Activity
From 05/31/2020 to 06/29/2020
06/29/2020
-
02:48 AM Bug #10700: not all VPN IPs added with vpnaddresses option
- Suricata 4 PR:
https://github.com/pfsense/FreeBSD-ports/pull/889
06/26/2020
-
01:29 PM Bug #10697 (Feedback): Missing New Line After NCP Parameter in Client Config
- PR has been merged. Thanks!
-
11:34 AM Bug #8688 (Feedback): Pass List Snort
- PR has been merged. Thanks!
-
11:32 AM Bug #10700 (Feedback): not all VPN IPs added with vpnaddresses option
- PR has been merged. Thanks!
-
11:30 AM Bug #10552 (Feedback): Typo in OpenBGPD's settings page
- PR has been merged. Thanks!
06/25/2020
-
01:11 PM Bug #10692: PIMD starts twice at boot
- With "the patch emulated" (by stopping pimd, disabling and anabling interfaced, stating pimd again) it is working mor...
-
07:46 AM Bug #10700 (Pull Request Review): not all VPN IPs added with vpnaddresses option
-
05:19 AM Bug #10700: not all VPN IPs added with vpnaddresses option
- https://github.com/pfsense/FreeBSD-ports/pull/888
-
05:05 AM Bug #10700 (Resolved): not all VPN IPs added with vpnaddresses option
- Suricata uses filter_get_vpns_list() to get vpnaddresses list
filter_get_vpns_list() returns only:
IPsec Mobile I... -
07:45 AM Bug #10552 (Pull Request Review): Typo in OpenBGPD's settings page
-
05:00 AM Bug #10552: Typo in OpenBGPD's settings page
- Fix:
https://github.com/pfsense/FreeBSD-ports/pull/887 -
07:40 AM Bug #10697 (Pull Request Review): Missing New Line After NCP Parameter in Client Config
-
01:31 AM Bug #10697: Missing New Line After NCP Parameter in Client Config
- https://github.com/pfsense/FreeBSD-ports/pull/809
-
01:31 AM Bug #10697 (Resolved): Missing New Line After NCP Parameter in Client Config
- "auth alg" digest algorithm client config parameter is erroneously merged into the same config line as the "ncp-disab...
-
03:14 AM Bug #8688: Pass List Snort
- Snort 3.x (pfSense 2.4.5) PR:
https://github.com/pfsense/FreeBSD-ports/pull/886 -
02:56 AM Bug #10679 (Resolved): Squid reverse proxy CA cert without prv key
- squid pkg 0.4.44_28 shows CA without private key on the Squid Reverse Proxy configuration page
06/24/2020
-
09:34 AM Feature #10689 (Feedback): Squid Reverse proxy IPv6 and HA support
- PR has been merged. Thanks!
-
09:34 AM Bug #10679 (Feedback): Squid reverse proxy CA cert without prv key
- PR has been merged. Thanks!
-
09:29 AM Bug #10688 (Feedback): Remove Zabbix 4.2 ports
- PR has been merged. Thanks!
-
09:23 AM Bug #10692: PIMD starts twice at boot
- I solved the "no enabled vifs" issue by changing in menu pimd/interfaces/interface binding from default to "Always bi...
-
04:49 AM Bug #10692: PIMD starts twice at boot
- Hello,
I did some tests in advance of this patch. I could do that by forcing a reread of the vifs by disabling and... -
04:49 AM Bug #10695 (New): FreeRadius Accounting skipping MBs after reboot due to power down
- I am running 2.4.5-RELEASE (amd64) version.
I am setting up Captive Portal with FreeRadius to limit users monthly qo...
06/23/2020
-
03:24 PM Bug #10693 (New): pfSense Bind Zone Editor UI does not update zone serial number when a change is made
- /pkg_edit.php?xml=bind_zones.xml&act=edit&id=0
populates the "Serial" field with the serial number of the current... -
12:57 PM Bug #10692 (Confirmed): PIMD starts twice at boot
- Hello,
I just discoverd a critical error in the pfSense boot sequence.
- Independed if you have enabled the PIMD...
06/22/2020
-
12:21 PM Feature #10689 (Pull Request Review): Squid Reverse proxy IPv6 and HA support
-
10:53 AM Feature #10689: Squid Reverse proxy IPv6 and HA support
- https://github.com/pfsense/FreeBSD-ports/pull/885
-
03:22 AM Feature #10689 (Resolved): Squid Reverse proxy IPv6 and HA support
- allow to listen on IPv4/IPv6/IPv4+IPv6 interfaces, see #8887
and add ability to select CARP interfaces, see #5168 -
07:29 AM Bug #10688 (Pull Request Review): Remove Zabbix 4.2 ports
-
07:11 AM Bug #10654 (Resolved): Whitelisted domains starting with a dot are ignored
- pfSense-pkg-squid 0.4.44_27 - work as expected
06/21/2020
-
02:45 PM Bug #10688: Remove Zabbix 4.2 ports
- https://github.com/pfsense/pfsense/pull/4365
https://github.com/pfsense/FreeBSD-ports/pull/884 -
02:42 PM Bug #10688 (Resolved): Remove Zabbix 4.2 ports
- - Remove Zabbix 4.2 ports.
- Fix typos, reported on https://github.com/pfsense/FreeBSD-ports/pull/876
Zabbix 4.2 ...
06/19/2020
-
09:10 AM Bug #10679 (Pull Request Review): Squid reverse proxy CA cert without prv key
-
09:05 AM Bug #10679: Squid reverse proxy CA cert without prv key
- https://github.com/pfsense/FreeBSD-ports/pull/883
-
08:55 AM Bug #10679 (Resolved): Squid reverse proxy CA cert without prv key
- from https://forum.netgate.com/topic/154504/squid-0-4-44_26-cannot-select-external-ca-s
Currently is not possible to... -
03:46 AM Feature #8727 (Resolved): Clone button in cron pkg
- Cron 0.3.7_4 - works as expected
-
01:18 AM Feature #9765 (Resolved): Update iperf package to iperf3
- pfSense 2.4.5 and 2.5 use iperf3
see also #10357 -
01:12 AM Bug #10611 (Resolved): FRR applies file permissions to missing files
- resolved in frr 0.6.6
-
01:11 AM Bug #10657 (Resolved): FRR: AS-Path Filter doesn't work anymore
- frr 0.6.6 generates a configuration with the correct as-path:...
06/18/2020
-
11:26 AM Bug #10673 (Rejected): Avahi interface list is missing interfaces
- Avahi already shows all enabled interfaces
all you need to do is assign and enable the OpenVPN interface -
10:23 AM Bug #10673 (Rejected): Avahi interface list is missing interfaces
- In avahi_settings.php, there is a list of network interfaces. Mine shows LAN, DMZ, WAN2. The list is missing my "WA...
-
09:00 AM Feature #10441 (Feedback): Integration of bfd daemon
- PR has been merged. Thanks!
-
08:45 AM Bug #10654 (Feedback): Whitelisted domains starting with a dot are ignored
- PR has been merged. Thanks!
-
08:42 AM Bug #10611 (Feedback): FRR applies file permissions to missing files
- PR has been merged. Thanks!
-
08:42 AM Bug #10657 (Feedback): FRR: AS-Path Filter doesn't work anymore
- PR has been merged. Thanks!
06/15/2020
-
10:00 AM Feature #10665 (Resolved): Manual OSPF neighbor definitions
- OSPF interface modes "non-broadcast" and "point-to-miltipoint" rely on being able to manually define specific OSPF ne...
06/12/2020
-
09:50 AM Bug #10656 (Pull Request Review): Acme letsencrypt doesn't change private key type
-
07:39 AM Bug #10656: Acme letsencrypt doesn't change private key type
- Fix:
https://github.com/pfsense/FreeBSD-ports/pull/881 -
06:45 AM Bug #10656 (Confirmed): Acme letsencrypt doesn't change private key type
- Right, got the same issue
-
05:56 AM Bug #10656: Acme letsencrypt doesn't change private key type
- It isn't really a duplicate of that bug. The fallout of that bug sets up the conditions where you might want to chan...
-
12:23 AM Bug #10656 (Rejected): Acme letsencrypt doesn't change private key type
- Duplicate of #10655
Please add any additional comments to that issue. -
09:44 AM Bug #10654 (Pull Request Review): Whitelisted domains starting with a dot are ignored
-
06:48 AM Bug #10654: Whitelisted domains starting with a dot are ignored
- Fix:
https://github.com/pfsense/FreeBSD-ports/pull/880 -
09:42 AM Bug #10657 (Pull Request Review): FRR: AS-Path Filter doesn't work anymore
-
04:58 AM Bug #10657: FRR: AS-Path Filter doesn't work anymore
- Correct, see http://docs.frrouting.org/en/latest/bgp.html#as-path-access-lists
Fix:
https://github.com/pfsense/Fr... -
04:21 AM Bug #10657: FRR: AS-Path Filter doesn't work anymore
- Syntax for as-path acl has changed in frr ...
Now it's ... -
03:54 AM Bug #10657 (Resolved): FRR: AS-Path Filter doesn't work anymore
- Hi,
after upgrade from 2.4.4_p3 to 2.4.5_p1 route-maps for BGP metric altering based on AS-Path match don't work a... -
09:41 AM Bug #10655 (Resolved): ntopng fails with letsencrypt ECC certificates
- If it works on the latest ntopng then it's already been fixed upstream. It may also be fixed by the newer OpenSSL on ...
-
04:40 AM Bug #10655: ntopng fails with letsencrypt ECC certificates
- It seems ntopng 3.8 issue, is the same error ERR_SSL_VERSION_OR_CIPHER_MISMATCH with EC-256 certificate
but there ... -
09:40 AM Bug #8688 (Pull Request Review): Pass List Snort
-
01:38 AM Bug #8688: Pass List Snort
- https://github.com/pfsense/FreeBSD-ports/pull/878
see also #10493 -
07:12 AM Feature #10557 (Resolved): Add Zabbix 5.0 LTS (agent and proxy) packages
06/11/2020
-
09:49 PM Bug #10656 (Closed): Acme letsencrypt doesn't change private key type
- As alluded to in this year and a half old post (https://forum.netgate.com/topic/116404/ntopng-and-let-s-encrypt-certi...
-
09:43 PM Bug #10655 (Resolved): ntopng fails with letsencrypt ECC certificates
- Configuring ntopng to use letsencrypt certificates (via the Acme package) works with default RSA 2048 bit certificate...
-
01:05 PM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- Seems to work for me
-
12:55 PM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- Danilo Baio wrote:
> Yes, it's missing zabbix config options for the 2.4.5 packages:
> https://github.com/pfsense/F... -
12:31 PM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- Pim Janssen wrote:
> Thanks, i just upgraded my zabbix-proxy on pfsense.
> Now i am getting the following error:
>... -
11:55 AM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- Thanks, i just upgraded my zabbix-proxy on pfsense.
Now i am getting the following error:
`connection to database '... -
11:04 AM Bug #10654 (Resolved): Whitelisted domains starting with a dot are ignored
- https://forum.netgate.com/topic/153933/solved-squid-0-4-44_25-assertion-failed-http-cc-1533-comm-monitorsread-serverc...
-
09:58 AM Bug #10146 (Resolved): squid4 obsolete options
- OK - no NO_SSLv2 option in squid pkg 0.4.44_26
-
04:38 AM Feature #9874 (Resolved): safesearch enforcing
- link is ok now
-
04:37 AM Feature #10627 (Resolved): add Yandex Site Checker link
- works as expected on the latest pfBlockerNG-devel
-
01:21 AM Feature #10653 (New): Allow to download frr_status
- Add a button on the status_frr.php page to load all the frr status output as a txt file.
-
01:08 AM Feature #10628 (Resolved): Allow to change url_rewrite_children options
- pfSense-pkg-squidGuard-1.16.18_6 works as expected
06/10/2020
-
05:28 PM Bug #10642: ACME certificate renewal with DNS-Gandi method fails when using multiple Gandi keys
- I don't have SSH access to the router, so unfortunately I cannot run acme.sh outside pfSense. I suppose the answer li...
-
12:56 PM Bug #10649: OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- Jim Pingle wrote:
> That particular document is outdated, the Cert Manager supports forming chains on its own now. I... -
12:15 PM Bug #10649: OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- That particular document is outdated, the Cert Manager supports forming chains on its own now. I have a setup with in...
-
12:10 PM Bug #10649: OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- > Either your CA/Cert subjects are not unique and it formed an incorrect internal association on import, or you impor...
-
08:42 AM Bug #10649 (Not a Bug): OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- Either your CA/Cert subjects are not unique and it formed an incorrect internal association on import, or you importe...
-
04:07 AM Bug #10649: OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- Note: I posted this initially on the Netgate forums. Several views but no feedback. Perhaps not many people set up a ...
-
04:05 AM Bug #10649 (Not a Bug): OpenVPN Cllient Export Wizard Using Wrong Root CA Certificate
- This occurs using pfSense 2.4.5-RELEASE (arm) on an SG-3100. OpenVPN CE Wizard v1.4.23.
I had two Root CAs in pfSe... -
11:04 AM Feature #10557 (Feedback): Add Zabbix 5.0 LTS (agent and proxy) packages
- PR has been merged. Thanks!
-
11:01 AM Feature #9874 (Feedback): safesearch enforcing
- PR has been merged. Thanks!
-
10:53 AM Feature #10628 (Feedback): Allow to change url_rewrite_children options
- PR has been merged. Thanks!
-
10:53 AM Feature #10627 (Feedback): add Yandex Site Checker link
- PR has been merged. Thanks!
-
10:52 AM Feature #10618 (Feedback): Set sysDescr the same as bsnmpd unless overriden with net-snmp
- PR has been merged. Thanks!
-
10:51 AM Bug #10146 (Feedback): squid4 obsolete options
- PR has been merged. Thanks!
-
10:50 AM Bug #5168 (Feedback): squid doesn't function during/after HA failover
- PR has been merged. Thanks!
-
10:49 AM Feature #9793 (Feedback): Add support for HAProxy ACLs "src -f /ipalias.lst" to use pfBlockerNG IP Alias Native
- PR has been merged. Thanks!
-
10:48 AM Feature #8727 (Feedback): Clone button in cron pkg
- PR has been merged. Thanks!
-
10:11 AM Bug #10647 (Feedback): FRR BGP Advanced > Aggregated Addresses ignores ipv6 subnets
- PR has been merged. Thanks!
-
09:19 AM Bug #10647 (Pull Request Review): FRR BGP Advanced > Aggregated Addresses ignores ipv6 subnets
-
01:48 AM Bug #10647: FRR BGP Advanced > Aggregated Addresses ignores ipv6 subnets
- Fix:
https://github.com/pfsense/FreeBSD-ports/pull/877 -
06:13 AM Feature #10599: Add support for hitless-reloads of HAproxy config
- Thanks and sorry, missed it
-
05:40 AM Feature #10599 (Rejected): Add support for hitless-reloads of HAproxy config
- Already supported:
see https://github.com/pfsense/FreeBSD-ports/blob/76396719e6e1b7c0c54dc70c2bb91c127a7ff8c4/net/...
06/09/2020
-
02:36 PM Bug #10647 (Resolved): FRR BGP Advanced > Aggregated Addresses ignores ipv6 subnets
- The php script generating the bgp.conf file only writes out the configuration if the subnet is an ipv4 subnet: https:...
-
11:49 AM Bug #10646 (Resolved): Reinstall package process stalls at pfBlockerNG when restoring a config
- The package install process for pfBlockerNG completes but the processes do not close out preventing subsequent packag...
-
07:55 AM Bug #10642: ACME certificate renewal with DNS-Gandi method fails when using multiple Gandi keys
- Have you tried doing this with acme.sh on its own (not through pfSense)? It may be a problem in the Gandi script, it ...
06/08/2020
-
03:17 PM Bug #10642 (Duplicate): ACME certificate renewal with DNS-Gandi method fails when using multiple Gandi keys
- With the ACME service, when trying to issue/renew a certificate on 2 domain names (or more) using the DNS-Gandi Live ...
-
09:11 AM Feature #10640 (Rejected): Request addition of ZNC to Package Manager available packages
- In my opinion, that kind of service is a poor fit for a firewall. Especially given its "poor security history":https:...
-
08:41 AM Feature #10557 (Pull Request Review): Add Zabbix 5.0 LTS (agent and proxy) packages
06/06/2020
-
02:40 PM Feature #10640 (Rejected): Request addition of ZNC to Package Manager available packages
- I would like to request the addition of the ZNC package for installation via the pfSense Package Manager, pfSense rel...
06/05/2020
-
08:20 PM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- Danilo Baio wrote:
> I'll open a PR later today for this...
https://github.com/pfsense/FreeBSD-ports/pull/876
ht... -
08:44 AM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- I'll open a PR later today for this...
-
08:44 AM Todo #9880 (Resolved): Remove Zabbix 2.2 Packages
-
08:43 AM Todo #9880: Remove Zabbix 2.2 Packages
- This can be closed
06/04/2020
-
03:01 AM Feature #10557: Add Zabbix 5.0 LTS (agent and proxy) packages
- The above issue has now status fixed.
06/03/2020
-
10:58 AM Feature #10628 (Pull Request Review): Allow to change url_rewrite_children options
-
10:49 AM Feature #10628: Allow to change url_rewrite_children options
- https://github.com/pfsense/FreeBSD-ports/pull/875
-
08:17 AM Feature #10628 (Resolved): Allow to change url_rewrite_children options
- https://forum.netgate.com/topic/153877/squid-and-squidguard-on-pfsense-for-large-deployment/2:...
-
10:39 AM Bug #10611 (Pull Request Review): FRR applies file permissions to missing files
-
07:53 AM Bug #10611: FRR applies file permissions to missing files
- Fix:
https://github.com/pfsense/FreeBSD-ports/pull/874 -
10:38 AM Feature #10627 (Pull Request Review): add Yandex Site Checker link
-
07:05 AM Feature #10627: add Yandex Site Checker link
- https://github.com/pfsense/FreeBSD-ports/pull/873
-
07:03 AM Feature #10627 (Resolved): add Yandex Site Checker link
- add link to https://yandex.com/safety/?url=_SITE_ on pfblockerng_threats.php page
See https://yandex.com/support/sea...
06/01/2020
-
01:51 PM Feature #10618 (Pull Request Review): Set sysDescr the same as bsnmpd unless overriden with net-snmp
-
11:59 AM Feature #10618 (Resolved): Set sysDescr the same as bsnmpd unless overriden with net-snmp
- The current behaviour breaks detection with SNMP NMS' where it will show as a generic FreeBSD box.
https://github.... -
01:49 PM Feature #10619 (Pull Request Review): Various FRR enhancements
-
12:01 PM Feature #10619: Various FRR enhancements
- Github PR: https://github.com/pfsense/FreeBSD-ports/pull/869
-
12:00 PM Feature #10619 (Resolved): Various FRR enhancements
- Started off tidying up the BFD integrating in #835 and found a few other things to tidy up.
1. Extend #10441 to be... -
10:01 AM Bug #10146 (Pull Request Review): squid4 obsolete options
-
09:58 AM Bug #5168 (Pull Request Review): squid doesn't function during/after HA failover
Also available in: Atom