Project

General

Profile

Activity

From 12/15/2023 to 01/13/2024

01/13/2024

11:06 AM Bug #15036 (Confirmed): Traffic Shaper Wizard Dedicated generates error
I've replicated the issue on:... Danilo Zrenjanin

01/11/2024

01:28 PM Bug #15153 (Not a Bug): Backup Restore Issues restoring (Restore Area: Firewall Rules) Aliases for Subnets
That is expected behavior in this case, as the Firewall Rules area of the backup/restore selection does not include A... Jim Pingle
07:56 AM Bug #15151: OpenVPN TAP & BRIDGE
Jim,
we don't need a forum, we need a contact to people who have real influence on the pfSense code - you don't ha...
Łukasz Rojczyk

01/10/2024

11:28 PM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
25.05.01 It has no issues with that ID Jonathan Lee
11:27 PM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
@Jim Pingle
@dco_update_peer_stat: invalid peer ID 0 returned by kernel@
shows when using the crypto chip it...
Jonathan Lee
11:22 PM Bug #15153 (Not a Bug): Backup Restore Issues restoring (Restore Area: Firewall Rules) Aliases for Subnets
Hello fellow Redmine members,
I wanted to report a bug I found in the Backup Restore section of pfSense Plus.
...
Jonathan Lee
07:41 PM Bug #15151: OpenVPN TAP & BRIDGE
A tap bridge is only useful for linking L2 which would see MAC addresses, so you reserve hosts in DHCP by MAC address... Jim Pingle
07:21 PM Bug #15151: OpenVPN TAP & BRIDGE
I checked what you suggested but from the client side it is also no longer possible to make a bridge with the OpenVPN... Łukasz Rojczyk
05:41 PM Bug #15151 (Rejected): OpenVPN TAP & BRIDGE
I provided a link with the "official" way to bridge OpenVPN to a LAN.
Third party guides/videos are not good refer...
Jim Pingle
05:30 PM Bug #15151: OpenVPN TAP & BRIDGE
You remain in error.
Somehow it was able to work well for 6 years and I think it was used by many people who use T...
Łukasz Rojczyk
05:20 PM Bug #15151 (Feedback): OpenVPN TAP & BRIDGE
Normally with a tap bridge you don't have an interface address / tunnel network on the member interfaces, only on the... Jim Pingle
04:44 PM Bug #15151 (Rejected): OpenVPN TAP & BRIDGE
When configuring OpenVPN TAP with a static address pool, there is a problem when configuring the TAP bridge with anot... Łukasz Rojczyk
03:46 PM Bug #14824: OpenVPN instance on IPv6 PPPoE interface does not always start automatically
I have diagnosed something, so far I know that removing the TAP bridge from the LAN solves the problem above.
Is t...
Łukasz Rojczyk

01/09/2024

10:54 PM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
This is what I mean by rule id I use it with my LED script. With the new rules when using them with wlan address they... Jonathan Lee
10:50 PM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
https://forum.netgate.com/topic/185443/example-of-layer-2-ethernet-firewall-rules
I was able to get it to work how...
Jonathan Lee
03:43 PM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
If it's shown on the dashboard as active, and there is kernel encryption happening on the VPN (e.g. OpenVPN DCO, IPse... Jim Pingle
03:27 PM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
Is there anything I can do because I have the older 2100 that has this chip, I understand the new 2100 does not come ... Jonathan Lee
01:49 PM Bug #15149 (Not a Bug): Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
The OpenVPN crypto hardware choice is not relevant and hasn't done anything meaningful in years. It should probably b... Jim Pingle
01:36 AM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
New firmware was installed also same issue Jonathan Lee
01:36 AM Bug #15149: Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
https://forum.netgate.com/topic/185411/23-09-01-hardware-crypto-showing-no-hardware-crypto-acceleration-for-system-wi... Jonathan Lee
01:30 AM Bug #15149 (Not a Bug): Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
The Hardware Crypto is no longer showing up under OpenVPN configuration. My Netgate appliance has a crypto chip insta... Jonathan Lee

01/04/2024

12:35 PM Bug #14824: OpenVPN instance on IPv6 PPPoE interface does not always start automatically
Jan 4 13:00:00 openvpn 21642 Exiting due to fatal error
Jan 4 13:00:00 openvpn 21642 FreeBSD ifconfig failed: ...
Łukasz Rojczyk

01/03/2024

03:23 PM Bug #15097: Upgrade to 23.09.1 is not offered for 23.05.1
I had this issue on appliances while upgrading to 23.09 two branches back, where new version check was always failing... Clément PAPPALARDO

01/02/2024

03:48 PM Bug #15097: Upgrade to 23.09.1 is not offered for 23.05.1
Marcos M wrote in #note-4:
> The issue is due to a missing @.default@ file, e.g. @/usr/local/etc/pfSense/pkg/repos/pf...
Tom L
01:33 PM Regression #14964 (Not a Bug): SG-3100: iscsi support removed from 23.09 kernel
At this point things removed from 3100 are unlikely to return as they were probably removed due to problems with armv... Jim Pingle

12/31/2023

12:43 AM Bug #15126: SG-1100 pfSense+ recovery results in non aligned disk slices
David Burns wrote:
> Currently preparing for an upgrade of SG-1100 remote worker fleet.
>
> However after install...
Kris Phillips

12/29/2023

07:48 PM Bug #15097 (Resolved): Upgrade to 23.09.1 is not offered for 23.05.1
The system link does exist:... Marcos M
11:25 AM Bug #14005: SFP Interfaces not available with Traffic Shaper in v23.01
For info; I have updated the Netgates to version 23.09.1 and the problem still exists. The interfaces Clx0 and clx1 (... Brendon Flint
03:11 AM Bug #15126 (Resolved): SG-1100 pfSense+ recovery results in non aligned disk slices
Currently preparing for an upgrade of SG-1100 remote worker fleet.
However after installing the latest SG-1100 rec...
David Burns

12/23/2023

09:20 PM Regression #14964: SG-3100: iscsi support removed from 23.09 kernel
I would imagine that the reason it wasn't mentioned in the release notes is because iSCSI support isn't officially su... Kris Phillips
09:18 PM Bug #14824: OpenVPN instance on IPv6 PPPoE interface does not always start automatically
Łukasz Rojczyk wrote in #note-12:
> is there any progress yet or will it never work properly ???
>
> Dec 18 10:19...
Kris Phillips
09:16 PM Bug #15097: Upgrade to 23.09.1 is not offered for 23.05.1
Danilo Zrenjanin wrote in #note-2:
> Yeah, I can confirm this behavior on Netgate 6100.
>
> [...]
>
> The reco...
Kris Phillips

12/22/2023

11:11 AM Bug #15097 (Confirmed): Upgrade to 23.09.1 is not offered for 23.05.1
Yeah, I can confirm this behavior on Netgate 6100.... Danilo Zrenjanin

12/21/2023

07:22 PM Bug #14515: Ethernet rule Action field hint text lists "reject" option which is not compatible with Ethernet rules

Christian McDonald wrote in #note-1:
> Thanks.
>
> pf(4) only supports pass/block action semantics for L2 rul...
Jonathan Lee
07:20 PM Bug #14515: Ethernet rule Action field hint text lists "reject" option which is not compatible with Ethernet rules
Do you still have this commit ID I do not think it shows up. I can't fetch 7cdf5ed172bbb98aa62e9a4ef534866ba1d63ef8 Jonathan Lee

12/20/2023

05:52 PM Bug #15103 (Resolved): Netgate Crypto ID missing in 23.09.01 after fresh firmware
Thoth is no longer used - the error is from old code which has been cleaned up in dev snaps. This is being tracked wi... Marcos M
04:15 AM Bug #15103: Netgate Crypto ID missing in 23.09.01 after fresh firmware
With 23.05.01
@AES-GCM,ChaCha20-Poly1305,AES-ICM,AES-XTS,SHA1,SHA256,SHA384,SHA512@
is shown for my model 21...
Jonathan Lee
04:32 PM Feature #12832: 6100 configurable Blinking Blue LED
Have you attempted to just manually set the GPIO settings with a cron job to a different color? Would that help or ma... Jonathan Lee
04:12 AM Bug #13206: SG-3100 LED GPIO hangs
Have you attempted to just manually set the GPIO settings with a cron job to a different color? Would that help or ma... Jonathan Lee
03:51 AM Bug #13497: unbound process looks like stuck periodically
Post this in the forum it could be you are not using the correct settings and ACL's for unbound. Jonathan Lee
02:19 AM Feature #14291: Support for cryptographic acceleration using the Multi-Buffer Crypto for IPsec Library (IPsec-MB, IIMB)
crypto id/ping-auth has nothing to do with cryptographic acceleration, it's not relevant to this issue in any way. Jim Pingle
02:12 AM Feature #14291: Support for cryptographic acceleration using the Multi-Buffer Crypto for IPsec Library (IPsec-MB, IIMB)
Old post however I wanted to bring more attention to CryptoID loss of ping-auth when fresh firmware is installed.
...
Jonathan Lee

12/19/2023

05:42 AM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
Thanks happy holidays. I enjoyed the experimental layer 2 broadcast storm puzzles that took me way back to old CCNA c... Jonathan Lee
05:40 AM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
Also you can see traffic on the experimental layer 2 firewall rules between the interfaces that is the main concern h... Jonathan Lee
05:23 AM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
I will be moving back to 23.05.01 it's layer 2 abilities were more secure within the broadcast domains. Jonathan Lee
05:21 AM Bug #15104: Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
Please see photo. Also when a client has a static entry for the firewall on a secure side "Firewall's LAN(WLAN)" and ... Jonathan Lee
01:18 AM Bug #15103: Netgate Crypto ID missing in 23.09.01 after fresh firmware
ping-auth -s no longer populates it for you so its empty, how does this effect OpenVPN users? Jonathan Lee
01:17 AM Bug #15103: Netgate Crypto ID missing in 23.09.01 after fresh firmware
It still works the thorth folder is empty.
I fixed it by transferring the folder over from an older SSD
Jonathan Lee
12:56 AM Bug #15103 (Confirmed): Netgate Crypto ID missing in 23.09.01 after fresh firmware
Also see: https://redmine.netgate.com/issues/12636
The CryptoID is shown as expected if the /etc/thoth/thothid is ...
Steve Wheeler

12/18/2023

10:48 PM Bug #15104 (New): Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
Layer 2 broadcast domain in 23.05.01 would separate compex card from the LAN RJ45 ports. It no longer separates the l... Jonathan Lee
10:39 PM Bug #15103 (Resolved): Netgate Crypto ID missing in 23.09.01 after fresh firmware
Hello I noticed this after fresh firmware install on a SG-2100
@ The command '/usr/local/sbin/ping-auth -s > /etc/...
Jonathan Lee
04:34 PM Feature #15101 (Rejected): Warning about using Kea DHCP for HA env
Kea does not support HA yet, and that has been warned about in the release notes. We aim to have support in the next ... Jim Pingle
04:29 PM Feature #15101 (Rejected): Warning about using Kea DHCP for HA env
Using Kea DHCP for HA environment can and will lead to issues with ARPs if you are using dynamic leases. Nice to have... Bartłomiej Bujak
09:25 AM Bug #14824: OpenVPN instance on IPv6 PPPoE interface does not always start automatically
is there any progress yet or will it never work properly ???
Dec 18 10:19:00 openvpn 15608 Exiting due to fatal...
Łukasz Rojczyk

12/17/2023

03:11 AM Bug #15097: Upgrade to 23.09.1 is not offered for 23.05.1
Can confirm that this seems to consistently happen basically every time someone upgrades from 23.01 to 23.05.1. Kris Phillips

12/15/2023

06:29 PM Bug #15097 (Resolved): Upgrade to 23.09.1 is not offered for 23.05.1
Since the release of 23.09.1, devices that upgrade to 23.05.1 from a previous version are unable to upgrade to 23.09.... Kris Phillips
 

Also available in: Atom