Project

General

Profile

Activity

From 11/20/2010 to 12/19/2010

12/19/2010

10:37 PM Bug #1096 (Feedback): pf TSO patch fallout - squid (and potentially other) issues
Chris Buechler
09:56 PM Revision 10518768: Fire this event later in the script
Scott Ullrich
09:50 PM Revision fb34dd22: Add effect when total allocated amount changes
Scott Ullrich
09:38 PM Revision e1271f32: Add note about leaving 1 megabyte free
Scott Ullrich
09:36 PM Revision 5c5610e9: Reword to not confuse
Scott Ullrich
09:35 PM Revision b98e3a72: Comment
Scott Ullrich
09:34 PM Revision d9f22217: Add rowhelper_onDelete call
Scott Ullrich
09:31 PM Revision 1c53acd3: Nuke function_exists()
Scott Ullrich
09:31 PM Revision 8fdc5159: Only for once
Scott Ullrich
09:29 PM Revision 346cc87f: Disable changing of allocated box. Merge two functions into one
Scott Ullrich
09:23 PM Revision 28a9cb7f: Add and use rowhelper_onAdd which will fire javascript code after adding new row
Scott Ullrich
09:15 PM Revision 8e946201: Remove debugging alert()
Scott Ullrich
09:14 PM Revision a17f284c: Add rowhelper_onChange variable for row helper and remove the previous function detection code
Scott Ullrich
09:08 PM Todo #881: Passive FTP over pfsense
work for me too.
can connect from the LAN to remote FTP servers using PASV.
Michel Samovojski
08:51 PM Revision a1532937: Minor formatting fixes
Scott Ullrich
08:46 PM Revision b1782537: Correctly --
Scott Ullrich
08:37 PM Revision d8c96528: Decrease size by 1 megabyte as some disks are failing
Scott Ullrich
08:34 PM Revision 47127d13: Format please wait better with a table
Scott Ullrich
08:32 PM Revision a97279db: Style the hr
Scott Ullrich
08:22 PM Revision ba0c3651: Save boot manager selection when returning to previous screens
Scott Ullrich
08:13 PM Bug #1116: IPsec error, racoon won't start with more than one phase 2
Will probably need some more logic in there then, because several types of mobile configurations will break without j... Jim Pingle
07:55 PM Bug #1116: IPsec error, racoon won't start with more than one phase 2
Note : the bug seems to be in /etc/inc/vpn.inc, line 640:... Pierre POMES
08:13 PM Revision 8206c01d: Fix typos. Align to middle in table header row
Scott Ullrich
08:11 PM Revision be1be0b8: Jettison the ugly yellow box. Customize the title of each page in the header of table. If an error has occurred do not show the begin installation button.
Scott Ullrich
07:40 PM Revision 97e721e7: Fix typos. Only show the encryption notice once.
Scott Ullrich
06:40 PM Revision cace4c41: Only show encryption warning once
Scott Ullrich
06:21 PM Revision 80f2185d: Only add to total allocated field if the value is above > 0 for the item
Scott Ullrich
06:18 PM Revision 611c9b3d: Disable encpass when we are not using an encrypted fstype. Alert to the operator that defining an encpass on an encyrpted volume will require a password on each bootup.
Scott Ullrich
06:14 PM Revision 40f9accf: Use full path to binaries. Make savemsg a global
Scott Ullrich
06:06 PM Revision 28f9612c: Throw an error if we have an encrypted / without a non-encrypted /boot
Scott Ullrich
04:53 PM pfSense Packages Bug #310: Nut needs changes for latest version
I don't want to be the inpatient en annoying guy,
But could someone implement a fix so it recognizes both types of s...
Marcus van Dam
03:51 PM pfSense Packages Bug #1117 (Resolved): TinyDNS-- Warning: Invalid argument supplied for foreach() in /usr/local/www/pkg.php on line 241
dns-server Version 1.0.6.14 running on pfsense 2.0-BETA4 (i386)built on Fri Dec 17 22:35:37 EST 2010 shows
Warnin...
mike stratoti
12:53 PM Bug #636: layer7 not work correctly
2.0-BETA4 (i386) built on Sun Dec 19 06:36:15 EST 2010
I have tried all my same combination of firewall rules (def...
Seth Scardefield
11:09 AM Bug #1102: Captive Portal does not work after upgrade
Hello,
I've tested today with pfSense-Full-Update-2.0-BETA4-20101219-0151.tgz (built on Sun Dec 19 05:36:18 EST) :...
Thomas NOEL
12:39 AM Revision 332bb9ab: Remove newline
Scott Ullrich
12:24 AM Revision 5faeedc6: Move total allocated box below rowhelper
Scott Ullrich

12/18/2010

11:48 PM Revision 4f646415: Add total allocated box that adds up all of the sizes that have been allocated thus far
Scott Ullrich
11:05 PM Revision 4b54648c: Rename conf to x counter
Scott Ullrich
11:04 PM Revision 99a20c51: Do not allow /conf and inform user to use /cf when making a dedicated conf slice
Scott Ullrich
10:58 PM Bug #636: layer7 not work correctly
Using 2.0-BETA4 (i386) built on Sat Dec 18 09:51:58 EST 2010, I re-applied the Layer 7 rule I'd created before (which... David Szpunar
10:46 PM Bug #1116 (Resolved): IPsec error, racoon won't start with more than one phase 2
Mobile IPsec connection with more than one Phase 2 connections create an invalid /var/etc/racoon.conf file that preve... David Szpunar
10:41 PM Revision a16d38c9: Fix softupdates
Scott Ullrich
09:43 PM Revision b8791a31: Restore encpass as well
Scott Ullrich
09:38 PM Revision 4fdc80b1: Save layout on disk. If an installer error occurs the layout will be restored on the rowhelper screen so that you can easily make changes
Scott Ullrich
09:20 PM Revision 1ddd4ba3: USe memory *2 for default swap space
Scott Ullrich
09:14 PM Revision 502e7c83: Note that .eli are encrypted
Scott Ullrich
08:43 PM Revision df40aa86: Be less chatty
Scott Ullrich
08:32 PM Revision e9954aef: Do not spam console, spam log
Scott Ullrich
08:22 PM Revision 77a842ef: No need to output 'Loading new configuration'. We already have a line written out telling the user what we are doing
Scott Ullrich
08:12 PM Revision 81868072: use is_dir(). Sometimes php lack of uniform function names can be annoying.
Scott Ullrich
07:57 PM Revision 42ee8bde: Ensure log directory exists before invoking syslogd
Scott Ullrich
07:42 PM Revision d64fa7f2: Touch log file so it can be created on livecd
Scott Ullrich
02:00 PM Bug #1102: Captive Portal does not work after upgrade
I just upgrade to 2.0-BETA4 (i386) built on Sat Dec 18 09:51:58 EST 2010, and still the same problem.
Thanks
Alfredo Frugone
10:59 AM Bug #1115 (Closed): squid bug
There was already a ticket on here for that, and it was closed because it was fixed. In the future, please update to ... Jim Pingle
07:33 AM Bug #1115: squid bug
Fixed on latest upgrade Dienis Rastegaeff
05:30 AM Bug #1115 (Closed): squid bug
Doesn't work "Transparent proxy" feature.
When it is enabled - blocks all HTTP traffic.
workaround - configuring us...
Dienis Rastegaeff
07:02 AM Revision cc9464c1: Disable easy options until refactored to work with new rowhelper style post
Scott Ullrich
06:25 AM Revision 75a28755: Redirect to / if already installed
Scott Ullrich
06:21 AM Revision 37bd1cbb: Misc comments
Scott Ullrich
06:06 AM Revision 72b14823: Add mirroring. Default to no boot manager saving a few seconds on bootup
Scott Ullrich
04:56 AM Revision dabad9b7: Correct path
Scott Ullrich
04:44 AM Revision 2f13a852: We do not need these files
Scott Ullrich
04:43 AM Revision e2912927: Add new files
Scott Ullrich
04:38 AM Revision 9b8707c3: Catch up to recent FreeBSD-9-CURRENT changes
Scott Ullrich
03:49 AM Revision 65c6cdfa: Show begabyte size in addition to pretty formatted style
Scott Ullrich
03:44 AM Revision 4d0a1ade: Echo out newline
Scott Ullrich
03:30 AM Revision d4e79776: Correct reboot link
Scott Ullrich
03:00 AM Revision b526ca11: Unbreak more than 2 slices
Scott Ullrich
02:49 AM Revision 8b590740: Auto set 256 and remaining to /
Scott Ullrich
01:22 AM Revision 86b521ea: Ignore mountpoint for SWAP
Scott Ullrich
01:19 AM Revision ba3feae8: Add rowhelper support
Scott Ullrich
01:19 AM Revision d5b2cfd4: Adding support for custom hooks. If the function row_helper_dynamic_custom() exists it will be called and pass a tr object which is the createElement("tr") handle.
Scott Ullrich
01:19 AM Revision b176ce91: Honor rowsize.
Scott Ullrich

12/17/2010

11:28 PM Revision 7afb7ea9: Safe belts to avoid errors.
Ermal LUÇI
10:55 PM Revision 67b057a9: Do not attach ng_etther(4) to every system interface. Instead do a search if netgraph is needed on single/every interface during interface configuration. Also enable netgraph support for interface as needed when enabling pptp/l2tp/pppoe/... . This should prevent the netgraph queue to slow down network performance on fast links.
Ermal LUÇI
10:52 PM Revision 0183a568: Move to index.php.
Scott Ullrich
10:10 PM Revision 15226bf3: Moving installer to it's own directory since we will have a number of helper javascript files and such soon
Scott Ullrich
09:57 PM Revision 9f154c16: Do not copy non existent /sys
Scott Ullrich
09:56 PM Revision a37308b2: Add /boot when encrypting
Scott Ullrich
09:52 PM Revision 7168ab88: Pass bootmanager and encryption settings
Scott Ullrich
09:35 PM Revision 89058570: Allow carp as parent only to ipalias.
Ermal LUÇI
09:31 PM Bug #1102: Captive Portal does not work after upgrade
That date is an hour before the fix was committed and comment here. "test new snapshots" always means a date of at le... Chris Buechler
09:23 PM Bug #1102: Captive Portal does not work after upgrade
Ermal Luçi wrote:
> Please test new snapshots it should be fixed.
I've just tested 2.0-BETA4 (i386) built on Fri ...
Thomas NOEL
08:21 PM Bug #1102: Captive Portal does not work after upgrade
Thomas NOEL wrote:
> Hello,
>
> Found a solution : # /sbin/sysctl net.inet.ip.fastforwarding=1
>
> I think the...
Nick K
03:51 PM Bug #1102 (Feedback): Captive Portal does not work after upgrade
Please test new snapshots it should be fixed. Ermal Luçi
01:46 PM Bug #1102: Captive Portal does not work after upgrade
Thomas NOEL wrote:
> Can you try this (on a shell) :
> # /sbin/sysctl net.inet.ip.fastforwarding=1
>
> It work...
Karsten H.
10:20 AM Bug #1102: Captive Portal does not work after upgrade
Same problem here! As soon as I enable captive portal there is no redirect and no more internet access on that interf... Karsten H.
08:12 AM Bug #1102: Captive Portal does not work after upgrade
gerard grazzini wrote:
> with 2.0-BETA4 (i386) built on Fri Dec 17 01:17:30 EST 2010
> the Captive Portal still be ...
Thomas NOEL
07:14 AM Bug #1102: Captive Portal does not work after upgrade
with 2.0-BETA4 (i386) built on Fri Dec 17 01:17:30 EST 2010
the Captive Portal still be broken for me ...
gerard grazzini
04:39 AM Bug #1102: Captive Portal does not work after upgrade
Hello,
Found a solution : # /sbin/sysctl net.inet.ip.fastforwarding=1
I think the regression came from commit:4...
Thomas NOEL
09:31 PM Revision 82db1bc5: More safety belts. Do not allow a carp referenced by an ipalias to be deleted.
Ermal LUÇI
09:22 PM Revision b3c1391a: Fallback to the sane limit of 255 now that the patch is backed out.
Ermal LUÇI
09:19 PM Revision a5a6ab28: Add safety belts since only aliases on same subnet can be added to an carp(4)
Ermal LUÇI
09:11 PM Revision dc2bb9e5: Allow ip aliases to be added to vips.
Ermal LUÇI
08:49 PM Revision 6b740881: Allow setting none for boot manager to turn off F1 pfSense
Scott Ullrich
08:34 PM Revision ffdc499a: Show when disk is encrypted. Do not uppercase .eli
Scott Ullrich
07:32 PM Revision d48927b4: Supply encpass if needed
Scott Ullrich
06:34 PM Bug #1087: vouchers need to save to CF periodically
I committed code to prevent that foreach error. Ermal Luçi
06:34 PM Bug #1030: Interface case change in apinger.conf needs reverted
Well as it is now it cannot use any lowercase name since it uses the gateway name!
Possibly on 2.x++ this can be fix...
Ermal Luçi
06:29 PM Feature #385: Allow the use of Captive Portal to restrict services on the firewall itself.
Well there is a possiblity to add an ipfw rule with direction out and keep-state to provision this!?
Ermal Luçi
06:27 PM Bug #1072 (Closed): Issues with increased CARP VHID limits
This is not anymore present in builds. Ermal Luçi
06:19 PM pfSense Packages Bug #1110 (Resolved): libgd.so.4 => not found (0x0) - bandwidthd won't start
I just installed OK on both i386 and amd64. All expected dependencies installed, ldd showed all libraries present.
...
Jim Pingle
05:47 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
Nah just uninstall the package by hitting the 'x' on the Installed Packages screen. Then find it in the list and try ... Jim Pingle
05:41 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
Hello Jim,
just did the following on amd64:
- Update to Vesion 2.0-Beta4 from Fri Dec 17 01:17:30 EST 2010 to hav...
Thomas Scholten
06:19 PM Revision f8895161: Add missing - in syslogd command line parameters, fixes #1111
Jim Pingle
04:51 PM Bug #1088 (Resolved): CARP sync broken
Jim Pingle
04:46 PM Bug #1088: CARP sync broken
Tested with 2.0-BETA4 (i386) built on Fri Dec 17 01:17:30 EST 2010
Revision: http://redmine.pfsense.org/projects/pf...
Francisco Brasileiro
04:09 PM Revision d9587b98: Add on disk encryption options and ability to set a encpass to the experimental installer
Scott Ullrich
03:53 PM Bug #636: layer7 not work correctly
I committed a change, please test newer snapshots. Ermal Luçi
03:53 PM Revision 6141561c: Add newline after 99 menu option. Otherwise it looks very strange.
Scott Ullrich
03:32 PM Revision 3aad9551: When we supply a version number, it should be under All/ and not Latest/ (which has names but no version numbers)
Jim Pingle
01:20 PM Bug #1111 (Feedback): SIGTERM to syslogd after enabling Remote syslog'ing
Applied in changeset commit:"f889516190ab1ec29ab533c662d932bb4f02c392". Jim Pingle
12:55 PM pfSense Packages Bug #1098 (Resolved): Squid Installation fail on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
Jim Pingle
12:24 PM pfSense Packages Bug #1098: Squid Installation fail on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
Yes installed and running. Mukesh Patel
03:08 AM Feature #1113: WAN Interfaces with the same Gateway
ok, but couldn't be an arp-proxy the solution of the problem ?
Falk
Falk Nisius
02:14 AM Feature #1113: WAN Interfaces with the same Gateway
There's one ARP table for the entire system regardless of how many NICs or jails or routing tables you have, and that... Chris Buechler
02:08 AM Feature #1113: WAN Interfaces with the same Gateway
excuse my investigation, its only for my understanding. if I wish to send an ip-packet from my box to an ip-adress, i... Falk Nisius
01:16 AM Feature #1113: WAN Interfaces with the same Gateway
layer 2 is the issue, not layer 3. Chris Buechler
01:14 AM Feature #1113: WAN Interfaces with the same Gateway
Yes You are right its ugly, but a small router with a 9V DC power supply beside is much uglier. I thought, that in Fr... Falk Nisius
12:45 AM Revision f444c396: Prevent division by zero if the file size is zero.
Erik Fonnesbeck

12/16/2010

10:36 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
It should be all clear on i386 now, too. Jim Pingle
03:32 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
FYI- It should be OK on amd64 now:... Jim Pingle
02:32 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
sorry i can only test the amd64 packages right now; still experiencing the same error Thomas Scholten
02:27 PM pfSense Packages Bug #1110 (Feedback): libgd.so.4 => not found (0x0) - bandwidthd won't start
This should have been set to feedback, not resolved just yet. Jim Pingle
02:25 PM pfSense Packages Bug #1110 (Resolved): libgd.so.4 => not found (0x0) - bandwidthd won't start
I did quite a bit of cleanup on the i386 package build machine today and did a complete fresh run just now. Can you t... Jim Pingle
02:17 PM pfSense Packages Bug #1110: libgd.so.4 => not found (0x0) - bandwidthd won't start
Hi,
i can confirm this issues. Running 'ldd /usr/local/bandwidthd/bandwidthd' as mentioned in Issue 1033 show a mi...
Thomas Scholten
06:56 PM Revision 979c5783: Make $rel lowercase, since that's how it is on FreeBSD's package servers.
Jim Pingle
03:12 PM Revision 9c4c5e80: If the IP stays the same, still resync VPNs if it's a PPP type interface.
Jim Pingle
03:12 PM Revision ebbae443: Move these back, it may not play nice with DHCP renews
Jim Pingle
02:57 PM Revision b7c38b2e: Move IPsec up too, it should always resync.
Jim Pingle
02:55 PM Revision 4d3367b1: OpenVPN needs resync even if the IP did not change, because the IP may have disappeared and caused it to exit.
Jim Pingle
02:38 PM pfSense Packages Bug #1114 (Resolved): Snort Dashboard Widget has wrong link
When activating the Dashboard Widget for snort and clicking the widget title '' it leads to the url https://snort/sno... Thomas Scholten
02:29 PM Feature #1113: WAN Interfaces with the same Gateway
that's not a viable solution for the same reasons it doesn't work without having a jail, and it's extremely ugly. it'... Chris Buechler
02:15 PM Feature #1113: WAN Interfaces with the same Gateway
excuse, but my proposal is not the duplicate of the problem, what is part of the system, it is a way for the solution... Falk Nisius
01:58 PM Feature #1113 (Rejected): WAN Interfaces with the same Gateway
duplicate of #228. please look at the open features before opening one. Chris Buechler
01:55 PM Feature #1113 (Rejected): WAN Interfaces with the same Gateway
if someone has two Cablemodems from the same provider and get via DHCP different IP-Adresses, but the same gateway, t... Falk Nisius
01:56 PM pfSense Packages Bug #1091 (Closed): snort - mysql package installation fails
Duplicate of #1080 Jim Pingle
01:52 PM pfSense Packages Bug #1091: snort - mysql package installation fails
Think this is a duplicate to Bug #1080 which i just updated a few seconds ago Thomas Scholten
01:54 PM pfSense Packages Bug #668: Snort does not deinstall properly
just for the record. I just did a deinstall / install for another ticket and had no issues with deinstalling.
(updat...
Thomas Scholten
01:51 PM pfSense Packages Bug #1080: Snort Installation fails
Thx to Dienis this helps intalling snort package, but i also experienced this error. AFAICS it depends on the url's u... Thomas Scholten
12:47 PM Bug #1111: SIGTERM to syslogd after enabling Remote syslog'ing
I confirm this bug. Alexander Kalashnikov
06:51 AM Bug #1111 (Resolved): SIGTERM to syslogd after enabling Remote syslog'ing
In Status->System Logs->Settings
When enabling "Enable syslog'ing to remote syslog server"
syslogd gets terminat...
Mykolas Norvaišas
12:42 PM Feature #1103 (Resolved): Wake-on-Lan Widget for Dashboard (with code)
If it tested ok, I'll go ahead and close the ticket out.
Thanks for the contribution!
Jim Pingle
12:35 PM Feature #1103: Wake-on-Lan Widget for Dashboard (with code)
It looks like it is working in "2.0-BETA4 (i386) - Thu Dec 16 04:59:28 EST 2010"
I tested display with 1, 2, and 3 e...
Yehuda Katz
10:32 AM Bug #1112 (Resolved): IPsec GUI/backend missing RADIUS support
The User and Group choices for User Authentication in the IPsec Mobile GUI are hardcoded to only show "System" and no... Jim Pingle
09:39 AM Bug #1102: Captive Portal does not work after upgrade
Yes, that update should no longer contain the patch in question. So it may not be related to that one after all. Jim Pingle
09:37 AM Bug #1102: Captive Portal does not work after upgrade

Tested pfSense-Full-Update-2.0-BETA4-20101216-0237.tgz : no redirection... :(
Does this update include the (anti...
Thomas NOEL
03:21 AM Bug #1096: pf TSO patch fallout - squid (and potentially other) issues
Updated to:
2.0-BETA4 (i386)
built on Wed Dec 15 20:50:23 EST 2010
Seems to work fine so far.
Maciej Kazulak
12:19 AM Revision 451e4a05: Fix condition that needed to be negated after a recent layout change here and prevent a PHP warning if there are no voucher rolls. Fixes #1106
Erik Fonnesbeck

12/15/2010

10:43 PM Bug #1093: Problems with em(4)
Arrggghhh!! Problem came back. page fault related to the intel nic. Shannon McMahon
09:32 PM Bug #1093: Problems with em(4)
I just reinstalled the Intel GB NIC. Loaded a build earlier today, and then just upgraded the build this evening. Al... Shannon McMahon
10:20 PM Feature #385: Allow the use of Captive Portal to restrict services on the firewall itself.
I just brought this up on the forum this week (http://forum.pfsense.org/index.php/topic,31079.0.html)
Regular user...
Yehuda Katz
08:05 PM Bug #1102: Captive Portal does not work after upgrade
What was new at that time is the patch that was backed out of the firmware updates I built above, and it will also be... Jim Pingle
07:57 PM Bug #1102: Captive Portal does not work after upgrade
Thomas NOEL wrote:
> Thomas NOEL wrote:
> > the captive portal works with pfSense-Full-Update-2.0-BETA4-20101201-2...
Thomas NOEL
02:17 PM Bug #1102: Captive Portal does not work after upgrade
Thomas NOEL wrote:
> the captive portal works with pfSense-Full-Update-2.0-BETA4-20101201-2252.tgz
works with pf...
Thomas NOEL
01:37 PM Bug #1102: Captive Portal does not work after upgrade
Thomas NOEL wrote:
> However, I tested this firmware (...)
Just for information : the captive portal works with ...
Thomas NOEL
12:35 PM Bug #1102: Captive Portal does not work after upgrade
Olé,
Jim P wrote:
> (...) It would help us narrow down the problem if you
> could test with the appropriate firm...
Thomas NOEL
11:07 AM Bug #1102: Captive Portal does not work after upgrade
As a test, I have built a custom firmware image without the TSO patch that Chris mentioned. It would help us narrow d... Jim Pingle
10:56 AM Bug #1102: Captive Portal does not work after upgrade
Hello, the probleme is present for me too with build on : built on Tue Dec 14 05:32:26 EST 2010
and the probleme is ...
gerard grazzini
06:20 AM Bug #1102: Captive Portal does not work after upgrade
Same here happened on snapshot 14December, 13 December, 8December.
So now I'm using December 1 snapshot.
Life Form
07:25 PM Bug #1106 (Feedback): Error in boot process
Applied in changeset commit:"451e4a05edd8f1a65dde0e32f7d6015c3c20cfcb". Erik Fonnesbeck
07:10 PM Bug #1106: Error in boot process
I found that there was a change yesterday that unintentionally made it so that code would run when vouchers are disab... Erik Fonnesbeck
06:39 PM Bug #1106: Error in boot process
Erik Fonnesbeck wrote:
> Looking at the source code, it looks like that probably means you don't have any voucher ro...
Yehuda Katz
06:33 PM Bug #1106: Error in boot process
Looking at the source code, it looks like that probably means you don't have any voucher rolls yet. However, this is... Erik Fonnesbeck
01:20 PM Bug #1106 (Resolved): Error in boot process
I am not sure how important this is, but I saw this error flash by during boot:
Enabling voucher support...
Warni...
Yehuda Katz
05:07 PM pfSense Packages Bug #1110 (Resolved): libgd.so.4 => not found (0x0) - bandwidthd won't start
I did everything mentioned in http://redmine.pfsense.org/issues/1033. I'm running latest 2.0 firmware. Here's what I ... John Smith
04:57 PM Feature #1109 (Duplicate): Allow prepending exception entries to SPD
I'm using pfsense 2.0 at a remote office, with an IPSEC site-to-site tunnel. Let's say that we have lots of sites, s... Bill Fenner
03:55 PM Bug #1096: pf TSO patch fallout - squid (and potentially other) issues
I disabled the patch and have a new snapshot building now. The next new snapshot dated after this update should be OK. Jim Pingle
03:35 PM Revision 254ac496: Add contributed WOL widget. Resolves #1103
Jim Pingle
01:53 PM Bug #1107 (Resolved): mpd on AMD64 generates invalid checksums with NAT
The issue is that I think that the checksum for some reason is calculated wrong or byte swapped when routing (with NA... Andreas Winge
12:21 PM Feature #1099: pptp does not use User Manager
It has already been changed to reflect that. Jim Pingle
12:11 PM Feature #1099: pptp does not use User Manager
Then can the doc wiki be changed to say that this is not the case until the feature works?
Thanks.
Moshe Katz
10:40 AM Feature #1103 (Feedback): Wake-on-Lan Widget for Dashboard (with code)
Applied in changeset commit:"254ac496401b2259a17dc2deee1fa19f963d89c6". Jim Pingle
09:57 AM Bug #1105 (Closed): WLAN Broadcom BCM 4306 problems -the fw file(bwn_v4_ucode5) not found
I'm using Broadcom BCM4306 802.11b/g Wireless in my pfSense 2.0 BETA 4 full.
(kernel: FreeBSD 8.1-RELEASE-p2 #1: Tue...
Luka Birsa
08:09 AM Feature #1104 (Closed): mwl driver patch to enable generation of new BSSIDs for additional VAPs
The current version of the mwl driver we are using has something that is disabling the code that generates new BSSIDs... Erik Fonnesbeck
04:22 AM Revision a5e64ca0: Remove config lock for filter reload, since no config file reads or writes are happening here. Ticket #1071
Erik Fonnesbeck
03:47 AM Revision fb548cde: No need to use escapeshellcmd here.
Scott Ullrich
02:31 AM Bug #1090: clean up interfaces mess in setup wizard
It is assumed that the port for your WAN connection is already assigned to WAN before the setup wizard is even starte... Erik Fonnesbeck
01:56 AM Bug #1090: clean up interfaces mess in setup wizard
This is probably obvious, but the Setup Wizard will silently fail to create a valid PPPoE or PPTP link if the WAN is ... Marcus Brown
12:34 AM Bug #1090: clean up interfaces mess in setup wizard
As far as I could tell, it doesn't end up writing that to the config between those steps, but it would probably be be... Erik Fonnesbeck
02:20 AM Bug #1072: Issues with increased CARP VHID limits
In the patch file, I saw this change that commented out this line:... Erik Fonnesbeck

12/14/2010

11:43 PM Feature #1103: Wake-on-Lan Widget for Dashboard (with code)
Looks like it did not work again.
There is just one line missing from the end.
The last line should be:...
Yehuda Katz
11:41 PM Feature #1103: Wake-on-Lan Widget for Dashboard (with code)
Looks like I uploaded and old version of the php file... Yehuda Katz
11:40 PM Feature #1103 (Resolved): Wake-on-Lan Widget for Dashboard (with code)
This is a dashboard widget for quick access to Wake-on-Lan. Yehuda Katz
11:22 PM Bug #1102: Captive Portal does not work after upgrade
I'm almost certain this is a duplicate of #1096, which describes the actual cause, but will leave it open to make sur... Chris Buechler
10:07 PM Bug #1102 (Resolved): Captive Portal does not work after upgrade
I upgraded to the latest snapshot 14 December but it failed the captive portal
access.
Whenever I activate captiv...
Edan Pedragosa
11:03 PM Revision 622bd5e7: Ticket #1043. Check for '' and not for 'default' since this is the default value of the select.
Ermal LUÇI
10:59 PM Revision 1d164dd4: Provide a default value to the function for converting kb/Mb to coeficient for math.
Ermal LUÇI
10:48 PM Revision f5c05fcc: Make voucher xmlrpc error checking the same as others.
Ermal LUÇI
10:39 PM Revision 666bc4d1: Ticket #1087. Cleanup whitespace and also do not rely on having the db dirty flag set for backing up the dbs but always do this!
Ermal LUÇI
10:28 PM Bug #1101: Wake-on-Lan display issue
Ok, it is not quite that simple.
(I would not be surprised if there was already be a function that does this.)
if...
Yehuda Katz
09:35 PM Bug #1101: Wake-on-Lan display issue
It looks like a lot of my ticket got cut off.
if ($wolent['interface'] == "lan")
echo "LAN";
else
echo $confi...
Yehuda Katz
09:32 PM Bug #1101 (Resolved): Wake-on-Lan display issue
Even if you have renamed the LAN interface, the page still shows saved clients on interface LAN.
The fix is easy, re...
Yehuda Katz
10:27 PM Revision eaca40df: Cleanup of whitespace and use exclusive lock during reconfiguration of vouchers.
Ermal LUÇI
10:27 PM Revision c1f9a4df: Set default interval of syncing voucher db to config to 5 minutes instead of 300. Ticket #1087.
Ermal LUÇI
10:22 PM Revision d12003c9: Revert "Add voucher backup, configurable from Diagnostics > NanoBSD. Fixes #1087" - voucher db backup already existed under a different name. Ticket is still fixed, just by different code that was already there.
This reverts commit 0d89a2fcac3deea06bdc4a481bbdfae4f18b1ff8. Jim Pingle
10:21 PM Revision deeaf52c: Revert "Set execute bit on backup script" Not needed.
This reverts commit d3a217e5d9e615058652cff5881a216c1a91a8c0. Jim Pingle
10:13 PM Revision d3a217e5: Set execute bit on backup script
Jim Pingle
10:10 PM Revision 0d89a2fc: Add voucher backup, configurable from Diagnostics > NanoBSD. Fixes #1087
Jim Pingle
09:15 PM Revision 95ceb35b: No functional change just simple cleanup.
Ermal LUÇI
08:59 PM Revision 70ed5a6a: Use file_put_contents()
Scott Ullrich
08:57 PM Revision d98d2db3: Redirect to the installedinfo page after package installation giving the system a chance to refresh the menus and the final installation text
Scott Ullrich
08:35 PM Bug #1072: Issues with increased CARP VHID limits
According to packet dump
carp vhid=1
192.168.252.254 > 224.0.0.18: VRRPv2, Advertisement, vrid 1, prio 0, autht...
Alexander Kalashnikov
07:03 PM Bug #1072: Issues with increased CARP VHID limits
yes Chris Buechler
07:01 PM Bug #1072: Issues with increased CARP VHID limits
Does anyone looking into the issue with broken CARP? Alexander Kalashnikov
07:48 PM Bug #1030: Interface case change in apinger.conf needs reverted
Changed to uppercase you mean?
I guess the question is: Should it also be reverted to lowercase?
(I think it should...
Jeppe Oland
06:03 PM Bug #1030: Interface case change in apinger.conf needs reverted
Well that has changes since long time now.
It is more than 5-6 months it has changed!
Ermal Luçi
07:13 PM pfSense Packages Bug #1098 (Feedback): Squid Installation fail on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
Should be good now. Installs fine after a fresh package builder run. Jim Pingle
01:17 PM pfSense Packages Bug #1098: Squid Installation fail on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
Known issue, something in the nightly rebuild is clobbering it. There's a forum thread already started for it as well... Jim Pingle
12:36 PM pfSense Packages Bug #1098 (Resolved): Squid Installation fail on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
Squid 2.7.9 installation failed with following error on 2.0-BETA4 (amd64) built on Wed Dec 8 22:08:02 UTC 2010
perl...
Mukesh Patel
07:12 PM Bug #1043 (Resolved): Inadequate input validation on limiters with floating rules
thanks Chris Buechler
06:19 PM Bug #1043: Inadequate input validation on limiters with floating rules
No problem.
It's working now.
Thank you.
Alexander Kalashnikov
06:02 PM Bug #1043 (Feedback): Inadequate input validation on limiters with floating rules
Yeah, thank you for catching that wrong check. Ermal Luçi
06:27 PM pfSense Packages Feature #1100 (Resolved): Add additional ports to squid (includes patch)
Background:
People on our network use Citrix XenApp to connect to other locations.
Citrix XenApp uses TCP ports 149...
Yehuda Katz
06:25 PM Bug #1088: CARP sync broken
It seems like that is only a cosmetic issue.
After a configuration sync filter reload status file just remains unt...
Alexander Kalashnikov
05:55 PM Bug #1087: vouchers need to save to CF periodically
oh, yeah it has a save interval there, guessing that wasn't working previously. Needs testing. Chris Buechler
05:40 PM Bug #1087: vouchers need to save to CF periodically
Just test with a snapshot including all the changes.
Should be ok now.
Ermal Luçi
05:26 PM Bug #1087: vouchers need to save to CF periodically
I backed out the changes I made. This was already present under the voucher config, there is an interval that can be ... Jim Pingle
05:25 PM Bug #1087: vouchers need to save to CF periodically
Applied in changeset commit:"d12003c99517c25105673c557aebec7e3fa55dcb". Jim Pingle
05:15 PM Bug #1087 (Feedback): vouchers need to save to CF periodically
Applied in changeset commit:"0d89a2fcac3deea06bdc4a481bbdfae4f18b1ff8". Jim Pingle
05:42 PM Bug #1093 (Feedback): Problems with em(4)
New driver is on new snapshots now. Ermal Luçi
05:38 PM Revision 74b7361f: Backend support for the retry parameter.
Jim Pingle
05:19 PM Revision 7a517ee4: Add a retry field to the LB Pool config to allow specifying how many times to retry a server before declaring it dead.
Jim Pingle
05:06 PM Revision ece25730: Replace the LB status widget completely with one that supports the current LB system.
Jim Pingle
03:42 PM Revision a776c720: Move some lb status parsing functions to a common area so they can be reused by the widget.
Jim Pingle
03:01 PM Revision 5ca559d2: Use a slightly different regex to catch all non-whitespace characters here instead of the current method. Fixes #1085
Jim Pingle
02:45 PM Feature #1099 (Closed): pptp does not use User Manager
In the wiki (http://doc.pfsense.org/index.php/PPTP_VPN_Settings and http://doc.pfsense.org/index.php/User_Manager) it... Moshe Katz
01:47 PM Bug #1079 (Feedback): Load balancer widget doesn't work on 2.0
Should be fixed on new snaps. I completely rewrote it to use data from the new load balancer setup. Jim Pingle
01:46 PM Revision 7bc5c543: For bsnmpd, checking hostres also requires checking mibii. Note this requirement in the GUI and enforce it via a simple JS check.
Jim Pingle
01:21 PM Revision 841c4125: Remove dropdown to select interface. Should fix #1090
Marcus Brown
12:34 PM Bug #1081 (New): traffic shaper wizard loops endless back to VOIP-settings
Chris Buechler
04:29 AM Bug #1081: traffic shaper wizard loops endless back to VOIP-settings
Ermal Luçi wrote:
> Fixed in latest snaps.
As of today with snap (i386) built on Mon Dec 13 21:32:21 EST its stil...
igor igor
12:03 PM Revision d299e102: Merge remote branch 'mainline/master'
Conflicts:
usr/local/www/fbegin.inc
Vinicius Coque
11:56 AM Revision c92ccac7: Merge remote branch 'mainline/master' into inc
Conflicts:
etc/inc/auth.inc
etc/inc/config.lib.inc
etc/inc/filter.inc
etc/inc/gwlb.in...
Vinicius Coque
10:05 AM Bug #1085 (Feedback): Status: Load Balancer: Virtual Server fails to display a correct status for «some» "virtual server" names
Applied in changeset commit:"5ca559d227855d9293a1d194e6981b8275e043ae". Jim Pingle
09:19 AM Bug #1096: pf TSO patch fallout - squid (and potentially other) issues
Same issue here.
Performed an auto update today. Installed squid. Normal proxy works ok, transparent does not. Fro...
Maciej Kazulak
08:37 AM Bug #757: PPPoE Disconnect button with multiple PPPoE interfaces
FYI, this behavior and surrounding trouble about the disconnect button is because one user felt that if the "disconne... Marcus Brown
08:28 AM Bug #1090: clean up interfaces mess in setup wizard
Committed the removal of the dropdown interfaces select box.
About the temp variable, I couldn't really figure out...
Marcus Brown
08:25 AM Bug #1090 (Feedback): clean up interfaces mess in setup wizard
Applied in changeset commit:"841c4125a6b4488c16a0c69e7642779f294fa449". Marcus Brown

12/13/2010

10:04 PM Revision d2cba83b: A few help page updates
Jim Pingle
09:37 PM Bug #1043: Inadequate input validation on limiters with floating rules
It seems like the issue is still present but only for gateways check since the $_POST['gateway'] contains an empty st... Alexander Kalashnikov
09:01 PM Bug #1043: Inadequate input validation on limiters with floating rules
Sure I can read code and any text since I've read your response and writing an answer here.
I'm sorry for that I've ...
Alexander Kalashnikov
05:07 PM Bug #1043: Inadequate input validation on limiters with floating rules
Hah it seems you cannot read code!
That code is correct!
Ermal Luçi
09:18 PM Revision 26732357: Ticket #960. Use XMLRPC automatic base64 encoding for strings (XML_RPC_auto_base64)
Pierre POMES
04:18 PM Bug #960 (Feedback): Problem with config sync + ipsec + special characters
Hi Thiago,
This problem should be solved now. Can you try again ?
Thanks !
Pierre
Pierre POMES
11:47 AM Bug #960: Problem with config sync + ipsec + special characters
Other information:
1) In the GUI, I used "CARP LAN éé" as description
2) config.xml shows :...
Pierre POMES
11:21 AM Bug #960: Problem with config sync + ipsec + special characters
Hi,
This also happens for other descriptions, I tested for a carp VIP description and the problem is the same (als...
Pierre POMES
02:26 PM Bug #1097: Onload Javascript on Rules page of management GUI
I ask because I've been on several systems with a lot of rules and never seen anything like you describe, and figured... Chris Buechler
02:22 PM Bug #1097: Onload Javascript on Rules page of management GUI
You've got me a bit worried with that question?!
I cannot get the 2.0-BETA4 GUI to even load in IE7, on any machine,...
dasanco dasanco
12:38 PM Bug #1097: Onload Javascript on Rules page of management GUI
You seeing this in IE? Chris Buechler
12:32 PM Bug #1097 (Closed): Onload Javascript on Rules page of management GUI
I attempted to install and run a test bed running 2.0-BETA4.
I proceeded to import existing rules from a live 1.2.3 ...
dasanco dasanco
02:44 AM pfSense Packages Bug #1094: Clicking pfSense logo start deinstall/reinstall of HAVP package
It is possible to repeat again? Serg Dvoriancev

12/12/2010

11:53 PM Bug #1096 (Resolved): pf TSO patch fallout - squid (and potentially other) issues
With commit:c57f939b20a6a7a66351ce973843ce7d8564ed72 ( https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/... Jim Pingle
11:49 PM Revision c9b08a50: Show the full URL used to download package files, to aid in tracking down packages that do not install correctly.
Jim Pingle
07:32 PM Bug #1093: Problems with em(4)
FYI: Let me know when you change the driver. I can throw the Intel NIC back in and test at that point. Shannon McMahon
07:31 PM Bug #1093: Problems with em(4)
Ah, interesting. I assumed it was the BSD 8 default driver.
Shannon McMahon
07:29 PM Bug #1093: Problems with em(4)
Thanks for confirming, it is a pfSense issue though as we changed the driver, need to change back to what we had prev... Chris Buechler
07:17 PM Bug #1093: Problems with em(4)
I think your hunch was on the money. I looked into known issues with em(4), and subsequently yanked the dual GB Inte... Shannon McMahon
01:39 AM Bug #1093 (New): Problems with em(4)
this sounds like the same thing I hit last night on em(4) as well, any traffic initiated by or destined to the host i... Chris Buechler
01:12 AM Bug #1093: Problems with em(4)
I just updated to the latest build. I then initiated an install of squid as an example. shortly after starting the ... Shannon McMahon
12:48 AM Bug #1093 (Feedback): Problems with em(4)
Needs a lot more detail.
I'm running snapshots later than that on amd64 and they do not crash. We need at the ver...
Jim Pingle
12:45 AM Bug #1093 (Resolved): Problems with em(4)
Some time after Dec 2, something has changed in the build. Now, when I attempt to upgrade to newer builds, or instal... Shannon McMahon
05:44 PM pfSense Packages Bug #1094: Clicking pfSense logo start deinstall/reinstall of HAVP package
If you did this after a firmware update, the flag file that tells the GUI it needs to reinstall all packages may stil... Jim Pingle
05:20 PM pfSense Packages Bug #1094: Clicking pfSense logo start deinstall/reinstall of HAVP package
That should say 'logo' but I don't think I can edit the title. Lars Hupfeldt Nielsen
05:15 PM pfSense Packages Bug #1094 (Resolved): Clicking pfSense logo start deinstall/reinstall of HAVP package
Hi, after installation of HAVP, when still on the package installation page, click the pfSense logo and an immediate ... Lars Hupfeldt Nielsen
05:39 PM pfSense Packages Bug #1095 (Rejected): HAVP attempts to write to readonly file system
Duplicate of #679. Please don't open new tickets if there is an existing ticket for the same issue. Put the full text... Jim Pingle
05:22 PM pfSense Packages Bug #1095 (Rejected): HAVP attempts to write to readonly file system
Error message shown in browse:
-----
Warning: file_put_contents(/usr/local/etc/havp/havp_conf.xml): failed to open ...
Lars Hupfeldt Nielsen
05:37 PM pfSense Packages Bug #679 (New): HAVP error message shows up behind top menu.
Jim Pingle
05:03 PM pfSense Packages Bug #679: HAVP error message shows up behind top menu.
Hi, the problem persists, see attached image.
----
Version 2.0-BETA4 (i386)
built on Sat Dec 11 21:35:41 EST 20...
Lars Hupfeldt Nielsen
03:31 PM Revision 96b4c29a: Ticket 1041. Fix bad commit...
Pierre POMES
06:52 AM Bug #1072: Issues with increased CARP VHID limits
Understood.
So the pfSense is not compatible with *BSD.
And I understood why CARP is broken now.
Alexander Kalashnikov
05:17 AM Bug #1092 (Closed): Changing NAT Port forward port setting not applied to firewall rule
I've tested every possible scenario here and they all work. Chris Buechler
05:14 AM Bug #1092: Changing NAT Port forward port setting not applied to firewall rule
Correct the associated filter rule. Just tried to replicate but couldn't. I must have missed the apply button or look... Perry Mason
02:45 AM Bug #1092: Changing NAT Port forward port setting not applied to firewall rule
with a linked rule you mean? Chris Buechler
01:04 AM Bug #1043 (New): Inadequate input validation on limiters with floating rules
Chris Buechler

12/11/2010

08:31 PM Revision 00752d5a: Ticket #959. Keep local items at the top of vip section
Pierre POMES
07:39 PM Bug #1030: Interface case change in apinger.conf needs reverted
For me, the quality graph was always the offending one. Jeppe Oland
07:38 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Any ideas on this one? Jeppe Oland
03:34 PM Bug #959: Config sync removes alias VIPs on the slave
Hi Thiago,
I finally added your suggestion, everything is ok on my pair of boxes
Revision 00752d5a82baea1f05c8d...
Pierre POMES
11:51 AM Bug #1092 (Closed): Changing NAT Port forward port setting not applied to firewall rule
Was changing sip to alias with 5060 and 16300:16700 Perry Mason
10:36 AM Bug #1072: Issues with increased CARP VHID limits
We have a patch in the builds which expands the field to two bytes. Jim Pingle
05:59 AM Bug #1072: Issues with increased CARP VHID limits
vhid field in CARP packet is one byte long, so this GUI change does not make any sense. Alexander Kalashnikov
07:41 AM Bug #1088: CARP sync broken
I'm not sure fixed it or not, because after a configuration sync "Filter reload status" just hangs on "Syncing CARP d... Alexander Kalashnikov
06:29 AM Bug #1043: Inadequate input validation on limiters with floating rules
The same needs to be done in:
&& $_POST['gateway'] != "default" && (empty($_POST['direction']) || $_POST['directio...
Alexander Kalashnikov
06:14 AM Bug #1043: Inadequate input validation on limiters with floating rules
Unfortunatelly it's not fixed.
Problem is in program logic:
http://redmine.pfsense.org/projects/pfsense/repositor...
Alexander Kalashnikov
01:42 AM Revision 25f6730a: Add IPSec 'ipalias' VIP support. Ticket #1041
Pierre POMES
12:01 AM pfSense Packages Bug #1091 (Closed): snort - mysql package installation fails
The snort package fails to install due to not being able to download mysql-client-5.1.53 after upgrade to "2.0-BETA4 ... Tom Bauer

12/10/2010

11:44 PM Revision 2c6b0d67: Call a filter reload even though the ip might not have changed. This makes the gateway pools work after an interface comes up again.
Ermal LUÇI
11:26 PM Revision 6d8ff5e9: Hard code maxlockouts to 15 until GUI portion is ready
Scott Ullrich
10:51 PM Revision ca092d26: Correct error messages.
Ermal LUÇI
10:47 PM Revision 37d202a3: Do not allow gateways to be selected without a direction.
Ermal LUÇI
09:53 PM Revision 65f7fba8: Correct webConfgurator auth/error messages
Scott Ullrich
09:38 PM Revision 20699f3f: Some IPsec mobile changes to inch a little closer to working L2TP+IPsec. Ticket #475
Jim Pingle
09:02 PM Revision 3aba1835: Add log_auth() which with send items to syslogd using LOG_AUTH facilities. Use this new log_authh() for login error and success entries
Scott Ullrich
08:50 PM Bug #1041 (Feedback): IP Alias VIPs are not available for use by IPsec
VIP aliases should now work with ipsec. Pierre POMES
08:24 PM Revision 6735d092: Allow floating rules without direction to be created again.
Ermal LUÇI
07:38 PM Revision d0f980d4: Log on the host the errors so we can use the sshlockout software for protection against abusal.
Ermal LUÇI
07:35 PM Revision 4d775dd0: Be consistent on shifting array during authentication. Also check for array to avoid strange errors.
Ermal LUÇI
07:13 PM Revision 602cb4b0: Leave a notice for this as well.
Ermal LUÇI
07:10 PM Revision 52a93b82: If we fail to authenticate consider it as fatal since nothing else can be done.
Ermal LUÇI
07:04 PM Revision a79c72d7: Actually the passed config sections are part of index 1 of the array. This fixes config sync of vips as well.
Ermal LUÇI
06:55 PM Revision 9e18b392: Do not call rc.newwanip on bootup. Remove bogus return 0;
Scott Ullrich
06:53 PM Revision d1265444: Start relayd after routing has been started.
Ermal LUÇI
06:43 PM Revision 9132ae35: Do not spam logs uselessly on bootup and sleep a bit before starting apinger.
Ermal LUÇI
06:34 PM Revision 0567899d: Fix config synchronization. Also unbreak the config when erroring out because it will loop indefinitely.
Ermal LUÇI
03:42 PM Bug #1090 (Resolved): clean up interfaces mess in setup wizard
Revision 389c778ec29d929a17843139f8cddf337b8fa9ad by gnhb added an interface drop down to the WAN configuration page ... Chris Buechler
03:23 PM Bug #1043 (Feedback): Inadequate input validation on limiters with floating rules
I fixed even the regression caused by fixing the limiters.
Test it with latest snapshots.
Ermal Luçi
11:18 AM Bug #1043: Inadequate input validation on limiters with floating rules
this particular issue isn't a problem, but yeah the fix broke other things. Chris Buechler
11:17 AM Bug #1043: Inadequate input validation on limiters with floating rules
Whoops, didn't see the comment by Alexander when I posted.
I can confirm the bug he reported, setting direction t...
Josh Stompro
11:14 AM Bug #1043: Inadequate input validation on limiters with floating rules
Tested on 2.0-beta4 (i386) Dec 10 02:17:09:EST 2010
When I tried to add a limiter (In/Out, which is not a very des...
Josh Stompro
10:06 AM Bug #1043 (New): Inadequate input validation on limiters with floating rules
Chris Buechler
09:52 AM Bug #1043: Inadequate input validation on limiters with floating rules
This fix led to that every rule in Floating tab MUST contain a direction.
So now it's unable to create there a rule ...
Alexander Kalashnikov
02:37 PM Bug #1088: CARP sync broken
Ok should be better than before on latest snapshot.
Be careful to have all the related commits.
Ermal Luçi
06:42 AM Bug #1088: CARP sync broken
Still broken.
Dec 10 13:41:43 php: : The other member is on older version of . Sync will not be done to prevent p...
Alexander Kalashnikov
03:25 AM Bug #1088: CARP sync broken
Will check in 5 hrs.
Current snapshots has been compiled with an old code.
Alexander Kalashnikov
12:13 PM pfSense Packages Bug #679 (Closed): HAVP error message shows up behind top menu.
Sounds good. Closing for now unless someone can reconfirm it with modern versions. Jim Pingle
12:01 PM pfSense Packages Bug #679: HAVP error message shows up behind top menu.
In my opinion this is should be closed. There have been changes in the code, solve the this problem. Serg Dvoriancev
11:00 AM pfSense Packages Bug #979 (Resolved): Broken LightSquid installation on 2.0 amd64
Jim Pingle
10:57 AM pfSense Packages Bug #979: Broken LightSquid installation on 2.0 amd64
Works. Thank you. Alexander Kalashnikov
01:18 AM Revision 4ecc2263: Hmmm use correct keys to returned array.
Ermal LUÇI
01:02 AM Revision bb92b70f: Actually pass the right parameter!
Ermal LUÇI
12:53 AM Revision 01b1cc6a: Fix line because of copy/pasto.
Ermal LUÇI
12:51 AM Revision 728719dd: Its too late and this is optional.
Ermal LUÇI
12:44 AM Revision de272dac: Just the password here.
Ermal LUÇI
12:34 AM Revision 18be996d: Actually we expect an array to be returned.
Ermal LUÇI
12:19 AM Revision e501de37: Hello xmlrpc to another function!
Ermal LUÇI

12/09/2010

08:42 PM Revision 68ef6e03: Teach convert_friendly_interface_to_friendly_descr about carp vips. This helps cases like Ticket #1086.
Ermal LUÇI
08:33 PM Revision 8c3450c7: Make this at least right though it might not be correct.
Ermal LUÇI
07:44 PM Revision 89428f03: Use correct variable name so the message is actually displayed.
Ermal LUÇI
07:18 PM Bug #1088 (Feedback): CARP sync broken
Check new snapshots. Ermal Luçi
03:36 PM Bug #1088 (Resolved): CARP sync broken
After http://redmine.pfsense.org/projects/pfsense/repository/revisions/7380bcdbe4be18bcb007f283b71fd5f83b51fced revis... Alexander Kalashnikov
07:03 PM Revision ec3e48f1: Remove \n here, it was being printed on the console. Echo should do the right thing and print a newline at the end on its own.
Jim Pingle
05:18 PM Revision 76bbcff0: make rebrand-friendly
Chris Buechler
05:10 PM Bug #1083: aliases cause error when creating NAT 1:1 rules
just need to remove alias capabilities from 1:1 NAT for now (it's not valid syntax in PF, though it's simply user spa... Chris Buechler
04:55 PM pfSense Packages Bug #1089 (Rejected): Carp and SYNC broken after upgrade to latest snapshot
Duplicate of #1088 Jim Pingle
04:51 PM pfSense Packages Bug #1089 (Rejected): Carp and SYNC broken after upgrade to latest snapshot
After upgrade to latest snapshot the sync was stoped.
Dec 9 17:53:20 hsfw-1 check_reload_status: syncing firewall...
Francisco Brasileiro
03:43 PM Feature #1086: [patch] CARP IPs as outer source addressed for GRE and GIF tunnels
Should be ok in new snapshots.
The method used is different.
Ermal Luçi
10:56 AM Feature #1086: [patch] CARP IPs as outer source addressed for GRE and GIF tunnels
Forgot to add the patch to visualise CARP IPs/Parent Interfaces in the GRE/GIF interfaces summary... Fulvio Scapin
08:31 AM Feature #1086 (Feedback): [patch] CARP IPs as outer source addressed for GRE and GIF tunnels
https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/11decf6ef66b329df6bd0e39ccfc57134c46d8d8
Thanks.
Ermal Luçi
08:20 AM Feature #1086 (Resolved): [patch] CARP IPs as outer source addressed for GRE and GIF tunnels
I applied the code from the ipsec/openvpn interface lists to include CARP VIP interfaces as outer source addresses fo... Fulvio Scapin
02:25 PM Revision 11decf6e: Show carp on the list of interfaces to be used for creating gif/gre tunnels.
Ermal LUÇI
02:24 PM Revision f1a93dee: Use the array index for this.
Ermal LUÇI
01:30 PM pfSense Packages Bug #1084 (Resolved): nmap package libpcap errors
Thanks for testing Jim Pingle
01:30 PM pfSense Packages Bug #1084: nmap package libpcap errors
Updated to latest snapshot and it's working now. Karsten leone
08:42 AM Bug #1087 (Resolved): vouchers need to save to CF periodically
Vouchers need to save to CF periodically the same as we have options for RRD and DHCP leases to avoid losing usage in... Chris Buechler
06:32 AM Bug #1085 (Resolved): Status: Load Balancer: Virtual Server fails to display a correct status for «some» "virtual server" names
I've noticed how inserting characters like «-» in a virtual server name breaks the regex match on the output of «rela... Fulvio Scapin
05:44 AM Revision 71809626: If available, display source IP's CIDR mask on external IP as well.
Erik Fonnesbeck
05:12 AM Revision 35aa4df3: This code must come after natent is defined or the style will never be applied. Ticket #1073
Erik Fonnesbeck
04:23 AM Feature #13: wireless page to have option to select transmit and receive antennas
on latest snap, 9th dec, i have set diversity to 1 as i have connected antennas on both connectors and set the tx and... Bipin Chandra

12/08/2010

09:51 PM Revision 1634524d: Fix field descriptions on input validation for LAGG edit.
Erik Fonnesbeck
06:45 PM Revision 4f76b144: Get rid of fastforwarding since it is not maintained from long time. Courtesy-of: battlez_ IRC
Ermal LUÇI
06:04 PM Revision 8ab82dec: Only print "sainfo anonymous" also for xauth-psk setups. See http://forum.pfsense.org/index.php/topic,29164.msg157864.html#msg157864
Jim Pingle
05:57 PM Revision 409dc2e1: Actually we do not use this code at all in pfSense.
Ermal LUÇI
05:55 PM Revision 6cf1cc61: Do not overrite the default gateway if already found.
Ermal LUÇI
05:52 PM pfSense Packages Bug #1084: nmap package libpcap errors
That issue has been fixed in HEAD since yesterday but a new snapshot hasn't uploaded yet. When a new snapshot is uplo... Jim Pingle
05:51 PM pfSense Packages Bug #1084: nmap package libpcap errors
That fixed the libpcap errors. It still goes to the dashboard page when I select Diagnostics -> NMap. Karsten leone
01:42 PM pfSense Packages Bug #1084 (Feedback): nmap package libpcap errors
I fixed some dependency issues, recompiled, and reuploaded nmap. Installs and runs fine for me now. Jim Pingle
01:09 PM pfSense Packages Bug #1084 (Resolved): nmap package libpcap errors
I installed the nmap package and when I go to Diagnostics -> NMap, I'm redirected to the dashboard page. When I run ... Karsten leone
03:45 PM Revision 20e18ef2: Properly test for ldap case when clicking save and test for GUI authserver.
Ermal LUÇI
10:00 AM Bug #845 (New): Need patch for PR usb/140883
Apparently a better version of this driver was posted to fix some bugs:
http://svn.freebsd.org/viewvc/base?view=re...
Jim Pingle
05:10 AM Bug #1039 (Resolved): Error on Syncronisation slave - DIOCADDRULE: Device busy
thanks Chris Buechler
05:10 AM Bug #1039: Error on Syncronisation slave - DIOCADDRULE: Device busy
On the Dec 7 snapshot
the problem seems to be fixed.
Thank You
Martin Klein

12/07/2010

11:59 PM Revision 2a834dcd: Adjust even advbase while synching. This should be params though.
Ermal LUÇI
11:51 PM Revision 6f247d1f: Expose advbase option of carp(4) to alleviate advanced configs.
Ermal LUÇI
08:30 PM Revision a00fc1e2: Do not atempt to start a service during installation.
Ermal LUÇI
08:08 PM Revision afa966a5: Ticket #1081. Fix header() function to do correct redirection. Also remove bogus step9 in the wizards.
Ermal LUÇI
06:32 PM Revision c5901d28: Use full path to binary and silence errors if any on unlink.
Ermal LUÇI
06:25 PM Revision 422bc2a7: Move all dynamic dns update processes under the same even 'reload dyndns' since it makes sense to do so.
Ermal LUÇI
06:13 PM Revision 8c41a3e4: Do the filter reload before vpn and some other services which get impacted or impact filter reload. Let alone that they do not impact filter reload at all.
Ermal LUÇI
04:59 PM Bug #1083 (Resolved): aliases cause error when creating NAT 1:1 rules
I can create 1:1 NAT rules using IP Addresses, for instance entering 192.168.1.3 as a source IP.
Creating an alias w...
Ryan Perkins
04:34 PM Revision 5a61331a: Move this validation down so we can still assume id=0 if it's not present, and then redirect if it's non-numeric.
Jim Pingle
03:42 PM Bug #1082 (Rejected): Proxy server: Cache management : Do not cache ne fonctionne pas
Please use the forum for this issue. It's not a bug in the GUI, but something that needs fixed in your config.xml - T... Jim Pingle
03:39 PM Bug #1082 (Rejected): Proxy server: Cache management : Do not cache ne fonctionne pas
Bonjour,
Je dois mettre certain site dans le "Do not cache" afin que ceux si ne passe pas par le proxy, surtout pa...
Franck LUDJET
03:32 PM Feature #811 (Resolved): PPTP/GRE NAT multiple connections to single server
Ermal Luçi
02:09 PM Feature #811: PPTP/GRE NAT multiple connections to single server
working for me under
2.0-BETA4 (i386) built on Sat Dec 4 01:44:52 EST 2010
Michel Samovojski
03:09 PM Bug #1039: Error on Syncronisation slave - DIOCADDRULE: Device busy
Please update to newer snapshots.
This should be fixed now.
Ermal Luçi
03:08 PM Bug #833 (Resolved): route-to for firewall-initiated traffic stops functioning when default gateway unreachable
Ermal Luçi
03:07 PM Bug #1081 (Feedback): traffic shaper wizard loops endless back to VOIP-settings
Fixed in latest snaps. Ermal Luçi
11:00 AM Bug #1081 (Resolved): traffic shaper wizard loops endless back to VOIP-settings
Every traffic shaper wizard loops endless back to VOIP-settings. Respective forum-entry:
http://forum.pfsense.org/...
igor igor
12:34 PM pfSense Packages Bug #1080: Snort Installation fails
Workaround is
pkg_add -r http://files.pfsense.org/packages/8/All/mysql-client-5.1.53.tbz
from command line
than...
Dienis Rastegaeff
10:32 AM pfSense Packages Bug #1080 (Feedback): Snort Installation fails
Actually, this should be working either way, unless snort is pulling that from a non-standard URL. That file is prese... Jim Pingle
08:01 AM pfSense Packages Bug #1080: Snort Installation fails
We need more info. We especially need to know if you are using amd64 or i386. Jim Pingle
04:16 AM pfSense Packages Bug #1080 (New): Snort Installation fails
it's a legit issue that needs to be fixed, probably missing binaries since the package rebuilds. Chris Buechler
04:14 AM pfSense Packages Bug #1080 (Closed): Snort Installation fails
Please follow the forum for such things. Ermal Luçi
02:45 AM pfSense Packages Bug #1080: Snort Installation fails
It's about Snort package :) Dienis Rastegaeff
02:31 AM pfSense Packages Bug #1080 (Closed): Snort Installation fails
Error
mysql-client-5.1.53 could not download.
of mysql-client-5.1.53 failed!
Dienis Rastegaeff
12:30 PM Revision 7380bcdb: Prevent sync problems when upgrading carp clusters. Now we check that the other cluster is at least at our config file version.
Ermal LUÇI
11:32 AM Revision d064a115: Tighten checks a bit also when check_firmware_version is called return the config version too.
Ermal LUÇI
11:10 AM Revision 137f46d8: Whitespace fixes to make this readble.
Ermal LUÇI
10:56 AM Revision be888d7f: Add lem(4) to our drivers list.
Ermal LUÇI
04:36 AM Bug #636 (New): layer7 not work correctly
this is broken again. Chris Buechler
04:20 AM pfSense Packages Bug #901 (Closed): Squid "Don't filter for RFC1918" doesn't work for PPTP (patch included)
Ermal Luçi
04:20 AM pfSense Packages Bug #901: Squid "Don't filter for RFC1918" doesn't work for PPTP (patch included)
You can do this from theGUI on 2.0.
I will close this since it will not be fixed on 1.2.3 so near to 2.0 release.
Ermal Luçi
04:17 AM pfSense Packages Bug #844: Open VM Tools Won't install
Please try new snapshots since all pacakges have been recompiled. Ermal Luçi
04:16 AM pfSense Packages Bug #979 (Feedback): Broken LightSquid installation on 2.0 amd64
Please try the new snapshots. Ermal Luçi
04:15 AM pfSense Packages Bug #1024 (Closed): Snort GUI broken in latest snapshots
Should be fixed.
It was a issue of newer security features.
Ermal Luçi
01:26 AM Revision dd62256f: Fix vip descriptions in openvpn and ipsec screens. Ticket #1042
Pierre POMES

12/06/2010

11:58 PM Revision 8d5b8c20: it's 2010, update (C)
Scott Ullrich
11:43 PM Revision 2db9a6d6: Make menu drape across two columns saving around 10 lines of text making room for more interfaces at the top. Looks good: perry|dk & jim-p
Scott Ullrich
08:42 PM Revision b0c6a4f1: Remove unused binary from list
Ermal LUÇI
08:39 PM Revision 27ca29e4: cleanup other bogus code.
Ermal LUÇI
08:38 PM Revision 265c88c6: Remove bogus code and use proper function here.
Ermal LUÇI
08:35 PM Revision 3e5d0d1d: Actually honor the mtu/mac spoofing option in the interfaces.php page even while the type is set to other than dhcp/static/none. For this inhance the interface_translate_type_to_real to return the real hardware interface for ppp* types.
Ermal LUÇI
08:30 PM Bug #1042 (Feedback): CARP VIP Descriptions incorrect on IPsec/OpenVPN
Now VIP descriptions should look like in firewall/nat screens. Pierre POMES
08:16 PM Revision ef130e9f: Ticket #829. Allow the user to change from ppp* type to static or dhcp type interface from interfaces.php.
Ermal LUÇI
06:53 PM Revision 7afd6325: Modify dhclient-script to call rc.newwanip after all the changes to system have been done so races and no stale information can be extracted from the later.
Ermal LUÇI
06:16 PM Revision 6706a83a: Do the setting earlier to not miss any code and make ipsec not work.
Ermal LUÇI
04:42 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
The kernel option is similar to how we do PPTP or FTP today.
Just you have to be very intimate with the internals of...
Ermal Luçi
03:27 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Ermal,
I see in the source of pfctl that ioctl is the underlying mechanism being used to dynamically add rules to ...
Ken Leland
02:10 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
There are 2 other choices to do that.
1- kernel
2- state adding through ioctl
Ermal Luçi
11:16 AM Feature #1064: VoIP - Dynamic Pinholes for RTP
Ermal, I want to implement this myself along with 2 of my colleagues. The purpose of this ticket is to discuss the d... Ken Leland
05:33 AM Feature #1064: VoIP - Dynamic Pinholes for RTP
What i do not understand is if you want to implement this yourself or want pfSense help on it? Ermal Luçi
03:47 PM Revision dcadda55: Do not reload twice carp and vips in general during an interface reload.
Ermal LUÇI
03:35 PM Bug #829 (Feedback): WAN stays assigned to pppoe0 interface after switching type from PPPoE to Static
Ermal Luçi
03:25 PM Revision ed62880b: Correct code to reconfigure an interface for groups/gre/gif tunnels to take into account that an interface might be part of many instances of this. Also reconfigure interface groups for every newwanip trigger on interfaces to make sure dynamic interfaces retain their membership on groups.
Ermal LUÇI
02:11 PM Bug #962 (Resolved): DHCP custom options must have type selection
Thank you for testing. Ermal Luçi
10:49 AM Bug #962: DHCP custom options must have type selection
This fix/feature worked just fine with the Sun Dec 5th 07:23:23 EST 2010 nanobsd snapshot.
I added one option of e...
Josh Stompro
01:55 PM Bug #1074 (Closed): Monitor IP Gateway ignored
Remove these two stale entries from your config ... Ermal Luçi
07:24 AM Bug #1074: Monitor IP Gateway ignored
system log, full xml and apinger.conf posted Danny Bogaards
06:51 AM Bug #1074: Monitor IP Gateway ignored
I cannot reproduce this on latest snapshots.
Please post even your system log and your full config.xml otherwise thi...
Ermal Luçi
06:13 AM Bug #1074: Monitor IP Gateway ignored
Hereby I upload some screenshots. Danny Bogaards
05:53 AM Bug #1074: Monitor IP Gateway ignored
Can you please paste some screenshots here of your gateways? Ermal Luçi
03:11 AM Bug #1074 (Closed): Monitor IP Gateway ignored
If I set an alternative 'Monitor IP' for a gateway, this is ignored. Is +is+ stored in config.xml though!
config.x...
Danny Bogaards
12:58 PM Revision c9e13418: Ticket #491. Do not actually check for enable to exist but for host since enable might be unset explicitly by the user. This should re-enable configs to work.
Ermal LUÇI
12:29 PM Revision 81f4ab8a: Ticket #1073. Gray out the rules when they are disabled.
Ermal LUÇI
10:37 AM Revision 5e3a84e2: Use send_event since touch()'ing files does not work.
Ermal LUÇI
10:29 AM Revision e53e7a5d: Do not call filter_configure here the caller does. Also remove old code of the times when check_reload_status used files as trigers.
Ermal LUÇI
10:18 AM Revision baa16005: The caller of this function is responsible for this and usually all the callers do this from what i can tell. Remove redundant call.
Ermal LUÇI
10:12 AM Revision 757c1bcc: Make sure filter_configure() is not called during bootup since its harmful.
Ermal LUÇI
10:08 AM Revision 847cd48d: Do not spam filter reload at boot.
Ermal LUÇI
10:03 AM Revision 831a5ff7: No need to call filter_reload from here.
Ermal LUÇI
09:39 AM Revision af904a20: Silence this.
Ermal LUÇI
07:11 AM Bug #491 (Feedback): Dynamic DNS upgrade code not working
Ermal Luçi
06:55 AM Bug #1030: Interface case change in apinger.conf needs reverted
That is the gateway quality graph not the interfaces one :)
As far as i can tell the interface graphs all use the no...
Ermal Luçi
06:34 AM Bug #1073 (Feedback): Disabled 1:1 NAT entries need to be grayed out
Ermal Luçi
05:47 AM Bug #1078 (Rejected): ipsec tunnel stalled if peer ip is updated
again this needs to go to the forum or list first unless you can provide the appropriate level of detail to pinpoint ... Chris Buechler
05:12 AM Bug #1078 (Rejected): ipsec tunnel stalled if peer ip is updated
until restarting racoon Grischa Zengel
05:42 AM Bug #1077 (Rejected): Pfsense needs very long for booting
Please post details to the forum and someone can help you determine the actual problem, this isn't nearly specific en... Chris Buechler
04:46 AM Bug #1077 (Rejected): Pfsense needs very long for booting
after booting the system needs more than 10 minutes for init files.
2.0-BETA4 (i386) built on Sun Dec 5 06:21:36 E...
Grischa Zengel
05:32 AM Bug #1079 (Resolved): Load balancer widget doesn't work on 2.0
The load balancer dashboard widget on pfsense 2.0 doesn't work.
Further investigation suggests it's expecting data...
Gary Richards
04:40 AM Bug #1075 (Resolved): rrd graphs missing / duplicate
On the rrd page the first graph
(11 hours / 1 min avg) is shown twice
instead of the daily graph.
See included scr...
Martin Klein

12/05/2010

10:21 PM Bug #1073 (Resolved): Disabled 1:1 NAT entries need to be grayed out
Disabled 1:1 NAT entries need to be grayed out like disabled firewall rules are.
Chris Buechler
06:50 PM Bug #1072 (Closed): Issues with increased CARP VHID limits
The increase to 65535 VHIDs has made firewall_virtual_ip_edit.php very slow. Aside from that, having 65535 VHIDs woul... Chris Buechler
06:41 PM Bug #1030: Interface case change in apinger.conf needs reverted
The quality RRDs are still using the uppercase interface name, where they previously always used lowercase and still ... Chris Buechler
06:07 PM Bug #491 (New): Dynamic DNS upgrade code not working
This is reportedly not working, config is gone after upgrade. Chris Buechler
05:48 PM Bug #812: RRD graph time axis not locked to latest times with higher average samples
This change was by design as it shows the full period rather than up to now (where 1 day = midnight to midnight). It'... Chris Buechler
03:10 PM Bug #636: layer7 not work correctly
Not working for me either. I have tried every combination of firewall rules I can think of as per conversation noted ... Seth Scardefield
02:19 PM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Sorry. One more thing. After reboot and installing the Backup package I now get a "404 - Not Found" error when trying... James Lepthien
02:17 PM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Tried again with snap from 12/5 and my RRD Summary and shellcmd packages got reinstalled, not my avahi and Backup pac... James Lepthien
05:46 AM Revision cd1de64d: Restore locking to filter reload, using an exclusive filter lock around the function, but also leave the existing shared lock for config. Ticket #1071
Erik Fonnesbeck
02:29 AM Bug #543 (Resolved): IP alias input validation problem
Chris Buechler
02:27 AM Bug #568 (Resolved): firewall rules advanced clean up
Chris Buechler
02:26 AM Bug #477 (Resolved): Swap usage graphic on dashboard is incorrect
Chris Buechler
02:25 AM Bug #374 (Resolved): "Register DHCP leases in DNS forwarder" doesn't work
Chris Buechler
02:24 AM Bug #860 (Resolved): Multiple PARP entries do not function
Chris Buechler
02:21 AM Feature #952 (Resolved): When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
Chris Buechler
12:28 AM Todo #1071 (Closed): Reevaluate locks
Since the change to the lock function in util.inc to make shared locks the default instead of exclusive locks, most l... Erik Fonnesbeck

12/04/2010

09:41 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
divert probably not a good solution for this scenario, that's good where you want to examine individual packets and p... Chris Buechler
07:31 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Using divert in pf lets you have a userspace daemon that gets only the traffic specified by a given rule sent through... Jim Pingle
05:40 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Documentation for Berkeley Packet Filter indicates that the requisite filtering exists.
"In addition, it supports ...
Ken Leland
05:04 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Thanks Chris.
As I understand your suggestion, we would have a user space daemon running and passively listening (...
Ken Leland
04:05 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
This is definitely not something that should be in kernel, we wouldn't accept that. It should passively listen and ad... Chris Buechler
03:36 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
We have concluded that this logic belongs in pf.
Here are a couple of the other options we evaluated and why we co...
Ken Leland
04:10 PM Bug #829 (New): WAN stays assigned to pppoe0 interface after switching type from PPPoE to Static
Chris Buechler
08:42 AM Bug #829: WAN stays assigned to pppoe0 interface after switching type from PPPoE to Static
I have the same problem from pppoe to DHCP.
2.0-BETA4 (i386)
built on Fri Dec 3 15:21:00 EST 2010
Alexandre Paradis
11:16 AM pfSense Packages Feature #1070 (Rejected): OpenVPN Client Export Utility : names of files in configuration archive
If you, for example, connect to two external routers and your certname is the same on both, using the hostname to dis... Jim Pingle
11:10 AM pfSense Packages Feature #1070 (Rejected): OpenVPN Client Export Utility : names of files in configuration archive
when exporting configuration archive for an openvpn client, having certname.* or clientname.* instead of pfsense-udp-... Julien ROLAND
11:13 AM Bug #1069 (Rejected): creating a 100 years valid CA makes this CA cert expires at year 1974
Sounds like a y2k38 issue (32-bit timestamp rollover), though in this case it's a PHP or OpenSSL bug. We pass the lif... Jim Pingle
10:45 AM Bug #1069 (Rejected): creating a 100 years valid CA makes this CA cert expires at year 1974
a CA cert, created today, with 36500 days of validity, have the following valid period:
from 2010-12-04 to 1974-10-04
Julien ROLAND
08:04 AM Bug #636: layer7 not work correctly
not working for me either. december 2 snapshot i386 Basel G.
04:08 AM Todo #765: Patch: Add custom DHCP configuration
My apologies; I'm not actually going to be able to test this for at least a few more weeks. I don't have physical ac... Jonathan Dieter
01:29 AM Bug #749: Downstream queues should not be assigned to LAN interfaces
I haven't had time to test it yet, but what I believe this is referring to is the queue for Internet traffic being at... Chris Buechler
12:30 AM Revision 7ac98d0b: Switches must come after the user name when using pw lock/unlock.
Erik Fonnesbeck

12/03/2010

11:56 PM Revision cdab65cc: Remove authorized_keys file when there are no authorized keys for the user.
Erik Fonnesbeck
06:50 PM Revision 5e86efe0: Actually make the other code correct.
Ermal LUÇI
06:46 PM Revision 9ce96456: Ooops actually return after disabling flowtables.
Ermal LUÇI
06:44 PM Revision 6c4ccf39: Actually do something on flowtables. Seems later image kernels have this included.
Ermal LUÇI
06:01 PM Todo #734: Fix up appearance of SSH tunnel shell
This is about the shell that a user sees when they have only the SSH tunnel privilege set and log in by SSH. Since i... Erik Fonnesbeck
05:10 PM Todo #734: Fix up appearance of SSH tunnel shell
Should this ticket be in feedback? It doesn't look like anything was actually done to resolve it, and the initial re... Josh Stompro
05:32 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
Chris Buechler wrote:
> The wizard in 1.2.3 creates seriously bad, wrong queues with behavior that cannot be duplica...
Josh Stompro
04:58 PM Bug #673: SSHD keys not created on restore
As far as I know, there is already reference counting for the conf_mount_rw/ro functions, so that it isn't mounted re... Erik Fonnesbeck
03:45 PM Bug #673: SSHD keys not created on restore
I added a little bit of debugging code to the end of the config_mount_ro function in config.lib.inc, send off an aler... Josh Stompro
12:38 PM Bug #673: SSHD keys not created on restore
I think there might still be an issue here, for Nanobsd at least.
Tested this with "2.0-Beta4 (I386) Built on Thu ...
Josh Stompro
04:56 PM Feature #520 (Resolved): ALIX reset button
Yeah it should probably get documented in the wiki, and will surely be in the book. Jim Pingle
04:36 PM Feature #520: ALIX reset button
I can confirm that this is working.
Tested with snapshot "pfsense 2.0-beta4-nanobsd (i386) Dec 2 11:27:45 EST 2010...
Josh Stompro
04:56 PM Bug #499 (Resolved): DHCP custom options on multiple interfaces not handled properly
Jim Pingle
04:53 PM Bug #499: DHCP custom options on multiple interfaces not handled properly
I can confirm that this is resolved in snapshot " Nanobsd i386 Beta4 Dec 2 11:27:45 EST 2010"
Entering the same th...
Josh Stompro
02:51 PM Bug #1067 (Closed): GUI bug in displaying Status -> Wireless
Jim Pingle
11:22 AM Bug #1067: GUI bug in displaying Status -> Wireless
New variable fixes bug if no wireless is in system (see attached screenshot).
CHess Master
09:25 AM Bug #1067 (Feedback): GUI bug in displaying Status -> Wireless
Applied in changeset commit:"273e9bf7dda8b7eb614bbb99d54389ba9c5f2238". Jim Pingle
02:22 AM Bug #1067 (Closed): GUI bug in displaying Status -> Wireless
Current version: 2.0-BETA4 (i386)
Built On: Tue Nov 30 13:09:03 EST 2010
When on the page "Traffic Graph",...
Anonymous
02:23 PM Revision 273e9bf7: Rename this variable to avoid collisions. Fixes #1067
Jim Pingle
02:15 PM Revision 5479df47: Fix this code a bit, my first attempt yesterday didn't work properly (this should).
Jim Pingle
12:41 PM Bug #1031 (Resolved): Firewall Log - Dynamic Update update only first row
Chris Buechler
11:46 AM Bug #1031: Firewall Log - Dynamic Update update only first row
Verified updates properly on:
2.0-BETA4 (i386)built on Wed Dec 1 17:21:34 EST 2010
CHess Master
10:23 AM Bug #1056 (Resolved): DHCP logs are empty since isc-dhcp-server upgrade
Thanks for the feedback! Jim Pingle
10:14 AM Bug #1056: DHCP logs are empty since isc-dhcp-server upgrade
Confirming, I now have logs showing DHCP requests and replies (as well as when the leases are saved to a file), in th... David Szpunar
10:08 AM Bug #636: layer7 not work correctly
This issue has not been resolved, including for me personally (no Layer 7 rules applied), per discussion at http://fo... David Szpunar
09:29 AM Bug #706 (Closed): OpenVPN client export needs to include remote-cert-tls server
We discovered that it was not compatible with the way we built the server certificates. See https://rcs.pfsense.org/p... Jim Pingle
02:14 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
The export does not include the option "remote-cert-tls server"
Exported config file:
dev tun
persist-tun
persi...
Anonymous
09:15 AM pfSense Packages Bug #1068: RRD Graphs not working on 64Bit Beta 4
Thanks. Although, it wasn't terribly intuitive when the firewall said there was an available update... I would think... Shannon McMahon
08:55 AM pfSense Packages Bug #1068 (Rejected): RRD Graphs not working on 64Bit Beta 4
You aren't running a 64-bit snapshot. You probably accidentally applied a 32-bit (i386) update after installing the a... Jim Pingle
08:38 AM pfSense Packages Bug #1068 (Rejected): RRD Graphs not working on 64Bit Beta 4
Installed build:
2.0-BETA4 (i386)
built on Thu Dec 2 09:23:11 EST 2010
Since install, RRD Graphs error:There...
Shannon McMahon
04:26 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Tried again via console update this time and snap http://snapshots.pfsense.com/FreeBSD_RELENG_8_1/i386/pfSense_HEAD/u... James Lepthien
04:04 AM Bug #1066: Remove old dynamic caches
Error gone and cache file left behind in /conf/ Perry Mason

12/02/2010

11:16 PM Revision 864bf774: Restore spoofed MAC after running hostapd to keep behavior consistent with other interfaces. Ticket #841
Erik Fonnesbeck
10:40 PM Revision acb0bce0: Restore the original MAC address before running hostapd to work around a hostapd bug. Ticket #841
Erik Fonnesbeck
09:31 PM Revision 650cb13b: Try to handle when cert subject entries are arrays.
Jim Pingle
08:29 PM Revision 0a0774b5: Allow a . in hostnames. Also, don't allow a space in hostname, it was adding a bunch of trailing spaces to the end of the field. Fixes #1063
Jim Pingle
07:53 PM Revision ca98b042: Merge remote branch 'mainline/master'
Conflicts:
usr/local/www/fbegin.inc
Vinicius Coque
07:46 PM Revision 386447ea: BP: Implement gettext() calls on fbegin.inc #multilang
Carlos Eduardo Ramos
07:44 PM Revision 8c06f62f: Fix gettext in priv.defs.inc
Vinicius Coque
07:34 PM Bug #1056: DHCP logs are empty since isc-dhcp-server upgrade

2.0-BETA4 (i386)
built on Thu Dec 2 09:23:11 EST 2010
This is what I got with this version on my test box...
...
Chris Palmer
07:08 PM Revision b098343a: Correct binaries needed.
Ermal LUÇI
06:46 PM Revision 94044c40: BP: Implement gettext() calls on fbegin.inc #multilang
Carlos Eduardo Ramos
06:09 PM Revision 8e428017: Do not try to be smart on the package name and also use a better resulting condition testing.
Ermal LUÇI
05:47 PM Bug #841 (Feedback): hostapd doesn't work with spoofed MAC (but should be able to)
The workaround I've committed should be sufficient to handle the hostapd issue until the bug gets fixed (if ever). Erik Fonnesbeck
05:29 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
When using this patch it causes issues when hostapd is run at startup, preventing clients from associating. When hos... Erik Fonnesbeck
12:39 AM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
The test utility I had made before for reading the BSSID was actually crashing in an unrelated section and I must not... Erik Fonnesbeck
05:21 PM Revision 41fafd53: Make use of the new tab menu and use _GET instead of _POST for pkg name passed in URL.
Warren Baker
05:01 PM Revision d589cccf: If a pkg has logging enabled in syslog, then correctly ensure that it does not get logged to one of the other logs but only to its specified log file.
Warren Baker
04:28 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Trust me - I tried.
Yesterday, the server kept giving me "Internal error" whenever I updated this bug ... other bugs...
Jeppe Oland
03:56 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Can you show me the new logs please? Ermal Luçi
03:08 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Sorry, but it doesn't seem to be working.
I tested with a clean install of pfSense-2.0-BETA4-20101201-1616.iso fol...
Jeppe Oland
04:04 PM Bug #651: Multiple gateways on WAN interface
Please test new snapshots.
This should be fixed from that time.
Ermal Luçi
03:53 PM Bug #713 (Resolved): Shaper Wizard: When backlogged, high priority queues get zero bandwidth
Ermal Luçi
01:10 PM Bug #713: Shaper Wizard: When backlogged, high priority queues get zero bandwidth
I can confirm this as resolved. The qACK and QOthersHigh get created without the Link Share M1 or D options set now.... Josh Stompro
03:52 PM Feature #702 (Resolved): Page with status for "Traffic Shaper: Limiter"
Ermal Luçi
01:15 PM Feature #702: Page with status for "Traffic Shaper: Limiter"
I think this is resolved also. Looking at the Dec 2nd snapshot, I see a new option under Diagnostics -> Limiter Info... Josh Stompro
03:50 PM pfSense Packages Bug #1065 (Feedback): error after rules installation
Should be fixed.
Reinstall.
Ermal Luçi
03:32 AM pfSense Packages Bug #1065 (Resolved): error after rules installation
when i am tryng to gep the page
/snort/snort_rules.php?id=1
It says "Fatal error: Cannot redeclare csrf_startup()...
Dienis Rastegaeff
03:48 PM Bug #875: Uninstalling packages can remove system libraries
Well i did a lot of testing today on this.
The only plausible option is to hardlink /usr/local/lib files that ship w...
Ermal Luçi
03:30 PM Bug #1063 (Feedback): Load balancer status doesn't work if the virtual server name contains a '.'
Applied in changeset commit:"0a0774b511c6833a2b87975c21fdb3b10897d6c9". Jim Pingle
03:28 PM Bug #1063: Load balancer status doesn't work if the virtual server name contains a '.'
Actually nevermind, I think I got it. Commit is pending. Jim Pingle
03:15 PM Bug #1063: Load balancer status doesn't work if the virtual server name contains a '.'
How about:... Jim Pingle
09:38 AM Bug #1063: Load balancer status doesn't work if the virtual server name contains a '.'
Bah, attached in a slightly more readable format Gary Richards
09:36 AM Bug #1063: Load balancer status doesn't work if the virtual server name contains a '.'
@
: relayctl show summary
Id Type Name Avlblty Status
1 redirect test ...
Gary Richards
09:24 AM Bug #1063: Load balancer status doesn't work if the virtual server name contains a '.'
Can you show the output of:... Jim Pingle
02:56 PM Revision eeb52fea: Syslog.conf would end up with multiple pkg facility names on the same line. So multiple pkgs with logging enabled would end up with the previous pkg prepended to its syslog entry.
Warren Baker
02:14 PM Revision a2ff08f8: Disable redirect gateway checkbox when using shared key (you can't push with shared key). Also re-run the code to hide the local network box if the gw redirect is checked when switching server modes, since there is no need to push a specific local network when pushing the default gateway.
Jim Pingle
01:22 PM Revision b8e2fd16: Use unlink here instead of an exec to rm. Remove escapeshellarg call as it isn't needed now. Fixes #1066
Jim Pingle
11:39 AM Bug #302: Shaper wizard remembers values on error, but are disabled
I see this same error again when using the Dec 2nd nanobsd snapshot.
2.0-Beta4 (i386) built on Thu Dec 2 03:39:46 E...
Josh Stompro
11:31 AM Bug #733: Shaper: Unexplained 30% bandwidth max restriction in p2p catch all
I have few more questions about this issue.
Is the user just supposed to know that custom bandwidths = p2p catchal...
Josh Stompro
09:12 AM Bug #1030: Interface case change in apinger.conf needs reverted
Well seems ok now.
Chris why do you think this is not fixed?
Ermal Luçi
04:49 AM Bug #1030 (New): Interface case change in apinger.conf needs reverted
That revert was correct but not for fixing this. Chris Buechler
04:36 AM Bug #1030: Interface case change in apinger.conf needs reverted
Not sure it works (pfSense-2.0-BETA4-20101201-1616.iso).
I restored my configuration just before midnight, and the R...
Jeppe Oland
08:25 AM Bug #1066 (Feedback): Remove old dynamic caches
Applied in changeset commit:"b8e2fd16e45c21e9942da71020682a3b79f05a69". Jim Pingle
05:25 AM Bug #1066: Remove old dynamic caches
should have looked like this :)... Perry Mason
05:14 AM Bug #1066 (Resolved): Remove old dynamic caches
php: /services_dyndns_edit.php: The command '/bin/rm /conf/dyndns_opt2opendns'Fullrate'.cache' returned exit code '1'... Perry Mason
05:29 AM Revision 310a9d7b: Confirm before deleting the interface.
Erik Fonnesbeck
02:23 AM Bug #1060 (Resolved): Firewall Aliases, no tooltip in Rules if apostrophe in detail description
thanks Chris Buechler
02:18 AM Bug #1060: Firewall Aliases, no tooltip in Rules if apostrophe in detail description
Confirmed fixed on latest snapshot, using same aliases from same config as the bug was submitted, and tooltip now sho... David Szpunar
02:14 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
I was able to get in remotely (through another firewall/VPN) and revert the VM to a (VM) snapshot from Nov. 3rd that ... David Szpunar
01:50 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
I just upgraded from a snapshot from yesterday to the most recent snapshot, full ISO install on a VM, with Open VM To... David Szpunar

12/01/2010

10:47 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
If you need development assistance along the way and have a budget for it, contact me via email (cmb at pfsense dot o... Chris Buechler
10:44 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Great, we'll start reviewing code to determine if it should be a package or part of the base system. Once we have a ... Ken Leland
10:39 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
Ah that's the first RTP-only security issue I've noticed, that does indeed make it worthwhile. Re-inviting is apparen... Chris Buechler
10:23 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
As far as RTP changing ports during a call, in asterisk language its called re-inviting, and if it is non-standard, a... Ken Leland
10:13 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
The application we intend to use this for is as follows:
Asterisk Cluster -- pfSense -- Public Internet -- VoIP Ph...
Ken Leland
10:00 PM Feature #1064: VoIP - Dynamic Pinholes for RTP
RTP is easy to accommodate without that mess, tons of VoIP providers run as is with no difficulties. It's most common... Chris Buechler
09:40 PM Feature #1064 (Closed): VoIP - Dynamic Pinholes for RTP
The media stream for a SIP call uses dynamically assigned port numbers. These port numbers can change several times d... Ken Leland
09:48 PM Bug #749 (New): Downstream queues should not be assigned to LAN interfaces
The wizard in 1.2.3 creates seriously bad, wrong queues with behavior that cannot be duplicated all over again. Where... Chris Buechler
05:08 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
The wizard is the same as in 1.2.3 it just takes more values for multiple interfaces.
And for me this is not much di...
Ermal Luçi
12:28 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
What would be the best design to handle shaping and routing?
I just ran into a duh moment after a site with limite...
Josh Stompro
08:30 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
Tried that hostapd configuration setting and got "bssid item not allowed for the default interface and this driver", ... Erik Fonnesbeck
07:35 PM Revision 1b844e70: Raise this to new limit of 2^16.
Ermal LUÇI
06:55 PM Bug #1000: lagg not working set to failover.
I think its an em(4) problem since it is not reporting that it lost its link state. Ermal Luçi
05:23 PM Revision 435a418f: Do not spam console with useless messages. Also remove killall not needed anymore.
Ermal LUÇI
05:04 PM Revision 6c9e8647: Enable LINK_DOWN event for interfaces. It will help cases similar to http://forum.pfsense.org/index.php/topic,29032.0.html
Ermal LUÇI
04:20 PM Revision 893f4784: If the protocol is not set in the config, it defaults to https, so assume port 443 since the port isn't set either.
Jim Pingle
02:58 PM Revision ddb09227: Use new style filterdns argument passing on cmd and remove hack for killall now that its not needed anymore.
Ermal LUÇI
01:45 PM Bug #682: WAN traffic graph is broken with MLPPP
Same issue exists for me in November 20 snapshot, all the way up to 8 lines. David Burgess
12:24 PM Bug #1063 (Resolved): Load balancer status doesn't work if the virtual server name contains a '.'
Hi,
I've spent a while trying to work out why a test load balancer config I created seemed to be working fine, but...
Gary Richards
12:14 PM Bug #1061: Error after upgrade to latest version
I had https, but i hadn't used 443 explicitly.
Nevertheless, pfSense-Full-Update-2.0-BETA4-20101130-0828.tgz was the...
Ilias-Dimitrios Vrachnis
12:03 PM Bug #1061 (Feedback): Error after upgrade to latest version
Should be fixed in the next new snapshot. In the meantime if you go to System > Advanced, on the admin tab, and expli... Jim Pingle
11:37 AM Bug #1061: Error after upgrade to latest version
I can confirm this too.
I'm currently downloading an older snapshot to test.
i'll report back if i'm successful
...
Ilias-Dimitrios Vrachnis
09:46 AM Bug #1061 (Resolved): Error after upgrade to latest version
/diag_tables.php show nothing in dropdown menu
AND
Filter Reload Status
"There were error(s) loading the rules: /t...
Dienis Rastegaeff
11:52 AM Revision b6ab9bd2: Ticket #1060. Escape even the alias entry descritpions.
Ermal LUÇI
11:22 AM Revision 1dbc0c43: Use correct variable name. Also related to Ticket #847.
Ermal LUÇI
10:06 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
I have avahi, rrd summary and shellcmd installed. But I guess it is not shellcmd because I just installed it yesterda... James Lepthien
09:39 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
I just updated an ALIX with cron, OpenVPN client export, shellcmd, blinkled, and siproxd installed. It worked fine. I... Jim Pingle
09:29 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Just want to let you know that the same problem is here too. ALIX Box with latest pfsense 2.0 snapshot.
This problem...
Peter Baumann
09:25 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Sure it works without any packages installed. But the ticket is for when you have some packages installed... James Lepthien
09:22 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
FYI I've upgrade (with no package) and it worked. Perry Mason
07:11 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Now tried with snaps from 11/30 and 12/1 and it even got worse. Installed the 12/1 and wanted to connect to the WebUI... James Lepthien
09:55 AM Feature #1062 (Resolved): Add per-rule delete ("X") button to Outbound NAT rules
Firewall rules, port forwards, etc, each have per-entry delete ("X") buttons, but not outbound NAT rules. For consist... Jim Pingle
09:03 AM Bug #1058 (Feedback): filterdns not honoring quit signal
Fixed. Ermal Luçi
05:56 AM Bug #1060 (Feedback): Firewall Aliases, no tooltip in Rules if apostrophe in detail description
Committed. Ermal Luçi
12:05 AM Bug #1060 (Resolved): Firewall Aliases, no tooltip in Rules if apostrophe in detail description
When editing aliases under Firewall->Aliases, if I have an alias of type Host(s) and in the Description field to the ... David Szpunar
05:28 AM Bug #847 (Feedback): Deleting interface leaves remnant in interface groups
Well this is indirectly resolved by the latest commit(referenced to this issue to).
link_interface_to_group() functio...
Ermal Luçi
03:02 AM Bug #847 (New): Deleting interface leaves remnant in interface groups
It either:
1) shouldn't allow deleting an interface that's in an interface group
or
2) should automatically remov...
Chris Buechler
02:43 AM Bug #847: Deleting interface leaves remnant in interface groups
This bug still exists, I just tested it on the most recent snapshot from this afternoon. I created an interface (opt1... David Szpunar
04:29 AM Revision 7eb2ebbe: Make page more html friendly.
Scott Ullrich
04:25 AM Revision 75e22cbc: Do not output blank pkg names
Scott Ullrich
04:23 AM Revision 5a0ce1fb: Revert "Do not output pgtitle twice. Make page more html friendly."
This reverts commit 38f16bf27c1ce12e22e8783bea62f6c12bece4b0. Scott Ullrich
04:22 AM Revision 38f16bf2: Do not output pgtitle twice. Make page more html friendly.
Scott Ullrich
04:18 AM Revision 92472a59: Do not output blank pkg name
Scott Ullrich
01:38 AM Revision d32698d3: Ensure inetd.conf exists
Scott Ullrich
01:36 AM Revision a1054b46: Make pfTop uniform
Scott Ullrich
01:10 AM Revision 50646b37: Temporarily killall -9 filterdns until the signal issue can be resolved. Will open a ticket
Scott Ullrich
12:52 AM Revision 50c35266: Make sure a port is always set. Remove trailing newline
Scott Ullrich
12:43 AM Revision 522b72c1: Set port
Scott Ullrich
12:35 AM Revision 76ffdf90: Add successful user for sshlockout
Scott Ullrich
12:29 AM Revision 56bff6a3: Make sure host private key permissions aren't too open so sshd won't complain.
Erik Fonnesbeck

11/30/2010

11:59 PM Revision d44798f7: Adding webConfiguratorlockout table and code.
Scott Ullrich
11:55 PM Revision 7a9ed301: Preseve attributes of files during copy.
Ermal LUÇI
11:46 PM Revision 88ecfc58: Reword auth error message to match ssh for the most part
Scott Ullrich
11:44 PM Bug #965 (Resolved): IPSec configuration network selection doesn't match rest of UI
thanks Chris Buechler
11:41 PM Bug #965: IPSec configuration network selection doesn't match rest of UI
Confirmed that I've seen this fix in action when heavily configuring several IPsec VPN (site-to-site and Mobile) conf... David Szpunar
11:41 PM Revision 1ea78906: Revert "Use -ss for syslogd. Suggested-by: Ermal"
This reverts commit c57e0d704ac08afee31e1e79f0b8228f5eb66cb1. Scott Ullrich
11:39 PM Revision c57e0d70: Use -ss for syslogd. Suggested-by: Ermal
Scott Ullrich
11:36 PM Revision e351fc2d: Use -l
Scott Ullrich
11:28 PM Revision be9303ac: Unbreak Status -> System Logs -> DHCP due to chroot and new version of DHCPD.
Scott Ullrich
10:33 PM Revision a4fe5cac: Reformat pfsync/xmlrpc sync settings. Hopefully make it more clear to understand and use.
Jim Pingle
10:18 PM Revision 628d1548: Do a fflush of file before closing and sync(2). Fix whitespace while here.
Ermal LUÇI
10:16 PM Revision 65c5cec3: Make sure we cannot add interfaces by entering the link directly on url address bar. This does the same check as the one for showing the plus button on interfaces_assign.
Ermal LUÇI
10:07 PM Bug #1000: lagg not working set to failover.
Output attached Rick Baranowski
09:48 PM Revision 5ba5a8de: Use pfSense_sync()
Scott Ullrich
08:29 PM Bug #1059 (Closed): ipfw-classifyd is running but qos is not enabled or configured
Oops, there was a layer7 container. Deleted. Scott Ullrich
08:28 PM Bug #1059 (Closed): ipfw-classifyd is running but qos is not enabled or configured
QOS is not enabled/configured. ipfw-classifyd is running:
[2.0-BETA4][root@hostname]/root(106): ps awux | grep 18...
Scott Ullrich
08:10 PM Bug #1058 (Resolved): filterdns not honoring quit signal
[2.0-BETA4][root@hostname]/root(85): ps awux | grep filterdns | wc -l
11
Chris was seeing 24 of them. The...
Scott Ullrich
07:08 PM Revision 00bc5bcc: Call sync after writing the file and before returning to continue processing.
Scott Ullrich
06:39 PM Bug #1056 (Feedback): DHCP logs are empty since isc-dhcp-server upgrade
This should be solved with latest commits. Ermal Luçi
08:31 AM Bug #1056 (Resolved): DHCP logs are empty since isc-dhcp-server upgrade
Since we upgraded to isc-dhcp41-server a few weeks ago, the DHCP logs tab is empty.
The config directives are stil...
Jim Pingle
06:35 PM Revision a6e0e07b: Set page title to Status: Dashboard for consistency
Scott Ullrich
06:15 PM Revision d2b20ab6: Store upgraded monitor IPs in gateway items, not accidentally as bogus interfaces. This was causing some configs to upgrade and then get stuck in a reassignment loop after the next reboot.
Jim Pingle
05:27 PM Revision 78b94214: Mount rw so we can have the packages processing correctly.
Ermal LUÇI
05:17 PM Revision 416e6432: Use fullpath
Ermal LUÇI
04:47 PM Revision b0cf10bf: Ticket #911. Provide an option under system->advanced->misc to disable killing states when a gateway goes down. Possibly on 2.1+ this might be made an option specific for each gateway!
Ermal LUÇI
04:30 PM Revision 7af33a75: Print file name when logging an xml error.
Jim Pingle
04:23 PM Bug #1039: Error on Syncronisation slave - DIOCADDRULE: Device busy
We are not running uPNP.
We have a few filter and nat rules
and we are running the following services:
carp (...
Martin Klein
10:58 AM Bug #1039: Error on Syncronisation slave - DIOCADDRULE: Device busy
By any chance you have services like uPNP running? Ermal Luçi
07:05 AM Bug #1039: Error on Syncronisation slave - DIOCADDRULE: Device busy
I am sorry to say but on a Tue Nov 30 02:04:03 EST 2010
Snapshot the problem is not fixed.
Martin Klein
04:21 PM Revision 0ac206f9: Ticket #1047. Make the flags the same for each member interface before adding them to lagg(4)/bridge(4)
Ermal LUÇI
03:15 PM Revision 0a1eabbe: Resolves #947. Blacklist interfaces to show as possible lagg members if they are present in a lagg already.
Ermal LUÇI
02:21 PM Revision e2d052b6: Remove extraneous ')'. So much for php -l
Ermal LUÇI
01:42 PM Revision af0b07d3: Make the RRD path if it doesn't yet exist at this point.
Jim Pingle
01:40 PM Revision fb2e53da: Run ecl through php instead of executing directly.
Jim Pingle
11:57 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
The commit to fix this just happened. It won't be in a new snapshot until one gets built that includes the fix. It ma... Jim Pingle
11:55 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Tried updating to latest snap from 11/30 just now. That update broke my box. Boots up says something about an error i... James Lepthien
11:31 AM Bug #1049: After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
Can you please try with the latest version of snapshots. Ermal Luçi
11:30 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
the selection of CA for LDAPS should be in the auth server settings, then everything else should point appropriately ... Chris Buechler
09:58 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
Let me clarify:
The situation was that ALL openvpn authentication requests were failing when it wasn't specified (...
Florent Daigniere
09:42 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
You suggested TLS_REQCERT=never while it seems that default setting is 'try' which is the recommended one!?
TLS is h...
Ermal Luçi
11:03 AM Feature #1057 (Needs Patch): Limiter mask only supports dest/src ip
Some scenario's benefit from src port differentiation using dynamic pipes. IE. Terminal Server connections from a NAT... Bastian Slikkerveer
10:58 AM Bug #1038 (Resolved): System Tuneables net.inet.carp.log not Working
Ermal Luçi
10:58 AM Bug #1038: System Tuneables net.inet.carp.log not Working
Yeah but that is another issue perse. Ermal Luçi
07:03 AM Bug #1038: System Tuneables net.inet.carp.log not Working
Using Tue Nov 30 02:04:03 EST 2010 Snapsot
net.inet.carp.log stayes at 1, wich fixes
the problem for me. But if i...
Martin Klein
10:54 AM Bug #729: if_bridge unpredictable filter interface selection
This possibly is to late for 2.0 since there are if_bridge(4) chagnes involved which might become problematic.
The p...
Ermal Luçi
10:51 AM Bug #911 (Feedback): Need option to disable state killing on WAN failure
Ermal Luçi
10:29 AM Bug #621: Certificate Manager won't accept a windows CA signed certificate
Possibly this is related to format of the cer ie DER....
So this must be an argument that must be supplied during im...
Ermal Luçi
10:25 AM Bug #1047 (Feedback): Disable TSO, hardware checksum don't work for unassigned but active interfaces
Patch committed. Ermal Luçi
09:20 AM Bug #947: existing lagg members should not be able to be added to lagg
Applied in changeset commit:"0a1eabbe814498d962a3f06f288bab0c39e4b512". Ermal Luçi
09:18 AM Bug #947 (Feedback): existing lagg members should not be able to be added to lagg
Ermal Luçi
08:33 AM Bug #1055: system is broken after upgrade
That's already been fixed by commit:e2d052b - wait for a new snap. Jim Pingle
08:32 AM Bug #1055: system is broken after upgrade
squid says that cannot create child processes, all ip settings are gone and i cannot connetct to it remotely.
er...
Dienis Rastegaeff
08:22 AM Bug #1055 (Rejected): system is broken after upgrade
That is way too vague for a problem report.
We need exact error messages, and specifics about what does and does n...
Jim Pingle
08:19 AM Bug #1055 (Rejected): system is broken after upgrade
my pfsense shows errors after upgrade to 20101130-0125
after reinstallation from this image (pfSense-2.0-BETA4-20101...
Dienis Rastegaeff
08:26 AM Bug #831: Status -> System logs - > DHCP bug
That is a completely different issue that needs a new ticket. Jim Pingle
08:13 AM Bug #831: Status -> System logs - > DHCP bug
i guess this needs to be opened again as currently the dhcp log doesn't show anything after the upgrade Bipin Chandra
07:46 AM pfSense Packages Bug #1046 (Resolved): pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
It was just added overnight. It will be picked up the next time the binaries are built. I'm closing this one out for ... Jim Pingle
04:16 AM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
Ehm, errata corrige.
It appears that the newly (quite newly) added Postfix Forwarder Package is missing.
Fulvio Scapin
04:12 AM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
Verified the change. Thanks
@Francisco Brasileiro:
Thanks for the formatting ;)
Fulvio Scapin

11/29/2010

11:49 PM Revision 5f36c658: Rework this loader.conf changing code a bit. Might help with ticket #560
Jim Pingle
11:38 PM Revision 16926fdc: Use grep -c instead of wc and awk. Also use full paths.
Jim Pingle
11:31 PM Revision ac617a8f: Eliminate a cat-to-grep
Jim Pingle
10:39 PM Revision 9ae11a62: Revert "Add Active Directory group membership checking Ticket #1009"
This reverts commit ef17372492fb3d271497160a816eba64b3bcf436. Scott Ullrich
10:36 PM Revision ef173724: Add Active Directory group membership checking Ticket #1009
Scott Ullrich
10:10 PM Bug #947 (New): existing lagg members should not be able to be added to lagg
Chris Buechler
11:56 AM Bug #947: existing lagg members should not be able to be added to lagg
Also interfaces available after added to a lagg interface. for example:
I created lagg interface with em2 and em3 in...
Serdar Cihaner
09:48 PM Revision 84c07e65: Include guiconfig.inc for auth
Scott Ullrich
09:41 PM Bug #1042: CARP VIP Descriptions incorrect on IPsec/OpenVPN
It's not broken as is, let's not break it. Taking the VIPxx and getting the description is easy enough. Chris Buechler
09:23 PM Bug #1042: CARP VIP Descriptions incorrect on IPsec/OpenVPN
Yes, I agree.
And it would be probably better to store the ip rather than the inferface in config.xml. At least fo...
Pierre POMES
09:06 PM Bug #1042: CARP VIP Descriptions incorrect on IPsec/OpenVPN
That may explain the difference in why it was coded that way but it's still not optimal for the user. I'd really pref... Jim Pingle
08:57 PM Bug #1042: CARP VIP Descriptions incorrect on IPsec/OpenVPN
Jim P wrote:
> CARP VIPs in the list for use by IPsec and OpenVPN are shown with the interface name (e.g. VIP22) inst...
Pierre POMES
08:36 PM Revision cb3b4ebc: Revert 2c4a13d91b72400c07b965b0a522be8dde2d1110 Interface names should appear as uppercase
Scott Ullrich
08:35 PM Revision 82bf9411: Revert 9c3cac0cb553e1610948e78dd119c1b0fcb04224 Interface names should appear as uppercase
Scott Ullrich
08:34 PM Revision e3feac4e: Revert "Interface names should appear as uppercase"
This reverts commit 66d57db5e44650658d95345683cf4afae6680b68. Scott Ullrich
08:34 PM Revision 96302ebd: Revert "Interface names should appear as uppercase"
This reverts commit 4cea35b344c8b4444f7a5a7a244bac528b483cbc. Scott Ullrich
08:34 PM Revision a6d9251e: Revert "Interface names should appear as uppercase"
This reverts commit e8ad860fb4d19d137e9cb490c498327db8fba719. Scott Ullrich
08:27 PM Revision fdf4e791: Set net.inet.carp.log=1. Ticket #1038
Scott Ullrich
08:18 PM Revision 74efe8bc: Deactivate cpu graph. Will bring back in 2.1
Scott Ullrich
08:07 PM Revision 7ff41586: Disable firewall rule drag and drop. Will bring this feature back in 2.1
Scott Ullrich
06:29 PM Feature #1010: Privilege setting for allowing login access through captive portal
An alternate patch that does not automatically create a captive portal group when enabling captive portal, leaving it... Erik Fonnesbeck
06:14 PM Feature #1010: Privilege setting for allowing login access through captive portal
Pushing this off to 2.1. Scott Ullrich
03:26 PM Feature #1010: Privilege setting for allowing login access through captive portal
Code was completed and thoroughly tested some time ago. Just need to know whether this should be pushed or left to a... Erik Fonnesbeck
06:28 PM Bug #560 (New): loader.conf is empty after a firmware update.
I just tested it again, it's still getting wiped out somehow during the update process. Jim Pingle
06:09 PM Bug #560 (Feedback): loader.conf is empty after a firmware update.
Scott Ullrich
05:53 PM Bug #560: loader.conf is empty after a firmware update.
I just downloaded http://snapshots.pfsense.org/FreeBSD_RELENG_8_1/i386/pfSense_HEAD/updates/pfSense-Full-Update-2.0-B... Scott Ullrich
06:23 PM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
corrected: ... Francisco Brasileiro
05:54 PM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
All files are present now (verified with a modified version of that one-liner, I couldn't get that to work). Jim Pingle
05:11 PM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
All of the entries that were not found should be fixed now, or will be once the last build finishes (for mod_security). Jim Pingle
12:41 PM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
OK, I'll have a look at these. Jim Pingle
11:21 AM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
Opss.
I forgot to quote the excerpt from the xml file.
Sorry
Fulvio Scapin
11:20 AM pfSense Packages Bug #1046: pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
Jim P wrote:
> Do you have a link to something that mentions specific packages that show issues like this? There are...
Fulvio Scapin
06:11 PM Bug #754: hifn driver and AES192 and 256
We need to follow up on the PR above, a customer needs this.
Chris Buechler
05:56 PM Bug #754: hifn driver and AES192 and 256
Still not fixed in FreeBSD. Delaying ticket to 2.1. Scott Ullrich
06:09 PM Bug #1000: lagg not working set to failover.
Rick,
Please show a ifconfig -a output and arp -a output
Scott Ullrich
05:46 PM Bug #1051 (Feedback): radius support in racoon
Even though we had explicitly set the option to use radius, it still was not compiled in. So I changed the Makefile t... Jim Pingle
05:00 AM Bug #1051 (Resolved): radius support in racoon
there is no radius support compiled in racoon daemon Ravine Pick
05:44 PM Todo #765: Patch: Add custom DHCP configuration
I just emailed Jonathan to check this ticket.
Scott Ullrich
05:43 PM Todo #765 (Feedback): Patch: Add custom DHCP configuration
Scott Ullrich
03:20 PM Todo #765: Patch: Add custom DHCP configuration
Bump. Please check to see if this is resolved. We would like to go to RC1 soon and this is lingering. Scott Ullrich
05:39 PM Feature #1009 (New): Active Directory group membership checking
We need a patch of changes here. auth.inc has diverged too much at this point. And even then Ermal does not agree w... Scott Ullrich
05:35 PM Feature #1009 (Feedback): Active Directory group membership checking
Scott Ullrich
05:15 PM Feature #1009: Active Directory group membership checking
i have been using this patch.
have not seen any issues so far.
vito B
05:36 PM Bug #830: Service provider information should be saved
I just spent some considerable time on #2 and had no luck. Both Ermal and myself agree that this is not doable witho... Scott Ullrich
03:36 PM Bug #1030 (Feedback): Interface case change in apinger.conf needs reverted
Reverted offending commits. Please test.
Scott Ullrich
03:26 PM Bug #1038 (Feedback): System Tuneables net.inet.carp.log not Working
Scott Ullrich
03:22 PM Bug #875: Uninstalling packages can remove system libraries
This ticket will require us moving to a PBI style package system where the libraries are self contained in the progra... Scott Ullrich
03:17 PM Bug #345: CPU graph widget reports wrong usage with SMP
widget deactivated in 2.0. Will bring back in 2.1. Scott Ullrich
03:14 PM Bug #437: Y2K38 bug in user manager expiration
Lets address in 2.1. Scott Ullrich
03:10 PM Bug #878 (New): Drag and Drop firewall rules causes corruption
I have disabled this feature. We will bring back in 2.1. Scott Ullrich
02:54 PM Revision 5b2f628e: Add exit; so the redirection actually works.
Ermal LUÇI
01:50 PM Revision 1bab0df1: Add suggested fix from ticket #1037
Jim Pingle
01:32 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
Keep in mind that hostapd was designed as a tool to use for every aspect of configuring the wireless interface on Lin... Erik Fonnesbeck
10:20 AM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
Well by just reading the supplied config file it states... Ermal Luçi
12:45 PM Bug #975 (Resolved): CARP / vip interface disappears on slave after interface change
Chris Buechler
10:42 AM Bug #975: CARP / vip interface disappears on slave after interface change

Yes, I had been unable to update because of problems with the amd64 build and met with disaster that
meant had to...
Rob Lister
12:40 PM Bug #1037 (Resolved): Openvpn broken when used with LDAPS backend
Chris Buechler
11:10 AM Bug #1037: Openvpn broken when used with LDAPS backend
It's confirmed-working with 1bab0df1b7fd06ecb2818f69187214a70de238b9
The other bug I was referring to:
bug #1052:...
Florent Daigniere
05:21 AM Bug #1037: Openvpn broken when used with LDAPS backend

Nope. Still broken.
You are missing a semi-column in befad72821f522bf2c23a883f72ade8af48b8533.
-$sed .= " \$m...
Florent Daigniere
11:53 AM Revision c45d1cfe: Remove old reference to function. Reported-by: http://forum.pfsense.org/index.php/topic,30508.0.html
Ermal LUÇI
10:39 AM Bug #1040 (Resolved): link doesn't work "add a new one."
Jim Pingle
10:34 AM Bug #1040: link doesn't work "add a new one."
Works ticket can be closed Perry Mason
10:21 AM Bug #831: Status -> System logs - > DHCP bug
Hard to say right now since the upgrade to a new version of the DHCP daemon has caused an issue with logging.
It m...
Jim Pingle
10:04 AM Bug #831: Status -> System logs - > DHCP bug
What happens when you just clear the file instead of removing and re-creating the file? I've seen more programs havin... Peter O
09:42 AM Bug #1039 (Feedback): Error on Syncronisation slave - DIOCADDRULE: Device busy
Possible fix committed. Ermal Luçi
07:27 AM Bug #1053 (Closed): CBQ per se, in kernel
plz refer to this forum thread
http://forum.pfsense.org/index.php/topic,29018.0.html
Bipin Chandra
05:27 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
One of the places where it should be fixed is openvpn's configuration with LDAPS (see bug #1037) Florent Daigniere
05:26 AM Bug #1052 (Resolved): Certificate validation of the LDAPS servers is not enforced
Hi,
Looking around in the source code, it seems that the certificate validation for LDAPS servers is not enforced....
Florent Daigniere
02:19 AM Revision f3c91cb5: Reintroduce this optimization, but use the correct return value this time.
Erik Fonnesbeck
01:27 AM Revision d04e8082: Unbreak sysctl handling.
Scott Ullrich
12:55 AM Revision 84cf0b3e: Use exec()
Scott Ullrich
12:04 AM Revision 690d24af: Add pfSsh.php externalconfiglocator playback script
Scott Ullrich

11/28/2010

11:10 PM Revision 8850a528: Nuke newline
Scott Ullrich
11:05 PM Revision c58b5f44: Skip slices on bootup device
Scott Ullrich
10:34 PM Revision 70bea648: Cleanup
Scott Ullrich
10:30 PM Revision b3405363: Use product name
Scott Ullrich
10:17 PM Revision 651a6867: Use head binary and eliminate a pipe to avoid broken pipe warning
Scott Ullrich
09:59 PM Revision 6edc4c0c: Fix misc errors. File now restores and throws an alert when completed.
Scott Ullrich
09:23 PM Revision a620ea36: Add php header
Scott Ullrich
07:26 PM Revision 58ba038a: Handle slices
Scott Ullrich
07:13 PM Revision 46dd9586: Only check / and /config for config.xml. Otherwise you might step on a nanobsd installation.
Scott Ullrich
07:03 PM Revision 206f684d: Adding external configuration loader which will look on all found disks except bootup disk for config.xml. If tconfig.xml is found on an external disk then it tests the roobobj to ensure its a valid file then calls test_config() to ensure it is a valid xml file. Once the file is validated a backup_config() is called to backup the current configuration and finally the file is installed using restore_backup()
Scott Ullrich
06:44 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
One way to test this: you can start hostapd with ether matching bssid and once started you can change ether to anythi... Erik Fonnesbeck
06:28 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
Each wireless clone has two different types of MAC addresses - in ifconfig, one is labeled ether and one is labeled b... Erik Fonnesbeck
05:31 PM Bug #841 (New): hostapd doesn't work with spoofed MAC (but should be able to)
Chris Buechler
05:28 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
Can you state an example of this?
If i get you right and this is the same as form vlan interfaces than its by desi...
Ermal Luçi
06:44 PM Bug #1013: Captive Portal Reauthentication broken
Please change status to new.
Bug1050:
As described in Bug#1013 the reauthentication feature is broken! I install...
L J
05:48 PM Bug #1013 (Feedback): Captive Portal Reauthentication broken
Chris Buechler
05:48 PM Bug #1050 (Rejected): Captive Portal Reauthentication broken
duplicate of #1013 Chris Buechler
05:43 PM Bug #1050 (Rejected): Captive Portal Reauthentication broken
As described in Bug#1013 the reauthentication feature is broken! I installed a 1.2.3 stable machine and configured th... L J
01:31 PM Bug #1049 (Resolved): After reinstalling packages at bootup, WebUI not accessable (NanoBSD)
After a firmware update and the first reboot of pfSense installed packages get reinstalled. Sometimes all packages ge... James Lepthien

11/27/2010

10:19 PM Feature #1032: Add all interfaces to Packet Capture drop-down
Yeah I think vip* (CARP) and lo0 would be the only two things to exclude, otherwise everything ifconfig returns. I ca... Chris Buechler
07:35 PM Bug #1048 (Rejected): Wireless clone can't be assigned to new interface (NanoBSD)
at least one Atheros chipset I have will panic like that with VAP. Driver problem, nothing we can do about it, needs ... Chris Buechler
06:57 PM Bug #1048 (Rejected): Wireless clone can't be assigned to new interface (NanoBSD)
Configuring a wireless clone works, but after you try to assign that clone to say interface OPT2 pfSense automaticall... James Lepthien
03:34 PM Bug #485 (Resolved): fake start with status_services.php and installed packages
Chris Buechler
03:33 PM Bug #975: CARP / vip interface disappears on slave after interface change
Rob, is this fixed on the latest snapshot? Chris Buechler
03:32 PM Bug #996 (Resolved): DHCP address not pulled with spoofed MAC address on WAN
Chris Buechler
03:32 PM Bug #1047 (Resolved): Disable TSO, hardware checksum don't work for unassigned but active interfaces
Interfaces that are unassigned but active (ex: part of a lagg, possibly VLAN parent-only) don't have TSO, hardware ch... Chris Buechler
03:30 PM Todo #703 (Resolved): Checkboxes to disable TSO and LRO
Chris Buechler
03:29 PM Feature #13 (Resolved): wireless page to have option to select transmit and receive antennas
Chris Buechler
03:27 PM Bug #754 (New): hifn driver and AES192 and 256
need to determine if there is a reason this patch in kern/120270 hasn't been committed. Chris Buechler
03:19 PM Bug #777 (Resolved): Edit File wipes out file on save
Chris Buechler
03:15 PM Bug #841: hostapd doesn't work with spoofed MAC (but should be able to)
This is not something that was ever resolved. Either hostapd should be fixed or a workaround should be put in place ... Erik Fonnesbeck
03:08 PM Bug #841 (Resolved): hostapd doesn't work with spoofed MAC (but should be able to)
Chris Buechler
03:15 PM Bug #990 (Resolved): xss in pfsense I was testing beta 4 pfSense-2.0-BETA4-20100902-0947.iso
Chris Buechler
03:15 PM Bug #826 (Resolved): Status > OpenVPN hangs when using TCP w/OpenVPN Int. "any"
Chris Buechler
03:14 PM Bug #302 (Resolved): Shaper wizard remembers values on error, but are disabled
Chris Buechler
03:13 PM Feature #887 (Resolved): Add an option for stricter OpenVPN ssl/tls+user auth checking
Chris Buechler
03:12 PM Feature #762 (Resolved): Display ICMP type on firewall rule list
Chris Buechler
03:11 PM Bug #831 (Resolved): Status -> System logs - > DHCP bug
Chris Buechler
03:10 PM Bug #320 (Resolved): Using special characters (e.g. åäö) in certificate "Descriptive name" breaks entire WebGUI
Chris Buechler
03:07 PM Bug #991 (Resolved): multiple XSS issues
Chris Buechler
03:06 PM Bug #845 (Resolved): Need patch for PR usb/140883
Chris Buechler
02:47 PM Revision 0ba17c67: Ooops add missing or.
Ermal LUÇI
09:51 AM Bug #1037: Openvpn broken when used with LDAPS backend
Try the latest snapshot and see if i got this right this time. Ermal Luçi

11/26/2010

11:06 PM Revision b9bc333b: Increase suhosin maximum memory to avoid this error: ALERT - script tried to increase memory_limit to 268435456 bytes which is above the allowed value (attacker 'REMOTE_ADDR not set', file '/etc/inc/config.inc', line 59)
Scott Ullrich
10:57 PM Revision 990d7c03: Check for pfsense root object name in config.xml as a fallback if the configured name is not found.
Erik Fonnesbeck
09:54 PM Revision befad728: Ticket #1037. Move environment manipulation to the authentication script since escaping slashes is not so easz on dynamic built paths.
Ermal LUÇI
09:35 PM Revision bad29897: No need to go through the array when the key can be tested directly.
Ermal LUÇI
09:26 PM Revision adc96206: Remove temporary hack which spams console during boot.
Ermal LUÇI
08:54 PM Revision 9a7f6731: Use php_uname where possible.
Ermal LUÇI
08:03 PM Revision 7a755156: Do not exec but use php_uname
Ermal LUÇI
12:20 PM Revision cfa62e06: include broadcast address to allow dhcp to work.
Ermal LUÇI
11:02 AM pfSense Packages Bug #1046 (Feedback): pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
Do you have a link to something that mentions specific packages that show issues like this? There are quite a large n... Jim Pingle
05:41 AM pfSense Packages Bug #1046 (Resolved): pfSense 2.0 beta 4 - Amd64: Discrepancy between package files repository and http://www.pfsense.com/packages/pkg_config.8.xml.amd64
As reported recently, several packages have been updated (removing the old ones) at http://files.pfsense.org/packages... Fulvio Scapin

11/25/2010

03:03 PM Bug #1037: Openvpn broken when used with LDAPS backend
There seems to be an escaping problem, with your patch server1.php contains
sed: 2: "s/\/\/<template>/$authm ...":...
Florent Daigniere
06:02 AM Bug #1037 (Feedback): Openvpn broken when used with LDAPS backend
Committed your suggestions to repo.
Thank you.
Ermal Luçi
12:31 PM Revision 979c816c: Do not guess the defaultgw this is static info.
Ermal LUÇI
12:29 PM Revision a980df9c: Resolves #1040. Fix dynamic addition of gateways from routes edit screen.
Ermal LUÇI
11:57 AM Revision e1b17c7a: Ticket #1037. Add suggestion in the ticket for using the CA supplied to openvpn for authenticating to SSL LDAP.
Ermal LUÇI
11:11 AM Revision 02d7e4a4: Resolves #1043. Do not allow limiters in floating rules without direction. It is invalid practice and while the backend skips it the user should be warned.
Ermal LUÇI
06:35 AM Bug #1040 (Feedback): link doesn't work "add a new one."
Applied in changeset commit:"a980df9c1b8e839880295d37f6fba990cb98a30c". Ermal Luçi
06:05 AM Bug #1044 (Closed): Authentication servers in LDAP and TLS mode needs ca certificate
A described in Ticket #1037 for TLS mode the ca certificate should be specified before attempting a connect.
There...
Ermal Luçi
05:20 AM Bug #1043 (Feedback): Inadequate input validation on limiters with floating rules
Applied in changeset commit:"02d7e4a43b6c6e1f8345c7561394305185905b33". Ermal Luçi
01:28 AM Bug #1043 (Resolved): Inadequate input validation on limiters with floating rules
With floating rules, it's possible to create an invalid ruleset by specifying a limiter on a rule without a direction... Chris Buechler

11/24/2010

06:08 PM Revision fedab998: Nuke trailing c/r
Scott Ullrich
06:04 PM Revision 6bd471ee: Nuke trailing c/r
Scott Ullrich
06:03 PM Revision 31c3942c: Set memory to 256M on amd64
Scott Ullrich
04:06 PM Bug #1023 (Resolved): Carp Status Incorrect
Chris Buechler
06:56 AM Bug #1023: Carp Status Incorrect
Tried the snapshot from today and
everything seems Fixed.
Thank You
Martin Klein
03:41 PM Bug #1042 (Resolved): CARP VIP Descriptions incorrect on IPsec/OpenVPN
CARP VIPs in the list for use by IPsec and OpenVPN are shown with the interface name (e.g. VIP22) instead of the CARP... Jim Pingle
03:29 PM Bug #1041 (Resolved): IP Alias VIPs are not available for use by IPsec
IP aliases are not in the drop-down list for use in IPsec, but CARP VIPs are. Both should be usable for IPsec.
(An...
Jim Pingle
03:29 PM Bug #1040: link doesn't work "add a new one."
thought I'd already opened a ticket for this but apparently not. That's been broken for at least 2-3 months, not sure... Chris Buechler
02:37 PM Bug #1040 (Resolved): link doesn't work "add a new one."
In system_routes_edit.php Choose which gateway this route applies to or add a new one.
Maybe just remove it. I can...
Perry Mason
12:56 PM Bug #1039 (Resolved): Error on Syncronisation slave - DIOCADDRULE: Device busy
On 10 - 30 % of config synchronisations to a slave machine we
get a notification from the slave:
There were erro...
Martin Klein
12:32 PM Bug #1038 (Resolved): System Tuneables net.inet.carp.log not Working
We are running a carp failover bundle in the same network with a
vrrp router pair and therefore we get a lot of unn...
Martin Klein
11:49 AM Bug #1037 (Resolved): Openvpn broken when used with LDAPS backend
The connection to LDAP fails if SSL is used
To get it to work, I had to add the following to /var/etc/openvpn/serv...
Florent Daigniere
10:42 AM Revision e46616a7: Fix text for the P1 table header.
Erik Fonnesbeck
03:30 AM Feature #702 (Feedback): Page with status for "Traffic Shaper: Limiter"
There is one on new snapshots under diagnostics Ermal Luçi
12:55 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
> Can you try with a new snapshot i committed fix to retry resolving 3 times before bailing.
Will do ... but with ...
Jeppe Oland

11/23/2010

11:54 PM Revision 7fd51c68: Add st and si options
Scott Ullrich
10:54 PM Revision 79992f17: Rename to pfInfo for consistency
Scott Ullrich
10:48 PM Revision 9242ba15: Adding Diagnostics: Limiter
Scott Ullrich
10:41 PM Revision b3584478: Increase setTimeout
Scott Ullrich
10:37 PM Revision 438d04f6: Adding Diagnostics: pf Info which shows the output of pfctl -vvi and pfctl -vvI via AJAX
Scott Ullrich
10:01 PM Revision 004b1e69: Cleanup code and fix dynamic firewall log reverse view, fixes #1031
Jim Pingle
06:54 PM Revision d9114ce0: Ensure returned item is an array.
Scott Ullrich
06:52 PM Revision 19f101d7: Return CARP IP Addresses in get_configured_ip_addresses()
Scott Ullrich
05:05 PM Bug #1031 (Feedback): Firewall Log - Dynamic Update update only first row
Applied in changeset commit:"004b1e6998c7e36fa3a4ba64c910b626946decfa". Jim Pingle
12:47 PM Bug #1031: Firewall Log - Dynamic Update update only first row
Yes i do, reverse order is enabled. Francisco Brasileiro
04:58 PM Revision bafe2769: Remove this since it does not make anymore sense after code arrangements.
Ermal LUÇI
04:57 PM Revision a0b205f0: Do not output done. because it does not related overall to the output messages.
Ermal LUÇI
12:58 PM Revision 2bfade90: Initialize variable. Ticket #1023.
Ermal LUÇI
12:57 PM Revision 4ed5ad5a: Ticket #1023. Correct carp status even on the status page.
Ermal LUÇI
12:47 PM Revision 108cfddf: Ticket #1023. Correct the widget code bringing it full speed with latest carp code.
Ermal LUÇI
11:33 AM Revision 83ae8103: Try 3 times to resolve the host to ip before giving up. Leave a proper log if we fail to resolve. Ticket #943.
Ermal LUÇI
11:32 AM Revision 51d0f816: Use full path to command binaries.
Ermal LUÇI
11:27 AM pfSense Packages Bug #1033 (Resolved): Please start bandwidthd to populate this directory
Chris Buechler
11:21 AM pfSense Packages Bug #1033: Please start bandwidthd to populate this directory
Bandwidthd is runing when I reloading firefox. Thank you for your help from my bottom heart.
samuel tang
09:52 AM pfSense Packages Bug #1033: Please start bandwidthd to populate this directory
I uninstalled and reinstalled, then started bandwidthd again, and it collected data properly. Are you checking "draw ... Jim Pingle
09:42 AM pfSense Packages Bug #1033: Please start bandwidthd to populate this directory
my pc is i386.
according to your suggesting: uninstall package and reinstall it. I checked status >status see the ...
samuel tang
09:45 AM pfSense Packages Bug #679: HAVP error message shows up behind top menu.
Lars Hupfeldt Nielsen wrote:
> Yes, I'm using NanoBSD, on Alix boards. There are no fields for build/platform detail...
Serg Dvoriancev
09:42 AM pfSense Packages Bug #669: HAVP does not remove "Antivirus" menu point when de-installed.
Ermal Luçi wrote:
> Possibly fixed with latest package improvements.
I've had in recent days a lot installations of...
Serg Dvoriancev
08:31 AM Bug #1034 (Closed): timezone settings not working in smtp notifications
I have two pfsense installations *2.0-BETA4 (i386) built on Sun Nov 14 17:23:12 EST 2010*
which both have the follo...
Fabian Schmidt
06:51 AM Bug #1023 (Feedback): Carp Status Incorrect
Ermal Luçi
05:39 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
@Jeppe Oland
can you try with a new snapshot i committed fix to retry resolving 3 times before bailing.
@Hugo ple...
Ermal Luçi
04:42 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Same problem. Dyndns(dynamic) only updates when saving.
No wildcards
Full new install no config restore.
ADSL(op...
Hugo Sousa

11/22/2010

11:18 PM Bug #840 (Resolved): RRD scripts not collecting new data into the RRD
yeah this was fixed long ago Chris Buechler
05:14 PM Bug #840: RRD scripts not collecting new data into the RRD
This seems to work fine and has done for a wail. Jonathan Bastin
10:56 PM Bug #1031: Firewall Log - Dynamic Update update only first row
Looks like this only happens with the logs in reverse order. Forward order works fine. Jim Pingle
09:07 PM Bug #1031: Firewall Log - Dynamic Update update only first row
Do you have your logs set for forward or reverse order? (i.e. is the newest entry at the top or the bottom) Jim Pingle
09:59 AM Bug #1031 (Resolved): Firewall Log - Dynamic Update update only first row
When use Dynamic Update on Status -> System Logs -> Firewall -> Dynamic View only the first row is updated.
Curren...
Francisco Brasileiro
08:01 PM pfSense Packages Bug #1033 (Feedback): Please start bandwidthd to populate this directory
Uninstall the package and then reinstall it. I fixed quite a few dependencies on it this afternoon. It started OK whe... Jim Pingle
07:50 PM pfSense Packages Bug #1033 (Resolved): Please start bandwidthd to populate this directory
built on Mon Nov 22 02:17:54 EST 2010
bandwidthd can not run
samuel tang
06:38 PM Revision a2b6c52f: Add option to control automatic creation of NAT rules which assist forwarding rules that send traffic out to the same subnet it originated from.
Erik Fonnesbeck
04:55 PM Feature #1032: Add all interfaces to Packet Capture drop-down
Anything valid for tcpdump. So perhaps not lo0, carp, or other interfaces from which a packet capture would not work ... Jim Pingle
04:24 PM Feature #1032: Add all interfaces to Packet Capture drop-down
Do you mean all interfaces from returned by ifconfig ?
Pierre POMES
03:18 PM Feature #1032: Add all interfaces to Packet Capture drop-down
Even better. :-) Jim Pingle
03:15 PM Feature #1032: Add all interfaces to Packet Capture drop-down
Changed to all interfaces, there are a number of scenarios in addition to OpenVPN where that capability would be help... Chris Buechler
02:55 PM Feature #1032 (Resolved): Add all interfaces to Packet Capture drop-down
It would be handy if all interfaces were available as targets for packet capture even without being assigned. Jim Pingle
04:23 PM Revision bddcbff2: When adding/editing a gateway, check IP alias subnets, too. Fixes #1015
Erik Fonnesbeck
03:53 PM Revision d48dbceb: Add other interfaces to local network selection and show proper names. Fixes #965
Erik Fonnesbeck
02:32 PM Revision e63d59c0: Do not save settings related to ports when protocol does not use ports. Ticket #953
Erik Fonnesbeck
01:39 PM Revision ae46e8b8: Do not save fields from translation section when "Do not NAT" is checked. Ticket #952
Erik Fonnesbeck
12:27 PM Revision 4389352c: In filter_generate_reflection_nat, generate a rule with the actual subnet instead of using the interface:network shortcut. Ticket #737
Erik Fonnesbeck
11:35 AM Bug #1015 (Feedback): Gateways IP subnet check needs to check IP aliases
Applied in changeset commit:"bddcbff2742d2855aa47b7af551aee11410183ca". Erik Fonnesbeck
11:05 AM Bug #965 (Feedback): IPSec configuration network selection doesn't match rest of UI
Applied in changeset commit:"d48dbceb9570a322e0ce8a7200847eeddfac22f9". Erik Fonnesbeck
09:47 AM Feature #953: On outbound NAT rule edit, hide ports when protocol does not use ports.
Should be fixed now. Erik Fonnesbeck
08:06 AM Feature #953: On outbound NAT rule edit, hide ports when protocol does not use ports.
This should probably leave out the port fields when saving when not set to a protocol that uses them. Erik Fonnesbeck
09:00 AM Feature #737: Make 1:1 NAT Reflection's NAT rule generation work for more setups
This thing is wrong because it slows down filter reload and things depends on it being snappy.
There is not justaf...
Ermal Luçi
07:45 AM Feature #737 (Feedback): Make 1:1 NAT Reflection's NAT rule generation work for more setups
Erik Fonnesbeck
07:45 AM Feature #737: Make 1:1 NAT Reflection's NAT rule generation work for more setups
Looking back at this, I didn't really write up a very good description of it. Anyway, it should work for a wider ran... Erik Fonnesbeck
08:42 AM Feature #952: When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
Should be fixed now. Erik Fonnesbeck
08:05 AM Feature #952: When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
This should probably not be saving the fields in the translation section when do not nat is checked. Erik Fonnesbeck
08:33 AM Revision 1452fa57: Use correct names for integer and boolean types in DHCP options and fix typo in hexadecimal validation for strings. Fixes #962
Erik Fonnesbeck
05:23 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
I am seeing the same problem on a clean boot of pfSense-2.0-BETA4-20101120-0520.iso - well a clean install followed b... Jeppe Oland
03:35 AM Bug #962 (Feedback): DHCP custom options must have type selection
Applied in changeset commit:"1452fa5788f6fd0cf73d957955b8bfeeac127541". Erik Fonnesbeck
02:28 AM Bug #962 (New): DHCP custom options must have type selection
One issue with this on the integers. It's putting int8, int16, uint8, etc. into dhcpd.conf file which is invalid synt... Chris Buechler
03:16 AM Bug #1030 (Closed): Interface case change in apinger.conf needs reverted
Interfaces are showing in upper case in apinger's conf now, splitting the RRDs into two different graphs. Unknown imp... Chris Buechler
02:51 AM Feature #1029 (Rejected): Add more native way to connect on WAN via DHCP+PPTP/L2TP
Please don't duplicate tickets. original is #624. It doesn't have a target version because we don't have plans of imp... Chris Buechler
02:45 AM Feature #1029 (Rejected): Add more native way to connect on WAN via DHCP+PPTP/L2TP
In some countries the connection to ISP works like this: A computer(pfsense in this case) takes an IP from the modem ... Lenny V.

11/21/2010

10:40 PM Revision b3a4ff7c: Add newlines
Scott Ullrich
09:26 PM Revision 279f4da8: nuke ;
Scott Ullrich
09:22 PM Revision 558dda01: Remove hw.bce.tso_enable item it is loader.conf only per jimp
Scott Ullrich
09:21 PM Revision f41b7bdf: Remove bce item it is loader.conf only per jimp
Scott Ullrich
09:20 PM Revision fb182cb2: Define hw.bce.tso_enable
Scott Ullrich
06:00 PM Bug #836: Captive portal logout popup windows doesn't disconnect the user
Could you explain what you mean in more detail? In particular, which page do you mean when you say "the logged in ov... Erik Fonnesbeck
05:56 PM Bug #836: Captive portal logout popup windows doesn't disconnect the user
Does NOT work actually. The user still remains at the logged in overview! L J
05:36 PM Revision ed32aef7: Don't consider the HTTP referrer check as passing if it was skipped. Ticket #1027
Erik Fonnesbeck
05:23 PM Revision 0f806eca: Upon restoring a config, replacing whole sections, or editing config.xml in edit.php, prevent possible accidental lockout from DNS rebind and HTTP referrer checks by disabling them until reboot or the next time they pass, whichever comes sooner. Ticket #1027
Erik Fonnesbeck
12:47 PM Bug #1027 (Feedback): Config restore triggers HTTP_REFERER check on interface mismatch
This workaround should prevent that from happening now. Erik Fonnesbeck
06:26 AM Bug #1027: Config restore triggers HTTP_REFERER check on interface mismatch
This also needs to be tested restoring a configuration that changes the host or domain, because that might trigger th... Erik Fonnesbeck

11/20/2010

11:15 PM Bug #560: loader.conf is empty after a firmware update.
I believe it still is, as a VM I keep updated has an empty loader.conf when it should the default entries.
It's a di...
Jim Pingle
10:54 PM Bug #560: loader.conf is empty after a firmware update.
Is this still an issue on full installs? Note that there is a separate ticket for this on nanobsd. Erik Fonnesbeck
11:07 PM Feature #953 (Resolved): On outbound NAT rule edit, hide ports when protocol does not use ports.
Chris Buechler
11:02 PM Feature #953: On outbound NAT rule edit, hide ports when protocol does not use ports.
2.0-BETA4 (i386)built on Sat Nov 20 05:54:55 EST 2010 using Firefox.
Testing Firewall/NAT/Outbound Add a mappin...
Chris Palmer
10:35 PM Feature #952: When "Do not NAT" is checked on outbound rule, the translation section should be hidden.
2.0-BETA4 (i386)built on Sat Nov 20 05:54:55 EST 2010
When "Do not NAT" is checked on an outbound NAT rule, the ...
Chris Palmer
09:53 PM Bug #955 (Resolved): Static IP gateway does not upgrade from 1.2.x to 2.0
That looks good, thanks for the extra detail. Jim Pingle
09:37 PM Bug #955: Static IP gateway does not upgrade from 1.2.x to 2.0

That page shows
Name Interface Gateway Monitor IP Description
GW_WAN (default) WAN 172...
Chris Palmer
09:23 PM Bug #955 (Feedback): Static IP gateway does not upgrade from 1.2.x to 2.0
The <gateway> tag under <wan> should _not_ be there with an IP post-upgrade, you should only have a gateway entry und... Jim Pingle
09:01 PM Bug #955 (Resolved): Static IP gateway does not upgrade from 1.2.x to 2.0
Chris Buechler
08:55 PM Bug #955: Static IP gateway does not upgrade from 1.2.x to 2.0
Setup 1.2.3 release on my test box today using a static wan address.
Let it update via Firmware/Auto Update to 2.0...
Chris Palmer
09:37 PM Bug #1012 (Resolved): DHCP Setting error
Chris Buechler
09:29 PM Bug #1012: DHCP Setting error

Ver. 2.0-BETA4 (i386)built on Sat Nov 20 05:54:55 EST 2010
I made multiple changes to my dhcp server on the LAN,...
Chris Palmer
07:42 PM Revision 2b8bdfe4: Add missing </item>
Scott Ullrich
07:40 PM Revision 24352196: oops, typo
Scott Ullrich
07:40 PM Revision feae85bc: Increase vfs.read_max to 32. See http://ivoras.sharanet.org/blog/tree/2010-11-19.ufs-read-ahead.html .. This can help dramatically if using Squid or any other packae that does a lot of hard disk reads.
Scott Ullrich
01:36 PM Bug #1028 (Closed): filter.inc - discover_pkg_rules
Chris Buechler
01:29 PM Bug #1028: filter.inc - discover_pkg_rules
Hmm.. sorry
I found my error in rules.
Task can be closed.
Serg Dvoriancev
12:32 PM Bug #1028 (Closed): filter.inc - discover_pkg_rules
filter.inc
Function discover_pkg_rules
Symptoms:
Errors in syslog
check_reload_status: syncing firewall
php: ...
Serg Dvoriancev
05:19 AM Revision c049daef: Disable this test, it was causing some package file downloads to be skipped for me, and nothing else seems to set/use this variable anywhere.
Jim Pingle
12:17 AM Feature #1020: Provide HTTP basic auth additional authentication option
Note I can't imagine this ever getting any consideration short of someone funding it or contributing the code. Chris Buechler
12:13 AM Feature #1020 (New): Provide HTTP basic auth additional authentication option
While not legit for reasons of obfuscating what you're running (almost every single commercial vendor does similar an... Chris Buechler
 

Also available in: Atom