Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    reza3swR

    @Gertjan
    Hello,
    Thank you.
    I had exactly the same issue, and your solution helped me fix it.

    Ask ChatGPT

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    J

    @dennypage Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working.

    So the issue, for me at least, seems resolved, but of course this leaves open the question of why a second reboot was needed. Here's some more information in case it helps.

    There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. Here's the output relating to the UPS, which was identical at all 3 points:

    ugen0.5: <PR1500LCDRT2U UPS Cyber Power System, Inc.> at usbus0, cfg=0 md=HOST spd=FULL (12Mbps) pwr=ON (2mA)

    Question: What would tell me whether or not a driver was loaded?

    Prior to rebooting, I also tried running usbhid-ups -DDDDDD -a CyberPower-1500, and the only apparently meaningful message was (complete output later):

    ... 0.001460 [D2] Initializing an USB-connected UPS with library libusb-1.0.0 (API: 0x1000102) (NUT subdriver name='USB communication driver (libusb 1.0)' ver='0.47') 0.001760 [D2] libusb1: No appropriate HID device found 0.001774 libusb1: Could not open any HID devices: no USB buses found 0.001780 No matching HID UPS found ...

    Here's the full output:

    [2.8.0-RELEASE][admin@janus.jhmg.pvt]/root: /usr/local/libexec/nut/usbhid-ups -DDDDDD -a CyberPower-1500 0.000001 [D5] send_to_all: SETINFO driver.state "init.starting" Network UPS Tools - Generic HID driver 0.53 (2.8.2) USB communication driver (libusb 1.0) 0.47 0.000284 [D1] upsdrv_makevartable... 0.000449 [D5] send_to_all: SETINFO driver.version.usb "libusb-1.0.0 (API: 0x1000102)" 0.000465 [D1] Using USB implementation: libusb-1.0.0 (API: 0x1000102) 0.000604 [D5] do_upsconf_args: confupsname=CyberPower-1500, var=driver, val=usbhid-ups 0.000616 [D5] do_upsconf_args: call main_arg() 0.000624 [D3] main_arg: var='driver' val='usbhid-ups' 0.000631 [D5] do_upsconf_args: not a main_arg() 0.000637 [D5] do_upsconf_args: this is a 'driver' setting, may we proceed? 0.000645 [D6] testval_reloadable: var=driver, oldval=usbhid-ups, newval=usbhid-ups, reloadable=0, reload_flag=0 0.000654 [D6] testval_reloadable: verdict for (re)loading var=driver value: -1 0.000659 [D5] do_upsconf_args: 'driver' setting already applied with this value 0.000667 [D5] do_upsconf_args: confupsname=CyberPower-1500, var=port, val=auto 0.000673 [D5] do_upsconf_args: call main_arg() 0.000678 [D3] main_arg: var='port' val='auto' 0.000685 [D6] testinfo_reloadable: var=port, infoname=driver.parameter.port, newval=auto, reloadable=0, reload_flag=0 0.000692 [D6] testinfo_reloadable: verdict for (re)loading var=port value: 1 0.000703 [D5] send_to_all: SETINFO driver.parameter.port "auto" 0.000728 [D1] Network UPS Tools version 2.8.2 (release/snapshot of 2.8.2) built with FreeBSD clang version 19.1.5 (https://github.com/llvm/llvm-project.git llvmorg-19.1.5-0-gab4b5a2db582); Target: x86_64-unknown-freebsd15.0; Thread model: posix and configured with flags: --sysconfdir=/usr/local/etc/nut --program-transform-name= --localstatedir=/var/db/nut --datadir=/usr/local/etc/nut --with-devd-dir=/usr/local/etc/devd --with-drvpath=/usr/local/libexec/nut --with-statepath=/var/db/nut --with-altpidpath=/var/db/nut --with-pidpath=/var/db/nut --with-pkgconfig-dir=/usr/local/libdata/pkgconfig --with-user=nut --with-group=nut --with-python=/usr/local/bin/python3.11 --without-python2 --with-python3=/usr/local/bin/python3.11 --without-nut_monitor --with-ltdl --with-nut-scanner --with-avahi --with-cgi --with-cgipath=/usr/local/www/cgi-bin/nut --with-htmlpath=/usr/local/www/nut --with-gd-includes=-I/usr/local/include --with-gd-libs='-L/usr/local/lib -lgd' --without-dev --with-freeipmi --without-ipmi --with-doc=no --with-modbus --with-neon --without-nss --with-openssl --with-powerman --with-serial --with-snmp --with-usb=auto --prefix=/usr/local --mandir=/usr/local/share/man --disable-silent-rules --infodir=/usr/local/share/info/ --build=amd64-portbld-freebsd15.0 0.000748 [D1] debug level is '6' 0.000759 [D5] send_to_all: SETINFO driver.debug "6" 0.000768 [D5] send_to_all: SETFLAGS driver.debug RW NUMBER 0.001368 [D1] Succeeded to become_user(nut): now UID=316 GID=316 0.001431 [D5] send_to_all: SETINFO device.type "ups" 0.001444 [D5] send_to_all: SETINFO driver.state "init.device" 0.001451 [D1] upsdrv_initups (non-SHUT)... 0.001460 [D2] Initializing an USB-connected UPS with library libusb-1.0.0 (API: 0x1000102) (NUT subdriver name='USB communication driver (libusb 1.0)' ver='0.47') 0.001760 [D2] libusb1: No appropriate HID device found 0.001774 libusb1: Could not open any HID devices: no USB buses found 0.001780 No matching HID UPS found 0.001809 [D5] send_to_all: SETINFO driver.state "cleanup.exit" 0.001818 upsnotify: failed to notify about state 4: no notification tech defined, will not spam more about it

    You might consider adding this resolution to the release notes for 2.8.

    Thanks for the assistance!

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    690 Topics
    4k Posts
    J

    I've read through some other posts about this, but they either didn't say whether the proposed solution worked or they were very convoluted and difficult to understand. Here is our scenario: We have 6 locations--Las Cruces (LC), Sunland Park (SP), El Paso (EP), Abilene (ABI), Fort Worth (FW), and Plano (PL). LC and ABI have software that is accessed by the other 4 locations via VPN. There are WireGuard VPNs set up between LC and those 4 locations (SP, EP, FW, PL), and ABI and those 4 locations (SP, EP, FW, PL). There is also a WireGuard VPN connection between LC and ABI. LC and ABI have 2 internet connections. SP, EP, FW, and PL each have one internet connection.

    If the primary internet connection goes down at either LC or ABI and failover occurs to the secondary internet connection, is there a way to set up the WireGuard VPN connections so that they also failover without purchasing some 3rd party application?

    Thanks.

  • Thresholds tab in snort - suppress not stopping alerts

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    G

    Wow I feel like an idiot that I did not see that before. I guess I believed the drop down menus only had Default like my Home Net and external net has and ignored the rest while completely ignoring the fine text which is quite small on my laptop…. duuurr

  • Sort test program

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G

    You can enable the scan category and use "NMAP -sS window 4096" from a remote computer.

  • Openbgpd status page

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    Yeah that status page needs a lot of help, takes way too long in such circumstances (mostly people use the command line bgpctl instead).

    It's on our radar to get fixed up sometime in the future. Patches welcome if you have ideas on how to make it more usable.

  • Little problem on Menu [snort]

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    G

    There is also a url error when traversing to the traffic shaper  from snort.

    With the following resulting URL
    http://192.168.153.1:8080/snort/firewall_shaper.php

  • OpenBGPD restart script error

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    _

    ok  ;)

    I agree with you, this script may not be used to start bgpd :) As you wrote, "Though I never investigated this issue and can't say anything" more ;)

    I found that error while deep testing a BGP configuration for OpenVPN/Link failover with carp, where openvpn may be started before bpgd, so that the tap device did not exist before, and for some obscure reasons (yet) bgpd was not started at boot time.
    So, I tested a script that check the existent of bgpd socket to restart it.
    It is not a standard configuration (unsupported).

  • Internet -havp-squid-client

    Locked
    12
    0 Votes
    12 Posts
    9k Views
    Q

    @ColdFusion:

    I have squid/havp/squidguard and my config works this way.
    Try putting Havp in Transparent and Squid transparent unchecked.

    Havp…
    Transparent checked
    upstream proxy...lan IP:squid port.....example 192.168.1.1:3128
    Havp proxy port 3121
    enable x-forward...checked

    In squid:
    x forward unchecked
    disable Via unchecked
    transparent unchecked

    I have my configuration set up exactly like this, but it doesn't work…the IP address in the logs (and in the denied page), is the router's LAN address, and NOT the client PC.  What am I doing wrong?  Is there a bug?  Can someone shed some light on this?  Thanks!

  • Squid+lusca+CDN+delay pools (pfs 1.2.3) ?

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • [patched] Apache + mod_security + proxy

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    M

    Had to manual configure ProxyPass and ProxyPassReverse inside httpd.conf to get it working.

    Site Proxy | Site Name *Enter a short descriptive name for the site. (e.g. intranet)
    its misleading since what you enter there will go into httpd.conf, be aware its not just a description.
    It will end up in the ProxyPassReverse!

    Will see for any other issues, maybe fix them if time permit … cheers.

  • Very urgent: Problem of updating of the SNORT rules

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T

    update to the latest snort as you mentioned are are using snort-old

    There was a lot of discussion on the old snort.  Basically you updated to the latest rules based on the latest snort using an old snort version.

    See this as well as other threads.
    http://forum.pfsense.org/index.php/topic,23185.0.html

  • LightSquid only updates manually

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    J

    Here is the result of running pkg_info.

    $ pkg_info arc-5.21o_1        Create & extract files from DOS .ARC files arj-3.10.22_1      Open-source ARJ bandwidthd-2.0.1_1  Tracks bandwidth usage by IP address clamav-0.95.1      Command line virus scanner written entirely in C db41-4.1.25_4      The Berkeley DB package, revision 4.1 gd-2.0.35,1        A graphics library for fast creation of images gdbm-1.8.3_3        The GNU database manager gettext-0.17_1      GNU gettext package grub-0.97_3        GRand Unified Bootloader havp-0.90          HTTP Antivirus Proxy jpeg-6b_4          IJG's jpeg compression utilities lha-1.14i_6        Archive files using LZSS and Huffman compression (.lzh file libdnet-1.11_2      A simple interface to low level networking routines libiconv-1.11_1    A character set conversion library lightsquid-1.7.1_1  A light and fast web based squid proxy traffic analyser lua-5.1.3_3        Small, compilable scripting language providing easy access mbmon-205_4        A tty motherboard monitor for LM78/79, W8378x, AS99127F, VT mysql-client-5.0.77 Multithreaded SQL database (client) mysql-client-5.1.44_1 Multithreaded SQL database (client) nano-2.0.9          Nano's ANOther editor, an enhanced free Pico clone openldap-client-2.4.10 Open source LDAP client implementation p5-GD-2.39          A perl5 interface to Gd Graphics Library version2 packages            BSD Installer mega-package pcre-7.8            Perl Compatible Regular Expressions library pcre-8.00          Perl Compatible Regular Expressions library perl-5.10.1        Practical Extraction and Report Language perl-5.8.8_1        Practical Extraction and Report Language pkg-config-0.23_1  A utility to retrieve information about installed libraries sqlite3-3.6.10      An SQL database engine in a C library w/ Tcl wrapper squid-2.7.7        HTTP Caching Proxy squidGuard-1.3_1    A fast redirector for squid squid_radius_auth-1.10 RADIUS authenticator for squid proxy 2.5 and later unzoo-4.4_2        A zoo archive extractor vnstat-1.6_3        A console-based network traffic monitor

    That's interesting I thought I had removed havp through the web interface.

  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Anyone interested in putting TCAR in Pfsense?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    It looks like that was written specifically for IPcop and uses its terminology and probably has specific requirements for that, and likely Linux-related conventions.

    pfSense uses FreeBSD, so it's unlikely that such a program would work properly without major work, if it can be done at all.

  • Squid Setup

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    L

    i am using 2.7.3 stable on debian and 2.7.8 on Pfsense.
    My ISP already allowed my IP address to bypass their proxy server. But i still want to redirect to my own proxy server.

    Thanks

  • Cannot open one Url only

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    jimpJ

    If the site is hosted locally behind that same pfSense box, try checking the box in squid to bypass the proxy for RFC1918 networks.

  • Freeradius startup problem

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ

    It's possible that this is falling victim to the same problem that several other packages have. On boot, they try to start up multiple times. First, they sync their settings and write out an rc script, and then start themselves. Then later in the boot process, the rc scripts get executed, starting them again. If you have a dynamic WAN (DHCP, PPPoE) sometimes it can happen one more time as the new IP will trigger another package sync.

    The package maintainer may need to add some more logic to handle this kind of situation.

  • Snort Help

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    G

    I used my own suggestion and googled this page for you since you were lacking the necessary skills to do so yourself
    http://forum.pfsense.org/index.php?topic=18926.0;prev_next=prev

  • Snort will not unblock a whitelisted IP

    Locked
    17
    0 Votes
    17 Posts
    16k Views
    G

    Reading another thread (spp_frag3) is a snort preprocessor error. Not sure how to fix it other than to suggest you turn on all the preprocessors to see if that fixes it.

    As far as whitelisting goes you need to find the offending rule that is blocking the address and create a suppress rule for it in the tab. I "believe" I got it to work by using this syntax.

    suppress gen_id 1, sig_id 11969, track by_src, ip 216.82.225.24

    I tried to get one rule to handle the same sig i.e.

    suppress gen_id 1, sig_id 11969, track by_src, ip 216.82.222.14
    suppress gen_id 1, sig_id 11969, track by_src, ip 216.82.212.10

    Edit: This doesn't work. I will try restarting the router and see if anything changes. It is still blocking a category I have recently unchecked.

    But I was not able to get it to work as above. Haven't had the time to test using a , or ; to separate due to time constraints.

  • Snort Memory Setting

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    G

    I second that AC-BNFA is the only usable setting for most systems. (My inner geek would love to see a system the handles AC with moderate traffic) My system has 2GB Ram with 3 interfaces running at this setting @ 23% memory usage with low traffic. It is also wise only to choose the categories that are necessary for that particular interface not all categories need to be checked. Use only what you need otherwise you will be wasting CPU time and memory for nothing.

  • VnStat errors

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J

    I wasn't the one to install the wireless NIC without an antenna & management doesn't seem to want to get some so that we can use that instead of the router we now use for our wireless connections. I guess in this case I could just un-assign it.

    I have to admit it but I am somewhat new at using pfSense.

    Edit 2010-05-14

    Well after un-assigning it & then uninstalling & re-installing vnStat the error went away. I still think you might want to look at the code I gave you as it could remove the error for anyone else when they first install vnStat on to their box.

  • How to use squid

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    You probably was to at least read this page:

    http://doc.pfsense.org/index.php/Setup_Squid_as_a_Transparent_Proxy

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.