Project

General

Profile

Activity

From 09/26/2021 to 10/25/2021

10/25/2021

12:31 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Just a quick update to let you know I've tested for this issue on the latest community release of OPNsense (21.7.3_3)... Ryan Roosa
10:02 AM Bug #11465 (Closed): Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
Jim Pingle
07:26 AM Feature #11386 (Resolved): Add WireGuard tunneled networks to vpnaddresses list
Tested on 21.05_p1 and on 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I see WireGuard tunnel network i...
Azamat Khakimyanov

10/24/2021

08:02 AM Bug #11682 (Resolved): Certificate Manager page do not show STunnel used certificates
Tested on 21.05.1 and 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I still see this Bug on 21.05.1 but ...
Azamat Khakimyanov
07:43 AM Bug #11683 (Resolved): Certificate Manager page doesn't show FreeRADIUS used certificates
Tested on 21.05.1 and 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I see FreeRADIUS certificate in 'IN ...
Azamat Khakimyanov
07:04 AM Bug #11687 (Resolved): Fix download URLs for SecuriteInfo.com
Tested on 21.05.1 and 22.01-DEVELOPMENT (Squid: 0.4.45_5).
I saw SecuriteInfo.com ID in /usr/local/pkg/squid_antivir...
Azamat Khakimyanov

10/23/2021

06:36 AM Bug #11465: Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
This ticket can now be closed as the PR has been merged Adam Cooper

10/22/2021

03:04 PM Bug #12482 (Pull Request Review): Outdated doc links
Jim Pingle
08:59 AM Bug #12482: Outdated doc links
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/140
Viktor Gurov
07:06 AM Bug #12482 (Resolved): Outdated doc links
The HAProxy-devel package (based on haproxy 2.4.x) uses outdated doc links (haproxy 1.7):... Viktor Gurov
12:56 PM Bug #12142 (Resolved): XMLRPC replication target configuration
Tested on the:... Danilo Zrenjanin
09:42 AM Bug #12484 (Duplicate): Unable to remove intermediate CA
It's the same as the other linked issue. Adding that feature will solve this problem as the user could choose the oth... Jim Pingle
09:38 AM Bug #12484 (Duplicate): Unable to remove intermediate CA
Some client needs to remove intermediate "ISRG Root X1" CA to allow legacy clients to work,
otherwise they will get ...
Viktor Gurov

10/20/2021

08:30 AM Bug #12475 (Pull Request Review): OpenVPN Client Export does not show certificate without private key
Jim Pingle
01:42 AM Bug #12475: OpenVPN Client Export does not show certificate without private key
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/137
Viktor Gurov
08:22 AM Bug #12293 (Resolved): Resolve host via Reverse DNS looks shows IDN domains as punnycode
suricata 6.0.3_3 - works as expected Viktor Gurov
03:16 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1117
Viktor Gurov

10/19/2021

01:54 PM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
I did not try intermediate versions between 6.0.0_14 and 6.0.3_3, just installed the latest, so I can't say when this... Steve Y
09:57 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
Edit: I have a 2100/21.05.1 with the latest Snort 4.1.4_3 and it doesn't have this issue. Steve Y
09:50 AM Regression #12476 (Resolved): Suricata 6.0.3_3 Pass List ignores all single IPs
After upgrading pfSense-pkg-suricata from 6.0.0_14 to 6.0.3_3 all Pass List entries for single IPs are ignored and no... Steve Y
07:24 AM Bug #12475 (Resolved): OpenVPN Client Export does not show certificate without private key
When using the page https://<server>/vpn_openvpn_export.php to export an openvpn client config package only certifica... Denis Grilli
05:21 AM Feature #12447: Acme add dnsapi dns_cpanel.sh
How can I upgrade? Akos Tomaschik

10/18/2021

04:46 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
FWIW, just wanted to share updates I've made to my bandaid script. I found that 'head -c' usage on '/dev/urandom' lik... Ryan Roosa
11:16 AM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Christian McDonald wrote in #note-13:
> Thank you for the detailed report here. This is immensely helpful. I will co...
Ryan Roosa
09:10 AM Feature #11163 (Pull Request Review): Preferred Chain option
Jim Pingle
07:47 AM Feature #12447 (Rejected): Acme add dnsapi dns_cpanel.sh
New providers all get added when we update ACME from upstream, we don't add them manually or separately like this, so... Jim Pingle
05:48 AM Todo #12456 (Resolved): Remove zabbix 5.2 packages
Max Leighton wrote in #note-3:
> I checked in
>
> 2.6.0-DEVELOPMENT (amd64)
> built on Sat Oct 16 05:24:35 UTC...
Renato Botelho

10/17/2021

12:30 AM Feature #12462: Telegraf: Add "devfs" to ignore_fs
https://github.com/pfsense/FreeBSD-ports/pull/1114 Viktor Gurov

10/16/2021

10:01 PM Bug #12381 (Rejected): mOTP with RADIUS drops the VPN connection after 60 minutes
Jim Pingle wrote in #note-1:
> I don't think that's FreeRADIUS, but OpenVPN. IIRC OpenVPN defaults to reconnecting e...
Kris Phillips
07:35 PM Feature #12465 (New): Add forwardfor advanced usecases
By default haproxy creates new x-forward-for header and do not touch existing one. This could be found in documentati... DRago_Angel [InV@DER]
11:16 AM Bug #11887 (Resolved): Squid service starts twice by /etc/rc.start_packages
Tested in:
22.01-DEVELOPMENT (amd64)
built on Wed Oct 13 05:25:11 UTC 2021
FreeBSD 12.2-STABLE
Squid: 0.4.45_5 ...
Max Leighton
10:36 AM Todo #12456: Remove zabbix 5.2 packages
I checked in
2.6.0-DEVELOPMENT (amd64)
built on Sat Oct 16 05:24:35 UTC 2021
FreeBSD 12.2-STABLE
And see tha...
Max Leighton

10/15/2021

09:37 PM Bug #11592: Node exporter can not read system statistics
The issue is that in "node_collector v1.0.0":https://github.com/prometheus/node_exporter/blob/master/CHANGELOG.md#100... Daniel Kimsey
09:19 PM Feature #11163: Preferred Chain option
I submitted a PR to implement this option as I found one my clients needed it for a particular cert I was issuing.
P...
Daniel Kimsey
08:56 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Ryan Roosa wrote in #note-12:
> Samuel Hanna wrote in #note-11:
> > The problem still persist on wireguard 0.1.5_1....
Samuel Hanna
08:55 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Thank you for the detailed report here. This is immensely helpful. I will continue to poke at this next week and repo... Christian McDonald
05:18 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Samuel Hanna wrote in #note-11:
> The problem still persist on wireguard 0.1.5_1.
> even after changing the keys and ...
Ryan Roosa
06:44 PM Feature #12462 (Pull Request Review): Telegraf: Add "devfs" to ignore_fs
The Netgate XG-1537 has the following disk paths at 100% utilization:
* /dev
* /var/dhcpd/dev
* /var/unbound/dev
...
Offstage Roller

10/14/2021

10:16 AM Todo #12456 (Feedback): Remove zabbix 5.2 packages
Done Renato Botelho
10:15 AM Todo #12456 (Resolved): Remove zabbix 5.2 packages
zabbix 5.2 were removed from FreeBSD ports because they are unsupported by upstream. Remove pfSense packages as well Renato Botelho
09:55 AM Bug #10431 (Resolved): pfBlockerNG Cron Job wrong - Clear IP / DNSBL Statistics
no such issue with pfBlockerNG-devel 3.1.0 (fixed):... Viktor Gurov
09:48 AM Feature #9798: add ipv4 and ipv6 dnscrypt-resolvers feeds
actual link:
https://download.dnscrypt.net/dnscrypt-resolvers/json/public-resolvers.json
Viktor Gurov
09:42 AM Bug #11817 (Closed): Enabling Firewall / pfBlockerNG / DNSBL / IPv6 DNSBL blocks radvd from starting
Viktor Gurov

10/13/2021

02:47 PM Bug #12251: Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
→ luckman212 wrote in #note-3:
> Hmm, seems like 86400 is not a valid value after all. It got silently accepted but ...
Adam Cooper
01:34 PM Bug #12258: Copy key buttons only work in HTTPS mode
Created PR 150 to resolve this.
Tested on local dev instance with HTTP only access and it fallsback, does a consol...
Adam Cooper
09:06 AM Bug #12443: DNSBL Category ```Enable All``` button not working
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1113
Viktor Gurov
03:11 AM Feature #12447 (Rejected): Acme add dnsapi dns_cpanel.sh
Hello,
Please add the following feature to the acme package:
https://github.com/acmesh-official/acme.sh/blob/mast...
Akos Tomaschik

10/11/2021

12:39 PM Bug #12444: ntopng throws errors when viewing single host
https://redmine.pfsense.org/issues/11530 - same/same? Jordan G
08:21 AM Bug #12126: freeradius3 0.15.7_31
Ok thanks for the info.
Any chance to have freeradius3 package update for 2.5.2 release?
Alexis Pellicier
08:14 AM Bug #12126: freeradius3 0.15.7_31
This looks to be a bug in Freeradius 3.0.22. See the 3.0.23 release notes:
https://github.com/FreeRADIUS/freeradius-...
Steve Wheeler
05:17 AM Feature #11310 (Resolved): Adding a widget to apcupsd plug-in
Renato Botelho

10/09/2021

09:08 PM Bug #12444 (Closed): ntopng throws errors when viewing single host
Users have reports that when navigating to Hosts>Hosts and clicking to view a single host within the ntopNG settings ... Max Leighton
07:27 PM Bug #11886 (Resolved): WireGuard: PHP error in vpn_wg_peers_edit.php
No longer able to reproduce this in 22.01 of pfSense Plus. Closing as Resolved. Kris Phillips
07:19 PM Bug #12101 (Assigned): ArpWatch Suppression Mac for "flip-flop" not suppressing
Moving status back to Assigned as this hasn't been confirmed as fixed in updated package. Kris Phillips
04:34 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
The problem still persist on wireguard 0.1.5_1.
even after changing the keys and ports nothing seems to help.
wish ...
Samuel Hanna
01:41 PM Bug #4615: /var/logs/c-icap/server.log & access.log growing without being rotated
Hi,
so I took a look: /var/log/c-icap/access.log - 272MB
the mentioned bugfix was meant for squid, I think?
...
Stephan Berger
11:04 AM Bug #12443 (Resolved): DNSBL Category ```Enable All``` button not working
https://forum.netgate.com/topic/167094/dnsbl-catagory-bug:
"I dunno if i'm doing something wrong but under Blacklist...
Viktor Gurov
09:58 AM Bug #12153 (Resolved): Incorrect Outgoing Network Interface on clean install
Viktor Gurov
07:52 AM Bug #12153: Incorrect Outgoing Network Interface on clean install
on clean install of 0.4.45_5 the default outgoing network interface shows as "Default (auto)" upon first visit to Ser... Jordan G
07:35 AM Feature #11310: Adding a widget to apcupsd plug-in
Dashboard widget for APCUPSD is available after installing and configuring package. Status, line voltage, load, batte... Jordan G
05:50 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
Viktor Gurov wrote in #note-6:
> You can try to apply the attached patch
No need to add this if version of haproxy w...
DRago_Angel [InV@DER]
05:48 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
DRago_Angel [InV@DER] wrote in #note-3:
> Hi, this is serious CVE, and still no updates? Even it possible to workaro...
Viktor Gurov
03:25 AM Feature #11972 (Resolved): Arpwatch - Add support for Telegram notifications
there is no
Alhusein Zawi wrote in #note-4:
> there is no option to add Telegram in Arpwatch page.
>
> Tested...
Viktor Gurov

10/07/2021

09:42 AM Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
Viktor, thanks for improving the error message. Two comments:
1. putting the full path might be even better. I assu...
Sean McBride
12:41 AM Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1112
Viktor Gurov
07:29 AM Todo #12354 (Pull Request Review): Update haproxy-devel to mitigate CVE-2021-40346
Jim Pingle
02:40 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/136 Viktor Gurov
07:18 AM Bug #12420 (Pull Request Review): rc file is not deleted
Jim Pingle
01:41 AM Bug #12420: rc file is not deleted
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/135
Viktor Gurov
04:19 AM Bug #1620: Can't use transparent proxy when using bridge.
transparent mode on bridge works fine on pfSense 2.6.0.a.20211006.2213 with net.link.bridge.pfil_bridge=1 and net.lin... Viktor Gurov

10/06/2021

07:14 AM Bug #12365 (Not a Bug): PFBlockerNG - Unbound fails to start 3.1.0
No worries, thanks for following up and letting us know. Those kinds of problems can be quite frustrating to track down. Jim Pingle
04:54 AM Bug #12365: PFBlockerNG - Unbound fails to start 3.1.0
Seems this was down to a hard to find memory problem that gave random errors.
Apologies
D B
07:02 AM Todo #12427 (New): ha-proxy: action order in the GUI is not keeped in the resulting ha-proxy configuration
If there are (for example) 'Use Backend' and 'http-request redirect' actions are defined in the GUI in a specific ord... Thomas Eckardt

10/04/2021

01:53 PM Bug #12424 (Pull Request Review): OpenVPN silent install uses incorrect parameters
Jim Pingle
01:37 PM Bug #12424: OpenVPN silent install uses incorrect parameters
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/133 Marcos M
01:07 PM Bug #12424 (Resolved): OpenVPN silent install uses incorrect parameters
The @.exe@ and @.msi@ installers require different parameters for a silent install. Currently, the same parameter is ... Marcos M

10/03/2021

06:54 PM Bug #12423 (Resolved): Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
See screenshot. The message tells to 'force reload' which I did, yet the error persists.
There's one post on the ...
Sean McBride
03:53 PM Feature #10739: Update HAproxy-devel package to 2.2 and HAproxy to 2.0
Hi, here many points are still undone. DRago_Angel [InV@DER]
03:34 PM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
Hi, this is serious CVE, and still no updates? Even it possible to workaround issue by adding own check, I sure most ... DRago_Angel [InV@DER]

10/02/2021

05:58 PM Bug #12188: client export breaks multi remote configurations
Based on reviewing the bug report with OpenVPN there doesn't appear to be anything that needs to be done here. They'... Kris Phillips
05:52 PM Bug #12365 (Feedback): PFBlockerNG - Unbound fails to start 3.1.0
Completed the following tests:
1. Installed pfBlockerNG-dev
2. Ran a force update and reload
3. Monitored loggin...
Kris Phillips
05:41 PM Bug #12030: Startup Errors for Avahi Package
Jim Pingle wrote in #note-11:
> It's a package, not a part of the base system, so updates are not tied to any releas...
Kris Phillips
03:37 PM Bug #11768 (Resolved): FRR OSPF - Comment field within the ospf interfaces gets longer and longer
Tested with FRR 1.1.0_15
Looks to be fixed. The description only matches the interface that it is actually set on...
Max Leighton
08:27 AM Bug #11465: Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
Submitted PR 19 (https://github.com/theonemcdonald/pfSense-pkg-WireGuard/pull/149).
Few queries on the PR regardin...
Adam Cooper
01:07 AM Bug #12420 (Resolved): rc file is not deleted
/usr/local/etc/rc.d/pimd.sh file is not deleted after disabling the service Viktor Gurov

10/01/2021

11:53 AM Bug #12058: pfBlockerNG / "Cannot allocate memory" from Geo blocking IP list
Indeed increasing that has eliminated the "Cannot allocate memory" messages.
Could the error message be improved t...
Sean McBride
04:42 AM Bug #12033: maxmindb and _sqlite3 modules not found
How to resolve:... Viktor Gurov
04:26 AM Bug #12033: maxmindb and _sqlite3 modules not found
see the same error on SG-3100 with pfSense-21.09.r.20210923.2242 and pfBlockerNG-3.1.0:... Viktor Gurov
12:23 AM Bug #12414: DNSBL SafeSearch page displays input validation error if DoH / DoT blocking is not enabled
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1111
Viktor Gurov
12:12 AM Bug #12414 (Resolved): DNSBL SafeSearch page displays input validation error if DoH / DoT blocking is not enabled
You need to enable DoH/DoT Blocking and select entries in the DoH/DoT Blocking List, otherwise you'll see:... Viktor Gurov

09/29/2021

12:02 AM Feature #12297 (Resolved): Suricata: show actual GID:SID rule on click
Viktor Gurov

09/27/2021

08:10 AM Bug #12030: Startup Errors for Avahi Package
It's a package, not a part of the base system, so updates are not tied to any release.
It could be updated any tim...
Jim Pingle
06:39 AM Bug #12365: PFBlockerNG - Unbound fails to start 3.1.0
php-fpm 52285 /status_services.php: The command '/usr/local/sbin/unbound -c /var/unbound/unbound.conf' returned exi... D B
 

Also available in: Atom