| `-- Installing oniguruma-6.9.10... | `-- Extracting oniguruma-6.9.10: .......... done `-- Extracting php82-mbstring-8.2.27: .......... done Extracting php82-phalcon-5.8.0: ........ done ===== Message from php82-session-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-18-session.ini.sample ===== Message from php82-mbstring-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-mbstring.ini.sample ===== Message from php82-phalcon-5.8.0: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-30-phalcon.ini.sample Installing php82-phpseclib-3.0.42... Extracting php82-phpseclib-3.0.42: ......... done Installing php82-session-8.2.27... the most recent version of php82-session-8.2.27 is already installed Installing php82-simplexml-8.2.27... Extracting php82-simplexml-8.2.27: ......... done ===== Message from php82-simplexml-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-simplexml.ini.sample Installing php82-sockets-8.2.27... Extracting php82-sockets-8.2.27: .......... done ===== Message from php82-sockets-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-sockets.ini.sample Installing php82-sqlite3-8.2.27... `-- Installing sqlite3-3.46.1,1... `-- Extracting sqlite3-3.46.1,1: .......... done Extracting php82-sqlite3-8.2.27: ......... done ===== Message from php82-sqlite3-8.2.27: -- This file has been added to automatically load the installed extension: /usr/local/etc/php/ext-20-sqlite3.ini.sample Installing php82-xml-8.2.27... the most recent version of php82-xml-8.2.27 is already installed Installing php82-zlib-8.2.27... the most recent version of php82-zlib-8.2.27 is already installed Installing pkg-1.19.2_5... the most recent version of pkg-1.19.2_5 is already installed Installing py311-Jinja2-3.1.4... `-- Installing py311-markupsafe-2.1.5_1... `-- Extracting py311-markupsafe-2.1.5_1: .......... done `-- Installing py311-Babel-2.16.0... | `-- Installing py311-setuptools-63.1.0_1... | `-- Extracting py311-setuptools-63.1.0_1: .......... done `-- Extracting py311-Babel-2.16.0: .......... done Extracting py311-Jinja2-3.1.4: .......... done Installing py311-dnspython-2.7.0,1... `-- Installing py311-httpx-0.28.1... | `-- Installing py311-httpcore-1.0.7... | | `-- Installing py311-h2-4.1.0... | | `-- Installing py311-hyperframe-6.0.0... | | `-- Extracting py311-hyperframe-6.0.0: .......... done | | `-- Installing py311-hpack-4.0.0... | | `-- Extracting py311-hpack-4.0.0: .......... done | | `-- Extracting py311-h2-4.1.0: .......... done | | `-- Installing py311-certifi-2024.12.14... | | `-- Extracting py311-certifi-2024.12.14: .......... done | | `-- Installing py311-h11-0.14.0... | | `-- Extracting py311-h11-0.14.0: .......... done | | `-- Installing py311-anyio-4.7.0... | | `-- Installing py311-truststore-0.10.0... | | `-- Extracting py311-truststore-0.10.0: .......... done | | `-- Installing py311-idna-3.10... | | `-- Extracting py311-idna-3.10: .......... done | | `-- Installing py311-typing-extensions-4.12.2... | | `-- Extracting py311-typing-extensions-4.12.2: .......... done | | `-- Installing py311-sniffio-1.3.1... | | `-- Extracting py311-sniffio-1.3.1: .......... done | | `-- Extracting py311-anyio-4.7.0: .......... done | `-- Extracting py311-httpcore-1.0.7: .......... done | `-- Installing py311-socksio-1.0.0_1... | `-- Extracting py311-socksio-1.0.0_1: .......... done `-- Extracting py311-httpx-0.28.1: .......... done `-- Installing py311-aioquic-1.2.0... | `-- Installing py311-pylsqpack-0.3.18... | `-- Extracting py311-pylsqpack-0.3.18: .......... done | `-- Installing py311-service-identity-24.2.0... | | `-- Installing py311-cryptography-42.0.8_5,1... | | `-- Installing py311-cffi-1.17.1... | | | `-- Installing py311-pycparser-2.22... | | | `-- Extracting py311-pycparser-2.22: .......... done | | `-- Extracting py311-cffi-1.17.1: .......... done | | `-- Extracting py311-cryptography-42.0.8_5,1: .......... done | | `-- Installing py311-pyasn1-modules-0.4.0... | | `-- Installing py311-pyasn1-0.6.0... | | `-- Extracting py311-pyasn1-0.6.0: .......... done | | `-- Extracting py311-pyasn1-modules-0.4.0: .......... done | | `-- Installing py311-attrs-24.3.0... | | `-- Extracting py311-attrs-24.3.0: .......... done | `-- Extracting py311-service-identity-24.2.0: .......... done | `-- Installing py311-openssl-24.1.0,1... | `-- Extracting py311-openssl-24.1.0,1: .......... done `-- Extracting py311-aioquic-1.2.0: .......... done `-- Installing py311-trio-0.28.0... | `-- Installing py311-sortedcontainers-2.4.0... | `-- Extracting py311-sortedcontainers-2.4.0: .......... done | `-- Installing py311-outcome-1.3.0_1... | `-- Extracting py311-outcome-1.3.0_1: .......... done | `-- Installing py311-async_generator-1.10... | `-- Extracting py311-async_generator-1.10: .......... done `-- Extracting py311-trio-0.28.0: .......... done Extracting py311-dnspython-2.7.0,1: .......... done Installing py311-ldap3-2.9.1... Extracting py311-ldap3-2.9.1: .......... done Installing py311-netaddr-1.3.0... Extracting py311-netaddr-1.3.0: .......... done Installing py311-requests-2.32.3... `-- Installing py311-charset-normalizer-3.4.1_1... `-- Extracting py311-charset-normalizer-3.4.1_1: .......... done `-- Installing py311-urllib3-1.26.20,1... | `-- Installing py311-pysocks-1.7.1_1... | `-- Extracting py311-pysocks-1.7.1_1: .......... done `-- Extracting py311-urllib3-1.26.20,1: .......... done Extracting py311-requests-2.32.3: .......... done ===== Message from py311-urllib3-1.26.20,1: -- Since version 1.25 HTTPS connections are now verified by default which is done via "cert_reqs = 'CERT_REQUIRED'". While certificate verification can be disabled via "cert_reqs = 'CERT_NONE'", it's highly recommended to leave it on. Various consumers of net/py-urllib3 already have implemented routines that either explicitly enable or disable HTTPS certificate verification (e.g. via configuration settings, CLI arguments, etc.). Yet it may happen that there are still some consumers which don't explicitly enable/disable certificate verification for HTTPS connections which could then lead to errors (as is often the case with self-signed certificates). In case of an error one should try first to temporarily disable certificate verification of the problematic urllib3 consumer to see if that approach will remedy the issue. Installing py311-sqlite3-3.11.11_7... Extracting py311-sqlite3-3.11.11_7: ........ done Installing py311-ujson-5.10.0... Extracting py311-ujson-5.10.0: ......... done Installing py311-vici-5.9.11... Extracting py311-vici-5.9.11: .......... done Installing radvd-2.19_4... Extracting radvd-2.19_4: .......... done Installing rrdtool-1.9.0... `-- Installing glib-2.80.5_1,2... | `-- Installing py311-packaging-24.2... | `-- Extracting py311-packaging-24.2: .......... done | `-- Installing libiconv-1.17_1... | `-- Extracting libiconv-1.17_1: .......... done `-- Extracting glib-2.80.5_1,2: .......... done Extracting rrdtool-1.9.0: .......... done Compiling glib schemas No schema files found: doing nothing. Generating GIO modules cache Installing samplicator-1.3.8.r1_1... Extracting samplicator-1.3.8.r1_1: ..... done Installing strongswan-5.9.14... Extracting strongswan-5.9.14: .......... done ===== Message from strongswan-5.9.14: -- The default strongSwan configuration interface have been updated to vici since version 5.9.2_1. To use the stroke interface by default either compile the port without the vici option or set 'strongswan_interface="stroke"' in your rc.conf file. Installing sudo-1.9.16p2... Extracting sudo-1.9.16p2: .......... done Installing syslog-ng-4.8.1_3... `-- Installing e2fsprogs-libuuid-1.47.1... `-- Extracting e2fsprogs-libuuid-1.47.1: .......... done `-- Installing json-c-0.18... `-- Extracting json-c-0.18: .......... done `-- Installing ivykis-0.43.2... `-- Extracting ivykis-0.43.2: .......... done Extracting syslog-ng-4.8.1_3: .......... done ===== Message from syslog-ng-4.8.1_3: -- syslog-ng is now installed! To replace FreeBSD's standard syslogd (/usr/sbin/syslogd), complete these steps: 1. Create a configuration file named /usr/local/etc/syslog-ng.conf (a sample named syslog-ng.conf.sample has been included in /usr/local/etc). Note that this is a change in 2.0.2 version, previous ones put the config file in /usr/local/etc/syslog-ng/syslog-ng.conf, so if this is an update move that file in the right place 2. Configure syslog-ng to start automatically by adding the following to /etc/rc.conf: syslog_ng_enable="YES" 3. Prevent the standard FreeBSD syslogd from starting automatically by adding a line to the end of your /etc/rc.conf file that reads: syslogd_enable="NO" 4. Shut down the standard FreeBSD syslogd: kill `cat /var/run/syslog.pid` 5. Start syslog-ng: /usr/local/etc/rc.d/syslog-ng start Installing unbound-1.22.0_1... `-- Installing libsodium-1.0.19... `-- Extracting libsodium-1.0.19: .......... done ===> Creating groups Using existing group 'unbound' ===> Creating users Using existing user 'unbound' Extracting unbound-1.22.0_1: .......... done Installing wpa_supplicant-2.11_2... Extracting wpa_supplicant-2.11_2: ....... done ===== Message from wpa_supplicant-2.11_2: -- To use the ports version of WPA Supplicant instead of the base, add: wpa_supplicant_program="/usr/local/sbin/wpa_supplicant" to /etc/rc.conf Installing zip-3.0_4... Extracting zip-3.0_4: .......... done Installing beep-1.0_2... Extracting beep-1.0_2: ..... done ===== Message from beep-1.0_2: -- Speaker sound support: ====================== For PC speaker sound to work you need to be in the operator group and need r/w permissions to /dev/speaker device. Load kernel module: # kldload speaker Add a user to operator group: % pw groupmod operator -m jerry Uncomment the following lines in /etc/devfs.rules file (create it if it doesn't exist): # Allow members of group operator to cat things to the speaker [speaker=10] add path 'speaker' mode 0660 group operator To load these new rules add the following to /etc/rc.conf: devfs_speaker_ruleset="speaker" Then restart devfs to load the new rules: % /etc/rc.d/devfs restart Installing py311-duckdb-1.1.3... `-- Installing py311-pandas-2.1.4,1... | `-- Installing py311-numpy-1.26.4_2,1... | `-- Extracting py311-numpy-1.26.4_2,1: .......... done | `-- Installing py311-numexpr-2.10.2... | `-- Extracting py311-numexpr-2.10.2: .......... done | `-- Installing py311-bottleneck-1.3.8_1... | `-- Extracting py311-bottleneck-1.3.8_1: .......... done | `-- Installing py311-tzdata-2024.2... | `-- Extracting py311-tzdata-2024.2: .......... done | `-- Installing py311-pytz-2024.2,1... | `-- Extracting py311-pytz-2024.2,1: .......... done | `-- Installing py311-python-dateutil-2.9.0... | | `-- Installing py311-six-1.17.0... | | `-- Extracting py311-six-1.17.0: .......... done | `-- Extracting py311-python-dateutil-2.9.0: .......... done `-- Extracting py311-pandas-2.1.4,1: .......... done Extracting py311-duckdb-1.1.3: .......... done ===== Message from py311-pandas-2.1.4,1: -- Install math/py-statsmodels to enable parts of pandas.stats. Install devel/py-xarray to enable the to_xarray() function. Installing py311-numpy-1.26.4_2,1... the most recent version of py311-numpy-1.26.4_2,1 is already installed Installing py311-pandas-2.1.4,1... the most recent version of py311-pandas-2.1.4,1 is already installed Installing suricata-7.0.8... `-- Installing libyaml-0.2.5... `-- Extracting libyaml-0.2.5: ......... done `-- Installing nss-3.107... | `-- Installing nspr-4.36... | `-- Extracting nspr-4.36: .......... done `-- Extracting nss-3.107: .......... done `-- Installing libnet-1.3,1... `-- Extracting libnet-1.3,1: .......... done `-- Installing py311-pyyaml-6.0.1... `-- Extracting py311-pyyaml-6.0.1: .......... done `-- Installing jansson-2.14... `-- Extracting jansson-2.14: .......... done `-- Installing hyperscan-5.4.2... `-- Extracting hyperscan-5.4.2: .......... done Extracting suricata-7.0.8: .......... done ===== Message from suricata-7.0.8: -- If you want to run Suricata in IDS mode, add to /etc/rc.conf: suricata_enable="YES" suricata_interface="" NOTE: Declaring suricata_interface is MANDATORY for Suricata in IDS Mode. However, if you want to run Suricata in Inline IPS Mode in divert(4) mode, add to /etc/rc.conf: suricata_enable="YES" suricata_divertport="8000" NOTE: Suricata won't start in IDS mode without an interface configured. Therefore if you omit suricata_interface from rc.conf, FreeBSD's rc.d/suricata will automatically try to start Suricata in IPS Mode (on divert port 8000, by default). Alternatively, if you want to run Suricata in Inline IPS Mode in high-speed netmap(4) mode, add to /etc/rc.conf: suricata_enable="YES" suricata_netmap="YES" NOTE: Suricata requires additional interface settings in the configuration file to run in netmap(4) mode. RULES: Suricata IDS/IPS Engine comes without rules by default. You should add rules by yourself and set an updating strategy. To do so, please visit: http://www.openinfosecfoundation.org/documentation/rules.html http://www.openinfosecfoundation.org/documentation/emerging-threats.html You may want to try BPF in zerocopy mode to test performance improvements: sysctl -w net.bpf.zerocopy_enable=1 Don't forget to add net.bpf.zerocopy_enable=1 to /etc/sysctl.conf >>> Staging files for opnsense-24.7.11_14... done >>> Generated version info for opnsense-24.7.11_14: { "product_abi": "24.7", "product_arch": "amd64", "product_conflicts": "os-firewall os-firewall-devel os-wireguard os-wireguard-devel os-wireguard-go os-wireguard-go-devel", "product_copyright_owner": "Deciso B.V.", "product_copyright_url": "https://www.deciso.com/", "product_copyright_years": "2014-2025", "product_email": "project@opnsense.org", "product_hash": "a675e29e2", "product_id": "opnsense", "product_name": "OPNsense", "product_nickname": "Thriving Tiger", "product_series": "24.7", "product_tier": "1", "product_version": "24.7.11_14", "product_website": "https://opnsense.org/" } >>> Generating metadata for opnsense-24.7.11_14... done >>> Packaging files for opnsense-24.7.11_14: file sizes/checksums [2262]: .......... done packing files [2262]: .......... done packing directories [0]: . done Creating repository in /usr/obj/usr/tools/config/24.7/amd64/.pkg-new/: .......... done Packing files for repository: .... done >>> Removing packages set >>> Creating package mirror set for 25.1.b_165-amd64... done -rw-r--r-- 1 root wheel 971M Jan 10 14:30 packages-25.1.b_165-amd64.tar >>> WARNING: The build provided additional info. >>> Rebuilt version 24.7.11_14 for opnsense 60.38 real 48.87 user 17.39 sys