Project

General

Profile

Activity

From 10/19/2021 to 11/17/2021

11/02/2021

03:38 PM Correction #9370: Update old screenshots
Cellular doc updated: https://gitlab.netgate.com/docs/pfSense-docs/-/commit/971d0fb77b22a551713108c35812932e24acee6f
...
Jim Pingle

11/01/2021

03:29 PM Correction #9370: Update old screenshots
Nut is updated:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/d9fc04f46bacb750a9a37c3e51d5b7d790841644
...
Jim Pingle
01:12 AM Todo #12496 (Closed): Feedback on Virtual Private Networks — OpenVPN — Controlling Client Parameters via RADIUS
*Page:* https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/client-parameters-radius.html
*Feedback:*
Better...
Viktor Gurov

10/29/2021

03:20 PM Correction #9370 (In Progress): Update old screenshots
* Updated RFC 1918 egress prevention recipe
* https://gitlab.netgate.com/docs/pfSense-docs/-/commit/597814b04beef...
Jim Pingle
07:37 AM Todo #11812 (Closed): Feedback on pfSense Configuration Recipes — Configuring IPv6 Through A Tunnel Broker Service
Jim Pingle
07:36 AM Todo #11743 (Closed): Feedback on Virtual Private Networks — VPN Scaling
Jim Pingle
07:36 AM New Content #12432 (Closed): Add documentation for DNS Resolver Status page
Jim Pingle
07:36 AM Todo #12429 (Closed): Feedback on Bridging
Jim Pingle
07:36 AM Correction #11176 (Closed): Feedback on Services — DNS Resolver
Jim Pingle
07:36 AM Todo #11417 (Closed): Feedback on Services — DNS Resolver — DNS Resolver Advanced Options
Jim Pingle
07:36 AM Correction #9373 (Closed): Feedback on Services — DNS — Configuring the DNS Resolver
Jim Pingle
07:35 AM Correction #9394 (Closed): Feedback on Services — DNS — Configuring the DNS Resolver
Jim Pingle
07:35 AM Todo #12182 (Closed): Update IPsec to match recent changes
Jim Pingle

10/28/2021

12:24 PM New Content #9753 (Feedback): Feedback on Installing and Upgrading — Writing Disk Images
Step 2: I replaced the info in the pfSense docs with just the Etcher info, and linked to the main reference doc for a... Jim Pingle
11:12 AM New Content #9753: Feedback on Installing and Upgrading — Writing Disk Images
Step 1: I updated the main shared reference doc with info on Etcher and made other updates as well
https://gitlab....
Jim Pingle
10:14 AM New Content #9753 (In Progress): Feedback on Installing and Upgrading — Writing Disk Images
I've already been working on this Jim Pingle

10/27/2021

01:05 PM Correction #12471: AES-XCBC should not be recommended as PRF for IPsec
Kev Kitchens wrote in #note-5:
> Totally understandable, although I believe most CPUs supporting AES-NI would also l...
Jim Pingle
12:55 PM Todo #12478 (Feedback): Feedback on Virtual Private Networks — IPsec — Mobile IPsec — Choosing a Mobile IPsec Style
Added to staged 22.01 docs:
https://gitlab.netgate.com/docs/pfSense-docs/-/commit/64cbd3b581c737171e0f592994b7bbce...
Jim Pingle

10/25/2021

05:24 PM Correction #12469: Automatic outbound NAT rules are applied to the WG interface
Brett Keller wrote in #note-8:
> Setting an upstream gateway includes the interface in automatic outbound NAT rule g...
Brett Keller

10/22/2021

08:42 PM Correction #12471: AES-XCBC should not be recommended as PRF for IPsec
Thanks for taking this up Jim!
> Originally that was recommended as it would result in the highest performance on ...
Kev Kitchens
01:11 PM Correction #12471 (Feedback): AES-XCBC should not be recommended as PRF for IPsec
Fixed in https://gitlab.netgate.com/docs/pfSense-docs/-/commit/5086c307ec3b213edcc7efbfc82eabf416053ce3 but won't be ... Jim Pingle
12:39 PM Correction #12471: AES-XCBC should not be recommended as PRF for IPsec
It's also worth noting that the native IPsec client in Android 11 and 12 does support AES-XCBC and has it listed befo... Jim Pingle
09:58 AM Correction #12471: AES-XCBC should not be recommended as PRF for IPsec
Originally that was recommended as it would result in the highest performance on systems with hardware acceleration f... Jim Pingle

10/21/2021

05:15 PM Correction #12471: AES-XCBC should not be recommended as PRF for IPsec
For some further justification, the NIST Guide to IPsec VPNs (SP 800-77) does not list AES-XCBC as an approved PRF al... Kev Kitchens

10/20/2021

05:53 PM Correction #12469: Automatic outbound NAT rules are applied to the WG interface
Christian McDonald wrote in #note-3:
> For assigned tunnel interfaces, the inverse is true...pfSense has no way of k...
Brett Keller
10:25 AM Correction #12469 (Closed): Automatic outbound NAT rules are applied to the WG interface
Merged and deployed. Jim Pingle
08:28 AM Correction #12469 (Pull Request Review): Automatic outbound NAT rules are applied to the WG interface
Jim Pingle
08:54 AM Todo #12478: Feedback on Virtual Private Networks — IPsec — Mobile IPsec — Choosing a Mobile IPsec Style
There are mentions of Group auth in the IPsec docs which are still pending (waiting on 22.01 now):
http://stage-v2...
Jim Pingle
08:37 AM Todo #12478 (Closed): Feedback on Virtual Private Networks — IPsec — Mobile IPsec — Choosing a Mobile IPsec Style
*Page:* https://docs.netgate.com/pfsense/en/latest/vpn/ipsec/mobile-choices.html#ikev2-with-eap-radius
https...
Viktor Gurov

10/19/2021

02:25 PM Correction #12469 (Waiting on Merge): Automatic outbound NAT rules are applied to the WG interface
Thanks for the feedback.
https://gitlab.netgate.com/docs/pfSense-docs/-/merge_requests/25
Christian McDonald
 

Also available in: Atom