Activity
From 01/29/2020 to 02/27/2020
02/27/2020
-
02:26 PM Bug #10299: Snort - Blocked Alert - Description loss -> Alert Description No Longer Available
- Bill Meeks wrote:
> Diego Leon wrote:
> > Snort v 3.2.9.10
> >
> > Package Dependencies:
> > snort-2.9.15 ... -
12:54 PM Bug #10299 (Not a Bug): Snort - Blocked Alert - Description loss -> Alert Description No Longer Available
-
12:54 PM Bug #10299: Snort - Blocked Alert - Description loss -> Alert Description No Longer Available
- Diego Leon wrote:
> Snort v 3.2.9.10
>
> Package Dependencies:
> snort-2.9.15 barnyard2-1.13_1
>
> The S... -
10:19 AM Bug #10299 (Not a Bug): Snort - Blocked Alert - Description loss -> Alert Description No Longer Available
- Snort v 3.2.9.10
Package Dependencies:
snort-2.9.15 barnyard2-1.13_1
The Snort first report in Blocked ta... -
01:02 PM Bug #10292: Suricata not respecting SID Mgmt list
- There were zero changes to that part of the Suricata code in version 4.1.6_3. In fact, both updates to 4.1.6_2 and 4....
-
10:12 AM Bug #10265: Adding a Note with malformed title will force system restore
- It is not viable to set that list up dynamically, since if a user removes the package, the value is still in the conf...
-
10:10 AM Bug #10265: Adding a Note with malformed title will force system restore
- Jim Pingle wrote:
>
> Yes that's a general issue with XML storage but it's unrelated to this specific bug. We use ... -
08:03 AM Feature #8574 (Pull Request Review): Enable AgentX-support in lldpd using GUI
-
05:35 AM Feature #8574: Enable AgentX-support in lldpd using GUI
- https://github.com/pfsense/FreeBSD-ports/pull/782
-
07:31 AM Feature #9989 (Pull Request Review): Add FreeBSD port and pfSense plugin for HoneyTrap
- PR: https://github.com/pfsense/FreeBSD-ports/pull/772
-
07:24 AM Feature #10297 (Pull Request Review): IPv6 user attributes
-
03:24 AM Feature #10297: IPv6 user attributes
- https://github.com/pfsense/FreeBSD-ports/pull/781
-
01:09 AM Feature #10297 (Assigned): IPv6 user attributes
- Add IPv6 related attributes no the user configuration page in the same way as existing IPv4 Network Configuration:
F... -
05:34 AM Feature #9249 (Feedback): [siproxd] Add config for siptrunk plugin
- PR has been merged. Thanks!
-
05:32 AM Feature #8878 (Feedback): Propagate user's description field into QR code for FreeRADIUS
- PR has been merged. Thanks!
-
05:28 AM Bug #8729 (Feedback): IPv6 - FRR BGP issue with Redistribute connected networks
- PR has been merged. Thanks!
-
05:21 AM Bug #4497 (Feedback): Using a specific password within FreeRADIUS user management causes pfSense to restore a backup!
02/26/2020
-
02:03 PM Bug #10291 (Resolved): Export using DDNS hostnames (port forward targets) does not include domain name for split DDNS types
- Works as expected now. Full hostname is observed in @remote@ statements which only had the short hostname before. Ent...
-
11:08 AM Bug #10294 (New): FRR Route Counts Incorrect on Status Page
- Something is still truncating the route counts on the FRR status pages. Seems to be intermittent.
Zebra Routes D... -
10:02 AM Feature #9249 (Pull Request Review): [siproxd] Add config for siptrunk plugin
-
04:37 AM Feature #9249: [siproxd] Add config for siptrunk plugin
- from siproxd.conf.example:...
-
09:57 AM Feature #8878 (Pull Request Review): Propagate user's description field into QR code for FreeRADIUS
-
03:27 AM Feature #8878: Propagate user's description field into QR code for FreeRADIUS
- https://github.com/pfsense/FreeBSD-ports/pull/779
-
03:43 AM Bug #8885 (Closed): HAProxy "Log hostname parameter broke local syslog
- no such issue with haproxy-devel 0.60_3 on pfSense 2.4.5.r.20200225.2100 and 2.5.0.a.20200225.0859
- hostname field...
02/25/2020
-
05:10 PM Bug #10292 (Not a Bug): Suricata not respecting SID Mgmt list
- I am running pfSense 2.4.4-RELEASE-p3 (amd64) with Suricata VERSION 4.1.6_3 on an SG-2440.
Suricata is inspecting ... -
10:45 AM Bug #10291 (Feedback): Export using DDNS hostnames (port forward targets) does not include domain name for split DDNS types
- Pushed a fix in OpenVPN client export pkg version 1.4.20
-
10:41 AM Bug #10291 (Resolved): Export using DDNS hostnames (port forward targets) does not include domain name for split DDNS types
- Some Dynamic DNS entries are considered "split" so they have the hostname and domain name in separate variables (e.g....
02/24/2020
-
01:35 PM Bug #10278 (New): pfBlockerNG: Formatting issue on DNSBL stats page
-
01:19 PM Bug #10278: pfBlockerNG: Formatting issue on DNSBL stats page
- Jim Pingle wrote:
> Did you mean pfBlockerNG? "pfsense-ng" is not a valid package name. For now I'll set this as pfB... -
07:48 AM Bug #10278 (Feedback): pfBlockerNG: Formatting issue on DNSBL stats page
- Did you mean pfBlockerNG? "pfsense-ng" is not a valid package name. For now I'll set this as pfBlockerNG since that s...
-
08:11 AM Feature #9003: Add 'Copy Running to Saved' option to the raw config
- Viktor Gurov wrote:
> I do not understand why quagga-way (saving configuration in base64 format in config.xml) may b... -
08:08 AM Feature #9003 (Pull Request Review): Add 'Copy Running to Saved' option to the raw config
-
07:54 AM Bug #8887 (Pull Request Review): Squid Proxy Interface not assignee to IPv6
-
07:39 AM Bug #4497 (Pull Request Review): Using a specific password within FreeRADIUS user management causes pfSense to restore a backup!
-
07:38 AM Bug #10265: Adding a Note with malformed title will force system restore
- Viktor Gurov wrote:
> Jim Pingle wrote:
> > The string uses characters which are invalid in XML, and that field is ... -
07:34 AM Bug #8729 (Pull Request Review): IPv6 - FRR BGP issue with Redistribute connected networks
-
03:14 AM Bug #10279: pfSense's OpenVM Tools on ESXi 6.7 no longer provides guest vm functionality
- graceful shutdown work with esxi 6.7u3 and pfsense 2.5.0-dev
02/23/2020
-
09:24 AM Feature #9003: Add 'Copy Running to Saved' option to the raw config
- I do not understand why quagga-way (saving configuration in base64 format in config.xml) may be error prone.
Both *...
02/22/2020
-
08:16 PM Bug #10279: pfSense's OpenVM Tools on ESXi 6.7 no longer provides guest vm functionality
- Might need to try on 2.4.5 or 2.5.0 to get the updated ports. I don't have any problem with guest functionality there...
-
12:52 PM Bug #10279 (New): pfSense's OpenVM Tools on ESXi 6.7 no longer provides guest vm functionality
- When I run pfSense on ESXi6.7 (Update 3) with Open-VM-Tools installed from Package Manager, ESXi sees the Open VM too...
-
10:46 AM Feature #8181 (Resolved): Quagga OSPF failover mechanism takes too much time to converge in HA environments
- successfully tested on 2.5.0.a.20200220.1948 with Quagga_OSPF 0.6.21_5
-
10:37 AM Bug #9652 (Resolved): Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
- Renato Botelho wrote:
> PR has been merged. Thanks!
works ok on 2.4.5.r.20200222.0000 and 2.5.0.a.20200221.1911 w... -
10:33 AM Bug #9681 (Resolved): [Monitoring] New views title are always in lower case.
- mixed titles is ok on 2.5.0.a.20200221.1911 and 2.4.5.r.20200222.0000
-
10:12 AM Bug #8887: Squid Proxy Interface not assignee to IPv6
- This fix allows you to select the IP protocol over which Squid will listen for connections:
https://github.com/pfsen... -
08:55 AM Bug #10278 (New): pfBlockerNG: Formatting issue on DNSBL stats page
I have found that on the stats pages, the center bar that divides source from the pie charts is static.
I cannot...-
07:41 AM Bug #4497: Using a specific password within FreeRADIUS user management causes pfSense to restore a backup!
- This fix allow to use only ^[a-zA-Z0-9_.-]*$ for usernames:
https://github.com/pfsense/FreeBSD-ports/pull/775 -
07:32 AM Bug #10265: Adding a Note with malformed title will force system restore
- Jim Pingle wrote:
> The string uses characters which are invalid in XML, and that field is not protected. The packag... -
07:08 AM Bug #8729: IPv6 - FRR BGP issue with Redistribute connected networks
- This PR allow to select No/IPv4/IPv6/IPv4+IPv6 in the Redistribute drop-down menu (where 'IPv4+IPv6' is 'yes' for bac...
02/20/2020
-
09:17 AM Bug #9934: suricata update kills WAN interface
- A look through the Suricata source code shows that the Suricata binary, when running in PCAP mode, will send explicit...
-
07:58 AM Bug #9934: suricata update kills WAN interface
- If Suricata is running using Legacy Mode Blocking, then the _libpcap_ library is used and bonded to the interface whe...
02/19/2020
-
11:25 PM Bug #8830 (Resolved): Automatic flowbit resolution setting does not match description
- works as expected on pfSense 2.4.5.a.20200123.1100 with snort 3.2.9.10_1
-
01:45 PM Bug #10261: Arpwatch fails to download ethercodes.dat
- Samuel: /etc/inc/pfsense-utils.inc: function download_file($url, $destination, *$verify_ssl = true*, $connect_timeout...
-
01:40 PM Feature #10227 (Resolved): ACME: Do not show passwords
- Thanks for testing!
-
01:39 PM Feature #10227: ACME: Do not show passwords
- It works nicely
-
12:06 PM Feature #10227 (Feedback): ACME: Do not show passwords
- Fixed in ACME package version 0.6.5
As well as it can be in the current framework anyhow. Passwords and other sens... -
01:38 PM Bug #10266: ACME: Changing validation from http to dns provokes ACME
- Hi,
Confirmed (again), the issue described now works correctly.
A -
01:25 PM Bug #10266 (Resolved): ACME: Changing validation from http to dns provokes ACME
- Thanks!
-
01:21 PM Bug #10266: ACME: Changing validation from http to dns provokes ACME
- Hi.
Confirmed working.
Regards,
M -
12:07 PM Bug #10266 (Feedback): ACME: Changing validation from http to dns provokes ACME
- Should be fixed in ACME package version 0.6.5 which synced up to the latest acme.sh changes.
-
12:15 PM Bug #7829 (Duplicate): Unable to expand the "Advanced Server Settings" in ACME certificate edit
- Actually duplicated by #9347 but that had a more accurate description of what was happening. It should be better on A...
-
12:12 PM Bug #9347 (Feedback): Domain SAN list displays "Key Algorithm: HMAC-MD5, API Endpoint: portal.nexcess.net"
- This should be better in ACME package version 0.6.5. I added default values for those fields which are set to 'none' ...
-
12:08 PM Bug #9752 (Resolved): ACME - Actions have no access to additionally generated certificate files.
- Fixed months ago, no additional feedback.
-
12:08 PM Bug #9888 (Resolved): ACME output sent to browser without encoding
- Fixed months ago, no additional feedback.
02/18/2020
-
06:02 AM Bug #8830: Automatic flowbit resolution setting does not match description
- Viktor Gurov wrote:
> works as expected on 2.5.0.a.20200214.1446 with snort 4.0_11
>
> 2.4.5 PR:
> https://githu... -
05:10 AM Bug #10266: ACME: Changing validation from http to dns provokes ACME
- Subject cut; should read *ACME: Changing validation from http to dns provokes ACME bug*
-
01:57 AM Bug #10266 (Resolved): ACME: Changing validation from http to dns provokes ACME
- ACME package version: 0.6.4
Updating the validation method of an existing certificate from http to dns causes an e...
02/17/2020
-
03:16 PM Bug #10265: Adding a Note with malformed title will force system restore
- The string uses characters which are invalid in XML, and that field is not protected. The package should probably val...
-
02:27 PM Bug #10265 (New): Adding a Note with malformed title will force system restore
- This is related to using Notes package.
Add a new note with title
"Add/Change/Set the custom resolution of you...
02/15/2020
-
06:44 AM Bug #10261: Arpwatch fails to download ethercodes.dat
- Viktor Gurov wrote:
> this is caused by the default connection timeout (5s) of the download_file() in arpwatch.inc:
... -
01:10 AM Bug #10261: Arpwatch fails to download ethercodes.dat
- this is caused by the default connection timeout (5s) of the download_file() in arpwatch.inc:...
-
01:35 AM Bug #8830: Automatic flowbit resolution setting does not match description
- works as expected on 2.5.0.a.20200214.1446 with snort 4.0_11
2.4.5 PR:
https://github.com/pfsense/FreeBSD-ports/p...
02/14/2020
-
04:27 PM Bug #10261: Arpwatch fails to download ethercodes.dat
- I have a workaround in place which involves disabling the update vendors option and using cron to run the command bel...
-
04:03 PM Bug #10261: Arpwatch fails to download ethercodes.dat
- This is version 2.4.4-RELEASE-p3 (arm64)
-
04:01 PM Bug #10261 (Resolved): Arpwatch fails to download ethercodes.dat
- I noticed that the ethernet vendor field in arpwatch alerts is always unknown even though the update vendors option i...
-
01:36 PM Bug #10244: PHP crash: suricata
- I think that forcing inclusion of the regex delimeter in the pcre: definition would be very flexible but would defini...
-
10:23 AM Bug #10244: PHP crash: suricata
- John Silva wrote:
> If I had to choose I'd choose to not use preg_quote() so that pcre works as expected.
>
> I t...
02/12/2020
-
07:02 PM Bug #10244: PHP crash: suricata
- If I had to choose I'd choose to not use preg_quote() so that pcre works as expected.
I think this could be done s... -
04:27 PM Bug #10244: PHP crash: suricata
- John Silva wrote:
> I think the issue is traced to the following line:
>
> [...]
>
> Unlike snort, the suricat... -
12:23 AM Feature #10220 (Resolved): Add softflow 1.0.0 features - sampling and PSAMP export
- tested on pfSense 2.5.0.a.20200211.1811 with softflowd 1.2.6
works as expected -
12:21 AM Feature #7895 (Resolved): Add a script for CARP monitoring to NRPE
- tested on pfSense 2.5.0.a.20200211.1811 with nrpe 3.1_2
ok now
02/11/2020
-
05:18 PM Bug #10252: pfblockerng-devel
- Grimson Gretzleburg wrote:
> Quote from the VIP section of the DNSBL Webserver Config:
> > Changes to the DNSBL VIP... -
05:17 PM Bug #10252: pfblockerng-devel
- When you change the DNSBL VIP a *Force Update* will not change the Sinkhole'd IPs already established in the pfb_dnsb...
-
09:02 AM Bug #10252 (Not a Bug): pfblockerng-devel
- The issue I want to address here is with the pfb_dnsbl.conf file. The IPs are incorrect and do not match the VIP I ha...
-
09:18 AM Bug #10251: Avahi-daemon choosing VIP instead of interface IP
- Chris Roadfeldt wrote:
> Jim Pingle wrote:
> > Avahi operates using interfaces and selects the addresses automatica... -
09:08 AM Bug #10251: Avahi-daemon choosing VIP instead of interface IP
- Jim Pingle wrote:
> Avahi operates using interfaces and selects the addresses automatically. All the config can do i... -
09:05 AM Bug #10251 (Not a Bug): Avahi-daemon choosing VIP instead of interface IP
- Avahi operates using interfaces and selects the addresses automatically. All the config can do is tell it to use or n...
-
08:55 AM Bug #10251 (Not a Bug): Avahi-daemon choosing VIP instead of interface IP
- I have pfblockerng-devel installed and configured with DNSBL on most of my interfaces and VLANs. I also have avahi-da...
-
09:17 AM Bug #10253 (New): pfblockerng-devel uses user interface for VIP causing issues with other services
- I have pfblockerng-devel installed and configured with DNSBL on most of my interfaces and VLANs. I also have avahi-da...
02/10/2020
-
10:02 PM Bug #10245 (Not a Bug): PHP errors in snort package
-
09:19 PM Bug #10245: PHP errors in snort package
- I think you're correct. This isn't a bug in your code.
There are a couple of things going on.
First, my SID ma... -
10:56 AM Bug #10245: PHP errors in snort package
- I don't believe this is a bug in the Snort package source code. I think it is instead a problem with your search term...
-
09:28 PM Bug #10244: PHP crash: suricata
- I think the issue is traced to the following line:...
-
08:45 PM Bug #10244: PHP crash: suricata
- Thanks for checking, Bill. These patterns worked OK in 2.4.4-p3 before the 2.4.5-RC upgrade. I do see a pattern typ...
-
11:02 AM Bug #10244: PHP crash: suricata
- Same as the issue you reported for the Snort package, I don't believe this is a bug in the Suricata package source co...
-
02:33 PM Feature #10242 (In Progress): E2guardian Web filtering package
- PR has been merged and code review / improvement just started but we won't build public packages while it's not finished
-
08:02 AM Feature #10242 (Pull Request Review): E2guardian Web filtering package
- Did you check with / confirm this was OK with the package author?
-
09:34 AM Feature #10243 (Feedback): rawserial driver for lcdproc
- PR has been merged. Thanks!
-
08:03 AM Feature #10243 (Pull Request Review): rawserial driver for lcdproc
-
07:37 AM Feature #10220 (Feedback): Add softflow 1.0.0 features - sampling and PSAMP export
- PR merged. Thanks!
-
07:26 AM Feature #10220 (Pull Request Review): Add softflow 1.0.0 features - sampling and PSAMP export
-
07:18 AM Feature #7895 (Feedback): Add a script for CARP monitoring to NRPE
- Fixed on version 3.1_2
02/08/2020
-
12:02 PM Bug #10245 (Not a Bug): PHP errors in snort package
- Running 2.4.5-RC with Snort package.
Crash Reporter is reporting an error in the snort package. Crash report foll... -
11:59 AM Bug #10244 (Closed): PHP crash: suricata
- Running 2.4.5-RC with Suricata package.
Crash Reporter is reporting an error in the suricata package. Crash repor... -
09:59 AM Bug #9935 (Resolved): hide ECDSA certs for Zabbix
- tested on pfSense 2.5.0.a.20200207.2007 with zabbix-agent44 1.0.4_3 and zabbix-proxy44 1.0.4_3
works as expected -... -
09:11 AM Feature #10243: rawserial driver for lcdproc
- https://github.com/pfsense/FreeBSD-ports/pull/768
-
09:09 AM Feature #10243 (Resolved): rawserial driver for lcdproc
- Rawserial driver has been avalbile since 0.5.7 this will dump raw serial data to the serial port. Hackers/makers can ...
-
08:56 AM Feature #10242: E2guardian Web filtering package
- https://github.com/pfsense/FreeBSD-ports/pull/767
initial version - copy of original package with changed director... -
08:48 AM Feature #10242 (New): E2guardian Web filtering package
- E2guardian Web filtering http://e2guardian.org
original package by Marcello Coutinho (Apache 2 license):
https://... -
07:19 AM Feature #7895: Add a script for CARP monitoring to NRPE
- fix that adds ${MKDIR} ${STAGEDIR}${PREFIX}/libexec/nagios line to Makefile:
https://github.com/pfsense/FreeBSD-port... -
01:12 AM Feature #10220: Add softflow 1.0.0 features - sampling and PSAMP export
- This PR fix input validation, to allow select PSAMP protocol version:
https://github.com/pfsense/FreeBSD-ports/pull/...
02/07/2020
-
11:15 PM Bug #10218 (Resolved): Telegraf: Error creating the telegraf.ca file when you have more then one CA in pfSense
- works as expected on pfSense 2.5.0.a.20200207.2007 and 2.4.5.r.20200206.1944
Telegraf 0.9_2
-
08:06 AM Bug #10218 (Feedback): Telegraf: Error creating the telegraf.ca file when you have more then one CA in pfSense
- Pull request has been merged. Thanks!
-
11:08 PM Feature #7895: Add a script for CARP monitoring to NRPE
- I'm getting a build error with the addition of the script:...
-
08:39 AM Feature #10140 (Closed): allow to select webserver certificate
- we discussed this with BBcan177 - this is unnecessary
I think this can be useful only if the company uses a specia... -
08:18 AM Bug #8830: Automatic flowbit resolution setting does not match description
- Pull Request only applied on 2.5.0
-
08:16 AM Bug #8830 (Feedback): Automatic flowbit resolution setting does not match description
- Pull request has been merged. Thanks!
-
08:11 AM Feature #9916 (Feedback): Check allow-transfer in custom option when the zone is slave
- Pull request has been merged. Thanks!
-
08:08 AM Feature #10220 (Feedback): Add softflow 1.0.0 features - sampling and PSAMP export
- Pull request has been merged. Thanks!
-
04:51 AM Bug #9934 (New): suricata update kills WAN interface
- same issue on XG-1537 (pfSense 2.4.4-p3, suricata 4.1.6_3) with ix interface,
I found that killing suricata process ...
02/06/2020
-
03:56 PM Feature #8547: fwknop Port Knocking Package
- Jim Pingle wrote:
> If you want secure remote access, use a VPN. If someone wants to make a package for this, we cou... -
02:24 PM Bug #9934 (Not a Bug): suricata update kills WAN interface
-
01:51 PM Bug #9934: suricata update kills WAN interface
- Suricata running with Inline IPS Mode uses the netmap kernel device. When Suricata stops and restarts, that also stop...
-
03:38 AM Bug #9934: suricata update kills WAN interface
- You can set Suricata to "Live Reload" the new rules without restarting itself.
Enable this global option to preven...
02/03/2020
-
07:41 AM Bug #8830 (Pull Request Review): Automatic flowbit resolution setting does not match description
-
04:33 AM Feature #10227 (Resolved): ACME: Do not show passwords
- Those DNS validation methods that uses ordinary username/password for authentication (such as DNS-GratisDNS) should n...
02/01/2020
-
06:19 AM Bug #8830: Automatic flowbit resolution setting does not match description
- This PR simply sets the default value for this checkbox to on when adding a new interface:
https://github.com/pfsens...
01/31/2020
-
09:38 PM Feature #9238: Add support for Zerotier
- Package has been updated to run on 2.4.4-RELEASE-p3. Still some work to be done on setting up the interfaces, right n...
-
08:33 AM Bug #8538 (Closed): arpwatch missing ethercodes.dat
- already in 0.2.0:...
01/30/2020
-
09:26 AM Feature #10165: Add High-Availability tracking to avahi package.
- Renato Botelho wrote:
> PR has been merged on 2.5.0 and 2.4.5 branches. Thanks!
do you plan to merge it on 2.4.4 ... -
08:03 AM Feature #7895 (Pull Request Review): Add a script for CARP monitoring to NRPE
-
05:43 AM Feature #7895: Add a script for CARP monitoring to NRPE
- https://github.com/pfsense/FreeBSD-ports/pull/759
-
06:56 AM Bug #8194 (Closed): BIND fails to respond after interface goes down
- no such issue on pfSense 2.4.5.r.20200128.2345 with BIND 9.14_1
-
06:12 AM Bug #8400 (Closed): FreeRadius 3 EAP-TLS Missing O.U. Option
- Duplicate of https://redmine.pfsense.org/issues/8224
-
05:14 AM Bug #8195 (Closed): BIND packages launches two instances of /usr/local/sbin/named on boot
- no such issue with BIND package 9.14_1
tested on pfSense 2.4.5.r.20200128.2118 and 2.5.0.a.20200129.1414 -
02:31 AM Feature #9916: Check allow-transfer in custom option when the zone is slave
- updated PR:
https://github.com/pfsense/FreeBSD-ports/pull/758
01/29/2020
-
07:18 AM Feature #10220 (Pull Request Review): Add softflow 1.0.0 features - sampling and PSAMP export
-
03:58 AM Feature #10220: Add softflow 1.0.0 features - sampling and PSAMP export
- https://github.com/pfsense/FreeBSD-ports/pull/757
-
03:14 AM Feature #10220 (Resolved): Add softflow 1.0.0 features - sampling and PSAMP export
- Add sampling configuration to softflowd package:...
-
07:16 AM Bug #10218 (Pull Request Review): Telegraf: Error creating the telegraf.ca file when you have more then one CA in pfSense
-
12:46 AM Bug #10218: Telegraf: Error creating the telegraf.ca file when you have more then one CA in pfSense
- https://github.com/pfsense/FreeBSD-ports/pull/756
Also available in: Atom