Activity
From 02/16/2011 to 03/17/2011
03/17/2011
-
07:57 PM Revision 52bac969: Up the number of packets that gets sent to divert consumers since this count includes for tcp even the 2way handshake count which might hurt the matching. This should possibly fix layer 7 Ticket #636.
-
06:58 PM Revision 3c69c52c: Log the configuration is not the same error message only when this is true. This message would have been shown even when a communication error would occur.
-
11:52 AM Revision 9498c8d7: Fix field lengths for IPv6 addresses
-
11:45 AM Revision c271c485: enlarge various address fields for IPv6 addresses
-
10:59 AM Revision 8a3b09ef: Comment out static mappings, this needs more research
- 10:21 AM Revision 7e5f3edb: Add Total number of CP users graph
03/16/2011
- 09:05 PM Revision 6f979763: Fix merge conflict
-
07:34 PM Revision af4c040e: Ticket #1356 use locking here rather than ps to serialize execution.
-
12:28 PM Revision aff70640: Swap if statement, add fields into ipsecpinghosts file
-
12:26 PM Revision e3e85044: Add field 8 for address family
-
12:19 PM Revision 840d845f: Add more helpful logging
-
12:18 PM Revision 80c1e99f: Correct ping hosts functionality for > 1 tunnel. Add v6 functionality
-
11:54 AM Revision ab299d4c: Fix ticket #1126
-
11:36 AM Revision 7916acc3: Change wording
-
11:29 AM Revision fe3801bf: Hopefully improve the useless ipsec logs with highlighting
-
11:27 AM Revision 505483ce: Fix ticket #1354
-
11:16 AM Revision ac463c00: Fix the IPsec ping hosts file generation. This only worked for the last
- tunnel
-
10:38 AM Revision 413a327e: Add v6 entries to the logs
-
09:03 AM Revision bfc0cb5b: Merge remote branch 'upstream/master'
-
07:46 AM Revision 323f3f9c: Keep a table of gateways we added for static routes to prevent us from making multiple entries to the same IP address
-
07:31 AM Revision 2d74f1cf: Add support for TLS/SSL for notification (tested with smtp.gmail.com port 465)
03/15/2011
-
09:31 PM Revision e58da189: Add code to allow custom upgrade code to run after the pfSense upgrade code for the same version switching(Just the custom upgrade functions should have _custom at the end of their name.
-
08:43 PM Revision 85071ea2: Add more colors to themes
-
05:10 PM Revision e2faab6d: Unbreak firewall logs
-
03:41 PM Revision 1f116988: Enable the IPv6 allow toggle, otherwise the other IPv6 rules do not work.
-
03:30 PM Revision 8336846a: More html fine tuning
-
03:30 PM Revision 8525bd86: Add the IPv6 addresses to the interfaces status widget
-
03:29 PM Revision 98790f61: Try to make IPv6 feature complete for IPv6 support. Looks like ipsec-tools was built without v6 support, make sure you have a newer build
-
03:28 PM Revision b47ceaea: Merge remote branch 'upstream/master'
-
12:53 PM Revision 401fb0ad: ipfw is not referenced here.
-
12:52 PM Revision 32c392aa: Make sure we have an ip to kill sessions from.
-
12:17 PM Revision 01c201e3: Do more strict checking if an ppp type interface is assigned before starting the mpd process behind it. Trigered-by: http://forum.pfsense.org/index.php/topic,34377.0.html
-
08:59 AM Revision 1ae43bfa: Merge remote branch 'upstream/master'
-
08:12 AM Revision d52a66f9: Fix the link for the easy rule block so that it always fills in the ip protocol
03/14/2011
-
09:09 PM Revision 1778480d: Show the proper Phase entry for the IPv6 tunnels
-
09:03 PM Revision fb17f629: Commit the backend function that writes out the racoon.conf
-
09:02 PM Revision e79b24ab: Extend the IPsec configuration with a protocol family for the phase 1
-
08:40 PM Revision 6c4f3b54: Make sure to note the limitations to gethostbyname, it does not work for Quad A records. Fix resolve_retry in the process, use that.
-
08:30 PM Revision fbcbfa44: Add the dhcp v6 page to the menu, eventhough it is broken. Tabs for later integration
-
08:29 PM Revision c1640267: Add the initial broken dhcp v6 leases page. I have no file to code it. Will wait for later.
-
07:53 PM Revision 96f1a57a: Remove comment since the service is not started anymore after installation in 2.0
-
06:24 PM Revision a3f1fa81: Allow port 547 to the filter rules for DHCP to work
-
05:49 PM Revision a41c5253: Properly configure lighty with the configured port when attached to the v6 socket. It was previously hardcoded to https
-
05:44 PM Revision 209620ea: Add IPv6 support to the DNS rebinding attack function
03/12/2011
-
12:36 AM Revision 2bf16ba2: Prevent the command wol for being called without propper ip information. Reported-by: http://forum.pfsense.org/index.php/topic,34314.0.html
-
12:26 AM Revision e92916d6: Make sure we do not write stale data during prunning periods.
03/11/2011
-
09:34 PM Revision 3795d067: Add the ability to differentiate between v4 and v6 tunnels. Bill says he can test
-
01:37 AM Revision d0404e46: Fix typo
03/10/2011
-
04:25 PM Revision 64d42525: Clarify text on outbound NAT page.
-
01:06 PM Revision 2f23caf2: Correctly generate the interface.
-
01:05 PM Revision 298ca201: Define only one loginterface since that is what pf(4) allows. This prevents a memory leak from pfctl(1) which may lead to memory depletion if the utility is run frequently with the pfSense generated ruleset.
-
08:55 AM Revision 36653869: Remove extra unmatched conf_mount_ro for a potential race condition preventing writes when generating ssh keys in the background. Ticket #673
-
07:32 AM Revision 48ab12a9: Remove quick from the filter rule by request of Erik.
-
07:31 AM Revision 05c8d0b1: Correct the config path to the upnp array, this prevented the filter rule from being generated
03/09/2011
-
09:21 PM Revision 15294580: Add the IPv6 tag to the version so that BSD perimeter can seen these installs from a mile away
-
09:14 PM Revision 47cc98de: Correctly use the WAN macro definition for the interface on 2.0. Though i still insist that people should do this themselves rather than relying on some obscure gui option.
-
07:49 PM Revision 28a581b8: Add {} around foreach contents. Fixes occasional duplication of the easyrule block alias.
-
07:49 PM Revision a0140246: Add block rule to the top of the firewall rules.
-
06:54 PM Revision 021b77af: If PPTP is set for redir, actually add the NAT rules to rdr.
-
06:03 PM Revision fa182351: Only delete files in /tmp, not directories. Fixes rm errors on shutdown. (Doing rm -rf might cause it to go across filesystem boundaries again, which we're trying to avoid.)
-
04:23 PM Revision b043503a: Teach the console update by url about the default auto update url.
-
01:40 PM Revision 354796f0: Unbreak the rrd graph img page
-
12:53 PM Revision 15f2cdc3: Merge remote branch 'upstream/master'
- Conflicts:
usr/local/www/status_rrd_graph_img.php
usr/local/www/themes/pfsense_ng/rrdcolors.inc.php -
12:27 PM Revision 947fe874: Correct firewall rule, remove flags any
-
12:04 PM Revision a3dd71ee: Merge remote branch 'upstream/master'
-
11:51 AM Revision f22c9ae2: Merge remote branch 'upstream/master'
-
11:50 AM Revision 9c5ad167: unbreak the broken merge
-
11:35 AM Revision 272c5d62: Automatically add a multicast allow rule for miniupnpd so that the Xbox 360 works.
-
10:58 AM Revision a6917c65: Add the 95th percentile line to the traffic graphs
-
10:48 AM Revision c7cfc098: Possible double RRD process fix.
-
07:20 AM Revision 9956b38a: Merge the config upgrade code, there was a mismatch, the one who merged this wrong should get a pointy hat.
03/08/2011
-
10:35 PM Revision fdc0e920: Add localhost to be natted automagically from auto-generated nat rules. This simplifies loadbalancing from the host itself.
-
10:14 PM Revision 01890f6a: Fix javascript errors reported by: http://forum.pfsense.org/index.php/topic,34139.0.html
-
09:30 PM Revision 53bd5790: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/rrd.inc -
08:02 PM Revision 55805397: Add missing image. Fixes #1339
-
07:37 PM Revision 4db0365d: Keep the output in a variable before passing it to rrdtool in case we also want to pass it to something else.
-
07:18 PM Revision ae3c0a12: Only run pfctl once per interface for stats, rather than four times.
-
05:47 PM Revision 3e5c0ab7: Use foreach here to be sure we do not reference unexisting results.
- 03:37 PM Revision 375eed5a: Merge remote branch 'upstream/master'
-
03:23 PM Revision 13927322: Do a proper test otherwise a override of the total_minutes var might happen.
-
03:16 PM Revision c4ea3691: Properly do testing of voucher existing or not rather than relying on an obscure feature of php. Also do exclusive locking rather than shared one when writing dbs.
-
08:14 AM Revision d2627d7c: Correct the link to the proper page for deleting a static mapping
03/07/2011
-
10:45 PM Revision 6b5e978b: Use racoonctl now that ipsec-0.8 is back to reload the config.
-
09:42 PM Revision 06d30ce7: Handle the case on some special configs with a gateway of all 1's otherwise strange thing happens.
-
08:03 PM Revision 214bd062: Fix typo
-
05:24 PM Revision a5ccf623: Add cas(4)
-
03:07 PM Revision e8567e89: When doing conf_mount_ro/rw on NanoBSD, pass sync,noatime to mount to preserve the options we have already set in fstab. Ticket #1279 and Ticket #444
-
08:14 AM Revision ae091de3: Commit the forgotten edit page for the dhcpv6 reservations
03/06/2011
- 09:18 PM Revision b4c826ad: Resolve merge conflict
-
07:44 PM Revision 283e9180: More fixes to differentiate between v4 and v6 gateways on the same interface.
-
07:17 PM Revision de140730: First stab at generating a link local address for the bridge interface if it's used by DHCP.
03/04/2011
-
10:05 PM Revision fd4151a9: Enforce session establishment.
-
10:02 PM Revision bb7469ca: Enforce session establishment.
-
10:00 PM Revision de4333ba: Enforce session establishment.
-
09:53 PM Revision 9fbb3599: Add missing pages to the authentication system.
-
08:50 PM Revision c53eb903: Be smart and remove the needs package sync toggle since the begining otherwise not behaving packages might mess up the whole thing.
-
08:27 PM Revision ce1942d6: Oops more make code correct.
-
08:24 PM Revision 328c1def: Oops make code correct.
-
08:15 PM Revision 006802ab: * Prevent concurrent logins on CP to not be recorded on the DB.
- * Make the locking more complex to avoid locking exclusively during pruning task which would hurt a lot CP performanc...
-
05:37 PM Revision 9ccecb65: If the interface triggering rc.newwanip is not assigned just reload packages and the filter and exit.
-
04:01 PM Revision 17a5b095: Correct one more variable in the process
-
03:51 PM Revision 4f332466: Fix broken gateway logic that mixed up v4 and v6
-
01:09 PM Revision 1b761f36: Check if the protocol is empty, not just if it's set. Fixes #1323
-
01:04 PM Revision 1c1a74fa: Only change protocol if it's set and not empty.
03/03/2011
-
09:13 PM Revision 7ec0e6e2: Add upgrade code to ensure rule protocols are all lower case.
-
08:40 PM Revision 06b3df52: Make this lowercase before checking, or people who ended up with TCP or UDP in their config might end up with rules that have no port specified, leaving them a bit more open than expected.
-
08:30 PM Revision 4e8e7662: Blind coded a edit page for IPv6. the subnet check needs to be written entirely. Checking if the IP address falls within the v6 subnet isn't so hard, what is harder is making sure that the ip does not fall within the dynamic subnet. For that we need proper subnet math calculus. Which we don't have yet.
-
08:18 PM Revision 11085d2a: Add the neighbour table to the menu
-
08:16 PM Revision aed47758: Fix the link to point to the v6 edit page instead
-
08:13 PM Revision 0461114f: Add the IPv6 Neighbour list status page
-
04:30 PM Revision 4f4e85df: Make sure we tell the code that the interface exists otherwise multiple laggs might get created.
-
04:30 PM Revision ee487a68: Not needed anymore.
-
02:24 PM Revision 6be90004: Ensure the protocol on the firewall rule from the OpenVPN wizard ends up lower case, or it causes some GUI irregularities. Seen http://forum.pfsense.org/index.php/topic,33865.0.html and elsewhere.
- 05:42 AM Revision 67b0ed57: lower limit to 101 MB
03/02/2011
-
05:24 PM Revision 56f25370: Simplify is_macaddr regex.
-
05:08 PM Revision c5682801: Slight regex fix on is_macaddr - the previous regex was letting through a mac without : separators, leading to improper validation and potentially invalid dhcp configs. Seen here http://forum.pfsense.org/index.php/topic,33830.0.html
-
02:09 PM Revision 199791f9: Show friendly names of interface for root queues of ALTQ.
-
01:57 PM Revision 93c1127f: Add GUI option to CARP settings for syncing certs. It was in the backend code but not the GUI. Fixes #1316
-
11:52 AM Revision e77ecd8e: Attempt to mitigate fork bombs of rc.newipsecdns. Alternatively we should probably bail out with a exit(0);
- instead.
-
09:39 AM Revision e269b621: Merge remote branch 'upstream/master'
-
09:14 AM Revision d161b4d4: Always write out the filterdns-ipsec.hosts file, otherwise deleted tunnels will never get removed from the
- filterdns-ipsec.hosts
-
08:08 AM Revision bb3c6562: Add the toggle to disable successful login messages, show actual help text for redirect item
-
07:47 AM Revision 4fc3855f: Make it possible to turn off successful login messages, this should quiet the console, system logs
-
07:21 AM Revision 829fa12e: Add a check that should prevent configuration of racoon with duplicate phase 1 IP entries.
-
04:51 AM Revision baca83aa: Fix page title text. Replace "Firewall" with "Interfaces" in title.
-
12:25 AM Revision 539d5973: Remove custom code for checking ip_addr and use the pfsense provided one.
-
12:23 AM Revision cf46a14f: Do not be so drastic on normal failure.
-
12:21 AM Revision dcc897e5: Since its only called during bootup there is no need to do conditionals here. Always sync config and start the miniupnpd process.
-
12:18 AM Revision 88cbd62a: More fixes to comments and code for upnpd. Also bring up to speed the stop/start logic.
-
12:05 AM Revision 2816f43f: Improve logging and some tests during miniupnpd config generation.
03/01/2011
-
11:51 PM Revision b469b7fe: This is not true anymore as piece of code.
-
11:46 PM Revision 8df14984: Correctly get only the interface mac address rather than any other found mac on this interface.
-
11:40 PM Revision 05c4bfa0: Pass the -a parameters to pgrep to be certain we search ancestors as well. The side effects might be inoquos from the pfSense context.
-
06:18 PM Revision c8487604: Use the call to basename to remove the extension rather than trim, since trim takes a list of characters, not the exact string to remove. Suggested by http://forum.pfsense.org/index.php/topic,32967.0.html
-
06:03 PM Revision 8b19f4a7: This is not NAT, so put it under the Firewall Advanced heading instead.
-
01:11 PM Revision 2936a57e: add subnet mask clarification for IPv6 and correct default count to 128 bits
-
01:06 PM Revision e53de0b3: Merge remote branch 'upstream/master'
02/28/2011
-
07:02 PM Revision 87ae1a2b: Fix page title.
- 06:28 PM Revision 6f5b2ff5: Merge remote branch 'upstream/master'
-
05:25 PM Revision 566193a5: Only make gateway changes if we have been given a new gateway IP.
-
05:21 PM Revision d7b4e38f: Setup gateway monitoring since we just altered a gateway.
-
05:16 PM Revision e121bebd: Fix gateway handling in setup wizard.
-
04:12 PM Revision 2d539f40: Only display gitsync settings on supported platforms.
02/27/2011
- 09:21 PM Revision 4e0cb56e: Merge remote branch 'upstream/master'
- 08:50 PM Revision cfaf6e69: Only show the you can monitor the filter reload process for filter related changes
- 08:43 PM Revision 58b4b246: Flush the buffer
02/26/2011
-
07:20 PM Revision 4ed69f33: Do a more strict check on the return value of the download function. Fixes #1309
-
04:40 PM Revision 153e3cb5: Declare $g a global here.
-
04:34 PM Revision 73d885d7: Ensure the pkg staging area exists on nanobsd before trying to use it.
02/25/2011
- 10:14 PM Revision 0c4f8ca8: Merge remote branch 'upstream/master'
- 05:45 PM Revision 17e7a243: missing $
- 05:44 PM Revision da666ca8: missing $
- 05:42 PM Revision a6f4ac66: misc whitespace cleanups
- 04:37 PM Revision 0c13af6c: Give this another shot
-
03:26 PM Revision ebcdcaaa: Fix admins group permission setting when upgrading from 1.2.3.
-
09:27 AM Revision bc75a430: Correct IPsec carp interface upgrade code, off by one
02/24/2011
-
06:51 PM Revision a09d8bfc: Use full path to pw
-
06:50 PM Revision 2aba8f77: Add missing _relayd group, and when upgrading from 1.2.3, add _relayd group and user.
-
06:20 PM Revision 072bc34c: Correct the test which displays an error if someone chose to save+test but doesn't have an ldap backend. Also, fix a typo.
-
03:51 PM Revision bcc85621: Fix find again... apparently -xdev is depreciated and tosses errors, replaced by -x
-
03:46 PM Revision 22beab88: Move this code up a bit and also use /root/tmp to fetch packages instead of /tmp so it won't fill up.
-
03:37 PM Revision 9011a843: If we're on nanobsd, pass -t to pkg_add to specify a different "staging area" path.
-
02:23 PM Revision 62958eae: Correct the vlan upgrade code to continue when we fixed up the interface
-
02:17 PM Revision 583f4913: Correct the find command, pipe into xargs
-
01:10 PM Revision 563b47bf: Make sure to resolve the gateway name before passing it off to the IPsec reload function
-
01:10 PM Revision 3acab378: Correct variable name. This could never have deleted the static route for IPsec vpns on multi wan
02/23/2011
-
07:09 PM Revision 003d1b3d: And one more place for PKG_TMPDIR... just in case.
-
07:07 PM Revision 633ef551: Set PKG_TMPDIR here too, to help nanobsd pkg installs.
-
05:49 PM Revision c99c1e4e: Allow queues on top of bridge. Though more investigation is needed on its correct meaning.
-
05:36 PM Revision 6c67a28d: Set PKG_TMPDIR for embedded/nano because it will fill up /var trying to download packages otherwise. (From sullrich)
-
05:14 PM Revision 0030036f: Don't forget to clear username field so it doesn't show up on next edit.
- And if for some reason user enters a username, store it for them.
-
05:06 PM Revision ec465066: Merge branch 'master' of rcs.pfsense.org:pfsense/mainline
-
05:05 PM Revision d9cc4b24: Try again, a little cleaner: Prevent GUI from giving error for freeDNS service since username and password
-
04:54 PM Revision 1f9d17ef: Revert "Prevent GUI from giving error for freeDNS service since username and password"
- This reverts commit 740f745922549283e29d3d964c7a60266d7dbf0a.
This is a little ugly. Let's do it a little differently. -
03:05 PM Revision 62ce9874: Update "Last Tested" date for freeDNS in comments
-
03:00 PM Revision 740f7459: Prevent GUI from giving error for freeDNS service since username and password
- aren't required.
Also add a note for freeDNS users to enter "Authentication Token"
in Hostname field. Zero out fake ... -
02:45 PM Revision 4aa58d46: Correct the config path to the vip array
-
02:19 PM Revision 443f2e6e: Attempted fix that should convert the old carp[$i] naming to vip[$vhid]
-
02:07 PM Revision 3d039701: Make sure we iterate by the vlan number lest we end up with a empty variable? Hopefully fix new vlan name not being assigned to interfaces section
-
02:01 PM Revision 685a26fc: Correct the gateway group member name to the correct GW_". strtoupper($if) uppercase. This fixes outbound load balancer pools upgraded from 1.2.3
- not working
-
01:55 PM Revision 219585da: Do not cross filesystem boundaries when removing files lest we empty Seth' USB stick
-
08:03 AM Revision a299232e: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/filter.inc
etc/inc/vpn.inc -
02:32 AM Revision b8778031: Add a check if the configuration of dhcpd exists for wan before unset, resolves #1303
02/22/2011
-
10:31 PM Revision c54c9d15: Remove direction from traffic shaper generated rules now that the match action is present to correctly put packets on proper queues. Before it was not possible since this would have also open firewall ports/holes.
-
07:29 PM Revision 2d1298ce: Reset this var before this test, otherwise if the test is skipped, it will carry over the value from the previous run.
-
07:29 PM Revision 8364184a: Don't consider a cert as in use by the GUI if it's in HTTP mode. Fixes #1171
-
07:27 PM Revision ac631bba: Move all functions from index.php for captiveportal.inc
-
01:30 PM Revision f1beeba5: Add Global reply-to disable checkbox, resolves the issue #1137
-
12:25 PM Revision 196440c8: reversal of accidentally deleted files
- Revert "Add Global reply-to disable checkbox, resolves the issue #1137"
This reverts commit c646776871dacebcaa4225b0... - 02:43 AM Revision c6467768: Add Global reply-to disable checkbox, resolves the issue #1137
02/21/2011
-
09:45 PM Revision 95938fae: Fix typo/spacing issue. Resolves #1300
-
06:23 PM Revision 4661598e: Add the diag_ipsec_xml.php page, this provides a XML interface to the
- tunnel status built for a Coltex BV monitoring system
-
02:46 PM Revision 9e050072: Prevent empty remote endpoints from skewing the log output
-
02:19 PM Revision a2a13c97: Trigger a VPN tunnel reload after configuring IPsec, it will handle all the hostname tunnels after boot finishes
-
01:47 PM Revision c2d7074e: Resolves #1288. Add alc(4) to altq(4) supported list.
-
01:17 PM Revision df82fae1: Don't forget to include $g, otherwise the check will fail and still perform a DNS resolve
-
12:45 PM Revision 33d5cb7a: Hold off on resolve_retry during boot. The rest of the IPsec config is already delayed during boot for tunnels with hostnames
-
12:29 PM Revision 71e91e50: Add more safeguards and IP address checks
-
11:47 AM Revision 621a459a: Do not resolve the hostname during boot, also make really sure we have a IP address here.
-
11:30 AM Revision 41393f1e: Prevent a empty remote gateway IP from ending up in the config
-
11:21 AM Revision 603b4346: Make sure to initialize the remote gateway IP variable so that it does not end up with a broken config
- 09:42 AM Revision b85f2451: Correct indentation
- 09:40 AM Revision 7c50552d: Make sure it is an array before foreach.
- 02:15 AM Revision 0e3e825c: log when CP is restarted. ticket #1278
02/20/2011
02/18/2011
- 06:42 AM Revision c7d56176: fix log text
02/17/2011
-
07:45 PM Revision 94d455da: Enforce FreeBSD's max username length of 16 chars. http://forum.pfsense.org/index.php/topic,33410.0.html
-
05:54 PM Revision 70edf50d: Fix whitespace formatting.
-
05:35 PM Revision 98776e04: Allow sorting of DNS forwarder entries.
02/16/2011
- 09:40 PM Revision 8e559859: Minor english fixes from Bill
- 09:39 PM Revision ccca3418: Merge remote branch 'upstream/master'
-
09:22 PM Revision 0aba3822: Add IPsec and OpenVPN to packet capture. Ticket #1032
-
08:32 PM Revision 3395ba20: Fix wording
-
06:53 PM Revision a8f9f07e: Comment out the "config write on bootup" error. This is normal now with the package reinstall, and the known issues with it should be OK now. The error is just confusing people.
-
06:19 PM Revision a3bac4ce: Do not rely on php new foreach by reference and use the old method of chaning array members by using full path. This fixes nat 1:1 upgrades.
-
06:04 PM Revision ed187b41: Change this form to a POST instead of using GET with button inputs. For some reason using the GET method was causing things to be invoked twice, which led to two concurrent XMLRPC syncs, which can cause issues.
-
05:15 PM Revision 72377228: Add automatic rules to pass DHCP failover traffic if a failover peer is defined. See http://forum.pfsense.org/index.php/topic,32731.msg172839.html#msg172839
-
04:31 PM Revision 3e8b3ccc: Use a better regex here, sometimes ad devices can be numbered >=10.
-
01:07 PM Revision 2d816c13: silence the music.
-
08:11 AM Revision f698b262: Merge remote branch 'upstream/master'
Also available in: Atom