Categories

  • 393 Topics
    1k Posts
    DataIdeas-JoshD
    While following the https://docs.netgate.com/tnsr/en/latest/recipes/gui/index.html guide. still getting the error "protocol invalid-value error HTTP cert verification failed: unable to verify the first certificate[21]" Not quite sure why getting the error. I did everything in the guide. Wish the gui was simpler to access rather than this over complicated way to do certs, then install, etc.
  • 122k Topics
    777k Posts
    stephenw10S
    If you are policy routing traffic to that gateway it relies on the gateway status for things like failover. If you have two WG tunnels for example you might want to use tunnel1 unless it goes down then use tunnel2. With it marked as always online pfSense will send that traffic to it even if the traffic is 100% lost in the route. So not really a security issue. More functionality.
  • 20k Topics
    129k Posts
    G
    @johnpoz said in Teamspeak Login generates Surricata alert: Base64 HTTP Password detected unencrypted on: @ghar36k if that is the case that seems insane in this day and age to be honest. I would do a packet capture, start the capture before you click your login and get the warning. Prob want to set the packet limit to 0 vs the default 1000. Do you see the alert, then look into the packet capture - download and using something like wireshark make it easier to read the pcap for sure. Do you see anything in the clear, or is all just https traffic. If something is encode with just base 64, it would be very easy to decode. There are many places on the net to paste in base64 and view it decoded. If you know where the data is being sent, you mention the IP seems legit.. Does it change when you do this test multiple times? If not be much easier to limit your packet capture to just that IP so it won't contain other traffic. I would also check on their forums, or send them a support request asking about it and the warning your seeing in your ips. I don't use teamspeak, or I would be very happy to look into it as well - quite possible other pfsense users do use it, maybe they will chime in? It's the same IP address every time. It took a little longer to generate the IPS alert when I was doing the packet capture this time (30 seconds to a minute). The alert in Surricata indicates the destination port is port 80 but when I was doing the packet capture it's showing the destination port as 41444. I'm not sure if it grabbed the right packet so I'm going to try again. I've kept the application open for 20-30 minutes after the first capture and it's not generating any additional alerts. The alerts only seem to come immediately/shortly after login. I'm also not seeing any actual data username/password (not that I'm super familiar with how to read a PCAP in wire shark).
  • 43k Topics
    267k Posts
    K
    @Kraeuter ja, die habe ich mit meinem Kabelanschluß genutzt, selbe Qualität wie Fritzbox. die Verbindung hatte alle paar Minuten aussetzer. Erst mit dem TC4400 lief der Anschluß stabil. Gruß ré
  • Information about hardware available from Netgate

    3k Topics
    21k Posts
    stephenw10S
    Yup changes to address that went in in 25.07: https://redmine.pfsense.org/issues/16210
  • Information about hardware available from Netgate

    44 Topics
    211 Posts
    AriKellyA
    It looks like unified web management could be coming soon. It would be great if it means easier control and management of all web services in one place. Let's see if any companies announce more details about it!
  • Feel free to talk about anything and everything here

    4k Topics
    19k Posts
    GertjanG
    @stephenw10
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.