Activity
From 02/16/2011 to 03/17/2011
03/17/2011
-
08:02 PM Bug #636: layer7 not work correctly
- Please test even with ...
-
03:50 PM Bug #636: layer7 not work correctly
- I was testing and getting the same behaviour as you.
Can you please restart your machines before testing if http will... -
07:57 PM Revision 52bac969: Up the number of packets that gets sent to divert consumers since this count includes for tcp even the 2way handshake count which might hurt the matching. This should possibly fix layer 7 Ticket #636.
-
06:58 PM Revision 3c69c52c: Log the configuration is not the same error message only when this is true. This message would have been shown even when a communication error would occur.
-
11:52 AM Revision 9498c8d7: Fix field lengths for IPv6 addresses
-
11:45 AM Revision c271c485: enlarge various address fields for IPv6 addresses
-
10:59 AM Revision 8a3b09ef: Comment out static mappings, this needs more research
- 10:21 AM Revision 7e5f3edb: Add Total number of CP users graph
-
09:22 AM Bug #1356 (Resolved): IPSec SPD definitions lost after reboot
-
08:55 AM Bug #1356: IPSec SPD definitions lost after reboot
- Thank you. Works as expected now.
-
08:17 AM Feature #1361: DNSMasq, source interface and IPSec VPNs
- well here is my first bit of php coding, so hopefully it is ok. It seems to do what I wanted it to do....
-
04:02 AM Feature #1361 (Resolved): DNSMasq, source interface and IPSec VPNs
- Posts: 1
View Profile Email Personal Message (Online)
DNSMasq, source interface and IPSec VPNs
« on: Mar...
03/16/2011
-
10:03 PM Bug #1126: Duplicate "System Activity" in /etc/inc/priv.defs.inc
- Show Bogonsity? Forgot to remove some text there. By the way, I think the show bogons page no longer exists.
-
09:08 AM Bug #1126 (Resolved): Duplicate "System Activity" in /etc/inc/priv.defs.inc
- Fixed
- 09:05 PM Revision 6f979763: Fix merge conflict
-
07:34 PM Revision af4c040e: Ticket #1356 use locking here rather than ps to serialize execution.
-
07:16 PM Bug #1360 (Closed): Auto PPTP firewall rules don't work if WAN isn't the default route
- If an OPT WAN port is the default route you have to manually add a rule allowing PPTP traffic to the WAN1 Address for...
-
04:15 PM Bug #1356: IPSec SPD definitions lost after reboot
- I have just tested your patch. This is working!
Better than my quick and dirty patch!
Thanks Ermal! -
03:33 PM Bug #1356 (Feedback): IPSec SPD definitions lost after reboot
- Please test latest snapshots a patch has been committed.
-
12:25 PM Bug #1356: IPSec SPD definitions lost after reboot
- Last comment : bug was introduced 14 days ago in commit:e77ecd8e
-
12:23 PM Bug #1356: IPSec SPD definitions lost after reboot
- I have a fix working at home :
In the file /etc/rc.newipsecdns line 47, the check for already running script is al... -
09:13 AM Bug #1356: IPSec SPD definitions lost after reboot
- Yes. Hostnames are used. You can speak with Chris. He knows my IPSec configs.
-
09:09 AM Bug #1356: IPSec SPD definitions lost after reboot
- Hi,
I have the same problem here using DNS hostname endpoints using 2.0-RC1 (i386) built on Mon Mar 14 21:48:11 ED... -
08:31 AM Bug #1356: IPSec SPD definitions lost after reboot
- Do you use hostnames for your endpoints?
-
03:24 PM Bug #1359 (Resolved): Optimize reloading of IPsec tunnels
- Presently when rc.newipsecdns is called it reloads all tunnels for each event.
Rather than do this the ph1id can be ... -
03:01 PM Bug #636: layer7 not work correctly
- I also am able to replicate this issue, tested the same as Seth. L7 containers don't block traffic.
Happy to help in... -
01:33 PM Bug #1358 (Resolved): OpenVPN Upgrade Issue
- There is an issue with certain configurations upgrading OpenVPN from 1.2.3 to 2.0. I have several config samples that...
-
12:28 PM Revision aff70640: Swap if statement, add fields into ipsecpinghosts file
-
12:26 PM Revision e3e85044: Add field 8 for address family
-
12:19 PM Revision 840d845f: Add more helpful logging
-
12:18 PM Revision 80c1e99f: Correct ping hosts functionality for > 1 tunnel. Add v6 functionality
-
11:54 AM Revision ab299d4c: Fix ticket #1126
-
11:36 AM Revision 7916acc3: Change wording
-
11:29 AM Revision fe3801bf: Hopefully improve the useless ipsec logs with highlighting
-
11:27 AM Revision 505483ce: Fix ticket #1354
-
11:16 AM Revision ac463c00: Fix the IPsec ping hosts file generation. This only worked for the last
- tunnel
-
10:38 AM Revision 413a327e: Add v6 entries to the logs
-
09:11 AM Feature #1357: captive portal informations throught SNMP
- This isn't really possible as it is now with our SNMP daemon. We have plans to correct this later, but it's too late ...
-
07:33 AM Feature #1357 (Needs Patch): captive portal informations throught SNMP
- Hi,
It seems that bsnmpd, used in pfSense, is not very extensible.
However, I must get -- throught SNMP -- the ... -
09:10 AM Feature #1169: Add load balancer status in SNMP
- Just a note for when we come back around to this later:
Looks like we might be able to do this with the bsnmp-ucd ... -
09:03 AM Revision bfc0cb5b: Merge remote branch 'upstream/master'
-
08:50 AM Bug #1283 (Resolved): Wording in script for configuring interfaces
- Changed wording
-
08:46 AM Feature #1308 (Rejected): monitor IP on Gateway Groups
- With the way the gateway system is designed this is not possible.
You can add more gateways/monitor IPs, put those... -
08:42 AM Bug #1354 (Resolved): Typo in Packets RRD graph
-
07:46 AM Revision 323f3f9c: Keep a table of gateways we added for static routes to prevent us from making multiple entries to the same IP address
-
07:31 AM Revision 2d74f1cf: Add support for TLS/SSL for notification (tested with smtp.gmail.com port 465)
-
05:28 AM Bug #1348 (Feedback): Multiple static routes that use the same next hop cause apinger issues
- I've coded a fix that keeps a table of what mapping we've created for the static routes.
http://rcs.pfsense.org/proj... -
05:06 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- New test, both logs are here:
When WORKING :
$ setkey -D
95.96.134.40[4500] 91.189.228.158[28909]
esp-ud... -
02:54 AM Bug #1317: Voucher database synchronization
- Hello again,
just thought I let you know, this is still present in current snapshots.
regards
Stefanero
03/15/2011
-
09:31 PM Revision e58da189: Add code to allow custom upgrade code to run after the pfSense upgrade code for the same version switching(Just the custom upgrade functions should have _custom at the end of their name.
-
08:43 PM Revision 85071ea2: Add more colors to themes
-
06:10 PM Bug #1356 (Resolved): IPSec SPD definitions lost after reboot
- It appeard that if 2.0 RC1 is restarted, all SPD definitions are not available post a reboot. Restart of racoon corre...
-
05:59 PM Bug #1355 (Closed): Clearing PPTP Raw Logs does not work
- Pressing "Clear Log" in the "PPTP Raw" screen does not clear the log as intended. It just reload the "PPTP Logins" sc...
-
05:10 PM Revision e2faab6d: Unbreak firewall logs
-
04:56 PM Bug #1342: kernel crash with RC1 on vmware
- Thanks a lot, I will do a "bt" (it crashes several times a week, randomly). I'm not very comfortable with FreeBSD ; I...
-
04:17 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- Is that from when it was working or when it was broken? (We need to see both states)
-
04:16 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- $ setkey -DP
10.1.1.0/24[any] 10.1.1.1[any] 255
in none
spid=2 seq=1 pid=7857
refcnt=1
10.1.1.1[any] 10.1.1.0... -
02:24 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- Don't type the $, that was just there as an example prompt. Diagnostics > Command in the shell execute box should be ...
-
02:23 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- $ setkey -D
$ setkey -DP
How can i give those commands , i've tried via command in GUI but nothing happens
I... -
03:41 PM Revision 1f116988: Enable the IPv6 allow toggle, otherwise the other IPv6 rules do not work.
-
03:30 PM Revision 8336846a: More html fine tuning
-
03:30 PM Revision 8525bd86: Add the IPv6 addresses to the interfaces status widget
-
03:29 PM Revision 98790f61: Try to make IPv6 feature complete for IPv6 support. Looks like ipsec-tools was built without v6 support, make sure you have a newer build
-
03:28 PM Revision b47ceaea: Merge remote branch 'upstream/master'
-
01:53 PM Bug #1354 (Resolved): Typo in Packets RRD graph
- In RRD graph category "Packets", "out-pass" is listed twice instead of "out-block".
-
12:53 PM Revision 401fb0ad: ipfw is not referenced here.
-
12:52 PM Revision 32c392aa: Make sure we have an ip to kill sessions from.
-
12:17 PM Revision 01c201e3: Do more strict checking if an ppp type interface is assigned before starting the mpd process behind it. Trigered-by: http://forum.pfsense.org/index.php/topic,34377.0.html
-
08:59 AM Revision 1ae43bfa: Merge remote branch 'upstream/master'
-
08:12 AM Revision d52a66f9: Fix the link for the easy rule block so that it always fills in the ip protocol
-
04:42 AM Bug #1353 (Resolved): Number of queues possible
- ALTQ algorithm for PRIQ has a forced 15 queue limitation.
While the other algorithms are forced to a 4096 queue limi... -
01:24 AM Bug #1339 (Resolved): Missing icon in "pfsense" theme in the dashboard
-
12:47 AM Bug #1346 (Rejected): Enter Key behaviour while voucher input with IE8
- this isn't a bug in our code base, and has nothing to do with our code base, just need to fix your HTML. this isn't t...
03/14/2011
-
09:09 PM Revision 1778480d: Show the proper Phase entry for the IPv6 tunnels
-
09:03 PM Revision fb17f629: Commit the backend function that writes out the racoon.conf
-
09:02 PM Revision e79b24ab: Extend the IPsec configuration with a protocol family for the phase 1
-
08:40 PM Revision 6c4f3b54: Make sure to note the limitations to gethostbyname, it does not work for Quad A records. Fix resolve_retry in the process, use that.
-
08:30 PM Revision fbcbfa44: Add the dhcp v6 page to the menu, eventhough it is broken. Tabs for later integration
-
08:29 PM Revision c1640267: Add the initial broken dhcp v6 leases page. I have no file to code it. Will wait for later.
-
07:53 PM Revision 96f1a57a: Remove comment since the service is not started anymore after installation in 2.0
-
07:18 PM Bug #1352: DNS forwarder domain override queries timeout if destination server on different subnet
- Jim P wrote:
> The easiest way around this is to add a route on the remote side so that 10.9.4.x goes across the tun... -
05:34 PM Bug #1352: DNS forwarder domain override queries timeout if destination server on different subnet
- Chris Buechler wrote:
> not a bug, you're either blocking that traffic or have a routing issue of some sort. could b... -
05:31 PM Bug #1352: DNS forwarder domain override queries timeout if destination server on different subnet
- Jim P wrote:
> The easiest way around this is to add a route on the remote side so that 10.9.4.x goes across the tun... -
05:19 PM Bug #1352 (Rejected): DNS forwarder domain override queries timeout if destination server on different subnet
- not a bug, you're either blocking that traffic or have a routing issue of some sort. could be moved to a feature requ...
-
05:09 PM Bug #1352: DNS forwarder domain override queries timeout if destination server on different subnet
- The easiest way around this is to add a route on the remote side so that 10.9.4.x goes across the tunnel. No need for...
-
05:02 PM Bug #1352 (Rejected): DNS forwarder domain override queries timeout if destination server on different subnet
- I'm running 2.0-RC1 (i386) built on Mon Mar 7 12:37:11 EST 2011. This is a complicated one to explain but I'll do my ...
-
06:24 PM Revision a3f1fa81: Allow port 547 to the filter rules for DHCP to work
-
05:49 PM Revision a41c5253: Properly configure lighty with the configured port when attached to the v6 socket. It was previously hardcoded to https
-
05:44 PM Revision 209620ea: Add IPv6 support to the DNS rebinding attack function
-
04:11 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- Also can we get the output of the following two commands:...
-
03:44 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- Can you provide ipsec and system log?
-
02:42 PM Bug #1351 (Resolved): Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- When a mobile tunnel is connected for the first time after configuration in pfsense 2.0RC1+shrewsoft client , all tra...
-
03:49 PM Bug #1325 (Closed): some package won't start after install
- A service will not be started anymore after install.
It is changed behaviour from 1.2.x -
03:47 PM Bug #1342: kernel crash with RC1 on vmware
- Can you do a bt at the prompt when this happens?
-
10:43 AM Bug #1350 (Rejected): reboot loop on soekris net4511
- I'm trying to install new PFSense img on my Soekris net4511 and it gets stuck in a reboot loop.
I'm using pfSense 2.... -
07:11 AM Bug #1336: PPTP VPN NAT on WAN or other external interface
- Hi,
Just installed second server with same version but i386 and not amd64 and this problem not exists. so, need to...
03/13/2011
-
04:47 PM Feature #1349 (Needs Patch): DHCP+L2tp/Pptp type connection.
- Description of connection.
http://forum.pfsense.org/index.php/topic,25465.msg178147.html#msg178147
Need to be imp... -
11:18 AM Bug #1348 (Resolved): Multiple static routes that use the same next hop cause apinger issues
- When you have multiple static routes that reference the same next-hop gateway we create multiple apinger targets for ...
03/12/2011
-
12:36 AM Revision 2bf16ba2: Prevent the command wol for being called without propper ip information. Reported-by: http://forum.pfsense.org/index.php/topic,34314.0.html
-
12:26 AM Revision e92916d6: Make sure we do not write stale data during prunning periods.
03/11/2011
-
09:34 PM Revision 3795d067: Add the ability to differentiate between v4 and v6 tunnels. Bill says he can test
-
05:54 PM Bug #1347 (Resolved): ntpd not starting
- Using 2.0rc1 built on Thu Mar 10 22:09:10 EST 2011
the ntpd service is not starting at boot time and
also not star... -
01:37 PM Bug #1334: Traffic Shaper Rules ignored
- I have the same problem. I created my queues, my floating rules (action=queue, quick=checked, direction any, protocol...
-
08:00 AM Bug #636: layer7 not work correctly
- Same problem here - Layer 7 filter isn't working :-(
It would be great if dev team could fix that issue for RC2! ... -
06:55 AM Todo #765: Patch: Add custom DHCP configuration
- My apologies for the incredibly long delay. I've just tested the March 10 snapshot, and there doesn't seem to be any...
-
02:48 AM Bug #1346 (Rejected): Enter Key behaviour while voucher input with IE8
- Hello all,
I am using pfSense 2.0 RC1 build on Thu Mar 10 20:40:57 EST 2011. (AMD64)
There is a strange behaviou... -
01:37 AM Revision d0404e46: Fix typo
03/10/2011
-
11:47 PM Bug #1339: Missing icon in "pfsense" theme in the dashboard
- Perfect, thank you. This can now be considered complete/closed.
-
04:25 PM Revision 64d42525: Clarify text on outbound NAT page.
-
03:49 PM Bug #1345: Static routes to DNS on local subnet should not be added
- By the way, this happened with OPT1 interface, with DHCP of course.
-
03:41 PM Bug #1345 (Closed): Static routes to DNS on local subnet should not be added
- In /sbin/dhclient-script : add_new_resolv_conf(),
it says:
@
# Add a route to the nameserver out the correct in... -
02:11 PM Bug #1344 (Resolved): Replace prototype javascript code with jQuery
- In light of this announcement http://twitter.com/#!/usejquery/statuses/45924060558925825 and due to the steam buildin...
-
01:06 PM Revision 2f23caf2: Correctly generate the interface.
-
01:05 PM Revision 298ca201: Define only one loginterface since that is what pf(4) allows. This prevents a memory leak from pfctl(1) which may lead to memory depletion if the utility is run frequently with the pfSense generated ruleset.
-
10:24 AM Bug #1343: 25% performance hit
- Jim P wrote:
> This may not be a bug, but a configuration issue, driver issue, etc. Use the forum (http://forum.pfse... -
10:15 AM Bug #1343: 25% performance hit
- This may not be a bug, but a configuration issue, driver issue, etc. Use the forum (http://forum.pfsense.org) and pos...
-
10:13 AM Bug #1343: 25% performance hit
- Jim P wrote:
> Please post in the forum with details for diagnosis. That detail alone isn't a valid bug report.
w... -
10:07 AM Bug #1343 (Rejected): 25% performance hit
- Please post in the forum with details for diagnosis. That detail alone isn't a valid bug report.
-
10:06 AM Bug #1343 (Rejected): 25% performance hit
- between 1.2.3 and 2.0-rc1, have lost 25% of bandwidth. configuration is identical, but uninstalled snort just to be ...
-
08:55 AM Revision 36653869: Remove extra unmatched conf_mount_ro for a potential race condition preventing writes when generating ssh keys in the background. Ticket #673
-
07:32 AM Revision 48ab12a9: Remove quick from the filter rule by request of Erik.
-
07:31 AM Revision 05c8d0b1: Correct the config path to the upnp array, this prevented the filter rule from being generated
-
05:17 AM Bug #1342 (Closed): kernel crash with RC1 on vmware
- Attached, a screenshot of a kernel crash... do you have any idea ?
It's RC1 on a VMWare guest.
Thanks by advanc... -
04:30 AM Bug #1279: Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
- Specifically it was commit:52f4c092b14cca36bcc430717baf907273b66532
I don't think I saw the discussion on this, so... -
04:12 AM Bug #673: SSHD keys not created on restore
- Right now it is left rw (not sure why it was done; this is only temporary, it will be fixed). When that is changed b...
03/09/2011
-
09:21 PM Revision 15294580: Add the IPv6 tag to the version so that BSD perimeter can seen these installs from a mile away
-
09:14 PM Revision 47cc98de: Correctly use the WAN macro definition for the interface on 2.0. Though i still insist that people should do this themselves rather than relying on some obscure gui option.
-
07:49 PM Revision 28a581b8: Add {} around foreach contents. Fixes occasional duplication of the easyrule block alias.
-
07:49 PM Revision a0140246: Add block rule to the top of the firewall rules.
-
06:54 PM Revision 021b77af: If PPTP is set for redir, actually add the NAT rules to rdr.
-
06:19 PM Bug #1341 (Resolved): Removing last host from alias does not truly remove it, host continues to be affected by rules
- Under certain circumstances the contents of an alias can still be affected by rules after having been removed from th...
-
06:03 PM Revision fa182351: Only delete files in /tmp, not directories. Fixes rm errors on shutdown. (Doing rm -rf might cause it to go across filesystem boundaries again, which we're trying to avoid.)
-
04:23 PM Revision b043503a: Teach the console update by url about the default auto update url.
-
01:40 PM Revision 354796f0: Unbreak the rrd graph img page
-
12:53 PM Revision 15f2cdc3: Merge remote branch 'upstream/master'
- Conflicts:
usr/local/www/status_rrd_graph_img.php
usr/local/www/themes/pfsense_ng/rrdcolors.inc.php -
12:27 PM Revision 947fe874: Correct firewall rule, remove flags any
-
12:04 PM Revision a3dd71ee: Merge remote branch 'upstream/master'
-
11:51 AM Revision f22c9ae2: Merge remote branch 'upstream/master'
-
11:50 AM Revision 9c5ad167: unbreak the broken merge
-
11:45 AM Bug #1270 (Resolved): bug with captive portal widget
-
11:35 AM Revision 272c5d62: Automatically add a multicast allow rule for miniupnpd so that the Xbox 360 works.
-
10:58 AM Revision a6917c65: Add the 95th percentile line to the traffic graphs
-
10:48 AM Revision c7cfc098: Possible double RRD process fix.
-
07:20 AM Revision 9956b38a: Merge the config upgrade code, there was a mismatch, the one who merged this wrong should get a pointy hat.
-
07:13 AM Feature #796 (Feedback): Add 95th Percentile Line to RRD
- 95th percentile calculation line added to the traffic graphs
http://tinyurl.com/4lo4k83
03/08/2011
-
10:35 PM Revision fdc0e920: Add localhost to be natted automagically from auto-generated nat rules. This simplifies loadbalancing from the host itself.
-
10:14 PM Revision 01890f6a: Fix javascript errors reported by: http://forum.pfsense.org/index.php/topic,34139.0.html
-
09:30 PM Revision 53bd5790: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/rrd.inc -
08:02 PM Revision 55805397: Add missing image. Fixes #1339
-
07:37 PM Revision 4db0365d: Keep the output in a variable before passing it to rrdtool in case we also want to pass it to something else.
-
07:18 PM Revision ae3c0a12: Only run pfctl once per interface for stats, rather than four times.
-
05:54 PM Bug #1338 (Closed): captiveportal_prune_old no longer works
- I hae put a patch separately of this.
Thanks for the prompt patch though. -
08:28 AM Bug #1338: captiveportal_prune_old no longer works
- *OOOOooooops... s/for/foreach/ in the patch. Sorry !!*
New patch below.
-
08:21 AM Bug #1338 (Closed): captiveportal_prune_old no longer works
- In /etc/inc/captiveportal.inc, captiveportal_read_db now returns a array() with sessionid.
captiveportal_prune_old... -
05:47 PM Revision 3e5c0ab7: Use foreach here to be sure we do not reference unexisting results.
-
03:58 PM Bug #1340 (Resolved): PPTP Rar "Clear Log" button does not work
- The "Clear Log" button located at: *Status --> System Logs --> VPN --> PPTP Raw* Does not clear the PPTP Raw log.
- 03:37 PM Revision 375eed5a: Merge remote branch 'upstream/master'
-
03:23 PM Revision 13927322: Do a proper test otherwise a override of the total_minutes var might happen.
-
03:16 PM Revision c4ea3691: Properly do testing of voucher existing or not rather than relying on an obscure feature of php. Also do exclusive locking rather than shared one when writing dbs.
-
03:05 PM Bug #1339 (Feedback): Missing icon in "pfsense" theme in the dashboard
- Applied in changeset commit:"55805397110a8d786d0e6a9edfaa3d3557588540".
-
02:43 PM Bug #1339 (Resolved): Missing icon in "pfsense" theme in the dashboard
- The icon located at themes/pfsense/images/icons/icon_info_pkg.gif is missing.
This icon is called from the dashboard... -
08:40 AM Bug #1336: PPTP VPN NAT on WAN or other external interface
- i tested. NAT is working but some thing wrong with checksum calculation. as i see traffic is dropped by first WAN rou...
-
08:37 AM Bug #1317: Voucher database synchronization
- Hi,
I think I found kinda relation between the duration of the voucher and the length of the ticket.
Looks like... -
08:14 AM Revision d2627d7c: Correct the link to the proper page for deleting a static mapping
-
07:46 AM Bug #1270: bug with captive portal widget
- Tried : this bug is resolved by latest CP patches. Thanks !
-
07:06 AM Feature #1337 (Assigned): VLANs with different MAC address than parent interface
- In FreeBSD it is possible to host an vlan(4) with a different mac address from the parent.
This needs the parent in... -
04:15 AM Bug #1327: RFC 2136 dynamic dns bug
- I can confirm this bug, the zone information mus be supplied, otherwise the request won't be accepted by RFC2136 comp...
03/07/2011
-
10:45 PM Revision 6b5e978b: Use racoonctl now that ipsec-0.8 is back to reload the config.
-
09:42 PM Revision 06d30ce7: Handle the case on some special configs with a gateway of all 1's otherwise strange thing happens.
-
08:03 PM Revision 214bd062: Fix typo
-
06:43 PM Bug #1336: PPTP VPN NAT on WAN or other external interface
- probably not a legit bug there (item 1 is how PPTP works, item 2 is not true and looks like a config problem in your ...
-
06:35 PM Bug #1336 (Closed): PPTP VPN NAT on WAN or other external interface
- I have PPTP server on 2.0-RC1 latest build. i have multiple internal and external interfaces.
I have following probl... -
05:53 PM Bug #1335 (Not a Bug): Scheduled Floating Queue Rules not prioritized correctly.
- When you configure a Floating Queue rule with a schedule, it prioritizes it above all other rules when the schedule i...
-
05:52 PM Bug #1334: Traffic Shaper Rules ignored
- BTW, I've confirmed this issue on 2 seperately configured routers. I have 2 wan, 1 lan, gateway with failovers in th...
-
05:45 PM Bug #1334 (Resolved): Traffic Shaper Rules ignored
- I was trying to add some queue rules to the Floating Rules for traffic shaping. The system allows you to add a "PASS"...
-
05:25 PM Bug #1333 (Resolved): Rate causes high CPU usage
- The rate package that provides the breakdown of which ips are using how much bandwidth on the traffic graph seems to ...
-
05:24 PM Revision a5ccf623: Add cas(4)
-
03:07 PM Revision e8567e89: When doing conf_mount_ro/rw on NanoBSD, pass sync,noatime to mount to preserve the options we have already set in fstab. Ticket #1279 and Ticket #444
-
01:14 PM Bug #1332 (Closed): Autoupdate erases line in /etc/sysctl.conf which was created by LiveCD
- Before running autoupdate from amd64-BETA5 (Feb 5 snapshot), the following line is present in /etc/sysctl.conf:
k... -
10:10 AM Bug #1331 (Rejected): Layer7 filtering not working
- Version 2.0-RC1 (i386)
built on Thu Mar 3 10:28:28 EST 2011
I have a layer7 container created with several traf... -
08:38 AM pfSense Packages Bug #585: Unable to start the ntop service
- See additional related errors in #1285 and #1330
-
08:36 AM pfSense Packages Bug #1330 (Closed): ntop library missing
- Duplicate of/same issues as #585
-
08:30 AM pfSense Packages Bug #1330 (Closed): ntop library missing
- # ntop
/libexec/ld-elf.so.1: Shared object "librrd_th.so.5" not found, required by "ntop"
-
08:36 AM pfSense Packages Bug #1285 (Closed): NTOP error in 2.0 RC-1
- Duplicate of/same issues as #585
-
08:14 AM Revision ae091de3: Commit the forgotten edit page for the dhcpv6 reservations
-
08:04 AM Bug #1329 (Rejected): Update Error
- Without telling us specifically what error you encountered, this is not a valid bug report.
Just a guess, but you'... -
02:50 AM Bug #1329 (Rejected): Update Error
- 2.0 Snapshot version - Invoke Auto Upgrade is working fine.
2.0 RC1 Fresh Install - Invoke Auto Upgrade, after downl... -
08:02 AM Bug #1328 (Rejected): Packages not working
- Please post on the forum for help. There is not enough detail here to constitute a valid bug report, and many others ...
-
02:04 AM Bug #1328 (Rejected): Packages not working
- Packages not working, but running.
examples.
imspector,squid,snort were configured, but no logs captured.
fresh in...
03/06/2011
- 09:18 PM Revision b4c826ad: Resolve merge conflict
-
07:44 PM Revision 283e9180: More fixes to differentiate between v4 and v6 gateways on the same interface.
-
07:37 PM pfSense Packages Bug #1026 (Resolved): bandwidthd makes bad assumptions about subnets
- fixed by lgcosta
-
07:37 PM Bug #1327 (Resolved): RFC 2136 dynamic dns bug
- Per this forum post: http://forum.pfsense.org/index.php/topic,33824.0/topicseen.html I am submitting a bug report:
... -
07:17 PM Revision de140730: First stab at generating a link local address for the bridge interface if it's used by DHCP.
03/05/2011
-
07:23 PM Feature #1326 (Resolved): OpenVPN Server in tap mode
- The ability to setup an OpenVPN server in bridge mode would be nice.
-
03:34 PM pfSense Packages Bug #1301: Squid package become unusable through time if we use large disk cache
- Louis-David Perron wrote:
> This happens when we use the default path for the cache dir (/var/squid/cache).
>
> T... -
03:27 PM Bug #1325 (Closed): some package won't start after install
- Confusing though. *Starting service* but doesn't do anything within the code.
/etc/inc/pkg-utils.inc
@} else {
... -
07:49 AM Bug #754: hifn driver and AES192 and 256
- Below I've posted results for the following series of commands, so you get a summary as well as all the output:
# ...
03/04/2011
-
10:05 PM Revision fd4151a9: Enforce session establishment.
-
10:02 PM Revision bb7469ca: Enforce session establishment.
-
10:00 PM Revision de4333ba: Enforce session establishment.
-
09:53 PM Revision 9fbb3599: Add missing pages to the authentication system.
-
08:50 PM Revision c53eb903: Be smart and remove the needs package sync toggle since the begining otherwise not behaving packages might mess up the whole thing.
-
08:27 PM Revision ce1942d6: Oops more make code correct.
-
08:24 PM Revision 328c1def: Oops make code correct.
-
08:15 PM Revision 006802ab: * Prevent concurrent logins on CP to not be recorded on the DB.
- * Make the locking more complex to avoid locking exclusively during pruning task which would hurt a lot CP performanc...
-
07:52 PM Bug #1292: PPTP server with Radius breaks on upgrade from 1.2.3 to 2.0
- here's a pretty stock config that exhibits problems
-
04:28 PM Bug #1292: PPTP server with Radius breaks on upgrade from 1.2.3 to 2.0
- Can you post your pptp section from the 1.2.3 config?
-
06:11 PM Bug #1251: /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
- Ermal Luçi wrote:
> From post_upgrade_command.php
> [...]
>
> Shouldn't that be unconditional?
Shouldn't run ... -
04:27 PM Bug #1251: /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
- From post_upgrade_command.php...
-
05:37 PM Revision 9ccecb65: If the interface triggering rc.newwanip is not assigned just reload packages and the filter and exit.
-
04:53 PM Feature #620: No privilege choice to allow access to Dashboard
- Although that is not easy on 2.0
You need to add also
Allow access to the 'XMLRPC Interface Stats' page. -
04:34 PM Bug #1107 (Feedback): mpd on AMD64 generates invalid checksums with NAT
- You should be able to fix this by setting a MSS or lowering the mtu on openvpn interface. MTU seems to be your problem.
-
04:32 PM Bug #1270 (Feedback): bug with captive portal widget
- Can you please try latest snapshot.
I incidentally should have resolved this as well during locking fixes on CP. -
04:20 PM Bug #1310: Check pakcage .inc files before including to avoid potential breakage
- That is too much overhead to be done dynamically.
eval() was supposed to help here but you cannot catch fatal parser... -
04:18 PM Bug #1318: Certificate error: certificate subject does not match signing request subject
- Can you show the subject that is displayed on pfSense screen of the signing request?
-
04:01 PM Revision 17a5b095: Correct one more variable in the process
-
03:51 PM Revision 4f332466: Fix broken gateway logic that mixed up v4 and v6
-
01:09 PM Revision 1b761f36: Check if the protocol is empty, not just if it's set. Fixes #1323
-
01:04 PM Revision 1c1a74fa: Only change protocol if it's set and not empty.
-
08:10 AM Bug #1323 (Feedback): Wrong rule file generation with build "Thu Mar 3 19:27:51 EST 2011"
- Applied in changeset commit:"1b761f36b7c2c484f894e6412a1efad769533696".
-
06:16 AM Bug #1323: Wrong rule file generation with build "Thu Mar 3 19:27:51 EST 2011"
- /etc/inc/filter.inc, change line 1763 into
if(isset($rule['protocol']) && !empty($rule['protocol'])) { -
05:45 AM Bug #1323 (Resolved): Wrong rule file generation with build "Thu Mar 3 19:27:51 EST 2011"
- The file which creates rules for pf (probably filter.inc), is creating wrong lines for rules which have no specific p...
-
02:59 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
- I am seeing this behaviour on RC1 (and was also on several Beta 5 builds prior to updating to RC1) with a 3G connecti...
03/03/2011
-
09:13 PM Revision 7ec0e6e2: Add upgrade code to ensure rule protocols are all lower case.
-
08:40 PM Revision 06b3df52: Make this lowercase before checking, or people who ended up with TCP or UDP in their config might end up with rules that have no port specified, leaving them a bit more open than expected.
-
08:30 PM Revision 4e8e7662: Blind coded a edit page for IPv6. the subnet check needs to be written entirely. Checking if the IP address falls within the v6 subnet isn't so hard, what is harder is making sure that the ip does not fall within the dynamic subnet. For that we need proper subnet math calculus. Which we don't have yet.
-
08:18 PM Revision 11085d2a: Add the neighbour table to the menu
-
08:16 PM Revision aed47758: Fix the link to point to the v6 edit page instead
-
08:15 PM Feature #1322 (Rejected): Squid 3
- Im adding packages, squid3 is marked as alpha,
this is correct? ?? ?? -
08:13 PM Revision 0461114f: Add the IPv6 Neighbour list status page
-
04:56 PM Bug #1320 (Closed): make src-nodes configurable
- already done in 2.0
-
04:44 PM Bug #1320 (Closed): make src-nodes configurable
- We recently run into the 10,000 src-nodes limitations on our firewall (1.2.3) and had to increase it manually.
Her... -
04:54 PM Feature #1321 (Closed): Expose the maximum number of state entries a rule can create
- We recently ran into an issue where we ran out of state entries which effectively made the firewall unresponsive. Sti...
-
04:30 PM Revision 4f4e85df: Make sure we tell the code that the interface exists otherwise multiple laggs might get created.
-
04:30 PM Revision ee487a68: Not needed anymore.
-
02:24 PM Revision 6be90004: Ensure the protocol on the firewall rule from the OpenVPN wizard ends up lower case, or it causes some GUI irregularities. Seen http://forum.pfsense.org/index.php/topic,33865.0.html and elsewhere.
- 05:42 AM Revision 67b0ed57: lower limit to 101 MB
-
01:56 AM Bug #560 (Resolved): loader.conf is empty after a firmware update.
- overwriting the changes is normal and unavoidable, just make sure your customizations are in .local and you can make ...
-
01:26 AM Bug #560: loader.conf is empty after a firmware update.
- Just upgraded from 1.2.3 Embedded to 2.0-RC1 Embedded. Loader.conf was NOT blank, but the changes I had put in there...
-
01:24 AM Bug #560: loader.conf is empty after a firmware update.
- Just upgraded from 1.2.3 Embedded to 2.0-RC1 Embedded. Loader.conf was NOT blank, but the changes I had put in there...
-
12:42 AM Bug #1319 (Closed): Memory Warning on 128MB
- Because when you tell vsphere to give 128 MB RAM, it only gives 102 MB usable to the OS. ...
03/02/2011
-
11:54 PM Bug #1319 (Closed): Memory Warning on 128MB
- Hi,
I'm running the latest 2.0-RC1 (built on Wed Mar 2 17:47:38 EST 2011) on a vSphere 4 VM with exactly +128MB o... -
08:24 PM Bug #636: layer7 not work correctly
- I am identical to Adam. Running 2.0-RC1 (i386) built on Wed Mar 2 12:33:12 EST 2011.
I have a L7 container for blo... -
07:26 PM Bug #1318 (Resolved): Certificate error: certificate subject does not match signing request subject
- Hi - I'm trying to apply a certificate from StartCom/Startssl.com to my PFSense 2.0-RC1 (amd64) -built on Wed Mar 2 ...
-
05:24 PM Revision 56f25370: Simplify is_macaddr regex.
-
05:08 PM Revision c5682801: Slight regex fix on is_macaddr - the previous regex was letting through a mac without : separators, leading to improper validation and potentially invalid dhcp configs. Seen here http://forum.pfsense.org/index.php/topic,33830.0.html
-
03:25 PM Bug #754: hifn driver and AES192 and 256
- pfSense 2.0-RC1-nanoBSD (i386) built on Sat Feb 26 16:33:51 EST 2011
Running on Soekris net5501 with Hardware crypt... -
02:09 PM Revision 199791f9: Show friendly names of interface for root queues of ALTQ.
-
01:57 PM Revision 93c1127f: Add GUI option to CARP settings for syncing certs. It was in the backend code but not the GUI. Fixes #1316
-
11:52 AM Revision e77ecd8e: Attempt to mitigate fork bombs of rc.newipsecdns. Alternatively we should probably bail out with a exit(0);
- instead.
-
09:39 AM Revision e269b621: Merge remote branch 'upstream/master'
-
09:14 AM Revision d161b4d4: Always write out the filterdns-ipsec.hosts file, otherwise deleted tunnels will never get removed from the
- filterdns-ipsec.hosts
-
09:08 AM Bug #1317 (Resolved): Voucher database synchronization
- I have 2 pfsense, one in the DMZ and one in LAN.
The LAN manages the vouchers,
on the page -> status_captivepor... -
09:00 AM Bug #1316 (Feedback): User certificates are not synced to backups via XMLRPC
- Applied in changeset commit:"93c1127fd84ee4c7ced02dcdee39db3eb93612f1".
-
08:14 AM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
- Most likely you're looking at /etc/openvpn.inc and /usr/local/www/vpn_openvpn_server.php - and if you want to fixup t...
-
08:08 AM Revision bb3c6562: Add the toggle to disable successful login messages, show actual help text for redirect item
-
07:47 AM Revision 4fc3855f: Make it possible to turn off successful login messages, this should quiet the console, system logs
-
07:21 AM Revision 829fa12e: Add a check that should prevent configuration of racoon with duplicate phase 1 IP entries.
-
04:51 AM Revision baca83aa: Fix page title text. Replace "Firewall" with "Interfaces" in title.
-
12:25 AM Revision 539d5973: Remove custom code for checking ip_addr and use the pfsense provided one.
-
12:23 AM Revision cf46a14f: Do not be so drastic on normal failure.
-
12:21 AM Revision dcc897e5: Since its only called during bootup there is no need to do conditionals here. Always sync config and start the miniupnpd process.
-
12:18 AM Revision 88cbd62a: More fixes to comments and code for upnpd. Also bring up to speed the stop/start logic.
-
12:05 AM Revision 2816f43f: Improve logging and some tests during miniupnpd config generation.
03/01/2011
-
11:51 PM Revision b469b7fe: This is not true anymore as piece of code.
-
11:46 PM Revision 8df14984: Correctly get only the interface mac address rather than any other found mac on this interface.
-
11:40 PM Revision 05c4bfa0: Pass the -a parameters to pgrep to be certain we search ancestors as well. The side effects might be inoquos from the pfSense context.
-
06:18 PM Revision c8487604: Use the call to basename to remove the extension rather than trim, since trim takes a list of characters, not the exact string to remove. Suggested by http://forum.pfsense.org/index.php/topic,32967.0.html
-
06:03 PM Revision 8b19f4a7: This is not NAT, so put it under the Firewall Advanced heading instead.
-
05:19 PM Bug #1316: User certificates are not synced to backups via XMLRPC
- Thanks, I searched a few times before submitting... hoping I didn't just miss something due to lack of sleep.
I ... -
05:12 PM Bug #1316 (New): User certificates are not synced to backups via XMLRPC
- I'll have to double check this tomorrow. I could swear I made a separate option for syncing certificates but I don't ...
-
05:07 PM Bug #1316 (Feedback): User certificates are not synced to backups via XMLRPC
- Certificates are synced if you have the option set on the CARP settings to sync them. User certificates are no differ...
-
05:04 PM Bug #1316 (Resolved): User certificates are not synced to backups via XMLRPC
- When firewalls A and B exist and A replicates settings to B through XMLRPC, user accounts on A are synced, as expecte...
-
03:50 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
- Jim/Chris,
I plan on getting an important box updated to 2.0rc1 which requires secondary auth via ldap with SSL/TLS.... -
02:57 PM pfSense Packages Bug #1315: ERROR 404 on packages area upper-left logo of psense.
- /usr/local/www/fbegin.inc
@line 238
<div id="header-left"><a href="index.php" id="status-link"><img src="/themes... -
02:52 PM pfSense Packages Bug #1315: ERROR 404 on packages area upper-left logo of psense.
- reported by matrix3000
-
02:49 PM pfSense Packages Bug #1315 (Closed): ERROR 404 on packages area upper-left logo of psense.
- /usr/local/www/fbegin.inc
line
<div id="header-left"><a href="*index.php*" id="status-link"><img src="/themes/<?... -
02:02 PM Bug #636: layer7 not work correctly
- Still not working for me, Clear states and can still browse http. I only have one layer 7 container, and http is sele...
-
01:11 PM Revision 2936a57e: add subnet mask clarification for IPv6 and correct default count to 128 bits
-
01:06 PM Revision e53de0b3: Merge remote branch 'upstream/master'
-
10:16 AM pfSense Packages Bug #1314 (Resolved): Typo in snort package /s/viwed/viewed
- Typo on the following page /snort/help_and_info.php
"viwed" is missing an "e" -
10:09 AM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
- Boot to single user mode, touch /conf/needs_package_sync, and then reboot.
-
10:07 AM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
- This is still an issue:
Install new VM from 1.2.3-Release LiveCD
Install Open VM Tools
Use automatic updater to ... -
09:07 AM Bug #1313 (Rejected): 1:1 NAT missing /32 Option
- Pierre is right. For /32, don't choose the Network option, use the Single Host option.
-
08:51 AM Bug #1313: 1:1 NAT missing /32 Option
- Hum... If you want to use a /32, use a "single host" for "type" field in the screen.
So I don't think this is a bu... -
08:44 AM Bug #1313 (Rejected): 1:1 NAT missing /32 Option
- The 1:1 NAT configuration page firewall_nat_1to1_edit.php is missing the option for a /32 subnet to be assigned, the ...
-
03:26 AM Bug #1312 (Closed): NAT reflection/DNS Forwarder broken again
- The RC1 i386- 20110226-1530 release has NAT reflection NOT working.
No matter if you enable or disable NAT reflect...
02/28/2011
-
11:03 PM Bug #1137 (Resolved): Global reply-to disable checkbox missing from 2.0
- confirmed works, thanks
-
04:16 PM Bug #1137: Global reply-to disable checkbox missing from 2.0
- *Feedback:* Fixed or Works-for-me
*Recommendation:* Close ticket or request details
*Findings:*
Running RC1 buil... -
10:20 PM pfSense Packages Bug #1236: Anyterm package doesn't start after upgrade
- Just upgraded to RC1, same issue.
-
07:02 PM Revision 87ae1a2b: Fix page title.
- 06:28 PM Revision 6f5b2ff5: Merge remote branch 'upstream/master'
-
05:25 PM Revision 566193a5: Only make gateway changes if we have been given a new gateway IP.
-
05:21 PM Revision d7b4e38f: Setup gateway monitoring since we just altered a gateway.
-
05:16 PM Revision e121bebd: Fix gateway handling in setup wizard.
-
04:42 PM Bug #636: layer7 not work correctly
- Bump.
Does this ticket's status need to be changed to Feedback? -
04:12 PM Revision 2d539f40: Only display gitsync settings on supported platforms.
-
03:53 PM Bug #1309 (Resolved): Firmware upgrade
- thanks
-
03:49 PM Bug #1309: Firmware upgrade
- *Feedback:* Fixed.
*Recommendation:* Close ticket.
*Findings:*
Running RC1 build "Sat Feb 26 16:00:14 EST 2011" ... -
03:53 PM Bug #1306: Load balancer user _relayd not created on upgrade
- Alex Kennedy wrote:
> From /etc/pass line 20 after upgrade
Should Read:
> From */etc/passwd* line 20 after upgrade -
03:33 PM Bug #1306 (Resolved): Load balancer user _relayd not created on upgrade
- Thanks for the feedback!
-
03:32 PM Bug #1306: Load balancer user _relayd not created on upgrade
- *Feedback:* Fixed.
*Recommendation:* Close ticket.
*Findings:*
Upgrade from 1.2.3 to RC1 build "Sat Feb 26 16:00... -
02:31 PM Bug #1311 (Closed): Cosmetic problem
- Hello,
I found one "cosmetic" problem on the update page. Take a look at the pic.
Regards,
Bohosh
02/27/2011
- 09:21 PM Revision 4e0cb56e: Merge remote branch 'upstream/master'
- 08:50 PM Revision cfaf6e69: Only show the you can monitor the filter reload process for filter related changes
- 08:43 PM Revision 58b4b246: Flush the buffer
-
11:33 AM Bug #1310 (Resolved): Check pakcage .inc files before including to avoid potential breakage
- To prevent a broken package from causing even more breakage, we should probably do a check on the package .inc files ...
02/26/2011
-
09:58 PM Bug #1097: Onload Javascript on Rules page of management GUI
- I can confirm the onload javascript issue seems to be fixed when in Firefox (win32) on the following build;
2.0-BE... -
07:20 PM Revision 4ed69f33: Do a more strict check on the return value of the download function. Fixes #1309
-
04:40 PM Revision 153e3cb5: Declare $g a global here.
-
04:34 PM Revision 73d885d7: Ensure the pkg staging area exists on nanobsd before trying to use it.
-
02:20 PM Bug #1309 (Feedback): Firmware upgrade
- Applied in changeset commit:"4ed69f3394a336c2fe6c8fa81741e55036bd70b7".
-
02:05 PM Bug #1309 (Resolved): Firmware upgrade
- If a firmware upgrade is attempted through system_firmware_check.php, and the target url is unavailable, a non HTML f...
02/25/2011
- 10:14 PM Revision 0c4f8ca8: Merge remote branch 'upstream/master'
- 05:45 PM Revision 17e7a243: missing $
- 05:44 PM Revision da666ca8: missing $
- 05:42 PM Revision a6f4ac66: misc whitespace cleanups
- 04:37 PM Revision 0c13af6c: Give this another shot
-
03:26 PM Revision ebcdcaaa: Fix admins group permission setting when upgrading from 1.2.3.
-
09:27 AM Revision bc75a430: Correct IPsec carp interface upgrade code, off by one
-
08:03 AM Feature #1308 (Rejected): monitor IP on Gateway Groups
- We have a unusual network scenario that uses failover. It used to work on pfSense 1.2.3, but now on 2.0 it isn't work...
02/24/2011
-
08:25 PM Feature #1307 (New): Request: Option To Resolve Addresses in State Table Summary
- Would you please add a mechanism to resolve addresses listed in the state table summary? Perhaps a link next to each ...
-
06:51 PM Revision a09d8bfc: Use full path to pw
-
06:50 PM Revision 2aba8f77: Add missing _relayd group, and when upgrading from 1.2.3, add _relayd group and user.
-
06:20 PM Revision 072bc34c: Correct the test which displays an error if someone chose to save+test but doesn't have an ldap backend. Also, fix a typo.
-
03:51 PM Revision bcc85621: Fix find again... apparently -xdev is depreciated and tosses errors, replaced by -x
-
03:46 PM Revision 22beab88: Move this code up a bit and also use /root/tmp to fetch packages instead of /tmp so it won't fill up.
-
03:37 PM Revision 9011a843: If we're on nanobsd, pass -t to pkg_add to specify a different "staging area" path.
-
02:31 PM Bug #1306: Load balancer user _relayd not created on upgrade
- Yes, new upgrades that happen on snapshots that include the commit I referenced will work fine. I changed the upgrade...
-
02:24 PM Bug #1306: Load balancer user _relayd not created on upgrade
- Yes adding the user does get the relayd service running. I wanted to open the bug so that the upgrade procsess can b...
-
01:53 PM Bug #1306 (Feedback): Load balancer user _relayd not created on upgrade
- Should be fixed commit:2aba8f77a2c0de6690f973e331f130000d35c451
If you've already upgraded and you are missing the... -
01:09 PM Bug #1306 (Resolved): Load balancer user _relayd not created on upgrade
- If upgrade from 1.2.3 to 2.0-Beta5 built on Fri Feb 18 06:31:46 EST 2011, the user _relayd which is needed for load b...
-
02:23 PM Revision 62958eae: Correct the vlan upgrade code to continue when we fixed up the interface
-
02:17 PM Revision 583f4913: Correct the find command, pipe into xargs
-
01:10 PM Revision 563b47bf: Make sure to resolve the gateway name before passing it off to the IPsec reload function
-
01:10 PM Revision 3acab378: Correct variable name. This could never have deleted the static route for IPsec vpns on multi wan
-
11:11 AM Bug #1051: radius support in racoon
- I found the issue, next snap should be OK.
-
11:10 AM Bug #1051: radius support in racoon
- it's on amd64
-
11:03 AM Bug #1051: radius support in racoon
- Need more info, i386 or amd64?
-
11:01 AM Bug #1051: radius support in racoon
- hello
I've just updated the system to build from Feb 23th 2011 and the issue reappeared.
02/23/2011
-
07:09 PM Revision 003d1b3d: And one more place for PKG_TMPDIR... just in case.
-
07:07 PM Revision 633ef551: Set PKG_TMPDIR here too, to help nanobsd pkg installs.
-
05:49 PM Revision c99c1e4e: Allow queues on top of bridge. Though more investigation is needed on its correct meaning.
-
05:36 PM Revision 6c67a28d: Set PKG_TMPDIR for embedded/nano because it will fill up /var trying to download packages otherwise. (From sullrich)
-
05:14 PM Revision 0030036f: Don't forget to clear username field so it doesn't show up on next edit.
- And if for some reason user enters a username, store it for them.
-
05:06 PM Revision ec465066: Merge branch 'master' of rcs.pfsense.org:pfsense/mainline
-
05:05 PM Revision d9cc4b24: Try again, a little cleaner: Prevent GUI from giving error for freeDNS service since username and password
-
04:54 PM Revision 1f9d17ef: Revert "Prevent GUI from giving error for freeDNS service since username and password"
- This reverts commit 740f745922549283e29d3d964c7a60266d7dbf0a.
This is a little ugly. Let's do it a little differently. -
03:05 PM Revision 62ce9874: Update "Last Tested" date for freeDNS in comments
-
03:00 PM Revision 740f7459: Prevent GUI from giving error for freeDNS service since username and password
- aren't required.
Also add a note for freeDNS users to enter "Authentication Token"
in Hostname field. Zero out fake ... -
02:45 PM Revision 4aa58d46: Correct the config path to the vip array
-
02:19 PM Revision 443f2e6e: Attempted fix that should convert the old carp[$i] naming to vip[$vhid]
-
02:07 PM Revision 3d039701: Make sure we iterate by the vlan number lest we end up with a empty variable? Hopefully fix new vlan name not being assigned to interfaces section
-
02:01 PM Revision 685a26fc: Correct the gateway group member name to the correct GW_". strtoupper($if) uppercase. This fixes outbound load balancer pools upgraded from 1.2.3
- not working
-
01:55 PM Revision 219585da: Do not cross filesystem boundaries when removing files lest we empty Seth' USB stick
-
01:13 PM Feature #1305 (Resolved): Queue Action should have its own symbol on the floating tab
- On the firewall rule floating tab, where it shows the list of all the floating rules, the "Queue" action should have ...
-
01:07 PM Bug #1304 (Resolved): Quick option ignored for "Queue" action rules on floating tab
- Hi,
I'm running 2.0-BETA5 (i386) built on Wed Feb 23 00:12:28 EST 2011.
Today I put 2 rules on the floating ta... -
08:03 AM Revision a299232e: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/filter.inc
etc/inc/vpn.inc -
02:32 AM Revision b8778031: Add a check if the configuration of dhcpd exists for wan before unset, resolves #1303
02/22/2011
-
10:31 PM Revision c54c9d15: Remove direction from traffic shaper generated rules now that the match action is present to correctly put packets on proper queues. Before it was not possible since this would have also open firewall ports/holes.
-
09:35 PM Bug #1303: Removal interface without setting of wan causes error unset
- Applied in changeset commit:"b877803194700f75cb264e7343695acf971fa07e".
-
09:33 PM Bug #1303 (Feedback): Removal interface without setting of wan causes error unset
-
09:26 PM Bug #1303 (Resolved): Removal interface without setting of wan causes error unset
- When trying to remove an interface on the assignment of interfaces, when we rename the wan interface or the definitio...
-
07:29 PM Revision 2d1298ce: Reset this var before this test, otherwise if the test is skipped, it will carry over the value from the previous run.
-
07:29 PM Revision 8364184a: Don't consider a cert as in use by the GUI if it's in HTTP mode. Fixes #1171
-
07:27 PM Revision ac631bba: Move all functions from index.php for captiveportal.inc
-
02:39 PM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
- Probably the same issue now as #1251 - /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0, s...
-
02:36 PM Bug #1251: /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
- This is really a base system problem and not a problem with this package.
-
02:36 PM Bug #1251: /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
- The real problem here is that /tmp/post_upgrade_command.php is not being run after the 1.2.3 to 2.0 upgrade completes...
-
02:30 PM Bug #1171 (Feedback): Switching from HTTPS to HTTP does not mark certificate as unused
- Applied in changeset commit:"8364184a866a6fb0f75b3368eb27f0c4fc3b4d7b".
-
01:30 PM Revision f1beeba5: Add Global reply-to disable checkbox, resolves the issue #1137
-
12:25 PM Revision 196440c8: reversal of accidentally deleted files
- Revert "Add Global reply-to disable checkbox, resolves the issue #1137"
This reverts commit c646776871dacebcaa4225b0... -
06:26 AM Bug #1302: fatal trap 12:page fault while in kernel mode
- Thanks.
upgrade
Version 2.0-BETA5 (i386)
built on Mon Feb 21 23:20:11 EST 2011 -
04:55 AM Bug #1302 (Resolved): fatal trap 12:page fault while in kernel mode
- this is already fixed, upgrade.
-
04:47 AM Bug #1302 (Resolved): fatal trap 12:page fault while in kernel mode
- Version 2.0-BETA5 (i386)
built on Sun Feb 6 04:04:00 EST 2011
My config is:
Motherboard: 3Q IPX7A-ION/330, Int... - 02:43 AM Revision c6467768: Add Global reply-to disable checkbox, resolves the issue #1137
02/21/2011
-
11:22 PM pfSense Packages Bug #1301 (Closed): Squid package become unusable through time if we use large disk cache
- This happens when we use the default path for the cache dir (/var/squid/cache).
The function squid_resync() calls ... -
09:47 PM Bug #1137 (Feedback): Global reply-to disable checkbox missing from 2.0
-
09:45 PM Revision 95938fae: Fix typo/spacing issue. Resolves #1300
-
08:11 PM Bug #1298 (Closed): Captive portal Idle timeout and Hard timeout not working
- works fine with your exact config too, diff RADIUS server and using the default portal pages, but those doesn't impac...
-
03:53 PM Bug #1298: Captive portal Idle timeout and Hard timeout not working
- My laptop was turned off for 4 hours. Still didn't timeout.
Here is the output from the config file. I removed the... -
03:37 PM Bug #1298 (Feedback): Captive portal Idle timeout and Hard timeout not working
- works for me. first a 5 minute hard timeout, second a 2 minute inactivity timeout. note you pretty much have to unplu...
-
03:06 PM Bug #1298 (Closed): Captive portal Idle timeout and Hard timeout not working
- Clients stay logged in even after being inactive for longer than the idle timeout and and aren't disconnected after t...
-
06:58 PM Bug #943 (Resolved): 2.0-BETA4 Dynamic DNS updates not working
-
06:56 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
- The only thing it's less stupid than is finding out that was the problem. I have no idea when or how that got checke...
-
06:42 PM Bug #1300 (Resolved): Typo in TCP flags section of advanced firewall settings
-
04:45 PM Bug #1300 (Feedback): Typo in TCP flags section of advanced firewall settings
- Applied in changeset commit:"95938fae08add39dabf08fe0b15eaddec5fca7ee".
-
04:32 PM Bug #1300 (Resolved): Typo in TCP flags section of advanced firewall settings
- In firewall_rules_edit.php at the bottom of the TCP flags section of the Advanced Settings it currently says "Use thi...
-
06:23 PM Revision 4661598e: Add the diag_ipsec_xml.php page, this provides a XML interface to the
- tunnel status built for a Coltex BV monitoring system
-
04:52 PM Feature #1299: update /etc/bogons
- Please compare /etc/bogons in 1.2.3 LiveCD and http://files.pfsense.org/bogon-bn-nonagg.txt, massive difference. Woul...
-
04:30 PM Feature #1299 (Rejected): update /etc/bogons
- every release already has the latest, it updates at the completion of the setup wizard for new installs, and automati...
-
04:24 PM Feature #1299 (Rejected): update /etc/bogons
- This is follow-up from http://redmine.pfsense.org/issues/1297
Basically the default /etc/bogons is fairly out-of-dat... -
04:32 PM Bug #1097: Onload Javascript on Rules page of management GUI
- Can you please confirm that this happens still on latest snapshots?
-
02:46 PM Revision 9e050072: Prevent empty remote endpoints from skewing the log output
-
02:19 PM Revision a2a13c97: Trigger a VPN tunnel reload after configuring IPsec, it will handle all the hostname tunnels after boot finishes
-
01:47 PM Revision c2d7074e: Resolves #1288. Add alc(4) to altq(4) supported list.
-
01:17 PM Revision df82fae1: Don't forget to include $g, otherwise the check will fail and still perform a DNS resolve
-
12:45 PM Revision 33d5cb7a: Hold off on resolve_retry during boot. The rest of the IPsec config is already delayed during boot for tunnels with hostnames
-
12:29 PM Revision 71e91e50: Add more safeguards and IP address checks
-
11:47 AM Revision 621a459a: Do not resolve the hostname during boot, also make really sure we have a IP address here.
-
11:30 AM Revision 41393f1e: Prevent a empty remote gateway IP from ending up in the config
-
11:21 AM Revision 603b4346: Make sure to initialize the remote gateway IP variable so that it does not end up with a broken config
-
09:53 AM Todo #1237 (Feedback): Restore patch for adding gif(4) to bridge(4)
- This is committed to the repo.
- 09:42 AM Revision b85f2451: Correct indentation
- 09:40 AM Revision 7c50552d: Make sure it is an array before foreach.
-
07:51 AM Bug #1288 (Resolved): Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
- Should be fixed on new snapshot.
The alc(4) driver was not on altq(4) supported interface list. - 02:15 AM Revision 0e3e825c: log when CP is restarted. ticket #1278
02/20/2011
- 10:31 PM Revision 75bf4f14: fix default password display
-
09:26 PM Bug #812 (Resolved): RRD graph time axis not locked to latest times with higher average samples
-
09:25 PM Bug #816: USB Keyboard Detection - Boot Hangs
- this is definitely hardware-specific as I have a ton of hardware that works fine with USB keyboards, and we aren't go...
-
09:19 PM Bug #906 (Resolved): Orphaned rules from deleted interfaces are still present in config
- this is ok as is since the original bug was fixed. for the few who may have orphaned rules, it's not a big enough dea...
-
09:13 PM Bug #1278 (Resolved): log when captive portal restarts
- committed, thanks
-
08:34 PM Bug #1297: /etc/bogons out-of-date
- ignore, all ok, /etc/crontab:
1 3 1 * * root /usr/bin/nice -n20 /etc/rc.update_bogo... -
08:34 PM Bug #1297: /etc/bogons out-of-date
- yes it's updated automatically, yours is failing for some reason (lacking DNS is most commonly the reason). It isn't ...
-
08:31 PM Bug #1297: /etc/bogons out-of-date
- nothing wrong with dns, it's just this code, which causes the script to sleep, if run with no arguments:
# Sleep f... -
08:15 PM Bug #1297: /etc/bogons out-of-date
- and it's fairly out-of-date, comparing to the current http://files.pfsense.org/bogon-bn-nonagg.txt
-
08:06 PM Bug #1297 (Rejected): /etc/bogons out-of-date
- not a bug. fix your DNS so it can update, and run "/etc/rc.update_bogons.sh now" so it doesn't sleep.
-
08:03 PM Bug #1297 (Rejected): /etc/bogons out-of-date
- I'm running version 1.2.3, and have noticed my IP belonging 2.120.0.0/15 is being blocked as bogons. Digging around I...
-
10:26 AM Bug #1296 (Resolved): SMART status not work, when hard drive controlller digit more than 9
- Works now - http://forum.pfsense.org/index.php/topic,33481.0.html
-
01:33 AM Bug #1296: SMART status not work, when hard drive controlller digit more than 9
- Once you have a chance to update, please check if it really is fixed for you. I haven't gotten any feedback on the fo...
-
01:30 AM Bug #1296: SMART status not work, when hard drive controlller digit more than 9
- Excuse, I was late, couldn't check up as there was no access to hardware. Thank's !
-
01:18 AM Bug #1296 (Feedback): SMART status not work, when hard drive controlller digit more than 9
- What snapshot are you on? I committed a fix for this a few days ago:
commit:3e8b3cccab55f02be654ba342ac9d0e02c719d78 -
01:14 AM Bug #1296 (Resolved): SMART status not work, when hard drive controlller digit more than 9
- The bookmark diagnostic - smart status doesn't work when hard drive is connected to the controler with number more th...
02/19/2011
-
08:54 PM Bug #1294: OpenVPN remote access (site-to-site) VPN Clients aren't listed
- SSL/TLS Peer-to-Peer OpenVPN, so I'm guessing that's PKI. This is on the server side - the client side shows the conn...
-
05:01 PM Bug #1294: OpenVPN remote access (site-to-site) VPN Clients aren't listed
- Are you talking about shared key clients/servers, or site-to-site PKI clients? And when viewed from which side?
Op... -
04:05 PM Bug #1294 (Closed): OpenVPN remote access (site-to-site) VPN Clients aren't listed
- Remote access / site-to-site VPN clients that are connected do NOT show up on the OpenVPN status page or the dashboar...
-
04:09 PM Feature #1295 (Rejected): SSH binds to all available "Virtual IP" IP aliases
- SSH, by default, in a pfSense installation, binds to all available "Virtual IP" IP aliases.
It would be nice to b... -
03:57 PM pfSense Packages Bug #1293 (Resolved): Imspector doesn't log anything on 2.0
- Imspector doesn't seem to log anything on pfSense 2.0.. in fact, looking at the configuration files generated from th...
-
12:23 PM Bug #1288: Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
- Interesting/surprising update:
I reconfigured this box and tested it as a dual WAN single LAN setup and found that...
02/18/2011
-
08:52 PM Bug #1292: PPTP server with Radius breaks on upgrade from 1.2.3 to 2.0
- After clearing the PPTP configuration from config.xml I was able to setup the PPTP server (so the page does work). H...
-
06:20 PM Bug #1292 (Resolved): PPTP server with Radius breaks on upgrade from 1.2.3 to 2.0
- If upgrading from 1.2.3 to 2.0 (BETA5-02182011) and you have a PPTP server with Radius configured. It breaks the PPT...
-
04:33 PM Bug #1288: Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
[2.0-BEAT5][admin@pfSense.localdomain]/root(34): ifconfig
em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> ...-
09:59 AM Bug #1288: Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
- Possibly your nic type does not support altq.
Can you do an ifconfig and paste the output here?
- 06:42 AM Revision c7d56176: fix log text
02/17/2011
-
07:45 PM Revision 94d455da: Enforce FreeBSD's max username length of 16 chars. http://forum.pfsense.org/index.php/topic,33410.0.html
-
05:54 PM Revision 70edf50d: Fix whitespace formatting.
-
05:35 PM Revision 98776e04: Allow sorting of DNS forwarder entries.
-
01:05 PM Bug #1284: Syslog does not work with CLOG disabled
- Maybe I found the problem.
On system boot, it checks if disablesyslogclog tag exists on config.xml, then create re... -
07:31 AM Feature #1225 (Closed): static port range and outbound rules source port range (only to be tested and integrated, already coded)
-
02:39 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
- I can't find how to close the task myself, so if someone could tell me how to (if I can!) or could close it...
-
02:36 AM Feature #1225: static port range and outbound rules source port range (only to be tested and integrated, already coded)
- This is rendered useless by support of port alias. No need to implement this anymore.
-
04:07 AM Bug #1291 (Closed): Inner VPN Roadwarrior IPSEC in Tunnel VPN IPSEC not working with Firewall Scrub enabled
- Running 2.0-BEAT5 (i386) built on Tue Feb 15 16:36:07 EST 2011.
WAN is an xl0 ethernet card, LAN is a sge0 ethernet ... -
02:20 AM Bug #1290 (Closed): IPsec roadwarrior use case: Traffic from LAN does not hit established tunnel
- Hello.
Remote Access IPsec client (Shrew) connecting to pfSense firewall terminating the IPsec connection does not... -
01:33 AM Bug #1289 (Resolved): IPsec mobile remote access (roadwarrior) responder (server) configuration
- Hello.
IPsec mobile client configuration (Hybrid XAuth Server) does not put 'passive on' directive into racoon.con...
02/16/2011
-
10:07 PM Bug #1221 (Resolved): igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
-
09:48 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
- Been testing hw.igb.num_queues="4" for the last week and so far it seems to be working with no problems so far with H...
- 09:40 PM Revision 8e559859: Minor english fixes from Bill
- 09:39 PM Revision ccca3418: Merge remote branch 'upstream/master'
-
09:22 PM Revision 0aba3822: Add IPsec and OpenVPN to packet capture. Ticket #1032
-
09:16 PM Bug #1288: Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
- Update to reference this forum thread where a similar (though single lan) issue appears to be affecting another test ...
-
09:12 PM Bug #1288 (Resolved): Single Wan multi Lan Traffic Shaper Wizard :: "You do not have 2 of local interfaces!"
- My test box has 3 total interfaces, all of which are properly connected to physical interfaces and function on their ...
-
08:32 PM Revision 3395ba20: Fix wording
-
07:33 PM Bug #1287 (Closed): CARP VIP sync sends incorrect interface
- OK. I'll close this out. Feel free to post on the forums to see if anyone else has hit any similar VLAN issues.
-
06:46 PM Bug #1287: CARP VIP sync sends incorrect interface
- Yep, that's the issue, thanks Jim. I'm still having some trouble with the VLAN(s) passing traffic after failing over ...
-
06:18 PM Bug #1287 (Feedback): CARP VIP sync sends incorrect interface
- Check your config.xml on both - for CARP sync to function correctly the interfaces must exist on both units and they ...
-
06:10 PM Bug #1287 (Closed): CARP VIP sync sends incorrect interface
- When the CARP VIPs are set to sync from Master to Backup under the CARP Settings it immediately adds new VIPs to the ...
-
06:53 PM Revision a8f9f07e: Comment out the "config write on bootup" error. This is normal now with the package reinstall, and the known issues with it should be OK now. The error is just confusing people.
-
06:19 PM Revision a3bac4ce: Do not rely on php new foreach by reference and use the old method of chaning array members by using full path. This fixes nat 1:1 upgrades.
-
06:04 PM Revision ed187b41: Change this form to a POST instead of using GET with button inputs. For some reason using the GET method was causing things to be invoked twice, which led to two concurrent XMLRPC syncs, which can cause issues.
-
05:15 PM Revision 72377228: Add automatic rules to pass DHCP failover traffic if a failover peer is defined. See http://forum.pfsense.org/index.php/topic,32731.msg172839.html#msg172839
-
04:31 PM Revision 3e8b3ccc: Use a better regex here, sometimes ad devices can be numbered >=10.
-
03:53 PM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
- R B wrote:
> Unfortunately I disagree - still not seeing DDNS update on a clean install of the NanoBSD images as not... -
11:50 AM Bug #943: 2.0-BETA4 Dynamic DNS updates not working
- Unfortunately I disagree - still not seeing DDNS update on a clean install of the NanoBSD images as noted in comment ...
-
02:45 PM pfSense Packages Bug #1084: nmap package libpcap errors
- Reinstall the package again, it should be OK now.
-
02:47 AM pfSense Packages Bug #1084: nmap package libpcap errors
- This error is back in 2.0-RC1
/libexec/ld-elf.so.1: Shared object "libpcap.so.1" not found, required by "nmap"
... -
01:07 PM Revision 2d816c13: silence the music.
-
08:11 AM Revision f698b262: Merge remote branch 'upstream/master'
-
06:30 AM Feature #1286 (Closed): Captive Portal sends WAN IP instead of Mac or custom string in "called-station-id" RADIUS attribute
- The Captive Portal is sending the WAN IP in the RADIUS "called-station-id" attribute.
It has been mentioned before i... -
03:48 AM Bug #1053: CBQ per se, in kernel
- any update on this?
-
02:50 AM pfSense Packages Bug #1285 (Closed): NTOP error in 2.0 RC-1
- I installed the nmap package and when I go to Diagnostics -> NMap, I'm redirected to the dashboard page. When I run n...
Also available in: Atom