Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    A

    @wbmstr2000 : Thanks! I will investigate it, greetings

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • How to block facebook?

    Locked
    21
    0 Votes
    21 Posts
    50k Views
    J

    Try my post <http: forum.pfsense.org="" index.php="" topic,39849.msg205547.html#msg205547="">and test it. Make a rule that reject 443/80 ports and destination all CIDR of facebook. It works form me even if they use https or http.

    jigp</http:>

  • Snort does not block traffic

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    W

    Make that a few weeks  :-\ ;)

  • Squid Guard Resets Each day - Time based ACLS

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    N

    Same issue. Need to click on "Apply". Perhaps, a poor solution would be to set a cronjob ….

  • Squid error - The request or reply is too large

    Locked
    10
    0 Votes
    10 Posts
    15k Views
    O

    thanks Nachtfalke
    i have changed the settings and also just had to post something there
    worked fine
    thanks a mil for your help!

    Oren

  • Sgerror.php page

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid filtering with MAC addresses

    Locked
    11
    0 Votes
    11 Posts
    18k Views
    C

    I did it this way:

    acl disallowed_clients arp "/var/squid/acl/allowed_clients.acl"
    http_access deny disallowed_clients

    then my acl had my macs as XX:XX:XX:XX:XX:XX

    I want to use it to deny certain boxes from using the internet/proxy

  • Squid Proxy website caching

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    R

    hi,

    you can add that 2 lines before your squid refresh_pattern lines.

    thanks

  • Snort_local.rules not shown in Rules

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort won't start after update

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    RonpfSR

    http://forum.pfsense.org/index.php/topic,41533.0.html

  • Snort issue with Preprocessor's HTTP Inspect

    Locked
    3
    0 Votes
    3 Posts
    7k Views
    JSmoradaJ

    I noticed that it wasn't a good idea…none of the rules would load basically causing snort to do a hard crash. I uninstalled/reinstalled Snort, set the suppress list as suggested and so far so good...thanks!

  • Squidguard blacklist download not working 2.0-RC1

    Locked
    23
    0 Votes
    23 Posts
    28k Views
    D

    Hi Guys I just want to help you guys with the problem you are having and giving you all the solution that worked for me to upload the Blacklist. I was having the same problem when hitting download nothing happened. Even do I setup correclty the URL under "General Settings", "Blacklist Options" chequed enabled and filled in the Backlist URL "http://www.shallalist.de/Downloads/shallalist.tar.gz". In my case I found out that Internet Explorer 8 is not working. I tried using Google Chrome, same procedure and everything worked just fine. I did not try any other borwser but for me IE 8 did not work. Hope it works for you guys also.

  • Squidguard not working - pfsense 2.0 release version

    Locked
    7
    0 Votes
    7 Posts
    12k Views
    D

    Hi Guys I just want to help you guys with the problem you are having and giving you all the solution that worked for me to upload the Blacklist. I was having the same problem when hitting download nothing happened. Even do I setup correclty the URL under "General Settings", "Blacklist Options" chequed enabled and filled in the Backlist URL "http://www.shallalist.de/Downloads/shallalist.tar.gz". In my case I found out that Internet Explorer 8 is not working. I tried using Google Chrome, same procedure and everything worked just fine. I did not try any other borwser but for me IE 8 did not work. Hope it works for you guts also.

  • SquidGuard: Target categories -> Expressions - are this RegExp or not ?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    N

    @LEPM:

    /.*\.(dlc|ccf|rsfd)

    Ok, than in this case the description "Expression" means "Regular Expressions" ?
    Then I think I know what I have to do ;-)

    Thanks!

  • Vnstat2 is this still being worked on?

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    johnpozJ

    Great - thanks!  So any package set for pbi will have to be manually installed currently.

    That might be great info to post for all users of 2.1 to read.

  • How to setup gui permissions to xml files?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    marcellocM

    OK. I've changed the permission info to 'allow all package config'

    Thanks Jimp.

  • Snort + Base

    Locked
    1
    0 Votes
    1 Posts
    926 Views
    No one has replied
  • Squid Install

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    N

    Yo don't need to create any directory. With the package install squid should be using /var/squid/cache (check squid server settings for cache)

  • What's the state of the FreeSwitch package?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    chpalmerC

    http://wiki.fusionpbx.com/index.php?title=PfSense_Install

    I did this but didn't finish before I had to go on with another project…

    I believe I had to modify this line-

    fetch http://code.google.com/p/fusionpbx/downloads/detail?name=fusionpbx-2.0.9.tar.gz

  • No LightSquid in package section

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    K

    Thanks kamel, Thanks jimp.
    It's clear now.
    NO LIGHTSQUID FOR NANOBSD
    :)

  • BandwidthD not calculating data correctly

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.