Project

General

Profile

Activity

From 03/28/2023 to 04/26/2023

04/26/2023

12:50 PM Bug #14315 (Resolved): Routes are not exposed on Tailscale when an empty route entry exists in the GUI
In the Tailscale package settings, if an empty entry exists for @Advertised Routes@, no routes will be exposed to the... Marcos M
07:32 AM Feature #14311 (Rejected): Widget for System -> Patches
Given the personal and custom nature of patches this is not viable. Not everyone will apply every patch, since not ev... Jim Pingle
06:13 AM Feature #14314 (Pull Request Review): Keep DDNS entries on config change
Each time the BIND config is changed, all DDNS entries in all master zones are lost because the zone.db is overwritte... Andreas Pross

04/25/2023

05:39 PM Feature #14311 (Rejected): Widget for System -> Patches
I have the System_Patches package installed. There is no notification of updates.
It would be nice to have a notifi...
William Liporace
12:45 PM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
Correction, I applied the patch at https://redmine.pfsense.org/issues/14230 and it didn't help. I know it's a differ... Loh Phat

04/24/2023

04:58 PM Feature #10818 (Feedback): UDP Broadcast Relay
The package is now available for dev snapshots (currently 23.05/2.7). Marcos M
07:16 AM Bug #14299: pfBlockerNG does not honor the cURL source interface setting for DNSBL lists
This morning I noticed the following:... Charles Hamilton

04/23/2023

12:58 PM Bug #14179: FreeRadius is active but in an inoperable state, switches to a generated freeradius-temp certificate upon restart
Hi Chris,
thanks for looking into this.
Yes I upgraded from 2.6.0 and the original version was probably somethi...
name name
10:24 AM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
Related https://redmine.pfsense.org/issues/13817 Marcos M
10:02 AM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
Looks like a pfSense PHP 8 code issue.
{main} thrown in /etc/inc/config.lib.inc on line 928
PHP ERROR: Type: 1, Fi...
BBcan177 .
08:50 AM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
Note that System Patches 2.2.1 is installed with all recommended patches applied. Loh Phat
08:36 AM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
Error when removing 3.2.0_4:... Loh Phat

04/22/2023

09:48 PM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
If you update to the latest pfBlockerNG and then uninstall it with Keep Settings unchecked, does this still leave orp... Kris Phillips
09:07 PM Bug #14179: FreeRadius is active but in an inoperable state, switches to a generated freeradius-temp certificate upon restart
Steps taken to reproduce:
1. Install FreeRadius package into a virtual machine of 23.01
2. Configure FreeRadius with...
Chris W
05:33 PM Bug #13632: tailscale does not survive reboot on pfsense with ram disk in use
tailscale v0.1.3 on 23.05.a.20230421.0022 in the package's settings provides a configurable field for state directory... Jordan G
04:02 AM Bug #13632: tailscale does not survive reboot on pfsense with ram disk in use
The latest Tailscale version under available packages is 0.1.2.
v0.1.3 is not listed yet. Please check.
Danilo Zrenjanin
05:38 AM Bug #13936 (Resolved): PHP error from RRD Graphs when attempting a query a newly created empty database
Tested against:... Danilo Zrenjanin
04:38 AM Bug #10900 (Not a Bug): /packages/backup/backup.php?a=download&t=backup HTTP 504, or Sends PHP Error Message as ASCII/Text file Named pfsense.bak.tgz
The References.7z file initially included indicates that the issue was with allocated PHP memory. ... Danilo Zrenjanin
04:17 AM Bug #10936: both haproxy/haproxy-devel non-existent option lb-agent-chk
haproxy 0.61_9
Still has the lb-agent-chk listed as the check method. The needs to be removed.
Danilo Zrenjanin
01:37 AM Bug #13985: Telegraf error After Update PFSense to 23.01
@aleksei prokofiev, what dependent Telefraf Package have you? Marijan Kruljac
01:18 AM Bug #13985: Telegraf error After Update PFSense to 23.01
Can't reproduce,
Installed 2.6 CE
Installed and configure Telegraf with influx DB
Upgraded to 23.01
no errors oc...
Lev Prokofev

04/21/2023

04:20 PM Bug #14299: pfBlockerNG does not honor the cURL source interface setting for DNSBL lists
More details:
https://redmine.pfsense.org/issues/12882#change-59903
The cURL interface can be specified via the...
Charles Hamilton
04:02 PM Bug #14299: pfBlockerNG does not honor the cURL source interface setting for DNSBL lists
Pull request: https://github.com/pfsense/FreeBSD-ports/pull/1251 Charles Hamilton
04:00 PM Bug #14299 (Resolved): pfBlockerNG does not honor the cURL source interface setting for DNSBL lists
Pull request to fix the problem is on its way. Charles Hamilton
06:38 AM Bug #13985: Telegraf error After Update PFSense to 23.01
I've tested on
23.01-RELEASE (amd64)
built on Fri Feb 10 20:06:33 UTC 2023
FreeBSD 14.0-CURRENT
I can't repro...
aleksei prokofiev

04/20/2023

11:27 AM Bug #13985: Telegraf error After Update PFSense to 23.01
New knowledge, have installed the community version virtually.
The Telegraf Package Dependencies are different.
Comm...
Marijan Kruljac

04/18/2023

03:57 PM Bug #13632: tailscale does not survive reboot on pfsense with ram disk in use
And as promised:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=270921
Christian McDonald
03:39 PM Bug #13632 (Feedback): tailscale does not survive reboot on pfsense with ram disk in use
@v0.1.3@ includes migration code that will move the state file from @/var/db/tailscale/tailscale.state@ to a location... Christian McDonald
11:00 AM Bug #13632 (In Progress): tailscale does not survive reboot on pfsense with ram disk in use
Looking at this.
First I need to expose the --statedir tailscaled option to the rc script (and upstream it). I'm t...
Christian McDonald
12:56 PM Bug #14287 (Resolved): pfBlockerNG does not uninstall cleanly when using RAM disks
UNchecking "keep config" and then trying to remove the 3.2.0_3 package results in PHP error.
Other user reports th...
Loh Phat

04/17/2023

06:55 PM Bug #11054: Check Client Certificate CN not working as described
pfSense CE @2.6.0@
FreeRADIUS package version @0.15.7_33@
As of April 2023, I was able to recreate this issue on acc...
Greg Maub
02:04 PM Bug #14284 (Incomplete): Wen changing frontend type, there will be invissible leftovers, disturbing defining the new type
During my trails to setup HA-proxy, I irregularly met a situation where I did not know which frontend type to use.
S...
Louis B

04/16/2023

11:47 AM Bug #14153: default whitelist is not created
I was using pfBlockerNG-devel 3.2.0_3 but upgraded to pfBlockerNG-devel 3.2.0_4 and then checked my findings.
h2. ...
Jon Brown
10:20 AM Bug #14179: FreeRadius is active but in an inoperable state, switches to a generated freeradius-temp certificate upon restart
So after reading through the source code I found something that I thought was strange to even exist:... name name
09:46 AM Bug #14179: FreeRadius is active but in an inoperable state, switches to a generated freeradius-temp certificate upon restart
Okay, now I've run into it again and discovered the following:
If the firewall has internet connectivity during co...
name name
04:07 AM Feature #14196: permitted firewall rules - additional text

* *Based on the text above this line, this is simply moving the rules from the one interface to a floating rule for...
Jon Brown
03:17 AM Bug #11797: Traffic Totals lost upon reboot when using a ramdisk for /var and /tmp
I'm experiencing this as well in pfSense @2.6.0 CE@ and Status_Traffic_Totals @2.3.2_2@ as of April 2023. Upon reboo... Greg Maub

04/15/2023

10:30 PM Bug #14021: Squid ClamAV showing bytecode errors for version 334
This has resolved on its own and updates again. Jonathan Lee
09:15 PM Bug #10692: PIMD starts twice at boot
double starting again with pfSense Plus 23.05.a.20230414.0600 and PIMD 0.0.3_6, at least it's self aware... Jordan G
09:14 PM Feature #14196 (Incomplete): permitted firewall rules - additional text
Based on the text above this line, this is simply moving the rules from the one interface to a floating rule for mult... Kris Phillips
09:12 PM Bug #14153: default whitelist is not created
What version of pfBlocker are you using?
I'm unable to reproduce this with a fresh install of pfBlockerNG-devel 3....
Chris W
09:11 PM Bug #14230: PHP error with pfBlockerNG
I'm not seeing any PHP errors in 3.2.0_4 of pfBlockerNG. Was there any particular steps to reproduce this problem? Kris Phillips
07:56 PM Bug #14228 (Resolved): pfBlockerNG might not support new Maxmind license keys
Chris W
07:56 PM Bug #14228: pfBlockerNG might not support new Maxmind license keys
Closing this out since 3.2.0_4 is now available in System > Package Manager. Chris W
06:05 PM Bug #14275: Deleting a route map that is assigned to an active neighbor causes crash

it shows an error if the route map was deleted..
the configuration shows the route map is not deleted while it w...
Alhusein Zawi
11:36 AM Bug #14218 (Resolved): Deleting a shellcmd entry results in a PHP error and crash report
Tested against:... Danilo Zrenjanin
09:31 AM Bug #11797 (Confirmed): Traffic Totals lost upon reboot when using a ramdisk for /var and /tmp
Steve Wheeler

04/14/2023

06:57 PM Bug #13654: Wireguard does not fail back failover WAN setup.
Still has this problem. Are there any progress on this? Frode Martin
03:17 PM Bug #14075 (Not a Bug): Using the ``Transparent ClientIP`` option in HAproxy results in kernel panics
Christian McDonald
03:15 PM Bug #14058 (Resolved): Update vendor=on triggers installation failure
Christian McDonald

04/13/2023

06:36 AM Bug #14275 (Resolved): Deleting a route map that is assigned to an active neighbor causes crash
Steps to reproduce:
2.7.0.a.20230405.0015 / FRR 7.5.1.
1) Establish BGP session to a neighbor and announce a p...
M Felden

04/12/2023

07:43 AM Bug #14258: HA-proxy, IPV6-address in combination with portnumber => fatal
Attached a picture from another situation where the IPV6-addresses are not properly extracted / handover from the GUI... Louis B
07:21 AM Bug #13969 (Resolved): Status_Monitoring ignores NAT states
Tested on 23.05-DEV (built on Fri Apr 07 01:20:44 UTC 2023) and on 2.7-DEV (built on Wed Apr 12 06:05:24 UTC 2023)
...
Azamat Khakimyanov
05:44 AM Bug #14199: ACME - Issue with corrupted cert
Attached PHP error log Juan Francisco Rodriguez Garcia

04/11/2023

10:45 PM Bug #14271 (Not a Bug): WireGuard does not work
Just for future reference these types of issues are best addressed first on the Forums before opening a Redmine issue... Christian McDonald
10:36 PM Bug #14271: WireGuard does not work
It's working, thanks! hao zhang
10:20 PM Bug #14271: WireGuard does not work
Did you enable WireGuard on the settings page? Christian McDonald
09:52 PM Bug #14271: WireGuard does not work
WireGuard0.1.6_2
!clipboard-202304121052-budas.png!
hao zhang
09:51 PM Bug #14271 (Not a Bug): WireGuard does not work
My WireGuard does not have a start/restart button after installation.
After going to the WireGuard configuration pag...
hao zhang
11:51 AM Bug #14096 (Resolved): Status_Traffic_Totals does not work on snapshots due to sqlite change
This apparently was fixed upstream and we brought it in during a recent ports merge. It's working on current snapshot... Jim Pingle

04/10/2023

02:58 PM Bug #14228: pfBlockerNG might not support new Maxmind license keys
This was fixed in the 3.2.0_4 which is live. Artur Hawkwing
08:59 AM Todo #14194: Better colours for alerts
Sergei Shablovsky wrote in #note-2:
> Jim Pingle wrote in #note-1:
> > Green and Red are also not great choices bec...
Jim Pingle
07:34 AM Bug #14218 (Feedback): Deleting a shellcmd entry results in a PHP error and crash report
MR merged Jim Pingle

04/09/2023

04:22 PM Feature #13195: Dedicated website for Feed mangement - Community Driven
Jon Brown wrote in #note-1:
> or the website could be website where end users (me and others) can add feeds and repo...
Sergei Shablovsky
04:03 PM Todo #14194: Better colours for alerts
Jim Pingle wrote in #note-1:
> Green and Red are also not great choices because some people are red/green color blin...
Sergei Shablovsky
01:27 PM Bug #14258 (New): HA-proxy, IPV6-address in combination with portnumber => fatal
I am setting up HA-proxy using IPV4 and IPV6. When trying to define an IPV6 frontend, there is a prolbem
When e.g....
Louis B
04:11 AM Bug #14228: pfBlockerNG might not support new Maxmind license keys
I can confirm this issue.
I used a workaround on Reddit and it worked.
https://www.reddit.com/r/pfBlockerNG/comment...
aleksei prokofiev

04/08/2023

08:36 PM Todo #14073 (Confirmed): Shalla block list is offline but still available in pfBlocker
Confirmed in 23.01 and 2.7:
UPDATE PROCESS START [ v3.2.0_4 ] [ 04/9/23 01:34:56 ]
===[ DNSBL Process ]=====...
Kris Phillips
08:28 PM Bug #14021 (Incomplete): Squid ClamAV showing bytecode errors for version 334
Unable to confirm this. Here are my logs:
ClamAV - freshclam Logs
Message
bytecode.cvd database is up-to-date (v...
Kris Phillips
08:25 PM Bug #14108 (Confirmed): Antivirus Bases showing outdated main.cvd with a version dated year 2021
This doesn't appear to be a bug with the file not being downloaded. The file at http://database.clamav.net/main.cvd ... Kris Phillips
08:09 PM Bug #14228 (Confirmed): pfBlockerNG might not support new Maxmind license keys
I can confirm this behavior in 3.2.0_3 on 23.01 of pfSense Plus. Kris Phillips

04/07/2023

06:02 PM Regression #14024: PHP error in HAProxy Widget with Show Client Traffic enabled
Sebastian Wagner wrote in #note-7:
> As a workaround, I change the file like this:
> [...]
> I don't know if the d...
Rodrigo Goncalves
01:27 PM Bug #14240 (Not a Bug): FRR OSPF Neighbor Not Detected for VTI Tunnels
It may have worked by accident, but it wasn't supposed to have worked that way. The interfaces were only intended to ... Jim Pingle
01:12 PM Bug #14240 (New): FRR OSPF Neighbor Not Detected for VTI Tunnels
Jim Pingle wrote in #note-4:
> Can't reproduce this, it's working fine here as it has for quite some time. Even on 23...
Kris Phillips
10:36 AM Bug #14240 (Not a Bug): FRR OSPF Neighbor Not Detected for VTI Tunnels
Can't reproduce this, it's working fine here as it has for quite some time. Even on 23.05 snapshots. Has to be a conf... Jim Pingle
10:02 AM Feature #14241 (New): The Abiility to Configure FreeRadius Proxy servers from the GUI
Currently adding radius proxy servers via the GUI is not supported. When a proxy listener is configured freeradius st... Boris Baeta

04/06/2023

10:09 PM Bug #14240: FRR OSPF Neighbor Not Detected for VTI Tunnels

to work around it (tested)
Add an IP(VIP) to the Localhost Firewall>Virtual IPs. (both sides, non used IPs)
ad...
Alhusein Zawi
09:41 PM Bug #14240: FRR OSPF Neighbor Not Detected for VTI Tunnels
Additional troubleshooting:
We re-saved the interfaces, restarted the FRR Zebra and OSPF service several times, dr...
Kris Phillips
09:40 PM Bug #14240 (Not a Bug): FRR OSPF Neighbor Not Detected for VTI Tunnels
Customer upgraded from 22.05 to 23.01 and FRR no longer showed a neighbor for a VTI tunnel with a /30 to an OSPF neig... Kris Phillips
12:10 PM Bug #14199: ACME - Issue with corrupted cert
I'm running pfSense+ 23.01 on a Netgate 2100.
This morning I was removing HAProxy (I've migrated to Nginx Proxy Ma...
Kevin Dorff
11:23 AM Regression #14024: PHP error in HAProxy Widget with Show Client Traffic enabled
As a workaround, I change the file like this:... Sebastian Wagner

04/05/2023

12:45 AM Feature #12889: FRR GUI add set ipv6 next-hop global
!https://i.imgur.com/ewwRoTm.jpg! yon Liu

04/04/2023

07:12 AM Regression #13958: Snort exits with signal 10 on arm32
Mateusz Guzik wrote in #note-2:
> Hi Bill, that was me.
>
> What changed is that there was a compiler update and ...
Bill Meeks
06:54 AM Regression #13958: Snort exits with signal 10 on arm32
Hi Bill, that was me.
What changed is that there was a compiler update and then it turned out some of the files *d...
Mateusz Guzik

04/03/2023

04:46 PM Regression #14232 (New): ntopng no longer tracks top talkers
ntopng version that now comes with pfsnese plus 23.01 no longer tracks top talkers across time(no historical tracking... Mike Moore
11:38 AM Regression #14189 (New): pfBlocker-NG: HA-Sync is not working
Marcos M
10:29 AM Regression #14189 (Duplicate): pfBlocker-NG: HA-Sync is not working
This issue has existed for some time unfortunately. It's covered by the following reports:
https://redmine.pfsense.or...
Marcos M
10:45 AM Bug #12916: pfBlockerNG-devel cron job does not trigger xmlrpc sync
Hello Marcos,
sadly this is not the same bug, because for me on pfSense+ 23.01 no update option worked, not even "...
name name
08:14 AM Bug #14220 (Duplicate): pfBlockerNG does not sync to HA secondary
Duplicate of #14189 Jim Pingle
08:11 AM Bug #13936 (Feedback): PHP error from RRD Graphs when attempting a query a newly created empty database
MR merged Jim Pingle
07:57 AM Feature #14193 (Duplicate): Website to add and remove feeds automatically
Jim Pingle

04/02/2023

03:21 PM Bug #14230: PHP error with pfBlockerNG
As a workaround, use the @System Patches@ package to apply the following patch (set @Path Strip Count@ to @0@).... Marcos M
03:11 PM Bug #14230 (New): PHP error with pfBlockerNG
On @pfBlockerNG-3.2.0_3@ and @pfSense-23.01@.... Marcos M
10:51 AM Bug #14075 (Feedback): Using the ``Transparent ClientIP`` option in HAproxy results in kernel panics
The original report was from a customer's system, however I have not been able to reproduce this either on 23.01 nor ... Marcos M
03:43 AM Bug #14228 (Resolved): pfBlockerNG might not support new Maxmind license keys
https://dev.maxmind.com/geoip/release-notes/2023?lang=en#changes-to-maxmind-license-keys
* New license keys will b...
Jon Brown
03:08 AM Feature #13195: Dedicated website for Feed mangement - Community Driven
or the website could be website where end users (me and others) can add feeds and report dead feeds that would then b... Jon Brown
03:06 AM Feature #14193: Website to add and remove feeds automatically
duplicate of #13195 - close this one Jon Brown

04/01/2023

08:49 PM Todo #14221: Sync settings and inline documentation needs improving
>>http is insecure because your password will be transmitted in plain text so use https
Not sure it's relevant to ...
Kris Phillips
03:35 AM Todo #14221 (New): Sync settings and inline documentation needs improving
This inline notes on the sync page (Firewall --> pfBlockerNG --> Sync) need improving.
* *Add: Allow Sync Pushes*
...
Jon Brown
08:34 PM Bug #14218: Deleting a shellcmd entry results in a PHP error and crash report
A diff of the merge request fixes the problem when applied as a system patch. Deleting a shellcmd job doesn't give an... Chris W
10:08 AM Bug #14218 (Pull Request Review): Deleting a shellcmd entry results in a PHP error and crash report
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/334 Christopher Cope
01:55 PM Bug #11477: FRR does not recognize some BFD options

not exist
frr 1.2_3
pfsense 23.01
Alhusein Zawi
11:17 AM Bug #14223 (New): Block Offenders - Incorrect statement/description
The description on the options 'Block Offenders' is incorrect for 'inline mode' but still valid for 'Legacy Mode'
...
Jon Brown
10:55 AM Bug #14220: pfBlockerNG does not sync to HA secondary
Apparently my search for "sync" wasn't good enough. Apologies for the dupe. Steve Y
06:46 AM Bug #14220: pfBlockerNG does not sync to HA secondary
I alreay created a bug for it, see https://redmine.pfsense.org/issues/14189 .
No feedback yet, if someone is even ...
name name

03/31/2023

05:27 PM Bug #14220 (Duplicate): pfBlockerNG does not sync to HA secondary
After making changes they are not replicated to the secondary. E.g. on /pfblockerng/pfblockerng_ip.php check "kill s... Steve Y
04:28 PM Bug #14218 (Resolved): Deleting a shellcmd entry results in a PHP error and crash report

1. Install the shellcmd package from System > Package Manager.
2. Services > shellcmd >
Command: ...
Chris W

03/30/2023

02:16 PM Regression #13978: PHP errors with squidGuard
Additionally:... Steve Wheeler
07:19 AM Bug #14203 (Rejected): Zabbix Agent 6.2 installation fails
The package installs fine (both agent and proxy) so whatever problem you are encountering is likely unique to your se... Jim Pingle
04:19 AM Bug #14203 (Rejected): Zabbix Agent 6.2 installation fails
I see that this issue is reported a couple of times, i.e. https://redmine.pfsense.org/issues/13587 however it still p... Rajib Momen

03/29/2023

05:29 PM Bug #14199: ACME - Issue with corrupted cert
Hi Jim .
My bad, I said HAProxy by mistake, I am using ACME for this, attached screenshot
Juan Francisco Rodriguez Garcia
11:57 AM Bug #14199: ACME - Issue with corrupted cert
The attached configuration snippet isn't a valid configuration for ACME. I'm not sure how it ended up in that state, ... Jim Pingle
02:58 PM Todo #14202 (Resolved): Rename exported OpenVPN connect files as "connect" rather than "ios"
Some of the files have names that are not following the same rules as the rest. I have made corrections to some of th... Jon Brown
10:02 AM Bug #14200 (New): WireGuard reply-to without NAT
I have discovered that the WireGuard package requires the interface to have the gateway set for the reply-to rules to... Carrnell Tech

03/28/2023

05:34 PM Bug #14199: ACME - Issue with corrupted cert
Attaching the Acme section of my config.xml backup which had this issue after upgrading to the new release on Feb 17 ... Jerold Von Hemel
04:55 PM Bug #14199 (Resolved): ACME - Issue with corrupted cert
Hi team
After creating a new cert in HAProxy i got an timeout on the webui interface then receive this error:
P...
Juan Francisco Rodriguez Garcia
02:25 PM Todo #14194: Better colours for alerts
Green and Red are also not great choices because some people are red/green color blind, so ideally whatever colors ar... Jim Pingle
01:32 PM Todo #14194 (New): Better colours for alerts
on the page Firewall --> pfBlockerNG --> Reports --> unified (and others)
pfBlocker uses
* 'Red' for traffic st...
Jon Brown
01:50 PM Feature #14196 (Incomplete): permitted firewall rules - additional text
Firewall --> pfBlockerNG --> DNSBL --> DNSBL Configuration --> Permit Firewall Rules
Can you add some additional i...
Jon Brown
01:45 PM Feature #14195 (New): Customise what are class as Full Domains when blocking with DNSBL
Currently when a DNSBL is Blocked you get one of 2 pages depending what was looked up. Most lookups will end up beeb ... Jon Brown
01:26 PM Feature #14193 (Duplicate): Website to add and remove feeds automatically
I would like to see a website where end users (me and others) can add feeds and report dead feeds that would then be ... Jon Brown
11:22 AM Feature #14192 (Rejected): Instant Website Redaction Technology Not working
Hello Fellow Netgate Community Members,
I wanted to share some topics for discussion and possibly create a communi...
Jonathan Lee
09:33 AM Regression #14189: pfBlocker-NG: HA-Sync is not working
I understand, but I don't know what is "not" happening.
There are two choices when configuring Sync for pfBlockerN...
name name
 

Also available in: Atom