Project

General

Profile

Activity

From 04/05/2020 to 05/04/2020

05/04/2020

02:11 PM Bug #10522: Telegraf, Netstat fails (missing lsof)
Yes, it works for me as well - after I manually install lsof. The reason I raised this is that lsof should be include... Russell Morris
01:57 PM Bug #10522: Telegraf, Netstat fails (missing lsof)
can't reproduce, it work for me
[2.4.5-RELEASE][root@pfSense.trmultiservice.lab]/root: telegraf --test --input-filte...
Manuel Piovan
02:02 PM Bug #7654 (Feedback): Can't use a LDAP search filter containing an accent
Jim Pingle
08:59 AM Bug #10526: Package pfBlockerNG Crashes on Alert view
Looks like your alert log was allowed to grow too large.
Post on https://forum.netgate.com/category/62/pfblockerng...
Jim Pingle
08:54 AM Bug #10526 (New): Package pfBlockerNG Crashes on Alert view
Error Message:
Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 513799651 bytes) in ...
Larry Westfall

05/03/2020

07:09 PM Bug #10487: Telegraf package not sending logs to influxdb server
I confirm that I encounter the same issue with telegraf version 0.9_3 and pfsense 2.4.5 (on a Netgate SG-1100) device Joseph jk

05/02/2020

10:27 PM Bug #10522 (Resolved): Telegraf, Netstat fails (missing lsof)
Enabling netstat from the web interface (as part of Telegraf) ... fails. The error message can be seen from a command... Russell Morris

05/01/2020

10:26 AM Feature #9874 (Feedback): safesearch enforcing
PR has been merged. Thanks! Renato Botelho
07:27 AM Feature #9874 (Pull Request Review): safesearch enforcing
Jim Pingle
12:53 AM Feature #9874: safesearch enforcing
Grimson Gretzleburg wrote:
> You forgot to add "/www/pfblockerng/pfblockerng_safesearch.php" to the package meta dat...
Viktor Gurov
08:27 AM Bug #9537: One month offset in displayed data between time changes
The underlying vnstat correctly reports the monthly data when run from the command line.
This is from vnstat:
v...
Randall Barth
03:54 AM Bug #10475 (Resolved): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
arpwatch 0.2.0_3 - OK Viktor Gurov
03:42 AM Feature #10479 (Resolved): Keep settings after deinstall option
0.15.7_15 works as expected Viktor Gurov
02:05 AM Bug #9424 (Resolved): arpwatch package logs CARP MAC address changes
works fine on 2.4.5/2.5 and arpwatch pkg 0.2.0_3 Viktor Gurov

04/30/2020

09:17 PM Bug #10516 (New): FRR Access list
When using Access list on BGP neighbor> Peer Filtering (in/out) , All routes will be blocked even if the rule was per... Alhusein Zawi
06:29 PM Feature #9874: safesearch enforcing
You forgot to add "/www/pfblockerng/pfblockerng_safesearch.php" to the package meta data, so it's not included in the... Grimson Gretzleburg
01:36 PM Feature #9874 (Feedback): safesearch enforcing
PR has been merged. Thanks! Renato Botelho
12:48 PM Bug #10444: FRR will not start in 2.4.5 aarch64
Luiz told me he'd work on this Jim Pingle
09:25 AM Feature #10479 (Feedback): Keep settings after deinstall option
PR has been merged. Thanks! Renato Botelho
08:57 AM Feature #10479 (Pull Request Review): Keep settings after deinstall option
Jim Pingle
06:28 AM Feature #10479: Keep settings after deinstall option
small fix:
https://github.com/pfsense/FreeBSD-ports/pull/855
Viktor Gurov
09:22 AM Bug #9211 (Pull Request Review): GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
Jim Pingle
09:17 AM Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
https://forum.netgate.com/topic/153105/ntopng-update-to-v0-8-13_4-crashes
clean install fix:
https://github.com/p...
Viktor Gurov
07:33 AM Bug #9211 (Feedback): GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
PR has been merged. Thanks! Renato Botelho
07:33 AM Bug #10475 (Feedback): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
PR has been merged. Thanks! Renato Botelho

04/29/2020

12:29 AM Bug #10507 (Resolved): Unable to use forwarders
When setting the forwarders in the settings tabs, the forwarders are added under the general "options" section.
Howe...
Jocelyn Viau

04/28/2020

11:58 PM Bug #10506 (Resolved): Recursion not working on fresh BIND install
I just installed BIND for the first time on a pfSense 2.4.5. After installation, despite the fact that I created a Vi... Jocelyn Viau
02:38 PM Bug #10475: pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
So the bug is the clear database checkbox was not being honored ever? "oops" Craig Leres
02:32 PM Bug #10475 (Pull Request Review): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
Jim Pingle
10:09 AM Bug #10475 (New): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
fix for https://github.com/pfsense/FreeBSD-ports/pull/844
to correctly check 'clear_database' value
otherwise arpwa...
Viktor Gurov
12:22 PM Bug #10429: Status Traffic Total broken 2.4.5
I can't replicate anything like this. It's been working solid here, and the data is sane.
The only thing I did not...
Jim Pingle
08:46 AM Bug #9211 (Pull Request Review): GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
Jim Pingle
03:31 AM Bug #9211: GeoIP broken in pfSense-pkg-ntopng-0.8.13_3
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/853
Viktor Gurov
08:24 AM Bug #10503 (New): Flapping any GW in multi-WAN influences restating all IPsec tunnels in FRR which leads to dropping all IPsec VTI static routes and related BGP issues
There are 2 nodes with a multi-WAN setup: 2 WANs, 2 Gateways. The are 2 IPsec VTI tunnel every working through its ow... Constantine Kormashev

04/27/2020

01:26 PM Bug #10502: LLDP spamming errors on Netgate XG-7100
I'm on 2.4.5 now. This error message appears for each ix0-4 and repeat each minute. Lldpd work, at least I can see my... DRago_Angel [InV@DER]
12:07 PM Bug #10502: LLDP spamming errors on Netgate XG-7100
Please provide more information about this issue.
Seems like https://redmine.pfsense.org/issues/9635
Viktor Gurov

04/26/2020

07:05 PM Bug #10502 (In Progress): LLDP spamming errors on Netgate XG-7100
... DRago_Angel [InV@DER]
02:16 AM Feature #10500: Build HAProxy Package with buildin Prometheus exporter
This only apply for HAProxy 2.0 and higher* DRago_Angel [InV@DER]
02:14 AM Feature #10500 (Resolved): Build HAProxy Package with buildin Prometheus exporter
Now if you try use in fronend:... DRago_Angel [InV@DER]

04/24/2020

09:27 AM Bug #9776 (Resolved): Wrong function in squidguard_log.php
squidGuard 1.16.18_5 - works fine Viktor Gurov
09:27 AM Bug #9350 (Resolved): not appear proxy config
squidGuard 1.16.18_5 - works fine Viktor Gurov
08:36 AM Feature #10474 (Resolved): Suppress notifications for specific MACs
arpwatch 0.2.0_2 works as expected Viktor Gurov
08:02 AM Bug #10494 (Resolved): Snort package Logs Management process not purging correctly
Jim Pingle
07:46 AM Bug #10494: Snort package Logs Management process not purging correctly
The pull requests have been merged. This bug is corrected in the latest Snort package versions 3.2.9.11 (for pfSense-... Bill Meeks
03:54 AM Bug #10475 (Resolved): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
arpwatch 0.2.0_2 - works as expected Viktor Gurov
02:00 AM Bug #10369 (Resolved): Remote OpenVPN server protocol definition
1.4.22 - legacy client export is OK now Viktor Gurov
01:45 AM Bug #10490 (Resolved): Syslog-ng syntax test failed
1.15_5 works as expected Viktor Gurov
01:41 AM Feature #9003 (Resolved): Add 'Copy Running to Saved' option to the raw config
now it works as expected on FRR 0.6.4_4 Viktor Gurov
01:36 AM Bug #10442 (Resolved): ACME: special characters in descriptions trigger silent error and rollback
tested acme 0.6.7 - now you can use any characters in the Description field Viktor Gurov
01:34 AM Bug #10452 (Resolved): acme - new DNS-Api namemaster.de in overview hash visible
acme 0.6.7 - resolved Viktor Gurov

04/23/2020

05:46 PM Bug #10490: Syslog-ng syntax test failed
Works OK with version 1.15_5.
Thanks!
e 1/1
12:40 PM Bug #10490 (Feedback): Syslog-ng syntax test failed
PR has been merged. Thanks! Renato Botelho
07:34 AM Bug #10490 (Pull Request Review): Syslog-ng syntax test failed
Jim Pingle
02:42 AM Bug #10490: Syslog-ng syntax test failed
On initial setup, syslogng_build_cert() tries to get the parameters from $config, but it needs to get it from $post, ... Viktor Gurov
04:10 PM Bug #10494: Snort package Logs Management process not purging correctly
Pull requests have been submitted to both the pfSense-2.4.5-RELEASE and pfSense-2.5-DEVEL branches to correct this is... Bill Meeks
01:19 PM Bug #10494: Snort package Logs Management process not purging correctly
If one of the pfSense guys can edit the title of this Issue, please correct my typo in "Management" in the title. Bill Meeks
01:17 PM Bug #10494: Snort package Logs Management process not purging correctly
Creating this and assigning it to me for tracking purposes. The fix for this will be submitted shortly.
Bill
Bill Meeks
01:16 PM Bug #10494 (Resolved): Snort package Logs Management process not purging correctly
The Logs Management process in Snort, when enabled, does not purge rotated alert logs that have exceeded the configur... Bill Meeks
12:43 PM Feature #9762 (Feedback): Squid Reverse Proxy Change redir domain(s) to use regex
PR has been merged. Thanks! Renato Botelho
12:43 PM Bug #9776 (Feedback): Wrong function in squidguard_log.php
PR has been merged. Thanks! Renato Botelho
12:43 PM Bug #10369 (Feedback): Remote OpenVPN server protocol definition
PR has been merged. Thanks! Renato Botelho
12:42 PM Feature #10479 (Feedback): Keep settings after deinstall option
PR has been merged. Thanks! Renato Botelho
12:41 PM Feature #9003 (Feedback): Add 'Copy Running to Saved' option to the raw config
PR has been merged. Thanks! Renato Botelho
12:40 PM Bug #10442 (Feedback): ACME: special characters in descriptions trigger silent error and rollback
PR has been merged. Thanks! Renato Botelho
12:40 PM Bug #10452 (Feedback): acme - new DNS-Api namemaster.de in overview hash visible
PR has been merged. Thanks! Renato Botelho
07:25 AM Bug #10452 (Pull Request Review): acme - new DNS-Api namemaster.de in overview hash visible
Jim Pingle
01:52 AM Bug #10452: acme - new DNS-Api namemaster.de in overview hash visible
NameMaster.de uses _nm_sha256_ field name for password hash,
but only fields containing _key, secret, password_ or _...
Viktor Gurov
12:39 PM Feature #10474 (Feedback): Suppress notifications for specific MACs
PR has been merged. Thanks! Renato Botelho
12:39 PM Bug #10475 (Feedback): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
PR has been merged. Thanks! Renato Botelho

04/22/2020

12:38 PM Feature #10486: Feature Request: Ability to transmit to remote syslog server via TCP
Jim Pingle wrote:
> This site is not for support or diagnostic discussion.
>
> For assistance in solving problems...
e 1/1
12:20 PM Feature #10486: Feature Request: Ability to transmit to remote syslog server via TCP
This site is not for support or diagnostic discussion.
For assistance in solving problems, please post on the "Net...
Jim Pingle
12:14 PM Feature #10486: Feature Request: Ability to transmit to remote syslog server via TCP
Jim Pingle wrote:
> This is already possible with the syslog-ng package. The base system syslog daemon does not supp...
e 1/1
12:09 PM Bug #10490 (Resolved): Syslog-ng syntax test failed
Steps to reproduce:
-Install syslog-ng on a new pfSense instance, version 1.15_4;
-go to Package->Services: Syslog-...
e 1/1
11:43 AM Bug #10476: Services - Acme - Certificates using loopia API
Tobias Müllauer wrote:
> Jim Pingle wrote:
> > The TTL value of @60@ is hardcoded in the "dns_loopia.sh script":htt...
Viktor Gurov

04/21/2020

01:07 PM Bug #10487 (New): Telegraf package not sending logs to influxdb server
On SG-1100, running 2.4.5-RELEASE, with pfSense-pkg-Telegraf-0.9_3, the Telegraf package does not function as expecte... Anonymous
11:02 AM Feature #10486 (Rejected): Feature Request: Ability to transmit to remote syslog server via TCP
This is already possible with the syslog-ng package. The base system syslog daemon does not support TCP. Jim Pingle
10:58 AM Feature #10486 (Rejected): Feature Request: Ability to transmit to remote syslog server via TCP
For those of us who care about our logs and want to ensure we don't drop events, it's standard practice to configure ... Bryan Sampsel
11:00 AM Feature #10485 (Rejected): Feature Request: Ability to leverage a blocklist by domain name or URL, such as at https://www.cyberthreatcoalition.org/ -- the new Cyber Threat Coalition site.
pfBlockerNG can already reject by domain -- reach out on the forum and raise the topic there: https://forum.netgate.c... Jim Pingle
10:56 AM Feature #10485 (Rejected): Feature Request: Ability to leverage a blocklist by domain name or URL, such as at https://www.cyberthreatcoalition.org/ -- the new Cyber Threat Coalition site.
There's a blocklist by domain name or URL at https://www.cyberthreatcoalition.org/
-- the new Cyber Threat Coalition...
Bryan Sampsel
08:02 AM Feature #9003 (Pull Request Review): Add 'Copy Running to Saved' option to the raw config
Jim Pingle
03:50 AM Feature #9003: Add 'Copy Running to Saved' option to the raw config
Renato Botelho wrote:
> PR has been merged. Thanks!
js function configCheck() is does not exist
This PR adds it...
Viktor Gurov

04/20/2020

10:13 AM Feature #10479 (Pull Request Review): Keep settings after deinstall option
Jim Pingle
09:41 AM Feature #10479: Keep settings after deinstall option
https://github.com/pfsense/FreeBSD-ports/pull/845 Viktor Gurov
10:11 AM Bug #10476: Services - Acme - Certificates using loopia API
Jim Pingle wrote:
> The TTL value of @60@ is hardcoded in the "dns_loopia.sh script":https://github.com/acmesh-offic...
Tobias Müllauer
08:57 AM Bug #10476 (Needs Patch): Services - Acme - Certificates using loopia API
The TTL value of @60@ is hardcoded in the "dns_loopia.sh script":https://github.com/acmesh-official/acme.sh/blob/mast... Jim Pingle
08:52 AM Todo #8332: pfBlockerNG doesn't include L2TP interface in outbound floating rules
Rules shouldn't be needed for each individual L2TP interface. There is an interface group called "l2tp" which handles... Jim Pingle
08:48 AM Feature #10474 (Pull Request Review): Suppress notifications for specific MACs
Jim Pingle
08:29 AM Bug #10475 (Pull Request Review): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
Jim Pingle

04/19/2020

03:30 AM Bug #10385 (Resolved): Pb with Username authorized characters when OTP is disabled
tested on 2.4.5/2.5 with freeradius3 0.15.7_13
works as expected - allows you to use special characters in the use...
Viktor Gurov
03:21 AM Feature #10479 (Resolved): Keep settings after deinstall option
Currently, it is not possible to clear FreeRADIUS settings except with the backup / restore configuration.
It will...
Viktor Gurov

04/18/2020

05:55 PM Bug #10476 (Resolved): Services - Acme - Certificates using loopia API
Hello i am trying to add certificate from letsecrypt using Acme.
I try diferent setup but it seams Acme try to ad...
Tobias Müllauer
01:28 PM Todo #8332: pfBlockerNG doesn't include L2TP interface in outbound floating rules
Something still needs to be fixed.
Either the rule needs to be applied to any/all L2TP interfaces created, or the ...
Stuart Wyatt
06:35 AM Todo #8332: pfBlockerNG doesn't include L2TP interface in outbound floating rules
Mpd5 will create new L2TP interfaces for each client:
l2tp0, l2tp1, l2tp2 etc..
The only way to apply firewall ru...
Viktor Gurov
12:44 PM Bug #10475 (Resolved): pfSense-pkg-arpwatch unconditinally clobbers the arpwatch database files on upgrade
I was surprised to find that upgrading the pfSense-pkg-arpwatch package today nuked all of my .dat files. There is an... Craig Leres
09:51 AM Feature #10474: Suppress notifications for specific MACs
https://github.com/pfsense/FreeBSD-ports/pull/843 Viktor Gurov
09:46 AM Feature #10474 (Resolved): Suppress notifications for specific MACs
From https://forum.netgate.com/topic/151832/suppress-arpwatch-flip-flop-emails-for-bonjour-sleep-proxy:
I just set u...
Viktor Gurov
09:34 AM Bug #10261 (Resolved): Arpwatch fails to download ethercodes.dat
Tobias Müllauer wrote:
> This is still a issue !!
>
> I have all vendors as unknown.
>
> I fix it and after a...
Viktor Gurov
09:32 AM Bug #10432 (Resolved): Arpwatch show unknown vendor
shows correct vendors on 2.4.5/2.5 with arpwatch 0.2.0_1 Viktor Gurov

04/17/2020

12:46 PM Feature #10472: Blocked host alert table break out by timestamp and type to allow sorting by date
Allowing filter by date & time would also be a handy feature on that page as well if that's easier or another thought... tasty ratz
12:36 PM Feature #10472 (Resolved): Blocked host alert table break out by timestamp and type to allow sorting by date
The blocked list doesn't by nature sort by last hit or date of creation so I have to read every entry for the most re... tasty ratz
06:18 AM Feature #9774: Squid logs / remote logs
Allow to download log files from WebGUI feature:
https://redmine.pfsense.org/issues/10468
Viktor Gurov
03:10 AM Feature #10466 (New): Add checkbox to Suricata blocked host view to resolve all resolvable IP's automatically
Manually resolving individual IP's is cumbersome when I want to get a holistic view of the blocked hosts. Also, resol... tasty ratz

04/16/2020

08:08 AM Bug #10369 (Pull Request Review): Remote OpenVPN server protocol definition
Jim Pingle
03:14 AM Bug #10369: Remote OpenVPN server protocol definition
OpenVPN < 2.4 doesn't support remote IPv4/IPv6 protocol definition (udp4/udp6/tcp4/tcp6),
If checkbox **Legacy Clien...
Viktor Gurov
01:05 AM Feature #10462 (Resolved): CPU Temp Screen
Hello, is it possible to add to the lcdproc package on pfsense a screen with the CPU-Temperature? I know that is not ... odo maitre

04/15/2020

10:44 AM Bug #9350 (Pull Request Review): not appear proxy config
Jim Pingle
10:24 AM Bug #9350: not appear proxy config
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/841
Viktor Gurov
10:43 AM Bug #9776 (Pull Request Review): Wrong function in squidguard_log.php
Jim Pingle
10:24 AM Bug #9776: Wrong function in squidguard_log.php
PR: https://github.com/pfsense/FreeBSD-ports/pull/841
it also fixes https://redmine.pfsense.org/issues/9350
Viktor Gurov
04:13 AM Feature #9762: Squid Reverse Proxy Change redir domain(s) to use regex
Updated PR with checkbox switch:
https://github.com/pfsense/FreeBSD-ports/pull/840
Viktor Gurov

04/14/2020

01:02 PM Feature #10428 (Resolved): LCDProc: Add the EZIO driver to the lcdproc config page
Looks good. Tested using an EZIO-300
Tested package: 0.10.6_10 in: 2.4.5-rel
Steve Wheeler
12:42 PM Feature #10428 (Feedback): LCDProc: Add the EZIO driver to the lcdproc config page
PR has been merged. Thanks! Renato Botelho
12:57 PM Feature #10356 (Feedback): Support for additional Notification Support
PR has been merged. Thanks! Renato Botelho
12:43 PM Feature #10297 (Feedback): IPv6 user attributes
PR has been merged. Thanks! Renato Botelho
12:37 PM Bug #10450 (Feedback): Squid reverse proxy switching peers
PR has been merged. Thanks! Renato Botelho
11:22 AM Bug #10452 (Resolved): acme - new DNS-Api namemaster.de in overview hash visible
Hi,
the new dnsapi-plugin for namemaster.de made it into my pfsense with package version 0.6.6
in Services / Ac...
Thilo Gass

04/13/2020

09:42 AM Bug #7797 (Pull Request Review): Squid Reverse Proxy alternating between destinations
PR: https://github.com/pfsense/FreeBSD-ports/pull/839 Jim Pingle
09:42 AM Bug #10450 (Pull Request Review): Squid reverse proxy switching peers
Jim Pingle
05:28 AM Bug #10450: Squid reverse proxy switching peers
https://github.com/pfsense/FreeBSD-ports/pull/839 Viktor Gurov
05:25 AM Bug #10450 (Feedback): Squid reverse proxy switching peers
https://forum.netgate.com/topic/118255/squid-reverse-proxy-switching-peers:
I want Squid to direct incoming requests...
Viktor Gurov

04/12/2020

05:57 PM Bug #10427 (Resolved): LCDproc: Handle multiple lcdproc clients
This works in as far as it avoids blowing up if there is more than one client. It now successfully kills all php clie... Steve Wheeler
10:43 AM Bug #10320 (Resolved): lcdproc Crash report begins
Looks good. Enabling the 'Addresses by traffic' screen shows the correct data and no longer throws a php error.
Te...
Steve Wheeler
10:36 AM Feature #10243 (Resolved): rawserial driver for lcdproc
Looks good. Size, speed and port are passed correctly to the conf file:... Steve Wheeler
10:21 AM Feature #8198 (Resolved): pfSense-pkg-LCDproc: Add a link status screen for each interface
Looks good. Tested in lcdproc 0.10.6_9, pfSense 2.4.5-rel Steve Wheeler

04/11/2020

02:42 AM Feature #9217 (Resolved): Squid LDAP Authentication - spaces in ldif values
squid pkg 0.4.44_21 - works as expected Viktor Gurov
02:40 AM Feature #10434 (Resolved): Squid whitelist/blacklist with IDN hostnames
squid pkg 0.4.44_21 works as expected Viktor Gurov
02:39 AM Bug #10440 (Resolved): Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
squid pkg 0.4.44_21 - OK Viktor Gurov

04/10/2020

09:37 AM Bug #10447 (Pull Request Review): Framed-IP-Address with plus sign is deprecated
Jim Pingle
07:38 AM Bug #10447: Framed-IP-Address with plus sign is deprecated
added to https://github.com/pfsense/FreeBSD-ports/pull/810 Viktor Gurov
02:13 AM Bug #10447 (Resolved): Framed-IP-Address with plus sign is deprecated
if you use Framed-IP-Address with plus sign, i.e.... Viktor Gurov
09:21 AM Bug #10442 (Pull Request Review): ACME: special characters in descriptions trigger silent error and rollback
Jim Pingle
05:13 AM Bug #10442: ACME: special characters in descriptions trigger silent error and rollback
this fix uses descr field name instead of desc,
it's included in the $cdata_fields of xmlparser.inc:
https://github...
Viktor Gurov
03:30 AM Bug #7654 (Resolved): Can't use a LDAP search filter containing an accent
works as expected on 2.5.0.a.20200409.0657:... Viktor Gurov
01:44 AM Bug #10369 (Resolved): Remote OpenVPN server protocol definition
openvpn-client-export 1.4.21
IPv4/IPv6 tested
works as expected
Viktor Gurov

04/09/2020

07:10 AM Feature #10428 (Pull Request Review): LCDProc: Add the EZIO driver to the lcdproc config page
Jim Pingle
04:49 AM Bug #10445: BIND crashed when added RPZ. rpz is not a master or slave zone.
i was able to reproduce it here
https://forum.netgate.com/topic/152274/rpz-rpz-local-is-not-a-master-or-slave-zone-c...
Manuel Piovan

04/08/2020

04:11 PM Feature #8196 (Resolved): pfSense-pkg-LCDproc: add a shutdown/reboot control menu
Tested on several LCDs with lcdproc 0.10.6_9.
Works well.
Steve Wheeler

04/07/2020

05:46 PM Bug #10445 (Feedback): BIND crashed when added RPZ. rpz is not a master or slave zone.
Before upgrade pfsense to version 2.4.5 i try update packages on 2.4.4p3.
After updating BIND to 9.14_3 (Package Dep...
lexxai lexxai
03:23 PM Bug #10444 (Resolved): FRR will not start in 2.4.5 aarch64
We have an internal bug open for this but it's not public.
https://redmine.netgate.com/issues/3765
Updates will b...
Steve Wheeler
11:44 AM Bug #10443 (Closed): pfSense-pkg-squid-0.4.44_19 and pfSense-pkg-squid-0.4.44_20
Fixed:
see https://redmine.pfsense.org/issues/10434#note-4
and PR https://github.com/pfsense/FreeBSD-ports/pull/836
Viktor Gurov
11:00 AM Bug #10443 (Closed): pfSense-pkg-squid-0.4.44_19 and pfSense-pkg-squid-0.4.44_20
After update from pfSense-pkg-squid-0.4.44_18 to pfSense-pkg-squid-0.4.44_19 Reverse proxy stopped working.
Squid do...
Ilian Cheneshev
11:36 AM Feature #10434 (Pull Request Review): Squid whitelist/blacklist with IDN hostnames
Jim Pingle
11:32 AM Feature #10434: Squid whitelist/blacklist with IDN hostnames
Use idn_to_ascii() only for ACL
Otherwise sq_text_area_decode() create incorrect files (i.e. crt or key files)
Fi...
Viktor Gurov
09:38 AM Bug #10442: ACME: special characters in descriptions trigger silent error and rollback
Ah I see. Would just filtering out those characters via an error message before trying to save it be a better approac... Jens Groh
09:30 AM Bug #10442: ACME: special characters in descriptions trigger silent error and rollback
No, it's not from htmlentities. It's that those characters are not valid in XML. So the field probably needs to have ... Jim Pingle
09:25 AM Bug #10442: ACME: special characters in descriptions trigger silent error and rollback
small addition:
is related to Acme 0.6.6 (still happens on 2.5.x snapshots)
There are special chars that work (...
Jens Groh
09:19 AM Bug #10442 (Resolved): ACME: special characters in descriptions trigger silent error and rollback
pfSense: 2.4.5
Acme: 0.6.6
Re-create:
1) ACME > Certificates: create new certificate
2) enter any settings fo...
Jens Groh
09:35 AM Bug #10439: BandwidthD stopped working after update
Jim Pingle wrote:
> It works fine here on 2.4.5, and you did not provide enough detail to even guess at what might b...
Mark Grant
08:05 AM Bug #10439 (Rejected): BandwidthD stopped working after update
It works fine here on 2.4.5, and you did not provide enough detail to even guess at what might be wrong in your speci... Jim Pingle
09:17 AM Bug #10440 (Feedback): Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
PR has been merged. Thanks! Renato Botelho
08:50 AM Bug #10440: Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
Thanks for your quick update :)
I patched the file and it works as before.
Tobias Meyer
08:06 AM Bug #10440 (Pull Request Review): Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
Jim Pingle
05:32 AM Bug #10440: Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
ACLs are blank on pre-2.4.5 pfSense,
caused by the absence of _idn_to_ascii()_
Fix:
https://github.com/pfsense/F...
Viktor Gurov
02:59 AM Bug #10440: Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
Viktor Gurov wrote:
> can you check it in your squid.conf?
> Need more information
I can see the subnet on the U...
Tobias Meyer
02:47 AM Bug #10440: Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
There is only one change in https://github.com/pfsense/FreeBSD-ports/pull/830
- fixes IPv6 duplicate addresses in lo...
Viktor Gurov
02:31 AM Bug #10440 (Resolved): Squid proxy ignoring allowed_subnets after package upgrade 0.4.44_9 ==> 0.4.44_19
We allow an additional subnet (OpenVPN Roadwarriors) on our squid proxy server additionally to the LAN interface.
...
Tobias Meyer
08:22 AM Feature #10441 (Pull Request Review): Integration of bfd daemon
Jim Pingle
07:48 AM Feature #10441: Integration of bfd daemon
Corresponding PR :
https://github.com/pfsense/FreeBSD-ports/pull/835
Emmanuel Roger
07:34 AM Feature #10441 (Resolved): Integration of bfd daemon
FRR package already include bfd daemon and it could be use to reduce fault detection.
Some changes are needed in o...
Emmanuel Roger
07:59 AM Bug #10338 (Resolved): FRR OSPF6 Router-ID configuration statement has changed
OK on frr 0.6.4_3 Viktor Gurov
03:30 AM Bug #7048 (Resolved): Add IPv6 support to squid
resolved in https://redmine.pfsense.org/issues/10335
and https://redmine.pfsense.org/issues/8887
Viktor Gurov
03:26 AM Feature #10335 (Resolved): Squid IPv6 transparent mode
works as expected on 2.4.5/2.5 with squid 0.4.44_19 Viktor Gurov
01:01 AM Bug #10422 (Resolved): Squid LDAP auth must use LDAPURI option
works as expected on 2.4.5 with squid 0.4.44_19 Viktor Gurov
12:59 AM Bug #10378 (Resolved): Add IPv6 network to Squid localnet
works as expected on 2.4.5 with squid 0.4.44_19 Viktor Gurov
12:54 AM Bug #10379 (Resolved): squid not authenticate LDAP/RADIUS
works as expected on 2.4.5 with squid 0.4.44_19 Viktor Gurov

04/06/2020

07:19 PM Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
Manuel Piovan wrote:
> me too
> can you try with the flag -P udp from console and report back?
> example /usr/loca...
Mark Hassman
06:25 AM Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
me too
can you try with the flag -P udp from console and report back?
example /usr/local/bin/softflowd -D -i 1:vmx1...
Manuel Piovan
02:01 AM Bug #10436 (Feedback): softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
Hi, after upgrading pfsense from v2.4.4_3 -> v2.4.5 (which included an upgrade of softflowd from v0.9.9_1 -> v1.0), s... Mark Hassman
06:49 PM Bug #10439 (Rejected): BandwidthD stopped working after update
BandwidthD package stopped working after an update.
it installs fine, but no graphs.
deinstall/reinstall, same ...
Mark Grant
02:21 PM Feature #10428: LCDProc: Add the EZIO driver to the lcdproc config page
tested here https://forum.netgate.com/topic/115071/ezio-driver-for-lcdproc/115
PR https://github.com/pfsense/FreeBSD...
Manuel Piovan
11:04 AM Bug #7654 (Feedback): Can't use a LDAP search filter containing an accent
PR has been merged. Thanks! Renato Botelho
07:55 AM Bug #7654 (Pull Request Review): Can't use a LDAP search filter containing an accent
Jim Pingle
11:01 AM Bug #10432 (Feedback): Arpwatch show unknown vendor
PR has been merged. Thanks! Renato Botelho
08:17 AM Bug #10432 (Pull Request Review): Arpwatch show unknown vendor
Jim Pingle
11:00 AM Feature #10434 (Feedback): Squid whitelist/blacklist with IDN hostnames
PR has been merged. Thanks! Renato Botelho
07:57 AM Feature #10434 (Pull Request Review): Squid whitelist/blacklist with IDN hostnames
Jim Pingle
11:00 AM Feature #10335 (Feedback): Squid IPv6 transparent mode
PR has been merged. Thanks! Renato Botelho
08:10 AM Feature #10335 (Pull Request Review): Squid IPv6 transparent mode
Jim Pingle
10:55 AM Bug #10427 (Feedback): LCDproc: Handle multiple lcdproc clients
PR has been merged. Thanks! Renato Botelho
07:49 AM Bug #10427 (Pull Request Review): LCDproc: Handle multiple lcdproc clients
Jim Pingle
10:55 AM Bug #10385 (Feedback): Pb with Username authorized characters when OTP is disabled
PR has been merged. Thanks! Renato Botelho
07:48 AM Bug #10385 (Pull Request Review): Pb with Username authorized characters when OTP is disabled
Jim Pingle

04/05/2020

03:03 PM Feature #10434: Squid whitelist/blacklist with IDN hostnames
https://github.com/pfsense/FreeBSD-ports/pull/832 Viktor Gurov
02:58 PM Feature #10434 (Resolved): Squid whitelist/blacklist with IDN hostnames
Squid doesn't block non-ascii domans
non-ascii domains must first be converted to punycode:
https://unix.stackexcha...
Viktor Gurov
02:11 PM Bug #7654: Can't use a LDAP search filter containing an accent
TODO:
CDATA encode FreeRADIUS LDAP options
Viktor Gurov
02:10 PM Bug #7654: Can't use a LDAP search filter containing an accent
CDATA encode Squid LDAP options:
https://github.com/pfsense/pfsense/pull/4265
Viktor Gurov
07:10 AM Feature #10428: LCDProc: Add the EZIO driver to the lcdproc config page
EZIO is a serial connection type for HD44780. It must be set for the server to be able to talk to it.
https://github...
Steve Wheeler
07:05 AM Feature #10428: LCDProc: Add the EZIO driver to the lcdproc config page
https://github.com/lcdproc/lcdproc/releases
HD44780 connection type "serial" supports Portwell EZIO-100 and EZIO-300...
Manuel Piovan
06:00 AM Bug #10432: Arpwatch show unknown vendor
this is due to $oui = strtoupper(substr($mac, 0, 8));
the content of ethercodes.dat is not uppercase
PR https://...
Manuel Piovan
05:55 AM Bug #10432 (Resolved): Arpwatch show unknown vendor
arpwatch.inc
line 164
if (preg_match("/^$oui\s+(.*)$/m", file_get_contents(ARPWATCH_LOCAL_DIR.'/ethercodes.dat'), $...
Manuel Piovan
05:31 AM Bug #10431: pfBlockerNG Cron Job wrong - Clear IP / DNSBL Statistics
Preview function is your friend. Cron looks like... Luki TJ
05:26 AM Bug #10431 (Resolved): pfBlockerNG Cron Job wrong - Clear IP / DNSBL Statistics
Configuring on the pfBlockerNG Widget the Statistic clearance on a weekly frequency results in this cron config:
*...
Luki TJ
 

Also available in: Atom