Project

General

Profile

Activity

From 10/12/2010 to 11/10/2010

11/10/2010

11:14 PM Revision f233231b: Take into account if we have redirection active to allow even port 443.
Ermal LUÇI
11:14 PM Revision 30bd17f5: Make the antilockout rule match the webgui and ssh(if enabled) rather than any traffic destined to pfSense itself.
Ermal LUÇI
10:22 PM Revision 29f76490: Only use escapeshellarg when passing the arguments to the shell. Fixes #1005
Jim Pingle
10:00 PM Bug #878: Drag and Drop firewall rules causes corruption
I've had numerous reports of it in the past two months from talking to people. Click and drag around and you'll event... Chris Buechler
09:40 PM Bug #878: Drag and Drop firewall rules causes corruption
I am having trouble replicating this problem in Chrome on Mac. Can someone else confirm? Scott Ullrich
10:00 PM Bug #714 (Feedback): Cellular RRD Graph Shows w/o 3G Modem Installed
Applied in changeset commit:"2b30323ef3ebbd11d84e913db3b33e514b0657a6". Anonymous
09:50 PM Bug #714: Cellular RRD Graph Shows w/o 3G Modem Installed
Oddly enough I do not see it on my ALIX, but I do see it on my amd64 full install, and only on the Settings tab, no o... Jim Pingle
09:42 PM Bug #714: Cellular RRD Graph Shows w/o 3G Modem Installed
I am not seeing any kind of cellular items on my box at this time. Scott Ullrich
09:49 PM Bug #918 (Feedback): CP redirection URL and logout on popup don't work
Setting this to feedback for now, since the first issue is fixed and the second one as described is intended behavior... Erik Fonnesbeck
09:42 PM Revision dd18038e: * Call get_configured_interface_* functions only once in the code
* Optimize the test if the passed interface is a vaild one
* Fix the apply settings to actually do something rather t...
Ermal LUÇI
08:09 PM Revision e7d3fc15: Small improvement no functional change.
Ermal LUÇI
07:40 PM Revision fa112436: Use php calls rather than forking to shell.
Ermal LUÇI
07:34 PM Revision b06d7ebb: Use exec and check return value of command to avoid priting messages of stderr to console.
Ermal LUÇI
07:16 PM Revision 35d26b25: Not sure why sometimes works sometimes does not work when bound to localhost the lighttpd instance of CP. Back to previous setup! Though security of it is debatble.
Ermal LUÇI
06:43 PM Revision 7f8d463f: Bring interfaces up only if there is a mismatch to allow them to be reassigned.
Ermal LUÇI
06:27 PM Revision e9d7afeb: Ticket #904. Hmm fix the interface_has_gateway() too.
Ermal LUÇI
06:25 PM Revision f6b30142: Ticket #904. Actually correctly handle the assigned openvpn client as a dynamic gateway rather than breaking the behaviour of the system. Strange nobody has noticed broken gateway behaviour with openvpn assigned!
Ermal LUÇI
06:18 PM Revision c422a169: Actually was coorect before. 3rd parameter is length not index.
Revert "Correct this to make it actually work. This is also mentioned in Ticket #904 though it was already implemente... Ermal LUÇI
05:45 PM Revision 0bb28795: Correct HTTP_REFERER check when using an IP Address vs the Firewalls hostname
Scott Ullrich
05:25 PM Bug #1005 (Feedback): Unable to kill individual states from Diagnostics > States
Applied in changeset commit:"29f76490d8db635646472f9e38f8402f31bb0e33". Jim Pingle
04:57 PM Bug #1005 (Resolved): Unable to kill individual states from Diagnostics > States
Reported here: http://forum.pfsense.org/index.php/topic,29968.0/topicseen.html
You can no longer kill individual s...
Jim Pingle
05:25 PM Revision 612fa572: Note that this textbox controls HTTP_REFERER hostname checks as well
Scott Ullrich
05:00 PM Revision 9734b054: Remove trailing carriage return
Scott Ullrich
04:56 PM Revision 4fe9c2dc: * Adding function get_configured_ip_addresses() which returns all interfaces and their configured IP address
* Add checkbox to System -> Advanced -> Admin for HTTP_REFERER checks
* Add and enforce HTTP_REFERER check if checkbo...
Scott Ullrich
04:44 PM Bug #996 (Feedback): DHCP address not pulled with spoofed MAC address on WAN
DHCP on spoofed mac address is fixed on latest snapshots.
The restore of mac address needs more work not sure if it ...
Ermal Luçi
02:49 PM Revision daab67a1: Fix misc XSS issues from davey b
Scott Ullrich
02:21 PM Bug #990 (Feedback): xss in pfsense I was testing beta 4 pfSense-2.0-BETA4-20100902-0947.iso
Ermal Luçi
02:16 PM Bug #1004 (Feedback): Captive Portal Problem
Try with newer snapshots. Ermal Luçi
09:49 AM Bug #1004: Captive Portal Problem
ok, the captive portal doesn't work!
the cp worked fine before the upgrade , after doesn't work correctly
Andrea Cutelle'
09:04 AM Bug #1004: Captive Portal Problem
Why should it!
That is a design choice made lately
Ermal Luçi
06:29 AM Bug #1004: Captive Portal Problem
just to confirm that i have the same issue with "built on Tue Nov 9 22:11:55 EST 2010"
the problem appear for me app...
gerard grazzini
05:05 AM Bug #1004 (Resolved): Captive Portal Problem
hi, after an upgrade to 2.0-BETA4 (i386)
built on Tue Nov 9 11:59:46 EST 2010
FreeBSD 8.1-RELEASE-p1
port 8000 ...
Andrea Cutelle'
01:34 PM Revision fe73e93f: check the correct routing table array otherwise we can never change the default route
Seth Mos
10:03 AM Revision f0ce6758: Add option to System: Firmware: Settings for running gitsync after installing an update, hidden/disabled if git has not been installed yet.
Erik Fonnesbeck
07:28 AM Revision 2545af04: Remove csrf-magic include from functions.inc -- it was causing problems with console PHP scripts.
Erik Fonnesbeck
07:18 AM Bug #747: Root schedulers (ie PRIQ) cannot be configured on interfaces that don't report bandwidth
Well if an assumption has to be made, it'd be best assume that the interface speed is to the fastest physical interfa... Mr Horizontal
07:16 AM Feature #753: Add OpenVPN foreign_option support
Essentially this relates to the fact when you have an interface bound to an OpenVPN tun device when the VPN is a clie... Mr Horizontal
07:00 AM Bug #754: hifn driver and AES192 and 256
This is still not fixed as of 10 Nov 2010... Mr Horizontal

11/09/2010

11:37 PM Revision 6f2cc3a6: Correct this to make it actually work. This is also mentioned in Ticket #904 though it was already implemented.
Ermal LUÇI
10:17 PM Revision 7673cdb5: Use a shell script rather than bad hack to execute php code for pppoe periodic reset.
Ermal LUÇI
08:10 PM Revision 12dfe8ca: Fix display of queues on rules and layer7 containers.
Ermal LUÇI
06:07 PM Revision 506f6e90: Ensure csrf magic is loaded
Scott Ullrich
05:35 PM Todo #881: Passive FTP over pfsense
Appears to work for me also. Running 20101108 20:20:58.
I can connect from the LAN to remote FTP servers using PASV...
Peter Hinman
04:44 PM pfSense Packages Bug #1003: captive portal not forwarding
..and have tried both workarounds per #868 Dan Emmons
04:39 PM pfSense Packages Bug #1003: captive portal not forwarding
I should add that squid isn't running, and is not configured.
output from netstat looks like its binding tcp8000...
Dan Emmons
04:36 PM pfSense Packages Bug #1003 (Rejected): captive portal not forwarding
duplicate of #868 Chris Buechler
03:07 PM pfSense Packages Bug #1003 (Rejected): captive portal not forwarding
Using pfSense-2.0-BETA4-20101109-0201 and pfSense-2.0-BETA4-20101104-0049
Configured captive portal for MAC bypass...
Dan Emmons
04:38 PM Revision 034f08e7: Fix Misc XSS issues
Scott Ullrich
04:26 PM Revision fea09886: Revert
Scott Ullrich
04:23 PM Revision 9b2bc1af: Testing csrf-magic
Scott Ullrich
03:28 PM Revision 5626a349: Set session.use_trans_sid to true
Scott Ullrich
02:05 PM Bug #995: New x64 snapshots won't boot
Confirmed. New snapshot just uploaded boots OK in my amd64 VM.
2.0-BETA4 (amd64)
built on Tue Nov 9 17:26:01 UTC 2010
Jim Pingle
12:41 PM Bug #995 (Feedback): New x64 snapshots won't boot
This should be fixed from latest commits. Ermal Luçi
12:14 PM Revision 678dfd0f: Add a setting for the data type of values used with DHCP option numbers and input validation for each type. Fixes #962
Erik Fonnesbeck
11:58 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Will look at doing so, but it may be a day or two. I may just set up a VM with a vanilla NanoBSD installation and te... R B
11:58 AM Revision 12984150: Merge remote branch 'mainline/master' into inc
Conflicts:
etc/inc/pkg-utils.inc
etc/inc/system.inc
Renato Botelho
10:02 AM Revision 5d27a3dc: Add a function type to the field types allowed, to allow more field types without directly adding all of them to row helper.
Erik Fonnesbeck
09:09 AM Feature #814: GUI should allow to bind openvpn on different ip same port
The wizard also needs adjusted to accept this scenario (Reported in #1002, but that was closed in favor of using this... Jim Pingle
09:08 AM Bug #1002 (Closed): openvpn wizard refuses to allow same port but different interfaces
Collapsing this into #814 since it's really the same core issue. Jim Pingle
06:44 AM Bug #1002 (Closed): openvpn wizard refuses to allow same port but different interfaces
Create an openvpn server using the wizard, listening on one interface on udp/1194
Try to create another OVPN serve...
Jon Gerdes
09:02 AM Bug #859 (Resolved): OpenVPN wizard stopped working
Jim Pingle
06:56 AM Bug #859: OpenVPN wizard stopped working
I've created several OVPN servers via the wizard and can't reproduce the reported bug. Jon Gerdes
09:02 AM Bug #900 (Resolved): OpenVPN Wizard: Server Certificate Wizard
Jim Pingle
06:37 AM Bug #900: OpenVPN Wizard: Server Certificate Wizard
I created a new server cert using wizard. It refused to allow me to continue unless all fields were filled in. I al... Jon Gerdes
09:01 AM Bug #971 (Resolved): OpenVPN wizard - wrong interface names
Jim Pingle
06:22 AM Bug #971: OpenVPN wizard - wrong interface names
I was able to create a new OVPN server and select interfaces using their descriptive names.
Current version: 2.0-B...
Jon Gerdes
07:25 AM Bug #962 (Feedback): DHCP custom options must have type selection
Applied in changeset commit:"678dfd0fa8d629bd45edad576c99d03aa8f40d70". Erik Fonnesbeck
02:23 AM Revision 58685470: fix input validation for GRE
Chris Buechler
12:48 AM Bug #636: layer7 not work correctly
under my side i can see the blocked rules in filter logs but torrent working Michel Samovojski

11/08/2010

11:22 PM Bug #1001 (Resolved): Captive portal session reuse invalid when MAC changes
Whenever the CP session timeout is longer than the DHCP lease length, and a different device gets assigned an IP, a n... Chris Buechler
10:42 PM Revision 58db1fc4: Kill dhcplease before writing the hosts file so that it does not scramble the content from kqueue events.
Ermal LUÇI
10:21 PM Revision 6e8b0ec3: Add a button to connect a non-mobile IPsec VPN from Status > IPsec. Sends a ping from a local IP in the p2 subnet (if one exists on the router) to the remote p2 subnet.
Jim Pingle
09:50 PM Bug #1000: lagg not working set to failover.
the not coming back after the panic is another issue entirely that needs another ticket open on it, I have a config f... Chris Buechler
04:22 PM Bug #1000 (Closed): lagg not working set to failover.
I have been testing pfsense2.0 Beta4 11-07-2010 and the lagg interfaces with failover don't seem to be working. I am ... Rick Baranowski
03:53 PM Revision 61ab4cd3: Return disabled interfaces as well
Scott Ullrich
03:52 PM Revision 157b9d46: Return disabled interfaces as well
Scott Ullrich
01:25 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Your log makes me suggest you reinstall from scratch because you might have some corrupted/modified files.
Ermal Luçi
01:20 PM Bug #958: reply-to for 1:1 from other directly connected subnets not functioning correctly
Can you show some debugging info's?!
Tracing of traffic etc to actually see what the issue is for you?
Ermal Luçi
01:19 PM Bug #950: Package installation failures leaves package installed
you tried those packages on 2.0 or 1.2.x? Ermal Luçi
07:27 AM Bug #950 (New): Package installation failures leaves package installed
Jim Pingle
06:03 AM Bug #950: Package installation failures leaves package installed
get the problem with imspector 0.8-9
2.0-BETA4 (i386)
built on Wed Nov 3 02:54:06 EDT 2010
FreeBSD 8.1-RELEASE-...
Hugo Sousa
07:26 AM Bug #964 (Resolved): Changing DHCP pool size allows overlap with static leases
Jim Pingle
05:40 AM Bug #964: Changing DHCP pool size allows overlap with static leases
edit : I don't have the lastest build, but a later one than this patch :
* 2.0-BETA4 (i386)
built on Tue Nov 2 14:...
Bastien Semene
05:38 AM Bug #964: Changing DHCP pool size allows overlap with static leases
Just tested, the DHCP Server GUI correctly forbidden me to extend the DHCP pool size while overlapping a static entry... Bastien Semene
07:25 AM Bug #902 (Resolved): configuring cron issue
Jim Pingle
12:37 AM Bug #902: configuring cron issue
u can close this, seems resolved Bipin Chandra
06:55 AM Revision 08452bff: Cosmetic issue, add space before 'done', otherwise package XML name and done are combined.
Warren Baker
06:44 AM Revision 4395500c: Recent move (d32d3970d58683d02f89073103eb595eaa8f395f) of routed/ items required additional files to be updated to reflect correct path.
Warren Baker

11/07/2010

09:29 PM Bug #958 (Feedback): reply-to for 1:1 from other directly connected subnets not functioning correctly
Chris Buechler
06:43 PM Bug #995: New x64 snapshots won't boot
Attaching a screencap of a panic+backtrace from booting a dev kernel on amd64 Jim Pingle
12:34 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Tested again with NanoBSD 1GB snapshot dated "Sun Nov 7 06:14:22 EST 2010" and still exhibiting the same behavior. U... R B
01:34 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Ermal -
Yes, I was running the latest snapshot two weeks ago when you asked me to try again, I made sure the snapsho...
R B
09:29 AM Bug #966 (Resolved): DHCP static lease inside the pool is not rejected
Thanks for testing!
Jim Pingle
03:52 AM Bug #966: DHCP static lease inside the pool is not rejected
seem to be okay i get this message if ill try to add ip from my dhcp range
The following input errors were detecte...
Michel Samovojski
03:48 AM Bug #950: Package installation failures leaves package installed
get the problem with this packages "ifBWStats Diagnostics 1.0" Michel Samovojski
01:41 AM pfSense Packages Bug #999 (Resolved): vhosts does not show up as started
In pfSense 1.x, checking whether a service was started was done using @ps axwu | grep '\b{$process}\b' | grep -v 'gre... Moshe Katz

11/06/2010

10:26 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
working well for me under this snapshot
Full 2.0-BETA4 (i386) built on Sat Oct 30 19:40:13 EDT 2010 FreeBSD 8.1-RE...
Michel Samovojski
10:20 PM Revision d32d3970: Add routed/ items to obsoleted files. Force removal of file so that directories can be included in the future
Scott Ullrich
09:02 PM Revision 277d55d7: Ignore /var/etc directory to avoid these kinds of errors: tar: /var/etc/openvpn/client1.sock: tar format cannot archive socket
Scott Ullrich
07:34 PM Revision 818c54ee: Do not use sub array
Scott Ullrich
07:31 PM Revision 43a0ac8a: Make sure ipsec is incuded in valid interfaces
Scott Ullrich
07:24 PM Revision e5fee340: Move Note to bottom of page
Scott Ullrich
07:22 PM Revision 366e2be8: Show interface description
Scott Ullrich
06:40 PM Revision 2c4a13d9: Interface names should appear as uppercase
Scott Ullrich
06:38 PM Revision 9c3cac0c: Interface names should appear as uppercase
Scott Ullrich
06:34 PM Revision 5aaae0e3: Do not escape strings twice
Scott Ullrich
06:26 PM Revision 0f08affe: Misc fixes. Use htmlspecialchars() in more places. Use escaped shell argument.
Scott Ullrich
06:11 PM Revision 66d57db5: Interface names should appear as uppercase
Scott Ullrich
06:10 PM Revision 4cea35b3: Interface names should appear as uppercase
Scott Ullrich
06:08 PM Revision c1f95f5c: Various CRL fixes.
Jim Pingle
06:03 PM Revision e8ad860f: Interface names should appear as uppercase
Scott Ullrich
06:01 PM Revision 94556105: Define variable a bit earlier in case its shared
Scott Ullrich
06:00 PM Revision d815d5fa: Use get_configured_interface_list() so Ermal does not yell at me :)
Scott Ullrich
04:40 PM Revision 98bcf1f8: Fix misc input validation errors. Move routed/* to same dir as pkg items
Scott Ullrich
04:31 PM Revision 6a937188: Ensure passed interface is valid
Scott Ullrich
04:24 PM Revision 8625c24f: Use htmlspecialchars() for santitized output
Scott Ullrich
04:15 PM Revision 50b2f6ab: Ensure that we are working with a proper passed interface..
Scott Ullrich
03:59 PM Bug #998: Installer fails on gmirror device files
Just reinstalled, but i could not find any loadable geom modules, just some .so files in /lib/geom.
It seems that on...
Marcus van Dam
03:06 PM Bug #998: Installer fails on gmirror device files
I will probably do a reinstall in a few minutes. So ill try and report back.
But please note that the problem is the...
Marcus van Dam
02:34 PM Bug #998: Installer fails on gmirror device files
It still may be worth loading all of the geom* modules to see if that makes the /dev/mirror shortcut appear when it d... Jim Pingle
01:29 PM Bug #998: Installer fails on gmirror device files
I did not load anything extra. I was expecting the livecd to load all the modules as it recognizes the mirror disks.
...
Marcus van Dam
12:28 PM Bug #998: Installer fails on gmirror device files
It's been a while since I tried a gmirror install, but is that still necessary if you kldload all of the gmirror/geom... Jim Pingle
12:26 PM Bug #998: Installer fails on gmirror device files
I just found the workaround,
Boot the livecd completely, then symlink /dev/gm0, gm0s1, gm0s1{a..z} to their /dev/mir...
Marcus van Dam
11:53 AM Bug #998 (Closed): Installer fails on gmirror device files
When doing an install on a gmirror device (created at or before booting the livecd) it will be looking for the wrong ... Marcus van Dam
02:39 PM Bug #991: multiple XSS issues
Scott Ullrich wrote:
> We prefer to have one ticket open per issue. Even though there where multiple files affected...
dave b
12:44 PM Bug #991 (Feedback): multiple XSS issues
Issues fixed in commits 98bcf1f8 6a937188 8625c24f 50b2f6ab
Scott Ullrich
12:43 PM Bug #991: multiple XSS issues
We prefer to have one ticket open per issue. Even though there where multiple files affected it is still one issue.
...
Scott Ullrich
10:12 AM Bug #995: New x64 snapshots won't boot
This is likely due to some recent performance patches added into the tree that behave OK on i386 but apparently not o... Jim Pingle

11/05/2010

08:56 PM Bug #958: reply-to for 1:1 from other directly connected subnets not functioning correctly
I finally had a chance to upgrade, and I'm sorry, but this *still* doesn't work (for me).
Now testing with 2.0-BETA4...
Adam Thompson
01:36 PM Bug #958 (Resolved): reply-to for 1:1 from other directly connected subnets not functioning correctly
Jim Pingle
06:33 PM Revision c62d973d: Spelling fix.
Warren Baker
02:12 PM Revision 03976254: If the anti-lockout rule is active, show it in the rules list for the LAN interface (or WAN if the interface count is 1, same rules as in filter.inc for putting the rule in the ruleset)
Jim Pingle
01:35 PM Bug #969 (Resolved): NAT rdr work only on one interface
Jim Pingle
01:34 PM Bug #969: NAT rdr work only on one interface
Confirmed fixed in the latest snapshots. Matt Corallo
07:49 AM Bug #969: NAT rdr work only on one interface
This is fixed with commits on #958 issue and I think it can be closed. ivan primus
10:35 AM Feature #997 (Closed): Add per-user setting for activating menu
In the future it would be nice to have a per-user setting that controls whether or not a given user is shown the rc.i... Jim Pingle
09:35 AM Bug #991: multiple XSS issues
Chris Buechler wrote:
> please don't open a bunch of tickets where there is only one issue.
OH so you think I did...
dave b
12:30 AM Bug #991: multiple XSS issues
please don't open a bunch of tickets where there is only one issue. Chris Buechler
12:41 AM Bug #994 (Closed): xss on the pfsense website ...
don't care, but fixed anyway Chris Buechler
12:29 AM Bug #992 (Closed): issue 3 THIS ONLY AFFECTS BETA 4 2.0
merged to #991 Chris Buechler
12:26 AM Bug #993 (Closed): issue 4 THIS AFFECTS STABLE
merged into #991 Chris Buechler

11/04/2010

06:30 PM Revision 428e66b6: Warn a user when entering the OpenVPN client/server screens that they need a CA/Cert if none exist.
Jim Pingle
05:18 PM Revision 9882cbef: Use addslashes() here to prevent unescaped quotes from causing PHP errors. Fixes advanced/custom options in OpenVPN wizard.
Jim Pingle
03:54 PM Bug #996 (Resolved): DHCP address not pulled with spoofed MAC address on WAN
Replaced production router ("old router") with pfSense 2.0BETA4 router ("test router" - 02-Nov-2010 snapshot) on broa... Ron Rosen
03:14 PM Revision f09ce147: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/services.inc
Seth Mos
03:11 PM Bug #928: pfSense freezes during boot if DHCP client interface doesn't get a reponse from DHCP server
Similar behavior observed in 02-Nov-2010 (embedded) snapshot. To reproduce:
# Connect LAN. (May not be necessary, bu...
Ron Rosen
02:39 PM Revision 3339c56f: Use a different variable name here to avoid colliding with another of the same name.
Jim Pingle
11:00 AM Bug #995 (Resolved): New x64 snapshots won't boot
The 2 latest x64 snapshots won't boot. They give the error "Cannot dump. Device not defined or unavailable" ("Automat... Peter O
09:06 AM Revision 0996a81e: Enlarge the address fields so that ipv6 addresses fit properly
Seth Mos
07:58 AM Bug #994 (Closed): xss on the pfsense website ...
xss on the pfsense website ...
I don't know if anyone cares about this but you can xss www.pfsense.org.
http://www....
dave b
07:52 AM Bug #993 (Closed): issue 4 THIS AFFECTS STABLE
issue 4 THIS AFFECTS STABLE (for more information see the first of these issues).
xss via graph.php:
poc:
1. htt...
dave b
07:50 AM Bug #992 (Closed): issue 3 THIS ONLY AFFECTS BETA 4 2.0
issue 3 THIS ONLY AFFECTS BETA 4 2.0 (for more information see the first of these issues).
xss via pkg_edit.php
p...
dave b
07:49 AM Bug #991 (Resolved): multiple XSS issues
/pkg_edit.php?xml=olsrd.xml&id=%22/%3E%3Cscript%3Ealert%282%29;%3C/script%3E/status_graph.php?if=%22/%3E%3Cscript%3Ea... dave b
07:47 AM Bug #990 (Resolved): xss in pfsense I was testing beta 4 pfSense-2.0-BETA4-20100902-0947.iso
NOTE:
I haven't against the latest dev, because when I tried to update via today's snapshot it broke and will no lon...
dave b
07:40 AM Bug #968 (Resolved): PHP error in user manager
Jim Pingle
04:59 AM Bug #968: PHP error in user manager
Seems to be fixed with that. Peter O
07:11 AM Bug #989 (Resolved): Unable to make a single outbound PPTP connection
2.0-BETA4 (i386)
built on Mon Nov 1 01:27:31 EDT 2010
FreeBSD 8.1-RELEASE-p1
Unable to make an outbound PPTP co...
Jamie Heckford
04:56 AM Feature #988: DHCP with manual fix IP
Would come in handy to be able to access IP telephones on a fixed IP while being able to update alle phones connected... Peter O

11/03/2010

09:26 PM Revision 9ad0ab80: Use != here to avoid a potential issue with empty() testing intermediate arrays.
Jim Pingle
09:18 PM Revision 42724fdd: Add a button to the filter reload screen to force a config sync (only shows up if a config sync peer is defined).
Jim Pingle
09:00 PM Revision de651e21: Change the dhcpd startup for isc dhcpd server 4.1
Seth Mos
08:11 PM Revision 36600615: Fix saving of off/disabled PPPoE server instances. Fixes #987
Jim Pingle
08:08 PM Revision 79eea0c1: Activate code to allow ipsec to work normally.
Ermal LUÇI
04:44 PM Feature #988 (Rejected): DHCP with manual fix IP
I can't imagine any instance where it's remotely sane to use a static IP and pull other options via DHCP. Chris Buechler
04:34 PM Feature #988 (Rejected): DHCP with manual fix IP
When an interface is defined as "DHCP" type, it's can be helpful that the machine stay with a fix predefined ip (to b... gerard grazzini
04:22 PM Bug #984: Dashboard : Services Status : Captive Portal show wrong service ...
after last change and some irc discussion, i have upgrade to built from "Wed Nov 3 02:54:06 EDT 2010", and the thinks... gerard grazzini
04:15 PM Bug #987 (Feedback): PPPoE Server instances cannot be disabled
Applied in changeset commit:"366006156f697037e9db546a5be0394986bb0bc1". Jim Pingle
02:59 PM Bug #987 (Resolved): PPPoE Server instances cannot be disabled
When you try to turn off a configured PPPoE server instance, the GUI complains about input errors and does not disabl... Jim Pingle
02:53 PM Revision 4816e5ca: Merge remote branch 'mainline/master' into inc
Conflicts:
etc/inc/auth.inc
etc/inc/config.lib.inc
etc/inc/priv.defs.inc
etc/inc/syst...
Renato Botelho
02:33 PM Todo #704 (Resolved): Load cpufreq.ko when powerd is enabled
Closing this as the error given is due to ALIX not really supporting powerd with the default TSC timecounter, which i... Jim Pingle
02:26 PM Revision b039f099: Don't show empty user IPsec keys.
Jim Pingle
01:25 PM Revision 9cb94dd4: Ticket #980. Bring CP widget up to date. Also bind lighty for CP to 127.0.0.1 it should not be accessible otherwise.
Ermal LUÇI
11:50 AM Revision 645ad665: This enabled finding of a carp vip on the ifconfig stack
Seth Mos
10:43 AM Revision 096cd5f5: Do not attempt to start relayd without entries
Seth Mos
10:32 AM Revision 6da3df4e: Enable both ipv4 and ipv6 forwarding before returning
Seth Mos
09:42 AM Revision 5bb1e653: Default to ipv6 routing on
Seth Mos
09:30 AM Revision 3502b5b1: Make it possible to create a inet6 carp address. This works surprisingly
What doesn't work is removing the previous IPv6 address from a interface. This should be hooked into the edit page Seth Mos
08:29 AM Bug #980 (Feedback): Dashboard from Captive Portal don't show connections ...
Ermal Luçi
07:49 AM Revision 105d618d: Merge remote branch 'upstream/master'
Seth Mos
04:44 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Are you sure that you have the latest snapshot?
Can you post a system log here?
Can you post your config here?
Ermal Luçi

11/02/2010

10:01 PM Revision 4ebde165: Make sure that the filter rules for static routes are correctly generated for ipv4 and ipv6
Seth Mos
09:16 PM Revision 72993196: Protect from strange situations on bootup by testing for is_array(). Do not add anymore the 127.0.0.2 route its not needed anymore. Also during bootup bring up all interfaces so the assignment process can deal with them(Possibly should be done in another code flow!).
Ermal LUÇI
09:00 PM Revision 14f565b4: Allow the entry of ipv6 networks, needs verification to prevent ipv4 gateways for ipv6 networks and vice versa
Seth Mos
08:48 PM Revision 6bc1e79a: Don't use pconfig in a widget, it can cause issues with other widget settings.
Jim Pingle
08:43 PM Revision 7617e245: Verify that we validate against a ipv6 subnet properly. This should help for static route gateways
Seth Mos
08:07 PM Revision 60e76c58: CSS changes, fixes misaligned cursor in some password fields. Fixes item 1 in ticket #830
Jim Pingle
07:14 PM Revision a6607b5f: More VPN log fixes, for consistency. Ticket #912
Jim Pingle
06:29 PM Revision f856e762: Fix typo (standart -> standard)
Jim Pingle
06:20 PM Bug #958 (Feedback): reply-to for 1:1 from other directly connected subnets not functioning correctly
Fix committed test new snapshots.
For reference:
https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/commit...
Ermal Luçi
06:11 PM Revision b2b61308: Switch from buttons to tabs, add a mode to view raw mpd logs for each vpn type, and some general cleanup. Fixes #912
Jim Pingle
05:22 PM Revision fbeaba66: Remove these now-obsolete linkup/linkdown scripts.
Jim Pingle
04:52 PM Revision 874e5f2c: Fix VPN log page to use the updated log format (again). Ticket #912.
Jim Pingle
03:57 PM Revision 2f9d2dc2: Use a unified vpn-linkup script that detects the type based on interface name.
Jim Pingle
03:43 PM Revision e9a95ac8: Switch to a unified vpn-linkup and vpn-linkdown.
Jim Pingle
02:15 PM Bug #912 (Feedback): PPTP/PPPoE/L2TP VPN logs missing
Applied in changeset commit:"b2b6130819e72ebf6e4f174444b59f40e88b7b06". Jim Pingle
01:18 PM Bug #912: PPTP/PPPoE/L2TP VPN logs missing
The logs for login/logout events should be back now in a bit more efficient way. Separate linkup and linkdown scripts... Jim Pingle
02:07 PM Revision 2c7feef7: Fix l2tp interface naming. Fixes #985
Jim Pingle
01:21 PM Revision 27b82e7c: Remove debug flag from rtadvd
Seth Mos
10:10 AM Bug #985 (Feedback): L2TP server is not using renamed interfaces
Applied in changeset commit:"2c7feef77728e36f9aaabcc3b9e3b35b3a6bf693". Jim Pingle
09:53 AM Bug #984 (Resolved): Dashboard : Services Status : Captive Portal show wrong service ...
That is unrelated to this ticket. My settings save fine on an updated VM. Start a forum thread with as much detail as... Jim Pingle
09:50 AM Bug #984: Dashboard : Services Status : Captive Portal show wrong service ...
Hello, i'm not sure that I have to post in these place ...
tanks for the quickly bug fix, the problem describe her...
gerard grazzini
09:13 AM Revision d57293a4: Fix services.inc dhcp6 configuration, add route advertising deamon config
Seth Mos
04:04 AM Feature #986 (New): Dynamic states view
It would be nice if "Diagnostics: Show States" could refresh itself periodically and apply any entered filter in orde... Torben Hørup
02:41 AM Bug #981: SSH shell Putty Function Keys
Erik Fonnesbeck wrote:
> This probably won't work for other programs you might run from the SSH session like editors...
Martin Hronek

11/01/2010

10:27 PM Bug #981: SSH shell Putty Function Keys
This probably won't work for other programs you might run from the SSH session like editors, etc. This is also speci... Erik Fonnesbeck
05:09 PM Bug #981: SSH shell Putty Function Keys
Did the entry now in ~/.tcshrc Martin Hronek
09:02 PM Revision 14905d9f: Show login/logout events for pptp, pppoe server, and l2tp. Could use some work to simplify. Ticket #912.
Jim Pingle
08:22 PM Revision 917b0a56: Use individual linkdown scripts.
Jim Pingle
08:15 PM Revision 6d1091dc: Add individual linkdown scripts so the service type can be set in the log.
Jim Pingle
08:05 PM Revision d282c96c: Add service type to vpn log
Jim Pingle
06:46 PM Revision a2071365: Sync service status widget code with service status page. Fixes #984
Jim Pingle
06:13 PM Revision 08724afa: Test for arrays first, should fix #968
Jim Pingle
05:20 PM Revision 5fb9e6d3: Various sync fixes to ensure sections are pushed even if empty, otherwise the last entries of these sections cannot be deleted and have that deletion sync to the secondary.
Jim Pingle
05:05 PM Bug #985 (Resolved): L2TP server is not using renamed interfaces
Both the PPTP server and PPPoE server use renamed interfaces (pptpd and poes, respectively) but the L2TP server still... Jim Pingle
04:04 PM pfSense Packages Bug #450: Some packages do not use authentication for their web interface
ok just did another edit
auth.require = ("/phpsysinfo/" => ("method" => "basic", "realm" => ".", "require" => "valid...
Martin Hronek
02:50 PM Bug #984 (Feedback): Dashboard : Services Status : Captive Portal show wrong service ...
Applied in changeset commit:"a2071365fbdbc906a61137caae735b642501a228". Jim Pingle
11:44 AM Bug #984 (Resolved): Dashboard : Services Status : Captive Portal show wrong service ...
on the Dashboard page, in the Service Status, the name who appear on the Service column is lighttpd but normally have... gerard grazzini
02:15 PM Bug #968 (Feedback): PHP error in user manager
Applied in changeset commit:"08724afa0a323fe5ec04805befbf36b19a67dbed". Jim Pingle
01:47 PM Bug #968: PHP error in user manager
The logic in that second suggested fix isn't quite right. It would skip all groups if the user didn't have any groups... Jim Pingle
10:13 AM Bug #968: PHP error in user manager
The 2 admin groups problem seems to have been fixed but the PHP error is still there. This should be an easy ticket t... Peter O
12:11 PM Revision 11b8ca39: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/filter.inc
Seth Mos
11:33 AM Feature #983 (Resolved): Improve/Enhance IP Alias VIP handling in GUI
IP Alias subnets should probably be included when choosing "(interface) Subnet" shortcuts, and should probably also b... Jim Pingle
07:31 AM Revision a8a98fb4: Do not throw warnings on empty dhcpd arrays
Seth Mos

10/31/2010

10:50 PM Bug #958: reply-to for 1:1 from other directly connected subnets not functioning correctly
This attempted fix has caused issues with reply-to across the board. Chris Buechler
09:36 PM Revision c75a8185: Add function for generating ipv6 subnet mask end, hook into ipv4 subnet mask check as well.
Seth Mos
05:50 PM Feature #982 (Closed): External Storage
In my alix board, I can plug a CF and an Hard drive. As I had troubles booting on my hard drive directly, my plan was... Nicolas Steinmetz
04:23 PM Bug #444: All mounts should be noatime
Tested the suggestion in the second comment on nanobsd 2.0 b4 and I got override questions on /conf, what I did to fo... Basel G.
01:43 PM pfSense Packages Bug #450: Some packages do not use authentication for their web interface
I tried it on my 1.2.3 Installtion.
Added the "mod_auth", in the /var/etc/lighty-webConfigurator.conf and for testin...
Martin Hronek
01:16 PM pfSense Packages Bug #450: Some packages do not use authentication for their web interface
http://redmine.lighttpd.net/projects/lighttpd/wiki/Docs:ModAuth
"When loaded together with mod_fastcgi, mod_auth mus...
Martin Hronek
08:16 AM Bug #981 (Closed): SSH shell Putty Function Keys
After SSH login with Putty and entering the shell with 8 the pos1 and home keys do not work properly in 1.2.3.
It ...
Martin Hronek

10/30/2010

09:24 PM Bug #958: reply-to for 1:1 from other directly connected subnets not functioning correctly
I'm open to workarounds as well as "fixing" the problem - this is suddenly getting a lot more important for us. Adam Thompson
09:23 PM Bug #958: reply-to for 1:1 from other directly connected subnets not functioning correctly
Here's some hard data describing the problem. The host "lisa.muug.mb.ca" is connected nearby via MRNet, but still ne... Adam Thompson

10/29/2010

09:48 PM Bug #958 (New): reply-to for 1:1 from other directly connected subnets not functioning correctly
this reportedly not fixed Chris Buechler
09:47 PM Bug #931 (Resolved): Don't try to backup DHCP leases if DHCP server disabled
Chris Buechler
09:46 PM Bug #684 (Resolved): interface status, disconenct button doesnt work
Chris Buechler
02:35 PM Bug #980 (Resolved): Dashboard from Captive Portal don't show connections ...
Hello,
my configuration : 2.0-BETA4 (i386) - built on Thu Oct 28 22:59:06 EDT 2010
I have install a CAPTIVE PORTA...
gerard grazzini
02:08 PM Revision 0e604b3a: Make isvalidpid() know about pidfile the same as the other *pid functions do.(consistency)
Ermal LUÇI
09:55 AM Revision b7ccf315: Make the change here, too.
Erik Fonnesbeck
08:48 AM pfSense Packages Bug #979 (Resolved): Broken LightSquid installation on 2.0 amd64
Binary package from repository contains more recent version while package manager looks for 1.8.0.
Distributed packa...
Alexander Kalashnikov
08:22 AM Revision 9d46f40b: Also mention that this allows access to the dashboard.
Erik Fonnesbeck

10/28/2010

06:34 PM Revision e3bbd29a: Replace \r from custom options otherwise it breaks config.
Ermal LUÇI
02:29 PM Revision 7c255188: Fix logging parameters.
Jim Pingle
02:29 PM Revision c815b877: Fix pfctl -b parameters to prevent the killing of unintended states.
Jim Pingle
01:56 PM Revision 9e303f2f: Fix formatting
Jim Pingle
01:56 PM Revision 5e58efd0: Fix this logic.
Jim Pingle
01:37 PM Revision 75337c33: Fix typo in services_dhcp_configure() for dhcp6 naming
Seth Mos
12:50 PM Revision ce76a45c: Add icmp6 rules so that stateless autoconfiguration can be used, this also requires that link local addresses work.
Seth Mos
12:29 PM Revision 2a1bd027: Add the rtadvd deamon to advertise the routing. We still need to make a proper config file if we want it to advertise the Carp IP instead of the interface IP
Also added safety guard for empty dhcp configs Seth Mos
10:59 AM Bug #912: PPTP/PPPoE/L2TP VPN logs missing
I tracked this down a bit more somewhat by accident.
It seems that the GUI log viewer is looking at /var/log/(vpn ...
Jim Pingle
10:56 AM Revision 65b1e7d5: Make sure that if either v4 or v6 dhcp servers are enabled that is_dhcp_enabled() will trigger
Seth Mos
10:34 AM Bug #976 (Resolved): DHCP client - option classless-routes does not work, static routes are not set
Ermal Luçi
08:18 AM Bug #976: DHCP client - option classless-routes does not work, static routes are not set
Tested on latest Beta. Works fine, many thanks for the quick fix! Anonymous
08:49 AM Revision 99caa67c: Add the dhcpv6 server service page.
Seth Mos
08:46 AM Revision 693833cb: Update services.inc for configuring isc dhcp server 4.1 with ipv6 subnet support. Much configuration needs validation.
There is no router option support, this needs to be handled by the router advertisement deamon. Perhaps this should b... Seth Mos
05:31 AM Bug #975: CARP / vip interface disappears on slave after interface change
Maybe that snapshot doesn't include the patch, as the date on it is
20:56 on 27th. Latest snapshot is only Oct 27 18...
Rob Lister
05:10 AM Bug #975: CARP / vip interface disappears on slave after interface change
Have updated both boxes to snapshot built on Wed Oct 27 18:59:53 EDT 2010 and the problem
still seems to be there.
...
Rob Lister

10/27/2010

09:15 PM Bug #959: Config sync removes alias VIPs on the slave
Thanks for the feedback.
I do not know if you should apply any "sorting" on the VIP array on the backup firewall. ...
Pierre POMES
10:54 AM Bug #959: Config sync removes alias VIPs on the slave
Here I made the following change and it seems to be working fine:... Thiago Witt
10:06 AM Bug #959: Config sync removes alias VIPs on the slave
Hi Pierre,
I just tested it and the config sync no longer removes the alias vips on the slave, but there's a catch...
Thiago Witt
09:13 PM Revision da51f26c: Ooops use meant logic.
Ermal LUÇI
08:56 PM Revision f48b6205: Ticket #975. Properly initialize variables to avoid caching issues. Also check an array exists before trying to foreach to avoid errors.
Ermal LUÇI
08:56 PM Revision a8200dbf: Ticket #975. Rearrange code a little.
Ermal LUÇI
08:55 PM Revision 6bef0554: Do some is_array() testing before renaming fields, otherwise empty variables can be accidentally created.
Jim Pingle
08:30 PM Revision bacd881e: Fixes #976. Bring in the piecies for classless routing from FreeBSD 8.1 script.
Ermal LUÇI
06:32 PM Revision 1da69624: Add the dhcpv6 server menu item and allow for configuration
Seth Mos
05:11 PM Revision 64ce9d72: Do not require LDAP search base DN. Requiring this can prevent some valid LDAP configurations from properly authenticating. (See GDD-550841).
Jim Pingle
04:55 PM Bug #975 (Feedback): CARP / vip interface disappears on slave after interface change
Please try latest snapshot. Ermal Luçi
03:29 PM Bug #975: CARP / vip interface disappears on slave after interface change
I think this is possibly related to Bug #959
Will wait and see if that is corrected first and test again on a newe...
Rob Lister
03:17 PM Bug #975 (Resolved): CARP / vip interface disappears on slave after interface change
In my testing 2.0 (build Mon Oct 25 02:28:25 EDT 2010) I think I have found an issue when
multiple CARP virtual int...
Rob Lister
04:30 PM Bug #976 (Feedback): DHCP client - option classless-routes does not work, static routes are not set
Applied in changeset commit:"bacd881efcd60aed8ffc44d1c5ebf9872b63fcad". Ermal Luçi
03:26 PM Bug #976 (Resolved): DHCP client - option classless-routes does not work, static routes are not set
The DHCP option classless-routes should be parsed and static routes delivered via this mechanism should be configured... Anonymous
04:02 PM Bug #977 (Resolved): IPSEC in transport mode patch
http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/146190
Might help on L2TP + IPSEC.
Add here to not forget it
Ermal Luçi
11:08 AM Bug #961 (Resolved): Config sync doesn't remove the last alias on the slave
Jim Pingle
10:37 AM Bug #961: Config sync doesn't remove the last alias on the slave
Problem solved.
Thank you.
Regards,
Thiago
Thiago Witt
11:05 AM Bug #969: NAT rdr work only on one interface
Hello,
I am also seeing this with my 3 WAN setup.
I have a port forwarded on all 3 interfaces for FTP - it only...
Pho Bia
07:47 AM Revision 31ace4ea: Add the ipv6 address and subnet onto the existing ifinfo array until the pfsense module supports it
Seth Mos
04:12 AM Bug #974 (Resolved): display corruption of gateways widget on dashboard.
It appears that this snapshot is affected by the issue where apinger can not be shutdown, a manual intervention with ... Seth Mos
04:05 AM Bug #974 (Resolved): display corruption of gateways widget on dashboard.
Eventhough the WAN connection was back online with a new IP address from DHCP it was still displaying "Gathering data... Seth Mos
12:29 AM Revision b019222a: Ticket #959: keep local ipalias and proxyarp vip's during a XMLRPC restore
Pierre POMES

10/26/2010

08:49 PM Bug #959 (Feedback): Config sync removes alias VIPs on the slave
Hi Thiago,
This should be ok now. Can you try again and let me know ?
Regards,
Pierre
Pierre POMES
04:33 PM Feature #177: IPv6 support
Created a forum topic and added a quick howto to get a /64 routed onto the LAN via a he.net tunnelbroker.
http://for...
Seth Mos
01:50 PM Revision 8b6ae027: Check against static configurations which can be staticv4 staticv6 or staticv4v6
Seth Mos
01:44 PM Revision 9b1ff028: Allow for creation of a ipv6 tunnel for he.net by creating a gif interface. This is the recommended procedure as advised by he.net
This allows for using ipv6 local and remote addresses, you will need to add a ipv6 default gateway on the routing tab Seth Mos
01:19 PM Revision e6c563bb: Make the $pgtitle output a link back to the current page for a convenient way of reloading.
Jim Pingle
09:44 AM Revision 22b5abac: Switch over the IPv6 functions from IPv6.inc, these are from the PHP PEAR library
Seth Mos
05:49 AM Bug #969: NAT rdr work only on one interface
I can confirm this issue. I have 2 wan interfaces: WAN and WANTMP
WAN is default gateway. I did nat from WANTMP to l...
ivan primus

10/25/2010

08:55 PM Revision dbb0e086: Remove unnecessary (and unclosed) form tag.
Jim Pingle
08:31 PM Revision c26c208f: Do not allow spaces in load balancer name fields, they are invalid in relayd.
Jim Pingle
07:29 PM Revision 5bb6e1f5: If there are no aliases, push an empty aliases array. Fixes #961
Jim Pingle
07:09 PM Revision 5ea2c125: Add a note to the DNS Rebinding protection error letting the user know to try by IP address.
Jim Pingle
06:06 PM Revision 146f0fad: Do not show on the queue/limiters list the disabled entries(optimized and cleaner version).
Ermal LUÇI
05:42 PM Revision 520ad1a4: Do not show on the queue/limiters list the disabled entries.
Ermal LUÇI
05:11 PM Bug #858 (Resolved): Widget settings will not save settings in some cases
Should be fixed by commit:dbb0e0865b4dbe976781646a490c8a05b6005f25
Jim Pingle
04:00 PM Feature #973 (Resolved): OpenVPN client in GUI cannot connect to a server requiring username/password
The OpenVPN client in the pfSense GUI cannot connect to a server which requires a username/password from the client.
...
Jim Pingle
03:36 PM Feature #177: IPv6 support
gen_subnet() needs to become ipv6 aware
trying to delete a ipv6 state from the traffic states results in an error.
...
Seth Mos
03:30 PM Bug #961 (Feedback): Config sync doesn't remove the last alias on the slave
Applied in changeset commit:"5bb6e1f54022c796e8c37510b287337c7b234cd1". Jim Pingle
03:21 PM Feature #972: Allow adding gateways outside of interface subnet
As I understood from Remko Lodder there is a large ISP in .de that also employs this with their ipv6 configuration. Odd. Seth Mos
12:33 AM Feature #972 (Resolved): Allow adding gateways outside of interface subnet
Gateways outside of the interface's IP subnet, on Ethernet links, cannot be added under normal circumstances as it's ... Chris Buechler
01:54 PM Revision b2c63fa3: up the subnet bits from 32 to 128 so that the access can be locked down to the host for ipv6.
This will require a javascript routine that prevents a subnet mask higher then 32 bits for a ipv4 address.
Alternati...
Seth Mos
12:35 PM Revision db8e9e53: Ticket #943. Call the update procedure directly to not do an unecessary loop.
Ermal LUÇI
12:28 PM Revision 52e5285f: Make this more strict checking.
Ermal LUÇI
11:48 AM Revision 290797ea: Fix the filter.inc rule generation for icmp to prevent a double inet6 in the rule
Add inet6 for user defined rules to ipv6 addresses. Seth Mos
11:19 AM Revision 24b2aa62: Resolves #971. Fix wizard.php to show interface descriptive names. Pointy-hat: gnhb
Ermal LUÇI
10:59 AM Revision 1306c7dd: Change the firewall rule generation to look for the ipprotocol tag which defines inet or inet6. This makes sure that we use ipv6 addresses and change to the correct ipv6-icmp tag.
Seth Mos
08:17 AM Feature #814: GUI should allow to bind openvpn on different ip same port
This can be done now because Ermal converted the management interface over to UNIX sockets, so the port from the GUI ... Jim Pingle
07:15 AM pfSense Packages Bug #844: Open VM Tools Won't install
I've been busy a bit more. With the above commands, the package will install and run but fail at the next boot.
Here...
Peter O
05:25 AM Bug #971 (Feedback): OpenVPN wizard - wrong interface names
Applied in changeset commit:"24b2aa62beafe22517dc34421b78001477703db7". Ermal Luçi
05:25 AM Bug #957 (Resolved): Dynamic DNS Fails with a disabled entry.
Ermal Luçi
01:06 AM Revision 6dbd2e74: Add l7 rules synchro. Ticket #951
Pierre POMES
12:33 AM Bug #970 (Rejected): Cannot add my gateway because the gateway IP is not in the same subnet
See feature #972.
Chris Buechler

10/24/2010

11:50 PM Bug #971 (Resolved): OpenVPN wizard - wrong interface names
When using the OpenVPN wizard, when it comes to the "General OpenVPN Server Information" section, the interface names... Adam Thompson
09:17 PM Feature #951 (Feedback): CARP doesn't sync Layer 7 rule groups
Hi Thomas,
Fix commited, can you try again ?
Thanks
Pierre
Pierre POMES
05:36 PM Bug #970 (Rejected): Cannot add my gateway because the gateway IP is not in the same subnet
System > Routing > I click the Edit icon next to my gateway.
Then, in gateway, I put the (private) IP of my DSL mode...
Martin Dupont
04:49 PM Feature #177: IPv6 support
patch checked in to git that should fix apinger for ipv6. It's now showing both my ipv4 wans up as well as the ipv6 g... Seth Mos
04:13 PM Bug #969 (Feedback): NAT rdr work only on one interface
The rules are fine and rules and rdr definitely are working properly. Do a packet capture on WAN, LAN and the interna... Chris Buechler
03:34 PM Revision a268a576: Add a rule so that the bare icmp ipv6 traffic can get out, otherwise the box can not communicate properly on ipv6
Seth Mos

10/23/2010

07:27 PM Revision 2bbb79cb: tack on the ipv6 information via the old fashioned way until the pfsense module is up to speed
Seth Mos
07:26 PM Revision bbcc0f9c: splay the IPv6 information on status interfaces.
Seth Mos
01:24 PM Bug #967 (Resolved): VLAN Interfaces not comming up at reboot
Chris Buechler
07:26 AM Bug #967: VLAN Interfaces not comming up at reboot
Hello Ermal
It seems that this problem is solved with version "built on Sat Oct 23 01:36:14 EDT 2010"
Thanks a lo...
Peter Baumann
12:26 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Updated to "FreeBSD 8.1-RELEASE-p1 #0: Sat Oct 23 01:35:35 EDT 2010" and no improvement. System log shows only the "... R B
10:54 AM Revision 6538e660: fix filter rule error
Seth Mos
10:49 AM Revision 640b3a9a: remove some debugging from filter inc, show correct ipv6 gateway from function
Seth Mos
10:32 AM Revision 66e0ff49: Run both traceroute and traceroute6 for ipv6 functionaility
Seth Mos
10:28 AM Revision 8bea9639: So gethostbyname() does not work for ipv6, instead run both ping and ping6. That works too.
Seth Mos
10:19 AM Revision 86551a06: Do a gethostbyname() on the host address to get a IP address, then perform ping or ping6 for correct type.
Seth Mos
07:31 AM Bug #969: NAT rdr work only on one interface
Ok, see attach. Mike Stupalov
03:58 AM Bug #969: NAT rdr work only on one interface
Can you show the /tmp/rules.debug Ermal Luçi
03:53 AM Bug #969 (Resolved): NAT rdr work only on one interface
Pfsence version:... Mike Stupalov
03:54 AM Todo #881: Passive FTP over pfsense
Yes, works. Thanks. Mike Stupalov

10/22/2010

09:47 PM Revision 98d75ad4: Be smart and correct; first check for opt*ip and after check for opt* otherwise it will never match the first case!
Ermal LUÇI
09:12 PM Bug #495 (Resolved): USB drive fails to mount during boot
Yeah I talked to thompsa a bit about this a couple days ago, our only option is to hard code kern.cam.boot_delay at a... Chris Buechler
07:05 PM Bug #495 (Feedback): USB drive fails to mount during boot
I think this should be documented somewhere and users can deal with it themselves.
It is not a bug in pfSense per se.
Ermal Luçi
08:06 PM Revision e4d79ab0: Balance <p> with </p>
Ermal LUÇI
07:56 PM Revision 67300ce5: Put </ul> tags inside the same <td> since they cannot span multiple of them.
Ermal LUÇI
07:52 PM Revision 4540ab2c: Clear some forgotten </img> </font> tags.
Ermal LUÇI
07:03 PM Bug #918: CP redirection URL and logout on popup don't work
You are sure you had selected that a popup window to be showed? Ermal Luçi
07:02 PM Bug #943 (Feedback): 2.0-BETA4 Dynamic DNS updates not working
Please try a new snapshot some fixes were done to dyndns which might fix even your issues. Ermal Luçi
07:01 PM Todo #881 (Feedback): Passive FTP over pfsense
This seems to be ok on latest snaps. Ermal Luçi
07:00 PM Bug #967 (Feedback): VLAN Interfaces not comming up at reboot
Please test a new snapshot.
Seems you have hit a bug that was present in recent snapshots and was resolved.
Ermal Luçi
06:51 AM Bug #967 (Resolved): VLAN Interfaces not comming up at reboot
I'm using 20101021 Snapshot of pfSense 2.0 on ALIX Box.
I setup the following:
# Factory Default
# create 4 VLAN...
Peter Baumann
04:05 PM Revision 1feb93cf: Mark this entry as an array before treating it as such otherwise php complains.
Ermal LUÇI
03:49 PM Revision 90e64fad: Check to see if it is not an array first - as per jim-p on IRC.
Warren Baker
02:01 PM Revision 5a5413bb: Add the default ipv4 route and the default ipv6 route, check both routing tables before adding or changing.
set the ipv6 IP address via a mwexec() until the pfsense module is adapted. FIXME.
Add filter rules for ipv6 to let t...
Seth Mos
11:32 AM Revision 47593ac6: Allow for configuring a IPv6 address on the interfaces page.
Add code to verify a ipv6 address
Let is_ipaddr() return true on a v4 and v6 address.
Change system gateways edit to ...
Seth Mos
11:07 AM Feature #177: IPv6 support
I've started ipv6 work on pfSense-smos clone and I've started running into the 1st few issues which I'm documenting h... Seth Mos
08:01 AM Bug #968: PHP error in user manager
I can see 2 admin groups in my group list, probably has something to do with it. Having the same problem on 2 freshly... Peter O
07:01 AM Bug #968 (Resolved): PHP error in user manager
Fresh install of built on Fri Oct 22 06:39:04 UTC 2010
A PHP error shows in the "select group membership" fields ...
Peter O
06:07 AM pfSense Packages Bug #844: Open VM Tools Won't install
People having this issue: You can install the tools with the following commands (I'm using ESXi 4.1 with 64 bit pfSen... Peter O
03:49 AM Revision be81b340: Display the ICMP type (abbreviated) in the firewall rule list and show the full text when the cursor is over it for ticket #762
Erik Fonnesbeck
02:54 AM Revision fc3e88f1: Fix crl upgrade code.
Jim Pingle
01:20 AM Bug #957: Dynamic DNS Fails with a disabled entry.
Confirmed, the applied patch fixes the issue. Matt Corallo
01:10 AM Bug #957: Dynamic DNS Fails with a disabled entry.
Matt, can you please confirm that fixed the issue? Chris Buechler

10/21/2010

11:54 PM Feature #762 (Feedback): Display ICMP type on firewall rule list
Erik Fonnesbeck
09:11 PM Revision 5e693f58: Break after the first error.
Jim Pingle
09:08 PM Revision 630d7025: Prevent the DHCP range from being changed to include static mapping entries. Fixes #964.
Jim Pingle
08:58 PM Revision ab8d138d: Reject DHCP static mappings that are inside of the DHCP range. Fixes #966
Jim Pingle
08:07 PM Revision 62b262e4: Remove WIP note. This should resolve #555.
Jim Pingle
08:00 PM Revision 6a0b3ea4: Indicate in various places if a certificate is revoked.
Jim Pingle
07:49 PM Revision 150bbe09: Indicate if a certificate has been revoked, both in the cert list and the user manager list.
Jim Pingle
07:11 PM Revision fc54f29b: Add ability to select reason codes for revocation. Reformat CRL edit screen a bit. Ticket #555
Jim Pingle
06:33 PM Revision 8e022a76: Refresh OpenVPN CRL files when a CRL has a cert added/removed. Ticket #555
Jim Pingle
05:34 PM Revision ad08687b: Add support for deleting a cert from a CRL (unrevoke). As of this point basic CRL functionality does work: Revoke a cert and it cannot connect. Remove it from the CRL and it can. (Have to edit/save OpenVPN server instance to update/refresh CRL though). Ticket #555
Jim Pingle
05:10 PM Bug #964 (Feedback): Changing DHCP pool size allows overlap with static leases
Applied in changeset commit:"630d7025810bf1ce006490db8524d6edc37ee6fb". Jim Pingle
04:45 PM Bug #964: Changing DHCP pool size allows overlap with static leases
See also #966 Jim Pingle
10:40 AM Bug #964 (Resolved): Changing DHCP pool size allows overlap with static leases
If you have a set pool size, then create static entries outside of the pool, and later expand the pool so it covers t... Jim Pingle
05:00 PM Bug #966 (Feedback): DHCP static lease inside the pool is not rejected
Applied in changeset commit:"ab8d138dcd5114c4892e12c514990797572fd318". Jim Pingle
04:45 PM Bug #966: DHCP static lease inside the pool is not rejected
See also #964 Jim Pingle
04:45 PM Bug #966 (Resolved): DHCP static lease inside the pool is not rejected
On 1.2.3, a static assignment inside of the DHCP pool is rejected (and rightly so), somewhere along the line in 2.0 t... Jim Pingle
04:10 PM Bug #555: Certificate Revocation List (CRL) missing from Certificate Manager
Applied in changeset commit:"62b262e4766bcd5e46b4191e0f618087b78d8f40". Jim Pingle
04:03 PM Bug #555 (Feedback): Certificate Revocation List (CRL) missing from Certificate Manager
This should be feature-complete as far as I can tell, unless anyone has any more ideas about how it should be changed... Jim Pingle
01:51 PM Bug #965 (Resolved): IPSec configuration network selection doesn't match rest of UI
Related to Feature Request #946, but not quite the same...
Everywhere else in the 2.0 UI (mostly rules, but I thin...
Adam Thompson
01:00 AM Revision 9f200d71: Change OpenVPN wizard to set input_errors when there is a fatal condition that will require preventing a config save.
Jim Pingle
12:59 AM Revision 7f167923: Add these error/info box classes to the wizard.css file.
Jim Pingle
12:59 AM Revision 27319e17: Add a patch to wizard.php to support input_errors from sullrich (with some modifications).
Jim Pingle
12:12 AM Revision 8f87a4a2: Reject special characters in CA/Cert field names during OpenVPN wizard. Fixes #900
Jim Pingle

10/20/2010

11:13 PM Revision 47319bfb: Add upgrade code for importing CRLs. Ticket #555
Jim Pingle
09:00 PM Bug #900 (Feedback): OpenVPN Wizard: Server Certificate Wizard
It should be fixed now after my latest commits (not seen on this ticket). Some changes to wizard.php were needed to p... Jim Pingle
08:21 PM Bug #900 (New): OpenVPN Wizard: Server Certificate Wizard
Spoke too soon. It prints the error message properly but the bad values are still saved in the config and a config re... Jim Pingle
08:15 PM Bug #900: OpenVPN Wizard: Server Certificate Wizard
Applied in changeset commit:"8f87a4a2aa746a44b6bd5f0ef4b4eea63c7703de". Jim Pingle
08:18 PM Bug #961: Config sync doesn't remove the last alias on the slave
OK, that is a bit different scenario that I have not tested yet. I shouldn't need your alias list to try that out. Jim Pingle
08:14 PM Bug #961: Config sync doesn't remove the last alias on the slave
Hi Jim,
Yes, I was talking about Firewall > Aliases.
I don't know if I was clear in my first message, by "last al...
Thiago Witt
05:41 PM Bug #961: Config sync doesn't remove the last alias on the slave
If you are talking about an Alias as in Firewall > Aliases, I can't reproduce this. If I delete the last one on the m... Jim Pingle
07:37 AM Bug #961 (Resolved): Config sync doesn't remove the last alias on the slave
If I setup two systems with carp sync and create an alias, it will sync correctly with the slave, but when I remove i... Thiago Witt
07:41 PM Revision 28ff7ace: Add more CRL functionality. Needs to wait on a new build for further testing.
Jim Pingle
07:41 PM Revision 5293bfec: Fix some forgotten name->descr changes.
Jim Pingle
07:06 PM Bug #963 (Closed): CARP Virtual IPs bind to actual interface, not interface description
Yes, you need to maintain the correct order. Chris Buechler
07:05 PM Bug #963 (Closed): CARP Virtual IPs bind to actual interface, not interface description
I have the following setup on Oct 2 snapshot:
Firewall A:
WAN (wan) -> em1 -> 2xx.xxx.xx...
Tom Pepper
06:46 PM Bug #555: Certificate Revocation List (CRL) missing from Certificate Manager
I've made some more CRL commits today. Once the new snapshot is up, it should (in theory) be capable of revoking a ce... Jim Pingle
06:43 PM Revision d8912c6b: move dhcpd.conf authoritative; so it's only there once, not once per interface.
Chris Buechler
05:53 PM Bug #601 (Resolved): VHID changes do not apply immediately on secondary
This works properly now. Jim Pingle
05:17 PM Feature #811 (Feedback): PPTP/GRE NAT multiple connections to single server
Ermal Luçi
04:14 PM Bug #368 (Closed): DHCP option is not recognized
this is a general issue covered in #962 Chris Buechler
04:14 PM Bug #962 (Resolved): DHCP custom options must have type selection
The custom DHCP options are currently all added as text type. This doesn't work for many options, which require a dif... Chris Buechler
03:13 PM Revision ac87dbbf: Traffic shaper wizards remove redirection before final step. This seems a forgotten item.
Ermal LUÇI
12:48 PM Revision 7d30a315: Sync CRLs, too.
Jim Pingle
08:22 AM Bug #960: Problem with config sync + ipsec + special characters
We escape that with CDATA in the config, though I'm not sure how well that translates via XMLRPC (pfsync and CARP rea... Jim Pingle
07:33 AM Bug #960 (Resolved): Problem with config sync + ipsec + special characters
When the description field in ipsec's phases 1 and 2 contains special characters such as accentuation config sync is ... Thiago Witt
07:25 AM Bug #959 (Resolved): Config sync removes alias VIPs on the slave
I want to have 2 CARP VIPs on the same interface, but each using a different subnet, so I need an alias on each syste... Thiago Witt

10/19/2010

08:08 PM Revision 50cafcf3: Correctly call die() in the places needed. Also remove unused global.
Ermal LUÇI
07:34 PM Revision d7381e71: Generalize the "low res" user agent detection so it isn't Apple-specific. Include Android in the detection, and also provide a mechanism so that the "low res" theme can be set in globals.inc.
Jim Pingle
06:19 PM Revision f2a86ca9: Rename 'name' to 'descr' for CA, Certificates, and CRLs, to gain CDATA protection and standardize field names. Ticket #320.
Jim Pingle
05:03 PM Revision 6751b3e7: Generalize this function and use it in more places to reduce duplicated code.
Jim Pingle
04:52 PM Bug #882 (Resolved): IP aliases should not sync
Hi Thiago,
Ok for the new ticket. I will put this one to resolved since the initial report is now ok.
Thanks,
...
Pierre POMES
10:35 AM Bug #882: IP aliases should not sync
Hi Pierre,
I just update both my systems with gitsync and now it no longer syncs the aliases, so that's ok.
Now...
Thiago Witt
04:51 PM Revision 9ff73b79: Convert fullname field on users to descr, so it gains CDATA protection.
Jim Pingle
04:39 PM Revision e988813d: desc to descr in Load Balancer config, so they gain CDATA protection and standardize field names. Ticket #320.
Jim Pingle
04:07 PM Revision c4f55084: Update field name reference in code, it was changed to descr but this code was missed. (Is this code even needed? Doesn't seem to do anything.)
Jim Pingle
04:00 PM Revision 15864861: Change the description field on sysctl tunables to be 'descr' and not 'desc' so they will gain CDATA protection. Ticket #320
Jim Pingle
03:44 PM Bug #729 (New): if_bridge unpredictable filter interface selection
This needs revisiting at proper time because now the patch that was added is not in the builds. Ermal Luçi
02:34 PM Bug #320 (Feedback): Using special characters (e.g. åäö) in certificate "Descriptive name" breaks entire WebGUI
I have renamed the fields in several parts of the config and GUI to descr in an attempt to help resolve this issue. I... Jim Pingle
07:17 AM Bug #879 (Resolved): Correct parsing of output by rate
Jim Pingle
02:44 AM Bug #879: Correct parsing of output by rate
Thanks. Just close this ticket. Torben Hørup
03:31 AM pfSense Packages Bug #265: Bugs in Squid LightSquid SquidGuard Packages in PFsense 2.0
squidGuard.conf contains the option "dbhome" which defines where blacklists are located, the default path is /usr/loc... Basel G.
12:46 AM Bug #958 (Resolved): reply-to for 1:1 from other directly connected subnets not functioning correctly
Where you have a system with two WANs, such as WAN1 and WAN2, when sourcing traffic from a host on the WAN1's IP subn... Chris Buechler

10/18/2010

10:36 PM pfSense Packages Bug #265: Bugs in Squid LightSquid SquidGuard Packages in PFsense 2.0
No need to make the CF mounted read/write all the time just to extract the Squidguard blacklists, why not to mount RW... Basel G.
09:16 PM pfSense Packages Bug #265: Bugs in Squid LightSquid SquidGuard Packages in PFsense 2.0
The only alternative to using /var is to keep the CF mounted read write all the time, which eliminates the purpose of... Chris Buechler
08:28 PM pfSense Packages Bug #265: Bugs in Squid LightSquid SquidGuard Packages in PFsense 2.0
To effectively remove packages you have to delete the .xml file(s) in "/usr/local/pkg", this seems to be a problem wi... Basel G.
09:19 PM pfSense Packages Bug #580: dns-server fails to install and remove
Nevermind. I recreated the whole thing on another instance of PfSense and everything works fine. I think the package ... Jorge Fabregas
07:58 PM Revision 8a98ce81: ipalias type should be handled in backup_vip_config_section. Remove useless code which copies vip section before call to backup_vip_config_section. Ticket #882
Pierre POMES
05:17 PM Revision f5fe66cd: Merge remote branch 'mainline/master' into inc
Renato Botelho
03:58 PM Bug #882 (Feedback): IP aliases should not sync
Hi Thiago,
A new fix hax been commited. Can you please try again ?
Thanks again,
Pierre
Pierre POMES
03:18 PM Bug #882 (Assigned): IP aliases should not sync
Thanks for the report. I will doublecheck.
Pierre
Pierre POMES
03:02 PM Bug #882: IP aliases should not sync
Hi, I've just tested it with the latest snapshot and it seems the problem remains.
Looking at the source, I think ...
Thiago Witt
03:16 PM Revision 5d763c0e: Fix the dedicated and multi_all wizards. They had typos in variable names and some remaining unused code which caused problems!
Ermal LUÇI
12:39 PM Revision 2e408f59: Disable the bandwidth speed selection field also to avoid errors/problems when the catch all is not activated.
Ermal LUÇI
11:52 AM Revision 232846a2: Ticket #868. Add Connection: close to the header to be proxy friendly. See http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html for reference.
Ermal LUÇI
11:14 AM Revision f21c7979: Use proper matching because the command might contain nice in it.
Ermal LUÇI
05:55 AM pfSense Packages Bug #868 (Feedback): transparent Squid breaks captive portal
Ermal Luçi
05:49 AM Bug #582: Add all Diffserv options
See #670 for more information. Ermal Luçi
05:48 AM Bug #670 (Closed): Diffserv Code Point in firewall rule isn't match with the result of "pfctl-sr"
The issue is that you are doing the calculation wrong.
AFAIK dscp values you see on Cisco site you have to add 00 at...
Ermal Luçi
02:44 AM Revision 00686fee: Character '#' is invalid in string fields of SNMP service screen. Ticket #956
Pierre POMES

10/17/2010

11:28 PM Bug #882 (Resolved): IP aliases should not sync
Chris Buechler
11:28 PM Bug #929 (Resolved): Remote syslog not working
Chris Buechler
11:28 PM Bug #797 (Resolved): UI: IPsec Phase 2 edit, Address field active for LAN subnet option
Chris Buechler
10:36 AM Bug #797 (Feedback): UI: IPsec Phase 2 edit, Address field active for LAN subnet option
Problem was due to a javascript issue, only for mobiles. Should be fixed now.
Pierre POMES
11:27 PM Bug #956 (Resolved): # cannot be used in SNMP configuration
Chris Buechler
10:44 PM Bug #956 (Feedback): # cannot be used in SNMP configuration
You are right. Fix commited in the screen. Pierre POMES
10:24 PM Bug #956: # cannot be used in SNMP configuration
That's fine, though it'd be easier and fine to just throw an input validation error if any of the fields contain # Chris Buechler
10:22 PM Bug #956: # cannot be used in SNMP configuration
Chris,
The man page of bsnmp deals with '#' in config file:...
Pierre POMES
09:07 PM Bug #956: # cannot be used in SNMP configuration
Just figured it out. Don't use "#" characters in any of the fields...
(I had the address set to "#200-135 Innovat...
Adam Thompson
07:39 PM Bug #956: # cannot be used in SNMP configuration
Hi Adam,
I just upgraded to the latest snapshot and I cannot reproduce the problem.
Can you give me the "snmpd"...
Pierre POMES
02:35 PM Revision 71880c96: Do not include 'remoteid' javascript functions for mobile ipsec. Ticket #797
Pierre POMES

10/16/2010

04:19 PM Revision 65996399: Resolves #957. Correct the code to reflect what its supposed to do.
Ermal LUÇI
03:28 PM Revision 814bb2dc: Bump config.
Ermal LUÇI
03:27 PM Revision 65167fcc: Do not run anymore the cron job for monitoring check_reload_status since it has a monitoring process that does this through kqueue.
Ermal LUÇI
01:16 PM Bug #906: Orphaned rules from deleted interfaces are still present in config
You are right the interface deletion code does get rid of the rules, but if someone deleted the interface before that... Jim Pingle
12:24 PM Bug #906: Orphaned rules from deleted interfaces are still present in config
This is how the interface deletion code works!
What are the details to reproduce the problems?
Ermal Luçi
12:20 PM Bug #957 (Feedback): Dynamic DNS Fails with a disabled entry.
Applied in changeset commit:"659963994dce689bdaaa5cdd83bc77008737d92a". Ermal Luçi
12:18 PM Bug #957: Dynamic DNS Fails with a disabled entry.
Thank you committed. Ermal Luçi

10/15/2010

08:54 PM pfSense Packages Bug #580: dns-server fails to install and remove
Hi, I'm running the latest (as of Oct 15th) and I just installed dns-server and a few minutes later decided to remove... Jorge Fabregas
07:11 PM Bug #957 (Resolved): Dynamic DNS Fails with a disabled entry.
Line 593 in /etc/inc/services.inc should be return, not continue.
This can cause the following error on a page whi...
Matt Corallo
04:18 PM Bug #956 (Resolved): # cannot be used in SNMP configuration
Actual problem is a # character can't be used in any of the SNMP configuration fields. Original post follows.
R...
Adam Thompson
02:29 PM Revision f5ea58da: Ticket #927. Increase timeout to gice mpd the time needed to exit gracefully.
Ermal LUÇI
01:59 PM Revision b641a575: Ticket #934. Perform test only for ldap backend. Also tell the user through a message when they click it for other backends.
Ermal LUÇI
01:42 PM Revision f1aad4d1: Resolves #879. Commit patch referenced in ticket to properly parse rate output.
Ermal LUÇI
12:14 PM Revision 26f131b8: Fix typo
Renato Botelho
12:11 PM Revision b96f6496: Merge remote branch 'mainline/master' into inc
Conflicts:
etc/inc/pkg-utils.inc
Renato Botelho
08:33 AM Bug #927 (Feedback): 3G modem rendered un-usable by forced cycling of connection
Try with latest changes. Ermal Luçi
08:02 AM Feature #934 (Feedback): Add RADIUS support to Diag>Auth page
Ermal Luçi
07:50 AM Bug #879 (Feedback): Correct parsing of output by rate
Applied in changeset commit:"f1aad4d1ad04214382ba577360732ae581c51264". Ermal Luçi
04:49 AM Feature #935 (Feedback): User manager RADIUS authentication method
You can create the same user locally and assign it to groups that should work iirc.
Never tested though.
Ermal Luçi

10/14/2010

11:25 PM Bug #714: Cellular RRD Graph Shows w/o 3G Modem Installed
Just FYI, still present as mentioned in the update (Cellular still appears when at the Settings tab) on:
2.0-BETA4...
Steve Vigneau
11:17 PM Bug #714 (New): Cellular RRD Graph Shows w/o 3G Modem Installed
Setting back to New since it hasn't been fixed. Jim Pingle
07:32 PM Revision 2c794549: Ticket #950. Correctly handle failures while installing packages which might leave stale information behind. Also do not try to startup services twice. Rename uninstall_package_from_name to uninstall_package because the operation on packages is only done through package names.
Ermal LUÇI
06:58 PM Revision ab0eced7: We want to upgrade all of interfaces/gateways.
Ermal LUÇI
03:30 PM Bug #950 (Feedback): Package installation failures leaves package installed
Ermal Luçi
03:00 PM Bug #955 (Feedback): Static IP gateway does not upgrade from 1.2.x to 2.0
Should be fixed in later versions. Ermal Luçi
12:33 PM Bug #955 (Resolved): Static IP gateway does not upgrade from 1.2.x to 2.0
If you have a 1.2.3 install with WAN configured with a static IP, the gateway does not upgrade to 2.0.
This used t...
Jim Pingle
02:47 PM Bug #922 (Feedback): Traffic Shaper
Is this happening with latest version? Ermal Luçi
01:07 PM Revision a1945b0a: Merge remote branch 'mainline/master' into inc
Renato Botelho
06:42 AM Bug #883 (Feedback): Renaming gateway doesn't update static routes
This should be ok in latest versions. AFAIR you cannot rename gateways anymore. Ermal Luçi
04:54 AM Revision 4b0c83c3: Hide ports when protocol does not use ports. Ticket #953
Erik Fonnesbeck
02:28 AM Revision f9106085: Hide translation section when "Do not NAT" is checked. Fixes #952
Erik Fonnesbeck
02:12 AM Revision c3f36fb5: Don't clear the source port when changing source address type to any. Also update source when editing a rule with source type any.
Erik Fonnesbeck
01:09 AM Feature #953 (Feedback): On outbound NAT rule edit, hide ports when protocol does not use ports.
Erik Fonnesbeck

10/13/2010

10:45 PM Feature #952 (Feedback): When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
Applied in changeset commit:"f91060852cd28d14fa2cfa100c358e3c4a7fab2c". Erik Fonnesbeck
07:33 PM Feature #952 (Resolved): When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
If "Do not NAT" is checked on an outbound NAT rule, it uses the "no nat" statement in the ruleset, which does not use... Erik Fonnesbeck
09:59 PM Bug #954 (Resolved): Switching to manual outbound NAT creates incorrect rule for PPTP server
When switching to manual outbound NAT when the PPTP server is enabled, it does not pick up any kind of IP address fro... Erik Fonnesbeck
09:57 PM Revision da6155e0: Make sure this is an array before entering the foreach loop. Reported at http://forum.pfsense.org/index.php/topic,29118.0.html
Erik Fonnesbeck
07:41 PM Feature #953 (Resolved): On outbound NAT rule edit, hide ports when protocol does not use ports.
In other rule types, the fields for ports are hidden when selecting a protocol that does not use them. The edit page... Erik Fonnesbeck
05:00 PM Feature #951 (Resolved): CARP doesn't sync Layer 7 rule groups
In pfsense 2.0 (Tue Oct 12 23:05:03 EDT 2010) CARP doesn't sync Layer 7 rule groups. Thomas Svedin
03:41 PM Bug #757: PPPoE Disconnect button with multiple PPPoE interfaces
Can you please try with latest version! Ermal Luçi
04:11 AM Bug #757: PPPoE Disconnect button with multiple PPPoE interfaces
i have the same problem, with period pppoe reset enabled also, once the connection is brought down, it never gets up,... Bipin Chandra
12:54 PM Revision 94823361: Add GUI checkbox to enable strict username/common name matching for SSL/TLS+User Auth mode. Fixes #887
Jim Pingle
11:43 AM Bug #948 (Closed): Can't assign VLANs to LAGG interface via web interface
Chris Buechler
11:29 AM Bug #948: Can't assign VLANs to LAGG interface via web interface
I was fiddling the settings before trying reinstall and renamed some vlans to remove couple of umlaut characters. Sud... Teemu Haapoja
08:05 AM Bug #948: Can't assign VLANs to LAGG interface via web interface
I upgraded to the latest snapshot (2.0-BETA4 (amd64) built on Wed Oct 13 05:08:20 UTC 2010) and the problem still pe... Teemu Haapoja
04:17 AM Bug #948 (Feedback): Can't assign VLANs to LAGG interface via web interface
I just setup VLANs on lagg with igb NICs yesterday, on yesterday's snapshot (same one in the original post), with 0 i... Chris Buechler
03:56 AM Bug #948: Can't assign VLANs to LAGG interface via web interface
Here is ifconfig output for the relevant parts. VLAN_MTU is present on the member interfaces (which do show up on the... Teemu Haapoja
11:39 AM Revision 8eec6fc0: Merge remote branch 'mainline/master' into inc
Renato Botelho
10:55 AM Bug #950 (Resolved): Package installation failures leaves package installed
When a package cannot be installed, such as missing binaries or binaries that cannot be fetched for any reason, the p... Chris Buechler
08:55 AM Feature #887 (Feedback): Add an option for stricter OpenVPN ssl/tls+user auth checking
Applied in changeset commit:"94823361c3216555761ff57463fe91b2a229a090". Jim Pingle
07:02 AM Revision 5a171fb7: Wording fix.
Warren Baker

10/12/2010

10:12 PM Revision 24997966: Ticket #942. Try to prevent empty entries and use implode to avoid problems.
Ermal LUÇI
10:01 PM Revision df2a0f18: Resolves #944. Actually bring down the vlan interface if it existed previously. This is a regression from the ppp dance/requests/whatever.
Ermal LUÇI
09:44 PM Revision 3c692174: Resolves #947. Blacklist lagg interfaces from the list of possible lagg members.
Ermal LUÇI
09:21 PM Revision 8901958c: Add backend code to verify username against cn on login if set by user. Needs GUI code to set the option yet. Ticket #887
Jim Pingle
08:16 PM Bug #757: PPPoE Disconnect button with multiple PPPoE interfaces
Hello again,
I heard from gnhb in the forums who indicated this was/is due to my PPPoE interfaces having the "Dial...
Pho Bia
06:46 PM Bug #920 (Feedback): Routing groups don't change monitor IP address when PPPoE reconnects
This should be solved by the apinger process restarting.
Please test newer snaps.
Ermal Luçi
06:11 PM Bug #942 (Feedback): dhcp relay breaks
Ermal Luçi
06:05 PM Bug #944 (Feedback): Moving VLANs to lagg doesn't remove old VLANs
Applied in changeset commit:"df2a0f1861be7a4b751bc4cb6e5fe7025b8f0f9c". Ermal Luçi
05:45 PM Bug #947 (Feedback): existing lagg members should not be able to be added to lagg
Applied in changeset commit:"3c69217457175c82b73922fca2ce578c3dbfc221". Ermal Luçi
09:19 AM Bug #947 (Resolved): existing lagg members should not be able to be added to lagg
interfaces available after added to a lagg interface. for example:
I created lagg interface with em2 and em3 interfa...
Chris Buechler
05:30 PM Bug #948: Can't assign VLANs to LAGG interface via web interface
Can you show an ifconfig of lagg members and lagg itself when this happens?
Probably one of the members of lagg is n...
Ermal Luçi
10:50 AM Bug #948 (Closed): Can't assign VLANs to LAGG interface via web interface
LAGG interface is missing from VLAN capable interfaces list when creating or editing VLANs, but existing VLANs using ... Teemu Haapoja
02:45 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Yeah that's good but the forum sees more traffic, and the 2.0 board is very active. There are probably quite a few pe... Jim Pingle
02:05 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Will look at opening a forum account and doing so. Already discussed on the support@ ML and Chris suggested opening ... R B
01:29 PM Bug #943 (New): 2.0-BETA4 Dynamic DNS updates not working
I'll set this back to new for now. You might want to start a forum post on the 2.0 board to see if anyone else has si... Jim Pingle
01:00 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Switched to DynDNS (Dynamic) and unset the wildcard. Tested with the three combinations (dynamic/wild, static/nowild... R B
12:37 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
That is possible, I am on a full install. First, can you try setting for DynDNS (Dynamic) and unchecking Wildcard jus... Jim Pingle
12:06 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Perhaps the difference is the platform. Mine's running the embedded NanoBSD build and I get no such 'DynDns: xxx' me... R B
11:33 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
And I do the same thing on mine and it works:... Jim Pingle
12:59 PM Revision bd6f4dcc: Correct this note, on at least one card (mxge) it defaults to an MTU of 9000, so we can't always say the default will be 1500.
Jim Pingle
12:42 PM Feature #949 (Rejected): Multiple IP Addresses on one interface
Already implemented in 2.0.
Firewall > Virtual IPs, the type of "IP Alias" is where this is done.
Jim Pingle
12:13 PM Feature #949 (Rejected): Multiple IP Addresses on one interface
Hello,
I read that you wanted to implement a feature throw which there can be assigned multiple IP's on one inter...
George Lucan
09:50 AM pfSense Packages Bug #945 (Feedback): vhosts package in pfsense 2.0
Applied in changeset commit:"ddac713985dc06d55d5b4222147792d4775bf894". Jim Pingle
08:15 AM Feature #946 (New): Allow aliases to be used to define IPsec phase 2 networks
Eventually it would be nice to allow using aliases on the IPsec phase 2 definition screen for local and remote networ... Jim Pingle
 

Also available in: Atom