Project

General

Profile

Activity

From 10/07/2021 to 11/05/2021

11/05/2021

03:49 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Look for Package Version 0.1.5_2, which will also upgrade net/wireguard-kmod to 0.0.20210606_2. Both are available on... Christian McDonald

11/04/2021

01:01 PM Bug #12490 (Rejected): pfSense(CE) completely freezes up with WireGuard
Closing due to inactivity.
If this continues to be a problem, please reach out via our social media and/or forum c...
Christian McDonald
12:58 PM Bug #12399 (Feedback): WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
We have pulled in the upstream patches and bumped our version numbers. You should find a new package version availabl... Christian McDonald

11/02/2021

06:06 PM Feature #12502 (Resolved): Option to include Syslog-ng Configuration Library (scl)
Although the @scl.conf@ is present in @/usr/local/etc/scl.conf@ the associated referenced tree ( @@include 'scl/*/*.c... Marco Rodriguez
08:40 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
Aren Breur wrote in #note-5:
> I am running 2.6.0-DEVELOPMENT (amd64). a network with /15 also does NOT work. I mad...
Bill Meeks

11/01/2021

09:24 AM Bug #11098 (Pull Request Review): Backup Files and Directories plugin crashes firewall if /root specified as backup location
Jim Pingle
12:37 AM Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/142
Viktor Gurov
05:56 AM Feature #11531 (New): Show netmap compatible cards in IPS Mode note
Azamat Khakimyanov wrote in #note-7:
> Tested on 21.05.1
> There is a list of Netmap! Supported drivers:
> _WARNIN...
Viktor Gurov
05:24 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
I am running 2.6.0-DEVELOPMENT (amd64). a network with /15 also does NOT work. I made it to 2 /16 networks that work... Aren Breur

10/31/2021

10:52 AM Feature #10297 (Assigned): IPv6 user attributes
Tested on 21.05.1 and on 22.01-DEVELOPMENT (built on Sun Oct 31 05:21:32 UTC 2021)
There are 'IPv6 Address' (Framed-...
Azamat Khakimyanov
06:07 AM Bug #9922 (Resolved): haproxy_version does not use full path to haproxy, leads to errors when run during cron
Tested on 21.05.1 and on 22.01-DEVELOPMENT (built on Sun Oct 31 05:21:32 UTC 2021)
Both versions have full path '/...
Azamat Khakimyanov

10/30/2021

07:12 PM Bug #12258 (Pull Request Review): Copy key buttons only work in HTTPS mode
Updating status to Pull Request Review until changes are live. Kris Phillips
12:42 PM Bug #12258: Copy key buttons only work in HTTPS mode
PR has been merged, this should be on the next release so ticket can be closed Adam Cooper
07:08 PM Bug #11098: Backup Files and Directories plugin crashes firewall if /root specified as backup location
Attempting a backup produces a crash, but doesn't freeze the entire firewall or fill the drive thankfully. It also s... Kris Phillips
12:43 PM Bug #12251: Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
PR has been merged, should be in the next release so ticket can be closed Adam Cooper

10/29/2021

10:41 AM Bug #12399 (Confirmed): WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Christian McDonald

10/28/2021

09:13 PM Bug #12487: Netgate Firmware Upgrade 0.41.1 offers to upgrade FW version 01.00.00.11 to itself
FWIW, it looks like the bug is here, where check_update() returns true when current version == new version on non-610... Andrew Warren
11:08 AM Bug #12487: Netgate Firmware Upgrade 0.41.1 offers to upgrade FW version 01.00.00.11 to itself
And it is not showing the update button when it should (Netgate 7100 on 21.05.2 0.41_1) Chris Linstruth
07:50 AM Bug #12487: Netgate Firmware Upgrade 0.41.1 offers to upgrade FW version 01.00.00.11 to itself
This also appears to affect RCC-VE devices. An SG-4860 here.
Tested:
pkg v0.43 in 22.01
Steve Wheeler
03:30 PM Feature #12491 (New): squidguard: allow multiple regex
When adding a Target category, please allow multiple lines in the 'Regular Expression' list. The upstream squidguard... Jesse Norell
02:46 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset

> Ryan,
>
> Thanks for the continued investigation here. I'm tracking the kernel module development closely. Prelim...
Ryan Roosa
09:52 AM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Ryan Roosa wrote in #note-17:
> Just a quick update to let you know I've tested for this issue on the latest communi...
Christian McDonald
01:23 PM Bug #12490: pfSense(CE) completely freezes up with WireGuard
Hi Mark,
We haven't run into any deadlocks and/or crashes like this for quite some time. First thing I would check...
Christian McDonald
12:44 PM Bug #12490 (Rejected): pfSense(CE) completely freezes up with WireGuard
Hello everyone,
I encountered a strange issue with the Wireguard plugin installed (and in use).
I had a very diff...
Mark Zeller

10/27/2021

12:26 AM Bug #12487 (Closed): Netgate Firmware Upgrade 0.41.1 offers to upgrade FW version 01.00.00.11 to itself
See attached screenshot. When current firmware version == latest firmware version, should there be an "Upgrade and R... Andrew Warren

10/26/2021

06:41 AM Feature #11531 (Assigned): Show netmap compatible cards in IPS Mode note
Tested on 21.05.1
There is a list of Netmap! Supported drivers:
_WARNING: Inline Mode only works with NIC drivers w...
Azamat Khakimyanov
06:31 AM Feature #11533 (Resolved): add ena(4) to the list of INLINE mode (netmap) supported cards
Tested on 21.05.1
There is ena NIC in the list of Netmap! Supported drivers.
Marked this Feature request as resolved.
Azamat Khakimyanov

10/25/2021

12:31 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Just a quick update to let you know I've tested for this issue on the latest community release of OPNsense (21.7.3_3)... Ryan Roosa
10:02 AM Bug #11465 (Closed): Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
Jim Pingle
07:26 AM Feature #11386 (Resolved): Add WireGuard tunneled networks to vpnaddresses list
Tested on 21.05_p1 and on 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I see WireGuard tunnel network i...
Azamat Khakimyanov

10/24/2021

08:02 AM Bug #11682 (Resolved): Certificate Manager page do not show STunnel used certificates
Tested on 21.05.1 and 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I still see this Bug on 21.05.1 but ...
Azamat Khakimyanov
07:43 AM Bug #11683 (Resolved): Certificate Manager page doesn't show FreeRADIUS used certificates
Tested on 21.05.1 and 22.01-DEVELOPMENT (built on Sun Oct 24 05:22:55 UTC 2021)
I see FreeRADIUS certificate in 'IN ...
Azamat Khakimyanov
07:04 AM Bug #11687 (Resolved): Fix download URLs for SecuriteInfo.com
Tested on 21.05.1 and 22.01-DEVELOPMENT (Squid: 0.4.45_5).
I saw SecuriteInfo.com ID in /usr/local/pkg/squid_antivir...
Azamat Khakimyanov

10/23/2021

06:36 AM Bug #11465: Input validation does not prevent multiple conflicting WireGuard peers on a single tunnel from attempting to act as default route
This ticket can now be closed as the PR has been merged Adam Cooper

10/22/2021

03:04 PM Bug #12482 (Pull Request Review): Outdated doc links
Jim Pingle
08:59 AM Bug #12482: Outdated doc links
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/140
Viktor Gurov
07:06 AM Bug #12482 (Resolved): Outdated doc links
The HAProxy-devel package (based on haproxy 2.4.x) uses outdated doc links (haproxy 1.7):... Viktor Gurov
12:56 PM Bug #12142 (Resolved): XMLRPC replication target configuration
Tested on the:... Danilo Zrenjanin
09:42 AM Bug #12484 (Duplicate): Unable to remove intermediate CA
It's the same as the other linked issue. Adding that feature will solve this problem as the user could choose the oth... Jim Pingle
09:38 AM Bug #12484 (Duplicate): Unable to remove intermediate CA
Some client needs to remove intermediate "ISRG Root X1" CA to allow legacy clients to work,
otherwise they will get ...
Viktor Gurov

10/20/2021

08:30 AM Bug #12475 (Pull Request Review): OpenVPN Client Export does not show certificate without private key
Jim Pingle
01:42 AM Bug #12475: OpenVPN Client Export does not show certificate without private key
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/137
Viktor Gurov
08:22 AM Bug #12293 (Resolved): Resolve host via Reverse DNS looks shows IDN domains as punnycode
suricata 6.0.3_3 - works as expected Viktor Gurov
03:16 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1117
Viktor Gurov

10/19/2021

01:54 PM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
I did not try intermediate versions between 6.0.0_14 and 6.0.3_3, just installed the latest, so I can't say when this... Steve Y
09:57 AM Regression #12476: Suricata 6.0.3_3 Pass List ignores all single IPs
Edit: I have a 2100/21.05.1 with the latest Snort 4.1.4_3 and it doesn't have this issue. Steve Y
09:50 AM Regression #12476 (Resolved): Suricata 6.0.3_3 Pass List ignores all single IPs
After upgrading pfSense-pkg-suricata from 6.0.0_14 to 6.0.3_3 all Pass List entries for single IPs are ignored and no... Steve Y
07:24 AM Bug #12475 (Resolved): OpenVPN Client Export does not show certificate without private key
When using the page https://<server>/vpn_openvpn_export.php to export an openvpn client config package only certifica... Denis Grilli
05:21 AM Feature #12447: Acme add dnsapi dns_cpanel.sh
How can I upgrade? Akos Tomaschik

10/18/2021

04:46 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
FWIW, just wanted to share updates I've made to my bandaid script. I found that 'head -c' usage on '/dev/urandom' lik... Ryan Roosa
11:16 AM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Christian McDonald wrote in #note-13:
> Thank you for the detailed report here. This is immensely helpful. I will co...
Ryan Roosa
09:10 AM Feature #11163 (Pull Request Review): Preferred Chain option
Jim Pingle
07:47 AM Feature #12447 (Rejected): Acme add dnsapi dns_cpanel.sh
New providers all get added when we update ACME from upstream, we don't add them manually or separately like this, so... Jim Pingle
05:48 AM Todo #12456 (Resolved): Remove zabbix 5.2 packages
Max Leighton wrote in #note-3:
> I checked in
>
> 2.6.0-DEVELOPMENT (amd64)
> built on Sat Oct 16 05:24:35 UTC...
Renato Botelho

10/17/2021

12:30 AM Feature #12462: Telegraf: Add "devfs" to ignore_fs
https://github.com/pfsense/FreeBSD-ports/pull/1114 Viktor Gurov

10/16/2021

10:01 PM Bug #12381 (Rejected): mOTP with RADIUS drops the VPN connection after 60 minutes
Jim Pingle wrote in #note-1:
> I don't think that's FreeRADIUS, but OpenVPN. IIRC OpenVPN defaults to reconnecting e...
Kris Phillips
07:35 PM Feature #12465 (New): Add forwardfor advanced usecases
By default haproxy creates new x-forward-for header and do not touch existing one. This could be found in documentati... DRago_Angel [InV@DER]
11:16 AM Bug #11887 (Resolved): Squid service starts twice by /etc/rc.start_packages
Tested in:
22.01-DEVELOPMENT (amd64)
built on Wed Oct 13 05:25:11 UTC 2021
FreeBSD 12.2-STABLE
Squid: 0.4.45_5 ...
Max Leighton
10:36 AM Todo #12456: Remove zabbix 5.2 packages
I checked in
2.6.0-DEVELOPMENT (amd64)
built on Sat Oct 16 05:24:35 UTC 2021
FreeBSD 12.2-STABLE
And see tha...
Max Leighton

10/15/2021

09:37 PM Bug #11592: Node exporter can not read system statistics
The issue is that in "node_collector v1.0.0":https://github.com/prometheus/node_exporter/blob/master/CHANGELOG.md#100... Daniel Kimsey
09:19 PM Feature #11163: Preferred Chain option
I submitted a PR to implement this option as I found one my clients needed it for a particular cert I was issuing.
P...
Daniel Kimsey
08:56 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Ryan Roosa wrote in #note-12:
> Samuel Hanna wrote in #note-11:
> > The problem still persist on wireguard 0.1.5_1....
Samuel Hanna
08:55 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Thank you for the detailed report here. This is immensely helpful. I will continue to poke at this next week and repo... Christian McDonald
05:18 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
Samuel Hanna wrote in #note-11:
> The problem still persist on wireguard 0.1.5_1.
> even after changing the keys and ...
Ryan Roosa
06:44 PM Feature #12462 (Pull Request Review): Telegraf: Add "devfs" to ignore_fs
The Netgate XG-1537 has the following disk paths at 100% utilization:
* /dev
* /var/dhcpd/dev
* /var/unbound/dev
...
Offstage Roller

10/14/2021

10:16 AM Todo #12456 (Feedback): Remove zabbix 5.2 packages
Done Renato Botelho
10:15 AM Todo #12456 (Resolved): Remove zabbix 5.2 packages
zabbix 5.2 were removed from FreeBSD ports because they are unsupported by upstream. Remove pfSense packages as well Renato Botelho
09:55 AM Bug #10431 (Resolved): pfBlockerNG Cron Job wrong - Clear IP / DNSBL Statistics
no such issue with pfBlockerNG-devel 3.1.0 (fixed):... Viktor Gurov
09:48 AM Feature #9798: add ipv4 and ipv6 dnscrypt-resolvers feeds
actual link:
https://download.dnscrypt.net/dnscrypt-resolvers/json/public-resolvers.json
Viktor Gurov
09:42 AM Bug #11817 (Closed): Enabling Firewall / pfBlockerNG / DNSBL / IPv6 DNSBL blocks radvd from starting
Viktor Gurov

10/13/2021

02:47 PM Bug #12251: Wireguard 0.1.5 - ignores "KeepAlive" parameter if empty (instead of disabling)
→ luckman212 wrote in #note-3:
> Hmm, seems like 86400 is not a valid value after all. It got silently accepted but ...
Adam Cooper
01:34 PM Bug #12258: Copy key buttons only work in HTTPS mode
Created PR 150 to resolve this.
Tested on local dev instance with HTTP only access and it fallsback, does a consol...
Adam Cooper
09:06 AM Bug #12443: DNSBL Category ```Enable All``` button not working
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1113
Viktor Gurov
03:11 AM Feature #12447 (Rejected): Acme add dnsapi dns_cpanel.sh
Hello,
Please add the following feature to the acme package:
https://github.com/acmesh-official/acme.sh/blob/mast...
Akos Tomaschik

10/11/2021

12:39 PM Bug #12444: ntopng throws errors when viewing single host
https://redmine.pfsense.org/issues/11530 - same/same? Jordan G
08:21 AM Bug #12126: freeradius3 0.15.7_31
Ok thanks for the info.
Any chance to have freeradius3 package update for 2.5.2 release?
Alexis Pellicier
08:14 AM Bug #12126: freeradius3 0.15.7_31
This looks to be a bug in Freeradius 3.0.22. See the 3.0.23 release notes:
https://github.com/FreeRADIUS/freeradius-...
Steve Wheeler
05:17 AM Feature #11310 (Resolved): Adding a widget to apcupsd plug-in
Renato Botelho

10/09/2021

09:08 PM Bug #12444 (Closed): ntopng throws errors when viewing single host
Users have reports that when navigating to Hosts>Hosts and clicking to view a single host within the ntopNG settings ... Max Leighton
07:27 PM Bug #11886 (Resolved): WireGuard: PHP error in vpn_wg_peers_edit.php
No longer able to reproduce this in 22.01 of pfSense Plus. Closing as Resolved. Kris Phillips
07:19 PM Bug #12101 (Assigned): ArpWatch Suppression Mac for "flip-flop" not suppressing
Moving status back to Assigned as this hasn't been confirmed as fixed in updated package. Kris Phillips
04:34 PM Bug #12399: WireGuard v0.1.5 - Tunnel Will Never Handshake Again After WAN Reset
The problem still persist on wireguard 0.1.5_1.
even after changing the keys and ports nothing seems to help.
wish ...
Samuel Hanna
01:41 PM Bug #4615: /var/logs/c-icap/server.log & access.log growing without being rotated
Hi,
so I took a look: /var/log/c-icap/access.log - 272MB
the mentioned bugfix was meant for squid, I think?
...
Stephan Berger
11:04 AM Bug #12443 (Resolved): DNSBL Category ```Enable All``` button not working
https://forum.netgate.com/topic/167094/dnsbl-catagory-bug:
"I dunno if i'm doing something wrong but under Blacklist...
Viktor Gurov
09:58 AM Bug #12153 (Resolved): Incorrect Outgoing Network Interface on clean install
Viktor Gurov
07:52 AM Bug #12153: Incorrect Outgoing Network Interface on clean install
on clean install of 0.4.45_5 the default outgoing network interface shows as "Default (auto)" upon first visit to Ser... Jordan G
07:35 AM Feature #11310: Adding a widget to apcupsd plug-in
Dashboard widget for APCUPSD is available after installing and configuring package. Status, line voltage, load, batte... Jordan G
05:50 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
Viktor Gurov wrote in #note-6:
> You can try to apply the attached patch
No need to add this if version of haproxy w...
DRago_Angel [InV@DER]
05:48 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
DRago_Angel [InV@DER] wrote in #note-3:
> Hi, this is serious CVE, and still no updates? Even it possible to workaro...
Viktor Gurov
03:25 AM Feature #11972 (Resolved): Arpwatch - Add support for Telegram notifications
there is no
Alhusein Zawi wrote in #note-4:
> there is no option to add Telegram in Arpwatch page.
>
> Tested...
Viktor Gurov

10/07/2021

09:42 AM Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
Viktor, thanks for improving the error message. Two comments:
1. putting the full path might be even better. I assu...
Sean McBride
12:41 AM Bug #12423: Dashboard shows "SQLite database missing, Force Reload DNSBL to recover!"
fix:
https://github.com/pfsense/FreeBSD-ports/pull/1112
Viktor Gurov
07:29 AM Todo #12354 (Pull Request Review): Update haproxy-devel to mitigate CVE-2021-40346
Jim Pingle
02:40 AM Todo #12354: Update haproxy-devel to mitigate CVE-2021-40346
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/136 Viktor Gurov
07:18 AM Bug #12420 (Pull Request Review): rc file is not deleted
Jim Pingle
01:41 AM Bug #12420: rc file is not deleted
fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/135
Viktor Gurov
04:19 AM Bug #1620: Can't use transparent proxy when using bridge.
transparent mode on bridge works fine on pfSense 2.6.0.a.20211006.2213 with net.link.bridge.pfil_bridge=1 and net.lin... Viktor Gurov
 

Also available in: Atom