Project

General

Profile

Activity

From 06/29/2023 to 07/28/2023

07/28/2023

08:46 PM Bug #14606 (Resolved): Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
Jim Pingle
08:30 PM Bug #14606: Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
Jim Pingle wrote in #note-4:
> Fixed in FRR Package v1.3, which is building now and will be available shortly.
I ...
Bill Hughes
05:44 PM Bug #14606 (Feedback): Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
Fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle
05:46 PM Bug #14275 (Feedback): Deleting a route map that is assigned to an active neighbor causes crash
This should be fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle
05:44 PM Regression #14493 (Feedback): FRR,PHP errors when deleting neighbor
Fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle
05:44 PM Regression #14494 (Feedback): FRR,PHP errors when deleting AS-path
Fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle
05:44 PM Regression #14561 (Feedback): FRR errors accessing Global Settings after deleting BGP neighbor
Fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle
05:44 PM Bug #14562 (Feedback): PHP error when trying to run OSPF and BGP in the same time
Fixed in FRR Package v1.3, which is building now and will be available shortly. Jim Pingle

07/26/2023

07:48 PM Bug #14491: FRR not starting with AgentX enabled
The FRR package is built with SNMP support but it doesn't appear to be loading the module somehow.
The vtysh CLI l...
Jim Pingle
12:22 PM Bug #14491: FRR not starting with AgentX enabled
Jim Pingle wrote in #note-3:
> For those hitting this error, do you have the NET-SNMP package installed and active?
...
Yif Swery
12:12 PM Bug #14491: FRR not starting with AgentX enabled
For those hitting this error, do you have the NET-SNMP package installed and active?
The AgentX integration is int...
Jim Pingle
10:15 AM Bug #14491 (Confirmed): FRR not starting with AgentX enabled
I can confirm this behavior.
Tested against:...
Danilo Zrenjanin
07:03 PM Feature #14321 (Feedback): Add UPS information to LCDproc screen
I added screens for both APCUPSD and NUT to LCDProc. The option only appears (and will only work) when the correspond... Jim Pingle
12:33 PM Bug #14484 (Feedback): lldpd php error on saving with no interface selected
I pushed a fix, it is building now and will be available shortly in lldpd pkg version 0.9.11_2 on Plus 23.05.1 and CE... Jim Pingle
06:41 AM Bug #14484 (Confirmed): lldpd php error on saving with no interface selected
Lev Prokofev
06:41 AM Bug #14484: lldpd php error on saving with no interface selected
I can reproduce it on 23.05.1, probably the "No interface selected" warning message is needed here.... Lev Prokofev
09:29 AM Bug #14199 (Resolved): ACME - Issue with corrupted cert
Perhaps this issue is related to the https://redmine.pfsense.org/issues/14592
I couldn't recreate any of the repo...
Danilo Zrenjanin
06:34 AM Bug #14606 (Confirmed): Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
Lev Prokofev
06:34 AM Bug #14606: Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
I can reproduce it on 23.05.1, error doesn't come if the BFD daemon is disabled, but occurs immediately when you enab... Lev Prokofev

07/24/2023

01:08 AM Bug #14606 (Resolved): Deleting Last BFD Profile in FRR Package Causes PHP Fatal Error
To reproduce:
1. Enable BFD in FRR.
2. Create a BFD profile (only requires a profile name).
3. Delete the BFD pr...
Bill Hughes

07/23/2023

02:04 AM Bug #14504 (Incomplete): FTP_Client_Proxy package doesn't create firewall rule
Hello,
Do you mean it doesn't create a rule from the inside interface outbound for FTP traffic? If so, typically ...
Kris Phillips
01:27 AM Bug #10502: LLDP spamming errors on Netgate XG-7100
still seeing this on 7100 running 23.05.1 lldpd 0.9.11_1 - set all protocol support to active, save... Jordan G
12:55 AM Bug #14498: php errors when looking at snort active rules
Jonathan Lee wrote in #note-16:
> @Christopher Cope
> I wanted to also take the time to message you and say I am so...
Christopher Cope

07/22/2023

12:09 PM Bug #14592 (Resolved): Issues with ACME Private Key handling
Danilo Zrenjanin
12:09 PM Bug #14592: Issues with ACME Private Key handling
I couldn't reproduce any of the listed issues on the 0.7.5 Acme package.
I am marking this case resolved.
Danilo Zrenjanin
10:59 AM Bug #14596 (Confirmed): FreeRADIUS falsely shows its default is to save data during package reinstall
I can confirm this behavior.
Tested on:...
Danilo Zrenjanin
06:57 AM Feature #14602: squidguard log search
Not sure if its possible to do with the package but if multiple categories are selected and the action is blocked, th... Mike Moore
06:52 AM Feature #14602 (New): squidguard log search
Package > SquidGuard > Logs
The ability to search through the logs in the GUI. Right now there is no ability to do...
Mike Moore

07/21/2023

07:47 PM Bug #14571: PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
For the record, I now have an LCD with buttons and the fix I committed last week did correct the errors. Jim Pingle
02:31 PM Bug #14596: FreeRADIUS falsely shows its default is to save data during package reinstall
Stated differently, it is not possible to restore FreeRADIUS settings unless one has at some point clicked the Save b... Steve Y
03:24 AM Bug #14596 (Duplicate): FreeRADIUS falsely shows its default is to save data during package reinstall
forum thread: https://forum.netgate.com/topic/181594/restore-missing-freeradius-config
A new install of FreeRADIUS...
Steve Y
02:03 PM Bug #14315 (Resolved): Routes are not exposed on Tailscale when an empty route entry exists in the GUI
Christian McDonald
11:57 AM Bug #14315: Routes are not exposed on Tailscale when an empty route entry exists in the GUI
Tested on 23.05.1 and CE 2.7.0, looks like it has been fixed, I could not reproduce.
23.05.1-RELEASE (amd64)
built ...
aleksei prokofiev

07/20/2023

04:08 PM Feature #14529: eBPFShield
https://github.com/generic-ebpf/generic-ebpf
should do the job adds kernel/user space tools
Generic eBPF run...
Michael Lawrence
12:52 PM Bug #14560 (Resolved): NRPE does not function properly on Plus 23.09 / CE 2.7.0
Jim Pingle
07:01 AM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0

Tested package 4.1 on ...
Lev Prokofev
09:12 AM Bug #14554: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string
I do have some customizations in unbound, but they're not connected with dhcp (private-domain, local-zone, forward-zo... Alex Kolesnik
08:51 AM Bug #14554: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string
I set up DHCP Static Mappings in the DHCP server but couldn't replicate the issue with a fresh pfBlocker installation... Danilo Zrenjanin
08:52 AM Regression #14561: FRR errors accessing Global Settings after deleting BGP neighbor
I can confirm this behavior.
This seems to be a duplicate of https://redmine.pfsense.org/issues/14493
Danilo Zrenjanin
08:12 AM Bug #14553 (Resolved): Call to undefined function sync_package_filer()
Tested on the:... Danilo Zrenjanin

07/19/2023

07:16 PM Bug #14592 (Feedback): Issues with ACME Private Key handling
Commit: https://github.com/pfsense/FreeBSD-ports/commit/2b3c7e925fed1d53763e6d2eee5e5ab2289b4116
Packages are buil...
Jim Pingle
06:40 PM Bug #14592 (Resolved): Issues with ACME Private Key handling
There are some problems with private key handling in the ACME package that appear to have been ongoing for a while.
...
Jim Pingle
03:00 PM Bug #14585 (Closed): Fatal error editing acme certificates
Looking at the PHP code blocks you showed above, something must not have updated in your setup. Lines were added to i... Jim Pingle
12:52 PM Feature #10462 (Resolved): CPU Temp Screen
Jim Pingle
12:51 PM Feature #10462: CPU Temp Screen
Works well! Thank you very much! odo maitre
12:44 PM Feature #10462 (Feedback): CPU Temp Screen
I didn't merge the original PR since other work on the package caused conflicts and made a lot of the changes unneces... Jim Pingle
12:51 PM Bug #11509 (Closed): LCD package - not starting at boot - stop and start in Status Window not possible
This report is quite old and the package has had significant work done to it since then. Please try it again on pfSen... Jim Pingle
12:46 PM Feature #14321: Add UPS information to LCDproc screen
It should be OK to add that in, but it would need to be made conditional. By that I mean the option for the screen sh... Jim Pingle
12:42 PM Bug #14571 (Resolved): PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
The error as originally stated in this issue is solved. If you still have problems starting LCDProc, please post a ne... Jim Pingle
02:26 AM Feature #14588 (Resolved): Add FRR diagnostic status output plugin
Since FRR is a package and the status output does not generate information for packages, it would be really helpful f... Chris Linstruth

07/18/2023

07:15 PM Bug #14585: Fatal error editing acme certificates
I just edited config.xml and added actions to my items.
It worked. I immediately got access to those items in pfS...
Phil Tull
05:32 PM Bug #14585: Fatal error editing acme certificates
Thanks. I'm going to try this tonight.
Perfect.
Phil Tull
05:01 PM Bug #14585: Fatal error editing acme certificates
Phil Tull wrote in #note-6:
> ok one more question please.
> Is it possible for me to edit the live config.xml and ...
Jim Pingle
04:59 PM Bug #14585: Fatal error editing acme certificates
ok one more question please.
Is it possible for me to edit the live config.xml and put in the actions (presumable to...
Phil Tull
04:53 PM Bug #14585: Fatal error editing acme certificates
Phil Tull wrote in #note-4:
> I'm considering your suggestion to reinstall acme.
In this case I doubt it would ma...
Jim Pingle
04:15 PM Bug #14585: Fatal error editing acme certificates
I'm considering your suggestion to reinstall acme.
Would that require me to rebuild all my acme settings?
I wonder ...
Phil Tull
04:10 PM Bug #14585 (New): Fatal error editing acme certificates
OK, you mean no actions defined in the list in the cert entry -- I thought you meant they showed no action icons in t... Jim Pingle
03:41 PM Bug #14585: Fatal error editing acme certificates
Yes, I'm in the config.xml and it looks perfectly normal to me. I'll attach an example entry.
Consider this...
<p...
Phil Tull
02:42 PM Bug #14585 (Feedback): Fatal error editing acme certificates
Sounds like you have a corrupted/incomplete certificate entry in the configuration that is leading to the errors, but... Jim Pingle
01:22 AM Bug #14585 (Closed): Fatal error editing acme certificates
After updating pfSense from 2.6.0 to 2.7.0, cannot manage acme certificates IF the certificate has NO actions.
Acme ...
Phil Tull
02:45 PM Bug #14553 (Feedback): Call to undefined function sync_package_filer()
Request merged. Jim Pingle
02:36 PM Feature #14583: Add LiveKit package
In my opinion, I don't believe this package, essentially being a video conference server, is a good fit for running o... Jim Pingle
12:58 PM Feature #14101 (Resolved): Add Zabbix 6.4 packages
Jim Pingle

07/17/2023

04:39 PM Bug #14571: PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
Soren Pedersen wrote in #note-7:
> @Jim Pringle:
>
> I installed the updated version of LCDProc on PFsense 2.7.0 ...
Jim Pingle
04:33 PM Bug #14571: PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
@Jim Pringle:
I installed the updated version of LCDProc on PFsense 2.7.0 and the service still refuses to start. Re...
Soren Pedersen
03:14 PM Feature #14583: Add LiveKit package
PR link => https://github.com/pfsense/FreeBSD-ports/pull/1273 Andrés Manelli
01:00 PM Feature #14583 (Pull Request Review): Add LiveKit package
This is to add the LiveKit server as a pfSense package and configuration UI.
I created a pull request in GitHub wi...
Andrés Manelli
02:45 PM Regression #14445: HAProxy PHP error /usr/local/www/haproxy/haproxy_global.php:138
I'm experiencing this regression on CE 2.7 when trying to de-activate HA Proxy. If I then refresh the browser, I am a... Alex Neihaus
02:27 AM Bug #14532: Error is logged every time a domain in the DNSBL is temporarily unlocked or re-locked
After doing some more testing on this, I also get the results you reported, i.e., nothing gets logged to py_errors.lo... Derek Fong

07/16/2023

02:04 AM Bug #14562: PHP error when trying to run OSPF and BGP in the same time

is there a specific configuration in OSPF/BGP?
Alhusein Zawi
12:39 AM Bug #14553 (Pull Request Review): Call to undefined function sync_package_filer()
Thank you for the bug report. I have tested and confirmed the issue. A merge request is created so this fix will be a... Christopher Cope

07/15/2023

08:15 PM Feature #14101: Add Zabbix 6.4 packages
the package is added .
23.05.1-RELEASE (amd64)
built on Wed Jun 28 03:57:27 UTC 2023
FreeBSD 14.0-CURRENT
Alhusein Zawi
06:39 PM Bug #14532 (Not a Bug): Error is logged every time a domain in the DNSBL is temporarily unlocked or re-locked
What pfSense and pfBlocker versions are you using?
I'm unable to replicate this on pfSense Plus 23.05.1 with pfBlo...
Chris W
07:32 AM Bug #14530 (Confirmed): Suricata 6.0.13 package interface settings
Danilo Zrenjanin

07/14/2023

07:07 PM Bug #14571 (Feedback): PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
This should be fixed now. I don't have a panel with buttons to test it (yet, it's on the way) but I see why it was fa... Jim Pingle
12:21 PM Bug #14571 (In Progress): PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
I have some ideas on why the button calls are hitting that error, I'll work on it some more.
Good to know the othe...
Jim Pingle
02:51 AM Bug #14571: PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
I've updated to the newest package and life is good again. thank you Cino .
12:18 PM Bug #13343 (Resolved): HAproxy cookie protection syntax needs updated
Jim Pingle
05:51 AM Bug #13343: HAproxy cookie protection syntax needs updated
Hello,
it works now together with the haproxy version 0.61_11.
Thanks!
Johannes Goldynia
01:02 AM Feature #14032: Neighbor Discovery Proxy (NDproxy)
There is a growing need for this with more providers sticking us with /64. It's understandable that this wouldn't be ... spoon spoon

07/13/2023

10:45 PM Bug #14571: PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
Seeing some errors when trying to use the Reboot or Shutdown functions from the LCD buttons:... Steve Wheeler
07:50 PM Bug #14571 (Feedback): PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
Fixed in the new version of the package I just committed. Will be available once the package builds finish.
Jim Pingle
07:54 PM Bug #14406: Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
Hello,
I wanted to add an issue I am experiencing with Squid plugin version 0.4.46.
I am not sure if this iss...
K Puleston
03:03 PM Bug #13343 (Feedback): HAproxy cookie protection syntax needs updated
PR merged, thanks!
Packages are building for Plus 23.05.1 and CE 2.7.0, they will be available shortly.
Jim Pingle
01:53 PM Todo #14202 (Resolved): Rename exported OpenVPN connect files as "connect" rather than "ios"
This has been available for Plus 23.05.1 and CE 2.7.0 for several days with no reports of trouble.
We can open new...
Jim Pingle
01:53 PM Todo #13255 (Resolved): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
This has been available for Plus 23.05.1 and CE 2.7.0 for several days with no reports of trouble.
We can open new...
Jim Pingle
01:52 PM Todo #13917 (Resolved): OpenVPN Client Export: Integrate OpenVPN 2.6.0
This has been available for Plus 23.05.1 and CE 2.7.0 for several days with no reports of trouble.
We can open new...
Jim Pingle
07:28 AM Feature #14321: Add UPS information to LCDproc screen
Geo Rou wrote:
> Hi,
>
> I'd like to add a new screen to LCDproc that reads the UPS information from NUT.
Jus...
odo maitre

07/12/2023

04:30 PM Bug #14572 (Resolved): Unused DNSBL files may not be removed
Hi,
I get the following crash report:...
Jove Too
03:28 PM Bug #14560 (Feedback): NRPE does not function properly on Plus 23.09 / CE 2.7.0
Updated package committed on devel branches and also to RELENG_2_7_0, should be available soon on CE 2.7.0 and in dev... Jim Pingle
01:32 PM Bug #14560 (In Progress): NRPE does not function properly on Plus 23.09 / CE 2.7.0
Some care will be needed here since CE 2.7.0 apparently has the OS package nrpe-4.1.0 while Plus 23.05.1 has nrpe3-3.... Jim Pingle
02:48 PM Bug #14571 (Resolved): PHP Error prevents LCDProc client from working properly due to empty VIP tags in config.xml
Since the latest pfSense update, the LCDproc client is unable to connect to the LCDproc server. I can confirm LCDproc... Cino .
12:26 PM Regression #14452: Prometheus node_exporter generates errors with the default config
Confirmed this also affects the 2.7 package:
https://forum.netgate.com/topic/180575/node_exporter-is-not-working-pr...
Steve Wheeler

07/11/2023

09:52 PM Bug #13489 (Resolved): Tailscale Exit node without IPv6 connectivity break connections with Chromium based browser
We are up to Tailscale v1.44.
> Tailscale 1.30.1 has been released which includes the fix for this issue. The upda...
Christian McDonald
09:08 PM Bug #13515: Snort with PHP 8.1 - TypeError when saving edits to an interface
I am still seeing this error in 2.7.0-RELEASE.... Jove Too
09:10 AM Bug #14554: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string
By reading /usr/local/pkg/pfblockerng/pfblockerng.inc it seems a few more lines down this part might be affected as w... Buster de

07/10/2023

08:13 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
Thank you all!
> So to re-summarize, these -5- 6 changes appear to restore 100% functionality from the previous rele...
Tom Huerlimann
05:25 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
@TomTheOne: I'd suggest rebooting after making the five changes I listed above. nrpe3.sh definitely seems to get gene... Jeff Morris
05:12 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
Ok, I think I've got this figured out... nrpe3.sh gets automatically generated, so disregard my previous comment rega... Jeff Morris
05:06 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
In my case, nrpe is already running by manually starting the service via start-script in /usr/local/etc/rc.d/nrpe.
I...
Tom Huerlimann
04:44 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
Sorry for the confusion Tom. Those changes do indeed fix it on my system, but after seeing your comment I just did so... Jeff Morris
04:18 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
Thank you
> So in summary, these 4 changes appear to restore 100% functionality from the previous release:
>
> /...
Tom Huerlimann
04:07 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
Two more notes:
(1) At least on my system, the command="/usr/local/sbin/nrpe" change had to be made to /usr/local/...
Jeff Morris
03:37 PM Bug #14560: NRPE does not function properly on Plus 23.09 / CE 2.7.0
In addition to the daemon name being changed from nrpe3 to nrpe, I've noticed that the associated check command has a... Jeff Morris
07:27 PM Bug #14566 (Confirmed): Softlflowd package don't send ICMP flows
I am using the softflowd package v.1.2.6_1 on pfsense v.2.7.0
Apparently icmp traffic is not sent from the sensor to...
Yuran Yastreb
01:06 PM Bug #14559 (Duplicate): nrpe 3.1_6 service control broken on pfSense 2.7.0
Jim Pingle

07/09/2023

08:03 AM Bug #14364: APCUPSD unable to process date string
Perfect, thanks Kris :-) Lloyd Collins
01:44 AM Bug #14364 (Confirmed): APCUPSD unable to process date string
Yeah we should add a date format option to the widget so that it properly displayed depending on user input. Kris Phillips
01:56 AM Bug #14349 (Confirmed): The ClamAV 0.105.1 got a few vulnerabilities
pfSense Plus 23.09 has the latest ClamAV 1.1.0, which is not vulnerable:
/usr/local/sbin/clamd --version
ClamAV 1...
Kris Phillips
01:37 AM Feature #14529: eBPFShield
The project appears to be primarily written for Debian-based Linux and the Summer of Code project from 2020 doesn't a... Kris Phillips
01:20 AM Bug #14560 (Confirmed): NRPE does not function properly on Plus 23.09 / CE 2.7.0
Tested on 23.09. Confirmed this behavior.
Editing /usr/local/etc/rc.d/nrpe to change this allows the service to...
Kris Phillips

07/08/2023

05:29 PM Bug #14562 (Resolved): PHP error when trying to run OSPF and BGP in the same time
The following PHP error is thrown when you enable OSPF while the BGP service is already running.... Danilo Zrenjanin
04:02 PM Regression #14561 (Resolved): FRR errors accessing Global Settings after deleting BGP neighbor
Steps to reproduce:
1. Install FRR.
2. Create a BGP neighbor without staring FRR.
3. Delete the neighbor.
4. Atte...
Christopher Cope
01:14 PM Regression #14494 (Confirmed): FRR,PHP errors when deleting AS-path
I can confirm this behavior.
Tested against:...
Danilo Zrenjanin
12:42 PM Regression #14493 (Confirmed): FRR,PHP errors when deleting neighbor
I can confirm this behavior.
Tested against:...
Danilo Zrenjanin
09:20 AM Bug #14559: nrpe 3.1_6 service control broken on pfSense 2.7.0
To be deleted, i posted in the wrong category.
Correct one here: https://redmine.pfsense.org/issues/14560
Tom Huerlimann
08:12 AM Bug #14559 (Duplicate): nrpe 3.1_6 service control broken on pfSense 2.7.0
nrpe 3.1_5 works smooth on pfSense 2.7.0, after the upgrade to nrpe 3.1_6 the service can not be controled anymore vi... Tom Huerlimann
09:20 AM Bug #14560 (Resolved): NRPE does not function properly on Plus 23.09 / CE 2.7.0
nrpe 3.1_5 works smooth on pfSense 2.7.0, after the upgrade to nrpe 3.1_6 the service can not be controled anymore vi... Tom Huerlimann
07:42 AM Bug #14364: APCUPSD unable to process date string
Done, and it's fixed the problem and the widget is working again, but apctest expects the format in DD/MM/YY and the ... Lloyd Collins
06:56 AM Bug #14364: APCUPSD unable to process date string
Are you able to try with the month and then day in the first and second numbers respectively when entering the date? ... Jordan G

07/07/2023

10:29 PM Bug #14557 (Not a Bug): SSL Offloading configuration settings missing from frontends
Jim Pingle
09:37 PM Bug #14557: SSL Offloading configuration settings missing from frontends
Andrew Cz wrote:
> The SSL Offloading section of any and all frontends are missing.
>
> I was expecting to see the s...
Andrew Cz
03:02 PM Bug #14557 (Not a Bug): SSL Offloading configuration settings missing from frontends
The SSL Offloading section of any and all frontends are missing.
I was expecting to see the section that can be fo...
Andrew Cz
06:43 PM Todo #13917 (Feedback): OpenVPN Client Export: Integrate OpenVPN 2.6.0
Included in OpenVPN client export package 1.9. Will be in snapshots for testing, then release branches if it tests OK.
Jim Pingle
06:43 PM Todo #13255 (Feedback): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
Included in OpenVPN client export package 1.9. Will be in snapshots for testing, then release branches if it tests OK.
Jim Pingle
05:11 PM Todo #13255 (In Progress): Set PKCS#12 algorithm when exporting OpenVPN ZIP or Windows bundles
Jim Pingle
06:43 PM Todo #14202 (Feedback): Rename exported OpenVPN connect files as "connect" rather than "ios"
Included in OpenVPN client export package 1.9. Will be in snapshots for testing, then release branches if it tests OK.
Jim Pingle
05:10 PM Todo #14202 (In Progress): Rename exported OpenVPN connect files as "connect" rather than "ios"
The change from "ios" to "connect" would be good.
The change from "config" to "archive" is not needed, it is a con...
Jim Pingle
06:15 PM Bug #14426: PHP errors in Lightsquid
This occurs with 23.05.1 also
Attached is logs
Jonathan Lee
02:28 PM Bug #14556 (New): Tailscale dropping routes from FIB
Installation has several tailscale nodes. The problematic node is a 6100. Some of the other nodes are 2100s.
At so...
Chris Linstruth
01:17 PM Feature #14101 (Feedback): Add Zabbix 6.4 packages
Brad Davis

07/06/2023

03:53 PM Bug #13343 (Pull Request Review): HAproxy cookie protection syntax needs updated
Jim Pingle
03:00 PM Bug #13343: HAproxy cookie protection syntax needs updated
Sorry for the duplicate report; for some reason I missed this one.
I've now prepared a pull request https://github...
Alfredo Pironti
08:36 AM Bug #14553: Call to undefined function sync_package_filer()
... Alex Kolesnik
08:29 AM Bug #14553 (Resolved): Call to undefined function sync_package_filer()
https://forum.netgate.com/topic/180220/filer-package-xmlrpc-sync-error Alex Kolesnik
08:34 AM Bug #14554 (Duplicate): PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string
https://forum.netgate.com/topic/180950/error-on-pfblockerng-inc-5310-pfblockerng-devel-3-2-0_5... Alex Kolesnik
07:06 AM Bug #13432: ups driver will not start
The root cause appears to be the kernel not recognizing some UPS models as a UPS. See discussion here:
https://fo...
Doug Miles

07/05/2023

05:51 PM Bug #14406: Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
@jonathanlee and @pete-wright I wanted to confirm that I had not seen this thread and had performed similar steps to ... Eric Reiss
03:23 PM Feature #14538 (Resolved): Add switch for Tailscale DNS
With the accept DNS option enabled (default):... Christian McDonald
01:51 PM Feature #14538 (Feedback): Add switch for Tailscale DNS
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/commit/543e81ef566acdd95d4c13f04f3535c62e1e9ac4
Done.
Christian McDonald
12:55 PM Bug #14536 (Duplicate): Backend cookie protection option generates invalid haproxy config file
Duplicate of #13343 Jim Pingle
12:42 PM Bug #10692 (Confirmed): PIMD starts twice at boot
Jim Pingle

07/04/2023

04:45 AM Feature #14539 (New): Add support for Oracle Cloud Infrastructure (OCI) vNIC management to work with unicast CARP
Add the ability to invoke OCI APIs to relocate secondary IPs (i.e. CARP VIPs) on vNICs when CARP VIP events occur in ... James George
01:27 AM Feature #14538 (Resolved): Add switch for Tailscale DNS
from cmacdonald on Reddit - Add a simple knob to the Tailscale section of the pfSense Web UI to toggle whether pfSens... Lily S

07/03/2023

11:00 PM Regression #14452: Prometheus node_exporter generates errors with the default config
I stumbled upon this today. This PR [[https://github.com/prometheus/node_exporter/pull/2584]] may provide additional ... Steven Hostetler
01:33 PM Bug #14536 (Duplicate): Backend cookie protection option generates invalid haproxy config file
On PFSense 2.7.0, with haproxy 0.61_10 package installed.
Create a haproxy backend, edit it and enable the "Cookie...
Alfredo Pironti
02:56 AM Bug #14498: php errors when looking at snort active rules
In the interest of coming to a resolution on this ticket...
The issue identified here is more of a generic problem w...
Bill Meeks
02:19 AM Bug #14498: php errors when looking at snort active rules
@Christopher Cope
I wanted to also take the time to message you and say I am sorry for the reply with, "If you do no...
Jonathan Lee
12:20 AM Bug #14498: php errors when looking at snort active rules
@Ryan Coleman
Can you mark my open TAC ticket #1731574435 as closed as it is confirmed this is a code/software is...
Jonathan Lee
01:11 AM Bug #14514: SNORT randomly starts blocking the IP address on the interface that it is residing on
Hello fellow Redmine members,
I do understand that adding my ISP issued IP address to the pass list and or suppres...
Jonathan Lee
01:05 AM Bug #14108: Antivirus Bases showing outdated main.cvd with a version dated year 2021
@Kris Phillips
Thanks for looking into this
Jonathan Lee
01:03 AM Regression #13984: PHP errors with squid
@Marcos
Thanks for looking into this.
Jonathan Lee
12:59 AM Bug #14406: Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
@Pete Wright thanks for confirming this issue. Jonathan Lee

07/02/2023

11:59 PM Bug #14498: php errors when looking at snort active rules
@Bill Meeks
Thank you for confirming the code issue. As you quoted,
"No matter how much RAM is in the firewall,...
Jonathan Lee
11:48 PM Bug #14498: php errors when looking at snort active rules
_How were you attempting to implement a paged output? Was it images that you created and or just accessing sections o... Ryan Coleman
10:47 PM Bug #14498: php errors when looking at snort active rules
I would just make a buffered image and save it everytime that method was called on. It would save the file and open i... Jonathan Lee
10:36 PM Bug #14498: php errors when looking at snort active rules
Thanks for your reply and looking into this at a granular level.
I noticed you said " _I've toyed around with tryi...
Jonathan Lee
06:24 PM Bug #14498: php errors when looking at snort active rules
This is a consequence of the PHP process itself running out of memory. Because the output is being buffered in an att... Bill Meeks
02:41 PM Bug #14498: php errors when looking at snort active rules
The truth is, I really want to fix this PHP software issue, again I am still a student and rather overzealous when I ... Jonathan Lee
05:30 AM Bug #14498: php errors when looking at snort active rules
Your ticket number is: 1731574435 Jonathan Lee
05:29 AM Bug #14498: php errors when looking at snort active rules
TAC ticket open with this referenced copy of config is loaded with my serial number. I hope that provides everything ... Jonathan Lee
05:11 AM Bug #14498: php errors when looking at snort active rules
Also attached is *proof* that the custom rules I have in Snort are in use and functional within this regard.
_S...
Jonathan Lee
05:03 AM Bug #14498: php errors when looking at snort active rules
After sometime I still show no memory errors inside of the SG-2100MAX for this timestamp.
Please let me know if y...
Jonathan Lee
04:59 AM Bug #14498: php errors when looking at snort active rules
Per your request in 23.05.1
See attached system goes to blank screen error occurs and no errors in system logs tha...
Jonathan Lee
04:46 AM Bug #14498: php errors when looking at snort active rules
I do also have custom rules active inside snort. I do not know if that causes it. As custom rules are pasted in and l... Jonathan Lee
04:38 AM Bug #14498: php errors when looking at snort active rules
Hello thanks for the reply. This PHP error occurs when I attempt to view the active rules in snort. I only have 20 pe... Jonathan Lee
09:33 PM Bug #14491: FRR not starting with AgentX enabled
We can confirm this also on our 2.7 Upgrade which broke FRR from starting (although I think its somthing to do with t... Yif Swery

07/01/2023

11:57 PM Bug #10692: PIMD starts twice at boot
confirming, same thing as above with 23.05.1 and pimd 0.0.3_6 Jordan G
10:30 PM Bug #14498: php errors when looking at snort active rules
We'll need more information to confirm if this is actually a bug. It is possible you are hitting the memory limit in ... Christopher Cope

06/30/2023

08:29 PM Bug #14532 (Not a Bug): Error is logged every time a domain in the DNSBL is temporarily unlocked or re-locked
From the Reports > Alerts tab, when I click the red lock icon to temporarily unlock a domain listed under the DNSBL P... Derek Fong
05:17 PM Todo #13917 (In Progress): OpenVPN Client Export: Integrate OpenVPN 2.6.0
Jim Pingle
03:47 PM Bug #14530 (Resolved): Suricata 6.0.13 package interface settings
Hello,
The text label at _Services / Suricata / Interfaces / <IF>(Edit) / <IF>Flow/Stream / Stream Memory Cap_ say...
Robert Karsai
12:56 PM Feature #14529: eBPFShield
Also can send alerts to SIEM ie call outs to "ransomware_.com" or other nastyware infected machines calling out to c... Michael Lawrence
12:46 PM Feature #14529 (New): eBPFShield
https://github.com/sagarbhure/eBPFShield
Advanced host monitoring and threat detection with eBPF 🛡️
eBPFShield ...
Michael Lawrence
07:03 AM Bug #10936: both haproxy/haproxy-devel non-existent option lb-agent-chk
Tested on: ... Danilo Zrenjanin

06/29/2023

04:23 PM Feature #9141: FRR xmlrpc
To understand the set up then.
nodeA and nodeB will have sepearate routing neighbors probably exchanging the same ...
Mike Moore
04:19 PM Feature #14512: Basic Auth through GUI
This can be achieved through Advanced pass-thru.
I am only advocating having a GUI option available to create users/...
Mike Moore
03:05 PM Feature #9833: ACME: add ability to use custom ACME server
+1 as well. Also a shout out to Step CA. There are more and more options for ACME endpoints hosted privately, this ... Jamison Maxwell
06:45 AM Bug #14460: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string in /usr/local/pkg/haproxy/haproxy.inc:2158
I have the exact same block of three lines on another appliance. So this might be some result of upgrades and changes... Stefan Weichinger
06:30 AM Bug #14460: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string in /usr/local/pkg/haproxy/haproxy.inc:2158
I can confirm that after removing the lines, there are no PHP errors, and the service starts successfully.
Danilo Zrenjanin
12:38 AM Bug #14523 (Resolved): PHP error when using an unsupported alias type in Advanced Rule Settings
Confirmed on both 2.6, 2.7-RC and 23.05 using pfBlockerNG-Devel 3.2.0_5 and 3.2.0_4. Removing pfBlockerNG-devel packa... Sengor K
 

Also available in: Atom