Subcategories

  • Discussions and feedback related to this forum

    610 Topics
    3k Posts
    G
    @stephenw10 This is my final note since it seem you will always look at this as an endpoint. It doesn't appear, it actually is, the facts are the facts. Still, moderator usually have a way to remove posts and ban single users, not just the entire herd, or at least the ones use. Perhaps those are more advance, or perhaps netgate forums lack that functionality. I never said negate took this issue lightly, I was just looking for some feedback. I have seen this process many times and for the looks of it, pfsense CE is very much in maintenance mode. Just because netgate wants to be politically correct does not mean it is not. The fact are there and they are fallowing the same path as others did. Again, this subject is just becoming redundant and it is affecting other users in the forum.
  • Community Hiring and For Hire postings related to jobs that require pfSense software skills

    29 Topics
    117 Posts
    w0wW
    @sef1414 Name it "run.sh", copy to pf and chmod according documentation https://docs.netgate.com/pfsense/en/latest/development/boot-commands.html#shell-script-option You will see messages in the system log like those quoted in the script after logger command.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • How do you design tagged and untagged networks?

    5
    0 Votes
    5 Posts
    952 Views
    bingo600B
    All my IF's with tags have PVID/"Native vlan" as 999 , and 999 is not used for anything, besides being "native". Well ... except my Unifi WiFi IF .... I made that back when you couldn't TAG the "Control" stream for the UNiFI's. And i have spread out the vlan load over two interfaces to improve throughput. Vlan1 is also unused in my networks. /Bingo
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • 2.6.0-2.7.0 update broke or worked strangely

    4
    3
    0 Votes
    4 Posts
    962 Views
    stephenw10S
    Yup, exactly as shown in those threads. You might need to add some other epp values or disable Speedshift for your CPU.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    10 Views
    No one has replied
  • Duckdns.org down

    1
    0 Votes
    1 Posts
    248 Views
    No one has replied
  • How to know your tired

    3
    1
    0 Votes
    3 Posts
    342 Views
    JonathanLeeJ
    @stephenw10 no it is not a bug. That is me playing with this Squid version 3 storeID program below. I was turning on debug to log my files the second I did that it was throwing errors, I learned how to spell true. hahah "“Store ID” is another name for the Squid cache key. By default, store IDs are computed by Squid so that different URLs are mapped to different store IDs. This feature allows the proxy admin to specify a custom store ID calculation algorithm via a helper program. It is usually used to assign the same store ID to transactions with different request URLs. Such mapping may reduce misses (i.e., increase hit ratio) when dealing with CDN URLs and similar cases where different URLs are known to point to essentially the same content. Store ID violates HTTP and causes havoc if URLs pointing to different content are incorrectly mapped to the same Store ID. A Squid admin lacks control over URL-to-content mapping used by external CDNs and content providers. Even if the initial reverse engineering of their URL space is successful, maintaining the Store ID helper correctness is usually difficult because of sudden external mapping changes" (wiki.squid-cache.org/). #!/usr/local/bin/php -q <?php /* This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see <http://www.gnu.org/licenses/>. Rudi Servo */ /* This is a CLI application made for PfSense and Squid 3 the idea is to use the already installed php in pfsense to do the storeid_helper. has of PfSense 2.2.6 php is on version 5.5.30 and Squid 3.4 Altough php has a bad reputation for being a continuous running application it has become more and more stable since version 5.5 now with version 7.0 it is not only stable has has many performance improvements that surpass most comon scripting languages. So there is no problem with php running this. Usage you can call out the script with many rewrite files to it or folders containing rewrite rules with .conf termination. inside the file it must have a hard tab between the match rule and and internal squid resolve */ #include a small config file, for debug and just in case something else comes up include 'conf/storeid.conf.php'; if ($_DEBUG) { file_put_contents($_LOG_FILE, 'Worker Spawn @'.date('Y-m-d H-i-s')."\n", FILE_APPEND ); } function addRules(&$rules, $filePath) { $file = fopen($filePath, 'r'); while (($line = fgets($file)) !== false) { $read = preg_split('/\s+/', $line); $rules['/'.$read[0].'/']=$read[1]; } fclose($file); } $rules = array(); $size = sizeof($argv); for ($i = 1 ; $i < $size ; $i++) { if (is_dir($argv[$i])) { $path = $argv[$i]; $files = scandir($path); foreach ($files as $file) { $p_info = pathinfo($file); if ($p_info['extension']=='conf') { addRules($rules, $path.'/'.$file); } } } else { addRules($rules, $argv[$i]); } } if (!empty($rules)) { $stdin = fopen('php://stdin', 'r'); $i_url = null; while (false !== ($url = rtrim(fgets($stdin), "\n\r")) && $url!='quit') { $found = false; foreach ($rules as $rule => $target) { if (preg_match($rule, $url, $matches)) { $i_url = $target; for ($i = 1 ; $i < sizeof($matches); $i++) { $i_url = "OK store-id=".preg_replace('/\$'.$i.'/',$matches[$i], $i_url)."\n"; } $found = true; break; } } if (!$found) { $i_url = "ERR\n"; } echo $i_url; if ($_DEBUG) { if (!$found) { $i_url = "ERR - ".$url."\n"; } file_put_contents($_LOG_FILE, $i_url, FILE_APPEND ); } } fclose($stdin); if ($_DEBUG) { file_put_contents($_LOG_FILE, 'Worker Closed @ '.date('Y-m-d H-i-s')."\n", FILE_APPEND ); } } (github.com/rudiservo) <?php $_DEBUG = false; $_LOG_FILE = '/var/squid/logs/storeid.log'; (github.com/rudiservo) I am trying to get better dynamic cache hits. [image: 1693581408262-1693549726245-8b56b38b-a13d-470c-9466-dd7890bd9912-image.png] Have you played with this ever? Again it should say refresh and not hit right? The wiki status codes are confusing also. [image: 1693581481143-screenshot-2023-09-01-at-8.17.47-am.png] [image: 1693581522777-1693464952581-screenshot-2023-08-30-at-11.47.10-pm-resized.png] Ref: https://github.com/rudiservo/pfsense_storeid/tree/master https://wiki.squid-cache.org/Features/StoreID https://wiki.squid-cache.org/Features/StoreID/DB
  • WIFI Malware Using Geolocator...

    11
    0 Votes
    11 Posts
    2k Views
    NollipfSenseN
    @provels said in WIFI Malware Using Geolocator...: what does this get the hacker? Maybe just to know the GPS info of where this WIFI lives...if the hacker lives aboard, maybe it's an invitation to visit... @provels said in WIFI Malware Using Geolocator...: what does Google even gain from providing this service? More info about a potential revenue source for Google to craft and perfect their approach to extracting wealth from client's pocket to fatten their shareholders. Remember, Google is in the business of extracting wealth through behavior modification of those who use its services.
  • Epic!!! A Connection Machine in a Raspberry pi!!

    1
    2
    1 Votes
    1 Posts
    210 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    13 Views
    No one has replied
  • vs. untangle (arista)

    Moved
    7
    0 Votes
    7 Posts
    1k Views
    S
    @chasinreno It doesn't sound like the firewall itself failed you. What kind of bot was it? How did it come in? How and where did you find it? The firewall CAN do AV scanning but if it was sent over an HTTPS connection then it would need to perform a MITM attack in order to be able to scan the download. AV scanning is best left to being able to view it in an unencrypted format, like directly on the PC. Paid AV has extra features like better scanning for fileless attacks, advanced script protection, or firewalls but I've found the real strength of the paid versions is the management, reporting, and support during an infection. In this case it sounds like the firewall did its job. It found malicious traffic going across the network and stopped it. IDS/IPS protects network traffic by, essentially, profiles. It protects based on the reputation of the remote network and the type of traffic being sent. It doesn't determine whether that traffic is good or bad. For example, if I want to port forward for SQL queries but I've blocked that in my IDS, it will be blocked. It doesn't care if it is me (good) or an attacker (bad). In this case, you downloaded a file (a legitimate type of traffic) from a site not blocked via IDS/IPS (a site with a neutral or better reputation) but then that file began sending traffic the IDS/IPS didn't like (NOT legitimate traffic) maybe to a site that was blocked (perhaps a poor reputation. That's what's supposed to happen. What appears to have failed you is your AV. It's best to figure out what got in and how, upload the infected files to virustotal (for crowdsourcing) and report it to the AV company. What was the infection and what was the AV you were using? When you upload it to virustutal it should give you a like. Post it here, I'd be curious to see what it was.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    1 Views
    No one has replied
  • 0 Votes
    14 Posts
    1k Views
    johnpozJ
    @velbon the only thing needed from pfsense is the config xml file.. Its very very small - do you not have a copy online with the pfsense ACB.. https://docs.netgate.com/pfsense/en/latest/backup/autoconfigbackup.html You should prob set that up going forward.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    4 Views
    No one has replied
  • This topic is deleted!

    1
    1
    0 Votes
    1 Posts
    3 Views
    No one has replied
  • I just Cloned & Upgraded my 1TB NVMe to a 2TB NVMe on my Thinkpad

    1
    0 Votes
    1 Posts
    171 Views
    No one has replied
  • How to safely open sketchy email?

    12
    0 Votes
    12 Posts
    1k Views
    F
    @DKenn Thanks, I did find out and it seems to have been ordinary spam, just formatted very well so the filter missed it. All good I hope
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    9 Views
    No one has replied
  • 0 Votes
    3 Posts
    751 Views
    planedropP
    @rcoleman-netgate Yeah @smokethrower2 if you can install OpenWRT or something then this would make your life easier, otherwise just getting another AP is probably the easiest route to go (not saying there aren't other solutions though).
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.