Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Problem with Squid Transparent Proxy

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    Try changing the WebGUI porocol/port to HTTPS/443.

  • After update and reinstall snort won't start anymore (solved)

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Moving Squid Logs

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Snort Blocking WAN IP address

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    3

    Hmm that's different than the alert I was getting.  I haven't had much time lately to look into this more.  For now I just have snort set to log alerts but not block.

    David

  • Squid not caching…

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    I

    it seems that are solved without any type of changes…..thanks for all.

  • Snort whitelist not working

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    C

    This is a known bug with the snort package on 2.0.. I believe the next package release will fix this problem.

  • Configuring varnish amd64 pfsense 2.0

    Locked
    2
    0 Votes
    2 Posts
    15k Views
    M

    read this => http://www.varnish-cache.org/docs/2.1/

  • Snort Problem

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    J

    I sent you a email @stuen93

  • LAN Device Monitor For pfSense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C

    you can try freebsd package/port monit but there is no support for it since its not a pfsense package. It can be setup to send email alerts…

  • Vhosts problem

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    K

    ok, I'm install PHPService
    make new host -ok

    /usr/local/etc/rc.d/vhosts-http.sh start

    (plugin.c.131) Cannot load plugin mod_accesslog more than once, please fix your config (we may not accept such configs in future releases

    ok!

    ee /var/etc/vhosts-http.conf
    lighttpd configuration file use a it as base for lighttpd 1.0.0 and above

    ############ Options you really have to take care of ####################

    FreeBSD!

    server.event-handler            = "freebsd-kqueue"
    server.network-backend          = "writev"  ## Fixes 7.x upload issues

    modules to load

    server.modules =  (
                                      "mod_accesslog",  # < 1 mod_accesslog
                                      "mod_access",
                                      "mod_accesslog",  # <2 mod_accesslog ??? ???
                      "mod_fastcgi", "mod_cgi","mod_rewrite"
                                    )

    lets get clean one "mod_accesslog", and all working

  • Snort banning myself every hour

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Pfsense 2.0 [embedded] + squid + usb stick

    Locked
    1
    0 Votes
    1 Posts
    10k Views
    No one has replied
  • Who maintains SquidGuard? Pls check dependency!

    Locked
    9
    0 Votes
    9 Posts
    3k Views
    jimpJ

    Then it must be some quirk because of the major version difference between squid 2 and 3. The squid 3 package is still considered alpha last I looked, I wouldn't trust it not to trash things, especially in combination with things like squidGuard and lightsquid.

  • Squid + OpenVPN Tunnel [SOLVED]

    Locked
    5
    0 Votes
    5 Posts
    8k Views
    jimpJ

    The rules to redirect into the proxy will happen automatically if you select the assigned OpenVPN interface in the squid configuration.

    The firewall rules on the OpenVPN interface should look like the firewall rules on the LAN interface, whatever will allow the clients to access what they need across the VPN.

  • Captive portal ip2name component for lightsquid

    Locked
    29
    0 Votes
    29 Posts
    20k Views
    _

    from dvserg this:```
    Thanks. I will place this in to package with next update

  • Squid + squid guard stops randomly

    Locked
    26
    0 Votes
    26 Posts
    19k Views
    O

    I have too problem with squid+squidguard randomly stop filtering and pass all traffic.
    (pfsense 1.2.3, squid 2.7.9_4, squidGuard 1.3_1 pkg v.1.9)

    I find in filter log this message:

    07.03.2011 06:07:45 going into emergency mode
    07.03.2011 06:07:45 overflow in vsprintf (sgLogError): Unknown error:

    in emergency mode squidguard according to documentation pass all traffic.

    I think if squidquard package is by mistake buid without this patches (or one of them):
    http://squidguard.org/Downloads/Patches/1.3/Readme.Patch-20091015
    http://squidguard.org/Downloads/Patches/1.3/Readme.Patch-20091019

    or is new similar bug.

    I apologize for my English  :)

  • Widget Snort bug

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    _

    Here clicking the link results in that:

    https://IP/https://IP/snort/snort_alerts.php

    By the way, the widged is always empty, not showing anything.

  • Freeswitch issues while I try to modify values.

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Haproxy -> 1:1 mapping domain to server

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    Y

    I'd love to know how you made it work.

  • FreeSWITCH issues - HELP!

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C

    Mark is usually most reachable in his IRC channel.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.