The Handbook

    Theme
    • Guides
        • Check a system before installing FreeBSD
        • Orient a Linux administrator on FreeBSD
        • Supported FreeBSD releases
        • Choose a FreeBSD documentation and support channel
        • Move files safely without GNU mv -t
        • Update, upgrade, or update packages?
        • Upgrade 14.4 or 15.0 to FreeBSD 15.1
        • Choose packages, ports, or poudriere
        • Choose the quarterly or latest package branch
        • Choose a FreeBSD download or package mirror
        • Make a system setting persistent
        • Configure locale, keyboard, and time zone
        • Configure a serial console for recovery
        • Choose a custom kernel, module, or loader setting
        • Run a Linux binary with the compatibility layer
        • Check desktop and laptop hardware before installation
        • Choose and check a graphics driver
        • Choose Xorg or Wayland
        • Build a maintainable desktop baseline
        • Install and check a desktop browser
        • Check laptop Wi-Fi, power, and suspend
        • Check multimedia readiness
        • Choose and configure a printing stack
        • Run Windows applications with Wine
        • Snapshot and replicate a ZFS dataset
        • Choose a filesystem and storage layout
        • Operate ZFS without losing the recovery path
        • Restore files from a ZFS snapshot
        • Read ZFS pool health and run a scrub
        • Replace a failed device in a ZFS mirror
        • Replicate a ZFS dataset over SSH
        • Change PF safely on a remote host
        • Configure a narrow WireGuard tunnel
        • Plan a FreeBSD home server
        • Choose a mail server or an outgoing relay
        • Publish a network service safely
        • Choose a jail network model
        • Choose native jails or a jail manager
        • Choose a jail or a bhyve virtual machine
        • Establish a FreeBSD security baseline
        • Choose a MAC policy
        • Audit security-relevant activity
        • Start a DTrace performance investigation
    • Integrations
        • Create a first jail with Bastille
        • Compare jail managers and OCI tooling
        • Publish a Bastille service through PF
        • Mount a ZFS dataset in a Bastille jail
        • Update and upgrade Bastille jails
        • Back up and restore a Bastille jail
        • Prepare bhyve and vm-bhyve
        • Choose NFS or Samba for file sharing
        • Choose ZFS backup automation
        • Operate a signed poudriere repository
        • Manage FreeBSD configuration with Ansible or Salt
        • Run Motion with webcamd on FreeBSD
        • Design a reverse proxy, certificates, and monitoring
    • FAQ
      • Troubleshooting
          • Recover an interrupted freebsd-update run
          • Resolve a package repository or ABI mismatch
          • Diagnose the FreeBSD boot path
          • Recover with a ZFS boot environment
          • Diagnose DNS, routing, and firewall paths
          • Diagnose network mbuf exhaustion
          • Bind a service to a low port without running it as root
          • Diagnose audio output or input
          • Diagnose webcamd, cuse, and a webcam
          • Fix USB device permissions without opening every device
      • About this handbook
      • Choose a task
        • Installation and orientation
        • Releases, packages, and settings
        • Desktop, laptop, and multimedia
        • Storage and ZFS
        • Hosts, isolation, networking, and security

      Guides

      Choose a task #

      Guides favor reproducible checks, reversible changes, and links to primary documentation. Confirm that a page lists the installed FreeBSD release before applying its commands.

      Installation and orientation #

      • Supported FreeBSD releases records the current maintenance boundary from one data source.
      • Check a system before installing FreeBSD covers release, storage, network, application, and recovery decisions.
      • Check desktop and laptop hardware establishes device-level evidence before installation.
      • Orient a Linux administrator on FreeBSD maps services, packages, devices, and configuration without assuming Linux conventions.
      • Move files without GNU mv -t translates target-directory commands into native operand order and safe find batches.
      • Choose a FreeBSD documentation and support channel routes interface, procedure, release, community, package, vendor, and defect questions to the right owner.
      • Configure locale, keyboard, and time zone keeps login locale, console keymap, graphical input, civil time, and clock synchronization separate.

      Releases, packages, and settings #

      • Update, upgrade, or update packages? separates base-system, release, package, and pkgbase maintenance.
      • Upgrade 14.4 or 15.0 to FreeBSD 15.1 provides a release-specific checklist and recovery boundaries.
      • Choose the quarterly or latest package branch makes repository cadence an explicit system policy.
      • Choose packages, ports, or poudriere selects a coherent third-party software workflow.
      • Choose a download or package mirror preserves automatic selection, verification, and fallback.
      • Make a system setting persistent distinguishes runtime, loader, and service configuration.
      • Choose a custom kernel, module, or loader setting preserves GENERIC unless a narrower mechanism cannot meet a stated requirement.

      Desktop, laptop, and multimedia #

      • Choose and check a graphics driver starts from the actual GPU and its maintained driver.
      • Choose Xorg or Wayland compares application, graphics, remote-access, and maintenance requirements.
      • Build a maintainable desktop baseline proves a small session before adding a display manager and applications.
      • Install and check a desktop browser separates browser failures from desktop, audio, and camera failures.
      • Check laptop Wi-Fi, power, and suspend tests the machine-specific laptop path.
      • Check multimedia readiness routes graphics, audio, camera, browser, and USB evidence by workload.
      • Run a Linux binary with the compatibility layer explains the Linux ABI and userland boundary.
      • Run Windows applications with Wine qualifies executable architecture, prefixes, host graphics and audio, and the VM boundary.
      • Choose and configure a printing stack selects base lpd or packaged CUPS from client, protocol, driver, discovery, and exposure needs.

      Storage and ZFS #

      • Choose a filesystem and storage layout separates storage policy, availability, and backup.
      • Operate ZFS without losing the recovery path routes snapshot, restore, replication, integrity, and device tasks.
      • Snapshot and replicate a ZFS dataset creates and verifies a point-in-time copy on another pool.
      • Restore files from a ZFS snapshot recovers selected files without rolling back a dataset.
      • Replicate a ZFS dataset over SSH defines remote authority, incremental state, and resumption boundaries.
      • Read pool health and run a scrub distinguishes integrity checks from backups.
      • Replace a failed device in a ZFS mirror covers one deliberately narrow replacement topology.

      Hosts, isolation, networking, and security #

      • Plan a FreeBSD home server starts from storage, service, exposure, and recovery boundaries.
      • Publish a network service safely makes software, runtime, listener, firewall, identity, data, update, and restore ownership explicit.
      • Configure a serial console for recovery verifies firmware, loader, kernel, single-user, and login access as separate stages.
      • Choose native jails or a jail manager decides whether a management layer earns its operational surface.
      • Choose a jail network model compares private NAT, shared-address, and VNET paths.
      • Choose a jail or a bhyve virtual machine selects the smallest suitable kernel and machine boundary.
      • Change PF safely on a remote host plans validation, observation, and rollback before loading rules.
      • Configure a narrow WireGuard tunnel avoids silently replacing the default route.
      • Choose a mail server or outgoing relay separates local delivery, authenticated relay, and public mail service.
      • Establish a security baseline records exposure, privilege, maintenance, recovery, and evidence before optional hardening.
      • Choose a MAC policy starts from a testable denial and the narrowest policy that can enforce it.
      • Audit security-relevant activity defines attribution, event selection, trail storage, review, privacy, and failure behavior.
      • Start a DTrace performance investigation moves from ordinary counters to one bounded traceable question.

      Independent documentation. Not affiliated with or endorsed by the FreeBSD Project or the FreeBSD Foundation.

      Report a bug
      • Choose a task
        • Installation and orientation
        • Releases, packages, and settings
        • Desktop, laptop, and multimedia
        • Storage and ZFS
        • Hosts, isolation, networking, and security