Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    656 Posts
    C
    @elvisimprsntr Updated 25.07.1 to 1.90.6_1, copied and pasted from @elvisimprsntr's post: pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6_1.pkg (Why it worked this time and not on previous updates: Over the last couple of days, I ran into the "Shared object "libutil.so.10, not found..." error that triggered the version 25.07.1 update issues some of us have been having. After I fixed that error, I decided to go back to the usual update method, and it worked.)
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @Bronko said in The service show not running but client can connect to wireguard server.: @patient0 Thanks! ( I'm on 2.8.1) Oh, I see, I didn't realize that the same issue existed on CE.
  • Squid + Squidguard: Not working in Time-Based ACL

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    D
    @xerxes: Hello.. I set up under Times then made two ACLs. BTW, I have only one source IP since after pfsense where one router lies. QUESTION: How would I allow time-based shifting of ACL? or.. is this kind of set-up realistic? Hope to hear from you guys in here..THanks in advance. Here howto:
  • TinyDNS and native DNS forwarder

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • New snort

    Locked
    1
    0 Votes
    1 Posts
    966 Views
    No one has replied
  • Snort rule download…

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    OK, it's working now. I just needed to reboot the pfSense box and the rules downloaded.
  • OpenBGPD package

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    E
    yah, i managed to fix it some how… and its up and running... sort of.. i now get the following error neighbor 192.168.254.137 (Keeana): write error: Operation not permitted neighbor 192.168.254.137 (Keeana): state change Established -> Idle, reason: Fatal error but it connects to the peer once, gives this error, then connects to the peer again. i have no idea why this is doing it or what could be causing it.
  • OpenBGPD and more then one peer's AS

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    E
    Yes, I know it is fixed. Thanks.
  • Snort Blocklist time

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    D
    Go to Menu Bar: Diagnostics: Backup/restore Find the following in the config.xml file (I have personally changed from 60 minutes to 20 minutes and 3600 snort2c to 1200snort2C) <minute>/20</minute> <hour></hour> <mday></mday> <month></month> <wday>*</wday> <who>root</who> <command></command>/usr/bin/nice -n20 /usr/local/sbin/expiretable -t 1200 snort2c
  • How can i use another gateway with squid

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    E
    Only 2.0 sorry.
  • Cant uninstall a package

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Vnstat not storing data

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    B
    bump
  • Newbie: Help with Squidguard

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Dashboard issue on nanobsd

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    I committed a fix for this in Dashboard 0.8.4, which should now be on the package servers.
  • Modifying squid.conf when WAN is up / down ?

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    G
    Finally it dosen't work :( With my multiwan config squid on the pfsense is lost with DNS resolution…Sometimes it's working, sometimes not...The OPT1 is really important for my client so i need a perfect access. I put a debian lenny only with squid3 on my lan and it's working really better, the squid is configured to use the pfsense as DNS server and default gateway. If i put down my WAN connection, it send an alert to the Squid3 wich restart with a special "conf" and use the parent proxy from my OPT1.
  • Need help on SUPER simple FreeSWITCH setup

    Locked
    6
    0 Votes
    6 Posts
    9k Views
    B
    @mcrane: Hopefully that will get you farther along. Feel free to post additional questions here. Good Luck! ok, so i've really been working on this and have been able to get external sip soft phones working on Freeswitch per your instructions now what i've done (to simplify things) is i put my Panasonic PBX on the public side of the pfsense, i have multiple public IP's. it looks like this: x-lite(x501)–-\                            pfsense/freeswitch      x-lite(x502)---->--(Internet)---IP1-[WAN]–----[LAN]–---[Internal Network] x-lite(x503)–-/                      /                                           /                                   [Gateway IP2]                                   [PanaTDE PBX]–-----PSTN                                   sip.ext 401-403 the wierd thing is that i can't seem to get FreeSwitch to register the gateways, then when i check the logs i keep seeing 107@IP#2 and i don't even have an extension or gateway with 107 in it. however i think i may have used that extension early on in my testing. in fact my first name "Ryan" is in there as well, even though my name isn't anywhere to be found in the configs anymore! i think its keeping some stuff from early on in there that i can't see. i've restored the default profiles and vars and can't seem to get rid of it. what should i do? i don't even mind defaulting the whole thing and starting over, i just can't redo pfsense because its a production box is there possibly anything else you might see wrong with my setup here? here's the log: 2009-08-13 23:16:00.466667 [DEBUG] sofia_glue.c:2039 Set Codec sofia/external/107@X.IP.2.X PCMU/8000 20 ms 160 samples 2009-08-13 23:16:00.466667 [DEBUG] sofia.c:3376 (sofia/external/107@X.IP.2.X) State Change CS_NEW -> CS_INIT 2009-08-13 23:16:00.466667 [DEBUG] switch_core_session.c:933 Send signal sofia/external/107@X.IP.2.X [BREAK] 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:397 (sofia/external/107@X.IP.2.X) Running State Change CS_INIT 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:480 (sofia/external/107@X.IP.2.X) State INIT 2009-08-13 23:16:00.466667 [DEBUG] mod_sofia.c:83 sofia/external/107@X.IP.2.X SOFIA INIT 2009-08-13 23:16:00.466667 [DEBUG] mod_sofia.c:111 (sofia/external/107@X.IP.2.X) State Change CS_INIT -> CS_ROUTING 2009-08-13 23:16:00.466667 [DEBUG] switch_core_session.c:933 Send signal sofia/external/107@X.IP.2.X [BREAK] 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:480 (sofia/external/107@X.IP.2.X) State INIT going to sleep 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:397 (sofia/external/107@X.IP.2.X) Running State Change CS_ROUTING 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:483 (sofia/external/107@X.IP.2.X) State ROUTING 2009-08-13 23:16:00.466667 [DEBUG] mod_sofia.c:130 sofia/external/107@X.IP.2.X SOFIA ROUTING 2009-08-13 23:16:00.466667 [DEBUG] switch_core_state_machine.c:78 sofia/external/107@X.IP.2.X Standard ROUTING 2009-08-13 23:16:00.466667 [INFO] mod_dialplan_xml.c:252 Processing Ryan->401 in context public Dialplan: sofia/external/107@X.IP.2.X parsing [public->unloop] continue=false Dialplan: sofia/external/107@X.IP.2.X Regex (PASS) [unloop] ${unroll_loops}(true) =~ /^true$/ break=on-false Dialplan: sofia/external/107@X.IP.2.X Regex (FAIL) [unloop] ${sip_looped_call}() =~ /^true$/ break=on-false Dialplan: sofia/external/107@X.IP.2.X parsing [public->outside_call] continue=true Dialplan: sofia/external/107@X.IP.2.X Absolute Condition [outside_call] Dialplan: sofia/external/107@X.IP.2.X Action set(outside_call=true) Dialplan: sofia/external/107@X.IP.2.X parsing [public->call_debug] continue=true Dialplan: sofia/external/107@X.IP.2.X Regex (FAIL) [call_debug] ${call_debug}(false) =~ /^true$/ break=never Dialplan: sofia/external/107@X.IP.2.X parsing [public->x101] continue=false
  • [TOPIC TO MOVE ?] Squid + IPSec : 2 different gateways needed

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Using Only Emerging Threat Rules with Snort( No Sourcefire Rules) A guide

    Locked
    1
    0 Votes
    1 Posts
    13k Views
    No one has replied
  • Havp widget and possible addition of logs page to havp webui

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    @matrix200: Ok thanks, I will go ahead with it then. If you like you can check the havp widget at development forum. Is it possible to download the package as an archive? I can't check this now. Up to september i'm have rst  :)
  • Package monitoring through Windows or Mac OSX

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    A
    Might want to look at using something like Nagios. It has plugins to hook into a lot of things.
  • FreePBX v3 for FreeSwitch - slightly off-topic

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • SquidGuard + Times

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    D
    ??? Why need use cron? SquidGuard use one config without "reconfigure" and etc.. Each timed ACL contains 2 ruleset - for ontime and for overtime. SG take current time and compare with self config. If current time IN ontime, then taked 1 ruleset, else taked 2 rilest(right column) You should setup you pfSense date/time to you local zone for correct work.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.