Project

General

Profile

Activity

From 12/28/2022 to 01/26/2023

01/26/2023

11:59 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
PR merged. Jim Pingle
09:01 AM Bug #13910: Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
Pull request 1221 has been submitted to correct this issue: https://github.com/pfsense/FreeBSD-ports/pull/1221.
Th...
Bill Meeks
08:41 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
There is a typo on line 253 of /usr/local/pkg/snort/snort_generate_conf. This can result in the creation of an invali... Bill Meeks

01/25/2023

02:39 PM Bug #13690 (Closed): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
The updated description and link appear as expected in the package list now.
Jim Pingle
01:01 PM Bug #13690 (Feedback): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #12948 (Feedback): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:18 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
The code added here was incorrect, see #13368 and #13877 Jim Pingle
09:17 AM Bug #12948 (New): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Jim Pingle
01:01 PM Bug #13877 (Feedback): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:47 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Tested on Windows 10 and Windows 11 against a VPN with and without a P2 hash selected and it worked as expected in ev... Jim Pingle
09:15 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
After testing, the value of @AuthenticationTransformConstants@ should be set to match @CipherTransformConstants@ when... Jim Pingle
01:01 PM Bug #13897 (Feedback): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #13368 (Feedback): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:13 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
After testing, the value of @AuthenticationTransformConstants@ should apparently be set to match @CipherTransformCons... Jim Pingle
01:01 PM Bug #12705 (Feedback): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:19 AM Bug #12705 (Confirmed): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Jim Pingle
01:00 PM Bug #13878 (Feedback): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:55 AM Todo #13906 (Resolved): Update tailscale from 1.34.2 to 1.36.0
https://tailscale.com/changelog/ Christian McDonald
09:13 AM Feature #13474: Don't set ListenPort in wireguard
Good point. Will add this soon Christian McDonald
09:13 AM Feature #13905 (Bogus): Introduce GUI knob for controlling ```--snat-subnet-routes``` tailscaled option
https://github.com/pfsense/FreeBSD-ports/commit/dfb9dcf53bd8e687cda708701f07217ec5e7f1ef Christian McDonald
02:14 AM Bug #13874 (Confirmed): pfBlocker -devel hanging on cron jobs
Yes, the issue is present on the 3.1.0_19 version. Danilo Zrenjanin

01/24/2023

02:01 PM Bug #13898 (New): Issues saving pfBlocker Sync Targets
I have the hosts visible in the image 1.png in the target list to sync. I click on "Save XMLRPC sync settings" and ge... Tom Huerlimann
09:59 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
This appears to have been broken by the change in #12948, the fix from that issue forced the P1 hash to 'None' when t... Jim Pingle
09:28 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Moving the unrelated split tunnel part to a new issue (#13897). Jim Pingle
09:30 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
When exporting an IPsec profile for Windows which includes split tunneling, if the local P2 network is set to @0.0.0.... Jim Pingle

01/23/2023

11:00 AM Regression #13892 (Feedback): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
Commit pushed and merged/picked as needed, will be in builds soon.
https://github.com/pfsense/FreeBSD-ports/commit...
Jim Pingle
10:03 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
When visiting status_monitoring.php, the user may get a PHP error if they have no valid OpenVPN server entries.
<p...
Jim Pingle

01/22/2023

06:43 PM Bug #13874: pfBlocker -devel hanging on cron jobs
I am seeing this on 3.1.0_19 Michael Kellogg

01/21/2023

08:10 PM Bug #13432 (Incomplete): ups driver will not start
I'm still unable to reproduce this problem with a fresh install of 23.01 and the latest NUT package. At this point I... Kris Phillips
07:59 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
No longer able to recreate this. Not sure what caused it before, but I was testing on a fresh install of 23.01 and o... Kris Phillips
07:29 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
They are there on internal 23.01 RC snaps.... Jim Pingle
06:44 PM Todo #13857: Update bundled installer in OpenVPN Export Utility
Checked on 22.05 and it appears these were merged properly. However, looking at the repos for 23.01, which is on a n... Kris Phillips
06:37 PM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Redmine 13368 may be related, as it's in a similar vein: https://redmine.pfsense.org/issues/13368
Kris Phillips
06:33 PM Bug #13886: NUT Server Package
# Installed NUT package on 23.01
# Setup usbhid with a simple UPS config and enabled the service with Local USB
# S...
Kris Phillips
12:29 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Based on a project spanning multiple clients / locations / firewalls, I can certify that this is still true in CE 2.6... Jonathan Edman
12:28 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Hannes Palmquist wrote in #note-11:
> +1
>
> Agent 6.2 install does not work, same error.
Based on a project s...
Jonathan Edman
10:46 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-7:
> It is still here, unfortunately.
I mean the issue was occurred after I update th...
Lev Prokofev
10:45 AM Bug #13874: pfBlocker -devel hanging on cron jobs
It is still here, unfortunately. Lev Prokofev
10:30 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-5:
> I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0...
Jim Pingle
05:03 AM Bug #13874: pfBlocker -devel hanging on cron jobs
I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0_16 Lev Prokofev
03:15 AM Bug #13328: Wireguard Site-to-Site broken after upgrade to 22.05
Still the same issue
PPPOE connection might be the problem.
I found more poeple with the same problem.
Tested...
Sebastian Schmid

01/19/2023

07:47 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Alex Sensation wrote in #note-10:
> I noticed that you created a separated ticket for the Apple profile and ECDSA ce...
Jim Pingle
07:17 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Apologies for the delay and the resurrection.
I have now tested my ECDSA cert with Windows 10 and it worked flawle...
Alex Sensation
07:42 AM Bug #13873: PHP Errors on FRR Global Settings
I can't reproduce it either, even from a clean install that has never had FRR before, but I can see why it might happ... Jim Pingle
06:52 AM Bug #13873: PHP Errors on FRR Global Settings
I couldn't reproduce this behavior on 22.05 or 23.01-RC.... Danilo Zrenjanin
07:37 AM Bug #13886 (Incomplete): NUT Server Package
There isn't nearly enough information here and this site is not for support or diagnostic discussion.
For assistan...
Jim Pingle
06:02 AM Bug #13886 (Closed): NUT Server Package
NUT server package (2.8.0_2) wont load in 23.01 Beta Anonymous

01/18/2023

12:59 PM Regression #13884 (Resolved): pfBlockerNG DNSBL TLD option causes reloads to take a long time
Enabling the DNSBL option @Wildcard Blocking (TLD)@ causes DNSBL reloads to take an extremely long time:... Marcos M

01/17/2023

01:53 PM Todo #13880: security/tailscale: update to 1.34.2_1
Also bump security/pfSense-pkg-Tailscale PORTREVISION to signal GUI for package upgrade. Christian McDonald
01:53 PM Todo #13880 (Closed): security/tailscale: update to 1.34.2_1
Christian McDonald

01/16/2023

11:38 PM Bug #13879: Squid blacklist definition causing issues.
Will be a good option to have those on the GUI and the user decide if they want to use regular expression or plain te... Peter Moreno
08:25 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
This is not a bug. It expects regular expressions, not plain strings.
If that works better for you, you can make t...
Jim Pingle
07:22 PM Bug #13879: Squid blacklist definition causing issues.
I have change squid.inc
$options = array(
'unrestricted_hosts' => 'src',
'banned...
Peter Moreno
07:11 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
Hello.
Working with pfsense 2.7-dev for some months and is going solid, excellent work team.
Now I face a issue t...
Peter Moreno
03:56 PM Bug #9934 (Closed): suricata update kills WAN interface
Interfaces are now reloaded live without bringing down the interface. Marcos M
03:54 PM Bug #10292 (Not a Bug): Suricata not respecting SID Mgmt list
Marcos M
03:54 PM Feature #10472 (Resolved): Blocked host alert table break out by timestamp and type to allow sorting by date
This is possible in the latest version. Marcos M
03:52 PM Bug #11780 (Rejected): Suricata package fails to prune suricata.log
Marcos M
03:45 PM Feature #10872 (Resolved): Add adjustable notification for Severity Alert
Marcos M
03:45 PM Bug #6964 (Resolved): Host OS Policy Assignment broken when using "Import" or "Aliases" buttons
Marcos M
03:45 PM Feature #12285 (Resolved): Add more EVE Logged Traffic protocols
Marcos M
03:44 PM Feature #12292 (Resolved): GeoIP look on the Alerts, Blocked and Files pages
Marcos M
03:44 PM Bug #11742 (Not a Bug): Blocking / Unblocking is not working correctly.
Marcos M
03:44 PM Bug #11742 (Closed): Blocking / Unblocking is not working correctly.
Marcos M
03:43 PM Bug #12322 (Resolved): Suricata creates invalid HOME_NET entries
Marcos M
03:43 PM Bug #11525 (Closed): pfsense 2.5.0 release version for vlan issue to suricata
Unable to reproduce using 23.01 and latest Suricata package. Marcos M
03:40 PM Feature #11210 (Resolved): 3rd party rulesets
Marcos M
03:08 PM Feature #12748 (Resolved): Suricata blocked page timestamp breakout to it's own sortable column
Marcos M
02:29 PM Regression #13856 (Resolved): OpenVPN Export Utility creates a broken installer package
Jim Pingle
02:23 PM Todo #13857 (Feedback): Update bundled installer in OpenVPN Export Utility
Updates are merged into all the relevant branches and will appear once a build succeeds.
Jim Pingle
01:50 PM Todo #13857 (In Progress): Update bundled installer in OpenVPN Export Utility
I've got the files and patch ready for this, testing it now.
Jim Pingle
12:53 PM Bug #13878 (Resolved): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
When importing a profile for EAP-MSCHAPv2 for example, the @AuthenticationMethod@ is set to @Certificate@ when it sho... Jim Pingle
12:50 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Sean McBride wrote in #note-8:
> Jim, thanks for investigating. Note however that we're not using the profile wizard...
Jim Pingle
12:48 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Jim, thanks for investigating. Note however that we're not using the profile wizard at all. Does that mean ECDSA is ... Sean McBride
12:22 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
This is not a bug in pfSense or macOS but from the way the profile wizard forms the configuration profile: The profil... Jim Pingle
12:47 PM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
I was exporting a test config to Windows which had a large number of different P1 options, and the profile generated ... Jim Pingle
12:32 PM Feature #13484: IPsec Profile Wizard/Apple: Support on-demand connections in exported profile
Would need to be set based on a toggle on user request rather than being set unconditionally. Jim Pingle
11:57 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Jim Pingle
11:14 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Pull request https://github.com/pfsense/FreeBSD-ports/pull/1214 has been merged. This issue may be marked as "Resolved". Bill Meeks
08:15 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Jim Pingle wrote in #note-4:
> That should probably be something like this instead:
>
> [...]
Thanks Jim. I believe...
Bill Meeks
07:11 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
That should probably be something like this instead:... Jim Pingle
06:45 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
I honestly don't know how to cause it to happen... I don't know this stuff to even find out where in the config ovpne... Brian Macy

01/14/2023

10:02 PM Bug #13780 (Rejected): pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
pfBlockerNG v2 will be retired and replaced with v3 on 23.01 and 2.7 and beyond. Christian McDonald
07:10 PM Bug #13780: pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
This is a known issue with pfBlockerNG on pfSense Plus 23.01. This issue should not be present on the -devel package... Kris Phillips
07:07 PM Bug #13822 (Confirmed): haproxy bug when adding a Frontend containing accented characters in description in generated XML entities
This issue is confirmed on pfSense Plus 23.01-BETA.
If you add an HAProxy frontend and attempt to use a special ch...
Kris Phillips
07:03 PM Bug #13870 (Incomplete): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
I'm unable to reproduce any bad interactions between Suricata and OpenVPN. I created an OpenVPN interface, enabled i... Kris Phillips
06:52 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
This code is part of a function added by Viktor Gurov in the recent past. The purpose of the function is to collect a... Bill Meeks
05:55 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
... Brian Macy
04:58 PM Bug #13874: pfBlocker -devel hanging on cron jobs
The PHP errors related to the widget provided by the customer were:... Chris W
04:54 PM Bug #13874 (Resolved): pfBlocker -devel hanging on cron jobs
Build:
23.01-BETA (amd64)
built on Fri Jan 06 06:04:43 UTC 2023
FreeBSD 14.0-CURRENT
When pfBlocker is told t...
Chris W
03:37 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
When navigating to the Global Settings tab under Services --> FRR Global/Zebra --> Global Settings, the following err... Kris Phillips

01/12/2023

09:46 AM Feature #13863 (New): squidguard auto update blacklist
Instead of creating a custom cron job none, auto update with a dropdown for daily, weekly, biweekly or monthly update... Mustafa Avcı
08:00 AM Bug #13858 (Resolved): Snort shares some GUI bugs previously identified and corrected in Suricata
Jim Pingle

01/11/2023

05:54 PM Bug #13858: Snort shares some GUI bugs previously identified and corrected in Suricata
The corrections for the issues identified here were manually merged by @jimp. This issue can be marked "resolved". Bill Meeks
11:38 AM Feature #10818: UDP Broadcast Relay
James R wrote in #note-49:
> D. I. wrote in #note-48:
> > I'm seeing a lot of talk about a package for pfSense 2.6....
D. I.
07:40 AM Feature #10818: UDP Broadcast Relay
D. I. wrote in #note-48:
> I'm seeing a lot of talk about a package for pfSense 2.6. However, the package seems to b...
James R
07:05 AM Feature #10818: UDP Broadcast Relay
I'm seeing a lot of talk about a package for pfSense 2.6. However, the package seems to be removed from this page (an... D. I.
06:38 AM Bug #13650 (Resolved): User with a wireguard permissions not able to edit peers/tunnels
Christian McDonald
06:38 AM Bug #13650 (Closed): User with a wireguard permissions not able to edit peers/tunnels
Christian McDonald
05:12 AM Bug #13650: User with a wireguard permissions not able to edit peers/tunnels
It works as expected with the patch.
Tested the patch against:...
Danilo Zrenjanin
06:05 AM Bug #13343: HAproxy cookie protection syntax needs updated
Hello,
Thank you Johannes Goldynia for the work-around, this worked for me too.
Is the fix in the GUI function ...
Alexandre J
04:26 AM Bug #12338: RRD Summary does not report data on 3100
Same issue for me on all the 3100's I've tested.
ntopng package 2.0_2 on pfSense 22.05
Karl Brown

01/10/2023

08:13 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Hi @Jim Pingle
Today we reproduced the same issue with newer macOS, namely Sierra(10) and Monterey(12) using the s...
Alex Sensation
07:06 PM Bug #13738 (Resolved): Typo under Services/Snort/Interface Settings/WAN - Rules
Fix merged. Christopher Cope
01:00 PM Bug #13738 (Pull Request Review): Typo under Services/Snort/Interface Settings/WAN - Rules
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/315 Christopher Cope
03:31 PM Bug #13858: Snort shares some GUI bugs previously identified and corrected in Suricata
The three issues identified in this ticket have all been fixed in Pull Request 1213 posted here: https://github.com/p... Bill Meeks
02:31 PM Bug #13858 (Resolved): Snort shares some GUI bugs previously identified and corrected in Suricata
Because the Snort and Suricata GUI packages share much of the same PHP code, three previously identified issues in Su... Bill Meeks
12:55 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Version update: https://redmine.pfsense.org/issues/13857
Cert looks good:...
Marcos M
12:50 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
This was just needing a fix to a new path for 7-zip since it moved, the other part is unrelated and should go in a se... Jim Pingle
12:37 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Last time I went to update it (Late Nov/Early Dec) their most recent installers were showing they had been signed wit... Jim Pingle
12:31 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Would be helpful to also update the bundled version given that 2.5.2 is fairly old. Marcos M
12:28 PM Regression #13856 (Resolved): OpenVPN Export Utility creates a broken installer package
Tested on @pfSense-23.01.b.20230106.0600@ using the latest @OpenVPN Export Utility@ package version.
The downloade...
Marcos M
12:55 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
The current installer version shows as @2.5.2-Ix01@. Latest version as of now is @OpenVPN-2.5.8-I604-amd64.msi@: http... Marcos M

01/09/2023

07:01 PM Feature #13855 (New): Allow specifying a custom port
The OpenVPN client export package already contains a function to set the host name resolution to "other", which, as t... Phil K
04:54 PM Bug #13753: Gateway groups stop sending traffic if they contain wireguard tunnels
In my case I do Load Balancing of Wireguard Tunnels, if I add only Wireguard tunnels it only uses one tunnel.
Seco...
Jeff Kuehl
02:27 PM Bug #12608: WireGuard tunnels monitored by dpinger causing system to stop routing completely in certain situations
I have noticed this whenever I enable or disable peers this happens. But I see that even interface-to-interface traff... Jeff Kuehl
08:54 AM Todo #13306 (Resolved): Update NUT to version 2.8.0 to match FreeBSD Packages
Jim Pingle
08:47 AM Feature #13733 (Resolved): Upgrade ha proxy 2.6
The HAProxy devel package is at 2.6.6 on both pfSense Plus 23.01 and CE 2.7.0 snapshots.
Jim Pingle
08:10 AM Bug #13842: RADIUS user accounting limit inputs for bandwidth and total usage are not validated to prevent exceeding a 32 bit unsigned value
From the description this is about adding input validation to limit what the FreeRADIUS package will allow, so moving... Jim Pingle

01/08/2023

10:20 PM Todo #13306: Update NUT to version 2.8.0 to match FreeBSD Packages
installed nut 2.8.0_2 on pfSense Plus 23.01.b.20230106.0600 Jordan G

01/07/2023

10:17 PM Feature #13733 (Feedback): Upgrade ha proxy 2.6
pfSense Plus 23.01 has HAProxy 2.6.6 available in the repos for the devel branch. I expect that 2.7 also has this in... Kris Phillips
10:05 PM Bug #13738 (Confirmed): Typo under Services/Snort/Interface Settings/WAN - Rules
Can confirm this on pfSense 23.01-BETA and 22.05. This is only present when a rule is force disabled and only shows ... Kris Phillips
08:55 PM Bug #13810 (Confirmed): Squid options obsolete
I can confirm this behavior on my 23.01-BETA install:
2023/01/08 02:53:54| Startup: Initializing Authentication Sc...
Kris Phillips
08:16 PM Feature #13809: Add Netdata package
Making the netdata package and dependencies available in the repos should be pretty trivial, but in order to configur... Kris Phillips

01/06/2023

06:07 PM Bug #13842 (New): RADIUS user accounting limit inputs for bandwidth and total usage are not validated to prevent exceeding a 32 bit unsigned value
In the FreeRadius package, user upload/download limits can be set to any positive integer, including any values that ... Reid Linnemann
04:21 PM Bug #13839: Suricata version updates take a long time
Marcos M wrote in #note-3:
> I certainly did not take any action during it that would have affected it. I did ommit s...
Bill Meeks
12:14 PM Bug #13839: Suricata version updates take a long time
I certainly did not take any action during it that would have affected it. I did ommit some unrelated lines like me l... Marcos M
09:54 AM Bug #13839: Suricata version updates take a long time
I have also noticed some overall package installation issues with both Suricata and Snort over the last couple of mon... Bill Meeks
03:38 PM Bug #13650 (Pull Request Review): User with a wireguard permissions not able to edit peers/tunnels
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/313 Christopher Cope
04:02 AM Bug #12036 (Resolved): Certificate Manager page do not show Zabbix used certificates
Tested against:... Danilo Zrenjanin
02:14 AM Regression #13828 (Resolved): ACME cron jobs persist after the package is uninstalled
Tested against:... Danilo Zrenjanin
01:30 AM Bug #11204 (Resolved): Fix net-snmp logging to syslog
Tested against:... Danilo Zrenjanin

01/05/2023

02:40 PM Bug #13839 (Resolved): Suricata version updates take a long time
Recently I've noticed that updating Suricata versions takes a very long time, every time. After an update to the late... Marcos M
09:57 AM Feature #13837 (New): PRTG Package
Is it possible to add a PRTG Remote Probe Package?
https://www.paessler.com
OpIT GmbH
09:45 AM Bug #13798 (Resolved): Crash report with lldpd package and 23.01.b.20221223.0600
Jim Pingle
08:47 AM Regression #13828 (Feedback): ACME cron jobs persist after the package is uninstalled
Fix committed, will be in the ACME package on the next build started after this commit:
https://github.com/pfsense...
Jim Pingle
08:30 AM Regression #13828 (Confirmed): ACME cron jobs persist after the package is uninstalled
The ACME cron job is still present after removing the package. The deinstall function isn't referencing the correct A... Jim Pingle
08:45 AM Regression #13817 (Confirmed): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
The cron job is still present after removing the package. There is likely a package-specific change that must be made... Jim Pingle
08:22 AM Bug #13830 (Resolved): Snort cron jobs persist after the package is uninstalled
Jim Pingle
08:11 AM Feature #10818: UDP Broadcast Relay
I've installed 23.01 RC and pfSense-pkg-udpbroadcastrelay-1.0.pkg installs without issue. James R

01/04/2023

04:22 PM Regression #13828 (Closed): ACME cron jobs persist after the package is uninstalled
Fixed in https://redmine.pfsense.org/issues/13833 Marcos M
04:22 PM Regression #13817 (Closed): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
Fixed in https://redmine.pfsense.org/issues/13833 Marcos M
03:10 PM Bug #13830: Snort cron jobs persist after the package is uninstalled
This issue may be closed and marked either "resolved" or "not a bug" as desired. It was addressed by this Changeset: ... Bill Meeks
11:34 AM Bug #13830: Snort cron jobs persist after the package is uninstalled
Update -- this is not actually a problem within the Snort GUI package. Instead, the issue is the result of a PHP 8.1 ... Bill Meeks
09:05 AM Bug #13830 (Resolved): Snort cron jobs persist after the package is uninstalled
Uninstalling the package does not remove the cron jobs added when the service is configured/enabled. Similar to https... Bill Meeks
02:44 PM Regression #13827 (Resolved): Suricata cron jobs persist after the package is uninstalled
PR merged, thanks! Jim Pingle
02:05 PM Regression #13827: Suricata cron jobs persist after the package is uninstalled
I made some changes to the Suricata uninstall code to ensure all code paths perform config writes before exiting. Tho... Bill Meeks
11:21 AM Regression #13827: Suricata cron jobs persist after the package is uninstalled
After some further investigation and testing, I'm not convinced the problem is within the package code. Instead, I be... Bill Meeks
09:03 AM Regression #13827: Suricata cron jobs persist after the package is uninstalled
This was actually broken, it appears, 6 years ago by this commit: https://github.com/pfsense/pfsense/commit/b2bb49709... Bill Meeks
12:36 PM Todo #13306 (Feedback): Update NUT to version 2.8.0 to match FreeBSD Packages
PR https://github.com/pfsense/FreeBSD-ports/pull/1175 Merged
Will be in snapshots overnight.
Jim Pingle
12:17 PM Todo #13306: Update NUT to version 2.8.0 to match FreeBSD Packages
Also updating for PHP 8.1 Denny Page
10:27 AM Bug #13829: WG not removing interface rules from config even if "Keep Configuration" is unchecked before pkg removal
Jim Pingle wrote in #note-3:
> Reopening this since there is a bit more to think about here.
Perhaps another ch...
Loh Phat
09:03 AM Bug #13829 (New): WG not removing interface rules from config even if "Keep Configuration" is unchecked before pkg removal
Reading this again, perhaps I misunderstood. I was talking about assigned interfaces since you mentioned interfaces s... Jim Pingle
08:53 AM Bug #13829: WG not removing interface rules from config even if "Keep Configuration" is unchecked before pkg removal
Jim Pingle wrote in #note-1:
> Interface rules are usually removed when removing an interface from assignments, which...
Loh Phat
08:19 AM Bug #13829 (Not a Bug): WG not removing interface rules from config even if "Keep Configuration" is unchecked before pkg removal
Interface rules are usually removed when removing an interface from assignments, which is a manual process and not pa... Jim Pingle
09:12 AM Bug #12178: WireGuard always shows 'Configuring WireGuard tunnels...done.' message on boot
Have to hop on this. This message (Configuring WireGuard tunnels) shows up couple of minutes if the interface the WG ... Car F

01/03/2023

02:31 PM Bug #13829 (New): WG not removing interface rules from config even if "Keep Configuration" is unchecked before pkg removal
In the pfsense (22.05) config.xml there was a section of rules for the "WireGuard" package i/f. I had tried the pack... Loh Phat
02:02 PM Regression #13828 (Resolved): ACME cron jobs persist after the package is uninstalled
Tested on @23.01.b.20221230.0600@ with the latest package.
Uninstalling the package does not remove the cron jobs ...
Marcos M
01:46 PM Regression #13827 (Resolved): Suricata cron jobs persist after the package is uninstalled
Tested on @23.01.b.20221230.0600@ with the latest package.
Uninstalling the package does not remove the cron jobs ...
Marcos M
12:06 PM Bug #13798 (Feedback): Crash report with lldpd package and 23.01.b.20221223.0600
Fixed: https://github.com/pfsense/FreeBSD-ports/commit/c0904ba7caffb3edf51ab67ce70dbbd362119987 Jim Pingle
09:30 AM Bug #13798: Crash report with lldpd package and 23.01.b.20221223.0600
The error in the original report is definitely from problematic code when run under PHP 8.1. It would be most evident... Jim Pingle
10:57 AM Bug #13808 (Resolved): Suricata saves duplicate entries for the default built-in events and files rule sets when saving changes on the CATEGORIES tab
PR Merged. Jim Pingle
10:57 AM Bug #13806 (Resolved): Suricata interface rules cannot be viewed.
PR Merged. Jim Pingle
10:57 AM Bug #13812 (Resolved): Attempting to change suricata blocking mode on LAN interface from legacy to inline throws a PHP error
PR Merged. Jim Pingle
09:37 AM Regression #13817 (New): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
I had originally opened this against just pfBLockerNG-devel, but changed it since I saw it was happening on all packa... Marcos M
07:57 AM Regression #13817 (Rejected): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
It's up to each package to manage its own cron jobs. There isn't a way for the package manager to know those belong t... Jim Pingle
08:10 AM Feature #13821 (Rejected): [New package] - DNS Leak Test
This is not a useful test compared to testing from a client behind the firewall where it matters more.
Furthermore...
Jim Pingle
08:01 AM Bug #13612 (Resolved): Snort building lists is broken
Jim Pingle
07:48 AM Regression #12643 (Resolved): Rule categories are cleared after clicking the save button on the Global Settings page
Jim Pingle

01/02/2023

10:17 AM Bug #13822 (Confirmed): haproxy bug when adding a Frontend containing accented characters in description in generated XML entities
Hello,
Running snapshot from 2022-12-30 and pfsense stable 2.6.0, same bug in haproxy package.
Adding a Frontend...
appzer0 appzer0
04:20 AM Feature #13821: [New package] - DNS Leak Test
PR Submitted -> https://github.com/pfsense/FreeBSD-ports/pull/1211 Luis Moraguez
03:54 AM Feature #13821 (Rejected): [New package] - DNS Leak Test
I've developed a package that I would like to be made available for other to install via the Package Manager.
I've...
Luis Moraguez

01/01/2023

08:34 PM Bug #13612: Snort building lists is broken
This has been resolved now, so the status is wrong. Flole Systems
03:04 PM Bug #13333 (Resolved): PHP error when saving Suricata rulesets
Marcos M
01:18 PM Regression #13817 (Confirmed): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
Tested on @23.01.b.20221230.0600@ with the latest pfBlockerNG-devel, Suricata, and ACME packages.
Using pfBlockerN...
Marcos M
04:21 AM Feature #10818: UDP Broadcast Relay
Is there any way to install 1.0 package in pfSense 2.6? Installation failed, see below. Or do I have to use the older... M J

12/31/2022

12:17 AM Feature #13469: Feature/Package request: Wireguard Client/Peer config files export
I think this is a much needed feature and should be prioritized. WireGuard is far superior than OpenVPN and other VPNs. Eric Nix

12/30/2022

08:53 AM Bug #13812: Attempting to change suricata blocking mode on LAN interface from legacy to inline throws a PHP error
The fix for this issue was added to open Pull Request #1210 against DEVEL posted here: https://github.com/pfsense/Fre... Bill Meeks
12:30 AM Bug #13812 (Resolved): Attempting to change suricata blocking mode on LAN interface from legacy to inline throws a PHP error
WebGUI reports:
The 'lan' interface does not support Inline IPS Mode with native netmap.
However, I then get a cr...
John Elliott

12/29/2022

09:12 PM Bug #13798: Crash report with lldpd package and 23.01.b.20221223.0600
I'm unable to reproduce any issue with the LLPDd package in pfSense 23.01-BETA's December 28th build. Please provide... Kris Phillips
08:53 PM Bug #10867 (Resolved): squidGuard Package Hangs on Uninstall or Upgrade
Tested on latest 23.01 builds and the install issue is no longer a problem. Closing as resolved. Kris Phillips
12:36 PM Bug #13811: Youtube content getting filtered on Squid when none is Selected
Maharsh Patel wrote:
> Youtube's content gets filtered by its SafeSearch headers even though I have selected *None* ...
Maharsh Patel
10:38 AM Bug #13811 (Closed): Youtube content getting filtered on Squid when none is Selected
Youtube's content gets filtered by its SafeSearch headers even though I have selected *None* on youtube restrictions ... Maharsh Patel
09:26 AM Feature #13791 (Resolved): package information link goes to an old forum post - change to pfBlockerNG package page
I agree...docs is better than an old forum post. Fixed. Christian McDonald
01:07 AM Bug #13810 (Rejected): Squid options obsolete
Hello guys.
Running squid -k parse we have some options that are no longer used, maybe is time to update the GUI:...
Peter Moreno

12/28/2022

10:18 PM Feature #13809 (New): Add Netdata package
I would like to see the Netdata monitoring package added to pfSense.
This would allow a fleet of pfSense systems to ...
Ben Woods
01:13 PM Bug #13738: Typo under Services/Snort/Interface Settings/WAN - Rules
It was intended to be 22.05. I fixed that. Danilo Zrenjanin
 

Also available in: Atom