Project

General

Profile

Activity

From 04/05/2012 to 05/04/2012

05/04/2012

10:37 PM Bug #2411 (Closed): OpenVPN Automatic Rule Generation does not update TCP/UDP
The only place that makes a firewall rule for OpenVPN is in the wizard, and that's a one-time deal. There isn't an au... Jim Pingle
10:06 PM Bug #2411 (Closed): OpenVPN Automatic Rule Generation does not update TCP/UDP
When changing the protocol type of an OpenVPN connection, the automatic firewall rule generation does not update the ... Phil Jaenke
10:27 AM Bug #2398: tftpd and tftp-proxy (inetd?) dies after WAN periodic reset
Anyone can confirm this issue ? Xavier Romain
08:02 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Hosts file would work great I suspect, interface mock looks good too. Thanks! allen landsidel
05:42 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Hi. I probably could put together something for pfSense 2.0. Instead of implementing "real" CNAME support I'd like to... znerol znerol

05/03/2012

12:55 PM Feature #2410 (New): Support name based aliasing via CNAMEs or some other mechanism.
Resubmission of feature request 129 from 1.2.2
I would like to request that this feature reconsidered. Regardless ...
allen landsidel
12:42 PM Feature #129: CNAME support for dnsmasq
Cancel that, entering new ticket for this in 2.x. allen landsidel
11:50 AM Feature #129: CNAME support for dnsmasq
I would like to request that this ticket be reopened and the feature reconsidered. Regardless of what DJB may think,... allen landsidel
12:39 PM Bug #2409 (Resolved): ipfw - entryzerostats
I apologize for my english...
pfSense 2.0.1
When logging in CaptivePortal (auth Radius, Accounting Updates - Start/...
Vlad Arakin
10:49 AM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
aggh, stupid dumb idiot darren forgot to commit changes.
they're there now in commit:6b2d4b5a .
Darren Embry
07:01 AM Bug #2408 (Rejected): Wireless run driver crashes kernel
we don't create or control drivers, report the problems upstream to FreeBSD, after testing with a newer base stock Fr... Chris Buechler
06:52 AM Bug #2408 (Rejected): Wireless run driver crashes kernel
The run driver for a common 11n Ralink chipset casues severe system instability and kernel crashes. I have tested tha... Volker Kuhlmann

05/01/2012

01:20 AM Bug #2330 (Resolved): vouchers disappear when saving
fixed Chris Buechler
12:25 AM Bug #2406 (Resolved): No IP alias within the subnet of a CARP IP can be deleted
The input validation that triggers: ... Chris Buechler

04/30/2012

03:30 PM Bug #2402 (Feedback): rc.stop_packages synxtax error when executed
Applied in changeset commit:60dd7649d02e4a82f9d57953359bf312038f174a. Jim Pingle
03:07 PM Bug #2402: rc.stop_packages synxtax error when executed
Looks like that syntax:... Jim Pingle
01:03 PM Bug #2405 (Rejected): Lack of traffic shaping queue parent can take firewall down (pass no traffic)
Simple: create a Traffic Shaper queue but forget to choose a queue parent.
from: http://tech.akom.net/archives/59...
Scott Ullrich

04/28/2012

02:54 PM Bug #2402 (Resolved): rc.stop_packages synxtax error when executed
PHP appears to be choking on the new changed syntax in /etc/rc.stop_packages. It's giving a syntax error when execute... Jim Pingle

04/27/2012

11:02 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
I've done some testing and I think the patch to add the "match" action must be missing. Erik Fonnesbeck
02:52 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Found this issue and have following observation:
It is always the first match rule that gives the syntax error, no m...
Beat Siegenthaler
02:44 PM Bug #2401 (Resolved): Mounting read-only after mounting read-write can be very slow on NanoBSD
Mounting read-only after mounting read-write can be very slow on recent NanoBSD images on 2.1, based on FreeBSD 8.3
...
Jim Pingle
08:08 AM Feature #2400 (Closed): GUI options for WPA Enterprise with identity/password
WebCfg WiFi Interfaces allows one to connect to just about anything, but connecting to a AD network with identity/pas... Mattias Ingered
08:04 AM Feature #1825: Dynamic DNS client IPv6 support
Just noticed that https://dns.he.net/ supports IPv6 for DynDNS now. Update format is identical to IPv4, just send the... Jim Pingle
04:07 AM Bug #2399: Typo from IGMP proxy service in system log
I confirm, "ERRO" is in igmpproxy daemon. Xavier Romain

04/26/2012

06:33 PM Bug #2399: Typo from IGMP proxy service in system log
with the exception of "ERRO" which isn't in our code. Chris Buechler
06:30 PM Bug #2399 (Resolved): Typo from IGMP proxy service in system log
fixed, thanks Chris Buechler
03:02 PM Bug #2399 (Resolved): Typo from IGMP proxy service in system log
1) igmpproxy: *+ERRO+*: There must be at least 2 Vif's where one is upstream. (vifcount 16, upStreamVif -1)
2) php: ...
Xavier Romain
06:08 PM Bug #2330: vouchers disappear when saving
Has this issue been resolved? You can answer by marking it as such. Thanks. :-) Darren Embry
06:06 PM Bug #2253: Quality Graphs not generated after 'Reset RRD Data'
> Cool, the one-minute graph is refreshing
by which I don't mean scintillating or interesting. :-)
Darren Embry
06:05 PM Bug #2253 (Resolved): Quality Graphs not generated after 'Reset RRD Data'
Cool, the one-minute graph is refreshing. Marking as resolved.
Darren Embry
06:00 PM Bug #2253 (Assigned): Quality Graphs not generated after 'Reset RRD Data'
I've implemented the fix in commit:0637b0a9. Let's see if graphs get populated again... Darren Embry
02:42 PM Bug #2398: tftpd and tftp-proxy (inetd?) dies after WAN periodic reset
TFTP package info from config.xml :... Xavier Romain
02:33 PM Bug #2398 (Closed): tftpd and tftp-proxy (inetd?) dies after WAN periodic reset
When the WAN (PPPoE in my case) connection is restarted by custom periodic reset or when connection resetted by ISP, ... Xavier Romain
10:37 AM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
P.S. The "array" would literally be every single value from 0 to (2 ^ _n_) - 1 for some value of _n_ (at least that's... Darren Embry
10:34 AM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
The code displays and validates for the range already.
!http://i.imgur.com/L0yoJ.png!
Darren Embry

04/25/2012

06:55 PM Feature #2386: Bridge member that is not an assigned interface
I'm adding screenshots of a configuration I use that would benefit from this. For firewall rules, the only interface... Ryan J
03:17 PM Bug #2314: Members to bridge not added
This is probably due to the changes made in
commit:2064fa2eb4e2bca59f7c675969ee13752283d4c1
And in pfSense-tools...
Jim Pingle
02:59 AM pfSense Packages Bug #2396 (Closed): apache_mod_security_package missing mod_proxy.so (and perhaps others)
Chris Buechler
02:40 AM Todo #2397 (Rejected): Gateway Groups
Currently when defining a new Gateway group, the default trigger level is set to 'Member Down'.
It ideally should be...
Warren Baker
02:40 AM Todo #2397: Gateway Groups
Applied in changeset commit:8de4a8bc4d52755dce1fbf2fe80d45687397a429. Warren Baker
01:22 AM Todo #2397: Gateway Groups
Hrmm. I think http://doc.pfsense.org/index.php/Multi-WAN_2.0#Trigger_Level needs to be changed then to indicate this ... Warren Baker
01:03 AM Todo #2397: Gateway Groups
"member down" doesn't mean link down, or it never has historically up to and including recent 2.1, it means it's comp... Chris Buechler

04/24/2012

03:20 PM Todo #2397 (Feedback): Gateway Groups
Applied in changeset commit:1cc71979e44d7955084a0cdb50d7698239fac770. Warren Baker
03:12 PM Todo #2397: Gateway Groups
Make sure to touch gwlb.inc return_gateways_array(); it defaults to memberdown for any dynamic gateway. That needs to... Seth Mos
02:51 PM Todo #2397 (Rejected): Gateway Groups
Currently when defining a new Gateway group, the default trigger level is set to 'Member Down'.
It ideally should be...
Warren Baker
02:37 PM pfSense Packages Bug #2396: apache_mod_security_package missing mod_proxy.so (and perhaps others)
Sorry for the duplicate, I hadn't seen issue #2318. Robin McLeod
02:35 PM pfSense Packages Bug #2396 (Closed): apache_mod_security_package missing mod_proxy.so (and perhaps others)
Related to issue #1244
This was supposed to have been fixed but I'm still getting the following error on a fresh i...
Robin McLeod
10:03 AM Bug #2395 (Closed): Port forwards with destination "any" on OpenVPN interface creates invalid rules
Seems to be a duplicate of #1882 which should be fixed in RELENG_2_0 and master. Jim Pingle
07:52 AM Bug #2395 (Closed): Port forwards with destination "any" on OpenVPN interface creates invalid rules
These two lines: ... Chris Buechler

04/23/2012

07:40 PM Bug #2394 (Resolved): IPsec keepalive doesn't work with 0.0.0.0/0 local subnet
When you have a keepalive IP defined in a phase 2 that uses 0.0.0.0/0 (everything) as the local network, the logic th... Chris Buechler
06:49 PM Bug #2314: Members to bridge not added
I can also confirm this behaviour on:
2.1-DEVELOPMENT (amd64)
built on Sun Apr 22 05:15:07 EDT 2012
FreeBSD 8.3-...
Daniel Llewellyn
11:50 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Hy,
It's works for me ! Thank you very much !
Have you a idea of the date of integration in official image ?
Regards
Pierre BLONDEAU
12:59 AM Bug #2384: "Network interface mismatch" displayed for some valid configurations
Reverted the get_interface_list() part. I had forgotten that the interfaces named in $vfaces don't show for interfac... Erik Fonnesbeck
12:35 AM Bug #2210 (Resolved): "scrub in" usage needs evaluated
reverted back to original behavior without "in" after further evaluation and discussion with Ermal. Chris Buechler

04/22/2012

05:08 PM pfSense Packages Bug #1737 (Closed): ospfd - Route deleted after reboot and reload of the ospfd process
closing since openospfd is being ditched in favor of quagga Chris Buechler
04:41 PM Bug #2393 (Closed): PF not "forgetting" older IP addresses after a change on the WAN interface
duplicate Chris Buechler
11:02 AM Bug #2393 (Closed): PF not "forgetting" older IP addresses after a change on the WAN interface
Hi,
when starting pfsense and the cable modem from my provider together at the same time, the cable modem comes up...
Oliver Loch
12:11 PM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
DNS damn autocorrect. Oliver Loch
12:10 PM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
When I do what I wrote in the first post, the DNA lookup via dnsmasq stops working -> bug.
Oliver
Oliver Loch
11:45 AM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
Well not meaning to be pedantic about it, but the bug/pebkac question should be solved on the forum before opening a ... Jim Pingle
11:34 AM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
Yeah, you're right, but when i try to differ between a bug and pebcak, one should be able to ask the question.
I'm...
Oliver Loch
11:11 AM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
That's really a question for the forum, not the ticket system. Such discussion doesn't belong on here. Jim Pingle
11:08 AM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
Hi,
yes it's also breaking if I don't assign the traffic to a queue.
The default queue is used anyway, which is...
Oliver Loch
10:57 AM Bug #2392: Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
Does it break without the QoS parts on the rule?
QoS on floating rules should be using the "match" action, not "pa...
Jim Pingle
10:54 AM Bug #2392 (Closed): Adding outgoing, floating rule for DNS on the WAN interface breaks DNS lookups.
Hi,
when adding a floating rule that allows outgoing traffic on the wan interface from the wan address to any tcp/...
Oliver Loch
03:21 AM Todo #1940: Integrate rSyslogd
Another vote for rsyslog here too . We too would like to monitor remote deployments. Joe Black

04/21/2012

07:12 PM Bug #2391 (Rejected): Change of Descriptions of Firewall:Rules by XMLRPC Sync
this is by design for complex reasons. it has another ticket already Chris Buechler
06:52 PM Bug #2391 (Rejected): Change of Descriptions of Firewall:Rules by XMLRPC Sync
I created a pfSense cluster with 2 members, using CARP IPs and XMLRPC for configuration sync.
I noticed that XMLRP...
Dim Hatz
07:11 PM Bug #2390 (Closed): Change of Descriptions of Firewall:Rules by XMLRPC Sync
Chris Buechler
06:53 PM Bug #2390: Change of Descriptions of Firewall:Rules by XMLRPC Sync
posting error, please remove (replaced by #2391) Dim Hatz
06:51 PM Bug #2390 (Closed): Change of Descriptions of Firewall:Rules by XMLRPC Sync
QoS - Catch TOS 0x30 traffic Squid cache HIT Dim Hatz
03:08 PM Bug #2389: CP asks for a voucher code from MACs in the passthrough list
I just tried changing "set 0" to "set 1" for the MAC entries (rules 2-7) and it didn't fix things. Those MACs are sti... Dim Hatz

04/20/2012

03:40 AM Bug #2384 (Feedback): "Network interface mismatch" displayed for some valid configurations
Applied in changeset commit:fd863e5cebe67258ed48387d6471c4411701cf6b. Erik Fonnesbeck
02:47 AM Feature #2240 (Feedback): Find interface subnets and static routes without the routing table in outbound NAT rule generation for reflection
I can't change the status of "todo" type tickets for some reason, so I'm changing this one to "feature"
With these...
Erik Fonnesbeck
01:35 AM Bug #2253: Quality Graphs not generated after 'Reset RRD Data'
This needs to call setup_gateways_monitor() in after enable_rrd_graphing() to fix. Seth Mos
01:33 AM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
I'm fine with a text box, make sure the input validation is correct.
The math function the filled the drop down is p...
Seth Mos

04/19/2012

10:23 PM Feature #1965: Support Multiple IPsec Peers
The biggest challenge is getting both ends to switch over correctly, as the remote would have to change its IP too. F... Chris Buechler
01:05 PM Feature #1965: Support Multiple IPsec Peers
More importantly would be a feature to at least have a "secondary wan" (Or a Gateway Group?) to use if the primary go... Jim Pingle
10:03 PM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
as we discussed, I think it's fine as a text box, having a drop down with tens of thousands of values is nuts. will l... Chris Buechler
09:08 PM Feature #2356 (Feedback): Fill the "Track Interface" prefix drop down list asynchronously
Converting to a text field because I've determined that, no matter how implemented, a dropdown with 65,536 possible v... Darren Embry
06:43 PM Feature #2356 (Assigned): Fill the "Track Interface" prefix drop down list asynchronously
Something other than that simple print loop is causing the page loads to take so long.
65,536 print statements doesn...
Darren Embry
05:30 PM Bug #2389: CP asks for a voucher code from MACs in the passthrough list
Looking further into this issue, the output of "ipfw -deS show" under pfsense 2.0.1 is exactly the same as above and ... Dim Hatz
05:04 PM Bug #2389 (Resolved): CP asks for a voucher code from MACs in the passthrough list
Installed 2.1-DEVEL 17-Apr-2012 and simply moved my conf*.xml from 2.0.1
For testing I used a CP configuration with ...
Dim Hatz
03:12 PM Bug #2383 (Resolved): Firmware AutoUpdate preset url dropdown not showing on IPv6 only connection
Manifest should be OK now. The v6 server was missing a ServerAlias entry for updates.pfsense.com - confirmed they sho... Jim Pingle
02:55 PM Bug #2383: Firmware AutoUpdate preset url dropdown not showing on IPv6 only connection
v4 host contains
pfSense i386 stable updates http://updates.pfsense.org/_updaters
pfSense amd64 stable updates http...
Seth Mos
02:42 PM Bug #2278 (Feedback): IPv6 Carp vip both master on FreeBSD 8.3
The latest snapshot I ran off by hand seems to do the trick with the updated CARP patches.
http://iserv.nl/files/p...
Seth Mos
08:15 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Jim found a very descriptive similar issue on Open that appears to hit the exact same thing.
http://old.nabble.com/c...
Seth Mos
02:40 PM Bug #2384: "Network interface mismatch" displayed for some valid configurations
The code recommended in the forum post seems appropriate. I think we only use stf for IPv6 specifically.
Commit that.
Seth Mos
01:19 AM Bug #2384 (Resolved): "Network interface mismatch" displayed for some valid configurations
http://forum.pfsense.org/index.php/topic,48366.0.html
Should tap and the various IPv6 interfaces be added to the l...
Erik Fonnesbeck
02:23 PM Bug #2334 (Resolved): quality rrd graphs do not automatically refresh
Fixed in commit:3a83296f.
And the refresh time is actually 6 minutes, not 5.
Darren Embry
11:29 AM Bug #830 (Closed): Service provider information should be saved
that other issue is fixed, and this original one, it's way more trouble than it's worth. Chris Buechler
11:28 AM Bug #830: Service provider information should be saved
In latest pfSense snapshot, I'm not seeing this error that Chris reported:
> also I noted if you pick United State...
Darren Embry
07:55 AM Feature #2387: Add (SMTP email) submission (port 587) to Firewall Rules GUI
Wow, that was fast! 15 mins! :D Seb A
07:50 AM Feature #2387: Add (SMTP email) submission (port 587) to Firewall Rules GUI
Applied in changeset commit:76e91d3ffee70fc047c64b6c9360df1e8eeffb9a. Warren Baker
07:49 AM Feature #2387 (Feedback): Add (SMTP email) submission (port 587) to Firewall Rules GUI
SUBMISSION port added in commit:76e91d3ffee70fc047c64b6c9360df1e8eeffb9a - it will be available in the next 2.1 snaps... Warren Baker
07:33 AM Feature #2387 (Resolved): Add (SMTP email) submission (port 587) to Firewall Rules GUI
People using e-mail clients to connect to e-mail servers should be using port 587 (not 25). Sometimes this will be th... Seb A
05:51 AM Feature #2386 (Pull Request Review): Bridge member that is not an assigned interface
As suggested on #2385, a solution for bridge members showing up in unwanted places in the web GUI and the rule set wo... Erik Fonnesbeck
05:25 AM Feature #2385 (Closed): Option to hide bridges or bridge members from pf-related pages based on bridge sysctls
This should not be done in this way.
It should be possible to create bridges without assigned interfaces that is the...
Ermal Luçi
01:42 AM Feature #2385 (Closed): Option to hide bridges or bridge members from pf-related pages based on bridge sysctls
For configurations with bridges, it might be nice to have an option to hide bridges or bridge members from pf-related... Erik Fonnesbeck

04/18/2012

05:00 PM Bug #2370 (Feedback): syslog.conf requires IPv6 literal
Applied in changeset commit:25ed9cf8a4c1bd4155ee4e1881821b9e10501916. Jim Pingle
04:54 PM Bug #2370: syslog.conf requires IPv6 literal
I added a cheap fix, if we have an ipv6 forwarding IP for syslog, it restarts syslog at the end of the boot cycle, wh... Jim Pingle
04:43 PM Bug #2372 (Resolved): Add static routes for gif,6rd and 6to4 endpoints
Seth Mos
04:37 PM Bug #2372: Add static routes for gif,6rd and 6to4 endpoints
It Works For Me(TM)
Jim Pingle
05:59 AM Bug #2372: Add static routes for gif,6rd and 6to4 endpoints
Needs Jim to verify if it adds the right static routes, he has multi wan and multi tunnel. Seth Mos
04:10 PM Bug #2305 (Feedback): PBI db stored on var does not survive reboot
Jim Pingle
08:27 AM Bug #2305: PBI db stored on var does not survive reboot
Merged, thanks!
FYI- If you put something like "Fixes #2305" or "Ticket #2305" in the commit message, redmine will...
Jim Pingle
02:33 AM Bug #2305: PBI db stored on var does not survive reboot
Pull request submitted 18 Apr 2012 to do as JimP suggests. Now the PBI db survives reboot. This should resolve this b... Phillip Davis
12:47 PM Bug #2332 (Feedback): gateways always renamed to "dynamic". Implement proper IPv6 support
Upgrade code checked in that I tested by upgrading a 2.0 vm with 3 dynamic wans, it upgraded accordingly but might ne... Seth Mos
09:28 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
I have found the difference, it's the uptime of client. If I restart them all, IPv6 will not work on them. Pierre BLONDEAU
07:15 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
on the one where it works :
ip -6 neigh show
2001:xxx:yyy::1 dev eth0 lladdr 00:00:5e:xx:xx:xx router DELAY
on th...
Pierre BLONDEAU
07:05 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Can you check if the CARP vip address is in the NDP table of any of the other machines?
On linux http://tldp.org/HOW...
Seth Mos
06:07 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
I have this problem, but only on one of my carp ipv6 addresses and only a few machines (not all).
I thought it was f...
Pierre BLONDEAU
07:21 AM Bug #2383 (Feedback): Firmware AutoUpdate preset url dropdown not showing on IPv6 only connection
fetch returns a 404... Seth Mos
07:14 AM Bug #2383 (Resolved): Firmware AutoUpdate preset url dropdown not showing on IPv6 only connection
On a IPv6 only connection the Preset URL drop down on system_firmware_settings.php is not showing.
It is possible ...
Seth Mos
06:46 AM Feature #1834 (Feedback): Stateless autoconfig WAN type for IPv6
I've added the option SLAAC to the list, this hooks into the dhcp6 client to request information only.
But it does...
Seth Mos
05:57 AM Bug #2380 (Resolved): 2 IPv6 nameserver advertisements fail to configure resolv.conf
Fix checked in, confirmed working, populates /var/etc/nameservers_v6{$if} with multiple nameservers
Ran into broken ...
Seth Mos
12:37 AM pfSense Packages Bug #2285 (Resolved): swapstate_check.php is being run when the Squid cache is null
thanks for all your follow ups Chris Buechler
12:31 AM pfSense Packages Bug #2285: swapstate_check.php is being run when the Squid cache is null
This was resolved by pull request 224 on 14 March 2012. Phillip Davis
12:36 AM Bug #2301 (Resolved): Adding symlinks for conf files when PBI packages have names that are substrings of each other
Chris Buechler
12:33 AM Bug #2301: Adding symlinks for conf files when PBI packages have names that are substrings of each other
This was resolved by pull requests 65, 66 and 67 in March 2012. Phillip Davis
12:34 AM pfSense Packages Bug #2280 (Resolved): pfblocker date() and mktime() warnings from cron job
Chris Buechler
12:24 AM pfSense Packages Bug #2280: pfblocker date() and mktime() warnings from cron job
This was resolved by pull request 225 on 15 March 2012. Phillip Davis
12:34 AM pfSense Packages Bug #2283 (Resolved): pfblocker array handling when alias table is empty
Chris Buechler
12:27 AM pfSense Packages Bug #2283: pfblocker array handling when alias table is empty
This was resolved by pull request 225 on 15 Mar 2012 Phillip Davis

04/17/2012

11:16 PM Feature #1965: Support Multiple IPsec Peers
Another possible method...
https://trac.ipsec-tools.net/wiki/FailOver
Jim Pingle
10:32 PM Bug #1874: Captive Portal Login dies on empty input
The patch for this broke the ability to use empty passwords. I opened issue 2377 before I realized the changes were r... Michael Newton
10:19 PM Bug #2382 (Resolved): RADIUS attribute Service-Type should not be sent with accounting packets
According to RFC 2865, Service-Type "MAY be used in both Access-Request and Access-Accept packets". No mention is mad... Michael Newton
05:06 PM pfSense Packages Bug #2381 (Resolved): nrpe2 not restarting on save or service restart
When changing the config of nrpe2 and you click Save or restarting nrpe from the Services menu, nrpe is not restarted... Craig Gill
04:17 PM Bug #1827 (Resolved): rc.newwanipv6 needs work
Added seperate ticket for the double DNS server issue. Doesn't currently cause recursive configure. Marking resolved ... Seth Mos
04:12 PM Bug #1827: rc.newwanipv6 needs work
Seems to be working ok, as-is. We'll open seperate tickets when we encounter other issues.
It fires ok for the DHC...
Seth Mos
04:16 PM Bug #2284 (Resolved): rc.newwanip handle case when gifs config is null
doesn't throw a error for me anymore. Seth Mos
04:13 PM Feature #2320 (Resolved): Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
yeah seems fine to me Chris Buechler
03:58 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
I like it so far, it appears to work as intended for me. Consider resolved? Seth Mos
04:13 PM Feature #1663 (New): DHCPv6 relay
Seth Mos
04:10 PM Bug #2065 (Resolved): PHP Warning on Interface Creation (master/IPv6 branch)
Ran into this issue as well, added a is_array() check for the DHCPdv6 array. Seth Mos
03:56 PM Bug #2332: gateways always renamed to "dynamic". Implement proper IPv6 support
Ok, so I now name the dynamic gateways by their config type, Jim uncovered a few corner cases and I'll look into what... Seth Mos
02:48 PM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
The last good snapshot is from http://files.pfsense.org/jimp/ipv6/
I'm still running the snapshots from Nov 25th o...
Seth Mos
12:15 PM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
I have a similar problem on 2.1-DEVELOPMENT (i386) built on Tue Apr 10 21:11:54 EDT 2012.
13 IPv4 carp OK
3 IPv6...
Pierre BLONDEAU
11:39 AM Bug #2305: PBI db stored on var does not survive reboot
We do this for NanoBSD in /etc/rc:... Jim Pingle
10:27 AM Bug #2380 (Resolved): 2 IPv6 nameserver advertisements fail to configure resolv.conf
When we get 2 IPv6 DNS servers through rc.newwanipv6 we need to explode(" ", $ENV['new_domain_name_servers']) before ... Seth Mos
10:22 AM Bug #2370: syslog.conf requires IPv6 literal
The binary is correct now but for whatever reason at bootup it does not send logs over IPv6. If you save the syslog s... Jim Pingle
09:58 AM Feature #1834: Stateless autoconfig WAN type for IPv6
Further investigation:
We need to extend the DHCP6 settings on the interfaces.php with the following information m...
Seth Mos
06:32 AM Bug #2379 (Closed): When using squid as a proxy server Traphic graph does not show the LAN specific Ip addresses
When using squid as a proxy server Traffic graph does not show the LAN specific Ip addresses that
are passing throu...
saye saye
06:26 AM Bug #1738: Restore fails when username in backup is not matching
Besides It affects to version 2.0.1 also.
saye saye
06:24 AM Bug #1738: Restore fails when username in backup is not matching
I do not know why this big issue has such a low priority?
Some bugs prevent us from reliably doing things and trus...
saye saye
04:38 AM Bug #2378 (Resolved): Captive portal selects additional interfaces where it shouldn't
Hello all,
There's still an annoying bug in the captive portal of pfsense 2.1 Devel. It was already present in t...
Mathieu Déom

04/16/2012

08:07 PM Bug #2377: Captive portal fails on empty RADIUS password
Sorry, should be under category "Captive Portal" but I can't make that change now. Michael Newton
08:07 PM Bug #2377 (Closed): Captive portal fails on empty RADIUS password
An empty password is not sent to the RADIUS server for verification, it just produces an error. PHP code is checking ... Michael Newton
03:40 PM Bug #2370: syslog.conf requires IPv6 literal
Copied one of the resulting binaries to a VM and that does seem to have done the trick, I'm getting messages to my se... Jim Pingle
03:29 PM Bug #2370: syslog.conf requires IPv6 literal
I added a patch to the pfPort and rebuilt it on the snapshot servers, we'll see how it goes. Jim Pingle
02:01 PM Bug #2370: syslog.conf requires IPv6 literal
That may be the difference, as I don't remember it being pfPorts before. Somewhere along the way we may have switched... Jim Pingle
01:45 PM Bug #2370: syslog.conf requires IPv6 literal
It's not the configured IPv6 IP as one binary is working and the other one is not. But I noticed that I may have used... Cyrill B
11:09 AM Bug #2370: syslog.conf requires IPv6 literal
Yours is larger because the binary is not stripped. I inspected the source and found that the patch was applied even ... Jim Pingle
10:03 AM Feature #2117: 6RD support for ISPs like Swisscom
Add a Enable 6rd checkbox on the 6rd or DHCP4 settings to automatically configure 6rd from DHCP option 212.
http:/...
Seth Mos
05:48 AM Bug #2363 (Resolved): IPv6 default interface missing from firewall rule
Seth Mos
05:48 AM Bug #2372 (Feedback): Add static routes for gif,6rd and 6to4 endpoints
Added code in interfaces.inc that succesfully adds static routes for 6rd, 6to4 and gif endpoints. This should fix tun... Seth Mos

04/14/2012

07:16 PM pfSense Packages Bug #1244: apache_mod_security_package missing mod_proxy.so (and perhaps others)
Hello, any solution to this ?
thanks
Carlos Cesario
02:17 PM Bug #2370: syslog.conf requires IPv6 literal
No success with the current snapshot (Fri Apr 13 22:04:24 EDT 2012 / i386). Just tested it and it seems the syslogd b... Cyrill B
12:15 PM Bug #2370: syslog.conf requires IPv6 literal
Using a full install on the latest snapshot.
I thought perhaps the formatting was throwing it off, so I tried it w...
Jim Pingle
11:27 AM Bug #830: Service provider information should be saved
05:28:23 < databeestje_> cmb: eri-- : dsevil : the core dump with xml2array() in combination with php 5.3 was caused ... Darren Embry

04/13/2012

07:02 PM Bug #2370: syslog.conf requires IPv6 literal
No error here, it's working for me. I couldn't test it with an actual IPv6 capable syslog server but I captured the p... Cyrill B
03:10 PM Bug #2330: vouchers disappear when saving
Applied in changeset commit:ab9526e619a948da1b4ab5f5c094e7204ecb4e94. Ermal Luçi
02:21 PM Bug #830: Service provider information should be saved
the statement... Darren Embry
01:55 PM Bug #830: Service provider information should be saved
failing somewhere in this call:... Darren Embry
01:52 PM Bug #830: Service provider information should be saved
I don't even get the countries filled in. /getserviceproviders.php yields a 500. Apparently this core dump. I'll s... Darren Embry
12:49 PM Feature #1864: "Start" button for IPsec should be available for IP alias networks
Just pushed commit:59231855 which is about all I can do at this point.
I don't have a way of testing whether the s...
Darren Embry
12:24 PM Feature #1864: "Start" button for IPsec should be available for IP alias networks
In any of those cases it doesn't matter as long as there is a VIP somewhere inside of the IPsec subnet it will work.
...
Jim Pingle
12:21 PM Feature #1864: "Start" button for IPsec should be available for IP alias networks
what if an ipsec had 192.168.2.0/28 and the virtual ip's had 192.168.2.1/24?
what if an ipsec had 192.168.2.0/24 and...
Darren Embry
11:43 AM Feature #1864: "Start" button for IPsec should be available for IP alias networks
Would this be the proper link URL?
/diag_ipsec.php?act=connect&remoteid=192.168.44.0&source=192.168.2.1
And wha...
Darren Embry
10:41 AM Bug #2374: When entering values in firewall rules leading and trailing spaces are not deleted
Same thing happens for IPs also. Shouldn't be too hard to trim() before checking though. Jim Pingle
10:40 AM Bug #2374 (Resolved): When entering values in firewall rules leading and trailing spaces are not deleted
Hi,
as the topic says. If you enter a port number in the firewall rules page and you add a leading or trailing spa...
Oliver Loch
10:30 AM Bug #1662 (Feedback): DNS server gateway selection missing input validation
Last commit should nail it.
This only happened when the system has just 1 gateway.
Seth Mos

04/12/2012

07:08 PM Feature #2123 (Assigned): Backup RRD files using the xml dump and restore from RRD tools
implemented in commit:8bdb6879
I did a backup/restore config with RRD data and it seems to work just fine.
But ...
Darren Embry
06:21 PM Bug #2370: syslog.conf requires IPv6 literal
Included the patch from the PR in snapshots to test it, and it doesn't seem to work. Like the other guy who posted on... Jim Pingle
11:05 AM Bug #2370: syslog.conf requires IPv6 literal
IPv6 IP fixed up in commit:bd29bb7baa068cb92828461207ea35f74b6c2383
Looking at the patch in the FreeBSD PR to see ...
Jim Pingle
10:54 AM Bug #2370: syslog.conf requires IPv6 literal
Unfortunately it appears that syslogd can only send to IPv6 when using a hostname that resolves to a quad A. I have t... Jim Pingle
12:39 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I commented out the line:
/usr/sbin/ngctl shutdown $1
from the file
/usr/local/sbin/ppp-linkdown
as recom...
David Burgess
10:54 AM Bug #2373 (Resolved): There were error(s) loading the rules... (Floating rules bug)
The problem is fully described here -
http://forum.pfsense.org/index.php/topic,48022.0.html
In short - traffic sh...
Vladimir Suhhanov
05:45 AM Bug #2367: display negate rules in firewall_rules.php and evaluate when added
Normally the NEGATE rules will only trigger when the destination is set to "any".
If we change the foreach($config...
Seth Mos
05:38 AM Bug #2372 (Resolved): Add static routes for gif,6rd and 6to4 endpoints
We need to add static routes for 6rd,6to4 and IPv6 GIF endpoints that do 6in4 traffic. Otherwise these tunnels will n... Seth Mos
03:19 AM Bug #2371 (Resolved): Typo in shaper.inc
fixed, thanks!
Chris Buechler

04/11/2012

05:26 PM Bug #2371 (Resolved): Typo in shaper.inc
When I was fiddling with my traffic shaping, I found that my limits stopped loading. When I rebooted the firewall, I ... Tim Broberg
05:09 PM Bug #2370 (Resolved): syslog.conf requires IPv6 literal
If I remember correctly syslogd uses literal IPv6 addresses (e.g. in square brackets) in its configuration file (also... Cyrill B
12:51 PM Bug #2204: DHCP reports client lease, but DNS doesn't know about
This may be an error known for version 2.55 as used by pfSense. This bug has been fixed later and shall be resolved w... Thomas Schweikle
12:03 PM Feature #2239: Use Firewall Alias in Static Routing setup
Mostly done in RELENG_2_0 in commit:c9e04cd59054cf839af96cdf71cfc4cf58ccabaf and in master in commit:f898c1a98213ec6b... Jim Pingle
12:02 AM Bug #2132 (Closed): Multi-wan inbound connections might cease to function when rules with forced-gateway exist on the same interface
replaced by #2367 which better specifies actual issues here. Chris Buechler
12:02 AM Bug #2367 (New): display negate rules in firewall_rules.php and evaluate when added
the fact the negate policy routing rule isn't shown is bad as it has lead to unintended consequences (ends up passing... Chris Buechler

04/10/2012

11:05 PM Bug #2366: Error in User Manager - Privileges are not being enforced
An example of what happens. User is sgroat. Granted admin access. Auth is through LDAP. When user logs on, logon is s... Stephen Groat
09:32 PM Bug #2366 (Rejected): Error in User Manager - Privileges are not being enforced
not a legit bug report. the CLI behavior is expected, and assigning privileges as described works. no idea what a "20... Chris Buechler
09:29 PM Bug #2366 (Rejected): Error in User Manager - Privileges are not being enforced
After adding a user and granting that user all privileges (both by adding to admin group and manually selecting all p... Stephen Groat
08:56 AM Feature #2365 (Rejected): add color to rules
Duplicate of #130 Jim Pingle
08:51 AM Feature #2365 (Rejected): add color to rules
It would be nice to assign a color on each firewall rule.
This make more easy to indentify rule on the liste
Laurent Jouanno
07:59 AM Feature #1829 (New): CARP with IPv6 support
Running radvd in debug mode... Seth Mos
03:44 AM Bug #1676 (Resolved): dead IPv6 gateway causes kernel panics
Considering this resolved, seen no hangs in a month Seth Mos

04/09/2012

10:12 PM Bug #2364 (Resolved): PPPoE Server doesn't restart correctly
After editing, saving, and applying changes on a PPPoE server, mpd is left not running. It logs the following
<pre...
Chris Buechler
08:07 PM Bug #2324 (Closed): AES 256 doesn't work with glxsb
This has been opened as a FreeBSD PR. glxsb only supports AES128, anything higher breaks which it technically shouldn... Chris Buechler
11:42 AM Bug #2363: IPv6 default interface missing from firewall rule
Thanks. just applied your patch manually to filter.inc, and it fixed the problem. Johannes Ullrich
09:28 AM Bug #2363 (Feedback): IPv6 default interface missing from firewall rule
Apologies for the breakage, I removed a piece of logic and didn't have the oversight to see what it would do.
It's...
Seth Mos
07:44 AM Bug #2363 (Resolved): IPv6 default interface missing from firewall rule
This is a bug introduced by last yesterday's update. Worked fine before that. (2.1-DEVELOPMENT (amd64)
built on Sun...
Johannes Ullrich

04/08/2012

06:47 PM Bug #2362 (Resolved): Deleting last/only port forward doesn't remove from secondary
if you delete the last/only port forward from the primary, it doesn't get removed from the secondary on config sync. Chris Buechler
05:12 PM Feature #2361 (Resolved): router adv. daemon only allows for one subnet / limited options
The router adv. daemon configuration probably deserves its own page, instead of tugging it under dhcpv6.
For examp...
Johannes Ullrich
05:10 PM Bug #2360 (Resolved): OpenVPN "tap" mode not working
OpenVPN establishes the connection fine, but the bridge is not setup correctly. ARP replies are not answered via the ... Johannes Ullrich
05:08 PM Bug #2314: Members to bridge not added
confirming this issue on 2.1-DEVELOPMENT (amd64)
built on Sat Apr 7 22:44:34 EDT 2012
FreeBSD 8.3-RC2
(install...
Johannes Ullrich
05:06 PM Bug #2359 (Resolved): Typo: OpenVPN Configuration Page has two items "Server DHCP Bridge Start"
Line 1146 /usr/local/www/vpn_openvpn_server.php should say "Server DHCP Bridge End" (not "Start" as it currently say... Johannes Ullrich
04:48 PM Feature #2358 (Resolved): NAT64 support
example http://ecdysis.viagenie.ca/ Seth Mos
04:47 PM Feature #2357 (New): Support Dual Stack Lite
Tunnel IPv4 over Native IPv6.
Seth Mos
04:17 PM Feature #2356 (Resolved): Fill the "Track Interface" prefix drop down list asynchronously
When a interface is selected as a IPv6 "Track interface" type it will calculate all possible prefix posibilities in a... Seth Mos
04:10 PM Bug #2352 (Resolved): Only allow 1 6rd or 6to4 interface
Code checked in that triggers for me. It succesfully blocks a 2nd 6to4 or 6rd. Seth Mos
11:56 AM pfSense Packages Bug #2355 (Resolved): Tinydns logs won't parse records containing ":0" in the time stamp
Log record from tinydns containing :0 in the time stamp aren't showing up in the log
for example 2012-04-08 12:36:08...
Anton Bontes
04:52 AM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
PPPoE server also impacted. Chris Buechler
02:33 AM Feature #1826: PPPoE server IPv6 support
After talking with Jim about it we both agree that this is a huge undertaking.
You would need either static addres...
Seth Mos

04/07/2012

02:47 PM Feature #2347: Add routes into the routing table for delegated IPv6 prefixes.
ok, the dhcpleases6 triggers adding of routes and that works, I can still access the ipv6 internet from behind 3 rout... Seth Mos
04:22 AM Feature #2347 (Feedback): Add routes into the routing table for delegated IPv6 prefixes.
* Code checked in, Ermal added a command option to dhcpleases to trigger the external php script that adds routes for... Seth Mos
09:43 AM pfSense Packages Bug #2350: Freeradius2 does not start up
pfSense 2.1 needs .pbi packages for installation. At the moment there are no pbis for freeradius2. Alexander Wilke
06:03 AM pfSense Packages Bug #2353: squid-reverse installation failure

2.1-DEVELOPMENT (amd64)
built on Thu Apr 5 12:15:36 EDT 2012
FreeBSD 8.3-RC2
E. Pek
06:02 AM pfSense Packages Bug #2353 (Resolved): squid-reverse installation failure
Beginning package installation for squid-reverse .
Downloading package configuration file... done.
Saving updated p...
E. Pek
04:21 AM Bug #2352 (Resolved): Only allow 1 6rd or 6to4 interface
Currently it is possible to configure more then 1 interface for 6to4/6rd, however, both use the same stf0 adapter so ... Seth Mos

04/06/2012

07:57 PM pfSense Packages Bug #2351 (Resolved): Bandwidthd does not start up
2.1-DEVELOPMENT (amd64)
built on Thu Apr 5 12:15:36 EDT 2012
FreeBSD 8.3-RC2
Bandwidthd package 2.0.1.3
Band...
E. Pek
07:50 PM pfSense Packages Bug #2350 (Resolved): Freeradius2 does not start up
On
2.1-DEVELOPMENT (amd64)
built on Thu Apr 5 12:15:36 EDT 2012
FreeBSD 8.3-RC2
Installing Freeradius2 seems ...
E. Pek
07:41 PM Bug #2231 (Resolved): Dashboard: Traffic Graph: Unable to save settings
fixed in commit:ee965a5c
I feel kinda sorta like this patch took longer and involved much more changed lines of co...
Darren Embry
12:49 PM Bug #2231: Dashboard: Traffic Graph: Unable to save settings
the issue still exists in
2.1-DEVELOPMENT (i386) built on Thu Apr 5 11:32:38 EDT 2012 FreeBSD 8.3-RC2
with Firef...
Rob Logan
06:10 PM Bug #2349 (Resolved): vlan(4) needs altq adaption on FreeBSD 8.3++
The vlan(4) code has been put to use if_transmit interface on 8.3 and up of FreeBSD and a solution needs to be found ... Ermal Luçi
02:10 PM Bug #2289 (Resolved): Logic error in firewall rule interface selection for drop-down menu case
Darren Embry
02:10 PM Bug #2289: Logic error in firewall rule interface selection for drop-down menu case
fixed in commit:0416d9a0 Darren Embry
12:37 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)
I'm not sure where it is in the code offhand, but it's configured under System>Advanced and should be easy to track b... Chris Buechler
12:15 PM Bug #2330 (Feedback): vouchers disappear when saving
I've troubleshooted and confirmed that in this scenario, lines 229-244 here are being executed when you click "Save";... Darren Embry
11:04 AM Bug #2329 (Resolved): checkbox js problem on diag_logs_settings.php
Darren Embry
11:00 AM Bug #2329: checkbox js problem on diag_logs_settings.php
fixed in commit:f3d91215 Darren Embry
10:40 AM Bug #2348 (Resolved): rc.filter_synchronize is broken
The recent "Move CARP settings from pkg XML to a real PHP page" (commit:f97a5b0419d0350cc85b91d180238975c308ac07) bro... Cyrill B
09:56 AM Feature #2347: Add routes into the routing table for delegated IPv6 prefixes.
... Seth Mos
08:30 AM Feature #2347 (Resolved): Add routes into the routing table for delegated IPv6 prefixes.
Currently we support Prefix Delegation in the DCHPv6 server (ISC dhcpd 4.2.3). However, the dhcpd server does not add... Seth Mos
07:38 AM Bug #2333 (Resolved): CARP filter_synchronize PHP error, can not break
Seth Mos
07:01 AM Feature #2117 (Feedback): 6RD support for ISPs like Swisscom
More debugging revealed the following, SwissCom and ATT do not filter inbound IPv6 traffic for IPv4 space they do not... Seth Mos

04/05/2012

07:06 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
I've restored default 24/64 bits.
I had to modify the normal behavior on dropdown value changes between ipv6 and i...
Darren Embry
06:47 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
Okay, all my changesets are committed now. Gotta think hard about this one then. Darren Embry
06:07 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
it should still default that way on IPsec. For v4 addresses, show 1-32 and default to 24, and for v6, show 1-128 and ... Chris Buechler
06:03 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
In vpn_ipsec_phase2.php there is some existing client-side JavaScript logic that changes the selected value for the #... Darren Embry
05:33 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
fixed firewall_virtual_ip_edit.php (will commit soonish)
Darren Embry
05:04 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
added on system_routes_edit.php Darren Embry
03:38 PM Feature #2320: Javascript helper to toggle subnet mask length for IPv4/IPv6 during input
Add on system_routes_edit.php too (needs gateways defined to save)
on firewall_virtual_ip_edit.php it jumps to a len...
Seth Mos
06:31 PM Todo #2346 (Closed): do we need to change our require() calls to require_once()?
Not sure if this is the right venue to start a discussion, but...
My change to vlsb.inc as part of this changeset:...
Darren Embry
04:28 PM pfSense Packages Bug #2345 (Resolved): Varnish3 Install Fails on pfsense 2.1 Head
I've found a little bug in /etc/inc/pkg-utils.inc on pFsense 2.1 HEAD Releases with pbi support.
It's because of t...
Julian Sternberg
02:04 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)

Pull request for solution #1 here: https://github.com/bsdperimeter/pfsense/pull/74
Regarding #2 (auto-set the ...
Irving Popovetsky
07:38 AM Bug #2333: CARP filter_synchronize PHP error, can not break
This was a setup with 2 carp members that only shared a single ipv6 vip.
Config sync was on the LAN interface over...
Seth Mos
07:27 AM Bug #2338: outbound NAT rules rewrite themselves if active interface is deleted
the issue is it removes the interface from the outbound NAT rule and then assumes WAN when there is no interface. del... Chris Buechler
 

Also available in: Atom