Project

General

Profile

Activity

From 01/17/2023 to 02/15/2023

02/15/2023

08:26 PM Regression #13950: PHP error with pfBlockerNG
Another report after upgrading to 23.01:... Marcos M
08:25 PM Regression #13960 (Resolved): PHP Fatal error - pfblockerng.widget.php
Upgrading to new 23.01 release today and was greeted with unusable WebConfigurator due to php error on Pfblocker dash... RED SKULL
07:10 PM Regression #13958: Snort exits with signal 10 on arm32
Signal 10 is the "unaligned memory access" fault. My first suspicion is an update of the llvm compiler in 23.01 has r... Bill Meeks
06:09 PM Regression #13958 (Resolved): Snort exits with signal 10 on arm32
In 23.01 Snort core dumps with signal 10:... Steve Wheeler
03:01 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
The final fix for this issue is contained in pull request #1226 posted for review and merge. The request may be viewe... Bill Meeks
02:58 PM Feature #13955: Add NETMAP_V14 build option knob to Suricata binary makefile options in file ./tools/conf/pfPorts/make.conf
The required Pull Request for this feature has been posted for review and merge. The request is available here: https... Bill Meeks
02:56 PM Bug #13925: Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
The pull request containing this fix has been posted for review and merge. The pull request can be viewed here: https... Bill Meeks
09:10 AM Feature #13957 (Rejected): BandwidthD
For any of that to be possible the actual developers of bandwidthd would have to add those functions first, which at ... Jim Pingle
09:01 AM Feature #13957 (Rejected): BandwidthD
The current application available through pfsense doesn't allow for monitoring of multiple interfaces and data collec... Mike Moore

02/14/2023

10:07 PM Feature #13955: Add NETMAP_V14 build option knob to Suricata binary makefile options in file ./tools/conf/pfPorts/make.conf
I will be submitting the pull request to accomplish this request as soon as pfSense Plus 23.01 exits RC status and go... Bill Meeks
10:01 PM Feature #13955 (Resolved): Add NETMAP_V14 build option knob to Suricata binary makefile options in file ./tools/conf/pfPorts/make.conf
Suricata 6.0.9 and later supports a new Makefile build option called NETMAP_V14. This enables a binary build using th... Bill Meeks
10:06 PM Bug #13925: Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
Thanks Marcos. I have already created the necessary fix and posted the commit to my personal FreeBSD-ports repo. I wi... Bill Meeks
07:06 PM Bug #13925: Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
Here's the diff submitted previously FWIW:... Marcos M
07:02 PM Bug #13925: Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
I have taken responsibility for correcting this issue in the Suricata GUI package. I have a PR ready for submission s... Bill Meeks

02/13/2023

03:52 PM Feature #12711: Add InfluxDB V2 support
Is it possible to get some TLC on this? I use Telegraf and InfluxDB V2 for my metrics from my homelab, so this is a b... Per-Arne Hellarvik
11:00 AM Regression #13947 (Feedback): Remove 4096GB quota limit
Validation removed in ddebe728, plumbed through plus-devel and 23.01 Reid Linnemann
10:23 AM Bug #13951: pfblockerNG does not allow for vlan description changes
A workaround i have found is to first disable the interface under Interfaces/Interface Assignments / Select an interf... Mike Moore
10:21 AM Bug #13951 (Resolved): pfblockerNG does not allow for vlan description changes
After a few weeks of troubleshooting within the forums, the problem has been traced directly to pfblocker. If install... Mike Moore

02/12/2023

09:00 PM Regression #13950 (Resolved): PHP error with pfBlockerNG
After restoring a config backup which contains pfBlockerNG-devel to a fresh install of 23.01, a crash/alert shows the... Marcos M

02/11/2023

12:03 PM Regression #13947: Remove 4096GB quota limit
As an observation, you can avoid the overflow consequences of premature logout due to the 32 bit unsigned integer ove... Dale Harron

02/09/2023

07:40 AM Bug #13874 (Resolved): pfBlocker -devel hanging on cron jobs
Thanks for testing and following up!
I'm going to mark this one resolved as there was some overlap with #13926 and...
Jim Pingle
07:39 AM Bug #13926 (Resolved): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Jim Pingle
05:39 AM Bug #13936 (Confirmed): PHP error from RRD Graphs when attempting a query a newly created empty database
I replicated the issue. ... Danilo Zrenjanin

02/08/2023

06:38 PM Bug #13874: pfBlocker -devel hanging on cron jobs
Work has had me tied up so I haven't been able to do review the information Jim was kind enough to provide. I freed ... Allen C
03:36 PM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
This change fixed two issues I have seen with pfB since moving to 23.01: 1) slow MaxMind downloads; 2) slow block lis... Glenn Hall
11:21 AM Regression #13947 (Feedback): Remove 4096GB quota limit
The 4096GB quota limit introduced to prevent pfSense-Max-Total-Octets overflowing uint32 for captive portal artificia... Reid Linnemann
08:37 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
Tested against the IPsec Profile Wizard pkg v. 1.1
It looks fine.
*Split Tunnel Routes* part is omitted if the loca...
Danilo Zrenjanin
07:14 AM Feature #13930: Hysteria Proxy/Relay
help doc link: https://hysteria.network/docs/advanced-usage/ yon Liu
04:41 AM Feature #13930: Hysteria Proxy/Relay
It supports using ACME to obtain encryption certificates or self-signed certificates can be used. yon Liu
04:40 AM Feature #13930: Hysteria Proxy/Relay
After I have tested and compared, it is designed to include encryption to bypass monitoring. After the network protoc... yon Liu
04:33 AM Feature #13930: Hysteria Proxy/Relay
No, it has encryption, and it's specifically designed to bypass internet surveillance in authoritarian countries. Cer... yon Liu

02/07/2023

02:19 PM Todo #13255: Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
That is part of the plan, see #13917 Jim Pingle
01:06 PM Todo #13255: Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
Jim Pingle wrote:
> Currently when crafting a PKCS#12 archive the OpenVPN Client Export package does not set a speci...
Thomas Ward
09:33 AM Bug #10646 (Resolved): Reinstall package process stalls at pfBlockerNG when restoring a config
This has been working since the fix went in. Jim Pingle
09:33 AM Bug #11398 (Resolved): pfBlocker upgrade hangs forever
This has been working since the fix went in. Jim Pingle
08:13 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
Jim Pingle

02/06/2023

02:38 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
The fix for this issue requires an update to the custom blocking plugin compiled into the Suricata binary on pfSense.... Bill Meeks
12:33 PM Bug #13936 (Resolved): PHP error from RRD Graphs when attempting a query a newly created empty database
Attempting to view an RRD graph of a new database that doesn't yet have data results in a PHP error.
Easiest way t...
Jim Pingle
07:48 AM Feature #13575: Update to frr 9.0.1
When this happens it's best to just move to 8.x and not keep two versions around.
Jim Pingle
07:46 AM Feature #13931 (Duplicate): Upgrade FRR from 7.x to 8.x
Duplicate of #13575 Jim Pingle
07:34 AM Feature #13930: Hysteria Proxy/Relay
It's no surprise that it's faster than WireGuard as it has no encryption. It's a proxy/relay setup, not an encrypted ... Jim Pingle

02/05/2023

09:18 AM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Bill Meeks wrote in #note-7:
> Just to be clear on this PHP error. I think you are getting that because you made an ...
Greger Blennerud
07:55 AM Feature #13930: Hysteria Proxy/Relay
I have notified the developer of this program, and the developer has agreed to promote this program. And it is recomm... yon Liu

02/04/2023

09:36 PM Bug #13932 (Not a Bug): Deprecation Message for Arpwatch
I checked the code. We are already using -w instead of -m. We could remove the pkg-message from our net-mgmt/arpwatch. Christian McDonald
06:12 PM Bug #13932 (Not a Bug): Deprecation Message for Arpwatch
During install, the following message about deprecated flags is mentioned:
_
The -m flag is deprecated. If you are ...
Kris Phillips
02:21 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Greger Blennerud wrote in #note-6:
> The actual list found in /usr/local/etc/suricata/suricata_28603_vtnet1 never cha...
Bill Meeks
04:08 AM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
I decided to do some more testing and discovered some wierd issues with the passlist.
First of all, I get a discrep...
Greger Blennerud
10:59 AM Feature #13931 (Duplicate): Upgrade FRR from 7.x to 8.x
The FRR latest version has fixed many problems. Including the bug fixes submitted by me. And added many new features.... yon Liu
10:55 AM Feature #13930 (New): Hysteria Proxy/Relay
Please consider adding this function. I have tested that its actual network speed is 5-10 times faster than wireguard... yon Liu
10:05 AM Bug #13925 (Pull Request Review): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/328 Christopher Cope
08:45 AM Bug #13925 (Confirmed): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
I'm able to reproduce this on... Christopher Cope

02/03/2023

04:33 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Looking into this deeper, I suspect there is potentially an issue with the custom blocking plugin used with the Suric... Bill Meeks
11:07 AM Regression #13884: pfBlockerNG DNSBL TLD option causes reloads to take a long time
Related forum thread: https://forum.netgate.com/topic/177504/v-3-2-0-with-pfsense-23-01-rc-20230202 Jim Pingle
10:40 AM Bug #13874: pfBlocker -devel hanging on cron jobs
There may be two distinct issues there: One with downloads, and one with processing.
If you find it's hanging up on ...
Jim Pingle
10:10 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Ran into this issue on pfBlockerNG-devel v3.2.0 a few days ago. Have been deploying dailies, currently on v2.7.0.a.2... Allen C
10:08 AM Bug #13926 (Feedback): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
I merged the changes to the pfBlockerNG cURL defaults, so the next build will include them. Jim Pingle
09:48 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Steve Wilson wrote in #note-2:
> Jim,
>
> With your patch applied the download completes in about 5 seconds, so i...
Jim Pingle
09:44 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Jim,
With your patch applied the download completes in about 5 seconds, so it solves the issue. But note that the...
Steve Wilson
09:24 AM Bug #13926: pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
If you can easily reproduce this, try the following patch (path strip=1):... Jim Pingle
04:37 AM Bug #13926 (Resolved): pfBlockerNG-devel 3.2.0 - Slow MaxMind Database Downloads under PHP 8.1
Prior to the update to PHP 8.1, downloads of the MaxMind database would take approximately 4 seconds. After the updat... Steve Wilson
08:11 AM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
PR merged, thanks! Jim Pingle
08:11 AM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
PR merged, thanks! Jim Pingle
08:11 AM Bug #13839 (Resolved): Suricata version updates take a long time
PR merged, thanks! Jim Pingle
01:54 AM Bug #13925 (Resolved): Suricata 6.0.8_7 - PHP Fatal Errror on IP Rep Tab
Clicking on the IP Rep tab when editing an existing interface throws a PHP error.
Steps to reproduce:
1. Naviga...
Steve Wilson

02/02/2023

07:26 PM Bug #13922: Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free... Bill Meeks
07:04 PM Bug #13922 (Resolved): Snort - rules package downloads may hang for an extended period if remote site offers an HTTP/2 connection
Changes in cURL function behavior in PHP 8.1 make the Snort package vulnerable to a hang condition when downloading r... Bill Meeks
07:26 PM Bug #13923: Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
This issue is resolved by pull request #1225 posted against the DEVEL snapshots here: https://github.com/pfsense/Free... Bill Meeks
07:10 PM Bug #13923 (Resolved): Snort - fails to clean-up all files when uninstalling and also creates an unnecessary barnyard2 logging subdirectory.
The Snort package fails to clean up all it's _*.rules_ files when uninstalling. It also creates a Barnyard2 logging s... Bill Meeks
06:27 PM Bug #13839: Suricata version updates take a long time
Jim Pingle wrote in #note-6:
> To fix some issues in Dynamic DNS where it didn't want to close connections (it hung ...
Bill Meeks
06:12 PM Bug #13839: Suricata version updates take a long time
The pull request to correct this issue has been submitted against the snapshots DEVEL branch here: https://github.com... Bill Meeks
05:19 PM Bug #13839: Suricata version updates take a long time
To fix some issues in Dynamic DNS where it didn't want to close connections (it hung pretty much indefinitely) we end... Jim Pingle
05:07 PM Bug #13839: Suricata version updates take a long time
After some digging around, I am pretty sure I found the problem here. It is related to HTTP/2 support in cURL. I can ... Bill Meeks
05:24 PM Bug #13566 (Resolved): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
Tested on... Christopher Cope
04:31 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Christian McDonald wrote in #note-3:
> Hi,
>
> I'll have a look. Might not be this week, but definitely next week...
Bill Meeks
02:23 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
Hi,
I'll have a look. Might not be this week, but definitely next week.
Christian McDonald
01:43 PM Bug #13920: 23.01RC - Suricata stops working after Wireguard installed
I might need some assistance from the Netgate wireguard guru on this one. I don't have a functioning wireguard packag... Bill Meeks
10:38 AM Bug #13920 (Resolved): 23.01RC - Suricata stops working after Wireguard installed
Upgraded to 23.01RC from 22.05 without any packages installed. Current base system shown as 23.01.r.20230202.0019
...
Greger Blennerud
10:47 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
PR merged Jim Pingle
08:34 AM Bug #13919: Typo in suricata package: cpnfig_set_path()
This issue has been corrected in pull request 1223 posted here: https://github.com/pfsense/FreeBSD-ports/pull/1223.
...
Bill Meeks
05:15 AM Bug #13919 (Resolved): Typo in suricata package: cpnfig_set_path()
FreeBSD 14.0-CURRENT #0 plus-RELENG_23_01-n256014-9cf2a68c5e5: Thu Feb 2 00:48:35 UTC 2023 root@freebsd:/var/jen... Brian Macy

02/01/2023

07:59 AM Bug #10436: softflowd no longer sends flow data after upgrade (v0.9.9_1 -> v1.0.0)
Can someone test this with 23.01 snaps on the SG-3100 ?
Marcelo Cury

01/30/2023

10:01 AM Todo #13917 (Resolved): OpenVPN Client Export: Integrate OpenVPN 2.6.0
We need to add OpenVPN 2.6.0 to the export package but doing so has a few caveats:
* OpenSSL 3.0 which is used in ...
Jim Pingle

01/28/2023

09:44 PM Bug #13566: Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
I'm assuming this will have to wait for the RC release, as I don't see this reflected in the BETA repos. Both versio... Kris Phillips
05:49 AM Bug #12808: Wireguard Gateways disabled when Wireguard Service is Manually Restarted
I'm still having the same issue. The link below has recently been update and would suggest that it's an issue using P... B P
02:06 AM Bug #13441: FRR fails to start with route map on "sequence 0" in configuration
The same behavior on frr 1.2_3
frr fail to start
_Jan 28 11:02:02 watchfrr 97266 [EC 268435457] bgpd state...
Lev Prokofev

01/27/2023

03:58 PM Bug #13566 (Feedback): Non-devel pfBlocker Package Broken in 2.7 CE with PHP 8.1
@security/pfSense-pkg-pfBlockerNG-devel@ has been copied to @security/pfSense-pkg-pfBlockerNG@.
The versions of bo...
Christian McDonald
10:52 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
I also closed out #13877 and #13368 since they were all related. Testing one means the others are also working.
Jim Pingle
10:50 AM Bug #12948 (Resolved): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Jim Pingle
10:05 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Tested against:... Danilo Zrenjanin
10:51 AM Bug #13368 (Resolved): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Jim Pingle
10:51 AM Bug #13877 (Resolved): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Jim Pingle

01/26/2023

11:59 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
PR merged. Jim Pingle
09:01 AM Bug #13910: Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
Pull request 1221 has been submitted to correct this issue: https://github.com/pfsense/FreeBSD-ports/pull/1221.
Th...
Bill Meeks
08:41 AM Bug #13910 (Resolved): Typo in Snort package GUI code may generate an invalid parameter value in snort.conf when Performance Stats logging is enabled
There is a typo on line 253 of /usr/local/pkg/snort/snort_generate_conf. This can result in the creation of an invali... Bill Meeks

01/25/2023

02:39 PM Bug #13690 (Closed): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
The updated description and link appear as expected in the package list now.
Jim Pingle
01:01 PM Bug #13690 (Feedback): IPsec Profile Wizard: Update package description and link in ``pkg-descr``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #12948 (Feedback): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:18 AM Bug #12948: IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
The code added here was incorrect, see #13368 and #13877 Jim Pingle
09:17 AM Bug #12948 (New): IPsec Profile Wizard/Windows: Script generated for IKEv2 VPN using GCM does not use an optimal Phase 2 hash configuration
Jim Pingle
01:01 PM Bug #13877 (Feedback): IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:47 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Tested on Windows 10 and Windows 11 against a VPN with and without a P2 hash selected and it worked as expected in ev... Jim Pingle
09:15 AM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
After testing, the value of @AuthenticationTransformConstants@ should be set to match @CipherTransformConstants@ when... Jim Pingle
01:01 PM Bug #13897 (Feedback): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
01:01 PM Bug #13368 (Feedback): IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:13 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
After testing, the value of @AuthenticationTransformConstants@ should apparently be set to match @CipherTransformCons... Jim Pingle
01:01 PM Bug #12705 (Feedback): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:19 AM Bug #12705 (Confirmed): IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Jim Pingle
01:00 PM Bug #13878 (Feedback): IPsec Profile Wizard/Apple: Generated profile does not contain the correct ``AuthenticationMethod`` for IKEv2 EAP configurations
Fixed in IPsec Profile Wizard pkg v. 1.1, which has been committed and will be available with the next build.
Jim Pingle
09:55 AM Todo #13906 (Resolved): Update tailscale from 1.34.2 to 1.36.0
https://tailscale.com/changelog/ Christian McDonald
09:13 AM Feature #13474: Don't set ListenPort in wireguard
Good point. Will add this soon Christian McDonald
09:13 AM Feature #13905 (Bogus): Introduce GUI knob for controlling ```--snat-subnet-routes``` tailscaled option
https://github.com/pfsense/FreeBSD-ports/commit/dfb9dcf53bd8e687cda708701f07217ec5e7f1ef Christian McDonald
02:14 AM Bug #13874 (Confirmed): pfBlocker -devel hanging on cron jobs
Yes, the issue is present on the 3.1.0_19 version. Danilo Zrenjanin

01/24/2023

02:01 PM Bug #13898 (Resolved): Issues saving pfBlocker Sync Targets
I have the hosts visible in the image 1.png in the target list to sync. I click on "Save XMLRPC sync settings" and ge... Tom Huerlimann
09:59 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
This appears to have been broken by the change in #12948, the fix from that issue forced the P1 hash to 'None' when t... Jim Pingle
09:28 AM Bug #13368: IPsec Profile Wizard/Windows: Cannot generate a script for IKEv2 VPN using GCM ciphers when mobile P2 has no hash algorithms selected
Moving the unrelated split tunnel part to a new issue (#13897). Jim Pingle
09:30 AM Bug #13897 (Resolved): IPsec Profile Wizard/Windows: Generated script adds an invalid route command for ``0.0.0.0/0``
When exporting an IPsec profile for Windows which includes split tunneling, if the local P2 network is set to @0.0.0.... Jim Pingle

01/23/2023

11:00 AM Regression #13892 (Feedback): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
Commit pushed and merged/picked as needed, will be in builds soon.
https://github.com/pfsense/FreeBSD-ports/commit...
Jim Pingle
10:03 AM Regression #13892 (Resolved): PHP error from ``status_monitoring.php`` with empty OpenVPN servers
When visiting status_monitoring.php, the user may get a PHP error if they have no valid OpenVPN server entries.
<p...
Jim Pingle

01/22/2023

06:43 PM Bug #13874: pfBlocker -devel hanging on cron jobs
I am seeing this on 3.1.0_19 Michael Kellogg

01/21/2023

08:10 PM Bug #13432 (Incomplete): ups driver will not start
I'm still unable to reproduce this problem with a fresh install of 23.01 and the latest NUT package. At this point I... Kris Phillips
07:59 PM Bug #13873 (Closed): PHP Errors on FRR Global Settings
No longer able to recreate this. Not sure what caused it before, but I was testing on a fresh install of 23.01 and o... Kris Phillips
07:29 PM Todo #13857 (Resolved): Update bundled installer in OpenVPN Export Utility
They are there on internal 23.01 RC snaps.... Jim Pingle
06:44 PM Todo #13857: Update bundled installer in OpenVPN Export Utility
Checked on 22.05 and it appears these were merged properly. However, looking at the repos for 23.01, which is on a n... Kris Phillips
06:37 PM Bug #13877: IPsec Profile Wizard/Windows: IKEv2 VPN using GCM configured by the generated script fails to connect with "The IPsec cipher transform is not compatible with the policy"
Redmine 13368 may be related, as it's in a similar vein: https://redmine.pfsense.org/issues/13368
Kris Phillips
06:33 PM Bug #13886: NUT Server Package
# Installed NUT package on 23.01
# Setup usbhid with a simple UPS config and enabled the service with Local USB
# S...
Kris Phillips
12:29 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Based on a project spanning multiple clients / locations / firewalls, I can certify that this is still true in CE 2.6... Jonathan Edman
12:28 PM Feature #13361: Add Zabbix 6.2 (agent and proxy) packages
Hannes Palmquist wrote in #note-11:
> +1
>
> Agent 6.2 install does not work, same error.
Based on a project s...
Jonathan Edman
10:46 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-7:
> It is still here, unfortunately.
I mean the issue was occurred after I update th...
Lev Prokofev
10:45 AM Bug #13874: pfBlocker -devel hanging on cron jobs
It is still here, unfortunately. Lev Prokofev
10:30 AM Bug #13874: pfBlocker -devel hanging on cron jobs
Lev Prokofev wrote in #note-5:
> I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0...
Jim Pingle
05:03 AM Bug #13874: pfBlocker -devel hanging on cron jobs
I can confirm this behavior on 22.05 after updating the pfBlocker package to v3.1.0_16 Lev Prokofev
03:15 AM Bug #13328: Wireguard Site-to-Site broken after upgrade to 22.05
Still the same issue
PPPOE connection might be the problem.
I found more poeple with the same problem.
Tested...
Sebastian Schmid

01/19/2023

07:47 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Alex Sensation wrote in #note-10:
> I noticed that you created a separated ticket for the Apple profile and ECDSA ce...
Jim Pingle
07:17 AM Bug #12705: IPsec Profile Wizard/Apple: IKEv2 VPN with ECDSA server certificate does not connect using generated profile
Apologies for the delay and the resurrection.
I have now tested my ECDSA cert with Windows 10 and it worked flawle...
Alex Sensation
07:42 AM Bug #13873: PHP Errors on FRR Global Settings
I can't reproduce it either, even from a clean install that has never had FRR before, but I can see why it might happ... Jim Pingle
06:52 AM Bug #13873: PHP Errors on FRR Global Settings
I couldn't reproduce this behavior on 22.05 or 23.01-RC.... Danilo Zrenjanin
07:37 AM Bug #13886 (Incomplete): NUT Server Package
There isn't nearly enough information here and this site is not for support or diagnostic discussion.
For assistan...
Jim Pingle
06:02 AM Bug #13886 (Closed): NUT Server Package
NUT server package (2.8.0_2) wont load in 23.01 Beta Anonymous

01/18/2023

12:59 PM Regression #13884 (Resolved): pfBlockerNG DNSBL TLD option causes reloads to take a long time
Enabling the DNSBL option @Wildcard Blocking (TLD)@ causes DNSBL reloads to take an extremely long time:... Marcos M

01/17/2023

01:53 PM Todo #13880: security/tailscale: update to 1.34.2_1
Also bump security/pfSense-pkg-Tailscale PORTREVISION to signal GUI for package upgrade. Christian McDonald
01:53 PM Todo #13880 (Closed): security/tailscale: update to 1.34.2_1
Christian McDonald
 

Also available in: Atom