Project

General

Profile

Activity

From 08/17/2011 to 09/15/2011

09/15/2011

06:52 PM pfSense Packages Bug #1880: snort package 2.9 v2
oh another thing when set to update every 12 hours (suggested)
it tends to override settings that was previously set.
not availible
01:08 AM pfSense Packages Bug #1880 (Resolved): snort package 2.9 v2
I don't know how important it is but, there seems to be a missing gid entry
snort_netbios.rules. it's not important...
not availible
05:24 PM Bug #1861: false log filterdns: host_dns: failed looking up "88.192.1250.131"
FQDNs in as network with a /32 are equivalent to hosts, that works fine, it's how all ours are setup. Chris Buechler
04:40 PM Bug #1861: false log filterdns: host_dns: failed looking up "88.192.1250.131"
Found your bug !
<alias>
<name>files2_zimbra_com</name>
<type>network</type>
<address>files2.zimbra.co...
Franck Bourdonnec
03:53 PM Bug #1861: false log filterdns: host_dns: failed looking up "88.192.1250.131"
Sep 15 21:48:05 filterdns: host_dns: failed looking up "a184": hostname nor servname provided, or not known
Sep 15 ...
Franck Bourdonnec
04:36 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Chris, I have to admit, I have not checked it in the past few weeks but replication was simple. Build a pfSense, c... Derrick Conner
09:42 AM Bug #1874: Captive Portal Login dies on empty input
The Probleme why it wont work for voucher codes is really simple.
On line 143 in /usr/local/captiveportal/index.ph...
Andreas Böhm
08:39 AM Bug #1874: Captive Portal Login dies on empty input
Just reviewd it on github, the problem is not fixed for usage with voucher codes! Andreas Böhm
08:32 AM Bug #1874: Captive Portal Login dies on empty input
Is it only for user or pass fixed or also for vouchers?
I ask because im unable to view the changeset :(
Andreas Böhm

09/14/2011

03:27 PM Bug #1879 (Rejected): At end of install to hard drive pfSense directs user to eject CD but doesn't unlock CD ROM drive.
Scott Ullrich
03:27 PM Bug #1879: At end of install to hard drive pfSense directs user to eject CD but doesn't unlock CD ROM drive.
I have installed pfSense in ESX hundreds if not thousands of times and recently 5-10 in 5. I have never seen this is... Scott Ullrich
03:24 PM Bug #1879 (Rejected): At end of install to hard drive pfSense directs user to eject CD but doesn't unlock CD ROM drive.
Issue:
While testing pfSense 2 RC3 on ESXi 5.0.0 I received an error that the install CD was still locked by the ope...
William Deans
08:07 AM pfSense Packages Bug #1870 (Closed): phpSysInfo on 2.0 RC3
Jim Pingle
07:52 AM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
Perry,
Your reasoning is logical. I also tried the newest version of phpsysinfo and It destroyed my 2.0 install whe...
thomas schaefer
01:51 AM Feature #1878 (Closed): Option to add permanent ARP entries for WOL
Hi,
NOYB helped me with this problem http://forum.pfsense.org/index.php/topic,40451.0.html
It would be nice featu...
Johnny Good

09/13/2011

07:01 PM Bug #781: Entering sim code problem on a Huawei E1752
Yoann Simon wrote:
> Hello,
> I have got same problem with my 3g modem ...
> On france in business connexion ...
...
Yoann Simon
06:56 PM Bug #781: Entering sim code problem on a Huawei E1752
Hello,
I have got same problem with my 3g modem ...
On france in business connexion ...
Crdt
Poustiquet
Yoann Simon
05:35 PM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
I was the package developer. As most of the info phpsysinfo provides is in pfSense 2.0 and I don't use pfSense on har... Perry Mason
03:48 PM pfSense Packages Bug #1873: Layer 7 RDP
HTTP and SSH works... RDP not. This means that the L7 rule is in use Anonymous
03:46 PM pfSense Packages Bug #1873: Layer 7 RDP
We had a new pfsense installation with no other rules then the L7 rule. We just configured it as documented in you (s... Anonymous
03:30 PM pfSense Packages Bug #1873: Layer 7 RDP
You have to show more how you have configured this.
Usually its better to go through the forum first for such things...
Ermal Luçi
07:10 AM pfSense Packages Bug #1873 (Closed): Layer 7 RDP
If you create a Layer7 filter with RDP blocked and assign it to a LAN (I didn't test WAN) it won't block RDP sessions... Anonymous
03:30 PM Bug #1874: Captive Portal Login dies on empty input
Applied in changeset commit:00eda3a2eb5fb7e43ba9504c90ad494f41504888. Ermal Luçi
03:30 PM Bug #1874 (Feedback): Captive Portal Login dies on empty input
Applied in changeset commit:90477318aad050eb1f1b5282fac790f2a985fce3. Ermal Luçi
09:35 AM Bug #1874 (Closed): Captive Portal Login dies on empty input
If you go to the captive portal login page and click submit without filling in any in the vouchercode-field you´ll ge... Andreas Böhm
03:14 PM Bug #1877 (Resolved): (cosmetic) aliases-edit markup to wide for background
@2.0-RC3 (amd64) built on Mon Sep 12 10:27:40 EDT 2011@
hi,
when editing a list of aliases the right side of som...
Alexander Swen
09:37 AM Bug #1875 (Resolved): Captive Portal Voucher Error Messages won´t accept Umlauts
If you enter an umlaut into "Invalid Voucher Message" or "Expired Voucher Message" you get an acknowledgement, that y... Andreas Böhm

09/12/2011

10:59 PM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
It having authentication for everything, and working in general, is adequate as far as I'm concerned. Chris Buechler
09:48 PM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
I've got it so that it requires authentication now by including the header and footer. Chris, does this satisfy your ... thomas schaefer
08:37 PM Bug #1696 (Resolved): Panic when finishing setup wizard with PPPoE WAN
fixed Chris Buechler
05:05 PM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:8678130da6c30f82272a1b27b190da3e90211bf1. Jim Pingle
05:05 PM Bug #1696 (Feedback): Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:75bb4bc3849cda6af49ee51cc495353dcb5ad489. Jim Pingle
12:24 PM Bug #1696 (New): Panic when finishing setup wizard with PPPoE WAN
Panic still happens even after a gitsync picking up these changes. First run through the wizard (going from DHCP to P... Jim Pingle
08:05 AM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:851083bd2f9c382dc513d4a10608f5dc840efc01. Ermal Luçi
08:05 AM Bug #1696 (Feedback): Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:43d8f1cc9cd5190858ed7220339c0a147cc68dd2. Ermal Luçi
04:49 PM Bug #1872 (Closed): ipsec-tools strict DPD cookie check
Problem as described here, with patch here.
http://sourceforge.net/mailarchive/forum.php?thread_name=4DA4F48F.10608...
Chris Buechler
04:15 PM Todo #1871: simplify or explain
you need to post to the forum or mailing list for further help. Things are the way they are for good reason, you just... Chris Buechler
04:12 PM Todo #1871: simplify or explain
and you will tell me that there is no need for a Disable this Rule in Outbound rule editor ?
Think a moment a non ...
Franck Bourdonnec
03:36 PM Todo #1871 (Rejected): simplify or explain
There is a vast difference there. One disables the rule (as it says) the other makes an exception where no nat is per... Jim Pingle
03:34 PM Todo #1871 (Rejected): simplify or explain
Hello,
Firewall: NAT: Port Forward: Edit
=================================
Disabled Disable this rule
Set this...
Franck Bourdonnec

09/11/2011

07:27 PM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
I would love to work on it and re-release it. How can we find out if the package maintainer is still around? thomas schaefer
05:28 PM pfSense Packages Bug #1870: phpSysInfo on 2.0 RC3
probably because it didn't work. I'm not sure the package creator is around anymore. It also has no authentication su... Chris Buechler
04:02 PM pfSense Packages Bug #1870 (Closed): phpSysInfo on 2.0 RC3
pkg_config.8.xml - phpSysInfo has a maximum_version attribute of 1.2.3 on pkg_config.8.xml.
phpSysInfo does not s...
thomas schaefer
05:24 PM pfSense Packages Bug #1852: Snort and IP-Block Installation/Deintsallation issue
This is a general issue with packages that have conflicting dependencies. We expect to switch packages to PBIs in the... Chris Buechler
04:06 PM pfSense Packages Bug #1852: Snort and IP-Block Installation/Deintsallation issue
Not really avoidable if multiple packages use a particular dependency and cleanup during install. Perhaps a solution ... thomas schaefer

09/10/2011

10:25 PM Bug #1869 (Rejected): Broadcom 4306 Won't work
I think that's a config issue of some sort, search on that or post to the forum or mailing list for help. regardless ... Chris Buechler
10:20 PM Bug #1869 (Rejected): Broadcom 4306 Won't work
I'm not entirely sure which logs to attach, or what you need, but just ask, and I'll reply.
When I us "ifconfig bw...
Rogan Helms
11:19 AM Bug #1865: Fatal error by saving System: Advanced: Miscellaneous
I've updated to 2.0-RC3 (i386) built on Fri Sep 9 12:46:04 EDT 2011 and it works fine again.
Thanks Jim.
Anonymous

09/09/2011

03:55 PM Feature #1868 (Needs Patch): RFE: DHCP Server option pull-down menus, pre-populated data types
It would be great to be able to pull down a menu when setting the advanced DHCP server options. The link given in th... Bill McGonigle
03:43 PM Feature #1867 (Closed): RFE: DHCP Server option to set interface-MTU option to lowest WAN interface value
I have a setup with a Multi-WAN configuration, with one cable modem with MTU 1500 and one DSL modem, MTU 1492. After... Bill McGonigle
02:49 PM Todo #1863: consistence in alias usage
happy to learn it (red background)
for me it is ok, I won't loose time anymore in creating 10 rules with varying t...
Franck Bourdonnec
02:27 PM Todo #1863: consistence in alias usage
Red background on a form field means an alias can be used. That is consistent throughout the entire GUI. Jim Pingle
02:26 PM Todo #1863: consistence in alias usage
"other" includes aliases. Just for you (-:
Can you for 1 minute impersonate someone discovering pfsense.
He sees ...
Franck Bourdonnec
11:15 AM Bug #1865: Fatal error by saving System: Advanced: Miscellaneous
Applied in changeset commit:98a4cdc2a27cb5723ba3c01e64cee980691be2a4. Jim Pingle
11:15 AM Bug #1865 (Feedback): Fatal error by saving System: Advanced: Miscellaneous
Applied in changeset commit:ae0023beeaa0da21cf2080e81cec9631bee63c8e. Jim Pingle
09:40 AM Bug #1865 (Resolved): Fatal error by saving System: Advanced: Miscellaneous
pfSense 2.0-RC3 (i386) built on Thu Sep 8 15:15:55 EDT 2011
When I click on the save button appears this error m...
Anonymous
10:09 AM Bug #1866 (Rejected): Dashboard: System Information: CPU Type no longer shows powersave details
The CPU frequency for power saving is only printed if the current frequency does match the highest frequency. If you ... Jim Pingle
09:50 AM Bug #1866 (Rejected): Dashboard: System Information: CPU Type no longer shows powersave details
pfSsense 2.0-RC3 (i386) built on Thu Sep 8 15:15:55 EDT 2011
Since this or previous snapshot the power saving de...
Anonymous
08:13 AM Feature #1864 (Resolved): "Start" button for IPsec should be available for IP alias networks
If the local subnet of an IPsec network is an IP alias, the "start" button under Status>IPsec doesn't show up. That's... Chris Buechler
02:35 AM Bug #1419: Incorrect Intel License information in dmesg
Found a copy:
http://cygnus.redirectme.net/FreeBSD_4.9_Docs/legal/intel_ipw/LICENSE
We should be careful of thi...
Bill McGonigle

09/08/2011

06:08 PM Todo #1863 (Rejected): consistence in alias usage
"other" includes aliases. Chris Buechler
06:01 PM Todo #1863 (Rejected): consistence in alias usage
Hello,
please make the 'Destination Port from' field display something like
'single port or alias' to be consistent...
Franck Bourdonnec
05:34 PM Bug #1851: ECC-Cert breaks the webconfigurator
maybe we want to "block" uploading the following curves until working ... Michal Fresel
05:22 PM Bug #1851: ECC-Cert breaks the webconfigurator
gen... Michal Fresel
04:53 PM Bug #1851: ECC-Cert breaks the webconfigurator
I think lighty need it enable in config and presently we do not enable sslv3. Ermal Luçi
04:50 PM Bug #1851: ECC-Cert breaks the webconfigurator
from /var/log/lighttpd.error.log ... Michal Fresel
04:41 PM Feature #1860: Allow NTP server to be overriden by WAN DHCP
will try to make it more readable in the future - hopefully ;) Michal Fresel
04:03 PM Feature #1860 (New): Allow NTP server to be overriden by WAN DHCP
ok I misunderstood what you were talking about there. I fixed the description to be more clear. Jim Pingle
03:36 PM Feature #1860: Allow NTP server to be overriden by WAN DHCP
pushing the official NTP-servers (counting 3) for my country by DHCP - so it is a reputable source declared by law.
...
Michal Fresel
03:18 PM Feature #1860 (Rejected): Allow NTP server to be overriden by WAN DHCP
The server entered for pfSense is used by the NTP daemon as its upstream source - you can't have pfSense use only its... Jim Pingle
03:16 PM Feature #1860 (Needs Patch): Allow NTP server to be overriden by WAN DHCP
As with DNS, (optionally) allow the upstream DHCP server to provide NTP servers to the firewall. Michal Fresel
03:22 PM Bug #1861: false log filterdns: host_dns: failed looking up "88.192.1250.131"
(fyi, searching '1250' in a fresh backup gives nothing of course) Franck Bourdonnec
03:17 PM Bug #1861 (Closed): false log filterdns: host_dns: failed looking up "88.192.1250.131"
Hello,
I made a typo while entering an IP in a alias object.
1250 instead of 250
I validated the alias (5 IP l...
Franck Bourdonnec
02:52 PM Feature #1859: default SSH-key should at least use 2048 bit RSA-keys
plz also read "further reading" from bug #1858 Michal Fresel
02:50 PM Feature #1859 (Resolved): default SSH-key should at least use 2048 bit RSA-keys
after installing a new box the system-SSH-key should default to 2048 or even 4096 bit RSA-keys... Michal Fresel
02:31 PM Feature #1858: default SSL-cert should at least use 2048 bit RSA-keys
key-sizes above 8192 will not work on Safari (Mac OS X) Michal Fresel
02:08 PM Feature #1858 (Resolved): default SSL-cert should at least use 2048 bit RSA-keys
after installing a new box the system-SSL-cert should default to 2048 or even 4096 bit RSA-keys
current: RSA - 102...
Michal Fresel
01:47 PM Bug #1849: Traffic shaper - By Queue view needs to show/use friendly inerface names
The friendly interfaces are shown now.
Remaining is showning the root interface so they can be cloned
Ermal Luçi
01:46 PM Bug #1857: LAN-if does not check if there is already another host using that address
so expecting a "feature" for the console would not be implemented either:
> ##external management-host##...
Michal Fresel
01:34 PM Bug #1857: LAN-if does not check if there is already another host using that address
We can't stop everyone from shooting themselves in the feet.
Changing the default LAN behavior to anything but st...
Jim Pingle
01:32 PM Bug #1857: LAN-if does not check if there is already another host using that address
I agree with Jim. This is not going in but thanks for the suggestion.
Scott Ullrich
01:28 PM Bug #1857: LAN-if does not check if there is already another host using that address
hi Jim,
somehow i still do not understand WHAT can get wrong?
I know it is not simple and some coding is needed
...
Michal Fresel
01:01 PM Bug #1857: LAN-if does not check if there is already another host using that address
Still too many things to go wrong. It is not that simple.
And the real fix is even simpler: Just don't plug a new ...
Jim Pingle
12:56 PM Bug #1857: LAN-if does not check if there is already another host using that address
hi Jim,
x) send just 1 (one) ICMP package for ping
x) single pings to the whole subnet concurrently and wait for ...
Michal Fresel
12:23 PM Bug #1857 (Rejected): LAN-if does not check if there is already another host using that address
It's a lot of work and a lot to go wrong for very little benefit there. If someone is concerned about it taking over ... Jim Pingle
12:19 PM Bug #1857: LAN-if does not check if there is already another host using that address
maybe we set the LAN-if to DHCP to test if there is already a server and that way we obtain an IP (this way we know t... Michal Fresel
11:55 AM Bug #1857 (Rejected): LAN-if does not check if there is already another host using that address
when a new installation is booting it should check if there is already another host using the default ip of 192.168.1.1 Michal Fresel
08:07 AM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
On the 2.1 IPv6 snaps dating September 1st I can not replicate this anymore, this may have been fixed somewhere by an... Seth Mos
06:28 AM Feature #1854 (Feedback): filter field on diag_logs_filter.php should be at top of page
Applied in commit:21c160361dff36941812424390c10a235762b411 Warren Baker
05:49 AM Feature #1855: NAT before IPsec VPN
Just to synchronize the answer
http://forum.pfsense.org/index.php/topic,38559.msg210340.html#msg210340
Ermal Luçi
02:52 AM Feature #1855: NAT before IPsec VPN
The linked info is still OpenBSD-only I believe. Chris Buechler
01:23 AM Feature #1855: NAT before IPsec VPN
Thanks to FreeBSD 9 it should be now possible to NAT before the VPN in order to solve network overlapping.
Here htt...
Michele Di Maria
01:14 AM Feature #1855 (Closed): NAT before IPsec VPN
I thought we already had a feature ticket open for IPsec+NAT in general but doesn't appear so. Michele Di Maria
05:18 AM Bug #1856 (Closed): Removing a Phase 2 does not remove the SPD policy
Removing a IPv6 phase 2 entry leaves the IPsec SPD policy in place.
Deleting it manually from the IPsec status SPD...
Seth Mos
02:34 AM Todo #595 (Closed): Test IPsec with NAT
what's mentioned in this ticket works, there are other caveats with IPsec and NAT Chris Buechler

09/07/2011

10:10 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
Alright, please give me a few weeks, as I am really far behind in my projects, thank you again for this quick fix. I ... Matt Crook
07:08 PM Bug #1437 (Resolved): More validation needed on CSR generation
thank you Chris Buechler
06:42 PM Feature #1854 (Resolved): filter field on diag_logs_filter.php should be at top of page
The filter field on diag_logs_filter.php should be at the top of the page, like the states display, as if you have a ... Chris Buechler
04:07 PM Bug #1850: WAN interface missing on traffic shaper queue interface
Ermal Luçi wrote:
> I cannot see this driver in FreeBSD 8.1 did you compile from some patch of sorts?
The driver ...
Oliver Loch
03:42 PM Bug #1850 (Closed): WAN interface missing on traffic shaper queue interface
driver doesn't exist in stock releases Chris Buechler
09:50 AM Bug #1850: WAN interface missing on traffic shaper queue interface
I cannot see this driver in FreeBSD 8.1 did you compile from some patch of sorts? Ermal Luçi
09:49 AM Bug #1850: WAN interface missing on traffic shaper queue interface
Hi,
after checking that altq is implemented into the driver, I added it to the is_altq_capable() function in the "...
Oliver Loch
06:44 AM Bug #1850 (Closed): WAN interface missing on traffic shaper queue interface
Hi,
running the latest 2.0RC3:
2.0-RC3 (amd64)
built on Tue Sep 6 22:44:22 EDT 2011
the WAN interface is m...
Oliver Loch
03:53 PM Feature #1846: strict nat 1-to-1
Having a /32 IP on an interface and a gateway on another subnet is not a valid pfSense configuration, and thus not su... Jim Pingle
03:43 PM Feature #1846: strict nat 1-to-1
then we have a problem.....!
If i read well, nat-1-to-1 is in both direction, when an interface is 'wan'.
You a...
Franck Bourdonnec
01:54 PM pfSense Packages Bug #1853 (Resolved): Barnyard2 binary not installed
After installing snort (2.8.6.1 pkg v 2.0) on pfsense 2.0-RC3 (amd64) (built on Tue Sep 6 22:44:22 EDT 2011) barnyard... david campbell
10:55 AM Bug #1851 (Feedback): ECC-Cert breaks the webconfigurator
Applied in changeset commit:f65b6851ea3d473128e48419450f0edb5d8830d9. Jim Pingle
10:25 AM Bug #1851: ECC-Cert breaks the webconfigurator
some ecc-test-certificates are available at "SECG's ECC/TLS test server":http://tls.secg.org/index1.php?action=server... Michal Fresel
07:16 AM Bug #1851: ECC-Cert breaks the webconfigurator
known bugs in lighttpd - fixed in 1.4.29
see http://www.lighttpd.net/2011/7/3/1-4-29
Michal Fresel
06:57 AM Bug #1851 (Closed): ECC-Cert breaks the webconfigurator
Uploading a certificate which is using Elliptic curve cryptography (ECC) - afterwards webconfigurator stops respondi... Michal Fresel
09:09 AM pfSense Packages Bug #1852 (Closed): Snort and IP-Block Installation/Deintsallation issue
If you install snort, it replaces system Perl with Perl-multi-threaded. Once you remove snort it removes Perl-multi-t... Darko Arandjelovic
03:37 AM Bug #1849 (New): Traffic shaper - By Queue view needs to show/use friendly inerface names
Traffic shaper - By Queue view needs to use friendly inerface names to allow easy configuration and presentation.
Al...
Ermal Luçi
02:57 AM Bug #1848 (Confirmed): Limiters after policy routing has taken place do not behave correctly
If there are 2 WANs and the primary one fails and there are limiters configured in floating rules(after policy routin... Ermal Luçi

09/06/2011

10:06 PM Bug #1437: More validation needed on CSR generation
I have so much going on, I thought I replied to this, but I guess I did not.
Everything that I did to cause an err...
Yehuda Katz
09:56 PM Bug #1437: More validation needed on CSR generation
should be fixed, awaiting Yehuda's confirmation Chris Buechler
09:57 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
should be fixed, will leave for confirmation Chris Buechler
09:53 PM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
if someone wants to see this get fixed in short order, purchase a 5 hour support subscription at portal.pfsense.org a... Chris Buechler
09:49 PM Bug #1318 (Resolved): Certificate error: certificate subject does not match signing request subject
Chris Buechler
09:47 PM Bug #1646 (Resolved): 'pfctl -b' does not function as intended
Chris Buechler
09:45 PM Bug #1552 (Resolved): DNS Reject Rule Crashes Router
Chris Buechler
09:44 PM Bug #1696 (New): Panic when finishing setup wizard with PPPoE WAN
no change
Chris Buechler
09:30 PM Bug #1517 (Closed): Captive Portal sends RADIUS output accounting packets with zero value
this has been confirmed working. Chris Buechler
07:07 PM Feature #972: Allow adding gateways outside of interface subnet
well, OVH big big french provider is also using this king of setup
A well english detailled big page explain all h...
Franck Bourdonnec
06:50 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
yes, I have added the 'dashboard' as small fixe, because all other unauthorized pages goes to 404.
In future release...
Franck Bourdonnec
06:36 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
The privilege system will redirect the user to whichever page is listed first in their permissions (which they are al... Jim Pingle
06:35 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
Applied in changeset commit:fce938b3a32ed071edf9aba6b1f07ec08a82a743. Jim Pingle
06:35 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
Applied in changeset commit:7179d00e0b0134615e442829792960f343b8a378. Jim Pingle
06:06 PM Bug #1845: diag_system_pftop 404 not found = cardiac crisis
menu system/user/manager
add a group
fix a few status/logs page among all proposed priviledges
create a user
ad...
Franck Bourdonnec
05:49 PM Bug #1845 (Feedback): diag_system_pftop 404 not found = cardiac crisis
not sure what you're referring to Chris Buechler
05:47 PM Bug #1845 (Resolved): diag_system_pftop 404 not found = cardiac crisis
Hello,
after day and day of tuning/discovering, I had tried the user/group settings to build a person able to consul...
Franck Bourdonnec
06:46 PM Feature #1847 (Rejected): Relax gateway checking
Duplicate of #972 Jim Pingle
06:44 PM Feature #1847 (Rejected): Relax gateway checking
Hello,
During network lessons at school you learn that the gateway must be reachable with an IP in the same subnet...
Franck Bourdonnec
06:21 PM Feature #1846: strict nat 1-to-1
it is both directions, where traffic is set to leave the interface where that 1:1 is assigned. Read http://pfsense.or... Chris Buechler
06:19 PM Feature #1846: strict nat 1-to-1
oh, I see no reason why you call nat-1to-1 when traffic is internet toward natted machine (B) and routing when it is ... Franck Bourdonnec
06:04 PM Feature #1846 (Rejected): strict nat 1-to-1
rules including policy routing and NAT are separate entities that must be configured as you desire. Chris Buechler
06:01 PM Feature #1846 (Rejected): strict nat 1-to-1
Hello,
Add a check box in NAT One to One that make it more strict.
Explanation
my system have
Two WAN inter...
Franck Bourdonnec
05:48 PM pfSense Packages Bug #1844: diag_system_pftop 404 not found = cardiac crisis
please close this one, I recreated it in 'pfsense' . Franck Bourdonnec
05:48 PM pfSense Packages Bug #1844 (Rejected): diag_system_pftop 404 not found = cardiac crisis
duplicate of #1845 Chris Buechler
05:39 PM pfSense Packages Bug #1844 (Rejected): diag_system_pftop 404 not found = cardiac crisis
Hello,
after day and day of tuning/discovering, I had tried the user/group settings to build a person able to consul...
Franck Bourdonnec
05:33 PM Bug #337: sticky connections do not work
Ermal, can you please check your last commit. I can confirm that sticky sessions work for me on snapshot 2.0-RC3 (i3... I K
08:12 AM Feature #1843 (Resolved): Diag > Limiter Info does not show queues under pipes
Under Diagnostics > Limiters, it only shows the limiter pipes and does not display any information about the child qu... Jim Pingle
04:23 AM pfSense Packages Bug #1842: problem with FreeRADIUS?
This is a package issue and not a Captive portal issue from what you have posted here. Ermal Luçi
03:45 AM pfSense Packages Bug #1842 (Closed): problem with FreeRADIUS?
With CP & vouchers, say a 1 hour voucher never kicks off/logs out the end user after an hour.
After searching there ...
Rob Heat
03:03 AM Bug #1841 (Duplicate): TCP state issue when traffic passing through a GRE tunnel within IPSEC
When running a GRE tunnel between two Pfsense 2.0 RC3 TCP traffic is shown as having its SYN/ACK packets dropped on t... Nigel Wright

09/05/2011

08:29 AM Bug #1052: Certificate validation of the LDAPS servers is not enforced
Ermal Luçi wrote:
> HAve you tested with latest snapshots?
Hi Ermal,
No, I haven't; just came back from holida...
Florent Daigniere

09/04/2011

04:29 PM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
That's good to know, we'll investigate. We're still not quite sure what's happening, some ipv6 builds seem to hit it ... Seth Mos
04:26 PM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
These errors showed up on the upgrade, and are associated with the upgrade process, not trying to display the graphs.... Eddie Atherton

09/03/2011

08:18 PM pfSense Packages Bug #1753: Spoink integration
Thanks to pfsense developers for the new version of snorte with the block offenders working, i've enabled it on my pf... Walter Gomes
04:29 PM Feature #1829: CARP with IPv6 support
ah, you mean the rtadvd settings? That would make sense, I tied them into the dhcp6 config as that seems the most str... Seth Mos
04:01 PM Feature #1829: CARP with IPv6 support
My thought was actually keeping it in the DHCPv6 screen even though it has nothing to do with it, since we already ha... Chris Buechler
02:59 PM Feature #1829: CARP with IPv6 support
Ah, yes, well, the gateway field needs to go from the dhcpv6 config in the UI since it doesn't exist.
Complain to th...
Seth Mos
02:22 PM Bug #1839: No Quality RRD Graph w/ Non-Default Frequency Probe

RRD Graphs: Quality

Works with Probe Frequency (System - Routing) set at default (empty), 1, 2, 3, and 9 (prob...
NOYB NOYB
12:43 AM Bug #1839 (Closed): No Quality RRD Graph w/ Non-Default Frequency Probe

Setting Gateway Frequency Probe (System - Routing) to a non-default value, say 10 seconds, causes the RRD Quality ...
NOYB NOYB
02:19 PM Feature #1836: RFC 5006 support for DNS from RAs
rtadvd service support committed. should fix both dns server and rtadvd clients to get the same information.
radns...
Seth Mos
01:36 PM pfSense Packages Bug #1840 (Resolved): Snort rules update and filename
The package has the snort rules file hardcoded in the code.
This makes it a step to be followed when upgrading snort...
Ermal Luçi
06:07 AM Bug #1662: DNS server gateway selection missing input validation
Still not fixed.
http://forum.pfsense.org/index.php/topic,40498.0.html
Seth Mos

09/02/2011

08:56 PM Bug #1690: PPPoE Server not passing IP from RADIUS server
I am just upgrading now, has there been some work since I last posted on the PPPoE server? If so, thank you. Matt Crook
11:09 AM Bug #1838: Dynamic DNS disabled checkbox doesn't work
Post you dyndns section from your config. Ermal Luçi
05:58 AM Bug #1838 (Resolved): Dynamic DNS disabled checkbox doesn't work
As disabling a dynamic dns client with the checkbox, nothing is done except still updating dyndns host. Checkbox does... Nicolas Liaudat
07:13 AM pfSense Packages Bug #692 (Feedback): snort pidfile issue
Latest package of snort should not have this issue. Ermal Luçi
07:13 AM pfSense Packages Bug #1746 (Feedback): Preprocessor do not work
Should be working now Ermal Luçi
07:12 AM pfSense Packages Bug #1747 (Feedback): Barnyard2
Should be working now Ermal Luçi
07:11 AM pfSense Packages Bug #1748 (Feedback): Rules GUI
Should work as intended now. Ermal Luçi
03:26 AM Bug #337: sticky connections do not work
Updated to version 2.0-RC3 (i386) built on Thu Sep 1 18:11:23 EDT 2011
Unfortunately the behavior is still the sam...
Mark Huijgen

09/01/2011

11:42 AM Bug #1837 (Resolved): Problem with PPP and default gateway switching
Description of how to replicate: ... Chris Buechler
11:25 AM Feature #1829: CARP with IPv6 support
need some additional consideration on how this should work from the GUI perspective. Maybe just make the underlying b... Chris Buechler
11:11 AM Feature #1829: CARP with IPv6 support
The specific issue is that you can not select a Carp IPv6 vip interface for router advertisements. Ideally we need to... Seth Mos
10:17 AM Feature #1829 (Resolved): CARP with IPv6 support
need to be able to bind router advertisements to CARP IPs. Chris Buechler
11:07 AM Feature #1836: RFC 5006 support for DNS from RAs
Found this client which is even listed in the FreeBSD ports, dump the info into our filesystem and the rest is picked... Seth Mos
10:28 AM Feature #1836 (Resolved): RFC 5006 support for DNS from RAs
Need RFC 5006 support for DNS from RAs Chris Buechler
11:05 AM Feature #1835: uPNP IPv6 support
probably will have to add a new port for miniupnpd-v6 or similar, as we're going to keep RELENG_2_0 snapshot builders... Chris Buechler
11:04 AM Feature #1835: uPNP IPv6 support
Thread in the miniupnp forum here.
http://miniupnp.tuxfamily.org/forum/viewtopic.php?t=728
This will take a while...
Seth Mos
10:25 AM Feature #1835 (Resolved): uPNP IPv6 support
uPNP needs IPv6 support. Chris Buechler
10:25 AM Feature #177: IPv6 support
I can't envision any scenario where you'd need proxy NDP, though maybe something will come up in the future. On the r... Chris Buechler
10:24 AM Feature #1834 (Resolved): Stateless autoconfig WAN type for IPv6
Need a WAN type for stateless autoconfiguration for IPv6, that's not going to be common in typical Internet firewall ... Chris Buechler
10:21 AM Feature #1833 (New): PPTP type WAN IPv6 support
PPTP type WANs need IPv6 support. Not sure how that works or if it's even feasible, needs research. Chris Buechler
10:20 AM Feature #1832 (Resolved): Traffic shaper needs review for IPv6
Layer 3 protocol isn't relevant for much of what it does, but needs review and at least some changes for IPv6. Chris Buechler
10:20 AM Feature #1831 (New): Captive portal IPv6 support
Captive portal needs IPv6 support. ipfw fwd doesn't function with IPv6 last I heard, amongst other things that need w... Chris Buechler
10:16 AM Feature #1828 (Resolved): Server load balancer IPv6 support
server load balancer needs IPv6 support. Chris Buechler
10:15 AM Bug #1827 (Resolved): rc.newwanipv6 needs work
rc.newwanipv6 needs work. Might need to converge with rc.newwanip to avoid race and stepping on each other causing re... Chris Buechler
10:15 AM Feature #1826 (New): PPPoE server IPv6 support
PPPoE server needs IPv6 support. Sends IPv6-CP packets, not confirmed if DHCPv6 server works. Chris Buechler
10:13 AM Feature #1825 (Resolved): Dynamic DNS client IPv6 support
DynDNS client needs IPv6 support for registering AAAAs. Chris Buechler
09:50 AM pfSense Packages Bug #1753 (Feedback): Spoink integration
Spoink is now integrated to snort and snort uses 2.9.0.5 port.
Possibly should ping the spoink author about this?
Ermal Luçi
04:17 AM Bug #1824 (Resolved): DHCPv6 and unknown-clients.
fixed Chris Buechler
03:38 AM Bug #1824 (Resolved): DHCPv6 and unknown-clients.
Hello,
There is a bug in the configuration of DHCPv6 : using the deny unknown-clients option makes the DHCPv6 fail...
Alexis Olivier

08/31/2011

05:12 PM Bug #1666 (Resolved): OpenVPN interface doesn't get added to bridge after reboot
thanks Chris Buechler
01:40 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Seems to be fixed with latest snapshot, thanks. Joost van den Broek
02:47 PM pfSense Packages Bug #1822: Snort won't start
This is for snort-dev from what i can see!? Ermal Luçi
11:57 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Also looking for a progress/status report here. Thanks. Alan Bryan

08/30/2011

11:08 PM Bug #1823 (Resolved): policy routing for firewall-initiated traffic only works for interface IPs
The rules such as: ... Chris Buechler
12:38 PM Bug #1052: Certificate validation of the LDAPS servers is not enforced
HAve you tested with latest snapshots? Ermal Luçi
11:50 AM Bug #1690 (Feedback): PPPoE Server not passing IP from RADIUS server
Can you please try latest snapshots?
Also if still seeing issues can you get packet traces and any logs from pfSense...
Ermal Luçi
11:20 AM Bug #1696 (Feedback): Panic when finishing setup wizard with PPPoE WAN
Applied in changeset commit:db74464bf6f980c5c5845d53624d4c6f1b139fa7. Ermal Luçi
10:48 AM Bug #1696: Panic when finishing setup wizard with PPPoE WAN
I was finally able to reproduce this in a VM, even when the WAN was initially set for DHCP. Same panic message/backtr... Jim Pingle
10:47 AM Bug #337: sticky connections do not work
Can you please test with tomorrows snapshot? Ermal Luçi
06:21 AM Bug #337: sticky connections do not work

I'm having the exact same behaviour as described by Mark Huijgen earlier. The only difference is that my two WAN in...
Siddharth Patil
07:44 AM Bug #1344: Replace prototype javascript code with jQuery
Bootstrap, a nice framework from Twitter which has a number of some quite nice features http://twitter.github.com/boo... Warren Baker
07:22 AM pfSense Packages Bug #1822 (Closed): Snort won't start
So many issues with this package.
1) Local rules get wiped every time the auto updater runs. Then we have to go t...
Stephen Lombard
07:16 AM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Did it with success, but with a little modification about the netmask. In fact to make it work I had to use the $mask... Rino Santilli
04:51 AM pfSense Packages Bug #1821 (Rejected): spanning tree options
STP options work fine, not enough here to do anything with. Please post to the forum or mailing list with information. Chris Buechler
04:12 AM pfSense Packages Bug #1821 (Rejected): spanning tree options
Spanning Tree options are not considered Enrico Pesce

08/29/2011

11:58 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Yup, I hear ya.
Maybe by 2.1 someone could figure out how to do the dynamic hosts part per interface also, instead...
NOYB NOYB
11:06 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
thanks. Too close to release to fix something that hasn't ever worked (probability of unintended consequences is alwa... Chris Buechler
10:27 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Attached patch should result in the following behavior for registering DHCP hosts in DNS Forwarder.
*+Statically A...
NOYB NOYB
09:38 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Maybe just a tad bit of logic for using system domain when not specified in dhcp interface.... NOYB NOYB
07:16 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Could fix for the statically assigned hosts of each interface in services dhcp be as simple as this?
--- /etc/in...
NOYB NOYB
04:24 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
That's always worked that way, the domain filled in for the DHCP server if different from the primary domain name of ... Chris Buechler
04:17 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
Can you please bring some examples and facts from pfSense config files? Ermal Luçi
03:37 PM Bug #1819 (Duplicate): DNS Resolver Not Registering DHCP Server Specified Domain Name
DHCP Server specified Domain Name not being registered in DNS Forwarder.
Hosts are resolvable by System General sp...
NOYB NOYB
06:29 PM Bug #1809 (Closed): Growl issue
Chris Buechler
07:17 AM Bug #1809: Growl issue
Well oke, thats now...
Never noticed that in RC1, But yes, it's working now :)
Thanks.
Richard van Herp
04:02 PM pfSense Packages Bug #1820 (Closed): widescreen package doens't show ipv6 link
widescreen package doens't show ipv6 link
dhcpv6 server & dhcpv6 lease link are missing when widescreen package is...
Alexandre Paradis
03:37 PM Bug #1806 (Feedback): OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Ermal Luçi
03:36 PM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Can you try this?... Ermal Luçi
03:30 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:737dbc05c13ddf31dc238ac59b406cc62716482a. Ermal Luçi
03:30 PM Bug #1666: OpenVPN interface doesn't get added to bridge after reboot
Applied in changeset commit:8614f335d1c9d62cdb65e41f235e123e6993368e. Ermal Luçi
03:30 PM Bug #1666 (Feedback): OpenVPN interface doesn't get added to bridge after reboot
Please try again newest snapshots Ermal Luçi
03:25 PM Bug #1818 (Closed): DNS Forwarder Not Registering DHCP Server Specified Domain Name
DHCP Server specified Domain Name not being registered in DNS Forwarder.
Hosts are resolvable by System General sp...
NOYB NOYB
10:37 AM Feature #1817 (Resolved): Expand easyrule functions
It would be nice if we could also use subnets for wan and lan interfaces and use the gateways thru the easyrule cli.
...
Sander Naudts
08:19 AM Feature #177 (Feedback): IPv6 support
Most of the basic system now works with IPv6.
Large things that don't work.
- PPTP Client. not checked into. Is that...
Seth Mos
08:08 AM Todo #1373 (Resolved): Upgrade OpenVPN
This code is already checked in and the client exporter supports the new options as well. Furthermore the client expo... Seth Mos
08:05 AM Todo #1441: IPv4 bogons list is now static
Negative, some networks will remain is bogon networks regardless, if networks are returned to a RIR they might come b... Seth Mos
05:00 AM Feature #1663 (Feedback): DHCPv6 relay
Please test Seth Mos
04:01 AM Bug #1816 (Feedback): diag_states_summary.php needs help for IPv6
Added Love, please check Seth Mos

08/28/2011

12:22 AM pfSense Packages Bug #1770 (Resolved): Can not install package Country Block
Chris Buechler
12:12 AM pfSense Packages Bug #1770: Can not install package Country Block
Fixed in version 2.2 thomas schaefer
12:22 AM pfSense Packages Bug #1579 (Resolved): countryblock doesn't uninstall cleanly
thanks Chris Buechler
12:14 AM pfSense Packages Bug #1579: countryblock doesn't uninstall cleanly
Fixed in version 2.2 thomas schaefer

08/27/2011

09:38 PM Bug #1816 (Resolved): diag_states_summary.php needs help for IPv6
diag_states_summary.php doesn't work correctly with IPv6. Seems to group everything under one entry, just listing the... Chris Buechler
07:28 PM pfSense Packages Bug #1218 (Feedback): Freeradius package does not start when i do reboot
should be fixed by https://github.com/bsdperimeter/pfsense-packages/pull/45 Chris Buechler
04:30 PM Feature #687: Test Button for Growl Notifications
Chris Buechler wrote:
> You can file a test notice by going to Diag>Command, in PHP box put in:
> file_notice("tes...
Gerald Livingston
07:57 AM pfSense Packages Bug #1753: Spoink integration
2.0-RC3 (amd64)
built on Wed Aug 24 10:10:33 EDT 2011
same case of hamilton, the error message is displayed onl...
Walter Gomes
04:45 AM pfSense Packages Feature #1815 (Closed): OpenVPN Client Export Additional Parameters
Hi,
The openvpn client configuration exporter doesn't have an option to pass additional parameters to the client (...
Andy I.
04:38 AM Feature #1009: Active Directory group membership checking
New version for auth.inc and system_authservers.php to allow for an extended LDAP query (Groups or otherwise) Andy I.

08/26/2011

05:28 PM Bug #1812: bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
i just uninstalled the widescreen package, shortcut are back. There is something missing for 2.1 in the widescreen pa... Alexandre Paradis
02:56 AM Bug #1812: bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
i found that right after an upgrade goth links are there. The links dissapear after all the package upgrade.
i hav...
Alexandre Paradis
01:29 AM Bug #1556 (Resolved): Changing local IPsec tunnel endpoint does not work
I can not replicate this anymore as I only have a single WAN left at work. Seth Mos

08/25/2011

06:59 PM Feature #1701: Vouchertime should be seperated
We have no current plans for implementing this. where "current plans" always means "someone willing to fund it" out o... Chris Buechler
04:17 AM Feature #1701: Vouchertime should be seperated
No intressst in this? Andreas Böhm
06:49 PM Bug #1556 (Feedback): Changing local IPsec tunnel endpoint does not work
I'm also unable to replicate this. Chris Buechler
08:22 AM Bug #1556: Changing local IPsec tunnel endpoint does not work
I switch one of my tunnels back and forth regularly between my two WANs and as long as I adjust the peer address on t... Jim Pingle
05:56 PM Bug #1814 (Rejected): Drive read/boot errors w/2.0 RC3
You have a dying hard drive or other fatal hardware quirk. Nothing we can do about that. Jim Pingle
05:55 PM Bug #1814 (Rejected): Drive read/boot errors w/2.0 RC3
From forum post: http://forum.pfsense.org/index.php/topic,39181.0.html which was submitted by palesius
I have a sy...
David T
05:13 AM Bug #1725 (Feedback): DHCPv6 non-common bitmask shows incorrect range
I've been able to create a new gen_subnetv6_max() function in about a hour or 2 of coding and testing. Should be reso... Seth Mos

08/24/2011

04:09 PM Bug #1659 (Feedback): Missing input validation in rules gateway selection
Should be all set, there was a unset of the input errors halfway the input validation that must have broken a lot of ... Seth Mos
09:31 AM Bug #1659: Missing input validation in rules gateway selection
Committed code in git that should fix most of this, shows only the correct address family when editing a pool or fire... Seth Mos
03:09 PM Bug #1660 (Feedback): Missing input validation in system_gateway_groups_edit.php
I've committed code to the gateway groups page that prevents you from adding different address families in the same g... Seth Mos
02:50 PM Feature #1726 (Resolved): Allow disabling the "Autonomous address-configuration"
Confirmed that my Macbook with 10.5 only has a link-local address when set to router-only. you can Still enable DHCP6... Seth Mos
07:43 AM Bug #1809: Growl issue
How are you testing Growl to say it is not working?
Growl creates a temp file (/var/db/growlnotices_lastmsg.txt) of...
Warren Baker
06:41 AM Bug #1610: v6 IPsec tunnels can trap 12 the kernel
This affects the kernel in 2.0 which is currently also in use on 2.1 Seth Mos
06:40 AM Bug #1633 (Feedback): Missing input validation in IPv6 gateways
Code committed that prevents address family mixups in gateways and monitors, prevent v6 gateways on v4 only interfaces. Seth Mos
05:37 AM Bug #1661 (Feedback): Missing input validation in system_routes_edit.php
Code with address family validation checked in, please test. Seth Mos
04:49 AM Bug #1662 (Feedback): DNS server gateway selection missing input validation
Code checked in that converts the interface names to gateway names, updated the system.inc code that updates the rout... Seth Mos
03:47 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
ronald meulendijks wrote:
> 0.0.0.0/0[any] 192.168.78.1[any] 255
> out ipsec
> esp/tunnel/95.96.134.40-91.189.22...
Chunlin Yao
03:45 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Jim P wrote:
> Some people are still hitting this same error, but not this specific circumstance. Two support custom...
Chunlin Yao
03:28 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
My situation maybe related to this issues.
Mobile clients connect to pfSense use nat-t. I think racoon should supp...
Chunlin Yao
03:45 AM Bug #1421: Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
Is there any progress on this issue? Derrick Conner
03:42 AM Feature #1807: Button needed for '-add a new one-' on the static IP configuration
Seems fair enough Seth Mos
03:40 AM Bug #1758: Upgrade fails to upgrade RRD data for traffic and packets
Caution, if the config is Upgraded on nanobsd platforms the converted RRD files are not immediately saved to the flas... Seth Mos

08/22/2011

06:11 PM Bug #1813: Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
floating rules can work around this Chris Buechler
05:50 PM Bug #1813 (Confirmed): Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
the 'pass out' rules such as:
pass out route-to ( em1 9.2.2.1 ) from 9.2.3.17 to !9.2.2.0/21 keep state allow-opt...
Chris Buechler
11:07 AM Bug #781: Entering sim code problem on a Huawei E1752
Having same problem here with a novatel eu850d minipcie card, although PIN is deactivated.
When removing the "GetOK ...
Christian Schwarz

08/21/2011

11:43 PM Bug #1812 (Rejected): bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
has to be a browser cache issue, they're there. Chris Buechler
11:36 PM Bug #1812 (Rejected): bug for ipv6 dhcpv6 & dhcpv6 lease shortcut
The dhcpv6 & dhcpv6 shortcut isn't present in the menu. but i have access if I type manualy the link in the address bar. Alexandre Paradis
06:28 PM Feature #1811 (Closed): Monitor PPP for connections stuck in "initial" state
I've been trying to help debug an issue with dynamic DNS updates on 3G connections (1545) but keep getting hampered b... Ross Williamson
06:10 PM Feature #1663: DHCPv6 relay
DHCP Relay page only has 4 fields which are all the same between v4 and v6 with the exception of input validation. I ... Chris Buechler
06:47 AM Feature #1663: DHCPv6 relay
I'll Investigate the needs. Page probably needs a total makeover because next to nothing that exists in ipv4 can be p... Seth Mos
01:11 PM Feature #1726 (Feedback): Allow disabling the "Autonomous address-configuration"
Added a "router" type that sends pinfoflags as being "". From the confusing documentation this might need to be "l" w... Seth Mos
06:38 AM Feature #1726: Allow disabling the "Autonomous address-configuration"
My thought was to add this as a choice from the drop down on the DHCP server page.
The config code currently does ...
Seth Mos
08:28 AM Bug #1583 (Feedback): IPv6 IPs with :: trigger DNS rebinding
Committed patches for both rebind and referrer checks.
Added patch for redirect url.
Seth Mos
06:58 AM Bug #1583: IPv6 IPs with :: trigger DNS rebinding
Confirmed that without a alternate port you do in fact trigger a DNS rebinding attack.
Found another gem related to ...
Seth Mos
06:50 AM Bug #1661: Missing input validation in system_routes_edit.php
Will fix, same javascript helper from firewall rules and DNS server settings (gateway) would apply. Seth Mos
06:49 AM Bug #1662: DNS server gateway selection missing input validation
This same issue exists on the firewall rules (edit) page for selection of gateways.
I can fix the input validation...
Seth Mos
06:45 AM Bug #1676: dead IPv6 gateway causes kernel panics
the sbappendaddr_locked() is a function that I believe comes from our one shot dumps patch which is active for our 2.... Seth Mos
06:41 AM Bug #1706 (Resolved): "Bypass firewall rules for traffic on the same interface" is broken
Resolved by a commit a week ago when I ran into this myself on my lab setup. Seth Mos
06:40 AM Bug #1725: DHCPv6 non-common bitmask shows incorrect range
The function that calculates this is currently a string operated function instead of proper math. We need to have thi... Seth Mos

08/20/2011

10:22 PM pfSense Packages Todo #596: Varnish package suggestions for VCL syntax checking
follow this forum topic:
http://forum.pfsense.org/index.php/topic,38271.15.html
Marcello Silva Coutinho
10:11 PM pfSense Packages Todo #596: Varnish package suggestions for VCL syntax checking
> I work in a web shop design company and we use varnish as a reverse proxy for mostly sites builded using Drupal, Co... Marcello Silva Coutinho
04:49 PM pfSense Packages Bug #1805 (Closed): Captive portal - Portal page contents - View current page url is incorrect.
duplicate of #1810 Chris Buechler
07:52 AM pfSense Packages Bug #1805: Captive portal - Portal page contents - View current page url is incorrect.
to be more specific: select line 700 - 710 and replace by:... Davy Moedbeck
08:13 AM Feature #1810 (Resolved): Captive portal - Portal page contents - View current page url is incorrect.
In the /usr/local/www/services_captiveportal.php file the link to the uploaded html can not be accessed from a networ... Davy Moedbeck
06:05 AM Bug #1809 (Closed): Growl issue
I reported Bug #1769 that Growl stopped working and it got rejected.
So I tried some other stuff and updated the bug...
Richard van Herp
01:35 AM Bug #1808 (Resolved): link to scrub info is dead
fixed, thanks Chris Buechler
12:49 AM Bug #1808 (Resolved): link to scrub info is dead
There is a link in the "Disable Firewall Scrub" section of /system_advanced_firewall.php that points to http://www.op... David Burgess

08/19/2011

04:48 PM Feature #1807 (Resolved): Button needed for '-add a new one-' on the static IP configuration
Button needed for '-add a new one-' on the static IP configuration. Currently this is just a link and not entirely o... Bobby Weiter
10:59 AM Bug #1344: Replace prototype javascript code with jQuery
Nice javascript spinner http://fgnass.github.com/spin.js/ Scott Ullrich
10:40 AM Bug #1806: OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
Those lines are from the OpenVPN log
/sbin/ifconfig ovpns2 3.3.3.5 *netmask 3.3.3.6* mtu 1500 up
/usr/local/sbin/...
Rino Santilli
10:27 AM Bug #1806 (Resolved): OpenVPN Tunnel Network label configuration creates a wrong configuration file when using TAP device mode
When creating a *layer 2 tunnel using TAP devices in peer-to-peer shared key mode* you get a warning in the OpenVPN l... Rino Santilli
08:09 AM pfSense Packages Bug #1805 (Closed): Captive portal - Portal page contents - View current page url is incorrect.
In the http://pfsense.local/services_captiveportal.php file there is an incorrect part:
the lines 701 till 709 nee...
Davy Moedbeck
07:11 AM Bug #1804 (Rejected): DNS forwarder
Please post in the forum to rule out a configuration issue and to gather more information. If it's determined that a ... Jim Pingle
05:02 AM Bug #1804 (Rejected): DNS forwarder
I am on latest RC3 - I just discovered DNS forward is completely non-functional.
I am using 2 WAN (WAN+Opt2)- balanc...
Sangye Ngawang

08/18/2011

03:24 PM Bug #1279 (New): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
It ends up read only but it breaks many other things if you upgrade with packages. GUI doesn't load, many processes d... Jim Pingle
09:54 AM Bug #1802: Interface not showing in traffic shaper
Yeah, unfortunately that is the case, axe(4) doesn't support altq. Was worth double checking though. Jim Pingle
09:52 AM Bug #1802: Interface not showing in traffic shaper
From the dmesg output I get, the NIC is using the Axe driver. So, no ALTQ support.
axe0: <vendor 0x0b95 product 0x...
Jonathan Frank
09:48 AM Bug #1802 (Closed): Interface not showing in traffic shaper
They all call themselves ue0 now I see. If you look in dmesg there would be a line saying what driver it actually is.... Jim Pingle
09:44 AM Bug #1802: Interface not showing in traffic shaper
It use the "ue", which is not listed in the ALTQ supported driver list. Jonathan Frank
08:42 AM Bug #1802: Interface not showing in traffic shaper
What driver does the network card use? It would be something like aue0, etc. We can double check the driver to see if... Jim Pingle
08:34 AM Bug #1802: Interface not showing in traffic shaper
After doing more research, it seem like not all drivers/network cards are supporting ALTQ, so that must be the issue.... Jonathan Frank
08:21 AM Bug #1802 (Closed): Interface not showing in traffic shaper
Hi,
I recently installed pfSense 2.0 and am using an USB network card for testing purpose. I noticed that the inte...
Jonathan Frank

08/17/2011

09:49 PM Feature #828 (Resolved): Import for User Certificates
Chris Buechler
09:32 PM Feature #1801 (Rejected): Intermediate SSL certs box
Hello, it would be great to have a box in the certificate creation page to include intermediate certs.
forum threa...
Alexandre Paradis
05:14 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
See also #1336 Jim Pingle
04:09 PM Bug #1279 (Feedback): Filesystem on NanoBSD is left read/write at first bootup after package reinstallation
I put a fix that helps this.
Can you please try with latest snapshots?
Ermal Luçi
03:23 PM Feature #1787: Everyone with access to user manager has full admin rights
That's just a fact of how it works, not a bug. If you have access to the user manager you have full admin rights. Chris Buechler
03:08 PM Feature #1787: Everyone with access to user manager has full admin rights
There are only a few things I have changed. I think this problem is not dependend on the configuration. To test this ... Hans-Harald Webers
11:30 AM Feature #1787: Everyone with access to user manager has full admin rights
Can you describe how you have setup your firewall that gives you this issue? Ermal Luçi
11:15 AM Feature #1787 (Closed): Everyone with access to user manager has full admin rights
In some scenarios, it's undesirable for user manager users to have full admin capabilities, such as managing CP users... Hans-Harald Webers
03:18 PM Bug #1767: Unable to modify pppoe interface which is linked to a vlan via WebGUI
This is not expected to work on 2.0.
The way you should do is assign the vlan and then go and create a PPP type li...
Ermal Luçi
03:10 PM pfSense Packages Bug #1590: Snort Will Not Start
amd64
pfsense rc3
Snort
Notes:
Snort seems to be still down
alerts tab clear log seems to be broken
not availible
01:07 AM pfSense Packages Bug #1590: Snort Will Not Start
the only snag that I think *might* cause an issue is a future rules update since that flushes the rules folder. if l... Brett Ussher
12:44 AM pfSense Packages Bug #1590: Snort Will Not Start
Another update. Just tried rebooting the server -- no updates were done or any changes to configuration or addition/... Brett Ussher
11:38 AM Feature #1184: Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
That may be possible, it would have to be tested to make sure it really works though. I haven't looked at this since ... Jim Pingle
11:33 AM Feature #1184: Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
Since we know in advance what kinds of extensions we want, they should all be specified in the openssl.cnf, but in di... George Macon
10:35 AM Bug #1786 (Rejected): NanoBSD auto upgrade fails
Auto upgrade works fine, I just tested it on my alix again. You may have a problem specific to your system or CF. Ple... Jim Pingle
10:09 AM Bug #1786 (Rejected): NanoBSD auto upgrade fails
I installed
2.0-RC3 (i386) built on Tue Aug 16 20:24:26 EDT 2011
on a Netgate ALIX.2D3 / 2D13.
by dd the image...
Bill Weidman
 

Also available in: Atom