Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Sarg package for pfsense

    Scheduled Pinned Locked Moved pfSense Packages
    467 Posts 99 Posters 539.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      check create index tree by file too onsarg config and force a report update.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • DonnyD
        Donny
        last edited by

        @marcelloc:

        check create index tree by file too on sarg config and force a report update.

        Hello Marcelloc, I have done what you say but a real user name still not work. as the screenshot below.

        Thank u very much. I am tired, I go to bed now.

        Users.png
        Users.png_thumb

        1 Reply Last reply Reply Quote 0
        • marcellocM
          marcelloc
          last edited by

          Donny,

          Thanks for your feedback.

          I found an error on field check that was preventing user file to be created.

          I'm fixing it and including some other options before publishing.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • marcellocM
            marcelloc
            last edited by

            Version 0.4 is out with

            • usertab fix

            • charset option field

            • few more report config options

            As users has its own tab, you may need to backup your sarg user configuration before update(just in case  ;))

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • DonnyD
              Donny
              last edited by

              @marcelloc:

              Version 0.4 is out with

              • usertab fix

              • charset option field

              • few more report config options

              As users has its own tab, you may need to backup your sarg user configuration before update(just in case  ;))

              Hello Marcelloc, today is a wonderful world, I have tested SARG with a real user name for a new SARG v.04. Now it is working.  see some screenshot. I will waiting for the next e-mail option to use for system log sending. The next step I will testing with Windows Server 2008 R2 Active Directory ( LDAP ). You are really really working hard. If I find something error more I will posting here as soon as possible.

              Thank u so much to help me a lot

              RealNameUserID.png
              RealNameUserID.png_thumb
              Sites&Users.png
              Sites&Users.png_thumb

              1 Reply Last reply Reply Quote 0
              • E
                elemay
                last edited by

                Hi,

                i updated today and now have:

                sarg [Sarg] config error: dansguardian logfile () does not exist

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  @elemay:

                  Hi,

                  i updated today and now have:

                  sarg [Sarg] config error: dansguardian logfile () does not exist

                  It happens just after reinstall or on every Sargent configuration save?

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • E
                    elemay
                    last edited by

                    reinstalling only.

                    [SOLVED] i also experience if i set up a schedule, and do a 'Force Update Now' i get no report, telling me:

                    Error: Could not find report index file.
                    Check sarg settings and try to force sarg schedule.
                    

                    in system logs i see:

                    Apr 10 15:55:45	php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 174067, reading: 0.00%^MSARG: Maybe you have a broken date in your /var/log/dansguardian/access.log file SARG: getword_atoll loop detected after 2 bytes. SARG: Line="xx.xx.xx.xx http" SARG: Record="xx.xx.xx.xx http" SARG: searching for 'x2f''
                    

                    i deleted access.log and restarted dansguradian, everythings fine again. :)

                    1 Reply Last reply Reply Quote 0
                    • marcellocM
                      marcelloc
                      last edited by

                      sarg reads dansguardian logs only in squid format.

                      A log rotate(or remove like you did :)) should fix it after changing format.

                      Treinamentos de Elite: http://sys-squad.com

                      Help a community developer! ;D

                      1 Reply Last reply Reply Quote 0
                      • DonnyD
                        Donny
                        last edited by

                        Hi,
                        I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
                        example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Users association" like this:
                        172.31.21.22 Don Van Cooper
                        172.31.21.23 Teun Van Laarhoven
                        172.31.21.24 Marijon Kooijstra > until 75 users.

                        pfSense:  
                        1. pfSense is DNS Server
                        2. pfSense is DNS Forwarder
                        3. pfSense is DHCP Server

                        at option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?

                        1 Reply Last reply Reply Quote 0
                        • marcellocM
                          marcelloc
                          last edited by

                          @Donny:

                          Hi,
                          I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
                          example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Use association" like this:
                          172.31.21.22 Don Van Cooper
                          172.31.21.23 Teun Van Laarhoven
                          172.31.21.24 Marijon Kooijstra > until 75 users.

                          Try to enable squid basic authentication with local users.

                          @Donny:

                          at option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?

                          This option is usefull only when you have ntlm authentication using samba and active directory.

                          Treinamentos de Elite: http://sys-squad.com

                          Help a community developer! ;D

                          1 Reply Last reply Reply Quote 0
                          • DonnyD
                            Donny
                            last edited by

                            @marcelloc:

                            @Donny:

                            Hi,
                            I just wonder, how can I map users name with dynamic IP address if my pfSense act as DHCP Server? Is it possible? In this case I do not use Windows Server.
                            example: I have 75 users desktop Windows XP or Windows 7 and get dynamic ip address from pfSense DHCP server or I have to map a real user name with ip address one by one at the option "Use association" like this:
                            172.31.21.22 Don Van Cooper
                            172.31.21.23 Teun Van Laarhoven
                            172.31.21.24 Marijon Kooijstra > until 75 users.

                            Try to enable squid basic authentication with local users.

                            @Donny:

                            at option "Ntlm User Format" When I have changed from "domainname+username(default)" to "Username" and Realtime report is not working. what is differences between "domainname+username" and "Username" to use?

                            This option is usefull only when you have ntlm authentication using samba and active directory.

                            Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              @Donny:

                              Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?

                              this is a config bug in sarg

                              config file says:

                              TAG: ntlm_user_format username|domainname+username

                              NTLM users format.

                              #ntlm_user_format domainname+username
                              ntlm_user_format username

                              but sarg returns with:
                              SARG: Unknown value "username" for parameter "ntlm_user_format"

                              if I change this option to 'user' it works.

                              I'm publishing a patch right now, whait 15 minutes and reinstall sarg

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • DonnyD
                                Donny
                                last edited by

                                @marcelloc:

                                @Donny:

                                Thank u Marcelloc, One more question. When I have changed from "domainname+username(default)" to "Username" and why a realtime report is not working?

                                this is a config bug in sarg

                                config file says:

                                TAG: ntlm_user_format username|domainname+username

                                NTLM users format.

                                #ntlm_user_format domainname+username
                                ntlm_user_format username

                                but sarg returns with:
                                SARG: Unknown value "username" for parameter "ntlm_user_format"

                                if I change this option to 'user' it works.

                                I'm publishing a patch right now, whait 15 minutes and reinstall sarg

                                Now I do a basic to authenticate and create local user on Squid-reverse. At authentication settings, they say that I have to turn off "Transparent proxy" and I have done it.
                                at shedule tab I try to "force Update now" but at realtime report tab when I click "Show log", it does not show any report. It does not work when I use local user and authetication:local.

                                LocalUsers.png
                                LocalUsers.png_thumb
                                AuthenticatLocal.png
                                AuthenticatLocal.png_thumb
                                RealTimeReportNotwork.png
                                RealTimeReportNotwork.png_thumb

                                1 Reply Last reply Reply Quote 0
                                • marcellocM
                                  marcelloc
                                  last edited by

                                  After disabling transparente proxy, you are able to filter ssl but you need first to configure proxy settings on client browsers.

                                  Treinamentos de Elite: http://sys-squad.com

                                  Help a community developer! ;D

                                  1 Reply Last reply Reply Quote 0
                                  • DonnyD
                                    Donny
                                    last edited by

                                    @marcelloc:

                                    After disabling transparente proxy, you are able to filter ssl but you need first to configure proxy settings on client browsers.

                                    at the web browsers client I have configured proxy setting and I tried to log in with local user name and password that I created from Squid proxy. after log in success I try to check at realtime report on SARG but the report only show ip address and it is not show user name that I used log in.

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      Are you using just squid?

                                      Can you check in log files if you can see the auth user?

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        klamath
                                        last edited by

                                        Thanks Marcelo…

                                        I've got some problem to get it done...
                                        It doesn't work for me...
                                        Can you help me?

                                        [Sarg]Sarg config error: log file () does not exists    .:.

                                        Apr 10 23:00:29 php: /pkg_edit.php: executing squid log rotate after sarg.
                                        Apr 10 23:00:29 php: /pkg_edit.php: executing squidguard log rotate after sarg.
                                        Apr 10 23:00:29 php: /pkg_edit.php: The command '/usr/local/bin/sarg ' returned exit code '1', the output was 'SARG: Records in file: 49003, reading: 0.00%^MSARG: Records in file: 5000, reading: 10.20%^MSARG: Records in file: 10000, reading: 20.41%^MSARG: Records in file: 15000, reading: 30.61%^MSARG: Records in file: 20000, reading: 40.81%^MSARG: Records in file: 25000, reading: 51.02%^MSARG: Records in file: 30000, reading: 61.22%^MSARG: Records in file: 35000, reading: 71.42%^MSARG: Records in file: 40000, reading: 81.63%^MSARG: Records in file: 45000, reading: 91.83%^MSARG: Cannot delete /usr/local/www/sarg-reports/08Apr2012-10Apr2012/d192_168_1_106.html - No such file or directory SARG: Records in file: 49003, reading: 100.00%'
                                        Apr 10 23:00:28 php: /pkg_edit.php: Sarg: force refresh now with '' args and rotate action after sarg finish.

                                        Command line

                                        sarg
                                        SARG: Records in file: 49194, reading: 100.00%
                                        SARG: Cannot delete /usr/local/www/sarg-reports/2012/04/08-10/d192_168_1_106.html - No such file or directory

                                        HP ProLiant MicroServer N40L - 2GB - 250G HD - 3 NIC Intel PRO/1000 MT Gigabit PCI
                                        pfSense 2.0.1-RELEASE (amd64)

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          Can you clean this problematic folder and try to run Sarg again?

                                          My current schedules are
                                          1h with no action after sarg
                                          1d with rotate and restart.

                                          Index options are selected on sarg configuration as well report overwrite.

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • DonnyD
                                            Donny
                                            last edited by

                                            @marcelloc:

                                            Are you using just squid?

                                            Can you check in log files if you can see the auth user?

                                            First I have uninstall SARG and Squid-reverse because It is not work. After that I tried to install normal Squid-proxy and SARG again. When I created local user on Squid-proxy, I can not use capital and small letter like this: "Donny" but just only small letter: "donny" if I try to login via web browsers otherwise I can not login.

                                            Now I turn off authenticate and go back to use "Transparent proxy" again. I will check log file in this evening and test again. I have to go to work now. bye

                                            Thank u Marcelloc

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.