Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    1. Home
    2. Popular
    Log in to post
    • All categories
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All Time
    • Day
    • Week
    • Month
    • marcelloc

      Unofficial E2guardian package for pfSense
      Cache/Proxy • • marcelloc

      1213
      4
      Votes
      1213
      Posts
      298035
      Views

      P

      @periko said in Unofficial E2guardian package for pfSense:

      Hello marcelloc or other e2guardian users, does e2guardian is already support for pfsense 2.5.2?
      Regards!!!

      I've been using it on 2.5.2 for months now, no issues.

    • W

      PfBlockerNG
      pfBlockerNG • • wbennett77

      1196
      1
      Votes
      1196
      Posts
      504769
      Views

      K

      @breeoge said in PfBlockerNG:

      @belt9:

      I wanted to chime in here as I just updated from a month old RC to 2.4.0-RELEASE last night and ran into this problem today.

      I haven't read through all of the many pages of the many threads that seem related to this issue (show how popular pfBNG is!), so maybe this has already been covered.

      But I've seen several people state that this doesn't happen on ZFS - I have a raidz2 ZFS install, and this happened to me, just throwing that out there.

      That is good to know. Thank you for the report.  BBcan177 is currently updating it to use SQLlite and this should fix any issues in the future.  In the other thread there is a temp fix posted..

      https://create.vista.com/colors/palettes/

      Thank you
      BreeOge

      Hello my friend. Many thanks to Bbcan177 for keeping the report up to date. as a result of this, in principle, the given problems are corrected.

    • dennypage

      NUT package
      pfSense Packages • • dennypage

      1119
      0
      Votes
      1119
      Posts
      329534
      Views

      JeGr

      @dennypage Nah, I can live with that :) But that only adds to another thing that packages should have more specific hooks like the XY interface instead of "any" interface, as theres no need otherwise. Or OpenVPN that gets restarted pretty often while listening on localhost so would be completely unphased by any changes. Also it'd be nice to have those notifications selectable and expandable so we can get more/specific notifications and disable others :)

      But I'll push that in another thread. Thanks for getting back :)

      Cheers
      \jens

    • Q

      Playing with fq_codel in 2.4
      Traffic Shaping • • qubit

      1108
      0
      Votes
      1108
      Posts
      310439
      Views

      Z

      @robnitro That sounds really good.

    • K

      Watchguard XTM 5 Series
      Hardware • • kmeyntz

      1078
      0
      Votes
      1078
      Posts
      290325
      Views

      tiggymiggy

      @stephenw10

      Could the voltage calculation have something to do with this? values are off... seem to need to divide by 4 to get in the right ballpark. i will keep looking though

      Meaning of the fid and vid
      The frequency ID (fid) is the multiplier for the reference clock (e.g. the FSB clock). The voltage ID (vid) is processor specific.

      Unfortunately Intel publishes no information about the meaning of this value but the conversion formula for Core CPU's seems to be

      UCpu = 700 mV + vid x 12.5 mV

      and for Core 2 CPU's it seems to be

      UCpu = 800 mV + vid x 12.5 mV

    • BBcan177

      PfBlockerNG v2.0 w/DNSBL
      pfBlockerNG • • BBcan177

      1077
      3
      Votes
      1077
      Posts
      618217
      Views

      RonpfS

      @ck42 The entry is related to Firewall / pfBlockerNG/ DNSBL / DNSBL Category Blacklist.

    • marcelloc

      Pacote não oficial E2guardian v5 para software pfsense®
      Portuguese • • marcelloc

      982
      4
      Votes
      982
      Posts
      219032
      Views

      gersonalves

      @patrick-pesegodinski maravilha ... sucesso!

    • marcelloc

      PfBlocker
      pfSense Packages • • marcelloc

      896
      0
      Votes
      896
      Posts
      529409
      Views

      jdillard

      There is now a pfBlockerNG package that replaces pfBlocker, so I am locking this thread.

    • marcelloc

      Postfix - antispam and relay package
      pfSense Packages • • marcelloc

      855
      0
      Votes
      855
      Posts
      343473
      Views

      Bismarck

      @winsonfa

      It should still work?

      Those errors are just cosmetic, you can ignore.

      On my machine, it gives that error but still works.

    • G

      What is the biggest attack in GBPS you stopped
      General pfSense Questions • • gadnet

      737
      0
      Votes
      737
      Posts
      107424
      Views

      J

      This topic is now locked.

    • D

      PC Engines apu2 experiences
      Hardware • • dugeem

      696
      0
      Votes
      696
      Posts
      163510
      Views

      D

      @stephenw10 Yes it's confusing. I am merely following advice from FreeBSD UPDATING

      20170109: The igb(4), em(4) and lem(4) ethernet drivers are now implemented via IFLIB. If you have a custom kernel configuration that excludes em(4) but you use igb(4), you need to re-add em(4) to your custom configuration.

      In any case the rx_process_limit tweak was only a 1-2% improvement (at least with previous versions).

    • T

      Country Block
      pfSense Packages • • tommyboy180

      691
      0
      Votes
      691
      Posts
      275616
      Views

      T

      I'll look into this. At the moment the Country data is static on Country IP Block. Country IP Ranges don't change enough to cause this app to pull dynamic data. There are times when the country data is updated but that's only about every 6 months.

      In the mean time focus has moved from Country Block to pfBlocker, FYI.

    • J

      Successful Install on Watchguard Firebox X700!
      Hardware • • jmcentire

      690
      0
      Votes
      690
      Posts
      479546
      Views

      D

      Hi guys, I know this is a super old thread - but just wondering if anyone in here could share me the a copy of the last x32 bit via DD configured for the x700 - Please see here for the actual thread with the background as to why: https://forum.netgate.com/topic/133044/pfsense-image-for-firebox-x700

    • R

      Packages wishlist?
      pfSense Packages • • rds_correia

      655
      0
      Votes
      655
      Posts
      351683
      Views

      MrPete

      nuttcp would be an AWESOME addition. Among other things, AFAIK it's the only packet generator that can reliably push/pull 10Gbps TCP/UDP loads.

      I may see if I can find a way to at least temporarily install it on my LAN.

    • N

      NEW Package: freeRADIUS 2.x
      pfSense Packages • • Nachtfalke

      628
      0
      Votes
      628
      Posts
      345189
      Views

      johnpoz

      You should most likely create a new thread if you feel you have found a bug, and if can duplicate it then please open a redmine on it. Locking this thread since it is 7 years old.

      And freerad 2.x is no longer a new package anyway.

    • marcelloc

      Squid 3.3.10 para pfsense 2.0 e 2.1 com filtro de SSL/HTTPS
      Portuguese • • marcelloc

      593
      0
      Votes
      593
      Posts
      204760
      Views

      K

      If you change pFSense / Services / Squid Proxy Server / GEneral tab Then check the SSL Man In The Middle Filtering area and change the SSL/MITM Mode from Splice WhiteList, Bumb OtherWise to the Splice ALL

      the problem can be solve with a this shape.

      OR

      With a default value of the SSL/MITM Mode with Splice WhiteList, Bumb OtherWise you can goto ACLs atb and add desıred web site url to the WhiteList area ie: online.kktcmaliye.com

    • M

      LCDProc 0.5.4-dev
      pfSense Packages • • mdima

      587
      0
      Votes
      587
      Posts
      235104
      Views

      fabricioguzzy

      Hello Stephenw10

      Thanks much for the message. I will check it, although the service can't start, not with that config.
      Anyway, I am also trying to use parallel port configuration since it doesnt' need any interface in between. (I have another display hd44780 compatible with no USB interface)
      Will post the results here after all.

      Thanks
      Fabricio.

    • ?

      Taming the beasts… aka suricata blueprint
      IDS/IPS • • A Former User

      504
      1
      Votes
      504
      Posts
      166870
      Views

      J

      @shred yup, I've been there, I also got confuse about that. but that rule is to block other interface to access management port. some of the link or pictures of this guide did not retrieve when netgate upgrade their forum.

      02268e4d-4c47-4b6c-b5ed-0cdbe7ee2a20-image.png

    • D

      ATT Uverse RG Bypass (0.2 BTC)
      Bounties • • dc81

      500
      0
      Votes
      500
      Posts
      68853
      Views

      G

      @bigjohns97

      When passing the nic, the netgraph method works for dealing with eapol.

      I was testing NOT passing the nic but creating a bridge specifying .0 as a bridge member as indicated in the proxmox link (https://forum.proxmox.com/threads/how-to-pass-vlan-0-priority-tags-to-pfsense-for-dhcp.112374/ post 2). Which did not work. I got no auth.

      Also tested specifying different interface drivers (virtio, vmxnet3, and e1000). The eapol data was just not coming through.

    • T

      IP-Blocklist
      pfSense Packages • • tommyboy180

      496
      0
      Votes
      496
      Posts
      258837
      Views

      J

      I cannot remove ip-blocklist in 1.2.2. Is there a way to remove or uninstall it using terminal?  Thanks

    • R

      Watchguard Firebox M400/M500
      Hardware • • revsie

      496
      0
      Votes
      496
      Posts
      91625
      Views

      stephenw10

      Yes the actual fan speed should vary with temperature. The value you set there is the minimum fan speed, the actual speed is determined by the minimum plus a value proportional to the CPU temp above a minimum temp value.

    • marcelloc

      Dansguardian package for 2.0
      pfSense Packages • • marcelloc

      492
      0
      Votes
      492
      Posts
      240443
      Views

      C

      if you really need ClamAV, use Squid 3-Dev. Works for me using i386 firmware..

      I've read the link you sent but still dont get this statement: The "core team" now compile the packages.

      try https://lists.pfsense.org/mailman/listinfo/dev if you want to send an email to the pfsense developers or post a bug on redmine.pfsense.org

    • marcelloc

      Sarg package for pfsense
      pfSense Packages • • marcelloc

      467
      0
      Votes
      467
      Posts
      250114
      Views

      Y

      @marcelloc

      Hello, Marcelo:

      Do you know how to install SARG in
      Hello, Marcelo:

      Do you know how to install SARG in pfsense 2.4.4, FreeBSD 11.2-RELEASE-p3 ?

      Thanks,
      Yosvany

    • marcelloc

      Squid3 - New GUI with sync, normal and reverse proxy
      Cache/Proxy • • marcelloc

      428
      0
      Votes
      428
      Posts
      270142
      Views

      P

      Ok, clear and understood.  8)

    • N

      How to get pfSense WAN to accept VLAN 0
      General pfSense Questions • • natbart

      403
      1
      Votes
      403
      Posts
      24579
      Views

      M

      @stephenw10 said in How to get pfSense WAN to accept VLAN 0:

      I would go with plan 2. Reviewing plan 1 again I can't see how that would work unless it's only DHCP that fails? If so then I guess a static IP might work for some time.... it might not though!

      You were right on the money going with plan 2. For anyone out there with the same issue as me the best way to upgrade is to edit your backup config file and change the wan interface to your preference. Not only did I change the wan interface but completely removed the shellcmd package and a lot of left over garbage from past package installs. You can really clean up your config file this way. And if you are using an em or igbx interface you can change your shellcmd (if your using one) to disable vlan filtering so you should be able to grab an IP from your ISP dhcp on your wan interface. Thanks

    • E

      DHCP + PPTP on WAN
      Russian • • Eugene

      402
      0
      Votes
      402
      Posts
      284293
      Views

      viktor_g

      @werter said in DHCP + PPTP on WAN:

      Добрый.
      У Билайна есть особенность - ip-адрес его pptp-сервера может меняться при каждом подключении.
      Скрины настроек lan + wan + pptp. Также скрины настроек dns.

      Зы. Свяжитесь с ТП Билайна. Возможно что у них есть и др. типы подключения (ipoe, pppoe, dhcp etc).

      Рабочий патч для PPTP/L2TP на DHCP WANе есть в https://forum.netgate.com/topic/164614/pfsense-2-4-5-p1-l2tp-server-ip-resolve-from-fqdn-during-boot-issue

    • R

      Firebox LCD Driver for LCDProc
      Hardware • • ridnhard19

      398
      0
      Votes
      398
      Posts
      228116
      Views

      D

      @stephenw10 yea, very strange. It seems to me that the lcdproc service window where you set that information isn't copying and saving that information.
      Thanks again

    • 1

      Вопросы новичка по pfsense
      Russian • • 1041107210881089

      398
      0
      Votes
      398
      Posts
      71014
      Views

      L

      @pigbrother Для конкретных IP. А для других конкретных IP прибиваем гатвей гвоздями и бай-бай Firewall / NAT / Port Forward

    • R

      OpenVPN PKI: Site-to-Site инструкция для обсуждения
      Russian • • rubic

      376
      0
      Votes
      376
      Posts
      106482
      Views

      P

      @Oleg2017:

      Не подскажите как у вас настроено на одном сервере два микротика. У меня при этом пингуется только один (пингуется из сети за  pfsense-ом) . Тот чья сеть указана  в  IPv4 Remote network(s) на сервере.

      Так сервер на то и сервер, чтоб обслуживать множество клиентов, не создавать же сервер для каждого.
      То, что за клиентом - сеть, значения не имеет.

      Сервер
      В IPv4 Remote network(s) - обе сети за Микротиками через запятую -  a.a.a.a/24, b.b.b.b/24 (хотя я исторически использую вместо Pv4 Remote network(s) директиву route в advanced).

      Сlient Specific Overrides
      Обязательно для каждого клиента Микротика в IPv4 Remote Network/s - сеть за этим Микротиком в виде a.a.a.a/24, а в Advanced
      push route "b.b.b.b 255.255.255.0 x.x.x.1"
      где
      b.b.b.b 255.255.255.0 - сеть за другим Микротиком
      x.x.x.1 - IP "серверного конца" OVPN туннеля. Это - ключевой момент, без него маршрут в сеть за другим Микротиком не будет воспринят.

      В IPv4 Local Network/s сети b.b.b.b быть не должно.

      Для второго Микротика - по аналогии

    • B

      Traffic shaper changes [90% completed, please send money to complete bounty]
      Completed Bounties • • billm

      375
      0
      Votes
      375
      Posts
      321305
      Views

      C

      This bounty is completed, for support, head to the 2.0 board.

    • Z

      UPnP support
      Expired/Withdrawn Bounties • • ZPrime

      363
      0
      Votes
      363
      Posts
      230141
      Views

      B

      Thanks, why didn't I see this in the first place  ::)
      Shame on me.
      All looks good now.

    • marcelloc

      Pacote não oficial E2guardian para software pfsense® - Adeus squidguard :D
      Portuguese • • marcelloc

      361
      0
      Votes
      361
      Posts
      69049
      Views

      M

      @marcelloc Boa noite Marcelloc... Eu instalei recentemente um Servidor Pfsense na versão 2.5 e fiz a instalação dos pacotes do git, porém eu fiz tudo o que o @lotus disse sobre o arquivo "#syslogsys = on" e continua indo para "off", já apliquei chmod -Rf 777 na pasta /var/log/e2guardian e por fim editei pelo "vi"/usr/local/etc/e2guardian/e2guardian.conf em syslogsys = on .... mas mesmo assim o serviço do e2guardian não inicia... sabe me dizer o que posso fazer para iniciar e2guardian? é permissão mesmo?

      OBS: ele não cria access.log na pasta /var/log/e2guardian

      Eu desconfio que deva ser um chown:

      ef4c4040-0a72-4200-9bb6-d59fdf182693-image.png

      Poderia me ajudar?

    • D

      IPv6 testing
      IPv6 • • databeestje

      357
      0
      Votes
      357
      Posts
      147988
      Views

      D

      Lion has a dhcp6 client, that wasn't there before, thus more addresses assigned.

    • B

      TIB5651Tr yazılımı (Static-Dynamic-Elle girilen kayıt dışı IP Raporlama)
      Turkish • • Bulo

      348
      1
      Votes
      348
      Posts
      126696
      Views

      M

      merhaba,
      çok uzun süredir herhangi bir hareket olmamış ama buna tekrar ihtiyacım oldu. kurulum dosyalarının olduğu sıkıştırılmış dosyayı nereden temin edebilirim?

    • M

      Tutorial: Configuring pfSense as VPN client to Private Internet Access
      OpenVPN • • mpboden

      348
      1
      Votes
      348
      Posts
      278852
      Views

      pitchfork

      great tutorial, thank you!
      are these instructions still valid for the current version of pfSense?

    • J

      Snort 2.9.2.3 pkg v. 2.5.0 Issues
      pfSense Packages • • judex

      331
      0
      Votes
      331
      Posts
      104993
      Views

      S

      I see a lot of false positives on my systems. It annoys me like hell tbh.

      #(http_inspect) UNKNOWN METHOD
      suppress gen_id 119, sig_id 31
      #(http_inspect) SIMPLE REQUEST
      suppress gen_id 119, sig_id 32

      (http_inspect) NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE

      suppress gen_id 120, sig_id 3

      (http_inspect) INVALID CONTENT-LENGTH OR CHUNK SIZE

      suppress gen_id 120, sig_id 8
      #PSNG_TCP_PORTSWEEP
      suppress gen_id 122, sig_id 3
      #ET MALWARE Suspicious FTP 220 Banner on Local Port (spaced)
      suppress gen_id 1, sig_id 2011124
      #ET SCAN Rapid IMAP Connections - Possible Brute Force Attack
      suppress gen_id 1, sig_id 2002994
      #PSNG_TCP_PORTSWEEP_FILTERED
      suppress gen_id 122, sig_id 7
      #ET SCAN Rapid IMAP Connections - Possible Brute Force Attack
      suppress gen_id 1, sig_id 2002994
      #FILE-IDENTIFY download of executable content
      suppress gen_id 1, sig_id 11192
      #FILE-IDENTIFY Portable Executable binary file magic detected
      suppress gen_id 1, sig_id 15306
      #ET POLICY PE EXE or DLL Windows file download
      suppress gen_id 1, sig_id 2000419
      #ET INFO Packed Executable Download
      suppress gen_id 1, sig_id 2014819

      #FILE-IDENTIFY Portable Executable binary file magic detected
      suppress gen_id 1, sig_id 15306

      This is my suppress list, but its not nearly as long as it should be!

      (http_inspect) IIS UNICODE CODEPOINT ENCODING - 02/22-03:06:06 is triggered.

      FILE-IDENTIFY download of executable content - 02/02-06:01:51
      ET INFO Packed Executable Download - 02/02-06:01:51
      ET POLICY PE EXE or DLL Windows file download - 02/02-06:01:51
      FILE-IDENTIFY Portable Executable binary file magic detected - 02/02-06:01:51

      Is triggered on whitelisted SRC IP's. It blocks Windows Update among other things.

      So snort is in my view not working as it should and its CORE functionality for a modern FW.

    • L

      Kernel Panic
      2.0-RC Snapshot Feedback and Problems - RETIRED • • LostInIgnorance

      325
      0
      Votes
      325
      Posts
      133912
      Views

      C

      locking this thread because people keep hijacking it, the original issue is resolved, start a new thread if you have an issue.

    • C

      FreeSWITCH package for pfSense 1.2.1 and 2.0 released. PBX or Proxy
      pfSense Packages • • cybrsrfr

      314
      0
      Votes
      314
      Posts
      227466
      Views

      D

      Running PFSense 1.2.3-RELEASE

      Having an issue when WAN IP address changes, even with an all LAN config.

      php: : pfSense package system has detected an ip change x.x.x.x -> x.x.x.x … Restarting packages.
      php: : The FreeSWITCH package is missing required dependencies and must be reinstalled.
      php: : Resyncing configuration for all packages.

      The service wont restart automatically, I have to go and restart it manually.

    • marcelloc

      Mailscanner + spamassassin + clamav package
      pfSense Packages • • marcelloc

      313
      0
      Votes
      313
      Posts
      163710
      Views

      D

      @marcelloc

      Hi Marcelloc, i have postfix and mailscanner running on pfsense 2.4.4-p1, i got the following warnings:

      MailScanner[64731]: Clamd::ERROR:: UNKNOWN CLAMD RETURN ./lstat() failed: Permission denied. ERROR :: /var/spool/MailScanner/incoming/64731

      Permissions looks fine, i did chown -R postfix:postfix /var/spool/MailScanner/incoming/, also chmod -R 6666 to the same folder.

      Runas user on MailScanner.conf and clamd.conf is postfix.

      Also mailscanner logs display syntax errors:

      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Syntax error(s) in configuration file:
      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "deliversuspiciouspdf" at line 93
      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "pdfidcommand" at line 84
      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "pdfidtimeout" at line 87
      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Unrecognised keyword "scanpdf" at line 90
      Mar 6 16:09:51 pfsense2 MailScanner[56749]: Warning: syntax errors in /usr/local/etc/MailScanner/MailScanner.conf.

      Please Help.

    • marcelloc

      Squid 3.3.4 package for pfsense with ssl filtering
      Cache/Proxy • • marcelloc

      305
      0
      Votes
      305
      Posts
      195998
      Views

      I

      Dear , I'm new to this, but fix this problem by simply checking the "Do not verify the remote certificate " located in Man SSL option menu in the filtering.

      SSL Man Int the Middle Filtering>Remote cert checks> check "Do not verify remote certificate".