Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Fatal error in arpwatch_reports.php on line 37

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    V

    Sorry, pFsense 2.0

  • Squid and captive portal

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R

    I do not have any 2.0 running atm. Would try so in near future…

  • Snort block

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    A

    Does anyone have any idea about this?  This seems to be an important concept of Snort that I'd like to learn.  Once again, for all enabled rules, some only alert, while other alert and block.  What determines blocking?

  • Load Balance DNS (new in 2.01) Fall Back pool not working

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    Because relayd does not support udp in general, but does support DNS.

    From the relayd.conf man page:

    The protocol directive is available for a number of different application
        layer protocols.  There is no generic handler for UDP-based protocols
        because it is a stateless datagram-based protocol which has to look into
        the application layer protocol to find any possible state information.

    And then:

    dns protocol
                (UDP) Domain Name System (DNS) protocol.  The requested IDs in
                the DNS header will be used to match the state.  relayd(8)
                replaces these IDs with random values to compensate for
                predictable values generated by some hosts.

    http protocol
                Handle the HyperText Transfer Protocol (HTTP, or "HTTPS" if
                encapsulated in an SSL tunnel).

    [tcp] protocol
                Generic handler for TCP-based protocols.  This is the default.

  • Ssp_ssl: Invalid Client HELLO after Server HELLO Detected

    Locked
    4
    0 Votes
    4 Posts
    11k Views
    D

    Hi Marcelloc,

    Thanks for your answer, but I did exactly that. I have serveral other suppressions and they work properly; they don't show up in the alert list and they don't get blocked…

    With this one they don't show up in the alert list, but they get blocked(?)

  • Squid is Slow working

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    marcellocM

    hdparm -tT /dev/sda

    It's a linux tool for hard disks.

    Pfsense is build on freebsd platform.

  • Is there someone uses Zabbix Proxy or Zabbix Agent?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jaderJ

    @guano:

    I installed them but i need some help to use.

    I've being trying to INSTALL for at least one week… allways fails:```

    Saving updated package information... done.
    Downloading Zabbix Proxy and its dependencies...
    Checking for package installation...
    Downloading http://files.pfsense.org/packages/8/All/zabbix-proxy-1.8.5,2.tbz ...  (extracting)

    Downloading http://files.pfsense.org/packages/8/All/iksemel-1.4_3.tbz ...  (extracting)

    Downloading http://files.pfsense.org/packages/8/All/p11-kit-0.9.tbz ...  could not download from there or http://ftp2.FreeBSD.org/pub/FreeBSD/ports/i386/packages-8.1-release/All/p11-kit-0.9.tbz.
    of zabbix-proxy-1.8.5,2 failed!

    Installation aborted.Backing up libraries...

    I'll keep trying… I'm installing a new pfSense (my FIRST in production) and this is a nice addon, because I have a zabbix install to monitor anything but kitchen sink! :)
  • Snort and blocking IPs

    Locked
    9
    0 Votes
    9 Posts
    11k Views
    D

    I too have the same problem.

    Isn't it possible to allways block the destination ip on one interface? So I can block destination ip-s on my LAN and source ip-s on the WAN interface…

  • Squid covering the space of harddisk so quickly

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    Squidguard has a gui option for it.

    Without squidguard, include file extension/mime types custom acls in squid gui.

    To find an acl that exclude some file types, just Google for squid +acl +file + extension

  • Basic url filter

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    V

    Ah yes, this is very nice thank you. Will be very handy :)

  • Postfix-Fowarder breaks system when enabled on 2.1

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    gwhynottG

    @darklogic:

    update your postfix forwarder from 2.3.2 to 2.3.3. It resolved the same issue you are having.

    as indicated in the link.  but thanks for taking the time to post.

    -g

  • Freeradius with rlm_ldap?

    Locked
    17
    0 Votes
    17 Posts
    15k Views
    N

    @aranel

    Is LDAP working for you now ?

    It would be greate to know if it is working now with the compiled module. I do not have any LDAP here to test with.

    Thanks for your feedback!

  • 0 Votes
    3 Posts
    5k Views
    H

    Snort Suppression Tutorial . . .
    https://www.youtube.com/watch?v=uQ7OrxtiAes

    Add Snort Suppression for Error: NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE
    suppress gen_id 120,sig_id 3

    Go to Snort WAN interface edit; Scroll down to Suppression and filtering
    Choose the Suppression just created
    Click Save
    Restart Service
    Do a port scan to see if it would trigger an alert https://www.grc.com/x/ne.dll?rh1dkyd2

    Good to Go Again  ;D  :D

    One down one to go.. Only need to Upgrade to Pfsense 2.0.1 now
    Cheers  8)

    Problem Solved…can someone mark it as solved ??
    I hope i dont have to repeat this process when i Upgrade to Pfsense 2.0.1

  • Unbound updated to 1.4.14

    Locked
    26
    0 Votes
    26 Posts
    7k Views
    johnpozJ

    Ok that seems to have fixed it, now it listens on both lan and loop when both selected in the gui

    Thanks!

    But I did not see it download the actual package .tbz file – guess I could completely uninstall it and then check with pkg_info to see if unbound its gets removed and if it then download loads it.

    But since it working and on current version I think will leave it until 1.4.15 comes out to test ;)

    Thanks again for the fix!

    But kind of curious still about the out of sync other packages.

    So 1.4.14 says it needs expat-2.0.1_2, but have _1 installed -- can I force removal and then install _2 -- but could that break git, cuz I use that like once a week when new changes come out.

  • All installed packages are missing after upgrade from 2.0.0 to 2.0.1

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    D

    thank you so much , server up.

    regards

  • Transferring lightsquid logs and squid cache folder

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    Compress logs with tar then transfer file to another server using scp for example.

    tar -cvzf backup.tar.gz  /path/to/squid/logs

  • Disk space used by squid.

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    L

    even easier.. nice one.

  • Can u help me!!!!!

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G

    Well, i have installed the previous and use the software i need it to run

    ;)

    That works out for me!!

    Thats a temp solution, of course when everything be back, i will update it and move forward :)

  • How change path in Package Manager for ftp2.FreeBSD.org…?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    There are depedencies that will break using 8-stable packages on 8.1 systems.

    Take a look on this update to see how you change it.
    https://github.com/bsdperimeter/pfsense/commit/c70452506a0ab84a9d72547656b516f6e61578da

  • Not able to install Squid , Squidguard packges gives error

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    marcellocM

    files.pfsense.org is offline, wait some time and try again.

    related topic

    http://forum.pfsense.org/index.php/topic,44242.msg229525.html#msg229525

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.