Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • W

      Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions ntopng
      3
      0 Votes
      3 Posts
      155 Views
      W

      @dennypage said in Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?:

      @wolffire said in Is it possible to prevent installed packages (e.g. ntopng) from accessing the Internet?:

      I really like ntopng, but I'd rather it not be able to access the internet whenever it wants.

      Is it possible to block package processes from doing so?

      You can't block individual packages. The closest you could get is to find the domain or addresses the package is accessing and block those.

      With specific regard to ntopng, I haven't examined all the callouts but I don't recall it doing much unless you were using the licensed version (activation check), or had one of ntopng's "active" modes enabled.

      Make sure you have Active Network Discovery disabled in ntopng. It's in Settings / Preferences / Network Discovery / Active Network Discovery. This option should never be enabled on pfSense. Ditto for Active Monitoring.

      Thanks for the quick answer.

      I'm a little surprised about not being able to lockdown individual processes for those 'who watches the watcher?' types of situations. Finding a dynamic workaround will be painful.

      As far as ntopng, I just don't want it to be able do anything online unless I've configured it to do so; I loath the idea of telemetry being sent off to various companies.
      Not that I've found anything (I haven't taken a serious look yet); I'm just a bit weary.

      Speaking of the settings, after reading that post about inadvertently scanning the Internet, I definitely ensured active monitoring and network discovery was turned off. 😆

    • P

      update from 25.07 beta to 25.07 RC

      Watching Ignoring Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
      4
      0 Votes
      4 Posts
      198 Views
      GertjanG

      @PiAxel said in update from 25.07 beta to 25.07 RC:

      The last version doesn't work for me!

      ??

      How do you know that the latest version doesn't work for you, before installing that latest version ?

      ( 😊 )

    • R

      Can't create schedule | "The schedule must have at least one time range configured."

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      3
      0 Votes
      3 Posts
      72 Views
      R

      @patient0 OK, that helped. I'm fairly certain I had tried clicking Add time before and it hadn't worked - with the error I previously reported. In any case, it worked for me now. Thank you!

    • dennypageD

      Has the 25.07 RC been withdrawn?

      Watching Ignoring Scheduled Pinned Locked Moved Development
      3
      3 Votes
      3 Posts
      180 Views
      dennypageD

      @cmcdonald Appears to be back/fixed. Thanks.

    • Bob.DigB

      The if_pppoe backend does not support all advanced features of the MPD implementation

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      0 Votes
      2 Posts
      42 Views
      RobbieTTR

      @Bob-Dig

      Needing a periodic reset every night does sound slightly odd but can you not reset what you need to via Chron?

      ☕️

    • B

      Nintendo Switches (2) - Getting NAT type D and connection issues

      Watching Ignoring Scheduled Pinned Locked Moved Gaming
      5
      0 Votes
      5 Posts
      686 Views
      B

      @LukasInCloud - not sure what the difference was, but disabled the Wire Guard instance, fixed the issue. I think I may have updated it, but I was able to restart the vpn instance and have not had any issues since, even though I didn't change any settings to the vpn connection.

    • I

      Restringir horário openvpn

      Watching Ignoring Scheduled Pinned Locked Moved Portuguese
      2
      0 Votes
      2 Posts
      51 Views
      acamouraA

      @ivanz você pode criar um agendamento em schedules e depois na regra de aceitar a conexão do OpenVPN na sua porta WAN do pfSense você aplicar a mesma nas opções avançadas da regra de aceitar a conexão do seu servidor de VPN o horário criado para ser aplicado.

      24eeadd0-9c0b-41c6-9074-2030244f94d4-image.png

      bcbc9e86-0248-45be-9e4c-e4859f78639c-image.png

      4d8018b2-3997-4ba5-889c-93eba6b2823a-image.png

    • N

      Advice on SFP+ modules for 6100

      Watching Ignoring Scheduled Pinned Locked Moved Hardware
      4
      0 Votes
      4 Posts
      312 Views
      N

      No, just ordered from Amazon.

    • M

      New pfSense Plus 25.03-BETA is here!

      Watching Ignoring Scheduled Pinned Locked Moved Messages from the pfSense Team
      55
      2 Votes
      55 Posts
      11k Views
      GertjanG

      @Gcon said in New pfSense Plus 25.03-BETA is here!:

      So if you introduce support in CE first, and then much later in Plus ...

      Probably because Plus uses 15.0 which isn't officially released yet. The latest official release is FreeBSD 14.3.
      So, afaik, driver writers (Intel ?) aren't done adapting yet.

    • J

      SG-1100 eMMC Lifetime UP

      Watching Ignoring Scheduled Pinned Locked Moved Official Netgate® Hardware
      14
      0 Votes
      14 Posts
      1k Views
      stephenw10S

      Nice. 👍

    • D

      Strange behaviour with alias firewalling: Pass is logged but traffic is blocked

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      2
      0 Votes
      2 Posts
      91 Views
      D

      I managed to resolve my above issue and for anyone ending up with the same question:

      My issue was caused because of a colleague who added a floating rule, rejecting traffic coming form another alias with logging disabled on that rule. Unfortunately that alias contained a different FQDN that resolved to the same IP of the removed FQDN.

      What is the important lesson here:

      Apparently the PF box handles floating rules AFTER interface rules. And since logging of that floating rule was disabled, the firewall log logged the allowed traffic from the interface rule, but blocked the traffic afterwards based on the floating rule with no logging! You end up seeing an allow in your log, but it is blocked in the end!

      This must be a culprit some else will face one day or another :)

    • A

      AutoBackup Device Key

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      2
      0 Votes
      2 Posts
      142 Views
      stephenw10S

      Do you have the NDI from the device? If you send that to me in chat I can check for an ACB key.

    • P

      IPv6 disconnects after 1 minute on some LAN clients (pfSense Plus 24.11)

      Watching Ignoring Scheduled Pinned Locked Moved IPv6
      2
      0 Votes
      2 Posts
      42 Views
      U

      What is the difference between the device/PC that IPV6 works on and the ones that don’t? I would start with looking at the IPV6 settings on the devices/PCs that are having problems. I’m going to guess that your router advertisements are managed. Try stateless DHCP advertisements and see if that solves your problem.

    • M

      System - Package Manager - Available Packages

      Watching Ignoring Scheduled Pinned Locked Moved Italiano
      2
      0 Votes
      2 Posts
      38 Views
      C

      Sulla web GUI di pfSense vai in diagnostica e poi in command prompt,nella casella execute shell command digita il seguente comando: certctl rehash
      Attendi un output e poi ricontrolla gli aggiornamenti o i pacchetti e dovrebbe funzionare.
      pfSense 2.7.0 è una versione vecchia,quindi penso dovresti aggiornare alla versione 2.7.2 e poi alla versione 2.8.0,prima di fare qualsiasi cosa ricordati di salvare il file XML della configurazione attuale di pfSense.

      Saluti

    • luckman212L

      25.07.r.20250715.1733 - incorrect help link on System → Advanced → Netgate Nexus

      Watching Ignoring Scheduled Pinned Locked Moved Plus 25.07 Develoment Snapshots
      2
      1 Votes
      2 Posts
      85 Views
      stephenw10S

      Hmm, I thought we'd fixed that. Let me see...

      Ah, maybe not: https://redmine.pfsense.org/issues/16207

    • M

      Issue with ACME Certificates Refresh & Restarting HAProxy

      Watching Ignoring Scheduled Pinned Locked Moved ACME acme haproxy
      5
      1 Votes
      5 Posts
      2k Views
      GertjanG

      @EChondo

      What's your pfSense version ?
      The instructions are shown here :

      1acdc586-cb29-4148-9e36-81ade4e5e60c-image.png

      A restart of a service will start by re creating their config files. If a certificate changed, it will get included. When the process starts, it will use the new certificate.

      @EChondo said in Issue with ACME Certificates Refresh & Restarting HAProxy:

      I haven't been able to confirm if the above works(mine just renewed, don't feel like doing it again just to test), so we'll see in 60 days I guess.

      No need to wait x days.
      You can re test / renew right away, as you are 'allowed' to renew a couple (5 max ?) of times per week.

    • J

      Installing 2.8 behind archaic PPPoE/VLAN from CenturyLink

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      5
      0 Votes
      5 Posts
      195 Views
      stephenw10S

      @jhg said in Installing 2.8 behind archaic PPPoE/VLAN from CenturyLink:

      Is this available yet?

      It's in testing now. No issues so far so should be available soon,

    • G

      Does this look like my pfSense was hacked

      Watching Ignoring Scheduled Pinned Locked Moved General pfSense Questions
      7
      0 Votes
      7 Posts
      3k Views
      GertjanG

      @luckman212

      Click on the image :

      1c8c8a2b-ed5f-4dd1-8694-8be0e58350e8-image.png

      I didn't test other search engines ...

      edit : the link @kpa posted is, imho, the best answer ( and totally not-FreeBSD related ^^ ).

    • A

      Firewall rule order is being changed every reboot.

      Watching Ignoring Scheduled Pinned Locked Moved Firewalling
      2
      0 Votes
      2 Posts
      67 Views
      S

      @aaronouthier There was a bug in 24.3/11 where deleting multiple rules would reorder them. There’s a patch.

      But otherwise no it’s not normal at a reboot. Maybe compare config files before and after?

    • P

      new PPPoE kernel - Suricata not working

      Watching Ignoring Scheduled Pinned Locked Moved IDS/IPS
      2
      0 Votes
      2 Posts
      72 Views
      bmeeksB

      I saw where the Netgate kernel developer updated the Suricata package in the pfSense 25.07 development branch to work with the new kernel PPPoE driver. But so far as I know that updated package has not been migrated to 2.8 CE.

      Here is the commit into the DEVEL branch: https://github.com/pfsense/FreeBSD-ports/commit/68a06b3a33c690042b61fb4ccfe96f3138e83b72.