“PFSENSE: GUI Apply deletes pfsense machine and does not recreate it, while CLI service crowdsec onerestart works.
kind/bugneeds/triageos/freebsdversion/1.7.8
### What happened?
“GUI Apply deletes pfsense machine and does not recreate it, while CLI service crowdsec onerestart works.
When clicking "Apply" in the pfSense settings under Services > CrowdSec, the pfSense machine is deleted by the script, and the script attempts to recreate it but fails to do so.
When running the following commands via the pfSense CLI:
/root: /usr/local/bin/cscli machines add pfsense --auto --force --error
Machine 'pfsense' successfully added to the local API.
API credentials written to '/usr/local/etc/crowdsec/local_api_credentials.yaml'.
### What did you expect to happen?
The script should be able to complete the steps correctly, or identify a creation error and apply the command: cscli machines add pfsense --auto --force --error
so that everything works as expected
### How can we reproduce it (as minimally and precisely as possible)?
Make any changes in the pfSense settings tab under Services > CrowdSec,
then check via the CLI using the command:
cscli machines list
### Anything else we need to know?
### Crowdsec version
<details>
version: v1.7.8-6322745
Codename: alphaga
BuildDate: 2026-06-17_18:15:38
GoVersion: 1.26.4
Platform: freebsd
libre2: WebAssembly
User-Agent: crowdsec/v1.7.8-6322745-freebsd
Constraint_parser: >= 1.0, <= 3.0
Constraint_scenario: >= 1.0, <= 3.0
Constraint_api: v1
Constraint_acquis: >= 1.0, < 2.0
Built-in optional components: cscli_setup, datasource_appsec, datasource_cloudwatch, datasource_docker, datasource_file, datasource_http, datasource_journalctl, datasource_k8s-audit, datasource_kafka, datasource_kinesis, datasource_loki, datasource_s3, datasource_syslog, datasource_victorialogs, datasource_wineventlog, db_mysql, db_postgres, db_sqlite
</details>
### OS version
<details>
```console
# On Linux:
PFsense 2.81 and 2.82
</details>
### Enabled collections and parsers
<details>
Loaded: 164 parsers, 12 postoverflows, 783 scenarios, 9 contexts, 5 appsec-configs, 219 appsec-rules, 163 collections
name,status,version,description,type
crowdsecurity/dateparse-enrich,enabled,0.2,,parsers
crowdsecurity/geoip-enrich,enabled,0.5,"Populate event with geoloc info : as, country, coords, source range.",parsers
crowdsecurity/http-logs,enabled,1.3,"Parse more Specifically HTTP logs, such as HTTP Code, HTTP path, HTTP args and if its a static ressource",parsers
crowdsecurity/nginx-logs,enabled,2.0,Parse nginx access and error logs,parsers
crowdsecurity/pfsense-gui-logs,enabled,0.1,Parse pfSense web auth logs,parsers
crowdsecurity/public-dns-allowlist,enabled,0.1,Allow events from public DNS servers,parsers
crowdsecurity/sshd-logs,enabled,3.1,Parse openSSH logs,parsers
crowdsecurity/sshd-success-logs,enabled,0.1,Parse successful ssh logins,parsers
crowdsecurity/syslog-logs,enabled,1.0,,parsers
crowdsecurity/whitelists,enabled,0.3,Whitelist events from private ipv4 addresses,parsers
firewallservices/pf-logs,enabled,0.8,Parse packet filter logs,parsers
crowdsecurity/cdn-whitelist,enabled,0.5,Whitelist CDN providers,postoverflows
crowdsecurity/google-special-crawlers-whitelist,enabled,0.1,"Whitelist events from Google special crawlers (e.g. Google-InspectionTool, GoogleOther)",postoverflows
crowdsecurity/rdns,enabled,0.4,Lookup the DNS associated to the source IP only for overflows,postoverflows
crowdsecurity/seo-bots-whitelist,enabled,0.5,Whitelist good search engine crawlers,postoverflows
crowdsecurity/apache_log4j2_cve-2021-44228,enabled,0.7,Detect cve-2021-44228 exploitation attempts,scenarios
crowdsecurity/CVE-2017-9841,enabled,0.2,Detect CVE-2017-9841 exploits,scenarios
crowdsecurity/CVE-2019-18935,enabled,0.2,Detect Telerik CVE-2019-18935 exploitation attempts,scenarios
crowdsecurity/CVE-2022-26134,enabled,0.4,Confluence - RCE (CVE-2022-26134),scenarios
crowdsecurity/CVE-2022-35914,enabled,0.2,Detect CVE-2022-35914 exploits,scenarios
crowdsecurity/CVE-2022-37042,enabled,0.2,Detect CVE-2022-37042 exploits,scenarios
crowdsecurity/CVE-2022-40684,enabled,0.3,Detect cve-2022-40684 exploitation attempts,scenarios
crowdsecurity/CVE-2022-41082,enabled,0.4,Detect CVE-2022-41082 exploits,scenarios
crowdsecurity/CVE-2022-41697,enabled,0.2,Detect CVE-2022-41697 enumeration,scenarios
crowdsecurity/CVE-2022-42889,enabled,0.3,Detect CVE-2022-42889 exploits (Text4Shell),scenarios
crowdsecurity/CVE-2022-44877,enabled,0.3,Detect CVE-2022-44877 exploits,scenarios
crowdsecurity/CVE-2022-46169,enabled,0.2,Detect CVE-2022-46169 brute forcing,scenarios
crowdsecurity/CVE-2023-22515,enabled,0.1,Detect CVE-2023-22515 exploitation,scenarios
crowdsecurity/CVE-2023-22518,enabled,0.3,Detect CVE-2023-22518 exploits,scenarios
crowdsecurity/CVE-2023-49103,enabled,0.3,Detect owncloud CVE-2023-49103 exploitation attempts,scenarios
crowdsecurity/CVE-2024-0012,enabled,0.1,Detect CVE-2024-0012 exploitation attempts,scenarios
crowdsecurity/CVE-2024-38475,enabled,0.1,Detect CVE-2024-38475 exploitation attempts,scenarios
crowdsecurity/CVE-2024-9474,enabled,0.1,Detect CVE-2024-9474 exploitation attempts,scenarios
crowdsecurity/f5-big-ip-cve-2020-5902,enabled,0.3,F5 BIG-IP TMUI - RCE (CVE-2020-5902),scenarios
crowdsecurity/fortinet-cve-2018-13379,enabled,0.4,Detect cve-2018-13379 exploitation attempts,scenarios
crowdsecurity/grafana-cve-2021-43798,enabled,0.3,Grafana - Arbitrary File Read (CVE-2021-43798),scenarios
crowdsecurity/http-admin-interface-probing,enabled,0.5,Detect generic HTTP admin interface probing,scenarios
crowdsecurity/http-backdoors-attempts,enabled,0.6,Detect attempt to common backdoors,scenarios
crowdsecurity/http-bad-user-agent,enabled,1.2,Detect usage of bad User Agent,scenarios
crowdsecurity/http-crawl-non_statics,enabled,0.7,Detect aggressive crawl on non static resources,scenarios
crowdsecurity/http-cve-2021-41773,enabled,0.3,Apache - Path Traversal (CVE-2021-41773),scenarios
crowdsecurity/http-cve-2021-42013,enabled,0.3,Apache - Path Traversal (CVE-2021-42013),scenarios
crowdsecurity/http-cve-probing,enabled,0.6,Detect generic HTTP cve probing,scenarios
crowdsecurity/http-generic-bf,enabled,0.9,Detect generic http brute force,scenarios
crowdsecurity/http-generic-test,enabled,0.2,Crowdsec Generic Test Scenario: basic HTTP trigger,scenarios
crowdsecurity/http-open-proxy,enabled,0.5,Detect scan for open proxy,scenarios
crowdsecurity/http-path-traversal-probing,enabled,0.4,Detect path traversal attempt,scenarios
crowdsecurity/http-probing,enabled,0.4,Detect site scanning/probing from a single ip,scenarios
crowdsecurity/http-sap-interface-probing,enabled,0.1,Detect generic HTTP SAP interface probing,scenarios
crowdsecurity/http-sensitive-files,enabled,0.4,"Detect attempt to access to sensitive files (.log, .db ..) or folders (.git)",scenarios
crowdsecurity/http-sqli-probing,enabled,0.4,A scenario that detects SQL injection probing with minimal false positives,scenarios
crowdsecurity/http-technology-probing,enabled,0.1,Detect HTTP technology/vendor probing,scenarios
crowdsecurity/http-wordpress-scan,enabled,0.4,Detect exploitation attempts against common WordPress endpoints,scenarios
crowdsecurity/http-xss-probing,enabled,0.4,A scenario that detects XSS probing with minimal false positives,scenarios
crowdsecurity/jira_cve-2021-26086,enabled,0.4,Detect Atlassian Jira CVE-2021-26086 exploitation attempts,scenarios
crowdsecurity/netgear_rce,enabled,0.4,Detect Netgear RCE DGN1000/DGN220 exploitation attempts,scenarios
crowdsecurity/nginx-req-limit-exceeded,enabled,0.3,Detects IPs which violate nginx's user set request limit.,scenarios
crowdsecurity/pfsense-gui-bf,enabled,0.2,Detect bruteforce on pfsense web interface,scenarios
crowdsecurity/pulse-secure-sslvpn-cve-2019-11510,enabled,0.4,Detect cve-2019-11510 exploitation attempts,scenarios
crowdsecurity/spring4shell_cve-2022-22965,enabled,0.3,Detect cve-2022-22965 probing,scenarios
crowdsecurity/ssh-bf,enabled,0.3,Detect ssh bruteforce,scenarios
crowdsecurity/ssh-cve-2024-6387,enabled,0.2,Detect exploitation attempt of CVE-2024-6387,scenarios
crowdsecurity/ssh-generic-test,enabled,0.2,Crowdsec Generic Test Scenario: SSH brute force trigger,scenarios
crowdsecurity/ssh-refused-conn,enabled,0.1,Detect sshd refused connections,scenarios
crowdsecurity/ssh-slow-bf,enabled,0.4,Detect slow ssh bruteforce,scenarios
crowdsecurity/ssh-time-based-bf,enabled,0.3,Detect time-based ssh bruteforce attempts that evade rate limiting (with false positive reduction),scenarios
crowdsecurity/thinkphp-cve-2018-20062,enabled,0.7,Detect ThinkPHP CVE-2018-20062 exploitation attempts,scenarios
crowdsecurity/vmware-cve-2022-22954,enabled,0.3,Detect Vmware CVE-2022-22954 exploitation attempts,scenarios
crowdsecurity/vmware-vcenter-vmsa-2021-0027,enabled,0.3,Detect VMSA-2021-0027 exploitation attempts,scenarios
firewallservices/pf-scan-multi_ports,enabled,0.5,Detect aggressive portscans (pf),scenarios
ltsich/http-w00tw00t,enabled,0.3,detect w00tw00t,scenarios
crowdsecurity/bf_base,enabled,0.1,,contexts
crowdsecurity/firewall_base,enabled,0.2,,contexts
crowdsecurity/http_base,enabled,0.3,,contexts
crowdsecurity/base-http-scenarios,enabled,1.4,http common : scanners detection,collections
crowdsecurity/freebsd,enabled,0.5,core freebsd support : syslog+geoip+ssh,collections
crowdsecurity/http-cve,enabled,3.0,Detect CVE exploitation in http logs,collections
crowdsecurity/nginx,enabled,0.3,nginx support : parser and generic http scenarios,collections
crowdsecurity/pfsense,enabled,0.3,core pfsense support,collections
crowdsecurity/pfsense-gui,enabled,0.2,pfSense web authentication support,collections
crowdsecurity/sshd,enabled,0.9,sshd support : parser and brute-force detection,collections
crowdsecurity/whitelist-good-actors,enabled,0.4,Good actors whitelists,collections
firewallservices/pf,enabled,0.3,Parser and scenario for Packet Filter logs,collections
</details>
### Acquisition config
<details>
```console
# On Linux:
$ cat /etc/crowdsec/acquis.yaml /etc/crowdsec/acquis.d/*
# paste output here
# On Windows:
C:\> Get-Content C:\ProgramData\CrowdSec\config\acquis.yaml
# paste output here
```
</details>
### Config show
<details>
/usr/local/bin/cscli config show
Global:
- Configuration Folder : /usr/local/etc/crowdsec
- Data Folder : /var/db/crowdsec/data
- Hub Folder : /usr/local/etc/crowdsec/hub
- Notification Folder : /usr/local/etc/crowdsec/notifications
- Simulation File : /usr/local/etc/crowdsec/simulation.yaml
- Log Folder : /var/log/crowdsec
- Log level : info
- Log Media : file
Crowdsec:
- Acquisition File : /usr/local/etc/crowdsec/acquis.yaml
- Parsers routines : 1
- Acquisition Folder : /usr/local/etc/crowdsec/acquis.d
cscli:
- Output : human
- Hub Branch :
API Client:
- URL : http://192.168.1.240:7979/
- Login : pfsense
- Credentials File : /usr/local/etc/crowdsec/local_api_credentials.yaml
Local API Server:
- Listen URL : 192.168.1.240:7979
- Listen Socket :
- Profile File : /usr/local/etc/crowdsec/profiles.yaml
- Trusted IPs:
- 127.0.0.1
- ::1
- Database:
- Type : sqlite
- Path : /var/db/crowdsec/data/crowdsec.db
- Flush age : 168h0m0s
- Flush size : 5000
[2.8.1-RELEASE][admin@fw1.exclusivetic.local]/root:
</details>
### Prometheus metrics
<details>
╭────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ Acquisition Metrics │
├──────────────────────────┬────────────┬──────────────┬────────────────┬────────────────────────┬───────────────────┤
│ Source │ Lines read │ Lines parsed │ Lines unparsed │ Lines poured to bucket │ Lines whitelisted │
├──────────────────────────┼────────────┼──────────────┼────────────────┼────────────────────────┼───────────────────┤
│ file:/var/log/filter.log │ 35.95k │ 770 │ 35.18k │ 106 │ 138 │
╰──────────────────────────┴────────────┴──────────────┴────────────────┴────────────────────────┴───────────────────╯
╭─────────────────────────────────────────────────╮
│ Local API Decisions │
├───────────────────────┬────────┬────────┬───────┤
│ Reason │ Origin │ Action │ Count │
├───────────────────────┼────────┼────────┼───────┤
│ http:bruteforce │ CAPI │ ban │ 94 │
│ http:crawl │ CAPI │ ban │ 2 │
│ http:dos │ CAPI │ ban │ 560 │
│ http:exploit │ CAPI │ ban │ 8989 │
│ ssh:bruteforce │ CAPI │ ban │ 1767 │
│ firehol_botscout_7d │ lists │ ban │ 1168 │
│ tor-exit-nodes │ lists │ ban │ 2180 │
│ generic:scan │ CAPI │ ban │ 275 │
│ http:scan │ CAPI │ ban │ 1613 │
│ tcp:scan │ CAPI │ ban │ 2392 │
│ vm-management:exploit │ CAPI │ ban │ 85 │
│ firehol_greensnow │ lists │ ban │ 5595 │
╰───────────────────────┴────────┴────────┴───────╯
╭──────────────────────────────────────╮
│ Local API Metrics │
├──────────────────────┬────────┬──────┤
│ Route │ Method │ Hits │
├──────────────────────┼────────┼──────┤
│ /v1/alerts │ GET │ 1959 │
│ /v1/decisions/stream │ GET │ 80 │
│ /v1/heartbeat │ GET │ 40 │
│ /v1/usage-metrics │ POST │ 29 │
│ /v1/watchers/login │ POST │ 2 │
╰──────────────────────┴────────┴──────╯
╭─────────────────────────────────────────────────────────╮
│ Local API Bouncers Metrics │
├──────────────────┬──────────────────────┬────────┬──────┤
│ Bouncer │ Route │ Method │ Hits │
├──────────────────┼──────────────────────┼────────┼──────┤
│ pfsense-firewall │ /v1/decisions/stream │ GET │ 80 │
╰──────────────────┴──────────────────────┴────────┴──────╯
╭─────────────────────────────────────────────────╮
│ Local API Machines Metrics │
├─────────────────┬───────────────┬────────┬──────┤
│ Machine │ Route │ Method │ Hits │
├─────────────────┼───────────────┼────────┼──────┤
│ crowdsec-web-ui │ /v1/alerts │ GET │ 1956 │
│ crowdsec-web-ui │ /v1/heartbeat │ GET │ 27 │
│ pfsense │ /v1/heartbeat │ GET │ 13 │
╰─────────────────┴───────────────┴────────┴──────╯
╭─────────────────────────────────────────────────────────────────╮
│ Parser Metrics │
├────────────────────────────────────┬────────┬────────┬──────────┤
│ Parsers │ Hits │ Parsed │ Unparsed │
├────────────────────────────────────┼────────┼────────┼──────────┤
│ child-crowdsecurity/syslog-logs │ 35.95k │ 35.95k │ - │
│ crowdsecurity/dateparse-enrich │ 770 │ 770 │ - │
│ crowdsecurity/geoip-enrich │ 653 │ 653 │ - │
│ crowdsecurity/public-dns-allowlist │ 770 │ 770 │ - │
│ crowdsecurity/syslog-logs │ 35.95k │ 35.95k │ - │
│ crowdsecurity/whitelists │ 770 │ 770 │ - │
│ firewallservices/pf-logs │ 35.95k │ 23.78k │ 12.17k │
│ firewallservices/pf-logs-drop │ 770 │ 770 │ - │
╰────────────────────────────────────┴────────┴────────┴──────────╯
╭────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ Scenario Metrics │
├──────────────────────────────────────┬───────────────┬───────────┬──────────────┬────────┬─────────┤
│ Scenario │ Current Count │ Overflows │ Instantiated │ Poured │ Expired │
├──────────────────────────────────────┼───────────────┼───────────┼──────────────┼────────┼─────────┤
│ firewallservices/pf-scan-multi_ports │ 10 │ - │ 103 │ 106 │ 93 │
╰──────────────────────────────────────┴───────────────┴───────────┴──────────────┴────────┴─────────╯
╭───────────────────────────────────────────────────────────────────────────────────────╮
│ Whitelist Metrics │
├────────────────────────────────────┬─────────────────────────────┬──────┬─────────────┤
│ Whitelist │ Reason │ Hits │ Whitelisted │
├────────────────────────────────────┼─────────────────────────────┼──────┼─────────────┤
│ crowdsecurity/public-dns-allowlist │ public DNS server │ 770 │ 21 │
│ crowdsecurity/whitelists │ private ipv4/ipv6 ip/ranges │ 770 │ 117 │
╰────────────────────────────────────┴─────────────────────────────┴──────┴─────────────╯
[2.8.1-RELEASE][admin@fw1.exclusivetic.local]/root:
</details>
### Related custom configs versions (if applicable) : notification plugins, custom scenarios, parsers etc.
<details>
</details>
1 条评论