Project

General

Profile

Activity

From 05/25/2011 to 06/23/2011

06/23/2011

11:30 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Just updated to 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011 which has the patch that Jim P linked to - same... David Rees
11:02 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim P wrote:
> Try it with commit:90ecc0b62f8b363d9497b4754133738edb9bc633
I have tried this on a "2.0-RC1 (amd64...
David Rees
11:02 PM Revision 95c8cf48: Intermediate CAs and openssl_xxx() error checking in CA management.
Evgeny Yurchenko
10:28 PM pfSense Packages Bug #1609: unable to install Avahi
The tgz is an ugly mess that needs to die. It really needs to install properly from the package system. It may just n... Jim Pingle
10:23 PM pfSense Packages Bug #1609: unable to install Avahi
Maybe we should remove
<depends_on_package>avahi-0.6.28.tbz</depends_on_package>
from pkg_config.8.xml.amd64 as it...
Evgeny Yurchenko
09:45 PM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
it was actually fixed a while back, I just missed the fact the file was still there, it's not an issue Chris Buechler
09:44 PM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
Tried to reproduce:
# echo test >/etc/rc.d/test
# chmod 555 /etc/rc.d/test
Install iperf package: /etc/rc.d/test i...
Evgeny Yurchenko
09:22 PM Bug #1605: DHCP Server should group known clients by interface
We are running dhcpd-4.2.1-P1 which supports grouping. The problem is 'host' cannot be related with 'subnet' (I tried... Evgeny Yurchenko
09:19 PM Bug #1437: More validation needed on CSR generation
I will test this on or right after July 4th. I will not have internet access between tomorrow and then (working at a ... Yehuda Katz
08:30 PM Bug #1437: More validation needed on CSR generation
Errors handling added:
https://github.com/bsdperimeter/pfsense/commit/95c8cf48f9bd72da5371aa01a03a070885411dbf
http...
Evgeny Yurchenko
08:12 PM Revision 034e4e83: Merge remote branch 'upstream/master'
Jim Pingle
06:08 PM Revision ca4acbcd: After an interface mismatch and apply actually show when we are rebooting instead of the same message that the interface mismatch exists when really the system is rebooting.
Scott Ullrich
05:37 PM Bug #1611: DHCP leases show as expired when they shouldn't be
Chris, here is the dhcp.leases:
# more /var/dhcpd/var/db/dhcpd.leases
# The format of this file is documented in ...
Dainel Spisak
10:58 AM Bug #1611: DHCP leases show as expired when they shouldn't be
Can't replicate.
I configured 3 VLAN on my LAN beside my untagged LAN. Every thing on em1
em1:192.168.10.0/24
...
rancor rancor
03:34 PM Revision d2a08a06: Add small comment about rrd binaries
Scott Ullrich
03:14 PM Revision cb6630e5: Loosen grep for rrd
Scott Ullrich
03:11 PM Revision efea7969: Backup rrdtool binaries during package reinstallation. Currently that is the onlyp package that can be clobbered by others. We will rework this completely in a future version when we adopt PBIs.
Scott Ullrich
02:34 PM pfSense Packages Bug #1616: Dell R210 incompatibility
How long did you let the system install at 38%? This is the longest step in the installer and it does not give a lo... Scott Ullrich
02:33 PM pfSense Packages Bug #1616 (Rejected): Dell R210 incompatibility
we don't track hardware-specific issues as there isn't anything we can do about them. Chris Buechler
05:52 AM pfSense Packages Bug #1616 (Rejected): Dell R210 incompatibility
I bought 2 Dell R210 and with all pfSense versions there's no way to install it!
With pfSense-2.0-RC3-amd64-201106...
Davide B
02:21 PM Bug #259 (Resolved): When disabling a dhcp interface, dhclient is not stopped
Ermal Luçi
02:14 PM Bug #259: When disabling a dhcp interface, dhclient is not stopped
It seems to work now.
Before I disable vlan203 the dhclient is running
$ ps ax | grep dhclient
8629 ?? Is ...
rancor rancor
02:09 PM Bug #1341 (Resolved): Removing last host from alias does not truly remove it, host continues to be affected by rules
Ermal Luçi
01:58 PM Bug #1341: Removing last host from alias does not truly remove it, host continues to be affected by rules
It seems to work now
Tested to reproduce with version 2.0 RC3 date 23 june 2011 and as quick as I remove the host ...
rancor rancor
02:06 PM Bug #455: On initial wizard reload button do not put browser on new assigned ip.
What is the needed feedback? I want to test fixes but there does not seems to be neither a fix nor a question
// r...
rancor rancor
01:08 PM Bug #1156 (Closed): Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
Thanks for the update! Scott Ullrich
01:05 PM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
It works for me with 2.0 RC3 - snapshot dated 23 june 2011
I just tested with a fresh install with pfSense-1.2.3-R...
rancor rancor
11:10 AM Bug #875: Uninstalling packages can remove system libraries
I just committed a change that should hopefully preserve rrdtool. Please test the next snapshot run. Scott Ullrich
11:05 AM Bug #875: Uninstalling packages can remove system libraries
Uninstalling the ntop package results in the removal of rrdtool, possibly others as it does have a long list of depen... David Miller
10:54 AM pfSense Packages Bug #1617 (Rejected): Uninstalling ntop package removes rrdtool
Already covered under #875 - add a note on that ticket instead of opening a new ticket. Jim Pingle
10:52 AM pfSense Packages Bug #1617 (Rejected): Uninstalling ntop package removes rrdtool
Subject pretty much sums it up. If you install and then uninstall the ntop package the rrdgraphs will stop working. ... David Miller
08:52 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Checked on 2.0-RC3 (amd64) built on Wed Jun 22 23:09:34 EDT 2011:
Dis-/re-enabling CARP is an issue even with no I...
Andreas Bochem
05:48 AM pfSense Packages Bug #1164: Installing pfSense 2.0 on a Dell PowerEdge R210
I bought 2 Dell R210 and with all pfSense versions there's no way to install it!
With pfSense-2.0-RC3-amd64-201106...
Davide B
02:08 AM Bug #1582: traffic shaper queues bug
queues adnd rules both created manually, no wizard used and it used to work also earlier but just went dead in newer ... Bipin Chandra

06/22/2011

11:25 PM Bug #1582 (Closed): traffic shaper queues bug
config issue not bug, UDP queues as configured (though probably related to general wizard issue covered by another ti... Chris Buechler
09:25 PM Revision e0ed1aa3: The fix of Ticket #1341 broke the FQDN aliases with only one hostname entry, reported-by: http://forum.pfsense.org/index.php/topic,38051.0.html. Fix this regression by properly handling this cases.
Ermal LUÇI
09:00 PM Revision 0e61e3e4: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/filter.inc
etc/inc/util.inc
Jim Pingle
08:29 PM Bug #1377: upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
4GB
I worked around this by physically going to the unit and reload the card with a 4G 2-RC1 image.
Bill McIlhargey
12:52 PM Bug #1377: upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
Is this specific to the 4GB size? I just did a manual update of a 1GB system and it had no problems upgrading that I ... Jim Pingle
07:06 PM Bug #1613: OpenVPN LDAP authentication should not modify mail attribute as login.
I've just realised my example is not a good one - in the company that I work for, our email addresses are in the form... Deon George
08:28 AM Bug #1613: OpenVPN LDAP authentication should not modify mail attribute as login.
The HTML (or something) has parsed my "description" and removed the "at" character. So all references to '' (double q... Deon George
08:25 AM Bug #1613 (Resolved): OpenVPN LDAP authentication should not modify mail attribute as login.
I have setup an LDAP user directory, using mail as the unique search key (to find users). In the organisation I work ... Deon George
06:52 PM Revision ff629977: Properly generate a subnet based on the range of IPs for PPTP clients. Bonus: fix off-by-one math error in the NAT code that does the same thing. Fixes #1614
Jim Pingle
05:19 PM Revision 91c31339: Revert "Correct displaying any availble default value."
This reverts commit 01c170c4612a4afdbaa2d6e9bf98552dddc1cde3. Warren Baker
02:55 PM Bug #1614 (Feedback): "pptp clients" macro for firewall rules does not work
Applied in changeset commit:ff629977e3d45c1d41fc12449e647abd8b780241. Jim Pingle
02:28 PM Bug #1614 (Resolved): "pptp clients" macro for firewall rules does not work
Using the "pptp clients" entry in the drop-down list for firewall rules does not work. It does not match/pass traffic... Jim Pingle
02:39 PM Revision 68d1632c: New line missing after pkg is extracted.
Warren Baker
02:31 PM Bug #1615 (Resolved): rrd graph not refreshing the correct time frame
The javascript is correctly triggering to refresh the rrd graphs, but the start and end time passed to the graphing s... Seth Mos
12:52 PM Bug #1554: Voucher page turns grey after parameter change
Oops, still on RC1. I don't know RC3 is out. When I log on, I can see:
***
2.0-RC1 (i386)
built on Sat Feb 26 1...
Pavel Pilat
12:34 PM Bug #1554: Voucher page turns grey after parameter change
It happened again today with what version? As Chris said you should be running 2.0-RC3. Scott Ullrich
12:29 PM Bug #1554: Voucher page turns grey after parameter change
make sure you're on RC3, a number of voucher-related things have been fixed since RC1. Chris Buechler
11:14 AM Bug #1554: Voucher page turns grey after parameter change
... and again! After I restored the voucher functionality using previous config file, we managed to set up only one v... Pavel Pilat
08:48 AM Bug #1554: Voucher page turns grey after parameter change
Today it happened again - I had to restore older config. It is OK after restart. Pavel Pilat
05:02 AM Bug #1612 (Closed): Custom scripts in /usr/local/etc/rc.d get deleted
nevermind, I apparently can't see straight this morning, the file is still there... it shifted positions in ls becau... Chris Buechler
03:57 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
I investigated this and i cannot see in any place in pfSense base code something like that being done apart
the sect...
Ermal Luçi
03:15 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
Yeah I thought it was, but it happens on the newest snapshot. Chris Buechler
03:11 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
You are sure to be on latest version.
I recall this happened during package improvements and i fixed this regression...
Ermal Luçi
12:39 AM Bug #1612 (Closed): Custom scripts in /usr/local/etc/rc.d get deleted
The package reinstall process (it appears) deletes unknown startup scripts in /usr/local/etc/rc.d/ which is commonly ... Chris Buechler
04:58 AM Bug #944 (Resolved): Moving VLANs to lagg doesn't remove old VLANs
thanks Chris Buechler
04:19 AM Bug #944: Moving VLANs to lagg doesn't remove old VLANs
confirm fixed in 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011 Andreas Bochem
04:57 AM Bug #1602 (Resolved): diag_arp.php hangs when DNS server unreachable
Chris Buechler
04:49 AM Bug #1602: diag_arp.php hangs when DNS server unreachable
Looks good on 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011.
My current test system does not have a workin...
Andreas Bochem

06/21/2011

07:13 PM Revision adc4bdcc: Set extension name correctly.. Duh!
Scott Ullrich
07:04 PM Revision 14033103: Fix copy and pasto
Scott Ullrich
06:55 PM Revision 9c881f26: Add extension directory
Scott Ullrich
06:05 PM Revision 5bbd08e1: More whitespace fixes.
Warren Baker
05:44 PM Revision 1015b3a9: If no event_address in globals.inc specified assume the default. Also fixed whitespaces.
Warren Baker
04:08 PM Revision 490615d3: Add custom boot early hook
Scott Ullrich
04:08 PM Revision f81cbdad: Use correct directory
Scott Ullrich
03:09 PM Bug #636: layer7 not work correctly
Hrm i see.
Thank you for the info.
Actually you cannot use the root queue in there and i will try to fix the interf...
Ermal Luçi
06:18 AM Bug #636: layer7 not work correctly
Pretty basic, as you can see. And the system logs still display:
Jun 20 23:49:07 ipfw-classifyd: Loaded Protocol:...
Jonathan Puddle
06:17 AM Bug #636: layer7 not work correctly
<l7shaper>
<container>
<name>test</name>
<enabled>on</enabled>
<description/>
<divert_port>41744<...
Jonathan Puddle
12:27 PM Revision 160d5497: Merge remote branch 'upstream/master'
Jim Pingle
12:26 PM Revision a6c85b8b: More icons missing from certain themes...
Jim Pingle
12:12 PM Revision c7bb0eed: Merge remote branch 'upstream/master'
Conflicts:
etc/version
Jim Pingle
08:25 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Hafiz Rafiyev wrote:
> Jim same problem is continued ,i have to restart racoon service after pptp client disconnect,...
Hafiz Rafiyev
06:58 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim same problem is continued ,i have to restart racoon service after pptp client disconnect,here is log.
Jun 21 1...
Hafiz Rafiyev
05:46 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Harry Gonzalez wrote:
> Luca Sari wrote:
> > I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:...
Luca Sari
08:02 AM Revision f27526cd: Do not store CA and CERT in config unless needed. Will allow deleting unused certs.
Evgeny Yurchenko
07:08 AM Revision 7cca77de: Kill olsrd if it is not enabled. Reported-by: http://forum.pfsense.org/index.php/topic,37931.0.html
Ermal LUÇI
03:16 AM Bug #1601 (Resolved): Authentication page loop
Confirmed on the forums. Ermal Luçi
03:14 AM Bug #1602 (Feedback): diag_arp.php hangs when DNS server unreachable
Ermal Luçi

06/20/2011

11:55 PM Revision 5b9afe1e: mkdir zend modules
Scott Ullrich
10:53 PM Revision 8ef700da: Add 'dynamodules' for zend_extension and zend_extension_ts. /etc/php_dynamodules_zend and /etc/php_dynamodules_zend_ts directories
Scott Ullrich
10:29 PM Revision c76ce920: Remove ioncube
Scott Ullrich
08:06 PM Revision 90ecc0b6: Disable state killing in VPN down scripts.
Jim Pingle
06:57 PM Revision c880d032: Fix ovpn-linkup so it writes out the proper gateway IP in all cases.
(For some reason -n wasn't working properly, plus $5 is the right parameter for the remote IP here) Jim Pingle
06:24 PM Bug #1611 (Feedback): DHCP leases show as expired when they shouldn't be
what does your /var/dhcpd/var/db/dhcpd.leases look like? Chris Buechler
06:15 PM Bug #1611 (Closed): DHCP leases show as expired when they shouldn't be
Running on 2.0-RC3 (i386) built on Sun Jun 19 21:45:34 EDT 2011, I have a system with multiple VLAN's on the LAN side... Dainel Spisak
05:19 PM Bug #1545: Dynamic DNS updates fail on 3G connections
You need to update since this is a bug fixed in latest snapshots of check_reload_Status. Ermal Luçi
04:05 PM Bug #1421 (Feedback): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim Pingle
04:05 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Try it with commit:90ecc0b62f8b363d9497b4754133738edb9bc633 Jim Pingle
03:59 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Chris Buechler wrote:
> We can't replicate this, I can connect and disconnect PPTP all day long and IPsec never drop...
Harry Gonzalez
03:51 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Harry it's so simple to replicate the bug.
Steps to replicate bug.
1)Make ipsec VPN tunnel between 2 PF 2.0RC2,...
Hafiz Rafiyev
10:33 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Luca Sari wrote:
> I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:42 EDT 2011 running under v...
Harry Gonzalez
02:40 PM Revision 06bfdd53: Add missing theme images.
Jim Pingle
11:50 AM Revision f0b17f3f: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
06:24 AM Bug #1607: MBUF usage grows geometrically
The RRD graphs mostly didn't survive the config restore, so the screenshot is the best I can do. I had firewall set t... David Burgess

06/19/2011

11:52 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:42 EDT 2011 running under vmWare.
the problem ...
Luca Sari
11:40 PM Revision 3745f21e: bump to RC3
Chris Buechler
07:08 PM Revision 857da904: Do not check dynamic and special interfaces for a complete interface mismatch error
Scott Ullrich
07:01 PM Revision 53bbbf04: Do not create blank domain lines if domain is gone from config.xml. It breaks tools such as dig when troubleshooting, etc.
Scott Ullrich
07:01 PM Revision a53992b7: Simplify message that wraps off screen
Scott Ullrich
04:39 PM Revision ffdcbeb6: Also ignore lines starting with server-duid, and fix the # ignore so it is anchored on the start of the line. Add a note to fix a loop later that can fall into infinity.
Jim Pingle
02:58 PM Revision 248501cd: Merge remote-tracking branch 'upstream/master'
Jim Pingle
11:39 AM Bug #1607: MBUF usage grows geometrically
Of those I would probably be most inclined to point a finger an mlppp since it's the least common used feature among ... Jim Pingle
12:45 AM Bug #1607: MBUF usage grows geometrically
Summary:
7 lines mlppp
2 em NICs
14 or so vlans on both NICS, total
openvpn client
no packages currently insta...
David Burgess

06/18/2011

06:12 PM Bug #1606 (Closed): Wizard does not add wangw
Chris Buechler
06:09 PM Bug #1606: Wizard does not add wangw
I checked, apparently it was not from a recent build, but it was recently downloaded from one of the mirror sites.(so... Bobby Weiter
05:49 PM Bug #1610 (Resolved): v6 IPsec tunnels can trap 12 the kernel
Configuring a IPsec tunnel with v6 endpoints and a v6 tunnel network is no issue in the ui. It all works as expected.... Seth Mos
05:29 PM Bug #1583: IPv6 IPs with :: trigger DNS rebinding
I currently can not replicate this on my local install but it has not been synced for a few weeks. Also, this install... Seth Mos
04:02 PM pfSense Packages Bug #1609 (Resolved): unable to install Avahi
Hi,
I'm unable to install Avahi on the 2.0rc1
Here the errorlog:
Beginning package installation for Avahi...
...
Anonymous
11:42 AM Bug #1607 (Feedback): MBUF usage grows geometrically
And it's still happening on that snapshot? (It's from yesterday, hasn't been 24hrs yet). The em driver was changed ou... Jim Pingle
04:10 AM Bug #1607: MBUF usage grows geometrically
Found my first mention of it in the forums:
http://forum.pfsense.org/index.php?topic=28169.0
Arch should includ...
David Burgess
04:06 AM Bug #1607 (Resolved): MBUF usage grows geometrically
MBUF usage reported in the dashboard grows by roughly 800 per day. When the max value hits the value of nmbclusters p... David Burgess
06:46 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Unfortunately still no go. Ppp log shows updated IP. No logs generated by phpDynDNS at all.
Jun 18 16:09:56 janus ...
Ross Williamson
04:53 AM Bug #1608 (Resolved): manual update on nanobsd and alix fails always
more info here
http://forum.pfsense.org/index.php/topic,37401.0.html
Bipin Chandra

06/17/2011

11:40 PM Revision 2dfaa85f: Cleanup and drop verbosity
Scott Ullrich
10:32 PM Revision ad893298: Add new config option cpdupPathsPrefix
Scott Ullrich
10:25 PM Revision dbd3b18c: Turn down verbosity
Scott Ullrich
09:38 PM Bug #1602: diag_arp.php hangs when DNS server unreachable
Please take a look at https://github.com/bsdperimeter/pfsense/commit/dd4bded7de6d6654afe2cf203df3136c1bef9515
Seems ...
Evgeny Yurchenko
06:14 PM Revision 5d2e5116: Fix formatting of fastcgi params in lighty config.
Jim Pingle
05:53 PM Revision c41602e1: Add a GUI field to adjust the max number of processes for lighttpd.
Jim Pingle
03:27 PM Revision dd4bded7: Bug #1602. diag_arp.php hangs when DNS server unreachable.
Evgeny Yurchenko
09:34 AM Bug #1606 (Feedback): Wizard does not add wangw
Was this on RC1 or a current snapshot? I fixed that shortly after RC1 went out.
commit:e121bebdceb095d5b905dc184c1...
Jim Pingle
09:30 AM Bug #1606 (Closed): Wizard does not add wangw
The wizard did not create a wan gateway, even though it was entered. I had to manually add this after going through t... Bobby Weiter
09:04 AM Bug #1605: DHCP Server should group known clients by interface
That is not "vlan hopping" by any stretch of the imagination. If they are attached to a port on that VLAN and get an ... Jim Pingle
07:11 AM Bug #1605 (Resolved): DHCP Server should group known clients by interface
This is an old issue initially reported by LJ Rand in 2006 on another forum. No one has answered since those days. Bu... Willy Tenner
04:57 AM Revision 24cbe7a8: Bug #1437. Dropdown list for country codes for CSRs (Cert Manager)
Evgeny Yurchenko
04:41 AM Revision 21cc2faa: Bug #1437. Check for invalid characters in the fields for ca, cert and csr.
Evgeny Yurchenko
03:04 AM Revision 9d2d65f3: Bug #1437. Dropdown list for country codes (CA manager)
Evgeny Yurchenko
01:02 AM Bug #1437: More validation needed on CSR generation
Adding countries now is just adding lines to the file /etc/ca_countries and could be easily done when needed.
Regard...
Evgeny Yurchenko

06/16/2011

08:26 PM Revision 2de8d745: Do a more thorough check for platform on the ro call, or factory reset blows up.
Jim Pingle
01:45 PM pfSense Packages Todo #1604 (Closed): Add Git to destination port range
git can use HTTP, HTTPS, SSH, and/or 9418 and 9418 is one of the lesser common of those, so that would be confusing t... Chris Buechler
01:34 PM pfSense Packages Todo #1604 (Closed): Add Git to destination port range
When adding a new firewall rule, the drop down for destination port range includes a list of commonly used ports.
...
Forest Mars

06/15/2011

11:45 PM Feature #1603 (Resolved): URL table aliases should be usable within network type aliases
It would be nice to be able to specify multiple URL table aliases within one network type alias. For instance I just ... Chris Buechler
07:31 PM Revision 3df8786b: Merge remote branch 'upstream/master'
Jim Pingle
07:30 PM Revision 62905808: Faster/more efficient xmlrpc sync for users/groups. Seems to work fine for me. Coded-By: Ermal
Jim Pingle
06:38 PM Bug #1602: diag_arp.php hangs when DNS server unreachable
Testing for a known host and skipping if that fails could work, as long as it only triggered on timeout and not a neg... Jim Pingle
06:28 PM Bug #1602: diag_arp.php hangs when DNS server unreachable
yeah I'm sure this isn't the only affected page. Not sure of the best solution. If before doing a reverse lookup on e... Chris Buechler
06:25 PM Bug #1602: diag_arp.php hangs when DNS server unreachable
what would be solution here? it's just hanging gethostbyaddr()
Many things slow when dns is unreachable -(
Evgeny Yurchenko
05:51 PM Bug #1602 (Resolved): diag_arp.php hangs when DNS server unreachable
diag_arp.php hangs for a long time (several minutes at least) when no DNS server is reachable, trying to do reverse l... Chris Buechler
04:57 PM Revision 1540194f: PHP says that arrays cannot be used as keys, protect against this case as reported that some keys are arrays!
Ermal LUÇI
04:15 PM Revision d56f17d1: Merge remote branch 'upstream/master'
Jim Pingle
03:19 PM Bug #1601 (Feedback): Authentication page loop
This should by fixed my Ermal's commit this morning.
https://github.com/bsdperimeter/pfsense/commit/f45075dd98eefbad...
Jim Pingle
03:17 PM Bug #1601 (Resolved): Authentication page loop
After I updated pfSense 2.0 RC1 to the lastest build on 13th of June the captive portal showed a bug.
First I notice...
Richard van Naam
02:22 PM Revision f45075dd: Restore this back to allow both users and vouchers enabled at same time.
Ermal LUÇI
02:05 PM Revision 8f5d92a9: Add carp.xml to obsolete file list.
Ermal LUÇI
02:04 PM Revision 12a0cd74: Remove obsolete file lurking on installs.
Ermal LUÇI
01:43 PM Revision 5aa7a46c: Ticket #1598. Correctly handle ipalias vips when re-enabling carp from the carp_status screen.
Ermal LUÇI
12:47 PM Feature #1422: short voucher codes
This are my exact thoughts too. The 11 chars are too long for user friendly input.
Richard van Naam
11:49 AM Bug #1437: More validation needed on CSR generation
1. There are other possible errors in csr generation besides invalid input. I am also suggesting that this wrappr can... Yehuda Katz
11:46 AM Bug #1437: More validation needed on CSR generation
Another thing we need to filter for is invalid characters in the fields for the certificate. A quick search turned up... Jim Pingle
11:39 AM Bug #1437: More validation needed on CSR generation
I see two different questions here:
1. User input validation. Country name validation? whatever approach we use (dro...
Evgeny Yurchenko
10:45 AM Bug #1437: More validation needed on CSR generation
I don't think that is the proper solution to the problem. Hard-coding a country code list only works until the count... Yehuda Katz
10:08 AM Bug #1437: More validation needed on CSR generation
Possible solution a listbox with values The solution for this probably is a listbox with values from http://www.digic... Ermal Luçi
09:45 AM Bug #1508 (Resolved): Wan Fai lback
Ermal Luçi
09:42 AM Bug #1598 (Feedback): IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Ermal Luçi

06/14/2011

08:41 PM Revision e49d4564: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/globals.inc
etc/inc/upgrade_config.inc
Jim Pingle
08:36 PM Revision 144fbff2: Show the OpenVPN instance description when listing interfaces to assign in the gui.
Jim Pingle
03:51 PM Bug #1598 (New): IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Just tried on a current snapshot, and your carp patch did fix the CARP VIP changing itself to master (so that's great... Jim Pingle
08:50 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Applied in changeset commit:b526daafae3405b27fa7219d90a81272d0979f57. Ermal Luçi
07:35 AM Bug #1598 (Feedback): IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Applied in changeset commit:2708a5cf1648c6d776588e0e4b9be1b6aad65994. Ermal Luçi
02:10 PM Revision c333d609: Use the new username field from the GUI or default to admin.
Ermal LUÇI
02:10 PM Revision 6a06d896: Up config number for username sync upgrade.
Ermal LUÇI
02:10 PM Revision 34fb609c: Up config number for username sync upgrade.
Ermal LUÇI
02:10 PM Revision e6ee8fc6: Upgrade sync username to latest config version.
Ermal LUÇI
01:43 PM Revision 88adfa28: Allow Accounting Updates to become configurable when Accounting is selected.
Warren Baker
01:40 PM Revision fddb3cd6: Allow people to enter another user than admin for syncrhonizing in the carp settings page.
Ermal LUÇI
01:39 PM Revision 01c170c4: Correct displaying any availble default value.
Ermal LUÇI
01:16 PM Revision 1127df5f: Correct check for ipaliases over carp so we do not allow the deletion.
Ermal LUÇI
01:00 PM Revision fb5830ef: Actually correct check so it throws some errors during the second try.
Ermal LUÇI
12:50 PM Revision b526daaf: Correct functiong does_vip_exist() to actually work. Fixes #1598
Ermal LUÇI
11:44 AM Revision 31d5d37e: Ooops fix the function. Spotted-by: wagnosa(IRC)
Ermal LUÇI
11:36 AM Revision 2708a5cf: NEw functiong does_vip_exist() which works for carp and ipalias type vips to help in carp sync issues. Fixes #1598
Ermal LUÇI
09:57 AM Revision 7905df98: Porvide information for the filter reload status screen.
Ermal LUÇI
09:54 AM Bug #1600 (Feedback): Captive Portal Reauthentication
Applied in changeset commit:88adfa28a848be5949015980aea0a367bc5ef61e
The moving of the section has not been done, ...
Warren Baker
09:32 AM Bug #1600 (Resolved): Captive Portal Reauthentication
When the Captive Portal is configured to use RADIUS and Accounting Updates are selected. One needs to select 'Reauthe... Warren Baker
07:36 AM Bug #1586 (Resolved): vouchers saved to XML config every 5 minutes even though no new vouchers have been activated
This is fixed and confirmed from forums. Ermal Luçi
02:17 AM Bug #1545: Dynamic DNS updates fail on 3G connections
OK latest snapshot (Mon EDT) installed.
DynDNS now updates on boot again, so that part is working. Now to see if t...
Ross Williamson
02:00 AM Bug #1545: Dynamic DNS updates fail on 3G connections
yeah pretty sure that wasn't fixed until Saturday's snapshots Chris Buechler
01:57 AM Bug #1545: Dynamic DNS updates fail on 3G connections
built on Fri Jun 10 20:04:53 EDT 2011
I'll upgrade now.
Will need to wait for another IP change :(
Ross Williamson
01:56 AM Bug #1545: Dynamic DNS updates fail on 3G connections
what's the date on that snapshot? If it's from last week you could be hitting the problem with check_reload_status no... Chris Buechler
01:54 AM Bug #1545: Dynamic DNS updates fail on 3G connections
OK the IP just changed again. However, this time, there are no dynDNS logs at all. ppp.log shows the new IP:
Jun 14 ...
Ross Williamson

06/13/2011

08:41 PM Feature #1599 (Duplicate): Browser detection for captive portal
I am using pfSense on a old computer with 4 network cards in a small hotel. It has two incoming lines that have now b... Svein Wisnaes
06:16 PM Revision 63f81fbd: Do not assume that every merge is about vips. Found-by: Jim
Ermal LUÇI
03:04 PM Revision 19ed1624: unset after checking that no reconfiguring is needed.
Ermal LUÇI
02:32 PM Bug #1598 (Resolved): IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Found while looking at #1534 but is really a separate issue, so I'm splitting it off into a new ticket.
Prerequisi...
Jim Pingle
01:51 PM Feature #1597 (Closed): FTP-Data
ftp-data is the source port on data transmissions, and too many people think it's a required destination port. That w... Chris Buechler
01:47 PM Feature #1597 (Closed): FTP-Data
It would be nice if you could add FTP-Data as a protocol in the firewall rule and nat rule drop down for source and d... Michael Miller
12:34 PM Revision b09c2d86: Do not call time() uselessly every time for each entry. Instead just snapshot it and use it in calculations. This helps performance and useless paranoic time fetching since every 60 seconds the code will be executed again.
Ermal LUÇI
12:22 PM Revision 48de5a10: Do not test for availbility of voucher session_timeout in the database it is mandatory for vouchers. This will make sure that if ever a corrupted db happens a user will be required to relogin and correct the db. Possibly related to: http://forum.pfsense.org/index.php/topic,37636.0.html
Ermal LUÇI
09:07 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
I do not know the state of the IPv6 code but can you try with latest snapshot of pfSense since there were some binary... Ermal Luçi
08:53 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
I've upgraded to 2.0-RC2-IPv6 (amd64) built on Sat Jun 11 23:14:29 EDT 2011. Had severe problems with this update. Af... Marcin Krol
02:30 AM pfSense Packages Bug #1561: HTTP traffic dies after disabling HAVP
Just a note. Even rebooting router with HAVP disabled doesn't bring HTTP traffic back. Only re-enabling HAVP helps. S... Marcin Krol
01:45 AM pfSense Packages Bug #1596 (Closed): Snort And PfseError
duplicate of #1590
Chris Buechler

06/12/2011

02:10 PM Revision f8c462dd: Allow packages to specify that their tabmenus should not be a drop-down list by using a <no_drop_down/> tag.
Warren Baker
06:26 AM Bug #1327 (Resolved): RFC 2136 dynamic dns bug
Ermal Luçi
06:24 AM Bug #1586 (Feedback): vouchers saved to XML config every 5 minutes even though no new vouchers have been activated
Ermal Luçi
12:51 AM Revision 424be584: Allow someone to add a host DNS override twice, so long as the IP type isn't the same. Lets you add a host override for both IPv4 and IPv6 for the same hostname.
Jim Pingle
12:49 AM Revision 06da79f9: Merge remote-tracking branch 'upstream/master'
Jim Pingle

06/11/2011

05:41 PM pfSense Packages Bug #1596 (Closed): Snort And PfseError
my english is very very bad
BUT in Pfsense 2.0-RC2 (i386)
built on Fri Jun 10 21:02:50 EDT 2011
Snort afer...
Joaquim Soares Soares
03:20 PM Feature #1594: numbers in "Interface Group" names
That is a limitation of the OS, not just the GUI. I know they cannot end in a number, and for simplicity's sake it's ... Jim Pingle
03:07 PM Feature #1594 (Closed): numbers in "Interface Group" names
I created an interface group, and it would only let me use alpha characters in the name, it would be nice to use numb... J Hyde
05:15 AM pfSense Packages Bug #1590: Snort Will Not Start
In the latest release of pfsense 2.0-RC2 I can't get Snort to start.
While my console output is the same as listed ...
Andrew Mitchell

06/10/2011

08:02 PM Revision 5ebe85e9: Fixes #1327. Trigger synching of vouchers to config through check_reload_status. Retire the saveinterval option since it is not useful anymore. Use the prune process of captiveportal to sync vouchers as well to fix issues as reported-by: http://forum.pfsense.org/index.php/topic,37636.0.html
Ermal LUÇI
07:20 PM Revision b9eccc77: Fixes #1327. Put description that a full qualified hostname is required.
Ermal LUÇI
04:37 PM Revision de408516: Merge remote branch 'upstream/master'
Jim Pingle
04:36 PM Bug #1399: rrdtool respawning too fast
at a minimum should get rid of the log message at some point Chris Buechler
03:10 PM Bug #1399: rrdtool respawning too fast
This seems to be an assumption made from apinger that after an error occured you cannot respawn rrdtool faster than 3... Ermal Luçi
04:19 PM Revision dd28abbd: Ticket #1545. Ooops pass parameter so the dyndns works correctly. Pointy-hat: Copy/pasto
Ermal LUÇI
04:05 PM Bug #1327: RFC 2136 dynamic dns bug
Applied in changeset commit:5ebe85e9344abfe52f3dced34c8e4515b8a8d293. Ermal Luçi
03:20 PM Bug #1327 (Feedback): RFC 2136 dynamic dns bug
Applied in changeset commit:b9eccc77815a3e9d4913fcad8f7c474291e9f67a. Ermal Luçi
02:18 PM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
That is a known issue. Fixed in the next snapshot (building now) try again with that. Jim Pingle
02:16 PM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
After upgrade I'm now on 2.0-RC2-IPv6 (amd64) built on Fri Jun 10 01:43:14 EDT 2011 and its even more broken. Whateve... Marcin Krol
12:18 PM Bug #1591 (Resolved): Sync issues on June 8 Snapshot
closefrom(0) patch added some days before imapcted this. Ermal Luçi
12:31 AM Bug #1591: Sync issues on June 8 Snapshot
2.0-RC2 (i386) built on Thu Jun 9 19:52:30 EDT 2011
When you switch between HTTP and HTTPS in System: Advanced: Admi...
Evgeny Yurchenko
12:17 PM Bug #1545: Dynamic DNS updates fail on 3G connections
My fault fixed it. Ermal Luçi

06/09/2011

05:08 PM Bug #1593 (Rejected): SSH login halts for a long time then disconnects
not a legit bug report, please post to the forum or mailing list Chris Buechler
03:53 PM Bug #1593 (Rejected): SSH login halts for a long time then disconnects
Whenever I try to ssh my pfsense router I wait a long time then the router disconnects me.
Running recent upgrade ...
David Bender
10:12 AM Bug #1591 (Resolved): Sync issues on June 8 Snapshot
Since the changes to check_reload_status yesterday, a primary is not syncing its config to a secondary. It's acting a... Jim Pingle

06/08/2011

09:33 PM Revision 7401c8c4: Allow OpenNTPD to listen on Virtual IPs, not just interfaces. Fixes #342
Jim Pingle
09:13 PM pfSense Packages Bug #1590 (Resolved): Snort Will Not Start
Hello all-
I just upgraded my pfsense firewall (from a snap on Tuesday May 31 to a snap today 2.0-RC2 (amd64) buil...
Mike Binkowski
07:53 PM Revision c7422829: Fixes #1341. If a table has not entries it is marked as persist and pf(4) does not clear its contents. Schedule a table flush for these tables after filter reload to make sure an entry is not forgotten.
Ermal LUÇI
06:47 PM Bug #1545: Dynamic DNS updates fail on 3G connections
Thanks, but not working. It is now not even updating on boot. The only way I can get it to update is to manually remo... Ross Williamson
06:22 PM Revision 92ca32cc: Actually make this code more readble.
Ermal LUÇI
06:21 PM Revision d1e03822: Remove the entry from old entries even when there are no changes to prevent marking them down.
Ermal LUÇI
06:16 PM Revision 3c3cd07e: Merge remote branch 'upstream/master'
Jim Pingle
06:15 PM Revision 578f20ec: Actually correct vip check to be correct for all vip types.
Ermal LUÇI
06:13 PM Revision 156bf9b1: Merge remote branch 'upstream/master'
Jim Pingle
05:35 PM Bug #342 (Feedback): OpenNTPD can only listen on interface IP
Applied in changeset commit:7401c8c451e33a5f5fd38e934760e1b855fee822. Jim Pingle
04:47 PM Bug #1514 (Resolved): Limiters not syncing
Since no complain received i am marking this as solved. Ermal Luçi
04:46 PM Bug #1394 (Resolved): MTU does not reset
The same issue exists for the mac address.
Possibly a fix for mac addresses should be done on 2.1
Ermal Luçi
04:44 PM Bug #1410: pfSense remains without default route
I am moving this to 2.1 for improving.
For 2.0 the option under system->advanced should be enough.
Ermal Luçi
04:41 PM Bug #1403 (Closed): Filter Rules description do not get saved when "(quote) present as character
It happened to me in a VM.
Not really sure on the circumstances, though if i can reproduce again i will check more t...
Ermal Luçi
03:55 PM Bug #1341 (Feedback): Removing last host from alias does not truly remove it, host continues to be affected by rules
Applied in changeset commit:c7422829b2a76301d2efbe0aa01e3dcfcce3012f. Ermal Luçi
03:53 PM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
Latest snapshot has more fixes in this regard. Ermal Luçi
03:18 PM Bug #1552: DNS Reject Rule Crashes Router
Evgeny you need fragments to trigger this panic. Ermal Luçi
02:54 PM Revision 0042f5d9: Send correct event for reloading packages.
Ermal LUÇI
02:49 PM Bug #1588: HAVP dashboard widget broken by June 7 build
Yes, it reinstalls all packages on every update. Jim Pingle
02:49 PM Bug #1588: HAVP dashboard widget broken by June 7 build
Indeded, removing and re-installing the package fixed that. Does pfSense remove and re-install all packages every tim... Bryan Agee
01:12 PM Bug #1588 (Rejected): HAVP dashboard widget broken by June 7 build
Looks like that file doesn't exist, which means you need to reinstall the package. Some other package may have failed... Jim Pingle
01:09 PM Bug #1588 (Rejected): HAVP dashboard widget broken by June 7 build
I have a box running 2.0 RC1 with the havp package installed. After upgrading to the June 7 build, the service appear... Bryan Agee
01:20 PM Bug #1589 (Rejected): pfsense crashes all the time with rt3070 wlan
Driver issue, we probably can't do anything for that. Try to reproduce it on a plain FreeBSD install and report it to... Jim Pingle
01:19 PM Bug #1589 (Rejected): pfsense crashes all the time with rt3070 wlan
Hello.
With rt3070 wlan card, pfsense is crashing all the time with the error that you can find a screenshot here ...
serge laurent
10:35 AM pfSense Packages Bug #1587 (Resolved): The openvpn client configuration exporter doesn't enforce TLS subject verification
Hi,
The openvpn client configuration exporter doesn't enforce TLS subject verification. This leads to a security v...
Florent Daigniere
07:44 AM Revision 6a7dd9bb: Do not destroy and create the vip during interface [re]configuration since it causes unecessary work and most importantly issues.
Ermal LUÇI
07:29 AM Revision 7fc6c005: Generate proper index for unsetting so we do not destroy all the vips in the backup.
Ermal LUÇI

06/07/2011

05:25 PM Revision 2c85b316: Disconnect any voucher forced to expire if there are active sessions with it.
Ermal LUÇI
05:15 PM Revision e64c894f: Allow a second optional argument to captiveportal_read_db to be able to index the read db by the field in the db.
Ermal LUÇI
05:06 PM Revision f989aa5b: Correct variable name so voucher disconnect on synchronized vouchers works properly.
Ermal LUÇI
04:52 PM Revision d06f9f45: Adding ioncube
Scott Ullrich
03:09 PM Revision 720e2e60: Nuke trailing newline
Scott Ullrich
01:47 PM Revision d8012adb: Merge remote-tracking branch 'mainline/master' into inc
Conflicts:
etc/inc/voucher.inc
usr/local/www/fbegin.inc
Vinicius Coque
10:13 AM Bug #1556: Changing local IPsec tunnel endpoint does not work
Still struggling to replicate though tested with OPT1 and OPT2 (can't touch WAN). -(
1. Tunnel works via OPT1.
2. C...
Evgeny Yurchenko
10:07 AM Feature #1571: Interfaces completely reset when hardware is changed
"this is how things have always worked" means that this is a far more serious bug than I first thought, and a fundame... Mr Horizontal
08:08 AM Revision 3f8a13e0: Oops correct the POST destination page.
Ermal LUÇI
05:18 AM Bug #1586 (Resolved): vouchers saved to XML config every 5 minutes even though no new vouchers have been activated
On "Services: Captive portal: Vouchers" page there is an interval for saving vouchers into config with default of 5 m... Pavel Pilat
01:00 AM pfSense Packages Bug #1585 (Closed): pfsense 2.0-RC1 intermittently disconnects PPTP client session
upgrade, that was fixed since then. Chris Buechler
12:25 AM pfSense Packages Bug #1585 (Closed): pfsense 2.0-RC1 intermittently disconnects PPTP client session
Hello,
I am testing pfsense 2.0 in a VMware virtual machine. My setup is:
Laptop (Ubuntu 10.04) pptp client
pl...
Jawaid Bazyar
12:44 AM Revision 60ccf01c: Add a div around input errors box so that it can be hidden on subequent page posting
Scott Ullrich

06/06/2011

09:09 PM Revision c88ff708: Include ssh2 module if available
Scott Ullrich
06:12 PM Revision 4e192846: Correct event calling during bootup for rc.newipsecdns and also convert the command executed during an ipsec even to go through check_reload_status which will prevent races on calling rc.newipsecdns. Which might lead to many filterdns processes.
Ermal LUÇI
05:57 PM Revision f6bf0661: Switch this to check_reload_status event to see if it solves any possible issues of nohup blocking signals to be delivered to filterdns proces.
Ermal LUÇI
04:04 PM Revision 63dfc7ef: Suppress keyboard device errors on bootup
Scott Ullrich
03:48 PM Revision 0b704a40: Correct whitespace.
Ermal LUÇI
02:37 PM Revision a9c489c7: Fix pppoe server user rule generation. Fixes #1577
Jim Pingle
01:12 PM Revision 7d6be855: Correct possible lock leak.
Ermal LUÇI
01:08 PM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
19 VIPs, 20 permanent OpenVPN tunnels, 1 OpenVPN for users, 2 gigabit NICs aggregated into 1 lagg0 interface, 14 VLAN... Marcin Krol
10:05 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
How many interfaces / VIPs do you have on that box? When I apply changes on my VM, I only see 1-2 of those and they i... Jim Pingle
12:40 PM Revision ac07425a: Fix whitespace.
Ermal LUÇI
11:07 AM Bug #1341 (New): Removing last host from alias does not truly remove it, host continues to be affected by rules
This doesn't seem to be fixed. If I clear a table/alias in the GUI, and it's really a table on the backend, the IPs a... Jim Pingle
11:04 AM Revision 43f26ab1: Ticket #1412. Provide even a link to this page through System->User Manager
Ermal LUÇI
10:53 AM Revision e33be77c: Ticket #1412. Fixing the access login to the user manager presented another problem since now users cannot change their passwords anymore. Allow this through another page and an extra priviledge needed to be added to the user for allowing them to change the password.
Ermal LUÇI
10:40 AM Bug #1577 (Feedback): Inserting any rules on VPN PPPoE interface cause filter not reload
Applied in changeset commit:a9c489c7ab68e9c853b37a3f132fbc2c53363bbb. Jim Pingle
10:22 AM Revision 425ba708: Ticket #1545. Take into account curl errors during dyndns service checks otherwise will just mark some updates as successful even though they are not.
Ermal LUÇI
06:53 AM Bug #1556: Changing local IPsec tunnel endpoint does not work
That is correct, racoon will listen on the correct interface, but ignore all communication for that phase 1.
The m...
Seth Mos
06:20 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Just updated the code to take into account some curl errors.
These errors just marked the service as updated but rea...
Ermal Luçi

06/05/2011

08:23 PM Revision 6627e4ec: Restoring gray background to the right of some tables in GUI (theme pfsense_ng).
Evgeny Yurchenko
08:09 PM Revision 79633b6c: Reverting class="sortable" damaged by commit 17d5077f61d963178f47e016b8768b768800ba68
Evgeny Yurchenko
07:17 PM Revision 8527bc02: Merge remote branch 'origin/master'
Evgeny Yurchenko
07:15 PM Revision 17d5077f: Restoring gray background to the right of some tables in GUI.
Evgeny Yurchenko
01:36 PM Feature #1578 (Rejected): Custom DynDNS Providers
Thanks Bill - will do.
Will reject this call, as indicated by Matt, it is a duplicate of #1241.
Warren Baker
01:27 PM Feature #1578: Custom DynDNS Providers
Additionally, this is a duplicate of #1241 sorry for the confusion there. I had just seen that git was moved off of ... Matt Corallo
01:20 PM Feature #1578: Custom DynDNS Providers
Originally posted here, uploaded to github to make it easier for me to keep it up-to-date http://forum.pfsense.org/in... Matt Corallo
01:00 PM Feature #1578: Custom DynDNS Providers
Pull request is at [[https://github.com/bsdperimeter/pfsense/pull/2]] Bill Marquette
12:55 PM Feature #1578: Custom DynDNS Providers
Can you please update the pull request with the items you don't want to pull so the author can modify his changes? A... Bill Marquette
01:27 PM Feature #1241: Custom Dynamic DNS
Github pull at: https://github.com/bsdperimeter/pfsense/pull/2
Sorry for the disturbance.
Matt Corallo
04:32 AM Bug #1583 (Resolved): IPv6 IPs with :: trigger DNS rebinding
When browsing to an IPv6 IP containing :: the DNS rebinding check is triggered as the :: causes part of the IP to be ... Chris Buechler
04:14 AM Bug #1567: pfsense rc1 2.0 DNS
*Update*
for general settings --> dns use gateway
have you tried it lately?
not availible
03:18 AM Revision cf371185: s/WAN//
Chris Buechler
02:58 AM Revision 14c354ee: fix typo, add warning
Chris Buechler
01:56 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Unfortunately this has not helped. Here's some more logs (with -rc2 in the filename) of it happening on the latest ve... Ross Williamson
12:43 AM Revision 81debd44: Show the MAC on the page rather than just a hover, too many times it needs to be copied/pasted or quickly viewed, and the vendor isn't nearly as useful as the actual MAC.
Chris Buechler

06/04/2011

10:13 PM Bug #1312 (Closed): NAT reflection/DNS Forwarder broken again
not seeing any issues here, Brian you can post on the 2.0 board of the forum for help troubleshooting if it's still a... Chris Buechler
10:12 PM Bug #1340 (Resolved): PPTP Rar "Clear Log" button does not work
Chris Buechler
10:10 PM Bug #1524 (Resolved): Dhcrelay not running when DHCP server not in same subnet.
Chris Buechler
10:10 PM Bug #1277 (Resolved): Rip propagation
Chris Buechler
10:09 PM Bug #1444 (Resolved): Reconfiguring interfaces doesn't deconfigure previous ones
Chris Buechler
10:08 PM Bug #1235 (Resolved): pfsense 2.0 load balancing with a https monitor seems to default timeout 200ms causing constant timeouts
Chris Buechler
10:07 PM Bug #1292 (Resolved): PPTP server with Radius breaks on upgrade from 1.2.3 to 2.0
Chris Buechler
10:07 PM Bug #954 (Resolved): Switching to manual outbound NAT creates incorrect rule for PPTP server
Chris Buechler
10:05 PM Bug #1511 (Resolved): panic in pfi_dynaddr_update
this should be worked around now, was triggered by a race condition in CARP deletion which has been worked around and... Chris Buechler
09:55 AM Bug #495: USB drive fails to mount during boot
Sondre Slathia wrote:
> I just came across this issue still present on latest nightly build of embedded 4g pfsense 2...
Jim Pingle
06:35 AM Bug #495: USB drive fails to mount during boot
I just came across this issue still present on latest nightly build of embedded 4g pfsense 2. Is this issue resolved ... Sondre Slathia
01:27 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
harry,same problem i have got on 2.0-RC2 (i386),problem not resolved.I think it's not normal priority case because o... Hafiz Rafiyev

06/03/2011

10:29 PM Revision 5cb0360b: Merge branch 'master' of github.com:bsdperimeter/pfsense
Bill Marquette
10:29 PM Bug #1552: DNS Reject Rule Crashes Router
I have slightly different results.
1. Setup as in the bug description - blocking rule just does not work, DNS reques...
Evgeny Yurchenko
10:29 PM Revision 5b542ae5: Typoes
Bill Marquette
07:34 PM Revision 534375b6: Merge remote branch 'upstream/master'
Conflicts:
etc/inc/openvpn.inc
Jim Pingle
06:53 PM Revision bd4b0982: If a mode_cfg subnet is defined for IPsec, also add it to outbound NAT.
Jim Pingle
02:35 PM Bug #1546: Traffic Shaper fails to handle UDP traffic
I disabled the upnp and tested again, but the same problem still occur, but for me is the upload traffic that goes to... Guilherme Barreto
07:06 AM Bug #1546: Traffic Shaper fails to handle UDP traffic
actually the topic was supposed to be UDP download traffic not going to proper queue, shaping as well as upload traff... Bipin Chandra
02:29 PM Revision c8ff68a4: Allow duplicating an IPsec phase 2. The code was already on vpn_ipsec_phase2.php but unlinked.
Jim Pingle
01:50 PM Revision 5cd9e96a: Add a GUI selection for racoon's generate_policy directive since it may be useful in certain configurations, especially for mobile clients.
Jim Pingle
01:29 PM Revision 039cb920: Add a button here to clear the package lock.
Jim Pingle
01:20 PM Revision 5dc6c910: When making a P2P SSL/TLS OpenVPN server, if the given CIDR for the tunnel network is a /30, don't use the OpenVPN server directive. See ticket #1417
Jim Pingle
01:03 PM Revision 19cdeb3e: Instead of showing an emtpy drop-down for CA/Cert/CRL, show an error that there are none defined, and link to the page to create one.
Jim Pingle
01:03 PM Revision 1591ea6f: Remove the warning message that a user doesn't have any CA/Certs when viewing OpenVPN connections. This is just confusing people, and isn't relevant to people using only shared key tunnels.
Jim Pingle
01:03 PM Revision 2f51259b: Redirect back to the CA/Cert management page after delete so a person can't refresh and accidentally delete other CA/Certs. (CRLs are deleted differently and don't need this fix)
Jim Pingle
12:10 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Still replicated this bug after updating to 2.0-RC2 (amd64) built on Thu Jun 2 10:50:48 EDT 2011.
I had the ipsec ...
Harry Gonzalez
10:30 AM Bug #1560 (Resolved): IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Tested a few different scenarios and this seems to be solved all the way around. Thanks! Jim Pingle
10:25 AM Bug #1577: Inserting any rules on VPN PPPoE interface cause filter not reload
Attached the config xml. Fabiano Heringer
10:16 AM Bug #1577: Inserting any rules on VPN PPPoE interface cause filter not reload
You can download the config from Diagnostics > Backup/Restore. Jim Pingle
10:01 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
I committed the change to check the CIDR and if it's 30+, it will not use the server/client-config-dir directives. Sh... Jim Pingle
09:52 AM Bug #1395 (Resolved): RRD data not collecting accurate information
Thanks for the feedback. I'll mark it as resolved. Jim Pingle
09:44 AM Bug #1395: RRD data not collecting accurate information
I just noticed that this problem appears to be fixed. I'm not sure when this behavior changed but this bug can be cl... David Miller
09:37 AM Bug #1572: DHCP + MAC spoofing leads to link cycling
Do you know the way to reproduce it? I can't see this behavior... Evgeny Yurchenko
07:25 AM Revision 327d958a: fixed for use pfsense API
Luiz Gustavo S. Costa
07:15 AM Revision 8c0199ea: Better management for reload lighttpd
Luiz Gustavo S. Costa
07:15 AM Bug #1582 (Closed): traffic shaper queues bug
bear in mind this is not the same bug as ports opened by upnp not being shaped, to replicate this bug add some rules ... Bipin Chandra
05:36 AM pfSense Packages Bug #1580 (Closed): countryblock doesn't uninstall cleanly
duplicate of #1579 Chris Buechler
04:31 AM pfSense Packages Bug #1580 (Closed): countryblock doesn't uninstall cleanly
The countryblock package doesn't uninstall cleanly and leaves some files behind, causing squid to fail on startup wit... Volker Kuhlmann
04:49 AM pfSense Packages Feature #1581 (Resolved): lightsquid logfile location
2.0RC1, lightsquid 1.8.0 pkg v.1.2
The lightsquid logfile location is hardcoded in
/usr/local/pkg/lightsquid.inc...
Volker Kuhlmann
04:31 AM pfSense Packages Bug #1579 (Resolved): countryblock doesn't uninstall cleanly
The countryblock package doesn't uninstall cleanly and leaves some files behind, causing squid to fail on startup wit... Volker Kuhlmann
03:20 AM Feature #1578 (Rejected): Custom DynDNS Providers
The ability to add a custom DynDNS Provider as per a mail to the support mailing list from 'TheBlueMatt'.
"Add the...
Warren Baker
02:52 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
I've updated yesterday and now I'm running 2.0-RC2-IPv6 (amd64) built on Wed Jun 1 18:03:37 EDT 2011 and last commits... Marcin Krol

06/02/2011

10:03 PM Revision 67dde8b0: Merge remote branch 'origin/master'
Evgeny Yurchenko
06:40 PM Bug #1546 (Closed): Traffic Shaper fails to handle UDP traffic
yeah it is, general UDP shaping works fine. Chris Buechler
06:34 PM Bug #1546: Traffic Shaper fails to handle UDP traffic
I use upnp to open ports for my ps3 games, so is very likely to be the same problem reported here http://redmine.pfse... Guilherme Barreto
06:11 PM Bug #1560: IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Jim P noticed that it is impossible now to edit P2, when you change something else rather than networks definitions i... Evgeny Yurchenko
09:39 AM Bug #1560: IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Corrected https://github.com/bsdperimeter/pfsense/commit/3da5c50d5c2285b439a56ab4fcd6f9dbe94f5c4e
Currently there is...
Evgeny Yurchenko
05:23 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
Just tested
exec("/etc/rc.reboot");
works ok. Probably because /etc/rc.reboot does not contain php code.
Evgeny Yurchenko
08:58 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
For the moment I disabled the package stop on reboot.
Though after sleeping on it, I remembered a similar problem I ...
Jim Pingle
05:07 PM Todo #1573 (Resolved): Test Android Gingerbread IPsec Options
The choices that use main mode (anything that isn't labeled "aggressive") won't work as the IP of the phone is used a... Jim Pingle
04:47 PM Revision f451ea09: Show how much data has passed on an SAD entry.
Jim Pingle
03:43 PM Revision e96bbf82: Patch from EvgenyY to allow editing an existing p2 without it being flagged a duplicate.
Jim Pingle
03:23 PM Revision b717f1bc: Bug #1560.IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1 (fixing p2 edit)
Evgeny Yurchenko
01:07 PM Revision 0640a65b: Add "Default" choice that will unset the media/mediaopt, otherwise whatever is first in the list is saved in the config.
Jim Pingle
12:36 PM Bug #1417: OpenVPN client specific overrides doesnt work by default
Yeah that's a fair point. I'll look into adding a check on the subnet mask side and tossing out the server/csc lines ... Jim Pingle
12:24 PM Bug #1417: OpenVPN client specific overrides doesnt work by default
The last section of http://backreference.org/2009/11/15/openvpn-and-iroute/ explains that there are situations where ... Bill Fenner
11:54 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
Well the remote network only adds a route, typically with SSL/TLS it requires an iroute to assocate that route to a g... Jim Pingle
11:51 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
I suppose I was using p2p+tls because it was the option that was selected when I clicked "add VPN server", not becaus... Bill Fenner
11:23 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
Ah, ok. I was thinking of a shared key and /30.
The main reason most people want to use p2p+tls is to push settin...
Jim Pingle
11:07 AM Bug #1417: OpenVPN client specific overrides doesnt work by default
We used 172.25.0.0/30, and OpenVPN gripes as follows:
Jun 2 07:55:09 tfw1 openvpn[60992]: Options error: --server...
Bill Fenner
09:30 AM Bug #1577: Inserting any rules on VPN PPPoE interface cause filter not reload
Hi,
Sorry i can´t know how to find config xml.
I created a rule on PPPoE Interface, with Action Pass from any sou...
Fabiano Heringer
08:13 AM Bug #1577: Inserting any rules on VPN PPPoE interface cause filter not reload
Please provide your config xml or description of the rules and pppoe server configuration. Ermal Luçi
07:16 AM Bug #1577 (Resolved): Inserting any rules on VPN PPPoE interface cause filter not reload
When I inserting any rule filter on interface VPN PPPoE, the filter reload don´t start, show the follow error:
The...
Fabiano Heringer
08:14 AM Revision 3781d809: Correct input object name from wrong copy/pasto. Reported-by: http://forum.pfsense.org/index.php/topic,37369.0.html
Ermal LUÇI
07:16 AM Bug #1386: Nested port aliases causes "Unknown port" error upon loading filters
As a closing note: I switched my firewall config fully to nested port aliases now (some are 3 levels deep), and it al... Frank Zavelberg
04:06 AM Bug #1575 (Resolved): Limiters are bypassed by local applications injecting rules
Taking a look at http://forum.pfsense.org/index.php/topic,37399.0.html
it would be good to teach the match action ab...
Ermal Luçi
03:28 AM Feature #1574 (New): Password quality enforcment.
It would be nice to be able to enforce password policy for local accounts.
http://www.openwall.com/passwdqc/ can hel...
Ermal Luçi

06/01/2011

11:22 PM Bug #1417: OpenVPN client specific overrides doesnt work by default
What exactly did you have entered for the Tunnel Network? It works fine when entering a proper value (a /30 where the... Jim Pingle
11:07 PM Bug #1417: OpenVPN client specific overrides doesnt work by default
Part of the last commit ( 0cc5ab4 ) broke my previously-working site-to-site p2p_tls vpn configuration using a /30. ... Bill Fenner
10:32 PM Todo #1573 (Resolved): Test Android Gingerbread IPsec Options
Gingerbread brought with it "Advanced IPsec VPNs", most of which look like they should work as a mobile client agains... Jim Pingle
10:29 PM Revision fc3dcc8b: Merge remote branch 'origin/master'
Evgeny Yurchenko
10:28 PM Revision 3da5c50d: Bug #1560.IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1 (improvement of previous patch)
Evgeny Yurchenko
10:07 PM Bug #1565 (New): Pull kern/134878 into pfsense 2.0
Chris Buechler
09:57 PM Bug #1565: Pull kern/134878 into pfsense 2.0
Patch attached. Tested against RELENG_8_1. Also requires puc enabled in kernel. Michael Reynolds
09:39 PM Revision 2e88102d: Disable this until it can be properly fixed.
Jim Pingle
08:56 PM Revision ee0cf21f: Merge remote branch 'upstream/master'
Jim Pingle
08:55 PM Bug #1570: Reboot doesn't work from ssh with option 5
Typo: 5.0 should be 5.)
And I can reboot from the web interface, so my bug is definitely different.
Joop Braak
08:53 PM Bug #1570: Reboot doesn't work from ssh with option 5
No, it doesn't , it is only mentioned in a comment that was added by you yesterday!
The original description clear...
Joop Braak
08:26 PM Bug #1570: Reboot doesn't work from ssh with option 5
you're the one who can't read, the other ticket covers both this and the web interface reboot. Chris Buechler
08:24 PM Bug #1570: Reboot doesn't work from ssh with option 5
Can you not read ? This is not the same , it is the opposite. Please reopen this bug. Joop Braak
08:54 PM Revision a01ce4c7: Make the ICMP echo request type less ambiguous, and since it's likely the main one to get used, move it to the top.
Jim Pingle
05:20 PM Bug #1560: IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Is 192.168.16.5/24 input considered valid? It's easier to error on this in gui... Evgeny Yurchenko
05:02 PM Bug #1560 (New): IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Still at least one case that needs checking:
It still allows you to overlap if you use the "[Interface Name] subnet"...
Jim Pingle
06:52 AM Bug #1560 (Feedback): IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Ermal Luçi
03:53 PM Bug #1572 (Resolved): DHCP + MAC spoofing leads to link cycling
If MAC spoofing is enabled on an interface that is a DHCP client, in some circumstances it can get itself into a mess... Chris Buechler
03:52 PM Bug #1351 (Resolved): Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
thanks Chris Buechler
04:45 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Just for a point of reference to my earlier info.
I eventually found that my issue was a problem with the client end...
Andy Giles
03:28 PM Feature #1571: Interfaces completely reset when hardware is changed
this is how things have always worked and how the system is intended to function. If you remove a physical interface ... Chris Buechler
12:15 PM Feature #1571 (Rejected): Interfaces completely reset when hardware is changed
I had a configuration that used 2 wireless cards (urtw) and had interfaces assigned. One of the urtw interfaces was c... Mr Horizontal
03:25 PM Revision 7af360ce: Add tunable, by default disabled, to enable the default gateway switching feature when the default one 'disappears'.
Ermal LUÇI
03:25 PM Revision f8f3732a: Fixes #1412. Properly pass the page to match so users are not always presented with the change password screen. Proper fix.
Ermal LUÇI
02:42 PM Revision b5ef447f: Fix merge blip.
Jim Pingle
02:03 PM Revision f4645d7f: Add tunable, by default disabled, to enable the default gateway switching feature when the default one 'disappears'.
Ermal LUÇI
01:00 PM Revision 58005e52: Merge remote branch 'upstream/master'
Conflicts:
conf.default/config.xml
etc/inc/filter.inc
etc/inc/globals.inc
etc/inc/pfs...
Jim Pingle
12:23 PM Revision 9584d162: Fixes #1412. Properly pass the page to match so users are not always presented with the change password screen. Proper fix.
Ermal LUÇI
11:14 AM Revision 97c1f268: Fixes #1412. Properly pass the page to match so users are not always presented with the change password screen.
Ermal LUÇI
11:14 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
That is because you are on the IPv6 branch which hadn't been merged in a while. I just synced it back up with mainlin... Jim Pingle
02:29 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
I just updated my backup router, but commits from 5 days ago are not included yet. I'm now running:
2.0-RC2-IPv6 (...
Marcin Krol
10:49 AM Revision 695a35ae: Ticket #944. Also destory the previous interface if the user changing the vlan tag of an existing vlan entry.
Ermal LUÇI
10:49 AM Revision 6b421a0f: Fixes #944. Use the correct interface name to destroy the previous vlan if the parent is changed.
Ermal LUÇI
09:46 AM Bug #1532: test_pfSpkg code breaks packages
This might be a long term change, but it might make sense to convert each package to a class which will prevent multi... Yehuda Katz
06:58 AM Bug #1532: test_pfSpkg code breaks packages
This has been reverted and it will not make 2.0 Ermal Luçi
09:32 AM Bug #1556: Changing local IPsec tunnel endpoint does not work
How to replicate?
I've tried switching between WAN and OPT1 and racoon always listens on respective interface. Reboo...
Evgeny Yurchenko
08:42 AM Bug #1529 (Resolved): bug related to ID: 57f2840e1faacf50b1a93d7954bb576eca77475b
Ermal Luçi
08:38 AM Bug #1408 (Resolved): DHCP DNS servers still get routes even if allow override is unchecked
Ermal Luçi
08:34 AM Bug #1391 (Resolved): Disable auto-added VPN rules missing
This has been solved if needed can be re-opened later on. Ermal Luçi
08:30 AM Bug #1383: Upgrade routines should check free space
This is doable only if we keep an approximate file size for upgrades hardcoded in the source.
This allows to do heur...
Ermal Luçi
08:23 AM Bug #1412 (Resolved): Assign a user the "WebCfg - System: User Manager Page" does'nt allow access
Ermal Luçi
07:15 AM Bug #1412 (Feedback): Assign a user the "WebCfg - System: User Manager Page" does'nt allow access
Applied in changeset commit:97c1f2684c5dd225075fec08148f084ff190af0a. Ermal Luçi
07:06 AM Bug #1353: Number of queues possible
This is not so critical for 2.0 Ermal Luçi
07:04 AM Bug #1303 (Resolved): Removal interface without setting of wan causes error unset
Ermal Luçi
07:02 AM Bug #482 (Resolved): OpenVPN config upgrade problems
I am closing this for now after 9 months.
If issues arise it can be re-opened.
Ermal Luçi
06:55 AM Bug #1541 (Resolved): /etc/rc.start/stop_packages do not start/stop .sh files
Ermal Luçi
06:54 AM Bug #1519 (Resolved): sshlockout truncates ip
Ermal Luçi
06:50 AM Bug #944: Moving VLANs to lagg doesn't remove old VLANs
Applied in changeset commit:6b421a0fb42a50d1e87ac63c64a5b8b8d2157577. Ermal Luçi
06:47 AM Bug #944: Moving VLANs to lagg doesn't remove old VLANs
I just pushed some fixes.
Please gitsync and verify they work correctly now.
Ermal Luçi
05:16 AM Bug #944: Moving VLANs to lagg doesn't remove old VLANs
still in 2.0-RC2(amd64) built on Tue May 31 12:13:03 EDT 2011
Andreas Bochem
06:39 AM Bug #1510 (Resolved): Aliases names over 32 characters in length cause table problem errors
Ermal Luçi
05:30 AM Bug #1510: Aliases names over 32 characters in length cause table problem errors
Looks good in 2.0-RC2 (amd64) built on Tue May 31 12:13:03 EDT 2011.
Trying to save an alias with name longer than...
Andreas Bochem
06:37 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
I will look at this a bit since its related to some other hangs that happen at times. Ermal Luçi
06:20 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
Changing rc.stop_packages to a shell script works. Which is a small trivial change and the following works for me:
...
Warren Baker
12:13 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
Forgot to mention: mwexec("/usr/local/bin/php -f /etc/rc.stop_packages"); does not work either. Evgeny Yurchenko
12:08 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
I've spent some time trying to understand why we get three processes rc.stop_packages after clicking reboot from gui:... Evgeny Yurchenko
06:28 AM Bug #636: layer7 not work correctly
Can you upload the generated config file i am not seeing it. Ermal Luçi
05:52 AM Bug #636: layer7 not work correctly
I've removed that, and there's no improvement. Jonathan Puddle
03:41 AM Revision 538b6eb3: Bug #1560. IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1(site-to-site).
Evgeny Yurchenko
12:31 AM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Multiple instances of iperf with udp traffic is very good way to generate substantial load. Evgeny Yurchenko

05/31/2011

11:46 PM Bug #1560: IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Fixed by https://github.com/bsdperimeter/pfsense/commit/061f28bfd582d1f08d8dfe60f87fc4fd99ec0a93 for mobile clients a... Evgeny Yurchenko
08:32 PM Revision 0ca52cff: fix typoes
Bill Marquette
07:39 PM Bug #1570 (Closed): Reboot doesn't work from ssh with option 5
same as #1564 Chris Buechler
07:34 PM Bug #1570 (Closed): Reboot doesn't work from ssh with option 5
When I log into pfsense with ssh and choose option 5 to reboot and then confirm with "y", the system doesn't reboot.
...
Joop Braak
07:39 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
same from console menu option 5 Chris Buechler
04:52 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
The php.net bug is a decade old. While include() may 'fix' this, IMHO it really obfuscates what it's trying to do an... Bill Marquette
10:33 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
#5 Solution works for me as well, for me please commit ... Karsten G
12:21 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
It seems that this is related to bug in php http://bugs.php.net/bug.php?id=11430 "Impossible to execute .php from ins... Evgeny Yurchenko
06:42 PM Revision f9d7c5b3: Use array_overlay()
Scott Ullrich
06:28 PM Revision 0b581a8a: Use array_extend
Scott Ullrich
06:26 PM Bug #1569 (Needs Patch): USB760 CD not recognized
driver issues are outside of our control. If you have a patch to fix it, we can commit it. Chris Buechler
06:13 PM Bug #1569 (Duplicate): USB760 CD not recognized
While inserting/booting a USB760 CDMA usb modem one can't eject the CD to put it in modem mode because pfSense does n... Scott Lampert
05:50 PM Revision 456026b5: Use pfsense.restore_config_section
Scott Ullrich
05:47 PM Revision 485b1ca5: Remove debugging code
Scott Ullrich
05:45 PM Revision db748384: Add merge handler code
Scott Ullrich
05:21 PM pfSense Packages Bug #1376: Text in "Interfaces" widget wraps when interface speed is more then 100mbit
The fixes from the ipv6 branch may apply here.
https://github.com/smos/pfsense-ipv6/commits/master/usr/local/www/wid...
Bill Marquette
04:35 PM Revision 10d74dff: Remove bogus protection. We have better handling of this now.
Scott Ullrich
04:14 PM Todo #1568 (Resolved): Import the IPv6 patch that allows router advertisements with forwarding enabled
It is impossible to accept v6 router advertisements when v6 forwarding is enabled.
this patch applies to FreeBSD 8...
Seth Mos
03:58 PM Revision 85055175: Remove old vidcontrol cruft lingering from long long ago
Scott Ullrich
10:45 AM pfSense Packages Bug #1563 (Closed): UPDATE: Squid errors on updating version
Moved note to #1443
Please don't open new tickets for an update, if there is a problem with redmine that is a separ...
Jim Pingle
10:45 AM pfSense Packages Bug #1443: Squid errors on updating version
Lloyd is still having issues (See #1563)
I still can't reproduce this no matter what I do.
Jim Pingle
10:15 AM Bug #1567 (Rejected): pfsense rc1 2.0 DNS
It works fine, I'm using it on my home router without problems. Please use the forum for help diagnosing such issues ... Jim Pingle
10:07 AM Bug #1567: pfsense rc1 2.0 DNS
architecture Amd 64 not availible
10:06 AM Bug #1567 (Rejected): pfsense rc1 2.0 DNS
Under general setup drop down box +use gateway+ does not seem to work when there are more then one interface not availible
10:13 AM Bug #1566 (Rejected): pfsense 2.0 rc1 Firewall rules
It works fine, even on the latest snapshots. Please use the forum to get help diagnosing an issue and confirming a bu... Jim Pingle
10:04 AM Bug #1566 (Rejected): pfsense 2.0 rc1 Firewall rules
Under firewall tab
adding a *rule* to wan interface does not seem to work
not availible
09:05 AM Revision 9d545c88: Merge remote branch 'origin/master'
Evgeny Yurchenko
09:03 AM Revision 061f28bf: Bug #1560. IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1(mobile clients).
Evgeny Yurchenko
02:58 AM Bug #636: layer7 not work correctly
You have a stray <containter/> tag what happens if you remove that? Ermal Luçi
02:02 AM Bug #636: layer7 not work correctly
The l7shaper config is attached, sorry, it took me a minute to find it. The log output looks similar to above, some e... Jonathan Puddle
02:10 AM Revision edb2a3da: Bug#1528. Automatically create outbound NAT rules on WAN for localhost when switching to manual.
Evgeny Yurchenko
01:05 AM Bug #1565 (Needs Patch): Pull kern/134878 into pfsense 2.0
attach a tested patch against RELENG_8_1 and we'll add it. Chris Buechler
12:58 AM Bug #1565 (Resolved): Pull kern/134878 into pfsense 2.0
I've submitted this as a bug because I am unable to use my 8 port serial card with pfsense, but can with 8_2_RELENG w... Michael Reynolds

05/30/2011

10:38 PM Todo #1528: Automatic outbound NAT from localhost needs a little work
not for 2.0, can be revisited in the future Chris Buechler
10:24 PM Todo #1528: Automatic outbound NAT from localhost needs a little work
Do we need "NAT from localhost out LAN and other internal interfaces as well"? It does not look hard to implement. Evgeny Yurchenko
10:16 PM Todo #1528: Automatic outbound NAT from localhost needs a little work
That much is adequate for 2.0. Chris Buechler
10:14 PM Todo #1528: Automatic outbound NAT from localhost needs a little work
The first part is fixed by this https://github.com/bsdperimeter/pfsense/commit/edb2a3dab4833fa024828f3150cdcc1521ea1b48 Evgeny Yurchenko
10:21 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
I can confirm that I have this issue using 2.0-RC2 (i386) Mon May 30 11:06:53.
Tried to reboot from reboot.php. We...
lude lude
04:45 PM Bug #1564 (New): rc.stop_packages causes reboot to only works from SSH, not from Web interface
Scott Ullrich
04:42 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
I can confirm on snapshot May 30 11:53:52 nanobsd 4G when I remove rc.stop_packages https://github.com/bsdperimeter/p... Perry Mason
02:04 PM Bug #1564 (Feedback): rc.stop_packages causes reboot to only works from SSH, not from Web interface
Cannot replicate this issue.
Scott Ullrich
02:02 PM Bug #1564 (Resolved): rc.stop_packages causes reboot to only works from SSH, not from Web interface
As reported in the forum (http://forum.pfsense.org/index.php/topic,37258.0.html), the reboot feature doesn't work fro... Pierre ROUSSET
07:27 PM Revision a3d58a12: Use aon plugin
Scott Ullrich
07:25 PM Revision 2ba7d6f8: Add plugin features to aon edit
Scott Ullrich
04:28 PM Revision 2ea00c3e: Add missing plugin code. Move the pre_write section up a bit.
Scott Ullrich
04:02 PM Revision 3dbceb92: Include .inc files for plugin system
Scott Ullrich
02:35 PM Bug #1403: Filter Rules description do not get saved when "(quote) present as character
I've added the same syntax checks to NAT pages.
https://github.com/bsdperimeter/pfsense/commit/b45babaeb55ac039f498d...
Evgeny Yurchenko
01:11 PM Revision d97ff036: Prevent races on resovlconf generation as well by adding a lock.
Ermal LUÇI
09:03 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
Can you try with latest snapshots? Ermal Luçi
09:00 AM Bug #1545 (Feedback): Dynamic DNS updates fail on 3G connections
Please try with latest version.
Currently increasing the timeout is the best solution.
In long term possibly the ...
Ermal Luçi

05/29/2011

09:44 AM pfSense Packages Bug #1563 (Closed): UPDATE: Squid errors on updating version
This is an update to http://redmine.pfsense.org/issues/1443 which will not let me edit
I am still experiencing the...
Lloyd Collins

05/28/2011

04:19 PM Revision ce91583b: Merge pull request #1 from EvgenyY/6e2a15e677fa0558ba0c9b1700be38f4065a76f6
Speed/duplex select for interfaces Ermal LUÇI
10:52 AM Bug #1562 (Rejected): atheros 9280 not working
nothing we can do with ath driver issues. usually forcing the channel will work around that particular problem. Chris Buechler
10:50 AM Bug #1562: atheros 9280 not working
These are driver issue which we try to look whenever possible. Ermal Luçi
04:39 AM Bug #1562 (Rejected): atheros 9280 not working
card is detected and it is possible to create wireless devices
but if i configure the device (tested in b also g mod...
Miroslav Hruska

05/27/2011

09:55 PM Revision b45babae: Bug #1403. Filter Rules description do not get saved when "(quote) present as character
Evgeny Yurchenko
05:27 PM Revision 55260532: Add note about voucher sync (only enable on slave nodes).
Scott Ullrich
05:06 PM Revision 58f963d0: Clarify auth option to include Vouchers
Scott Ullrich
04:02 PM Revision f40a03a4: Only add pppoe to the interfaces list if it both has an entry and is in server mode (i.e. not disabled.)
Jim Pingle
04:02 PM Revision 685c9776: Some extra protection against putting empty values into the ruleset.
Jim Pingle
03:32 PM Revision a1b86994: Ticket #1534. Try to stop packages during reboot of system.
Ermal LUÇI
03:21 PM Revision 6e2a15e6: Hiding mediaopt under Advanced button
Evgeny Yurchenko
02:42 PM Bug #1372 (Resolved): RRD is not updating VPN statistics
Jim Pingle
02:41 PM Bug #1372: RRD is not updating VPN statistics
Verified in
2.0-RC2 (i386)
built on Fri May 27 07:59:32 EDT 2011
It is fixed now.
Thx.
Sven Rubben
10:46 AM Revision 93b8df2a: Increase timeout to 2 minutes. Ticket #1545.
Ermal LUÇI
10:45 AM Revision 71070cc5: Ticket #1545. Lock each dnsHost to be updated to prevent running two instances in parallell.
Ermal LUÇI
08:24 AM Revision 224ddbad: Silence the route changing since it fills the logs with not needed info.
Ermal LUÇI
07:56 AM Revision dfb30a89: Trigger reloading of packages through check_reload_status so it can serialize the calls to not DoS the OS with processes triggered from this. Ticket #1534
Ermal LUÇI
05:06 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Sorry, this happened ages ago. Didn't realise it was so quick. Here's the logs as requested. As mentioned the first u... Ross Williamson
03:52 AM Revision e5770bc2: DHCP only knows about IPv4
don't allow admins to shoot themselves with v6 addresses in the config Bill Marquette
03:28 AM Revision 13f0762d: Fix #1277
Wasn't able to remove the multicast RIPv2 discovery at startup, but
all ripv1 response's are gone now.
Bill Marquette
03:02 AM pfSense Packages Bug #1561 (Resolved): HTTP traffic dies after disabling HAVP
Yesterday I've installed HAVP. I've set it up to run in transparent mode and it works fine with one exception. If I'l... Marcin Krol
02:53 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
Disabling and re-enabling HAVP on master router causes even more severe load on backup router. It also causes other i... Marcin Krol
02:43 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
Indeed I was using old gitsync URL. I've performed few tests yesterday on updated systems. Unfortunately applied chan... Marcin Krol

05/26/2011

11:30 PM Bug #1277 (Feedback): Rip propagation
Applied in changeset commit:13f0762d9c2f23e19eec13dc1041506c40051be8. Bill Marquette
09:43 PM Bug #1555 (Resolved): Wrong DHCP configuration option when activating "Deny unknown clients"
Chris Buechler
08:51 PM Revision b75d32e5: Free ipfw rule number after mac pass-through deletion.
Ermal LUÇI
08:16 PM Revision ab731f54: Bring more consistent style to CP edit mac and ip passthrough pages.
Ermal LUÇI
07:39 PM Revision adcf909a: Just use the long reference here instead of creating potential dangerous reference.
Ermal LUÇI
01:56 PM Bug #1415 (Resolved): Nat reflection is installing rules with 'Array'
OK, I'm closing this out. That other bug isn't right either, it's really just this problem too.
Start a new ticke...
Jim Pingle
01:52 PM Bug #1415: Nat reflection is installing rules with 'Array'
Dear Jim,
I tried, but it didn't work anyway... btw, I think this specific issue can be closed since is resolved, ma...
Michele Di Maria
08:16 AM Bug #1415: Nat reflection is installing rules with 'Array'
Try switching to manual outbound NAT if you haven't already, and then add an outbound NAT rule on the LAN with a sour... Jim Pingle
01:57 AM Bug #1415: Nat reflection is installing rules with 'Array'
Hello,
I confirm that rules are not defined with "array" even in the case of "port alias" described above.
Anyway,...
Michele Di Maria
01:41 PM Bug #1559: Static IP on interface not updating properly
Jim P wrote:
> Is this on a current snapshot? That bug was fixed a week or so ago (there is already a ticket for it,...
David Miller
10:50 AM Bug #1559 (Closed): Static IP on interface not updating properly
Is this on a current snapshot? That bug was fixed a week or so ago (there is already a ticket for it, #1522, reopen t... Jim Pingle
10:35 AM Bug #1559 (Closed): Static IP on interface not updating properly
I don't know if this behavior is as desired or if it's even a new issue with 2.0 rc2.
I've found that when you c...
David Miller
01:25 PM Bug #1560: IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Error from the IPsec log:... Jim Pingle
10:48 AM Bug #1560 (Resolved): IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.
Currently, the GUI lets you specify the same source/destination subnet more than once in the list of phase 2 definiti... Jim Pingle
12:44 PM Bug #636: layer7 not work correctly
You need to show the generated config file and you have not shown your layer7 from your config. Ermal Luçi
07:54 AM Bug #636: layer7 not work correctly
I've tested things a bit more today, and am seeing some strange behaviour. I've added some Layer7 rules, and am then ... Jonathan Puddle
11:41 AM Revision 1a6cb6e7: Remove decimals from cumulative users graph.
Warren Baker
11:11 AM Bug #651: Multiple gateways on WAN interface
Sorry!
The post is:
http://forum.pfsense.org/index.php/topic,37116.0.html
Josep Pujadas-Jubany
11:11 AM Bug #651: Multiple gateways on WAN interface
Hello!
At the Spanish Forum there is an user with similar problem.
He posted images of its topology. So, its ea...
Josep Pujadas-Jubany
10:08 AM Feature #1557 (Resolved): Add the Interface descriptions to the OS interface descriptions
When configuring an interface we can specify a "description" of the interface.
Unfortunately this description is not...
Peter Baumann
08:37 AM Bug #1556 (Resolved): Changing local IPsec tunnel endpoint does not work
When attempting to change over a tunnel from a OPT back to the WAN interface the tunnel never came up.
The other s...
Seth Mos
08:25 AM Revision 3c5e10fc: Add debugging notes so that we can easily fix this when IPv6 support is added to the pfSense module.
Remove the Accept router advertisement from all interfaces unless we enable them Seth Mos
08:14 AM Revision 668ce1f9: Increase the minimum time between generating images from 5 to 15 seconds to prevent DoS the firewall.
Seth Mos
08:13 AM Revision d67d99a1: Fix packet graph label alignment
Seth Mos
08:10 AM Revision a63f2b7d: Fix the graph label alignment
Seth Mos
07:59 AM Revision a555cc58: Fix my traffic graphs
Seth Mos

05/25/2011

11:51 PM Revision e4a8ed97: Add function header
Scott Ullrich
11:43 PM Revision d65962a7: Adding a new hook system for firewall nat edit and firewall rules edit page.
Basically if the directory exists it will suck in the files to extend these pags.
/usr/local/pkg/firewall_nat/input_...
Scott Ullrich
10:43 PM Revision 838e4eb8: Rather make use of $global variable for RRD path.
Warren Baker
10:02 PM Revision 474f36d1: * Add is_ipaddr_configured() so that people do not need to reinvent the wheel for this task
* Check to make sure the administrator is not entering the IP address of the same host preventing a issue where the f... Scott Ullrich
10:00 PM Revision 5c723d9f: Remove out-dated RRD file as it will cause broken images to appear on RRD graphs page.
Warren Baker
08:36 PM Revision c206a2ab: Disable csrf checks when posting from scripts.
Ermal LUÇI
08:28 PM Revision 05771a24: Provide a voucher_expire function so that voucher can be expired through a POST.
Ermal LUÇI
05:35 PM Revision 669113f9: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
05:33 PM Revision 19bd7032: Remove gettext from negotiation mode
It is causing errors on raccon because config file were generated with
translated words
Vinicius Coque
05:08 PM Revision dceff62e: Put some debug info during dyndns update under debug conditionals.
Ermal LUÇI
04:51 PM Revision 193ee786: Actually add more error checking and do not schedule a scan if it is not possible to retreive the wan ip address.
Ermal LUÇI
04:41 PM Revision dd575ea4: Improve some code and check return value from _checkIP.
Ermal LUÇI
04:29 PM Revision 7788c76a: Don't overwrite the $target variable. Fixes #1415
Jim Pingle
04:10 PM Bug #1552 (New): DNS Reject Rule Crashes Router
This really does crash the box. Attaching a backtrace. I can reproduce it at will.
Jim Pingle
03:38 PM Revision c749ef62: Check that the returned ip is an ip_address and not blindly trust the returned information.
Ermal LUÇI
01:35 PM Revision f0e80b72: Correct dhcpd statement for unknown-clients. Fixes #1555
Jim Pingle
12:30 PM Bug #1415 (Feedback): Nat reflection is installing rules with 'Array'
Applied in changeset commit:7788c76a4e9e04b356f40f2129ff5309617dad99. Jim Pingle
11:02 AM Revision f6f1c847: Update some code to be more readble and more compliant to php5
Ermal LUÇI
09:35 AM Bug #1555 (Feedback): Wrong DHCP configuration option when activating "Deny unknown clients"
Applied in changeset commit:f0e80b72a3c359f52596e9b6948178ad48d6bb1b. Jim Pingle
09:27 AM Bug #1555 (Resolved): Wrong DHCP configuration option when activating "Deny unknown clients"
Hello everybody,
There is a bug in the generated dhcpd.conf when enabling "Deny unknown clients".
the resulting...
Alexis Olivier
08:43 AM Bug #1386 (Resolved): Nested port aliases causes "Unknown port" error upon loading filters
Ermal Luçi
08:37 AM Bug #1386: Nested port aliases causes "Unknown port" error upon loading filters
Using the "Tue May 24 04:45:10 EDT 2011" version, the problem seems to be successfully fixed. :) I was able to create... Frank Zavelberg
05:35 AM Revision b2d00d91: Unset the correct variables
Seth Mos
02:28 AM Bug #1554 (Resolved): Voucher page turns grey after parameter change
"Services: Captive portal: Vouchers" page gets nearly all greyed out and no new roll can be generated (the "+" icon d... Pavel Pilat
 

Also available in: Atom