Activity
From 04/06/2011 to 05/05/2011
05/05/2011
-
08:47 PM Revision f02c3e1d: Misc OpenVPN CRL selection fixes.
-
08:41 PM Revision 93a138ab: Add a field for the prefix pools. Fix the DUID check
-
08:27 PM Revision a59831e7: If we have deleted the last cert from the CRL, blank out the text.
-
08:14 PM Revision 461aa9d0: When deleting a CA, delete its associated CRLs.
- 07:56 PM Revision 85936586: Enable accidentally commented out dhclient command for ipv4
- 07:46 PM Revision 0d8562ed: Fix the parse error, missing bracket.
-
07:29 PM Revision 7149c4e7: Add backend support for the dhcp v6 client
-
06:42 PM Bug #1508: Wan Fai lback
- Changing anything in the web interface to do with gateways makes the system failback but this is a manual process.
... -
06:39 PM Bug #1508: Wan Fai lback
- Subject should say "Wan Fail Back"
-
06:39 PM Bug #1508 (Resolved): Wan Fai lback
- When the WAN interface has a static ip and the system fails over the gateway to a tier2 opt1 interface it will not fa...
-
06:35 PM Bug #1386: Nested port aliases causes "Unknown port" error upon loading filters
- What feedback exactly would you require? I was of the impression that I described the "procedure to reproduce the pro...
-
05:18 PM Bug #1386 (Feedback): Nested port aliases causes "Unknown port" error upon loading filters
- Can you please give more detail on this?
Seems not many people havie seen this! -
06:32 PM Bug #1507 (Rejected): openvpn.inc Local line in openvpn.inc failover
- to change an OpenVPN client from WAN to OPT1 you have to change its config from WAN to OPT1, there is no failover of ...
-
06:27 PM Bug #1507 (Rejected): openvpn.inc Local line in openvpn.inc failover
- if (!empty($iface_ip)) {
$conf .= "local {$iface_ip}\n";
}
in /etc/inc/openvpn.inc c... -
05:50 PM Bug #1493: pf blocks all traffic following filter reload.
- pftop shows only traffic being passed, not blocked. check /tmp/rules.debug and the loaded rulesets and other info in ...
-
12:19 PM Bug #1493: pf blocks all traffic following filter reload.
- Hi, can you let me know what information would be useful?
At present, the only system logs immediately preceding f... -
02:08 PM Bug #636 (Feedback): layer7 not work correctly
- I pushed this https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/commits/99030511af941f6679b15a8920e720486...
-
12:58 PM Feature #1506 (New): Notifications should spool
- If the firewall can't connect to the mail server notifications fail and never attempt to notify again. A nice featur...
-
12:55 PM Bug #1505 (Closed): usb 3g 760 modem doesn't respond
- The first time you insert the 3g modem it will work properly, if you disconnect or soft reboot ppp can't connect stat...
-
12:52 PM Feature #1504 (Closed): Verizon 3g usb760
- Pfsense is not ejecting the cdrom when you insert/boot a verizon usb760 3g card. Without ejecting the cd-rom you don'...
-
11:50 AM Revision e7230cb3: Add firewall rules so that the DHCPv6 replies can come back in
-
10:23 AM Revision 5fd3cb92: Ticket #CZH-831780. If gif(4) is part of a bridge and its mtu is smaller than 1500(ethernet standard) do not consider it in finding the smaller mtu because we have a patch to allow gif(4) be member of a bridge with smaller mtu. See https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/commits/67d3135722db4a3c911761ead5c881ccaef02c65 for details.
-
08:18 AM Bug #1502: web interface needs to be manually started
- when RC1 boots the web interface does not come up (at least here).
Once I see the LCD display come alive I then have... -
08:16 AM Bug #1502 (Closed): web interface needs to be manually started
- That is definitely not normal, but there is not enough information here to reach any kind of conclusion. Please post ...
-
08:14 AM Bug #1502 (Closed): web interface needs to be manually started
- it seems since I switched to using rc1 when PFSense is rebooted I have to ssh in and then restart the web configurato...
-
08:18 AM Bug #1503 (Closed): autoupdater and reboots
- That is also not normal behavior, and not something that anyone else has seen that I'm aware of. Between your previou...
-
08:16 AM Bug #1503 (Closed): autoupdater and reboots
- seems that the autoupdater may not be rebooting and shutting down instead. Also, the web interface keeps showing that...
-
07:07 AM Revision c495f88b: Add the dhcp6 client into the backend code. Needs scripts for up down events also.
-
05:02 AM Bug #1501 (Closed): Captive Portal Logout popup does not work
- The logout popup for the captive portal does not work. People can still use the network and RADIUS is getting its acc...
05/04/2011
- 11:39 PM Revision 4a916dc8: Timeout is either a global option and/or a table stanza option. For now made it a global option.
- For the future each pool should probably have a configurable timeout.
-
09:54 PM Revision 8b1e7d04: Correct wrong key for checking if a interface type switched. Ticket #1420
-
09:31 PM Revision 56da23dc: Fixes #1394. Create a function get_itnerface_default_mtu and use it for resetting the mtu of a interface to default when needed. This adds the overhead of fetching the interface mtu and comparing with the default one every interface configuration run.
-
07:42 PM Bug #1235 (Feedback): pfsense 2.0 load balancing with a https monitor seems to default timeout 200ms causing constant timeouts
- I have added a patch for this but for now made this a global option. We should, at a later stage add the option for c...
-
02:25 PM Bug #1235: pfsense 2.0 load balancing with a https monitor seems to default timeout 200ms causing constant timeouts
- Did some quick tests: The timeout option is only valid as a global config or in the table stanza, not in a redirect ...
-
02:17 PM Bug #1235: pfsense 2.0 load balancing with a https monitor seems to default timeout 200ms causing constant timeouts
- I have confirmed this issue. The default relayd timeout of 200ms is being used even with a timeout specified inside ...
-
07:18 PM Feature #1492: Captive Portal Interim Updates
- Not sure we want to expose this for 2.0, potential for fallout since that's never been exposed, though it's probably ...
-
09:44 AM Feature #1492 (Resolved): Captive Portal Interim Updates
- Currently there is nothing in webGUI to configure how often Captive Portal pruning should be executed. So the default...
-
07:14 PM Bug #1493 (Feedback): pf blocks all traffic following filter reload.
- not enough info to do anything with this. Definitely not a universal issue, maybe something specific to KVM or someth...
-
12:17 PM Bug #1493 (Resolved): pf blocks all traffic following filter reload.
- Version: 2.0-RC1 (i386) built on Tue Apr 19 23:03:17 EDT 2011
Hardware: /usr/libexec/qemu-kvm -S -M rhel5.4.0 -cpu... -
05:58 PM Revision 131f3a50: Disable this log message, as it can be extremely spammy in the logs.
-
05:52 PM Bug #1420 (Feedback): Changing a WAN's type from PPPoE to other breaks it
- Test latest snapshots.
-
05:42 PM Bug #636: layer7 not work correctly
- @Jonathan,
can you show any picture of your configuration and the system log with the relevant layer7 logs(they sh... -
03:48 PM Bug #636: layer7 not work correctly
Okay,
On image 2.0-RC1 (i386)
built on Tue May 3 10:51:27 EDT 2011
Confirmed that it works as previous comme...-
09:20 AM Bug #636: layer7 not work correctly
- I haven't tried any advance layer 7 rules yet but I do agree with Jonathan that a simple rule to block traffic(I bloc...
-
05:22 AM Bug #636: layer7 not work correctly
- I've tested with a snapshot from the evening of the 3rd. It appears to be partially working now. If I create a simple...
-
05:30 PM Bug #1394 (Feedback): MTU does not reset
- Applied in changeset commit:"56da23dc5ffebdb6cf52f3b46abebc0ef56e9861".
-
02:58 PM Bug #1494 (Closed): Limiter does not apply to active FTP
- The only way to do active FTP work is enabling functionality ftp.proxy.handle which brings the problem of not applyin...
-
12:26 PM Revision a9543eae: Remove the dhcp6 type, add the DUID field to the dhcp config.
-
10:50 AM Feature #1489: Can't configure PPPoE over VLAN
- Howdy Mr. Stretz,
It is possible to do what you want without changing code, but it requires an extra step.
You ca... -
09:49 AM Feature #1489 (New): Can't configure PPPoE over VLAN
- Marking item as future as this is a legitimate problem.
-
05:37 AM Feature #1489: Can't configure PPPoE over VLAN
- I'm confused. You write "for now" though close this bug. Does that mean forever? I had a look at the code and with...
-
10:07 AM Revision cfd2ca3c: Remove stray debugging lines in VPN
-
10:06 AM Revision 776603cd: Remove debugging
-
08:58 AM Revision 2fb056d8: More DHCPv6 server fixes, split the function out into seperate v4 and v6. Make the router advertisement stand alone on the dhcp server page.
-
07:05 AM Bug #1491 (Closed): Optional interface problem pinging LAN interface static IP's
- Please use the forum at http://forum.pfsense.org/ for support questions, and post as much detail there in a thread as...
-
06:48 AM Bug #1491 (Closed): Optional interface problem pinging LAN interface static IP's
- There are 3 interface, WAN(pppoe),LAN and WLAN(optional wireless AP).
DHCP server is turned on on all interfaces.
O... -
03:30 AM Bug #845: Need patch for PR usb/140883
- Only owners can process and verify merge requests!
-
02:12 AM Bug #845: Need patch for PR usb/140883
- merge request for this: https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/merge_requests/72
-
12:19 AM Bug #1486 (Resolved): relayd does not set sticky-address option when set in advanced/misc
05/03/2011
-
11:04 PM Bug #1486: relayd does not set sticky-address option when set in advanced/misc
- I tested the Tue May 3 11:16:02 EDT 2011 and the bug is fixed. Thanks for the quick turn around!
-
04:30 AM Bug #1486: relayd does not set sticky-address option when set in advanced/misc
- There was a typo s/conf/config/ - this has been fixed.
Applied in change set commit:327ef8eb3244f79e1b669dca792c83... -
12:48 AM Bug #1486: relayd does not set sticky-address option when set in advanced/misc
- Unfortunately this still doesn't fix the issue. I tested and (isset($conf['system']['lb_use_sticky'])) returns false...
-
07:20 PM Revision ab1047d4: Make sure to send both the managed and other config flags.
-
12:55 PM Feature #1489 (Closed): Can't configure PPPoE over VLAN
- Its the way it works for now.
So please assign your vlan and choose the assigned interface as parent. -
07:44 AM Feature #1489 (Closed): Can't configure PPPoE over VLAN
- I currently have to run a PPPoE link over a 802.1Q tagged VLAN (don't ask...). When I go to [[http://10.49.1.1/inter...
-
12:25 PM Bug #1402: When creating a QinQ it works until reboot.
- Im just trying to connect two pfsense and pass into a parent vlan 2 vlans.
!qinq.jpg! -
10:20 AM Bug #1488: "There are no packages currently installed." is a lie
- Looks like all packages failed to reinstall for some reason, so I guess the problem isn't/wasn't in the packages but ...
-
10:12 AM Bug #1488: "There are no packages currently installed." is a lie
- That is because a package failed to reinstall, which is not related to this. If a package fails during the reinstall ...
-
10:04 AM Bug #1488: "There are no packages currently installed." is a lie
- But anyterm and darkstat are still packages, right? I still have their entries in the menu (though they are broken d...
-
09:02 AM Bug #1488 (Closed): "There are no packages currently installed." is a lie
- OpenVPN is not a package on 2.0, it's part of the base system. OpenNTPd is also part of the base system, even if it i...
-
07:28 AM Bug #1488 (Closed): "There are no packages currently installed." is a lie
- I upgraded from 1.2.3 nanobsd to 2.0-rc1 (currently a snapshot built on Mon May 2 21:11:55 EDT 2011).
The package ... -
10:06 AM Feature #1490: The Package Manager should hide packages for old platforms per default
- Ah, ok, that wasn't obvious from the output. I'd suggest changing the string "platform:" to "minimum version:".
-
08:56 AM Feature #1490 (Closed): The Package Manager should hide packages for old platforms per default
- that's the minimum version, if they aren't compatible they aren't in 2.0's package lists.
-
08:19 AM Feature #1490 (Closed): The Package Manager should hide packages for old platforms per default
- A quick glance at the list of Available Packages in the Package Manager shows a lot of packages. But most of these p...
- 08:12 AM Revision 0130b756: Some more whitespace fixes.
-
08:09 AM Revision dcb846e3: Merge remote branch 'upstream/master'
- Conflicts:
usr/local/www/status_rrd_graph_img.php - 08:07 AM Revision 327ef8eb: Use correct config variable and fix some whitespaces.
-
03:40 AM Bug #1487 (Rejected): INTERNET PROBLEM
- this is not a support site and not a valid bug report, use the forum or mailing list.
-
03:03 AM Bug #1487 (Rejected): INTERNET PROBLEM
- We are using pfsense as a software & firewall.We have lot of windows & linux mechines.Yesterday i reinstalled the pfs...
05/02/2011
-
10:26 PM Revision 8c218e1d: Give time to filterdns to exit gracefully and after that start a new process.
-
10:04 PM Revision 9b0ddd8c: Resolves #1486. When sticky option is selected under advanced->misc honor it even in the relayd.conf setting.
-
08:57 PM Revision 0b1321e2: Bring back the optimization on max-packets at pf(4) level now that the issues with daemon have been identified.
-
08:57 PM Revision 81e14406: Bring back the optimization on max-packets at pf(4) level now that the issues with daemon have been identified.
-
08:57 PM Revision 2dc14ea2: Now that layer7 daemon issues are resolved bring back this optimization.
- Revert "Do not write ont rules anymore max-packets. This apparently was done by me in a previous commit, it helps wit...
-
08:52 PM Bug #1485 (Resolved): WebUI password changes do not change shell and VPN passwords
- thanks
-
01:43 PM Bug #1485: WebUI password changes do not change shell and VPN passwords
- Thanks for quick fix! It works.
I updated to 2.0 RC1 built Fri Apr 29 21:19:09 EDT 2011. I changed the privileges ... -
07:32 PM Revision b01adece: Set default colors explicity, the theme can then override them. This prevents missing colors in themes from crashing the graphs.
-
06:36 PM Revision 49825b17: If the rrd multiplier is negative, use 5% for out instead of 95% for the 95th percentile line.
-
06:05 PM Bug #1486 (Feedback): relayd does not set sticky-address option when set in advanced/misc
- Applied in changeset commit:"9b0ddd8cf37fbf4e453d476a985f00e36bbb0861".
-
04:47 PM Bug #1486 (Resolved): relayd does not set sticky-address option when set in advanced/misc
- When the sticky session flag is set in advanced/misc and then a relayd pool setup the sticky-session option is not se...
-
05:02 PM Bug #636: layer7 not work correctly
- I put a patch yesterday in the layer7 daemon used for classification.
It was forgetting the protocols during reload.... -
04:53 PM Revision 3bae60be: Add a newline to the igmpproxy config to resolve issues of it not parsing correctly the file. Reported-by: http://forum.pfsense.org/index.php/topic,36279.0.html
-
11:00 AM Bug #1402: When creating a QinQ it works until reboot.
- Usually it will be needed for the QinQ vlan, 1000 3000, in your case.
I cannot answer to you without a clear descr...
04/30/2011
-
12:15 PM Bug #1402: When creating a QinQ it works until reboot.
- Do I have to change the MTU of the interface involved in order to get work?. Is just an idea....
04/29/2011
-
07:43 PM Revision c639315e: Set password on the OS instead of just the gui. Fixes #1485
-
06:23 PM Revision f7ea0505: Remove static routes that are added for dns servers when allow override is allowed when a ppp interface goes down. Code borrowed from dhclient-script.
-
06:19 PM Revision a73a9886: Ticket #1408. Honor the allow override settings even for ppp devices.
-
06:15 PM Revision e5f3359c: Send route delete message to blackhole.
-
06:13 PM Revision cfe92577: Ticket #1408. Do not add static routes for automatically learned dns servers from dhcp if Allow override is not selected.
-
03:45 PM Bug #1485 (Feedback): WebUI password changes do not change shell and VPN passwords
- Applied in changeset commit:"c639315e3c86ae6cc2a1d1030347340f340f8270".
-
03:40 PM Bug #1485: WebUI password changes do not change shell and VPN passwords
- I committed an ipsec xauth permission for users to fix #1202 a couple weeks ago, you should be using that instead.
... -
03:25 PM Bug #1485 (Resolved): WebUI password changes do not change shell and VPN passwords
- Version:
2.0-RC1 (amd64)
Goal:
Have user accounts that only work for IPSec VPN access. And allow the user to cha... -
03:34 PM Bug #1202 (Feedback): Shell access permission required for IPsec Xauth clients
- The previous commit should fix this, but needs additional testing.
-
02:24 PM Bug #1402: When creating a QinQ it works until reboot.
- Sorry the last image is like this for example:
!3.png! -
02:15 PM Bug #1402: When creating a QinQ it works until reboot.
- Hello,
I have tested the changes and now the members are displayed correctly, thanks for that.
So I tryied agai... -
02:15 PM Bug #1408 (Feedback): DHCP DNS servers still get routes even if allow override is unchecked
- Committed a fix.
-
01:53 AM Bug #1415: Nat reflection is installing rules with 'Array'
- Here you are:
@$ ps -ax | grep inetd
7108 ?? Ss 0:44.47 /usr/sbin/inetd -wW -R 0 -a 127.0.0.1 /var/etc/ine...
04/28/2011
-
09:21 PM Revision 9cf46050: Correct saving of qinq specified members and also correctly destroy parent vlan when deleteing the interfaces. Also take care of attaching to netgraph now that we detach by default.
-
08:44 PM Revision a7ee5777: Remove rndtest sysctl since the kernel module is not anymore part of our kernels. Leftover noticed by: Jim
-
08:31 PM Revision 2d14181b: Remove rndtest sysctl since the kernel module is not anymore part of our kernels.
-
07:53 PM Revision 27dfd848: Bring comment up-to-date
-
07:33 PM Revision 65531b4b: Make sure that openvpn tunnels are not impacted by hitting 'Save' on the Interface->Configuration page when assigned.
-
07:29 PM Revision d1ae9705: Use the needed variable here so hitting 'Save' from Interface->Configuration section does not leave the assigned gif interfaces without tunnel addresses.
-
07:16 PM Revision 40b0c024: Correct code description during assignment
-
07:09 PM Revision d7f1891b: Some configurations might have gre/gif on top of carp. Make sure to handle this configurations and to bring the tunnel correctly up.
-
05:58 PM Bug #1415: Nat reflection is installing rules with 'Array'
- Can you show the content of /var/etc/inetd.conf?
Also ps -ax | grep inetd -
05:20 PM Bug #1402 (Feedback): When creating a QinQ it works until reboot.
- Try again. https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/9cf46050fc708f3a3395c7800acf5d81a69b1013
... -
02:25 PM Revision 03f824a5: Remove the quotes, these break the advertisement
-
01:27 PM Revision 61fbafc2: Hopefully fix the router advertisement
-
11:11 AM Bug #1318: Certificate error: certificate subject does not match signing request subject
- I can also confirm this is the case with PositiveSSL's issued from Comodo.
2.0-RC1 (amd64)
built on Thu Apr 28... -
11:10 AM Todo #1373: Upgrade OpenVPN
- Change for the netsh interface on windows 7, use set address, instead of add address. Otherwise the command will exit...
-
10:56 AM Todo #1373: Upgrade OpenVPN
- The current openvpn-ipv6 port has both the endpoint and payload patch for IPv6. The current installer we include in t...
-
09:33 AM Revision fcdc8943: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/pfsense-utils.inc -
09:18 AM Feature #1431: PPPoE LQR Echo
- I'm still waiting ISP (TM Net) to reply regarding this issue. I ask them if they can disable LQR echo. I will update ...
-
01:53 AM Feature #1431: PPPoE LQR Echo
- so far tricking the WAN interface in and out of DHCP works, but I don't understand why is this working
-
01:50 AM Feature #1431: PPPoE LQR Echo
- Alot of us are having the same problem with the same ISP and modem provided. The same issue occurs when PPPoE through...
-
09:09 AM Revision 753bd64d: Change the rtadvd daemon options to a more readable format that should hopefully work better.
- 01:10 AM Revision 1dfb7795: fix typo
-
12:25 AM Revision b0c2087e: Comment out debug print
04/27/2011
-
10:13 PM Todo #1438: Add override for CSR request->response subject mismatch
- My semester ends in about 2-3 weeks. At that point I will look around in the code for other places where this type of...
-
10:11 PM Todo #1438: Add override for CSR request->response subject mismatch
- tested this with a cert from namecheap, originally was seeing the issue described here, synced up to Yehuda's git clo...
-
07:02 PM Bug #1336: PPTP VPN NAT on WAN or other external interface
- Any news with this bug?
-
07:02 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
- actually I was wrong, this wasn't fixed in the official RC1 release, it's been in snapshots since early March though.
-
11:14 AM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
- I think the problem is that I use a Bridge between LAN and OPT1. I have 3 interfaces
WAN
LAN
OPT1
The WAN-In... -
06:58 PM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- i found why its don't work. Eri removed pptp proxy patch at 16/3/2011. i have amd64 iso from 10 Mar 2011 and this iso...
-
04:03 PM Revision f35abee2: Whitespace cleanup, code cleanup, add choice to filter on ipv4/ipv6 and also accept a subnet to filter on via the host field.
-
09:33 AM Bug #1484 (Rejected): Captive Portale
- because there is no way to tell that "username" is the same as "domain\username" or "username@domain" or other possib...
-
06:10 AM Bug #1484 (Rejected): Captive Portale
- Hi, I've enabled "Disable concurrent logins" in Captive Portal and I've configured a Radius Server (Windows Active Di...
-
08:07 AM Bug #1433: Config sync causes CARP state change
- I tryed the latest snapshot and I'm still having the CARP switch issue.
Each time I apply a change,using LAN CARP as... -
06:19 AM Feature #1482: Captive Portal support for a configurable RADIUS NAS ID
- Hi just found out that the code in /etc/inc/radius.inc function putStandardAttributes() does not call the getNasId() ...
-
12:31 AM Bug #1415: Nat reflection is installing rules with 'Array'
- Processes are not spawn anymore but for example nat reflection seems anyway not working properly...
Examples: A nsl...
04/26/2011
-
09:08 PM Revision c41997ce: Allow users to select SSL/TLS+User Auth with external authentication sources.
-
09:07 PM Bug #1105: WLAN Broadcom BCM 4306 problems -the fw file(bwn_v4_ucode5) not found
- it can be built on a stock FreeBSD 8.1 system and copied over.
-
08:39 PM Bug #1380 (Closed): NAT reflection of UDP (or DNS?) doesn't work, spawns thousands of processes
- #1415 duplicated this
-
08:35 PM Bug #1347 (Resolved): ntpd not starting
-
08:30 PM Feature #1322 (Rejected): Squid 3
- this is not a legit bug report, ask questions on the forum or mailing list.
-
08:29 PM Bug #1358 (Resolved): OpenVPN Upgrade Issue
-
08:29 PM Bug #1403: Filter Rules description do not get saved when "(quote) present as character
- under what circumstances is this a problem? The input validation doesn't allow quotes in rule descriptions.
-
08:27 PM Bug #1355 (Closed): Clearing PPTP Raw Logs does not work
- duplicate of #1340
-
06:37 PM Revision 7100a85c: No need to include head.inc twice
-
02:18 PM Revision 0b9d02f3: Don't just blindly echo to the ntpd.log, it's a clog file and that will break it.
-
02:08 PM Bug #1483 (Rejected): OpenVPN peer-2-peer routing doesn't work
- it works, you have a config issue of some sort. post to the forum or mailing list for help.
-
02:03 PM Bug #1483 (Rejected): OpenVPN peer-2-peer routing doesn't work
- Hi,
i have here installed pfsense 2.0-RC1 (i386) built on Thu Apr 14 19:19:42, and i tried to establish a peer-2-p... -
02:00 PM Bug #1433: Config sync causes CARP state change
- Ok for the first one...
For the second one I attach you two different crashes I just caused while making changes on... -
06:48 AM Bug #1433: Config sync causes CARP state change
- The second picture seems and issue from the shaper.
I cannot tell anything if i do not see the trace, type bt on the... -
09:59 AM Feature #1482 (Resolved): Captive Portal support for a configurable RADIUS NAS ID
- When running network traces to examine the packets sent/received during Captive Portal authentication and accounting ...
-
07:05 AM Revision 787de45a: Push the ipv6 routes for the local network with push route-ipv6
-
03:44 AM Bug #1445: Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
- There is a driver bug logged, have a look at http://www.freebsd.org/cgi/query-pr.cgi?pr=156493 - otherwise one person...
04/25/2011
-
08:12 PM Revision 97ffc513: Add the ipv6 configuration options for routing ipv6 over the tunnel. Currently only a /64 is supported for the routed network, so use a /64 and then route the /56
-
07:50 PM Revision 9f5d14ce: Show OpenVPN instances on Status > Traffic Graphs, with descriptions.
-
07:07 PM Bug #1402: When creating a QinQ it works until reboot.
- Thanks Ermal for your response but when I create the step 1, and assign the member 1000 and click save, I get the nex...
-
04:03 PM Bug #1402: When creating a QinQ it works until reboot.
- You do not need to create teh vlan in step2 since it is done automatically by the GUI.
-
05:57 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
- Hmm... I use the RC1 (i386) version and have this problem, that's the reason I asked. The pptp Traffic-Flow stops aft...
-
05:53 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
- yes. if it's marked as resolved, it's resolved.
-
05:52 PM Bug #1151: Outgoing pptp Traffic-Flow stops after a while
- Is this bug fixed in the RC1 version?
-
05:43 PM Bug #1420: Changing a WAN's type from PPPoE to other breaks it
- probably, that would be consistent with 1.2.x
-
02:48 PM Bug #1420: Changing a WAN's type from PPPoE to other breaks it
- Should it delete the already created pppoe config?
-
05:17 PM Revision b1ba04cf: Add ipv6 tunnel remote subnets
-
03:42 PM Bug #1445: Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
- I am having problems too with the msk0 Marvell Yukon Gigabit on an iMac.
I will get a watchdog timeout on that int... -
02:45 PM Bug #846 (Closed): if_bridge triggers link state cycling on em(4)
-
12:55 PM Bug #1433: Config sync causes CARP state change
- Ok, I understand... I try to explain you the problems I encounter, you give me your opinion if it's related to this i...
-
10:40 AM Bug #1433: Config sync causes CARP state change
- I am sorry but it will still go up and down on slave but it want cause any issues!
If you can reproduce the issue ... -
11:14 AM Todo #1481 (Needs Patch): Bring back console menu banner link indication
- On 1.2.3 if an interface is up, it had a * next to it to indicate the link state. This was removed a while ago on 2.0...
04/24/2011
-
07:04 PM Feature #1477: IGMPPROXY spamming the main systemlog
- We're not running igmpproxy with verbose logging enabled, not sure if that log level is from something in the pfport ...
-
03:02 PM Feature #1477 (Resolved): IGMPPROXY spamming the main systemlog
- Since Igmpproxy is finally working now theres only one big problem left:
Igmpproxy is massivly spamming the main s... -
06:54 PM Bug #1478: some characters in FW rule descriptions do not sync properly
- that's intentional. though with CDATA now they may be safe, it's not going to change for now.
-
04:39 PM Bug #1478 (Resolved): some characters in FW rule descriptions do not sync properly
- Parentheses, periods and commas: "(", ")", ",", "." all get stripped out of the firewall rule description on the seco...
-
05:15 PM Todo #1373: Upgrade OpenVPN
- Added the IPv6 payload patch from Gert Doering for full IPv6 support.
04/23/2011
-
09:08 AM Feature #1449: LAG setup from CLI (like VLANs)
- I would like to +1 on this request. I currently use a basic config exported from a working system, change it and use ...
-
04:19 AM Bug #1432 (Resolved): Carp Vips are promoted to master before firewall filter load
- thanks
-
04:09 AM Bug #1432: Carp Vips are promoted to master before firewall filter load
- Tested and working! (see image) the red lines at 10:03:50 and 10:05:05 represents the moments where the secondary mac...
-
04:17 AM Bug #1433: Config sync causes CARP state change
- mmhh... with build "Fri Apr 22 18:24:14 EDT 2011" i386 on both machines, when I modify something on the master machin...
04/22/2011
-
08:42 PM Bug #1453 (Closed): Voucher RSA key generation problem
-
10:04 AM Bug #1453: Voucher RSA key generation problem
- I reinstalled pfSense, and RSA key regeneration works well. I'm unable to reproduce this problem.
-
05:57 AM Bug #1453 (Closed): Voucher RSA key generation problem
- I just installed pfsense 2.0-RC1 (i386) built on Fri Apr 22 01:23:40 EDT 2011 on an Alix 2D3 board. I tested the Vou...
-
07:48 PM Revision e3dc055a: Actually correct check meaning.
-
07:23 PM Revision bd17f93d: Do not an ip of all 1s as a gateways since it cannot be pinged.
-
06:28 PM Revision bce14123: Actually call interfaces_carp_setup after the carp interfaces are created so carp traffic can only flow after we have all vips up and running. This prevents premption more early than necessary. Ticket #1432.
-
04:40 PM Bug #1433 (Feedback): Config sync causes CARP state change
- Applied in changeset commit:"9411fbf73e52f01730da3fc8ba663bc901087144".
-
04:40 PM Bug #1432: Carp Vips are promoted to master before firewall filter load
- Applied in changeset commit:"9411fbf73e52f01730da3fc8ba663bc901087144".
-
02:32 PM Bug #1432: Carp Vips are promoted to master before firewall filter load
- I pushed another change so try with that.
Though i think carp needs to be teached about a 'start' sysctl as it has a... -
03:23 PM Revision d8da6350: Provide a method for rebrands to force a theme. Otherwise upgrading nanobsd from pfSense to a rebrand image without the theme in the config.xml will have a broken GUI since the theme isn't there.
-
09:42 AM Feature #1457: Bridge as interface
- Reassign the bridge0 interface as LAN, and assign your old LAN interface as a separate interface that is a member of ...
-
09:39 AM Feature #1457: Bridge as interface
- Yes but nat all LAN interface functionality can be moved to bridge interface yet (e.g. firewall anti-lockout). If you...
-
06:30 AM Feature #1457 (Closed): Bridge as interface
- already exists in 2.0, assign bridgeX
-
06:28 AM Feature #1457 (Closed): Bridge as interface
- Please add possibility to handle a bridge as an interface (e.g. add one IP address etc.). It would be useful if you a...
-
06:19 AM Feature #1456 (Closed): Vouchers expire at fixed time
- Please add a feature to create vouchers valid to a fixed time/date not for an amount of time.
-
06:16 AM Feature #1455 (Resolved): Voucher manager only user
- If you add a user responsible the voucher management of captive portal only with rights for vouchers only he/she have...
-
06:02 AM Bug #1454 (Resolved): Voucher error messages character set problem
- If you use accented characters outside the ASCII character set, the WebCfg seems to save the messages but it does not...
-
05:57 AM Todo #1373: Upgrade OpenVPN
- Needs to have this fix to make OpenVPN 2.2-RC2 work.
http://openvpn.git.sourceforge.net/git/gitweb.cgi?p=openvpn/open... -
04:57 AM pfSense Packages Bug #1452 (Resolved): Snort: broken link in snort_rules_edit.php [2.8.6.1 pkg v. 1.35]
- Patch attached
- 12:31 AM Revision de7222fb: correctly unmount drives where a config doesn't exist
04/21/2011
-
09:52 PM Feature #1451: Certificate errors after CARP election
- There's only one cert on each. However, I don't think the 2ry has been rebooted since setup; I'll do that and confir...
-
09:44 PM Feature #1451: Certificate errors after CARP election
- config sync does indeed sync the cert that's used, and there currently isn't any way to do otherwise. But, if you sta...
-
09:43 PM Feature #1451: Certificate errors after CARP election
- On the slave, go to System > Advanced, on the Admin tab, make sure the cert selected there is the same as the cert se...
-
09:41 PM Feature #1451: Certificate errors after CARP election
- Hmm... in that case, I think this is a bug, not a feature. If the identical certificate is being offered from both m...
-
09:19 PM Feature #1451 (Feedback): Certificate errors after CARP election
- Usually you would want to access the GUI on the boxes directly by accessing their actual IPs, not the CARP VIP, since...
-
07:03 PM Feature #1451 (Resolved): Certificate errors after CARP election
- Using CARP VIP to administer pfSense, after the backup is promoted to master, Firefox complains about SSL certificate...
-
09:39 PM Revision 2d4003aa: If the bandwidth value is coming from radius scale it up to the requested Kbit/s unit.
-
08:05 PM Revision 2594f401: missed a bit of my last commit
-
07:33 PM Revision 908cbaf9: Set user when removing privileges, otherwise things like the user's shell would not be reset until pressing save, which is inconsistent with that step not being needed when adding privileges.
-
06:54 PM Feature #1450 (Closed): XMLRPC syncs all VPN types *except* PPTP
- Just got burned by this... I never noticed that XMLRPC Sync keeps IPSEC and OpenVPN in sync, but not PPTP. Even if t...
-
06:34 PM Revision a29aeb47: Merge branch 'master' of http://gitweb.pfsense.org/pfsense/mainline.git
-
06:33 PM Revision ea7763c0: ignore dreamweaver temp files
-
06:29 PM Revision a828210b: checking moduli of ssl csr request and response
-
06:22 PM Bug #1433: Config sync causes CARP state change
- Do we have the ability to diff chunks of the config xml? If diff(old-carp-config,new-carp-config)==zero-changes, don...
-
03:09 PM Bug #1433: Config sync causes CARP state change
- pfSense is a long time having this code.
It was done because otherwise lots of code need to be added just to test fo... -
06:11 PM Bug #1391: Disable auto-added VPN rules missing
- Perhaps I'm missing something - I have yet to see a single auto-added FW rule for VPNs on my boxes: I thought the che...
-
06:03 PM Feature #1449 (Closed): LAG setup from CLI (like VLANs)
- Provide a mechanism during initial interface assignment to create LAGs, not just VLANs. In a moderately complex envi...
-
05:48 PM Bug #747: Root schedulers (ie PRIQ) cannot be configured on interfaces that don't report bandwidth
- I put a patch for this and it would give by default to an interface 100Mbit line if it is not reported automatically.
-
05:46 PM Bug #1381 (Closed): GRE tunnel interface IP address updated after reboot only
- Its an OP issue.
-
05:27 PM Todo #1438: Add override for CSR request->response subject mismatch
- New merge request sent
-
05:10 PM Revision 1f0c76cf: Fix PPPoE upgrade, the <pppoe> tag is considered an array these days and the upgrade code wasn't treating it properly, accessing it directly instead of using the first entry ([0]). Fixes #1439 - PPPoE credentials upgrade properly now.
-
02:33 PM Revision 46698c3f: Reject encrypted CA private keys. Resolves #1446
-
01:59 PM Revision 0cc5ab42: Confirmed working fix for ticket #1417 - with this change I have two-way connectivity on Site-to-Site (SSL/TLS) with iroutes.
-
01:10 PM Bug #1439: WAN PPPoE config dropped on update from 1.2.3 (nanobsd) to 2.0-RC1 (snapshot 20110415-1518)
- Applied in changeset commit:"1f0c76cfd7086aa90ea97a9775f2f024390a02ec".
-
10:35 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- Applied in changeset commit:"46698c3f3c5e3f2e98829757616ddda3ce779b6d".
-
10:07 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- Prompting for the password is too large of a change to try squeezing in at this point in the release cycle. I'll look...
-
02:38 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- I thing I found the problem. The imported CA-private key was encrypted:
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: ... -
10:00 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- OK, I finally got it all the way straightened out. I confirmed it worked between two test VM networks with my last co...
-
05:56 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- For me, the client-config-dir works with the build "Fri Apr 15 18:54:32 EDT 2011". I didn't upgrade yet.
I read th... -
07:12 AM pfSense Packages Bug #1385: Open-VM-Tools not working anymore
- Jim P wrote:
> We need to fix the automated build process, not upload new binaries.
Any news on that problem?
... -
06:51 AM Bug #1448 (Feedback): PPTP VPN Radius authentication and accounting don't work
- I find it very hard to believe there is any difference between amd64 and i386, all my systems that work fine are i386...
-
06:44 AM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- Just tested with 64bit version. it's work directly after install using same config backup. 32 bit not working (latest...
-
03:14 AM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- it is definitely working on 32 bit.
-
03:12 AM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- please reopen it. PPTP Auth via radius not working in 32bit version!!!!
-
03:27 AM pfSense Packages Bug #1423: Open-VM-Tools package script files broken in 2.0rc-1
- _Include file open-vm-tools.inc could not be found for inclusion._
but why ? -
03:23 AM pfSense Packages Bug #1423: Open-VM-Tools package script files broken in 2.0rc-1
- The EOFA has gone now...
04/20/2011
-
08:28 PM Bug #1448 (Closed): PPTP VPN Radius authentication and accounting don't work
- doubly confirmed, accounting and auth work fine. The posted config is correct. If you're seeing no traffic to your RA...
-
08:18 PM Bug #1448 (Feedback): PPTP VPN Radius authentication and accounting don't work
- it works fine. Also disables fine, you have to actually disable it by unchecking, you can't just take out the IP.
-
08:01 PM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- Instead of opening a new bug i figured i would add to this.
I am having the same issue with PPTP authenticating to... -
03:33 PM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- attached files from requested directory
-
03:19 PM Bug #1448: PPTP VPN Radius authentication and accounting don't work
- Can you show the contents of cat /var/etc/pptp-vpn/*
-
10:45 AM Bug #1448 (Closed): PPTP VPN Radius authentication and accounting don't work
- PPTP VPN configured to use radius authentication and accounting. no traffic to radius server. no users authentication...
-
10:59 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- Might be something specific to your CA then, hard to say without trying it out. I imported a CA I had made a long tim...
-
10:55 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- Annexed the properties of the imported CA-certificate in case that the properties of the CA are the problem.
(create... -
10:46 AM Bug #1446: Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- Tag in /cf/conf/config.xml is empty:
<cert>
<refid>4daeeb458a580</refid>
<descr><![CDATA[thomas_c]]></descr>
... -
08:33 AM Bug #1446 (Feedback): Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- I performed that exact same sequence (imported a CA, generated a certificate, and exported) and I got the expected da...
-
07:32 AM Bug #1446 (Resolved): Export of internal generated cerificate (crt) ist empty when made from encrypted CA key
- After generating a own certificate the exported crt is empty.
How the problem can be reproduced:
# An own CA-cert... -
09:03 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- Yeah I had the wording in that wrong. There may be something else going on in P2P/TLS then. People on the forum were ...
-
02:49 AM Bug #1417 (Feedback): OpenVPN client specific overrides doesnt work by default
- that commit looks like it would have been ok, it was changed for P2P TLS, not shared key.
-
02:44 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- Hm, okay. But I use certificate based authentication....
So please reopen? -
07:46 AM Feature #1447 (Resolved): Export certificates in pkcs12 format
- It would help if the stored certificates could be exported also in PKCS12-format, because many clients (like some on ...
04/19/2011
-
11:59 PM Revision bd24573b: Backing out changes from ticket #1417, it was not a valid openvpn config that the user was trying to make.
- 09:06 PM Revision 673ee7b1: Harden SSL settings a bit. Verified OK with @cmb and @billm
-
07:56 PM Bug #1417 (Closed): OpenVPN client specific overrides doesnt work by default
- Apparently it's just not allowed to have a shared key tunnel and push with client-config-dir. Backing out changes, as...
-
03:37 PM Bug #1318: Certificate error: certificate subject does not match signing request subject
- Also confirmed with RapidSSL with GeoTrust as the intermediate CA.
2.0-RC1 (amd64)
built on Thu Apr 14 11:13:23 ... -
05:34 AM Bug #1432: Carp Vips are promoted to master before firewall filter load
- I caught it, the master firewall started to work after this log line:
Apr 19 10:03:27 pfsense1 check_reload_status... -
04:13 AM Bug #1432: Carp Vips are promoted to master before firewall filter load
- The situation has improved, but not resolved yet... (tested with build 18 23:29:41 EDT 2011 i386)
In the image att...
04/18/2011
-
10:31 PM Bug #1433: Config sync causes CARP state change
- the secondary has no need to blow away its CARP IPs and recreate them unless there has been a CARP change, and never ...
-
06:07 PM Bug #1433: Config sync causes CARP state change
- In etc/inc/interfaces.inc, before line 1827, there could be something like:
$ints = get_interface_arr(true);
fore... -
03:25 PM Bug #1433: Config sync causes CARP state change
- Makes sense that the VIPS are destroyed and recreated after reconfiguring on the backup machine, unfortunately when t...
-
02:45 PM Bug #1433: Config sync causes CARP state change
- Well this is normal considering that the slave just destroys and recreates its vips and an election occurs in carp co...
-
10:27 PM Revision 6c9cf466: Slightly different fix for #1417 that doesn't mess up other parameters needed by p2p_tls
-
07:18 PM Revision e2e934e0: override option for certificate subject mismatch
-
06:56 PM Revision 359f6307: Block instead of allowing proto carp/pfsync during bootup since this may cause issues. Ticket #1432
-
06:25 PM Revision 42c07003: Add an option under advanced->misc to specify a proxy for retreiving pfsense package info or downloading packages.
-
05:08 PM Revision e8503ff4: Only start log update ajax timer if the updateDelay is defined. http://forum.pfsense.org/index.php/topic,35771.0.html
-
04:38 PM Bug #1439: WAN PPPoE config dropped on update from 1.2.3 (nanobsd) to 2.0-RC1 (snapshot 20110415-1518)
- Here's the old and the new config. I replaced passwords and usernames, also removed some settings like firewall filt...
-
11:35 AM Bug #1439 (Feedback): WAN PPPoE config dropped on update from 1.2.3 (nanobsd) to 2.0-RC1 (snapshot 20110415-1518)
- The upgrade log won't tell us anything relevant here. We need the before and after upgrade versions of your config.xm...
-
04:19 PM Todo #1438: Add override for CSR request->response subject mismatch
- Better than a patch: I did a merge request on https://rcs.pfsense.org/projects/pfsense/repos/yakatz-sandbox/commits/e...
-
02:32 PM Todo #1438: Add override for CSR request->response subject mismatch
- What I meant to say there is this patch fixes the problem.
I am working on a patch that will actually completely wor... -
02:24 PM Todo #1438: Add override for CSR request->response subject mismatch
- Here is the simple patch. A better one is on the way.
-
02:58 PM Bug #1426 (Feedback): IPsec descriptions need trimmed in rule labels
- This seems to have been fixed by Seth.
-
02:55 PM Bug #1432 (Feedback): Carp Vips are promoted to master before firewall filter load
-
02:47 PM Bug #636: layer7 not work correctly
- Still not working here either (2.0-RC1 (i386) built on Mon Apr 18 10:01:33 EDT 2011). L7 container set to block HTTP....
-
02:31 PM Bug #1444: Reconfiguring interfaces doesn't deconfigure previous ones
- No its not like #174. This is in console and i am not sure that it has been forseen for such use.
I will give a look... -
12:18 PM pfSense Packages Bug #1443: Squid errors on updating version
- I definitely have the errors, as does Nachtfalke as per http://forum.pfsense.org/index.php/topic,35673.0.html
I in... -
12:15 PM pfSense Packages Bug #1443: Squid errors on updating version
- I can't reproduce this. I have installed/reinstalled/uninstalled and starting and stopping the service works as expec...
-
09:08 AM Revision 81b44848: Surround the IPv6 address with brackets
-
06:39 AM Feature #1431: PPPoE LQR Echo
- I try setting up suggest by Calvin Teh, and it working, but after restart it come back to the problem.
-
06:39 AM Feature #1431: PPPoE LQR Echo
- I try setting up suggest by Calvin Teh, and it working, but after restart it come back to problem.
-
01:37 AM Feature #1431: PPPoE LQR Echo
- I'm also having same problem. Any update regarding this issue
04/17/2011
-
08:25 PM pfSense Packages Bug #1443: Squid errors on updating version
- More information:
Reinstalling the package allows it to run for the period of time that the system is up. As soon ... -
08:12 PM Bug #1445 (Rejected): Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
- not convinced that's a driver problem, sounds like it may be config related, but if it is, not something we can fix. ...
-
11:26 AM Bug #1445 (Rejected): Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
- This is a follow-up to bug 1444. Installed via pfSense-memstick-2.0-RC1-i386-20110417-0359.img.gz.
As described i... -
03:43 PM pfSense Packages Bug #1315: ERROR 404 on packages area upper-left logo of psense.
- PS: the files changed are:
config/snort/index.php
config/snort/snort.xml
Thanks!
Michele -
02:58 AM pfSense Packages Bug #1315: ERROR 404 on packages area upper-left logo of psense.
- According to this thread http://forum.pfsense.org/index.php/topic,33812.0.html I added a index.php in the snort direc...
-
03:39 PM pfSense Packages Bug #1114: Snort Dashboard Widget has wrong link
- ps: the file changed is
config/widget-snort/snort_alerts.inc
Thanks! -
02:46 AM pfSense Packages Bug #1114: Snort Dashboard Widget has wrong link
- Made the change, waiting for someone to merge my git clone in the master
-
11:28 AM Bug #1444: Reconfiguring interfaces doesn't deconfigure previous ones
- BTW, this sounds like bug 174, fixed a year ago.
-
10:56 AM Bug #1444 (Resolved): Reconfiguring interfaces doesn't deconfigure previous ones
- I just installed 2.0-RC1 via pfSense-memstick-2.0-RC1-i386-20110417-0359.img.gz with the quick install wizard (SMP ke...
-
05:27 AM Revision 5381b341: Don't include RFC1918 in bogons.
04/16/2011
- 10:19 PM Revision 988d498c: sync bogons
-
10:12 PM pfSense Packages Bug #1443: Squid errors on updating version
- UPDATE: I have just reinstalled the latest version of 2.0RC1-i386-20110415-11416 and I still have the same issues. Th...
-
07:47 PM pfSense Packages Bug #1443 (Closed): Squid errors on updating version
- As per http://forum.pfsense.org/index.php/topic,35673.0.html some of us are experiencing Squid errors when updating f...
-
06:26 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
- Only if you're willing to pay to have it fixed. Otherwise it gets fixed when we get to it.
-
03:03 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
- is it possible to rise priority from normal to high?because i have to disable PPTP VPN on my production firewalls wit...
-
12:05 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
- any fix for this bug?
-
06:20 PM Bug #1440 (Closed): Bogons list is outdated
- cron job was broken when the server died recently, fixed.
-
11:32 AM Bug #1440 (Closed): Bogons list is outdated
- The pfsense bogon list in http://files.pfsense.org/mirrors/bogon-bn-nonagg.txt is hoplessly outdated. The following ...
-
06:09 PM Todo #1441 (Closed): IPv4 bogons list is now static
- not going to remove it as it could possibly change though it most likely won't, and the same mechanism will be used f...
-
11:52 AM Todo #1441 (Closed): IPv4 bogons list is now static
- Once the IPv4 bogons list is updated with the updates in http://redmine.pfsense.org/issues/1440, the ipv4 bogon list ...
-
03:13 PM Bug #1442: Upgrade to 2.0-RC1 breaks 1.2.3 on other slice.
- Actually, it wasn't clear to me that the config partition is shared between the slices. I thought it was stored with...
-
01:22 PM Bug #1442 (Rejected): Upgrade to 2.0-RC1 breaks 1.2.3 on other slice.
- That is a known and expected problem. There is no way around that since both slices share the same config. No code we...
-
12:59 PM Bug #1442 (Rejected): Upgrade to 2.0-RC1 breaks 1.2.3 on other slice.
- I just upgraded a firewall from 1.2.3 to todays snapshot, using pfSense-2.0-RC1-4g-i386-20110415-1518-nanobsd-upgrade...
-
11:25 AM Bug #1439 (Resolved): WAN PPPoE config dropped on update from 1.2.3 (nanobsd) to 2.0-RC1 (snapshot 20110415-1518)
- I just upgraded a firewall from 1.2.3 to todays snapshot, using pfSense-2.0-RC1-4g-i386-20110415-1518-nanobsd-upgrade...
04/15/2011
-
08:57 PM Revision 13399e17: Properly add dns and wins fields, load them on page load.
-
08:54 PM Revision d7bccf3c: Generate a address from the bridge mac and configure a v6 address
- 04:38 PM Revision a51493d1: Merge remote-tracking branch 'mainline/master' into inc
- Conflicts:
etc/inc/gwlb.inc -
04:11 PM Revision 7b2fdeb3: Properly set/unset voucher enable/disable bit.
-
03:17 PM Bug #954: Switching to manual outbound NAT creates incorrect rule for PPTP server
- The internal automatic rule is wrong as well. Regardless of how many clients you have, the outbound NAT rule it makes...
-
01:06 PM Revision 3df79aa0: Merge remote branch 'upstream/master'
- Conflicts:
usr/local/www/interfaces.php -
12:53 PM Revision b9bbae04: Move the link to add a gateway up next to the drop-down box so it is more obvious.
-
12:37 PM Revision 6d3fd938: Change the wording and the link placement for adding a new gateway
-
08:42 AM Revision b1c305e7: Merge remote branch 'upstream/master'
-
08:41 AM Revision cfd40454: Make it possible to add a IPv6 gateway using the ajax add button
-
12:44 AM Todo #1438 (Resolved): Add override for CSR request->response subject mismatch
- Just a bit of bug checking and the code that I mentioned on the mailing list will be ready (I am waiting on my CA to ...
04/14/2011
-
11:15 PM Bug #1437 (Resolved): More validation needed on CSR generation
- It appears that if the countryName in the requested subject is not recognized by openssl, it throws these two errors ...
-
10:32 PM Feature #752 (Resolved): Ease policy routing across OpenVPN
- this has been good for a while, using it on a number of installs.
-
08:50 PM Revision ca90133b: Save a little space on the interface list for console assignment.
-
07:11 PM Bug #1436 (Resolved): firewall syslog stops working after reboot
- 2.0-RC1 (i386)
built on Thu Apr 14 15:32:22 EDT 2011
You are on the latest version.
Platform nanobsd (1g)
H... -
05:26 PM Revision d2903c0c: Test if a variable is set before trying to unset it. If a user has no rules in their config, then $config['filter'] would not be undefined, so unsettings $config['filter']['bypassstaticroutes'] would result in an error. http://forum.pfsense.org/index.php/topic,35702.0.html
-
02:35 PM pfSense Packages Feature #1435 (Needs Patch): Squid - add syslog capability
- Hi,
Is it possible to add the squid log module rather than storing the logs
locally on the pfsense device?
If... -
11:08 AM Feature #1434 (New): Radius Accounting in OpenVPN
- Radius Accounting packets are critical to any enterprise implementation of OpenVPN due to compliance reasons. It is a...
-
06:03 AM Bug #1149: nano build - upgrade size failure on USB flash drives
- newbie on bsd and pfsense.
filed a bug week or so ago, got rejected. found this, exactly my problem.
currently ... -
06:00 AM Bug #1149: nano build - upgrade size failure on USB flash drives
- newbie on bsd and pfsense.
filed a bug week or so ago, got rejected. found this, exactly my problem.
currently ...
04/13/2011
-
08:13 PM Bug #1402: When creating a QinQ it works until reboot.
- Is there any news about this issue??
Saludos! -
06:01 PM Bug #651: Multiple gateways on WAN interface
- Ermal Luçi wrote:
> The problem with this is that apinger will bind to the same address and has no idea that the mon... -
04:34 PM Todo #648: Move "base" packages such as RIP, OLSR, etc, back into packages
- Currently I know about at least 5 installations using the LiveCD in corporate installations
(+ my own one).
The r... -
12:38 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
- my pf info
2.0-RC1 (i386)
built on Tue Apr 12 11:38:49 EDT 2011 -
12:31 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
at last i found my periodically ipsec disconnect problem after researching in redmine,i'm using pptp from home to c...-
07:52 AM Revision c8cc0c1c: Add missing fields for l2tp to define dns and wins servers
04/12/2011
- 10:18 PM Revision a93020d5: Do not send growl notices twice
- 10:08 PM Revision 2632934e: Remove blank trailing c/r.
- 10:08 PM Revision 10c3d4c0: Notify via smtp as well as growl
-
05:52 PM Revision cd11a142: Drop the ntpdate sync in favor of using ntpd -s, which should have the same net effect without needing the shell script that has been prone to hanging.
-
05:14 PM Bug #1397 (Resolved): ntpdate sync not functioning properly
-
05:13 PM Bug #1397: ntpdate sync not functioning properly
- Hi Jim P,
That change seemed to do the trick. NTP is running just perfectly after making those changes and rebooti... -
04:58 PM Bug #1397: ntpdate sync not functioning properly
- I updated this again with commit:cd11a14
ntpdate sync is completely gone, since simply starting ntpd with -s will ... -
04:58 PM Bug #1347: ntpd not starting
- I updated this again with commit:cd11a14
ntpdate sync is completely gone, since simply starting ntpd with -s will ... -
04:29 PM Revision 2816c5a1: Fix Parse error
-
02:04 PM Revision d67b6b17: Also exclude grep from running processes when grepping for a running packet capture. Also, fix other test to match the recent changes made.
-
08:43 AM Revision 2521266a: Only pick up the ipv6 addresses from the DNS servers section
-
08:40 AM Revision af8f910e: Merge remote branch 'upstream/master'
-
08:39 AM Revision 86966fba: Merge remote branch 'upstream/master'
- Conflicts:
etc/inc/filter.inc
usr/local/www/themes/the_wall/rrdcolors.inc.php -
01:24 AM Feature #1431: PPPoE LQR Echo
- tricking the WAN interface to become a DHCP connection and back to PPPoE works . However after a system restart, the ...
-
01:05 AM Feature #1431: PPPoE LQR Echo
- I don't have anything with PPPoE handy but it looks at a glance like keep-alive should always be present. From interf...
-
12:37 AM Bug #1433 (Resolved): Config sync causes CARP state change
- Any config change causes the CARP IPs on the secondary to come up as master and back down to backup, which is unneces...
04/11/2011
-
08:58 PM Revision 127eb8e0: Add a toggle under System > Advanced on the misc tab to enable/disable debug mode for racoon.
-
09:25 AM pfSense Packages Bug #1385: Open-VM-Tools not working anymore
- Confirm not working on amd64 platform as well
2.0-RC1 (amd64)
built on Sun Apr 10 21:49:29 EDT 2011 -
09:19 AM Bug #1428 (Resolved): DNS servers not assigned
- I was able to reproduce this, and committed a fix on Saturday. This is fixed on current snapshots, and confirmed with...
-
09:04 AM Bug #1428: DNS servers not assigned
- Same problem here after update... ISP DNS servers not applied. Had to enter DNS servers manually.
2.0-RC1 (i386)
... -
07:15 AM Bug #1381: GRE tunnel interface IP address updated after reboot only
- you can close it. it's work as explained in your update
-
04:44 AM Bug #1432 (Resolved): Carp Vips are promoted to master before firewall filter load
- When the "master" machine boots, the CARP ips are promoted to master immediately, even before the firewall filters ar...
-
01:10 AM Bug #1399: rrdtool respawning too fast
- Noticed this message in syslog long ago.
-
12:56 AM Feature #1431: PPPoE LQR Echo
- one thing that I have noticed is , when WAN interface is on DHCP the keep alive option is working perfectly fine. Cha...
04/10/2011
-
11:48 PM Feature #1431: PPPoE LQR Echo
- mpd5 mentions it as a "set link keep-alive seconds max" parameter under mpd.conf .. but that mpd.conf is no where to ...
-
09:42 PM Feature #1431: PPPoE LQR Echo
- you'll have to look into mpd 5 and see if it supports that.
-
09:28 PM Feature #1431 (Closed): PPPoE LQR Echo
- Some ISPs that I have experienced with locally requires LQR echo reply sent from the client to ensure that the sessio...
-
09:43 PM Bug #1413 (Closed): PPPoE connection disconnects consistently
- actual cause in #1431
-
09:02 PM Bug #1413: PPPoE connection disconnects consistently
- Dear All,
I have found the root cause of the issue that the ISP requires a LCP echo inteval reply of 30 seconds in... -
05:10 AM Bug #1347: ntpd not starting
- with the Fri Apr 8 18:33:38 EDT 2011 build the
issue seems to be gone.
Thank you
04/09/2011
-
04:31 PM Bug #1428: DNS servers not assigned
- need dhclient logs, that just looks like you aren't being assigned DHCP servers.
-
01:36 PM Bug #1428: DNS servers not assigned
- They should be assigned via DHCP by the ISP but PFSense will not accept them so I have assigned them manually in gene...
-
11:36 AM Bug #1428: DNS servers not assigned
- Not enough info here. Are these assigned manually? By DHCP? Any errors in the logs or console?
-
09:25 AM Bug #1428 (Resolved): DNS servers not assigned
- I just updated my PFsense install to the latest version (2.0-RC1 (i386)built on Fri Apr 8 18:33:38 EDT 2011) and DNS ...
-
04:00 PM Revision 4eb4b18a: Revert changes to dhclient-script. Appears to have broken DNS servers from DHCP. Ticket #1428
-
06:43 AM Bug #1413: PPPoE connection disconnects consistently
- here are the screenshot attachments for the PPPoE configuration
04/08/2011
-
08:08 PM Revision e9e06fb2: Fix copy/paste error
-
07:39 PM Bug #1397: ntpdate sync not functioning properly
- Hi Jim P,
I've also applied your commits, but it didn't resolve the issue. Once I applied them and started the dis... -
05:28 PM Bug #1397: ntpdate sync not functioning properly
- The ntp issue would be separate (it has its own ticket), but I didn't test with openvpn. I suspect that's because Ope...
-
04:59 PM Bug #1397: ntpdate sync not functioning properly
- Jimp, I've applied your commits and I see the service is now running fine at startup and is able to stop and restart ...
-
11:49 AM Bug #1397 (Feedback): ntpdate sync not functioning properly
- Should be fixed as of commit:edf99ce (See also commit:2db351a and commit:54c1859)
-
06:15 PM Revision ac6651c9: Make sure a theme directory actually exists before blindly using it.
-
03:46 PM Revision edf99ce4: Rework ntpdate_sync_once.sh, so it makes sure ntp/ntpdate/itself are not running before trying to sync time, and then launch ntpd at the end for time sync (last commit was premature)
-
03:20 PM Revision 54c18594: Don't unconditionally start ntpd after doing ntpdate, it might be disabled.
-
03:20 PM Revision 2db351a7: Send ntpdate output to syslog
-
02:10 PM Bug #1427: Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
- Use the pre button for code.
The issue here is somewhat moot: The UP kernel is eventually going to be phased out. ... -
02:08 PM Bug #1427: Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
- Let's try one more time...
> if [ $KERNELTYPE = "UP" ]; then
> > -if [ -f /kernels/kernel_SMP.gz ]; then-
> > +if ... -
02:07 PM Bug #1427: Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
- The formatting of that ticket came out really bad.
> if [ $KERNELTYPE = "UP" ]; then
> > if [ -f /kernels/kernel_SM... -
02:05 PM Bug #1427 (Resolved): Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
- From the mailing list:...
-
12:59 PM Revision fbfd675a: Add an IPsec xauth permission. Try to use the nologin shell first (just unlock the account). Ticket #1202
-
12:28 PM Revision 02d99511: Putting client-config-dir in the config is valid also for p2p_tls servers. Fixes #1417.
-
11:54 AM Bug #1347 (Feedback): ntpd not starting
-
11:52 AM Bug #1347: ntpd not starting
- If you have a WAN failure or don't have working DNS, then launching ntpd is just as useless because it uses the same ...
-
08:30 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- Applied in changeset commit:"02d99511539a3312f8aab54b7dd1cdcaec9c0847".
-
08:22 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- Strike that. Looking at the backend code, you must be using "Peer to Peer (SSL/TLS)". It seems that one case was miss...
-
08:17 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- What exact settings are you using for your OpenVPN server?
I just set up an instance with the wizard and it does h... -
03:59 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
- I have the following content in the client specific configuration....
-
03:19 AM Bug #1426 (Resolved): IPsec descriptions need trimmed in rule labels
- On configs upgraded from 1.2.3 at a minimum, and possibly others, the automatically generated IPsec rules do not trim...
04/07/2011
- 08:17 PM Revision b510be5c: use same egrep statement for both checks
- 08:16 PM Revision 1fd807da: Use full path to egrep
- 08:15 PM Revision d0cc727e: Use full path to egrep
- 08:11 PM Revision 955f2d78: Use some Seth egrep foo to protect from compromised DHCP servers. CVE-2011-0997
-
07:32 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
- The FreeBSD bug indicates that the bug is triggered by high traffic/bandwidth via the interface.
If someone can re... -
06:59 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
- It will be 8.1. Will see if we can easily back port the 8.2 driver if that is the fix.
-
06:30 PM Bug #1425 (Closed): pfSense stops receiving traffic on 'bge' driven interface
- Hi guys,
This bug has happened to our installation twice, now. Seemingly randomly, the bge0 interface (I have bge0... -
05:13 PM pfSense Packages Bug #1390 (Resolved): pfflowd amd64 binary missing
- 04:35 PM Revision e05458b0: Remove extra variable set
- 04:34 PM Revision 7ec2a858: Remove copy paste
- 04:33 PM Revision 0c951d9b: Unbreak check if capture is running
- 04:00 PM Revision 5d788161: When using ' variables are not expanded. Use double quotes so that the variable is exanded
-
03:49 PM Revision c76fc19f: Don't test for a user cert here either, see previous commit.
-
03:47 PM Revision 72d8453d: Don't test if a cert is in use here, you could in theory use a cert for a user and a server.
-
01:55 PM Bug #1402: When creating a QinQ it works until reboot.
- Ok here are some screenshots:
1. First I create the QinQ with the SVLAN 13 and as member the VLAN 1000.
!1.png!
... -
05:30 AM Bug #1402: When creating a QinQ it works until reboot.
- Please provide the logs and screenshots to help with this.
-
10:58 AM pfSense Packages Bug #1385: Open-VM-Tools not working anymore
- I can confirmed this issue on i386 platform :...
-
10:55 AM Bug #1342: kernel crash with RC1 on vmware
- I just reinstalled to i386 (and change VM type to FreeBSD 32bits). It seems much more stable now...
Let's wait a f... -
08:05 AM Bug #1413: PPPoE connection disconnects consistently
- here is an attachment of the packet capture done on the WAN interface. Ping was initiated as soon the PPPoE connectio...
-
07:56 AM Feature #1424 (Closed): OpenVPN entry on interface groups
- It would be consistent to add/show the OpenVPN, PPPoE, PPTP, etc.. under interface groups as permanent entries since ...
-
07:27 AM pfSense Packages Bug #1423 (Resolved): Open-VM-Tools package script files broken in 2.0rc-1
- /usr/local/pkg/open-vm-tools.inc seems to have issues.
One of which is an erroneous "A " at the end of a here doc ... -
07:10 AM Feature #1422 (Closed): short voucher codes
- Please add an option for shorter voucher codes. For home use 5 or 6 chars codes would be sufficient instead of the or...
-
03:38 AM Bug #1418: SNMP bind to LAN
- Thanks Ermal, lastest snapshot is OK.
Regards
04/06/2011
-
11:53 PM Revision 8fee59d6: Fix link; use same message for missing certs.
- 11:41 PM Revision 0930bd01: Make the default openvpn cert authority message a bit relaxed and let user know about the wizard option as well
-
11:31 PM Bug #1402: When creating a QinQ it works until reboot.
- mmmm...sorry because I am not giving any screenshot, but im not at the office right now.
I have been testing like ... -
10:56 PM Bug #1421 (Rejected): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
- Disconnecting PPTP VPNs drops IPsec when using a public IP as the PPTP server IP, which is an incorrect configuration...
-
10:47 PM Bug #1420 (Resolved): Changing a WAN's type from PPPoE to other breaks it
- When a WAN interface set for PPPoE is switched to any other type, it breaks it, as it leaves that interface assigned ...
-
07:01 PM Bug #1381: GRE tunnel interface IP address updated after reboot only
- It's work. please update documentation
-
06:23 PM Revision 87bb66af: Correct text to include PPTP as well.
-
06:22 PM Revision 9a36dc9d: Resolves #1391. Bring back VPN auto rule disable advanced setting.
-
05:36 PM Revision ab75b4ee: CRL is read in as an array now, so even in the imported config it will appear to be an array even though it can only have one value. Fixes #1358
-
05:14 PM Revision 6177fd92: Fixup text.
-
04:55 PM Revision 557300a7: Actually re-parse the config if a valid config was not written. (Should help stop installs from blowing up on failed config upgrades). Save the bad config for inspection, and print a message to the console about what was done.
-
02:59 PM Revision 4c613f84: Correct error message for gateways to report down when the gateway is down and not high latency.
-
02:58 PM Revision 19d91466: Another sweep at keeping the default route always present when the default setup route is marked as down. This now adds checks for configuration where a defaultgw is not specified by the user but deduced automatically.
-
02:26 PM Bug #802: Interface reassignment with VLANs after config restore to diff hardware doesn't work
- Forward to me to take a look.
-
02:25 PM Bug #1391 (Feedback): Disable auto-added VPN rules missing
- Applied in changeset commit:"9a36dc9d241e004e7bcdec25def3b7b0c9d94cff".
-
02:23 PM Bug #1410: pfSense remains without default route
- Another improvement was committed related to this.
It now considers gateways that are not marked as default in the GUI. -
10:54 AM Bug #1410: pfSense remains without default route
- Ermal Luçi wrote:
> A setup with multiple WANs can losse its default route when its gateway is marked as down from a... -
01:45 PM Bug #1358 (Feedback): OpenVPN Upgrade Issue
- Applied in changeset commit:"ab75b4ee5475fe1be718cb0e93d0a34f293c5ed0".
-
11:30 AM Bug #1417 (Feedback): OpenVPN client specific overrides doesnt work by default
- I know for a fact this works without doing that, need more info.
-
10:49 AM Revision d10da0f9: Resolves #1418. Correct test to actully do what's intended.
-
10:43 AM Bug #1342: kernel crash with RC1 on vmware
- are these all 64 bit?
-
07:28 AM Bug #1342: kernel crash with RC1 on vmware
- Same problem here... With lastest snapshot update applied (pfSense-Full-Update-2.0-RC1-amd64-20110405-1827.tgz)
!k... -
10:42 AM Revision 5766add8: If the supplied gateway is all ones(255.255.255.255) do not report it as a gateway since its useless.
-
10:41 AM Bug #1419 (Rejected): Incorrect Intel License information in dmesg
- just a fact of the Intel driver, we don't include doc. You'll have to get it from a stock FreeBSD.
-
10:26 AM Bug #1419 (Rejected): Incorrect Intel License information in dmesg
- Running:
FreeBSD fw 8.1-RELEASE-p2 FreeBSD 8.1-RELEASE-p2 #1: Tue Apr 5 17:09:22 EDT 2011 sullrich@FreeBSD_8.0_pfS... -
10:16 AM Bug #1407 (New): GUI is sluggish without working DNS
- That may help with multi-wan, but doesn't help the case when there is only one WAN, or all WANs are down.
-
05:28 AM Bug #1413: PPPoE connection disconnects consistently
- will furnish with a screenshot since the VM is disabled at the moment. However what I have configured on the WAN inte...
-
04:57 AM Bug #1413: PPPoE connection disconnects consistently
- Show your pppoe configuration please
-
04:53 AM Bug #1418 (Resolved): SNMP bind to LAN
- Thanks committed.
-
04:41 AM Bug #1418 (Resolved): SNMP bind to LAN
- Hi,
With 2.0, it's impossible to make bsnmpd bind to LAN. It's very usefull when we want to access SNMP data from ... -
02:01 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- Rob Eckel wrote:
> I solved the problem that I was experiencing today. I noticed that the step of the connection th... -
12:49 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
- I solved the problem that I was experiencing today. I noticed that the step of the connection that it was stalling o...
Also available in: Atom