Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    D
    @BBcan177 Thank you for the kind reminder; I am so accustomed to ensuring Save Settings is checked that I didn't follow your instructions properly (thanks @tinfoilmatt for uploading and highlighting the screen shot). I've properly followed the instructions and the update did not report and db problems. Thank you again! drac
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    661 Posts
    L
    For me I might have fixed (without kinda complicated solution which I could find). Since it worked when I did an restart in the UI, and that the tailscale service in pfsense was actually running, I came to the conclusion, that maybe some other tailscale service was started at boot, so I tried below. I tried to reboot it after, and tailscale came up just fine. I haven't tested it further though. LIke power it down completely, or do multiple reboots. /usr/local/etc/rc.d/pfsense_tailscaled enable /usr/local/etc/rc.d/tailscaled disable
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • Widescreen pkg bug

    Locked
    1
    0 Votes
    1 Posts
    960 Views
    No one has replied
  • HAVP and AVG Scanning

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    @mrhotflamin: i looked and their wasn't even a reference to avg. can i just add the option in somehow or is it simply not available? You can add the options you want, having studied the config HAVP
  • VHOST PACKAGE CONFIG

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Havp setup

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    Got it working. Thanks!
  • Tracking Cookies

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    O
    good morning everyone, solution for all 66 visitors till now ;) with proxyfilter is the best solution!!!! Point -> Tracker ;) therefore i havent to block by myself ;) that would a life task^^ CLOSED!!!!
  • Snort rules driving me crazy

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    T
    Yes we are using the free codes. But I found out in the past that it did not work for more then 1 firewall because of the limitations. So last week I have created codes for all firewalls, that cannot be the problem anymore. But thanks for the help, I appreciate it!
  • CountryBlock Questions For 2.0-RC1

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    T
    One of the coolest things that countryblock is that it's all written in php. There isn't any thing that changes from pfsense 1.2.3 to pfsense 2.0. Since php is php it will always work. Feel free to contact me if you have any specific questions but I think I can put you worries to rest.
  • Possibility of sorting USERS in freeRADIUS package like in DHCP leases ?

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    N
    I hoped you wouldn't say that ;) Perhaps someone will find some time in future and can implement this. Till there I will use the browsers search function.
  • Ntop: mako

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    C
    Thank you, it works setenv PACKAGESITE ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-8-stable/Latest/ pkg_add -r py27-mako It is required by RRD alarm, at http://gateway.localdomain:3000/python/rrdalarm/config.py
  • SquidGuard: don't log safesearch redirect

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    jimpJ
    It doesn't look like there is a GUI option to do that. To do it manually it looks like you could hack it up by editing /usr/local/pkg/squidguard.inc and changing line 1230 where the log statement is hardcoded:     $res[F_LOG]        = 'on';
  • Transparent squid for client PPP0e

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    N
    http://forum.pfsense.org/index.php/topic,12933.0.html close topic
  • Avoid the reload of a specific package after PPPoE WAN address is changed

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • LCDPROC - LIS Driver in Pfsense 1.2.3 or 2.0

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    You will need to find or compile LIS.so driver for your build(i386 ro AMD64). After that, you will have to edit some of the files to use the driver. Please see this thread as a guide line for editing the files: http://forum.pfsense.org/index.php/topic,23919.msg123663.html#msg123663
  • Problem IP-Blocklist

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    G
    rm /usr/local/pkg/pf/IP-Blocklist.sh That seemed to do the trick. Brutal, but not as bad as having all that junk filling up my logs.
  • [SOLVED] VNSTAT Not updating

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    X
    That fixed it. Should have asked sooner, I was trying various shots in the dark, going nowhere. Thanks again Perry.
  • Need to Block GMAIL

    Locked
    6
    0 Votes
    6 Posts
    6k Views
    jimpJ
    If you are using squid in transparent mode, yes. If you have the proxy hardcoded on someone's PC settings, no.
  • Squid Windows Update regular expression

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    C
    Finally, I modified the regexp to: refresh_pattern ([^.]+.)?(download|(windows)?update).(microsoft.)?com/.*.(cab|exe|msi|msp|psf) 4320 100% 43200 reload-into-ims;range_offset_limit -1;
  • 0 Votes
    5 Posts
    5k Views
    N
    Great! Thanks. I will give it a try tomorrow at work.
  • Arpwatch alfa

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    nesenseN
    clearing the log causes an error ;/
  • Ntop: automatically reset statistics every month

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    jimpJ
    I suppose you could just rm -rf /var/db/ntop and then restart ntop, but that seems a bit harsh. There may be an ntop tunable setting under Admin > Configure > Preferences inside of ntop.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.