Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Failed to retrieve package or update following a manual install of ntopng 5.1

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    16 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thwong
      last edited by

      Sorry for not knowing well the FreeBSD system. Following a manual ntopng 5.1 installation, I seem to have corrupted the repo and couldn't retrieve any updates or packages. I have performed a 'factory reset' but the system still failed to retrieve any update.

      Below is the output when I manually run update from the console.

       0) Logout (SSH only)                  9) pfTop
       1) Assign Interfaces                 10) Filter Logs
       2) Set interface(s) IP address       11) Restart webConfigurator
       3) Reset webConfigurator password    12) PHP shell + Netgate pfSense Plus tools
       4) Reset to factory defaults         13) Update from console
       5) Reboot system                     14) Disable Secure Shell (sshd)
       6) Halt system                       15) Restore recent configuration
       7) Ping host                         16) Restart PHP-FPM
       8) Shell
      
      Enter an option: 13
      
      >>> Updating repositories metadata...
      Updating ntop repository catalogue...
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      pkg-static: https://packages.ntop.org/FreeBSD/FreeBSD:12:amd64/latest/meta.txz: Authentication error
      repository ntop has no meta file, using default settings
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      Certificate verification failed for /CN=packages.ntop.org
      34369421312:error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed:/var/jenkins/workspace/pfSense-build-release-tarballs/BUILD_NODE/pkg-amd64/OS_MAJOR_VERSION/freebsd12/PLATFORM/aws/crypto/openssl/ssl/statem/statem_clnt.c:1915:
      pkg-static: https://packages.ntop.org/FreeBSD/FreeBSD:12:amd64/latest/packagesite.txz: Authentication error
      Unable to update repository ntop
      Updating pfSense-core repository catalogue...
      Fetching meta.conf: . done
      Fetching packagesite.txz: . done
      Processing entries: .. done
      pfSense-core repository update completed. 14 packages processed.
      Updating pfSense repository catalogue...
      Fetching meta.conf: . done
      Fetching packagesite.txz: .......... done
      Processing entries:
      Processing entries............. done
      pfSense repository update completed. 528 packages processed.
      Error updating repositories!
      ERROR: Unable to compare version of pfSense-repo
      Netgate SG-5100 - Serial: NG202104008217 - Netgate Device ID: 35adf34c7104fc274f17
      

      Could someone please shed me a light to get my sg-5100 back to normal?

      V GertjanG 2 Replies Last reply Reply Quote 0
      • V
        viragomann @thwong
        last edited by

        @thwong
        If you're still on an outdated pfSense version maybe this thread helps: https://forum.netgate.com/topic/166905/pfsense-2-4-5-cannot-curl-letsencrypt-website-since-dst-root-ca-x3-expiration/3

        T 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @thwong
          last edited by

          @thwong said in Failed to retrieve package or update following a manual install of ntopng 5.1:

          /var/jenkins/workspace

          ...... that's a May Day - not a Pan Pan.

          The system has been edited manually, which is perfectly fine, but this :

          for not knowing well the FreeBSD system.

          makes a

          manual ntopng 5.1 installation,

          a big no-go.

          Experts do expert things. Others do other things.
          I'm mean, it might be possible to do what you want, but you have to deal with the consequences, which are pretty unknown upfront.
          For example, the "ntopng 5.1" should be based on FreeBSD 12.2.
          This package can pull in other packages, can can actually upgrade pfSense FreeBSD packages, so chances are that they break.

          The original "ntopng 5.1" has not a GUI interface - and most surely not a pfSEnse GUI style interface.

          This means you wind up setting everything from the command line.
          I wouldn't do that on a pfSense, but on a vanilla FreeBSD.

          have performed a 'factory reset'

          That will reset default parameters, not repair system files.

          I advise you to manually (you win ๐Ÿ˜Š ) re install pfSense.
          ntopng is possible, but it will be this one :

          d3cd15c3-4d37-48ee-873e-d2db7d578c85-image.png

          as it is the latest version that came out for FreeBSD 12.2 - the version pfSense 52.5.2 uses.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          T 1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by jimp

            If you want ntopng 5.x, then you can run pfSense Plus 22.01 snapshots on that 5100. It has ntopng 5.0.

            As you have found out the fun way, manually installing packages from other repositories causes numerous problems and it's one of the reasons we discourage the practice.

            The 22.01 snapshots are quite stable these days, I run it on my edge at home and update it every week or so, and it has yet to fail me. But YMMV. 2.6.0 is similarly stable if you run CE, but if you have a 5100 then run Plus.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            T 2 Replies Last reply Reply Quote 0
            • T
              thwong @viragomann
              last edited by

              @viragomann Thanks for your suggestion. I'm running 21.05.1 which seems to be the latest one. :(

              1 Reply Last reply Reply Quote 0
              • T
                thwong @Gertjan
                last edited by

                @gertjan Thanks mate for the feedback. nTopng did save me at least a $100 in the coming few months. nTopng 0.8 may not have the feature that I need to monitor suspicious and unexpected traffic.

                I'm not going to be an expert of Linux as being a network professional. Probably I should be back to where I was.

                1 Reply Last reply Reply Quote 0
                • T
                  thwong @jimp
                  last edited by

                  @jimp Thanks mate. I found 21.05 has a ntopng package of 4.x which doesn't come with the feature that I need. For now, I think I would be happy to have everything resumed with 4.x until it has a 'standard' 5.x package.

                  1 Reply Last reply Reply Quote 0
                  • T
                    thwong
                    last edited by

                    Wanna end this thread and the easy fix for me is to:

                    1. remove the ntopng packages.
                    2. update all the packages.
                    3. restart the firewall.
                    1 Reply Last reply Reply Quote 0
                    • T
                      thwong @jimp
                      last edited by

                      @jimp Thanks for mentioning the 21.02. I tried the development one and it still showing ntopng 4.0 community.
                      In shell, I got the following from 'ntopng -V'.

                      Version: 4.0.0 [Community build]
                      GIT rev: :5.0.211014

                      Thinking the package's built from 5.0. I either manually install ntopng 5.0 or get ntop to refund me the license I purchase. Seems there isn't an ideal solution for me.

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        I had a typo above, it should be 22.01 snapshots, not 21.02.

                        This is from a firewall running a 22.01 snapshot:

                        90f6a6f5-0439-47aa-ab88-dc9807e8bdf5-image.png

                        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        T 1 Reply Last reply Reply Quote 1
                        • T
                          thwong @jimp
                          last edited by

                          @jimp Thanks for the screenshot. The GUI appearance is v5.0 but it's somehow showing community version 4.0 that doesn't recognize my license. I had a word with nTop and they said pfsense ntop package should be still v4.0 and therefore cannot recognise my license which is in 5.0 format.

                          I'm running 22.01 development build and manually run ntopng 5.1 at my own risk because I really need it for improving my Internet usage at a lower cost to save the money I put it in buying the nTop license.

                          The broken pfsense repo can be recovered when I manually remove all the ntop related packages.

                          The following screen is from pfsense+ ntopng package.
                          Screen Shot 2021-11-15 at 23.43.12.png

                          The following screen is from ntop's ntopng package.
                          Screen Shot 2021-11-16 at 01.50.00.png

                          1 Reply Last reply Reply Quote 0
                          • jimpJ
                            jimp Rebel Alliance Developer Netgate
                            last edited by

                            Then something else must be wrong in your system.

                            I'd suggest first trying it in an isolated setup, like a test VM running a 22.01 snapshot.

                            The ntopng package is definitely 5.x on 22.01, if you are seeing 4.x, then it isn't installing properly, likely due to other changes you've made on there.

                            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            T 2 Replies Last reply Reply Quote 1
                            • T
                              thwong @jimp
                              last edited by

                              @jimp Thanks for your suggestion. I am not a Linux guru and have no idea to run pfsense in a VM. The only I could try is to:

                              1. remove all ntop packages
                              2. remove all ntop directories
                              3. remove all ntop configuration in the system
                              4. remove the ntop repo
                              5. install ntop from pfsense repo

                              Will give it a try later this week.

                              GertjanG 1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan @thwong
                                last edited by

                                @thwong said in Failed to retrieve package or update following a manual install of ntopng 5.1:

                                I am not a Linux guru and have no idea to run pfsense in a VM.

                                If, by any chance, you have a Windows 10 Pro system some where, you don't need any 'Linux' knowledge (actually worse, now you need Microsoft knowledge ...).

                                It goes like this " Virtualizing pfSense with Hyper-V Virtualizing pfSense with Hyper-V ".
                                Or take a look at several step-by-step youtube videos. Look at more then one !

                                I'll add in some advise :
                                Use at least 2 NIC's, which probably means you have a slide an extra network card.
                                Don't even think you can use an USB-NIC. Just don't ;)
                                One NIC will be your LAN, the other will be solely reserved for the VM and will be WAN.

                                It's pretty straight forward, and very nice to test thing out using close to zero extra hardware.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                T 1 Reply Last reply Reply Quote 1
                                • T
                                  thwong @Gertjan
                                  last edited by

                                  @gertjan Thanks mate for your advice. I will see if my daughter's Surface running Windows 10 Pro or not. All my systems are running OSX (Intel or M1). I recalled I run VirtualBox a long time ago for Arista switch stuff. Will see what I can do.

                                  1 Reply Last reply Reply Quote 0
                                  • T
                                    thwong @jimp
                                    last edited by

                                    @jimp I did the following and still without luck to get the v5.0 running.

                                    • removal of all ntop packages
                                    • deletion of all ntop folders
                                    • reinstall ntopng package

                                    However, I can tell the interface is looking like v5.0. v4.0 wouldn't be giving me some screens that I'm familiar with. At least my company is running both v4.2 and v5.1 so I could identify the difference.

                                    I hope I have a chance to get it up in a VM. Or perhaps if I can pay to get it fixed because I run out of time for work.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.