Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • G

      Does this look like my pfSense was hacked

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      7
      0 Votes
      7 Posts
      3k Views
      GertjanG

      @luckman212

      Click on the image :

      1c8c8a2b-ed5f-4dd1-8694-8be0e58350e8-image.png

      I didn't test other search engines ...

      edit : the link @kpa posted is, imho, the best answer ( and totally not-FreeBSD related ^^ ).

    • A

      Firewall rule order is being changed every reboot.

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      2
      0 Votes
      2 Posts
      67 Views
      S

      @aaronouthier There was a bug in 24.3/11 where deleting multiple rules would reorder them. There’s a patch.

      But otherwise no it’s not normal at a reboot. Maybe compare config files before and after?

    • A

      Looking for few pointers getting Suricata on PFSense to talk to my Security Onion box.

      Watching Ignoring Scheduled Pinned Locked Moved pfSense Packages
      5
      0 Votes
      5 Posts
      100 Views
      bmeeksB

      @aaronouthier said in Looking for few pointers getting Suricata on PFSense to talk to my Security Onion box.:

      Ok, so I've been researching the topic. It seems SO has an integration for PFSense. However, the FreeBSD implementation of Syslog is not optimal for this purpose, as mentioned above.

      Although I am comfortable with CLI Linux, I am effectively a Newbie with regard to BSDs.

      My next question is: What would be the least invasive method as far as the PFSense Box to export just the Suricata logs? I believe I saw an option to log to a Unix Socket. Would that be helpful coupled with something like Netcat? I'm not necessarily looking for help with such a feat, just wondering if such would likely be fruitful, or am I just chasing the infamous wild goose?

      I recommend exporting the EVE JSON log as that will be the most comprehensive. To export to a UNIX socket, change the EVE OUTPUT TYPE setting to UNIX socket. You will need to manually create the socket and give it a name. It will be up to you then to "receive" the socket data stream and redirect it elsewhere (seems you want it remote for your case to Security Onion).

    • T

      Is pkg.pfsense.org down?

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      2
      0 Votes
      2 Posts
      144 Views
      T

      The repo seems to be back online today Jul 19th, I was able to complete the fresh install.

    • D

      Как скачать pfsense 2.8.0?

      Watching Ignoring Scheduled Pinned Locked Moved Russian
      3
      0 Votes
      3 Posts
      87 Views
      D

      @werter
      Благодарю за ссылки!
      Поток негатива на netinstaller уже пошёл.
      Задушат pf CE походу...

    • A

      25.07 RC - Multiple Default Gateways

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      1
      0 Votes
      1 Posts
      13 Views
      No one has replied
    • P

      Now Available: pfSense® CE 2.8.0-RELEASE

      Watching Ignoring Scheduled Pinned Locked Moved Messages from the pfSense Team
      113
      12 Votes
      113 Posts
      19k Views
      O

      I find it annoying that the Netgate Installer makes you configure your LAN and WAN interfaces, then after installing pfSense CE you need to configure them again.

    • C

      External leased /24 class

      Watching Ignoring Scheduled Pinned Locked Moved Routing and Multi WAN
      1
      0 Votes
      1 Posts
      33 Views
      No one has replied
    • S

      Using VTI IPsec to bypass managed office NAT

      Watching Ignoring Scheduled Pinned Locked Moved IPsec
      1
      0 Votes
      1 Posts
      9 Views
      No one has replied
    • J

      Wireguard Failover

      Watching Ignoring Scheduled Pinned Locked Moved WireGuard
      1
      0 Votes
      1 Posts
      30 Views
      No one has replied
    • W

      DNSBL_Malicious not downloading

      Watching Ignoring Scheduled Pinned Locked Moved pfBlockerNG
      10
      0 Votes
      10 Posts
      482 Views
      W

      @qinn
      Sent him an email Dan an email to the address on his site.. Not sure what is happening, my Teams stopped working. Disable it/turn it off and the problem went away.

    • B

      Traffic Shaper Limiters just won't work - FQ_CoDel

      Watching Ignoring Scheduled Pinned Locked Moved Traffic Shaping
      12
      0 Votes
      12 Posts
      2k Views
      R

      @pfsvrb
      this was an issue on my system also..
      Target & Interval were default set to 0..
      change to 5 & 100 fixed it

    • Z

      GitLab CI (Docker on Proxmox LXC) Slow/Stuck with pfSense DHCP - Works with Static IP

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      2
      0 Votes
      2 Posts
      32 Views
      stephenw10S

      Do you see anything blocked in the firewall logs?

      Connectivity from that host is otherwise good?

      Is it using the same DNS server(s) when configured statically?

      Ultimately I would run a packet capture when you run the failing task and see what's actually failing there.

    • L

      How to update No-IP IPv6 (dynupdate.no-ip.com does not have an AAAA record)

      Watching Ignoring Scheduled Pinned Locked Moved DHCP and DNS
      12
      0 Votes
      12 Posts
      1k Views
      R

      @Lars_ said in How to update No-IP IPv6 (dynupdate.no-ip.com does not have an AAAA record):

      @SteveITS Determined testing pays off. It works now 🎉

      Same for
      dynupdate.no-ip.com/nic/update?hostname=thisismydomain.ddns.net&myip=%IP%
      with option "HTTP API DNS Options = Force IPv4 DNS Resolution" enabled.

      I was actually quite close. The solution is to update the AAAA record using IPv4:

      Service Type: Custom (v6)

      HTTP API DNS Options = Force IPv4 DNS Resolution

      Update URL:
      dynupdate.no-ip.com/nic/update?hostname=thisismydomain.ddns.net&myipv6=%IP%

      Note: It has to be &myipv6=, not &myip=

      Is this something that makes sense to be implemented in No-IP (v6) and No-IP (free-v6)? It would not work if IPv4 DNS resolution isn't available, but I guess that is not very common in the wild.

      Haven't found a way to tag this thread as SOLVED.

      This solution worked for me!

    • M

      No failover when Gateway is offline

      Watching Ignoring Scheduled Pinned Locked Moved HA/CARP/VIPs
      1
      0 Votes
      1 Posts
      22 Views
      No one has replied
    • D

      Strange behaviour with alias firewalling: Pass is logged but traffic is blocked

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      2
      0 Votes
      2 Posts
      79 Views
      D

      I managed to resolve my above issue and for anyone ending up with the same question:

      My issue was caused because of a colleague who added a floating rule, rejecting traffic coming form another alias with logging disabled on that rule. Unfortunately that alias contained a different FQDN that resolved to the same IP of the removed FQDN.

      What is the important lesson here:

      Apparently the PF box handles floating rules AFTER interface rules. And since logging of that floating rule was disabled, the firewall log logged the allowed traffic from the interface rule, but blocked the traffic afterwards based on the floating rule with no logging! You end up seeing an allow in your log, but it is blocked in the end!

      This must be a culprit some else will face one day or another :)

    • N

      [2.8.0] Limiter rule not honored on LAN download with multiple limiters & queues

      Watching Ignoring Scheduled Pinned Locked Moved Traffic Shaping
      4
      0 Votes
      4 Posts
      362 Views
      D

      I'm experiencing this issue as well. I've been watching for patches and new releases to see if this is resolved.

    • S

      pfSense and Squid going forward?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      10
      0 Votes
      10 Posts
      374 Views
      JonathanLeeJ

      @JonathanLee https://github.com/pfsense/FreeBSD-ports/pull/1420

      I have tested this and it complies I do not know if anyone else has the ability to test this on pfsense dev mode but here is the pull that sets the Makefile to use Squid 7. I took a long long time to compile and it removes Auth for SMB_LM

    • JonathanLeeJ

      pfsense-tools.git clang gcc

      Watching Ignoring Scheduled Pinned Locked Moved Development clang gcc pfsense-tools
      12
      0 Votes
      12 Posts
      197 Views
      JonathanLeeJ

      If anyone wants to test this out

      https://github.com/pfsense/FreeBSD-ports/pull/1420

      I did get it to fully compile with the adapted Makefile they disable SMB_LM that has been removed

    • bmeeksB

      Important Info: Inline IPS Mode with Suricata and VLANs

      Watching Ignoring Scheduled Pinned Locked Moved IDS/IPS
      24
      3 Votes
      24 Posts
      6k Views
      cyb3rtr0nianC

      @bmeeks So after upgrading to the newest PfSense 2.8.0 everything is now working like a charm!

      Suricata no longer seems to strip off tags like it did before! Which means I can now use my network segmented by VLANs and still use the benefits of Suricata Inline IPS! Very niiize!

      I checked in the Alerts section and it is indeed generating the correct alerts from the different VLAN sections, I put Inline IPS on the parent interface of all the VLANs.

      I assume this is because the FreeBSD version is also updated with the new PfSense 2.8.0 version?

      Because before, as soon as I selected Inline IPS mode, my entire VLAN tagging would break and nothing was reachable until I switched back to Legacy mode.