Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Help with SquidGuard

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D

    Enter from console

    touch /usr/local/etc/squidGuard/blacklist.files

  • Snort exception for VPN traffic?

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    M

    Thanks for your input, Rob.

    Whitelisting is not really relevant when the remote user is logging in from a range of locations. Actually, it's not really meaningful even when they are coming in from a single location in many cases - our chief developer uses an internet connection with dynamic IP from one of the biggest ISPs in this country - I've had to whitelist their entire IP range and, in the process, told SNORT to ignore probably thirty percent or more of the UK internet users!

    I also spent a lot of time turning off rules - but there's a lot of them that trigger from time to time. I described them as "false positives" which may not be strictly true - I guess the point is that a lot of remote users coming into the network over VPNs are doing so from public ISPs and quite a lot of the attacks I'm seeing are probably genuine. We are a commercial organisation hosting public facing web sites behind this firewall and it's harmful to business to block incoming traffic unnecessarily.

    How does pfSense block traffic from IP addresses identified by SNORT? Does it generate hidden firewall rules to block the offending IP addresses? If that is the case, could we set it up so that the generated block rules were inserted at an identifiable point in the rule list? That way, I could simply insert exception rules above that point which would always override the internally generated blocks and, thus, permit specific protocols or destinations irrespective of the SNORT decisions.

    This would actually be better than putting in some sort of VPN exception - it would also allow me, for example, to add further exceptions to allow access to my web sites even while stopping port scans and attempts to bust into the RDP ports on my servers!

    Martin

  • Squid in Transparent and Port mode. ssh into lan, proxy local connections

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Transparent Proxy partially functional

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    R

    Completed the upgrade to 1.2.3 and reinstalled the packages. LightSquid appears to be showing all of the traffic again. Thanks for the help.

  • Encryped LDAP communication with Squid?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Siproxd and Telia

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Snort - Unblock blacklisted hosts from the command line

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    jimpJ

    I'm not sure of the details, it's changed a few times over the years, not sure what the package author has it doing these days.

  • Lightsquid report

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • MagicJack on pfSense PC?

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    N

    @Cry:

    My understanding is that MagicJack is an entire service, you can't just go switching the software you run.

    I'd suggest that going down the FreeSwitch route should only be done after you read up on FreeSwitch.

    MJ is actually uses the standard SIP protocol.  As long as you can get at your credentials, you can use any SIP application in place of the MJ dongle.  Some have used an ATA instead.

    http://www.magicjacksupport.com/any-new-way-to-get-sip-info-t8145.html

  • I need to update php4 to php5

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ

    That will not work, you will break many things.

    You should not use your firewall for things like that, but if you must, 2.0 uses PHP5.

    And if you're going to be altering the firewall and running insecure services on it, you may as well be using the 2.0 RC version because it will in no way be considered stable at that point.

  • Suppresing Priority 3 alert in snort 2.8.6.1

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Vnstat time not correct

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Correctly monitor bandwidth?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    A

    On my system Bandwidthd shows more traffic than the rrd graph and I have a filter to keep it from counting lan traffic. 
    "ip and not ((src net 192.168.0.0/16) and (dst net 192.168.0.0/16))"  I think this will cover all the 192.168 subnets as I have a static route to another lan on the opt1 interface with servers on both lans.

  • Snort acting very weird!

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Does anyone use the BlockHosts script from ACZoom.com?

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    T

    @ToxIcon:

    Tommyboy180 did you ever create a package for blockhosts

    My work is saved on my desktop right now. I am currently moving right now. When I get settled in then I can resume development.

  • Pfsense 1.2.3-Release + Squid + OPEN-LDAP

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S

    Hello,

    This is really late, but I just began using pfSense and ran into this same problem. In my searching for the answer I have found your post with no answer I too was struggling with exactly what you are/were experiencing.

    Here is a solution I figured out after much messing around

    for the filter search string type in "uid=%s" the rest of what you have should be OK

  • Snort Suppression can't get to work in release 2.0 RC1

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    T

    Sorry I missed the option to enable it on "If Setting" under the Snort Interface using Suppresion and filtering option. It is working now.

    Thanks.

  • Snort

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    N

    @stuen93:

    Do you have any IP ranges white listed?

    You also set how long the IP stays blocked for so if the alert was generated longer ago then the block time the IP will be removed from the block list.

    No i do not have anything white listed .

  • HAVP without Squid. Does not block anything

    Locked
    11
    0 Votes
    11 Posts
    8k Views
    M

    weird but rebooting the system after seems to make it work - maybe i just needed to 'rehash' from ssh…

  • Snort Will now work in Bridge mode

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.