Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    D
    @BBcan177 Thank you for the kind reminder; I am so accustomed to ensuring Save Settings is checked that I didn't follow your instructions properly (thanks @tinfoilmatt for uploading and highlighting the screen shot). I've properly followed the instructions and the update did not report and db problems. Thank you again! drac
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    GPz1100G
    @agitelzon I have no issue connecting to LE servers from pf shell. The issue is cloudflare security setting is configured as a whitelist for api zone record changes. The whitelist includes my ipv4 address only, as a /32. As I mentioned, I could add the ipv6 prefix as a /64. Given that pf is configured to prefer ipv4, I thought that would carry over to acme as well.
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    659 Posts
    C
    After saving the script: chmod +x /usr/local/etc/rc.d/tailscaled sysrc tailscaled_enable=YES service tailscaled restart
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    @tinfoilmatt Thanks! I have done that and it worked when forcing just her TV out the Centurylink.. My problem is my local box here. Im missing something because I can not get it to pass traffic from the WAN to the Wireguard tunnel. Ive got some time today so will chip away on my lab setup to see if I can finally accomplish it here first.
  • Squid AD LDAP authentication

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    Can you open a feature request ticket under pfSense packages to have this added? It shouldn't be hard to do, but may have to wait until some developer time opens up (or someone submits a patch)
  • Snort preprocessor blocking but nothing in alerts

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    What pfsense version are you running? If it's v.2 Beta, check Snort > Alerts tab if the "Default is On" option is ticked.
  • Snort no tabs Rule, Categorie and Serveur

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid in transparent mode + PPTP Issue

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid log rotation. Basic infos

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C
    Thanks for your help guys
  • IMSpector V2

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    Anyone ?
  • Igmpproxy noworking

    Locked
    67
    0 Votes
    67 Posts
    58k Views
    E
    The first packet indeed looks weird. Can you send me off-list: packet captures from downstream and upstream for the same time frame. what you see in System->Logs for the same time frame. Regarding 2.0 - several people reported that igmpproxy worked for 2.0 though I've never tested it.
  • How i install nod32,avg,avira on pfsense?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    Cry HavokC
    To what end?  What do you want to do with them? Oh, and you'd install them by following the instructions that came with them.
  • Proxy filter

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ntop 4

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    I don't know, I'm not sure I've heard of anyone trying. If it works on FreeBSD, the chances are good that it would work on pfSense, so long as you don't need GUI integration.
  • Bock URL ????

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    cyber7C
    Hi vinhk20119 the short answer, YES… The long answer: Install SQUID/SQUIDGUARD and do it though this. Kind regards Aubrey Kloppers
  • Squid - Dynamics CRM client blocked

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    R
    sorry, this actually started again - if anyone has any ideas on what it could be please post up Thanks
  • Debian proxy + pfsense Squid guard is it possible ?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    D
    1. Install & configure pfSense. 2. Install configure & Squid, setup you debian proxy as parent for Squid. 3. Install configure & squidGuard All examples exists in the forum and FAQ.
  • Bandwidthd Day changing

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid - How to stop loggin a single ip? - SOLVED!

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • How to make a crontab for backup aliases, rules everyday?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    B
    This pretty much outlines your options: http://doc.pfsense.org/index.php/Remote_Config_Backup
  • Squid - reverse proxy?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    L
    well, after a while i give up as time was precious. i then spotted the apache server with mod security package (reverse proxy etc) and decided to have a go at this. out went squid and in came apache (this is on an alix 2d3 with cf) i had this horrible feeling that it was too much for the poor old alix and this was confirmed by the amount of packages etc that it installed with it. the alix started to creak and i couldn't access the web config. it became so unresponsive, i couldn't hardly do anything with it. so, from the shell….. lots of pkg_delete -f -a with lots of /etc/rc.conf_mount_rw after about 7 runs, i finally clear everything out so no packages. i even delete the remaining traces of them. i'm on the net but no web configurator. a check of the logs reveals missing dependancies. no prob's, i have another pfsense and i copy the missing shared files over. but still, no web configurator. it's starting to beat me now. i have a config backup etc so i keep ploding away. everything is working fine but the web configurator. ummm, check the config and i can't see any port under webgui so i add a <port>443 in front of</port> thinking that's why i couldn't get onto it. crash.... now i'm really stuffed, no web either now. i'm off the net with a few choice words. i now remember, i tried an upgrade to v2 and had that on the other slice (silly me, why didn't i duplicate it back to 1.2.3 before all of this? lesson learnt! won't happen again!) maybe time to upgrade to v2 as i have this other slice....... no, i get the usual probs with it not remembering vlans etc. no prob's, i will configure it with minimal lan and from there, install backup config. no, it's beat me again with "a scalar value error" and just won't let any lan be configured under v2. shock horror..... i don't want to remove the cf card and reinstall etc. i'm not on the internet at this time and i haven't got a copy of pfsense with me. so, now i'm back into the config and removing the <port>443 and pfsense is back up but still no web config. and then it hit me....... try an upgrade with v1.2.3 on the v2 slice that doesn't work. so i upgrade this slice to 1.2.3 and voila...... pfsense is backup and running with web config. phew! moral of the story? 1. have a working opposite slice & config backup before adding any packages 2. don't go against your better judgement (me by loading apache etc on an alix) unless you have time to spare 3. don't panic. sit back and think it out and you can get there in the end. you learn a bit too! now.... how can i waste my next sunday?</port>
  • Snort update issue

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    B
    Is nobody else seeing this, I notice another post relating to this but for pfSense V1.2.3, the common factor is the Snort package version. I had to manually install the rules but this isn't my first choice of ways to pass the time. I'd appreciate it if anyone running V1.35 could try to update and post the result (PS although my version says 1.35 on the package page the package reports v1.34 - and yes I have re-installed three times).
  • Snort, Help Blocking Anonymous Proxy Usage

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    L
    have you also tried using opendns as your forwarders? then just set a firewall rule that only opendns can be used. i find opendns quite effective and it's another layer for them to try and overcome.
  • Squid/squidguard kills connexion client

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    C
    @brcisna: clutch68, I don't like having this teachers workstation "outside" of the firewall for sure as we have so may possibilities of viruses in a school setting. Kids are just 'trying' to kill every system on the lan, it goes without saying. At least the connexion client is usable with this cludge,,,:). Hi Barry, glad to be of help. I could certainly be wrong here, but simply bypassing the proxy should not further expose the client PC. Although a local firewall is prudent, your staff client should also still be "behind" the firewall protection of the pfsense box, just as it was before the proxy bypass. In other words, a squid bypass doesn't necessarily = firewall bypass. The client is simply not routing outbound web traffic through squid. This post is begging for correction if anyone has further thoughts on this.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.