Project

General

Profile

Activity

From 07/04/2011 to 08/02/2011

08/02/2011

09:37 PM Bug #611: Firmware upgrade error: "There has been an error verifying the signature on this image."
It's a refreshing issue. If you chenga the update url to something than change it back, it works. Filipe Vieira
09:33 PM Bug #611: Firmware upgrade error: "There has been an error verifying the signature on this image."
This problem occurs on pfSense 2 RC3. I have checked "Allow auto-update firmware images with a missing or invalid dig... Filipe Vieira
09:25 PM Revision e9df45f0: Oops fix variable name
Ermal LUÇI
09:25 PM Revision e56a7306: Blacklist lan as being used as default gateway when auto switching is on. This prevents some problems in general functionality with services.
Ermal LUÇI
09:24 PM Revision 4ac9cdf2: Oops fix variable name
Ermal LUÇI
09:24 PM Revision 0fea7000: Blacklist lan as being used as default gateway when auto switching is on. This prevents some problems in general functionality with services.
Ermal LUÇI
09:17 PM Revision b0d088eb: Correctly check the values for VoIP on multi_lan traffic shaper wizard. Reported-by: http://forum.pfsense.org/index.php/topic,32833.15.html. Ticket #1728
Ermal LUÇI
09:15 PM Revision 834a3e6a: Correctly check the values for VoIP on multi_lan traffic shaper wizard. Reported-by: http://forum.pfsense.org/index.php/topic,32833.15.html. Ticket #1728
Ermal LUÇI
08:32 PM Bug #1629: invalid state table entries after WAN IP change
I just copied the system log page and state table in attached document.
Would collecting the data with a syslog se...
Eli Hunter
08:32 PM Revision 9afdf058: Correct the link to index.php so it always works correctly.
Ermal LUÇI
08:31 PM Revision ea858be0: Correct the link to index.php so it always works correctly.
Ermal LUÇI
07:59 PM Revision 233e2af1: If no pppoe service name is configured, send a null service name. Seems to help clients especially when reconnecting.
Jim Pingle
07:57 PM Revision 5c5d2cad: If no pppoe service name is configured, send a null service name. Seems to help clients especially when reconnecting.
Jim Pingle
02:55 PM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
Does this happen on current snapshots? I can't reproduce this in a VM. Jim Pingle
08:14 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I also upgraded new snap today,but nothing changed.Ermal you can test yourself ipsec drop after pptp client disconnec... Hafiz Rafiyev
08:00 AM Revision eea89a5c: Declare the arrays as global since that is what they are. Correct the name of asterisk in the global defniition.
Ermal LUÇI
07:59 AM Revision a7951d4a: Declare the arrays as global since that is what they are. Correct the name of asterisk in the global defniition.
Ermal LUÇI
07:47 AM Revision b3795cb9: Correct battlenet data to not be overriden. Reported-by: http://forum.pfsense.org/index.php/topic,39176.0.html
Ermal LUÇI
07:47 AM Revision 3adc6769: Correct battlenet data to not be overriden. Reported-by: http://forum.pfsense.org/index.php/topic,39176.0.html
Ermal LUÇI
03:48 AM Bug #1736 (Closed): Allow other users to be used as authenticator in xmlrpc exchanges
Presently only admin user, hardcoded, can allow the sync of the user data through xmlrpc.
It would need to be done...
Ermal Luçi
12:11 AM Bug #1572: DHCP + MAC spoofing leads to link cycling
I now wonder if it's also this:
http://forum.pfsense.org/index.php/topic,36643.0.html
if so, I can reproduce but al...
Derrick Brashear

08/01/2011

06:15 PM Revision 6ecb52bd: Start hostid
Scott Ullrich
06:15 PM Revision 1fd3fe31: Start hostid
Scott Ullrich
02:44 PM Bug #1027: Config restore triggers HTTP_REFERER check on interface mismatch
2.0-RC3 (i386)
built on Sun Jul 31 05:05:32 EDT 2011
Same as Braden, changed interface, swap WAN and OPT1. Chang...
jikjik lim
03:02 AM Bug #1027: Config restore triggers HTTP_REFERER check on interface mismatch
This is happening to me on 2.0 RC3, nanobsd, with a clean install.
Steps to reproduce:
changed interface defs via...
Braden McGrath
02:19 PM Bug #1729: IMSpector-wip is missing some files for install
Looks like the package build system got an updated MySQL port. Working on it now. Thanks! Bill Marquette
02:18 PM Bug #1729 (Assigned): IMSpector-wip is missing some files for install
Bill Marquette
02:11 PM Bug #1121: wireless interface antenna settings not applied at boot
i never put anything manually coz i have no knowledge in freebsd etc, i dont even know where the config file is store... Bipin Chandra
12:45 PM Bug #1121 (Closed): wireless interface antenna settings not applied at boot
Nothing puts them in the config. You had to have done that manually. Jim Pingle
12:43 PM Bug #1121: wireless interface antenna settings not applied at boot
i removed that line and rebooted, so far the antenna settings r applied, let me test for further 24hrs and if its rem... Bipin Chandra
12:09 PM Bug #1121: wireless interface antenna settings not applied at boot
For starters, in that config you have:... Jim Pingle
11:56 AM Bug #1121: wireless interface antenna settings not applied at boot
i just use one card at a time that too as a access point only and nothing fancy, i have tried clearing the config and... Bipin Chandra
11:46 AM Bug #1121: wireless interface antenna settings not applied at boot
I am not sure what else might be relevant - If the code did not work, it would be broken for everyone, not just you.
...
Jim Pingle
11:43 AM Bug #1121: wireless interface antenna settings not applied at boot
what info can i provide for analysis coz i have 2 atheros cards and both the same, both different makes but same athe... Bipin Chandra
11:13 AM Bug #1121: wireless interface antenna settings not applied at boot
There may be something specific to your card or config going on then, as no matter what I do, the settings always app... Jim Pingle
10:45 AM Bug #1728 (Resolved): Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
http://forum.pfsense.org/index.php/topic,32833.15.html Ermal Luçi
03:01 AM Bug #1734 (Feedback): Traffic Shaper Issues in resent builds
Seems like you are using PRIQ as a discipline.
Can you please check that putting the bandwidth of the physical inter...
Ermal Luçi
01:59 AM pfSense Packages Bug #1735 (Resolved): Tinydns load balancing not working
Chris Buechler
01:58 AM pfSense Packages Bug #1735: Tinydns load balancing not working
Verified. Thanks Heinrich Lee Yu
01:53 AM pfSense Packages Bug #1735 (Feedback): Tinydns load balancing not working
Merged in github, thanks, please verify. Chris Buechler

07/31/2011

11:51 PM pfSense Packages Bug #1735 (Resolved): Tinydns load balancing not working
When specifying extra IP addresses for failover and load balancing, failover works but load balancing doesnt.
Actu...
Heinrich Lee Yu
02:20 PM Bug #1730: DHCP Failover
Jim, thanks for the update. No one responded to my forum post and I must have missed the fix since build 2.0-RC3 Buil... Chris Mirchandani
12:00 PM Bug #1730 (Rejected): DHCP Failover
Check your /tmp/rules.debug. We already have code in place to account for that.... Jim Pingle
11:48 AM Bug #1730 (Rejected): DHCP Failover
Running 2.0-RC3 Built On: Sun Jul 24 04:39:44 EDT 2011
I have discovered that I have to manually allow access to p...
Chris Mirchandani
12:49 PM Bug #1734 (Closed): Traffic Shaper Issues in resent builds
I am using the AMD64 builds of pfSense 2.0 RC3. I have the same build running on dedicated hardware and in a VM with ... Chris Mirchandani
12:10 PM Bug #1732 (Rejected): CARP does not Failover on all interfaces
Please post on the forum to rule out configuration errors. I have just tested all that in a VM pair this week and it ... Jim Pingle
12:06 PM Bug #1732 (Rejected): CARP does not Failover on all interfaces
I am using the AMD64 builds of pfSense 2.0 RC3. I have the same build running on an dedicated hardware and in a VM wi... Chris Mirchandani
11:55 AM Bug #1731 (Resolved): Hostnames are not allowed access when using an Alias in an Alias
I am using the AMD64 builds of pfSense 2.0 RC3. I have the same build running on dedicated hardware and in a VM with ... Chris Mirchandani
03:57 AM Bug #1121: wireless interface antenna settings not applied at boot
i use the below command to check the applied settings
sysctl dev.ath
then i set them properly by using
sysctl de...
Bipin Chandra

07/30/2011

12:17 PM Bug #708: Need more checks for dns rebind issue
Chris Buechler wrote:
> That's impossible because 5 will never happen, browsers' internal DNS caches don't come anyw...
Cyrus Patel
08:25 AM Bug #1728: Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
Using the build 2.0-RC3 (i386)
built on Fri Jul 29 22:08:01 EDT 2011
Still seeing the same error messages. Have se...
Tony Graziano
12:19 AM Revision 43086fae: Max procs should be 1 when using an op code cacher
Scott Ullrich
12:17 AM Revision 94436824: Max procs should be 1 when using an op code cacher
Scott Ullrich

07/29/2011

08:00 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Hafiz Rafiyev wrote:
> Ermal Luçi wrote:
> > I have put a fix in latest snapshots.
> >
> > @Hafiz Rafiyev,
> > ...
Hafiz Rafiyev
01:18 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> I have put a fix in latest snapshots.
>
> @Hafiz Rafiyev,
> i have put the fix on your box s...
Hafiz Rafiyev
04:48 PM Revision a3cc48b7: Silence pfctl -d errors
Scott Ullrich
04:47 PM Revision 02edeac5: Silence pfctl -d errors
Scott Ullrich
11:41 AM Bug #1728: Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
ezshaper part of config.xml attached. Tony Graziano
10:57 AM Bug #1728: Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
The ezshaper part not the shaper part. Ermal Luçi
09:35 AM Bug #1728: Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments

<shaper>
<queue>
<interface>wan</interface>
<name>wan</name>
<scheduler>CBQ</scheduler>
<bandwidth>2<...
Tony Graziano
09:15 AM Bug #1728: Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
Can you provide the ezshaper from config.xml that caused this? Ermal Luçi
09:00 AM Bug #1728 (Resolved): Shaper wizard not defining queues properly, doesn't shape manually by floating, ip or voip assignments
When running through the wizard for shaping, the following occurs when applying the configuration:
29 08:43:38 php...
Tony Graziano
09:39 AM Bug #1729 (Resolved): IMSpector-wip is missing some files for install
See below error while installing the package:
Downloading http://files.pfsense.org/packages/8/All/mysql-client-...
Cino .
09:24 AM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
See here:
http://doc.pfsense.org/index.php/Tuning_and_Troubleshooting_Network_Cards
Jim Pingle
06:20 AM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
hw.pci.enable_msix Ermal Luçi
08:56 AM Bug #1727: No default nor static routes after reboot.
Sorry, I was migrating from smos ipv6 git and I was on an old update URL (http://snapshots.pfsense.org/FreeBSD_RELENG... Alexis Olivier
07:13 AM Bug #1727 (Rejected): No default nor static routes after reboot.
Please use snapshots from upgrading since binary can change during commits.
go grab latest snapshot and use that to ...
Ermal Luçi
06:57 AM Bug #1727 (Rejected): No default nor static routes after reboot.
After a gitsync and a reboot, i get no static nor default routes added on launch.
I got the error :...
Alexis Olivier
07:18 AM Revision d7894259: fix text
Chris Buechler
07:17 AM Revision 73800013: fix text
Chris Buechler
07:14 AM Revision 32363c2e: Merge branch 'master' of github.com:bsdperimeter/pfsense
Chris Buechler
03:04 AM Bug #1121: wireless interface antenna settings not applied at boot
for me i have set diversity off and tx/rx to 1 but after boot those values r all 0 and even after leaving it as it is... Bipin Chandra
01:12 AM Feature #1726 (Resolved): Allow disabling the "Autonomous address-configuration"
You should add a checkbox allowing to disable the "Autonomous address-configuration", setting the rtadvd option "pinf... Chris Buechler
01:09 AM Bug #1725 (Resolved): DHCPv6 non-common bitmask shows incorrect range
On the DHCPv6 page, when you have a non-common bitmask, showed range is incorrect. Example:
Address ...
Chris Buechler

07/28/2011

11:05 PM Bug #1724 (Feedback): Adding new gateway throws JS error in Chrome
can't replicate with the latest version of Chrome on OS X, looks like problem with your Chrome (cache maybe, especial... Chris Buechler
10:54 PM Bug #1724 (Closed): Adding new gateway throws JS error in Chrome
I just did a clean install-to-disk of pfSense 2.0-RC3.
When I went to the WAN page.
I selected the "add" new gate...
Christian Höltje
08:56 PM Revision 31a15efb: Add an override for default interval to send icmp
Ermal LUÇI
08:56 PM Revision f7203985: Add an override for default interval to send icmp
Ermal LUÇI
08:45 PM Revision 8687d2ba: Clarify notes for pptp "Server address"
Jim Pingle
08:45 PM Revision 6d1ae23c: Clarify notes for pptp "Server address"
Jim Pingle
08:35 PM Revision db07cc25: Fix status page of gateways to show gateways with monitoring disabled as up.
Ermal LUÇI
08:35 PM Revision 253591c7: Fix status page of gateways to show gateways with monitoring disabled as up.
Ermal LUÇI
08:31 PM Revision 33c06ef7: Add a new option to allow disabling of gateway monitoring. This gateways will always be reported as up.
Ermal LUÇI
08:31 PM Revision b8873098: Add a new option to allow disabling of gateway monitoring. This gateways will always be reported as up.
Ermal LUÇI
07:58 PM Revision b9f98526: Use route change here as well to avoid leaving the routing table without a destination for a short period.
Ermal LUÇI
07:58 PM Revision 4c41b626: Use route change here as well to avoid leaving the routing table without a destination for a short period.
Ermal LUÇI
07:45 PM Revision 3e8fad13: Rework rc.stop_packages a little. Fixes #1564
Jim Pingle
07:44 PM Revision 0124456b: Rework rc.stop_packages a little. Fixes #1564
Jim Pingle
07:35 PM Revision e151744e: Just break states based on the remote host ip and not with localip. The later might be the same as address used by other services and might interrupt them
Ermal LUÇI
07:35 PM Revision dfd9c31d: Just break states based on the remote host ip and not with localip. The later might be the same as address used by other services and might interrupt them
Ermal LUÇI
06:33 PM Revision 77877238: Move the textarea displaying packet capture outside of the form tag, or else a browser will try to submit the contents of the textarea when hitting a button. If you were viewing a large capture, that can be quite a long time it's wasting on uploading data that serves no purpose.
Jim Pingle
06:33 PM Revision 89fae3e7: Fix whitespace formatting
Jim Pingle
06:31 PM Revision 5ab25db0: Move the textarea displaying packet capture outside of the form tag, or else a browser will try to submit the contents of the textarea when hitting a button. If you were viewing a large capture, that can be quite a long time it's wasting on uploading data that serves no purpose.
Jim Pingle
06:29 PM Revision d427daea: Fix whitespace formatting
Jim Pingle
06:24 PM Revision d3347fdf: Fix display of ssh port on anti-lockout rule display in GUI.
Jim Pingle
06:23 PM Revision 1f82f5e0: Fix display of ssh port on anti-lockout rule display in GUI.
Jim Pingle
06:08 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Okay, fair enough. Can you please help me with the process of disabling 'msix'? I'm finding it difficult to discover ... Chris Smith
05:41 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
The simplest way to do that is getting a FreeBSD 8.1 box and build the latest bge drivers from FreeBSD HEAD.
Then lo...
Ermal Luçi
05:39 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
I have had TSO disabled since two weeks ago and have not experienced any crashes, but the systems could go literally ... Chris Smith
05:05 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
I am removing dependency on 2.0 since this a driver/hw issue and out of our control. Ermal Luçi
05:09 PM Feature #620: No privilege choice to allow access to Dashboard
Presently there is no proper way to do it.
The solution is envolved and it will wait 2.1
Ermal Luçi
05:06 PM Bug #1437 (Feedback): More validation needed on CSR generation
Ermal Luçi
05:03 PM Bug #1393 (Feedback): IPSec Xauth
There has been merged a setting for allowing LDAP as backend to be configured.
Not sure it should be merged in 2.0.
Ermal Luçi
04:10 PM Bug #1709 (Feedback): RRD failures for Traffic and Packets graphs on NanoBSD
Something must have corrupted (or failed to upgrade) your RRD files in the past. Or you had a backup of the bad files... Jim Pingle
03:57 PM Bug #1407: GUI is sluggish without working DNS
Does it happen if resolv.conf has an entry
'options timeout:1'
'options attempts:1'
Ermal Luçi
03:49 PM Bug #1688 (Feedback): DHCP server subnet input validation needs to check config.xml, not ifconfig
Ermal Luçi
03:47 PM Bug #1629: invalid state table entries after WAN IP change
Can you post system log with state table as well? Ermal Luçi
03:45 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
Applied in changeset commit:0124456b0c4d602adea538cee35fc67c977e9f2e. Jim Pingle
03:45 PM Bug #1564 (Feedback): rc.stop_packages causes reboot to only works from SSH, not from Web interface
Applied in changeset commit:3e8fad13ae4a029fc6d872d87399f98f04a752cb. Jim Pingle
03:40 PM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
rc.stop_packages is currently disabled which is why reboots are still working now.
Since the upgrade to PHP 5.2.1...
Jim Pingle
03:42 PM Todo #1723 (Resolved): PPTPd and all mpd based services need more checks
More checks need to be added for the localip parameter of mpd based services when used as a concentrator since people... Ermal Luçi
03:36 PM Bug #1421 (Feedback): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I have put a fix in latest snapshots.
@Hafiz Rafiyev,
i have put the fix on your box so you can test directly wit...
Ermal Luçi
01:37 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Chris Buechler wrote:
> someone who can replicate this and can get us access to their system, please email me (cmb a...
Hafiz Rafiyev
03:11 PM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
I have no problems with this that I can reproduce. I have about every combination of VIPs on interfaces and IP aliase... Jim Pingle
02:36 PM Bug #1377 (Feedback): upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
This works fine for me. Imaged a CF with 1.2.3 4GB, configured it, ran for a bit, then upgraded to a current 2.0 snap... Jim Pingle
01:54 PM Bug #1336 (Feedback): PPTP VPN NAT on WAN or other external interface
It works for me with Ermal's patch directly applied. Once snapshots with this fix are uploaded, others can test. Jim Pingle
01:51 PM Bug #1318 (Feedback): Certificate error: certificate subject does not match signing request subject
Can anyone reproduce this since #1438 has been fixed/closed? Jim Pingle
01:40 PM Bug #1121 (Feedback): wireless interface antenna settings not applied at boot
I can't reproduce this on current snapshots. If I set to Diversity=Off, And TX/RX for antenna 2, then it shows 2/2/0 ... Jim Pingle
01:33 PM Bug #875 (Resolved): Uninstalling packages can remove system libraries
yeah i think this is good Chris Buechler
01:17 PM Bug #875: Uninstalling packages can remove system libraries
I've installed/uninstalled quite a few packages and the only way I have managed to break the system is if I use pkg_d... Jim Pingle
01:09 PM Bug #802 (Feedback): Interface reassignment with VLANs after config restore to diff hardware doesn't work
I restored a config with vlans to a VM and it worked fine - I had to go to the VLANs tab and reparent the VLANs one b... Jim Pingle
12:58 PM Bug #1722 (Closed): Associated filter rule retains original Interface option after copying a NAT rule
I discovered a problem with the automatic filter rules created for NAT rules. When copying a NAT rule, the associate... Oz Solomon
12:24 PM Revision 4222087e: Also escape \ in pptp passwords.
Jim Pingle
12:23 PM Revision 001c9bed: Also escape \ in pptp passwords.
Jim Pingle
10:40 AM pfSense Packages Bug #1714 (Resolved): Missing png-1.4.5_1 port for ntop and vnstat2
Jim Pingle
10:05 AM pfSense Packages Bug #1714: Missing png-1.4.5_1 port for ntop and vnstat2
both packages installed for me.. Thanks again!! Cino .
08:17 AM Revision 1f33a712: Correct priority number to not have clashes with PRIQ which do not allow same priority numbers for two different queues.
Ermal LUÇI
08:16 AM Revision 609debe5: Correct priority number to not have clashes with PRIQ which do not allow same priority numbers for two different queues.
Ermal LUÇI
08:00 AM Revision 800d973d: Do not add any reply-to information to rules with action match. Reported-by: http://forum.pfsense.org/index.php/topic,39247.msg202728.html#msg202728
Ermal LUÇI
07:57 AM Revision f829cd35: Do not add any reply-to information to rules with action match. Reported-by: http://forum.pfsense.org/index.php/topic,39247.msg202728.html#msg202728
Ermal LUÇI

07/27/2011

11:24 PM Revision b22bf161: Adding hook
Scott Ullrich
11:23 PM Revision ff49f684: Adding hook
Scott Ullrich
11:03 PM Revision d9327477: Add hooks
Scott Ullrich
11:03 PM Revision 439cc13f: Add hooks
Scott Ullrich
10:31 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
someone who can replicate this and can get us access to their system, please email me (cmb at pfsense dot org).
Chris Buechler
10:16 PM Bug #708: Need more checks for dns rebind issue
That's impossible because 5 will never happen, browsers' internal DNS caches don't come anywhere near obeying short T... Chris Buechler
12:02 PM Bug #708: Need more checks for dns rebind issue
The checks won't protect against DNS rebind attacks that run like this:
1. browser makes DNS lookup for <hostname-of...
Cyrus Patel
10:05 PM Bug #1719 (Resolved): OpenVPN Status in Dashboard
Chris Buechler
09:26 PM Bug #1719: OpenVPN Status in Dashboard
Looks good. Thanks. Alex Vergilis
08:40 PM Revision 8b618d91: Correct check as per http://forum.pfsense.org/index.php/topic,39155.0.html
Ermal LUÇI
08:39 PM Revision 6968b356: Correct check as per http://forum.pfsense.org/index.php/topic,39155.0.html
Ermal LUÇI
08:31 PM Revision 96267107: Correct whitespace and some problems in the just merged ldap auth sorce for racoon
Ermal LUÇI
08:19 PM Revision 5d6bade4: Merge pull request #8 from ninja76/master
IPSec xAuth allowing LDAP to be used as a backend Ermal LUÇI
07:41 PM Revision f9199cd3: Check for null Array and move option system to top
Bryan Haase
05:43 PM Revision 3ab1b036: Prevent php from coring if the wrong parameters are passed to ip2long
Ermal LUÇI
05:40 PM Revision 1fb8d314: Prevent php from coring if the wrong parameters are passed to ip2long
Ermal LUÇI
04:54 PM Revision 4cf82d52: Relax PPTP password restrictions, just prevent starting with a !, and limit to common printable/keyboard characters so it doesn't result in invalid xml. Fixes #1720
Jim Pingle
04:49 PM Revision 2c466077: Relax PPTP password restrictions, just prevent starting with a !, and limit to common printable/keyboard characters so it doesn't result in invalid xml. Fixes #1720
Jim Pingle
04:19 PM Revision 9140006b: Correct issue with adding IPv6 default gateway reported http://forum.pfsense.org/index.php/topic,39344.0/topicseen.html
Ermal LUÇI
04:05 PM Revision 94efbf8b: Shift OpenVPN require, it was causing CRLs to not save changes properly.
Jim Pingle
04:05 PM Revision c3555734: Shift OpenVPN require, it was causing CRLs to not save changes properly.
Jim Pingle
03:51 PM Revision 8c011fc9: Fix variable so CSC/Overrides for OpenVPN are actually deleted from the fs when deleted from the GUI.
Jim Pingle
03:50 PM Revision e6af6518: Fix variable so CSC/Overrides for OpenVPN are actually deleted from the fs when deleted from the GUI.
Jim Pingle
03:41 PM Bug #1703 (Resolved): editing/removing interface groups leaves remnant
Ermal Luçi
05:49 AM Bug #1703: editing/removing interface groups leaves remnant
Looks good as of _2.0-RC3 (amd64) built on Tue Jul 26 19:09:40 EDT 2011_:
The group name is not removed in all ca...
Anonymous
03:37 PM Revision 95305736: Rework OpenVPN status, show status for shared key servers.
Jim Pingle
03:36 PM Revision f27d726c: Rework OpenVPN status, show status for shared key servers.
Jim Pingle
02:01 PM Bug #1721: uPnP issue with STATIC ip addresses
Where do I find the logs or is it easier to find them via the file system? Matt Crook
01:58 PM Bug #1721: uPnP issue with STATIC ip addresses
Seth Mos wrote:
> If I remember correctly the Xbox will not request uPNP mapping when the IP address is configured s...
Matt Crook
05:59 AM Bug #1721 (Feedback): uPnP issue with STATIC ip addresses
pretty sure Seth's right from some quick searching. Chris Buechler
05:16 AM Bug #1721: uPnP issue with STATIC ip addresses
If I remember correctly the Xbox will not request uPNP mapping when the IP address is configured statically.
Try t...
Seth Mos
01:47 PM Revision 2c189c8c: Improved ipsec ldap xauth
Bryan Haase
01:06 PM Bug #1676: dead IPv6 gateway causes kernel panics
Definitely easy to reproduce with the right conditions, mine panics thusly:
* Home router with IPv6 connectivity v...
Jim Pingle
12:55 PM Todo #1720: Relax input validation for PPTP Passwords
Applied in changeset commit:2c466077934c3812aed9d15b77ab515e4b3e116d. Jim Pingle
12:55 PM Todo #1720 (Feedback): Relax input validation for PPTP Passwords
Applied in changeset commit:4cf82d52943b00c2710b7867387230a0e58225be. Jim Pingle

07/26/2011

09:30 PM Revision 6d013706: Resolves #1719. Prevent disabled client/servers from being displayed on the widget.
Ermal LUÇI
09:30 PM Revision 6b2dcac5: Resolves #1719. Prevent disabled client/servers from being displayed on the widget.
Ermal LUÇI
09:10 PM Bug #1721 (Closed): uPnP issue with STATIC ip addresses
"No I'm rejecting it because it's a support request, not a bug report. If you want to dig into it and find the real c... Matt Crook
08:49 PM Bug #1629: invalid state table entries after WAN IP change
It's still happening.
Again here's a relevant section. Our Asterisk server at 10.0.4.3 is still trying to use the o...
Eli Hunter
05:33 PM Todo #1720 (Resolved): Relax input validation for PPTP Passwords
Allow more characters for passwords as described at the forum:
http://forum.pfsense.org/index.php/topic,39003.0.html...
Grischa Zengel
05:30 PM Bug #1719: OpenVPN Status in Dashboard
Applied in changeset commit:6b2dcac596477f7201a0c6b5734ab8f1b9a04c5e. Ermal Luçi
05:30 PM Bug #1719 (Feedback): OpenVPN Status in Dashboard
Applied in changeset commit:6d0137065075d48498f28b6ef476858320a79c2f. Ermal Luçi
04:18 PM Bug #1719 (Resolved): OpenVPN Status in Dashboard
If one of the defined OpenVPN servers has been marked as disabled, the OpenVPN status in the Dashboard produces the f... Alex Vergilis
04:58 PM Bug #1395: RRD data not collecting accurate information
Oh I should have mentioned that my current build is a week or so old.
2.0-RC3 (i386) built on Fri Jul 15 05:55:15...
David Miller
04:54 PM Bug #1395: RRD data not collecting accurate information
I need to open this one back up. :(
I'm not sure what build this behavior returned but I'm now seeing the traffic ...
David Miller
02:57 PM pfSense Packages Bug #1714: Missing png-1.4.5_1 port for ntop and vnstat2
i386 just uploaded, give it another shot. Jim Pingle
02:38 PM pfSense Packages Bug #1714: Missing png-1.4.5_1 port for ntop and vnstat2
thanks Jim! Let me know when I should retest. Cino .
12:30 PM pfSense Packages Bug #1714: Missing png-1.4.5_1 port for ntop and vnstat2
Yeah there is still an issue, another (hopefully ok) set of packages has been building all day, should be done in a c... Jim Pingle
12:12 PM pfSense Packages Bug #1714: Missing png-1.4.5_1 port for ntop and vnstat2
vnstat2 is able to install but it breaks my RRD graphs. un-install the package then a firmware update seems to fix it... Cino .
09:40 AM Bug #1718 (Closed): RRD Graphs error
You probably installed a package that overwrote rrdtool (like ntop). There is an issue with the uploaded package bina... Jim Pingle
09:37 AM Bug #1718 (Closed): RRD Graphs error
Unable to Show RRD Graphs, with a message to check System logs.
In the System logs, the following error:...
Slobodan Lakic
08:36 AM pfSense Packages Bug #1717 (Feedback): BandwidthD Service not starting
Looks like there was a slight mixup with the uploaded package binaries. New ones are building now, should be fine lat... Jim Pingle
08:02 AM pfSense Packages Bug #1717 (Resolved): BandwidthD Service not starting
After upgrade to 2.0-RC3 (i386) built on Sun Jul 24 19:17:15 EDT 2011, and installation of BandwidthD, the BandwidhtD... Slobodan Lakic
04:19 AM Bug #1715 (Closed): NTP client is waiting endless during boot when NTP server is not responding
thanks Chris Buechler
04:15 AM Bug #1715: NTP client is waiting endless during boot when NTP server is not responding
I just tried to reproduce my scenario from yesterday. But got no way to force this issue again. I am sorry, please cl... Willy Tenner
12:11 AM Bug #1716 (Rejected): Xboxes 360s not able to use upnp
stop opening bugs unless there actually is a specific bug detailed in the report. This is for confirmed, specific bug... Chris Buechler

07/25/2011

11:48 PM Bug #1716 (Rejected): Xboxes 360s not able to use upnp
I have found this on the forums, and seems to be an unfixed issue. Please stop ignoring this.
Link: http://forum.p...
Matt Crook
09:10 PM Revision 320bba64: Always send the route delete command even if it fails its ok. This avoids having to dump the routing table.
Ermal LUÇI
09:10 PM Revision 74225193: Always send the route delete command even if it fails its ok. This avoids having to dump the routing table.
Ermal LUÇI
08:36 PM Bug #1715 (Feedback): NTP client is waiting endless during boot when NTP server is not responding
Me neither. There is a timeout, it continues to boot whether or not the NTP server is reachable and whether you even ... Chris Buechler
08:34 PM Bug #1715: NTP client is waiting endless during boot when NTP server is not responding
I can't reproduce. Yes ntpd hangs for a bit and them boot process continues. Evgeny Yurchenko
10:04 AM Bug #1715 (Closed): NTP client is waiting endless during boot when NTP server is not responding
Starting pfSense hangs when NTP client is initializing. The NTP server outside is reachable, but cannot answer due to... Willy Tenner
07:42 PM Revision 6390cdac: Use the new change to be less distuptive
Ermal LUÇI
07:39 PM Revision a6ed5ab8: Use the new change to be less distuptive
Ermal LUÇI
07:39 PM Revision 8ff6b72c: Use the new change to be less distuptive
Ermal LUÇI
07:36 PM Revision 74dafdec: Use change here to be cleaner and less disruptive.
Ermal LUÇI
07:35 PM Revision 8ad0ee24: Use change here to be cleaner and less disruptive.
Ermal LUÇI
07:07 PM Revision 85f9faa6: Resolves #1703. Correct array key value.
Ermal LUÇI
07:05 PM Revision 073cd52e: Resolves #1703. Correct array key value.
Ermal LUÇI
05:56 PM Revision b368b35a: Resolve issues that made php core dump or eat a lot of memory when big routing tables are present.
Ermal LUÇI
05:49 PM Revision fb85533d: Resolve issues that made php core dump or eat a lot of memory when big routing tables are present
Ermal LUÇI
03:09 PM Revision 6813d6e7: Add a flag that defaults to on allowing the control of delete states from external callers such as pfCenter
Scott Ullrich
03:09 PM Revision 997ea9bb: Add a flag that defaults to on allowing the control of delete states from external callers such as pfCenter
Scott Ullrich
03:05 PM Bug #1703: editing/removing interface groups leaves remnant
Applied in changeset commit:073cd52e5836a961bcaf677d34b2252964fc9e10. Ermal Luçi
03:05 PM Bug #1703: editing/removing interface groups leaves remnant
Applied in changeset commit:85f9faa67f7eee5ca824c598b67927a1b71235f7. Ermal Luçi
03:03 PM Bug #1703: editing/removing interface groups leaves remnant
Ok solved. Check snapshots. Ermal Luçi
03:02 PM Revision caf40204: Run on CD-ROM, too, it should be writable after rc.cdrom
Jim Pingle
03:02 PM Revision ba8366d5: Sync password database right after mount, in case it is corrupt. (Except on CD-ROM platform).
Jim Pingle
03:01 PM Revision 01656166: Run on CD-ROM, too, it should be writable after rc.cdrom
Jim Pingle
02:58 PM Revision ca3537ba: Sync password database right after mount, in case it is corrupt. (Except on CD-ROM platform).
Jim Pingle
10:00 AM pfSense Packages Bug #1714 (Feedback): Missing png-1.4.5_1 port for ntop and vnstat2
Looks like the last package build didn't upload that file because another build cleared it out before it uploaded. I ... Jim Pingle
09:56 AM pfSense Packages Bug #1714 (Resolved): Missing png-1.4.5_1 port for ntop and vnstat2
Port png-1.4.5_1 is missing. Packages ntop and vnstat2 won't install with this port.
Downloading http://files...
Cino .
09:52 AM Bug #1713 (Rejected): Field for the NTP time server cannot be cleared
You must define a time server, as many operations on the firewall require correct time. You could enter an IP address... Jim Pingle
09:47 AM Bug #1713 (Rejected): Field for the NTP time server cannot be cleared
In the WebGUI under System->General Setup you can set the name(s) for NTP time servers. But you cannot clear this set... Willy Tenner
09:23 AM Revision 581e4f7a: Merge branch 'master' of github.com:bsdperimeter/pfsense
Chris Buechler
05:16 AM pfSense Packages Bug #1244: apache_mod_security_package missing mod_proxy.so (and perhaps others)
Had the same issue with a fresh AMD64 install.
Looking at http://files.pfsense.org/packages/amd64/8/All/apache-2.2...
K T
12:37 AM Bug #1712 (Rejected): pfSense UPnP issues with xbox 360
"I believe this is a bug" isn't enough for a bug report, bug reports must have the specific bug. Please post to the f... Chris Buechler
12:34 AM Bug #1712 (Rejected): pfSense UPnP issues with xbox 360
Okay, I have tried everything, and beleive this is a bug. I have Upnp turned on and the xbox isn't able to open a por... Matt Crook

07/24/2011

07:38 PM Bug #1711 (Closed): Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages
Chris Buechler
07:32 PM Bug #1711: Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages
Rolled back changes as they were wrong (Thanks Ermal).
The problem does not exist in current snapshot, I was using o...
Evgeny Yurchenko
04:28 PM Revision 90c386ba: Revert "Already doing this no need to duplicate" <- no, we aren't 100% duplicating this. This commit breaks fully reconfiguring assigned gif interfaces.
This reverts commit 87f0f42c3230ad7ad15b14a8a9d63c58f8b2e379. Jim Pingle
02:54 AM Revision 6684d275: Adding hook for first tr
Scott Ullrich
02:53 AM Revision b733ce0d: Adding hook for first tr
Scott Ullrich
02:25 AM Revision 3597b8b0: Fix copy and pasto
Scott Ullrich
01:56 AM Revision e5c6bd24: Load chosen but do not use it (for pkgs)
Scott Ullrich
01:55 AM Revision 7be7e519: Load chosen but do not use it (for pkgs)
Scott Ullrich
01:51 AM Revision 56f547cb: Move hook code up a bit
Scott Ullrich
01:51 AM Revision 20246b93: Move hook up some
Scott Ullrich
01:06 AM Revision 3a4ca65e: Adding hooks that will be used for filtering plugins
Scott Ullrich
01:05 AM Revision 40e02230: Adding hooks that will be used for filtering plugins
Scott Ullrich
12:03 AM Revision 4a6cf823: Move hook code up a few lines
Scott Ullrich
12:03 AM Revision 13ac0f40: Move hook code up a few lines
Scott Ullrich

07/23/2011

11:14 PM Revision 7a7ec6f4: Add hook for overriding interfaces
Scott Ullrich
11:13 PM Revision 6e9dd2ab: Add hook for overriding interfaces
Scott Ullrich
11:01 PM Revision f4a8f48f: Adding chosen but do not actually use it beyond loading
Scott Ullrich
10:51 PM Revision 4bb99603: Add chosen js library (mit lic). Modify interface multiple select box to use.
Scott Ullrich
10:48 PM Bug #1572: DHCP + MAC spoofing leads to link cycling
Chris Buechler wrote:
> If MAC spoofing is enabled on an interface that is a DHCP client, in some circumstances it c...
Johnny Good
10:36 PM Revision 8c5bf3d7: Add hook for bottom icon row
Scott Ullrich
10:35 PM Revision 2d302d50: Add hook for bottom icon row
Scott Ullrich
10:25 PM Revision 4e17a1a3: Add hook and fix style for anti lockout
Scott Ullrich
10:25 PM Revision 5fec5fe4: Add hook and fix style for anti lockout
Scott Ullrich
10:04 PM Revision 7c1e7572: Add missing ;
Scott Ullrich
10:04 PM Revision 7af82a98: Add missing ;
Scott Ullrich
10:02 PM Revision afabae93: Adding pre_id_tablerow hook
Scott Ullrich
10:02 PM Revision 3a71f473: Adding pre_id_tablerow hook
Scott Ullrich
09:55 PM Bug #1711: Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages
Fixed in commit: f6d6c33 Evgeny Yurchenko
09:13 PM Bug #1711 (Closed): Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages
Thu Jul 21 22:38:38 2011
NAS-IP-Address = 10.0.3.15
NAS-Identifier = "pfsense.localdomain"
User-Name = "test"
...
Evgeny Yurchenko
09:20 PM Revision 4b891efd: Revert "fix text"
This reverts commit 423023b6dff620fe790c09bd0398ba4fad9ee444. Chris Buechler
09:20 PM Revision b5556bbf: Revert "fix text"
This reverts commit c27ca36eb3fb3a5c5c1ca7feb9567bd6d23a16dc. Chris Buechler
09:02 PM Revision c27ca36e: fix text
Chris Buechler
09:01 PM Revision 423023b6: fix text
Chris Buechler
12:09 AM Revision d728dd67: Adding apply hooks
Scott Ullrich
12:09 AM Revision 1a700ea6: Adding apply hooks
Scott Ullrich

07/22/2011

10:36 PM Revision a38c57d8: make the tab character limit 92, leaves plenty of room and prevents some custom builds from unnecessarily turning tabs into a drop down
Chris Buechler
10:34 PM Revision 1ee5815c: make the tab character limit 92, leaves plenty of room and prevents some custom builds from unnecessarily turning tabs into a drop down
Chris Buechler
09:17 PM Revision 3a497aa3: Bump to 1.7
Scott Ullrich
09:17 PM Revision e099a671: Bump to 1.7
Scott Ullrich
09:03 PM Revision 860a83e4: Switch back to the default gateway configured when possible when gateway switching is active
Ermal LUÇI
09:03 PM Revision e75be7fc: Switch back to the default gateway configured when possible when gateway switching is active
Ermal LUÇI
08:38 PM Revision 50383036: Correct check for the gif mtu during an interface readdition to bridge.
Ermal LUÇI
08:38 PM Revision 73481ad3: Correct check for the gif mtu during an interface readdition to bridge.
Ermal LUÇI
08:21 PM Revision cec917b5: Only apply remote_network setting for p2p modes, since it is not valid for remote access modes. Fixes #1707
Jim Pingle
08:20 PM Revision 17c98ba9: Only apply remote_network setting for p2p modes, since it is not valid for remote access modes. Fixes #1707
Jim Pingle
06:45 PM Revision e5ba916a: Remove whitespace at the start of firewall_aliases.php - it was causing errors in the GUI.
Jim Pingle
06:07 PM Bug #1703: editing/removing interface groups leaves remnant
@ifconfig -g@ still shows the members. Anonymous
05:21 PM Bug #1703: editing/removing interface groups leaves remnant
That is normal if it does not have the members. Ermal Luçi
05:19 PM Bug #1703: editing/removing interface groups leaves remnant
_2.0-RC3 (amd64) built on Fri Jul 22 11:43:53 EDT 2011_:
Renaming the group now works correctly. But deleting the ...
Anonymous
07:05 AM Bug #1703: editing/removing interface groups leaves remnant
Applied in changeset commit:4869860590338234776737cf871e21d2e584f404. Ermal Luçi
07:05 AM Bug #1703 (Feedback): editing/removing interface groups leaves remnant
Applied in changeset commit:cdfd39e2b9df28910e4b339c9589ab5377a5933c. Ermal Luçi
07:02 AM Bug #1703: editing/removing interface groups leaves remnant
Should be fixed on latest snaps. Ermal Luçi
05:53 PM Bug #1709 (Closed): RRD failures for Traffic and Packets graphs on NanoBSD
None of the Traffic and Packet graphs work on my ALIX systems. Here's a sample output for a failure:
php: /status_...
Jens Kuehnel
05:34 PM Revision 53a37558: Clear \r from these files to be readble
Ermal LUÇI
05:34 PM Revision e1110f88: Clear \r from these files to be readble
Ermal LUÇI
05:28 PM Revision b7d7f4b8: Ticket #749. Make the rules of the traffic shaper wizard select the wan side of the interfaces to not make the intra-lan traffic classifible in this way.
Ermal LUÇI
05:27 PM Revision 8fd84f87: Ticket #749. Make the rules of the traffic shaper wizard select the wan side of the interfaces to not make the intra-lan traffic classifible in this way.
Ermal LUÇI
04:55 PM Bug #1344: Replace prototype javascript code with jQuery
Very nice select box http://harvesthq.github.com/chosen/
Scott Ullrich
04:40 PM Feature #1708 (Closed): LDSR from Yahoo
It would be nice to import https://github.com/yahoo/l3dsr/tree/master/freebsd from direct server return.
Its BSD a...
Ermal Luçi
04:20 PM Bug #1707: Pfsense 2.0 RC3 keeps route of deleted openvpn server
Applied in changeset commit:17c98ba974bd48fd5b43d1ff4fd70ea50cf01b77. Jim Pingle
04:20 PM Bug #1707 (Feedback): Pfsense 2.0 RC3 keeps route of deleted openvpn server
Applied in changeset commit:cec917b53a3921b5ce427045219240b71087103b. Jim Pingle
12:29 PM Bug #1707 (Resolved): Pfsense 2.0 RC3 keeps route of deleted openvpn server
I configured peer to peer SSL/TLS openvpn server and set the Remote Network to 192.168.4.0/24. Afterwards I changed i... Chantal Rosmuller
02:20 PM Revision e3d35704: format error
Bryan Haase
02:18 PM Revision e9ccd9b1: More sanity checking
Bryan Haase
01:37 PM Bug #636: layer7 not work correctly
Try with latest snaps.
It was only a cosmetic issue.
Ermal Luçi
01:25 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
I just committed an optimization that should address your concerns. Ermal Luçi
01:18 PM Revision 64f3141f: Ipsec xAuth patch
Bryan Haase
12:35 PM Bug #1704 (Closed): Traffic graph hangs web configurator (webConfigurator)
Pleaase upgrade. Ermal Luçi
12:31 PM Revision c8950140: Revert wrong fix of Bug #1711.
Evgeny Yurchenko
12:29 PM Revision 9ee5069a: Revert wrong fix of Bug #1711.
Evgeny Yurchenko
11:04 AM Revision cdfd39e2: Resolves #1703. Correctly delete a interface group members when the group is deleted.
Ermal LUÇI
11:03 AM Revision 48698605: Resolves #1703. Correctly delete a interface group members when the group is deleted.
Ermal LUÇI
10:05 AM Revision 3ad667cd: Correctly restart the SSL lighty instance when running.
Ermal LUÇI
10:05 AM Revision d73da773: Correctly restart the SSL lighty instance when running.
Ermal LUÇI
10:04 AM Revision 699cb4fe: Correctly restart the SSL lighty instance when running.
Ermal LUÇI
10:04 AM Revision f32f09d4: Correctly restart the SSL lighty instance when running.
Ermal LUÇI
09:11 AM Bug #1688: DHCP server subnet input validation needs to check config.xml, not ifconfig
This is in master https://github.com/bsdperimeter/pfsense/commit/51cd7a1e31fd5018aa465c0de66905e759f2e8cb
This is in...
Evgeny Yurchenko
07:13 AM Bug #1688: DHCP server subnet input validation needs to check config.xml, not ifconfig
Evgeny i do not see the commit anywhere? Ermal Luçi
08:55 AM Revision 8818c188: Remove 'maxproc' since its unused in the code and correctly use maxprocperip to allow the GUI setting to be actually usable. Reported-by: http://forum.pfsense.org/index.php/topic,39155.0.html
Ermal LUÇI
08:55 AM Revision 985070dc: Remove 'maxproc' since its unused in the code and correctly use maxprocperip to allow the GUI setting to be actually usable. Reported-by: http://forum.pfsense.org/index.php/topic,39155.0.html
Ermal LUÇI
07:04 AM Bug #1512 (Resolved): Ghost CAs
Ermal Luçi
04:23 AM Bug #1512: Ghost CAs
Hi all,
I tested this today on my version on a ALIX Box:
2.0-RC3 (i386)
built on Wed Jul 20 19:51:58 EDT 2011
...
Peter Baumann
04:14 AM Bug #1564: rc.stop_packages causes reboot to only works from SSH, not from Web interface
Just want to let you know that I use many pfSense 2.0-RC3 firewalls here for testing.
I use amd64 and i386 in XenSer...
Peter Baumann
03:04 AM Revision f6d6c332: Bug #1711. Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages.
Evgeny Yurchenko
02:53 AM Revision ee0617fa: Bug #1711. Acct-x-Octets are always 0 in Captive Portal -> Radius acct messages.
Evgeny Yurchenko
01:15 AM Bug #1706: "Bypass firewall rules for traffic on the same interface" is broken
that's only an issue in IPv6, 2.1.
Chris Buechler
12:43 AM Bug #1706 (Resolved): "Bypass firewall rules for traffic on the same interface" is broken
Turning on the "Bypass firewall rules for traffic on the same interface" option will not generate the required firewa... Andreas Damm

07/21/2011

11:57 PM Bug #1705 (Closed): Multi-WAN Failover loses default route
Сonfigured Multi-WAN (Gateway groups: tier 1, tier 2, member down) and turned on "Allow default gateway switching" (S... Andrey Shimanskiy
09:10 PM Revision 8380e833: Fix redirurl collection so after login the user can be redirected correctly
Ermal LUÇI
09:10 PM Revision c7b5a8cf: Plug a security risk on CP where a user can login by submitting a special request
Ermal LUÇI
09:10 PM Revision 739e227a: Plug a security risk on CP where a user can login by submitting a special request
Ermal LUÇI
09:09 PM Revision adbb495c: Fix redirurl collection so after login the user can be redirected correctly
Ermal LUÇI
07:02 PM Bug #1692: OpenVPN Clients can't route to IPSEC peer
Correct and helpful response. Thanks. Nei Ka
07:01 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I've been watching/experiencing this bug for a while now and it's also now a stopper for us too. I'm also open to pa... Alan Bryan
03:29 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Pablo - I emailed you. Chris Buechler
07:01 PM Bug #1704 (Closed): Traffic graph hangs web configurator (webConfigurator)
2.0-RC3 on Soekris or Linux.
Traffic graph hangs web configurator with "cannot get data about interface"
Attemp...
Nei Ka
06:57 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Andreas Bochem wrote:
> The issue on my machine is resolved in that version.
Addendum:
Not quite. The secondary ...
Anonymous
05:20 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Jim P wrote:
> That is not the most recent snapshot. See http://forum.pfsense.org/index.php/topic,38687.0.html
Th...
Anonymous
05:52 AM Bug #1703 (Resolved): editing/removing interface groups leaves remnant
I noticed that removed interface groups are still shown by @pfctl -s Interfaces@ until I reboot the machine.
So I di...
Anonymous
03:31 AM Feature #1701 (Closed): Vouchertime should be seperated
The Vouchertime should be seperated, so the user can login today for 2 hours, logout (through logout-popup or idle-ti... Andreas Böhm

07/20/2011

10:39 PM Revision 006f5f16: Correct the check for mtu 1500 to inlcude it. Also add the check on bridge_add_member function
Ermal LUÇI
10:39 PM Revision 58794ce5: Correct the check for mtu 1500 to inlcude it. Also add the check on bridge_add_member function
Ermal LUÇI
09:16 PM Revision bbcc16cb: Fix php behaviour on xmlrpc sync and vouchers starting with a number. Apparently php uses that to deduce the type of var and gets confused.
Ermal LUÇI
09:16 PM Revision 12a5a039: Fix php behaviour on xmlrpc sync and vouchers starting with a number. Apparently php uses that to deduce the type of var and gets confused.
Ermal LUÇI
06:00 PM Bug #1700 (Resolved): Captive Portal cannot work on master branch
With IPv6 changes the CP now lighty of CP listens only on localhost which breaks CP.
No clear resolution or appare...
Ermal Luçi
05:48 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Hi, Is there any estimated hours to resolve this issue, I'm willing to pay to resolve this issue since it's a stopper... Pablo Garcia Melga
03:18 PM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
Just added a "Pre-2.0 Upgrade Check" package for 1.2.x that will flag such things, though it can't be done automatica... Jim Pingle
12:38 PM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
Whoops, make that: http://doc.pfsense.org/index.php/Upgrade_Guide#International.2FSpecial_Characters_in_1.2.x_Configs Jim Pingle
12:37 PM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
Note added: (broken link) Jim Pingle
12:09 PM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
It's been mentioned in dozens of forum threads and on the mailing list, and elsewhere. I'm not sure if it's on the do... Jim Pingle
11:53 AM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
Could you at least added this to the "known problems" or the README file for the update.
It worked in 1.2.3 and will...
Jens Kuehnel
11:50 AM Bug #1699 (Rejected): Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
They were not supported in 1.2.3, count yourself lucky it didn't blow up on you earlier. This is a known issue, not m... Jim Pingle
11:45 AM Bug #1699: Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
Tested it with update from 1.2.3-RELEASE to both:
pfSense-Full-Update-2.0-RC3-i386-20110719-2331.tgz
pfSense-Full...
Jens Kuehnel
11:41 AM Bug #1699 (Rejected): Update fail from 1.2.3 to 2.0-RC3 if umlaute are used in descriptions
If umlaut like äöü are used in the description somewhere like FW-rules the update from 1.2.3-release to 2.0-RC3 hangs... Jens Kuehnel
10:47 AM Bug #1698: IPSec tunnel from CARP backup interface
Yes, there's no impact on the local systems, it's just a matter of bothering the remote system with continuous reques... Michele Di Maria
06:31 AM Bug #1698: IPSec tunnel from CARP backup interface
this is generally a non-issue because nothing will try to bring up the connection unless it's failed over. But hopefu... Chris Buechler
06:12 AM Bug #1698 (Resolved): IPSec tunnel from CARP backup interface
Hello,
it happens this. When I create a IPSec tunnel I set as interface a CARP ip address in order to let the tun...
Michele Di Maria
04:29 AM Bug #636: layer7 not work correctly
Is there any progress on this? I appreciate your hard work, Ermal. Jonathan Puddle
04:09 AM Bug #749: Downstream queues should not be assigned to LAN interfaces
qLink will get all traffic that is not matched by the wizard rules.
Ermal Luçi
01:14 AM Revision a7377124: Bug#1688. DHCP server subnet input validation needs to check config.xml, not ifconfig.
Evgeny Yurchenko
01:01 AM Revision 51cd7a1e: Bug#1688. DHCP server subnet input validation needs to check config.xml, not ifconfig.
Evgeny Yurchenko
12:48 AM Bug #1697 (Resolved): Interface group doesn't apply to all interfaces in all cases
I have an interface group "WANs" containing two WANs, em1 and em2. This is correct. ... Chris Buechler

07/19/2011

09:03 PM Bug #1688: DHCP server subnet input validation needs to check config.xml, not ifconfig
Commit 51cd7a1e31fd5018aa465c0de66905e759f2e8cb Evgeny Yurchenko
08:33 PM Revision 56771d56: Fix label for SMTP server. Hostnames work fine.
Jim Pingle
08:32 PM Revision d58b93d2: Fix label for SMTP server. Hostnames work fine.
Jim Pingle
03:30 PM Revision 41fa9c97: Extend this script to also add an ipv6 rule.
Jim Pingle
12:37 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
I tested out the shaper wizard without the p2p catch all, and it looks like the queues were created as intended.
q...
Josh Stompro
12:36 PM Bug #1493: pf blocks all traffic following filter reload.
I found the solution for my problem with broken states on filter reload:
I had to activate 'States' under @System ...
Markus Schlager
01:31 AM Bug #1696 (Resolved): Panic when finishing setup wizard with PPPoE WAN
By going through the setup wizard and changing the WAN type to PPPoE, or just changing the PPPoE username and passwor... Chris Buechler

07/18/2011

10:22 PM Revision 50261132: Adding dashboard hook
Scott Ullrich
10:22 PM Revision 810a11bc: Adding dashboard hook
Scott Ullrich
10:17 PM Revision 173d8e75: Adding hook to pre_table for aliases
Scott Ullrich
10:17 PM Revision c6fa5230: Adding hook to pre_table for aliases
Scott Ullrich
10:13 PM Revision 88377362: Add alias edit hook
Scott Ullrich
10:12 PM Revision 193716d0: Add alias edit hook
Scott Ullrich
10:07 PM Revision 2a74593e: Add pre_input_errors hook to interfaces assign
Scott Ullrich
10:07 PM Revision 25746baf: Add pre_input_errors hook to interfaces assign
Scott Ullrich
07:44 PM Bug #1694: /etc/hosts gets dhcp clients entries with wrong domainnames
Chris Buechler wrote:
> Needs to be fixed at some point, but if you end up with a loop like that you have something ...
Cyrus Patel
06:49 PM Bug #1694: /etc/hosts gets dhcp clients entries with wrong domainnames
Needs to be fixed at some point, but if you end up with a loop like that you have something configured in a non-optim... Chris Buechler
06:44 PM Bug #1694 (Closed): /etc/hosts gets dhcp clients entries with wrong domainnames
For 2.0-RC3 (i386) snapshot of Fri Jul 15 19:39:23 EDT 2011
The dynamic entries being written to /etc/hosts on a...
Cyrus Patel
07:39 PM Revision 343d4981: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
07:32 PM Todo #1695 (Resolved): local services should also use the forwarder (if enabled) for DNS.
Presently, local services do not use the DNS forwarder (if enabled).
The solution (recommended by the dnsmasq manp...
Cyrus Patel
07:25 PM Revision 48fc39a3: Adding pre_input_errors hook
Scott Ullrich
07:25 PM Revision f1bf74ca: Adding pre_input_errors hook
Scott Ullrich
07:23 PM Revision 355ab787: Revert "Move early call up a bit"
This reverts commit 50cd07ff1190cdd25293ecdd7e08e81161de33c5. Scott Ullrich
07:23 PM Revision b4b7bda6: Revert "Move early call up a bit"
This reverts commit 35843e59c81366a7d30a44a94c8a135fc6834454. Scott Ullrich
07:12 PM Revision 35843e59: Move early call up a bit
Scott Ullrich
07:11 PM Revision 50cd07ff: Move early call up a bit
Scott Ullrich
06:33 PM Revision b1e4005f: removes variables concatenation on gettext strings
Vinicius Coque
05:42 PM Revision 3f48162f: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
05:33 PM Revision d1d0a1ad: makes correct use of printf and gettext
removes variables names and replace it with '%s' Vinicius Coque
05:00 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
Ermal Luçi wrote:
> Can you please be more clear?
> Exapnd what works and what not and possibly go first through th...
Matt Crook
08:59 AM Bug #1690: PPPoE Server not passing IP from RADIUS server
Can you please be more clear?
Exapnd what works and what not and possibly go first through the forums?
Ermal Luçi
04:28 PM Revision b2f54b5e: Oops fix hook name
Scott Ullrich
04:26 PM Revision a1dece5e: Adding hook for interfaces edit
Scott Ullrich
04:26 PM Revision 40b83796: Adding hook for interfaces edit
Scott Ullrich
04:26 PM Revision 920d1d01: Adding hook for interfaces edit
Scott Ullrich
01:45 PM Feature #1687: GetText code inspection
We are reviewing the gettext code, strings with incorrect use of printf are already fixed. Soon they will be merged i... Vinícius Coque
01:00 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
I tried to test this out, but the description that Ermal added doesn't clearly tell me what I'm looking for. At firs... Josh Stompro
11:19 AM Bug #1629: invalid state table entries after WAN IP change
I had it reset again this weekend which took the asterisk server down again. Unfortunately I wasn't near a computer ... Eli Hunter
07:48 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Ross Williamson wrote:
> So I have no idea what is going on. This is on the latest snapshot which appears to be Jul ...
Jim Pingle
04:55 AM Bug #1545: Dynamic DNS updates fail on 3G connections
For whatever reason dynamic DNS has completely stopped working for me now. I can't even force an update. On first boo... Ross Williamson
06:24 AM Bug #1493: pf blocks all traffic following filter reload.
Similar problem here:
Hardware: Fujitsu Primergy; VMWare VSphere
pfSense 2.0-RC3 (amd64)
built on Mon Jul 4 ...
Markus Schlager
05:19 AM Bug #1493: pf blocks all traffic following filter reload.
Hi,
I have tested with a vanilla install of pfSense.
I consistently encounter this issue. I have tried i386 pf...
Aaron Roberts
05:42 AM Bug #1692 (Rejected): OpenVPN Clients can't route to IPSEC peer
that's a configuration issue, the PPTP clients are likely on the LAN subnet which means they fall into the P2, your O... Chris Buechler
03:31 AM Bug #1692 (Rejected): OpenVPN Clients can't route to IPSEC peer
Client PC connects using OpenVPN to a central pfsense firewall (2.0-RC3). Central firewall has IPSEC tunnel to remote... Nei Ka

07/17/2011

11:55 PM Revision a41e80f9: Redirect errors to file
Scott Ullrich
11:55 PM Revision aa840cf9: Redirect errors to file
Scott Ullrich
08:33 PM Revision 10995178: Make name similar
Scott Ullrich
08:33 PM Revision eeee6c24: Make name similar
Scott Ullrich
08:29 PM Revision 5c08b73f: Adding hooks
Scott Ullrich
08:29 PM Revision 1db196b2: Adding hooks
Scott Ullrich
06:21 AM Bug #1691 (Closed): Virtio driver not working
In commit:2ac109889ae1afeeea6cdd8dbcc339023a3f32a0 the virtio driver was added from upstream freebsd.
However, when ...
Marcus Beyer
03:33 AM Bug #1690 (Resolved): PPPoE Server not passing IP from RADIUS server
I have tried both with windows RADIUS and the packaged offered as an add-on for pfSense (freeradius) and both with th... Matt Crook
02:15 AM Revision cb2518bf: Merge branch 'master' of git@github.com:bsdperimeter/pfsense
Chris Buechler
12:55 AM Revision 0040bcfa: Adding hook for interfaces allowing pfCenter and friends to add interfaces to the dropdown
Scott Ullrich
12:55 AM Revision 29af4f6f: Adding hook for interfaces allowing pfCenter and friends to add interfaces to the dropdown
Scott Ullrich

07/16/2011

08:53 PM Bug #1629: invalid state table entries after WAN IP change
No, no, Im not talking about IPv6 in pfSense, Im talking about IPv6 NAT passthrough in the "System: Advanced: Network... Matt Corallo
05:33 PM Bug #1629: invalid state table entries after WAN IP change
IPv6 is a completely different version, that's 2.1 not 2.0, post info to the IPv6 board on the forum. Chris Buechler
04:57 PM Bug #1629: invalid state table entries after WAN IP change
I have the same problem (after the fixes) with IPv6 tunneling, so this is not resolved. Matt Corallo
02:14 AM pfSense Packages Bug #1689 (Resolved): Home URL broken from package paths
The pfsense image in the top left corner which takes the user back to the index.php page has it's url dynamically cre... reg ister

07/15/2011

11:02 PM Bug #1688 (Resolved): DHCP server subnet input validation needs to check config.xml, not ifconfig
The DHCP server subnet input validation in 2.0 checks what IP is configured on the interface, so it's impossible to c... Chris Buechler
08:12 PM Revision d470bf70: Ticket #1552. Do not allow route-to to be set on block/reject rules for now. The issue is in the kernel but for 2.0 this protection is enough.
Ermal LUÇI
08:12 PM Revision e5df770b: Ticket #1552. Do not allow route-to to be set on block/reject rules for now. The issue is in the kernel but for 2.0 this protection is enough.
Ermal LUÇI
08:04 PM Revision 0b664809: Ticket #1193. Do not show default queue checkbox when another queue has it selected.
Ermal LUÇI
08:02 PM Revision acebc1ec: Ticket #1193. Do not show default queue checkbox when another queue has it selected.
Ermal LUÇI
07:25 PM Revision 5f8f263a: Actually increase the default queue length for the new default queue
Ermal LUÇI
07:25 PM Revision 4a60bca6: Respect the p2p catchall setting.
Ermal LUÇI
07:24 PM Revision 2a9eb326: Add checks to prevent php warnings.
Ermal LUÇI
07:24 PM Revision f06efc95: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
07:24 PM Revision caac28a5: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
07:23 PM Revision 91942bd3: Revert "Ticket #749. Do not create the queues at LAN side for traffic_shaper_wizard_dedicated. Since we cannot control bandwidth its useless to try to handle it(ALTQ was built with this concept in mind)."
This reverts commit cd3346e205ad0f818977b7ccd0bd7259ed2f2e4e. Ermal LUÇI
07:23 PM Revision e1439000: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
07:23 PM Revision 9039e3dd: Revert "Ticket #749. Do not create the queues at LAN side for traffic_shaper_wizard and traffic_shaper_wizard_multi_all. Since we cannot control bandwidth its useless to try to handle it(ALTQ was built with this concept in mind."
This reverts commit 4447358371f80814ea1c5e0f00c1a7301a2396f6. Ermal LUÇI
07:22 PM Revision f1715738: Actually increase the default queue length for the new default queue
Ermal LUÇI
07:17 PM Revision 058a4f1c: Respect the p2p catchall setting.
Ermal LUÇI
07:11 PM Revision 8f864d33: Add checks to prevent php warnings.
Ermal LUÇI
07:08 PM Revision ed7c364d: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
07:02 PM Revision b2608f72: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
06:27 PM Revision 189b043d: fix correct name
Luiz Gustavo S. Costa
06:20 PM Revision 6fd23d7a: Revert "Ticket #749. Do not create the queues at LAN side for traffic_shaper_wizard_dedicated. Since we cannot control bandwidth its useless to try to handle it(ALTQ was built with this concept in mind)."
This reverts commit cd3346e205ad0f818977b7ccd0bd7259ed2f2e4e. Ermal LUÇI
06:19 PM Revision 1750ed78: Re-enable downstream queues but with the difference that the default queue now tries to use all the link when possible and the bandwidth limit is specified on a subqueue instead of the interface.
Ermal LUÇI
05:36 PM Revision 746fc9ec: Revert "Ticket #749. Do not create the queues at LAN side for traffic_shaper_wizard and traffic_shaper_wizard_multi_all. Since we cannot control bandwidth its useless to try to handle it(ALTQ was built with this concept in mind."
This reverts commit 4447358371f80814ea1c5e0f00c1a7301a2396f6. Ermal LUÇI
05:13 PM Feature #1687: GetText code inspection
<td colspan="2" class="listtopic">< ? php printf (gettext("Last $nentries PPP log entries"),$nentries); ? ></td>
Serg Dvoriancev
05:12 PM Feature #1687: GetText code inspection
ver 2.0
Quickly i able to find it here
/diag_logs_ppp.php [91]
<td colspan="2" class="listtopic"><?php printf ...
Serg Dvoriancev
04:58 PM Feature #1687: GetText code inspection
Can you please point to such locations? Ermal Luçi
04:56 PM Feature #1687 (Resolved): GetText code inspection
In some cases, you can find such code:
$myname = 'NameName';
$myvar = 'abcd123';
$mytext = gettext("This is {$m...
Serg Dvoriancev
04:46 PM Revision b473da5f: Ticket #1052. Enforce certificates if they are present for authenticating to ldap. Allow to select a CA under ldap type authentication backend to be used for this.
Ermal LUÇI
04:40 PM Bug #1686 (Closed): guiconfig.inc GetText logical bug
guiconfig.inc
function print_info_box_np($msg, $name="apply",$value="Apply changes")
This function is called with...
Serg Dvoriancev
04:11 PM Bug #1552: DNS Reject Rule Crashes Router
This has been fixed for now by nullifying the gateway selection silently. Ermal Luçi
04:10 PM Bug #1552 (Feedback): DNS Reject Rule Crashes Router
Ermal Luçi
04:00 PM Bug #1193 (Feedback): Traffic Shaper default queue Problem
Plese test latest snapshots. Ermal Luçi
03:50 PM Bug #1685: Web configurator silently fails when "Private key does not match the certificate public key"
In the meantime you can get back in by resetting the LAN IP from the console, entering the same information again. Du... Jim Pingle
03:48 PM Bug #1685: Web configurator silently fails when "Private key does not match the certificate public key"
This is for version 2.0 RC3 x86. Jeff Shaw
03:48 PM Bug #1685 (Resolved): Web configurator silently fails when "Private key does not match the certificate public key"
After choosing a particular certificate for the web administrator under System -> Advanced, the web server fails to r... Jeff Shaw
03:39 PM Revision 1852870c: fix correct name
Luiz Gustavo S. Costa
03:17 PM Bug #749 (Feedback): Downstream queues should not be assigned to LAN interfaces
This has been worked around by creating a queue that can go full interface speed. Ermal Luçi
02:57 PM Revision d792cf48: Correct ts filename
Scott Ullrich
02:56 PM Revision 8164e340: Correct ts filename
Scott Ullrich
02:24 PM Bug #1684 (Rejected): Clearing the IPsec log causes webadmin to become unresponsive.
Can't reproduce this on current snapshots, full or nanobsd. Clearing logs returns fast and works as expected. Please ... Jim Pingle
02:19 PM Bug #1684 (Rejected): Clearing the IPsec log causes webadmin to become unresponsive.
So far the only way I've found to fix this is reboot. Restarting the web administrator from the console just printed ... Jeff Shaw
02:17 PM Bug #76: Changes needed to traffic shaper since its rewrite
Sorry, I don't understand. Can't do what?
Isn't the error I am experiencing exactly same as #2 in the description o...
torontob toronbot
01:25 AM Bug #76: Changes needed to traffic shaper since its rewrite
yes but that's no longer a bug, in this ticket that wasn't checked correctly, it is now. you can't do that. Chris Buechler
01:23 AM Bug #76: Changes needed to traffic shaper since its rewrite
I am trying RC3 today and I still see the error with Single-WAN-Multi-LAN:
*"You cannot set the VoIP upload bandwi...
torontob toronbot
01:10 PM Revision fe2031ab: Ticket #1052. Enforce certificates if they are present for authenticating to ldap. Allow to select a CA under ldap type authentication backend to be used for this.
Ermal LUÇI
09:09 AM Bug #1052 (Feedback): Certificate validation of the LDAPS servers is not enforced
Just committed a fix for this.
You have to select the CA where you configure LDAP settings for it to be used.
This ...
Ermal Luçi
08:03 AM Revision e6bd2312: Fixes #1618. Always convert the NAS_PORT value to int in php and pass the attribute type during encoding to guarantee that it is encoded as an integer.
Ermal LUÇI
08:02 AM Revision b451691f: Fixes #1618. Always convert the NAS_PORT value to int in php and pass the attribute type during encoding to guarantee that it is encoded as an integer.
Ermal LUÇI
07:56 AM Feature #1683 (New): PF scrub min-ttl option
Idea from this forum post http://forum.pfsense.org/index.php/topic,27206.0.html
It would be nice if pfsense have thi...
Nikolay Stoyanov
07:35 AM Feature #1682 (Closed): second MAC address for one IP address
Idea from this forum post http://forum.pfsense.org/index.php/topic,36066.0.html
It would be nice if pfsense have thi...
Nikolay Stoyanov
07:24 AM Bug #1545: Dynamic DNS updates fail on 3G connections
i have the same issue, pfSense RC3 with two WAN.
Primary with lan connection to a router with fixed ip
Secondary PP...
Emanuel Milani
05:57 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
i have to restart racoon service in order it works properly after pptp client disconnect.But i'm not sure this shutdo... Hafiz Rafiyev
04:47 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I think that restart is user-triggered, people restart racoon to fix it. The log that looks interesting to me is:
...
Chris Buechler
03:36 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Well i need the system logs since seems something is resetting ipsec daemon.... Ermal Luçi
05:10 AM Bug #1681 (Resolved): OpenVPN tun IPs fail HTTP REFERER checks
tun IPs on OpenVPN connections fail the local IP check used for the HTTP_REFERER web interface protection, so the def... Chris Buechler
04:31 AM Bug #1565 (Resolved): Pull kern/134878 into pfsense 2.0
You would have to load puc manually as a module from loader.conf but the patch is imported now. Ermal Luçi
04:05 AM Bug #1618: Captive portal: Invalid AVP value in Radius accounting packet
Applied in changeset commit:b451691f08e5615158b04c767bc6c7cb876bc913. Ermal Luçi
04:05 AM Bug #1618: Captive portal: Invalid AVP value in Radius accounting packet
Applied in changeset commit:e6bd231242cb43ad7e8fca8635d6adcb17f38186. Ermal Luçi
04:01 AM Bug #1618 (Feedback): Captive portal: Invalid AVP value in Radius accounting packet
This should be fixed in latest snapshots. Ermal Luçi
03:48 AM Bug #1407: GUI is sluggish without working DNS
resolv.conf was populated in this case.
This instance was exacerbated by AutoConfigBackup so it was even worse th...
Chris Buechler
03:33 AM Bug #1407: GUI is sluggish without working DNS
Can you check if /etc/resolv.conf has any entry during this time? Ermal Luçi
01:16 AM Bug #1407: GUI is sluggish without working DNS
still hit this and it creates major issues with trying to operate or troubleshoot the system when there's no Internet. Chris Buechler
03:43 AM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Can you please try by disabling msix and tso on bge interfaces? Ermal Luçi
03:34 AM Bug #1679: Login redirect issue
There was a reason of removing automatic redirection.
Mostly was because of automatic posting that could break thing...
Ermal Luçi

07/14/2011

07:18 PM Revision 84bc8eb7: Fix missing " in gettext line
Jim Pingle
03:00 PM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
The one shot patch is not needed at all now.
You can just increase the sysctl sockmaxbuf to give the same results.
Ermal Luçi
01:13 PM Revision 87f0f42c: Already doing this no need to duplicate
Ermal LUÇI
12:30 PM Bug #1680 (Rejected): Automatic Nat inter IpAlias
Please open a forum thread to discuss this and eliminate any possible configuration errors. IF a bug has been confirm... Jim Pingle
12:23 PM Bug #1680 (Rejected): Automatic Nat inter IpAlias
I believe this is a bug
PfSense doing this automatically Nat inter all IpAlias of a interface
In my setup I have
...
Joaquim Soares Soares
03:39 AM Bug #1679: Login redirect issue
Note:
This fix keeps the redirect for non privileged users active.
Andreas Böhm
03:35 AM Bug #1679 (Rejected): Login redirect issue
1. Login and go to the captive portal status page (URL: http://your-pfsense-box.org/status_captiveportal.php)
2. Wai...
Andreas Böhm

07/13/2011

10:42 PM Revision fc23b860: Revert "Only load modules once"
This reverts commit 00b9730d6fe20272a40e707b709e677a847b7863. Scott Ullrich
10:42 PM Revision 59d15836: Revert "Only load modules once"
This reverts commit e4f3307c8bd1673bb6fbf74eed6aababb88c83e2. Scott Ullrich
10:37 PM Revision 00b9730d: Only load modules once
Scott Ullrich
10:36 PM Revision e4f3307c: Only load modules once
Scott Ullrich
10:12 PM Revision 427fa49c: Allow a ZMQ syslog address
Andrew Thompson
09:17 PM Revision 2ce206b0: CRL fixes for empty CRLs (so they don't kill OpenVPN)
Jim Pingle
09:16 PM Revision cfcc6994: CRL fixes for empty CRLs (so they don't kill OpenVPN)
Jim Pingle
08:43 PM Revision 0a81ee27: Adding ioncube_loader
Scott Ullrich
08:43 PM Revision 4a79ec20: Adding ioncube_loader
Scott Ullrich
03:15 PM Bug #1675: Captive portal logout problems with pop-up blockers.
The problem here is that a generic way of implementing this is needed.
Some javascript tricks are needed which with ...
Ermal Luçi
01:45 PM Revision 17ad7de4: Correct version in /etc/version to say what it is rather than the wrong thing from the merge.
Ermal LUÇI
01:39 PM Revision b2484fd2: Remove extra "/"
Warren Baker
12:31 PM Revision cdfdb1a7: Fix merge conflict
Jim Pingle
12:26 PM Revision d685dad4: Merge pull request #5 from smos/master
Welcome IPv6! Jim Pingle
11:32 AM Bug #1676 (Resolved): dead IPv6 gateway causes kernel panics
It appears just having an IPv6 gateway configured that's unreachable will result in panics several times a day, even ... Chris Buechler
11:26 AM Revision 0b07c763: fix missing "
Chris Buechler
11:09 AM Bug #1627 (Resolved): VPN VOIP Traffic Ignoring Traffic Shaper Queues
Ermal Luçi
10:58 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
Ermal great thanks for your fix,i had same problem(voip queue in ipsec vpn).After your last fix it's working just fin... Hafiz Rafiyev
10:12 AM Bug #1344: Replace prototype javascript code with jQuery
jQuery UI Core has a progress bar builtin:
http://jqueryui.com/demos/progressbar/
It is easy to control, is built...
G D
07:17 AM Bug #1344: Replace prototype javascript code with jQuery
Progress bar replacement?
http://t.wits.sg/misc/jQueryProgressBar/demo.php for the demo
http://t.wits.sg/jquery...
Warren Baker
09:43 AM Bug #1501 (Closed): Captive Portal Logout popup does not work
it does work Chris Buechler
07:30 AM Bug #1664: DHCP Server no longer allows empty gateway
I have tested and can confirm the fix.
It's working as expected now.
// rancor
rancor rancor
04:20 AM Revision a213ad18: Allow a ZMQ syslog address
Andrew Thompson

07/12/2011

11:57 PM Revision 8b6313a4: Merge remote-tracking branch 'upstream/master'
Conflicts:
etc/inc/easyrule.inc
etc/inc/filter.inc
etc/inc/interfaces.inc
etc/inc/ser...
Jim Pingle
10:22 PM Revision 0a213420: Fix botched patch, add closing bracket
Andrew Thompson
10:22 PM Revision f7c7eecb: Allow DHCP mappings to be resolved first for reverse lookups.
This was affecting a kerberos installation where the first DNS alias was
given for the PTR instead of the static DHCP...
Andrew Thompson
07:41 PM Revision c317af99: Create dynamodules in the order they where touche
Scott Ullrich
07:39 PM Revision fd3e19f3: Create dynamodules in the order they where touched
Scott Ullrich
05:13 PM Bug #1675 (New): Captive portal logout problems with pop-up blockers.
Need to change the Captive portal pop-up page to use techniques to bypass pop-up blockers. Ermal Luçi
04:59 PM Revision 3994cc70: Do a more strict check on this to avoid warnings
Ermal LUÇI
04:59 PM Revision d916bfab: Do a more strict check on this to avoid warnings
Ermal LUÇI
04:17 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Tried the latest snapshot which contains this patch, but still doesn't get the OVPN interface added to the bridge aft... Joost van den Broek
12:52 PM Feature #1673 (Rejected): PPTP VPN Server Address by Interface Name
That is not the IP to listen for connections on, it is the IP to be used by connecting clients as their gateway on th... Jim Pingle
12:43 PM Feature #1673 (Rejected): PPTP VPN Server Address by Interface Name
Could the ability to type the interface name (eg WAN) in the server address instead of just the IP address be added. ... Com DAC
10:20 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Andreas Bochem wrote:
> Same issue persisting on latest _2.0-RC3 (amd64) built on Mon Jul 4 16:49:48 EDT 2011_.
T...
Jim Pingle
07:10 AM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Same issue persisting on latest _2.0-RC3 (amd64) built on Mon Jul 4 16:49:48 EDT 2011_. Anonymous
04:08 AM Revision 649ea752: Fix botched patch, add closing bracket
Andrew Thompson
03:35 AM Revision aa994814: Allow DHCP mappings to be resolved first for reverse lookups.
This was affecting a kerberos installation where the first DNS alias was
given for the PTR instead of the static DHCP...
Andrew Thompson
03:13 AM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
What snapshot are you on?
There have been made some fixes lately to fix this can you please test?
By looking at the ...
Ermal Luçi

07/11/2011

09:32 PM Revision 1ee701fb: Enable the pfsync checking unconditionally
Ermal LUÇI
09:32 PM Revision 156ecb64: Enable the pfsync checking unconditionally
Ermal LUÇI
09:23 PM Bug #1627: VPN VOIP Traffic Ignoring Traffic Shaper Queues
2.0-RC2 (i386)
built on Fri Jun 10 21:40:17 EDT 2011
I added our config with ip's and keys changed, and a screen...
Abdiel Marin
09:05 PM Revision 514f63d1: Put a netmask of /32 to all parameters of -k/-K/-b of pfctl to avoid any issues.
Ermal LUÇI
09:05 PM Revision 639223f3: Put a netmask of /32 to all parameters of -k/-K/-b of pfctl to avoid any issues.
Ermal LUÇI
08:37 PM Revision 70013f06: Actually give pfsync time to catch up.
Ermal LUÇI
08:37 PM Revision 2eb9c02f: Actually give pfsync time to catch up.
Ermal LUÇI
08:33 PM Revision 6d8097b2: If the sync has not finished do not start carp yet
Ermal LUÇI
08:27 PM Revision 6930e805: If the sync has not finished do not start carp yet
Ermal LUÇI
06:26 PM Bug #1629: invalid state table entries after WAN IP change
I got the update installed last week but haven't had the IP change on me yet (surprisingly). I'll update this once t... Eli Hunter
05:04 PM Bug #1629: invalid state table entries after WAN IP change
Have you tested this on 2.0? Ermal Luçi
02:17 PM Bug #1634: Limiter and bridge needs special handling
There may also be some routing concerns when used on a bridge. See QYX-233317. Jim Pingle
01:50 PM Feature #1668: OpenVPN Client Export support Tunnelblick
Ok good to know. I don't have a Mac to try it out on but I know some of my users have Macs at home so the support qu... David Miller
01:46 PM Feature #1668: OpenVPN Client Export support Tunnelblick
The config archive works fine for Tunnelblick. Chris Buechler
01:41 PM Feature #1668: OpenVPN Client Export support Tunnelblick
I typo'ed the name of the client in the subject and don't have permissions to correct it. Could someone please corre... David Miller
01:33 PM Feature #1668 (Closed): OpenVPN Client Export support Tunnelblick
TunnelBrick is an opensource MacOSX OpenVPN client that seems to be pretty active. https://code.google.com/p/tunnelb... David Miller
12:58 PM Revision 3cfc695c: Fix gettext
Vinicius Coque
12:55 PM Revision 5237d356: Fixes #1666. For OpenVPN interfaces always check if part of bridge or not.
Ermal LUÇI
12:52 PM Revision 0b932972: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
12:41 PM Revision bf17eb72: Fixes #1666. For OpenVPN interfaces always check if part of bridge or not.
Ermal LUÇI
12:02 PM Revision fdbce60c: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
09:37 AM Bug #1667 (New): L2TP server does not respond properly from a CARP VIP
If you setup an L2TP server and try to connect to a CARP VIP on the same interface, it does not work. The server resp... Jim Pingle
08:55 AM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:5237d356f41b6ac44cabaaa17208795b8471abcd. Ermal Luçi
08:40 AM Bug #1666 (Feedback): OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:bf17eb72c18ee9b751f9e3eb22a082fd9c273ac9. Ermal Luçi
07:51 AM Bug #1666 (Resolved): OpenVPN interface doesn't get added to bridge after reboot
When using an interface assigned to an OpenVPN tap interface in a bridge, it won't be added correctly after rebooting... Joost van den Broek
05:07 AM pfSense Packages Bug #1631 (Resolved): incorrect syntax of /boot/loader.conf after open-vm-tools package installed
thanks Chris Buechler
04:55 AM pfSense Packages Bug #1631: incorrect syntax of /boot/loader.conf after open-vm-tools package installed
The same installation sequence now works fine. All OK. Ivars Strazdins

07/10/2011

08:11 PM Bug #1664 (Resolved): DHCP Server no longer allows empty gateway
Chris Buechler
12:05 PM Bug #1664: DHCP Server no longer allows empty gateway
Applied in changeset commit:7988ce7581efee9aef0184edfb2eeb2f352477a8. Anonymous
12:05 PM Bug #1664 (Feedback): DHCP Server no longer allows empty gateway
Applied in changeset commit:45d1024db3d3d32fb26f2b6c42460cbe98e24096. Anonymous
08:33 AM Bug #1664 (Resolved): DHCP Server no longer allows empty gateway
The default is to use the IP on this interface of the firewall as the gateway but if I leave this empty (default) it'... rancor rancor
04:11 PM Revision 24e5d98b: MFC: Do not check to see if gateway alls within a null value.
Scott Ullrich
04:04 PM Revision 45d1024d: Do not check to see if gateay falls within a null value. Resolves #1664
Scott Ullrich
04:03 PM Revision 7988ce75: Do not check to see if gateay falls within a null value. Resolves #1664
Scott Ullrich
05:08 AM Revision a5334f5c: fix text
Chris Buechler
05:07 AM Revision f745b8ef: fix text
Chris Buechler
03:54 AM Bug #1608 (Resolved): manual update on nanobsd and alix fails always
Chris Buechler
02:52 AM Bug #1608: manual update on nanobsd and alix fails always
this is fixed now Bipin Chandra
02:53 AM Bug #1053: CBQ per se, in kernel
will this be fixed in 2.0? Bipin Chandra
02:51 AM Bug #1582: traffic shaper queues bug
this is fixed now Bipin Chandra
01:09 AM Feature #1663 (Resolved): DHCPv6 relay
Need to add support for DHCPv6 relay. Can just copy DHCP Relay as DHCPv6 Relay, the existing dhcrelay supports IPv6 r... Chris Buechler
12:59 AM Bug #1662 (Resolved): DNS server gateway selection missing input validation
If a gateway is chosen for a DNS server on system.php, the gateway must be the same protocol as that of the DNS serve... Chris Buechler
12:57 AM Bug #1661 (Resolved): Missing input validation in system_routes_edit.php
system_routes_edit.php doesn't validate that the gateway selected is the same protocol as the entered "Destination ne... Chris Buechler
12:54 AM Bug #1660 (Resolved): Missing input validation in system_gateway_groups_edit.php
Members of a gateway group must all be of the same protocol, IPv4 or IPv6 only, not both. Currently you can create a ... Chris Buechler
12:53 AM Bug #1659 (Resolved): Missing input validation in rules gateway selection
Currently you can pick an IPv4 gateway for an IPv6 firewall rule, and an IPv6 gateway for an IPv4 firewall rule. Need... Chris Buechler

07/09/2011

03:36 PM Bug #1344: Replace prototype javascript code with jQuery
Neat tool for generating network maps!?
http://jsplumb.org/jquery/anchorDemo.html
Scott Ullrich
07:24 AM Revision 47b5ce1f: fix text
Chris Buechler
07:23 AM Revision 5eeb1d9d: fix text
Chris Buechler
02:21 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please post the system logs more complete not the ipsec related part?
Ermal,I special...
Hafiz Rafiyev

07/08/2011

09:29 PM Revision 2612ebc6: Ticket #1564. Give +x to the script so it can be executed. Simple hah :)
Ermal LUÇI
09:16 PM Revision 89bb7dcc: Ticket #1564. Give +x to the script so it can be executed. Simple hah :)
Ermal LUÇI
08:53 PM Bug #1658: Adding new Gateway in interface page needs input validation
it has no input validation currently (partially because it can't check the subnet before the interface is configured) Chris Buechler
08:50 PM Bug #1658 (Resolved): Adding new Gateway in interface page needs input validation
When adding a new gateway in the interface page, it asks you to specify a "Gateway Name" for the interface; when subm... Jeff Reid
05:42 PM Bug #1641 (Resolved): DHCP server default gateway needs input validation
Chris Buechler
12:54 PM Bug #1641: DHCP server default gateway needs input validation
Running 2.0-RC3 (i386) Fri Jul 8 06:31:45 EDT 2001
I just tried adding a gateway that was outside the subnet I'm u...
Josh Stompro
05:24 PM Bug #1657: Timezone should be synchronized on all utilities
this only applies when the tz is changed while the system is running, and has always been the case. I've always just ... Chris Buechler
04:43 PM Bug #1657 (Closed): Timezone should be synchronized on all utilities
During setup the timzeone is set correctly but some utilities in base do not honor it which creates some problems to ... Ermal Luçi
05:20 PM Bug #1598: IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
For what it's worth, I have a pair of devices running 2.0-BETA5 (8.1-RELEASE-p2 #0: Tue Jan 25 20:12:38 EST 2011 ... Steve Polyack
03:23 PM Bug #1279 (New): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
The filesystem is mounted noatime, so even if it's left rw, it still isn't touched except when the system wants to wr... Jim Pingle
03:19 PM Bug #1279: Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
Using nanobsd i386 8.1-release-p4 Jul 8 06:31:18 EDT 2011, after resetting to system default and rebooting, the / mou... Josh Stompro
02:41 PM Bug #673: SSHD keys not created on restore
I now see bug #1279, which discusses the rw nanobsd mount issue.
Josh
Josh Stompro
02:25 PM Bug #673: SSHD keys not created on restore
I'm not sure how to test this since in the latest snapshot the / mount is still set to rw by default. Erik, you ment... Josh Stompro
11:16 AM Bug #1501: Captive Portal Logout popup does not work
Running 2.0-RC3 (i386) Tur Jul 7 01:04:41 EDT 2011
The logout popup does work for me. I'm not using Radius or acc...
Josh Stompro
10:30 AM Feature #1656 (New): Teach pfctl to kill states by port number
It would be useful in the future if Diag > States could kill states more selectively by port number instead of only b... Jim Pingle
10:19 AM Bug #1653 (Resolved): CP timeout bug: get_last_activity
Ermal Luçi
10:07 AM Revision 650969bf: Merge branch 'master' of git@github.com:bsdperimeter/pfsense
Chris Buechler
09:21 AM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Basically it checks for invalid combinations. I did not feel safe to call is_alias(something) without making sure 'so... Evgeny Yurchenko
08:14 AM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Isnt this commit a bit drastic?
Possibly just check impossible combination should be enough?
Ermal Luçi
08:12 AM Bug #1639 (Feedback): Port alias missing input validation in firewall_rules_edit.php
Ermal Luçi
05:10 AM Bug #1655 (Rejected): Change WAN address and their gateway
changing the WAN IP and gateway works fine, whether in re-running the setup wizard or interfaces.php. Post to the lis... Chris Buechler
04:27 AM Bug #1655 (Rejected): Change WAN address and their gateway
When change the IP of the WAN and its gateway (the wizard proposes WANGW).
The gateway is not working properly, prob...
Oscar Francia
03:28 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Can you please post the system logs more complete not the ipsec related part? Ermal Luçi
12:49 AM Revision cfceda6d: Bug #1639. Port alias missing input validation in firewall_rules_edit.php.
Evgeny Yurchenko
12:46 AM Revision 5909b520: Bug #1639. Port alias missing input validation in firewall_rules_edit.php.
Evgeny Yurchenko

07/07/2011

11:32 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please test latest snapshots and see if this happends again.
Ermal any changes with l...
Hafiz Rafiyev
11:31 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Just tested the latest snapshot 2.0-RC3 (amd64) built on Thu Jul 7 16:01:09 EDT 2011 - no change. All VPNs still dro... David Rees
08:56 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
They're up now, the branch changed on the snapshots so the links were not pointing to the right place. Also, auto upd... Jim Pingle
07:23 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim P wrote:
> That snapshot was not created after Ermal's note. Please wait for the next new snapshot. It should be...
Hafiz Rafiyev
10:48 PM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
Commit https://github.com/bsdperimeter/pfsense/commit/cfceda6d3528d4cdb87fccdb00f28ce194bf393f Evgeny Yurchenko
10:01 PM Bug #1639: Port alias missing input validation in firewall_rules_edit.php
> A port alias can be assigned only as the "to" or "from" port, which is invalid and results in a pf syntax error.
...
Evgeny Yurchenko
10:21 PM Revision eaa549ea: Bug #1641 fix. DHCP server default gateway needs input validation.
Evgeny Yurchenko
10:10 PM Revision 9bc59815: Bug #1641 fix. DHCP server default gateway needs input validation.
Evgeny Yurchenko
08:26 PM Bug #1629: invalid state table entries after WAN IP change
That's expected to happen in 1.2.3 (it has no provisions for dealing with that scenario, only 2.0 does). Chris Buechler
08:12 PM Bug #1641: DHCP server default gateway needs input validation
Commit https://github.com/bsdperimeter/pfsense/commit/9bc59815c6eba7051a401404d4d0b0c7842a9d2f Evgeny Yurchenko
08:03 PM Revision 13b9dba9: Merge remote branch 'upstream/master'
Jim Pingle
07:59 PM Revision d8532e5d: $g needs to be a global. Resolves #1654
Scott Ullrich
07:58 PM Revision 44a4d54d: Reconfigure wan/lan when finishing wizard, or the new IPs will not be applied.
Jim Pingle
07:57 PM Revision 10f5d53c: Reconfigure wan/lan when finishing wizard, or the new IPs will not be applied.
Jim Pingle
07:16 PM Revision aa6798c0: $g needs to be a global. Resolves #1654
Scott Ullrich
05:01 PM Bug #1654: miniupnpd.pid located in wrong folder
gitsync my pfsense and noticed miniupnpd.pid is now located in /var/run after reboot
thanks again guys!
Cino .
04:49 PM Bug #1654: miniupnpd.pid located in wrong folder
thanks for the quick fix... I'll test once a new snapshot comes out Cino .
04:00 PM Bug #1654: miniupnpd.pid located in wrong folder
Applied in changeset commit:d8532e5db1abd2e4f6fd07998629936967fc9e67. Anonymous
03:15 PM Bug #1654 (Feedback): miniupnpd.pid located in wrong folder
Applied in changeset commit:aa6798c07088b4a45f85e2626576e33876d04263. Anonymous
03:03 PM Bug #1654 (Resolved): miniupnpd.pid located in wrong folder
Running snapshot Thu Jun 30 17:12:48 EDT 2011 currently and also noticed it on Jul 4th snapshot.
miniupnpd.pid is ...
Cino .
04:55 PM Revision fab60c5e: Merge remote-tracking branch 'mainline/master' into inc
Vinicius Coque
02:37 PM Revision 2108ada4: Use RELENG_2_0 for updates and gitsync default.
Jim Pingle
10:04 AM Feature #1652: Improvements in captive portal page
Lo Zio,
I like your suggestions, so I'm going to add my own wish list items for the CP here.
- Hide certain po...
Josh Stompro
09:38 AM Bug #1653: CP timeout bug: get_last_activity
I can confirm that this is fixed with the Jul 7 01:04:41 snapshot.
"ipfw table 1 entrystats 192.168.1.130" Now ret...
Josh Stompro
08:48 AM Bug #1653: CP timeout bug: get_last_activity
Also "Last activity" info from Captive portal status (/status_captiveportal.php?order=&showact=1) is wrong.
It shows...
Lo Zio
04:18 AM Bug #1653: CP timeout bug: get_last_activity
I confirm this is the behaviour of my previus bug report (1647).
As per previous request, here is the log:
Jul 6 13...
Lo Zio
08:49 AM Bug #1607 (Resolved): MBUF usage grows geometrically
Ermal Luçi
01:02 AM Bug #1607: MBUF usage grows geometrically
After 10 days uptime my MBUF Usage has almost completely levelled off at 6062 /9856. The second number was at 9730 fo... David Burgess

07/06/2011

09:41 PM Revision 6c76bd8d: Actually do pass an argument for second -b to avoid matching more tha supposed too.
Ermal LUÇI
09:40 PM Revision c13337f2: Actually do pass an argument for second -b to avoid matching more tha supposed too.
Ermal LUÇI
09:20 PM Revision c41f755c: Ticket #1646. Put netmasks of /32 to the parameters of pfctl -b to avoid that ocassions it matches more than it should.
Ermal LUÇI
09:19 PM Revision 66977fc7: Ticket #1646. Put netmasks of /32 to the parameters of pfctl -b to avoid that ocassions it matches more than it should.
Ermal LUÇI
09:05 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
That snapshot was not created after Ermal's note. Please wait for the next new snapshot. It should be uploading soon. Jim Pingle
09:04 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Ermal Luçi wrote:
> Can you please test latest snapshots and see if this happends again.
Just tested on 2.0-RC3 (...
David Rees
08:50 PM Revision 0f2826c0: Kill states from the previous ip the link had on all mpd consumers. Resolves #1629
Ermal LUÇI
08:50 PM Revision 8ed47897: Kill states from the previous ip the link had on all mpd consumers. Resolves #1629
Ermal LUÇI
06:59 PM Revision 3a26fb7f: Feature #1603. Correct nested urltable alias code to be more fullproof to errors and does not break the ruleset on large lists of urltables. Though this needs a revisit to work properly since it breaks urltable alias property of reloading contents.
Ermal LUÇI
06:52 PM Revision 5ffa3389: Feature #1603. Correct nested urltable alias code to be more fullproof to errors and does not break the ruleset on large lists of urltables. Though this needs a revisit to work properly since it breaks urltable alias property of reloading contents.
Ermal LUÇI
06:34 PM Revision 590b8a38: Merge remote branch 'upstream/master'
Jim Pingle
06:33 PM Revision b4a7f7f2: Add function to return a certificate's common name.
Jim Pingle
06:32 PM Revision b34b2b7d: Add function to return a certificate's common name.
Jim Pingle
06:11 PM Feature #1260: Allow other Backends for Remote Access ( SSL/TLS + User Auth )
Much appreciated!
Thanks
John Doe
04:10 PM Feature #1260 (Feedback): Allow other Backends for Remote Access ( SSL/TLS + User Auth )
I changed the code around a while back to allow this, didn't realize there was still a ticket hanging out for it. Thi... Jim Pingle
05:50 PM Bug #1549: Sip INVITE dropped.
I was able to reproduce the issue again, but the problem only lasted ~5 minutes before resetting itself. I was unable... William King
05:45 PM Bug #1646 (Feedback): 'pfctl -b' does not function as intended
Ermal Luçi
04:53 PM Bug #1646: 'pfctl -b' does not function as intended
Well today it kills if the first ip, passed on first -b, matches src address or if the second ip, passed as second -b... Ermal Luçi
05:20 PM Revision b8c372e5: Merge remote branch 'upstream/master'
Jim Pingle
05:19 PM Revision b7ca271f: Fix test for tun device, -f fails because it's a char device, not a regular file. -e works.
Jim Pingle
05:17 PM Revision 152f5759: Fix test for tun device, -f fails because it's a char device, not a regular file. -e works.
Jim Pingle
04:50 PM Bug #1629: invalid state table entries after WAN IP change
Applied in changeset commit:8ed478973f20678568f03f00309a5165aa48a1b3. Ermal Luçi
04:50 PM Bug #1629 (Feedback): invalid state table entries after WAN IP change
Applied in changeset commit:0f2826c03d3e3971f6d83041f9322737686846d9. Ermal Luçi
03:51 PM Feature #1603: URL table aliases should be usable within network type aliases
This is probably broken in the case when the urltablealias contents change and pfSense reloads the alias but not its ... Ermal Luçi
03:49 PM Revision efa38d08: Merge remote branch 'upstream/master'
Jim Pingle
03:48 PM Revision 292b356f: Fix use post here, since the other var isn't defined as it was before my commit yesterday.
Jim Pingle
03:47 PM Revision 9622da26: Fix use post here, since the other var isn't defined as it was before my commit yesterday.
Jim Pingle
03:34 PM Bug #1653 (Feedback): CP timeout bug: get_last_activity
Fixed on next snapshots thanks for reporting. Ermal Luçi
03:17 PM Bug #1653: CP timeout bug: get_last_activity
When I set idletimeout to blank the problem goes away.
When I set timeout to blank and idletimeout to 30, the prob...
Josh Stompro
02:58 PM Bug #1653 (Resolved): CP timeout bug: get_last_activity
Running 2.0-RC3(i386) Jul 4 17:29 Nanobsd.
Captive portal is expiring entries every cycle (60 seconds by default)....
Josh Stompro
03:02 PM Bug #1647 (Closed): Captive portal timeout
Closing in favor of #1653 which has a lot more detail and appears to be the same issue. Jim Pingle
01:13 PM Bug #1647: Captive portal timeout
Please give the captiveportal log when this happens?
Also what is the idle timeout value you configure?
Ermal Luçi
08:50 AM Bug #1647: Captive portal timeout
Tried to unset the proxy transparent mode. Same thing.
Uninstalled squid, same thing.
It seems to log the user out ...
Lo Zio
08:29 AM Bug #1647 (Feedback): Captive portal timeout
Have you tried this without squid installed? And this works normally without an idle timeout defined? Jim Pingle
07:56 AM Bug #1647 (Closed): Captive portal timeout
using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
On captive portal, after setting a IDLE timeout (not t...
Lo Zio
02:55 PM pfSense Packages Bug #1587 (Feedback): The openvpn client configuration exporter doesn't enforce TLS subject verification
Applied in changeset commit:e366b753b24d8cadbe15bc6778e46c3159dc9983. Jim Pingle
01:41 PM Revision 5a4c0b5c: Merge remote branch 'upstream/master'
Conflicts:
etc/version
Jim Pingle
01:38 PM Revision 00243d59: Fix select detection code for the RADIUS NAS IP. Fixes #1648
Jim Pingle
01:35 PM Revision 54dd9832: Fix select detection code for the RADIUS NAS IP. Fixes #1648
Jim Pingle
01:30 PM Revision 1fbd1878: Implement gettext
Vinicius Coque
12:49 PM Bug #1344: Replace prototype javascript code with jQuery
2.0 has Growl support already. Might be nice to use the jGrowl deal. Scott Ullrich
12:39 PM Bug #1344: Replace prototype javascript code with jQuery
Other Growl style notifications:
-----------------------
jGrowl
URL: http://stanlemon.net/projects/jgrowl.html
...
G D
06:32 AM Bug #1344: Replace prototype javascript code with jQuery
Also another notification bar called foobar http://themergency.com/foobar/ - which is pretty neat.
Then there is als...
Warren Baker
12:41 PM Revision 1623ed97: Merge remote-tracking branch 'mainline/master' into inc
Conflicts:
etc/inc/priv.defs.inc
Vinicius Coque
12:29 PM Revision b22fbdd2: Spelling fix.
Warren Baker
10:58 AM Revision f49c41c5: Spelling fix.
Warren Baker
09:40 AM Bug #1648: NAS IP setting
Applied in changeset commit:00243d599dcb840eccf52f39f6d7da28d3605528. Jim Pingle
09:35 AM Bug #1648 (Feedback): NAS IP setting
Applied in changeset commit:54dd98320d569f7f1c6041ec06dfe84c05948161. Jim Pingle
08:08 AM Bug #1648: NAS IP setting
And the data sent to the RADIUS server is ok. It is an interface problem. Lo Zio
07:59 AM Bug #1648 (Resolved): NAS IP setting
Using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
Trying to set:
RADIUS NAS IP attribute
in captive po...
Lo Zio
08:29 AM Bug #1650: IE9 logs off
Confirmed, it does log the user out. Yet another reason not to use IE... :-)
Jim Pingle
08:05 AM Bug #1650 (Resolved): IE9 logs off
using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
Using IE9, clicking Status->Traffic graphs logs the u...
Lo Zio
08:22 AM Bug #1649 (Rejected): Schedule is blocking outside its range instead of passing the traffic
On 2.0 the rules do not have the opposing effect as they did on 1.2.3 when off-schedule. They merely act like they do... Jim Pingle
07:59 AM Bug #1649 (Rejected): Schedule is blocking outside its range instead of passing the traffic
I did some testing with schedules. For this created a schedule to block traffic between 00:00 and 06:00 every day.
B...
A B
08:21 AM Feature #1652 (Closed): Improvements in captive portal page
Using 2.0-RC3 (i386)
built on Mon Jul 4 16:48:37 EDT 2011
In Portal page contents:
- ability to revert to stan...
Lo Zio
08:13 AM pfSense Packages Bug #1651 (Closed): Removing Squidgard removes squid
Removing squidguard version
Beta
1.4_2 pkg v.1.9
platform: 1.1
removes installed squid in an unclean manner.
...
Lo Zio
07:31 AM Feature #1214: Firewall Schedule Time Should Be Allowed to Straddle Midnight
I got the same error again with 2.0-RC3 (amd64) built on Fri Jun 24 19:26:29 EDT 2011.
Could not create a schedule...
A B
06:47 AM Bug #1445: Trouble with interface msk0 (Marvell Yukon 88E8057 Gigabit Ethernet)
I have the problem too with the RC3 version of pfsense, according to
http://freebsd.1045724.n5.nabble.com/msk0-in...
George M

07/05/2011

09:13 PM Bug #1629: invalid state table entries after WAN IP change
PPPoE is supposed to clear all states on that interface when an IP changes, that's not happening correctly. Chris Buechler
09:00 PM Bug #1629: invalid state table entries after WAN IP change
Hopfully this is what you wanted.
My IP before the address changed was 76.254.18.100 and the new assigned addres...
Eli Hunter
09:11 PM Bug #1646 (Resolved): 'pfctl -b' does not function as intended
'pfctl -b' should selectively kill states for a single IP/gateway, but what it really does is wipe all states (or clo... Chris Buechler
08:31 PM Revision fbaec9eb: Add issing include to avoid PHP fatal error when calling enable_rrd_graphing()
Scott Ullrich
08:28 PM Revision 76f5d95c: Add issing include to avoid PHP fatal error when calling enable_rrd_graphing()
Scott Ullrich
08:21 PM Revision b36cf3fc: Add checks for miniupnpd to avoid php errors.
Ermal LUÇI
08:20 PM Revision f7ee0818: Add checks for miniupnpd to avoid php errors.
Ermal LUÇI
07:45 PM Revision 6108a08c: Fix handling of interface selectors in packages.
Jim Pingle
07:43 PM Revision 8aafd58e: Fix handling of interface selectors in packages.
Jim Pingle
03:16 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I can, on another system, had to remove the one failing from production. Should know something by tomorrow.
Th...
Derrick Conner
03:02 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Can you please test latest snapshots and see if this happends again. Ermal Luçi
02:37 PM Bug #1344: Replace prototype javascript code with jQuery
Another alerting jQuery plugin: http://boedesign.com/demos/gritter/ Scott Ullrich
01:34 PM Bug #1344: Replace prototype javascript code with jQuery
For log/state/etc... tables, I would highly recommend the DataTables jQuery plugin ( http://www.datatables.net ). I h... G D
01:07 PM Bug #1344: Replace prototype javascript code with jQuery
Possible on / off / service buttons: http://www.givainc.com/labs/ibutton_example.htm Scott Ullrich
01:03 PM Bug #1344: Replace prototype javascript code with jQuery
This will be a great alerts replacement: http://www.red-team-design.com/wp-content/uploads/2011/07/cool-notification-... Scott Ullrich
09:07 AM pfSense Packages Bug #1631 (Feedback): incorrect syntax of /boot/loader.conf after open-vm-tools package installed
Jim Pingle
08:53 AM Bug #1642 (Rejected): Occasional Easy rule creation failure when IP == WAN Address
Without a lot more detail this is impossible to track down. Please start a forum thread and see if anyone else has ha... Jim Pingle
01:39 AM pfSense Packages Bug #1640 (Closed): Error to use squidguard with username
Chris Buechler
01:32 AM pfSense Packages Bug #1640: Error to use squidguard with username
Mukesh Patel wrote:
> its not a bug, please try with single or double coat i.e "mpatel" or 'mpatel'
Yes, the user...
Serg Dvoriancev
01:30 AM Revision 579f00da: Make it HEAD since we already have builder code using this
Scott Ullrich
01:29 AM Revision dc4106cf: Version bump master branch to MASTER
Scott Ullrich

07/04/2011

11:53 PM Revision 088de6b1: Revert "Revert "Simplify message""
This reverts commit 6f385195612e5d5aaa9b870c293f81692785cd47. Scott Ullrich
11:53 PM Revision a9ee006d: Revert "Revert "Add php errors (non warnings) to the crash reporter""
This reverts commit eac584f3b61de3513baf54633d9a9b854ff6eb03. Scott Ullrich
11:39 PM Revision eac584f3: Revert "Add php errors (non warnings) to the crash reporter"
This reverts commit cb61dad8ab812a3740648dc0e3f4b74959713ef3. Scott Ullrich
11:39 PM Revision 6f385195: Revert "Simplify message"
This reverts commit 6608507d3ba546a8a0c9ce2d6570f98d5494f11e. Scott Ullrich
11:32 PM Revision 6608507d: Simplify message
Scott Ullrich
11:30 PM Revision cb61dad8: Add php errors (non warnings) to the crash reporter
Scott Ullrich
11:26 PM Revision 88dadca1: Copy crash file to crash reporter directory if it exists
Scott Ullrich
11:21 PM Revision e9b5f8c7: Oops use ;
Scott Ullrich
11:19 PM Revision 001c5e8a: Show errors.
Scott Ullrich
07:56 PM Revision 1a863be2: If vouchers are disabled do not allow users to authenticate thorugh existing(active/in use) vouchers. Reported-by: http://forum.pfsense.org/index.php/topic,38342.0.html
Ermal LUÇI
07:16 PM Bug #1645 (Rejected): CARP sync problem for deleting process.
not sure what you're referring to, deleting, adding, everything with config sync is working fine on the latest 2.0 ve... Chris Buechler
04:38 PM Bug #1645 (Rejected): CARP sync problem for deleting process.
Can not be sync to backup server for the virtual Ips, nat, load balancer and aliases record deleting process ın the c... Atıf CEYLAN
06:48 PM Revision c3ebb669: Launch running script as well
Scott Ullrich
03:11 PM Revision 769c4591: Merge remote-tracking branch 'upstream/master'
Jim Pingle
06:04 AM Bug #1642 (Rejected): Occasional Easy rule creation failure when IP == WAN Address
Applies to: 2.0-RC3 (i396) built on Sun Jul 3 13:02:53 EDT 2011
Attempting to use the "easy rule" feature for Dest...
Cyrus Patel
05:52 AM pfSense Packages Bug #1640: Error to use squidguard with username
its not a bug, please try with single or double coat i.e "mpatel" or 'mpatel' Mukesh Patel
12:32 AM pfSense Packages Bug #1640: Error to use squidguard with username
I'm not sure that's a bug, you should post to the forum for help. Chris Buechler
12:21 AM pfSense Packages Bug #1640 (Closed): Error to use squidguard with username
Hi,
I installed the squidguard module. In SERVICE -> PROXY FILTER -> GROUP ACL, I created an ACL and when I try to...
Alan Testoni
05:13 AM Revision d9489532: Don't check OpenVPN ports in use against disabled clients or servers
Chris Buechler
03:40 AM Bug #1549: Sip INVITE dropped.
Evgeny Yurchenko wrote:
> No packet-dumps so far (details are on forum)?
I have been unable to catch the issue ag...
William King
02:41 AM Revision 32cd7c36: Add rc.local.running if rc.local is running so it can reattach after a console logout
Scott Ullrich
02:13 AM Bug #636: layer7 not work correctly
Latest version has the same problem.
Jul 4 02:15:14 ipfw-classifyd: Loaded Protocol: citrix (rule altq)
Jul 4 02...
Jonathan Puddle
01:04 AM Feature #1603: URL table aliases should be usable within network type aliases
I am sorry, did not pay attention to target version, just felt that it was doable. Evgeny Yurchenko
12:58 AM Feature #1603 (Feedback): URL table aliases should be usable within network type aliases
Evgeny - this is ok but in the future please don't commit anything with a target 2.1 to 2.0. Chris Buechler
12:40 AM Bug #1545: Dynamic DNS updates fail on 3G connections
OK, 3 Jul snapshot managed to keep the interface up over an IP change. Still not updating dynamic DNS:
Jul 4 16:3...
Ross Williamson
12:31 AM Bug #1641 (Resolved): DHCP server default gateway needs input validation
The DHCP server screen allows any IP as the gateway IP, needs input validation there to ensure only IPs within that s... Chris Buechler
 

Also available in: Atom