Activity
From 02/20/2022 to 03/21/2022
03/21/2022
-
11:59 PM Feature #10809 (Resolved): IDS/IPS - Notifications when new rule categories are released
-
05:26 PM Feature #10809: IDS/IPS - Notifications when new rule categories are released
- Chiming in to note all is good, notifications are sent when new rule categories appear.
Can be closed. -
04:55 PM Feature #12963: Run nmap scans in the background
- Phil Wardt wrote in #note-3:
> Phil Wardt wrote in #note-2:
> > Add a working test patch that can be copied into Sy... -
07:51 AM Feature #12963: Run nmap scans in the background
- Phil Wardt wrote in #note-2:
> Add a working test patch that can be copied into System Patches package:
Added opt... -
03:35 PM Bug #12969 (Duplicate): Status_Traffic_Totals GUI showing graphical data for the wrong month
- In the GUI for version 2.3.2_2, the Interactive Graph and Date Summary are both showing the current data under the wr...
-
08:39 AM Bug #12965: FRR BFD peer configuration is handled incorrectly in some cases
- fixes:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/199
03/20/2022
-
11:56 PM Feature #12718 (Resolved): add igc(4) to the list of INLINE mode (iflib/netmap) supported cards
-
04:04 PM Bug #12965: FRR BFD peer configuration is handled incorrectly in some cases
- To summarize:
* load the saved @Profile@ value on BFD peer edit
* allow the selection of VIPs for @Local Source Add... -
03:58 PM Bug #12965 (Pull Request Review): FRR BFD peer configuration is handled incorrectly in some cases
- Saving the following BFD peer configuration results in no configuration change (checked by looking at @FRR / Status /...
-
08:48 AM Feature #12963: Run nmap scans in the background
- Add a working test patch that can be copied into System Patches package:
-
08:23 AM Feature #12963: Run nmap scans in the background
- Github commit, tested with screen shots:
https://github.com/pfsense/FreeBSD-ports/pull/1148
Note: it properly sup... -
08:19 AM Feature #12963 (Feedback): Run nmap scans in the background
- NMap package cannot actually run from gui because of nginx timeout
This patch adds the following features:
- run ... -
06:14 AM Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- Also see:
https://old.reddit.com/r/PFSENSE/comments/tc8zsx/wireguard_service_not_starting_on_system/
Can also con...
03/19/2022
-
03:21 PM Bug #12917: LoopiaAPI changed
- Jim Pingle wrote in #note-2:
> Viktor Gurov wrote in #note-1:
> > acme.sh updated to v3.0.2 in #12886
> >
> > Lo... -
01:37 PM Feature #12718: add igc(4) to the list of INLINE mode (iflib/netmap) supported cards
- was able to start suricata inline mode on igc interface (6100) running 22.01 v6.0.4_1
-
09:11 AM Bug #12951: FRR cannot remove IPv6 routes
- https://github.com/FRRouting/frr/issues/10827
-
05:32 AM Bug #12951: FRR cannot remove IPv6 routes
- 2022/03/19 02:16:50 BGP: can't connect to 2604:8800:60:240::100 fd 34 : Permission denied
2022/03/19 02:16:50 BGP: c... -
06:31 AM Bug #12777 (Resolved): STunnel writes config.xml on each start
- Tested with Stunnel 5.50_10
It writes to config.xml only after config changes. Ticket resoloved.
03/18/2022
-
12:38 AM Bug #12956: suricata fails to use pcre in SID management (e.g. dropsid.conf)
- Indeed, I've found the commit that caused the regression:
https://github.com/pfsense/FreeBSD-ports/commit/9d8801b498... -
12:31 AM Bug #12956 (Resolved): suricata fails to use pcre in SID management (e.g. dropsid.conf)
- In suricata/suricata.inc, under "Test the SID token for the PCRE: keyword", the match for the regular expression will...
03/17/2022
-
08:01 AM Bug #12952 (Closed): After update to v. 22.01 DNS Resolver Custom Options for bypassing PfBlockerNG not working
- I cannot reproduce any issues with views in the DNS resolver as described. It's possible there is a local issue in pf...
-
03:45 AM Bug #12952 (Closed): After update to v. 22.01 DNS Resolver Custom Options for bypassing PfBlockerNG not working
Immediately after updating PfSense+ on Netgate 7100 from v. 21.05.2 to 22.01 the bypass setting for PfBlockerNG sto...-
12:52 AM Bug #12951 (Feedback): FRR cannot remove IPv6 routes
pfsense 2.6 system
frr log show:
2022/03/16 21:46:42 ZEBRA: [EC 100663303] kernel_rtm: 2606:2800:e004::/48: r...
03/16/2022
-
11:38 AM Bug #12948 (Resolved): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
- When mixing AE ciphers in a P2 with AEAD ciphers (e.g. AES with AES128-GCM), the wizard will generate a script with t...
03/14/2022
-
08:55 AM Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- I have the same issue. One side of the Wireguard VPN is disabled after reboot. Both sides of the VPN appear to have t...
03/13/2022
-
08:17 PM Feature #9833: ACME: add ability to use custom ACME server
- +1 for this as well.
Just started looking into sorting out the self-signed cert and thought there would be a better ... -
11:46 AM Bug #12912 (Resolved): ACME is failing to fully issue a new certificate
- This works again on 0.7_4.
03/12/2022
-
02:55 AM Bug #12898 (Resolved): Update HAProxy Backend to Latest LTS
- Installed HAproxy on the:...
03/11/2022
-
06:51 PM Bug #12933 (Resolved): Vulnerability in ClamAV Engine Used by Squid
- https://www.tenable.com/plugins/nessus/156698
pfSense CE 2.6 and pfSense Plus 22.01 use ClamAV 0.104.1,1, which is... -
11:42 AM Bug #12924: DNS Resolver WireGuard ACL Inconsistency
- Christian McDonald wrote in #note-2:
> Hi Kevin,
>
> I am having a hard time replicating this based on your initi... -
09:20 AM Bug #12924: DNS Resolver WireGuard ACL Inconsistency
- Hi Kevin,
I am having a hard time replicating this based on your initial issue description. Can you please outline... -
11:08 AM Feature #12932 (New): pfblockerng per user whitelist
- Have the ability to not have DNS blocking applied to certain IPs. Right now this can be written into Unbound using cu...
03/10/2022
-
03:42 PM Bug #12623: acme.sh package | DNS-ISPConfig settings
- This one fixes the issue: https://github.com/acmesh-official/acme.sh/commit/01ace11293f4cf27f8e761114f48148bbcbad063
-
03:05 PM Bug #12623: acme.sh package | DNS-ISPConfig settings
- Leaving the Allow Insecure blank, results in a different error:...
-
02:37 PM Bug #12623: acme.sh package | DNS-ISPConfig settings
- I should add, I tested the script and it is placing the correct variables into the environment and the script does se...
-
02:32 PM Bug #12623 (New): acme.sh package | DNS-ISPConfig settings
- The upstream code still has a problem. If you leave "Allow Insecure" blank now it should at least get past that part,...
-
06:35 AM Bug #12623: acme.sh package | DNS-ISPConfig settings
- I'm on 0.7_4 now and still see the exact same error - so no, still not fixed
-
06:45 AM Bug #12917: LoopiaAPI changed
- Viktor Gurov wrote in #note-1:
> acme.sh updated to v3.0.2 in #12886
>
> Looks like we need to update acme.sh mon... -
02:07 AM Bug #12917: LoopiaAPI changed
- acme.sh updated to v3.0.2 in #12886
Looks like we need to update acme.sh monthly/quarterly. -
06:10 AM Bug #12928 (Not a Bug): FRR When using vtysh to save the configuration, any changes to the webgui are invalid
- This is correct behavior.
The "Raw Config" tab is used for custom configuration:
https://docs.netgate.com/pfsense... -
05:45 AM Bug #12928 (Not a Bug): FRR When using vtysh to save the configuration, any changes to the webgui are invalid
- about FRR,When using vtysh to save the configuration, any changes to the webgui are invalid.
Because there are man...
03/09/2022
-
12:38 PM Bug #12869 (Feedback): Bind DNS Package AAAA filtering Broken on new ZFS Installs
- Merged to devel and 22.01/2.6
-
07:34 AM Bug #12869 (Pull Request Review): Bind DNS Package AAAA filtering Broken on new ZFS Installs
-
07:10 AM Bug #12869 (New): Bind DNS Package AAAA filtering Broken on new ZFS Installs
- regression: https://forum.netgate.com/topic/170558/bind-package-9-16_12-reads-from-cf-named-but-changes-in-the-gui-ar...
-
10:59 AM Bug #12924 (New): DNS Resolver WireGuard ACL Inconsistency
- Initially, I had two pfsense nodes connected via the WireGuard package. My tunnel network was 10.0.3.0/30 for p2p. I ...
-
10:57 AM Bug #12898: Update HAProxy Backend to Latest LTS
- FreeBSD-ports merge:
https://github.com/pfsense/FreeBSD-ports/commit/da9ed529f30212fd826aebc3b7e896fce7a15217 -
08:05 AM Bug #12898 (Feedback): Update HAProxy Backend to Latest LTS
- Applied in changeset pfsense:commit:07fe3d3d60a61621171fbc0a1a5e42c1462fb5ed.
03/07/2022
-
03:51 PM Bug #12907: PIMD: Nonexistent interfaces should be hidden/disabled in pimd.conf before bringing up the service
- I faced an issue similar to this with the Snort and Suricata packages some time back. I handled it there by always ch...
-
10:02 AM Bug #12907: PIMD: Nonexistent interfaces should be hidden/disabled in pimd.conf before bringing up the service
- The base system has no way to scan/inform packages about an interface being removed, it's up to the admin to maintain...
-
09:30 AM Bug #12907: PIMD: Nonexistent interfaces should be hidden/disabled in pimd.conf before bringing up the service
- Jim Pingle wrote in #note-1:
> PIMD has options to not behave that way.
>
> Sounds like what you really want is t... -
08:26 AM Bug #12907 (Feedback): PIMD: Nonexistent interfaces should be hidden/disabled in pimd.conf before bringing up the service
- PIMD has options to not behave that way.
Sounds like what you really want is to have PIMD set to "Bind to None" an... -
02:29 PM Feature #12918 (New): pfBlockerNG-devel changes from xmlrpc sync do not take effect immediately
- When pfBlockerNG-devel syncs its settings (e.g. custom IPv4 list) to a secondary firewall, the settings on the second...
-
01:54 PM Bug #12917 (Resolved): LoopiaAPI changed
- Any users using LoopiaAPI can't issue or renew certificates. This has been fixed upstream at the below link.
https... -
01:34 PM Bug #12916 (New): pfBlockerNG-devel cron job does not trigger xmlrpc sync
- Tested on pfSense 2.6.0 and pfBlockerNG-devel 3.1.0_1
pfBlockerNG-devel option "Enable Sync" with "Sync to host(s) d... -
11:01 AM Bug #12912 (Feedback): ACME is failing to fully issue a new certificate
- Fix merged, will be in ACME pkg v 0.7_4.
In the meantime, check the debug option on a certificate and it should wo... -
10:44 AM Bug #12912 (Resolved): ACME is failing to fully issue a new certificate
- Creating a new certificate in ACME is not working properly. The GUI output only shows that it generates the private k...
-
10:58 AM Bug #12670: ACME package writes credentials to system log
- If we try this again as a debug option we must test this better, at a minimum:
* Creating a new account key should... -
10:44 AM Bug #12670 (New): ACME package writes credentials to system log
- The debug option added broke several things. It broke the ability to create account keys, and it is breaking new ACME...
-
08:28 AM Feature #12909 (New): Convert Suricata GeoIP Lookup feature on ALERTS tab to use local GeoIP2 database
- Convert the GeoIP lookup feature available on the ALERTS tab in the Suricata package to use the local GeoIP2 database...
-
07:35 AM Bug #12898 (Pull Request Review): Update HAProxy Backend to Latest LTS
- They are still putting out 2.2.x releases and it's a smaller and therefore safer jump. If that is OK then after a whi...
03/06/2022
-
05:41 PM Feature #9833: ACME: add ability to use custom ACME server
- Manny Tew wrote in #note-5:
> + 1 for this as well. This is critical for proper security in a homelab in 2021+ Inval... -
05:30 PM Bug #12907 (Feedback): PIMD: Nonexistent interfaces should be hidden/disabled in pimd.conf before bringing up the service
- At this point, pimd is unaware of nonexistent interfaces. This can lead to a kernel panic.
(My case: I removed newly... -
04:31 AM Feature #11827: Please include acme deploy folder/scripts
- +1 for this as well. Note, the certs seem to be stored in a non-standard acme.sh way under /conf/acme, so more work m...
-
01:28 AM Bug #12898: Update HAProxy Backend to Latest LTS
- Kris Phillips wrote in #note-2:
> Viktor Gurov wrote in #note-1:
> > HAProxy-devel is already 2.4 (2026-Q2 (LTS))
...
03/05/2022
-
11:47 PM Bug #12844 (Resolved): Invalid title link in the apcupsd package dashboard widget
-
02:47 PM Bug #12844: Invalid title link in the apcupsd package dashboard widget
- Patch works to correct Apcupsd widget link to status page - applied to 22.01 and 22.05.a.20220305.0600
-
08:35 PM Bug #11530: ntopng 4.2 needs to be updated to 4.3, Bug when accessing a host for details
- Sish Kitane wrote in #note-4:
> I can reproduce this in VMs for both 2.5.2 and 2.6. I don't think the new 5.0 packag... -
08:27 PM Bug #12898: Update HAProxy Backend to Latest LTS
- Viktor Gurov wrote in #note-1:
> HAProxy-devel is already 2.4 (2026-Q2 (LTS))
>
> HAProxy-stable update to 2.2 ve... -
01:10 AM Bug #12898: Update HAProxy Backend to Latest LTS
- HAProxy-devel is already 2.4 (2026-Q2 (LTS))
HAProxy-stable update to 2.2 version (2025-Q2 (LTS)):
https://gitlab...
03/04/2022
-
01:22 PM Bug #12899 (Resolved): Suricata doesn't honor Pass List
- It sometimes blocks the hosts defined in the selected Pass List. No matter whether you used IP subnet or Alias under ...
-
01:19 PM Bug #12898 (Resolved): Update HAProxy Backend to Latest LTS
- The version of HAProxy in stable is very old and due to be unsupported at the end of the year. We should really move...
-
12:20 PM Todo #12865: RRD Summary improvements
- cherry-picked to 22.01/2.6
-
07:51 AM Todo #12865 (Feedback): RRD Summary improvements
- Merged to 2.7/22.05:
https://github.com/pfsense/FreeBSD-ports/commit/fb702643e590f7545cbbaf5bd4e5060f9ab293cc -
12:20 PM Bug #12869: Bind DNS Package AAAA filtering Broken on new ZFS Installs
- cherry-picked to 22.01/2.6
-
08:04 AM Bug #12869 (Feedback): Bind DNS Package AAAA filtering Broken on new ZFS Installs
- Merged to 2.7/22.05:
https://github.com/pfsense/FreeBSD-ports/commit/a6943737bb6b2df2dcc050bd0db5ebf127be2df4
03/03/2022
-
11:16 PM Bug #12706: pfBlockerNG and unbound does not work after switching /var to RAM disk
- This bug causes a delay in boot processing when the ramdisk option is enabled. If the option is disabled, no delay i...
-
02:29 PM Feature #12882: Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- >Thanks for the contribution! Its appreciated!
Sure thing! This solves a big problem for me :-)
Your revisions ... -
02:03 PM Feature #12882: Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- Great Thanks.
I have done some limited testing and it seems to be ok.
I made some minor formatting changes in ... -
07:46 AM Feature #12882: Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- Ok, all done! https://github.com/pfsense/FreeBSD-ports/pull/1146
-
09:01 AM Bug #12891: Trailing space in Acme Account Keys "name" breaks UI functions
- Commit: https://github.com/pfsense/FreeBSD-ports/commit/29bab84437fcdde206f205610d341302093fa4f3
Package update is... -
08:47 AM Bug #12891 (Feedback): Trailing space in Acme Account Keys "name" breaks UI functions
- Fix merged.
-
08:39 AM Bug #12891 (Pull Request Review): Trailing space in Acme Account Keys "name" breaks UI functions
- This approach is a more comprehensive fix: https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/193
-
08:25 AM Bug #12891 (In Progress): Trailing space in Acme Account Keys "name" breaks UI functions
-
12:50 AM Bug #12891: Trailing space in Acme Account Keys "name" breaks UI functions
- fix:
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/192 -
12:53 AM Feature #11531 (Feedback): Show netmap compatible cards in IPS Mode note
- Merged
03/02/2022
-
04:56 PM Bug #12891 (Resolved): Trailing space in Acme Account Keys "name" breaks UI functions
- If any ACME account key is entered into the UI with a trailing space in the name, the pfSense UI becomes unable to ha...
-
02:05 PM Bug #10656 (Closed): Acme letsencrypt doesn't change private key type
-
02:05 PM Feature #11948 (Closed): ACME: Support specifying non-default port for nsupdate DNS validation method
-
02:03 PM Feature #11879 (Feedback): Add support for SSL.com ACME server
- The latest version of the ACME package now includes the new CAs.
-
02:02 PM Bug #12623 (Feedback): acme.sh package | DNS-ISPConfig settings
- The fix for this is now in the latest ACME package. Please update and test it again to see if it works.
-
02:01 PM Todo #12886 (Closed): Update acme.sh from upstream
- No problems I can find so far. I picked it back to 22.01/2.6.0 for wider testing. Can tackle new issues as they come.
-
08:37 AM Feature #12882: Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- Sure thing! I'll close the other pull request, thanks!
-
06:10 AM Feature #12889 (New): FRR GUI add set ipv6 next-hop global
- i need setup this. but frr webgui cant add
https://team-cymru.com/community-services/bogon-reference/bogon-refer...
03/01/2022
-
08:56 PM Feature #12882: Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- Thanks for the PR!
There isn't much development in "pfBlockerNG" as everything is taking place in "pfBlockerNG-devel... -
04:19 PM Todo #12886 (Feedback): Update acme.sh from upstream
- Merged to devel and plus-devel for testing in snapshots. If it's OK there, can pick back to 22.01/2.6.0
-
09:58 AM Todo #12886 (Closed): Update acme.sh from upstream
- It's been a while since the last upstream sync of acme.sh code and bringing in new providers. Need to sync up the for...
-
12:45 PM Bug #12742 (Feedback): freeRADIUS virtual-server-default: modules dailycounter, monthlycounter, noresetcounter, expire_on_login in authorize section prevent virtual server from loading
- Thank You!
Merged:
https://github.com/pfsense/FreeBSD-ports/commit/4497706f404be238cdfc41dacc00678ab329e575
http... -
07:20 AM Bug #12742: freeRADIUS virtual-server-default: modules dailycounter, monthlycounter, noresetcounter, expire_on_login in authorize section prevent virtual server from loading
- For future reference:
https://github.com/FreeRADIUS/freeradius-server/blob/master/doc/antora/modules/raddb/pages/m... -
02:42 AM Bug #12844 (Feedback): Invalid title link in the apcupsd package dashboard widget
- Merged:
https://github.com/pfsense/FreeBSD-ports/commit/086e17ae29cf61d1c09e88167ae73df7877fcae4
02/28/2022
-
01:53 PM Feature #12882 (Resolved): Add the option to specify CURLOPT_INTERFACE in pfBlockerNG IPv4/IPv6 lists
- Sometimes it is desirable to tell cURL to use a specific interface when downloading IPv4/IPv6 pass/block lists. For e...
02/27/2022
-
10:47 PM Bug #11530: ntopng 4.2 needs to be updated to 4.3, Bug when accessing a host for details
- I can reproduce this in VMs for both 2.5.2 and 2.6. I don't think the new 5.0 package for ntopng solved this and I th...
02/25/2022
-
12:59 PM Bug #12802 (Resolved): OpenVPN client imported using Client Import works until first time editing and saving settings (SHA1 replaced with SHA256)
- Tested on the:...
-
10:49 AM Feature #12246 (Closed): Load a file into patch textarea
- Works well, closing.
-
07:43 AM Bug #12869 (Pull Request Review): Bind DNS Package AAAA filtering Broken on new ZFS Installs
-
05:52 AM Bug #12869: Bind DNS Package AAAA filtering Broken on new ZFS Installs
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/188
02/24/2022
-
10:58 AM Bug #12869: Bind DNS Package AAAA filtering Broken on new ZFS Installs
- Thread that discusses this is here
https://forum.netgate.com/topic/169742/bind-dns-package-aaaa-filtering-problem
-
10:06 AM Bug #12869 (Resolved): Bind DNS Package AAAA filtering Broken on new ZFS Installs
- Reference this older bug for some background (#10413)
This breaks again in newer installs with zfs file systems du... -
07:34 AM Todo #12865 (Pull Request Review): RRD Summary improvements
-
03:14 AM Todo #12865: RRD Summary improvements
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/187
-
03:01 AM Todo #12865 (Resolved): RRD Summary improvements
- 1) Wrong period, mirror date displayed:...
-
07:18 AM Feature #12860: add mmc-utils package to all images
- We already build @mmc-utils@ for Plus and it can be installed manually from the CLI. Trying to build a GUI around it ...
02/23/2022
-
05:35 PM Feature #12860: add mmc-utils package to all images
- This would be helpful/useful now that ZFS is the new default, and/or for folks who don't realize some packages are "r...
-
04:44 PM Feature #12860 (New): add mmc-utils package to all images
- Both Netgate & 3rd party hardware integrators are increasingly using eMMC components.
SATA (& historically SCSI) d... -
11:51 AM Feature #12658: Adding prometheus metrics to darkstat
- I see that the package made it to FreeBSD version 13:
https://freebsd.pkgs.org/13/freebsd-amd64/darkstat-3.0.721.p... -
07:11 AM Feature #12859 (Resolved): Add Zabbix 6.0 LTS (agent and proxy) packages
- New LTS release from zabbix. Please add this new version.
https://www.zabbix.com/rn/rn6.0.0
Zabbix 3.0 is out of ...
02/22/2022
-
07:46 AM Bug #12844 (Pull Request Review): Invalid title link in the apcupsd package dashboard widget
02/21/2022
-
10:40 AM Bug #12845: softflowd wrong vlan tag
- similar to #9486
-
10:13 AM Bug #12845 (New): softflowd wrong vlan tag
- When I try to send information about the vlan through IPFIX or Netflow v9, the vlan tag is incorrectly entered in the...
-
03:03 AM Bug #12623: acme.sh package | DNS-ISPConfig settings
- Still an issue after updating to Acme 0.6.10_1
-
12:11 AM Bug #12844: Invalid title link in the apcupsd package dashboard widget
- fix:
https://github.com/pfsense/FreeBSD-ports/pull/1110 -
12:11 AM Bug #12844 (Resolved): Invalid title link in the apcupsd package dashboard widget
- clicking on the widget title results in an error:
https://192.168.1.1/apcupsd.widget.php - 404 not found
Also available in: Atom