Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Have you tried this?

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    Z

    Informative!I really appreciated it.

    I dont have any idea 'bout the sessions or caching sessions.I think should go deep on this.
    At least I know its possible,enough for now.

    Thanks for the help.

  • Unbound error

    Locked
    16
    0 Votes
    16 Posts
    8k Views
    I

    You might also try looking for an error along the lines of BAD-TRAFFIC TMG Firewall Client long host entry exploit.
    That message is triggered by a bad traffic rule that looks for odd traffic on port 53, which happens to be DNS.
    If you have a lot of these in your alerts of blocked log, chances are that some or all DNS replies are being blocked by snort.

  • FreeRadius replication

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    marcellocM

    Varnish, postifix, haproxy.

    You do not need carp enabled to use it.

  • Squid and AD authentication

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort install errors - pulling my hair out!

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G

    emerging threats rules change all the time so if you enable a rule and later update the rule set there is always the possibility that you are attempting to load a rule that no longer exists in emerging threats. That will give you your error.

  • [Help] Unable to make imspector work on PFSense 2.0-Release

    Locked
    7
    0 Votes
    7 Posts
    2k Views
    D

    Dear all,
    I figure out that the Y!M version 10.0.27 didn't use the default port 5050.
    After i update Y!M to another version, it use port 5050 and seem to be OK with imspector.
    Thread close, thanks all

  • SQUID on DUAL WAN only use DEFAULT

    Locked
    8
    0 Votes
    8 Posts
    8k Views
    N

    Yes, you have to balance the web traffic from the localhost instead of the traffic for you lan clients.

  • Problems with apcupsd and/or nut

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    libwrap.so.6 is not part of a package, its part of FreeBSD.
    It appears the package you are attempting to use is newer then
    FreeBSD 7.0-Release, which 1.2.3 is based off of.

    ls -al /usr/lib/libwrap.* will show you what files you have. You probably
    have libwrap.so.5

    Using ln -s, you may be able to link libwrap.so.6 to libwrap.so.5, and it
    may work. But it may also not work / melt your box / kill your cat…

    Otherwise, try installing the package for a 7.x variant (not sure when
    libwrap.so.6 was introduced)

  • Jail on pfsense 2.0

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    marcellocM

    thanks for you reply.

    ezjail is working much better then pfjctrl.

    If you are doing patches, means that you know what you are doing.

    backup your vm's, uninstall pfjctrl and install ezjail.

    ezjail-admin will help you creating new virtual machines with freebsd 8.1.

    follow ezjail build steps on a freebsd 8.1-p4 and you will have same version on pfsense and jails.

    As pfsense2 has been release there is no problem on migrating pfjctrl to ezail.

    I'll try to start it soon.

  • Varnish for multiple CARP IP Interfaces distinct from WAN IP address

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    marcellocM

    Today the package listens on all interfaces at port you specified.

    To have multiple varnish, you can copy conf file and put a second daemon startup at gui advanced startup option.

    When using multiple varnish, you will need to name each one with -n arg.

    sample advanced startup options

    -n apache #set name on default daemon #startup second daemon /usr/local/sbin/varnishd \     -a :3129 \     -n squid \     -f /var/etc/squid.vcl \     -s malloc,2048MB \     -w 32,1024,300

    I will find a way to change setup To let you choose interface and auto name them.
    Wait for pkg v 0.9.

    Thanks for your reply.

  • SNORT issues in BRIDGE and VLAN'ed Environment

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort Problems Again !!!

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    T

    Snort is working great here.
    2.0 Release 64bit
    All pre-processors on
    Lots of rules enabled.

    Works after reboot.
    2gb on a vnware vm.

    I did have to follow other posts by uninstalling/reinstalling to get it running the first time when we were in the RC stage.  Also if I had known so rules were only 64 bit, I would have installed 32 bit pfsense.

  • OVPN Client Export installer error

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    L

    Apparently this is a recent issue.  There is a fix over here:
    http://forum.pfsense.org/index.php/topic,41180.0.html

    For those who dont feel like reading the thread (Please DO though– and COMMENT so that it gets fixed :D ), or for those from google:
    @gusdvg:

    Ok so I added an error handler to the openvpn-client-export.inc file such that warnings are not printed to the exe. Tried and it works again!

    If you want to try this, edit /usr/local/pkg/openvpn-client-export.inc and add these lines after the require_once lines at the beginning of the file:

    function ignoreError($errno, $errstr) {   //does nothing... } set_error_handler("ignoreError",E_WARNING);

    I guess the problem still remains if you need to add additional options, but I have little time at the moment and this patch will do for now.

  • Snort on pfSense packet flow

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R

    @marcelloc:

    Pfsense rules are set on source interface. The rule with destination To blacklist must be on lan.

    I set the rules up on the appropriate interfaces based on source and destination IP, but Snort sees (and then blocks) offenders that should be covered by these rules.

    The rule covering destination to blacklist is on the LAN interface.

    The rule covering source from blacklist is on the WAN interface.

    Still, Snort sees and blocks traffic covered by these rules.

    I still have these questions:

    Perhaps someone can clarify both the Snort alerting on hosts blocked by a firewall rule (Snort gets the packets first?), and Snort behavior in pfSense when a Blacklist and a Whitelist host are both involved in an alert.

  • Ipblocklist blocking 0 networks-syslog error

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • POP3 Filter

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    marcellocM

    No, only for internal smtp servers.

    I think pop3 protocol is getting quite old. I'd prefer IMAP.

    Pop3 wastes bandwidth even using p3scan or other tool, you need to download all messages to then see if you want it or not.

    You can build a virtual machine an try to install freebsd p3scan package. if it works as you expect install on your firewall.

  • Squid Guard Time Based ACL issues

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H

    So I updated the firewall this morning from 1.2.3 to 2.0 and now the proxy is working 100%… Not sure what changed or anything but very happy with the new release.

    Thank you guys. Keep up the awesome work on a fantastic product.

  • Facebook, Twitter Like button error in squidguard

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    marcellocM

    I saw the same thing at varnish report.

    Every time you apply settings, it will be included.

    Make report simple and it will never return.

  • Help with SNORT

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    Hi, I'm also new to snort…

    I'm just wondering if there is any easier way to search for a rule.
    I have a lot of them and when I want to review one upon an alert,
    I have to do find the matching one by hand.. The same with suppression....

  • Snort on 2.0-RELEASE (amd64)

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    B

    CPU usage on my Atom D525 X64 with Snort enabled is really low, like 1%

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.