Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    sshguard update question

    pfSense Packages
    4
    10
    613
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wgstarksW
      wgstarks
      last edited by

      When installing the recent update to sshguard I got the following message-

      You may need to manually remove /usr/local/etc/sshguard.conf if it is no longer needed.
      

      My question is, is this file just a remnant of a previous version that wasn't removed as a part of the update or will it be recreated constantly and I'll need to remove it with every update?
      Not sure why it must be removed manually?

      Box: SG-4200

      johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @wgstarks
        last edited by

        @wgstarks where did you upgrade sshguard - that is not part of the pfsense packages that I am aware of.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        wgstarksW 1 Reply Last reply Reply Quote 0
        • wgstarksW
          wgstarks @johnpoz
          last edited by

          @johnpoz
          I got a notification that there was an update available. I don’t remember installing the package. It’s possible that it was installed as part of CrowdSec if it’s not part of pfSense.

          Box: SG-4200

          johnpozJ 1 Reply Last reply Reply Quote 0
          • provelsP
            provels
            last edited by provels

            I saw the same. I got the notice through the update script. I also had crowdsec installed but had previously removed it. Didn't delete the .conf file referred to, though.

            From the pfSense Docs

            Login Protection¶
            
            pfSense software utilizes the sshguard daemon to protect against brute force logins for both the GUI and SSH connections. The options in this section fine-tune the behavior of this protection.
            
            Threshold:
            
                The total score value above which sshguard will block clients. Most attacks have a score of 10, the default threshold value is 30.
            
            

            Peder

            MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
            BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @wgstarks
              last edited by

              @wgstarks said in sshguard update question:

              I don’t remember installing the package

              yeah its not a addon package. Where did you get a notification - an email? a notice in pfsense, the little bell in the top right of the web gui?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              provelsP wgstarksW 2 Replies Last reply Reply Quote 0
              • provelsP
                provels @johnpoz
                last edited by

                @johnpoz I got it from this update script.

                Peder

                MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                1 Reply Last reply Reply Quote 0
                • wgstarksW
                  wgstarks @johnpoz
                  last edited by

                  @johnpoz said in sshguard update question:

                  @wgstarks said in sshguard update question:

                  I don’t remember installing the package

                  yeah its not a addon package. Where did you get a notification - an email? a notice in pfsense, the little bell in the top right of the web gui?

                  Auto Update Check

                  Box: SG-4200

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @wgstarks
                    last edited by

                    @wgstarks ah ok, I see it now..

                    [24.03-RELEASE][admin@sg4860.home.arpa]/root: pkg upgrade
                    Updating pfSense-core repository catalogue...
                    pfSense-core repository is up to date.
                    Updating pfSense repository catalogue...
                    pfSense repository is up to date.
                    All repositories are up to date.
                    Checking for upgrades (1 candidates): 100%
                    Processing candidates (1 candidates): 100%
                    The following 1 package(s) will be affected (of 0 checked):
                    
                    Installed packages to be UPGRADED:
                            sshguard: 2.4.3_1,1 -> 2.4.3_2,1 [pfSense]
                    
                    Number of packages to be upgraded: 1
                    
                    The process will require 2 MiB more space.
                    800 KiB to be downloaded.
                    
                    Proceed with this action? [y/N]: y
                    [1/1] Fetching sshguard-2.4.3_2,1.pkg: 100%  800 KiB 819.0kB/s    00:01    
                    Checking integrity... done (0 conflicting)
                    [1/1] Upgrading sshguard from 2.4.3_1,1 to 2.4.3_2,1...
                    [1/1] Extracting sshguard-2.4.3_2,1: 100%
                    You may need to manually remove /usr/local/etc/sshguard.conf if it is no longer needed.
                    [24.03-RELEASE][admin@sg4860.home.arpa]/root: 
                    

                    Yeah I wouldn't delete that.. notice the "may need" I would just leave it alone.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 2
                    • GertjanG
                      Gertjan @wgstarks
                      last edited by

                      @wgstarks said in sshguard update question:

                      You may need to manually remove /usr/local/etc/sshguard.conf if it is no longer needed.

                      A glitch of the update/upgrade process.
                      As this file probably doesn't contain default values, it wasn't removed, and the admin received a notification.
                      Worst case : you wind up with an orphan file ... no big deal.

                      But : the file /usr/local/etc/sshguard.conf is actually maintained (created, updated) by the pfSense GUI, as it contains these settings :

                      5f71a652-824b-494e-bcfc-e786f02658c3-image.png

                      Same for the the related /usr/local/etc/sshguard.whitelist file.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @Gertjan
                        last edited by

                        @Gertjan

                        @wgstarks : you double clicked posted ?

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.