Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Networkwide Adblocking - possible package?

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    J

    dns can be anywhere but you want that dns server to use the host file downloaded and to redirect ads to pfsense ip. basically i didn't do anything special but decide to compile the pixelserv program for freebsd

  • 0 Votes
    58 Posts
    23k Views
    marcellocM

    changing ports to compile 1.4.19, it return erros

    In file included from src/proto_http.c:22: /usr/include/netinet/tcp.h:40: error: expected '=', ',', ';', 'asm' or '__attribute__' before 'tcp_seq' /usr/include/netinet/tcp.h:50: error: expected specifier-qualifier-list before 'u_short' /usr/include/netinet/tcp.h:175: error: expected specifier-qualifier-list before 'u_int8_t' gmake: *** [src/proto_http.o] Error 1 *** Error code 1 Stop in /usr/ports/net/haproxy. *** Error code 1 Stop in /usr/ports/net/haproxy.

    Maybe we will need to way ports update to be able to create haproxy 1.4.19 package

  • Barnyard log Sguil?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Varnish

    Locked
    25
    0 Votes
    25 Posts
    19k Views
    marcellocM

    check backend status on varnish widget.

    You must disable nat for port 80, varnish will do the job.

    Until you get this working, publish varnish on port 81 for example, create a wan rule to permit port 81 communication and do tests.

  • HOw do you make disabled rules stay disabled?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A

    Thanks for the updated info.  I mis-used the "suppress" part.  I thought it was just to not show those events being triggered in the webConfiguration log.

    Thanks!

    AWS

  • BGP filters

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort: Where are the Alert log's saved?

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    W

    Thank You!

  • I am not getting Blocked site web page in squid

    Locked
    11
    0 Votes
    11 Posts
    3k Views
    N

    @marcelloc:

    squid works very well on 2.x platform.

    but congratulations on your successful setup.

    Its a surprise for me again, my server was working fine till Saturday and Today on Monday is has started giving same error. I had not upgraded my PFsense it is still 1.2version, then how come it had it started behaving like my previous issue.
    Please letme know how my ACL's can we make and how many computers we can allow for internet. I had made 23 Group ACL's and around 400 IP address is been allowed for internet.
    Below is my configs for Cache Management
    Hard disk cache size : 4096 MB
    Hard disk cache system : ufs (please explain what this means)
    Memory cache size : 512 MB
    Minimum object size : 0
    Maximum object size : 1024
    Maximum object size in RAM : 10240
    Level 1 subdirectories : 16
    Memory replacement policy : Heap GDSF (please explain what this means)
    Cache replacement policy : Heap LFUDA (please explain what this means)
    For Traffic Management
    Maximum download size : 10240
    Maximum upload size : 10240
    Overall bandwidth throttling : 0
    Per-host throttling : 0
    Finish transfer if less than x KB remaining : 0
    Abort transfer if more than x KB remaining : 0
    Finish transfer if more than x % finished : 0

    Please Guide on above config are the required any corrections

  • Squid Redirection

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    R

    Nevermind, got it working. Logging in as root helps. Thanks for the info, everything is great now. BTW, didn't need to change to port 80, I just specified the same port my GUI uses in the squidguard blacklist config. I don't know why, but I feel using a port other than 80 adds some additional layer of protection. I know that the port number change up is miniscule, but it fools passing probes on the internet. Thanks for the pointer again, I had no clue it was that simple…

  • HAProxy issue with FireFox

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM

    @gommox:

    I also don't understand one thing: how HAProxy knows to which server to route the request if there is no any map between the hostname and the IP? when the request comes from Internet "www.server_1.com" how HAProxy knows to which serverto route the request? I thought that it checks on DNS Forward configuration in PFSense box (all domains are configured there, domains existing in my DMZ). It is correct or I'm wrong?

    That's the point, haproxy balance based on ip addresses not based on host names.

    If you need hostname balance, then you need to use varnish or apache2+mod_security

    take a look on package description to choose between both.

    I prefer varnish  ;)

  • Postfix forwarder - soft_bounce

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM

    I can't work out whether this last sentence is saying soft_bounce should always be off (for both postfix and postscreen) in a non-test environment.   Do you have any further information/advice on this?

    The soft bouce field has this info taken from postfix documentation
    Safety net to keep mail queued that would otherwise be returned to the sender.
    This parameter disables locally-generated bounces, and prevents the Postfix SMTP server from rejecting mail permanently, by changing 5xx reply codes into 4xx.
    However, soft_bounce is no cure for address rewriting mistakes or mail routing mistakes.

    I have this enabled and working for many weeks, so i think using default option 'enabled only in postscreen' will be enough.

  • Squid 2.7.9_4.2 fails to fully install on 2.1 Dev

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    P

    I also have problems installing Squid on PFSense 2.1 DEV (i386).
    When installing the package, on the re configuring filter part, I briefly get the following warning:
    Warning: unlink(/etc/squid/squid.conf): No such file or directory in /etc/inc/pkg-utils.inc on line 794 Warning: symlink(): No such file or directory in /etc/inc/pkg-utils.inc on line 795

    Then, the package seems to have installed successfully, but when I access the "Proxy Server" from the Services menu, I get this error:
    Warning: dir(/usr/local/etc/squid/errors/): failed to open dir: No such file or directory in /etc/inc/pfsense-utils.inc on line 432 Fatal error: Call to a member function read() on a non-object in /etc/inc/pfsense-utils.inc on line 433

    Anyone can give me an idea what to do and how can I troubleshoot this ?

    Thanks a lot.

  • Munin-node on PFsense 2.0

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    H

    Revised instructions for dhcpd3:

    setenv PACKAGESITE "ftp://ftp-archive.freebsd.org/pub/FreeBSD-Archive/ports/amd64/packages-8.1-release/Latest/"

    pkg_add -r p5-Net-IP make++ p5-YAML p5-Net-Netmask

    ln -s /usr/local/bin/makepp /usr/local/bin/make

    /usr/bin/perl -MCPAN -e shell

    install HTTP::Date

    printf '[dhcpd3]\nuser root\nenv.configfile /var/dhcpd/etc/dhcpd.conf\nenv.leasefile /var/dhcpd/var/db/dhcpd.leases' > /usr/local/etc/munin/plugin-conf.d/dhcpd3.conf

    ln -s /usr/local/share/munin/plugins/dhcpd3 /usr/local/etc/munin/plugins/dhcpd3

    /usr/local/etc/rc.d/munin-node.sh restart

    patch –ignore-whitespace /usr/local/share/munin/plugins/dhcpd3 <<end<br>--- dhcpd3.orig 2012-01-06 19:05:37.000000000 -0600
    +++ dhcpd3      2012-01-06 19:07:14.000000000 -0600
    @@ -219,6 +219,12 @@
                print "# DEBUG: in $1\n" if $DEBUG;
                $ip = $1;
            }
    +        if($ip && /binding\s+state\s+([^;]+);/) {
    +            if(($1 eq "free") || ($1 eq "backup")) {
    +                print "# DEBUG: binding state $1\n" if $DEBUG;
    +                $abandon = 1;
    +            }
    +        }
            if($ip && /ends\s+\d+\s+([^;]+);/) {
                # 2037/12/31 23:59:59 is max date on perl <= 5.6
                print "# DEBUG: end $1\n" if $DEBUG;
    END</end<br>

  • IMSLogViewer - MySQL Log Viewer for IMSpector

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S

    Updated it a lot, now auto-updating data by default in background, remembering last read logs and last selected item in tree, showing unread logs as red icons, several UI tweaks and optimizations, better  MySQL queries. Also remembers it's window position. Exceptions are handled nicely and shown in nice looking toolbar if something happens, also all other types of issues etc.

    Source code (VS2010, .NET 4.0 Client):
    http://www.datafilehost.com/download-656d8917.html

    Compiled application:
    http://www.datafilehost.com/download-5b81570b.html

  • Postfix forwarder - bounce retries

    Locked
    7
    0 Votes
    7 Posts
    8k Views
    marcellocM

    I saw that there is a forum on MailEnable site. You can try to find out how to extract valid recipients there.

  • Postfix-Fowarder - enabling remote policyd server breaks config

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    gwhynottG

    @marcelloc:

    You did right.  :)

    I'll include this fix on next release.

    thanks,  have a good weekend.

    -g

  • Captive Portal redirection url after aunthentication

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    marcellocM

    Look for cative portal forum threads, there are posts for captive portal then transparent proxy

  • Freeswitch wont start

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    A

    @chpalmer:

    Take a look here and see if an alternative install to pfSense might work for you…

    http://wiki.fusionpbx.com/index.php?title=PfSense_Install

    Im not sure how well if at all the freeswitch packages have been kept up...

    Hi Chpalmer, I am running the latest version 2.0.1 of pfsense. Are you suggesting that freeswitch may not work well with this release and I install an older one?

  • Squid install failed… packages-8.1-release/All/perl-5.12.4.tbz

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM

    See what perl version are available on files.pfsense.org. Could be just a minor version Fix on squid install.

  • Squid reverse Proxy

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    T

    this one here's working…
    perhaps you can have a look...

    INTWEB_SSL;192.168.10.20;443;HTTPS
    INTWEB;192.168.10.20;80;HTTP

    WEBAPP_SSL;faq;https://ext.host.net
    WEBAPP_SSL;gallery;https://ext.host.net
    WEBAPP_SSL;kplaylist;https://ext.host.net
    WEBAPP_SSL;filez;https://ext.host.net
    WEBAPP_SSL;piwik;https://ext.host.net
    WEBAPP;faq;http://ext.host.net
    WEBAPP;gallery;http://ext.host.net
    WEBAPP;kplaylist;http://ext.host.net
    WEBAPP;piwik;http://ext.host.net

    INTWEB_SSL;WEBAPP_SSL
    INTWEB;WEBAPP

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.