Project

General

Profile

Activity

From 08/17/2023 to 09/15/2023

09/15/2023

08:05 PM Feature #14786: Add GUI option for host_verify_strict
Keep in mind my concern is not of Apple's use of UPP rather for, when UPP Get requests are used invasively. How can a... Jonathan Lee
07:49 PM Feature #14786 (Duplicate): Add GUI option for host_verify_strict
Ref for research of UPP get requests:
https://forum.netgate.com/topic/182866/universal-procedure-pointers-upp-mzstat...
Jonathan Lee
12:17 PM Regression #14024 (Resolved): PHP error in HAProxy Widget with Show Client Traffic enabled
I couldn't reproduce this issue.
Tested against:...
Danilo Zrenjanin
10:33 AM Regression #14445 (Resolved): HAProxy PHP error /usr/local/www/haproxy/haproxy_global.php:138
I can not reproduce this issue.
Tested on packages:
HAproxy 0.63_1
haproxy-devel 0.63_1
I am marking this cas...
Danilo Zrenjanin

09/14/2023

01:03 PM Bug #14748: FRR reload script is not executed properly

i using frr webgui setup Route Handling not normal work also.
yon Liu
12:57 PM Regression #14774: Lightsquid won't allow change the password.
Hello Jim.
Other thing, there is a way to create users with lightsquid?
If I type newuser + password and save, ...
Peter Moreno
12:55 PM Bug #14780 (Not a Bug): The assigned Tailscale interface causes the "Network interface mismatch" on booting
Christian McDonald
12:17 PM Bug #14780: The assigned Tailscale interface causes the "Network interface mismatch" on booting
That is expected, users should not assign the Tailscale interface, it isn't meant to be used that way.
There may n...
Jim Pingle
10:13 AM Bug #14780 (Confirmed): The assigned Tailscale interface causes the "Network interface mismatch" on booting
I can confirm this behavior on the: ... Danilo Zrenjanin
07:16 AM Bug #14780: The assigned Tailscale interface causes the "Network interface mismatch" on booting
Tested on ... Lev Prokofev
07:09 AM Bug #14780 (Not a Bug): The assigned Tailscale interface causes the "Network interface mismatch" on booting
If you assign the tailscale0 as the interface, it will cause "Network interface mismatch" during the boot and prevent... Lev Prokofev
09:36 AM Bug #14711 (Resolved): pfBlocker ASN to IP Address option doesn't work
I am marking this case resolved. Danilo Zrenjanin
09:35 AM Bug #14711: pfBlocker ASN to IP Address option doesn't work
Yes, I can confirm it works again. ... Danilo Zrenjanin
05:21 AM Feature #14779 (New): dynamic dns for wireguard peer
Dear team;
we have multiple business with many branches the have smb internet with no static ip address assigned t...
Abdulaziz Al-Marwani

09/13/2023

12:25 PM Feature #14588: Add FRR diagnostic status output plugin
See #14777 for implementation details once that is complete. Jim Pingle

09/12/2023

05:45 PM Regression #14739 (Resolved): PHP error with lightsquid when generating an SSL certificate
Resolved with 3.0.7_1. Marcos M
05:04 PM Regression #14739 (Feedback): PHP error with lightsquid when generating an SSL certificate
Jim Pingle
03:31 PM Bug #14775 (New): FRR LocPrf and Weight is forced to 0
frr8-8.5.2
Because some upstream routes show that LocPrf and Weight are 0. FRR LocPrf and Weight is forced to 0
...
yon Liu
02:17 PM Regression #14774 (Feedback): Lightsquid won't allow change the password.
I pushed a fix for this, it will be available shortly. Jim Pingle
01:42 PM Regression #14774 (Resolved): Lightsquid won't allow change the password.
I had the latest version of lightsquid 1.8.5 3.0.7_2.
Is not accepting new password for the user 'admin'.
It wo...
Peter Moreno

09/11/2023

03:57 PM Regression #14739: PHP error with lightsquid when generating an SSL certificate
Fixed in commit @9be9459ba796313087ca34b63c3deee7f181faea@ it will be in the next snapshot builds. Jim Pingle
03:32 PM Regression #14739 (In Progress): PHP error with lightsquid when generating an SSL certificate
The new fix wasn't quite right (has a couple incorrect variable references. New fix coming momentarily. Jim Pingle
03:56 PM Bug #14771: Lightsquid creating multiple SSL certificates, not starting
I pushed a fix for this ( @52f6d98647b961eefa693ca3ab793785befd3a5d@ ), it should be available soon.
The fix could...
Jim Pingle
03:47 PM Bug #14771 (In Progress): Lightsquid creating multiple SSL certificates, not starting
I take that back, it's not related, but I fixed it when I fixed the other issue. Though when I fixed that, I used fun... Jim Pingle
03:40 PM Bug #14771 (Duplicate): Lightsquid creating multiple SSL certificates, not starting
This is from the change in #14739 -- that one is still open (in feedback state) so I'm closing this and noting the fi... Jim Pingle
02:14 PM Bug #14771 (Resolved): Lightsquid creating multiple SSL certificates, not starting
Hello we update lightsquid the latest version and we found that stop working.
Every time we try to access the repo...
Peter Moreno
03:14 AM Feature #14770: Search for addresses and ports optimization
I understand there is a note for admins to use regex style but there really should be a simplier way....
a seperate ...
Mike Moore
02:57 AM Feature #14770 (New): Search for addresses and ports optimization
The search field for source IP addresses requires a bit of optimization.
If you search for source IP 192.168.3.3 the...
Mike Moore

09/10/2023

03:32 PM Bug #14748: FRR reload script is not executed properly
yes, Now any changes need to restart the frr service to take effect. yon Liu
01:53 AM Regression #14739: PHP error with lightsquid when generating an SSL certificate
Hello.
Does this bug is related to the error about lightsquid creating certs each we try to access the reports and w...
Peter Moreno

09/09/2023

07:08 PM Regression #14764 (Confirmed): HAProxy local syslog not working
HAProxy package v0.63_1
Setting the syslog host to @/var/run/log@ in the HAProxy settings doesn't produce any entr...
Michael Vincent

09/08/2023

09:11 PM Bug #14711: pfBlocker ASN to IP Address option doesn't work
It seems to be working again for me! Hayden Hill
07:49 PM Feature #9833: ACME: add ability to use custom ACME server
+1 for me too. I'd like to set it up with FreeIPA 4.9 as it starts to support the ACME protocol for certificates. Ben Tyger
05:39 AM Bug #14748 (Confirmed): FRR reload script is not executed properly
I can confirm this behavior, the Frr keeps the neighbor config until the restart of the service
tested on
<pre...
Lev Prokofev
02:05 AM Feature #14539: Add support for Oracle Cloud Infrastructure (OCI) vNIC management to work with unicast CARP
Package PR: https://github.com/pfsense/FreeBSD-ports/pull/1291
With initial commit to introduce this capability.
James George

09/07/2023

04:07 PM Bug #14760 (New): When RPKI is enabled for filtering, no upstream routes are received
When RPKI is enabled for filtering, no upstream routes are received.
route-map RPKI deny 20
match rpki invalid
...
yon Liu
12:54 PM Bug #14460: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string in /usr/local/pkg/haproxy/haproxy.inc:2158
Will open issue in TAC asap.
Currently I don't have a GUI ... because the LE-Cert-Renewal fails because of the non-wo...
Stefan Weichinger
12:52 PM Bug #14460: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string in /usr/local/pkg/haproxy/haproxy.inc:2158
Stefan Weichinger wrote in #note-12:
> I have a 2nd pfSense (SG1100) that also has HAproxy not starting.
> Should I...
Jim Pingle
12:42 PM Bug #14460: PHP Fatal error: Uncaught TypeError: Cannot access offset of type string on string in /usr/local/pkg/haproxy/haproxy.inc:2158
I have a 2nd pfSense (SG1100) that also has HAproxy not starting.
Should I open a new issue in TAC, may I post the r...
Stefan Weichinger

09/06/2023

06:30 PM Feature #14032: Neighbor Discovery Proxy (NDproxy)
The port does not currently build on FreeBSD 14 according to:
https://gitlab.com/FreeBSD/freebsd-ports/-/commit/d738...
Marcos M
02:53 PM Bug #14754: Snort security issue bug within tcp/UDP scan detection blocking tool DoS event
Please Note:
bugs@snort.org does not respond to any emails with the report listed above. If you are reading this ...
Jonathan Lee
02:52 PM Bug #14754: Snort security issue bug within tcp/UDP scan detection blocking tool DoS event
Per Netgate Security Team on August 25, 2023 at 5:17:05 AM PDT:
Hello,
The Snort package for pfSense software i...
Jonathan Lee
02:50 PM Bug #14754 (Not a Bug): Snort security issue bug within tcp/UDP scan detection blocking tool DoS event
*Version:*
Snort 4.1.6_8 built on pfSense plus Netgate 2100 appliance running an ARM processor. Package is prebuilt...
Jonathan Lee
01:58 PM Bug #14753: pfBlockerNG sync issues
Tested on pfSense 23.05.1 and pfBlocker 3.2.0_6 and can confirm such issue. aleksei prokofiev
01:50 PM Bug #14753 (New): pfBlockerNG sync issues
pfBlockerNG sync user's password may cause sync issues and be recognised as an attacker by sshguard if it's password ... Georgiy Tyutyunnik

09/05/2023

08:04 PM Bug #14668: FRR BGP route is not making into kernel route table after WireGuard's peer change is applied
please upgrade pf23.09 and frr 8.5.2 for test yon Liu
07:58 PM Bug #12951: FRR cannot remove IPv6 routes

https://github.com/FRRouting/frr/issues/14205
23.09-DEVELOPMENT (amd64)
built on Tue Sep 05 05:55:55 UTC 2023...
yon Liu
07:39 PM Bug #14748 (Feedback): FRR reload script is not executed properly
I deleted frr Neighbors through webgui, but it was not deleted in frr.
That is, the deletion operation through pf...
yon Liu
05:12 PM Bug #14711: pfBlocker ASN to IP Address option doesn't work
For those looking for a workaround for now I found this. Can use it to pull a JSON.
https://github.com/ipverse/asn-ip
Hayden Hill
02:12 AM Bug #14711: pfBlocker ASN to IP Address option doesn't work
I can confirm this is an issue. ASN lookup no longer working for me. Hayden Hill
12:35 PM Bug #14747 (Needs Patch): softflowd sending same data with different snmp versions
That looks like something specific to the behavior of the daemon which is out of our control (unless there is a CLI/c... Jim Pingle

09/04/2023

11:36 PM Bug #14747: softflowd sending same data with different snmp versions
It seems that the problem is related to VLAN interfaces.
I've been doing some tests and if you set softflowd to coll...
Marcelo Cury
06:32 PM Bug #14747: softflowd sending same data with different snmp versions
upstream bug reported:
https://github.com/irino/softflowd/issues/51
Marcelo Cury
06:05 PM Bug #14747 (Needs Patch): softflowd sending same data with different snmp versions
My environment:
SG-4100 23.05.1, packages up to date and System patches applied.
sotflowd running on LAN, WIFI an...
Marcelo Cury
12:40 PM Feature #14712: CrowdSec package
Hi!
The package is ready for public testing.
Three things to read:
- the short repository readme - https://...
Marco Mariani
05:56 AM Bug #14745 (New): haproxy: backend, SSL health check
During testing with a backend HTTPS server, I wanted to test if the SSL health check would work; it did not.
So, I d...
Stephen Trotter
01:33 AM Feature #14468: pass along ntopng professional license key
Just an update to say I have now successfully installed NTOPNG Pro version, via console, and licensed it on latest ve... Russ Reynolds

09/02/2023

07:12 PM Bug #14659: vlan (add/modify/delete) with pfblockerNG installed - all interfaces flap
This is still an issue but I have a feeling it’s related to 14484
Edit any interface will lead to a reconfiguration ...
Mike Moore
05:33 PM Bug #14659: vlan (add/modify/delete) with pfblockerNG installed - all interfaces flap
do you still see this flapping issue after removing or correcting the unresolvable source/destination alias messages ... Jordan G
07:11 AM Feature #14629 (Resolved): Add option control LCDProc ``syslog`` behavior
Tested the package version:... Danilo Zrenjanin

09/01/2023

06:23 PM Regression #14739 (Feedback): PHP error with lightsquid when generating an SSL certificate
Should be fixed in commit @11ed1711e84357241c044c82e7f2be7186375e75@ (https://github.com/pfsense/FreeBSD-ports/commit... Jim Pingle
05:40 PM Regression #14739 (Resolved): PHP error with lightsquid when generating an SSL certificate
... Marcos M
04:24 PM Bug #14406 (Feedback): Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
I tested this on 23.09 dev snapshots and I'm not able to replicate the issue. The files are in the directory:
{{co...
Marcos M
09:08 AM Bug #14730: FreeRADIUS package has wrong/old internal_name specified in backup xml causing package reinstall failure on backup restore
Let me try give you more info to reproduce. We have the issue on many devices not just one. We also had this issue on... Luca Piccirillo
06:54 AM Bug #14733: CARP Master before HA Proxy is started
Hi Jim,
Thanks for the quick response and suggestion. Changing the WebUI port makes sense to get rid of the confli...
Christopher de Haas
06:48 AM Bug #13405: Wireguard: The webgui becomes excessively slow to respond with a large number of peers
I can also confirm this, but its happening to me with only some Peers (exactly, 4 tunnels, about 10 peers in total) I... David Martin

08/31/2023

05:16 PM Bug #14406: Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
"2Amos Jeffries 2023-08-29 18:26:02 UTC
AFAICT "0.4.46" is the version number of the pfsense plugin used to integra...
Jonathan Lee
02:43 PM Bug #14733 (Not a Bug): CARP Master before HA Proxy is started
Sounds like you have something misconfigured. You are trying to bind two things to the same port on the same address ... Jim Pingle
11:09 AM Bug #14733 (Not a Bug): CARP Master before HA Proxy is started
Pfsense becomes CARP master before HA proxy is started. This is a significant problem and causes unneeded outages. Wh... Christopher de Haas
09:02 AM Bug #14730: FreeRADIUS package has wrong/old internal_name specified in backup xml causing package reinstall failure on backup restore
Just checked on pfSense 2.7.0
Backup version is the same as yours.
internal_name is still there as before.
Not sure ...
Luca Piccirillo
06:41 AM Bug #14730: FreeRADIUS package has wrong/old internal_name specified in backup xml causing package reinstall failure on backup restore
I couldn't reproduce this issue on the:... Danilo Zrenjanin
07:24 AM Bug #14670 (Resolved): net-snmp does not ignore /var/unbound/dev
The latest release 0.1.5_11 contains the ignoreDisk directive for /var/unbound/dev ... Danilo Zrenjanin

08/30/2023

09:01 PM Bug #14108: Antivirus Bases showing outdated main.cvd with a version dated year 2021
Also confirmed via Andrew C. Aitchison of ClamAV users support email system.
"It is a very big file and stores the...
Jonathan Lee
02:12 PM Feature #8547: fwknop Port Knocking Package
I'm willing to chip in, help code this myself or hire someone to develop this. Either way I'd like to see this packa... Alan V
02:09 PM Feature #8547: fwknop Port Knocking Package
I really want to see this as well. I'll explain why people want fwknop or at the minimum knockd support...
Fwknop...
Alan V
12:49 PM Bug #14722 (Duplicate): Snort Rule Update time settings does not create cron job correctly with certain times
Jim Pingle
12:49 PM Bug #14724 (Resolved): Suricata package incorrectly accounts for 24-hour rollover when creating automated rules update cron task and a 12-hour update interval is selected
PR merged, thanks! Jim Pingle
12:49 PM Bug #14723 (Resolved): Snort package incorrectly handles rollover from 23 to 00 hours when calculating rules update cron task times
PR merged, thanks! Jim Pingle
11:14 AM Bug #14730 (New): FreeRADIUS package has wrong/old internal_name specified in backup xml causing package reinstall failure on backup restore
When backing up with package info included:... Luca Piccirillo

08/29/2023

07:41 PM Bug #14108 (Rejected): Antivirus Bases showing outdated main.cvd with a version dated year 2021
2021 is the most recent main.cvd/main.cld file from ClamAV directly. The daily file gets updated more regularly.
F...
Jim Pingle
06:40 PM Bug #14108: Antivirus Bases showing outdated main.cvd with a version dated year 2021
From Squid and indirectly also c-icap upstream(s):
Neither Squid nor c-icap have anything to do with the ClamAV dat...
Amos Jeffries
06:31 AM Bug #14108: Antivirus Bases showing outdated main.cvd with a version dated year 2021
https://bugs.squid-cache.org/show_bug.cgi?id=5297
Bug zilla ticket also open for Squid side for more visibility of...
Jonathan Lee
01:54 PM Feature #14729 (New): OpenVPN Client Export - Support PLAP on Windows
OpenVPN 2.6 for Windows introduced support for PLAP (Pre-Logon Access Provider). With this support, users get a new i... Pablo Bendersky
06:36 AM Bug #14341: Squid Cache Table Logs Showing incorrect date
https://bugs.squid-cache.org/show_bug.cgi?id=5298
Added to bugzilla for Squid for more support visibility
Jonathan Lee
06:21 AM Bug #14406: Squid Proxy version 0.4.46 Missing Error subfolder and files for "en" or "en-usa" and all other languages.
https://bugs.squid-cache.org/show_bug.cgi?id=5296
Bugzilla Squid ticket now open for more Squid support visibility.
Jonathan Lee

08/28/2023

05:15 PM Bug #14722: Snort Rule Update time settings does not create cron job correctly with certain times
This is a duplicate of bug 14723. My report of the user-identified issue and the acutal user's report of the same iss... Bill Meeks
04:37 PM Bug #14722 (Duplicate): Snort Rule Update time settings does not create cron job correctly with certain times
What happens is that when a combination of update interval and hour is set that adds up to 24, the script that create... Benjamin McRobert
05:13 PM Bug #14724: Suricata package incorrectly accounts for 24-hour rollover when creating automated rules update cron task and a 12-hour update interval is selected
Pull Request 1289 (https://github.com/pfsense/FreeBSD-ports/pull/1289) has been submitted to correct this issue. This... Bill Meeks
04:44 PM Bug #14724 (Resolved): Suricata package incorrectly accounts for 24-hour rollover when creating automated rules update cron task and a 12-hour update interval is selected
The Suricata package GUI incorrectly adjusts the starting hour for the automated rules update cron task when the user... Bill Meeks
05:12 PM Bug #14723: Snort package incorrectly handles rollover from 23 to 00 hours when calculating rules update cron task times
Pull Request 1288 (https://github.com/pfsense/FreeBSD-ports/pull/1288) has been submitted to resolve this issue.
T...
Bill Meeks
04:38 PM Bug #14723 (Resolved): Snort package incorrectly handles rollover from 23 to 00 hours when calculating rules update cron task times
The Snort package incorrectly adjusts the rollover from 23:xx hours to 00:xx hours when creating the cron task for au... Bill Meeks
04:01 PM Bug #13432: ups driver will not start
I started having similar issue after upgrade to 2.7.0 (was working before)
got notices and saw "upsmon" giving "fail...
Tom Bauer
01:02 PM Bug #14426 (Resolved): PHP errors in Lightsquid
The PR was merged. Jim Pingle

08/27/2023

08:05 AM Feature #9916 (Resolved): Check allow-transfer in custom option when the zone is slave
Tested on 23.05_1
Allow-transfer option check was added and there wasn't any bind error if I add this option into Cu...
Azamat Khakimyanov
05:21 AM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"

Different way to iterate the variable for multiple cases
You can also use the the case command to iterate over t...
Jonathan Lee

08/26/2023

11:57 PM Regression #13817: pfBlockerNG-devel cron jobs persist after the service is disabled or the package is uninstalled
on 23.05.1 and pfB 3.2.0_6 after working through getting the package to uninstall successfully (see https://redmine.p... Jordan G
11:47 PM Bug #14572: Unused DNSBL files may not be removed
Kris Phillips wrote in #note-1:
> Hello,
>
> Is this with the devel or stable branch of pfBlockerNG?
devel and...
Jordan G
11:03 PM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
This is still happening with pfBlockerNG 3.2.0_6. I believe I've found a workaround for this after chasing a few of t... Jordan G
07:08 AM Bug #14711 (Confirmed): pfBlocker ASN to IP Address option doesn't work
Tested on pfBlocker 3.2.0_6
It failed to load list....
Lev Prokofev
07:06 AM Bug #14718 (New): pfBlocker DNSBL IPs list action is wrongly named
!clipboard-202308260857-oz2vd.png!
Under *Firewall/pfBlockerNG/DNSBL* there is *DNSBL IPs* section.
The *Alias ...
Danilo Zrenjanin
12:19 AM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
Non standard colours also
@#!/bin/sh
pfctl -vvss | grep ', rule 79' >/dev/null
res=$?
if [ $res = 0 ];
then
...
Jonathan Lee

08/25/2023

08:56 PM Bug #14426 (Pull Request Review): PHP errors in Lightsquid
https://gitlab.netgate.com/pfSense/FreeBSD-ports/-/merge_requests/353 Marcos M
08:10 PM Regression #13984 (Resolved): PHP errors with squid
Marcos M
04:13 PM Bug #14714: HAProxy Agent Check
Bug No 2 is now described in Bug #14715 Jacques Bourdeau
03:56 PM Bug #14714: HAProxy Agent Check
Jacques Bourdeau wrote in #note-2:
> Jim Pingle wrote in #note-1:
> > Please create a separate issue entry for each...
Jim Pingle
03:46 PM Bug #14714: HAProxy Agent Check
Jim Pingle wrote in #note-1:
> Please create a separate issue entry for each problem, even if they appear to be rela...
Jacques Bourdeau
03:21 PM Bug #14714: HAProxy Agent Check
Please create a separate issue entry for each problem, even if they appear to be related.
Jim Pingle
03:03 PM Bug #14714 (New): HAProxy Agent Check
For my load balancing, I ended up needing to use Agent-based checks in HAProxy.
I configured it in my pfSense+ (23...
Jacques Bourdeau
04:06 PM Bug #14715 (New): HAProxy Agent-Check are not enabled in the config despite being checked in the UI
Related to Bug #14714 which also does not populate the config file properly for agent-check based monitoring in HAPro... Jacques Bourdeau
04:01 PM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
If anyone knows of a more efficient want to poll the state table, please let me know.
Have a good day
Jonathan Lee
03:59 PM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
Here is a photo of testing with the three LEDs enabled when rule 79 went active.
Does the state table counters als...
Jonathan Lee
03:49 PM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
I wonder if there is another way to do it maybe with the active state tables counters. Thanks for looking into this i... Jonathan Lee
03:27 PM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
I don't see anything like that being added to the base system, but maybe someone might design a package around it.
...
Jim Pingle
04:54 AM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
Side note, I recently learned "The Air force one Executive Phone has a light on the back that lights up red when secu... Jonathan Lee
02:03 AM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
pfctl -vvss| grep '192.168.1.11' would work great too as it would be IP address based not rule based
also
pfctl -vv...
Jonathan Lee
01:26 AM Feature #14710: Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
The capability is you can take any rule ID you have that establishes a connection and you could configure it to be us... Jonathan Lee
01:12 AM Feature #14710 (New): Possible Idea for new firewall feature "ACL CONNECTED RED LED FLAG FEATURE"
Hello fellow Netgate pfSense Redmine community members,
I wanted to share this with you all to see if this is any...
Jonathan Lee
01:17 PM Feature #14712: CrowdSec package
e ok wrote:
> I think is not necessary another IPS, but I leave here If something consider that is more robust or go...
Marco Mariani
12:32 PM Feature #14712 (New): CrowdSec package
I think is not necessary another IPS, but I leave here If something consider that is more robust or good tan Snort or... e ok
06:30 AM Bug #14711 (Resolved): pfBlocker ASN to IP Address option doesn't work
pfBlocker relies on Team Cymru IP to ASN Lookup v1.0 to get the list of prefixes for the defined ASN. But it seems th... Danilo Zrenjanin
06:12 AM Bug #12822 (Confirmed): IPv4 Source ASN format not working
I have tried to define the ASN format and it appears that it is still not working consistently. Occasionally, it does... Danilo Zrenjanin

08/24/2023

02:29 PM Feature #14706 (New): Add Cloudflare tunnel pkg
Hello everybody,
I've been using Cloudflare tunnel for more than an year as I'm now behind CGNAT so no more open p...
Vlad Saftoiu

08/23/2023

05:18 PM Bug #14704 (Duplicate): FRR BGP Neighbor configuration page no longer displays BFD Peer(s) in the BFD section
Duplicate of #14654
It's already fixed in the most recent version of the package.
Jim Pingle
05:10 PM Bug #14704 (Duplicate): FRR BGP Neighbor configuration page no longer displays BFD Peer(s) in the BFD section
Hello,
I can no longer select a BFD Peer when creating a FRR BGP neighbor.
As an example.
I have two (2) BFD...
Michael Mercier

08/22/2023

07:16 PM Bug #14349 (Closed): The ClamAV 0.105.1 got a few vulnerabilities
It's already fixed in dev snaps, it'll come back naturally with the next release.
Jim Pingle

08/21/2023

02:01 PM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
Thanks for looking at this and testing the various inputs. I did not know about the other reporting URL I will use th... Jonathan Lee
01:52 PM Feature #14696 (Rejected): possible cross site scripting and URL manipulation shell access injection issue sgerror.php
That action is just echoing back the input to the user but as it passes through a query string and so on, the content... Jim Pingle

08/19/2023

05:47 PM Bug #14683: PHP error on ``status_frr.php`` from using too much memory
Since this is the same base issue solved by the PHP patch, I'm marking this as a duplicate of https://redmine.pfsense... Christopher Cope
05:47 PM Bug #14683 (Duplicate): PHP error on ``status_frr.php`` from using too much memory
Christopher Cope
12:05 AM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
/usr/local/www/sgerror.php
has no ability to disable internal error redirect functionality when utilizing externa...
Jonathan Lee
12:03 AM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
In my case https://192.168.1.1:8080/sgerror.php?url=403%20Blocked%20by%20Mom%20and%20Dad&a=%a&n=%n&i=%i&s=%s&t=%t&u=%... Jonathan Lee
12:02 AM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
sgerror.php is also still accessible even with the internal error redirector redirecting to external site like Google... Jonathan Lee

08/18/2023

11:13 PM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
I wonder if there is any php injection vulnerabilities here. I did get it to say hello world. I noticed there is some... Jonathan Lee
10:48 PM Feature #14696: possible cross site scripting and URL manipulation shell access injection issue sgerror.php
if I can force it to say hello world, you could force it to say it a million times and do a denial of service attack ... Jonathan Lee
10:33 PM Feature #14696 (Rejected): possible cross site scripting and URL manipulation shell access injection issue sgerror.php
Hello fellow pfSense Redmine team,

I seem to have found an issue with sgerror.php allowing a user to adapt the ph...
Jonathan Lee
04:31 PM Bug #14694 (Not a Bug): HAProcy
I'm using ACME certs with HAProxy and it works fine here, so it's not clear why yours might be failing.
This site ...
Jim Pingle
05:02 AM Bug #14694 (Not a Bug): HAProcy
After the latest update I can no longer assign an ACME certificate to a HAProxy Frontend, not matter which certificat... Rick Strangman

08/17/2023

08:10 AM Bug #14683: PHP error on ``status_frr.php`` from using too much memory

and changed config.inc
// Set memory limit to 512M on amd64.
if ($ARCH == "amd64") {
ini_set("memory_limit", ...
yon Liu
08:06 AM Bug #14683: PHP error on ``status_frr.php`` from using too much memory
i have changed php tomemory_limit = 1200M now,it is ok.
and if run frr bgp route, the kern.ipc.maxsockbuf must be ch...
yon Liu
 

Also available in: Atom