Project

General

Profile

Activity

From 02/23/2021 to 03/24/2021

03/25/2021

09:17 PM Bug #11726 (Rejected): Network traffic stops with latest RC build.
After updating to the RC build 21.02.2.r.20210324.0300 network traffic ceased. No NAT traffic was passing, each inter... Ian Mitchell

03/24/2021

01:59 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Svein Wisnaes wrote:
> Grzegorz Krzystek wrote:
> > last known working version is 2.4.5p1
> >
> > No ETA on this...
Kris Phillips
07:32 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Grzegorz Krzystek wrote:
> last known working version is 2.4.5p1
>
> No ETA on this, nor known workaround yet.
...
Svein Wisnaes

03/23/2021

11:15 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
I can concur that with 2 Wan Interfaces (different subnet in our case), with DMZ and LAN networks that traffic coming... Gerald Drouillard
09:57 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Thanks for that.
The only progress I can report so far is that this demonstrates that the initial SYN arrives and ...
Kristof Provost
08:38 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
last known working version is 2.4.5p1
No ETA on this, nor known workaround yet.
Grzegorz Krzystek
08:34 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Netgate XG-1537
21.02-RELEASE-p1 (amd64)
built on Mon Feb 22 09:39:51 EST 2021
FreeBSD 12.2-STABLE
2 x WAN wi...
Svein Wisnaes
07:49 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
please check your mailbox ;) Grzegorz Krzystek
07:44 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Yes, that's the setup I have, and I'm unable to reproduce the problem. The port forwarding just work on both WAN and ... Kristof Provost
05:44 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
What is funny is it need to be related with routing.
reflection nat works. this is impacting only when connection ca...
Grzegorz Krzystek
05:33 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Kristof Provost wrote:
> With a PPPoE setup I still can't reproduce the problem. Along with the latest report that's...
Grzegorz Krzystek
05:22 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
With a PPPoE setup I still can't reproduce the problem. Along with the latest report that's fairly strong evidence th... Kristof Provost

03/22/2021

04:43 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
I am not using PPPOE. Both WANs are DHCP. My config attached. Rick Strangman
11:45 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Thanks. I've not immediately spotted anything suspect in there.
However, it appears that all reports of this issue...
Kristof Provost
08:48 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
I've so far been unable to reproduce this problem.
It's possible that I'm missing some relevant factor in my setup. ...
Kristof Provost
09:58 AM Regression #11689 (Resolved): LEDs do not indicate available upgrade status
Confirmed working on latest snapshot Renato Botelho

03/21/2021

09:18 PM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
Since Wireguard is being removed from the next release, this bug report should be closed out as Rejected. Kris Phillips
09:14 PM Bug #11673: Thermal Sensors Non-functional on SG-3100
Important to note that this seemed to work fine in the 2.4.5p1 images. Its just the newer release that has issues. Kris Phillips

03/17/2021

10:25 AM Regression #11689: LEDs do not indicate available upgrade status
Relevant commits:
https://gitlab.netgate.com/pfSense/factory/-/commit/2add5e3aaaa59a66b2de8789b39b61efff27dfb8
ht...
Jim Pingle
10:07 AM Regression #11689: LEDs do not indicate available upgrade status
I committed another change to use the middle LED for this rather than overloading the use of the ready LED, since the... Jim Pingle
09:41 AM Regression #11689 (Feedback): LEDs do not indicate available upgrade status
Fix committed, should be in tomorrow's image Jim Pingle
08:44 AM Regression #11689 (Resolved): LEDs do not indicate available upgrade status
LEDs are not being updated when a new upgrade is available.
Only affects Plus.
Variable in @etc/rc.update_pkg_m...
Jim Pingle
07:11 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
I have the same problem with 21.02. No VPN's just straight multi-wan. WAN2 (non-default) responds to a ping and works... Rick Strangman

03/16/2021

03:27 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Sounds like it may be related to my issue as well (#11630). It was working normally on my daily build from January du... James Blanton

03/15/2021

06:32 AM Bug #11673: Thermal Sensors Non-functional on SG-3100
I can reproduce it here even on a 21.02.2 snapshot. It's specific to the Thermal Sensors widget and not the temperatu... Jim Pingle

03/14/2021

11:18 PM Bug #11673: Thermal Sensors Non-functional on SG-3100
Unable to reproduce
Could be related to #11443
Viktor Gurov
10:01 PM Bug #11673: Thermal Sensors Non-functional on SG-3100
Kris Phillips wrote:
> The Dashboard Widget for the SG-3100 showing the thermal sensor information gets stuck on "Up...
Michael Spears
06:20 PM Bug #11673 (Duplicate): Thermal Sensors Non-functional on SG-3100
The Dashboard Widget for the SG-3100 showing the thermal sensor information gets stuck on "Updating...." in pfSense P... Kris Phillips

03/13/2021

10:31 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Sounds like this issue might be causing my problem but I can't tell 100% from the description.
One of our sites ha...
Eduard Rozenberg

03/12/2021

12:38 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Updating subject for release notes.
Also made it more general since this can affect more than port forwards.
Jim Pingle
10:50 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Just to update. The nat rule on 2.4.5p1 for 1:1 Nat is... Greg Hulands
10:20 AM Feature #10804: Interface Status page information for switch uplinks may be replaced by switch port data when media state monitoring is set
Updating subject for release notes. Jim Pingle
09:36 AM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Updating subject for release notes. Jim Pingle
09:16 AM Regression #11504 (Resolved): CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Jim Pingle

03/11/2021

02:32 PM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
Christian,
Nope! I explored that line of thought as well. I did have it set up at one point, but then I removed i...
James Blanton
07:57 AM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
If anybody from Netgate would like to jump into a Zoom meeting so that they can observe this edge case, just reach ou... Christian McDonald
07:38 AM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
Christian,
What I've found is that unless you do something to interfere with WireGuard, such as disabling and re-e...
James Blanton
07:23 AM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
I'm seeing this on 2.5.0 as well. I have a failover group set as default gateway IPv4. WAN1 dropped out and WG starte... Christian McDonald
02:20 PM Feature #10804 (Feedback): Interface Status page information for switch uplinks may be replaced by switch port data when media state monitoring is set
Cherry-picked to RELENG_2_5_1 Renato Botelho
02:05 PM Bug #11466: PHP exit with sig 11 on SG-3100
Likely related #11605 and #11551 Marcos Mendoza
01:26 PM Bug #11466: PHP exit with sig 11 on SG-3100
Updating bug report to focus on PHP issue, given that the snort sig 10 issue is unlikely related, and this seems to a... Marcos Mendoza
01:12 PM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Confirmed working on 21.02.2 Marcos Mendoza
10:40 AM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Tested on 21.02p1 and it showed as invalid. After updating to latest dev build image (Mar 10), the cert no longer sho... Marcos Mendoza

03/10/2021

02:37 PM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Needs re-tested on snapshots.
If needed, I have a user-supplied certificate which can replicate the problem and ca...
Jim Pingle
11:08 AM Bug #11653: duplicate comconsole_port="0x2F8" lines in loader.conf
fix:
https://gitlab.netgate.com/pfSense/pfSense/-/merge_requests/184
Viktor Gurov
10:51 AM Bug #11653 (New): duplicate comconsole_port="0x2F8" lines in loader.conf
In my loader.conf file there are several identical lines with
comconsole_port ="0x2F8"
and after each reboot a...
Guido Glaus
08:12 AM Bug #11626: Google LDAP connection failed due to lack of SNI for TLS 1.3
Not that I like the idea of downgrading to a lower TLS version but I wonder if it would work if we forced off TLS 1.3... Jim Pingle
05:45 AM Bug #11626: Google LDAP connection failed due to lack of SNI for TLS 1.3
Using the STunnel package as a workaround helps:
https://docs.netgate.com/pfsense/en/latest/recipes/auth-google-gsui...
Viktor Gurov

03/09/2021

03:00 PM Bug #11466: PHP exit with sig 11 on SG-3100
Tested on:... Marcos Mendoza
12:28 PM Bug #11466: PHP exit with sig 11 on SG-3100
Has anyone tried this on a 21.05 snapshot with PHP 7.4.16? The release notes for PHP 7.4.16 mention they fixed a segf... Jim Pingle
01:48 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
gnn is taking a look at this to see if he can track it down. Jim Pingle
07:40 PM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Site to Site OpenVPN is broken for me in 2.5.0. The tunnel encryption is setup, but running openvpn at verbosity leve... Greg Hulands
01:16 PM Feature #10804 (Waiting on Merge): Interface Status page information for switch uplinks may be replaced by switch port data when media state monitoring is set
Jim Pingle

03/08/2021

11:29 AM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
This also appears to be related to Bug #11613, where the user had to reboot pfSense to get WireGuard to follow the st... James Blanton
11:21 AM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
FYI - The "nightly" build I was using during testing was 2.5.0.a.20210122.2350. James Blanton
11:32 PM Bug #11630: WireGuard MultiWAN Not Failing Back to Tier 1
see also #11570 and #6370 Viktor Gurov
09:46 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
the last filter generating change is https://github.com/pfsense/pfsense/commit/fce8a99bffae47c965c692dbe763ae9732092f... Viktor Gurov
09:17 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Same issue here after upgrade to v21.02,
MultiWan wont NAT properly on both wan.
A new message to let you know this...
R M

03/07/2021

11:21 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
It looks like the reply traffic is not matching the state created by the inbound connection on the WAN.
The firewa...
Steve Wheeler

03/06/2021

10:20 AM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
bdaa35dcf31def521ba8c60c0aa9c41bf5005311 is working when applied to 21.02p1 on an SG-3100. The change hasn't made it ... Max Leighton

03/05/2021

04:31 PM Bug #11630 (Closed): WireGuard MultiWAN Not Failing Back to Tier 1
When using a GW group for WAN failover, WireGuard will fail to Tier2 when the Tier1 GW is down. However, when Tier1 i... James Blanton
10:23 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Marcos Mendoza wrote:
[...]
>
> I noticed the PPPoE gateway that was automatically created was outside of the sub...
Grzegorz Krzystek
09:59 AM Regression #11436: State matching problem with reponses to packets arriving on non-default WANs
Another report:
Port forward and firewall rules are in place on a secondary PPPoE WAN interface. Traffic comes in,...
Marcos Mendoza
08:06 AM Bug #11626: Google LDAP connection failed due to lack of SNI for TLS 1.3
If OpenLDAP ldapsearch fails directly it's unlikely to be related to #9417
All the references I see to SNI seem fa...
Jim Pingle
02:07 AM Bug #11626: Google LDAP connection failed due to lack of SNI for TLS 1.3
may be related to #9417 Viktor Gurov
02:02 AM Bug #11626 (New): Google LDAP connection failed due to lack of SNI for TLS 1.3
https://forum.netgate.com/topic/161725/google-ldap-connection-failed:
I have a problem after update my Netgate XG-...
Viktor Gurov

03/03/2021

02:52 PM Bug #11615: OpenVPN + Ldap broken in 21.02-RELEASE-p1
Read all of the recent notes, it's a general problem with fcgicli that manifests in multiple ways, including validati... Jim Pingle
02:46 PM Bug #11615: OpenVPN + Ldap broken in 21.02-RELEASE-p1
I do not believe this is a duplicate
here the longest cert
1) ST=CA, OU=XXXXXX, O=XXXXXX Technologies Inc, L=XXXX...
Luc Suryo
11:22 AM Bug #11615 (Duplicate): OpenVPN + Ldap broken in 21.02-RELEASE-p1
Almost certainly a duplicate of #4521 (See notes there with attached patches to try).
If that doesn't help, please...
Jim Pingle
11:20 AM Bug #11615 (Duplicate): OpenVPN + Ldap broken in 21.02-RELEASE-p1
We recently upgraded to 21.02-RELEASE-p1 (AWS)
And since we see an odd behavior that prevent user to login
OpenLD...
Luc Suryo

03/01/2021

02:06 AM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
Let me share some of mny observartions in the last 3 days.
* hw.ncpu=unset, all non default Packages diabled = Sta...
Marco Goetze

02/26/2021

07:36 AM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
Marco Goetze wrote:
> Question: Was 21.02.p1 just a quick fix addind a cpu limit to laoder.conf or was the membar al...
Jim Pingle
05:42 AM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
What Viktor mentioned could be a reason. In my tested and still failing SG-3100 it also used the pfBlockerNG-dev pack... Marco Goetze
04:18 AM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
same issue after upgrading to 21.02-p1:... Viktor Gurov
02:41 AM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
After the Problem occurred first time I applied the quick fix setting to 1 CPU in the loader.conf > hw.ncpu=1
Now ...
Marco Goetze

02/25/2021

04:01 PM Bug #11466: PHP exit with sig 11 on SG-3100
Another day of frustrating, but ultimately not too productive, testing leads me to conclude this is something with 32... Bill Meeks
08:40 AM Bug #11466: PHP exit with sig 11 on SG-3100
Steve Yates wrote:
> Simply out of curiosity I did a quick search and found this "not a bug" from 2008: https://bugs...
Bill Meeks
10:35 PM Bug #11466: PHP exit with sig 11 on SG-3100
Simply out of curiosity I did a quick search and found this "not a bug" from 2008: https://bugs.php.net/bug.php?id=45... Steve Yates
09:57 PM Bug #11466: PHP exit with sig 11 on SG-3100
*Update on this issue*
The problem is somewhere within the PHP base function _preg_match()_.
Here is a PHP code...
Bill Meeks
03:42 PM Bug #11540 (Not a Bug): Nat not working
There isn't nearly enough information there to classify it as a bug, and this site is not for support or diagnostic d... Jim Pingle
03:29 PM Bug #11540 (Not a Bug): Nat not working
Hello,
After updating to version 21.02 on SG-4860 nat stopped working.
What can we do to make nat work again?
...
Alex Adati
11:11 AM Regression #11444 (Resolved): SG-3100 doesn't pass traffic after upgrade to 21.02
Jim Pingle

02/24/2021

11:50 PM Regression #11444: SG-3100 doesn't pass traffic after upgrade to 21.02
Scott Lang, that tracks along the same lines with the issues I was having back in Sep 2020: https://forum.netgate.com... Daniel Gordon

02/23/2021

03:35 PM Regression #11504 (Feedback): CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Applied in changeset pfsense:commit:bdaa35dcf31def521ba8c60c0aa9c41bf5005311. Jim Pingle
03:26 PM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
When applying the patch for this, you will probably need to apply @cb17faca3b07197db4b1eb1502a876873ddc222c@ first an... Jim Pingle
03:25 PM Regression #11504: CA and certificate validity end dates after 2038 are not handled properly on 32-bit ARM
Looks like this is from the @validTo@ date in the parsed details using a four digit date and the code assumed a two d... Jim Pingle
03:10 PM Bug #11466: PHP exit with sig 11 on SG-3100
*Another Update*
None of the conditions described in this bug report occur on an SG-1100 (64-bit ARM CPU), and nei...
Bill Meeks
11:40 AM Bug #11466: PHP exit with sig 11 on SG-3100
Marcos:
-I'm running into difficulty updating my SG-1100 to the latest version. It is still on the 2.4.4 factory i...
Bill Meeks
08:07 AM Bug #11466: PHP exit with sig 11 on SG-3100
Thanks for the additional info. I will investigate further. The Signal 10 from the Snort binary I am not really surpr... Bill Meeks
01:21 AM Bug #11466: PHP exit with sig 11 on SG-3100
The behavior with both Snort and Suricata installed was definitely strange and didn't make sense to me. I did a fresh... Marcos Mendoza
 

Also available in: Atom