Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    RedDelPaPaR
    @bmeeks Understood. Thank for kindly for your help. I will likely be ordering a new unit soon.
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @netboy said in is something wrong with pfBlockerNG?: After my post, I "changed" DNSBL -> DNSBL mode from "unbound python mode" to "unbound mode" and so far i have no issues. Terrible idea. Moving backwards in development history there.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: If I remove ignorelb directive, my UPS shuts down after 16 seconds This means your UPS is signaling a low battery. Either your battery is bad, or your UPS is bad. Most likely battery, but you never know. I suggest reaching out to Eaton support.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    645 Posts
    E
    Updated CE 2.8.1 to 1.90.6. Freshports pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.6.pkg Changelog
  • Discussions about WireGuard

    714 Topics
    4k Posts
    S
    do you have a guide for setting up a Multi-Hop VPN inside pfSense (running on VMware)? Right now, I have an extra server running OpenVPN, and I want to route it through a Multi-Hop setup. Do you know how to do it? I’ve also heard that Multi-Hop setups are prone to more leaks, so it needs to be configured properly.
  • Thank you for Squid and Lightsquid packages

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    jahonixJ
    Krishna, if you are running a full install go to Packages and add it. If embedded is what you are using then it won't work since packages are not available on that platform.
  • Overall bandwidth throottling with Youtube ..

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    J
    @Shackattack: My Setup: Maximum download size: 95000 Maximum upload size: 20000 Overall bandwidth throttling: 600 Per-host throttling: 400 All trottles are marked Throttle other extensions: avi,mov,mpeg,mpg,wmv,rm,wma,wmv,wav,mp3,mp4,swf,flv,pdf,doc,ppt,zip,rar,bz2,gz,bin,exe,msi,7z,nrg,iso,mdf Works perfekt and I think the Per-host throttling is used to limit bandwith. All Video Streams are limited to 400 KB/s in my network Thanks! I am trying now .. which version do you have ?
  • Snort - block offenders

    Locked
    16
    0 Votes
    16 Posts
    17k Views
    C
    hi! i have made some kind of workaround: 2 solutions: first one: if you have spare hardware left put in 2 nics, install a base debian system and have a look at this: http://www.openmaniak.com/inline.php when you are at the point installing base, take the precompiled debian package acidbase. you will have less troubles and dont forget to add the startup script. When finished you will have a fine IPS based on snort rules. second one: just like 1 but: install 4 nics, after completing installing snort inline, install vmware, install pfsense on vmware example nic definition: eth0 and eth1 used for bridge br0 under debian bridge vmnet0 to eth2 = LAN pfsense bridge vmnet2 to eth3 = WAN pfsense bridge vmnet3 to eth2 = OPT1 pfsense You now have a firewall, an IDS and an IPS on one machine regards CC
  • Squid - bypass transparent proxy when going through IPsec {SOLVED}

    Locked
    5
    0 Votes
    5 Posts
    7k Views
    T
    I added an option to let squid NOT redirect RFC1918 subnets… just reinstall the package and have a look :-)
  • Squid can't connect some web sites

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    D
    Dear Mrsense, Thank you so much, it works.
  • Squid setting for use of subversion

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    T
    it's not a new squid version… just a checked-in-patch... reinstall and have fun... have a look at the timeline to see the changes...
  • Unable to Install Squid on 1.2-RC2

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J
    Great thanks a lot !!
  • Snort and 1.2RC2

    Locked
    10
    0 Votes
    10 Posts
    4k Views
    C
    hi folks! hiting save also solved the snort probelm here but imspector refuses to work i am using pfsense as transparent bridge only with traffic on wan and opt1 has anyone yet found a solution? regards cc
  • Question about miniupnpd package

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    F
    I did a firmware update last night to 1.2 RC2, and it seems to have cleared up on its own.  Both the UPnP and MiniUPnPd pages show up properly now.  Thanks everyone!
  • Monowall + pfSense as FreeRadius and Squid

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    J
    Thank you ! the 1st problem is solved (and now i can see who visited wich page on lightsquid) but now i have only the second dragon to kill… hack pfsense freeradius to give monowall the per user bandwidth.
  • FreeRadius Package

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Unable to install Packages

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    Cry HavokC
    Have you read the other threads on this topic?  They contain a number of tests you can use to find out where the problem is.
  • PfSense v1.2 RC3 - Bandwidthd - Not working

    Locked
    3
    0 Votes
    3 Posts
    6k Views
    G
    Fixed it! Change to scan LAN and enable promiscuous mode.
  • How to manually uninstall packages (bandwidthd)?

    Locked
    8
    0 Votes
    8 Posts
    38k Views
    jahonixJ
    @gshipp: …can I use Microsoft Word or Dreamer Weaver to edit the .XML? No, please don't! Even though it's an XML file you can edit it with most any pure text editors like notepad from Windows. I'd like to mention notepad++ (http://notepad-plus.sourceforge.net) which is a free notepad alternative comparable to hoba's editor of choice. UltraEdit should work as well but I think it's not free…
  • Avast Updates Fail!

    Locked
    12
    0 Votes
    12 Posts
    8k Views
    R
    I live by the web interface and do not dig to deep into the config files! I have to have a "keep it simple stupid" policy! Because if I get hit by a truck there is NO ONE to keep the systems going! I am in Egypt and after 3 years here I now know that Aliens built the pyramids! Because there is now way in hell they got build by the Egyptian Minds and Egyptian Natives! So I did it the simple way and figured the naming convention for most of the primary virus protection companies and loaded it into a text file and maualy loaded it to all pfsense servers… Problem solved and all is quite! If wanted I can post the No Cache Virus Server Update List.... Let me know!
  • I don't see the packages menu

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    C
    ntop is not going to work on a 4501 even if you did run a full install on a microdrive. It requires way too much RAM to function on a system with only 64 MB. pfSense technically isn't even supported on less than 128 MB, though for some purposes 64 MB will suffice.
  • Hobbitclient - monitoring (or installhowto ;-) )

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Openntpd doesn't work

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    K
    Will a fix for this be incorperated into 1.2 rc 3? im currently using 1.2 rc2 its yet to auto sync with the exception of first boot for 13 days now. Ive been logging in through ssh to force a sync the past two days
  • Possible problem in Snort package dealing with MicroSoft IE

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    G
    Well - here is a fix to the issue with Microsoft IE vs other browsers…. In the /usr/local/www/snort_rules.php file there is a javascript function called 'go'. brackets to denote an array index but instead uses the () parans… and then only if there are more than one object of the same type (lousy implementation if you ask me!)... Anyway - the "fix" to allow the different browsers, including Microsoft's IE, to display the Category information properly is to detect if the browser is msie or a different one - then setup the go function assignements accordingly: function go() {     var agt=navigator.userAgent.toLowerCase(); if (agt.indexOf("msie") != -1) {         box = document.forms.selectbox;}     else         {box = document.forms[1].selectbox;} destination = box.options[box.selectedIndex].value;     if (destination) location.href = destination; } I have tested the above code using both Firefox and MSIE-7 and it works properly - if anyone else wants to test please feel free - hopefully this will end up in the snort package as a fix.. gm…
  • Darkstat cannot connect on 666

    Locked
    5
    0 Votes
    5 Posts
    6k Views
    L
    No but I will do that now thanks :D
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.