ITADN

“PFSENSE: GUI Apply deletes pfsense machine and does not recreate it, while CLI service crowdsec onerestart works.

#4530Openexclusiveticsc-lab 创建于 2026-06-30
kind/bugneeds/triageos/freebsdversion/1.7.8
### What happened? “GUI Apply deletes pfsense machine and does not recreate it, while CLI service crowdsec onerestart works. When clicking "Apply" in the pfSense settings under Services > CrowdSec, the pfSense machine is deleted by the script, and the script attempts to recreate it but fails to do so. When running the following commands via the pfSense CLI: /root: /usr/local/bin/cscli machines add pfsense --auto --force --error Machine 'pfsense' successfully added to the local API. API credentials written to '/usr/local/etc/crowdsec/local_api_credentials.yaml'. ### What did you expect to happen? The script should be able to complete the steps correctly, or identify a creation error and apply the command: cscli machines add pfsense --auto --force --error so that everything works as expected ### How can we reproduce it (as minimally and precisely as possible)? Make any changes in the pfSense settings tab under Services > CrowdSec, then check via the CLI using the command: cscli machines list ### Anything else we need to know? ### Crowdsec version <details> version: v1.7.8-6322745 Codename: alphaga BuildDate: 2026-06-17_18:15:38 GoVersion: 1.26.4 Platform: freebsd libre2: WebAssembly User-Agent: crowdsec/v1.7.8-6322745-freebsd Constraint_parser: >= 1.0, <= 3.0 Constraint_scenario: >= 1.0, <= 3.0 Constraint_api: v1 Constraint_acquis: >= 1.0, < 2.0 Built-in optional components: cscli_setup, datasource_appsec, datasource_cloudwatch, datasource_docker, datasource_file, datasource_http, datasource_journalctl, datasource_k8s-audit, datasource_kafka, datasource_kinesis, datasource_loki, datasource_s3, datasource_syslog, datasource_victorialogs, datasource_wineventlog, db_mysql, db_postgres, db_sqlite </details> ### OS version <details> ```console # On Linux: PFsense 2.81 and 2.82 </details> ### Enabled collections and parsers <details> Loaded: 164 parsers, 12 postoverflows, 783 scenarios, 9 contexts, 5 appsec-configs, 219 appsec-rules, 163 collections name,status,version,description,type crowdsecurity/dateparse-enrich,enabled,0.2,,parsers crowdsecurity/geoip-enrich,enabled,0.5,"Populate event with geoloc info : as, country, coords, source range.",parsers crowdsecurity/http-logs,enabled,1.3,"Parse more Specifically HTTP logs, such as HTTP Code, HTTP path, HTTP args and if its a static ressource",parsers crowdsecurity/nginx-logs,enabled,2.0,Parse nginx access and error logs,parsers crowdsecurity/pfsense-gui-logs,enabled,0.1,Parse pfSense web auth logs,parsers crowdsecurity/public-dns-allowlist,enabled,0.1,Allow events from public DNS servers,parsers crowdsecurity/sshd-logs,enabled,3.1,Parse openSSH logs,parsers crowdsecurity/sshd-success-logs,enabled,0.1,Parse successful ssh logins,parsers crowdsecurity/syslog-logs,enabled,1.0,,parsers crowdsecurity/whitelists,enabled,0.3,Whitelist events from private ipv4 addresses,parsers firewallservices/pf-logs,enabled,0.8,Parse packet filter logs,parsers crowdsecurity/cdn-whitelist,enabled,0.5,Whitelist CDN providers,postoverflows crowdsecurity/google-special-crawlers-whitelist,enabled,0.1,"Whitelist events from Google special crawlers (e.g. Google-InspectionTool, GoogleOther)",postoverflows crowdsecurity/rdns,enabled,0.4,Lookup the DNS associated to the source IP only for overflows,postoverflows crowdsecurity/seo-bots-whitelist,enabled,0.5,Whitelist good search engine crawlers,postoverflows crowdsecurity/apache_log4j2_cve-2021-44228,enabled,0.7,Detect cve-2021-44228 exploitation attempts,scenarios crowdsecurity/CVE-2017-9841,enabled,0.2,Detect CVE-2017-9841 exploits,scenarios crowdsecurity/CVE-2019-18935,enabled,0.2,Detect Telerik CVE-2019-18935 exploitation attempts,scenarios crowdsecurity/CVE-2022-26134,enabled,0.4,Confluence - RCE (CVE-2022-26134),scenarios crowdsecurity/CVE-2022-35914,enabled,0.2,Detect CVE-2022-35914 exploits,scenarios crowdsecurity/CVE-2022-37042,enabled,0.2,Detect CVE-2022-37042 exploits,scenarios crowdsecurity/CVE-2022-40684,enabled,0.3,Detect cve-2022-40684 exploitation attempts,scenarios crowdsecurity/CVE-2022-41082,enabled,0.4,Detect CVE-2022-41082 exploits,scenarios crowdsecurity/CVE-2022-41697,enabled,0.2,Detect CVE-2022-41697 enumeration,scenarios crowdsecurity/CVE-2022-42889,enabled,0.3,Detect CVE-2022-42889 exploits (Text4Shell),scenarios crowdsecurity/CVE-2022-44877,enabled,0.3,Detect CVE-2022-44877 exploits,scenarios crowdsecurity/CVE-2022-46169,enabled,0.2,Detect CVE-2022-46169 brute forcing,scenarios crowdsecurity/CVE-2023-22515,enabled,0.1,Detect CVE-2023-22515 exploitation,scenarios crowdsecurity/CVE-2023-22518,enabled,0.3,Detect CVE-2023-22518 exploits,scenarios crowdsecurity/CVE-2023-49103,enabled,0.3,Detect owncloud CVE-2023-49103 exploitation attempts,scenarios crowdsecurity/CVE-2024-0012,enabled,0.1,Detect CVE-2024-0012 exploitation attempts,scenarios crowdsecurity/CVE-2024-38475,enabled,0.1,Detect CVE-2024-38475 exploitation attempts,scenarios crowdsecurity/CVE-2024-9474,enabled,0.1,Detect CVE-2024-9474 exploitation attempts,scenarios crowdsecurity/f5-big-ip-cve-2020-5902,enabled,0.3,F5 BIG-IP TMUI - RCE (CVE-2020-5902),scenarios crowdsecurity/fortinet-cve-2018-13379,enabled,0.4,Detect cve-2018-13379 exploitation attempts,scenarios crowdsecurity/grafana-cve-2021-43798,enabled,0.3,Grafana - Arbitrary File Read (CVE-2021-43798),scenarios crowdsecurity/http-admin-interface-probing,enabled,0.5,Detect generic HTTP admin interface probing,scenarios crowdsecurity/http-backdoors-attempts,enabled,0.6,Detect attempt to common backdoors,scenarios crowdsecurity/http-bad-user-agent,enabled,1.2,Detect usage of bad User Agent,scenarios crowdsecurity/http-crawl-non_statics,enabled,0.7,Detect aggressive crawl on non static resources,scenarios crowdsecurity/http-cve-2021-41773,enabled,0.3,Apache - Path Traversal (CVE-2021-41773),scenarios crowdsecurity/http-cve-2021-42013,enabled,0.3,Apache - Path Traversal (CVE-2021-42013),scenarios crowdsecurity/http-cve-probing,enabled,0.6,Detect generic HTTP cve probing,scenarios crowdsecurity/http-generic-bf,enabled,0.9,Detect generic http brute force,scenarios crowdsecurity/http-generic-test,enabled,0.2,Crowdsec Generic Test Scenario: basic HTTP trigger,scenarios crowdsecurity/http-open-proxy,enabled,0.5,Detect scan for open proxy,scenarios crowdsecurity/http-path-traversal-probing,enabled,0.4,Detect path traversal attempt,scenarios crowdsecurity/http-probing,enabled,0.4,Detect site scanning/probing from a single ip,scenarios crowdsecurity/http-sap-interface-probing,enabled,0.1,Detect generic HTTP SAP interface probing,scenarios crowdsecurity/http-sensitive-files,enabled,0.4,"Detect attempt to access to sensitive files (.log, .db ..) or folders (.git)",scenarios crowdsecurity/http-sqli-probing,enabled,0.4,A scenario that detects SQL injection probing with minimal false positives,scenarios crowdsecurity/http-technology-probing,enabled,0.1,Detect HTTP technology/vendor probing,scenarios crowdsecurity/http-wordpress-scan,enabled,0.4,Detect exploitation attempts against common WordPress endpoints,scenarios crowdsecurity/http-xss-probing,enabled,0.4,A scenario that detects XSS probing with minimal false positives,scenarios crowdsecurity/jira_cve-2021-26086,enabled,0.4,Detect Atlassian Jira CVE-2021-26086 exploitation attempts,scenarios crowdsecurity/netgear_rce,enabled,0.4,Detect Netgear RCE DGN1000/DGN220 exploitation attempts,scenarios crowdsecurity/nginx-req-limit-exceeded,enabled,0.3,Detects IPs which violate nginx's user set request limit.,scenarios crowdsecurity/pfsense-gui-bf,enabled,0.2,Detect bruteforce on pfsense web interface,scenarios crowdsecurity/pulse-secure-sslvpn-cve-2019-11510,enabled,0.4,Detect cve-2019-11510 exploitation attempts,scenarios crowdsecurity/spring4shell_cve-2022-22965,enabled,0.3,Detect cve-2022-22965 probing,scenarios crowdsecurity/ssh-bf,enabled,0.3,Detect ssh bruteforce,scenarios crowdsecurity/ssh-cve-2024-6387,enabled,0.2,Detect exploitation attempt of CVE-2024-6387,scenarios crowdsecurity/ssh-generic-test,enabled,0.2,Crowdsec Generic Test Scenario: SSH brute force trigger,scenarios crowdsecurity/ssh-refused-conn,enabled,0.1,Detect sshd refused connections,scenarios crowdsecurity/ssh-slow-bf,enabled,0.4,Detect slow ssh bruteforce,scenarios crowdsecurity/ssh-time-based-bf,enabled,0.3,Detect time-based ssh bruteforce attempts that evade rate limiting (with false positive reduction),scenarios crowdsecurity/thinkphp-cve-2018-20062,enabled,0.7,Detect ThinkPHP CVE-2018-20062 exploitation attempts,scenarios crowdsecurity/vmware-cve-2022-22954,enabled,0.3,Detect Vmware CVE-2022-22954 exploitation attempts,scenarios crowdsecurity/vmware-vcenter-vmsa-2021-0027,enabled,0.3,Detect VMSA-2021-0027 exploitation attempts,scenarios firewallservices/pf-scan-multi_ports,enabled,0.5,Detect aggressive portscans (pf),scenarios ltsich/http-w00tw00t,enabled,0.3,detect w00tw00t,scenarios crowdsecurity/bf_base,enabled,0.1,,contexts crowdsecurity/firewall_base,enabled,0.2,,contexts crowdsecurity/http_base,enabled,0.3,,contexts crowdsecurity/base-http-scenarios,enabled,1.4,http common : scanners detection,collections crowdsecurity/freebsd,enabled,0.5,core freebsd support : syslog+geoip+ssh,collections crowdsecurity/http-cve,enabled,3.0,Detect CVE exploitation in http logs,collections crowdsecurity/nginx,enabled,0.3,nginx support : parser and generic http scenarios,collections crowdsecurity/pfsense,enabled,0.3,core pfsense support,collections crowdsecurity/pfsense-gui,enabled,0.2,pfSense web authentication support,collections crowdsecurity/sshd,enabled,0.9,sshd support : parser and brute-force detection,collections crowdsecurity/whitelist-good-actors,enabled,0.4,Good actors whitelists,collections firewallservices/pf,enabled,0.3,Parser and scenario for Packet Filter logs,collections </details> ### Acquisition config <details> ```console # On Linux: $ cat /etc/crowdsec/acquis.yaml /etc/crowdsec/acquis.d/* # paste output here # On Windows: C:\> Get-Content C:\ProgramData\CrowdSec\config\acquis.yaml # paste output here ``` </details> ### Config show <details> /usr/local/bin/cscli config show Global: - Configuration Folder : /usr/local/etc/crowdsec - Data Folder : /var/db/crowdsec/data - Hub Folder : /usr/local/etc/crowdsec/hub - Notification Folder : /usr/local/etc/crowdsec/notifications - Simulation File : /usr/local/etc/crowdsec/simulation.yaml - Log Folder : /var/log/crowdsec - Log level : info - Log Media : file Crowdsec: - Acquisition File : /usr/local/etc/crowdsec/acquis.yaml - Parsers routines : 1 - Acquisition Folder : /usr/local/etc/crowdsec/acquis.d cscli: - Output : human - Hub Branch : API Client: - URL : http://192.168.1.240:7979/ - Login : pfsense - Credentials File : /usr/local/etc/crowdsec/local_api_credentials.yaml Local API Server: - Listen URL : 192.168.1.240:7979 - Listen Socket : - Profile File : /usr/local/etc/crowdsec/profiles.yaml - Trusted IPs: - 127.0.0.1 - ::1 - Database: - Type : sqlite - Path : /var/db/crowdsec/data/crowdsec.db - Flush age : 168h0m0s - Flush size : 5000 [2.8.1-RELEASE][admin@fw1.exclusivetic.local]/root: </details> ### Prometheus metrics <details> ╭────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮ │ Acquisition Metrics │ ├──────────────────────────┬────────────┬──────────────┬────────────────┬────────────────────────┬───────────────────┤ │ Source │ Lines read │ Lines parsed │ Lines unparsed │ Lines poured to bucket │ Lines whitelisted │ ├──────────────────────────┼────────────┼──────────────┼────────────────┼────────────────────────┼───────────────────┤ │ file:/var/log/filter.log │ 35.95k │ 770 │ 35.18k │ 106 │ 138 │ ╰──────────────────────────┴────────────┴──────────────┴────────────────┴────────────────────────┴───────────────────╯ ╭─────────────────────────────────────────────────╮ │ Local API Decisions │ ├───────────────────────┬────────┬────────┬───────┤ │ Reason │ Origin │ Action │ Count │ ├───────────────────────┼────────┼────────┼───────┤ │ http:bruteforce │ CAPI │ ban │ 94 │ │ http:crawl │ CAPI │ ban │ 2 │ │ http:dos │ CAPI │ ban │ 560 │ │ http:exploit │ CAPI │ ban │ 8989 │ │ ssh:bruteforce │ CAPI │ ban │ 1767 │ │ firehol_botscout_7d │ lists │ ban │ 1168 │ │ tor-exit-nodes │ lists │ ban │ 2180 │ │ generic:scan │ CAPI │ ban │ 275 │ │ http:scan │ CAPI │ ban │ 1613 │ │ tcp:scan │ CAPI │ ban │ 2392 │ │ vm-management:exploit │ CAPI │ ban │ 85 │ │ firehol_greensnow │ lists │ ban │ 5595 │ ╰───────────────────────┴────────┴────────┴───────╯ ╭──────────────────────────────────────╮ │ Local API Metrics │ ├──────────────────────┬────────┬──────┤ │ Route │ Method │ Hits │ ├──────────────────────┼────────┼──────┤ │ /v1/alerts │ GET │ 1959 │ │ /v1/decisions/stream │ GET │ 80 │ │ /v1/heartbeat │ GET │ 40 │ │ /v1/usage-metrics │ POST │ 29 │ │ /v1/watchers/login │ POST │ 2 │ ╰──────────────────────┴────────┴──────╯ ╭─────────────────────────────────────────────────────────╮ │ Local API Bouncers Metrics │ ├──────────────────┬──────────────────────┬────────┬──────┤ │ Bouncer │ Route │ Method │ Hits │ ├──────────────────┼──────────────────────┼────────┼──────┤ │ pfsense-firewall │ /v1/decisions/stream │ GET │ 80 │ ╰──────────────────┴──────────────────────┴────────┴──────╯ ╭─────────────────────────────────────────────────╮ │ Local API Machines Metrics │ ├─────────────────┬───────────────┬────────┬──────┤ │ Machine │ Route │ Method │ Hits │ ├─────────────────┼───────────────┼────────┼──────┤ │ crowdsec-web-ui │ /v1/alerts │ GET │ 1956 │ │ crowdsec-web-ui │ /v1/heartbeat │ GET │ 27 │ │ pfsense │ /v1/heartbeat │ GET │ 13 │ ╰─────────────────┴───────────────┴────────┴──────╯ ╭─────────────────────────────────────────────────────────────────╮ │ Parser Metrics │ ├────────────────────────────────────┬────────┬────────┬──────────┤ │ Parsers │ Hits │ Parsed │ Unparsed │ ├────────────────────────────────────┼────────┼────────┼──────────┤ │ child-crowdsecurity/syslog-logs │ 35.95k │ 35.95k │ - │ │ crowdsecurity/dateparse-enrich │ 770 │ 770 │ - │ │ crowdsecurity/geoip-enrich │ 653 │ 653 │ - │ │ crowdsecurity/public-dns-allowlist │ 770 │ 770 │ - │ │ crowdsecurity/syslog-logs │ 35.95k │ 35.95k │ - │ │ crowdsecurity/whitelists │ 770 │ 770 │ - │ │ firewallservices/pf-logs │ 35.95k │ 23.78k │ 12.17k │ │ firewallservices/pf-logs-drop │ 770 │ 770 │ - │ ╰────────────────────────────────────┴────────┴────────┴──────────╯ ╭────────────────────────────────────────────────────────────────────────────────────────────────────╮ │ Scenario Metrics │ ├──────────────────────────────────────┬───────────────┬───────────┬──────────────┬────────┬─────────┤ │ Scenario │ Current Count │ Overflows │ Instantiated │ Poured │ Expired │ ├──────────────────────────────────────┼───────────────┼───────────┼──────────────┼────────┼─────────┤ │ firewallservices/pf-scan-multi_ports │ 10 │ - │ 103 │ 106 │ 93 │ ╰──────────────────────────────────────┴───────────────┴───────────┴──────────────┴────────┴─────────╯ ╭───────────────────────────────────────────────────────────────────────────────────────╮ │ Whitelist Metrics │ ├────────────────────────────────────┬─────────────────────────────┬──────┬─────────────┤ │ Whitelist │ Reason │ Hits │ Whitelisted │ ├────────────────────────────────────┼─────────────────────────────┼──────┼─────────────┤ │ crowdsecurity/public-dns-allowlist │ public DNS server │ 770 │ 21 │ │ crowdsecurity/whitelists │ private ipv4/ipv6 ip/ranges │ 770 │ 117 │ ╰────────────────────────────────────┴─────────────────────────────┴──────┴─────────────╯ [2.8.1-RELEASE][admin@fw1.exclusivetic.local]/root: </details> ### Related custom configs versions (if applicable) : notification plugins, custom scenarios, parsers etc. <details> </details>
1 条评论