Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    A

    @wbmstr2000 : Thanks! I will investigate it, greetings

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Squid https - SSL download is slow

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T

    I'm seeing brutally slow load times on anything behind Squid. Installed the latest everything today. If I turn on Squid, then sites take up to 7 or 10 seconds to load all the elements. They load fast from cache after that, but the initial load, for any cold site, is completely useless.

  • Rate Package 2.0

    Locked
    10
    0 Votes
    10 Posts
    3k Views
    G

    @Cino:

    unless your using 2.1, my workaround wont work for you since the 2.0 file is my workaround.

    http://forum.pfsense.org/index.php/topic,42631.msg220911.html#msg220911

    have your tried a fresh install of 2.0 and imported your config? Make sure you remove any entries that would install rate package from your config.xml

    another option would be install 1.2.3 again, import your last 1.2.3 config… remove the rate package and upgrade to 2.0

    I'm running current stable so I believe it is 2.0.  If so I'll try your fix and see if that does the trick.

    Thanks!

  • Can I update the haproxy binary on my own?

    Locked
    12
    0 Votes
    12 Posts
    4k Views
    B

    Sounds good I think I'll try to deploy a FreeBSD VM tomorrow. I do actually need a stable version of HAProxy so I don't want to use the 1.5 Devel version. Thanks again you've been really helpful. I'll let you know how it works out.

  • How can I setup squid as a http proxy?

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    M

    if you want only browsing to be used without any restrictions, why not allow ssh login and then use socks proxy

  • Snort - how to create a netlist/whitelist?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    Just make sure you check off the options that you want added to the whitelist or netlist under "Add auto generated ips"

    From my experience:
    I use whitelist for friendly IPs and check off every auto generated ip option, then I use netlist to add any subnet that pfSense doesn't know about and check off every auto generated ip option(My cable modem's internal subnet range, vpn subnets that pfsense dont know about because of custom routes i have)

    hope this helps

  • Solution: FTP from LAN to WAN over SQUID.

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R

    This solution did not work in my case.

    I  use SquidGuard. Is there any thing else that I could  try?

    Regards.
    Rafael

  • Ignroe audio streaming and video in squid

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    N

    Hi,

    to cache custom file-extensions I am using this:

    refresh_pattern -i /.*.(iso|wmv|mov|rm|avi|mp4|mpeg|mpg|divx|xvid|swf|flv|x-flv) 10080 100% 10080 override-expire override-lastmod reload-into-ims ignore-reload ignore-no-cache ignore-private;

    This is working BUT the options are only working if it is http.

    Your types could be correct ( I don't know for sure) but I think they are only for allowing or denying access to this kind of files. But I do not think that you are now able to cache these files.

  • Siproxd errors in system logs

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    D

    Quoting from siproxd 0.8.1 README

    Known interoperability issues with SIP service providers:

    callcentric.com      (afaik callcentric fails with "500 network failure"
                            during REGISTER if more than one Via header is
                            present in a SIP packet. Having multiple Via headers
                            is completely in compliance with RFC3261. This might
                            be related to their "NAT problem avoidance magic".
                            There is nothing that can be done within siproxd
                            to avoid this issue as callcentric does not comply
                            with the SIP specification.
  • LightSquid Error

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    A

    I've had this problem on a few installs as well.

    I discovered that when I get the error, if I go wipe out all the reports in that folder it mentions, I can then Refresh Full and the problem goes away. Go to the shell:

    cd /var/lightsquid/report
    rm -rf *

    Refresh full from Status -> Proxy Report, and problem solved.

  • Unbound issues with DHCP, DNS forwarding

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    W

    @wagonza:

    This stopping might be related to a change which fixed another problem - Im still yet to find a fix for this.

    I have put a fix in for this, so just update your package.

  • Masq a dns with unbound?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    S

    wagonza your back!!!!
    YAY! Yes I did that :)

    Thanks!

  • Squid causing page not to load.

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    T

    i found the reason is i'm not open proxy port for all VLAN. It simple but I must take a half day to find.

  • 0 Votes
    1 Posts
    5k Views
    No one has replied
  • PfSense 2.0 and Squid in transparent mode don't working

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    B

    Hi

    I have the same problem :-(. its ok when configure the manual proxy in my the navegator

    My PFSense is 2.0 and the squid is

    Squid Cache: Version 2.7.STABLE9
    configure options:  '–bindir=/usr/local/sbin' '--sbindir=/usr/local/sbin' '--datadir=/usr/local/etc/squid' '--libexecdir=/usr/local/libexec/squid' '--localstatedir=/var/squid' '--sysconfdir=/usr/local/etc/squid' '--enable-removal-policies=lru heap' '--disable-linux-netfilter' '--disable-linux-tproxy' '--disable-epoll' '--enable-auth=basic digest negotiate ntlm' '--enable-basic-auth-helpers=DB NCSA PAM MSNT SMB LDAP SASL YP' '--enable-digest-auth-helpers=password ldap' '--enable-external-acl-helpers=ip_user session unix_group wbinfo_group ldap_group' '--enable-ntlm-auth-helpers=SMB' '--enable-negotiate-auth-helpers=squid_kerb_auth' '--with-pthreads' '--enable-storeio=ufs diskd null aufs coss' '--enable-delay-pools' '--enable-snmp' '--enable-ssl' '--with-openssl=/usr' '--enable-htcp' '--enable-forw-via-db' '--enable-cache-digests' '--enable-referer-log' '--enable-arp-acl' '--enable-pf-transparent' '--enable-follow-x-forwarded-for' '--with-large-files' '--enable-large-cache-files' '--enable-err-languages=Armenian Azerbaijani Bulgarian Catalan Czech Danish  Dutch English Estonian Finnish French German Greek  Hebrew Hungarian Italian Japanese Korean Lithuanian  Polish Portuguese Romanian Russian-1251 Russian-koi8-r  Serbian Simplify_Chinese Slovak Spanish Swedish  Traditional_Chinese Turkish Ukrainian-1251  Ukrainian-koi8-u Ukrainian-utf8' '--enable-default-err-language=English' '--prefix=/usr/local' '--mandir=/usr/local/man' '--infodir=/usr/local/info/' '--build=i386-portbld-freebsd8.1' 'build_alias=i386-portbld-freebsd8.1' 'CC=cc' 'CFLAGS=-O2 -pipe -I/usr/local/include -I/usr/local/include  -I/usr/include -DLDAP_DEPRECATED -fno-strict-aliasing' 'LDFLAGS= -L/usr/local/lib -L/usr/local/lib -rpath=/usr/lib:/usr/local/lib -L/usr/lib' 'CPPFLAGS=-I/usr/local/include' 'CPP=cpp'

  • Avahi on pfsense 2.0

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    I

    Anyone else using Apple gear and pfsense 2.0 ?????

  • Snort fails to start, error must enable 'extended_response_inspection'

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S

    Thank you for that, it's working now.

  • Issue with Queues in RRD Mailreport package

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    jimpJ

    Not sure, but it's possible it's a timing issue that only pops up at certain times, where the rrd file is being updated by the system when the report is being run and it can't find the file at the moment it's trying to attach it.

    Not sure what else it might be…

  • Squid Reverse Proxy advanced configuration

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Imspector have a problem

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Fix: squidguard and hostnames

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.