Project

General

Profile

Activity

From 09/17/2017 to 10/16/2017

10/16/2017

03:28 PM Bug #7871 (Resolved): Add squid validation for selected CA when MITM is enabled
Great, thanks for testing! Jim Pingle
03:22 PM Bug #7871: Add squid validation for selected CA when MITM is enabled
Looks good here, only usable CAs are being offered in the Squid GUI with 0.4.42. Thanks! Kill Bill
11:19 AM Bug #7871 (Feedback): Add squid validation for selected CA when MITM is enabled
OK I added two different sets of protection:
1. Input validation to warn if a user selected a CA without a private...
Jim Pingle
03:20 PM Bug #7954 (Confirmed): Package upgrade/reinstall gets stuck on deinstall if the package-provided service is not running
So you have a package and the service is not running. Trying to upgrade/reinstall produces the following:... Kill Bill
01:12 PM Bug #7947 (Rejected): freeRadius 3 on pfSense 2.4 not work
There isn't enough really to go on here, please start a forum thread so we can discuss and diagnose the issue. Also, ... Jim Pingle
12:57 AM Bug #7947: freeRadius 3 on pfSense 2.4 not work
i edit /usr/local/etc/raddb/sites-enabled/default
i comment:...
Konstantin Ab
12:42 AM Bug #7947: freeRadius 3 on pfSense 2.4 not work
i use EAP section
and freeRadius2 worked in 2.3.4
2.4 + FR3 = not worked
Konstantin Ab
12:18 PM Feature #7945 (Resolved): NET-SNMP - Flooding log entries
Great, thanks for testing!
Jim Pingle
12:06 PM Feature #7945: NET-SNMP - Flooding log entries
Jim Pingle wrote:
> I just pushed a fix for this, it will show up shortly to install.
Updated and tested. Looks g...
Nonada Nonadz
07:49 AM Feature #7945 (Feedback): NET-SNMP - Flooding log entries
I just pushed a fix for this, it will show up shortly to install. Jim Pingle
11:35 AM Bug #7941 (Not a Bug): ntop-ng. Unable to reach web page
This was an issue with the rules on that one system and not a problem with ntopng. Jim Pingle
08:19 AM Bug #7941 (Feedback): ntop-ng. Unable to reach web page
I see those errors here but it appears they happen during install or boot when it gets stopped/started a couple times... Jim Pingle
11:16 AM Bug #7952 (Closed): OpenVPN export package for Windows flagged by a few AV's
We have received a report that exported OpenVPN client package is flagged by a few AV's.
https://forum.pfsense.or...
Ivor Kreso
07:22 AM Bug #7950 (Feedback): Quagga not displaying status messages on 2.4-rel
It's working fine here. Are all of the daemons running?
Does running one of the status commands at the CLI work?
<...
Jim Pingle
06:59 AM Bug #7950 (Closed): Quagga not displaying status messages on 2.4-rel
See attached screenshot. Quagga is working but no status messages are displayed. Vladimir Lind
06:20 AM Bug #7935 (Feedback): FFR doesn't save prefix lists to bgpd.conf
PR has been merged Renato Botelho

10/15/2017

11:00 PM Bug #7947 (Rejected): freeRadius 3 on pfSense 2.4 not work
Afrer upgrade pfsense to 2.4 and install freeradius v3 -- freeRadius not execute.... Konstantin Ab
05:11 PM Feature #7945 (Resolved): NET-SNMP - Flooding log entries
Please make a better solution for the NET-SNMP logging. Currently it floods the Genereal Log Entries (System Logs / S... Nonada Nonadz
03:44 PM Bug #7944 (Resolved): Bind XMLRPC Sync Error
After upgrading to pfsense 2.4.0 syncing Bind is not possible anymore. Each time I update the config I get the follow... Maximilian Sesterhenn
12:52 PM Bug #7941 (Not a Bug): ntop-ng. Unable to reach web page
After installing and enabling ntop-ng with default settings in 2.4 it is not possible to reach the data display page ... Steve Wheeler

10/14/2017

11:20 AM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
No, it's not directly a Snort issue. It appears to be something that was perhaps inadvertently introduced when the t... Bill Meeks
03:43 AM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Cheers guys, it does disapear after moving pfSense.mo pfSense.mo.old
So not a Snort issue then.
Andy Kniveton

10/13/2017

02:30 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Bill Meeks wrote:
> Andy Kniveton wrote:
> UPDATE- an empty string is the cause, now to find out why ???
>
> Bi...
Kill Bill
02:09 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Andy Kniveton wrote:
> Ah I don't have an Assigned Alias, so it displays the txt regardless of what ever the locale ...
Bill Meeks
12:29 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Ah I don't have an Assigned Alias, so it displays the txt regardless of what ever the locale is set to.
Just creat...
Andy Kniveton
12:22 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
I've upgraded from 2.3.4-p1 to 2.4.0 and not changed the locale. it's using the default English I guess as I've not s... Andy Kniveton
10:23 AM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
I am so far unable to reproduce this problem in my virtual machine test environment. What language/locale is your fi... Bill Meeks
09:46 AM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Thanks for the report. I will look into the problem.
Bill
Bill Meeks
12:10 PM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
This is definitely due to a locking issue with file access in the index.php file for pfBlocker DNSBL. Not sure why it... Jim Pingle
10:48 AM Bug #7935: FFR doesn't save prefix lists to bgpd.conf
There is a pending PR for this, https://github.com/pfsense/FreeBSD-ports/pull/417
We'll be reviewing PRs shortly n...
Jim Pingle

10/12/2017

07:28 PM Bug #7935 (Resolved): FFR doesn't save prefix lists to bgpd.conf
Prefix lists referenced in route-maps or directly do not work with bgp when created using the webui. Have to copy the... Louis McLennan
12:03 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
https://forum.pfsense.org/index.php?topic=137921.0 Andy Kniveton
12:02 PM Bug #7932: 2.4.0 & Snort 3.2.9.5_1 Pass Lists
Please also post that in the IDS/IPS board of the forum so the package maintainer has a higher chance of seeing it:
...
Jim Pingle
11:53 AM Bug #7932 (Resolved): 2.4.0 & Snort 3.2.9.5_1 Pass Lists
The following appears under Assigned Alias header :-
Project-Id-Version: PACKAGE VERSION Report-Msgid-Bugs-To: POT...
Andy Kniveton

10/11/2017

12:24 PM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
If it's happening on 2.4.0 and started around that time, it's likely related to the FreeBSD 11.1 change and not the I... Jim Pingle
10:53 AM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
Jim Pingle wrote:
> The affected code was on 2.4.0 for a couple days but is no longer there now. Current 2.4.0-RC sn...
Chad Brandenburg
10:35 AM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
The affected code was on 2.4.0 for a couple days but is no longer there now. Current 2.4.0-RC snapshots and the actua... Jim Pingle
10:28 AM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
Jim Pingle wrote:
> At the moment, the only change in 2.4.1 that isn't in 2.4.0 that might be relevant is #7856
>
...
Chad Brandenburg
07:13 AM Bug #7923: 502 Bad Gateway and unresponsive OS with 2.4
At the moment, the only change in 2.4.1 that isn't in 2.4.0 that might be relevant is #7856
And since we already k...
Jim Pingle
06:21 AM Bug #7923 (Resolved): 502 Bad Gateway and unresponsive OS with 2.4
Multiple users complaining that following the infamous 502 Bad Gateway, they eventually are unable to do anything wit... Kill Bill

10/02/2017

03:54 AM Feature #7895: Add a script for CARP monitoring to NRPE
Little fix, the current plugin did not set the return code upon exiting. Stéphane Lapie

09/30/2017

10:53 AM Feature #7903 (New): Duo ssh package
When trying to compile the Duo ssh package I get errors. After fixing these, I cannot get the sshd configs to stick o... Jaosn Beitler
04:45 AM Bug #6129: zabbix agent/proxy 2.4 not ported to pfSense 2.3
Brendon Baumgartner wrote:
> Zabbix proxies have to match the version of the Zabbix server so just supporting LTS he...
Pim Janssen
02:02 AM Bug #6129: zabbix agent/proxy 2.4 not ported to pfSense 2.3
Zabbix agents can be any version.
Zabbix proxies have to match the version of the Zabbix server so just supporting...
Brendon Baumgartner

09/29/2017

02:15 PM Feature #7902 (New): allow vpn client export of other to be a blank field
Under: OpenVPN -> Client Export -> Host Name Resolution -> Other
The Host Name field that appears requires a valu...
Brendon Baumgartner
11:51 AM Bug #7729 (Resolved): pfBlockerNG orders NAT licked rules to the bottom of firewall rules
Jim Pingle
11:34 AM Bug #7729: pfBlockerNG orders NAT licked rules to the bottom of firewall rules
Merged and fixed since 2.1.1_9 Kill Bill
10:04 AM Bug #7893: Kernel Panic Suricata Inline
Additional warning text has been added to the Group Help displayed in the Blocking Mode section of the INTERFACE SETT... Bill Meeks

09/28/2017

07:09 AM Bug #7716 (Resolved): Suricata - Barnyard2 webui configuration updates result in base64-encoded value written to the config for the password
Jim Pingle
03:21 AM Bug #7716: Suricata - Barnyard2 webui configuration updates result in base64-encoded value written to the config for the password
Fixed. Kill Bill
07:09 AM Bug #7756 (Resolved): suricata suricata_check_dir_size_limit() needs to be improved
Jim Pingle
03:21 AM Bug #7756: suricata suricata_check_dir_size_limit() needs to be improved
Fixed. Kill Bill
07:08 AM Bug #7578 (Resolved): Suricata -- Removing Hosts from Block Table via Alerts
Jim Pingle
03:13 AM Bug #7578: Suricata -- Removing Hosts from Block Table via Alerts
Fixed. Kill Bill
07:08 AM Bug #5996 (Closed): Snort service does not start back after rules update
Jim Pingle
02:49 AM Bug #5996: Snort service does not start back after rules update
Certainly not a general issue plus insufficient info here to identify any bug. Kill Bill
06:29 AM Bug #7736: Crahs with Quagga OSPF and the latest 2.4 Beta
bump Jim Thompson
06:29 AM Bug #6456 (Not a Bug): vm-bhyve not correctly detecting the modules in kernel
Jim Thompson
03:30 AM Bug #6456: vm-bhyve not correctly detecting the modules in kernel
As noted above, long fixed. Kill Bill

09/27/2017

05:08 PM Bug #7850 (Resolved): Include file containing XML_RPC_encode() missing from snort
Jim Pingle
03:53 PM Bug #7850: Include file containing XML_RPC_encode() missing from snort
Fixed. Kill Bill
01:15 PM Feature #6022: Consider MLVPN for bonded VPN
Has there been any traction with this? I have been looking for something like this too. I'll add to the kitty for t... Mike T
05:16 AM Feature #7895 (Resolved): Add a script for CARP monitoring to NRPE
I have deployed several CARP clusters at work, but I realized there is no real good way to monitor CARP status :
* S...
Stéphane Lapie
01:12 AM Bug #7893: Kernel Panic Suricata Inline
The “generic_XXXXXX” in one of your screenshots shows you’re not running s netmap-capable NIC. (You’re getting the e... Jim Thompson

09/26/2017

06:30 PM Bug #7893: Kernel Panic Suricata Inline
Thanks for the info, you guys might want to get the package maintainer to put some info under the inline selection, i... Ken Sim
06:22 PM Bug #7893 (Needs Patch): Kernel Panic Suricata Inline
Inline/Netmap is known to have issues with certain hardware (real or virtual). It's still somewhat of an experimental... Jim Pingle
06:12 PM Bug #7893: Kernel Panic Suricata Inline
I rebooted the VM a few times, and it appears to have stopped it's panic reboot cycle. When I went in to view Suricat... Ken Sim
06:01 PM Bug #7893 (Needs Patch): Kernel Panic Suricata Inline
I have been playing around with the 2.4.0/1 snapshots, and have found that when Suricata is enabled with inline block... Ken Sim

09/25/2017

08:57 AM Bug #7891 (Rejected): (suricata), uid 0: exited on signal 11 (core dumped) latest 2.4.0-RC
This does not appear to be a general issue with suricata, but may be specific to your configuration or installation. ... Jim Pingle

09/24/2017

09:06 PM Bug #7891: (suricata), uid 0: exited on signal 11 (core dumped) latest 2.4.0-RC
Did a fresh reinstall and restored the backup and still got same issue. rub man
04:20 PM Bug #7891: (suricata), uid 0: exited on signal 11 (core dumped) latest 2.4.0-RC
I found the core dump file.
I couldn't upload the .core file here as it is huge...
so I upload it to my dropbox:
...
rub man
03:49 PM Bug #7891 (Rejected): (suricata), uid 0: exited on signal 11 (core dumped) latest 2.4.0-RC
Hi,
Just upgraded from latest stable to next major version 2.4.0-RC today via gui.
Only major problem I have is s...
rub man

09/22/2017

12:44 PM Bug #7278 (Resolved): Suricata Service - Advanced Configuration Pass-Through not working
Jim Pingle

09/20/2017

02:32 PM Bug #7876 (Resolved): Potential XSS in status_monitoring.php
Confirmed fixed on the latest snapshot. Jim Pingle

09/19/2017

10:41 AM Bug #7876 (Feedback): Potential XSS in status_monitoring.php
Fixes pushed to the freebsd-ports repo:
FreeBSD-ports/devel "f044c1e4e3f647028c57ae1a572dc6377e555f...
Jim Pingle
09:45 AM Bug #7876 (Resolved): Potential XSS in status_monitoring.php
The "view" variable in status_monitoring.php is taken from $_GET and used in a hidden input ("view-title") without en... Jim Pingle

09/18/2017

09:39 PM Bug #7875 (Rejected): HAProxy Frontend bug - pfsense 2.3.4-RELEASE-p1 (amd64)
This is not a platform for discussion or asking support questions. Please post on the forum, mailing list, reddit, et... Jim Pingle
08:40 PM Bug #7875 (Rejected): HAProxy Frontend bug - pfsense 2.3.4-RELEASE-p1 (amd64)
Hi Support,
This issue is related to ticket #7851 .We are advise to upgrade to the latest version 2.3.4-RELEASE-p1...
Peter Omolo
06:24 AM Bug #7872 (Not a Bug): Edits not saving
Also, don't manually edit the config files. The GUI will always overwrite them on purpose. That's what the GUI is for... Jim Pingle
03:05 AM Bug #7872: Edits not saving
Noone is fixing packages in outdated versions that you should not be using in the first place. There were multiple HA... Kill Bill
02:50 AM Bug #7872: Edits not saving
Is it a known issue? Will upgrading fix? Don't want to upgrade and encounter the same. David Maina
02:40 AM Bug #7872: Edits not saving
How about upgrading your pfSense? Kill Bill
02:28 AM Bug #7872: Edits not saving
Am on *2.3.2-RELEASE-p1 (amd64)* David Maina
02:26 AM Bug #7872 (Not a Bug): Edits not saving
Am editing */var/etc/haproxy/haproxy.cfg* but looks like changes are getting cleared if someone uses *Services/HAProx... David Maina

09/17/2017

06:39 PM Bug #7871: Add squid validation for selected CA when MITM is enabled
P.S. There's https://github.com/pfsense/FreeBSD-ports/pull/402 that's been sitting there for about a month, would be ... Kill Bill
06:32 PM Bug #7871 (Resolved): Add squid validation for selected CA when MITM is enabled
Obviously, this needs to be a CA we have a private key to so that it can issue certificates on the fly to prevent PEB... Kill Bill
 

Also available in: Atom