Project

General

Profile

Activity

From 06/19/2011 to 07/18/2011

07/18/2011

07:44 PM Bug #1694: /etc/hosts gets dhcp clients entries with wrong domainnames
Chris Buechler wrote:
> Needs to be fixed at some point, but if you end up with a loop like that you have something ...
Cyrus Patel
06:49 PM Bug #1694: /etc/hosts gets dhcp clients entries with wrong domainnames
Needs to be fixed at some point, but if you end up with a loop like that you have something configured in a non-optim... Chris Buechler
06:44 PM Bug #1694 (Closed): /etc/hosts gets dhcp clients entries with wrong domainnames
For 2.0-RC3 (i386) snapshot of Fri Jul 15 19:39:23 EDT 2011
The dynamic entries being written to /etc/hosts on a...
Cyrus Patel
07:32 PM Todo #1695 (Resolved): local services should also use the forwarder (if enabled) for DNS.
Presently, local services do not use the DNS forwarder (if enabled).
The solution (recommended by the dnsmasq manp...
Cyrus Patel
05:00 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
Ermal Luçi wrote:
> Can you please be more clear?
> Exapnd what works and what not and possibly go first through th...
Matt Crook
08:59 AM Bug #1690: PPPoE Server not passing IP from RADIUS server
Can you please be more clear?
Exapnd what works and what not and possibly go first through the forums?
Ermal Luçi
01:45 PM Feature #1687: GetText code inspection
We are reviewing the gettext code, strings with incorrect use of printf are already fixed. Soon they will be merged i... Vinícius Coque
01:00 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
I tried to test this out, but the description that Ermal added doesn't clearly tell me what I'm looking for. At firs... Josh Stompro
11:19 AM Bug #1629: invalid state table entries after WAN IP change
I had it reset again this weekend which took the asterisk server down again. Unfortunately I wasn't near a computer ... Eli Hunter
07:48 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Ross Williamson wrote:
> So I have no idea what is going on. This is on the latest snapshot which appears to be Jul ...
Jim Pingle
04:55 AM Bug #1545: Dynamic DNS updates fail on 3G connections
For whatever reason dynamic DNS has completely stopped working for me now. I can't even force an update. On first boo... Ross Williamson
06:24 AM Bug #1493: pf blocks all traffic following filter reload.
Similar problem here:
Hardware: Fujitsu Primergy; VMWare VSphere
pfSense 2.0-RC3 (amd64)
built on Mon Jul 4 ...
Markus Schlager
05:19 AM Bug #1493: pf blocks all traffic following filter reload.
Hi,
I have tested with a vanilla install of pfSense.
I consistently encounter this issue. I have tried i386 pf...
Aaron Roberts
05:42 AM Bug #1692 (Rejected): OpenVPN Clients can't route to IPSEC peer
that's a configuration issue, the PPTP clients are likely on the LAN subnet which means they fall into the P2, your O... Chris Buechler
03:31 AM Bug #1692 (Rejected): OpenVPN Clients can't route to IPSEC peer
Client PC connects using OpenVPN to a central pfsense firewall (2.0-RC3). Central firewall has IPSEC tunnel to remote... Nei Ka

07/17/2011

06:21 AM Bug #1691 (Closed): Virtio driver not working
In commit:2ac109889ae1afeeea6cdd8dbcc339023a3f32a0 the virtio driver was added from upstream freebsd.
However, when ...
Marcus Beyer
03:33 AM Bug #1690 (Resolved): PPPoE Server not passing IP from RADIUS server
I have tried both with windows RADIUS and the packaged offered as an add-on for pfSense (freeradius) and both with th... Matt Crook

07/16/2011

08:53 PM Bug #1629: invalid state table entries after WAN IP change
No, no, Im not talking about IPv6 in pfSense, Im talking about IPv6 NAT passthrough in the "System: Advanced: Network... Matt Corallo
05:33 PM Bug #1629: invalid state table entries after WAN IP change
IPv6 is a completely different version, that's 2.1 not 2.0, post info to the IPv6 board on the forum. Chris Buechler
04:57 PM Bug #1629: invalid state table entries after WAN IP change
I have the same problem (after the fixes) with IPv6 tunneling, so this is not resolved. Matt Corallo
02:14 AM pfSense Packages Bug #1689 (Resolved): Home URL broken from package paths
The pfsense image in the top left corner which takes the user back to the index.php page has it's url dynamically cre... reg ister

07/15/2011

11:02 PM Bug #1688 (Resolved): DHCP server subnet input validation needs to check config.xml, not ifconfig
The DHCP server subnet input validation in 2.0 checks what IP is configured on the interface, so it's impossible to c... Chris Buechler
05:13 PM Feature #1687: GetText code inspection
<td colspan="2" class="listtopic">< ? php printf (gettext("Last $nentries PPP log entries"),$nentries); ? ></td>
Serg Dvoriancev
05:12 PM Feature #1687: GetText code inspection
ver 2.0
Quickly i able to find it here
/diag_logs_ppp.php [91]
<td colspan="2" class="listtopic"><?php printf ...
Serg Dvoriancev
04:58 PM Feature #1687: GetText code inspection
Can you please point to such locations? Ermal Luçi
04:56 PM Feature #1687 (Resolved): GetText code inspection
In some cases, you can find such code:
$myname = 'NameName';
$myvar = 'abcd123';
$mytext = gettext("This is {$m...
Serg Dvoriancev
04:40 PM Bug #1686 (Closed): guiconfig.inc GetText logical bug
guiconfig.inc
function print_info_box_np($msg, $name="apply",$value="Apply changes")
This function is called with...
Serg Dvoriancev
04:11 PM Bug #1552: DNS Reject Rule Crashes Router
This has been fixed for now by nullifying the gateway selection silently. Ermal Luçi
04:10 PM Bug #1552 (Feedback): DNS Reject Rule Crashes Router
Ermal Luçi
04:00 PM Bug #1193 (Feedback): Traffic Shaper default queue Problem
Plese test latest snapshots. Ermal Luçi
03:50 PM Bug #1685: Web configurator silently fails when "Private key does not match the certificate public key"
In the meantime you can get back in by resetting the LAN IP from the console, entering the same information again. Du... Jim Pingle
03:48 PM Bug #1685: Web configurator silently fails when "Private key does not match the certificate public key"
This is for version 2.0 RC3 x86. Jeff Shaw
03:48 PM Bug #1685 (Resolved): Web configurator silently fails when "Private key does not match the certificate public key"
After choosing a particular certificate for the web administrator under System -> Advanced, the web server fails to r... Jeff Shaw
03:17 PM Bug #749 (Feedback): Downstream queues should not be assigned to LAN interfaces
This has been worked around by creating a queue that can go full interface speed. Ermal Luçi
02:24 PM Bug #1684 (Rejected): Clearing the IPsec log causes webadmin to become unresponsive.
Can't reproduce this on current snapshots, full or nanobsd. Clearing logs returns fast and works as expected. Please ... Jim Pingle
02:19 PM Bug #1684 (Rejected): Clearing the IPsec log causes webadmin to become unresponsive.
So far the only way I've found to fix this is reboot. Restarting the web administrator from the console just printed ... Jeff Shaw
02:17 PM Bug #76: Changes needed to traffic shaper since its rewrite
Sorry, I don't understand. Can't do what?
Isn't the error I am experiencing exactly same as #2 in the description o...
torontob toronbot
01:25 AM Bug #76: Changes needed to traffic shaper since its rewrite
yes but that's no longer a bug, in this ticket that wasn't checked correctly, it is now. you can't do that. Chris Buechler
01:23 AM Bug #76: Changes needed to traffic shaper since its rewrite
I am trying RC3 today and I still see the error with Single-WAN-Multi-LAN:
*"You cannot set the VoIP upload bandwi...
torontob toronbot
09:09 AM Bug #1052 (Feedback): Certificate validation of the LDAPS servers is not enforced
Just committed a fix for this.
You have to select the CA where you configure LDAP settings for it to be used.
This ...
Ermal Luçi
07:56 AM Feature #1683 (New): PF scrub min-ttl option
Idea from this forum post http://forum.pfsense.org/index.php/topic,27206.0.html
It would be nice if pfsense have thi...
Nikolay Stoyanov
07:35 AM Feature #1682 (Closed): second MAC address for one IP address
Idea from this forum post http://forum.pfsense.org/index.php/topic,36066.0.html
It would be nice if pfsense have thi...
Nikolay Stoyanov
07:24 AM Bug #1545: Dynamic DNS updates fail on 3G connections
i have the same issue, pfSense RC3 with two WAN.
Primary with lan connection to a router with fixed ip
Secondary PP...
Emanuel Milani
05:57 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
i have to restart racoon service in order it works properly after pptp client disconnect.But i'm not sure this shutdo... Hafiz Rafiyev
04:47 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I think that restart is user-triggered, people restart racoon to fix it. The log that looks interesting to me is:
...
Chris Buechler
03:36 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Well i need the system logs since seems something is resetting ipsec daemon.... Ermal Luçi
05:10 AM Bug #1681 (Resolved): OpenVPN tun IPs fail HTTP REFERER checks
tun IPs on OpenVPN connections fail the local IP check used for the HTTP_REFERER web interface protection, so the def... Chris Buechler
04:31 AM Bug #1565 (Resolved): Pull kern/134878 into pfsense 2.0
You would have to load puc manually as a module from loader.conf but the patch is imported now. Ermal Luçi
04:05 AM Bug #1618: Captive portal: Invalid AVP value in Radius accounting packet
Applied in changeset commit:b451691f08e5615158b04c767bc6c7cb876bc913. Ermal Luçi
04:05 AM Bug #1618: Captive portal: Invalid AVP value in Radius accounting packet
Applied in changeset commit:e6bd231242cb43ad7e8fca8635d6adcb17f38186. Ermal Luçi
04:01 AM Bug #1618 (Feedback): Captive portal: Invalid AVP value in Radius accounting packet
This should be fixed in latest snapshots. Ermal Luçi
03:48 AM Bug #1407: GUI is sluggish without working DNS
resolv.conf was populated in this case.
This instance was exacerbated by AutoConfigBackup so it was even worse th...
Chris Buechler
03:33 AM Bug #1407: GUI is sluggish without working DNS
Can you check if /etc/resolv.conf has any entry during this time? Ermal Luçi
01:16 AM Bug #1407: GUI is sluggish without working DNS
still hit this and it creates major issues with trying to operate or troubleshoot the system when there's no Internet. Chris Buechler
03:43 AM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Can you please try by disabling msix and tso on bge interfaces? Ermal Luçi
03:34 AM Bug #1679: Login redirect issue
There was a reason of removing automatic redirection.
Mostly was because of automatic posting that could break thing...
Ermal Luçi

07/14/2011

03:00 PM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
The one shot patch is not needed at all now.
You can just increase the sysctl sockmaxbuf to give the same results.
Ermal Luçi
12:30 PM Bug #1680 (Rejected): Automatic Nat inter IpAlias
Please open a forum thread to discuss this and eliminate any possible configuration errors. IF a bug has been confirm... Jim Pingle
12:23 PM Bug #1680 (Rejected): Automatic Nat inter IpAlias
I believe this is a bug
PfSense doing this automatically Nat inter all IpAlias of a interface
In my setup I have
...
Joaquim Soares Soares
03:39 AM Bug #1679: Login redirect issue
Note:
This fix keeps the redirect for non privileged users active.
Andreas Böhm
03:35 AM Bug #1679 (Rejected): Login redirect issue
1. Login and go to the captive portal status page (URL: http://your-pfsense-box.org/status_captiveportal.php)
2. Wai...
Andreas Böhm

07/13/2011

03:15 PM Bug #1675: Captive portal logout problems with pop-up blockers.
The problem here is that a generic way of implementing this is needed.
Some javascript tricks are needed which with ...
Ermal Luçi
11:32 AM Bug #1676 (Resolved): dead IPv6 gateway causes kernel panics
It appears just having an IPv6 gateway configured that's unreachable will result in panics several times a day, even ... Chris Buechler
11:09 AM Bug #1627 (Resolved): VPN VOIP Traffic Ignoring Traffic Shaper Queues
Ermal Luçi
10:58 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
Ermal great thanks for your fix,i had same problem(voip queue in ipsec vpn).After your last fix it's working just fin... Hafiz Rafiyev
10:12 AM Bug #1344: Replace prototype javascript code with jQuery
jQuery UI Core has a progress bar builtin:
http://jqueryui.com/demos/progressbar/
It is easy to control, is built...
G D
07:17 AM Bug #1344: Replace prototype javascript code with jQuery
Progress bar replacement?
http://t.wits.sg/misc/jQueryProgressBar/demo.php for the demo
http://t.wits.sg/jquery...
Warren Baker
09:43 AM Bug #1501 (Closed): Captive Portal Logout popup does not work
it does work Chris Buechler
07:30 AM Bug #1664: DHCP Server no longer allows empty gateway
I have tested and can confirm the fix.
It's working as expected now.
// rancor
rancor rancor

07/12/2011

05:13 PM Bug #1675 (New): Captive portal logout problems with pop-up blockers.
Need to change the Captive portal pop-up page to use techniques to bypass pop-up blockers. Ermal Luçi
04:17 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Tried the latest snapshot which contains this patch, but still doesn't get the OVPN interface added to the bridge aft... Joost van den Broek
12:52 PM Feature #1673 (Rejected): PPTP VPN Server Address by Interface Name
That is not the IP to listen for connections on, it is the IP to be used by connecting clients as their gateway on th... Jim Pingle
12:43 PM Feature #1673 (Rejected): PPTP VPN Server Address by Interface Name
Could the ability to type the interface name (eg WAN) in the server address instead of just the IP address be added. ... Com DAC
10:20 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Andreas Bochem wrote:
> Same issue persisting on latest _2.0-RC3 (amd64) built on Mon Jul 4 16:49:48 EDT 2011_.
T...
Jim Pingle
07:10 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Same issue persisting on latest _2.0-RC3 (amd64) built on Mon Jul 4 16:49:48 EDT 2011_. Andreas Bochem
03:13 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
What snapshot are you on?
There have been made some fixes lately to fix this can you please test?
By looking at the ...
Ermal Luçi

07/11/2011

09:23 PM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
2.0-RC2 (i386)
built on Fri Jun 10 21:40:17 EDT 2011
I added our config with ip's and keys changed, and a screen...
Abdiel Marin
06:26 PM Bug #1629: invalid state table entries after WAN IP change
I got the update installed last week but haven't had the IP change on me yet (surprisingly). I'll update this once t... Eli Hunter
05:04 PM Bug #1629: invalid state table entries after WAN IP change
Have you tested this on 2.0? Ermal Luçi
02:17 PM Bug #1634: Limiter and bridge needs special handling
There may also be some routing concerns when used on a bridge. See QYX-233317. Jim Pingle
01:50 PM Feature #1668: OpenVPN Client Export support Tunnelblick
Ok good to know. I don't have a Mac to try it out on but I know some of my users have Macs at home so the support qu... David Miller
01:46 PM Feature #1668: OpenVPN Client Export support Tunnelblick
The config archive works fine for Tunnelblick. Chris Buechler
01:41 PM Feature #1668: OpenVPN Client Export support Tunnelblick
I typo'ed the name of the client in the subject and don't have permissions to correct it. Could someone please corre... David Miller
01:33 PM Feature #1668 (Closed): OpenVPN Client Export support Tunnelblick
TunnelBrick is an opensource MacOSX OpenVPN client that seems to be pretty active. https://code.google.com/p/tunnelb... David Miller
09:37 AM Bug #1667 (New): L2TP server does not respond properly from a CARP VIP
If you setup an L2TP server and try to connect to a CARP VIP on the same interface, it does not work. The server resp... Jim Pingle
08:55 AM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:5237d356f41b6ac44cabaaa17208795b8471abcd. Ermal Luçi
08:40 AM Bug #1666 (Feedback): OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:bf17eb72c18ee9b751f9e3eb22a082fd9c273ac9. Ermal Luçi
07:51 AM Bug #1666 (Resolved): OpenVPN interface doesn't get added to bridge after reboot
When using an interface assigned to an OpenVPN tap interface in a bridge, it won't be added correctly after rebooting... Joost van den Broek
05:07 AM pfSense Packages Bug #1631 (Resolved): incorrect syntax of /boot/loader.conf after open-vm-tools package installed
thanks Chris Buechler
04:55 AM pfSense Packages Bug #1631: incorrect syntax of /boot/loader.conf after open-vm-tools package installed
The same installation sequence now works fine. All OK. Ivars Strazdins

07/10/2011

08:11 PM Bug #1664 (Resolved): DHCP Server no longer allows empty gateway
Chris Buechler
12:05 PM Bug #1664: DHCP Server no longer allows empty gateway
Applied in changeset commit:7988ce7581efee9aef0184edfb2eeb2f352477a8. Anonymous
12:05 PM Bug #1664 (Feedback): DHCP Server no longer allows empty gateway
Applied in changeset commit:45d1024db3d3d32fb26f2b6c42460cbe98e24096. Anonymous
08:33 AM Bug #1664 (Resolved): DHCP Server no longer allows empty gateway
The default is to use the IP on this interface of the firewall as the gateway but if I leave this empty (default) it'... rancor rancor
03:54 AM Bug #1608 (Resolved): manual update on nanobsd and alix fails always
Chris Buechler
02:52 AM Bug #1608: manual update on nanobsd and alix fails always
this is fixed now Bipin Chandra
02:53 AM Bug #1053: CBQ per se, in kernel
will this be fixed in 2.0? Bipin Chandra
02:51 AM Bug #1582: traffic shaper queues bug
this is fixed now Bipin Chandra
01:09 AM Feature #1663 (Resolved): DHCPv6 relay
Need to add support for DHCPv6 relay. Can just copy DHCP Relay as DHCPv6 Relay, the existing dhcrelay supports IPv6 r... Chris Buechler
12:59 AM Bug #1662 (Resolved): DNS server gateway selection missing input validation
If a gateway is chosen for a DNS server on system.php, the gateway must be the same protocol as that of the DNS serve... Chris Buechler
12:57 AM Bug #1661 (Resolved): Missing input validation in system_routes_edit.php
system_routes_edit.php doesn't validate that the gateway selected is the same protocol as the entered "Destination ne... Chris Buechler
12:54 AM Bug #1660 (Resolved): Missing input validation in system_gateway_groups_edit.php
Members of a gateway group must all be of the same protocol, IPv4 or IPv6 only, not both. Currently you can create a ... Chris Buechler
12:53 AM Bug #1659 (Resolved): Missing input validation in rules gateway selection
Currently you can pick an IPv4 gateway for an IPv6 firewall rule, and an IPv6 gateway for an IPv4 firewall rule. Need... Chris Buechler

07/09/2011

03:36 PM Bug #1344: Replace prototype javascript code with jQuery
Neat tool for generating network maps!?
http://jsplumb.org/jquery/anchorDemo.html
Scott Ullrich
02:21 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please post the system logs more complete not the ipsec related part?
Ermal,I special...
Hafiz Rafiyev

07/08/2011

08:53 PM Bug #1658: Adding new Gateway in interface page needs input validation
it has no input validation currently (partially because it can't check the subnet before the interface is configured) Chris Buechler
08:50 PM Bug #1658 (Resolved): Adding new Gateway in interface page needs input validation
When adding a new gateway in the interface page, it asks you to specify a "Gateway Name" for the interface; when subm... Jeff Reid
05:42 PM Bug #1641 (Resolved): DHCP server default gateway needs input validation
Chris Buechler
12:54 PM Bug #1641: DHCP server default gateway needs input validation
Running 2.0-RC3 (i386) Fri Jul 8 06:31:45 EDT 2001
I just tried adding a gateway that was outside the subnet I'm u...
Josh Stompro
05:24 PM Bug #1657: Timezone should be synchronized on all utilities
this only applies when the tz is changed while the system is running, and has always been the case. I've always just ... Chris Buechler
04:43 PM Bug #1657 (Closed): Timezone should be synchronized on all utilities
During setup the timzeone is set correctly but some utilities in base do not honor it which creates some problems to ... Ermal Luçi
05:20 PM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
For what it's worth, I have a pair of devices running 2.0-BETA5 (8.1-RELEASE-p2 #0: Tue Jan 25 20:12:38 EST 2011 ... Steve Polyack
03:23 PM Bug #1279 (New): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
The filesystem is mounted noatime, so even if it's left rw, it still isn't touched except when the system wants to wr... Jim Pingle
03:19 PM Bug #1279: Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
Using nanobsd i386 8.1-release-p4 Jul 8 06:31:18 EDT 2011, after resetting to system default and rebooting, the / mou... Josh Stompro
02:41 PM Bug #673: SSHD keys not created on restore
I now see bug #1279, which discusses the rw nanobsd mount issue.
Josh
Josh Stompro
02:25 PM Bug #673: SSHD keys not created on restore
I'm not sure how to test this since in the latest snapshot the / mount is still set to rw by default. Erik, you ment... Josh Stompro
11:16 AM Bug #1501: Captive Portal Logout popup does not work
Running 2.0-RC3 (i386) Tur Jul 7 01:04:41 EDT 2011
The logout popup does work for me. I'm not using Radius or acc...
Josh Stompro
10:30 AM Feature #1656 (New): Teach pfctl to kill states by port number
It would be useful in the future if Diag > States could kill states more selectively by port number instead of only b... Jim Pingle
10:19 AM Bug #1653 (Resolved): CP timeout bug: get_last_activity
Ermal Luçi
09:21 AM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Basically it checks for invalid combinations. I did not feel safe to call is_alias(something) without making sure 'so... Evgeny Yurchenko
08:14 AM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Isnt this commit a bit drastic?
Possibly just check impossible combination should be enough?
Ermal Luçi
08:12 AM Bug #1639 (Feedback): Port alias missing input validation in firewall_rules_edit.php
Ermal Luçi
05:10 AM Bug #1655 (Rejected): Change WAN address and their gateway
changing the WAN IP and gateway works fine, whether in re-running the setup wizard or interfaces.php. Post to the lis... Chris Buechler
04:27 AM Bug #1655 (Rejected): Change WAN address and their gateway
When change the IP of the WAN and its gateway (the wizard proposes WANGW).
The gateway is not working properly, prob...
Oscar Francia
03:28 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Can you please post the system logs more complete not the ipsec related part? Ermal Luçi

07/07/2011

11:32 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please test latest snapshots and see if this happends again.
Ermal any changes with l...
Hafiz Rafiyev
11:31 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Just tested the latest snapshot 2.0-RC3 (amd64) built on Thu Jul 7 16:01:09 EDT 2011 - no change. All VPNs still dro... David Rees
08:56 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
They're up now, the branch changed on the snapshots so the links were not pointing to the right place. Also, auto upd... Jim Pingle
07:23 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim P wrote:
> That snapshot was not created after Ermal's note. Please wait for the next new snapshot. It should be...
Hafiz Rafiyev
10:48 PM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Commit https://github.com/bsdperimeter/pfsense/commit/cfceda6d3528d4cdb87fccdb00f28ce194bf393f Evgeny Yurchenko
10:01 PM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
> A port alias can be assigned only as the "to" or "from" port, which is invalid and results in a pf syntax error.
...
Evgeny Yurchenko
08:26 PM Bug #1629: invalid state table entries after WAN IP change
That's expected to happen in 1.2.3 (it has no provisions for dealing with that scenario, only 2.0 does). Chris Buechler
08:12 PM Bug #1641: DHCP server default gateway needs input validation
Commit https://github.com/bsdperimeter/pfsense/commit/9bc59815c6eba7051a401404d4d0b0c7842a9d2f Evgeny Yurchenko
05:01 PM Bug #1654: miniupnpd.pid located in wrong folder
gitsync my pfsense and noticed miniupnpd.pid is now located in /var/run after reboot
thanks again guys!
Cino .
04:49 PM Bug #1654: miniupnpd.pid located in wrong folder
thanks for the quick fix... I'll test once a new snapshot comes out Cino .
04:00 PM Bug #1654: miniupnpd.pid located in wrong folder
Applied in changeset commit:d8532e5db1abd2e4f6fd07998629936967fc9e67. Anonymous
03:15 PM Bug #1654 (Feedback): miniupnpd.pid located in wrong folder
Applied in changeset commit:aa6798c07088b4a45f85e2626576e33876d04263. Anonymous
03:03 PM Bug #1654 (Resolved): miniupnpd.pid located in wrong folder
Running snapshot Thu Jun 30 17:12:48 EDT 2011 currently and also noticed it on Jul 4th snapshot.
miniupnpd.pid is ...
Cino .
10:04 AM Feature #1652: Improvements in captive portal page
Lo Zio,
I like your suggestions, so I'm going to add my own wish list items for the CP here.
- Hide certain po...
Josh Stompro
09:38 AM Bug #1653: CP timeout bug: get_last_activity
I can confirm that this is fixed with the Jul 7 01:04:41 snapshot.
"ipfw table 1 entrystats 192.168.1.130" Now ret...
Josh Stompro
08:48 AM Bug #1653: CP timeout bug: get_last_activity
Also "Last activity" info from Captive portal status (/status_captiveportal.php?order=&showact=1) is wrong.
It shows...
Lo Zio
04:18 AM Bug #1653: CP timeout bug: get_last_activity
I confirm this is the behaviour of my previus bug report (1647).
As per previous request, here is the log:
Jul 6 13...
Lo Zio
08:49 AM Bug #1607 (Resolved): MBUF usage grows geometrically
Ermal Luçi
01:02 AM Bug #1607: MBUF usage grows geometrically
After 10 days uptime my MBUF Usage has almost completely levelled off at 6062 /9856. The second number was at 9730 fo... David Burgess

07/06/2011

09:05 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
That snapshot was not created after Ermal's note. Please wait for the next new snapshot. It should be uploading soon. Jim Pingle
09:04 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please test latest snapshots and see if this happends again.
Just tested on 2.0-RC3 (...
David Rees
06:11 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
Much appreciated!
Thanks
John Doe
04:10 PM Feature #1260 (Feedback): Allow other Backends for Remote Access ( SSL/TLS + User Auth )
I changed the code around a while back to allow this, didn't realize there was still a ticket hanging out for it. Thi... Jim Pingle
05:50 PM Bug #1549: Sip INVITE dropped.
I was able to reproduce the issue again, but the problem only lasted ~5 minutes before resetting itself. I was unable... William King
05:45 PM Bug #1646 (Feedback): 'pfctl -b' does not function as intended
Ermal Luçi
04:53 PM Bug #1646: 'pfctl -b' does not function as intended
Well today it kills if the first ip, passed on first -b, matches src address or if the second ip, passed as second -b... Ermal Luçi
04:50 PM Bug #1629: invalid state table entries after WAN IP change
Applied in changeset commit:8ed478973f20678568f03f00309a5165aa48a1b3. Ermal Luçi
04:50 PM Bug #1629 (Feedback): invalid state table entries after WAN IP change
Applied in changeset commit:0f2826c03d3e3971f6d83041f9322737686846d9. Ermal Luçi
03:51 PM Feature #1603: URL table aliases should be usable within network type aliases
This is probably broken in the case when the urltablealias contents change and pfSense reloads the alias but not its ... Ermal Luçi
03:34 PM Bug #1653 (Feedback): CP timeout bug: get_last_activity
Fixed on next snapshots thanks for reporting. Ermal Luçi
03:17 PM Bug #1653: CP timeout bug: get_last_activity
When I set idletimeout to blank the problem goes away.
When I set timeout to blank and idletimeout to 30, the prob...
Josh Stompro
02:58 PM Bug #1653 (Resolved): CP timeout bug: get_last_activity
Running 2.0-RC3(i386) Jul 4 17:29 Nanobsd.
Captive portal is expiring entries every cycle (60 seconds by default)....
Josh Stompro
03:02 PM Bug #1647 (Closed): Captive portal timeout
Closing in favor of #1653 which has a lot more detail and appears to be the same issue. Jim Pingle
01:13 PM Bug #1647: Captive portal timeout
Please give the captiveportal log when this happens?
Also what is the idle timeout value you configure?
Ermal Luçi
08:50 AM Bug #1647: Captive portal timeout
Tried to unset the proxy transparent mode. Same thing.
Uninstalled squid, same thing.
It seems to log the user out ...
Lo Zio
08:29 AM Bug #1647 (Feedback): Captive portal timeout
Have you tried this without squid installed? And this works normally without an idle timeout defined? Jim Pingle
07:56 AM Bug #1647 (Closed): Captive portal timeout
using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
On captive portal, after setting a IDLE timeout (not t...
Lo Zio
02:55 PM pfSense Packages Bug #1587 (Feedback): The openvpn client configuration exporter doesn't enforce TLS subject verification
Applied in changeset commit:e366b753b24d8cadbe15bc6778e46c3159dc9983. Jim Pingle
12:49 PM Bug #1344: Replace prototype javascript code with jQuery
2.0 has Growl support already. Might be nice to use the jGrowl deal. Scott Ullrich
12:39 PM Bug #1344: Replace prototype javascript code with jQuery
Other Growl style notifications:
-----------------------
jGrowl
URL: http://stanlemon.net/projects/jgrowl.html
...
G D
06:32 AM Bug #1344: Replace prototype javascript code with jQuery
Also another notification bar called foobar http://themergency.com/foobar/ - which is pretty neat.
Then there is als...
Warren Baker
09:40 AM Bug #1648: NAS IP setting
Applied in changeset commit:00243d599dcb840eccf52f39f6d7da28d3605528. Jim Pingle
09:35 AM Bug #1648 (Feedback): NAS IP setting
Applied in changeset commit:54dd98320d569f7f1c6041ec06dfe84c05948161. Jim Pingle
08:08 AM Bug #1648: NAS IP setting
And the data sent to the RADIUS server is ok. It is an interface problem. Lo Zio
07:59 AM Bug #1648 (Resolved): NAS IP setting
Using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
Trying to set:
RADIUS NAS IP attribute
in captive po...
Lo Zio
08:29 AM Bug #1650: IE9 logs off
Confirmed, it does log the user out. Yet another reason not to use IE... :-)
Jim Pingle
08:05 AM Bug #1650 (Resolved): IE9 logs off
using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
Using IE9, clicking Status->Traffic graphs logs the u...
Lo Zio
08:22 AM Bug #1649 (Rejected): Schedule is blocking outside its range instead of passing the traffic
On 2.0 the rules do not have the opposing effect as they did on 1.2.3 when off-schedule. They merely act like they do... Jim Pingle
07:59 AM Bug #1649 (Rejected): Schedule is blocking outside its range instead of passing the traffic
I did some testing with schedules. For this created a schedule to block traffic between 00:00 and 06:00 every day.
B...
A B
08:21 AM Feature #1652 (Closed): Improvements in captive portal page
Using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
In Portal page contents:
- ability to revert to stan...
Lo Zio
08:13 AM pfSense Packages Bug #1651 (Closed): Removing Squidgard removes squid
Removing squidguard version
Beta
1.4_2 pkg v.1.9
platform: 1.1
removes installed squid in an unclean manner.
...
Lo Zio
07:31 AM Feature #1214: Firewall Schedule Time Should Be Allowed to Straddle Midnight
I got the same error again with 2.0-RC3 (amd64) built on Fri Jun 24 19:26:29 EDT 2011.
Could not create a schedule...
A B
06:47 AM Bug #1445: Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
I have the problem too with the RC3 version of pfsense, according to
http://freebsd.1045724.n5.nabble.com/msk0-in...
George M

07/05/2011

09:13 PM Bug #1629: invalid state table entries after WAN IP change
PPPoE is supposed to clear all states on that interface when an IP changes, that's not happening correctly. Chris Buechler
09:00 PM Bug #1629: invalid state table entries after WAN IP change
Hopfully this is what you wanted.
My IP before the address changed was 76.254.18.100 and the new assigned addres...
Eli Hunter
09:11 PM Bug #1646 (Resolved): 'pfctl -b' does not function as intended
'pfctl -b' should selectively kill states for a single IP/gateway, but what it really does is wipe all states (or clo... Chris Buechler
03:16 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I can, on another system, had to remove the one failing from production. Should know something by tomorrow.
Th...
Derrick Conner
03:02 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Can you please test latest snapshots and see if this happends again. Ermal Luçi
02:37 PM Bug #1344: Replace prototype javascript code with jQuery
Another alerting jQuery plugin: http://boedesign.com/demos/gritter/ Scott Ullrich
01:34 PM Bug #1344: Replace prototype javascript code with jQuery
For log/state/etc... tables, I would highly recommend the DataTables jQuery plugin ( http://www.datatables.net ). I h... G D
01:07 PM Bug #1344: Replace prototype javascript code with jQuery
Possible on / off / service buttons: http://www.givainc.com/labs/ibutton_example.htm Scott Ullrich
01:03 PM Bug #1344: Replace prototype javascript code with jQuery
This will be a great alerts replacement: http://www.red-team-design.com/wp-content/uploads/2011/07/cool-notification-... Scott Ullrich
09:07 AM pfSense Packages Bug #1631 (Feedback): incorrect syntax of /boot/loader.conf after open-vm-tools package installed
Jim Pingle
08:53 AM Bug #1642 (Rejected): Occasional Easy rule creation failure when IP == WAN Address
Without a lot more detail this is impossible to track down. Please start a forum thread and see if anyone else has ha... Jim Pingle
01:39 AM pfSense Packages Bug #1640 (Closed): Error to use squidguard with username
Chris Buechler
01:32 AM pfSense Packages Bug #1640: Error to use squidguard with username
Mukesh Patel wrote:
> its not a bug, please try with single or double coat i.e "mpatel" or 'mpatel'
Yes, the user...
Serg Dvoriancev

07/04/2011

07:16 PM Bug #1645 (Rejected): CARP sync problem for deleting process.
not sure what you're referring to, deleting, adding, everything with config sync is working fine on the latest 2.0 ve... Chris Buechler
04:38 PM Bug #1645 (Rejected): CARP sync problem for deleting process.
Can not be sync to backup server for the virtual Ips, nat, load balancer and aliases record deleting process ın the c... Atıf CEYLAN
06:04 AM Bug #1642 (Rejected): Occasional Easy rule creation failure when IP == WAN Address
Applies to: 2.0-RC3 (i396) built on Sun Jul 3 13:02:53 EDT 2011
Attempting to use the "easy rule" feature for Dest...
Cyrus Patel
05:52 AM pfSense Packages Bug #1640: Error to use squidguard with username
its not a bug, please try with single or double coat i.e "mpatel" or 'mpatel' Mukesh Patel
12:32 AM pfSense Packages Bug #1640: Error to use squidguard with username
I'm not sure that's a bug, you should post to the forum for help. Chris Buechler
12:21 AM pfSense Packages Bug #1640 (Closed): Error to use squidguard with username
Hi,
I installed the squidguard module. In SERVICE -> PROXY FILTER -> GROUP ACL, I created an ACL and when I try to...
Alan Testoni
03:40 AM Bug #1549: Sip INVITE dropped.
Evgeny Yurchenko wrote:
> No packet-dumps so far (details are on forum)?
I have been unable to catch the issue ag...
William King
02:13 AM Bug #636: layer7 not work correctly
Latest version has the same problem.
Jul 4 02:15:14 ipfw-classifyd: Loaded Protocol: citrix (rule altq)
Jul 4 02...
Jonathan Puddle
01:04 AM Feature #1603: URL table aliases should be usable within network type aliases
I am sorry, did not pay attention to target version, just felt that it was doable. Evgeny Yurchenko
12:58 AM Feature #1603 (Feedback): URL table aliases should be usable within network type aliases
Evgeny - this is ok but in the future please don't commit anything with a target 2.1 to 2.0. Chris Buechler
12:40 AM Bug #1545: Dynamic DNS updates fail on 3G connections
OK, 3 Jul snapshot managed to keep the interface up over an IP change. Still not updating dynamic DNS:
Jul 4 16:3...
Ross Williamson
12:31 AM Bug #1641 (Resolved): DHCP server default gateway needs input validation
The DHCP server screen allows any IP as the gateway IP, needs input validation there to ensure only IPs within that s... Chris Buechler

07/03/2011

11:47 PM Bug #1639 (Resolved): Port alias missing input validation in firewall_rules_edit.php
A port alias can be assigned only as the "to" or "from" port, which is invalid and results in a pf syntax error. If a... Chris Buechler
11:33 PM Bug #1549: Sip INVITE dropped.
No packet-dumps so far (details are on forum)? Evgeny Yurchenko
08:57 PM Bug #875: Uninstalling packages can remove system libraries
I finally had a opportunity to update my pfSense install at work. And the rrdtool issue with uninstalling the ntop p... David Miller
07:46 PM Bug #1638 (Rejected): Package re-install failure after restore
we're not fixing 1.2.x issues Chris Buechler
07:40 PM Bug #1638 (Rejected): Package re-install failure after restore
After doing a restore from a backup configuration, the packages that I want to have automatically reinstall do not. b... Jordan McDonald
12:45 PM Bug #1635: timeout setting on firewall rules does not work for UDP
I'd assume that the 'udp' timeout is ignored for non-UDP traffic, in the same way as the 'tcp' timeout is ignored for... Adam Gundy
11:02 AM Bug #1635: timeout setting on firewall rules does not work for UDP
Now if I configure this option through gui for different types of traffic I get this:
pass in quick on em0 inet from...
Evgeny Yurchenko
10:27 AM Feature #1603: URL table aliases should be usable within network type aliases
Here is commit https://github.com/bsdperimeter/pfsense/commit/ae660b3ce7d7e2b1f34cb9f1b52eb4ce21e17c42 Evgeny Yurchenko
04:39 AM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
I created this bug describing my problem and its enough for me.
I will wait for the new release.
Thanks
Joao Seabra

07/02/2011

10:00 PM Bug #1629: invalid state table entries after WAN IP change
Please provide state-table dump before IP change and after. Evgeny Yurchenko
09:56 PM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
Then create separate Bug report describing the problem. Evgeny Yurchenko
07:21 PM Bug #1625 (Feedback): installer shouldn't offer to install over boot drive/partition or install bootblocks on boot drive
I have checked in a fix for this.
Scott Ullrich
06:34 PM Bug #1624 (Resolved): installer needs to zero first and last block of disk
Scott Ullrich
06:15 PM Bug #1611 (Closed): DHCP leases show as expired when they shouldn't be
it is that package, uninstall it. It doesn't do anything that isn't in 2.0 base now AFAIK. I disabled it. Chris Buechler
06:12 PM Bug #1611: DHCP leases show as expired when they shouldn't be
Yes, same here, I haven't tried removing it though. Eirik Zakariassen
05:48 PM Bug #1611: DHCP leases show as expired when they shouldn't be
Indeed I do have that package installed! Dainel Spisak
04:15 PM Bug #1611: DHCP leases show as expired when they shouldn't be
MAC-to-vendor does overwrite this page, and I haven't seen this anywhere (also don't have that package installed anyw... Chris Buechler
02:36 PM Bug #1611: DHCP leases show as expired when they shouldn't be
I think this is a bug in the MAC-to-vendor package. remove it and suddenly leases show up correctly. Adam Gundy
04:38 PM Bug #1636: outbound state timeout control not possible?
huh? which filter state?
I agree that you shouldn't have to set the timeout in two different places, but currently...
Adam Gundy
04:10 PM Bug #1636 (Rejected): outbound state timeout control not possible?
NAT states have the same timeout as the filter state and there isn't any scenario where doing otherwise would be a go... Chris Buechler
03:27 PM Bug #1636 (Rejected): outbound state timeout control not possible?
it does not appear to be possible to control the timeout on an outgoing NAT connection.
you can control the settin...
Adam Gundy
04:26 PM Bug #1637: captive portal web service port bind validation issue
forgot to provide pfsense version 2.0-RC3 (i386) built on Fri Jul 1 20:11:57 EDT 2011 ellis melman
04:21 PM Bug #1637 (Needs Patch): captive portal web service port bind validation issue
captive portal uses port 8000 for the web interface but fails to report to the user if the port is already in useby a... ellis melman
02:59 PM Bug #1635 (Resolved): timeout setting on firewall rules does not work for UDP
the 'state timeout' firewall rule setting (under 'advanced options') has no effect on UDP connections. that's because... Adam Gundy

07/01/2011

10:36 PM Bug #1582: traffic shaper queues bug
really think this should be re-opened, there is definitely something wrong with queuing UDP traffic. I find that a s... Philip Wipf
07:25 PM Bug #1624: installer needs to zero first and last block of disk
I added a utility that will zap any prior GPT partitions. This should do the same thing.
Scott Ullrich
07:32 AM Bug #1634 (Duplicate): Limiter and bridge needs special handling
As reported by customers to have working limiters working with bridges its needed to have an ip on the bridge interfa... Ermal Luçi
05:31 AM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
Sorry to insist but the problem showed up after a change in config.I deactivated the interface and when I activated i... Joao Seabra
12:24 AM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
Forgot to mention: now user can always fix the mess he got after several reassignments by going to Interfaces->(assig... Evgeny Yurchenko
12:08 AM Bug #1621 (New): Switching WAN from type PPP to other leaves former port assigned
updated with the real cause, though this isn't ideal and should be improved in the future, its cause is user error, n... Chris Buechler
03:13 AM Bug #1632: Captive Portal changed behaviour
DesktopShare PC is restricted through firewall rules, but this rules were applied only after captive portal authentic... Davide B
02:55 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
This one got me too, going to have to back out one system and go back to 1.2.3, any idea when this will be addressed? Derrick Conner
12:05 AM Bug #1633 (Resolved): Missing input validation in IPv6 gateways
It's possible to pick an IPv4-only interface for your IPv6 gateway, which results in deletion of the default IPv4 rou... Chris Buechler

06/30/2011

11:40 PM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
Whenever you set up WAN to PPP section <ppps><ppp><ports> in config.xml changes to whatever you shoos in "modem port"... Evgeny Yurchenko
05:17 PM Bug #1632 (Rejected): Captive Portal changed behaviour
not a bug, fact of how CP works, that passthrough is required. Chris Buechler
12:44 PM Bug #1632: Captive Portal changed behaviour
Can you provide more information on this?
Your configuration in 1.2.3 and your config in 2.0.
Aslo an architecture ...
Ermal Luçi
12:21 PM Bug #1632 (Rejected): Captive Portal changed behaviour
Hi,
I've upgraded (maintaining the same configuration) a corporate firewall with a "Transit LAN" with corporate netw...
Davide B
09:16 AM Bug #1421 (New): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim Pingle
06:27 AM pfSense Packages Bug #1631: incorrect syntax of /boot/loader.conf after open-vm-tools package installed
Thanks, fixed in changeset commit:d7807cc49fb9c3c28f417c929b19c65c56ec6cb8
Warren Baker
05:55 AM pfSense Packages Bug #1631 (Resolved): incorrect syntax of /boot/loader.conf after open-vm-tools package installed
After vmwate tools package installation, file /boot/loader.conf has inforrect syntax , which prevents kernel modules ... Ivars Strazdins
03:01 AM Feature #1630: lagg ALTQ support
Chris Buechler wrote:
> I don't believe lagg supports ALTQ which is why, it's not as simple as showing that interfac...
Matt Crook
02:23 AM Feature #1630: lagg ALTQ support
I don't believe lagg supports ALTQ which is why, it's not as simple as showing that interface. Chris Buechler
02:19 AM Feature #1630 (Resolved): lagg ALTQ support
when you go to use the wizard "traffic_shaper_wizard_multi_lan.xml" when you are using lagg for your lan, it won't le... Matt Crook
02:54 AM Bug #1628: Static ARP entries need reapplied after link loss
Tested it with embedded and it works! going to apply it to a full version install now. Basel G.

06/29/2011

11:24 PM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
Indeed if you change from PPP to PPPoE you'll have /dev/cuau0 remained in <ports></ports>. Evgeny Yurchenko
10:33 PM pfSense Packages Bug #1626: Snort snort_rules.php drop down only works in Firefox
Can't install snort at all -( Installation fails with
Downloading http://files.pfsense.org/packages/8/All/snortsam...
Evgeny Yurchenko
04:53 PM Bug #1351 (New): Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Some people are still hitting this same error, but not this specific circumstance. Two support customers, plus others... Jim Pingle
03:55 PM Bug #1628 (Feedback): Static ARP entries need reapplied after link loss
Applied in changeset commit:8ee623f3a98dca5681274d6a14450223236b4013. Jim Pingle
12:42 PM Bug #1628: Static ARP entries need reapplied after link loss
yes the only issue is ARP entries are disappearing
I'm power cycling all the switches since we get powercuts and w...
Basel G.
12:31 PM Bug #1628: Static ARP entries need reapplied after link loss
The problem is still with the ARP entries disappearing. That's the only issue here.
Are you power cycling the indi...
Jim Pingle
12:29 PM Bug #1628: Static ARP entries need reapplied after link loss
My setup is like this: about 20 switches serving around 150 clients connected through LAN, when I do a power cycle on... Basel G.
12:18 PM Bug #1628: Static ARP entries need reapplied after link loss
The problem with Static ARP is its locking out everyone listed when they disconnect and try to reconnect, maybe its r... Basel G.
11:08 AM Bug #1628: Static ARP entries need reapplied after link loss
Deny Unknown Clients only affects the DHCP server giving out IPs to clients that are not listed. A client can hardcod... Jim Pingle
11:04 AM Bug #1628: Static ARP entries need reapplied after link loss
small clarification about "Deny unknown hosts", if users are using a static IP they can bypass this if they are not i... Basel G.
08:06 AM Bug #1628 (Resolved): Static ARP entries need reapplied after link loss
Enabling static ARP in DHCPD causes the ARP table to get cleared if a disconnect happens to switches/clients connecte... Basel G.
11:01 AM Bug #1629 (Resolved): invalid state table entries after WAN IP change
We have an asterisk server behind pfsense 2.0-RC3 using a PPPoE DSL connection.
Whenever our WAN IP changes the aste...
Eli Hunter
08:20 AM Bug #1534 (Resolved): rc.newwanip issues (CARP slave problems, package issues)
Chris Buechler
04:48 AM Bug #1534: rc.newwanip issues (CARP slave problems, package issues)
Unfortuntely I can't drop IPv6 support on my machines. I'm currently running 2.0-RC3-IPv6 (amd64) built on Mon Jun 27... Marcin Krol
04:24 AM Bug #636: layer7 not work correctly
Updated to the latest version, but logging is busted, so I can't say what's happening. (There's a bunch of comments i... Jonathan Puddle
03:22 AM Bug #1627 (Feedback): VPN VOIP Traffic Ignoring Traffic Shaper Queues
Chris Buechler
03:22 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
what version? what type of VPN? Chris Buechler
02:06 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
is it this that ur referring to?
http://forum.pfsense.org/index.php/topic,36742.0.html
Bipin Chandra
03:15 AM Bug #1545: Dynamic DNS updates fail on 3G connections
I'm having trouble keeping the 3G connection active. It is now deciding to get stuck in PPP "Initial" state on IP cha... Ross Williamson

06/28/2011

08:30 PM Bug #1627 (Resolved): VPN VOIP Traffic Ignoring Traffic Shaper Queues
I have a VPN setup for remote employees. The VOIP traffic usually goes to the VOIP queue between our PBX and the VOIP... Abdiel Marin
04:10 PM Bug #636: layer7 not work correctly
Can you please test with latest snapshots? Ermal Luçi
02:20 PM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
No,I din't configure pfsense to use /dev/cua0.What happened was that I changed WAN type to DHCP,PPP,etc and saved tho... Joao Seabra
02:43 AM pfSense Packages Bug #1626 (Closed): Snort snort_rules.php drop down only works in Firefox
snort_rules.php?id=X drop down seems to have taken its code from our old interfaces drop down on firewall_rules.php a... Chris Buechler

06/27/2011

10:38 PM Bug #1622 (Rejected): Loss of connectivity and response from pfSense system in 2.0 RC3
there isn't a general problem with systems dropping offline, and this doesn't have a specific problem hence isn't a v... Chris Buechler
02:57 PM Bug #1622 (Rejected): Loss of connectivity and response from pfSense system in 2.0 RC3
Running a "fresh" 2.0 RC3 AMD64 install on a system with 4 Gig of RAM and an Intel EXPI9402PT Dual Port NIC. After so... Justin Mitchell
07:59 PM Bug #1572: DHCP + MAC spoofing leads to link cycling
this has never worked in any 8.x base versions, it's a problem in FreeBSD 8.x. It's intermittent, I ran that way for ... Chris Buechler
07:56 PM Bug #1572: DHCP + MAC spoofing leads to link cycling
I'm facing the same problem with the latest snapshots for the past 4 days, also "Deny unkown hosts" doesn't do as it ... Basel G.
05:44 PM Bug #1623 (Closed): Redirect in System : Advanced loses port number
works as it should, if a non-default port is specified that's where the redirect goes, if there isn't a port specifie... Chris Buechler
05:18 PM Bug #1623 (Closed): Redirect in System : Advanced loses port number
Making a change under system_advanced_admin.php results in a delayed redirect. This redirect forgets to add a port nu... Bill McGonigle
05:38 PM Bug #1625: installer shouldn't offer to install over boot drive/partition or install bootblocks on boot drive
Please test the new installer located at /installer on 2.0.
There are no plans to further develop the LUA based in...
Scott Ullrich
05:30 PM Bug #1625 (Resolved): installer shouldn't offer to install over boot drive/partition or install bootblocks on boot drive
When running the installer from rw media (pfsense-memstick image in this case) the installer offers the drive/partiti... Bill McGonigle
05:28 PM Bug #1624: installer needs to zero first and last block of disk
Please test the new installer located at /installer on 2.0.
There are no plans to further develop the LUA based in...
Scott Ullrich
05:26 PM Bug #1624 (Resolved): installer needs to zero first and last block of disk
I've seen some problems installing pfSense 2 on previously used disks.
In one case I had a disk which just minutes...
Bill McGonigle
02:54 PM Bug #1611: DHCP leases show as expired when they shouldn't be
I also have this issue, running
2.0-RC3 (i386)
built on Sun Jun 26 20:44:17 EDT 2011
Running Pfsense on Vmwa...
Eirik Zakariassen
09:43 AM pfSense Packages Bug #1620: Can't use transparent proxy when using bridge.
It's not a squid issue, its a nat/rdr issue.
As I told even creating a rdr rule, I cant't see any traffic going to...
Marcello Silva Coutinho

06/26/2011

07:30 PM Bug #1621 (Feedback): Switching WAN from type PPP to other leaves former port assigned
You have it configured to use /dev/cuau0 so no, it won't use re0 since it's not configured to do so. You must have ed... Chris Buechler
06:54 PM Bug #1621: Switching WAN from type PPP to other leaves former port assigned
attach your config or can email it to me (cmb at pfsense dot org) Chris Buechler
06:50 PM Bug #1621 (Closed): Switching WAN from type PPP to other leaves former port assigned
replacing description with actual problem found by Evgeny:
Whenever you set up WAN to PPP section <ppps><ppp><por...
Joao Seabra
11:05 AM Bug #1615: rrd graph not refreshing the correct time frame
Commit https://github.com/bsdperimeter/pfsense/commit/0da02ef5d99de2c04846934b0cd7504e9e880eec.
ststus_rrd_graph_img...
Evgeny Yurchenko

06/25/2011

03:14 AM pfSense Packages Bug #1620 (New): Can't use transparent proxy when using bridge.
Can't foward any package To localhost while using bridge and setting ip address only on new bridge interface.
Sam...
Marcello Silva Coutinho
02:56 AM Bug #1619: crontab wrong expiretable check time
Ir Does not make sense. Why configure an Option To expire in 60 minutes but not in 60 minutes.
If i want To limit co...
Marcello Silva Coutinho

06/24/2011

11:16 PM Bug #1619 (Rejected): crontab wrong expiretable check time
it's not designed to expire them after exactly an hour and has no need for doing so. Running it more frequently would... Chris Buechler
09:59 PM Bug #1619 (Rejected): crontab wrong expiretable check time
**/60 * * * * root /usr/bin/nice -n20 /usr/local/sbin/expiretable -v -t 3600 sshlockout*
**/60* checks...
Marcello Silva Coutinho
01:51 PM Bug #1336: PPTP VPN NAT on WAN or other external interface
I can confirm Jim P's analysis. On VMWare, i386 works fine, amd64 does not. R W
09:39 AM Bug #1605: DHCP Server should group known clients by interface
Yeah that may be fine then, though the code to implement this should not use .0, but mathematically calculate the nul... Jim Pingle
09:25 AM Bug #1605: DHCP Server should group known clients by interface
This is what it does:
01:18:15.819317 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 08:00:27:a6:50:bf...
Evgeny Yurchenko
09:10 AM Bug #1605: DHCP Server should group known clients by interface
It still does its ping test to ensure an IP is open before assignment, though I suppose on .0 in a /24 that would fai... Jim Pingle
08:56 AM Bug #1605: DHCP Server should group known clients by interface
Just tested with
host s_lan_0 {
hardware ethernet 08:00:27:e5:68:94;
fixed-address 192.168.56.99,...
Evgeny Yurchenko
07:49 AM Bug #1605: DHCP Server should group known clients by interface
That hack might work for the first client to connect in a subnet, but if two of them crossed at once it would not ass... Jim Pingle
04:03 AM Bug #1605: DHCP Server should group known clients by interface
@Evgeny:
Uuh, nice hack. Accepted! But I don't think it's really easy to implement. Every time, someone creates/modi...
Willy Tenner
08:24 AM Bug #1572: DHCP + MAC spoofing leads to link cycling
I encountered the same problem. Enabling MAC spoofing on WAN Interface using DHCP will instantly trigger link cycling... Daniel Bernhardt
08:23 AM Bug #1618 (Resolved): Captive portal: Invalid AVP value in Radius accounting packet
Hello,
Using captive portal, with Radius authentication and accounting enabled, my server (tinyradius java lib) co...
Serge ALEXANDRE
05:27 AM Bug #1334: Traffic Shaper Rules ignored
is this the same as
http://redmine.pfsense.org/issues/1582
for more info
http://forum.pfsense.org/index.php/topi...
Bipin Chandra
05:18 AM Bug #1582: traffic shaper queues bug
i compared an old config file with the current one and didnt notice any major change in the queues and rules, should ... Bipin Chandra

06/23/2011

11:30 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Just updated to 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011 which has the patch that Jim P linked to - same... David Rees
11:02 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim P wrote:
> Try it with commit:90ecc0b62f8b363d9497b4754133738edb9bc633
I have tried this on a "2.0-RC1 (amd64...
David Rees
10:28 PM pfSense Packages Bug #1609: unable to install Avahi
The tgz is an ugly mess that needs to die. It really needs to install properly from the package system. It may just n... Jim Pingle
10:23 PM pfSense Packages Bug #1609: unable to install Avahi
Maybe we should remove
<depends_on_package>avahi-0.6.28.tbz</depends_on_package>
from pkg_config.8.xml.amd64 as it...
Evgeny Yurchenko
09:45 PM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
it was actually fixed a while back, I just missed the fact the file was still there, it's not an issue Chris Buechler
09:44 PM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
Tried to reproduce:
# echo test >/etc/rc.d/test
# chmod 555 /etc/rc.d/test
Install iperf package: /etc/rc.d/test i...
Evgeny Yurchenko
09:22 PM Bug #1605: DHCP Server should group known clients by interface
We are running dhcpd-4.2.1-P1 which supports grouping. The problem is 'host' cannot be related with 'subnet' (I tried... Evgeny Yurchenko
09:19 PM Bug #1437: More validation needed on CSR generation
I will test this on or right after July 4th. I will not have internet access between tomorrow and then (working at a ... Yehuda Katz
08:30 PM Bug #1437: More validation needed on CSR generation
Errors handling added:
https://github.com/bsdperimeter/pfsense/commit/95c8cf48f9bd72da5371aa01a03a070885411dbf
http...
Evgeny Yurchenko
05:37 PM Bug #1611: DHCP leases show as expired when they shouldn't be
Chris, here is the dhcp.leases:
# more /var/dhcpd/var/db/dhcpd.leases
# The format of this file is documented in ...
Dainel Spisak
10:58 AM Bug #1611: DHCP leases show as expired when they shouldn't be
Can't replicate.
I configured 3 VLAN on my LAN beside my untagged LAN. Every thing on em1
em1:192.168.10.0/24
...
rancor rancor
02:34 PM pfSense Packages Bug #1616: Dell R210 incompatibility
How long did you let the system install at 38%? This is the longest step in the installer and it does not give a lo... Scott Ullrich
02:33 PM pfSense Packages Bug #1616 (Rejected): Dell R210 incompatibility
we don't track hardware-specific issues as there isn't anything we can do about them. Chris Buechler
05:52 AM pfSense Packages Bug #1616 (Rejected): Dell R210 incompatibility
I bought 2 Dell R210 and with all pfSense versions there's no way to install it!
With pfSense-2.0-RC3-amd64-201106...
Davide B
02:21 PM Bug #259 (Resolved): When disabling a dhcp interface, dhclient is not stopped
Ermal Luçi
02:14 PM Bug #259: When disabling a dhcp interface, dhclient is not stopped
It seems to work now.
Before I disable vlan203 the dhclient is running
$ ps ax | grep dhclient
8629 ?? Is ...
rancor rancor
02:09 PM Bug #1341 (Resolved): Removing last host from alias does not truly remove it, host continues to be affected by rules
Ermal Luçi
01:58 PM Bug #1341: Removing last host from alias does not truly remove it, host continues to be affected by rules
It seems to work now
Tested to reproduce with version 2.0 RC3 date 23 june 2011 and as quick as I remove the host ...
rancor rancor
02:06 PM Bug #455: On initial wizard reload button do not put browser on new assigned ip.
What is the needed feedback? I want to test fixes but there does not seems to be neither a fix nor a question
// r...
rancor rancor
01:08 PM Bug #1156 (Closed): Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
Thanks for the update! Scott Ullrich
01:05 PM Bug #1156: Upgrade from 1.2.3 to 2.0 with VMware tools installed will panic
It works for me with 2.0 RC3 - snapshot dated 23 june 2011
I just tested with a fresh install with pfSense-1.2.3-R...
rancor rancor
11:10 AM Bug #875: Uninstalling packages can remove system libraries
I just committed a change that should hopefully preserve rrdtool. Please test the next snapshot run. Scott Ullrich
11:05 AM Bug #875: Uninstalling packages can remove system libraries
Uninstalling the ntop package results in the removal of rrdtool, possibly others as it does have a long list of depen... David Miller
10:54 AM pfSense Packages Bug #1617 (Rejected): Uninstalling ntop package removes rrdtool
Already covered under #875 - add a note on that ticket instead of opening a new ticket. Jim Pingle
10:52 AM pfSense Packages Bug #1617 (Rejected): Uninstalling ntop package removes rrdtool
Subject pretty much sums it up. If you install and then uninstall the ntop package the rrdgraphs will stop working. ... David Miller
08:52 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Checked on 2.0-RC3 (amd64) built on Wed Jun 22 23:09:34 EDT 2011:
Dis-/re-enabling CARP is an issue even with no I...
Andreas Bochem
05:48 AM pfSense Packages Bug #1164: Installing pfSense 2.0 on a Dell PowerEdge R210
I bought 2 Dell R210 and with all pfSense versions there's no way to install it!
With pfSense-2.0-RC3-amd64-201106...
Davide B
02:08 AM Bug #1582: traffic shaper queues bug
queues adnd rules both created manually, no wizard used and it used to work also earlier but just went dead in newer ... Bipin Chandra

06/22/2011

11:25 PM Bug #1582 (Closed): traffic shaper queues bug
config issue not bug, UDP queues as configured (though probably related to general wizard issue covered by another ti... Chris Buechler
08:29 PM Bug #1377: upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
4GB
I worked around this by physically going to the unit and reload the card with a 4G 2-RC1 image.
Bill McIlhargey
12:52 PM Bug #1377: upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
Is this specific to the 4GB size? I just did a manual update of a 1GB system and it had no problems upgrading that I ... Jim Pingle
07:06 PM Bug #1613: OpenVPN LDAP authentication should not modify mail attribute as login.
I've just realised my example is not a good one - in the company that I work for, our email addresses are in the form... Deon George
08:28 AM Bug #1613: OpenVPN LDAP authentication should not modify mail attribute as login.
The HTML (or something) has parsed my "description" and removed the "at" character. So all references to '' (double q... Deon George
08:25 AM Bug #1613 (Resolved): OpenVPN LDAP authentication should not modify mail attribute as login.
I have setup an LDAP user directory, using mail as the unique search key (to find users). In the organisation I work ... Deon George
02:55 PM Bug #1614 (Feedback): "pptp clients" macro for firewall rules does not work
Applied in changeset commit:ff629977e3d45c1d41fc12449e647abd8b780241. Jim Pingle
02:28 PM Bug #1614 (Resolved): "pptp clients" macro for firewall rules does not work
Using the "pptp clients" entry in the drop-down list for firewall rules does not work. It does not match/pass traffic... Jim Pingle
02:31 PM Bug #1615 (Resolved): rrd graph not refreshing the correct time frame
The javascript is correctly triggering to refresh the rrd graphs, but the start and end time passed to the graphing s... Seth Mos
12:52 PM Bug #1554: Voucher page turns grey after parameter change
Oops, still on RC1. I don't know RC3 is out. When I log on, I can see:
***
2.0-RC1 (i386)
built on Sat Feb 26 1...
Pavel Pilat
12:34 PM Bug #1554: Voucher page turns grey after parameter change
It happened again today with what version? As Chris said you should be running 2.0-RC3. Scott Ullrich
12:29 PM Bug #1554: Voucher page turns grey after parameter change
make sure you're on RC3, a number of voucher-related things have been fixed since RC1. Chris Buechler
11:14 AM Bug #1554: Voucher page turns grey after parameter change
... and again! After I restored the voucher functionality using previous config file, we managed to set up only one v... Pavel Pilat
08:48 AM Bug #1554: Voucher page turns grey after parameter change
Today it happened again - I had to restore older config. It is OK after restart. Pavel Pilat
05:02 AM Bug #1612 (Closed): Custom scripts in /usr/local/etc/rc.d get deleted
nevermind, I apparently can't see straight this morning, the file is still there... it shifted positions in ls becau... Chris Buechler
03:57 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
I investigated this and i cannot see in any place in pfSense base code something like that being done apart
the sect...
Ermal Luçi
03:15 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
Yeah I thought it was, but it happens on the newest snapshot. Chris Buechler
03:11 AM Bug #1612: Custom scripts in /usr/local/etc/rc.d get deleted
You are sure to be on latest version.
I recall this happened during package improvements and i fixed this regression...
Ermal Luçi
12:39 AM Bug #1612 (Closed): Custom scripts in /usr/local/etc/rc.d get deleted
The package reinstall process (it appears) deletes unknown startup scripts in /usr/local/etc/rc.d/ which is commonly ... Chris Buechler
04:58 AM Bug #944 (Resolved): Moving VLANs to lagg doesn't remove old VLANs
thanks Chris Buechler
04:19 AM Bug #944: Moving VLANs to lagg doesn't remove old VLANs
confirm fixed in 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011 Andreas Bochem
04:57 AM Bug #1602 (Resolved): diag_arp.php hangs when DNS server unreachable
Chris Buechler
04:49 AM Bug #1602: diag_arp.php hangs when DNS server unreachable
Looks good on 2.0-RC3 (amd64) built on Tue Jun 21 23:37:22 EDT 2011.
My current test system does not have a workin...
Andreas Bochem

06/21/2011

03:09 PM Bug #636: layer7 not work correctly
Hrm i see.
Thank you for the info.
Actually you cannot use the root queue in there and i will try to fix the interf...
Ermal Luçi
06:18 AM Bug #636: layer7 not work correctly
Pretty basic, as you can see. And the system logs still display:
Jun 20 23:49:07 ipfw-classifyd: Loaded Protocol:...
Jonathan Puddle
06:17 AM Bug #636: layer7 not work correctly
<l7shaper>
<container>
<name>test</name>
<enabled>on</enabled>
<description/>
<divert_port>41744<...
Jonathan Puddle
08:25 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Hafiz Rafiyev wrote:
> Jim same problem is continued ,i have to restart racoon service after pptp client disconnect,...
Hafiz Rafiyev
06:58 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim same problem is continued ,i have to restart racoon service after pptp client disconnect,here is log.
Jun 21 1...
Hafiz Rafiyev
05:46 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Harry Gonzalez wrote:
> Luca Sari wrote:
> > I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:...
Luca Sari
03:16 AM Bug #1601 (Resolved): Authentication page loop
Confirmed on the forums. Ermal Luçi
03:14 AM Bug #1602 (Feedback): diag_arp.php hangs when DNS server unreachable
Ermal Luçi

06/20/2011

06:24 PM Bug #1611 (Feedback): DHCP leases show as expired when they shouldn't be
what does your /var/dhcpd/var/db/dhcpd.leases look like? Chris Buechler
06:15 PM Bug #1611 (Closed): DHCP leases show as expired when they shouldn't be
Running on 2.0-RC3 (i386) built on Sun Jun 19 21:45:34 EDT 2011, I have a system with multiple VLAN's on the LAN side... Dainel Spisak
05:19 PM Bug #1545: Dynamic DNS updates fail on 3G connections
You need to update since this is a bug fixed in latest snapshots of check_reload_Status. Ermal Luçi
04:05 PM Bug #1421 (Feedback): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim Pingle
04:05 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Try it with commit:90ecc0b62f8b363d9497b4754133738edb9bc633 Jim Pingle
03:59 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Chris Buechler wrote:
> We can't replicate this, I can connect and disconnect PPTP all day long and IPsec never drop...
Harry Gonzalez
03:51 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Harry it's so simple to replicate the bug.
Steps to replicate bug.
1)Make ipsec VPN tunnel between 2 PF 2.0RC2,...
Hafiz Rafiyev
10:33 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Luca Sari wrote:
> I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:42 EDT 2011 running under v...
Harry Gonzalez
06:24 AM Bug #1607: MBUF usage grows geometrically
The RRD graphs mostly didn't survive the config restore, so the screenshot is the best I can do. I had firewall set t... David Burgess

06/19/2011

11:52 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I've got the same problem on a 2.0-RC2 (i386)built on Mon Jun 6 00:12:42 EDT 2011 running under vmWare.
the problem ...
Luca Sari
11:39 AM Bug #1607: MBUF usage grows geometrically
Of those I would probably be most inclined to point a finger an mlppp since it's the least common used feature among ... Jim Pingle
12:45 AM Bug #1607: MBUF usage grows geometrically
Summary:
7 lines mlppp
2 em NICs
14 or so vlans on both NICS, total
openvpn client
no packages currently insta...
David Burgess
 

Also available in: Atom