Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    D
    Retested on 24.11-RELEASE (amd64) all seems to work. So it seems right to file a bug for this issue.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC
    @rlrobs Yes it’s still working fine here.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K
    @pulsartiger The database name is vnstat.db and its location is under /var/db/vnstat. With "Backup Files/Dir" we are able to do backup or also with a cron.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    M
    I resolved this by accepting the T+Cs via https://www.maxmind.com/en/accounts/1205389/geolite2/eula
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG
    @EChondo What's your pfSense version ? The instructions are shown here : [image: 1753262126227-1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png] A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate. @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy: I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess. No need to wait x days. You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    J
    @div444 i'm finding the same - did you find a solution or did reverting fix it? Hoping there is a patch fix or something to get it working! Rather not rollback if i can avoid it
  • Discussions about the Tailscale package

    90 Topics
    580 Posts
    T
    @Gertjan Thanks. This is a compiled binary the tailscale vpn network mesh using wireguard. So this is s definite no then.
  • Discussions about WireGuard

    691 Topics
    4k Posts
    U
    Hi. My SG-2100 is currently setup with Surfshark utilising OpenVPN which is working however the bandwidth isn't great. I was hoping that switching to WireGuard would speed things up. I enquired about this a while ago and it seemed like openVPN was still the best option at the time but perhaps things have changed..... I have created my key pair and have the config info for WireGuard from Surfshark. Questions: Is it worth it? Should I back up and reset the 2100 before configuring WireGuard? Can you advise on the steps to configure WireGuard with my Surfshark VPN info within pfsense+ on my SG-2100? Thank you.
  • Dashboard 0.8.3_1 IPsec strangeness

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    dotdashD
    Ah, that would be it. It was upgraded from 1.2. Good catch: /usr/local/sbin/setkey -D my.wan.carp.ip[4500] mobileclient.public.ip[30883]         esp-udp mode=any spi=304123313(0x12208db1) reqid=0(0x00000000)         E: aes-cbc  a68ee719 c719199a 30aef38d 7524469a         A: hmac-sha1  1bf31131 c2c3e9dc 25888fca 026d9802 ad0856f3         seq=0x0001b1c1 replay=4 flags=0x00000000 state=mature         created: Jun 29 07:33:05 2009  current: Jun 29 09:27:55 2009         diff: 6890(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:55 2009      hard: 0(s)      soft: 0(s)         current: 13942840(bytes)        hard: 0(bytes)  soft: 0(bytes)         allocated: 111041      hard: 0 soft: 0         sadb_seq=6 pid=9564 refcnt=2 mobileclient.public.ip[30883] my.wan.carp.ip[4500]         esp-udp mode=tunnel spi=163139250(0x09b94eb2) reqid=0(0x00000000)         E: aes-cbc  05d6cf01 9fbe5b6a 358cf833 e9da3aad         A: hmac-sha1  feea0912 bd67cfea 6b734dee be610ec2 e973a04c         seq=0x00028d22 replay=4 flags=0x00000000 state=mature         created: Jun 29 07:33:05 2009  current: Jun 29 09:27:55 2009         diff: 6890(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:55 2009      hard: 0(s)      soft: 0(s)         current: 226902514(bytes)      hard: 0(bytes)  soft: 0(bytes)         allocated: 167202      hard: 0 soft: 0         sadb_seq=5 pid=9564 refcnt=1 my.wan.carp.ip remote.ip.D         esp mode=any spi=120936904(0x073559c8) reqid=16389(0x00004005)         E: aes-cbc  6b76fbdb 4a1c6c28 9f396457 655cb910         A: hmac-sha1  81eeab0d 0694980a 07a48cc9 de001298 9f956ad4         seq=0x000013fe replay=4 flags=0x00000000 state=mature         created: Jun 29 07:57:26 2009  current: Jun 29 09:27:55 2009         diff: 5429(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:50 2009      hard: 0(s)      soft: 0(s)         current: 1169424(bytes) hard: 0(bytes)  soft: 0(bytes)         allocated: 5118 hard: 0 soft: 0         sadb_seq=4 pid=9564 refcnt=2 remote.ip.D my.wan.carp.ip         esp mode=tunnel spi=227089053(0x0d891a9d) reqid=16390(0x00004006)         E: aes-cbc  d16c5888 752d83be fb5cda1c 09137340         A: hmac-sha1  4a4edba1 99efb15b e9192b16 40f727f6 7b8142f7         seq=0x00000dc6 replay=4 flags=0x00000000 state=mature         created: Jun 29 07:57:26 2009  current: Jun 29 09:27:55 2009         diff: 5429(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:50 2009      hard: 0(s)      soft: 0(s)         current: 597881(bytes)  hard: 0(bytes)  soft: 0(bytes)         allocated: 3526 hard: 0 soft: 0         sadb_seq=3 pid=9564 refcnt=1 remote.ip.D my.wan.carp.ip         esp mode=tunnel spi=47308714(0x02d1dfaa) reqid=16390(0x00004006)         E: aes-cbc  4d7635cb e77e5ad2 f5a864f0 aaa441e4         A: hmac-sha1  007d7961 1fb4072c 4bece018 850108ab 006c3936         seq=0x00000000 replay=4 flags=0x00000000 state=mature         created: Jun 29 07:57:25 2009  current: Jun 29 09:27:55 2009         diff: 5430(s)  hard: 28800(s)  soft: 23040(s)         last:                          hard: 0(s)      soft: 0(s)         current: 0(bytes)      hard: 0(bytes)  soft: 0(bytes)         allocated: 0    hard: 0 soft: 0         sadb_seq=2 pid=9564 refcnt=1 my.wan.carp.ip remote.ip.G         esp mode=any spi=145602196(0x08adb694) reqid=16391(0x00004007)         E: aes-cbc  e40282bc 734c5f93 a12b51bb d8b66a96         A: hmac-sha1  6cc652f7 f8679ebb 2b9c6522 57b963d5 60b03b87         seq=0x0007a755 replay=4 flags=0x00000000 state=mature         created: Jun 29 04:43:41 2009  current: Jun 29 09:27:55 2009         diff: 17054(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:55 2009      hard: 0(s)      soft: 0(s)         current: 61248056(bytes)        hard: 0(bytes)  soft: 0(bytes)         allocated: 501589      hard: 0 soft: 0         sadb_seq=1 pid=9564 refcnt=2 remote.ip.G my.wan.carp.ip         esp mode=tunnel spi=257452519(0x0f5869e7) reqid=16392(0x00004008)         E: aes-cbc  e61e358e 8999e9c1 61a588ce 26b07a72         A: hmac-sha1  fc2948b5 8c93bc95 9f879e40 6aad17b7 3de2d5a2         seq=0x000c49f2 replay=4 flags=0x00000000 state=mature         created: Jun 29 04:43:41 2009  current: Jun 29 09:27:55 2009         diff: 17054(s)  hard: 28800(s)  soft: 23040(s)         last: Jun 29 09:27:55 2009      hard: 0(s)      soft: 0(s)         current: 1084481374(bytes)      hard: 0(bytes)  soft: 0(bytes)         allocated: 805362      hard: 0 soft: 0         sadb_seq=0 pid=9564 refcnt=1
  • Freeradius package - user expiration not working (FIX)

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    S
    @hadi57: freeRADIUS is not starting with me i am using 1.2.3, even after adding the line: require_once('filter.inc'); I downloaded latest snapshot of pfsense 1.2.3 and applied same changes and it worked fine, the "require_once('filter.inc');" was only meant for version 2 if you read more closely, but I think this might not be an issue anymore with ver 2.0. The best advice I can give is to uninstall radius, rm -rf /usr/local/etc/raddb and reinstall radius again, then apply the 2 fixes above (for verion 1.2.3). you can also run radius in debug mode from console "radius -X" and see if you have any errors there. Hope that helps Slam
  • Daloradius setup

    Locked
    9
    0 Votes
    9 Posts
    10k Views
    S
    Thanks for the clarification :)
  • Re: Snort package should work now…Post problems here.

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    J
    @jamesdean: I'm using a ALIX 2d3 board that's 500 mhz and 256 ram and it takes around 5 minus to extract. Give it some more time…. I gave it several hours during one attempt and it never progressed beyond the extracting rules phase.
  • Pfsense freezes when add squid package

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    X
    i have same problem, it stuck at installing perl about 32%…..
  • Nmap doesn't work with pppoe interface

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Squid.conf don"t accept any change

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    C
    squid.conf is generated by squid.inc. if you like to modify or add. add it on squid.inc or at webgui custom configuration and where is squid.inc? /usr/local/pkg/squid.inc
  • [Squid] How is this possible?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    J
    Going bald is never fun. Now where do I scratch?? There is a workaround for what I want to do, but it's more configuration and not sure if it would have been possible with another firewall, big plus for PFsense here. thanks for the comments and the insights. Appreciated…Jits.
  • Squid not working on WAN

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    GruensFroeschliG
    Why would you want to run squid on the WAN? To control external requests to your internal servers? This is afaik currently not possible.
  • Questions mostly about squid

    Locked
    6
    0 Votes
    6 Posts
    7k Views
    C
    @serangku: is squid 2.6 pfsense has support delay_body_max_size option ? still newbie on squid thing :) nope.
  • NTOP crashes since we moved to 7.2

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    H
    it is crashing on 5 server i installed, i am using 1.2.3-RC1
  • Snort: Are Blocked IP addressed logged after they are released again

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    U
    jamesdean I turned out that I didn't have the latest version of snort installed Thnx!
  • Block IP and/or Domains with EasyList

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    U
    drarkanex you might want to have a look at the following thread: http://forum.pfsense.org/index.php/topic,11279.msg62689/topicseen.html#msg62689 I suppose that it is what you are looking for
  • Trying to integrate BlockLists

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    U
    Mike have a look at the following thread: http://forum.pfsense.org/index.php/topic,11279.msg62689/topicseen.html#msg62689 I think it is what you are looking for.
  • FreeSwitch can't have duplicate gateways

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    C
    As discussed on IRC change the gateway name so they are unique in some way. Then if your provider expects a specific name assign it by using the realm.
  • FreeSwitch hunt group not ringing

    Locked
    8
    0 Votes
    8 Posts
    6k Views
    C
    @clarknova: I'm getting this in the log on a reloadxml though 2009-06-25 10:10:27.820797 [ERR] switch_xml.c:1282 Couldnt open /usr/local/freeswitch/conf/autoload_configs/../sip_profiles/lan/*.xml (No such file or directory) This just means that a sip_profiles/lan directory doesn't exist. You can create it manually if you want to get rid of the annoyance. We don't use it for anything so it errors but doesn't cause any problem other than the error.
  • Logging Connections / Firewall States on HDD with date and time

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    L
    I need to log all the connections of a private network to the Internet. If I am not mistaken by enabling logging on default rule created during pfSense installation on the LAN interface … "LAN net"   *   *   *   *   "Default LAN -> any" ... are logged all packages "good". To avoid rivers of data I would Log only the packages packets for the new connections, or those with SYN bit set (NEW Connections in SPI terminology). Is it possible?
  • Proxy_monitor.sh fixed

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    S
    may i know … what this goal ? btw, i would like to try it soon  :)
  • SquidGard not working [solved]

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    Z
    Now my squidgard working perfect. Cheers. –-------------------------- Mzar
  • Squid custom error pages

    Locked
    4
    0 Votes
    4 Posts
    15k Views
    C
    right here -> http://forum.pfsense.org/index.php/topic,16307.0.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.