Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    H
    We installed haproxy on Netgate 8200 device 25.07.1-RELEASE (amd64) installed acme certificates and get certificate from letsencrypt, everything ok. checked ssl offload in frontend and selected the acme generated certificate under SSL Offloading. result after Apply Changes: Errors found while starting haproxy [NOTICE] (72045) : haproxy version is 2.9.14-7c591d5 [NOTICE] (72045) : path to executable is /usr/local/sbin/haproxy [ALERT] (72045) : config : Couldn't open the ca-file '/var/etc/haproxy_test/clientca_WAN_117.pem' (No such file or directory). [ALERT] (72045) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind x.x.x.x:443' in section 'frontend' : 'ca-file' : unable to load /var/etc/haproxy_test/clientca_WAN_117.pem [ALERT] (72045) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (72045) : config : Fatal errors found in configuration. also package _devel has the same issue. on other boxes where haproxy was configured on 24.11 - upgraded to 25.07.1 its working. BUG ?? so what can we do now -bolded text we need this function. thank you all in advance
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    RedDelPaPaR
    Hello all, This is an older implementation of pfSense and Suricata running on a Netgate SG-3100 box. pfSense version: 2.4.4-RELEASE-p3 (arm) Suricata version: 4.1.7_2 This firewall has been working flawlessly for years but recently has been producing a lot of false alerts/blocks in Suricata during basic internet usage. I have noticed that the ETOpen rules in Suricata have not been updating since early October. Here is the log: Starting rules update... Time: 2025-11-02 08:16:16 Downloading Emerging Threats Open rules md5 file... Emerging Threats Open rules md5 download failed. Server returned error code 410. Server error message was: 410 Gone Emerging Threats Open rules will not be updated. The Rules update has finished. Time: 2025-11-02 08:16:17 Is there any solution to this without going through a risky/painful upgrade to the entire firewall OS and packages? Thanks for any help, Nate
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    N
    @netboy Most probaly a configuration regression. You really need to dig deeper. From which pf version did you upgrade? Have you tried removing and reinstalling pfblockerng? Looking to the moon for craters with naked eye doesn't show the one that the crashed spaceship created. Use a telescope instead. FWIW, I see quite a few pfblockerng instances on 25.07.1 running with no (apparent) issues τοο
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    dennypageD
    @fjmp24 said in Notification: UPS ups battery is low: @dennypage My UPD indicate runtime: 18:21 Yes, but that may be completely inaccurate, especially with bad batteries. That's why you run a calibration test.
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    92 Topics
    639 Posts
    E
    Updated CE 2.8.1 to 1.90.4. Looks like they are already working on .6 Freshports pkg add -f https://pkg.freebsd.org/FreeBSD:15:amd64/latest/All/tailscale-1.90.4.pkg Changelog
  • Discussions about WireGuard

    712 Topics
    4k Posts
    D
    I feel like I’ve followed every guide there was. I was able to get nordvpn via wireguard on my pfsense but for the life of me I can’t get my own wireguard server working. I can’t even get a handshake. I have all the firewall rules mentioned, the gateway, interfaces. Etc. I got no clue what to do at this point. Can anyone please help? I’ll provide any information required I just don’t even know where to start I’ve tried every YouTube video possible and guide it’s strange. I was able to get nordvpn working but I can’t get my own.
  • OpenVPN Multihop Package

    6
    3
    2 Votes
    6 Posts
    2k Views
    A
    @John2893ax Hello, can you update pkg for 24.03?
  • Thoughts on CrowdSec

    2
    0 Votes
    2 Posts
    472 Views
    A
    @beloc I have tried him, looks working. Can be integrated with Suricata. They are making update for pfSense, but still not in official repo. If will support official will have to test again)))
  • Requesting help setting up Bind9 on SG1100

    1
    0 Votes
    1 Posts
    136 Views
    No one has replied
  • Bind config window blank - Error Msg on nslookup

    1
    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • Howto enable DNSSEC for a domain configured in Bind

    5
    1
    0 Votes
    5 Posts
    1k Views
    A
    @megapearl said in Howto enable DNSSEC for a domain configured in Bind: Now finding a way to save the keys in the config xml or write them to a different location to make them persistent upon reboot Also looking for a way to save my slave zone. After reboot my slave zone is empty, if there is no master. https://forum.netgate.com/topic/188369/slave-zone-in-bind-9-17/3
  • CloudFlare WARP, WARP+ and WireGuard working setup?

    1
    0 Votes
    1 Posts
    408 Views
    No one has replied
  • Problem with Avahi mdns after upgrade.

    4
    0 Votes
    4 Posts
    762 Views
    GertjanG
    @trautmann Avahi doesn't know if traffic goes over wires only, or if a part of the path is over Wifi ....
  • System Patches Package v2.2.11

    1
    5 Votes
    1 Posts
    957 Views
    No one has replied
  • New 2.7.2 Install. Packages are displaying in triplicates.

    4
    1
    0 Votes
    4 Posts
    521 Views
    J
    @SteveITS Looks good now... That was weird. Thanks.....
  • arpwatch database edit

    2
    0 Votes
    2 Posts
    913 Views
    johnpozJ
    @jester95 had a sim thread recently - the db files are here /usr/local/arpwatch https://forum.netgate.com/post/1163611 the dat files seem to be just text files, so you should be able to edit them I would think.
  • Please Consider Netbird Support | The Truly Free Tailscale Alternative

    1
    5 Votes
    1 Posts
    2k Views
    No one has replied
  • pfSense 2.7 and UDP Broadcast Relay

    9
    1
    1 Votes
    9 Posts
    2k Views
    S
    @Nyxtorm Yes, I had the same feeling; perhaps the best thing is to have the TVs in the same VLAN. In the end, I switched to OpenWRT; I find it better for home use.
  • arpwatch and voluminous amounts of SPAM

    9
    0 Votes
    9 Posts
    746 Views
    J
    Nice! Enjoy!
  • help with ntopng

    4
    0 Votes
    4 Posts
    674 Views
    dennypageD
    @detox To be clear, what I meant was that I don't know if the new pfSense-pkg-ntopng version is in the pfSense community repo yet. You should check in System / Package Manager. GeoIP will not work until a new version of pfSense-pkg-ntopng is installed because the old version does not provide the Login ID. [MaxMind now requires a Login ID as well as the License Key. There are several posts discussing this in the forum.]
  • 23.09.1 from 23.05.1 freeRadius broke

    9
    0 Votes
    9 Posts
    1k Views
    P
    @vanwinkle-rip, thanks for posting this! The log suggested to make that change but didn't specify where. You pointed in the right direction. Do you or anyone else know how to make this change permanent? Any changes in the GUI revert the changes. Maybe we can create an eap.local file or something like this?
  • Configuring UDP Broadcast Relay

    25
    0 Votes
    25 Posts
    7k Views
    R
    @iptvcld i'm sure there's a more eloquent and effective way to find out but I've actually just googled and messaged various companies to ask them what the udp forwarding port the app uses and been moderately successful. Can't get the the printer to reliably talk across the vlans but that could be a "printers are terrible" thing
  • System Patches Package v2.2.10_1

    3
    8 Votes
    3 Posts
    2k Views
    jimpJ
    They can't be in the release notes immediately along with the release since the issues are marked private until after the release is out, but they'll be added shortly.
  • Netmap root directory

    Moved
    1
    0 Votes
    1 Posts
    164 Views
    No one has replied
  • Rebooting pfsense on wan gateway failure

    2
    0 Votes
    2 Posts
    886 Views
    styxlS
    @ipfftw Try this link text
  • FreeRADIUS

    2
    1
    0 Votes
    2 Posts
    370 Views
    P
    The screenshot I posted above got removed somehow so I'm posting in text sshguard 14637 Blocking "192.168.4.103/32" for 480 secs (1 attacks in 0 secs, after 3 abuses over 693 secs.)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.