Subcategories

  • Discussions about development snapshots for pfSense Plus 25.11

    9 Topics
    66 Posts
    yon 0Y
    I urgently need to upgrade to the latest version of FRR 10. last pid: 50887; load averages: 2.35, 2.29, 2.41 up 0+20:30:18 05:20:00 105 processes: 3 running, 102 sleeping CPU: 46.3% user, 0.0% nice, 21.0% system, 1.2% interrupt, 31.6% idle Mem: 1505M Active, 1806M Inact, 1921M Wired, 14G Free ARC: 228M Total, 66M MFU, 155M MRU, 533K Anon, 1302K Header, 4429K Other 185M Compressed, 414M Uncompressed, 2.24:1 Ratio Swap: 1024M Total, 1024M Free PID USERNAME THR PRI NICE SIZE RES STATE C TIME WCPU COMMAND 77832 root 4 141 0 2583M 2462M CPU2 2 505:23 196.84% bgpd 38116 root 1 1 0 23M 11M select 2 7:55 1.61% openvpn 44320 root 8 0 0 228M 155M select 3 17:31 1.12% zebra 58666 root 1 0 0 14M 3664K select 0 47:36 0.70% miniupnpd 63264 root 1 0 0 23M 11M select 2 0:36 0.51% openvpn 41157 root 1 0 0 23M 11M select 0 1:14 0.39% openvpn 81930 root 1 0 0 23M 11M select 2 1:00 0.32% openvpn 22300 root 5 59 0 15M 3144K uwait 1 0:01 0.24% dpinger 62794 root 1 0 0 267M 234M select 2 0:32 0.16% bsnmpd 48156 root 1 5 0 15M 4236K CPU1 1 0:00 0.15% top 78090 root 1 0 0 26M 10M select 3 16:03 0.14% ntpd 95229 root 1 59 0 14M 3008K nanslp 2 0:01 0.06% cron 23298 root 5 59 0 15M 3140K uwait 1 0:01 0.04% dpinger 17794 root 5 47 0 15M 3140K uwait 3 0:01 0.04% dpinger 26716 root 5 59 0 15M 3140K uwait 2 0:01 0.03% dpinger 21621 root 5 59 0 15M 3140K uwait 0 0:01 0.03% dpinger 24135 root 5 59 0 15M 3148K uwait 1 0:01 0.03% dpinger 23729 root 5 59 0 15M 3152K uwait 1 0:01 0.03% dpinger 18311 root 5 57 0 15M 3192K uwait 1 0:01 0.03% dpinger 25099 root 5 59 0 15M 3136K uwait 0 0:01 0.03% dpinger 35794 root 1 0 0 25M 13M select 2 0:00 0.03% sshd-session 20955 root 5 59 0 15M 3132K uwait 3 0:01 0.03% dpinger 21956 root 5 59 0 15M 3136K uwait 0 0:01 0.03% dpinger 19832 root 5 59 0 15M 3148K uwait 3 0:01 0.03% dpinger 20181 root 5 59 0 19M 3276K uwait 1 0:01 0.03% dpinger 19392 root 5 59 0 15M 3140K uwait 2 0:01 0.03% dpinger 22947 root 5 59 0 15M 3144K uwait 1 0:01 0.02% dpinger 24345 root 5 59 0 15M 3140K uwait 2 0:01 0.02% dpinger 21305 root 5 59 0 15M 3140K uwait 0 0:01 0.02% dpinger 69255 root 1 0 0 14M 2892K kqread 1 0:13 0.02% tail 26294 root 5 59 0 15M 3136K uwait 1 0:01 0.02% dpinger 24687 root 5 59 0 15M 3140K uwait 1 0:01 0.02% dpinger 71886 root 1 0 0 14M 2880K select 1 0:12 0.02% tail 20571 root 5 59 0 15M 3140K uwait 1 0:00 0.02% dpinger 25472 root 5 59 0 19M 3272K uwait 1 0:01 0.01% dpinger 6517 root 9 0 0 58M 26M select 2 0:03 0.01% kea-dhcp4 22779 root 5 59 0 19M 3276K uwait 1 0:01 0.01% dpinger 18902 root 5 59 0 15M 3136K uwait 0 0:01 0.01% dpinger 25947 root 5 59 0 19M 3292K uwait 2 0:01 0.01% dpinger 68884 root 1 0 0 14M 3504K kqread 2 0:09 0.01% syslogd 17031 root 1 0 0 25M 8468K select 3 0:03 0.01% watchfrr 8925 root 9 0 0 46M 24M select 1 0:02 0.01% kea-dhcp6 663 root 1 0 0 125M 37M kqread 1 0:04 0.01% php-fpm 15542 root 1 0 0 23M 11M select 1 0:08 0.00% openvpn 50040 root 1 0 0 15M 3892K bpf 3 0:03 0.00% filterlog 51743 root 1 0 0 37M 14M kqread 1 0:51 0.00% nginx 37889 root 1 59 0 163M 67M accept 3 0:28 0.00% php-fpm
  • Multiple issues on RELENG_2_7_0 GitHub Source Code.

    3
    1 Votes
    3 Posts
    579 Views
    D
    Thank you for doing this important research Fabricio. I apologize if I have misspelled your name. Please connect with me. I have information that can help both of us.
  • if fi bash shell script

    Moved
    3
    0 Votes
    3 Posts
    583 Views
    NogBadTheBadN
    @heartk What shell are you running ? If its /bin/csh if ends with an endif
  • https://redmine.pfsense.org/issues/14515

    commitid redmine 23.09.01
    5
    0 Votes
    5 Posts
    772 Views
    jimpJ
    That one is not plus specific, the commit referenced there is showing on Github.
  • Athp driver

    71
    0 Votes
    71 Posts
    24k Views
    JonathanLeeJ
    @stephenw10 I was reading the firmware for this card can also be updated at one point.
  • 0 Votes
    12 Posts
    5k Views
    Sergei_ShablovskyS
    Is any news about enabling QUIC in pfSense CE at the end of 2023? Because around 90% of traffic in the world come to/from mobile gadgets, but we still using old congestion protocols in pfSense (even QUIC available in FreeBSD in that pfSense based, since several years…)
  • New Feature Request

    1
    0 Votes
    1 Posts
    284 Views
    No one has replied
  • Download development snapshot

    8
    0 Votes
    8 Posts
    1k Views
    bmeeksB
    @Patch said in Download development snapshot: @bmeeks Seems to be fixed now as the binaries for the last few days are all different with relevant targeted changes. I checked out the latest 10-31-2023 image at the link you shared. It installs and appears to run fine, but you can't install any packages nor update any existing installed ones. I believe public access is shut down for now as the team is in the middle of merging some base updates from FreeBSD 14 into the 2.8 CE DEVEL snapshot branch. I also guess that effort has taken a bit of a back seat of late as it's probably "all hands on deck" prepping the 23.09 Plus release. Once pfSense Plus 23.09 releases, I expect activity to resume on the 2.8 CE snapshot branch.
  • Trying to recompile mpd5 to override the PPPOE_CONNECT_TIMEOUT

    Moved
    11
    0 Votes
    11 Posts
    2k Views
    bmeeksB
    Yeah, while hex editing on a binary can work every now and then, one problem I foresee in this particular case is that the PPPOE_CONNECT_TIMEOUT constant is defined once but then will possibly be used in a several places in the code. Finding all of those would be a tedious exercise. Edit the wrong 0x09 value somewhere and you would create a potentially serious bug.
  • Does anyone have the Yubico pam libraries built?

    1
    0 Votes
    1 Posts
    266 Views
    No one has replied
  • Inconsistency with PHP shell & committing changes

    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • FreeBSD OS choice

    7
    1 Votes
    7 Posts
    888 Views
    J
    @SteveITS I know it is not recommended, so I won't ask for help for my particular problem challenge. :) However, I have to manage lots of systems with different OS's, and I like to minimize the number of packages I manage them with. Luckily, except for this one, all other packages I use are in the pfSense repo.
  • another os

    12
    0 Votes
    12 Posts
    2k Views
    M
    @jimp said in another os: Like others have said, Netgate does our best to support hardware for as long as possible. My SG-2440 is a good example of this. It perfect sitting in the closet as a cold backup if needed right now. Following is my opinion: As for the OP question, if it's out of warranty, add non-eMMC storage reinstall the latest using ZFS and use it as a cold/warm backup.
  • Where can I find information on the backup/restore XML schema?

    14
    0 Votes
    14 Posts
    2k Views
    T
    @Patch I'll definitely be looking at example configs pulled from manually-configured pfsense installs, and refining what I need to include in the config.xml. The point of what I'm doing is to fully-automate the pfsense installation, like described here in the docs by providing the installer a config.xml file to apply. This config.xml will be different for different installations on different machines, so I must generate it programatically, which is why I'm asking about the xml schema and/or other config generation tools.
  • Patches update

    patch systempatches
    13
    1
    0 Votes
    13 Posts
    3k Views
    M
    @michmoor said in Patches update: Yep. Sorry if that wasnt clear. I am doing full MITM. Np, I was just trying to understand :) @michmoor said in Patches update: If you rely only on the internal redirect then pfsense points back to itself on the management port (firewall.example.com:443) . The problem of course is that in order to serve the page you must make your management port accessible to all LAN clients. That means making management accessible to all LAN clients. The only workaround is to use an external webserver that has php code on it to interrupt whats being sent to it from pfsense Now I see what you meant, yes, indeed that would be a problem.. Using an external server for that solves this problem.
  • DiagnosticsCrash Reporter

    2
    0 Votes
    2 Posts
    464 Views
    bmeeksB
    That error has only been reported one other time that I am aware of, and it turned out to be a corrupted alerts.log file if I recall correctly. That error is saying that a value read from the alerts.log was NULL, but there is no way that can happen unless the file is corrupt. One possibility is a disk read or write error. When you go to the ALERTS tab, can you display all the alerts from all Suricata configured interfaces without any problem? The exact same code is used within the ALERTS tab and Suricata Wiget, so a corrupt file would impact both. It's also possible that the error happened some time back in the past and by now the alerts.log has been rotated out and the current file may be fine. Does the error repeat every single time the widget updates, or has it only popped up once? Normally, issues with Snort or Suricata would be posted here: https://forum.netgate.com/category/53/ids-ips.
  • new package / best practices

    5
    4 Votes
    5 Posts
    2k Views
    M
    @bmeeks said in new package / best practices: I think the /usr/local/etc/rc.d/ path is currently hard-coded into the parts of pfSense that start packages at boot or when executing a "restart all packages" command. I do not believe it will find a script in /etc/rc.d/. Of course, sorry, I meant /usr/local/etc/rc.d/crowdsec and crowdsec_firewall. Meaning I don't need to wrap them from another script. They are supposed to work in vanilla freebsd after all. I can just enable them in /usr/local/etc/rc.conf.d/* I'm tagging @jimp in this thread. He is a Netgate developer and may have some helpful input. Great, thanks
  • Bug - Mellanox MT26448

    1
    0 Votes
    1 Posts
    314 Views
    No one has replied
  • Compiling from Source - Problems with "php-pfSense-module"

    4
    0 Votes
    4 Posts
    608 Views
    bmeeksB
    @fabricioguzzy said in Compiling from Source - Problems with "php-pfSense-module": @bmeeks Hi Bill, Thanks for the heads up. I have created a ticket --> Issue #14593 on redmine. Hopefully it will be fixed. Did you open a ticket for the pfsense-repoc ? I have noticed that it points to an internal Netgate URL, so it's impossible to compile it. Thanks Much, Fabricio. No, I had not gotten around to submmitting a ticket. This issue with pointing to the internal Gitlab URL has happened with other packages in the past, and it eventually sorted itself out. Was just still waiting to see if it would get updated when I saw your post about it.
  • 1 Votes
    5 Posts
    2k Views
    U
    According to my tests, the valid syntax $config['interfaces']['opt1']['enable'] = ""; or unset($config['interfaces']['opt1']['enable']); interface_reconfigure('opt1'); write_config('enable/disable opt1 interface'); exec Real-time enable/disable interface No need for system_reboot_sync();
  • 0 Votes
    3 Posts
    645 Views
    fabricioguzzyF
    pfSense-repoc-5b49b75f2a3cdf2349139152b2ca52e78dcbfd18_GL0.tar.gz doesn't seem to exist in /usr/local/poudriere/ports/Kontrol_v2_7_0/distfiles/. => Attempting to fetch https://gitlab.netgate.com/pfSense/repoc/-/archive/5b49b75f2a3cdf2349139152b2ca52e78dcbfd18.tar.gz?dummy=/pfSense-repoc-5b49b75f2a3cdf2349139152b2ca52e78dcbfd18_GL0.tar.gz fetch: https://gitlab.netgate.com/pfSense/repoc/-/archive/5b49b75f2a3cdf2349139152b2ca52e78dcbfd18.tar.gz?dummy=/pfSense-repoc-5b49b75f2a3cdf2349139152b2ca52e78dcbfd18_GL0.tar.gz: Host does not resolve => Attempting to fetch http://distcache.FreeBSD.org/ports-distfiles/pfSense-repoc-5b49b75f2a3cdf2349139152b2ca52e78dcbfd18_GL0.tar.gz fetch: http://distcache.FreeBSD.org/ports-distfiles/pfSense-repoc-5b49b75f2a3cdf2349139152b2ca52e78dcbfd18_GL0.tar.gz: Not Found => Couldn't fetch it - please try to retrieve this => port manually into /usr/local/poudriere/ports/Kontrol_v2_7_0/distfiles/ and try again. *** Error code 1 This is pointing to some internal netgate repository.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.