Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    cyb3rtr0nianC

    @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

    Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

    I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

    I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

    Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    GertjanG

    @EChondo

    What's your pfSense version ?
    The instructions are shown here :

    1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

    A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

    @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

    I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

    No need to wait x days.
    You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    89 Topics
    574 Posts
    A

    Hello,
    I am unable to get the Tailscale package to work. The page at VPN > Tailscale > Authentication is stuck. It displays the error "Tailscale is not online," but also shows a "Logout and Clean" button, with no option to log in.
    link text

    This state persists even after performing the following troubleshooting steps:

    Rebooting the pfSense router.

    Completely uninstalling and reinstalling the Tailscale package multiple times.

    Clearing browser cache and using a private browser window.

    Toggling the main "Enable Tailscale" checkbox in the settings.

    Checking the logs, which show the service gets a "terminate" signal and shuts down cleanly; it does not crash.

    Manually trying to delete the state file with rm /var/db/tailscale/tailscaled.state, which failed because the file does not exist.

    It appears that the package's configuration is corrupted in a way that persists even after reinstallation. Can anyone advise on how to perform a complete manual cleanup of all Tailscale files and settings?

  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • Can not update or uninstall any packages.

    7
    0 Votes
    7 Posts
    1k Views
    GertjanG

    Same problem ?
    Same solution ?! See here.

  • RRD_Summary, dates issues

    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • Trying to install ntopng, hangs at Writing configuration... done.

    5
    0 Votes
    5 Posts
    822 Views
    G

    @netblues said in Trying to install ntopng, hangs at Writing configuration... done.:

    @gawainxx Have you tried this?
    https://docs.netgate.com/pfsense/en/latest/hardware/forcing-a-filesystem-check.html

    It's working now. Thanks!!! see my above reply.

  • bind dns ipv6 PTR zone and gui options problem.

    4
    0 Votes
    4 Posts
    420 Views
    GertjanG

    @viktor_g said in bind dns ipv6 PTR zone and gui options problem.:

    BIND

    Oops.
    My answer was ... just noise in open space.
    I'm using the Resolver.

  • FreeRadius with Active Directory and Google authenticator

    1
    1 Votes
    1 Posts
    159 Views
    No one has replied
  • Frezing during package reinstall

    5
    0 Votes
    5 Posts
    673 Views
    hugoeyngH

    Hello.
    I uninstalled Lightsquid and after this I could reinstall/uninstall/ squidGuard.
    Solved.
    Thank you.

  • 0 Votes
    3 Posts
    3k Views
    K

    @Gertjan said in Packages reinstall issue when restoring config in a brand new pfsense installation:

    @kevindd992002 said in Packages reinstall issue when restoring config in a brand new pfsense installation:

    ideas

    Yes, one that works for you right now.
    Your list :remove right away : Service_Watchdog is it is dangerous, and you're probably not a developer (and even they would not use it). Netgate_Coreboot_Upgrade as this updates Netgate devices only (is Netgate_Coreboot_Upgrade a Netgate device ?).

    After a pfSense install, make WAN work - and stop there.
    Install the packages by hand, one after another.
    Then import your backed up config to finalize the setup.
    Do a reboot, and you'll be fine.

    Somewhere on the forum, you'll fuind a reason for why the initial automatic install can fail. It's has something to do with a process that didn't get restarted (or something like that).

    Sorry, what do you mean "yes, one that works for you right now."?

    Why is Service_Watchdog dangerous? I have Netgate_Coreboot_Upgrade for the sole reason that I want flashrom installed (I know I can install it manually in the CLI but I want it to keep it this way so that I have a reference in the GUI). Regardless, I am fine with my list, this is simply a home firewall/router :)

    Your suggestion makes sense but it's just that I had no problems with my other box (same model, APU2C4) when I did this a month ago. That other box even has more packages on top of the list that I posted here. I can install the packages manually (and that's probably what I'll be doing anyways) but I just want to know what's causing this. I have to find that thread you're talking about.

  • Zabbix Proxy 4.2 Missing after pfSense v2.4.5-p1 update

    5
    0 Votes
    5 Posts
    875 Views
    viktor_gV

    @DaddyGo said in Zabbix Proxy 4.2 Missing after pfSense v2.4.5-p1 update:

    @zimmy6996

    because EOL!? 😉

    https://www.freshports.org/net-mgmt/zabbix42-agent

    37bdb3ec-e236-4fb0-8f40-581e52a65bb7-image.png

    Correct,
    See https://redmine.pfsense.org/issues/10688

  • NGINX as a Load balancer

    2
    0 Votes
    2 Posts
    204 Views
    jimpJ

    There are no current plans to do that internally, but if someone wants to write up a package for it, we'd certainly be open to reviewing it for inclusion.

  • rpz 'rpz.local' is not a master or slave zone crash BIND

    5
    0 Votes
    5 Posts
    3k Views
    viktor_gV

    See https://redmine.pfsense.org/issues/10445#note-3

  • Traffic Total not working

    2
    0 Votes
    2 Posts
    372 Views
    RicoR

    Did you try the Reset Graphing Data button?

    -Rico

  • New SG-1100 can't install packages from the web UI

    2
    0 Votes
    2 Posts
    303 Views
    J

    Well it turns out there's something with the web UI that doesn't like Firefox. Chrome seems to work just fine.

  • 0 Votes
    8 Posts
    877 Views
    nzkiwi68N

    I too am having this problem.

    with 2.4.5-p1 I can't cleanly upgrade Squid or FRR, they just hang, even when left for 30+ minutes.

    I've tried rebooting, uninstalling the packages (that mostly hangs too).

    In the end I tried;

    # pkg-static clean -ay; pkg-static install -fy pkg pfSense-repo pfSense-upgrade

    and

    # pkg-static upgrade -f

    But, guess what, that hung also once it got to installing the packages.

  • pfsesne - freeradius with ldap, a/d and dynamic vlan conf

    1
    1 Votes
    1 Posts
    143 Views
    No one has replied
  • Avahi Help!

    19
    0 Votes
    19 Posts
    2k Views
    W

    it looks like everything IS working...discovery app return a number of things from the IOT vlan while I was on my trust network. Thanks for putting up with and helping a newbie.

  • Help with configuring NUT master and slave

    1
    0 Votes
    1 Posts
    364 Views
    No one has replied
  • Did updater get broken?!?!

    2
    0 Votes
    2 Posts
    262 Views
    GertjanG

    @OverLabyss said in Did updater get broken?!?!:

    I am running the 2.4.5 train

    Download an original version from here : https://www.pfsense.org/download/

    Also : what about reading, for example, this : https://docs.netgate.com/pfsense/en/latest/install/upgrade-troubleshooting.html

    @OverLabyss said in Did updater get broken?!?!:

    Did the updater get broken

    We'll be having a hard time explain why thousands did upgrade since "1/11".

    @OverLabyss said in Did updater get broken?!?!:

    snapshots

    are only available for 2.5.0 (called 'the bleeding edge').

    @OverLabyss said in Did updater get broken?!?!:

    hasn't updated since 1/11

    At least two major versions came out, and you stay silent ?

    Btw : For example : https://www.netgate.com/blog/pfsense-2-4-5-release-p1-now-available.html - read the fat lines.

  • AVAHI and Sonos

    2
    0 Votes
    2 Posts
    2k Views
    SetarcosS

    Check your firewall logs for the corresponding interfaces and you will likely see UDP multicast traffic on port 5353 still being blocked. It looks like * doesn't include multicast destinations. I found another forum poster had added an alias for something like this, recreated it, and it solved my problems with Avahi traffic being blocked:
    51f6b17e-897c-4b59-8b6c-a2bb50603d3d-image.png

  • Wireshark for pfsense?

    7
    0 Votes
    7 Posts
    691 Views
    DaddyGoD

    @kiokoman

    I agree, SPAN is a good solution, we use on Cisco SG350 series switchs with Wireshark VLAN + SPAN

    b26f5637-d4cc-4875-8207-4a86c9ac9d3a-image.png

  • How to manually remove squidanalyzer?

    2
    0 Votes
    2 Posts
    389 Views
    W

    Solved :)
    I manually edited config.xml in /conf and remove this line

    <menu> <name>SquidAnalyzer</name> <section>Services</section> <url>/pkg_edit.php?xml=squidanalyzer.xml</url> </menu>
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.