Packages wishlist?
-
IPTraf is a pretty useful realtime network monitoring package
Check the consolemenu or ssh in. Try the pftop option. It's similiar to this.
Not that good as IPtraf…. IPtraf shows for example number of pkt per second, statistics for interrested port, protocol etc..
It's very usefull and powerfull tool. IMHO
;-)press h. left right arrow and so on. sounds like you haven'T seen all the pages/infos yet
-
has an asterisk package been talked about? a package where you could have have a 2nd pfsense box running asterisk? or even run it on the same machine as your firewall which would make life a bit easier.
-
Yeah, its been tossed around. I would like to see one get going at some point. I've got some files started but they are a little dated and the structure really wasn't that hot.
With that said, if someone wants to work on this and wants to use these, I can try to dig them up. In fact, I would help out with this but I am looking for someone to "own" this package and maintain it.
-
Well my vote goes to Quagga, or at least some kind of RIP/OSPF supporting routing daemon. Purely for use on VPN's, of course!
I've just spotted that it's in ports, but a web extension for it would be nice. I did a package of Quagga for smoothwall a while back (web bit didn't work though, but never got round to fixing it) so I might try and do something for pfSense.
-
Well my vote goes to Quagga, or at least some kind of RIP/OSPF supporting routing daemon. Purely for use on VPN's, of course!
I've just spotted that it's in ports, but a web extension for it would be nice. I did a package of Quagga for smoothwall a while back (web bit didn't work though, but never got round to fixing it) so I might try and do something for pfSense.
Yes, please do! If you want to take over the package it currently does not have a maintainer.
-
IPtraf is not a BSD util. Its linux, and it's a ugly hack imo. ;)
-
mmm IDS like snort and adaptive firewalling capabilities like snort-sam
i.e. kiddie starts scanning me, ids generates firewall rules to block kiddie before he hits my open ports / or temporarily 'hides' those ports.
-
Well my vote goes to Quagga, or at least some kind of RIP/OSPF supporting routing daemon. Purely for use on VPN's, of course!
I've just spotted that it's in ports, but a web extension for it would be nice. I did a package of Quagga for smoothwall a while back (web bit didn't work though, but never got round to fixing it) so I might try and do something for pfSense.
Yes, please do! If you want to take over the package it currently does not have a maintainer.
I'll start having a crack at it today then, my BSD isn't a patch on my Linux but I'm sure I can muddle through ;)
-
http://www.pfsense.com/~sullrich/pfSenseDevelopersVMWareEdition.7z may help…. Full dev environment in vmware.
-
I know this isn't what you want on a firewall normally, but I would like to see a samba client along with rsync for remote backups (I guess with a cron scheduler) through the firewall to a local windows machine.
I know it would be better to have a seperate machine, but it's just not feasible in my friends enviroment at the time. I've been using a Linux based firewall/server installation at his location, but it's several releases back and I can't upgrade it remotely. pfSense of course is my choice for a firewall, and with just these few features it would fit perfectly in that enviroment, and I'd always be able to remotely maintain the firewall.
Likely I could just add the packages, but then they would get wiped out with each upgrade…
-
Likely I could just add the packages, but then they would get wiped out with each upgrade…
No they won't not unless your doing a clean install. I have Been running a jabber server on my pfSense box that survived several upgrades.
Likewise, I didnt want to get a separate box just to run a jabber server, so I just installed and configured it on my firewall. -
Oh, okay, that's cool, I didn't know that!! ::)
Thanks Leoandru!
-
Okay, I've tried this out on my own pfSense FW, I can install the packages no problem. I guess I need to make a custom kernel however, because there is now smbfs.ko to be loaded. I tried just copying one from my freebsd system, but that doesn't work. I've built a kernel before, but just with very basic changes. What would I have to do to build the pfSense kernel with only the addition of that one module? Where do I specify for it to build that module?
Thanks for your help…
-
Some form of packet capturing for use with Ethereal would be incredible!
-
This might be possible for a package?
Is there a way, (or possible) to have pfSense put IP addresses of people in a sort of temporary pool that will block all access from them, if they say lauch an attack against the router.
Multiple attempts to attack the router results in a 6 hour ban. Something of that sort.
-
This might be possible for a package?
Is there a way, (or possible) to have pfSense put IP addresses of people in a sort of temporary pool that will block all access from them, if they say lauch an attack against the router.
Multiple attempts to attack the router results in a 6 hour ban. Something of that sort.
That's possible with Snort. However, it's not always desirable to run an IDS in your firewall. Besides, if you have to use such a system, you should be confortable enough to implement it manually, without GUIs.
-
No they won't not unless your doing a clean install. I have Been running a jabber server on my pfSense box that survived several upgrades.
Likewise, I didnt want to get a separate box just to run a jabber server, so I just installed and configured it on my firewall.maybe you could publish the package for the community to use?
-
Anything custom that starts from /usr/local/etc/rc.d/ is not touched during upgrades.
This is basically the package area (/usr/local/).
You are pretty safe in adding you own startup files in /usr/local/etc/rc.d/*.sh … We do not touch them during upgrade.
-
I think it would be great to see a package for myNetWatchman (http://www.mynetwatchman.com) if possible. That and perhaps SFTP :-[
-
-
SFTP is already in, it's part of SSH.
This is true, but I'd like to know how to use an SFTP client when the menu is presented after every SSH login…
-
login true a sftp client
then you don't get that ssh menu -
I'm not sure if this can be done but some sort of log reporting package which would generate a couple web pages on the statistics….kinda like awstats with a builtin syslog thing....sorta hard to describe but would be cool.
-
login true a sftp client
then you don't get that ssh menuI've tried gftp, putty-tools, hsftp and the sftp binary all with the same result - what would you recommend for a linux sftp client?
-
login true a sftp client
then you don't get that ssh menuI've tried gftp, putty-tools, hsftp and the sftp binary all with the same result - what would you recommend for a linux sftp client?
gftp works. Double check your configuration.
-
One I always liked and it was a pain in the ass to configure and to setup Squid with Squid Guard.
Maybe there is a better content filter out there but SquidGuard seemed to work fairly well.
I know of a lot of buisnesses/clients that love to have either reality/pornographic/sports/etc/etc websites filtered. Although I havn't messed with SquidGuard in some time it had no Auto Blacklist to update. I did however right a script to grab one from my FTP server ever week when it was updated.
-
I'd like to see gkrellmd(the X11-less daemon only) and bfilter(an ad/script/img blocking proxy).
Atm I have a gkrellm(thanks to some very nice people from irc) installed but it's lacking an interface to configure it via the web configurator.
-
I've found www.ipp2p.org for iptables/netfilter.
Is there any packages can do blocking p2p filesharing traffic in FreeBSD/pfSense? -
Snort would be able to do this, also a layer7 filter of some sort would also be able to do this.
P2P is in general hard to filter out as it tends to use whatever port it can get it's hands on (like www port 80).
You need either a raw packet filter, or a layer7 filter.
At this point there is no way to effectively block P2P in pfsense. -
i like to see a complete packages (tftpd,nfs,etc…) to allow diskless/pxe client boot into something like thinstation or puppy or others...
like these ones:
thinstation.sf.net
http://forums.freesco.org/support/index.php?showtopic=13170&st=45&#entry74098 -
Nagios would be a good package
-
I wonder, is it possible to add to RDD graph some new options such a wireless client's statistics… ::)
I mean statistics about connections in time period. -
I've found www.ipp2p.org for iptables/netfilter.
Is there any packages can do blocking p2p filesharing traffic in FreeBSD/pfSense?Yes my vote also goes to a Layer 7 filter.. Also Snort is quite good to block P2P, at least we know how to use it. ;)
But an embedded option for blocking P2P in pfSense it self is the most desirable. -
Hello ppl. ! I will like to see HAVP+ClamAV+Dansguardian as content filter, Snort as IDS, OpenVPN as VPN default app., AdvancedProxy+Calamaris+URLFilter. Smoothwall, IPCop and EndianFirewall already have these.
-
Nagios would be a good package
What about something like NRPE (nagios remote plugin executor) and the plugins? Useful for checking stuff behind the NAT and/or firewall from an external nagios install.
-
I find it difficult to determine, what else should be running on the firewall machine. If squid is on, I'd suggest the following should be as well:
Privoxy: web proxy with advanced filtering capabilities for protecting privacy, modifying web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk. Privoxy has a very flexible configuration and can be customized to suit individual needs and tastes. Privoxy has application for both stand-alone systems and multi-user networks.
Tor: toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.
-
Oh, forgot one thing which may be quite important:
APCUPSD: You definitely also want your firewall machine hanging on your UPS, if you performed a full installation on a harddrive.
-
a dshield package, and a fixed freeradius package with webgui integration
-
Nagios would be a good package
What about something like NRPE (nagios remote plugin executor) and the plugins? Useful for checking stuff behind the NAT and/or firewall from an external nagios install.
Would people find these useful? NRPE and some plugins? What plugins would be most useful (other than check_ping)
-
I'd like to see more package maintainers. This pie in the sky discussion is great but there is nobody to implement these ideas.