pfSense bugtracker: Issueshttps://redmine.pfsense.org/https://redmine.pfsense.org/favicon.ico?16780521162024-03-28T15:30:27ZpfSense bugtracker
Redmine pfSense Plus - Feature #15368 (New): Bulk import DHCP host reservationshttps://redmine.pfsense.org/issues/153682024-03-28T15:30:27ZChris W
<p>It'd be a huge time saver to import from a CSV or XML file into Kea, or even just pasting into a text field like Firewall > Alias > Bulk Import currently does.</p> pfSense Plus - Feature #15306 (New): Change Gateway Status from Pending to Unavailablehttps://redmine.pfsense.org/issues/153062024-03-03T01:25:28ZKris Phillips
<p>Per customer statement and request, gateway statuses of "Pending" are confusing as a state for gateways that do not exist yet due to dynamic allocation. Something like a state of "Unavailable" may be more appropriate wording.</p> pfSense Plus - Feature #15305 (New): Gateway Status Changes to Pending Do Not Trigger Gateway Log...https://redmine.pfsense.org/issues/153052024-03-03T01:22:28ZKris Phillips
<p>When a gateway transitions from an Online state to a Pending state, there is no logged event in the Gateway monitoring logs currently to state that the gateway has become unavailable.</p>
<p>Additionally, Email/System Notifications will send a notification for Gateway Up/Down events, but will not send a notification for changes to and from a Pending state. This would be useful for things like ISP equipment power loss or failures where the physical link is lost.</p> pfSense Plus - Feature #15295 (New): State Filter Rule ID needs clarificationhttps://redmine.pfsense.org/issues/152952024-02-28T23:38:28ZMike Moore
<p>Not sure if this is a feature request but this isn't a bug.</p>
<p>See the forum post for details - <a class="external" href="https://forum.netgate.com/topic/186429/no-states-show-up-when-filtering-by-trackerid/5?_=1709161373761">https://forum.netgate.com/topic/186429/no-states-show-up-when-filtering-by-trackerid/5?_=1709161373761</a></p>
<p>Searching for states under Diagnostics/States/States and if you filter by Rule ID I mistakingly thought this meant TrackerID. The RuleID shows up if you hover over the state's entry of the firewall rule in the GUI and look at the bottom of the WebUI url and it will show what the corresponding ruleID is.</p>
<p>This doesnt make much sense considering if I search the firewall log in the WebUI and if i filter by "Rule Tracker ID" I can submit the TrackerID there and im able to narrow down my search whereas if i filter in the states screen nothing matches Rule ID because it's specifically looking for a number that the system generates for the Rule but there is no place in the UI to even know what that rule number could or would be.</p>
<p>The solution would be to either:<br />1. Fix the State filter so that it can filter by tracker ID instead of Rule ID<br />2. OR update documentation to inform users of the best place to find the rule ID.</p> pfSense Plus - Feature #15284 (New): Specify a Device parameter for Pushover Notificationshttps://redmine.pfsense.org/issues/152842024-02-22T03:14:10ZMichael Klein
<p>Hello,</p>
<p>Can you please add the ability to specify a DEVICE parameter for Pushover notifications so that a notification is sent to a specific device under that user account instead of ALL DEVICES under that user account? The menu is located at: System, Advanced, Notifications, Pushover.</p>
<p>Thank you!</p> pfSense Plus - Feature #15280 (New): Boot Environments 2.0https://redmine.pfsense.org/issues/152802024-02-21T19:59:52ZChristian McDonaldcmcdonald@netgate.com
<p>Changes:</p>
<ul>
<li>Configuration History is now a separate page and is no longer part of Backup & Restore.</li>
<li>Configuration History is now aware of Boot Environments. Supports downloading, deleting and restoring across boot environment boundaries.</li>
<li>System updates are now installed in an offline clone of the running system and booted "temporarily" to facilitate automatic fallback to previous working environment.</li>
<li>Boot Verification is performed when booting temporary Boot Environments. System will automatically reboot into prior boot environment upon boot failure.</li>
</ul>
<p><img src="https://redmine.pfsense.org/attachments/download/5936/clipboard-202402211456-bdjnl.png" alt="" /><br /><img src="https://redmine.pfsense.org/attachments/download/5937/clipboard-202402211457-fegcy.png" alt="" /><br /><img src="https://redmine.pfsense.org/attachments/download/5938/clipboard-202402211457-rbjkq.png" alt="" /><br /><img src="https://redmine.pfsense.org/attachments/download/5939/clipboard-202402211457-fcvqv.png" alt="" /><br /><img src="https://redmine.pfsense.org/attachments/download/5940/clipboard-202402211458-ydyne.png" alt="" /></p> pfSense Plus - Todo #15266 (Feedback): Prevent usage of the default password in User Manager acco...https://redmine.pfsense.org/issues/152662024-02-16T18:53:24ZJim Pingle
<p>Currently we detect in the GUI when the admin account is using the default password (<code>"pfsense"</code>) and print a warning message: source:src/usr/local/www/head.inc#L564</p>
<p>We should change that to check any account (not just <code>admin</code>) and force a password change during one or more of the user's initial interactions, for example:</p>
<ul>
<li>During the setup wizard</li>
<li>GUI login any time the password matches the default password</li>
<li>Shell (console or SSH) login any time the password matches the default password</li>
<li>Possibly during the installation process</li>
</ul>
<p>We should also not allow the user to change their password to any variation of "pfsense" in upper/lower/mixed case.</p> pfSense Plus - Feature #15186 (New): Test DNS over TLShttps://redmine.pfsense.org/issues/151862024-01-24T23:57:32ZJeff Kuehl
<p>The ability to readily confirm TLS DNS would be established once saved.</p> pfSense Plus - Feature #15070 (New): Script to fix: ld-elf.so.1: Shared object "libssl.so.30" not...https://redmine.pfsense.org/issues/150702023-12-06T05:14:20ZJonathan Lee
<p>When using boot environments to move system back a version to last stable version users can no longer check for updates. This version is displayed under GUI as a version to still use. Thus a boot environment should not contain this error for standard users it should default back also.</p>
<p>Error is:<br /><code>ld-elf.so.1: Shared object "libssl.so.30" not found, required by "pfSense-repoc"</code></p>
<p>stephenw10 fixed my issue with the linked library Boot Environment issue for plus</p>
<p><code>pkg-static upgrade -f pfSense-repoc</code></p>
<p>can we add a simple script that will auto run this command when users change to an older boot environment have a try catch error condition for this?</p>
<p>That way previous stable version boot environments do not see this error.</p> pfSense Plus - Feature #15022 (New): Package install/reinstall feature request.https://redmine.pfsense.org/issues/150222023-11-22T01:23:31ZJonathan Lee
<p>Hello fellow Redmine community members. I have noticed time and time again I have the ability to scroll during package installs to see the what package dependencies are installing and to check version numbers but I can't get it to stay still for longer than a split second before it auto scrolls back to the bottom. Can we make this stay where users are when the scroll and remove the auto scroll function?</p>
<p>We currently have no way to see the dependency information after it scrolls past because auto scroll takes us back to the bottom again.</p>
<p>See attached photo, I wanted to check what dependency versions were installed, Everytime you scroll it defaults to bottom again.</p> pfSense Plus - Feature #15013 (New): Speed Shift - Add Field to control lowest C-Statehttps://redmine.pfsense.org/issues/150132023-11-19T14:56:54ZDieter Kreuz
<p>Dear pfSense-team,</p>
<p>after updating to 2.7.1 i was curious how well the new speed shift GUI entries work.<br />In fact after adjusting it to per core and a value of 90, i can see my i3-7100U is able to clock somewhat lower and park the cores more often.</p>
<p>One thing in noticed with the command:<br />sysctl dev.cpu | grep cx_</p>
<p>is, that my CPU supports C1 and C2, but the lowest c-state setting was set to C1 by default:<br />dev.cpu.0.cx_method: C1/mwait/hwc C2/mwait/hwc<br />dev.cpu.0.cx_lowest: C1</p>
<p>By adding the following command to the tunables:<br />hw.acpi.cpu.cx_lowest = C2</p>
<p>I was able to get the CPU to use its C2-states too. Another XEON-pfsense setup was able to use its C3 states as well, by using the commands stated.<br />One is able to see the usage of c-states with the following command:<br />sysctl dev.cpu | grep cx_usage</p>
<p>dev.cpu.0.cx_usage_counters: 3717721 111658492<br />dev.cpu.0.cx_usage: 3.22% 96.77% last 294us</p>
<p>Would it be possible to add a new selection-field to the now existing speedshift-gui in order to be able to select the lowest c-state.<br />May the selectable values can be parsed from the cpus cabability, which is represented by the values of "dev.cpu.0.cx_method".</p>
<p>Thanks in advance.<br />Best regards<br />Dieter</p> pfSense Plus - Feature #14976 (New): Cleaner way to know if an interface failedhttps://redmine.pfsense.org/issues/149762023-11-13T15:36:44ZMike Moore
<p>When an interface status changes from UP to DOWN or is flapping, there are other syslog messages that get generated because of it, such as packages restarting and dpinger restarting interfaces, etc.. This makes finding root cause very difficult as one has to shift through the noise as i recently had to do.</p>
<p>See forum post here: <a class="external" href="https://forum.netgate.com/topic/184059/random-disconnect/12?_=1699889265804">https://forum.netgate.com/topic/184059/random-disconnect/12?_=1699889265804</a></p>
<p>Request: Maybe have Kernel messages in a separate tab in the System > Logs menu. Or maybe just have some method in the GUI to indicate that a link did flap - some notification.</p>
<p>Juniper Networks keeps a timer counter of when the link last flapped when a 'show interface' command is given. This is helpful in knowing when a link issue occurred.</p> pfSense Plus - Feature #14743 (New): Add Passkey/Certificate-based Authenticationhttps://redmine.pfsense.org/issues/147432023-09-03T04:21:49ZKris Phillips
<p>pfSense Plus's webConfigurator is currently limited in authentication for local auth, requiring third party implementations to add 2FA or other authentication means.</p>
<p>There is already redmine 12546 for adding 2FA to pfSense Plus natively, but it would also be beneficial to add passkey/cert-based authentication to pfSense Plus' webConfigurator and other functions.</p> pfSense Plus - Feature #14297 (New): Add Option for Vendor Class ID in DHCP Clienthttps://redmine.pfsense.org/issues/142972023-04-21T15:07:26ZKris Phillips
<p>Some ISPs require a Vendor Class ID be sent (option 60) when requesting DHCP. This can currently be accomplished in pfSense with vendor-class-identifier manually added to a dhcp config file, but adding this as a field would be helpful.</p> pfSense Plus - Feature #12832 (New): 6100 configurable Blinking Blue LED https://redmine.pfsense.org/issues/128322022-02-19T11:56:10Zshawn butts
<p>The blinking blue like for "normal operation status" feels like an "everything is ok ALARM!!!!"</p>
<p>I'd like to see an option to either make it solid blue for "normal" or disable the LED altogether.</p>