Project

General

Profile

Activity

From 08/11/2011 to 09/09/2011

09/09/2011

03:55 PM Feature #1868 (Needs Patch): RFE: DHCP Server option pull-down menus, pre-populated data types
It would be great to be able to pull down a menu when setting the advanced DHCP server options. The link given in th... Bill McGonigle
03:43 PM Feature #1867 (Closed): RFE: DHCP Server option to set interface-MTU option to lowest WAN interface value
I have a setup with a Multi-WAN configuration, with one cable modem with MTU 1500 and one DSL modem, MTU 1492. After... Bill McGonigle
03:16 PM Revision ae0023be: Don't try to unset this variable if it isn't set to begin with. Fixes #1865
Jim Pingle
03:15 PM Revision 98a4cdc2: Don't try to unset this variable if it isn't set to begin with. Fixes #1865
Jim Pingle
02:49 PM Todo #1863: consistence in alias usage
happy to learn it (red background)
for me it is ok, I won't loose time anymore in creating 10 rules with varying t...
Franck Bourdonnec
02:27 PM Todo #1863: consistence in alias usage
Red background on a form field means an alias can be used. That is consistent throughout the entire GUI. Jim Pingle
02:26 PM Todo #1863: consistence in alias usage
"other" includes aliases. Just for you (-:
Can you for 1 minute impersonate someone discovering pfsense.
He sees ...
Franck Bourdonnec
11:15 AM Bug #1865: Fatal error by saving System: Advanced: Miscellaneous
Applied in changeset commit:98a4cdc2a27cb5723ba3c01e64cee980691be2a4. Jim Pingle
11:15 AM Bug #1865 (Feedback): Fatal error by saving System: Advanced: Miscellaneous
Applied in changeset commit:ae0023beeaa0da21cf2080e81cec9631bee63c8e. Jim Pingle
09:40 AM Bug #1865 (Resolved): Fatal error by saving System: Advanced: Miscellaneous
pfSense 2.0-RC3 (i386) built on Thu Sep 8 15:15:55 EDT 2011
When I click on the save button appears this error m...
Anonymous
10:09 AM Bug #1866 (Rejected): Dashboard: System Information: CPU Type no longer shows powersave details
The CPU frequency for power saving is only printed if the current frequency does match the highest frequency. If you ... Jim Pingle
09:50 AM Bug #1866 (Rejected): Dashboard: System Information: CPU Type no longer shows powersave details
pfSsense 2.0-RC3 (i386) built on Thu Sep 8 15:15:55 EDT 2011
Since this or previous snapshot the power saving de...
Anonymous
08:40 AM Revision 65319e4c: fix firewall_nat_out to not auto-generate outbound NAT rules with one too many IPs
Chris Buechler
08:39 AM Revision 70ec6cc2: fix firewall_nat_out to not auto-generate outbound NAT rules with one too many IPs
Chris Buechler
08:13 AM Feature #1864 (Resolved): "Start" button for IPsec should be available for IP alias networks
If the local subnet of an IPsec network is an IP alias, the "start" button under Status>IPsec doesn't show up. That's... Chris Buechler
02:35 AM Bug #1419: Incorrect Intel License information in dmesg
Found a copy:
http://cygnus.redirectme.net/FreeBSD_4.9_Docs/legal/intel_ipw/LICENSE
We should be careful of thi...
Bill McGonigle

09/08/2011

06:08 PM Todo #1863 (Rejected): consistence in alias usage
"other" includes aliases. Chris Buechler
06:01 PM Todo #1863 (Rejected): consistence in alias usage
Hello,
please make the 'Destination Port from' field display something like
'single port or alias' to be consistent...
Franck Bourdonnec
05:49 PM Revision d523215b: Show friendly interface names
Ermal LUÇI
05:48 PM Revision 7c7d856c: Show friendly interface names
Ermal LUÇI
05:34 PM Bug #1851: ECC-Cert breaks the webconfigurator
maybe we want to "block" uploading the following curves until working ... Michal Fresel
05:22 PM Bug #1851: ECC-Cert breaks the webconfigurator
gen... Michal Fresel
04:53 PM Bug #1851: ECC-Cert breaks the webconfigurator
I think lighty need it enable in config and presently we do not enable sslv3. Ermal Luçi
04:50 PM Bug #1851: ECC-Cert breaks the webconfigurator
from /var/log/lighttpd.error.log ... Michal Fresel
04:41 PM Feature #1860: Allow NTP server to be overriden by WAN DHCP
will try to make it more readable in the future - hopefully ;) Michal Fresel
04:03 PM Feature #1860 (New): Allow NTP server to be overriden by WAN DHCP
ok I misunderstood what you were talking about there. I fixed the description to be more clear. Jim Pingle
03:36 PM Feature #1860: Allow NTP server to be overriden by WAN DHCP
pushing the official NTP-servers (counting 3) for my country by DHCP - so it is a reputable source declared by law.
...
Michal Fresel
03:18 PM Feature #1860 (Rejected): Allow NTP server to be overriden by WAN DHCP
The server entered for pfSense is used by the NTP daemon as its upstream source - you can't have pfSense use only its... Jim Pingle
03:16 PM Feature #1860 (Needs Patch): Allow NTP server to be overriden by WAN DHCP
As with DNS, (optionally) allow the upstream DHCP server to provide NTP servers to the firewall. Michal Fresel
03:22 PM Bug #1861: false log filterdns: host_dns: failed looking up "88.192.1250.131"
(fyi, searching '1250' in a fresh backup gives nothing of course) Franck Bourdonnec
03:17 PM Bug #1861 (Closed): false log filterdns: host_dns: failed looking up "88.192.1250.131"
Hello,
I made a typo while entering an IP in a alias object.
1250 instead of 250
I validated the alias (5 IP l...
Franck Bourdonnec
02:52 PM Feature #1859: default SSH-key should at least use 2048 bit RSA-keys
plz also read "further reading" from bug #1858 Michal Fresel
02:50 PM Feature #1859 (Resolved): default SSH-key should at least use 2048 bit RSA-keys
after installing a new box the system-SSH-key should default to 2048 or even 4096 bit RSA-keys... Michal Fresel
02:31 PM Feature #1858: default SSL-cert should at least use 2048 bit RSA-keys
key-sizes above 8192 will not work on Safari (Mac OS X) Michal Fresel
02:08 PM Feature #1858 (Resolved): default SSL-cert should at least use 2048 bit RSA-keys
after installing a new box the system-SSL-cert should default to 2048 or even 4096 bit RSA-keys
current: RSA - 102...
Michal Fresel
01:47 PM Bug #1849: Traffic shaper - By Queue view needs to show/use friendly inerface names
The friendly interfaces are shown now.
Remaining is showning the root interface so they can be cloned
Ermal Luçi
01:46 PM Bug #1857: LAN-if does not check if there is already another host using that address
so expecting a "feature" for the console would not be implemented either:
> ##external management-host##...
Michal Fresel
01:34 PM Bug #1857: LAN-if does not check if there is already another host using that address
We can't stop everyone from shooting themselves in the feet.
Changing the default LAN behavior to anything but st...
Jim Pingle
01:32 PM Bug #1857: LAN-if does not check if there is already another host using that address
I agree with Jim. This is not going in but thanks for the suggestion.
Scott Ullrich
01:28 PM Bug #1857: LAN-if does not check if there is already another host using that address
hi Jim,
somehow i still do not understand WHAT can get wrong?
I know it is not simple and some coding is needed
...
Michal Fresel
01:01 PM Bug #1857: LAN-if does not check if there is already another host using that address
Still too many things to go wrong. It is not that simple.
And the real fix is even simpler: Just don't plug a new ...
Jim Pingle
12:56 PM Bug #1857: LAN-if does not check if there is already another host using that address
hi Jim,
x) send just 1 (one) ICMP package for ping
x) single pings to the whole subnet concurrently and wait for ...
Michal Fresel
12:23 PM Bug #1857 (Rejected): LAN-if does not check if there is already another host using that address
It's a lot of work and a lot to go wrong for very little benefit there. If someone is concerned about it taking over ... Jim Pingle
12:19 PM Bug #1857: LAN-if does not check if there is already another host using that address
maybe we set the LAN-if to DHCP to test if there is already a server and that way we obtain an IP (this way we know t... Michal Fresel
11:55 AM Bug #1857 (Rejected): LAN-if does not check if there is already another host using that address
when a new installation is booting it should check if there is already another host using the default ip of 192.168.1.1 Michal Fresel
10:29 AM Revision 21c16036: Move filter box up to the top, so it is more easily accessible
Warren Baker
08:07 AM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
On the 2.1 IPv6 snaps dating September 1st I can not replicate this anymore, this may have been fixed somewhere by an... Seth Mos
06:28 AM Feature #1854 (Feedback): filter field on diag_logs_filter.php should be at top of page
Applied in commit:21c160361dff36941812424390c10a235762b411 Warren Baker
05:49 AM Feature #1855: NAT before IPsec VPN
Just to synchronize the answer
http://forum.pfsense.org/index.php/topic,38559.msg210340.html#msg210340
Ermal Luçi
02:52 AM Feature #1855: NAT before IPsec VPN
The linked info is still OpenBSD-only I believe. Chris Buechler
01:23 AM Feature #1855: NAT before IPsec VPN
Thanks to FreeBSD 9 it should be now possible to NAT before the VPN in order to solve network overlapping.
Here htt...
Michele Di Maria
01:14 AM Feature #1855 (Closed): NAT before IPsec VPN
I thought we already had a feature ticket open for IPsec+NAT in general but doesn't appear so. Michele Di Maria
05:18 AM Bug #1856 (Closed): Removing a Phase 2 does not remove the SPD policy
Removing a IPv6 phase 2 entry leaves the IPsec SPD policy in place.
Deleting it manually from the IPsec status SPD...
Seth Mos
02:34 AM Todo #595 (Closed): Test IPsec with NAT
what's mentioned in this ticket works, there are other caveats with IPsec and NAT Chris Buechler

09/07/2011

10:10 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
Alright, please give me a few weeks, as I am really far behind in my projects, thank you again for this quick fix. I ... Matt Crook
08:18 PM Revision 50779708: Correct check
Ermal LUÇI
07:59 PM Revision ebc0e4b6: Add support for multiple radius server to be used during authentication
Ermal LUÇI
07:08 PM Bug #1437 (Resolved): More validation needed on CSR generation
thank you Chris Buechler
06:42 PM Feature #1854 (Resolved): filter field on diag_logs_filter.php should be at top of page
The filter field on diag_logs_filter.php should be at the top of the page, like the states display, as if you have a ... Chris Buechler
06:07 PM Revision 5b4f3f1b: Remove duplicated occurence during merging
Ermal LUÇI
04:07 PM Bug #1850: WAN interface missing on traffic shaper queue interface
Ermal Luçi wrote:
> I cannot see this driver in FreeBSD 8.1 did you compile from some patch of sorts?
The driver ...
Oliver Loch
03:42 PM Bug #1850 (Closed): WAN interface missing on traffic shaper queue interface
driver doesn't exist in stock releases Chris Buechler
09:50 AM Bug #1850: WAN interface missing on traffic shaper queue interface
I cannot see this driver in FreeBSD 8.1 did you compile from some patch of sorts? Ermal Luçi
09:49 AM Bug #1850: WAN interface missing on traffic shaper queue interface
Hi,
after checking that altq is implemented into the driver, I added it to the is_altq_capable() function in the "...
Oliver Loch
06:44 AM Bug #1850 (Closed): WAN interface missing on traffic shaper queue interface
Hi,
running the latest 2.0RC3:
2.0-RC3 (amd64)
built on Tue Sep 6 22:44:22 EDT 2011
the WAN interface is m...
Oliver Loch
03:53 PM Feature #1846: strict nat 1-to-1
Having a /32 IP on an interface and a gateway on another subnet is not a valid pfSense configuration, and thus not su... Jim Pingle
03:43 PM Feature #1846: strict nat 1-to-1
then we have a problem.....!
If i read well, nat-1-to-1 is in both direction, when an interface is 'wan'.
You a...
Franck Bourdonnec
01:54 PM pfSense Packages Bug #1853 (Resolved): Barnyard2 binary not installed
After installing snort (2.8.6.1 pkg v 2.0) on pfsense 2.0-RC3 (amd64) (built on Tue Sep 6 22:44:22 EDT 2011) barnyard... david campbell
01:04 PM Revision 00257cf5: Remove references to undeclared table
Ermal LUÇI
01:04 PM Revision b4792bf8: Add the multi instance CP to master branch. This allows to define CP with different properties on different interfaces.
Ermal LUÇI
01:03 PM Revision 7bc6d62b: Remove references to undeclared table
Ermal LUÇI
11:06 AM Revision 9b55203f: Show the hexadecimal value of the integer for readability
Seth Mos
10:55 AM Bug #1851 (Feedback): ECC-Cert breaks the webconfigurator
Applied in changeset commit:f65b6851ea3d473128e48419450f0edb5d8830d9. Jim Pingle
10:25 AM Bug #1851: ECC-Cert breaks the webconfigurator
some ecc-test-certificates are available at "SECG's ECC/TLS test server":http://tls.secg.org/index1.php?action=server... Michal Fresel
07:16 AM Bug #1851: ECC-Cert breaks the webconfigurator
known bugs in lighttpd - fixed in 1.4.29
see http://www.lighttpd.net/2011/7/3/1-4-29
Michal Fresel
06:57 AM Bug #1851 (Closed): ECC-Cert breaks the webconfigurator
Uploading a certificate which is using Elliptic curve cryptography (ECC) - afterwards webconfigurator stops respondi... Michal Fresel
09:09 AM pfSense Packages Bug #1852 (Closed): Snort and IP-Block Installation/Deintsallation issue
If you install snort, it replaces system Perl with Perl-multi-threaded. Once you remove snort it removes Perl-multi-t... Darko Arandjelovic
03:37 AM Bug #1849 (New): Traffic shaper - By Queue view needs to show/use friendly inerface names
Traffic shaper - By Queue view needs to use friendly inerface names to allow easy configuration and presentation.
Al...
Ermal Luçi
02:57 AM Bug #1848 (Confirmed): Limiters after policy routing has taken place do not behave correctly
If there are 2 WANs and the primary one fails and there are limiters configured in floating rules(after policy routin... Ermal Luçi

09/06/2011

10:38 PM Revision 7179d00e: Match pftop page exatly with privilege, there is no other page that glob would catch. Fixes #1845
Jim Pingle
10:37 PM Revision fce938b3: Match pftop page exatly with privilege, there is no other page that glob would catch. Fixes #1845
Jim Pingle
10:06 PM Bug #1437: More validation needed on CSR generation
I have so much going on, I thought I replied to this, but I guess I did not.
Everything that I did to cause an err...
Yehuda Katz
09:56 PM Bug #1437: More validation needed on CSR generation
should be fixed, awaiting Yehuda's confirmation Chris Buechler
09:57 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
should be fixed, will leave for confirmation Chris Buechler
09:53 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
if someone wants to see this get fixed in short order, purchase a 5 hour support subscription at portal.pfsense.org a... Chris Buechler
09:49 PM Bug #1318 (Resolved): Certificate error: certificate subject does not match signing request subject
Chris Buechler
09:47 PM Bug #1646 (Resolved): 'pfctl -b' does not function as intended
Chris Buechler
09:45 PM Bug #1552 (Resolved): DNS Reject Rule Crashes Router
Chris Buechler
09:44 PM Bug #1696 (New): Panic when finishing setup wizard with PPPoE WAN
no change
Chris Buechler
09:30 PM Bug #1517 (Closed): Captive Portal sends RADIUS output accounting packets with zero value
this has been confirmed working. Chris Buechler
08:25 PM Revision 3aa114d5: Add proper validation to the services_rtadvd_configure() to only pick up the IPv6 nameservers if any
Ticket #1836 Seth Mos
07:07 PM Feature #972: Allow adding gateways outside of interface subnet
well, OVH big big french provider is also using this king of setup
A well english detailled big page explain all h...
Franck Bourdonnec
06:50 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
yes, I have added the 'dashboard' as small fixe, because all other unauthorized pages goes to 404.
In future release...
Franck Bourdonnec
06:36 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
The privilege system will redirect the user to whichever page is listed first in their permissions (which they are al... Jim Pingle
06:35 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
Applied in changeset commit:fce938b3a32ed071edf9aba6b1f07ec08a82a743. Jim Pingle
06:35 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
Applied in changeset commit:7179d00e0b0134615e442829792960f343b8a378. Jim Pingle
06:06 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
menu system/user/manager
add a group
fix a few status/logs page among all proposed priviledges
create a user
ad...
Franck Bourdonnec
05:49 PM Bug #1845 (Feedback): diag_system_pftop 404 not found = cardiac crisis
not sure what you're referring to Chris Buechler
05:47 PM Bug #1845 (Resolved): diag_system_pftop 404 not found = cardiac crisis
Hello,
after day and day of tuning/discovering, I had tried the user/group settings to build a person able to consul...
Franck Bourdonnec
06:46 PM Feature #1847 (Rejected): Relax gateway checking
Duplicate of #972 Jim Pingle
06:44 PM Feature #1847 (Rejected): Relax gateway checking
Hello,
During network lessons at school you learn that the gateway must be reachable with an IP in the same subnet...
Franck Bourdonnec
06:21 PM Feature #1846: strict nat 1-to-1
it is both directions, where traffic is set to leave the interface where that 1:1 is assigned. Read http://pfsense.or... Chris Buechler
06:19 PM Feature #1846: strict nat 1-to-1
oh, I see no reason why you call nat-1to-1 when traffic is internet toward natted machine (B) and routing when it is ... Franck Bourdonnec
06:04 PM Feature #1846 (Rejected): strict nat 1-to-1
rules including policy routing and NAT are separate entities that must be configured as you desire. Chris Buechler
06:01 PM Feature #1846 (Rejected): strict nat 1-to-1
Hello,
Add a check box in NAT One to One that make it more strict.
Explanation
my system have
Two WAN inter...
Franck Bourdonnec
05:48 PM pfSense Packages Bug #1844: diag_system_pftop 404 not found = cardiac crisis
please close this one, I recreated it in 'pfsense' . Franck Bourdonnec
05:48 PM pfSense Packages Bug #1844 (Rejected): diag_system_pftop 404 not found = cardiac crisis
duplicate of #1845 Chris Buechler
05:39 PM pfSense Packages Bug #1844 (Rejected): diag_system_pftop 404 not found = cardiac crisis
Hello,
after day and day of tuning/discovering, I had tried the user/group settings to build a person able to consul...
Franck Bourdonnec
05:33 PM Bug #337: sticky connections do not work
Ermal, can you please check your last commit. I can confirm that sticky sessions work for me on snapshot 2.0-RC3 (i3... I K
05:29 PM Revision f8707b15: Also show queues on limiter info page, so that the child queues of limiter pipes can be viewed. (See ticket #1843)
Jim Pingle
05:29 PM Revision da2bee02: Also show queues on limiter info page, so that the child queues of limiter pipes can be viewed. (See ticket #1843)
Jim Pingle
08:12 AM Feature #1843 (Resolved): Diag > Limiter Info does not show queues under pipes
Under Diagnostics > Limiters, it only shows the limiter pipes and does not display any information about the child qu... Jim Pingle
04:23 AM pfSense Packages Bug #1842: problem with FreeRADIUS?
This is a package issue and not a Captive portal issue from what you have posted here. Ermal Luçi
03:45 AM pfSense Packages Bug #1842 (Closed): problem with FreeRADIUS?
With CP & vouchers, say a 1 hour voucher never kicks off/logs out the end user after an hour.
After searching there ...
Rob Heat
03:03 AM Bug #1841 (Duplicate): TCP state issue when traffic passing through a GRE tunnel within IPSEC
When running a GRE tunnel between two Pfsense 2.0 RC3 TCP traffic is shown as having its SYN/ACK packets dropped on t... Nigel Wright

09/05/2011

08:29 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
Ermal Luçi wrote:
> HAve you tested with latest snapshots?
Hi Ermal,
No, I haven't; just came back from holida...
Florent Daigniere

09/04/2011

04:29 PM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
That's good to know, we'll investigate. We're still not quite sure what's happening, some ipv6 builds seem to hit it ... Seth Mos
04:26 PM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
These errors showed up on the upgrade, and are associated with the upgrade process, not trying to display the graphs.... Eddie Atherton

09/03/2011

08:18 PM pfSense Packages Bug #1753: Spoink integration
Thanks to pfsense developers for the new version of snorte with the block offenders working, i've enabled it on my pf... Walter Gomes
06:01 PM Revision a04959b8: Also add the new RDNSS fields to the rtadvd config for prefix delegation cases.
Seth Mos
05:58 PM Revision f535d5a0: Now that our rtadvd binary supports RDNSS we can tack the search domain and DNS servers onto the stack.
Ticket #1836 Seth Mos
05:48 PM Revision 520c3d61: Remove the gateway field from view since it is not a valid option for now.
Seth Mos
04:29 PM Feature #1829: CARP with IPv6 support
ah, you mean the rtadvd settings? That would make sense, I tied them into the dhcp6 config as that seems the most str... Seth Mos
04:01 PM Feature #1829: CARP with IPv6 support
My thought was actually keeping it in the DHCPv6 screen even though it has nothing to do with it, since we already ha... Chris Buechler
02:59 PM Feature #1829: CARP with IPv6 support
Ah, yes, well, the gateway field needs to go from the dhcpv6 config in the UI since it doesn't exist.
Complain to th...
Seth Mos
02:22 PM Bug #1839: No Quality RRD Graph w/ Non-Default Frequency Probe

RRD Graphs: Quality

Works with Probe Frequency (System - Routing) set at default (empty), 1, 2, 3, and 9 (prob...
NOYB NOYB
12:43 AM Bug #1839 (Closed): No Quality RRD Graph w/ Non-Default Frequency Probe

Setting Gateway Frequency Probe (System - Routing) to a non-default value, say 10 seconds, causes the RRD Quality ...
NOYB NOYB
02:19 PM Feature #1836: RFC 5006 support for DNS from RAs
rtadvd service support committed. should fix both dns server and rtadvd clients to get the same information.
radns...
Seth Mos
01:36 PM pfSense Packages Bug #1840 (Resolved): Snort rules update and filename
The package has the snort rules file hardcoded in the code.
This makes it a step to be followed when upgrading snort...
Ermal Luçi
10:20 AM Revision 02091d23: Encapsulate in curlies for safety
Seth Mos
10:17 AM Revision ea91a8c0: Unbreak system_routing_configure();
Seth Mos
09:13 AM Revision 26ecc19c: Only add the Interface scope on link local addresses
Seth Mos
09:13 AM Revision 5a8371cd: Add a / for the prefix length value. As suggested on
http://forum.pfsense.org/index.php/topic,40377.msg209028.html#msg209028 Seth Mos
06:07 AM Bug #1662: DNS server gateway selection missing input validation
Still not fixed.
http://forum.pfsense.org/index.php/topic,40498.0.html
Seth Mos

09/02/2011

08:56 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
I am just upgrading now, has there been some work since I last posted on the PPPoE server? If so, thank you. Matt Crook
05:03 PM Revision 4fbc8429: Only do cookie check if the form has already been posted. The cookie check is not accurate for the first page load after a browser has been opened, has to be at least one refresh/post first.
Jim Pingle
04:20 PM Revision 20a35f92: Revert "If a user's browser does not support cookies, print an error on the login form telling them so."
This reverts commit a2e90569ab481bc85f5b3be7a01cc1608b3d065a. Ermal LUÇI
01:10 PM Revision 399ccb4d: Merge pull request #12 from marcelloc/patch-1
load balance monitor type send/expect must have a '' when using more then Chris Buechler
11:09 AM Bug #1838: Dynamic DNS disabled checkbox doesn't work
Post you dyndns section from your config. Ermal Luçi
05:58 AM Bug #1838 (Resolved): Dynamic DNS disabled checkbox doesn't work
As disabling a dynamic dns client with the checkbox, nothing is done except still updating dyndns host. Checkbox does... Nicolas Liaudat
07:13 AM pfSense Packages Bug #692 (Feedback): snort pidfile issue
Latest package of snort should not have this issue. Ermal Luçi
07:13 AM pfSense Packages Bug #1746 (Feedback): Preprocessor do not work
Should be working now Ermal Luçi
07:12 AM pfSense Packages Bug #1747 (Feedback): Barnyard2
Should be working now Ermal Luçi
07:11 AM pfSense Packages Bug #1748 (Feedback): Rules GUI
Should work as intended now. Ermal Luçi
05:43 AM Revision 1ce020c0: load balance monitor type send/expect must have a '' when using more then one argument.
Marcello Silva Coutinho
03:26 AM Bug #337: sticky connections do not work
Updated to version 2.0-RC3 (i386) built on Thu Sep 1 18:11:23 EDT 2011
Unfortunately the behavior is still the sam...
Mark Huijgen

09/01/2011

07:54 PM Revision 6f14b34a: Unlink the failed downloaded file if present. Since it might contain harmful and not expected content
Ermal LUÇI
07:53 PM Revision 47397d86: Unlink the failed downloaded file if present. Since it might contain harmful and not expected content
Ermal LUÇI
06:18 PM Revision 3adae4db: Check/set array for $config['staticroutes']['route'] as well, fixes deleting of the last static route not syncing to secondary unit.
Jim Pingle
06:13 PM Revision 4fef0242: Check/set array for $config['staticroutes']['route'] as well, fixes deleting of the last static route not syncing to secondary unit.
Jim Pingle
11:42 AM Bug #1837 (Resolved): Problem with PPP and default gateway switching
Description of how to replicate: ... Chris Buechler
11:25 AM Feature #1829: CARP with IPv6 support
need some additional consideration on how this should work from the GUI perspective. Maybe just make the underlying b... Chris Buechler
11:11 AM Feature #1829: CARP with IPv6 support
The specific issue is that you can not select a Carp IPv6 vip interface for router advertisements. Ideally we need to... Seth Mos
10:17 AM Feature #1829 (Resolved): CARP with IPv6 support
need to be able to bind router advertisements to CARP IPs. Chris Buechler
11:16 AM Revision 8fb12535: Add empty dhcp6c client control socket file
Seth Mos
11:07 AM Feature #1836: RFC 5006 support for DNS from RAs
Found this client which is even listed in the FreeBSD ports, dump the info into our filesystem and the rest is picked... Seth Mos
10:28 AM Feature #1836 (Resolved): RFC 5006 support for DNS from RAs
Need RFC 5006 support for DNS from RAs Chris Buechler
11:05 AM Feature #1835: uPNP IPv6 support
probably will have to add a new port for miniupnpd-v6 or similar, as we're going to keep RELENG_2_0 snapshot builders... Chris Buechler
11:04 AM Feature #1835: uPNP IPv6 support
Thread in the miniupnp forum here.
http://miniupnp.tuxfamily.org/forum/viewtopic.php?t=728
This will take a while...
Seth Mos
10:25 AM Feature #1835 (Resolved): uPNP IPv6 support
uPNP needs IPv6 support. Chris Buechler
10:33 AM Revision 81a3b6f5: Add a find_interface_ipv6_ll() to find the link local address of a interface.
Use this link local address for the apinger srcip otherwise we might try using the DHCP6 /128 address which will fail... Seth Mos
10:25 AM Feature #177: IPv6 support
I can't envision any scenario where you'd need proxy NDP, though maybe something will come up in the future. On the r... Chris Buechler
10:24 AM Feature #1834 (Resolved): Stateless autoconfig WAN type for IPv6
Need a WAN type for stateless autoconfiguration for IPv6, that's not going to be common in typical Internet firewall ... Chris Buechler
10:21 AM Feature #1833 (New): PPTP type WAN IPv6 support
PPTP type WANs need IPv6 support. Not sure how that works or if it's even feasible, needs research. Chris Buechler
10:20 AM Feature #1832 (Resolved): Traffic shaper needs review for IPv6
Layer 3 protocol isn't relevant for much of what it does, but needs review and at least some changes for IPv6. Chris Buechler
10:20 AM Feature #1831 (New): Captive portal IPv6 support
Captive portal needs IPv6 support. ipfw fwd doesn't function with IPv6 last I heard, amongst other things that need w... Chris Buechler
10:16 AM Feature #1828 (Resolved): Server load balancer IPv6 support
server load balancer needs IPv6 support. Chris Buechler
10:15 AM Bug #1827 (Resolved): rc.newwanipv6 needs work
rc.newwanipv6 needs work. Might need to converge with rc.newwanip to avoid race and stepping on each other causing re... Chris Buechler
10:15 AM Feature #1826 (New): PPPoE server IPv6 support
PPPoE server needs IPv6 support. Sends IPv6-CP packets, not confirmed if DHCPv6 server works. Chris Buechler
10:13 AM Feature #1825 (Resolved): Dynamic DNS client IPv6 support
DynDNS client needs IPv6 support for registering AAAAs. Chris Buechler
09:50 AM pfSense Packages Bug #1753 (Feedback): Spoink integration
Spoink is now integrated to snort and snort uses 2.9.0.5 port.
Possibly should ping the spoink author about this?
Ermal Luçi
08:21 AM Revision d5bff5e4: fix unknown-clients on DHCPv6
Chris Buechler
06:41 AM Revision 1a40ed8a: Fix system_routing_configure() so that that it also passes the interface scope with the IPv6 address on route changes. This is required for link local gateways to work.
Seth Mos
06:41 AM Revision 4ddbdfc1: Remove stray print_r debugging from the dhcp6 client function
Seth Mos
04:17 AM Bug #1824 (Resolved): DHCPv6 and unknown-clients.
fixed Chris Buechler
03:38 AM Bug #1824 (Resolved): DHCPv6 and unknown-clients.
Hello,
There is a bug in the configuration of DHCPv6 : using the deny unknown-clients option makes the DHCPv6 fail...
Alexis Olivier

08/31/2011

06:46 PM Revision 0041092c: If a user's browser does not support cookies, print an error on the login form telling them so.
Conflicts:
etc/inc/authgui.inc
Jim Pingle
06:37 PM Revision a2e90569: If a user's browser does not support cookies, print an error on the login form telling them so.
Jim Pingle
05:12 PM Bug #1666 (Resolved): OpenVPN interface doesn't get added to bridge after reboot
thanks Chris Buechler
01:40 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Seems to be fixed with latest snapshot, thanks. Joost van den Broek
02:47 PM pfSense Packages Bug #1822: Snort won't start
This is for snort-dev from what i can see!? Ermal Luçi
12:36 PM Revision baf9fdca: Further fix up the DHCPv6 client support, launch rtsol to figure out our gateway and add this into the interface router file in /tmp.
This will then be picked up by the rest of the system. My testlab happens to block ping showing it down but should ot... Seth Mos
11:57 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Also looking for a progress/status report here. Thanks. Alan Bryan
07:19 AM Revision 46a7c9aa: Do not send reconfigure events in the rc.newwanipv6 until we figure out a way to not step on the v4 configure too.
Correct some variable names Seth Mos

08/30/2011

11:08 PM Bug #1823 (Resolved): policy routing for firewall-initiated traffic only works for interface IPs
The rules such as: ... Chris Buechler
08:34 PM Revision 360ed9fa: Avoid a blank trailing entry
Jim Pingle
08:33 PM Revision ff99a638: Avoid a blank trailing entry
Jim Pingle
08:32 PM Revision 44587cdf: Have Diag>DNS pull servers from /etc/resolv.conf instead of the config, so it reflects all of the servers in use for the speed report.
Jim Pingle
08:32 PM Revision 40af551f: Have Diag>DNS pull servers from /etc/resolv.conf instead of the config, so it reflects all of the servers in use for the speed report.
Jim Pingle
08:04 PM Revision d89fdda0: Add a note to the server Load Balancer page to let users know it's not for Multi-WAN.
Jim Pingle
08:04 PM Revision c2bae113: Add a note to the server Load Balancer page to let users know it's not for Multi-WAN.
Jim Pingle
07:48 PM Revision 96beb23d: Wording fix to better describe the Translation address.
Warren Baker
07:47 PM Revision 3305f3ed: Wording fix to better describe the Translation address.
Warren Baker
07:30 PM Revision badc2340: Fix bottom note when viewing Floating rules to better reflect how they operate.
Jim Pingle
07:29 PM Revision 55833877: Fix bottom note when viewing Floating rules to better reflect how they operate.
Jim Pingle
07:16 PM Revision bde9fd21: Fix note width for 1:1 NAT
Jim Pingle
07:16 PM Revision 3499a954: Fix note width for 1:1 NAT
Jim Pingle
07:00 PM Revision abc16ee6: Fix QinQ note width.
Jim Pingle
06:59 PM Revision ce6577d2: Fix QinQ note width.
Jim Pingle
06:50 PM Revision 2fb92548: Clarify text
Jim Pingle
06:50 PM Revision 944b6946: Clarify text
Jim Pingle
06:23 PM Revision c61ed3db: Clarify text
Jim Pingle
06:23 PM Revision 1bad7228: Clarify text
Jim Pingle
06:07 PM Revision 37412b2f: Clarify notes so people don't think they need to disable pf to disable NAT.
Jim Pingle
06:07 PM Revision 5a8a7545: Clarify notes so people don't think they need to disable pf to disable NAT.
Jim Pingle
05:33 PM Revision 3f9f70cb: Move the option to exclude localhost as a DNS server under System > General so it is grouped with other system DNS options in a more logical location.
Jim Pingle
05:32 PM Revision 8ca95ed8: Move the option to exclude localhost as a DNS server under System > General so it is grouped with other system DNS options in a more logical location.
Jim Pingle
05:20 PM Revision 973444a8: Sync note for "server address" between PPTP/PPPoE/L2TP for consistency.
Jim Pingle
05:19 PM Revision d07b96a5: Sync note for "server address" between PPTP/PPPoE/L2TP for consistency.
Jim Pingle
05:07 PM Revision 546a3db1: Add some help links for pages that were missing.
Jim Pingle
05:07 PM Revision 571aa4aa: Add some help links for pages that were missing.
Jim Pingle
04:54 PM Revision 3d534c69: Change mbuf output on dashboard to read total/max, instead of current/total, to give a more useful view. Also only use a single netstat command instead of two.
Jim Pingle
04:54 PM Revision 7a21d1b8: Change mbuf output on dashboard to read total/max, instead of current/total, to give a more useful view. Also only use a single netstat command instead of two.
Jim Pingle
04:33 PM Revision 716fc5a0: Revert "Make the webConfigurator lockout rule to catch even edp protocol so that xmlrpc bruteforce is caught as well."
This reverts commit cde671805cccb380e60acb35374a23d3a7f48a99. Ermal LUÇI
04:32 PM Revision d2b56044: Revert "Make the webConfigurator lockout rule to catch even edp protocol so that xmlrpc bruteforce is caught as well."
This reverts commit 8a4f3015e44007dad22a6e1821f678293cf703a4. Ermal LUÇI
04:19 PM Revision 8a4f3015: Make the webConfigurator lockout rule to catch even edp protocol so that xmlrpc bruteforce is caught as well.
Ermal LUÇI
04:18 PM Revision cde67180: Make the webConfigurator lockout rule to catch even edp protocol so that xmlrpc bruteforce is caught as well.
Ermal LUÇI
04:11 PM Revision b0943409: Fix several issues in pppoe code and remove duplicated code.
Ermal LUÇI
04:11 PM Revision fcf07bb7: Fix several issues in pppoe code and remove duplicated code.
Ermal LUÇI
01:48 PM Revision 453d9c96: Fixup OpenVPN status a bit to properly handle SSL servers using a /30 (no server directive) and also be a little more verbose about what is happening, if we can tell.
Jim Pingle
01:45 PM Revision 28ba77e4: Disable the rtsol command for now until we have a proper script to handle this.
Seth Mos
01:44 PM Revision 1f2f6024: Fixup OpenVPN status a bit to properly handle SSL servers using a /30 (no server directive) and also be a little more verbose about what is happening, if we can tell.
Jim Pingle
01:01 PM Revision ca7c83ac: Correct the path to rtsol
Seth Mos
12:56 PM Revision ef851fed: Accept router advertisments for DHCP6 WAN interfaces. Also launch a rtsol process.
Seth Mos
12:38 PM Bug #1052: Certificate validation of the LDAPS servers is not enforced
HAve you tested with latest snapshots? Ermal Luçi
11:50 AM Bug #1690 (Feedback): PPPoE Server not passing IP from RADIUS server
Can you please try latest snapshots?
Also if still seeing issues can you get packet traces and any logs from pfSense...
Ermal Luçi
11:20 AM Bug #1696 (Feedback): Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:db74464bf6f980c5c5845d53624d4c6f1b139fa7. Ermal Luçi
10:48 AM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
I was finally able to reproduce this in a VM, even when the WAN was initially set for DHCP. Same panic message/backtr... Jim Pingle
10:47 AM Bug #337: sticky connections do not work
Can you please test with tomorrows snapshot? Ermal Luçi
06:21 AM Bug #337: sticky connections do not work

I'm having the exact same behaviour as described by Mark Huijgen earlier. The only difference is that my two WAN in...
Siddharth Patil
07:44 AM Bug #1344: Replace prototype javascript code with jQuery
Bootstrap, a nice framework from Twitter which has a number of some quite nice features http://twitter.github.com/boo... Warren Baker
07:22 AM pfSense Packages Bug #1822 (Closed): Snort won't start
So many issues with this package.
1) Local rules get wiped every time the auto updater runs. Then we have to go t...
Stephen Lombard
07:16 AM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Did it with success, but with a little modification about the netmask. In fact to make it work I had to use the $mask... Rino Santilli
04:51 AM pfSense Packages Bug #1821 (Rejected): spanning tree options
STP options work fine, not enough here to do anything with. Please post to the forum or mailing list with information. Chris Buechler
04:12 AM pfSense Packages Bug #1821 (Rejected): spanning tree options
Spanning Tree options are not considered Enrico Pesce

08/29/2011

11:58 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Yup, I hear ya.
Maybe by 2.1 someone could figure out how to do the dynamic hosts part per interface also, instead...
NOYB NOYB
11:06 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
thanks. Too close to release to fix something that hasn't ever worked (probability of unintended consequences is alwa... Chris Buechler
10:27 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Attached patch should result in the following behavior for registering DHCP hosts in DNS Forwarder.
*+Statically A...
NOYB NOYB
09:38 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Maybe just a tad bit of logic for using system domain when not specified in dhcp interface.... NOYB NOYB
07:16 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Could fix for the statically assigned hosts of each interface in services dhcp be as simple as this?
--- /etc/in...
NOYB NOYB
04:24 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
That's always worked that way, the domain filled in for the DHCP server if different from the primary domain name of ... Chris Buechler
04:17 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Can you please bring some examples and facts from pfSense config files? Ermal Luçi
03:37 PM Bug #1819 (Duplicate): DNS Resolver Not Registering DHCP Server Specified Domain Name
DHCP Server specified Domain Name not being registered in DNS Forwarder.
Hosts are resolvable by System General sp...
NOYB NOYB
10:43 PM Revision ac429b42: Unlink last msg cache for growl when sending test messagws
Scott Ullrich
10:43 PM Revision f670f0a2: Unlink last msg cache for growl when sending test messagws
Scott Ullrich
07:33 PM Revision 8614f335: Fixes #1666. Check if the interface needs to be added to a bridge during rc.newwanip as well.
Ermal LUÇI
07:32 PM Revision 737dbc05: Fixes #1666. Check if the interface needs to be added to a bridge during rc.newwanip as well.
Ermal LUÇI
06:29 PM Bug #1809 (Closed): Growl issue
Chris Buechler
07:17 AM Bug #1809: Growl issue
Well oke, thats now...
Never noticed that in RC1, But yes, it's working now :)
Thanks.
Richard van Herp
04:02 PM pfSense Packages Bug #1820 (Closed): widescreen package doens't show ipv6 link
widescreen package doens't show ipv6 link
dhcpv6 server & dhcpv6 lease link are missing when widescreen package is...
Alexandre Paradis
03:37 PM Bug #1806 (Feedback): OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Ermal Luçi
03:36 PM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Can you try this?... Ermal Luçi
03:30 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:737dbc05c13ddf31dc238ac59b406cc62716482a. Ermal Luçi
03:30 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:8614f335d1c9d62cdb65e41f235e123e6993368e. Ermal Luçi
03:30 PM Bug #1666 (Feedback): OpenVPN interface doesn't get added to bridge after reboot
Please try again newest snapshots Ermal Luçi
03:25 PM Bug #1818 (Closed): DNS Forwarder Not Registering DHCP Server Specified Domain Name
DHCP Server specified Domain Name not being registered in DNS Forwarder.
Hosts are resolvable by System General sp...
NOYB NOYB
02:04 PM Revision edf1c0d9: Give the Layer7 patterns page some much needed love.
Warren Baker
01:57 PM Revision f067d924: Give the Layer7 patterns page some much needed love.
Warren Baker
01:19 PM Revision 9d05f1d1: renable IPv6 rc.newwanipv6 but comment out reconfigure($if) until we track down how to best handle this.
Dhclient does not pass the interface as a argument which makes this really hard. Seth Mos
10:37 AM Feature #1817 (Resolved): Expand easyrule functions
It would be nice if we could also use subnets for wan and lan interfaces and use the gateways thru the easyrule cli.
...
Sander Naudts
09:03 AM Revision 71282744: Unbreak the services.inc Ticket #1663
Seth Mos
08:42 AM Revision b7a15cf8: Added blind coded DHCPv6 relay backend code. Needs to be tested, basic adaption to IPv6 implemented, only works on IPv6 interfaces. Checks inet6 route tables. Adds distinct PID file for dhcrelay -6. Adds to Ticket #1663
Seth Mos
08:33 AM Revision 1eca1a2f: Add DHCPv6 relay pages for the DHCPv6 relay. Ticket #1663
Seth Mos
08:19 AM Feature #177 (Feedback): IPv6 support
Most of the basic system now works with IPv6.
Large things that don't work.
- PPTP Client. not checked into. Is that...
Seth Mos
08:16 AM Revision 47fc7453: Correct the link for EasyRule so that IPv6 addresses parse
Seth Mos
08:08 AM Todo #1373 (Resolved): Upgrade OpenVPN
This code is already checked in and the client exporter supports the new options as well. Furthermore the client expo... Seth Mos
08:05 AM Todo #1441: IPv4 bogons list is now static
Negative, some networks will remain is bogon networks regardless, if networks are returned to a RIR they might come b... Seth Mos
08:04 AM Revision 748ff86f: Another address family check for dynamic gateways, v4 has dynamic, v6 has dynamic6 as string.
Seth Mos
07:59 AM Revision 96bddaf3: Add IPv6 love to diag states Summary. For Ticket #1816
Seth Mos
07:14 AM Revision 181816f1: Reflect the dynamic(6) gateway naming change in interfaces.php too
Seth Mos
07:05 AM Revision 791d3ac9: Add a possible "dynamic6 type to differentiate between IPv6 and IPv4 dynamic connections"
Seth Mos
05:00 AM Feature #1663 (Feedback): DHCPv6 relay
Please test Seth Mos
04:01 AM Bug #1816 (Feedback): diag_states_summary.php needs help for IPv6
Added Love, please check Seth Mos

08/28/2011

05:17 PM Revision 8d29f477: Merge pull request #10 from namezero111111/patch-2
Added web interface capability to make the LDAP search more specific in o Scott Ullrich
05:07 PM Revision 7e982e0a: Log when XMLRPC auth fails so that the brute force lockout will kick in.
Scott Ullrich
05:06 PM Revision 3dd2a278: Log when XMLRPC auth fails so that the brute force lockout will kick in.
Scott Ullrich
03:41 AM Revision a574b960: Add default values for latency, packet loss, down on GUI
Alexander Wilke
02:43 AM Revision c7073ebf: Added web interface capability to make the LDAP search more specific in order to filter for group membership for example.
Andy I.
02:37 AM Revision d1b69106: Added extended query possibility (for example, group membership)
Andy I.
12:22 AM pfSense Packages Bug #1770 (Resolved): Can not install package Country Block
Chris Buechler
12:12 AM pfSense Packages Bug #1770: Can not install package Country Block
Fixed in version 2.2 thomas schaefer
12:22 AM pfSense Packages Bug #1579 (Resolved): countryblock doesn't uninstall cleanly
thanks Chris Buechler
12:14 AM pfSense Packages Bug #1579: countryblock doesn't uninstall cleanly
Fixed in version 2.2 thomas schaefer

08/27/2011

09:38 PM Bug #1816 (Resolved): diag_states_summary.php needs help for IPv6
diag_states_summary.php doesn't work correctly with IPv6. Seems to group everything under one entry, just listing the... Chris Buechler
07:28 PM pfSense Packages Bug #1218 (Feedback): Freeradius package does not start when i do reboot
should be fixed by https://github.com/bsdperimeter/pfsense-packages/pull/45 Chris Buechler
04:43 PM Revision cb51a6df: Merge pull request #11 from Nachtfalkeaw/patch-1
Add default values for latency, packet loss, down on GUI Scott Ullrich
04:39 PM Revision 655e9271: Merge pull request #9 from namezero111111/patch-1
Added extended query possibility (for example, group membership) Scott Ullrich
04:30 PM Feature #687: Test Button for Growl Notifications
Chris Buechler wrote:
> You can file a test notice by going to Diag>Command, in PHP box put in:
> file_notice("tes...
Gerald Livingston
07:57 AM pfSense Packages Bug #1753: Spoink integration
2.0-RC3 (amd64)
built on Wed Aug 24 10:10:33 EDT 2011
same case of hamilton, the error message is displayed onl...
Walter Gomes
04:45 AM pfSense Packages Feature #1815 (Closed): OpenVPN Client Export Additional Parameters
Hi,
The openvpn client configuration exporter doesn't have an option to pass additional parameters to the client (...
Andy I.
04:38 AM Feature #1009: Active Directory group membership checking
New version for auth.inc and system_authservers.php to allow for an extended LDAP query (Groups or otherwise) Andy I.

08/26/2011

05:28 PM Bug #1812: bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
i just uninstalled the widescreen package, shortcut are back. There is something missing for 2.1 in the widescreen pa... Alexandre Paradis
02:56 AM Bug #1812: bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
i found that right after an upgrade goth links are there. The links dissapear after all the package upgrade.
i hav...
Alexandre Paradis
11:12 AM Revision 2feb85af: Add a interface_has_gatewayv6() function to determine if a interface has a IPv6 gateway.
Implement that function return_gateways_array() to prevent ghost entries Seth Mos
07:37 AM Revision 7671c940: Add the IP protocol to the configured gateway list to prevent duplicate entries on dynamic interfaces
Seth Mos
01:29 AM Bug #1556 (Resolved): Changing local IPsec tunnel endpoint does not work
I can not replicate this anymore as I only have a single WAN left at work. Seth Mos

08/25/2011

08:58 PM Revision 2661e5d3: Remove stray echo statement
Seth Mos
08:57 PM Revision 60c62dee: Remove stray print_r()
Seth Mos
08:56 PM Revision c3a0d2a5: Automatically pick up on dynamic IPv6 interfaces. For Example dhcp6.
Seth Mos
06:59 PM Feature #1701: Vouchertime should be seperated
We have no current plans for implementing this. where "current plans" always means "someone willing to fund it" out o... Chris Buechler
04:17 AM Feature #1701: Vouchertime should be seperated
No intressst in this? Andreas Böhm
06:49 PM Bug #1556 (Feedback): Changing local IPsec tunnel endpoint does not work
I'm also unable to replicate this. Chris Buechler
08:22 AM Bug #1556: Changing local IPsec tunnel endpoint does not work
I switch one of my tunnels back and forth regularly between my two WANs and as long as I adjust the peer address on t... Jim Pingle
05:56 PM Bug #1814 (Rejected): Drive read/boot errors w/2.0 RC3
You have a dying hard drive or other fatal hardware quirk. Nothing we can do about that. Jim Pingle
05:55 PM Bug #1814 (Rejected): Drive read/boot errors w/2.0 RC3
From forum post: http://forum.pfsense.org/index.php/topic,39181.0.html which was submitted by palesius
I have a sy...
David T
01:17 PM Revision 107f0cc8: Add a couple more mobile browser detection strings (BlackBerry, Opera Mini/Mobi)
Jim Pingle
01:15 PM Revision e6eb0fcb: Add a couple more mobile browser detection strings (BlackBerry, Opera Mini/Mobi)
Jim Pingle
09:14 AM Revision 5dc98f2e: Implement correct gen_subnetv6_max function that you can throw random prefix lengths in. Fixes Ticket #1725
Seth Mos
05:13 AM Bug #1725 (Feedback): DHCPv6 non-common bitmask shows incorrect range
I've been able to create a new gen_subnetv6_max() function in about a hour or 2 of coding and testing. Should be reso... Seth Mos
01:55 AM Revision 42964851: fix text
Chris Buechler
01:54 AM Revision ace9a954: fix text
Chris Buechler

08/24/2011

09:24 PM Revision 5c52cd56: force a set path for ioncube loader
Luiz Gustavo S. Costa
09:13 PM Revision ba35e0de: force a set path for ioncube loader
Luiz Gustavo S. Costa
08:10 PM Revision 99bdb17e: Unbreak the firewall rule Edit page, input error array was unset halfway the validation. Set that back up ontop.
Add gateway validation Seth Mos
07:21 PM Revision 4108dee8: Catch another possiblity for invalid rule generation
Seth Mos
04:59 PM Revision 196dafe9: Make sure this does not operate on empty parameters, and also log when removing states.
Jim Pingle
04:59 PM Revision 197c30ae: Make sure this does not operate on empty parameters, and also log when removing states.
Jim Pingle
04:09 PM Bug #1659 (Feedback): Missing input validation in rules gateway selection
Should be all set, there was a unset of the input errors halfway the input validation that must have broken a lot of ... Seth Mos
09:31 AM Bug #1659: Missing input validation in rules gateway selection
Committed code in git that should fix most of this, shows only the correct address family when editing a pool or fire... Seth Mos
03:20 PM Revision defe335c: DNSMasq was generating the error 'Socket operation on non-socket' and using 100% of the CPU, changing it to mwexec_bg() resolves the issue.
Warren Baker
03:18 PM Revision 923d15bf: DNSMasq was generating the error 'Socket operation on non-socket' and using 100% of the CPU, changing it to mwexec_bg() resolves the issue.
Warren Baker
03:09 PM Bug #1660 (Feedback): Missing input validation in system_gateway_groups_edit.php
I've committed code to the gateway groups page that prevents you from adding different address families in the same g... Seth Mos
02:50 PM Feature #1726 (Resolved): Allow disabling the "Autonomous address-configuration"
Confirmed that my Macbook with 10.5 only has a link-local address when set to router-only. you can Still enable DHCP6... Seth Mos
02:14 PM Revision 52e21fa1: Fix VPN network listing for OpenVPN, and also add tunnel networks to this list.
Jim Pingle
02:13 PM Revision 0c074cfb: Fix VPN network listing for OpenVPN, and also add tunnel networks to this list.
Jim Pingle
01:26 PM Revision a1c10b7f: Properly fix the address family check for gateway groups Ticket #1659
Seth Mos
01:12 PM Revision 8c591d01: Unbreak firewall rules edit, missing a )
Seth Mos
01:07 PM Revision 16b03b79: Fix a typo in the subnet generation causing the code to fail
Seth Mos
12:31 PM Revision fcb816d9: Only show gateways from the same address family on the groups edit page. Ticket #1659
Seth Mos
12:04 PM Revision 6fd35fe3: These html tags are not required since they are used in head.inc which is included.
Warren Baker
12:01 PM Revision 2299007e: These html tags are not required since they are used in head.inc which is included.
Warren Baker
11:02 AM Revision 270a2576: Add address family validation, also hide gateways or gateway groups from the gateway list.
Fix Ticket #1659 Seth Mos
10:42 AM Revision 9e80d14c: Add address family input validation on the Gateways edit page, also prevent adding gateways on interfaces that do not carry that address family.
Fix Ticket #1633 Seth Mos
09:40 AM Revision bb5a2d0e: Automatically adjust the subnet size drop down when editing a entry
Ticket #1661 Seth Mos
09:36 AM Revision 1831a00d: Add Address Family input validation on the system routes edit page. Do not allow IPv4 subnet masks > 32 bits.
Ticket #1661 Seth Mos
08:51 AM Revision c935003d: Update the system.inc code that sets up the static routes for DNS servers to reflect the interface to gateway name conversion
Seth Mos
08:47 AM Revision 9d8ee15b: Fix the address family check to skip empty DNS gateway fieldS
Seth Mos
08:29 AM Revision d623f2da: Change the DNS interface code to DNS gateway code. This will need upgrade code for existing configs.
Seth Mos
07:43 AM Bug #1809: Growl issue
How are you testing Growl to say it is not working?
Growl creates a temp file (/var/db/growlnotices_lastmsg.txt) of...
Warren Baker
06:41 AM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
This affects the kernel in 2.0 which is currently also in use on 2.1 Seth Mos
06:40 AM Bug #1633 (Feedback): Missing input validation in IPv6 gateways
Code committed that prevents address family mixups in gateways and monitors, prevent v6 gateways on v4 only interfaces. Seth Mos
05:37 AM Bug #1661 (Feedback): Missing input validation in system_routes_edit.php
Code with address family validation checked in, please test. Seth Mos
04:49 AM Bug #1662 (Feedback): DNS server gateway selection missing input validation
Code checked in that converts the interface names to gateway names, updated the system.inc code that updates the rout... Seth Mos
03:47 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
ronald meulendijks wrote:
> 0.0.0.0/0[any] 192.168.78.1[any] 255
> out ipsec
> esp/tunnel/95.96.134.40-91.189.22...
Chunlin Yao
03:45 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Jim P wrote:
> Some people are still hitting this same error, but not this specific circumstance. Two support custom...
Chunlin Yao
03:28 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
My situation maybe related to this issues.
Mobile clients connect to pfSense use nat-t. I think racoon should supp...
Chunlin Yao
03:45 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Is there any progress on this issue? Derrick Conner
03:42 AM Feature #1807: Button needed for '-add a new one-' on the static IP configuration
Seems fair enough Seth Mos
03:40 AM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
Caution, if the config is Upgraded on nanobsd platforms the converted RRD files are not immediately saved to the flas... Seth Mos

08/23/2011

08:38 PM Revision a5308b81: Simplify this code a bit, should be the same test in both locations since this should be either/or, and with the other code it can apparently fall into a trap where it shows neither.
Jim Pingle
08:36 PM Revision 28ce79ad: Simplify this code a bit, should be the same test in both locations since this should be either/or, and with the other code it can apparently fall into a trap where it shows neither.
Jim Pingle
06:46 PM Revision 318189b6: Add a function that allows you to validate the address family on 2 addresses or 1 address and a gateway name. the gateway name must be the 2nd argument.
Seth Mos

08/22/2011

06:11 PM Bug #1813: Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
floating rules can work around this Chris Buechler
05:50 PM Bug #1813 (Confirmed): Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
the 'pass out' rules such as:
pass out route-to ( em1 9.2.2.1 ) from 9.2.3.17 to !9.2.2.0/21 keep state allow-opt...
Chris Buechler
12:37 PM Revision 9debac94: Fix field name label.
Jim Pingle
12:37 PM Revision b4eec6e6: Fix field name label.
Jim Pingle
11:07 AM Bug #781: Entering sim code problem on a Huawei E1752
Having same problem here with a novatel eu850d minipcie card, although PIN is deactivated.
When removing the "GetOK ...
Christian Schwarz
03:56 AM Revision dba5f621: un-break services_dhcpv6.php
Chris Buechler

08/21/2011

11:43 PM Bug #1812 (Rejected): bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
has to be a browser cache issue, they're there. Chris Buechler
11:36 PM Bug #1812 (Rejected): bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
The dhcpv6 & dhcpv6 shortcut isn't present in the menu. but i have access if I type manualy the link in the address bar. Alexandre Paradis
06:28 PM Feature #1811 (Closed): Monitor PPP for connections stuck in "initial" state
I've been trying to help debug an issue with dynamic DNS updates on 3G connections (1545) but keep getting hampered b... Ross Williamson
06:10 PM Feature #1663: DHCPv6 relay
DHCP Relay page only has 4 fields which are all the same between v4 and v6 with the exception of input validation. I ... Chris Buechler
06:47 AM Feature #1663: DHCPv6 relay
I'll Investigate the needs. Page probably needs a total makeover because next to nothing that exists in ipv4 can be p... Seth Mos
04:45 PM Revision 4fcab77b: Unbreak the DNS rebind check when accessing over IPv4
Seth Mos
03:32 PM Revision 826ac52c: Add router type to rtadvd daemon configuration to only advertise the router without slaac.
Seth Mos
03:11 PM Revision fd1e6c05: Clarify advertising options, add router only type.
Seth Mos
01:11 PM Feature #1726 (Feedback): Allow disabling the "Autonomous address-configuration"
Added a "router" type that sends pinfoflags as being "". From the confusing documentation this might need to be "l" w... Seth Mos
06:38 AM Feature #1726: Allow disabling the "Autonomous address-configuration"
My thought was to add this as a choice from the drop down on the DHCP server page.
The config code currently does ...
Seth Mos
11:36 AM Revision ac005767: Fix the redirect URL for IPv6 addresses Ticket #1583
Seth Mos
11:13 AM Revision e6f7e0be: Fix the referrer checks for IPv6 addresses Ticket #1583
Seth Mos
11:03 AM Revision 4cf79fdd: Fix the DNS rebind Check for IPv6 addresses Ticket #1583
Seth Mos
08:50 AM Revision 385ed7d0: Make sure to set the $pconfig prefix delegation setting from the config.
Seth Mos
08:28 AM Bug #1583 (Feedback): IPv6 IPs with :: trigger DNS rebinding
Committed patches for both rebind and referrer checks.
Added patch for redirect url.
Seth Mos
06:58 AM Bug #1583: IPv6 IPs with :: trigger DNS rebinding
Confirmed that without a alternate port you do in fact trigger a DNS rebinding attack.
Found another gem related to ...
Seth Mos
06:50 AM Bug #1661: Missing input validation in system_routes_edit.php
Will fix, same javascript helper from firewall rules and DNS server settings (gateway) would apply. Seth Mos
06:49 AM Bug #1662: DNS server gateway selection missing input validation
This same issue exists on the firewall rules (edit) page for selection of gateways.
I can fix the input validation...
Seth Mos
06:45 AM Bug #1676: dead IPv6 gateway causes kernel panics
the sbappendaddr_locked() is a function that I believe comes from our one shot dumps patch which is active for our 2.... Seth Mos
06:41 AM Bug #1706 (Resolved): "Bypass firewall rules for traffic on the same interface" is broken
Resolved by a commit a week ago when I ran into this myself on my lab setup. Seth Mos
06:40 AM Bug #1725: DHCPv6 non-common bitmask shows incorrect range
The function that calculates this is currently a string operated function instead of proper math. We need to have thi... Seth Mos

08/20/2011

10:22 PM pfSense Packages Todo #596: Varnish package suggestions for VCL syntax checking
follow this forum topic:
http://forum.pfsense.org/index.php/topic,38271.15.html
Marcello Silva Coutinho
10:11 PM pfSense Packages Todo #596: Varnish package suggestions for VCL syntax checking
> I work in a web shop design company and we use varnish as a reverse proxy for mostly sites builded using Drupal, Co... Marcello Silva Coutinho
04:49 PM pfSense Packages Bug #1805 (Closed): Captive portal - Portal page contents - View current page url is incorrect.
duplicate of #1810 Chris Buechler
07:52 AM pfSense Packages Bug #1805: Captive portal - Portal page contents - View current page url is incorrect.
to be more specific: select line 700 - 710 and replace by:... Davy Moedbeck
01:28 PM Revision 6f75aab2: Fix mismatched curly brace
Jim Pingle
08:13 AM Feature #1810 (Resolved): Captive portal - Portal page contents - View current page url is incorrect.
In the /usr/local/www/services_captiveportal.php file the link to the uploaded html can not be accessed from a networ... Davy Moedbeck
06:05 AM Bug #1809 (Closed): Growl issue
I reported Bug #1769 that Growl stopped working and it got rejected.
So I tried some other stuff and updated the bug...
Richard van Herp
05:39 AM Revision b51960fe: remove dead link, no equivalent exists, will add info on that page's help
Chris Buechler
05:37 AM Revision 1caa6adc: remove dead link, no equivalent exists, will add info on that page's help
Chris Buechler
01:35 AM Bug #1808 (Resolved): link to scrub info is dead
fixed, thanks Chris Buechler
12:49 AM Bug #1808 (Resolved): link to scrub info is dead
There is a link in the "Disable Firewall Scrub" section of /system_advanced_firewall.php that points to http://www.op... David Burgess

08/19/2011

10:45 PM Revision 3de1a999: USB slices are under-reported even more than CF slices when viewed directly, instead of when looking at the entire disk. Compensate by adding a few MB. Fixes NanoBSD upgrades when installed on USB thumbdrives. (Imaged after this fix, someone can apply this fix locally and then upgrade as well.)
Jim Pingle
07:33 PM Revision b881a921: Compensate some more occurencies of write_config() during the path
Ermal LUÇI
07:02 PM Revision 2add8ea7: Make update_status and update_output_window consistent on checking for console version or not.
Ermal LUÇI
07:01 PM Revision 23fc1ae8: Show the package name that are geing downloaded even during console update
Ermal LUÇI
06:22 PM Revision 582934a9: Compenstate for the write_config calls sending the filesystem to ro during pacakge installation.
Ermal LUÇI
05:42 PM Revision d5f25de6: Put rw/ro calls on pkg_edit.php on POST to avoid packages having to do these calls.
Ermal LUÇI
05:12 PM Revision 8420f4fe: Prevent negative references to be used for the refcount API. This should help with misusage of it as may occur in mount rw/ro calls.
Ermal LUÇI
05:10 PM Revision 595ddf1b: start packages script is called after rc.bootup so the filesystem is makred RO already. Put the script around the mount rw-ro calls to avoid problems.
Ermal LUÇI
04:48 PM Feature #1807 (Resolved): Button needed for '-add a new one-' on the static IP configuration
Button needed for '-add a new one-' on the static IP configuration. Currently this is just a link and not entirely o... Bobby Weiter
10:59 AM Bug #1344: Replace prototype javascript code with jQuery
Nice javascript spinner http://fgnass.github.com/spin.js/ Scott Ullrich
10:40 AM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Those lines are from the OpenVPN log
/sbin/ifconfig ovpns2 3.3.3.5 *netmask 3.3.3.6* mtu 1500 up
/usr/local/sbin/...
Rino Santilli
10:27 AM Bug #1806 (Resolved): OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
When creating a *layer 2 tunnel using TAP devices in peer-to-peer shared key mode* you get a warning in the OpenVPN l... Rino Santilli
08:09 AM pfSense Packages Bug #1805 (Closed): Captive portal - Portal page contents - View current page url is incorrect.
In the http://pfsense.local/services_captiveportal.php file there is an incorrect part:
the lines 701 till 709 nee...
Davy Moedbeck
07:11 AM Bug #1804 (Rejected): DNS forwarder
Please post in the forum to rule out a configuration issue and to gather more information. If it's determined that a ... Jim Pingle
05:02 AM Bug #1804 (Rejected): DNS forwarder
I am on latest RC3 - I just discovered DNS forward is completely non-functional.
I am using 2 WAN (WAN+Opt2)- balanc...
Sangye Ngawang

08/18/2011

09:18 PM Revision 3d749ab3: Fix copy paste error which cleared args
Andrew Thompson
09:18 PM Revision 237ac198: Fix copy paste error which cleared args
Andrew Thompson
03:24 PM Bug #1279 (New): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
It ends up read only but it breaks many other things if you upgrade with packages. GUI doesn't load, many processes d... Jim Pingle
11:47 AM Revision 6d063da3: Calculate the possible subnet ids from the delegated prefix length for the dropdown
Seth Mos
10:50 AM Revision 3dda090b: Add DHCP6 to the default configuration
Seth Mos
10:10 AM Revision 302d646e: Make sure to wait for the interface to be really created before letting the function return for PPP(oE) interfaces.
Seth Mos
09:54 AM Bug #1802: Interface not showing in traffic shaper
Yeah, unfortunately that is the case, axe(4) doesn't support altq. Was worth double checking though. Jim Pingle
09:52 AM Bug #1802: Interface not showing in traffic shaper
From the dmesg output I get, the NIC is using the Axe driver. So, no ALTQ support.
axe0: <vendor 0x0b95 product 0x...
Jonathan Frank
09:48 AM Bug #1802 (Closed): Interface not showing in traffic shaper
They all call themselves ue0 now I see. If you look in dmesg there would be a line saying what driver it actually is.... Jim Pingle
09:44 AM Bug #1802: Interface not showing in traffic shaper
It use the "ue", which is not listed in the ALTQ supported driver list. Jonathan Frank
08:42 AM Bug #1802: Interface not showing in traffic shaper
What driver does the network card use? It would be something like aue0, etc. We can double check the driver to see if... Jim Pingle
08:34 AM Bug #1802: Interface not showing in traffic shaper
After doing more research, it seem like not all drivers/network cards are supporting ALTQ, so that must be the issue.... Jonathan Frank
08:21 AM Bug #1802 (Closed): Interface not showing in traffic shaper
Hi,
I recently installed pfSense 2.0 and am using an USB network card for testing purpose. I noticed that the inte...
Jonathan Frank
09:39 AM Revision 5a3031ea: Make sure that we disable accepting router advertisements unless we explicitly enable them
Seth Mos
08:15 AM Revision 49047fb4: Add a log message when we enable router advertisements for a interface
Seth Mos
08:11 AM Revision 5f24a4de: Disable the rc.newwanipv6 script called from the dhcp6 client, this causes a recursing configure.
Seth Mos
07:19 AM Revision 12de53a8: Remove the gateway check here and always show the prefix delegation ID. Alternative we should consider a dhcp-pd type for the interface v6 address. Using a FE80::1 as the interface address for now.
Seth Mos
07:17 AM Revision 37fb708c: Add debugging to interface down function, add support for the type6 = dhcp6.
This really needs to be sorted out in a better way taking both v4 and v6 into consideration simultaneously. Seth Mos
06:55 AM Revision b868d9a0: Add the dhcp6 firewall rules so the client can get out.
Add a type6 field so that we can distinguish the ipv6 configuration types Seth Mos
02:28 AM Revision 35627492: fix text
Chris Buechler
02:28 AM Revision 2a5d416d: fix text
Chris Buechler

08/17/2011

09:49 PM Feature #828 (Resolved): Import for User Certificates
Chris Buechler
09:32 PM Feature #1801 (Rejected): Intermediate SSL certs box
Hello, it would be great to have a box in the certificate creation page to include intermediate certs.
forum threa...
Alexandre Paradis
08:15 PM Revision e15e9c6b: Ticket #1279. Decrease the refcount even though we're in booting phase. This helps the refcount to work as intended and help in making filesystem read only correctly on embedded platfroms. While here put some exceptions to refcount API and silent any related errors that might trigger. Also take not of the NOTE on the php manual that after a share memory is opened further references to it for size and access mode should be 0.
Ermal LUÇI
08:09 PM Revision e1b068d7: Ticket #1279. Decrease the refcount even though we're in booting phase. This helps the refcount to work as intended and help in making filesystem read only correctly on embedded platfroms. While here put some exceptions to refcount API and silent any related errors that might trigger. Also take not of the NOTE on the php manual that after a share memory is opened further references to it for size and access mode should be 0.
Ermal LUÇI
05:15 PM Revision 86e1405d: Include the rate output in the privilege for the traffic graph.
Jim Pingle
05:14 PM Revision 8e95a671: Include the rate output in the privilege for the traffic graph.
Jim Pingle
05:14 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
See also #1336 Jim Pingle
04:09 PM Bug #1279 (Feedback): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
I put a fix that helps this.
Can you please try with latest snapshots?
Ermal Luçi
03:23 PM Feature #1787: Everyone with access to user manager has full admin rights
That's just a fact of how it works, not a bug. If you have access to the user manager you have full admin rights. Chris Buechler
03:08 PM Feature #1787: Everyone with access to user manager has full admin rights
There are only a few things I have changed. I think this problem is not dependend on the configuration. To test this ... Hans-Harald Webers
11:30 AM Feature #1787: Everyone with access to user manager has full admin rights
Can you describe how you have setup your firewall that gives you this issue? Ermal Luçi
11:15 AM Feature #1787 (Closed): Everyone with access to user manager has full admin rights
In some scenarios, it's undesirable for user manager users to have full admin capabilities, such as managing CP users... Hans-Harald Webers
03:18 PM Bug #1767: Unable to modify pppoe interface which is linked to a vlan via WebGUI
This is not expected to work on 2.0.
The way you should do is assign the vlan and then go and create a PPP type li...
Ermal Luçi
03:10 PM pfSense Packages Bug #1590: Snort Will Not Start
amd64
pfsense rc3
Snort
Notes:
Snort seems to be still down
alerts tab clear log seems to be broken
not availible
01:07 AM pfSense Packages Bug #1590: Snort Will Not Start
the only snag that I think *might* cause an issue is a future rules update since that flushes the rules folder. if l... Brett Ussher
12:44 AM pfSense Packages Bug #1590: Snort Will Not Start
Another update. Just tried rebooting the server -- no updates were done or any changes to configuration or addition/... Brett Ussher
11:38 AM Feature #1184: Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
That may be possible, it would have to be tested to make sure it really works though. I haven't looked at this since ... Jim Pingle
11:33 AM Feature #1184: Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
Since we know in advance what kinds of extensions we want, they should all be specified in the openssl.cnf, but in di... George Macon
10:35 AM Bug #1786 (Rejected): NanoBSD auto upgrade fails
Auto upgrade works fine, I just tested it on my alix again. You may have a problem specific to your system or CF. Ple... Jim Pingle
10:09 AM Bug #1786 (Rejected): NanoBSD auto upgrade fails
I installed
2.0-RC3 (i386) built on Tue Aug 16 20:24:26 EDT 2011
on a Netgate ALIX.2D3 / 2D13.
by dd the image...
Bill Weidman
09:02 AM Revision 4bd491a3: Comment out code that seems to not be anymore useful. Remove later on if no complaints in sight.
Ermal LUÇI
09:01 AM Revision c63630f0: Comment out code that seems to not be anymore useful. Remove later on if no complaints in sight.
Ermal LUÇI
02:15 AM Revision 7734aea6: Make initial changes to allow pfSense to work in a jail.
This mostly avoids starting things that will not work and gets the
initial config. Most of the pfSense functionality ...
Andrew Thompson
02:12 AM Revision 3c6d704a: Revert "Make initial changes to allow pfSense to work in a jail."
This reverts commit a26d95383a6146734f67c9db21cd83534052843a. Andrew Thompson
02:07 AM Revision a26d9538: Make initial changes to allow pfSense to work in a jail.
This mostly avoids starting things that will not work and gets the
initial config. Most of the pfSense functionality ...
Andrew Thompson

08/16/2011

10:05 PM Revision 487830da: Allow custom dnsmasq options so ppl can set SRV records and such for xmpp/kerberos
Andrew Thompson
10:02 PM Revision 8f9bffbc: Allow custom dnsmasq options so ppl can set SRV records and such for xmpp/kerberos
Andrew Thompson
07:01 PM pfSense Packages Bug #1590: Snort Will Not Start
I used the above command, which fixed that issue. However, after turning on some more Snort rules categories, when I... Brett Ussher
05:06 PM Revision 2a319b4f: Fix the filter rules to trigger for the right address family
Seth Mos
03:37 PM pfSense Packages Bug #1768: DNS Forwarder of Tinydns
Any news on this?
I would really like to patch the stuff and make it work. All I'm waiting for is some response on...
Oliver Loch
08:58 AM Bug #636: layer7 not work correctly
Hi all,
I tried with version:
2.0-RC1-IPv6 (amd64)
built on Mon Aug 15 22:32:41 EDT 2011
This seems definitely...
Peter Baumann
06:05 AM Bug #1773 (Resolved): wrong URL is displayed for web interface access at console for DHCP
After going through the Set IP address at the console and configuring an interface for DHCP, the displayed URL is wro... Chris Buechler
05:52 AM Bug #1407 (Resolved): GUI is sluggish without working DNS
When having localhost as a first server in resolv.conf, as is done on latest snapshots, this bug does not manifest.
...
Ermal Luçi
05:13 AM Bug #1407: GUI is sluggish without working DNS
Hi all,
I just tested successfull with the following snapshot:
2.0-RC3 (amd64)
built on Mon Aug 15 22:32:41 EDT ...
Peter Baumann

08/15/2011

08:23 PM Revision 0e12792d: Unbreak filter.inc. Pointy-hat ?
Ermal LUÇI
08:23 PM Revision 7a787c58: Resolves #1731. Correctly handle nested alias that have hostnames. While here prevent putting duplicated dns hostnames under the same table to prevent possible hickups and save double work.
Ermal LUÇI
08:16 PM Revision 24a682d3: Resolves #1731. Correctly handle nested alias that have hostnames. While here prevent putting duplicated dns hostnames under the same table to prevent possible hickups and save double work.
Ermal LUÇI
07:36 PM Revision 619e4229: Revert "Feature#1603. URL table aliases should be usable within network type aliases."
This reverts commit ae660b3ce7d7e2b1f34cb9f1b52eb4ce21e17c42. Ermal LUÇI
07:32 PM Revision df58fd46: Revert "Feature #1603. Correct nested urltable alias code to be more fullproof to errors and does not break the ruleset on large lists of urltables. Though this needs a revisit to work properly since it breaks urltable alias property of reloading contents."
This reverts commit 3a26fb7f03a0336ed8dd642c46c6e513fca794da. Ermal LUÇI
07:21 PM Revision 460082ce: Another roll at fixing the voucher sync problems.
Ermal LUÇI
07:20 PM Revision 6dd45e0d: Another roll at fixing the voucher sync problems.
Ermal LUÇI
06:22 PM Revision 1e37f324: Unbreak interfaces.php
Seth Mos
06:07 PM Revision 52a1f701: Fix broken static route bypass rules
Seth Mos
04:20 PM Bug #1731: Hostnames are not allowed access when using an Alias in an Alias
Applied in changeset commit:24a682d3b646b61f9f3fdf787113b3861bb3be09. Ermal Luçi
04:20 PM Bug #1731 (Feedback): Hostnames are not allowed access when using an Alias in an Alias
Applied in changeset commit:7a787c581eb272e7dba5fe83994e129db06bfb2c. Ermal Luçi
03:44 PM Bug #1629: invalid state table entries after WAN IP change
From the attached:
- What is the old gateway?
- What is the new gateway?
- What is the wrong entry?
Ermal Luçi
03:40 PM Feature #1603: URL table aliases should be usable within network type aliases
Reverted the changes. Ermal Luçi
01:55 PM Revision 8103bd1e: Reflect the changes in the UI page that IPv4 and IPv6 are no lounger coupled together. They are now 2 seperate switch() statements.
This should also allow for toggling the dhcp6 client on a PPPoE interface Seth Mos
01:54 PM Revision 20b49b17: Fix a typo that caused stripping of the v4 config
Seth Mos
01:01 PM Bug #1771 (Rejected): OpenVPN and PPPoE Wan Interface
The GUI always binds to 443 on all interfaces. The fact that it works at all in that configuration is surprising. As ... Jim Pingle
12:53 PM Bug #1771 (Rejected): OpenVPN and PPPoE Wan Interface
Hi,
if a pppoe interface is used as wan interface and OpenVPN is attached to the wan interface on port 443/tcp (wh...
Oliver Loch
12:15 PM Revision e029943a: Split the IPv4 and IPv6 configuration out into 2 seperate drop downs.
Seth Mos
11:04 AM Bug #1769: Growl stopped working
Well yes and no :)
I reinstalled the system (2.0 RC1) and it worked, I updated to 2.0 RC3 and it still worked, tha...
Richard van Herp
06:05 AM pfSense Packages Bug #1770: Can not install package Country Block
make sure you post this in the country block thread on the forum, the maintainer of that package doesn't watch ticket... Chris Buechler
05:49 AM pfSense Packages Bug #1770 (Resolved): Can not install package Country Block
Can not install package Country Block.... Andrey Shimanskiy

08/14/2011

09:35 PM pfSense Packages Bug #1590: Snort Will Not Start
This issue is back again in RC3. I found the following fix in the forums:
http://forum.pfsense.org/index.php?topi...
Brett Ussher
07:20 PM Bug #1769 (Rejected): Growl stopped working
works fine on that snapshot. Chris Buechler
09:35 AM Bug #1769 (Rejected): Growl stopped working
I just noticed that Grow will not display a message but only registrar itself.
To be sure it's not Lion I tried to s...
Richard van Herp
07:18 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Also, just as an aside, I was unable to trigger the issue using generated traffic from iperf. I tried to generate bot... Chris Smith
07:14 PM Bug #1425: pfSense stops receiving traffic on 'bge' driven interface
Disabling msix on our system caused serious problems (we also have igb Intel Pro cards in these systems which I suspe... Chris Smith
05:14 PM pfSense Packages Bug #1218: Freeradius package does not start when i do reboot
This bug is stila actual on RC-3.
The webGUI shows freeRADIUS running but clients cannot authenticate anymore. This ...
Alexander Wilke
03:20 AM Bug #1545: Dynamic DNS updates fail on 3G connections
Dynamic DNS does not update without manual intervention on Aug 12 build Ross Williamson

08/13/2011

11:46 PM Bug #1618 (Resolved): Captive portal: Invalid AVP value in Radius accounting packet
confirmed fixed Chris Buechler
11:00 PM Bug #1618: Captive portal: Invalid AVP value in Radius accounting packet
Serge: can you confirm this fix please? Chris Buechler
11:31 PM Bug #1193 (Resolved): Traffic Shaper default queue Problem
Chris Buechler
11:31 PM Bug #1744 (Closed): Upgrading
Chris Buechler
11:12 PM Bug #1744: Upgrading
I haven't seen any package reinstall issues in general of late, sounds like this one may be something specific to tha... Chris Buechler
11:30 PM Bug #1628 (Resolved): Static ARP entries need reapplied after link loss
Chris Buechler
11:29 PM Bug #1336 (Closed): PPTP VPN NAT on WAN or other external interface
this is the same as #1107, closing in favor of that one. Chris Buechler
11:26 PM Bug #1552: DNS Reject Rule Crashes Router
Aaron - is this fixed?
Chris Buechler
11:26 PM Bug #1707 (Resolved): Pfsense 2.0 RC3 keeps route of deleted openvpn server
Chris Buechler
11:23 PM Bug #1401 (Feedback): VLANs and Web settings "TCP Segmentation Offload"
Chris Buechler
11:22 PM Bug #1666 (New): OpenVPN interface doesn't get added to bridge after reboot
Chris Buechler
11:22 PM Bug #1564 (Resolved): rc.stop_packages causes reboot to only works from SSH, not from Web interface
Chris Buechler
11:21 PM Bug #1097 (Closed): Onload Javascript on Rules page of management GUI
Chris Buechler
11:21 PM Bug #1402 (Closed): When creating a QinQ it works until reboot.
Chris Buechler
11:20 PM Bug #802 (Resolved): Interface reassignment with VLANs after config restore to diff hardware doesn't work
Chris Buechler
11:18 PM Bug #1239 (Resolved): PPTP - Assign password to a user with ñ
Chris Buechler
11:17 PM Bug #1107 (New): mpd on AMD64 generates invalid checksums with NAT
Chris Buechler
11:16 PM Bug #455 (Closed): On initial wizard reload button do not put browser on new assigned ip.
Chris Buechler
11:15 PM Bug #1243 (Resolved): GUI/Backend code needs updated after multi-PPPoE-server code switch
Chris Buechler
11:15 PM Bug #1377 (Closed): upgrade 1.2.3-Final nanobsd 4g to 2.0-RC1 nanobsd 4gb fails
Chris Buechler
11:15 PM Bug #886 (Resolved): RRD graph generation time scaling not written correctly
Chris Buechler
11:13 PM Bug #1047 (Resolved): Disable TSO, hardware checksum don't work for unassigned but active interfaces
Chris Buechler
11:13 PM Bug #1577 (Resolved): Inserting any rules on VPN PPPoE interface cause filter not reload
Chris Buechler
11:13 PM Bug #1426 (Resolved): IPsec descriptions need trimmed in rule labels
Chris Buechler
11:12 PM Todo #576 (Resolved): Make sure IPsec upgrade code properly handles mobile clients
Chris Buechler
11:09 PM Bug #1437: More validation needed on CSR generation
Yehuda - is this fixed? Chris Buechler
11:08 PM Feature #1260 (Resolved): Allow other Backends for Remote Access ( SSL/TLS + User Auth )
Chris Buechler
11:08 PM Bug #1251 (Resolved): /tmp/post_upgrade_command.php is not executing when going from 1.2.3 to 2.0
Chris Buechler
11:08 PM Bug #1417 (Resolved): OpenVPN client specific overrides doesnt work by default
Chris Buechler
11:07 PM Bug #1639 (Resolved): Port alias missing input validation in firewall_rules_edit.php
Chris Buechler
11:01 PM Bug #1598 (Resolved): IP Alias VIP configured on a CARP VIP, resets CARP VIP on sync
Chris Buechler
10:59 PM Bug #1614 (Resolved): "pptp clients" macro for firewall rules does not work
Chris Buechler
10:58 PM Bug #1515 (Resolved): Upgrading from 1.2.3, Load Balancer Pool to Gateway Group needs to strip invalid characters
Chris Buechler
10:58 PM Bug #1439 (Resolved): WAN PPPoE config dropped on update from 1.2.3 (nanobsd) to 2.0-RC1 (snapshot 20110415-1518)
Chris Buechler
10:58 PM Bug #1724 (Closed): Adding new gateway throws JS error in Chrome
no one else is seeing this Chris Buechler
10:57 PM Bug #1648 (Resolved): NAS IP setting
Chris Buechler
10:56 PM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
I can still replicate this. If the WAN is set to PPPoE and you run through the setup wizard leaving the same settings... Chris Buechler
10:47 PM Feature #1603 (New): URL table aliases should be usable within network type aliases
This needs to be backed out and moved to target 2.1 for fixing, putting URL table aliases within network aliases resu... Chris Buechler
01:09 PM pfSense Packages Bug #1768 (Resolved): DNS Forwarder of Tinydns
Hello,
just playing around with the TinyDNS package on pfs and found some "issues":
As far as I got it, the ide...
Oliver Loch
01:21 AM pfSense Packages Bug #1587 (Resolved): The openvpn client configuration exporter doesn't enforce TLS subject verification
Chris Buechler
01:20 AM pfSense Packages Bug #1742 (Resolved): Installation of Varnish on pfS RC broken and makes machine unusable
Chris Buechler

08/12/2011

02:32 PM Revision af6576a8: Also only add 127.0.0.1 as a DNS server if dnsmasq (DNS Forwarder) is enabled.
Jim Pingle
02:31 PM Revision 6a4ec785: Also only add 127.0.0.1 as a DNS server if dnsmasq (DNS Forwarder) is enabled.
Jim Pingle
11:57 AM Revision 37f33271: Correct the link generation. Reported-by: http://forum.pfsense.org/index.php/topic,39855.0.html
Ermal LUÇI
11:57 AM Revision 704143f5: Correct the link generation. Reported-by: http://forum.pfsense.org/index.php/topic,39855.0.html
Ermal LUÇI
11:53 AM Revision bf866028: Remove a slipped in text that confuses people
Ermal LUÇI
11:53 AM Revision 14f62733: Remove a slipped in text that confuses people
Ermal LUÇI
11:47 AM Revision 6c86a39f: Allow disabling having localhost in resolv.conf. There are some special setups that might need this.
Ermal LUÇI
11:46 AM Revision 89289853: Allow disabling having localhost in resolv.conf. There are some special setups that might need this.
Ermal LUÇI

08/11/2011

09:41 PM Revision f61dc8e6: Resolves #1193. Properly warn about duplicate default queue
Ermal LUÇI
09:39 PM Revision 401869ec: Resolves #1193. Properly warn about duplicate default queue
Ermal LUÇI
07:48 PM Revision 30696466: Fix description
Jim Pingle
07:47 PM Revision 221b170b: Fix description
Jim Pingle
07:29 PM Revision ea8eef6f: Move these permissions to user.priv.inc so they don't get blasted when priv.defs.inc is automatically regenerated.
Conflicts:
etc/inc/priv.defs.inc
Jim Pingle
07:26 PM Revision 84d86f07: Fix missing $ on variable.
Jim Pingle
07:25 PM Revision 9a26f342: Move these permissions to user.priv.inc so they don't get blasted when priv.defs.inc is automatically regenerated.
Jim Pingle
07:25 PM Revision d6c311d3: Fix missing $ on variable.
Jim Pingle
06:04 PM Revision aeb6ffe2: Populate pconfig in all cases with user info, or else when you delete a privilege, the list disappears until you go back and edit the user again. (Certs too)
Jim Pingle
06:04 PM Revision 5574e742: Sort user privileges so dashboard/index.php come first, so if a user has those permissions, they get redirected there first and not to another page.
Jim Pingle
06:03 PM Revision adacdf5f: Populate pconfig in all cases with user info, or else when you delete a privilege, the list disappears until you go back and edit the user again. (Certs too)
Jim Pingle
06:02 PM Revision 3f109700: Sort user privileges so dashboard/index.php come first, so if a user has those permissions, they get redirected there first and not to another page.
Jim Pingle
05:56 PM Bug #749: Downstream queues should not be assigned to LAN interfaces
Well making p2pcatch all only valid for Wan->Lan traffic is not easily possbile today.
It certainly would be possibl...
Ermal Luçi
05:40 PM Bug #1193: Traffic Shaper default queue Problem
Applied in changeset commit:401869ec326193cac13fbe4b6e2c8c879039445a. Ermal Luçi
05:40 PM Bug #1193: Traffic Shaper default queue Problem
Applied in changeset commit:f61dc8e6d638949866fdcb61c05c9d5905a48a80. Ermal Luçi
04:01 PM Revision 5457129f: Add Dashboard privilege which is a collection of all required pages for the dashboard. Partial fix for ticket #620 - may do something more for 2.1
Jim Pingle
03:59 PM Revision 72f7c837: Add Dashboard privilege which is a collection of all required pages for the dashboard. Partial fix for ticket #620 - may do something more for 2.1
Jim Pingle
03:44 PM Revision cfb5b1b1: Fix privilege matching so that it respects wildcards better, especially when leading.
Jim Pingle
03:44 PM Revision 3f655b44: Fix privilege matching so that it respects wildcards better, especially when leading.
Jim Pingle
03:36 PM Bug #1741 (Feedback): Default page when not authorised
If the user has either the Login/Logout, or the new Dashboard privilege, those now get sorted first in the list when ... Jim Pingle
01:28 PM Bug #1421 (New): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Jim Pingle
05:54 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
please change status to new,because it's unresolved Hafiz Rafiyev
12:39 PM Feature #620: No privilege choice to allow access to Dashboard
This should be worked around for now on 2.0/2.1 but if there is a more elegant long-term solution for 2.1 that would ... Jim Pingle
10:43 AM Revision d560b783: Syncrhonize the information with the wizards xml. Reported-by: http://forum.pfsense.org/index.php/topic,39176.msg205359.html#msg205359
Ermal LUÇI
10:42 AM Revision a020b638: Syncrhonize the information with the wizards xml. Reported-by: http://forum.pfsense.org/index.php/topic,39176.msg205359.html#msg205359
Ermal LUÇI
10:40 AM Bug #1767: Unable to modify pppoe interface which is linked to a vlan via WebGUI
Hi Oliver,
from the view of the WAN interface sis0_vlan7 is a network port and the name of this network port was c...
Willy Tenner
07:53 AM Bug #1767: Unable to modify pppoe interface which is linked to a vlan via WebGUI
Hi,
IMHO it's not a real bug - it's just the way it's configured. You create a VLAN and then you assign the VLAN i...
Oliver Loch
07:45 AM pfSense Packages Bug #1764: Wrong version of squid3 among the packages for pfSense 1.2.3
No, I mean the squid3 package has been broken in some fashion the majority of the time, and when it works, you're luc... Jim Pingle
03:47 AM pfSense Packages Bug #1764: Wrong version of squid3 among the packages for pfSense 1.2.3
Fulvio Scapin wrote:
> Jim P wrote:
> > Squid 3 is not and has never been recommended for general use. It's experim...
Fulvio Scapin
03:46 AM pfSense Packages Bug #1764: Wrong version of squid3 among the packages for pfSense 1.2.3
Jim P wrote:
> Squid 3 is not and has never been recommended for general use. It's experimental at best. Please use ...
Fulvio Scapin
 

Also available in: Atom