Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    E
    I even tried deleting and creating a new certificate. Any suggestions?
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    fireodoF
    @Gradius said in Feodo Tracker Botnet C2 IP Rules down for almost 48h: Any mirror or alternative ? No - AFAIK ...
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    572 Topics
    3k Posts
    keyserK
    @Antibiotic No it’s not possible with NtopNG as it is not a Netflow collector. You need nProbe for that which will “translate” recieved netflows into flows that NtopNG understands and can visualize (with very very little detail might I add as Netflows has no additonal information apart from sender/reciever and volume). The NtopNG package and the product in general is more geared towards visualising and recording traffic details from actual packet captures. This contains MUCH more metadata about the sessions than netflows (DNS names, protocol information and myriads of other things). But pffSense Plus has a builtin Netflow exporter if you have an external netflow collector on hand.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @BiloxiGeek said in DNSBL and IPv6: Does it just follow the IPv4 address that is listed above that? In my case it would end up being ::10.0.0.86 Yes. In this specific context that's the notation being used. (Full IPv6 web server address, for reference then, would be: http://[0000:0000:0000:0000:0010:0000:0000:0086]) Nota bene: I use 0.0.0.0 which renders the DNSBL webserver useless and inaccessible, but otherwise returns 0.0.0.0 or ::/NOERROR answers to all blocked lookups.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    101 Topics
    2k Posts
    dennypageD
    @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: Interesting. I would have thought the initial reboot, which occurred as part of the upgrade, would have done the trick, but it took a second reboot, just now, to get things working. Glad you have it sorted. There was no difference in the output of usbconfig show_ifdrv at any point -- before or after unplugging/replugging the USB cable, nor after rebooting. ... Question: What would tell me whether or not a driver was loaded? If there were an attached driver, it should have shown up with the show_ifdrv command. If you use the command and look at the other usb devices, I think they will show attached drivers. I don't expect to see a driver attached to the ups, because there is a quirk that tells the OS to ignore that device (and not attach a driver). Look for idVendor and idProduct in the above output. The Vendor ID for your device is 0764, which corresponds to Cyber Power Systems, and the Product ID for your device is 0601, which is registered as "PR1500LCDRT2U UPS" (don't sweat an exact match for the name). You can see the quirk with the following command: [25.07-RC][root@fw]/root: usbconfig dump_device_quirks | grep 0764 VID=0x0764 PID=0x0005 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0501 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE VID=0x0764 PID=0x0601 REVLO=0x0000 REVHI=0xffff QUIRK=UQ_HID_IGNORE [25.07-RC][root@fw]/root: Your device is third on the list. The HID_IGNORE quirk says to ignore the device and not attach a driver. @jhg said in NUT fails to start after 2.7.2 -> 2.8.0 upgrade: You might consider adding this resolution to the release notes for 2.8. LOL... sorry, I don't have input to the release notes (I don't work here). While I wrote and maintain various packages, including NUT, I'm still just a volunteer. Most packages are actually written by volunteers.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    501 Topics
    3k Posts
    A
    Hi, Please help to forward / report the bugs in ACME 1.0 package. Thanks.
  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    yon 0Y
    said in Please update frr on Pfsense+ to FRR 10.3: https://redmine.pfsense.org/issues/15785 now frr 10.4.1
  • Discussions about the Tailscale package

    90 Topics
    610 Posts
    E
    Updated CE 2.7.2 to 1.86.4_1 Changelog pkg add -f https://pkg.freebsd.org/FreeBSD:14:amd64/latest/All/tailscale-1.86.4_1.pkg Freshports
  • Discussions about WireGuard

    699 Topics
    4k Posts
    S
    @Bob.Dig what's the right place?
  • BSDstats package

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Squid working, but getting some "operation timed out" errors

    Locked
    2
    0 Votes
    2 Posts
    5k Views
    C
    From the "Better Late Than Never" Department: Log into the box and use squidclient to query squid for stats: squidclient mgr:menu will give you a complete list of available commands. squidclient mgr:info is generally the first and most useful query to run. Look at the statistics related to median response time. Of particular interest will be the time it takes DNS to answer requests. Remember, squid is a proxy, that means that it's doing a lot of work in place of clients. Each request consumes system resources while it's being processed and the longer it takes to complete the transaction the longer those resources are unavailable to handle other requests. Also, make sure you're using diskd for async I/O, if possible, and that shared mem is tuned properly (if shared mem isn't tuned properly you'll get scary messages about resources being unavailable in the logs). NOTE: diskd can be a pain. If aufs works, use it instead. The last info I read on diskd v. aufs stated that in order for aufs to work on freebsd, threads would have to be able to do non-blocking I/O. I'm not sure about the current kernel, so more research is required. Don't use the default cache object removal policy, it's slow, inefficient and indiscriminate. Use one of the heap-based policies instead. Choose whichever policy meets your need, the primary distinguishing characteristic being their affinity for object size or age. Check the squid FAQ for more information.
  • DSpam

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    S
    Great! We should start a Starbucks fund for the dev's… I know I drank way too much Russian Sludge (no offense to the ruskies, but adding coffee grounds to a basket over and over until you can't close it makes for some interesting coffee) in my day developing grid software for super collider research. Anyways, I'm going to get a test box or two running. Let me know if there's any other way I can contribute other than submitting meaningful and detailed bug reports. Unfortunately no matter how many Frapa's or Mocha's you drink, it still doesn't make release day come any sooner lol… Keep up the good work guys.
  • Updated packages, incoming breakage, feedback needed

    Locked
    31
    0 Votes
    31 Posts
    18k Views
    R
    @mrreload: Ok, I tried again and I am getting the same thing. Log shows exactly the same as earlier post. I have tried deleteing the havp package file from /tmp, same. Tried to install it with or without squid installed. Tried a fresh install of pfsense, same. Strange thing is I have other packages installed without any issue. Squid and Freeradius. The same happens for me, even on a new install of pfsense.  Here's the error i get for HAVP: Downloading package configuration file… done. Saving updated package information... done. Downloading havp and its dependencies... done. Checking for successful package installation... failed! Installation aborted. Here's the error I get when trying to install CLAMAV: Installing clamav and its dependencies. Executing custom_php_resync_config_command()... It just sits there until I go and close the page after several minutes.  Weird thing though is that CLAMSMTP installs fine without any problems. Thanks in advance...
  • Asterisk

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    H
    Get a soekris/wrap and throw one of these ready made asterisk images to it. This will only use around 3 watts.
  • IMAP server

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    B
    @Kane66: Hi, Is there any way to install the IMAP server like dovecot or smth else on PFSENSE with full install (on HDD) ? I must have IMAP server in my network and i don't want leave PFSENSE which is great for me (stability and superios traffic control) :( Router with PFSENSE is only computer who work 24h per day :/ Best regards, You'd also need it to run as a MTA, which would require sendmail or some other MTA installed.  Have fun! –Bill
  • Unable to communicate to pfSense.com

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    P
    wan is up because I can navigate and dns are ok…  :(
  • Squid error

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    B
    need help, another error here… it says: Warning: fopen(/var/squid/acl/throttle_exts.acl): failed to open stream: No such file or directory in /root/solidgateweb/etc/inc/pfsense-utils.inc on line 321 Warning: fwrite(): supplied argument is not a valid stream resource in /root/solidgateweb/etc/inc/pfsense-utils.inc on line 322 Warning: fclose(): supplied argument is not a valid stream resource in /root/solidgateweb/etc/inc/pfsense-utils.inc on line 323 Warning: Cannot modify header information - headers already sent by (output started at /root/solidgateweb/etc/inc/pfsense-utils.inc:321) in /root/solidgateweb/usr/local/www/pkg_edit.php on line 215 what's wrong?:)
  • OpenVPN and 1.0-BETA1

    Locked
    87
    0 Votes
    87 Posts
    68k Views
    A
    That's great drakan, I'm gonna try it out now. Tried it on friday and the firewall hang. I needed to restore to factory defaults because webconfigurator wasn't reachable through any of the interfaces. Thanks again for your tests. BTW: what version where you running? RC1a?
  • ASSP won't work in RC1

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    S
    I have no intention on fixing it.  Someone else needs to step up to the plate.
  • SPAMD usage guide

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    Everything in the SpamD package is from OpenBSD's SpamD: http://www.openbsd.org/spamd/
  • Installing own package (instead of from port collection)

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    Looks about right to me..
  • How does "viralator" work?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    D
    Thx
  • Squid Web proxy cache stopped

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    D
    I install manually SquidGuard configure Squid for them. Squid worked. IMHO - not correct rule for configuration without redirector(SquidGuard, Claw …) PS Can add selection for redirector type - none/Claw/SquidGuard/any other  ? Possible i will be able to finish my webGUI for squidGuard package.
  • Can't get squid to uninstall

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    Download your config.xml without package information and reupload it again. Might work.
  • Havp 0.6 error install

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    Hi, Will check it tomorrow. HAVP is not currently pulled from pfsense package repository, but directly from my development box, whch can be slow. Today HAVP has been checked in to the ports collection and thus can be directly pulled from FreeBSD repositories. I will checkin the package with updated paths. raj
  • Squid not working

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S
    http://forum.pfsense.org/index.php?topic=1352.0
  • Squid grafic bug

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • New version havp 0.5

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    http://forum.pfsense.org/index.php?topic=1352.0
  • Error install HAVP

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S
    http://forum.pfsense.org/index.php?topic=1352.0
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.