Project

General

Profile

Activity

From 01/19/2011 to 02/17/2011

02/17/2011

07:45 PM Revision 94d455da: Enforce FreeBSD's max username length of 16 chars. http://forum.pfsense.org/index.php/topic,33410.0.html
Jim Pingle
05:54 PM Revision 70edf50d: Fix whitespace formatting.
Jim Pingle
05:35 PM Revision 98776e04: Allow sorting of DNS forwarder entries.
Jim Pingle
01:05 PM Bug #1284: Syslog does not work with CLOG disabled
Maybe I found the problem.
On system boot, it checks if disablesyslogclog tag exists on config.xml, then create re...
Vinícius Coque
07:31 AM Feature #1225 (Closed): static port range and outbound rules source port range (only to be tested and integrated, already coded)
Jim Pingle
02:39 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
I can't find how to close the task myself, so if someone could tell me how to (if I can!) or could close it... Martin Dupont
02:36 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
This is rendered useless by support of port alias. No need to implement this anymore. Martin Dupont
04:07 AM Bug #1291 (Closed): Inner VPN Roadwarrior IPSEC in Tunnel VPN IPSEC not working with Firewall Scrub enabled
Running 2.0-BEAT5 (i386) built on Tue Feb 15 16:36:07 EST 2011.
WAN is an xl0 ethernet card, LAN is a sge0 ethernet ...
Davide B
02:20 AM Bug #1290 (Closed): IPsec roadwarrior use case: Traffic from LAN does not hit established tunnel
Hello.
Remote Access IPsec client (Shrew) connecting to pfSense firewall terminating the IPsec connection does not...
Tero Mononen
01:33 AM Bug #1289 (Resolved): IPsec mobile remote access (roadwarrior) responder (server) configuration
Hello.
IPsec mobile client configuration (Hybrid XAuth Server) does not put 'passive on' directive into racoon.con...
Tero Mononen

02/16/2011

10:07 PM Bug #1221 (Resolved): igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Chris Buechler
09:48 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Been testing hw.igb.num_queues="4" for the last week and so far it seems to be working with no problems so far with H... R M
09:40 PM Revision 8e559859: Minor english fixes from Bill
Scott Ullrich
09:39 PM Revision ccca3418: Merge remote branch 'upstream/master'
Scott Ullrich
09:22 PM Revision 0aba3822: Add IPsec and OpenVPN to packet capture. Ticket #1032
Jim Pingle
09:16 PM Bug #1288: Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
Update to reference this forum thread where a similar (though single lan) issue appears to be affecting another test ... brandon b
09:12 PM Bug #1288 (Resolved): Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
My test box has 3 total interfaces, all of which are properly connected to physical interfaces and function on their ... brandon b
08:32 PM Revision 3395ba20: Fix wording
Jim Pingle
07:33 PM Bug #1287 (Closed): CARP VIP sync sends incorrect interface
OK. I'll close this out. Feel free to post on the forums to see if anyone else has hit any similar VLAN issues. Jim Pingle
06:46 PM Bug #1287: CARP VIP sync sends incorrect interface
Yep, that's the issue, thanks Jim. I'm still having some trouble with the VLAN(s) passing traffic after failing over ... Mike McLaughlin
06:18 PM Bug #1287 (Feedback): CARP VIP sync sends incorrect interface
Check your config.xml on both - for CARP sync to function correctly the interfaces must exist on both units and they ... Jim Pingle
06:10 PM Bug #1287 (Closed): CARP VIP sync sends incorrect interface
When the CARP VIPs are set to sync from Master to Backup under the CARP Settings it immediately adds new VIPs to the ... Mike McLaughlin
06:53 PM Revision a8f9f07e: Comment out the "config write on bootup" error. This is normal now with the package reinstall, and the known issues with it should be OK now. The error is just confusing people.
Jim Pingle
06:19 PM Revision a3bac4ce: Do not rely on php new foreach by reference and use the old method of chaning array members by using full path. This fixes nat 1:1 upgrades.
Ermal LUÇI
06:04 PM Revision ed187b41: Change this form to a POST instead of using GET with button inputs. For some reason using the GET method was causing things to be invoked twice, which led to two concurrent XMLRPC syncs, which can cause issues.
Jim Pingle
05:15 PM Revision 72377228: Add automatic rules to pass DHCP failover traffic if a failover peer is defined. See http://forum.pfsense.org/index.php/topic,32731.msg172839.html#msg172839
Jim Pingle
04:31 PM Revision 3e8b3ccc: Use a better regex here, sometimes ad devices can be numbered >=10.
Jim Pingle
03:53 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
R B wrote:
> Unfortunately I disagree - still not seeing DDNS update on a clean install of the NanoBSD images as not...
M Schweitzer
11:50 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Unfortunately I disagree - still not seeing DDNS update on a clean install of the NanoBSD images as noted in comment ... R B
02:45 PM pfSense Packages Bug #1084: nmap package libpcap errors
Reinstall the package again, it should be OK now. Jim Pingle
02:47 AM pfSense Packages Bug #1084: nmap package libpcap errors
This error is back in 2.0-RC1
/libexec/ld-elf.so.1: Shared object "libpcap.so.1" not found, required by "nmap"
...
Ralf Wessling
01:07 PM Revision 2d816c13: silence the music.
Jim Pingle
08:11 AM Revision f698b262: Merge remote branch 'upstream/master'
Seth Mos
06:30 AM Feature #1286 (Closed): Captive Portal sends WAN IP instead of Mac or custom string in "called-station-id" RADIUS attribute
The Captive Portal is sending the WAN IP in the RADIUS "called-station-id" attribute.
It has been mentioned before i...
Mark Dammer
03:48 AM Bug #1053: CBQ per se, in kernel
any update on this? Bipin Chandra
02:50 AM pfSense Packages Bug #1285 (Closed): NTOP error in 2.0 RC-1
I installed the nmap package and when I go to Diagnostics -> NMap, I'm redirected to the dashboard page. When I run n... Ralf Wessling

02/15/2011

10:59 PM Revision b807a161: Break on 'You can also monitor the reload progress' instead of letting it wrap into a newline.
Scott Ullrich
08:16 PM Revision c10dbf92: Add snort2c table back in for now.
Jim Pingle
04:03 PM Revision efe8fa78: Pass $notices to print_notices(), since it requires a parameter.
Jim Pingle
12:03 PM Bug #1284 (Resolved): Syslog does not work with CLOG disabled
I put the tag disablesyslogclog on my config.xml to disable clog, since I have free disk space and want to keep all l... Vinícius Coque
10:15 AM Bug #1280 (Resolved): DHCP range validation is wrong then adding static mapping
Jim Pingle
10:02 AM Bug #1280: DHCP range validation is wrong then adding static mapping
Sorry, verified with 2.0-RC1 (i386) built on Mon Feb 14 03:24:30 EST 2011 rancor rancor
10:01 AM Bug #1280: DHCP range validation is wrong then adding static mapping
This issue has been solved.
My DHCP range is 192.168.10.10 to 192.168.10.199
Static mapping to:
192.168.10.9 -...
rancor rancor
08:40 AM Bug #754: hifn driver and AES192 and 256
I did the test with and without glxsb activated. There was no difference in the results.
Could it be that the hifn...
A B
07:42 AM Bug #754: hifn driver and AES192 and 256
F S wrote:
> Test System: alix 2d2 + vpn1411 card.
> Beta Version: pfSense-2.0-RC1-4g-i386-20110214-0324
>
> see...
Jim Pingle
03:20 AM Bug #754: hifn driver and AES192 and 256
Test System: alix 2d2 + vpn1411 card.
Beta Version: pfSense-2.0-RC1-4g-i386-20110214-0324
seems like the vpn card...
F S
02:18 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
I think this can be closed now...
I've been testing it for about Two weeks and it works fine.
M Schweitzer

02/14/2011

09:57 PM Revision ee21b736: Adding support for snortsam from Robert Z
Scott Ullrich
09:27 PM Revision bd40781a: add a ipprotocol variable to the easy add rules
Seth Mos
07:04 PM Bug #1283 (Resolved): Wording in script for configuring interfaces
In pfSense-2.0-beta5-20110210 there are a few sentences in the script for initially configuring interfaces that are w... Vaughan Chandler
03:08 PM Revision ad67f6af: Back to beta5
Scott Ullrich
02:15 PM Bug #1282: Default drop policy should log?
I do not agree and I do have logging on by default on block
I have 3 interfaces, WAN, LAN and DMZ
I added one ...
rancor rancor
01:08 PM Bug #1282 (Rejected): Default drop policy should log?
It already does log:... Jim Pingle
01:05 PM Bug #1282 (Rejected): Default drop policy should log?
I have spent hours of debug different network configurations and VPN configurations (IPsec and OpenVPN) just to find ... rancor rancor
11:09 AM Bug #1281 (Closed): "Easy Rule: Pass this traffic" applies to phy. device and not VLAN device with name LAN
Ideally you shouldn't have the parent interface of VLANs assigned. If you use VLANs on a physical interface, anything... Jim Pingle
10:05 AM Bug #1281 (Closed): "Easy Rule: Pass this traffic" applies to phy. device and not VLAN device with name LAN
I setup a alix 2d2 box for some pfSense 2.0RC1 tests. Used image is pfSense-2.0-RC1-4g-i386-20110214-0324-nanobsd-upg... A B
09:36 AM Bug #754: hifn driver and AES192 and 256
I did a test with my alix 2d2 box and a vpn1411 card.
Here are the results with the fresh updated image (pfSense-2...
A B
06:27 AM Bug #475: L2TP is not functional in the way users will expect
Another helpful link
http://kuapp.com/2010/07/14/how-to-setup-l2tpipsec-vpn-on-freebsd.html
Ermal Luçi
12:19 AM Revision 49e4ebf8: Fix start/end test for an IP in DHCP pool. Resolves #1280
Jim Pingle

02/13/2011

09:54 PM Revision b5993a02: Fix update check fix. Skipped a parameter.
Jim Pingle
08:21 PM Bug #836 (Resolved): Captive portal logout popup windows doesn't disconnect the user
thanks. I also confirmed this a few days ago Chris Buechler
08:10 PM Bug #836: Captive portal logout popup windows doesn't disconnect the user
Ermal Luçi wrote:
> Patch committed please test.
I can verify pfSense 2.0 beta 5
When I first start to surf fr...
rancor rancor
07:20 PM Bug #1280 (Feedback): DHCP range validation is wrong then adding static mapping
Applied in changeset commit:"49e4ebf8348d32e0ecc2dc7f9dc9d1d113c765ca". Jim Pingle
07:15 PM Bug #1280 (Resolved): DHCP range validation is wrong then adding static mapping
I'm using pfSense 2.0 beta5
DHCP range is 192.168.10.10 to 192.168.10.200
Static mapping to:
IP 192.168.10.201...
rancor rancor
06:11 PM Revision a42e5d25: Get ready for tomorrow.
Scott Ullrich
04:37 PM Revision 4c37209a: Suppress curl errors (if we get a 404 it tosses its own error if there is no response body, just a 404 code.)
Jim Pingle
04:27 PM Revision ca640261: Add alias support for source and destination ports on outbound NAT.
Erik Fonnesbeck
04:14 PM Revision d164643a: Make update check a little more robust. Timeout after a few seconds, and if we get a non-200 http code, ignore the response.
Jim Pingle
03:08 PM Revision b43b7613: Check for aliases in 1:1 and outbound NAT rules, too.
Erik Fonnesbeck
02:44 PM Revision 43f2eca7: Use autocomplete='off' like all other fields that accept aliases, to prevent web browser auto-complete from covering up the alias list popup.
Erik Fonnesbeck
02:25 PM Revision c769f983: Simply code for determining whether an alias is currently in use.
Erik Fonnesbeck
01:44 PM Revision f1ac1733: In update_alias_names_upon_change function add capability to access more deeply nested sections and fields.
Erik Fonnesbeck
12:38 PM Revision b0aa7413: Use alias style and add AutoSuggestControl for source and destination address fields.
Erik Fonnesbeck
08:15 AM Revision 97bc0bcc: The doubled "$rule = array();" lines are probably a copy/paste error. Probably meant to paste the line that sets the rule type to the match action like the rest of what was added in the affected commit.
Erik Fonnesbeck

02/12/2011

09:07 PM Revision bd259571: Correctly verify the input on bandwith at voip step for traffic shaper wizards. Reported-by: http://forum.pfsense.org/index.php/topic,32833.0.html
Ermal LUÇI
06:34 PM Revision bd2b98c9: Remove any previous file with the same name as the one that will be downloaded. This avoid the gui to always show update availble even though the site could not be reached.
Ermal LUÇI
06:33 PM Revision 5ee6a457: Remove any previous file with the same name as the one that will be downloaded. This avoid the gui to always show update availble even though the site could not be reached.
Ermal LUÇI
06:31 AM Revision ac5eb23b: Catch up
Scott Ullrich

02/11/2011

05:32 PM Revision b3205cc3: Convert the shapers to the match action so the generated rules do not impact the filtering policy implemented.
Ermal LUÇI
05:26 PM Revision a391d0ab: Allow match action on Floating rules and exposed it with name Queue. More validation is needed.
Ermal LUÇI
05:18 PM Revision a39c7dae: Allow action match to be passed down to pf.
Ermal LUÇI
05:14 PM Bug #754 (Feedback): hifn driver and AES192 and 256
This has been committed to repo.
Please test.
Ermal Luçi
11:40 AM Revision b8452906: BP: fix syntax error on gettext implementation
Vinicius Coque
08:55 AM Bug #1279 (Resolved): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
It should be read only by the end of the boot process, but it doesn't seem to be making that change when packages wer... Jim Pingle
08:28 AM Bug #1278 (Resolved): log when captive portal restarts
Hi,
When captive portal is reconfigured, it restarts and disconnects all clients. We have a message on the service...
Thomas NOEL
08:28 AM Revision d6109468: Delay resolving dynamic DNS tunnels during boot
Seth Mos
08:14 AM Bug #1121: wireless interface antenna settings not applied at boot
/tmp/ath0_wlan0_setup.sh has the below
/sbin/sysctl dev.ath.0.diversity='0'
/sbin/sysctl dev.ath.0.txantenna='1'
...
Bipin Chandra
08:13 AM Revision 1d564143: Merge remote branch 'upstream/master'
Seth Mos
08:09 AM Revision 07dfd121: Add a IPv6 enable option in the mpd5 config
Seth Mos
07:33 AM Bug #769 (Resolved): OpenVPN interface assignment on upgrade
Ermal Luçi
07:31 AM Bug #1276 (Closed): Packet capture for wireshark desn't work
If it does not work and you want the max length please put a 0 in there instead of 65k. Ermal Luçi
05:08 AM Bug #1276 (Closed): Packet capture for wireshark desn't work
When the packet size is set to 65535, the form reset the value and the import in wireshark doesn't work. Xavier MORTELETTE
07:25 AM Bug #906: Orphaned rules from deleted interfaces are still present in config
This was a bug which is fixed.
There is no magic autofix for this rather than telling people to clean their config.
...
Ermal Luçi
07:25 AM Revision d0399410: Do not resolve the dyndns hostnames during boot. With many tunnels that have a hostname this can
cause huge boot issues if the DNS server is slow or not responding at all. By skipping those but
adding them to the D...
Seth Mos
07:22 AM Bug #475: L2TP is not functional in the way users will expect
This cannot be achived in 2.0 timeframe. Ermal Luçi
07:22 AM Bug #1224 (Resolved): Changing Aliasnames for Ports are not reflected in Rules
Ermal Luçi
07:21 AM Bug #1207 (Resolved): Renaming a limiter creates new limiter
Ermal Luçi
07:20 AM Bug #1208 (Closed): Limiters don't work on non-quick rules
This is more a confusion between what a non-quick rule can match or not rather than it does not work.
Its not a bug ...
Ermal Luçi
05:16 AM Bug #1277 (Resolved): Rip propagation
When the rip is activate, and set to Ripv2 with password, all interface broadcast a RIPv1 response. Xavier MORTELETTE
04:19 AM Bug #1273 (Resolved): bugs if pfs_version_compare
Ermal Luçi
01:10 AM Revision 554d3bc2: fix text
Chris Buechler

02/10/2011

11:58 PM pfSense Packages Bug #585: Unable to start the ntop service
I hate being an utter n00b, but how does one attempt to install the various missing packages? I would love to get n... Joshua Schmidlkofer
09:52 PM Bug #1275: Web management GUI; "Help" menu wraps around, and blocks access to "System" menu.
That's true of all browsers, you'll have to use one of the alternate themes that lists the menus down the left side o... Chris Buechler
09:49 PM Bug #1275 (Closed): Web management GUI; "Help" menu wraps around, and blocks access to "System" menu.
See attached screenshot.
I have my web browser set up to use a slightly larger font size, due to limited eyesight....
Anonymous
09:36 PM Revision e35d6cda: There is no need to call the script to reconfigure CP here. Even more when it breaks all kind of things.
Ermal LUÇI
09:11 PM Bug #1256 (Resolved): DPD does not work in ipsec-tools 0.7.3
confirmed fixed in latest snapshots.
Chris Buechler
04:16 PM Revision 8c5df705: Also fix easyrule and auto->manual nat switch code. Ticket #1243
Jim Pingle
03:58 PM Revision 93c2c1e6: Generalize pppoe server enabled check and use it elsewhere in the GUI that needed fixed. Still needs changes in filter.inc - Ticket #1243
Jim Pingle
03:08 PM Revision 2c1b25d6: Merge remote branch 'upstream/master'
Seth Mos
03:05 PM Revision 9103d9ee: Fix static routes, typo in the variable name
Seth Mos
02:44 PM Revision 0fc6be3f: Allow autocomplete on login form (Fixes saving password on Firefox and Chrome)
Jim Pingle
02:04 PM Revision b6a1d960: Add the 1.2.3 dashboard package's /usr/local/www/filter_log.inc to the obsoleted files list. (It's in /etc/inc/ now)
Jim Pingle
01:34 PM Revision bda131b2: Fix a date compare bug, resolves #1273
Jim Pingle
12:19 PM Bug #1271: My VPN (openvpn + Ldap) still broken
Tradução do português para inglês
But with this bug but
includes the export script on the client side command po...
Joaquim Soares Soares
11:21 AM Bug #1243: GUI/Backend code needs updated after multi-PPPoE-server code switch
Ermal said he'd have a look at the filter.inc part when he gets a chance. Every other reference to the old style conf... Jim Pingle
11:00 AM Bug #1243 (New): GUI/Backend code needs updated after multi-PPPoE-server code switch
I fixed the places in the GUI that you saw (in a more general way) but the filter.inc changes need more care. What yo... Jim Pingle
11:20 AM Bug #1208: Limiters don't work on non-quick rules
Well it depends. If they match the rule than they work otherwise they don't.
I think i should teach the match rules e...
Ermal Luçi
10:18 AM Revision 6715c2a2: Fix the IP address check to allow for interfaces that just have a IPv6 address but no IPv4
Seth Mos
08:35 AM Bug #1273 (Feedback): bugs if pfs_version_compare
Applied in changeset commit:"bda131b275f0761f15533da8dc633a4c0a452bf2". Jim Pingle
08:33 AM Bug #1273: bugs if pfs_version_compare
Committed, thanks! Jim Pingle
08:21 AM Bug #1273 (Resolved): bugs if pfs_version_compare
There are two bugs in functions which compare pfSense versions.
It doesn't work when update version is older than th...
Thomas NOEL
07:15 AM Bug #1154: Kernel panic after connecting to OpenVPN
Peter Overtoom wrote:
> I don't know when it's supposed to be fixed but when trying yesterday on a fresh 1.2.3 insta...
Jim Pingle
05:26 AM Bug #1154: Kernel panic after connecting to OpenVPN
I don't know when it's supposed to be fixed but when trying yesterday on a fresh 1.2.3 install with openvm tools, I s... Peter O
04:12 AM Bug #1154 (Closed): Kernel panic after connecting to OpenVPN
This is cause from mbuf tag patch and for 2.0 this is fixed.
I will close it since it is not anymore relevant.
Ermal Luçi
05:56 AM Bug #1221 (Feedback): igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
This is a tunable that can be recommended as a workaround or ship by default!
hw.igb.num_queues
Ermal Luçi

02/09/2011

11:05 PM pfSense Packages Bug #1272 (Closed): AXFR Zone transfers not working in v2 Beta5
This bug seems to have been previously cleared (refer bug issue 119) however as of 10 Feb, it's present when using pf... Peter Atkinson
10:06 PM Revision 30ef6f8d: Allow renaming even shaper queues as an improvement.
Ermal LUÇI
09:52 PM Revision 50124de1: Check if this is an array first, just in case.
Jim Pingle
09:41 PM Revision 1cbe86f0: Fixes #1207. Allow renaming a limiter. Also prevent a limiter to be deleted if it is referenced in filter rules.
Ermal LUÇI
09:11 PM Revision dabcf28c: Turn off file size check
Scott Ullrich
08:33 PM Revision 652ed95d: Merge remote branch 'upstream/master'
Scott Ullrich
07:13 PM Revision c90ba62d: Fix an issue with dhcp parameters not specifying a defaultgw and the dhcp is the only interface with gateway as a result the box is left wihtout a default gw. Some sporadic reports have been done on this.
Ermal LUÇI
04:40 PM Bug #1207 (Feedback): Renaming a limiter creates new limiter
Applied in changeset commit:"1cbe86f032a6dc1480c5b62d1d9a641a29105bac". Ermal Luçi
04:11 PM Bug #1271 (Rejected): My VPN (openvpn + Ldap) still broken
Please use the forum for support. This isn't a valid bug.
Our OpenVPN doesn't talk to LDAP directly, it uses a scr...
Jim Pingle
03:45 PM Bug #1271 (Rejected): My VPN (openvpn + Ldap) still broken
My VPN (openvpn + Ldap) still broken
I noticed you did not install the operating openvpn-auth-ldap ??? !!!!
I th...
Joaquim Soares Soares
03:41 PM Revision 8b0041e0: Fix typo in the subnetmask for the unblockable icmp types. This makes the all-routers work again
Seth Mos
02:16 PM Bug #757 (Resolved): PPPoE Disconnect button with multiple PPPoE interfaces
Chris Buechler
08:46 AM Bug #757: PPPoE Disconnect button with multiple PPPoE interfaces
I am able to use the disconnect button to stop PPPOE sessions from the Interfaces screen. Thanks. Pho Bia
11:00 AM Bug #1270 (Resolved): bug with captive portal widget
Hi,
Small but annoying bug with the captive portal *widget*.
If I click on the "disconnect" button, the user is...
Thomas NOEL
07:36 AM Bug #1266: now my VPN is broken
Okay, but passtos, was included in the pfsense configuration file client [pfSense-udp-1194-config.ovpn]
If I remov...
Joaquim Soares Soares
01:30 AM Bug #1266 (Rejected): now my VPN is broken
you can't use passtos with Windows hosts, not a bug.
Chris Buechler

02/08/2011

10:28 PM Revision 36d6af43: Resolves #1224. Correctly change name on port alias in firewall rules if the alias name changes.
Ermal LUÇI
05:32 PM Bug #846: if_bridge triggers link state cycling on em(4)
I will close this if no more input comes.
This is only related to how if_bridge works, while it is questionable why ...
Ermal Luçi
05:30 PM Bug #1224 (Feedback): Changing Aliasnames for Ports are not reflected in Rules
Applied in changeset commit:"36d6af4399089ea910befb6e5b29b894ae4c50cd". Ermal Luçi
05:16 PM Bug #1265 (Resolved): config.console asks for WAN & LAN but displays LAN & WAN
Ermal Luçi
09:15 AM Bug #1265 (Feedback): config.console asks for WAN & LAN but displays LAN & WAN
Applied in changeset commit:"9552450897319ab9e8810bd1a487d2936122c2d3". Ermal Luçi
09:14 AM Bug #1265: config.console asks for WAN & LAN but displays LAN & WAN
Committed thx. Ermal Luçi
08:44 AM Bug #1265 (Resolved): config.console asks for WAN & LAN but displays LAN & WAN
Very small bug, but, hey... we want a perfect system, aren't we ? :)
On the very first configuration (first boot o...
Thomas NOEL
05:15 PM Bug #1263 (Resolved): "Alternate Update URL" is not used on system information widget
Ermal Luçi
09:20 AM Bug #1263 (Feedback): "Alternate Update URL" is not used on system information widget
Applied in changeset commit:"c3606a3b47230707d1a793ead4837822a183d392". Ermal Luçi
09:19 AM Bug #1263: "Alternate Update URL" is not used on system information widget
Committed thx. Ermal Luçi
08:36 AM Bug #1263 (Resolved): "Alternate Update URL" is not used on system information widget
"Alternate Update URL" is not used on system information widget. The widget always use http://snapshot.pfsense...
...
Thomas NOEL
05:15 PM Bug #1264 (Resolved): httpsname is forgotten on services/captiveportal config
Ermal Luçi
09:20 AM Bug #1264 (Feedback): httpsname is forgotten on services/captiveportal config
Applied in changeset commit:"8f29b8923411e3d4a1cbec520c385c6dad91490a". Ermal Luçi
09:16 AM Bug #1264: httpsname is forgotten on services/captiveportal config
Committed thx. Ermal Luçi
08:39 AM Bug #1264 (Resolved): httpsname is forgotten on services/captiveportal config
httpsname is forgotten on the services/captiveportal config page.
Here is a patch...
Thomas NOEL
03:51 PM Revision a120c194: BP: Fix gettext implementation
Vinicius Coque
03:18 PM Revision aa0103f5: Disable the wins server input boxes, these don't work on v6
Seth Mos
02:31 PM Feature #1257 (New): Handle encypted CA/Certificate private keys
Not sure if this will make 2.0 or not. It may have to wait for 2.1 at this point, it may end up a documented limitati... Jim Pingle
01:49 PM Feature #1257: Handle encypted CA/Certificate private keys
One more clarification...
I just checked and see that the private key is encrypted, so cert signing must fail since ...
Brad Langhorst
01:38 PM Feature #1257: Handle encypted CA/Certificate private keys
When you imported the CA, did you import both the cert and private key of the CA?
All of the certificates are made...
Jim Pingle
01:35 PM Feature #1257: Handle encypted CA/Certificate private keys
Seems to be related to importing of a certificate authority.
To isolate a bit... I created an internal certificate...
Brad Langhorst
02:20 PM Revision c3606a3b: Resolves #1263. Use correct config toggle for detecting alternate url for firmware.
Ermal LUÇI
02:18 PM Revision 8f29b892: Resolves #1264. Read even the httpsname option from config so it displays correctly.
Ermal LUÇI
02:15 PM Revision 95524508: Resolves #1265. Show the interfaces in the same order requested during assignment on console.
Ermal LUÇI
02:15 PM Feature #1269 (Closed): define a default end date for for new certs by CA
This would make it easier to set up all certificates to expire on a specific day (thus simplifying the admin burden o... Brad Langhorst
02:12 PM Feature #1268 (New): Allow mass renewing of certs
Im thinking of a UI that would allow checking off of all the certs to renew.
filtering by expiration date would ma...
Brad Langhorst
02:08 PM Feature #1267 (Resolved): Show certificate expiration dates in UI
would be handy to see when the certs will expire. Brad Langhorst
01:46 PM Bug #1266 (Rejected): now my VPN is broken
----------------------
Using My Cert My client
----------------
** Log in client
Tue Feb 08 11:56:58 2011 ...
Joaquim Soares Soares
09:19 AM Bug #1248 (Resolved): CARP failover isn't happening as a group (preemption)
It was just a misconfiguration. Ermal Luçi
05:40 AM Revision 45666137: fix text (remove entirely, comment is related to an open feature request). ticket #1262
Chris Buechler
05:11 AM Bug #1177: Passive FTP
Been running recent builds on i386 and
no problems so far.
Thank You for your Work.
Martin Klein
12:28 AM Bug #1177: Passive FTP
No problems for the last several builds. Thank you! Lee Thornhill
03:18 AM Revision 8e572710: Increase a bit
Scott Ullrich
03:17 AM Revision 2988636c: Limit file sizes to roughly 143k
Scott Ullrich
03:16 AM Revision 85c3229a: Limit file sizes to roughly 143k
Scott Ullrich
02:52 AM Revision 9b700cf2: Global g
Scott Ullrich
02:52 AM Revision 4b665f74: Adding crashreporterurl for rebrands
Scott Ullrich
02:44 AM Revision f75a4575: s/er//
Scott Ullrich
02:44 AM Revision c26c01d7: Spell out more clearly
Scott Ullrich
02:37 AM Revision 36365f49: Add a global g option named disablecrashreporter which defaults to false for rebrands
Scott Ullrich
02:08 AM Revision d440e668: fix text
Chris Buechler
12:44 AM pfSense Packages Bug #1218: Freeradius package does not start when i do reboot
I am running the FEB 7th Beta5 build. Free radius starts, and the services page confirms this. However, it seems that... Brian G
12:38 AM Todo #1262 (Resolved): Typo in ifup script
fixed, thanks Chris Buechler

02/07/2011

10:57 PM Todo #1262 (Resolved): Typo in ifup script
/usr/local/sbin/ovpn-linkup
# write nameservers to file needs dns fidnings?!
...
John Doe
10:47 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
We were really overthinking it, it can be as simple as forcing individual certificates to be created. It doesn't have... Chris Buechler
07:00 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
Ok, I understand but that's a bit pedantic as this is how it is in every other installation outside of pfSense. My vo... John Doe
06:49 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
It's currently done that way because only with Local auth can you manage both the users and the certificates easily i... Jim Pingle
06:41 PM Feature #1260 (Resolved): Allow other Backends for Remote Access ( SSL/TLS + User Auth )
Currently in 2.0 BETA5, only the local user db is allowed for use in a Remote Access ( SSL/TLS + User Auth ) template... John Doe
10:32 PM Revision 63526c2c: Note that we are deleting the local crash reports
Scott Ullrich
10:19 PM Revision e8aef0ec: minicron is now used on a number of items in the gui. tell the cp prune process to use the pid name cp-prunedb.pid
Scott Ullrich
10:12 PM Revision aa69dbd2: Do not launch multiple copies of the captive portal database pruner.
Scott Ullrich
08:00 PM Bug #1261 (Rejected): OpenVPN Requires Unique Local Ports regardless of Interface
duplicate of #814 Chris Buechler
07:50 PM Bug #1261 (Rejected): OpenVPN Requires Unique Local Ports regardless of Interface
The OpenVPN GUI permits the creation of multiple tunnels, but requires that each have a unique local port. As far as... Joshua Schmidlkofer
05:42 PM Revision 166c7354: Echo out server response
Scott Ullrich
04:40 PM Bug #1259 (Rejected): This OpenVPN Broken? ????
works fine, post to the forum. Chris Buechler
04:40 PM Bug #1259 (Rejected): This OpenVPN Broken? ????
Use Wizard in openvpn, and exported the OpenVPN Client
BUT
Open Vpn does not work
This OpenVPN Broken? ????
Joaquim Soares Soares
03:43 PM Revision 90716b8c: Merge remote branch 'upstream/master'
Scott Ullrich
03:39 PM Revision 4a1ab618: Ask the person to actually read the page before clicking yes
Scott Ullrich
03:28 PM Revision 4cd81611: Fix check to ignore minfree (and the rest of $skip_files)
Jim Pingle
03:25 PM Bug #1254: IPsec dynamic tunnels don't reload correctly
Joe - the second issue you noticed requires DPD to function, see my post on the 2.0 board on the forum re: ipsec-tool... Chris Buechler
01:35 PM Bug #1254: IPsec dynamic tunnels don't reload correctly
If this is the same issue as the one discussed in the forum thread "VPN IPsec Remote gateway using DDNS doesn't updat... Joe Kelly
10:59 AM Todo #595: Test IPsec with NAT
Here my test case for qualifying pfSense for VPN and NAT.
Hope It'll help before pfSense 2.1.
(works great under Xe...
Fabien Allaine
09:32 AM pfSense Packages Feature #105: SquidGuard: Add progress bar for blacklist fetch with cancel/resume button
> A progress bar for fetching the blacklist file is needed in the SquidGuard package.
Exists.
>I noticed that wh...
Serg Dvoriancev
09:06 AM Feature #1257 (Rejected): Handle encypted CA/Certificate private keys
I can't replicate this - I can make certificates several different ways on current snapshots and they are complete in... Jim Pingle
07:34 AM Revision 2f14d021: Make it possible to set the default gateway bit for 1 ipv4 gateway and 1 ipv6 gateway
Seth Mos
07:23 AM Revision 7f00afac: Remove the icmp6 ping requests from the mandatory allow rulE
Seth Mos
04:43 AM Revision 104faa07: Move routine under includes. Simplify the file skip check
Scott Ullrich
04:40 AM Revision ee3f28cc: s/We have/product name has/
Scott Ullrich
04:32 AM Revision 4261af1d: Include newlines
Scott Ullrich
04:29 AM Revision e0a7f441: Include filename of files in report
Scott Ullrich

02/06/2011

11:31 PM Revision 5cb07d09: Fix typo
Scott Ullrich
11:06 PM Revision 8c5d112a: Not that we are deleting files
Scott Ullrich
10:47 PM Revision ee8ae159: Add link to kernel crash info on wikipedia for those who are not familiar with a panic
Scott Ullrich
10:45 PM Revision 9b091133: Make textarea read only
Scott Ullrich
10:42 PM Revision ffb9c06d: Include anonymous machine information in bug report including:
Crash report begins. Anonymous machine information:
i386
8.1-RELEASE-p2
FreeBSD 8.1-RELEASE-p2 #1: Sun Feb 6 05:07...
Scott Ullrich
10:18 PM Revision 217e9af7: Merge remote branch 'upstream/master'
Scott Ullrich
10:16 PM Revision b9439789: Simplify message for crash reports
Scott Ullrich
10:16 PM Revision e143e829: Simplify message for crash reports
Scott Ullrich
09:35 PM Revision 7139a9bf: Merge remote branch 'upstream/master'
Scott Ullrich
09:34 PM Revision fca795f8: Set a savemsg when a crash report exists and show across top instead of redirecting
Scott Ullrich
09:32 PM Revision 56f024e8: Add <br/> between ipv6 and ipv4 blocks
Scott Ullrich
09:31 PM Revision 1bea00f9: Merge remote branch 'upstream/master'
Scott Ullrich
09:03 PM Revision f0e9bdfb: Ignore minfree file
Scott Ullrich
08:03 PM Revision b32ccfce: Merge remote branch 'upstream/master'
Seth Mos
07:44 PM Revision 998930ab: fix url for jumpto
Scott Ullrich
07:40 PM Revision f5208bf2: If product name == pfSense show a link to redmine / bug database
Scott Ullrich
07:24 PM Revision 4f09471c: Crash reporter is now working.
Scott Ullrich
06:51 PM Revision 3a6cda80: Correctly detect amount of files in /var/crash
Scott Ullrich
06:41 PM Revision 52cdb50b: Set textarea size
Scott Ullrich
06:11 PM Revision 812ed2bb: Redirect to crash reporter if a crash exists for processing. The crash reporter will either upload the data per the operators consent and or delete the data afterwards and redirect back.
Scott Ullrich
06:11 PM Revision 49c8f964: gettext()
Scott Ullrich
05:13 PM Bug #1154: Kernel panic after connecting to OpenVPN
It's probably one that ermal fixed a few weeks ago. Several people hit it on the forums and they are no longer able t... Jim Pingle
05:12 PM Bug #1154: Kernel panic after connecting to OpenVPN
I can't replicate this - anyone else? Chris Buechler
05:13 PM Bug #1093 (Resolved): Problems with em(4)
this seems to be fine. Chris Buechler
04:27 PM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
After upgrade, still panics and reboots. Craig Reynolds
02:23 PM Feature #1258 (Resolved): dyndns - DNS Made Easy
I agree that the ability to customize dyndns from the GUI makes the most sense (http://redmine.pfsense.org/issues/124... Chris Goundry
01:47 PM Bug #1251: /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
After uppgrading to latest 404 error dissappears...
But the bug remains..
Adde BC
09:41 AM Feature #1257: Handle encypted CA/Certificate private keys
the title of this bug should be "certificate file is not properly generated or saved." using internal cert auth Brad Langhorst
09:38 AM Feature #1257: Handle encypted CA/Certificate private keys
upon further investigation, i see that the crt was not saved.
here's a bit of the config file.
...
Brad Langhorst
09:32 AM Feature #1257 (Pull Request Review): Handle encypted CA/Certificate private keys
when i export a certificate using
http://192.168.3.1/system_certmanager.php
i get an empty file.
the private ...
Brad Langhorst
08:26 AM Revision c7f70dbc: fix NTP server IPs in openvpn config
Chris Buechler
05:13 AM Revision 020b954f: at least don't touch rrd here, that rrd won't exist anyway
Chris Buechler
05:05 AM Revision bfa49cae: Revert "the only thing ping_hosts.sh is used for is pinging IPsec hosts. comment out all this complexity that makes it do way more than it needs to (and was throwing an error on rrd, it shouldn't be touching rrd)" this is used by at least the DNS server pkg
This reverts commit 9fcf15773caa87261314bfe6e8a33a3f0d1d18bd. Chris Buechler
04:48 AM Revision 891b3fa2: need config.inc here, otherwise it fails to reload, config arrays are blank in vpn_ipsec*. Actual issue and fix for bug #1254
Chris Buechler
03:25 AM Bug #1255 (Resolved): GUI fails to correctly create NTP client options
fixed, thanks Chris Buechler
01:43 AM Bug #1255 (Resolved): GUI fails to correctly create NTP client options
When creating an Openvpn server instance, one or more entered ntp servers get rendered in the conf file missing the a... John Doe
01:49 AM Bug #1256 (Resolved): DPD does not work in ipsec-tools 0.7.3
this has been a known issue for a while, and we have a solution with ipsec-tools 0.8.0 (not yet committed), just open... Chris Buechler
01:47 AM Bug #1116 (Resolved): IPsec error, racoon won't start with more than one phase 2
the original bug is fixed, and the later issue with non-0 exit status on racoonctl is fixed in ipsec-tools 0.8.0.
Chris Buechler

02/05/2011

11:54 PM Bug #1254 (Resolved): IPsec dynamic tunnels don't reload correctly
updated ticket to actual problem, it appears actually that there is no caching at all in gethostbyname, it issues a D... Chris Buechler
01:25 PM Bug #1254: IPsec dynamic tunnels don't reload correctly
Use this test program to compare:
#!/usr/local/bin/php
<?php
$dns_record = "www.pfsense.org";
echo "gethost...
Scott Ullrich
01:20 PM Bug #1254: IPsec dynamic tunnels don't reload correctly
We should test http://php.net/manual/en/function.dns-get-record.php vs gethostbyname Scott Ullrich
12:16 AM Bug #1254 (Resolved): IPsec dynamic tunnels don't reload correctly
/etc/rc.newipsecdns does not reload dynamic tunnels as it should. Chris Buechler
07:30 PM Bug #942: dhcp relay breaks
I'm seeing the same issue:... Jeremy Phillips
12:18 PM Bug #444: All mounts should be noatime
At this point I am not to keen on touching the BSDInstaller. We should set this ticket to future and deal with this... Scott Ullrich
12:15 PM Bug #1156 (Feedback): Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
Marking as feedback, the recent package changes should have resolved this.
Scott Ullrich
12:14 PM Bug #1220 (Resolved): Setup dumpon/savecore and friends to aid debugging
This works ok marking as resolved.
Scott Ullrich
12:12 PM Bug #560 (Feedback): loader.conf is empty after a firmware update.
This should be resolved. I fixed the bug in the kernel upgrade code that was causing this.
Scott Ullrich
10:13 AM Bug #1238 (Closed): Dynamic DNS update with Freedns not working?
Jim Pingle
04:27 AM Bug #1238: Dynamic DNS update with Freedns not working?
Warren Baker wrote:
> Works for me - freedns works slightly different to the other 2 dyn providers you mentioned. Di...
Thomas Burger
08:10 AM Revision 9fcf1577: the only thing ping_hosts.sh is used for is pinging IPsec hosts. comment out all this complexity that makes it do way more than it needs to (and was throwing an error on rrd, it shouldn't be touching rrd)
Chris Buechler
04:47 AM Revision e5a30665: fix text
Chris Buechler

02/04/2011

04:27 PM pfSense Packages Bug #1253: RRD Graphs dosen't work corect
Please post on the forum to ask questions of that nature, this is a bug tracking tool and not a general support system. Jim Pingle
04:25 PM pfSense Packages Bug #1253: RRD Graphs dosen't work corect
Ok, but If I can't see at the right moment what is the right speed of the transfer, how can I do that after 1 day? I ... bohosh bohosh
04:00 PM pfSense Packages Bug #1253 (Closed): RRD Graphs dosen't work corect
That's just the effect of averaging the data out over longer periods. As the timespan of each graph gets larger, the ... Jim Pingle
03:44 PM pfSense Packages Bug #1253 (Closed): RRD Graphs dosen't work corect
Hello,
I'm with the last version of 2.0-BETA5 (i386)
built on Fri Feb 4 02:36:03 EST 2011
I have attached 6 pict...
bohosh bohosh
03:34 PM Bug #1252 (Resolved): bug in header.inc
there is a coding error in /usr/local/www/header.inc that should be corrected.
Please see
http://forum.pfsense.o...
Luis Soltero
02:18 PM Revision 3fc4a490: Remove this compress line, it breaks the dhcpv6 config
Seth Mos
01:39 PM Revision 20f59893: Display the source subnet bits as 32 rather than 0 if it is empty.
Erik Fonnesbeck
01:20 PM Revision 6a97db1c: Allow aliases to be entered for source and destination addresses of outbound NAT rules.
Erik Fonnesbeck
01:04 PM Revision 9f1e3b2b: Add backend support for aliases on source and destination address of outbound NAT rules.
Erik Fonnesbeck
12:58 PM Revision b5efd82a: Display the last used repository and branch and add a couple more descriptions.
Erik Fonnesbeck
11:58 AM Revision 891012ce: Change destination back to the field type for fields that allow an alias - they appear to work there (or at least doesn't say it is an error?).
Erik Fonnesbeck
11:51 AM Revision b663d4ce: Remove redundant input validation for source port that also prevents use of port ranges.
Erik Fonnesbeck
10:03 AM Revision 393cd3fc: After finishing the installation clear the flag for package sync.
Ermal LUÇI
09:26 AM Bug #373: Package Manager not available in menus
I faced this issue too. It happens if you are running out of LiveCD. Install pfsense 2.0 to hard disk and then "Packa... sanjiv marathe
02:44 AM Bug #1177: Passive FTP
With 2.0-BETA5 (amd64)built on Thu Feb 3 22:33:00 EST 2011, it's not resolved. The LIST command times out from FTP cl... Blaise Hurtlin

02/03/2011

10:47 PM Revision 421f72a7: Fix url
Scott Ullrich
10:46 PM Revision 886caa75: Remove formatting in between textarea
Scott Ullrich
10:45 PM Revision 528d5abf: Set priv info
Scott Ullrich
10:39 PM Revision 45d72d82: Adding a page that will allow uploading of crash (panic) data. Once the server piece is in place we will detect crash data in php and redirect to this page to prompt if the operator would like to upload the data. Remove the crash data after upload or if the operator does not want to upload the crash data.
Scott Ullrich
10:08 PM Revision 54ac51b5: Make the subnet check failure better readable
Seth Mos
10:07 PM Revision cf6bc278: Fix the subnet check for gif tunnels by dropping the bits to 126.
Always compress the subnet address for easier reading Seth Mos
09:38 PM Revision a23a99cb: Lie to the system and report a subnetmask of 127 instead of 128. This should fix the subnetmask check
Seth Mos
07:12 PM Revision 1f676b67: Ticket #259. Actually kill dhlient when the interface type changes before going through apply changes otherwise the information would be lost and dhclient will remain running.
Ermal LUÇI
06:38 PM Revision 1ec2bedd: Ticket #1248. Do not set this higher since the slave will take more time to detect a switch needs to be done.
Ermal LUÇI
06:31 PM Bug #1210 (Resolved): Erasing limiter advanced options does not save the change
Ermal Luçi
05:14 PM Bug #1251 (Resolved): /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
In 1.2.3 i had a addon named "OpenVPN Status" after upgrade under Status menu i had two "Open VPN"
both of them went...
Adde BC
04:56 PM Bug #444 (New): All mounts should be noatime
Looks like this only got applied to NanoBSD and not the full installs. The installer isn't putting noatime,sync in fs... Jim Pingle
02:14 PM Bug #1177 (Resolved): Passive FTP
Ermal Luçi
02:12 PM Bug #259: When disabling a dhcp interface, dhclient is not stopped
Found the remaining issue.
The previous, dhcp, interface type information was being lost when the apply changes butt...
Ermal Luçi
06:43 AM Bug #259: When disabling a dhcp interface, dhclient is not stopped
Hi, in the 2011 02 02 snapshot the dhclient still isn't killed when switching to static from the console or UI.
Fe...
Seth Mos
01:43 PM Bug #1248 (Feedback): CARP failover isn't happening as a group (preemption)
Should be resolved. Put it on feedback to wait for any last time problems. Ermal Luçi
12:41 PM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
Mistake in the patch files.
In firewall_nat_out_edit.php, you should add after lin 223:
$natent['sourceportend'] ...
Martin Dupont
08:13 AM Bug #1231 (Resolved): Upgrading pfSense Removed Internal CA
Several people on the forum who could reproduce this before are no longer losing their CA. Looks like it's fixed. Jim Pingle
08:01 AM Revision 6376913c: Merge remote branch 'upstream/master'
Seth Mos

02/02/2011

09:39 PM Revision 847e5e82: Note reinit will disconnect folks
Scott Ullrich
09:37 PM Revision 7d9d6f6a: Correctly grab the hostname from config for filterdns.
Ermal LUÇI
09:27 PM Revision 442dc4a4: Do not call true here according to Ermal
Scott Ullrich
09:20 PM Revision b44f72d1: Reinit rules after edit
Scott Ullrich
03:26 PM Revision 396243e9: Alter the traffic collector kill function, alter the output of top from a pipe to a file. We can now have /tmp/top_output.txt for status
Seth Mos
02:24 PM Revision 31a7477d: Fix the TERM setting in the updaterrd script. Only get the last part of the top outpuT
Seth Mos
12:57 PM Revision 9d7dd0be: Add a newline to this command
Seth Mos
04:01 AM Bug #1177: Passive FTP
Yeah, this looks pretty good!
thnx
Michael Heller

02/01/2011

11:05 PM Bug #636: layer7 not work correctly
Any update? Seth Scardefield
07:36 PM Revision 5289dc57: Do not use references here when building a ca_chain_array. Really fixes #1231 - CAs are no longer lost when a config write happens at bootup.
Jim Pingle
07:32 PM Revision b0899ee4: Test for arrach before foreach'ing. Reported-by: http://forum.pfsense.org/index.php/topic,32865.0.html
Ermal LUÇI
07:09 PM Revision 4e8c89fd: Allow ipalias with carp as parent interface to be synchronized.
Ermal LUÇI
05:35 PM Bug #1177: Passive FTP
Just committed the final fix which should fix the issues and prevent hangs. Ermal Luçi
05:32 PM Bug #1249 (Rejected): Wireless Issue with bwn0
driver issue we can't do anything about. Also referenced here.
http://forums.freebsd.org/showthread.php?t=2477&page...
Chris Buechler
05:22 PM Bug #1249 (Rejected): Wireless Issue with bwn0
[2.0-BETA5] Latest SNAP, ALIX Board with NANOBSD
Driver is detected. Go through and assign physical wireless card ...
Ignat Esso
04:56 PM Bug #1248 (Resolved): CARP failover isn't happening as a group (preemption)
If you have a CARP pair and unplug/kill LAN, the VIPs do not all fail over to the slave unit. Only the VIPs on the fa... Jim Pingle
03:08 PM Revision 01ee74a8: Add a tab between ipv4 and ipv6 addresses
Seth Mos
02:35 PM Bug #1231: Upgrading pfSense Removed Internal CA
Applied in changeset commit:"5289dc575b0ed5a8d3c1ca556442cf57525d3fb5". Jim Pingle
02:28 PM Revision 7203754c: Merge remote branch 'upstream/master'
Seth Mos
02:23 PM Revision cebd086a: Adjust layout
Seth Mos
02:16 PM Revision bf7c1674: Add the IPv6 counters to the packets graph, also make all traffic counters stack
Seth Mos
12:07 PM Bug #1243: GUI/Backend code needs updated after multi-PPPoE-server code switch
Jim P your fix makes the PPPoE tab appear, but the firewall rules are not generated after applying changes. I attache... Vinícius Coque
11:28 AM Revision d49816e5: kill rrdtool before killing shellscripts
Seth Mos
09:43 AM Revision 9991ff2c: Fix the find_subnet v6 function to properly return the tunnel subnet
Seth Mos
09:08 AM Revision 2845d097: Further improvements on the ICMP6 allow rules
Seth Mos
09:02 AM Revision fea1b66d: Further rc.banner display adjustment
Seth Mos
08:53 AM Revision f668cbcf: Make interface name 2 longer
Seth Mos
08:41 AM Revision eef5ca2e: Simplify the updaterrd.sh to reduce the amount of pfctl calls
Seth Mos
08:19 AM Revision 41dfef33: Show IPv6 addresses in the banner message
Seth Mos
08:12 AM Revision d55ea970: Change wording
Seth Mos

01/31/2011

09:06 PM Revision 20fef17c: Show PPPoE tab if any of the PPPoE server instances are enabled. Fixes #1243
Jim Pingle
08:46 PM Revision 5ded8bab: Catch the OpenVPN widget up to the status page code for killing clients.
Jim Pingle
07:51 PM Revision a2eec62a: Don't save CA/Cert for a PSK IPsec tunnel.
Jim Pingle
07:39 PM Revision 9bc8b6b6: Add support for IPv6 counters to the RRD graphs. This adds 4 more data sources in the rrd file.
The graphing code colors are currently a mismatch and sorts waiting for someone with eyes to adjust to something usef... Seth Mos
07:11 PM Revision 5cda0e03: Fix typo (swapped parameters)
Jim Pingle
06:25 PM Revision f5c704b6: Fix copypasto
Jim Pingle
06:20 PM Revision 01d473df: Fix typo
Jim Pingle
05:38 PM Revision 54eb029e: Fix display of these pages on Opera. http://forum.pfsense.org/index.php/topic,32773.0.html
Jim Pingle
04:28 PM Bug #1246 (Rejected): TP-LINK WN851N PCI (Atheros AR922X) 802.11n problem
FreeBSD doesn't support 11n yet and there's nothing we can do to fix that. Should be supported in FreeBSD 9 reportedly. Chris Buechler
12:21 PM Bug #1246 (Rejected): TP-LINK WN851N PCI (Atheros AR922X) 802.11n problem
This card works fine only in 802.11b and 802.11g mode. Oscar Francia
04:10 PM Bug #1243 (Feedback): GUI/Backend code needs updated after multi-PPPoE-server code switch
Applied in changeset commit:"20fef17c7398170e18c9d03bcc04ee794002e981". Jim Pingle
06:40 AM Bug #1243 (Resolved): GUI/Backend code needs updated after multi-PPPoE-server code switch
After creating a PPPoE server a new tab should be displayed at Firewall Rules, but it isn't. Then I can't create rule... Vinícius Coque
11:46 AM pfSense Packages Bug #1245 (Closed): barnyard2 won't start
barnyard2 configured with remote mysql server won't start.
I tried from command line and I receive:
@/usr/local/b...
Ravine Pick
11:17 AM pfSense Packages Bug #1244 (Resolved): apache_mod_security_package missing mod_proxy.so (and perhaps others)
and perhaps other files (mod_proxy*.so) on "2.0-BETA5 (amd64) built on Sun Jan 30 23:04:29 EST 2011"
"Jan 31 10:46...
Robin McLeod
09:07 AM Bug #1238 (Feedback): Dynamic DNS update with Freedns not working?
Works for me - freedns works slightly different to the other 2 dyn providers you mentioned. Did you follow http://for... Warren Baker
04:16 AM Bug #1242 (Rejected): Gateway in an other subnet on Wan
Chris Buechler
03:44 AM Bug #1242: Gateway in an other subnet on Wan
search before write!
see ticket Bug #970,Bug #972
Gateways outside of the interface's IP subnet, on Ethernet link...
Dominik Nufer
03:39 AM Bug #1242 (Rejected): Gateway in an other subnet on Wan
Hi
I tried to install the pfsense 2.0 with the following configuration:
Netopia router with PPPoE Ip Forward to...
Dominik Nufer
12:38 AM Bug #1177: Passive FTP
Really ? On my side, it's still the same.. can't perform "LIST" command from WAN... Blaise Hurtlin

01/29/2011

05:25 PM Bug #1231 (Feedback): Upgrading pfSense Removed Internal CA
There have been a couple positive reports that some commits I made last week may have solved this. I'll leave it in '... Jim Pingle
05:07 PM Revision a49b2235: Missing colour for RRD would have caused errors in creating the graphs.
Warren Baker
06:35 AM Feature #1241 (Resolved): Custom Dynamic DNS
Because there are so many services which require an updated IP Address, which provide some kind of API via an HTTP re... Matt Corallo
12:40 AM Revision 44ab93a4: Correct configuration file name.
Ermal LUÇI

01/28/2011

10:22 PM Bug #1240 (Rejected): NAT & Alias NEtWORK
This is a duplicate of internal (private) ticket #1045 - it should be in 2.0, it just isn't there yet. Jim Pingle
10:15 PM Bug #1240 (Rejected): NAT & Alias NEtWORK
It should not be possible to use aliases network "in Nat outbound? ?????
Joaquim Soares Soares
10:09 PM Revision a3755fe7: Exclude loader.conf from being update during kernel update
Scott Ullrich
09:07 PM Bug #1239 (Resolved): PPTP - Assign password to a user with ñ
Hi there,
VPN / PPTP / User, assign a password with an accent generated an error in the config file. pfSense resto...
Ricardo Ramirez R.
08:58 PM Bug #1220 (Feedback): Setup dumpon/savecore and friends to aid debugging
This should be good in the latest snaps. Jim Pingle
08:04 PM Bug #1238 (Closed): Dynamic DNS update with Freedns not working?
Hello PFSense-Team,
I just tried to get a free-dns account to work. With dyndns and no-ip it is working but howeve...
Thomas Burger
07:32 PM Revision 9d3d8d00: Merge branch 'master' into inc
Conflicts:
etc/inc/captiveportal.inc
etc/inc/config.console.inc
etc/inc/config.lib.inc
...
Vinicius Coque
06:38 PM Revision 1596d9c1: Merge remote branch 'mainline/master'
Vinicius Coque
04:51 PM Bug #560: loader.conf is empty after a firmware update.
I discovered another vector for loader.conf being emptied - it's included in the kernel archives (kernel_Dev.gz, kern... Jim Pingle
04:03 PM Revision 9b2e42c9: When setting the ip from the console also enable the interface otherwise the HTTP_REFERER checks will not let you use the GUI.
Ermal LUÇI
03:16 PM Revision 20413b72: Added Captive Portal RRD graphs, there are two graphs one for the number of logged in users since last rrd poll, and concurrent number of users logged in.
Warren Baker
02:39 PM Revision 9d0b0635: Make this actually work as it should. The warnings about default queue should be ok now.
Ermal LUÇI
02:27 PM Revision 161cc65b: Activate the firewall rules for DHCPDv6.
Add pass in to port 546, pass out to 547 Seth Mos
02:17 PM Revision b3cf4d5a: adjust the firewall rules to allow for proper ICMP6 allow so that normal pmtu works
Seth Mos

01/27/2011

09:54 PM Revision fc05822b: Don't pass these by reference. Might be related to ticket #1231
Jim Pingle
06:48 PM Todo #1237 (Resolved): Restore patch for adding gif(4) to bridge(4)
bridge(4) before allowed gif(4) to be added as member with lower mtu.
This should be restored since naturally gif(4)...
Ermal Luçi
06:43 PM Bug #317 (Resolved): SSH authorized keys lost on upgrade on embedded
Confirmed on forums http://forum.pfsense.org/index.php/topic,31906.0.html Ermal Luçi
03:59 PM pfSense Packages Bug #1236 (Closed): Anyterm package doesn't start after upgrade
After an upgrade, Anyterm doesn't start automaticly.
Restarting the service won't work. I have to reinstall the pack...
Alexandre Paradis
03:48 PM Bug #1216 (Resolved): OpenVPN client interfaces should not be NATed out of when assigned
This is fixed since we have people on forum complaining for the now missing nat. Ermal Luçi
03:47 PM Bug #1093 (Feedback): Problems with em(4)
The problems should be fixed in latest snapshot that comes out. Ermal Luçi
03:45 PM Bug #1154 (Feedback): Kernel panic after connecting to OpenVPN
You can even update at the next snapshot that will come out.
It should fix the issues.
Ermal Luçi
09:46 AM Bug #1235 (Resolved): pfsense 2.0 load balancing with a https monitor seems to default timeout 200ms causing constant timeouts
Hi,
I've been failing with load balancing between two https web servers on pfsense 2.0.
I have two https server...
Gary Richards
07:34 AM Revision 6ac28fbd: Add the bogonsv6 file, it's empty for now
Seth Mos
05:05 AM pfSense Packages Bug #1234: bge NIC not working
Thank you Chris.
I will try replicate the error on a fresh BSD box.
Danilo Chilene
04:58 AM pfSense Packages Bug #1234 (Rejected): bge NIC not working
we don't develop or control the drivers, there is apparently an issue with that particular chipset and FreeBSD 8.1, y... Chris Buechler
04:46 AM pfSense Packages Bug #1234 (Rejected): bge NIC not working
Hello,
I have a PFsense 2.0-BETA5 (amd64) built on Wed Jan 26 01:53:43 EST 2011 running on a HP hardware and none ...
Danilo Chilene

01/26/2011

10:47 PM Revision a798fd3e: At least bring the interface up. Sometimes even though the linkup is reported interfaces like em(4) do not come up.
Ermal LUÇI
10:44 PM Revision c3770c78: Ups actually single quotes are needed when / is the first char of a command. Requirment enforced by the parser.
Ermal LUÇI
10:15 PM Revision f7f22750: Remove last references to dnswatch.
Ermal LUÇI
09:12 PM Revision f8c10a18: Use filterdns instead of dnswatch which will be retired.
Ermal LUÇI
07:41 PM Bug #1233: License Error for ipw_bss, ipw_ibss, wpi, ipw_monitor, etc.
Maybe (I think there is a really old ticket for that) but it was considered beyond the scope of what we wanted to do ... Jim Pingle
07:37 PM Bug #1233: License Error for ipw_bss, ipw_ibss, wpi, ipw_monitor, etc.
Wouldn't it be possible to present the user with the license file during install, then have a check box they explicit... Steve Vigneau
07:35 PM Bug #1233 (Rejected): License Error for ipw_bss, ipw_ibss, wpi, ipw_monitor, etc.
Those have always been there.
It's an unfortunate requirement for certain Intel cards. If you have the card you ha...
Jim Pingle
07:33 PM Bug #1233 (Rejected): License Error for ipw_bss, ipw_ibss, wpi, ipw_monitor, etc.
While watching _2.0-BETA5 (i386) built on Wed Jan 26 10:45:46 EST 2011_ boot I noticed this. It can also be seen in d... Steve Vigneau
07:36 PM Bug #1232: Unable to load dynamic library '/usr/local/lib/php/20060613/mhash.so' - /usr/local/lib/libmhash.so.2
For what it's worth, I just tried to change a user's password and received this:
_Fatal error: Call to undefined f...
Steve Vigneau
07:29 PM Bug #1232 (Resolved): Unable to load dynamic library '/usr/local/lib/php/20060613/mhash.so' - /usr/local/lib/libmhash.so.2
Noticed a number of these while booting and on the console:
PHP Warning: PHP Startup: Unable to load dynamic libr...
Steve Vigneau
06:40 PM Revision 422b8b4e: Switch to filterdns new and shiny for taking care of dns in CP.
Ermal LUÇI
06:29 PM Revision c3c7fc06: These are pf type aliases.
Ermal LUÇI
05:44 PM Revision 1749da31: Fix exec bit for savecore
Jim Pingle
05:42 PM Revision e5323cca: Run dumpon earlier, split dumpon/ddb from savecore and run savecore later.
Jim Pingle
04:21 PM Revision 9caffe86: Remove duplicate advbase in ifconfig command
Seth Mos
02:40 PM Revision 9740fad8: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/system.inc
Seth Mos
02:30 PM Bug #1231: Upgrading pfSense Removed Internal CA
We've been trying to track that down for a bit.
See this thread:
http://forum.pfsense.org/index.php/topic,32372.0...
Jim Pingle
02:22 PM Bug #1231 (Resolved): Upgrading pfSense Removed Internal CA
Updated from a version of pfSense from early today to the latest version (2.0-BETA5 (i386) built on Wed Jan 26 10:45:... Steve Vigneau
01:32 PM Bug #1230 (Closed): Switching pfSense to HTTP from HTTPS Doesn't Free Up Certificate
Duplicate of #1171 Jim Pingle
01:29 PM Bug #1230 (Closed): Switching pfSense to HTTP from HTTPS Doesn't Free Up Certificate
When pfSense is switched from HTTPS to HTTP the certificate that had previously been selected for HTTPS is still list... Steve Vigneau
01:27 PM Revision 22599010: Show the TCP protocol for ipv6 filter rules
Seth Mos
12:22 PM Revision 1f321f66: Move the ICMP rules further to the top in order for normal neighbour contact via icmp6 to work
Seth Mos
12:14 PM Revision 80766f71: Do not block fec0::/10 as this includes fe80:: local link addresses which breaks everything else
Seth Mos
11:55 AM Revision 1525ca4c: reference the IPv6 bogons table as well
Seth Mos
11:53 AM Revision 7de4359a: Add the bogonsv6 table for the IPv6 bogons
Seth Mos
10:54 AM Revision b0538842: Add the IPv6 fc00::/7 and fEc0::/10 to the Private block on WAN
Seth Mos
10:45 AM Revision 23f1acdd: Setup packet spoofing rules for inet and inet6
Adjust the default Deny All rules for inet and inet6, rename labels Seth Mos
10:43 AM Revision aec7edd4: Adjust firewall rule to reflect inet or inet6
Seth Mos
10:41 AM Revision 29bed6ca: Adjust the loopback firewall rules for inet and inet6 and give them unique labels
Seth Mos
10:17 AM Revision ee4fc984: Silence warnings.
Ermal LUÇI
01:24 AM Bug #1177: Passive FTP
Looks like FTP is working better with build from Tue Jan 25 06:07:53. Did not get a chance to really hammer on it. Th... Lee Thornhill
01:05 AM Revision b638ef51: BP: Add gettext() function #multilang
Carlos Eduardo Ramos

01/25/2011

11:12 PM Revision 0ad7bcd8: Fix case for disabling RRD graphing for spamd package.
Erik Fonnesbeck
10:44 PM Bug #1220 (New): Setup dumpon/savecore and friends to aid debugging
Something isn't quite right with textdump support. I can trigger the panic, I see the textdump script run, but saveco... Jim Pingle
05:06 PM Bug #1220 (Feedback): Setup dumpon/savecore and friends to aid debugging
dumpon/savecore are now run at boot on full installs (with swap space). Of course you'll need enough swap space to ho... Jim Pingle
10:23 PM Revision 27d5c1dd: Setup textdumps too while we're at it. Handy.
Jim Pingle
10:05 PM Revision 726b5d85: Fix exec bits on rc.dumpon
Jim Pingle
10:03 PM Revision 1e2ee714: Redirect to correct page
Scott Ullrich
10:02 PM Revision c3a56ba9: Add support for dumpon/savecore to run on full installs.
Jim Pingle
10:02 PM Revision 3b39d0ac: Whitespace fix
Jim Pingle
10:00 PM Revision 1b01056c: Redirect to correct page
Scott Ullrich
08:20 PM Revision 96920d07: Restart lighty captive portal after sync
Scott Ullrich
08:11 PM Revision c4e228f3: Transform PORTAL_REDIRURL variable
Scott Ullrich
07:55 PM Revision ec192fe5: Fix url. Do not include mod_accesslog twice
Scott Ullrich
07:24 PM Bug #560: loader.conf is empty after a firmware update.
Apologies. Please disregard my previous comment.
Wrongly perceived the issue to be that values entered manually in...
R M
07:09 PM Revision 2953848b: remove single quotes
Scott Ullrich
06:50 PM Revision eac181ca: BP: Add gettext() function #multilang
Carlos Eduardo Ramos
06:38 PM Revision 9abe1997: Brute force dnswatch kill if needed
Scott Ullrich
06:24 PM Revision a00e1d89: move pre-auth url before after auth url for consistency.
Scott Ullrich
06:23 PM Revision f6a0f982: Set form field type, make URL boxes same size
Scott Ullrich
06:22 PM Revision 76607020: move option near the other
Scott Ullrich
06:19 PM Revision ecc19349: Increase textbox size. Clarify the original Redirection URL purpouse
Scott Ullrich
06:13 PM Revision 38060391: Handle PORTAL_REDIRURL variable
Scott Ullrich
06:09 PM Revision e0f1a8d6: Adding CP pre-authentication redirect URL box
Scott Ullrich
06:03 PM Revision 75d12406: Launch dnswatch correctly.
Scott Ullrich
06:00 PM Revision 8b73cc7e: Allowed hostname is now working. Make bw up and down checks a bit more strict using intval() and comparing >0. Fix bw and upload checks allowing either to be set.
Scott Ullrich
05:58 PM Revision 0b108eda: Allowed hostname is now working. Make bw up and down checks a bit more strict using intval() and comparing >0. Fix bw and upload checks allowing either to be set.
Scott Ullrich
05:31 PM Revision 620ac186: Misc fixups
Scott Ullrich
05:30 PM Revision 79e99eb4: Make allowedhostname an array.
Scott Ullrich
05:12 PM Revision 9592c132: Prevent drop down menu creation
Scott Ullrich
05:11 PM Revision d413cd50: Adding switch to prevent dropdown menu creation.
Scott Ullrich
05:07 PM Revision 4e978135: Adding tab for allowed hostnames
Scott Ullrich
04:55 PM Revision 55c18b30: Adding preliminary version of allowed hostnames. Allowed hostnames function similar to allowed IP addresses and permit the captive portal to pass traffic out. An example usage of this is to allow access to a hotel web page freely and then require authentcation hotlinking from this point.
Scott Ullrich
04:35 PM Revision f23a6091: Fix formatting. Die, VIM, DIE!
Scott Ullrich
03:32 PM Revision 5060dea7: Reformat file. VIM needs to die a flaming death.
Scott Ullrich
03:18 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
All that has been discussed at length (and not on an unrelated ticket), it was much easier to leave loader.conf.local... Jim Pingle
03:15 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Thanks for the response Jim.
Since there's no man pages available in pfSense, my reference regarding the matter wa...
R M
10:38 AM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
bug #560 isn't really relevant to this, you should store your personal customizations in loader.conf.local - that fil... Jim Pingle
03:17 PM Bug #1027 (Resolved): Config restore triggers HTTP_REFERER check on interface mismatch
Ermal Luçi
03:13 PM Bug #1154: Kernel panic after connecting to OpenVPN
Please test with the kernel located at http://files.pfsense.org/kernel.gz
Just copy it to /boot/kernel/kernel.gz and ...
Ermal Luçi
03:12 PM Bug #1194 (Closed): Captive Portal Logout Issue
Linked with #836 Ermal Luçi
01:49 PM Todo #1229 (Closed): Captive Portal configuration page needs advanced button love
The captive portal page has grown and grown and has a lot of features that most people will not be using.
In the s...
Scott Ullrich
10:32 AM Revision f0e69fca: don't show version on this page either, to match the other pages
Chris Buechler
09:18 AM Bug #1228 (Rejected): Autoreboot
Please post in the forum for help in gathering more information. There are already several threads for similar issues... Jim Pingle
08:17 AM Bug #1228 (Rejected): Autoreboot
Hi! I've 2.0-BETA5 (i386)
built on Mon Jan 24 07:08:15 EST 2011 installed on a alix 2d3 and another installation on...
Andrea Cutelle'
09:16 AM Revision d11e01f4: Comment out this code since it currently segfaults and get_real_interface could cause major slowdown here for some configurations.
Erik Fonnesbeck
08:34 AM Revision 5357f386: Remove extra call to get_real_interface.
Erik Fonnesbeck
08:26 AM Bug #729: if_bridge unpredictable filter interface selection
Chris, was that in response to the issue I noted or the original one? I could understand the IP of the management int... Derek Buttineau
08:03 AM Revision 56919157: Use the first element of the array instead of the array itself for the comparison.
Erik Fonnesbeck
07:47 AM Bug #1226: Possible DOS in CARP synchronization
I can reproduce it only using a "big" configuration file (~120 firewall rules + 10 interfaces) and with moderate HW p... Alexander Kalashnikov
03:04 AM Bug #1226: Possible DOS in CARP synchronization
I can't replicate this even clicking the force sync button as fast and as many times as I possibly can, it just works... Chris Buechler
07:45 AM Revision a1476a94: Revert "I think this is supposed to be get_real_interface too, not get_parent." - This function should not call get_real_interface here to avoid slowdown from recursion.
This reverts commit 54ac5d9080c2ea6669af07aa49a5ce660f2ede76. Erik Fonnesbeck
07:16 AM Revision 20cb9803: Make get_parent_interface return an array to handle MLPPP and make it find vlan parents too.
Also, update interface_netgraph_needed to handle MLPPP on vlans. Marcus Brown
04:36 AM Revision a3af8146: Add NULL check to wireless functions.
The old interface_translate_type_to_real function used previously would return OPTX
if it was passed "OPTX" and OPTX ...
Marcus Brown
04:27 AM Revision 54ac5d90: I think this is supposed to be get_real_interface too, not get_parent.
Revert if I mis-understood. Marcus Brown
04:16 AM Revision d5dfcb52: Change name of function "interface_translate_type_to_real" to match what it's doing (or should be doing.)
Next commits will change functionality of this function because before now
it's identical to "get_real_interface" fun...
Marcus Brown

01/24/2011

11:14 PM Revision 67bc955d: handle alternate xml_rootobj correctly when doing config backups w/RRD data
Chris Buechler
10:48 PM Revision a1d52f81: Resolves #1216. Do not create nat entries on ovpn interfaces.
Ermal LUÇI
07:34 PM Revision 261c7de8: Warn users a different way if packages are being reinstalled in the background. Only lock out package pages, still print a giant warning on the others. (Some people were getting stuck in this state http://forum.pfsense.org/index.php/topic,32531.0.html )
Jim Pingle
07:30 PM Bug #1227 (Closed): Unifying multiple interfaces into bridge breaks connectivity
there was some breakage in bridging the past few days, fixed today. If you still have issues with a new snapshot plea... Chris Buechler
07:09 PM Bug #1227 (Closed): Unifying multiple interfaces into bridge breaks connectivity
I have following machine:
Dual-core Atom CPU @ 1.8 GHz
1 x 1GB RAM
2 GB Flash storage
1000/100/10 Ethernet adapte...
Anton Vorobyov
06:10 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Apologies. Doesn't look like I set the target version of the bug correctly which means it doesn't show up in the cust... R M
06:00 PM Bug #1155: [patch] status_gateways.php doesn't show last check time
I will move this to 2.1 because the way we use/reload apinger there will not always be a time to show which is not ri... Ermal Luçi
05:52 PM Bug #491 (Resolved): Dynamic DNS upgrade code not working
Ermal Luçi
05:50 PM Bug #1216 (Feedback): OpenVPN client interfaces should not be NATed out of when assigned
Applied in changeset commit:"a1d52f81879fc1f2253eeef5189adfa2e6396c11". Ermal Luçi
05:24 PM Revision 8633930d: Actually send a notice even if no default queue could not be found. This might be serious in some cases.
Ermal LUÇI
05:18 PM Revision ef8fca71: Do not put the queue config on the rules if there is no default queue, just log it. This prevents errors in rules loading which is worse than having no shaper.
Ermal LUÇI
05:08 PM Bug #729: if_bridge unpredictable filter interface selection
it works exactly as it should per the man page, there are just certain ways you shouldn't configure it or you should ... Chris Buechler
05:04 PM Revision 00ca3fb1: Log the errors we know for not allowing a queue to be added.
Ermal LUÇI
04:55 PM Bug #1093: Problems with em(4)
I committed the driver from STABLE so it should be on new snapshots.
Please anybody with the issue test that snapshot.
Ermal Luçi
04:54 PM Revision 49946455: Do proper input validation on traffic shaper wizards to not allow empty fiedls.
Ermal LUÇI
04:53 PM Bug #1151 (Resolved): Outgoing pptp Traffic-Flow stops after a while
Ermal Luçi
04:52 PM Bug #1183 (Resolved): Alias change reloads filter twice
Ermal Luçi
04:38 PM Revision 8d9c3f76: Properly check empty fields when specifying bandwidth values.
Ermal LUÇI
09:38 AM Bug #1226: Possible DOS in CARP synchronization
UPD:
System can be only rebooted by issuing ssh [ip] reboot -q
Alexander Kalashnikov
08:05 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
We use a sip server which handles both trunking and remote users. We typically use static port NAT for both functions... Tony Graziano
04:56 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
When a SIP peer starts the dialog, it sends thru SDP the port on which it is expecting the RTP stream.
There are of ...
Martin Dupont
07:34 AM Revision 71f88d75: Add the npt tag which is used by the IPv6 tree to the 2.0 mainline tree.
This prevents a config blowup when a ipv6 config loads on 2.0. Seth Mos
02:28 AM Bug #1177: Passive FTP
yes, the same behaviour for me.
still getting a lot of timeout/reconnets.
on thre other hand it looks much better...
Michael Heller

01/23/2011

10:48 PM Feature #150: Option to change syslog facility
In addition to facility, everything comes through as "warning" currently where some logs should be marked as informat... Chris Buechler
08:37 PM Bug #1226: Possible DOS in CARP synchronization
I'm sure that that is a pretty real scenario, since that two or more admins can make some changes simultaneously.
...
Alexander Kalashnikov
08:21 PM Bug #1226: Possible DOS in CARP synchronization
You're hanging PHP by doing that, don't do that is the answer. Killing all php processes at the console or an existin... Chris Buechler
06:01 PM Bug #1226 (Closed): Possible DOS in CARP synchronization
When you press "Force config sync" couple of times in a very short period of time (4\5 in a second) the slave machine... Alexander Kalashnikov
08:06 PM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
I've never seen RTP have to be static, though a worthwhile feature to have post-2.0.
Chris Buechler
11:08 AM Feature #1225 (Closed): static port range and outbound rules source port range (only to be tested and integrated, already coded)
When you go to NAT Outbound, you can create rules to make 1 port static, or to force the source port (for example, fo... Martin Dupont
02:41 PM Feature #1222: Support for tun or tap mode in openvpn server
This is a patch that adds the option to choose tun or tap mode for server Eino Efimov
05:36 AM Revision 1f17c623: it's 2011
Chris Buechler
04:58 AM Feature #1223: gateway group based sticky connections
Updated to a more feasible solution, per-rule isn't easily possible with the way it works. Chris Buechler
04:38 AM Feature #1223 (Closed): gateway group based sticky connections
There are some circumstances, that global sticky connections option isn't the best case.
One of that is an internal ...
Falk Nisius
04:46 AM Bug #1224 (Resolved): Changing Aliasnames for Ports are not reflected in Rules
Renaming of Host-Alias, would be changed also in the Ruleset.
Renaming of Port-Alias, isn't seen in the Ruleset, per...
Falk Nisius
02:49 AM Revision 3eb00b49: We don't want to detach netgraph nodes from interfaces that are used by
any PPPoE/PPTP/L2TP configurations. Marcus Brown

01/22/2011

09:04 PM Revision e5d83b70: Fix dhcp server group
Seth Mos
08:05 AM Revision e9d6c27f: fix variable and text for this log
Chris Buechler

01/21/2011

11:53 PM Bug #1177: Passive FTP
Updated to Fri Jan 21 06:52:27. Sorry, still no love. The number of tries before failure is inconsistent. After updat... Lee Thornhill
12:26 AM Bug #1177: Passive FTP
There were some changes to the patches this afternoon. Grab the next snap that comes out (it's almost done building n... Jim Pingle
12:24 AM Bug #1177: Passive FTP
-loaded the developer's kernel -> solid, cannot duplicate the crashes-
Nope just takes more tries to bring it down.
...
Lee Thornhill
10:54 PM Revision 3d9e9252: Do not write the old ip to the cache file unless it changes. Might help in Ticket #943.
Ermal LUÇI
08:13 PM Revision 0e01b3c6: Fix OpenVPN wizard.
Jim Pingle
06:09 PM Feature #1222 (Closed): Support for tun or tap mode in openvpn server
Capability to change interface TAP or TUN for the server configuration in GUI. Eino Efimov
05:52 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Some other possible fix pushed. Ermal Luçi
10:31 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Attaching log from start of test through end. R B
10:13 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Post your system log from the time of the reconnect, especially anything that mentions rc.newwanip and entries around... Jim Pingle
10:00 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
Updated to "Version 2.0-BETA5 (i386) built on Thu Jan 20 23:14:10 EST 2011", same behavior:
1. Unplug working br...
R B
05:09 PM Revision 81e54dab: Use a better method to determine the FTP URL for FreeBSD based on the version being used. The old method worked with 8.1-RELEASE-p2 but failed with just 8.1-RELEASE.
Jim Pingle
03:58 PM Revision e9bcc5fe: Lock firmwarelock when upgrading packages
Scott Ullrich
02:38 PM Bug #910 (Feedback): CARP+Bridging+NAT can lead to "freeze"/"lockup"
A patch to fix this issue has been committed. Ermal Luçi
01:41 PM Bug #1221 (Resolved): igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
I'm creating this ticket in relation to the following forum topic since I don't think an bug was submitted by the OP:... R M
10:38 AM Bug #1220 (Resolved): Setup dumpon/savecore and friends to aid debugging
On systems where we have a swap partition (read: full installs) we should setup the equivalent of the FreeBSD scripts... Jim Pingle
08:48 AM Revision 462f9006: Add filter code for adding the binat rules required for Network Prefix Translation
Seth Mos
08:35 AM Revision 36e81b98: Add the firewall_nat_npt* pages so that you can enter use binat for Network prefix translation
Seth Mos
08:34 AM Revision 292ef22a: Unbreak static routes
Add initial NPt Network Prefix Translation pages Seth Mos
07:50 AM Revision bb8f186e: fix text
Chris Buechler
03:18 AM Feature #1219 (New): Ship DTRACE enabled kernels in the images
It would be better to ship some dtrace enabled kernel with images and create some scripts to easy reporting info and ... Ermal Luçi
02:41 AM Revision eadb78bc: correct field type, no aliases allowed here
Chris Buechler

01/20/2011

10:19 PM Revision 582c58ae: Add drop-down to select OpenVPN hardware crypto (finds usable devices from "openssl engine" list) for clients and servers.
Jim Pingle
06:47 PM pfSense Packages Bug #1218 (Resolved): Freeradius package does not start when i do reboot
first of all i am not debeloper , i am not sure if this place is the right way to post the bug
Every time i reboot ,...
Abdelmonem Abuelezz
05:52 PM Revision 1801c223: Add the empty check otherwise all static routes are skipped. Reported-by: Seth
Ermal LUÇI
05:33 PM Revision bca35cff: Add a checkbox for duplicate-cn on OpenVPN servers.
Jim Pingle
05:23 PM Feature #1217 (Needs Patch): Change OpenVPN local/remote networks to lists instead of single boxes
In 2.1 or beyond it would be nice to have the OpenVPN local and remote network boxes instead be lists of networks, so... Jim Pingle
04:33 PM Revision 09e11b69: Comment what this variable does
Scott Ullrich
04:30 PM Revision f0695975: Adding $builder_package_install variable. When set to true ignore library fixups and sync_package() directives.
Scott Ullrich
03:58 PM Bug #560: loader.conf is empty after a firmware update.
I'm seeing a slightly different behaviour which may be unique to having serial console enabled after a an update.
...
R M
02:57 PM Bug #1216: OpenVPN client interfaces should not be NATed out of when assigned
to clarify, that is the tun interfaces are included as "nat on ...", though possibly only where the tun interfaces ar... Chris Buechler
02:49 PM Bug #1216 (Resolved): OpenVPN client interfaces should not be NATed out of when assigned
outbound NAT is applied on OpenVPN client interfaces when they are assigned, and should not be. Routing is almost alw... Chris Buechler
01:24 PM Bug #1209 (Resolved): cannot restore encrypted configuration file
Jim Pingle
01:22 PM Bug #1209: cannot restore encrypted configuration file
confirmed, I can now restore my encrypted config backup. thank you! Jesse Norell
01:18 PM Feature #1215 (Resolved): DHCP Bootp Flags
Need support for DHCP Bootp flags on WAN interface. Specifically 0x8000 (Broadcast).
Some ISP's do not set dhcp s...
NOYB NOYB
01:11 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
pptp also working here :) Christian Schwarz
12:40 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
The lockup issue is likely separate. The forum thread for that is here: http://forum.pfsense.org/index.php/topic,3245... Jim Pingle
12:25 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
I updated on 1/19 as well and my PPTP VPN stability issue seemed to be resolved. But, as Chris stated above, I am ha... Stefan Pinson
08:26 AM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
Just updated to the latest versions the morning of 1/19 and in the afternoon, both versions introduced system lockups... Chris Baker
12:42 PM Feature #1214 (Closed): Firewall Schedule Time Should Be Allowed to Straddle Midnight
Jim Pingle
12:37 PM Feature #1214: Firewall Schedule Time Should Be Allowed to Straddle Midnight
Nevermind, I just realized that I can add multiple time ranges to the same schedule. See attached screenshot. My bad. Joe Kelly
12:31 PM Feature #1214 (Closed): Firewall Schedule Time Should Be Allowed to Straddle Midnight
I wanted to create a schedule for late night _plus_ wee hours of the morning. I entered a Start Time of 21 Hr 00 Min ... Joe Kelly
11:34 AM pfSense Packages Bug #1213 (Resolved): Mod_Security+Apache+Proxy
in general setting
"Bind to IP Address
This is the IP address the Proxy Server will listen on.
NOTE: Leave b...
Dienis Rastegaeff
10:52 AM Bug #1075 (Resolved): rrd graphs missing / duplicate
Chris Buechler
09:59 AM Bug #1075: rrd graphs missing / duplicate
The problem seems solved, i will continue
to test it at different times of day.
If i find further problems I will ...
Martin Klein
10:49 AM Revision 15705bc0: Enlarge subnet bits to 128
Seth Mos
09:37 AM Bug #1211 (Rejected): System Lockup after upgrading from December build to January 19th builds
This is not you hotline support.
Please use the forums for this issues.
Ermal Luçi
08:19 AM Bug #1211 (Rejected): System Lockup after upgrading from December build to January 19th builds
After upgrading to yesterday mornings's build pfense locked up after a few hours. I then upgraded to the latest buil... Chris Baker
08:03 AM Revision d2619fa0: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/system.inc
Seth Mos
12:08 AM Bug #1177: Passive FTP
was running the SMP kernel
loaded the developer's kernel -> solid, cannot duplicate the crashes
Lee Thornhill

01/19/2011

11:35 PM Revision 86ae3621: Allow setting package interfaces to loopback (lo0)
Scott Ullrich
11:10 PM Bug #1177: Passive FTP
Same problems as I reported before using the i386 Wed Jan 19 11:47:04 build.
With testing tonight I was 3 for 3 on...
Lee Thornhill
02:36 AM Bug #1177: Passive FTP
Also only able to retrieve the directory listing on the second try.
Response: 200 Switching to Binary mode.
Comma...
Lee Thornhill
02:17 AM Bug #1177: Passive FTP
Testing with a client behind pfsense using Tue Jan 18 03:34:33. FTP helper takes down box when re-initializing a prev... Lee Thornhill
12:57 AM Bug #1177: Passive FTP
after some heavy tests I found out that there are a lot of connections droped by the default deny rule!
This finally...
Michael Heller
12:37 AM Bug #1177: Passive FTP
2.0-BETA5 (i386)
built on Tue Jan 18 03:34:33 EST 2011
confirmed.. FTP helper is working..
Branko Lukman
09:23 PM Revision daacb818: Ticket #1210. Also here unset any previous value if none posted.
Ermal LUÇI
09:20 PM Revision c2461a56: If no value is posted means we have no value to save in config and should unset any pervious set ones.
Ermal LUÇI
08:56 PM Revision f5bafe95: Resolves 1209. Correctly calculate the necessary data to return from an 'pfsense' format encrypted file.
Ermal LUÇI
06:57 PM Revision 38bdc48d: This logic was reversed fix it. Reported-by: Seth
Ermal LUÇI
06:53 PM Revision 33a2693c: don't show platform here (rebrands)
Chris Buechler
06:25 PM Revision bcfe4ae5: Ticket #259 trim the \n from the command output and return only the numeric part of it.
Ermal LUÇI
06:07 PM Revision 1c4edc3c: If an outbound nat rule has a protocol specified, show it in the summary view.
Jim Pingle
05:42 PM Bug #755 (Resolved): dnswatch not working
https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/commits/750951f9b2bd4cdb1bde4748cc51a0258b59f5b3
Fixes...
Ermal Luçi
04:18 PM Bug #1210 (Feedback): Erasing limiter advanced options does not save the change
Committed a fix https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/c2461a56d45b678213488ea1ced099a38ead267e Ermal Luçi
04:17 PM Bug #1210 (Resolved): Erasing limiter advanced options does not save the change
Create a limiter, add a delay, and save. Edit the limiter, erase the delay, and save. The value is still there, not b... Jim Pingle
03:55 PM Bug #1209: cannot restore encrypted configuration file
Applied in changeset commit:"f5bafe95a1fb4372288816debaa21b4f943a32e8". Ermal Luçi
03:54 PM Bug #1209 (Feedback): cannot restore encrypted configuration file
https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/f5bafe95a1fb4372288816debaa21b4f943a32e8
Fixes the i...
Ermal Luçi
02:08 PM Bug #1209 (Resolved): cannot restore encrypted configuration file
I'm unable to restore an encrypted configuration file in the latest 2.0 snapshot. It fails with a "real" config back... Jesse Norell
01:49 PM Bug #1208 (Closed): Limiters don't work on non-quick rules
Limiters should not be allowed to be specified on non-quick floating rules as they don't work in such a scenario. Chris Buechler
01:48 PM Bug #1207 (Resolved): Renaming a limiter creates new limiter
when a limiter is renamed it creates a new one rather than renaming it. Chris Buechler
01:38 PM Bug #1198 (Resolved): Incorrect tls-auth setting for Peer to Peer SSL/TLS OpenVPN Server with tls-auth enabled
thanks Chris Buechler
01:36 PM Bug #1198: Incorrect tls-auth setting for Peer to Peer SSL/TLS OpenVPN Server with tls-auth enabled
Hi, I upgraded to the Jan 17th firmware yesterday and I can confirm that this bug is fixed. Thanks! Joe Kelly
01:24 PM Bug #259 (Feedback): When disabling a dhcp interface, dhclient is not stopped
Ermal Luçi
09:41 AM Bug #259 (New): When disabling a dhcp interface, dhclient is not stopped
Jim Pingle
09:29 AM Bug #259 (Feedback): When disabling a dhcp interface, dhclient is not stopped
I just tested this with a clean 2.0 BETA5 i386 install and I still see dhclient messages in the system logs. Seth Mos
12:58 PM Bug #863: floating rules breaks passive mode ftp
There is some improvement, I can now use an ftp client on LAN in both passive or active mode, but still can't use pas... Jesse Norell
10:51 AM Bug #1206 (Rejected): OpenVPN client is not Multi-WAN capable
Out of the box, a single client instance will not fail from WAN1 to WAN2 when coming from pfSense itself. You can sel... Jim Pingle
10:43 AM Bug #1206 (Rejected): OpenVPN client is not Multi-WAN capable
After several day of trying every possible solution, I have to report that the built-in OpenVPN client is not multi-W... Stefan Seidel
10:50 AM Bug #463: PPTP VPN rediction does not work
This still does not work in Beta5, I still had to make the rules by hand. The the option "Redirect incoming PPTP conn... tarz an
07:30 AM Revision 911a262f: Prevent a IPv6 address from breaking system routing. This is a hack because we don't have the proper ip validation in 2.0 mainline
Seth Mos
06:19 AM Feature #1205 (Closed): VPN: User-based / Group-based firewall rules
Firewall rules on a per-user or per-group basis would be very helpfull.
This means we could limit acces to certain ...
Mark Laagland
02:36 AM Revision ff998f10: fix DNS rebinding descr
Chris Buechler
12:07 AM Bug #1130 (Resolved): NAT reflection broken...
Chris Buechler
12:05 AM Bug #1130: NAT reflection broken...
2.0-BETA5 (i386)built on Tue Jan 18 02:47:41 EST 2011 everything works fine!
Problem seems to have been solved.
...
Brian Jensen
 

Also available in: Atom