Project

General

Profile

Activity

From 01/05/2023 to 02/03/2023

02/03/2023

04:33 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Looking into this deeper, I suspect there is potentially an issue with the custom blocking plugin used with the Suric... Bill Meeks
11:07 AM Regression #13884: pfBlockerNG DNSBL TLD option causes reloads to take a long time
Related forum thread: https://forum.netgate.com/topic/177504/v-3-2-0-with-pfsense-23-01-rc-20230202 Jim Pingle
10:40 AM Bug #13874: pfBlocker -devel hanging on cron jobs
There may be two distinct issues there: One with downloads, and one with processing.
If you find it's hanging up on ...
Jim Pingle
10:10 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Ran into this issue on pfBlockerNG-devel v3.2.0 a few days ago. Have been deploying dailies, currently on v2.7.0.a.2... Allen C
10:08 AM Bug #13926 (Feedback): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
I merged the changes to the pfBlockerNG cURL defaults, so the next build will include them. Jim Pingle
09:48 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Steve Wilson wrote in #note-2:
> Jim,
>
> With your patch applied the download completes in about 5 seconds, so i...
Jim Pingle
09:44 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Jim,
With your patch applied the download completes in about 5 seconds, so it solves the issue. But note that the...
Steve Wilson
09:24 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
If you can easily reproduce this, try the following patch (path strip=1):... Jim Pingle
04:37 AM Bug #13926 (Resolved): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Prior to the update to PHP 8.1, downloads of the MaxMind database would take approximately 4 seconds. After the updat... Steve Wilson
08:11 AM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
PR merged, thanks! Jim Pingle
08:11 AM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
PR merged, thanks! Jim Pingle
08:11 AM Bug #13839 (Resolved): Suricata version updates take a long time
PR merged, thanks! Jim Pingle
01:54 AM Bug #13925 (Resolved): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
Clicking on the IP Rep tab when editing an existing interface throws a PHP error.
Steps to reproduce:
1. Naviga...
Steve Wilson

02/02/2023

07:26 PM Bug #13922: Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free... Bill Meeks
07:04 PM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
Changes in cURL function behavior in PHP 8.1 make the Snort package vulnerable to a hang condition when downloading r... Bill Meeks
07:26 PM Bug #13923: Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free... Bill Meeks
07:10 PM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
The Snort package fails to clean up all it's _*.rules_ files when uninstalling. It also creates a Barnyard2 logging s... Bill Meeks
06:27 PM Bug #13839: Suricata version updates take a long time
Jim Pingle wrote in #note-6:
> To fix some issues in Dynamic DNS where it didn't want to close connections (it hung ...
Bill Meeks
06:12 PM Bug #13839: Suricata version updates take a long time
The pull request to correct this issue has been submitted against the snapshots DEVEL branch here: https://github.com... Bill Meeks
05:19 PM Bug #13839: Suricata version updates take a long time
To fix some issues in Dynamic DNS where it didn't want to close connections (it hung pretty much indefinitely) we end... Jim Pingle
05:07 PM Bug #13839: Suricata version updates take a long time
After some digging around, I am pretty sure I found the problem here. It is related to HTTP/2 support in cURL. I can ... Bill Meeks
05:24 PM Bug #13566 (Resolved): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
Tested on... Christopher Cope
04:31 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Christian McDonald wrote in #note-3:
> Hi,
>
> I'll have a look. Might not be this week, but definitely next week...
Bill Meeks
02:23 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Hi,
I'll have a look. Might not be this week, but definitely next week.
Christian McDonald
01:43 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
I might need some assistance from the Netgate wireguard guru on this one. I don't have a functioning wireguard packag... Bill Meeks
10:38 AM Bug #13920 (Resolved): 23.01RC - Suricata stops working after Wireguard installed
Upgraded to 23.01RC from 22.05 without any packages installed. Current base system shown as 23.01.r.20230202.0019
...
Greger Blennerud
10:47 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
PR merged Jim Pingle
08:34 AM Bug #13919: Typo in suricata package: cpnfig_set_path()
This issue has been corrected in pull request 1223 posted here: https://github.com/pfsense/FreeBSD-ports/pull/1223.
...
Bill Meeks
05:15 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
FreeBSD 14.0-CURRENT #0 plus-RELENG_23_01-n256014-9cf2a68c5e5: Thu Feb 2 00:48:35 UTC 2023 root@freebsd:/var/jen... Brian Macy

02/01/2023

07:59 AM Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
Can someone test this with 23.01 snaps on the SG-3100 ?
Marcelo Cury

01/30/2023

10:01 AM Todo #13917 (Resolved): OpenVPN Client Export: Integrate OpenVPN 2.6.0
We need to add OpenVPN 2.6.0 to the export package but doing so has a few caveats:
* OpenSSL 3.0 which is used in ...
Jim Pingle

01/28/2023

09:44 PM Bug #13566: Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
I'm assuming this will have to wait for the RC release, as I don't see this reflected in the BETA repos. Both versio... Kris Phillips
05:49 AM Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
I'm still having the same issue. The link below has recently been update and would suggest that it's an issue using P... B P
02:06 AM Bug #13441: FRR fails to start with route map on "sequence 0" in configuration
The same behavior on frr 1.2_3
frr fail to start
_Jan 28 11:02:02 watchfrr 97266 [EC 268435457] bgpd state...
Lev Prokofev

01/27/2023

03:58 PM Bug #13566 (Feedback): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
@security/pfSense-pkg-pfBlockerNG-devel@ has been copied to @security/pfSense-pkg-pfBlockerNG@.
The versions of bo...
Christian McDonald
10:52 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
I also closed out #13877 and #13368 since they were all related. Testing one means the others are also working.
Jim Pingle
10:50 AM Bug #12948 (Resolved): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Jim Pingle
10:05 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Tested against:... Danilo Zrenjanin
10:51 AM Bug #13368 (Resolved): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Jim Pingle
10:51 AM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Jim Pingle

01/26/2023

11:59 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
PR merged. Jim Pingle
09:01 AM Bug #13910: Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
Pull request 1221 has been submitted to correct this issue: https://github.com/pfsense/FreeBSD-ports/pull/1221.
Th...
Bill Meeks
08:41 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
There is a typo on line 253 of /usr/local/pkg/snort/snort_generate_conf. This can result in the creation of an invali... Bill Meeks

01/25/2023

02:39 PM Bug #13690 (Closed): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
The updated description and link appear as expected in the package list now.
Jim Pingle
01:01 PM Bug #13690 (Feedback): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #12948 (Feedback): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:18 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
The code added here was incorrect, see #13368 and #13877 Jim Pingle
09:17 AM Bug #12948 (New): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Jim Pingle
01:01 PM Bug #13877 (Feedback): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:47 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Tested on Windows 10 and Windows 11 against a VPN with and without a P2 hash selected and it worked as expected in ev... Jim Pingle
09:15 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
After testing, the value of @AuthenticationTransformConstants@ should be set to match @CipherTransformConstants@ when... Jim Pingle
01:01 PM Bug #13897 (Feedback): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #13368 (Feedback): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:13 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
After testing, the value of @AuthenticationTransformConstants@ should apparently be set to match @CipherTransformCons... Jim Pingle
01:01 PM Bug #12705 (Feedback): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:19 AM Bug #12705 (Confirmed): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Jim Pingle
01:00 PM Bug #13878 (Feedback): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:55 AM Todo #13906 (Resolved): Update tailscale from 1.34.2 to 1.36.0
https://tailscale.com/changelog/ Christian McDonald
09:13 AM Feature #13474: Don't set ListenPort in wireguard
Good point. Will add this soon Christian McDonald
09:13 AM Feature #13905 (Bogus): Introduce GUI knob for controlling ```--snat-subnet-routes``` tailscaled option
https://github.com/pfsense/FreeBSD-ports/commit/dfb9dcf53bd8e687cda708701f07217ec5e7f1ef Christian McDonald
02:14 AM Bug #13874 (Confirmed): pfBlocker -devel hanging on cron jobs
Yes, the issue is present on the 3.1.0_19 version. Danilo Zrenjanin

01/24/2023

02:01 PM Bug #13898 (New): Issues saving pfBlocker Sync Targets
I have the hosts visible in the image 1.png in the target list to sync. I click on "Save XMLRPC sync settings" and ge... Tom Huerlimann
09:59 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
This appears to have been broken by the change in #12948, the fix from that issue forced the P1 hash to 'None' when t... Jim Pingle
09:28 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Moving the unrelated split tunnel part to a new issue (#13897). Jim Pingle
09:30 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
When exporting an IPsec profile for Windows which includes split tunneling, if the local P2 network is set to @0.0.0.... Jim Pingle

01/23/2023

11:00 AM Regression #13892 (Feedback): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
Commit pushed and merged/picked as needed, will be in builds soon.
https://github.com/pfsense/FreeBSD-ports/commit...
Jim Pingle
10:03 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
When visiting status_monitoring.php, the user may get a PHP error if they have no valid OpenVPN server entries.
<p...
Jim Pingle

01/22/2023

06:43 PM Bug #13874: pfBlocker -devel hanging on cron jobs
I am seeing this on 3.1.0_19 Michael Kellogg

01/21/2023

08:10 PM Bug #13432 (Incomplete): ups driver will not start
I'm still unable to reproduce this problem with a fresh install of 23.01 and the latest NUT package. At this point I... Kris Phillips
07:59 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
No longer able to recreate this. Not sure what caused it before, but I was testing on a fresh install of 23.01 and o... Kris Phillips
07:29 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
They are there on internal 23.01 RC snaps.... Jim Pingle
06:44 PM Todo #13857: Update bundled installer in OpenVPN Export Utility
Checked on 22.05 and it appears these were merged properly. However, looking at the repos for 23.01, which is on a n... Kris Phillips
06:37 PM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Redmine 13368 may be related, as it's in a similar vein: https://redmine.pfsense.org/issues/13368
Kris Phillips
06:33 PM Bug #13886: NUT Server Package
# Installed NUT package on 23.01
# Setup usbhid with a simple UPS config and enabled the service with Local USB
# S...
Kris Phillips
12:29 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Based on a project spanning multiple clients / locations / firewalls, I can certify that this is still true in CE 2.6... Jonathan Edman
12:28 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Hannes Palmquist wrote in #note-11:
> +1
>
> Agent 6.2 install does not work, same error.
Based on a project s...
Jonathan Edman
10:46 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-7:
> It is still here, unfortunately.
I mean the issue was occurred after I update th...
Lev Prokofev
10:45 AM Bug #13874: pfBlocker -devel hanging on cron jobs
It is still here, unfortunately. Lev Prokofev
10:30 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-5:
> I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0...
Jim Pingle
05:03 AM Bug #13874: pfBlocker -devel hanging on cron jobs
I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0_16 Lev Prokofev
03:15 AM Bug #13328: Wireguard Site-to-Site broken after upgrade to 22.05
Still the same issue
PPPOE connection might be the problem.
I found more poeple with the same problem.
Tested...
Sebastian Schmid

01/19/2023

07:47 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Alex Sensation wrote in #note-10:
> I noticed that you created a separated ticket for the Apple profile and ECDSA ce...
Jim Pingle
07:17 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Apologies for the delay and the resurrection.
I have now tested my ECDSA cert with Windows 10 and it worked flawle...
Alex Sensation
07:42 AM Bug #13873: PHP Errors on FRR Global Settings
I can't reproduce it either, even from a clean install that has never had FRR before, but I can see why it might happ... Jim Pingle
06:52 AM Bug #13873: PHP Errors on FRR Global Settings
I couldn't reproduce this behavior on 22.05 or 23.01-RC.... Danilo Zrenjanin
07:37 AM Bug #13886 (Incomplete): NUT Server Package
There isn't nearly enough information here and this site is not for support or diagnostic discussion.
For assistan...
Jim Pingle
06:02 AM Bug #13886 (Closed): NUT Server Package
NUT server package (2.8.0_2) wont load in 23.01 Beta Anonymous

01/18/2023

12:59 PM Regression #13884 (Resolved): pfBlockerNG DNSBL TLD option causes reloads to take a long time
Enabling the DNSBL option @Wildcard Blocking (TLD)@ causes DNSBL reloads to take an extremely long time:... Marcos M

01/17/2023

01:53 PM Todo #13880: security/tailscale: update to 1.34.2_1
Also bump security/pfSense-pkg-Tailscale PORTREVISION to signal GUI for package upgrade. Christian McDonald
01:53 PM Todo #13880 (Closed): security/tailscale: update to 1.34.2_1
Christian McDonald

01/16/2023

11:38 PM Bug #13879: Squid blacklist definition causing issues.
Will be a good option to have those on the GUI and the user decide if they want to use regular expression or plain te... Peter Moreno
08:25 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
This is not a bug. It expects regular expressions, not plain strings.
If that works better for you, you can make t...
Jim Pingle
07:22 PM Bug #13879: Squid blacklist definition causing issues.
I have change squid.inc
$options = array(
'unrestricted_hosts' => 'src',
'banned...
Peter Moreno
07:11 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
Hello.
Working with pfsense 2.7-dev for some months and is going solid, excellent work team.
Now I face a issue t...
Peter Moreno
03:56 PM Bug #9934 (Closed): suricata update kills WAN interface
Interfaces are now reloaded live without bringing down the interface. Marcos M
03:54 PM Bug #10292 (Not a Bug): Suricata not respecting SID Mgmt list
Marcos M
03:54 PM Feature #10472 (Resolved): Blocked host alert table break out by timestamp and type to allow sorting by date
This is possible in the latest version. Marcos M
03:52 PM Bug #11780 (Rejected): Suricata package fails to prune suricata.log
Marcos M
03:45 PM Feature #10872 (Resolved): Add adjustable notification for Severity Alert
Marcos M
03:45 PM Bug #6964 (Resolved): Host OS Policy Assignment broken when using "Import" or "Aliases" buttons
Marcos M
03:45 PM Feature #12285 (Resolved): Add more EVE Logged Traffic protocols
Marcos M
03:44 PM Feature #12292 (Resolved): GeoIP look on the Alerts, Blocked and Files pages
Marcos M
03:44 PM Bug #11742 (Not a Bug): Blocking / Unblocking is not working correctly.
Marcos M
03:44 PM Bug #11742 (Closed): Blocking / Unblocking is not working correctly.
Marcos M
03:43 PM Bug #12322 (Resolved): Suricata creates invalid HOME_NET entries
Marcos M
03:43 PM Bug #11525 (Closed): pfsense 2.5.0 release version for vlan issue to suricata
Unable to reproduce using 23.01 and latest Suricata package. Marcos M
03:40 PM Feature #11210 (Resolved): 3rd party rulesets
Marcos M
03:08 PM Feature #12748 (Resolved): Suricata blocked page timestamp breakout to it's own sortable column
Marcos M
02:29 PM Regression #13856 (Resolved): OpenVPN Export Utility creates a broken installer package
Jim Pingle
02:23 PM Todo #13857 (Feedback): Update bundled installer in OpenVPN Export Utility
Updates are merged into all the relevant branches and will appear once a build succeeds.
Jim Pingle
01:50 PM Todo #13857 (In Progress): Update bundled installer in OpenVPN Export Utility
I've got the files and patch ready for this, testing it now.
Jim Pingle
12:53 PM Bug #13878 (Resolved): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
When importing a profile for EAP-MSCHAPv2 for example, the @AuthenticationMethod@ is set to @Certificate@ when it sho... Jim Pingle
12:50 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Sean McBride wrote in #note-8:
> Jim, thanks for investigating. Note however that we're not using the profile wizard...
Jim Pingle
12:48 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Jim, thanks for investigating. Note however that we're not using the profile wizard at all. Does that mean ECDSA is ... Sean McBride
12:22 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
This is not a bug in pfSense or macOS but from the way the profile wizard forms the configuration profile: The profil... Jim Pingle
12:47 PM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
I was exporting a test config to Windows which had a large number of different P1 options, and the profile generated ... Jim Pingle
12:32 PM Feature #13484: IPsec Profile Wizard/Apple: Support on-demand connections in exported profile
Would need to be set based on a toggle on user request rather than being set unconditionally. Jim Pingle
11:57 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Jim Pingle
11:14 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Pull request https://github.com/pfsense/FreeBSD-ports/pull/1214 has been merged. This issue may be marked as "Resolved". Bill Meeks
08:15 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
Jim Pingle wrote in #note-4:
> That should probably be something like this instead:
>
> [...]
Thanks Jim. I believe...
Bill Meeks
07:11 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
That should probably be something like this instead:... Jim Pingle
06:45 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
I honestly don't know how to cause it to happen... I don't know this stuff to even find out where in the config ovpne... Brian Macy

01/14/2023

10:02 PM Bug #13780 (Rejected): pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
pfBlockerNG v2 will be retired and replaced with v3 on 23.01 and 2.7 and beyond. Christian McDonald
07:10 PM Bug #13780: pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
This is a known issue with pfBlockerNG on pfSense Plus 23.01. This issue should not be present on the -devel package... Kris Phillips
07:07 PM Bug #13822 (Confirmed): haproxy bug when adding a Frontend containing accented characters in description in generated XML entities
This issue is confirmed on pfSense Plus 23.01-BETA.
If you add an HAProxy frontend and attempt to use a special ch...
Kris Phillips
07:03 PM Bug #13870 (Incomplete): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
I'm unable to reproduce any bad interactions between Suricata and OpenVPN. I created an OpenVPN interface, enabled i... Kris Phillips
06:52 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
This code is part of a function added by Viktor Gurov in the recent past. The purpose of the function is to collect a... Bill Meeks
05:55 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
... Brian Macy
04:58 PM Bug #13874: pfBlocker -devel hanging on cron jobs
The PHP errors related to the widget provided by the customer were:... Chris W
04:54 PM Bug #13874 (Resolved): pfBlocker -devel hanging on cron jobs
Build:
23.01-BETA (amd64)
built on Fri Jan 06 06:04:43 UTC 2023
FreeBSD 14.0-CURRENT
When pfBlocker is told t...
Chris W
03:37 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
When navigating to the Global Settings tab under Services --> FRR Global/Zebra --> Global Settings, the following err... Kris Phillips

01/12/2023

09:46 AM Feature #13863 (New): squidguard auto update blacklist
Instead of creating a custom cron job none, auto update with a dropdown for daily, weekly, biweekly or monthly update... Mustafa Avcı
08:00 AM Bug #13858 (Resolved): Snort shares some GUI bugs previously identified and corrected in Suricata
Jim Pingle

01/11/2023

05:54 PM Bug #13858: Snort shares some GUI bugs previously identified and corrected in Suricata
The corrections for the issues identified here were manually merged by @jimp. This issue can be marked "resolved". Bill Meeks
11:38 AM Feature #10818: UDP Broadcast Relay
James R wrote in #note-49:
> D. I. wrote in #note-48:
> > I'm seeing a lot of talk about a package for pfSense 2.6....
D. I.
07:40 AM Feature #10818: UDP Broadcast Relay
D. I. wrote in #note-48:
> I'm seeing a lot of talk about a package for pfSense 2.6. However, the package seems to b...
James R
07:05 AM Feature #10818: UDP Broadcast Relay
I'm seeing a lot of talk about a package for pfSense 2.6. However, the package seems to be removed from this page (an... D. I.
06:38 AM Bug #13650 (Resolved): User with a wireguard permissions not able to edit peers/tunnels
Christian McDonald
06:38 AM Bug #13650 (Closed): User with a wireguard permissions not able to edit peers/tunnels
Christian McDonald
05:12 AM Bug #13650: User with a wireguard permissions not able to edit peers/tunnels
It works as expected with the patch.
Tested the patch against:...
Danilo Zrenjanin
06:05 AM Bug #13343: HAproxy cookie protection syntax needs updated
Hello,
Thank you Johannes Goldynia for the work-around, this worked for me too.
Is the fix in the GUI function ...
Alexandre J
04:26 AM Bug #12338: RRD Summary does not report data on 3100
Same issue for me on all the 3100's I've tested.
ntopng package 2.0_2 on pfSense 22.05
Karl Brown

01/10/2023

08:13 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Hi @Jim Pingle
Today we reproduced the same issue with newer macOS, namely Sierra(10) and Monterey(12) using the s...
Alex Sensation
07:06 PM Bug #13738 (Resolved): Typo under Services/Snort/Interface Settings/WAN - Rules
Fix merged. Christopher Cope
01:00 PM Bug #13738 (Pull Request Review): Typo under Services/Snort/Interface Settings/WAN - Rules
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/315 Christopher Cope
03:31 PM Bug #13858: Snort shares some GUI bugs previously identified and corrected in Suricata
The three issues identified in this ticket have all been fixed in Pull Request 1213 posted here: https://github.com/p... Bill Meeks
02:31 PM Bug #13858 (Resolved): Snort shares some GUI bugs previously identified and corrected in Suricata
Because the Snort and Suricata GUI packages share much of the same PHP code, three previously identified issues in Su... Bill Meeks
12:55 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Version update: https://redmine.pfsense.org/issues/13857
Cert looks good:...
Marcos M
12:50 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
This was just needing a fix to a new path for 7-zip since it moved, the other part is unrelated and should go in a se... Jim Pingle
12:37 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Last time I went to update it (Late Nov/Early Dec) their most recent installers were showing they had been signed wit... Jim Pingle
12:31 PM Regression #13856: OpenVPN Export Utility creates a broken installer package
Would be helpful to also update the bundled version given that 2.5.2 is fairly old. Marcos M
12:28 PM Regression #13856 (Resolved): OpenVPN Export Utility creates a broken installer package
Tested on @pfSense-23.01.b.20230106.0600@ using the latest @OpenVPN Export Utility@ package version.
The downloade...
Marcos M
12:55 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
The current installer version shows as @2.5.2-Ix01@. Latest version as of now is @OpenVPN-2.5.8-I604-amd64.msi@: http... Marcos M

01/09/2023

07:01 PM Feature #13855 (New): Allow specifying a custom port
The OpenVPN client export package already contains a function to set the host name resolution to "other", which, as t... Phil K
04:54 PM Bug #13753: Gateway groups stop sending traffic if they contain wireguard tunnels
In my case I do Load Balancing of Wireguard Tunnels, if I add only Wireguard tunnels it only uses one tunnel.
Seco...
Jeff Kuehl
02:27 PM Bug #12608: WireGuard tunnels monitored by dpinger causing system to stop routing completely in certain situations
I have noticed this whenever I enable or disable peers this happens. But I see that even interface-to-interface traff... Jeff Kuehl
08:54 AM Todo #13306 (Resolved): Update NUT to version 2.8.0 to match FreeBSD Packages
Jim Pingle
08:47 AM Feature #13733 (Resolved): Upgrade ha proxy 2.6
The HAProxy devel package is at 2.6.6 on both pfSense Plus 23.01 and CE 2.7.0 snapshots.
Jim Pingle
08:10 AM Bug #13842: RADIUS user accounting limit inputs for bandwidth and total usage are not validated to prevent exceeding a 32 bit unsigned value
From the description this is about adding input validation to limit what the FreeRADIUS package will allow, so moving... Jim Pingle

01/08/2023

10:20 PM Todo #13306: Update NUT to version 2.8.0 to match FreeBSD Packages
installed nut 2.8.0_2 on pfSense Plus 23.01.b.20230106.0600 Jordan G

01/07/2023

10:17 PM Feature #13733 (Feedback): Upgrade ha proxy 2.6
pfSense Plus 23.01 has HAProxy 2.6.6 available in the repos for the devel branch. I expect that 2.7 also has this in... Kris Phillips
10:05 PM Bug #13738 (Confirmed): Typo under Services/Snort/Interface Settings/WAN - Rules
Can confirm this on pfSense 23.01-BETA and 22.05. This is only present when a rule is force disabled and only shows ... Kris Phillips
08:55 PM Bug #13810 (Confirmed): Squid options obsolete
I can confirm this behavior on my 23.01-BETA install:
2023/01/08 02:53:54| Startup: Initializing Authentication Sc...
Kris Phillips
08:16 PM Feature #13809: Add Netdata package
Making the netdata package and dependencies available in the repos should be pretty trivial, but in order to configur... Kris Phillips

01/06/2023

06:07 PM Bug #13842 (New): RADIUS user accounting limit inputs for bandwidth and total usage are not validated to prevent exceeding a 32 bit unsigned value
In the FreeRadius package, user upload/download limits can be set to any positive integer, including any values that ... Reid Linnemann
04:21 PM Bug #13839: Suricata version updates take a long time
Marcos M wrote in #note-3:
> I certainly did not take any action during it that would have affected it. I did ommit s...
Bill Meeks
12:14 PM Bug #13839: Suricata version updates take a long time
I certainly did not take any action during it that would have affected it. I did ommit some unrelated lines like me l... Marcos M
09:54 AM Bug #13839: Suricata version updates take a long time
I have also noticed some overall package installation issues with both Suricata and Snort over the last couple of mon... Bill Meeks
03:38 PM Bug #13650 (Pull Request Review): User with a wireguard permissions not able to edit peers/tunnels
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/313 Christopher Cope
04:02 AM Bug #12036 (Resolved): Certificate Manager page do not show Zabbix used certificates
Tested against:... Danilo Zrenjanin
02:14 AM Regression #13828 (Resolved): ACME cron jobs persist after the package is uninstalled
Tested against:... Danilo Zrenjanin
01:30 AM Bug #11204 (Resolved): Fix net-snmp logging to syslog
Tested against:... Danilo Zrenjanin

01/05/2023

02:40 PM Bug #13839 (Resolved): Suricata version updates take a long time
Recently I've noticed that updating Suricata versions takes a very long time, every time. After an update to the late... Marcos M
09:57 AM Feature #13837 (New): PRTG Package
Is it possible to add a PRTG Remote Probe Package?
https://www.paessler.com
OpIT GmbH
09:45 AM Bug #13798 (Resolved): Crash report with lldpd package and 23.01.b.20221223.0600
Jim Pingle
08:47 AM Regression #13828 (Feedback): ACME cron jobs persist after the package is uninstalled
Fix committed, will be in the ACME package on the next build started after this commit:
https://github.com/pfsense...
Jim Pingle
08:30 AM Regression #13828 (Confirmed): ACME cron jobs persist after the package is uninstalled
The ACME cron job is still present after removing the package. The deinstall function isn't referencing the correct A... Jim Pingle
08:45 AM Regression #13817 (Confirmed): pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
The cron job is still present after removing the package. There is likely a package-specific change that must be made... Jim Pingle
08:22 AM Bug #13830 (Resolved): Snort cron jobs persist after the package is uninstalled
Jim Pingle
08:11 AM Feature #10818: UDP Broadcast Relay
I've installed 23.01 RC and pfSense-pkg-udpbroadcastrelay-1.0.pkg installs without issue. James R
 

Also available in: Atom