Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    JonathanLeeJ
    Squid can be configured externally, I would love a how to guide on how to do this correctly.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    656 Posts
    C
    @elvisimprsntr Updated 25.07.1 to 1.90.6_1, copied and pasted from @elvisimprsntr's post: pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6_1.pkg (Why it worked this time and not on previous updates: Over the last couple of days, I ran into the "Shared object "libutil.so.10, not found..." error that triggered the version 25.07.1 update issues some of us have been having. After I fixed that error, I decided to go back to the usual update method, and it worked.)
  • Discussions about WireGuard

    716 Topics
    4k Posts
    chpalmerC
    Im trying to set up Fubo TV for my mother using AT&T Wireless.. problem is they keep showing her California news channels... She wants local. Even though the website asks for her zip code they seem to default to the IP location. I have tried several times to sit down with this but can never get the thing to even ping from the other side. Connected with Wireguard here successfully for helping troubleshoot things for her otherwise.. Fubo is a PITA and keeps reverting back so I am finished trying to deal with them. Anyone got any tips? or a good tutorial??
  • Regarding Blocking Upload

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    GruensFroeschliG
    AFAIK this is not possible. Maybe someone has an idea how you could do something like this without pfSense.
  • Squid/squidGuard CLI

    Locked
    5
    0 Votes
    5 Posts
    12k Views
    jimpJ
    It is probably preferable to use: squid -k shutdown then squid This will ensure that squid shuts down cleanly.
  • Preview of Snort-dev snort pkg 1.7 alpha

    Locked
    24
    0 Votes
    24 Posts
    10k Views
    T
    Snort 2.8.4.1_7 pkg v. 1.8 RC4 their seem to be something wrong with the Emergingthreats rules It will download but they are not listed in Categories or rules also their are no alerts or blocking also what would you recommend for HTTP server flow depth I have it set to 0
  • Can't access WebGUI

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    R
    @chpalmer: Try consoling in and select Reset Webconfigurator". Do you mean selection (11) "Restart webConfigurator"?  If so, I also tried that. Same problem. I'm really confused… Attached is a graphic from my log. Can anyone decipher what "No free leases" means? And why does it repeat this error so much? [image: webGUI.jpg]
  • How can i download IMSpector log file through gui?

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • MOVED: I have to assign (WAN/LAN) interfaces after every pfSense reboot

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Dnsomatic

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    X
    I am still waiting to hear from dnsomatic on the issue of selective updates as well as afraid.org. Your package works. Thanks for taking the time to not only write the "package" for dnsomatic support but for putting on the forum for all to use. I will wait for their response to update only selected records v. all and wil post their reply Thanks for your help.
  • How to compile a binary for pfsense (need help with owfs/owserver)?

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    A
    owserver does compile under freebsd. (See http://owfs.org/index.php?page=porting) thanks to the work of Robert Nilsson.
  • Vnstat problem

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    P
    Yes from scratch When those kind of data is vital you have to use rsync,scp or wget for continual backup.
  • Who utilising the more bandwidth in a LAN

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    http://doc.pfsense.org/index.php/How_can_I_monitor_bandwidth_usage%3F
  • Testing new packages?

    Locked
    37
    0 Votes
    37 Posts
    56k Views
    S
    The XMLRPC package repo has been moved to: https://rcs.pfsense.org/projects/xmlrpc-server/
  • Remove residual DTMF in audio stream

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Site takes forever to load through transparent proxy

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D
    Thanks for the help. redbot.org is a great tool.
  • Imspector with squid logging problem

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Siproxd : Operation not permitted

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 1.2.3-RC3 squid only display general settings!

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    L
    thanks option onClick="document.location='/pkg_edit.php?xml=squid.xml&id=0';" SELECTED>General settings <option onclick="document.location='/pkg_edit.php?xml=squid_upstream.xml&id=0';">Upstream proxy</option> <option onclick="document.location='/pkg_edit.php?xml=squid_cache.xml&id=0';">Cache management</option> <option onclick="document.location='/pkg_edit.php?xml=squid_nac.xml&id=0';">Access control</option> <option onclick="document.location='/pkg_edit.php?xml=squid_traffic.xml&id=0';">Traffic management</option> <option onclick="document.location='/pkg_edit.php?xml=squid_auth.xml&id=0';">Auth settings</option> <option onclick="document.location='/pkg.php?xml=squid_users.xml';">Local users</option> i copy  http://192.168.1.1:8888/pkg_edit.php?xml=squid_cache.xml&id=0 can be edit squid_cache  . i cat /usr/local/etc/squid/squid.conf, YAHOO,it changed. ;D
  • SquidGuard on alix embedded

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    ok it s done and working i ve changed a few path  like u said in squidGuardconfigurator.inc and commented lines 1438 & 1439 #        if (file_exists($squidguard_config[F_DBHOME]))  $dbhome = $squidguard_config[F_DBHOME]; #        if (file_exists($squidguard_config[F_WORKDIR])) $workdir = $squidguard_config[F_WORKDIR]; those lines attribes to $dbhome the default value and i didn t find in the include nor in the inc where  $squidguard_config[F_DBHOME]; is set so if someone know where  it is … :) greets
  • Building custom packages for pfSense

    Locked
    11
    0 Votes
    11 Posts
    13k Views
    A
    OKay, I've done a lot of Googling and reading today (in between meetings).  I finally found this - http://tfm.cz/man/8/softflowd  which has been a huge help.  For some silly reason I also did not think of just entering the package name (softflowd) and hitting enter - which, of course, brings up the correct syntax dialog.  ::) I am now exporting flow data as I should be…. I think.  My Solarwinds collector doesn't seem to be recognizing or doing anything with the packets it is getting.  But that is for another forum... Thanks again for the help. Aaron
  • PfSense transparent proxy bridge + trafficshaper possible?

    Locked
    7
    0 Votes
    7 Posts
    10k Views
    S
    Hi, @Danswartz Thx for Reply. Not an expert on bridging pfsense, but I seem to recall recommendations to NOT put an IP on both interfaces.  Have you tried removing one of them? U are right. How i can remove one adress? Is filtering possible after removing Interface adress? @trinli I tested many hours and dont get it to work if clientgateway isnt PfSense Interface. Maybe the pf redirect to proxy port only work with transparent firewall Gateway adress. In my opinion its more useful to set Proxy via GPO or Script because wouldn't bypass SSL connections. Otherwise you cant log SSL Sessions.
  • How to enable Lightsquid report

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    R
    @_igor_: The post from dvserg IS for webIF (or browser)… Thanks it works.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.