Project

General

Profile

Activity

From 10/16/2023 to 11/14/2023

11/14/2023

09:50 PM Bug #14748: FRR reload script is not executed properly
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=275095 Christian McDonald
05:54 PM Bug #14748: FRR reload script is not executed properly
We are looking into it here. Christian said he sees the issue in port and is looking into a fix. Jim Pingle
04:51 PM Bug #14748: FRR reload script is not executed properly
Im impacted as well
Jim - Who is supposed to follow up with any upstream issue?
Mike Moore
04:07 PM Bug #14748: FRR reload script is not executed properly
Looks like that's an upstream bug in the @frr9@ or @frr9-pythontools@ port(s).
The script at @/usr/local/sbin/frr-...
Jim Pingle
12:19 PM Bug #14748: FRR reload script is not executed properly
We had the same issue when using FRR OSPF. It seems that the "frr-reload" script that is used to communicate config c... Steffen S
04:39 PM Todo #14795: Transition to nut-devel
Hey all, I've got a good dozen testers that have reported successful results with 2.8.1. Reported tests include local... Denny Page
04:31 PM Bug #14979 (Resolved): Snort generates an invalid $EXTERNAL_NET variable in snort.conf due to a missing escape character in the PHP code
PR Merged, thanks! Jim Pingle
12:55 AM Bug #14979: Snort generates an invalid $EXTERNAL_NET variable in snort.conf due to a missing escape character in the PHP code
Two different pull requests have been submitted to correct this bug: 1 each for the 2.7.0 CE Release and 2.8.0 CE DEV... Bill Meeks
12:27 AM Bug #14979 (Resolved): Snort generates an invalid $EXTERNAL_NET variable in snort.conf due to a missing escape character in the PHP code
The recent 4.1.6_12 Snort GUI package update contained a typo in @/usr/local/pkg/snort/snort_generate_conf@ . A backs... Bill Meeks

11/13/2023

07:49 PM Bug #14956 (Resolved): Suricata GUI generates invalid syslog priority values in suricata.yaml file for some drop-down list values
PR merged, thanks! Jim Pingle
07:48 PM Bug #14955 (Resolved): Suricata GUI throws a PHP error when creating an EventTime object for use on the ALERTS or BLOCKS tabs if there is a malformed log file entry
PR merged, thanks! Jim Pingle
07:48 PM Feature #14954 (Resolved): Add GUI option to Suricata interface settings for logging of Ethernet (MAC) addresses to the EVE JSON log
PR merged, thanks! Jim Pingle
07:48 PM Bug #14961 (Resolved): Snort package issue in snort_Getdirsize() function due to behavior change in PHP 8.x
PR merged, thanks! Jim Pingle
07:48 PM Bug #14645 (Resolved): Snort interface "External Net" (EXTERNAL_NET) custom IP list should have negation when expanded
PR merged, thanks! Jim Pingle
06:34 PM Bug #14645: Snort interface "External Net" (EXTERNAL_NET) custom IP list should have negation when expanded
Hi Bill,
main problem is when you have some static IPs outside of your network (let's say your work IPs or your VP...
Dzmitry Kazei
01:45 PM Todo #14971: Add text about the limit to use only Network type alias for Custom Destination
Thanks.
I think it will be good to add a category of UI, for both the text and visuals of UI.
Wolfgang Thegreat
01:41 PM Todo #14971: Add text about the limit to use only Network type alias for Custom Destination
Wolfgang Thegreat wrote in #note-2:
> I didn't find a more suitable place to ask for it. Can you direct me?
It's ...
Jim Pingle
01:32 PM Todo #14971: Add text about the limit to use only Network type alias for Custom Destination
I didn't find a more suitable place to ask for it. Can you direct me? Wolfgang Thegreat
01:24 PM Todo #14971: Add text about the limit to use only Network type alias for Custom Destination
This is asking for a change to the GUI, not the documentation. Jim Pingle
01:23 PM Bug #14638 (Closed): Upgrading from Tailscale 0.1.3.1 to 0.1.4 does not start tailscale after upgrading
Jim Pingle

11/12/2023

01:06 AM Regression #13970 (Feedback): PHP error in apcupsd widget from UTF-8 string handling
The widget has the following for the default entries in the warning/critical values by default, or possibly from a pr... Jordan G

11/11/2023

11:56 PM Regression #14764: HAProxy local syslog not working
Discussion thread: https://forum.netgate.com/topic/182508/haproxy-local-syslog-not-working Michael Vincent
11:46 PM Bug #14364: APCUPSD unable to process date string
Not sure where the date format is being pulled from, I'm using an older bn700 APC UPS and my date format is mm/dd/yyy... Jordan G
09:45 PM Todo #14971 (New): Add text about the limit to use only Network type alias for Custom Destination
Hello,
At the UI path of pfBlockerNG > IP > IPv4 > edit of a table object > the section of "Advanced Inbound Firew...
Wolfgang Thegreat
09:56 AM Bug #14638: Upgrading from Tailscale 0.1.3.1 to 0.1.4 does not start tailscale after upgrading
I couldn't replicate it either.
There are no complaints from anyone else.
As a result, I recommend that we pro...
Danilo Zrenjanin

11/10/2023

02:02 AM Bug #14645: Snort interface "External Net" (EXTERNAL_NET) custom IP list should have negation when expanded
This issue is corrected by Snort package update 4.1.6_12 posted for review and merge here: https://github.com/pfsense... Bill Meeks
12:40 AM Bug #14645: Snort interface "External Net" (EXTERNAL_NET) custom IP list should have negation when expanded
Sorry to be late replying to this ticket.
First, the double brackets is a bug and will be corrected in a forthcoming...
Bill Meeks
02:01 AM Bug #14961: Snort package issue in snort_Getdirsize() function due to behavior change in PHP 8.x
This issue is corrected by Snort package update 4.1.6_12 posted for review and merge here: https://github.com/pfsense... Bill Meeks
12:46 AM Bug #14961 (Resolved): Snort package issue in snort_Getdirsize() function due to behavior change in PHP 8.x
Beginning with PHP 8.x specific ASCII control characters should be wrapped with @chr()@ to insure they are interprete... Bill Meeks

11/09/2023

10:20 PM Feature #14954: Add GUI option to Suricata interface settings for logging of Ethernet (MAC) addresses to the EVE JSON log
The requested feature has been added in code associated with Pull Request 1313 posted here for review and merge: http... Bill Meeks
01:44 AM Feature #14954: Add GUI option to Suricata interface settings for logging of Ethernet (MAC) addresses to the EVE JSON log
I am working on adding this feature to a forthcoming GUI package update. Bill Meeks
01:31 AM Feature #14954 (Resolved): Add GUI option to Suricata interface settings for logging of Ethernet (MAC) addresses to the EVE JSON log
Add an option to the INTERFACE SETTINGS tab to allow the use to enable or disable Ethernet (MAC) addresses to the EVE... Bill Meeks
10:18 PM Bug #14955: Suricata GUI throws a PHP error when creating an EventTime object for use on the ALERTS or BLOCKS tabs if there is a malformed log file entry
This issue is resolved by Pull Request 1313 posted for review and merging here: https://github.com/pfsense/FreeBSD-po... Bill Meeks
01:44 AM Bug #14955: Suricata GUI throws a PHP error when creating an EventTime object for use on the ALERTS or BLOCKS tabs if there is a malformed log file entry
I will address this problem in a forthcoming GUI package update. Bill Meeks
01:36 AM Bug #14955 (Resolved): Suricata GUI throws a PHP error when creating an EventTime object for use on the ALERTS or BLOCKS tabs if there is a malformed log file entry
A line containing a number of consecutive spaces in either the @alerts.log@ or @blocks.log@ files will cause a fatal ... Bill Meeks
10:17 PM Bug #14956: Suricata GUI generates invalid syslog priority values in suricata.yaml file for some drop-down list values
This issue is resolved with Pull Request 1313 posted for review and merge here: https://github.com/pfsense/FreeBSD-po... Bill Meeks
01:45 AM Bug #14956: Suricata GUI generates invalid syslog priority values in suricata.yaml file for some drop-down list values
I am addressing this problem in a forthcoming GUI package update. Bill Meeks
01:42 AM Bug #14956 (Resolved): Suricata GUI generates invalid syslog priority values in suricata.yaml file for some drop-down list values
The Suricata GUI code generates invalid syslog priority values in the @suricata.yaml@ file for several drop-down list... Bill Meeks
08:58 PM Bug #14898: Suricata core dumps with signal 11
I may have found the culprit here (quite by accident I will admit). I think this commit by @kprovost might have fixed... Bill Meeks
04:43 AM Bug #14898: Suricata core dumps with signal 11
I have not been able to reliably reproduce this crash, but I am testing on pfSense 2.7.0 CE with the latest Suricata ... Bill Meeks
05:16 PM Todo #14795: Transition to nut-devel
Thank you! Denny Page
05:15 PM Todo #14795: Transition to nut-devel
Sure, see attached. Marcos M
03:09 AM Todo #14795: Transition to nut-devel
Thank you Marcos. Can you also post the ARM version please?
Denny Page
12:33 AM Todo #14795 (Feedback): Transition to nut-devel
# Install @nut@ from the package manager GUI
# Upload the attached file to the firewall
# Remove the old dependency...
Marcos M

11/08/2023

03:09 PM Bug #14898: Suricata core dumps with signal 11
Thank you Marcos for the hint about the VIP. I am investigating. The crash is happening within a portion of the custo... Bill Meeks
01:51 PM Bug #14951 (Duplicate): Tripplite Smart1500LCD UPS
Almost certainly the same as other similar recent reports. Some driver/OS change is causing this device to need root ... Jim Pingle
04:19 AM Bug #14951 (Duplicate): Tripplite Smart1500LCD UPS
I wanted to create this incident ticket to advise the pfsense development team that when I had pfsense version 2.6, I... Adam Di Vizio
12:15 AM Todo #14073: Shalla block list is offline but still available in pfBlocker
Can we get this package cleaned up at least with the removal of the list.
Its causing confusion from users.
Mike Moore

11/07/2023

04:48 PM Bug #14932: mailreport 3.6.4_1 doesn't handle name address format "Name <email@domain.com>" in sender
From examining mail server logs it looks like mailreport sends the email but it sets the from address in the header t... Andrew Dakin

11/06/2023

08:58 PM Feature #14712: CrowdSec package
I created a PR for the package at https://github.com/pfsense/FreeBSD-ports/pull/1311
Marco Mariani
01:08 AM Bug #14926: Squid Proxy contains critical vulnerabilities
Pretty sure there isnt an official maintainer for Squid in pfSense. Assume that the package will not receive any bug ... Mike Moore

11/05/2023

06:40 AM Bug #14836: squid and capitive portal integration bug
Tested on
23.05.1-RELEASE (amd64)
built on Wed Jun 28 03:57:27 UTC 2023
FreeBSD 14.0-CURRENT
I can confirm such...
aleksei prokofiev
06:31 AM Bug #14932: mailreport 3.6.4_1 doesn't handle name address format "Name <email@domain.com>" in sender
Tested on
23.05.1-RELEASE (amd64)
built on Wed Jun 28 03:57:27 UTC 2023
FreeBSD 14.0-CURRENT
mailreport 3.6.4...
aleksei prokofiev

11/04/2023

09:31 AM Bug #11074 (Confirmed): bind Zone Settings Zones, Save button opens "Confirmation required to save changes"
I can confirm that the Popup dialog appears after hitting the *Save* button.
I don't see the purpose of this Popu...
Danilo Zrenjanin
08:48 AM Bug #14771 (Resolved): Lightsquid creating multiple SSL certificates, not starting
Tested against:... Danilo Zrenjanin
02:32 AM Bug #14895: Wireguard / bad performance after reboot, if running together with OpenVPN
Is it possible your Wireguard tunnel is trying to establish over your OpenVPN tunnel somehow due to a route-all direc... Kris Phillips
02:30 AM Bug #14934: haproxy-devel: "Warning: process cannot be trusted anymore!" since pfSense Plus Upgrade to
This issue only affects the devel version of HAProxy and not the stable version on 23.05.1. Tested this on pfSense P... Kris Phillips

11/03/2023

09:46 AM Feature #14941 (New): add directdomains list in GUI
Is it possible to add directly in the GUI a directdomains category like whitelist or blacklist ...
this directdomain...
Claude-Axel Piller

11/02/2023

01:58 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
Patch was sent upstream: https://reviews.freebsd.org/D42415 Christian McDonald

11/01/2023

05:18 PM Regression #14904 (Resolved): FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
I can confirm it works as expected on 23.09. ... Danilo Zrenjanin

10/31/2023

11:33 PM Bug #14898: Suricata core dumps with signal 11
This time it continued to crash after an update to the latest 23.09 snap. It seems to be related to the existence of ... Marcos M
02:16 PM Feature #14633: Cleanup states on dynamic routing changes
Any update on this? Without cleanup up states on route changes, routing based redundancy is impossible to implement. ... Christopher de Haas

10/30/2023

05:07 PM Bug #14934: haproxy-devel: "Warning: process cannot be trusted anymore!" since pfSense Plus Upgrade to
At the suggestion of one of the Netgate admins on the forums when I asked this to get poked, this issue **does not ha... Thomas Ward
04:43 PM Bug #14934: haproxy-devel: "Warning: process cannot be trusted anymore!" since pfSense Plus Upgrade to
NOTE: As part of testing, I reverted to 2.7.6-4dadaaa and into the pfSense Plus 23.05 (without .1) saved auto boot en... Thomas Ward
04:26 PM Bug #14934 (Resolved): haproxy-devel: "Warning: process cannot be trusted anymore!" since pfSense Plus Upgrade to
haproxy-devel version: 2.8-dev6-4c7588d
pfSense+ Version: 23.05.1
With the update to pfSense 23.05.1, HAProxy no...
Thomas Ward
01:30 PM Feature #14652: FRR OSPF6 not working over wireguard
when restart wg service, then VIP setup LL address is lost in wg interface. it can't always keep for wg interface yon Liu
01:30 PM Todo #14881: for wiregaurd interface add linklocal IPv6 address
when restart wg service, then VIP setup LL address is lost in wg interface. it can't always keep for wg interface. yon Liu

10/29/2023

08:42 AM Bug #14753: pfBlockerNG sync issues
Tested on pfBlocker 3.2.0_6
23.09-RC (amd64)
built on Fri Oct 27 1:51:00 UTC 2023
FreeBSD 14.0-CURRENT
The iss...
aleksei prokofiev
04:54 AM Bug #11515: node_exporter 0.18.1_1 - Unable to interact or start the service from web ui
service appears to start when enabled and shows positive indication in the service status dashboard on 23.09.r.202310... Jordan G
04:29 AM Bug #14287: pfBlockerNG does not uninstall cleanly when using RAM disks
seeing this on pfBlockerNG 3.2.0_6 on 23.09.r.20231027.0151, this was a clean install and immediately attempting to r... Jordan G
02:57 AM Bug #14861 (New): PHP error when pings are enabled but no ping hosts are defined
Crash report from Forum post:
Crash report begins. Anonymous machine information:
amd64
14.0-CURRENT
FreeBSD ...
Kris Phillips
02:57 AM Bug #14861: PHP error when pings are enabled but no ping hosts are defined
David Bowen wrote in #note-2:
> Kris Phillips wrote in #note-1:
> > Tested on 23.09 and unable to reproduce.
> >...
Kris Phillips
12:37 AM Bug #7267 (Resolved): Status Traffic Totals - Stacked Bar - Scale not high enough
No longer an issue on... Christopher Cope

10/28/2023

03:43 PM Bug #14932 (New): mailreport 3.6.4_1 doesn't handle name address format "Name <email@domain.com>" in sender
mailreport 3.6.4_1 doesn't handle name address format "Name <email@domain.com>". pfSense will correctly use and send ... Andrew Dakin
02:23 PM Bug #14861: PHP error when pings are enabled but no ping hosts are defined
Kris Phillips wrote in #note-1:
> Tested on 23.09 and unable to reproduce.
>
> What are the exact steps to prod...
David Bowen

10/27/2023

12:38 PM Bug #14926 (Rejected): Squid Proxy contains critical vulnerabilities

Squid 5.8 (shipped by the current pfSense package) is affected by the following vulnerabilities:
Critical:
* "S...
Peter Müller

10/26/2023

04:18 PM Bug #14858 (Closed): Possible SNORT Regression with Remove Blocked Hosts interval / Alert length of time / duration timer being auto changed timer changed by itself and is deleting blocked hosts at 5 mins when set to never
Marcos M

10/23/2023

03:28 PM Bug #14913 (Resolved): [Security] Zabbix packages need updating bec. of recent critical security CVEs
Several critical CVEs in Zabbix got recently reported. They are already addressed/fixed by Zabbix, but not yet availa... Carsten Lohrmann
01:50 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
Seems to be specific to 3100/armv7... Jim Pingle
12:22 PM Bug #14858 (Resolved): Possible SNORT Regression with Remove Blocked Hosts interval / Alert length of time / duration timer being auto changed timer changed by itself and is deleting blocked hosts at 5 mins when set to never
Jim Pingle
12:13 PM Bug #14905 (Duplicate): ARPing causes menu bar to stop working
This isn't a problem in arping but a problem with how some packages handle command output. It's already covered by #8502 Jim Pingle
12:13 PM Bug #13405: Wireguard: The webgui becomes excessively slow to respond with a large number of peers
+1 - Adding Wireguard widget to dashboard makes the dashboard load extremely slowly. Also the menus relating to wireg... Bogdan Tomasciuc

10/22/2023

06:49 PM Bug #14858: Possible SNORT Regression with Remove Blocked Hosts interval / Alert length of time / duration timer being auto changed timer changed by itself and is deleting blocked hosts at 5 mins when set to never
This issue was resolved when I saved the interval again can you please close this ticket. Jonathan Lee
06:47 PM Feature #14908 (New): FEATURE REQUEST: Snort Alerts / Blocked Page ability to save users order of list choice
Hello fellow Redmine pfSense community members,
I wanted to bring this up and see if anyone else noticed this. I a...
Jonathan Lee
01:21 PM Bug #11802: FreeRADIUS sync
The problem is relevant. It is impossible to use synchronization: the configuration of certificates on recipient node... Alex Viper_Rus
05:23 AM Bug #14905: ARPing causes menu bar to stop working
I have tested and can confirm this behavior. aleksei prokofiev

10/21/2023

11:31 PM Bug #14905 (Duplicate): ARPing causes menu bar to stop working
After running ARPing and getting the results, any attempt to navigate to another page by clicking the menu bar (Syste... Christopher Cope
08:14 PM Bug #14861 (Incomplete): PHP error when pings are enabled but no ping hosts are defined
Tested on 23.09 and unable to reproduce.
What are the exact steps to produce this PHP error? What platform are ...
Kris Phillips
06:40 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
There was a theory that this was UFS versus ZFS related. Testing on whitebox amd64 with ZFS I'm unable to reproduce ... Kris Phillips
04:38 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
I can reliably replicate the issue only on 3100. Danilo Zrenjanin
03:14 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
I can't reproduce it on the amd64 build ... Lev Prokofev
03:09 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
I can confirm that it worked as expected on 23.09.b.20231018.0600.
Danilo Zrenjanin
03:00 PM Regression #14904: FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
Tested against 23.09.b.20231020.0600 Danilo Zrenjanin
02:55 PM Regression #14904 (Resolved): FRR 9 crashes at startup on 23.09-BETA armv7 (3100)
... Danilo Zrenjanin

10/20/2023

06:32 PM Feature #14901 (New): Feature request - Adding in the GUI the advanced SHA and AES values for SNMPv3
I post this following this community forum post I published - https://forum.netgate.com/topic/183532/setting-advanced... Wolfgang Thegreat
04:17 PM Todo #14795: Transition to nut-devel
Merged here:
https://github.com/pfsense/FreeBSD-ports/commit/e55ac518e1e2a4359dbf3b0e5e36aa235bfe1f13
Marcos M
04:17 PM Todo #14795 (Resolved): Transition to nut-devel
Marcos M

10/19/2023

05:12 PM Bug #14898 (Resolved): Suricata core dumps with signal 11
I installed Suricata on a system with previous config using Legacy Mode, Enable/Disable/Drop SID lists. After attempt... Marcos M

10/18/2023

08:06 PM Bug #14895 (New): Wireguard / bad performance after reboot, if running together with OpenVPN
Hello,
I initially posted in the netgate forum, but in the meantime I conducted more investigations and I think I ...
Pascal Terrien
02:53 PM Bug #14390: Squid: SECURITY ALERT: Host header forgery detected
Can anyone advise on the feasibility of building a custom patched version of Squid (at least for testing purposes to ... Simon Byrnand

10/17/2023

03:48 PM Todo #14881: for wiregaurd interface add linklocal IPv6 address
The VIP page allows LL addresses, a new page isn't needed for that part. The MAC address can be manually set on assig... Marcos M
11:43 AM Todo #14881: for wiregaurd interface add linklocal IPv6 address

I used firewall_virtual_ip.php to add the fe80 address before, and it worked. However, this method has failed in re...
yon Liu
01:43 PM Feature #14890: dtlspipe package
I have told the author and he has seen this post. yon Liu
01:38 PM Feature #14890: dtlspipe package
First it would have to be added to FreeBSD ports Jim Pingle
01:24 PM Feature #14890 (New): dtlspipe package
This is a DTSL tool that has been tested and used. It can add DTLS support to almost all UDP. It is especially suitab... yon Liu

10/16/2023

10:30 PM Feature #13575 (Resolved): Update to frr 9.0.1
Marcos M
08:52 PM Todo #14881 (Duplicate): for wiregaurd interface add linklocal IPv6 address
Marcos M
08:48 PM Todo #14881 (Incomplete): for wiregaurd interface add linklocal IPv6 address
> I originally used aliases to add wg interfaces, but this method is invalid in version pf23.09.
What method is th...
Marcos M
08:51 PM Feature #14652: FRR OSPF6 not working over wireguard
> I guess this request might be regarded as a feature request to add link-local ipv6 to the tun_wg interface by defau... Marcos M
08:27 PM Feature #14652: FRR OSPF6 not working over wireguard
Probably related to #14881 beermount beermount
 

Also available in: Atom