Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    H
    We installed haproxy on Netgate 8200 device 25.07.1-RELEASE (amd64) installed acme certificates and get certificate from letsencrypt, everything ok. checked ssl offload in frontend and selected the acme generated certificate under SSL Offloading. result after Apply Changes: Errors found while starting haproxy [NOTICE] (72045) : haproxy version is 2.9.14-7c591d5 [NOTICE] (72045) : path to executable is /usr/local/sbin/haproxy [ALERT] (72045) : config : Couldn't open the ca-file '/var/etc/haproxy_test/clientca_WAN_117.pem' (No such file or directory). [ALERT] (72045) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind x.x.x.x:443' in section 'frontend' : 'ca-file' : unable to load /var/etc/haproxy_test/clientca_WAN_117.pem [ALERT] (72045) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (72045) : config : Fatal errors found in configuration. also package _devel has the same issue. on other boxes where haproxy was configured on 24.11 - upgraded to 25.07.1 its working. BUG ?? so what can we do now -bolded text we need this function. thank you all in advance
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    RedDelPaPaR
    Hello all, This is an older implementation of pfSense and Suricata running on a Netgate SG-3100 box. pfSense version: 2.4.4-RELEASE-p3 (arm) Suricata version: 4.1.7_2 This firewall has been working flawlessly for years but recently has been producing a lot of false alerts/blocks in Suricata during basic internet usage. I have noticed that the ETOpen rules in Suricata have not been updating since early October. Here is the log: Starting rules update... Time: 2025-11-02 08:16:16 Downloading Emerging Threats Open rules md5 file... Emerging Threats Open rules md5 download failed. Server returned error code 410. Server error message was: 410 Gone Emerging Threats Open rules will not be updated. The Rules update has finished. Time: 2025-11-02 08:16:17 Is there any solution to this without going through a risky/painful upgrade to the entire firewall OS and packages? Thanks for any help, Nate
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N
    @netboy Most probaly a configuration regression. You really need to dig deeper. From which pf version did you upgrade? Have you tried removing and reinstalling pfblockerng? Looking to the moon for craters with naked eye doesn't show the one that the crashed spaceship created. Use a telescope instead. FWIW, I see quite a few pfblockerng instances on 25.07.1 running with no (apparent) issues τοο
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    F
    @dennypage I can't run the test. But there's an automated system that does it every week. I tested it without override.ups.delay.shutdown. My UPS shuts down after 30 seconds, compared to 1 minute with the override.ups.delay.shutdown. I don't understand anything :-((
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    92 Topics
    639 Posts
    E
    Updated CE 2.8.1 to 1.90.4. Looks like they are already working on .6 Freshports pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.4.pkg Changelog
  • Discussions about WireGuard

    712 Topics
    4k Posts
    D
    I feel like I’ve followed every guide there was. I was able to get nordvpn via wireguard on my pfsense but for the life of me I can’t get my own wireguard server working. I can’t even get a handshake. I have all the firewall rules mentioned, the gateway, interfaces. Etc. I got no clue what to do at this point. Can anyone please help? I’ll provide any information required I just don’t even know where to start I’ve tried every YouTube video possible and guide it’s strange. I was able to get nordvpn working but I can’t get my own.
  • Snort Bug: HOME_NET line being mis-written. Comma at string end.

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    N
    Bug opened, but closed.  Thanks for that. :)  Now if only I could figure out why /var/db/whitelist winds up being such a mess for me. :(  It doesn't work right at all unless I manually clean it up after each reboot.  It appears to keep dumping duplicates into the file, and unless I sort network large to small, it's no good. That, and I have a network, x.x.x.0/24 for I have in /var/db/whitelist, but snort keeps adding x.x.x.11 to the blocklist.  Unless I put x.x.x.11/32 in there as well, it keeps getting blocked.
  • Package that block ports

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    H
    You can see pen connections at diagnostics>states if that helps.
  • Idea for New Package: PBNJ

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    @mrquintopolous: I just started using pfSense on an internal firewall where I work, and it works pretty nice. Good work guys! So I had an idea to extend pfSense with the capabilities of PBNJ (http://pbnj.sourceforge.net/). Basically, I think it would be a cool feature to be able to automatically scan your LAN machines with nmap and see changes over time and maybe even be alerted when a machine has a new port open. That way, an admin can jump on figuring out why this happened. In an attempt to figure out the internals of pfSense and waste time, I have been fiddling with getting PBNJ installed on the pfSense box. Without the ports system, it requires the following steps: pkg_add -r perl pkg_add -r <various 6="" perl="" modules,="" around="">3) One of the dependencies, p5-Nmap-Parser is not in the packages, so it requires downloading the tarball, extracting, installing etc. This requires a pkg_add -r gmake extract PBNJ, perl Makefile.pl, gmake, gmake install, gmake test Maye more that I subsequently forgot. Pretty involved, maybe installing ports and going from there would have been smarter. Anyways, I was wondering: Do people on this forum think that this would be a useful thing to have in a pfSense box? If so, is installing perl too much? i.e., would it be better to rewrite something similar in php? Would anyone be interested in making a package / ui frontend for it with me? I hope to hear your thoughts.</various> Not as involved as you would think.  Check out the squid package which in turns install perl.  Theres a number of packages that install multiple dependencies and then setup the package.  I don't see anything that would change this situation for this package. Check out http://pfsense.com/cgi-bin/cvsweb.cgi/tools/pkg_config.xml?rev=1.407 and http://pfsense.com/cgi-bin/cvsweb.cgi/tools/packages/
  • Are there any "packet sniffers" available?

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    S
    Recent snapshots have a tcpdump GUI component.
  • Squid Proxy Sever Blacklist

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    ?
    Please be a LOT more specific about what you're talking about.
  • Iperf Installation problem

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    M
    Working for me, thanks a lot!
  • MiniUPnPd and My Network Places

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    H
    I vote him for package maintainer of the year!  ;D
  • Pure-FTPD

    Locked
    21
    0 Votes
    21 Posts
    10k Views
    M
    thank you very much!
  • Bleeding Threats Support in SNORT

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Gateway AV and Snort

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B
    Yes, that is true. I'm out of work right now, but if I was working I'd offer $50 and then possibly more once it was done. $30-$50 for me is my starting place for things. However I have to work though and hopefully by the end of Feb I can start a new job. If there's not a gateway AV for pfsense when I am back to work then I will be offering a bounty for it. At least I hope I can afford to do that. You guys who work on pfsense really do a good job on the UI and stuff.
  • No packages work for me

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B
    Everything is working good. The issue was I guess you had to select LAN/WAN in that window. I don't remember what area that is. Like settings area for the package or something. I had to fiddle with it a while untill I understood it better since there is no documentation for anything. I also did upgrade to the latest snapstop as suggested and it's good so far. Thank you!!
  • Squid does´nt start

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    D
    I think I finaly fixed this today in version p15
  • Packages offline

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J
    Double check your boxes by sending a ping to google or yahoo in the terminal.  I haven't ever had a problem with the package system that didn't involve me forgettting about something.
  • SQUID Problem.

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    D
    See the other 10 page long squid thread. set a space in the unrestricted and banned fields and it should work then. Commited version p9 just now.
  • Pfsense

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    The packages that exist for this are not finished/working atm. If you have some knowledge feel free to fix/finish them.
  • Squid help

    Locked
    12
    0 Votes
    12 Posts
    4k Views
    J
    I'm guessing there is a language barrier, try your forum language and post there if it is listed, you should have more luck, but all in all this is NOT setup to work correctly yet
  • Squid Whitelist URL Capacity

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    D
    The current squid whitelisting and blacklisting should work starting from version p8. So you can try what size the limit is now :-)
  • Squid log to a remote server

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    B
    I found a command who can do the job : tail -f /log/squid/access.log | logger -p "local4.info" & To work syslog must be configured tu send "local4.info" to the remote server.
  • Snort Alert Question?

    Locked
    9
    0 Votes
    9 Posts
    4k Views
    S
    Yep I just noticed that as I went to reconfigure! Thanks for your help guys.  ;D [Edit:] In fact, it would appear that Snort does not like to run on multiple interfaces; a bug perhaps?
  • Squid and Traffic Shaping possible work around?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    U
    I had a quick look at what you did, so I don't know what causing squid to crash, but what I said before, squid has been changed for transparent proxying.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.