• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Packages wishlist?

pfSense Packages
384
661
1.4m
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O
    oasisgate
    last edited by Oct 9, 2006, 12:17 AM

    the good service to addon pfsense…apcupsd for APC UPS...

    1 Reply Last reply Reply Quote 0
    • ?
      Guest
      last edited by Oct 9, 2006, 2:13 PM

      @mdepot:

      It would also be nice to have a lightweight (relative to sendmail/postfix anyway) SMTP reverse proxy capable of scanning email for junk and virus signatures.  This would be a transparent reverse proxy for SMTP (& SMTPS?), preventing junk mail and virus emails from ever making it to the mail servers inside.  (Check out ASSP and DspamPD if you're looking to get a better idea of the concept.

      ASSP doesn't support AV scanning and DspamPD hasn't been actively developed for over a year.

      1 Reply Last reply Reply Quote 0
      • G
        gbelanger
        last edited by Oct 17, 2006, 12:08 AM Oct 14, 2006, 7:05 AM

        I liked the idea of a 'voting system' for package suggestions. I would really like to see something out there to enforce corporate content-filtering policies. Right now, the squid package somewhat addresses the web side. The SMTP part is a bit less interesting unless you are putting the firewall in your production environment (as opposed to office) where it can behave as a server-side proxy. I have successfully used transparent POP3 proxying in the past. However, I dont think its a very clean way of doing email filtering.

        The one still missing from most distros is instant messaging proxying/filtering for the main clients (MSN/Yahoo/AOL/Google). This would allow for a complete content-filtering solution. (Web + IM, while mail is imparted). Note that some suggested antivirus support for the web proxy, this is fairly difficult to implement, and very unefficient. (Because the proxy cant really know if its a virus until the download is .. well.. done).

        As for SMTP filtering (SpamAssassin and such) - I do think that  spam filtering without a proper quarantaine solution is a bit wreckless. As such, I would be tempted to leave the spam filtering to a dedicated solution. However, blocking malicious code and extensions as well as defanging potentially dangerous dynamic content are all very feasible tasks. I myself would tend to focus on these features.

        Someone proposed bind as a package. I find the mention of bind running on a firewall a little disturbing =P I frankly don't really see the point of running DNS off a firewall. It seems somewhat off-focus.

        Just my 2 cents -

        1 Reply Last reply Reply Quote 0
        • A
          anystupidassname
          last edited by Oct 20, 2006, 2:20 AM

          Congrats on the gold release! I've been impressed with pfsense from the beginning when I discovered it from a m0n0wall source.

          My 2 cents on the packages wishlist:

          -FakeAP(http://www.blackalchemy.to/project/fakeap/)
          -Linblock (http://www.dessent.net/linblock/) this is really just a script but I have no clue how to implement it on BSD
          -A package allowing you to provide a one-time (expiring) link to a file download from the local freeNAS raid volumes (scawf if you want…)

          These were already talked about but I 2nd the request for these:
          snort
          nagios
          asterisk
          tftp/pxe capabilities
          dansguardian
          cups

          I saw these in the list pre 1.0 so I'm hoping they'll get re-added:
          freeradius
          freeNAS

          Thanks for listening!

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by Oct 24, 2006, 8:26 PM

            Snort is already included.  The TFTP/PXE proxy is in HEAD and should make its way to a future version.

            1 Reply Last reply Reply Quote 0
            • Y
              yoda715
              last edited by Nov 5, 2006, 2:40 AM

              I would like to see a content filter package using Dansguardian.

              1 Reply Last reply Reply Quote 0
              • B
                bluekkis
                last edited by Nov 5, 2006, 10:53 PM

                I'd like to see no-ip.com client as package for pfsense so I don't have to remember my ip address all the time, which isn't static anyway.

                1 Reply Last reply Reply Quote 0
                • H
                  hoba
                  last edited by Nov 5, 2006, 11:02 PM

                  @bluekkis:

                  I'd like to see no-ip.com client as package for pfsense so I don't have to remember my ip address all the time, which isn't static anyway.

                  It's already there: services>Dynamic DNS.

                  1 Reply Last reply Reply Quote 0
                  • B
                    bluekkis
                    last edited by Nov 6, 2006, 7:50 AM

                    @hoba:

                    @bluekkis:

                    I'd like to see no-ip.com client as package for pfsense so I don't have to remember my ip address all the time, which isn't static anyway.

                    It's already there: services>Dynamic DNS.

                    Duh… and I though I had already gone through all features, thx anyway =)

                    1 Reply Last reply Reply Quote 0
                    • R
                      rdevries
                      last edited by Nov 8, 2006, 4:25 PM

                      I would like to see spam filtering ie:spamassassin
                      Content filtering ie: squidguard, dansguardian

                      Thanks

                      1 Reply Last reply Reply Quote 0
                      • G
                        gbelanger
                        last edited by Nov 20, 2006, 2:49 AM

                        This :

                        http://www.imspector.org/

                        Would be a very valuable addition. It's basically a Instant Messenging proxy, which means that it can be used to provide logging facilities that are mandatory for most security certifications.

                        It could also be used to block IM file transfers and eventually provide antivirus/extension-based blocking. Its a great addition to pfSense because this way it could provide application-layer filtering for the three main point of entry for viruses/malware: web, email and im.

                        1 Reply Last reply Reply Quote 0
                        • M
                          mrsense
                          last edited by Nov 28, 2006, 9:36 PM Nov 25, 2006, 10:13 AM

                          I would love to have a monitoring/net management package that is suitable even for an embeded edition and yet capable of monitoring via SMTP, IMAP, POP3, HTTP,TCP,UDP, NNTP, and PING tests and posting results in html or terminal.

                          http://www.sysmon.org/config.html

                          Rrealtime accounting and monitoring would be nice to have as well:
                          pktstat (FreeBSD port exists)
                          ->listens to the network and shows the bandwidth being consumed by packets of various kinds in realtime. It understands some protocols (including FTP, HTTP, and X11) and adds a descriptive name next to the entry (e.g., 'RETR cd8.iso', 'GET http://slashdot.org/' or 'xclock -fg blue').

                          iftop (FreeBSD port exists)
                          ->listens to network traffic on a named interface,  or on  the  first  interface  it can find which looks like an external interface if none is specified,  and  displays  a table of current bandwidth usage by pairs of hosts.

                          monit (compiles under FreeBSD); http://www.tildeslash.com/monit/
                          ->monit is a utility for managing and monitoring, processes, files, directories and devices on a UNIX system. Monit conducts automatic maintenance and repair and can execute meaningful causal actions in error situations.

                          my 2c…

                          regards,
                          mr-s

                          1 Reply Last reply Reply Quote 0
                          • N
                            Nil Einne
                            last edited by Dec 30, 2006, 2:52 PM

                            A LPR/LPD package to support using pfSense as a print (printer) server would be nice. Preferably with SAMBA support.

                            1 Reply Last reply Reply Quote 0
                            • L
                              llewis
                              last edited by Jan 15, 2007, 10:46 PM

                              FreeRADIUS additions/modifications…

                              I've configured FreeRADIUS to add eap_tls and eap_ttls to authenticate my access point for WPA2-CCM on my pfsense box. What would be nifty is a the ability to integrate the CA similarly to how it is done for IPSEC VPN's to manage certificates for both the CA and users. This would give users the option to utilize either eap_tls or eap_ttls (for the more lazy). If you think about it, possibly just a centralized CA that was separated per duty might be sufficient (e.g., one for IPSEC another for OpenVPN, another for WPA, however utilizing the same openssl.cnf, etc and just splitting off different directories per usage type). Sorry for rambling... but I think this might provide a nice feature and pull together any loose ends that utilize certs for a auth method.

                              1 Reply Last reply Reply Quote 0
                              • E
                                ellisgl
                                last edited by Jan 15, 2007, 11:29 PM

                                OSPF and  RIP I + II would be on the top of the list.
                                Newer nVidia chipsets.. 4+
                                64 bit support would be nice too.

                                1 Reply Last reply Reply Quote 0
                                • jahonixJ
                                  jahonix
                                  last edited by Jan 16, 2007, 7:47 AM

                                  @ellisgl:

                                  OSPF and  RIP I + II would be on the top of the list.

                                  routed: RIP v1 and v2 daemon
                                  Already available as package.

                                  1 Reply Last reply Reply Quote 0
                                  • W
                                    WildTangent
                                    last edited by Jan 30, 2007, 2:14 AM

                                    I'd like to second the request for TorrentFlux. This couldn't be too hard to implement, TorrentFlux itself is just a PHP controlled implementation of BitTornado as far as I understand.

                                    1 Reply Last reply Reply Quote 0
                                    • J
                                      Justinw
                                      last edited by Jan 31, 2007, 4:09 AM

                                      @mrsense:

                                      I would love to have a monitoring/net management package that is suitable even for an embeded edition and yet capable of monitoring via SMTP, IMAP, POP3, HTTP,TCP,UDP, NNTP, and PING tests and posting results in html or terminal.

                                      http://www.sysmon.org/config.html

                                      Rrealtime accounting and monitoring would be nice to have as well:
                                      pktstat (FreeBSD port exists)
                                      ->listens to the network and shows the bandwidth being consumed by packets of various kinds in realtime. It understands some protocols (including FTP, HTTP, and X11) and adds a descriptive name next to the entry (e.g., 'RETR cd8.iso', 'GET http://slashdot.org/' or 'xclock -fg blue').

                                      iftop (FreeBSD port exists)
                                      ->listens to network traffic on a named interface,  or on  the  first  interface  it can find which looks like an external interface if none is specified,  and  displays  a table of current bandwidth usage by pairs of hosts.

                                      monit (compiles under FreeBSD); http://www.tildeslash.com/monit/
                                      ->monit is a utility for managing and monitoring, processes, files, directories and devices on a UNIX system. Monit conducts automatic maintenance and repair and can execute meaningful causal actions in error situations.

                                      my 2c…

                                      regards,
                                      mr-s

                                      Try a pkg_add -r nagios I think you will be surprised what it will do out of the box.  There are still some bugs that I am working with on my box from the stock install, but a person with some time could easily get it going I think.

                                      1 Reply Last reply Reply Quote 0
                                      • C
                                        cdsu
                                        last edited by Mar 16, 2007, 2:25 AM

                                        I'd like to see some options for snort to include bleedingrules, controlled ip blocking. Maybe have an option to move the blocked ips to a permanent blacklist. A file editor option for snort.conf that lets you permanently make changes to the file for tuning. mysql support for snort to log to a database. It would also be nice to have the option to pull the rules from a different location like a local webserver.that would be awesome!!

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          mastrboy
                                          last edited by Mar 27, 2007, 7:00 PM

                                          @WildTangent:

                                          I'd like to second the request for TorrentFlux. This couldn't be too hard to implement, TorrentFlux itself is just a PHP controlled implementation of BitTornado as far as I understand.

                                          WTF! what kind of person are you, putting a torrent client on a firewall ! makes me wanna cry  :'( :'( :'( :'(

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.