Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    tinfoilmattT
    @johnpoz said in Please help to configure HAProxy to serve certifficate on internal LAN too: Yeah - what part do you not understand if you always resolve nextcloud.domain.tld so that it hits your haproxy on your pfsense wan IP are you not getting? You have 2 options - use a different domain internally and always go to nextcloud.publicdomain.tld, or use the same domain internally as external and run into the problem of what IP it resolves to.. Change your local domain to say home.arpa or .internal or atleast something different than the public domain your using to point to pfsense wan IP on the public internet. You are shooting yourself in the foot trying to use the same domain externally as internally. There are ways around it, but they complicate the setup. For example you might be able to use views in unbound as one way to work around the problem. You could use only host entries for all your resources. But then again you run into a problem of using the fqdn for this service, now always pointing to your wan IP.. And that is great when you want to access the service haproxy is doing - but if you want to access that resource on some other service that haproxy doesn't handle - like say simple file sharing.. You are going to have problems. Since you clearly do not understand how any of this works - the simple solution is change the local domain you are using so it is not the same as the public domain you want to use to get to your nextcloud. This tone is outrageous directed at somebody who acknowledged right off the rip that English is not their first language. How many languages do you speak, John? And safely assuming it's only one—English of course—take it from a fellow English native that you'd do well to say more with less words. You otherwise were directing OP in the right direction in my opinion.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    V
    Ah, I changed the action to deny both and now I also have a wan firewall rule, which I also had on OPNsense. With this wan rule I can see the blocks already coming now! Is it a bad idea to have the action set to deny both instead of inbound only?
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    F
    @dennypage I tested it with a new UPS and I no longer have the problem. It was the UPS that wasn't working properly. Thanks for your help.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga that looks good, the same is needed for LAN.
  • Cron package error!!

    2
    1
    0 Votes
    2 Posts
    509 Views
    kiokomanK
    require_once("/usr/local/pkg/cron.inc"); $a_cron = &$config['cron']['item']; <- line 25 if ($_GET['act'] == "del") { you have probably corrupted the config file, go to Diagnostics / Backup & Restore / Config History and restore to a working config [image: 1581857261466-immagine.jpg]
  • Arpwatch fails to download ethercodes.dat

    2
    0 Votes
    2 Posts
    665 Views
    E
    Here is a link to the bug report: https://redmine.pfsense.org/issues/10261
  • Service Watchdog Bug?

    2
    0 Votes
    2 Posts
    381 Views
    jimpJ
    That's the same as most any other page. Just click back or click away in the menu. Not a bug. There is no valid reason for anyone to add every service to the watchdog. It's illogical and highly likely to cause problems. Don't do that. Also not a bug since nobody should ever be in that situation.
  • Avahi-daemon choosing VIP instead of interface IP

    2
    0 Votes
    2 Posts
    547 Views
    C
    Based on feedback I've opened https://redmine.pfsense.org/issues/10253 to pfblockerng to move the default VIP bind to localhost instead of a user interface.
  • Syslog-ng not binding on multiple interfaces

    Moved
    1
    0 Votes
    1 Posts
    191 Views
    No one has replied
  • Unable to retrieve package info

    13
    0 Votes
    13 Posts
    2k Views
    GertjanG
    Don't know. And bye bye the security if it would be possible to change the URL being used for updates.
  • [solved] VPN Client Export Utility on 2.5.0-DEV

    3
    1 Votes
    3 Posts
    514 Views
    C
    Hello Hin4ik, thanks a lot for helping me here. I forgot to create a user certificate, after creating one I see also the config Kind Regards Robert
  • NTP PPS Jitter Question

    6
    0 Votes
    6 Posts
    2k Views
    C
    I have a Garmin 18x LVC wired and configured the same way (no LED though) and am also getting PPS jitter, see below [image: 1581011652491-capture.png]
  • DNS slave server ignoring updates from master

    3
    0 Votes
    3 Posts
    454 Views
    S
    Yeah, rndc doesn't work but it turns out it did eventually replicate. It just took hours and hours
  • HAProxy with thousand of additional certificates

    10
    0 Votes
    10 Posts
    1k Views
    C
    Sorry for weird word. Because of when I searching about memory_limit most of comments is to increase memory_limit configuration, and for pfsense I found to increase is in the file '/etc/inc/config.inc'. But after upgrade this file is override that the reason I said it's not a good idea ( not the right place ) to modify this file configuration. Thank you, If you want more information or any support from me don't hesitate to ask me.
  • Oracle Database Freeradius

    2
    0 Votes
    2 Posts
    400 Views
    kiokomanK
    it is not supported, you can ask a new feature here https://redmine.pfsense.org/ your only option is to install freeradius on another machine or convert the database the configuration files are overwritten every time you change something on the GUI consequently you lose what you entered manually
  • Random Failing Websites

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Testing Multicast using PIMD

    1
    0 Votes
    1 Posts
    484 Views
    No one has replied
  • New package: pimd

    Locked
    35
    11 Votes
    35 Posts
    15k Views
    jimpJ
    This seems to have strayed very far from the original intent of the thread. If you'd like to continue to discuss the merits of multicast routing in general, rather than issues directly related to the functionality of the package, start a new thread in an appropriate (non-packages) category. For those who have feedback about pimd, start a fresh thread for your individual issues. Please include details about your use case as well as current package settings. Ensure you are on pimd version 0.0.2. Locking this.
  • 0 Votes
    1 Posts
    429 Views
    No one has replied
  • [solved] Snort Registered User rules download fails

    13
    0 Votes
    13 Posts
    6k Views
    C
    I've been battling this as well. Be sure the Oinkcode is correct and without a leading space. Rookie mistake but it happens, drove me crazy for a week. Good luck!
  • HAProxy Listen On LAN - Pass Internal Traffic Through Proxy

    2
    0 Votes
    2 Posts
    640 Views
    B
    Did you figure this out? When I do, I'll post my response here.
  • Python 3 in pfsense

    28
    0 Votes
    28 Posts
    14k Views
    jwsiJ
    @guardian great! Look forward to hearing how you get on
  • 0 Votes
    6 Posts
    883 Views
    johnpozJ
    https://docs.netgate.com/pfsense/en/latest/general/can-i-sell-pfsense.html What can not be offered is a commercial redistribution of pfSense software, for example the guidelines do not permit someone to offer “Installation of pfSense software” as a service or to sell a device pre-loaded with pfSense software to customers without the prior express written permission of ESF pursuant to the trademark policy.
  • FreeRadius 0.15.7_8 and you are using a SQL database ?

    1
    1
    0 Votes
    1 Posts
    169 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.