Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Squidguard + embedded, a solution?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G

    Same problem.  I reported in this thread…
    http://forum.pfsense.org/index.php/topic,31717.0.html
    I've tried various squid and squid configs, including changes to permission but can't seem to find a fix.  I've asked the issue be forwarded to the lead developer for this package for comment and resolution.

  • Proxy Server with mod_security

    Locked
    4
    0 Votes
    4 Posts
    6k Views
    S

    Little help over here…i run

    pkg_info

    i reviewed the installed packages and

    pkg_delete mod_security

    but still i can't connect to webconfigurator…

  • Problem with SquidGuard Log Gui

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    D

    @painmaker:

    I have this problem when I use Firefox in IE 8 work ok.

    Chrome work correctly too.

  • Ntop with Pfsense 1.2.3

    Locked
    24
    0 Votes
    24 Posts
    16k Views
    jimpJ

    That post is from almost a year ago, and it was committed at the time I posted the message. If you have problems, please start a new thread instead of hijacking a thread that has been dead for many months.

  • DAP bypass pfsense squid bandwidth throttling

    Locked
    5
    0 Votes
    5 Posts
    14k Views
    S

    when i checked again thru squid only then the states are like,
    tcp    10.1.1.17:8080 <- 10.1.18.3:4122    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4124    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4126    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4127    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4133    FIN_WAIT_2:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4135    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4137    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4138    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4139    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4140    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4142    ESTABLISHED:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4148    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4153    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4156    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4157    ESTABLISHED:ESTABLISHED   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4158    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4159    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4161    FIN_WAIT_2:FIN_WAIT_2   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4162    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4163    TIME_WAIT:TIME_WAIT   
    tcp    10.1.1.17:8080 <- 10.1.18.3:4164    TIME_WAIT:TIME_WAIT

    i think dap creating multiple connections for a single download in the downloading window of DAP it showing 4 connections, is thr any method to limit connections?

  • Problem lightsquid

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    M

    @dvserg:

    Check squid config file - really log enabled ?

    Yes :/

  • Squid Blocking Websites In Whitelist

    Locked
    6
    0 Votes
    6 Posts
    8k Views
    H

    @Cry:

    Are all your systems on the 10.5.1.x/24 network?  Do any of them route in from other networks?

    Did you work through the documentation?

    Question One: Yes, Squid is only running on the site that has the 10.5.1.x/24 network. The pfSense box at my satellite office which is on another subnet is not running Squid.

    Question Two: Yes, that's how I was able to get Squid up and running initially. It's definitely working but the whitelist.acl is being ignored. I literally have to shut Squid down to access these sites.

  • Squid: Bypass proxy for Private Address Space

    Locked
    6
    0 Votes
    6 Posts
    9k Views
    jimpJ

    If you add an override to the DNS forwarder for that hostname that points to the internal IP it should work.

  • SquidGuard: how to "Proxy filter SquidGuard: Destinations: Edit"?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    Thanks bro…love it :)

  • How can I install SARG?

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    K

    try: pkg_add -r {ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-7-stable/www/sarg-2.2.7.1_2.tbz}

  • The Cron package is missing required dependencies and must be reinstalled

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    N

    i will try.
    thanks

  • Spamd issues

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    I

    Hi
    My system is 2.0-BETA4 (i386) built on Tue Dec 21 12:44:54 EST 2010 and use spamd.
    Works fine.

  • Cannot install FreeRadius…. Alix with 2GB

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    I don't think anyone got around to finishing FreeRADIUS up to work on ALIX. It needs a fair amount of disk space in /var/ (a ram disk) to write its database and I think as it is it would be lost at reboot even if it did work.

  • Squid default settings vanished

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    Cry HavokC

    I've never seen the behaviour you describe, and I don't remember coming across it on another thread. You may have stumbled across a package bug with squidGuard, or it may be related to your particular install and setup.

    Are you able to do a fresh install of pfSense and re-install your packages and see if it happens again.  If you can document it step by step as a repeatable process it'll give folks something meaningful to look into.

  • Squid3 (ALPHA 3.1.9 platform: 2.0)

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    No, but Squid 2.7.9 does on 2.0 if you have proper NAT and floating rules setup.

  • How to restart Squid and do a full lightsquid refresh daily

    Locked
    7
    0 Votes
    7 Posts
    15k Views
    L

    You might look at this discussion…

    http://forum.pfsense.org/index.php/topic,26604.0.html

    logs of gory details on squid vs light squid rotation issues.

    Bottom line... currently you can do log rotation in squid or lightsquid but not both. If using light squid to do the rotation then make sure that log rotation is disabled in squid.

    --luis

  • PFSense package server is down?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    T

    yup, it's up again…

  • Please help with Freeswitch Auto Attendant

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    F

    And the last screeshot

    freeswitch3.jpg
    freeswitch3.jpg_thumb

  • PFSence and Zabbix Agent via IPSec

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    K

    Resolved.  I had a static routes in place so that packets would route between the various firewalls (as per 13.4.4 in the guide book)  Once I removed those (coupled with a better understanding of how the agent was communicating with the server and things are now working)

  • Ad block with PixelServ

    Locked
    10
    0 Votes
    10 Posts
    7k Views
    F

    @DigitalJer:

    heh, what I've done is configure SquidGaurd to redirect to ext URL, and that URL is:

    http://upload.wikimedia.org/wikipedia/commons/c/c0/Blank.gif

    Not the most elegant…but kinda the same thing!

    Nice! I've never work with squidguard before, do you use some sort of block list with squidguard?

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.