Subcategories

  • Discussions about development snapshots for pfSense Plus 25.11

    9 Topics
    66 Posts
    yon 0Y
    I urgently need to upgrade to the latest version of FRR 10. last pid: 50887; load averages: 2.35, 2.29, 2.41 up 0+20:30:18 05:20:00 105 processes: 3 running, 102 sleeping CPU: 46.3% user, 0.0% nice, 21.0% system, 1.2% interrupt, 31.6% idle Mem: 1505M Active, 1806M Inact, 1921M Wired, 14G Free ARC: 228M Total, 66M MFU, 155M MRU, 533K Anon, 1302K Header, 4429K Other 185M Compressed, 414M Uncompressed, 2.24:1 Ratio Swap: 1024M Total, 1024M Free PID USERNAME THR PRI NICE SIZE RES STATE C TIME WCPU COMMAND 77832 root 4 141 0 2583M 2462M CPU2 2 505:23 196.84% bgpd 38116 root 1 1 0 23M 11M select 2 7:55 1.61% openvpn 44320 root 8 0 0 228M 155M select 3 17:31 1.12% zebra 58666 root 1 0 0 14M 3664K select 0 47:36 0.70% miniupnpd 63264 root 1 0 0 23M 11M select 2 0:36 0.51% openvpn 41157 root 1 0 0 23M 11M select 0 1:14 0.39% openvpn 81930 root 1 0 0 23M 11M select 2 1:00 0.32% openvpn 22300 root 5 59 0 15M 3144K uwait 1 0:01 0.24% dpinger 62794 root 1 0 0 267M 234M select 2 0:32 0.16% bsnmpd 48156 root 1 5 0 15M 4236K CPU1 1 0:00 0.15% top 78090 root 1 0 0 26M 10M select 3 16:03 0.14% ntpd 95229 root 1 59 0 14M 3008K nanslp 2 0:01 0.06% cron 23298 root 5 59 0 15M 3140K uwait 1 0:01 0.04% dpinger 17794 root 5 47 0 15M 3140K uwait 3 0:01 0.04% dpinger 26716 root 5 59 0 15M 3140K uwait 2 0:01 0.03% dpinger 21621 root 5 59 0 15M 3140K uwait 0 0:01 0.03% dpinger 24135 root 5 59 0 15M 3148K uwait 1 0:01 0.03% dpinger 23729 root 5 59 0 15M 3152K uwait 1 0:01 0.03% dpinger 18311 root 5 57 0 15M 3192K uwait 1 0:01 0.03% dpinger 25099 root 5 59 0 15M 3136K uwait 0 0:01 0.03% dpinger 35794 root 1 0 0 25M 13M select 2 0:00 0.03% sshd-session 20955 root 5 59 0 15M 3132K uwait 3 0:01 0.03% dpinger 21956 root 5 59 0 15M 3136K uwait 0 0:01 0.03% dpinger 19832 root 5 59 0 15M 3148K uwait 3 0:01 0.03% dpinger 20181 root 5 59 0 19M 3276K uwait 1 0:01 0.03% dpinger 19392 root 5 59 0 15M 3140K uwait 2 0:01 0.03% dpinger 22947 root 5 59 0 15M 3144K uwait 1 0:01 0.02% dpinger 24345 root 5 59 0 15M 3140K uwait 2 0:01 0.02% dpinger 21305 root 5 59 0 15M 3140K uwait 0 0:01 0.02% dpinger 69255 root 1 0 0 14M 2892K kqread 1 0:13 0.02% tail 26294 root 5 59 0 15M 3136K uwait 1 0:01 0.02% dpinger 24687 root 5 59 0 15M 3140K uwait 1 0:01 0.02% dpinger 71886 root 1 0 0 14M 2880K select 1 0:12 0.02% tail 20571 root 5 59 0 15M 3140K uwait 1 0:00 0.02% dpinger 25472 root 5 59 0 19M 3272K uwait 1 0:01 0.01% dpinger 6517 root 9 0 0 58M 26M select 2 0:03 0.01% kea-dhcp4 22779 root 5 59 0 19M 3276K uwait 1 0:01 0.01% dpinger 18902 root 5 59 0 15M 3136K uwait 0 0:01 0.01% dpinger 25947 root 5 59 0 19M 3292K uwait 2 0:01 0.01% dpinger 68884 root 1 0 0 14M 3504K kqread 2 0:09 0.01% syslogd 17031 root 1 0 0 25M 8468K select 3 0:03 0.01% watchfrr 8925 root 9 0 0 46M 24M select 1 0:02 0.01% kea-dhcp6 663 root 1 0 0 125M 37M kqread 1 0:04 0.01% php-fpm 15542 root 1 0 0 23M 11M select 1 0:08 0.00% openvpn 50040 root 1 0 0 15M 3892K bpf 3 0:03 0.00% filterlog 51743 root 1 0 0 37M 14M kqread 1 0:51 0.00% nginx 37889 root 1 59 0 163M 67M accept 3 0:28 0.00% php-fpm
  • Looking for Intel NIC I/O features guide(Linksec)

    2
    0 Votes
    2 Posts
    541 Views
    HLPPCH
    I found something on MACsec https://www.synopsys.com/blogs/chip-design/what-is-macsec-protocol.html And ECMA-393 ProxZzzy on some intel cards https://ecma-international.org/publications-and-standards/standards/ecma-393/ There are also intel vpro features on NICs and RYZEN DASH remote access control features on ECC capable ryzen pro cpus. [image: 9sFSPjG] I am sure a combination of the default deny rule and L2 rules protect these features, but I'd also like to secure them all with snort/suricata and use them accordingly without investing into even more proprietary tech. Is there a steamlined way of identifying all of these features with opensolaris or with nmap or ptrace/dtrace? Their corresponding kernel module necessities etc?
  • Bitcoin mining for Netgate Enterprise sub

    1
    0 Votes
    1 Posts
    377 Views
    No one has replied
  • 0 Votes
    1 Posts
    357 Views
    No one has replied
  • pfSense on iPhone

    3
    0 Votes
    3 Posts
    859 Views
    stephenw10S
    @HLPPC said in pfSense on iPhone: There are probably easier ways to go about implementing a firewall Umm, yes. Just about any other way! That doesn't look like a full VM host. I've no idea how you might go about booting FreeBSD there. At a guess I'd say that's impossible. At the very least I would start with OpenWRT. But that too looks like it wouldn't work in what appears to be a terminal emulator. Unless I'm misreading it horribly. Steve
  • How to get Feedback on PRs

    11
    1 Votes
    11 Posts
    1k Views
    JonathanLeeJ
    @michmoor you know big tech says, They say : "Squid is dangerous ..." You want to maintain it with me? We just need to fix the gui is all
  • 24.08-DEVELOPMENT snapshots are now available

    Locked
    1
    1 Votes
    1 Posts
    484 Views
    No one has replied
  • Is there not a beta version any more?

    4
    1 Votes
    4 Posts
    771 Views
    B
    Yeah, and they spent a lot of time fixing and putting in features in this release. I don't blame them for taking some time off before they jump into another release. They have been releasing patches for 24.03 for specific bugs that are problematic though, so their not just sitting idle.
  • Intel Atom P5000 Snow Ridge line support

    11
    0 Votes
    11 Posts
    2k Views
    J
    Its working now with the Plus 24.02 beta installer. Only cavehat u need to run the installer , note the NDI, contact TAC support to pre activate that NDI.(because new Hardware) After that Installer will run and detect activated NDI so u can install.
  • 24.03 System Logs Formatting

    2
    0 Votes
    2 Posts
    544 Views
    jimpJ
    https://redmine.pfsense.org/issues/15411
  • Recurring Crash 2.7.0

    2
    0 Votes
    2 Posts
    462 Views
    stephenw10S
    Backtrace: db:0:kdb.enter.default> bt Tracing pid 11 tid 100007 td 0xfffffe0003fd6720 kdb_enter() at kdb_enter+0x32/frame 0xfffffe000379d9c0 vpanic() at vpanic+0x183/frame 0xfffffe000379da10 panic() at panic+0x43/frame 0xfffffe000379da70 trap_fatal() at trap_fatal+0x409/frame 0xfffffe000379dad0 trap_pfault() at trap_pfault+0x4f/frame 0xfffffe000379db30 calltrap() at calltrap+0x8/frame 0xfffffe000379db30 --- trap 0xc, rip = 0xffffffff80b05c80, rsp = 0xfffffe000379dc00, rbp = 0xfffffe000379dc00 --- vmxnet3_isc_txd_credits_update() at vmxnet3_isc_txd_credits_update+0x20/frame 0xfffffe000379dc00 iflib_fast_intr_rxtx() at iflib_fast_intr_rxtx+0xf7/frame 0xfffffe000379dc60 intr_event_handle() at intr_event_handle+0x123/frame 0xfffffe000379dcd0 intr_execute_handlers() at intr_execute_handlers+0x4a/frame 0xfffffe000379dd00 Xapic_isr1() at Xapic_isr1+0xdc/frame 0xfffffe000379dd00 --- interrupt, rip = 0xffffffff8125b026, rsp = 0xfffffe000379ddd0, rbp = 0xfffffe000379ddd0 --- acpi_cpu_c1() at acpi_cpu_c1+0x6/frame 0xfffffe000379ddd0 acpi_cpu_idle() at acpi_cpu_idle+0x2fe/frame 0xfffffe000379de10 cpu_idle_acpi() at cpu_idle_acpi+0x48/frame 0xfffffe000379de30 cpu_idle() at cpu_idle+0x9e/frame 0xfffffe000379de50 sched_idletd() at sched_idletd+0x4d1/frame 0xfffffe000379def0 fork_exit() at fork_exit+0x7d/frame 0xfffffe000379df30 fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe000379df30 --- trap 0, rip = 0, rsp = 0, rbp = 0 --- We've seen that a few times and looked into it. We submitted a bug fix for it upstream: https://reviews.freebsd.org/D43712 Disabling multi-queue support prevents it if you're hitting it repeatedly. Increasing the descriptor counts in the tunables will make it happen less frequently. But will still eventually hit it. Steve
  • Azure Wizard

    3
    0 Votes
    3 Posts
    502 Views
    stephenw10S
    Or in: https://redmine.pfsense.org/projects/pfsense-plus
  • Python and pfSense

    2
    0 Votes
    2 Posts
    913 Views
    GertjanG
    @John-Willard pfSense has python. Open up a command line : console, or SSH into pfSEnse, and fire it up : [23.09.1-RELEASE][root@pfSense.bhf/tld]/root: python3.11 -h usage: python3.11 [option] ... [-c cmd | -m mod | file | -] [arg] ... Options (and corresponding environment variables): -b : issue warnings about str(bytes_instance), str(bytearray_instance) and comparing bytes/bytearray with str. (-bb: issue errors) -B : don't write .pyc files on import; also PYTHONDONTWRITEBYTECODE=x -c cmd : program passed in as string (terminates option list) -d : turn on parser debugging output (for experts only, only works on debug builds); also PYTHONDEBUG=x ........ Be aware : pfSense is a firewall, not a dev system. You'll have a hard time pulling in more packages and other tools that maybe not present in the base system. @John-Willard said in Python and pfSense: Does pfSense have an API pfSense is build upon the FreeBSD kernel, and that one is 100 % open source. But again : it's probably not on pfSense that you develop anything, it's not the correct environment. Btw : Snort, Surriata, Wireshark etc are all binaries, certainly not "interpreted scripts" ;)
  • 0 Votes
    5 Posts
    815 Views
    GertjanG
    @Ellis-Michael-Lieberman said in A questions about certs from a small-shop / home user (Maybe wrong category?): Do I understand that you want me to list "pfsense.netwrightt.net" in my public record? if you want Letsencrypt to sign you a certificate that contains "pfsense.netwrightt.net" you must proof the Letsencrypt that you are "pfsense.netwrightt.net" == that you handle (admin, own, etc) that domain name. There are multiple ways to do this, hence the big list here : https://github.com/acmesh-official/acme.sh/wiki/dnsapi Example : there is a domain name server that handles "netwrightt.net". With a acme.sh script, and access credentials your registrar gave you, acme.sh access your registrar's domain server, and places in the sub domain /.well-known/ a text (TXT) file. The filename and content of the file name are give to acme.sh by Letsencrypt. When done, Letencrypt test the existence of that file name, and the content, so it knows that you 'admin' that domain name. This method is called "rfc2136". Since then, registrars have created their own methods and that's what the dnsapi list is so big.
  • Installer public beta

    installer
    4
    1 Votes
    4 Posts
    1k Views
    rcfaR
    @stephenw10 That would be greatly appreciated! Thanks!
  • How to run sh or php script for filer or cron

    28
    0 Votes
    28 Posts
    5k Views
    stephenw10S
    Nice.
  • Lost GUI on latest development release

    4
    0 Votes
    4 Posts
    584 Views
    stephenw10S
    New build is good.
  • Need Help...Want to build custom pFSense build...

    4
    0 Votes
    4 Posts
    755 Views
    rtorresR
    @jrey said in Need Help...Want to build custom pFSense build...: @dapperamer786 said in Need Help...Want to build custom pFSense build...: with my required changes in the GUI What? the GUI is web based. There are even some completely different dashboards floating around. what is it are you trying to do? I think what he is trying to do is install pfSense with his backup config? Rather than install a clean install then go through the process of uploading the config.xml in backup/restore.
  • Creating a new dashboard widget

    17
    0 Votes
    17 Posts
    2k Views
    S
    @hulleyrob said in Creating a new dashboard widget: Are there any tutorials for this or does someone know of a good starting point? I want to create a widget that would show the current days totals from traffic totals stats page. All the code should already be done in the php files but I have no idea how to go about running it to see what it already gets and what I need to do to filter out the data I want. Seems like a simple thing but hopefully if I would use it other people would find it useful too. Any help would be appreciated. To begin building a widget that shows daily traffic totals from PHP files, you must first comprehend the PHP code that is currently in use and how the data is computed. For the widget, set up an HTML structure and apply CSS styling. Use JavaScript to asynchronously retrieve data from PHP so that the widget is updated dynamically. Verify locally that the PHP files are retrieving data properly. PHP should be modified if needed to support APIs. For a thorough overview, look for tutorials on HTML, CSS, JavaScript, and PHP. Install the widget on a server so that anyone can use it and maybe help others who are looking for a similar feature.
  • 0 Votes
    7 Posts
    3k Views
    L
    After attempting to manually start vnstatd, you can check its status using the following command: service vnstatd status You should ensure that the configuration file for vnstatd is correctly set up. You can find the configuration file at /usr/local/etc/rc.d/vnstatd. See if any parameters or settings that might have changed in the new version. If your system uses systemd, there might be conflicts between the init system and systemd. Ensure that vnstatd is configured to work correctly with your init system. Even though you haven't found anything in the General logs, it's worth checking other logs such as /var/log/messages for any potential vnstatd-related issues.
  • Snort problem

    10
    1 Votes
    10 Posts
    2k Views
    P
    @JonathanLee I am running 2.7.2-RELEASE and everything is the latest.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.