Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Packages wishlist?

    pfSense Packages
    384
    661
    1.4m
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      g0dsp33d
      last edited by

      One I always liked and it was a pain in the ass to configure and to setup Squid with Squid Guard.

      Maybe there is a better content filter out there but SquidGuard seemed to work fairly well.

      I know of a lot of buisnesses/clients that love to have either reality/pornographic/sports/etc/etc websites filtered. Although I havn't messed with SquidGuard in some time it had no Auto Blacklist to update. I did however right a script to grab one from my FTP server ever week when it was updated.

      1 Reply Last reply Reply Quote 0
      • R
        ruskie
        last edited by

        I'd like to see gkrellmd(the X11-less daemon only) and bfilter(an ad/script/img blocking proxy).

        Atm I have a gkrellm(thanks to some very nice people from irc) installed but it's lacking an interface to configure it via the web configurator.

        1 Reply Last reply Reply Quote 0
        • A
          agismaniax
          last edited by

          I've found www.ipp2p.org for iptables/netfilter.
          Is there any packages can do blocking p2p filesharing traffic in FreeBSD/pfSense?

          1 Reply Last reply Reply Quote 0
          • L
            lsf
            last edited by

            Snort would be able to do this, also a layer7 filter of some sort would also be able to do this.
            P2P is in general hard to filter out as it tends to use whatever port it can get it's hands on (like www port 80).
            You need either a raw packet filter, or a layer7 filter.
            At this point there is no way to effectively block P2P in pfsense.

            -lsf

            1 Reply Last reply Reply Quote 0
            • R
              rexster
              last edited by

              i like to see a complete packages (tftpd,nfs,etc…) to allow diskless/pxe client boot into something like thinstation or puppy or others...

              like these ones:
              thinstation.sf.net
              http://forums.freesco.org/support/index.php?showtopic=13170&st=45&#entry74098

              http://www.GoBlogLah.com

              1 Reply Last reply Reply Quote 0
              • A
                Aderium
                last edited by

                Nagios would be a good package

                Anthony Palermo

                1 Reply Last reply Reply Quote 0
                • M
                  mbedyn
                  last edited by

                  I wonder, is it possible to add to RDD graph some new options such a wireless client's statistics… ::)
                  I mean statistics about connections in time period.

                  1 Reply Last reply Reply Quote 0
                  • D
                    doush
                    last edited by

                    @agismaniax:

                    I've found www.ipp2p.org for iptables/netfilter.
                    Is there any packages can do blocking p2p filesharing traffic in FreeBSD/pfSense?

                    Yes my vote also goes to a Layer 7 filter.. Also  Snort is quite good to block P2P, at least we know how to use it. ;)
                    But an embedded option for blocking P2P in pfSense it self is the most desirable.

                    1 Reply Last reply Reply Quote 0
                    • D
                      doncipo
                      last edited by

                      Hello ppl. ! I will like to see HAVP+ClamAV+Dansguardian as content filter, Snort as IDS, OpenVPN as VPN default app., AdvancedProxy+Calamaris+URLFilter. Smoothwall, IPCop and EndianFirewall already have these.

                      1 Reply Last reply Reply Quote 0
                      • B
                        buraglio
                        last edited by

                        @Aderium:

                        Nagios would be a good package

                        What about something like NRPE (nagios remote plugin executor) and the plugins?  Useful for checking stuff behind the NAT and/or firewall from an external nagios install.

                        https://www.forwardingplane.net/

                        1 Reply Last reply Reply Quote 0
                        • M
                          Master One
                          last edited by

                          I find it difficult to determine, what else should be running on the firewall machine. If squid is on, I'd suggest the following should be as well:

                          Privoxy: web proxy with advanced filtering capabilities for protecting privacy, modifying web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk. Privoxy has a very flexible configuration and can be customized to suit individual needs and tastes. Privoxy has application for both stand-alone systems and multi-user networks.

                          Tor: toolset for a wide range of organizations and people that want to improve their safety and security on the Internet. Using Tor can help you anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol. Tor also provides a platform on which software developers can build new applications with built-in anonymity, safety, and privacy features.

                          1 Reply Last reply Reply Quote 0
                          • M
                            Master One
                            last edited by

                            Oh, forgot one thing which may be quite important:

                            APCUPSD: You definitely also want your firewall machine hanging on your UPS, if you performed a full installation on a harddrive.

                            1 Reply Last reply Reply Quote 0
                            • M
                              mastrboy
                              last edited by

                              a dshield package, and a fixed freeradius package with webgui integration

                              1 Reply Last reply Reply Quote 0
                              • B
                                buraglio
                                last edited by

                                @buraglio:

                                @Aderium:

                                Nagios would be a good package

                                What about something like NRPE (nagios remote plugin executor) and the plugins?  Useful for checking stuff behind the NAT and/or firewall from an external nagios install.

                                Would people find these useful?  NRPE and some plugins?  What plugins would be most useful (other than check_ping)

                                https://www.forwardingplane.net/

                                1 Reply Last reply Reply Quote 0
                                • S
                                  sullrich
                                  last edited by

                                  I'd like to see more package maintainers.  This pie in the sky discussion is great but there is nobody to implement these ideas.

                                  1 Reply Last reply Reply Quote 0
                                  • R
                                    rafael.cardoso
                                    last edited by

                                    Any idea for SARG (Squid Analysis Report Generator)!

                                    Respect is Everything!

                                    1 Reply Last reply Reply Quote 0
                                    • T
                                      timb0311
                                      last edited by

                                      POUND - REVERSE-PROXY AND LOAD-BALANCER
                                      http://www.apsis.ch/pound/

                                      The Pound program is a reverse proxy, load balancer and HTTPS front-end for Web server(s). Pound was developed to enable distributing the load among several Web-servers and to allow for a convenient SSL wrapper for those Web servers that do not offer it natively. Pound is distributed under the GPL - no warranty, it's free to use, copy and give away.

                                      This would be good for running mutiple web servers with limited IPs or just plain old load balancing for applications.  Can route HTTP request to backend web server based on domain/host name.

                                      1 Reply Last reply Reply Quote 0
                                      • M
                                        mdepot
                                        last edited by

                                        My wishlist would be improvements to:

                                        * Web Proxy Content Filtering
                                          * Web & Email Anti-Virus Scanning Proxies

                                        Proxy filtering has been tossed around quite a bit, notably with SquidGuard, but looking for a solution that checks based on actual content scanning (as opposed to just list checking).  Something similar to DansGuardian (but with a more open licence) would be great.  And if we're scanning the content anyway, it would be great if virus signature scanning could be done at the same time.

                                        It would also be nice to have a lightweight (relative to sendmail/postfix anyway) SMTP reverse proxy capable of scanning email for junk and virus signatures.  This would be a transparent reverse proxy for SMTP (& SMTPS?), preventing junk mail and virus emails from ever making it to the mail servers inside.  (Check out ASSP and DspamPD if you're looking to get a better idea of the concept.)

                                        Both of these wishlist ideas are not exactly 'lightweight' and may not belong on a box that's strictly a firewall, but they do both protect the inside from the outside, and would be a good fit for many smaller orgs without dedicated resources for these.

                                        1 Reply Last reply Reply Quote 0
                                        • K
                                          kferguson
                                          last edited by

                                          I'd like an interface to allow creation of firewall rules based on GEOIP data.  Many organizations provide services within a limited geographical area, and could live without all the traffic from regions outside those service areas.  I've seen examples of pf implementations, but I'm not sure what would be required to integrate this functionality into pfsense.

                                          Kirk

                                          1 Reply Last reply Reply Quote 0
                                          • H
                                            hoba
                                            last edited by

                                            @kferguson:

                                            I'd like an interface to allow creation of firewall rules based on GEOIP data.  Many organizations provide services within a limited geographical area, and could live without all the traffic from regions outside those service areas.  I've seen examples of pf implementations, but I'm not sure what would be required to integrate this functionality into pfsense.

                                            Kirk

                                            That might be quite easy with the uopcoming alias features of pfSense (already implemented in the HEAD tree), where you can update your aliases frequently by downloading an external file (see http://pfsense.com/~sullrich/pics/SampleAlias.PNG for a screenshot of that already implemented feature).

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.