Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    D
    @BBcan177 Thank you for the kind reminder; I am so accustomed to ensuring Save Settings is checked that I didn't follow your instructions properly (thanks @tinfoilmatt for uploading and highlighting the screen shot). I've properly followed the instructions and the update did not report and db problems. Thank you again! drac
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    663 Posts
    C
    For what it’s worth, we may have had the same issue but for different reasons. I checked, and my system has the duplicate two files. Therefore, I asked Grok.ai about “/usr/local/etc/rc.d/pfsense_tailscaled enable /usr/local/etc/rc.d/tailscaled disable” versus the solution it had provided me yesterday. See the answer below. (Grok.ai used sources that included this Netgate forum, Lawrence Systems Forums – Networking & Firewalls, and https://forum.tailscale.com/.) The Two Service Files: Quick Breakdown Before diving into the relation, let’s clarify what those files are (based on standard pfSense Tailscale package behavior on 25.07.x/FreeBSD 15-CURRENT): • /usr/local/etc/rc.d/tailscaled: This is the generic FreeBSD/Tailscale rc.d script. It originates from the underlying tailscale package (the one you manually installed via' pkg add' for version 1.90.6). It’s a basic daemon starter/stopper that just runs /usr/local/bin/tailscaled without any pfSense-specific smarts (e.g., no auto-auth, no route advertising, no GUI integration). • /usr/local/etc/rc.d/pfsense_tailscaled: This is the pfSense-specific wrapper script. It’s installed by the official pfSense-pkg-Tailscale package. It wraps the generic tailscaled binary but adds pfSense magic: it reads your GUI config (auth key, advertised routes, exit node flags), writes them to /usr/local/etc/rc.conf.d/pfsense_tailscaled (e.g., pfsense_tailscaled_authkey="yourkey"), and handles the full tailscale up with flags on boot. It’s what makes the service “pfSense-aware.” In a stock official package install (without your manual binary upgrade), only pfsense_tailscaled exists and runs everything. When you force-installed the newer tailscale pkg on top, it added the generic tailscaled script as a side effect—but your fixed script (the one we pasted into /usr/local/etc/rc.d/tailscaled) overrode it to behave correctly.
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • 2.0 RC1 snort blocks ipsec

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 2.0RC1 Slow Squid proxy server

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    An update: using this as /boot/loader.conf autoboot_delay="1" #kern.ipc.nmbclusters="0" hint.apic.0.disabled=1 kern.hz=100 #for squid kern.ipc.nmbclusters="32768" kern.maxfiles="65536" kern.maxfilesperproc="32768" net.inet.ip.portrange.last="65535" seems to let squid download about 20% (or about 40-80MB) of a file at full link speed. After that, the speed just tumbles to 200-300kbits/s. Really frustrating. Not using any traffic shaping mechanisms.
  • How to rrevent restart of NUT package when PPPoE WAN IP changes ?

    Locked
    1
    0 Votes
    1 Posts
    885 Views
    No one has replied
  • How to blcok Video Streaming in pfsense->Squid+Squid Guard

    Locked
    1
    0 Votes
    1 Posts
    4k Views
    No one has replied
  • Internet access at certain times using squidguard

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G
    continuing problem :)
  • Edit squidguard configuration manualy + doubts

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    Z
    It's a shame :( I'll do then with the hard way. Thank you very much. P.S. : it would be great to have a "copy rule" button …... my mouse will die of so much deny click ..... ;)
  • Problem with starting bandwidthd

    Locked
    13
    0 Votes
    13 Posts
    15k Views
    jimpJ
    Looks like that field was missing some input validation. If you reinstall the package it should pick up this change and work better: https://rcs.pfsense.org/projects/pfsense-packages/repos/mainline/commits/ebba0c9ebf5b53eded7897e428b493787a13a6de
  • Proxy Server (PFSense 2.0 rc1)

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Barnyard2 on 1.2.3-RELEASE not working

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid transparent proxy and BOINC DC projects

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    A
    ncolunga, as your issue seems to be unrelated, I would suggest a new thread. You might get more attention.
  • Is there a package to identify traffic on IPSEC tunnel?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Pfsense 2 and mod_security

    Locked
    5
    0 Votes
    5 Posts
    11k Views
    D
    So I just figured it out.  On the NAT rule I had to enable NAT reflection (the default setting is off).
  • Transparent Squid on bridge

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    D
    @ncolunga: Thanks for the info. As workaround i'm using the bridge ip as default gw of the network and now squid is working as transparent proxy-cache. Regards. Thx good idea.
  • SRG - How to configure daily reports

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Are pfsense package server down?? "Unable to communicate to pfSense.com…

    Locked
    15
    0 Votes
    15 Posts
    10k Views
    H
    yes, borwser connect fsense.org and fsense.com in System: Package Manager >> 1.2.3-RELEASE packages  and  Installed packages is blank . I did restore and reinstall package and Loading package configuration … Starting package deletion for ... done. Removing dns-server components... Configuration... done. Saving updated package information... overwrite! The dns-server package is not installed. Installation aborted.Writing configuration... done. Starting service. All packages reinstalled. My dns is 8.8.8.8 [image: relased.jpg] [image: relased.jpg_thumb] [image: installed.jpg] [image: installed.jpg_thumb]
  • Block Adult Sites without Squid?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    M
    You can still use squid in this case. Just place the websites you have trouble with in the squid white list. I have to do this once in a while for people with watchgaurd proxy's too.
  • Snort not working?

    Locked
    12
    0 Votes
    12 Posts
    7k Views
    B
    Yeah, it turned out I had to turn on the preprocessors. BTW, it lists an option for collecting performance statistics, but I couldn't find where they're collected.  Any ideas?
  • Snort blacklist and blocked IPs "problem"

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Anonymizing squid (v2.7 and 3 - i386 and amd64)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid with openLDAP not working

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D
    for my windows server 2003R2 right setting is LDAP username DN attribute :cn LDAP search filter :cn=%s
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.