Project

General

Profile

Activity

From 12/06/2023 to 01/04/2024

01/04/2024

08:51 AM Bug #15100: Tailscale IPv6 Exit Node uses first LAN interface when WAN is set to Only Request Prefix
This, or the broader issue of exit node gateway affects me with IPv4.
The seeming lack of configuration ability to s...
C C

01/03/2024

11:17 PM Bug #15132: bind-tools 9.18 pkg moved dnssec-* tools from sbin to bin
I'm working on the fix. The docs say to bump the version number in the makefile.
"When updating a package is it i...
Stuart Wyatt
04:12 AM Bug #15132 (New): bind-tools 9.18 pkg moved dnssec-* tools from sbin to bin
In bind.inc, the path to dnssec-keygen and dnssec-dsfromkey are hard coded to the /user/local/sbin/ directory. In bin... Stuart Wyatt

01/02/2024

06:41 PM Bug #15131: OpenVPN client export issues with iPhone and IPV6 connections
https://forums.openvpn.net/viewtopic.php?p=119902 (lists fix)
https://forums.openvpn.net/viewtopic.php?p=119904 (my ...
Jonathan Lee
06:38 PM Bug #15131 (Confirmed): OpenVPN client export issues with iPhone and IPV6 connections
I have researched and found an issue within the OpenVPN's client export config file for iPhones (OpenVPN Connect (iOS... Jonathan Lee
05:04 PM Todo #15119 (Feedback): Update nut-devel version and update startup script
Merged into devel branches, should be in snapshots for testing tomorrow. Jim Pingle

01/01/2024

01:30 PM Bug #14058: Update vendor=on triggers installation failure
I just ran into this with arpwatch on 23.09.1... JohnPoz _

12/27/2023

09:37 PM Bug #15120 (Not a Bug): Suricata upgrade/install adds default rulesets
Marcos M
09:21 PM Bug #15120: Suricata upgrade/install adds default rulesets
Suricata upstream periodically adds new built-in rules with upgrades. The new QUIC rules are one recent example, but ... Bill Meeks
08:12 PM Bug #15120 (Not a Bug): Suricata upgrade/install adds default rulesets
We had traditionally disabled stream-events.rules because of false positives. I have noticed a couple times lately it... Steve Y
08:00 PM Todo #15119: Update nut-devel version and update startup script
The startup script change is contained in PR https://github.com/pfsense/FreeBSD-ports/pull/1340.
The nut-devel upd...
Denny Page
07:48 PM Todo #15119 (Resolved): Update nut-devel version and update startup script
* Update nut startup script to avoid ups failure notifications on nut restart following interface changes.
* Updat...
Denny Page

12/26/2023

06:14 AM Bug #15115 (Closed): NUT Package Functionality
I read online that updating the OS version from 2.7 to 2.7.2 should fix some security bugs and I have also followed t... Adam Di Vizio
05:44 AM Bug #14951: Tripplite Smart1500LCD UPS
I read online that updating the OS version from 2.7 to 2.7.2 should fix some security bugs and I have followed the in... Adam Di Vizio

12/25/2023

07:38 PM Bug #13421: Stunnel certificate does not refresh
Tested, had to add 2 lines to /usr/local/etc/stunnel at the begining so now it looks like:... A Schnee

12/24/2023

12:03 AM Bug #15027 (Confirmed): Bind DNS Server cannot reorder zones
Chris W
12:02 AM Bug #15027: Bind DNS Server cannot reorder zones
Can confirm with Bind 9.17 on pfSense Plus 23.09.1.
To reproduce:
1. Create two zones.
2. On the Zones tab, drag...
Chris W

12/23/2023

04:21 PM Feature #9833: ACME: add ability to use custom ACME server
+1 also
there is a FreeBSD port of step-ca
https://www.freshports.org/security/step-certificates/
Max Budnick

12/21/2023

07:33 PM Feature #14999: Feature Request: Update Squid Package to Version 6.5 this was released on updated Nov 6
Pretty Please ...
Maybe a Christmas package..
Jonathan Lee
09:38 AM Todo #14073: Shalla block list is offline but still available in pfBlocker
Mike Moore wrote in #note-3:
> Can we get this package cleaned up at least with the removal of the list.
> Its cau...
OpIT GmbH

12/20/2023

07:29 PM Regression #14452: Prometheus node_exporter generates errors with the default config
I'm still seeing this on CE 2.7.2 with node_exporter 0.18.1_3 (upstream node_exporter-1.6.1) installed. Note that the... Logan Marchione
07:08 PM Bug #15080: Suricata process dying due to Hyperscan error - also may randomly segfault
PR merged, thanks! Jim Pingle
05:18 PM Bug #15080: Suricata process dying due to Hyperscan error - also may randomly segfault
Additional update for this issue for a complete history:
Two additional heap memory buffer overflow bugs were rece...
Bill Meeks
07:08 PM Bug #14898: Suricata core dumps with signal 11
PR merged, thanks! Jim Pingle
05:19 PM Bug #14898: Suricata core dumps with signal 11
Additional update for this issue for a complete history:
Two additional heap memory buffer overflow bugs were rece...
Bill Meeks
05:02 AM Feature #15107 (New): An option to disable routes
When using Wireguard with FRR (dynamic routing) there needs to be an option to select 'Disable routes'
This will pre...
Mike Moore

12/19/2023

05:46 PM Bug #15086 (Rejected): openvpn-client-export 1.9.2 | Viscosity Bundle | ECDSA cert missing key
I can't replicate this. I created a fresh EC cert using that curve and all export formats contain the certificate and... Jim Pingle

12/18/2023

01:17 PM Feature #15099 (Closed): ACME: please update GUI to include recently added DNSapi providers.
This happens during any update we do, no need for a separate issue to track it. Jim Pingle

12/17/2023

03:04 AM Bug #15100 (New): Tailscale IPv6 Exit Node uses first LAN interface when WAN is set to Only Request Prefix
When Tailscale on pfSense Plus is being used as an exit node for IPv6 connectivity and the WAN interface is set to "O... Kris Phillips
02:58 AM Feature #14453: Expand prefix list entry window
Any update on this?
The workaround is to go into the pfsense shell, go into the FRR cli <vtysh> and examine the pref...
Mike Moore

12/16/2023

02:49 PM Feature #15099 (Closed): ACME: please update GUI to include recently added DNSapi providers.
Please update GUI to include DNS API providers like DnsExit.com that was recently added to acme.sh.
https://github...
Michael C

12/14/2023

10:44 AM Feature #15091 (New): FRR, add the ability to change the order of BGP neighbours
Hi!
I currently have over 20 bgp peers, and it's getting awkward to add new peers to an existing group as they app...
Oleksii Tucha

12/13/2023

06:52 PM Feature #9833: ACME: add ability to use custom ACME server
+1 also. Stephen Nelson

12/12/2023

07:43 PM Bug #15088 (Confirmed): BIND does not start after a config restore
Steps:
# Fresh install of pfSense+ 23.09.1
# Install bind package
# Restore a config backup with bind configuratio...
Marcos M
01:22 PM Bug #15086 (Rejected): openvpn-client-export 1.9.2 | Viscosity Bundle | ECDSA cert missing key
Export VPN cert/settings as viscosity bundle do not include the key.key if the cert is ECDSA / secp521r1.
If the c...
slu -
09:16 AM Bug #14668: FRR BGP route is not making into kernel route table after WireGuard's peer change is applied
CE 2.7.2, FRR 2.0.2_1 (frr9-9.0.2), WireGuard 0.2.1 - still the same. Oleksii Tucha
09:10 AM Feature #14878: Integrated syslog support
Unfortunately I cannot code myself, so I have to ask for changes in detail instead. I think the solution should be ma... Tue Madsen

12/11/2023

08:19 PM Bug #11970: Netgate Firmware Upgrade Doesn't Work on XG-2758 (ADI/coreboot)
Jordan G wrote in #note-3:
> user reporting fw upgrade failing on 7100 @ 23.09.1 (ref # 2156023693)
>
> [...]
...
Marcos M
06:25 PM Bug #15033 (Resolved): Suricata rule lists can't be manually updated unless the ETOpen Emerging Threats list is enabled
PRs merged, thanks! Jim Pingle
06:24 PM Bug #15080 (Resolved): Suricata process dying due to Hyperscan error - also may randomly segfault
PRs merged, thanks! Jim Pingle
06:24 PM Bug #14898 (Resolved): Suricata core dumps with signal 11
PRs merged, thanks! Jim Pingle
05:59 PM Regression #14189: pfBlocker-NG: HA-Sync is not working
comparing:
https://github.com/pfsense/FreeBSD-ports/blob/734989ab5809fe5c7bde23a240e717da656775ac/net/pfSense-pkg-pf...
Steve Y

12/10/2023

10:11 PM Bug #11970: Netgate Firmware Upgrade Doesn't Work on XG-2758 (ADI/coreboot)
user reporting fw upgrade failing on 7100 @ 23.09.1 (ref # 2156023693)... Jordan G
06:38 PM Bug #15033: Suricata rule lists can't be manually updated unless the ETOpen Emerging Threats list is enabled
A fix for this issue has been submitted via this pull request against the RELENG_2_7_2 branch: https://redmine.pfsens... Bill Meeks
10:49 AM Feature #14878: Integrated syslog support
I completely agree. The lack of integrated SYSLOG support (independent of local pfBlockerNG logging) is a MAJOR drawb... Tue Madsen
04:55 AM Bug #14898: Suricata core dumps with signal 11
Pull request 1333 for the RELENG_2_7_2 branch of FreeBSD-ports has been submitted to address this issue.
https://git...
Bill Meeks
04:55 AM Bug #14491: FRR not starting with AgentX enabled
Mike Moore wrote in #note-10:
> Found a use case for AgentX and ran into the frr start.
>
> Jim - i see the targe...
Jim Pingle
04:52 AM Bug #14491: FRR not starting with AgentX enabled
Found a use case for AgentX and ran into the frr start.
Jim - i see the target versions have been deleted. Does th...
Mike Moore
04:50 AM Bug #15080: Suricata process dying due to Hyperscan error - also may randomly segfault
Pull request 1333 for the RELENG_2_7_2 branch of FreeBSD-ports has been submitted to address this issue.
https://git...
Bill Meeks
04:31 AM Bug #15080 (Resolved): Suricata process dying due to Hyperscan error - also may randomly segfault
Several users on the Netgate Forum are reporting random issues with Suricata failing due to the following Hyperscan e... Bill Meeks
01:18 AM Todo #14073: Shalla block list is offline but still available in pfBlocker
This is an issue on the pfSense Plus 23.09.X branch still. Kris Phillips
01:16 AM Bug #13810 (Rejected): Squid options obsolete
Marking this as Rejected since Squid is being deprecated and removed in a future version of pfSense CE and Plus. Kris Phillips
01:14 AM Feature #14447 (Resolved): Update haproxy from 2.6 to 2.8 lts
Marking this as resolved. pfSense Plus 23.09 and 23.09.1 both have haproxy 2.8.2 for the backend on stable. Kris Phillips

12/08/2023

04:37 PM Todo #15058 (Feedback): Remove Zabbix 4 Agent and Proxy
Zabbix 4 is EoL upstream Brad Davis
04:34 PM Bug #14913 (Feedback): [Security] Zabbix packages need updating bec. of recent critical security CVEs
Done in 23.09.1 and 2.7.2 Brad Davis

12/07/2023

06:52 PM Feature #15072: [pfBlockerNG] RFE: Add ability to disable reverse DNS lookup for log entries
I've filed some initial work here: https://github.com/pfsense/FreeBSD-ports/pull/1331 Orion Poplawski
12:12 AM Feature #15072 (New): [pfBlockerNG] RFE: Add ability to disable reverse DNS lookup for log entries
Currently pfBlockerNG logs the result of a reverse DNS lookup for a block IP address to ip_block.log and unified.log.... Orion Poplawski

12/06/2023

04:42 AM Todo #15058: Remove Zabbix 4 Agent and Proxy
Is there a reason for it to be removed?
Jonathan Lee
 

Also available in: Atom