Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    N

    Can I use pgblockerng aliases in Haproxy?

    80758505-9bad-4dad-a80b-c159be1045a2-image.png

    If it was a firewall rule, typing pfb would produce a dropdown to select.

    Here it has to be written, but will it work? Is it supported?

  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    bmeeksB

    I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

    Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.

  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    571 Topics
    3k Posts
    K

    @pulsartiger
    The database name is vnstat.db and its location is under /var/db/vnstat.
    With "Backup Files/Dir" we are able to do backup or also with a cron.

  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    GertjanG

    @AlexK-0 said in Can't receive GeoIP databases updates anymore, banned:

    Days ago, I received from MaxMind an email, notifying me that my country has been banned to receive GeoLite City database updates.

    You've found a reason to use a VPN.

  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    99 Topics
    2k Posts
    K

    @elvisimprsntr thanks for your suggestion. I will give it a try.

  • Discussions about the ACME / Let’s Encrypt package for pfSense

    493 Topics
    3k Posts
    johnpozJ

    @MacUsers

    https://help.zerossl.com/hc/en-us/articles/360060119933-Certificate-Revocation

    edit: oh you prob out of luck

    You can revoke any certificate issued via the ZeroSSL portal. Currently, certificates issued via ACME can not be revoked from inside the portal - please follow the instructions of your ACME client for revoking those certificates.

    the gui in pfsense does not have the ability to revoke - you prob have to move the certs to something you have certbot installed to and revoke that way.

  • Discussions about the FRR Dynamic Routing package on pfSense

    294 Topics
    1k Posts
    R

    I had a similar issue with Routed VTI over IPsec recently. FRR lost its neighbors after rebooting or when a tunnel went down. It never re-discovered it automatically. Only restarting FRR (either in GUI or via CLI) brought the neighbors back.

    When I manually added those under the OSPF neighbors tab in the GUI it seems to solve the problem as well.

  • Discussions about the Tailscale package

    88 Topics
    573 Posts
    luckman212L

    For 25.07 RC, this worked for me (run sh first)

    [25.07-RC][root@r1.lan]/root: sh # export IGNORE_OSVERSION=yes # pkg add https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.84.2.pkg # service tailscaled restart # tailscale up # tailscale version 1.84.2 go version: go1.24.4 # tailscaled -version 1.84.2 go version: go1.24.4
  • Discussions about WireGuard

    689 Topics
    4k Posts
    P

    @patient0 Thanks for further suggestions. The tunnel is definitely up and so I don't think this is a CGNAT issue after all. WAN firewall rule is in place for UDP on port 51823 (otherwise the tunnel wouldn't work, right?). I can ping from client 1 -> client 2 and visa versa and also ping all points in between like you suggest. I just can't open an HTTPS connection from pfSenseB from Client 1 using a browser. But I can do this the other way round i.e. from Client 2 to pfSenseA

    I will try and do some packet capture to see if that reveals anything.

  • AVAHI Does not start

    1
    0 Votes
    1 Posts
    607 Views
    No one has replied
  • LcdProc on 2.5

    3
    0 Votes
    3 Posts
    235 Views
    J

    OK ! That's are wonderful news.

    Thank you

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    15 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • FreeRADIUS3: 0.15.7_3 -> 0.15.7_6 iOS clients can't connect

    2
    0 Votes
    2 Posts
    309 Views
    H

    Scratch that. I generated a new self-signed certificate and chose that instead of my Let's Encrypt cert and now my iOS devices connected again. Sorry for the false alarm.

  • FreeRadius3: MD5-Password encryption

    3
    0 Votes
    3 Posts
    414 Views
    JeGrJ

    @jimp said in FreeRadius3: MD5-Password encryption:

    Is there maybe some whitespace around the password that got ignored for cleartext but included in the MD5 hash?

    @jimp
    Nope, double checked that. The internal auth test works with cleartext password, MD5 gets rejected with above error. Don't understand it the least, as my box at home for example is configured exactly the same way and has no problems testing both kinds of users... I'm at a complete loss...

  • FreeRadius3: Certificates for TLS gone after updating to 0.15.7_4

    9
    0 Votes
    9 Posts
    752 Views
    J

    @jimp I just did, and it works. That was fast, thank you.

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    7 Views
    No one has replied
  • Arpwatch Question

    2
    0 Votes
    2 Posts
    465 Views
    N

    Same problem here with the same problem of router. I have a Linksys E3200 in bridge mode
    I will put some xxx where its not important

    hostname: <unknown>
    ip address: xxx.xxx.1.2
    ethernet address: xx:xx:xx:xx:xx:4e
    ethernet vendor: Linksys
    old ethernet address: xx:xx:xx:xx:xx:4f
    old ethernet vendor: Linksys
    timestamp: Monday, November 25, 2019 21:22:56 -0500
    previous timestamp: Monday, November 25, 2019 21:22:48 -0500
    delta: 8 seconds

  • APCUPSD Shutting down PFSense immediatly after boot up

    3
    0 Votes
    3 Posts
    355 Views
    A

    Well I have resolved this problem by reinstalling PfSense and applying a backup I made a few days ago.

    Will do more research into APCUPSD before I consider having that control my device again.

  • New Avahi package

    57
    2 Votes
    57 Posts
    42k Views
    L

    @dennypage said in New Avahi package:

    @logan5247 said in New Avahi package:

    My BLACKHOLE network isn't allowed to talk back to LAN, let me open some stuff up and see!

    @dennypage thank you! I had blocked all communication back from BLACKHOLE to my LAN. I had to allow 5353/udp from BLACKHOLE to LAN and now it's working great!

    I think you want to allow BLACKHOLE to send mDNS (5353) to firewall rather than to any.

    I just tried that (switching from ANY to FIREWALL) and it didn't work. When I switched back to ANY, it works. The firewall logs show it's trying to send to 224.0.0.251, so maybe I can just allow it to go to that address.

  • repository unavailable

    Moved
    18
    0 Votes
    18 Posts
    1k Views
    M

    I tested it on other hardware and it really seems to be some local glitch

  • Suricata setup

    7
    0 Votes
    7 Posts
    3k Views
    S

    Thank you so much!
    It is up, but for some reason I am only getting 1 single traffic type:
    ICMP src: switch dest:224.0.0.1.....

    Will have to figure this one out, I believe it is on the switch side, not sending the traffic

  • Filter out OSPF route?

    7
    0 Votes
    7 Posts
    1k Views
    A

    @Derelict Thank you.

  • Norton.com/Setup - How to activate Norton product?

    1
    0 Votes
    1 Posts
    224 Views
    No one has replied
  • Is there a Bacula howto?

    5
    0 Votes
    5 Posts
    504 Views
    V

    So sorry, I asked in the wrong forum.

  • Zabbix Proxy?

    1
    0 Votes
    1 Posts
    401 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.