Activity
From 01/14/2023 to 02/12/2023
02/12/2023
-
09:00 PM Regression #13950 (Resolved): PHP error with pfBlockerNG
- After restoring a config backup which contains pfBlockerNG-devel to a fresh install of 23.01, a crash/alert shows the...
02/11/2023
-
12:03 PM Regression #13947: Remove 4096GB quota limit
- As an observation, you can avoid the overflow consequences of premature logout due to the 32 bit unsigned integer ove...
02/09/2023
-
07:40 AM Bug #13874 (Resolved): pfBlocker -devel hanging on cron jobs
- Thanks for testing and following up!
I'm going to mark this one resolved as there was some overlap with #13926 and... -
07:39 AM Bug #13926 (Resolved): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
-
05:39 AM Bug #13936 (Confirmed): PHP error from RRD Graphs when attempting a query a newly created empty database
- I replicated the issue. ...
02/08/2023
-
06:38 PM Bug #13874: pfBlocker -devel hanging on cron jobs
- Work has had me tied up so I haven't been able to do review the information Jim was kind enough to provide. I freed ...
-
03:36 PM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- This change fixed two issues I have seen with pfB since moving to 23.01: 1) slow MaxMind downloads; 2) slow block lis...
-
11:21 AM Regression #13947 (Feedback): Remove 4096GB quota limit
- The 4096GB quota limit introduced to prevent pfSense-Max-Total-Octets overflowing uint32 for captive portal artificia...
-
08:37 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
- Tested against the IPsec Profile Wizard pkg v. 1.1
It looks fine.
*Split Tunnel Routes* part is omitted if the loca... -
07:14 AM Feature #13930: Hysteria Proxy/Relay
- help doc link: https://hysteria.network/docs/advanced-usage/
-
04:41 AM Feature #13930: Hysteria Proxy/Relay
- It supports using ACME to obtain encryption certificates or self-signed certificates can be used.
-
04:40 AM Feature #13930: Hysteria Proxy/Relay
- After I have tested and compared, it is designed to include encryption to bypass monitoring. After the network protoc...
-
04:33 AM Feature #13930: Hysteria Proxy/Relay
- No, it has encryption, and it's specifically designed to bypass internet surveillance in authoritarian countries. Cer...
02/07/2023
-
02:19 PM Todo #13255: Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
- That is part of the plan, see #13917
-
01:06 PM Todo #13255: Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
- Jim Pingle wrote:
> Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a speci... -
09:33 AM Bug #10646 (Resolved): Reinstall package process stalls at pfBlockerNG when restoring a config
- This has been working since the fix went in.
-
09:33 AM Bug #11398 (Resolved): pfBlocker upgrade hangs forever
- This has been working since the fix went in.
-
08:13 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
02/06/2023
-
02:38 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- The fix for this issue requires an update to the custom blocking plugin compiled into the Suricata binary on pfSense....
-
12:33 PM Bug #13936 (Resolved): PHP error from RRD Graphs when attempting a query a newly created empty database
- Attempting to view an RRD graph of a new database that doesn't yet have data results in a PHP error.
Easiest way t... -
07:48 AM Feature #13575: Update to frr 9.0.1
- When this happens it's best to just move to 8.x and not keep two versions around.
-
07:46 AM Feature #13931 (Duplicate): Upgrade FRR from 7.x to 8.x
- Duplicate of #13575
-
07:34 AM Feature #13930: Hysteria Proxy/Relay
- It's no surprise that it's faster than WireGuard as it has no encryption. It's a proxy/relay setup, not an encrypted ...
02/05/2023
-
09:18 AM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- Bill Meeks wrote in #note-7:
> Just to be clear on this PHP error. I think you are getting that because you made an ... -
07:55 AM Feature #13930: Hysteria Proxy/Relay
- I have notified the developer of this program, and the developer has agreed to promote this program. And it is recomm...
02/04/2023
-
09:36 PM Bug #13932 (Not a Bug): Deprecation Message for Arpwatch
- I checked the code. We are already using -w instead of -m. We could remove the pkg-message from our net-mgmt/arpwatch.
-
06:12 PM Bug #13932 (Not a Bug): Deprecation Message for Arpwatch
- During install, the following message about deprecated flags is mentioned:
_
The -m flag is deprecated. If you are ... -
02:21 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- Greger Blennerud wrote in #note-6:
> The actual list found in /usr/local/etc/suricata/suricata_28603_vtnet1 never cha... -
04:08 AM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- I decided to do some more testing and discovered some wierd issues with the passlist.
First of all, I get a discrep... -
10:59 AM Feature #13931 (Duplicate): Upgrade FRR from 7.x to 8.x
- The FRR latest version has fixed many problems. Including the bug fixes submitted by me. And added many new features....
-
10:55 AM Feature #13930 (New): Hysteria Proxy/Relay
- Please consider adding this function. I have tested that its actual network speed is 5-10 times faster than wireguard...
-
10:05 AM Bug #13925 (Pull Request Review): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
- https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/328
-
08:45 AM Bug #13925 (Confirmed): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
- I'm able to reproduce this on...
02/03/2023
-
04:33 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- Looking into this deeper, I suspect there is potentially an issue with the custom blocking plugin used with the Suric...
-
11:07 AM Regression #13884: pfBlockerNG DNSBL TLD option causes reloads to take a long time
- Related forum thread: https://forum.netgate.com/topic/177504/v-3-2-0-with-pfsense-23-01-rc-20230202
-
10:40 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- There may be two distinct issues there: One with downloads, and one with processing.
If you find it's hanging up on ... -
10:10 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- Ran into this issue on pfBlockerNG-devel v3.2.0 a few days ago. Have been deploying dailies, currently on v2.7.0.a.2...
-
10:08 AM Bug #13926 (Feedback): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- I merged the changes to the pfBlockerNG cURL defaults, so the next build will include them.
-
09:48 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- Steve Wilson wrote in #note-2:
> Jim,
>
> With your patch applied the download completes in about 5 seconds, so i... -
09:44 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- Jim,
With your patch applied the download completes in about 5 seconds, so it solves the issue. But note that the... -
09:24 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- If you can easily reproduce this, try the following patch (path strip=1):...
-
04:37 AM Bug #13926 (Resolved): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
- Prior to the update to PHP 8.1, downloads of the MaxMind database would take approximately 4 seconds. After the updat...
-
08:11 AM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
- PR merged, thanks!
-
08:11 AM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
- PR merged, thanks!
-
08:11 AM Bug #13839 (Resolved): Suricata version updates take a long time
- PR merged, thanks!
-
01:54 AM Bug #13925 (Resolved): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
- Clicking on the IP Rep tab when editing an existing interface throws a PHP error.
Steps to reproduce:
1. Naviga...
02/02/2023
-
07:26 PM Bug #13922: Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
- This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free...
-
07:04 PM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
- Changes in cURL function behavior in PHP 8.1 make the Snort package vulnerable to a hang condition when downloading r...
-
07:26 PM Bug #13923: Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
- This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free...
-
07:10 PM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
- The Snort package fails to clean up all it's _*.rules_ files when uninstalling. It also creates a Barnyard2 logging s...
-
06:27 PM Bug #13839: Suricata version updates take a long time
- Jim Pingle wrote in #note-6:
> To fix some issues in Dynamic DNS where it didn't want to close connections (it hung ... -
06:12 PM Bug #13839: Suricata version updates take a long time
- The pull request to correct this issue has been submitted against the snapshots DEVEL branch here: https://github.com...
-
05:19 PM Bug #13839: Suricata version updates take a long time
- To fix some issues in Dynamic DNS where it didn't want to close connections (it hung pretty much indefinitely) we end...
-
05:07 PM Bug #13839: Suricata version updates take a long time
- After some digging around, I am pretty sure I found the problem here. It is related to HTTP/2 support in cURL. I can ...
-
05:24 PM Bug #13566 (Resolved): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
- Tested on...
-
04:31 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- Christian McDonald wrote in #note-3:
> Hi,
>
> I'll have a look. Might not be this week, but definitely next week... -
02:23 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- Hi,
I'll have a look. Might not be this week, but definitely next week. -
01:43 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
- I might need some assistance from the Netgate wireguard guru on this one. I don't have a functioning wireguard packag...
-
10:38 AM Bug #13920 (Resolved): 23.01RC - Suricata stops working after Wireguard installed
- Upgraded to 23.01RC from 22.05 without any packages installed. Current base system shown as 23.01.r.20230202.0019
... -
10:47 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
- PR merged
-
08:34 AM Bug #13919: Typo in suricata package: cpnfig_set_path()
- This issue has been corrected in pull request 1223 posted here: https://github.com/pfsense/FreeBSD-ports/pull/1223.
... -
05:15 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
- FreeBSD 14.0-CURRENT #0 plus-RELENG_23_01-n256014-9cf2a68c5e5: Thu Feb 2 00:48:35 UTC 2023 root@freebsd:/var/jen...
02/01/2023
-
07:59 AM Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
- Can someone test this with 23.01 snaps on the SG-3100 ?
01/30/2023
-
10:01 AM Todo #13917 (Resolved): OpenVPN Client Export: Integrate OpenVPN 2.6.0
- We need to add OpenVPN 2.6.0 to the export package but doing so has a few caveats:
* OpenSSL 3.0 which is used in ...
01/28/2023
-
09:44 PM Bug #13566: Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
- I'm assuming this will have to wait for the RC release, as I don't see this reflected in the BETA repos. Both versio...
-
05:49 AM Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
- I'm still having the same issue. The link below has recently been update and would suggest that it's an issue using P...
-
02:06 AM Bug #13441: FRR fails to start with route map on "sequence 0" in configuration
- The same behavior on frr 1.2_3
frr fail to start
_Jan 28 11:02:02 watchfrr 97266 [EC 268435457] bgpd state...
01/27/2023
-
03:58 PM Bug #13566 (Feedback): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
- @security/pfSense-pkg-pfBlockerNG-devel@ has been copied to @security/pfSense-pkg-pfBlockerNG@.
The versions of bo... -
10:52 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
- I also closed out #13877 and #13368 since they were all related. Testing one means the others are also working.
-
10:50 AM Bug #12948 (Resolved): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
-
10:05 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
- Tested against:...
-
10:51 AM Bug #13368 (Resolved): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
-
10:51 AM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
01/26/2023
-
11:59 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
- PR merged.
-
09:01 AM Bug #13910: Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
- Pull request 1221 has been submitted to correct this issue: https://github.com/pfsense/FreeBSD-ports/pull/1221.
Th... -
08:41 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
- There is a typo on line 253 of /usr/local/pkg/snort/snort_generate_conf. This can result in the creation of an invali...
01/25/2023
-
02:39 PM Bug #13690 (Closed): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
- The updated description and link appear as expected in the package list now.
-
01:01 PM Bug #13690 (Feedback): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
01:01 PM Bug #12948 (Feedback): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
09:18 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
- The code added here was incorrect, see #13368 and #13877
-
09:17 AM Bug #12948 (New): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
-
01:01 PM Bug #13877 (Feedback): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
09:47 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
- Tested on Windows 10 and Windows 11 against a VPN with and without a P2 hash selected and it worked as expected in ev...
-
09:15 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
- After testing, the value of @AuthenticationTransformConstants@ should be set to match @CipherTransformConstants@ when...
-
01:01 PM Bug #13897 (Feedback): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
01:01 PM Bug #13368 (Feedback): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
09:13 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
- After testing, the value of @AuthenticationTransformConstants@ should apparently be set to match @CipherTransformCons...
-
01:01 PM Bug #12705 (Feedback): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
09:19 AM Bug #12705 (Confirmed): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
-
01:00 PM Bug #13878 (Feedback): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
- Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
-
09:55 AM Todo #13906 (Resolved): Update tailscale from 1.34.2 to 1.36.0
- https://tailscale.com/changelog/
-
09:13 AM Feature #13474: Don't set ListenPort in wireguard
- Good point. Will add this soon
-
09:13 AM Feature #13905 (Bogus): Introduce GUI knob for controlling ```--snat-subnet-routes``` tailscaled option
- https://github.com/pfsense/FreeBSD-ports/commit/dfb9dcf53bd8e687cda708701f07217ec5e7f1ef
-
02:14 AM Bug #13874 (Confirmed): pfBlocker -devel hanging on cron jobs
- Yes, the issue is present on the 3.1.0_19 version.
01/24/2023
-
02:01 PM Bug #13898 (Resolved): Issues saving pfBlocker Sync Targets
- I have the hosts visible in the image 1.png in the target list to sync. I click on "Save XMLRPC sync settings" and ge...
-
09:59 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
- This appears to have been broken by the change in #12948, the fix from that issue forced the P1 hash to 'None' when t...
-
09:28 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
- Moving the unrelated split tunnel part to a new issue (#13897).
-
09:30 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
- When exporting an IPsec profile for Windows which includes split tunneling, if the local P2 network is set to @0.0.0....
01/23/2023
-
11:00 AM Regression #13892 (Feedback): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
- Commit pushed and merged/picked as needed, will be in builds soon.
https://github.com/pfsense/FreeBSD-ports/commit... -
10:03 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
- When visiting status_monitoring.php, the user may get a PHP error if they have no valid OpenVPN server entries.
<p...
01/22/2023
-
06:43 PM Bug #13874: pfBlocker -devel hanging on cron jobs
- I am seeing this on 3.1.0_19
01/21/2023
-
08:10 PM Bug #13432 (Incomplete): ups driver will not start
- I'm still unable to reproduce this problem with a fresh install of 23.01 and the latest NUT package. At this point I...
-
07:59 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
- No longer able to recreate this. Not sure what caused it before, but I was testing on a fresh install of 23.01 and o...
-
07:29 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
- They are there on internal 23.01 RC snaps....
-
06:44 PM Todo #13857: Update bundled installer in OpenVPN Export Utility
- Checked on 22.05 and it appears these were merged properly. However, looking at the repos for 23.01, which is on a n...
-
06:37 PM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
- Redmine 13368 may be related, as it's in a similar vein: https://redmine.pfsense.org/issues/13368
-
06:33 PM Bug #13886: NUT Server Package
- # Installed NUT package on 23.01
# Setup usbhid with a simple UPS config and enabled the service with Local USB
# S... -
12:29 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
- Based on a project spanning multiple clients / locations / firewalls, I can certify that this is still true in CE 2.6...
-
12:28 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
- Hannes Palmquist wrote in #note-11:
> +1
>
> Agent 6.2 install does not work, same error.
Based on a project s... -
10:46 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- Lev Prokofev wrote in #note-7:
> It is still here, unfortunately.
I mean the issue was occurred after I update th... -
10:45 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- It is still here, unfortunately.
-
10:30 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- Lev Prokofev wrote in #note-5:
> I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0... -
05:03 AM Bug #13874: pfBlocker -devel hanging on cron jobs
- I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0_16
-
03:15 AM Bug #13328: Wireguard Site-to-Site broken after upgrade to 22.05
- Still the same issue
PPPOE connection might be the problem.
I found more poeple with the same problem.
Tested...
01/19/2023
-
07:47 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- Alex Sensation wrote in #note-10:
> I noticed that you created a separated ticket for the Apple profile and ECDSA ce... -
07:17 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- Apologies for the delay and the resurrection.
I have now tested my ECDSA cert with Windows 10 and it worked flawle... -
07:42 AM Bug #13873: PHP Errors on FRR Global Settings
- I can't reproduce it either, even from a clean install that has never had FRR before, but I can see why it might happ...
-
06:52 AM Bug #13873: PHP Errors on FRR Global Settings
- I couldn't reproduce this behavior on 22.05 or 23.01-RC....
-
07:37 AM Bug #13886 (Incomplete): NUT Server Package
- There isn't nearly enough information here and this site is not for support or diagnostic discussion.
For assistan... -
06:02 AM Bug #13886 (Closed): NUT Server Package
- NUT server package (2.8.0_2) wont load in 23.01 Beta
01/18/2023
-
12:59 PM Regression #13884 (Resolved): pfBlockerNG DNSBL TLD option causes reloads to take a long time
- Enabling the DNSBL option @Wildcard Blocking (TLD)@ causes DNSBL reloads to take an extremely long time:...
01/17/2023
-
01:53 PM Todo #13880: security/tailscale: update to 1.34.2_1
- Also bump security/pfSense-pkg-Tailscale PORTREVISION to signal GUI for package upgrade.
-
01:53 PM Todo #13880 (Closed): security/tailscale: update to 1.34.2_1
01/16/2023
-
11:38 PM Bug #13879: Squid blacklist definition causing issues.
- Will be a good option to have those on the GUI and the user decide if they want to use regular expression or plain te...
-
08:25 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
- This is not a bug. It expects regular expressions, not plain strings.
If that works better for you, you can make t... -
07:22 PM Bug #13879: Squid blacklist definition causing issues.
- I have change squid.inc
$options = array(
'unrestricted_hosts' => 'src',
'banned... -
07:11 PM Bug #13879 (Not a Bug): Squid blacklist definition causing issues.
- Hello.
Working with pfsense 2.7-dev for some months and is going solid, excellent work team.
Now I face a issue t... -
03:56 PM Bug #9934 (Closed): suricata update kills WAN interface
- Interfaces are now reloaded live without bringing down the interface.
-
03:54 PM Bug #10292 (Not a Bug): Suricata not respecting SID Mgmt list
-
03:54 PM Feature #10472 (Resolved): Blocked host alert table break out by timestamp and type to allow sorting by date
- This is possible in the latest version.
-
03:52 PM Bug #11780 (Rejected): Suricata package fails to prune suricata.log
-
03:45 PM Feature #10872 (Resolved): Add adjustable notification for Severity Alert
-
03:45 PM Bug #6964 (Resolved): Host OS Policy Assignment broken when using "Import" or "Aliases" buttons
-
03:45 PM Feature #12285 (Resolved): Add more EVE Logged Traffic protocols
-
03:44 PM Feature #12292 (Resolved): GeoIP look on the Alerts, Blocked and Files pages
-
03:44 PM Bug #11742 (Not a Bug): Blocking / Unblocking is not working correctly.
-
03:44 PM Bug #11742 (Closed): Blocking / Unblocking is not working correctly.
-
03:43 PM Bug #12322 (Resolved): Suricata creates invalid HOME_NET entries
-
03:43 PM Bug #11525 (Closed): pfsense 2.5.0 release version for vlan issue to suricata
- Unable to reproduce using 23.01 and latest Suricata package.
-
03:40 PM Feature #11210 (Resolved): 3rd party rulesets
-
03:08 PM Feature #12748 (Resolved): Suricata blocked page timestamp breakout to it's own sortable column
-
02:29 PM Regression #13856 (Resolved): OpenVPN Export Utility creates a broken installer package
-
02:23 PM Todo #13857 (Feedback): Update bundled installer in OpenVPN Export Utility
- Updates are merged into all the relevant branches and will appear once a build succeeds.
-
01:50 PM Todo #13857 (In Progress): Update bundled installer in OpenVPN Export Utility
- I've got the files and patch ready for this, testing it now.
-
12:53 PM Bug #13878 (Resolved): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
- When importing a profile for EAP-MSCHAPv2 for example, the @AuthenticationMethod@ is set to @Certificate@ when it sho...
-
12:50 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- Sean McBride wrote in #note-8:
> Jim, thanks for investigating. Note however that we're not using the profile wizard... -
12:48 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- Jim, thanks for investigating. Note however that we're not using the profile wizard at all. Does that mean ECDSA is ...
-
12:22 PM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
- This is not a bug in pfSense or macOS but from the way the profile wizard forms the configuration profile: The profil...
-
12:47 PM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
- I was exporting a test config to Windows which had a large number of different P1 options, and the profile generated ...
-
12:32 PM Feature #13484: IPsec Profile Wizard/Apple: Support on-demand connections in exported profile
- Would need to be set based on a toggle on user request rather than being set unconditionally.
-
11:57 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
-
11:14 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- Pull request https://github.com/pfsense/FreeBSD-ports/pull/1214 has been merged. This issue may be marked as "Resolved".
-
08:15 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- Jim Pingle wrote in #note-4:
> That should probably be something like this instead:
>
> [...]
Thanks Jim. I believe... -
07:11 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- That should probably be something like this instead:...
-
06:45 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- I honestly don't know how to cause it to happen... I don't know this stuff to even find out where in the config ovpne...
01/14/2023
-
10:02 PM Bug #13780 (Rejected): pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
- pfBlockerNG v2 will be retired and replaced with v3 on 23.01 and 2.7 and beyond.
-
07:10 PM Bug #13780: pfBlockerNG v2.1.4_28 on 23.01b Alerts-page results in error
- This is a known issue with pfBlockerNG on pfSense Plus 23.01. This issue should not be present on the -devel package...
-
07:07 PM Bug #13822 (Confirmed): haproxy bug when adding a Frontend containing accented characters in description in generated XML entities
- This issue is confirmed on pfSense Plus 23.01-BETA.
If you add an HAProxy frontend and attempt to use a special ch... -
07:03 PM Bug #13870 (Incomplete): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- I'm unable to reproduce any bad interactions between Suricata and OpenVPN. I created an OpenVPN interface, enabled i...
-
06:52 AM Bug #13870: pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- This code is part of a function added by Viktor Gurov in the recent past. The purpose of the function is to collect a...
-
05:55 AM Bug #13870 (Resolved): pfSense-pkg-suricata-6.0.8_5 error in /usr/local/pkg/suricata/suricata.inc(4261)
- ...
-
04:58 PM Bug #13874: pfBlocker -devel hanging on cron jobs
- The PHP errors related to the widget provided by the customer were:...
-
04:54 PM Bug #13874 (Resolved): pfBlocker -devel hanging on cron jobs
- Build:
23.01-BETA (amd64)
built on Fri Jan 06 06:04:43 UTC 2023
FreeBSD 14.0-CURRENT
When pfBlocker is told t... -
03:37 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
- When navigating to the Global Settings tab under Services --> FRR Global/Zebra --> Global Settings, the following err...
Also available in: Atom