• [solved] Error every time I try to post to the forum

    20
    0 Votes
    20 Posts
    4k Views
    JeGrJ

    @Steve You were referring me? If so, yes I also used other browsers (firefox in that case, as I mainly use Chrome synced across Win/Lin/Android) and even a stay-logged-in-Firefox had the same problem once in a while that I had to remove the cookie from its cache.

    Last time was a few weeks ago, since then I'm good. Hasn't happen again and I'm hoping it is fixed.

    Greets Jens

  • Nginx Error 500 posting attachments

    3
    0 Votes
    3 Posts
    1k Views
    C

    Should be fixed.

  • Issue with attachments?

    6
    0 Votes
    6 Posts
    2k Views
    M

    Same problem here.

  • Unable to send a message (PM)

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ipv6 *.pfsense.org is down

    12
    0 Votes
    12 Posts
    3k Views
    M

    fixed :)

  • Snort IPS/IDS

    4
    0 Votes
    4 Posts
    3k Views
    bmeeksB

    @volga629:

    Hello Everyone,
    Thank you for reply, I found and it working.
    Is possible use snort based on firewall rules ? It will be narrow down which probes to use and it will be allow be very specific on which traffic to filter instead whole interface.
    For example:

    If I need protect http server, I like to create firewall rule which allow connect to the port and in advance settings select snort profile in this case will be HTTP ( contain checks for HTTP, and web languages) and action instead default pass will be pass with IDS/IPS.

    No, Snort is not that tightly integrated with the firewall.  However, you can configure what the Snort package on pfSense calls "engines" on the PREPROCESSORS tab for each interface.  An "engine" is a single host or multiple hosts, or network block or multiple network blocks, that are used to target the Snort inspection.  For example, for web servers, you might have all of them in a specific subnet.  On the PREPROCESSORS tab in the section for the HTTP_INSPECT preprocessor, you would create an engine for the subnet containing your web servers.  You first need to create an alias under Firewall…Aliases, then use that alias as the "destination" address for the engine.  Once the engine is created, you can edit many parameters associated with it including which ports to inspect as HTTP.  This way Snort does not waste time and energy inspecting all the ports for web traffic if only say ports 80 and 443 are actually listening.

    Read up on preprocessor configuration details in the online manual at snort.org.  Then play around with the setting on the PREPROCESSOR tab for the various engines (frag3, stream5 and http_inspect, etc.).

    Bill

  • Dropdown menu Pfsense 2.1.5

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Forum certificate expired

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Disk usage

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • German sub-forum moderation

    5
    0 Votes
    5 Posts
    2k Views
    JeGrJ

    Coffee? Where!? :D

  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • Attachment problems?

    5
    0 Votes
    5 Posts
    1k Views
    C

    Ok good, thanks.

  • Sticky about bug reporting

    3
    0 Votes
    3 Posts
    1k Views
    C

    It's not put out in a more obvious fashion because we get too many bunk bug reports as it is. Like the linked thread, there doesn't appear to be any legit bugs there (short of the package reinstall getting stuck, which has an open ticket already), everything is behaving as you've configured it to.

  • Suggestion for the Hangout

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Sticky about required information

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Persian International support

    1
    0 Votes
    1 Posts
    917 Views
    No one has replied
  • MOVED: Comment on upgrade

    Locked
    1
    0 Votes
    1 Posts
    930 Views
    No one has replied
  • Request for Security (Issues?) Sub-forum

    2
    0 Votes
    2 Posts
    986 Views
    jdillardJ

    See: https://www.pfsense.org/security/

    There is also a security announcements list you can join.

  • Can't find "new topic" button

    4
    0 Votes
    4 Posts
    2k Views
    C

    Oops, I inadvertently applied the more limited permissions of the Vendor board (no new topics for newbies) to the entire forum. That's fixed. Should see the new topic button now.

  • Establish Czech International Support

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.