jamesdean for clarifying how the pfsense snort package handles Sourcefire VRT/premium rules subscriptions.
  • Fusionpbx/freeswitch package is missing

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    S
    I can try a fresh install later tonight. I really need to find a way to clone a UDMA CF card…using a CF2IDE adapter on a nano-itx motherboard's IDE primary port. Trying to keep the hardware down to zero moving parts. Having a number of CF cards to cycle through would make it a bit easier to test various packages.
  • Freeradius2 not at list package

    Locked
    8
    0 Votes
    8 Posts
    2k Views
    N
    @neewbie: I use the hard drive. I might have to reinstall my pfsense machine. You should reinstall your machine. freeradius2 is available for HDD install on amd64 and i386 :)
  • SquidGuard old version install howto

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    Blacklist rebuild can take time from 10 min up to 1.5 hour (depends on the speed of you system) Is it possible if the blacklist rebuild does not fully complete Only if it had been interrupted manually or reboot.
  • OpenNTPD timing out when performing queries

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    @biggsy: I was curious about this, having tried ntpq myself with the same timeout. I did some searching and found this thread http://www.monkey.org/openbsd/archive/misc/0408/msg00448.html It seems, from the first few responses in the very long thread, that openntpd doesn't respond to ntpq and probably never will. Do you know/suspect your LAN clients aren't sync'ing to pfSense? I expected " ntpq -p " to work, but never bothered to use anything else to check if the ntp server is working. I just performed ntpdate on one of my computers and got some positive feedback: ntpdate 10.119.97.61 29 Jan 11:38:06 ntpdate[15951]: adjust time server 10.119.97.61 offset -0.004357 sec I guess this thread can be closed. Would be nice to see what servers the pfSense box is sync'ed to, but I suppose this would suffice. Thanks for having me .. think outside the box :)
  • What is going on with Snort package?

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    C
    I just donated a bit. Thanks guys!
  • Freeswitch- process is not starting

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A
    now its working fine …thanks  ;)
  • Pfsense 2.0.1 and freeswitch

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    marcellocM
    Another hit http://forum.pfsense.org/index.php/topic,45593.msg238114.html#msg238114 Are you searching the forum? ???
  • Jail (PfJailCtl pkg) on pfsense 2

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    R
    I still use pfJailCtl GUI on 2.0.1 and it's capable to start my jail on boot. Of course it needed additional work to make it run smoothly: 1.  Turn on the debug in the GUI. 2. Configure jail and push Create which of course would not work, just copy script from debug output. 3. Replace sysinstall installed by the packet (from FreeBSD 7) with FreeBSD 8.1 version. 4. Modify script from §3 according to your needs, remember to change FreeBSD release to something 8-tish ie I used 8.2, turn ssh if you wish - remember to change port because otherwise pfSense and jail ssh would not be distinguishable. 5. Run your script from shell. 6. Boot jail from GUI. I successfully share SMB from jail, which I know is not too great idea on firewall, but it save me one box @home and it's a bit safer than sharing directly from pfsense. I also managed to run vnc to xfce4 on xvbf in the jail. If someone would need such functionality I shall share this result.
  • Snort stops working after snort update (newest 2.0 RELEASE)

    Locked
    113
    0 Votes
    113 Posts
    68k Views
    J
    @antilog: @Cino: i've always had a space, at least for the last 2 years: suppress gen_id 119, sig_id 2 suppress gen_id 120, sig_id 3 suppress gen_id 122, sig_id 22 This was in response to johnybe, who did not have a space.  :) Sorry, it was a typo.  :)
  • Snort 2.9.2.1 Upgrade?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort 2.9.1 pkg v. 2.1.1 update broke my Snort

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    C
    @mentalhemroids: ***UPDATE *** BTW, I didn't have to restart the system.  Just uninstall and reinstall. usually you dont need to reboot but i throw that out there to be safe
  • Proxy Server package (squid3) bandwidth limits not working(?)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    marcellocM
    Squid3 is not fully updated, test this feature with squid 2 package.
  • Squidguard bypassed by facebook android app

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ
    Last time I sniffed the traffic from my tablet it looked like the Facebook app just used standard HTTPS, so as marcelloc said, transparent proxying wouldn't catch it. You'd have to set the proxy settings on the phone/tablet if it's supported.
  • Snort not starting error

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    i love how no one searches anymore…
  • Can squidguard merge permission from Group ACL?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    You clients will use first-mach rule only.
  • Squid stops from working

    Locked
    6
    0 Votes
    6 Posts
    11k Views
    P
    ok. rebooting pfsense resolves the issue. I don't know what could be the issue but what I'm sure is WAN got an issue but it was restored but it seems pfsense needs to reboot. I can now ping google.com and no more No route to host issue
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.