Project

General

Profile

Activity

From 04/27/2012 to 05/26/2012

05/26/2012

04:59 PM Feature #1986: Find a way to list logged in IPsec xauth users
A bit better info now, the i386/amd64 bit was a red herring, it can crash on both. They key factor is that you have t... Jim Pingle
12:50 PM Feature #1986 (New): Find a way to list logged in IPsec xauth users
Ermal - running the show-users command with no users connected seems to crash racoon with no logged error, just a cor... Jim Pingle
01:10 PM Bug #2455: IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
I'll check it out as soon as a snapshot is live that incorporates the change... Ronald Antony
08:41 AM Bug #2455 (Feedback): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Should be ok now, could you test again ?
Thanks.
Pierre
Pierre POMES
08:19 AM Bug #2455 (Assigned): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Pierre POMES
10:44 AM Bug #1629: invalid state table entries after WAN IP change
Same deal, 2.0.1-RELEASE and this happens every so often, but not on every IP change. I can delete the 2 state entri... Akom Benevolent
03:20 AM pfSense Packages Bug #2457 (Resolved): Lightsquid 1.8.2 pkg v.2.32 logpath is wrong in lightsquid.cfg
In my pfSense router:
2.1-DEVELOPMENT (amd64)
built on Mon May 14 10:01:41 EDT 2012
FreeBSD 8.3-RELEASE-p1
...
Gabriel Paniagua Castro

05/25/2012

10:32 PM Feature #2456 (Resolved): Option to choose default tab in IPsec status Dashboard widget
There are two things that would massively increase the usefulness of that widget:
a) remember or allow to be confi...
Ronald Antony
07:59 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Thanks Jim, sorry I was a bit frustrated - not with you guys, with myself for not testing the build before running it... Mark Uhde
11:15 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
OK, iff there are PPTP issues, that would be a new/separate ticket. Try to confirm with others on the forum first. Th... Jim Pingle
10:52 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
At least I have no annoying error messages anymore and looks like shaping is working, but i need more time to test it... Vladimir Suhhanov
05:38 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
This bug appears fixed Ermal, BUT the changes seem to have broken the PPTP server *and* traffic shaping still doesn't... Mark Uhde
05:12 PM Bug #2440 (New): Wireless client nic set for DHCP does not start dhclient
Ok, this is definitely not fixed, I can't make sense of it. Deferring. Seth Mos
04:40 PM Feature #1986: Find a way to list logged in IPsec xauth users
Applied in changeset commit:6e0b68bfdea29b2943b6f104373f43cc56537bd8. Jim Pingle
04:33 PM Bug #2455 (Resolved): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
On the VPN:IPsec:Edit Phase 2 page there is the section Phase 2 proposal (SA/Key Exchange)
If under Protocol ESP i...
Ronald Antony
02:39 PM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Now that the traffic shaper itself is fixed, this is the bug I run up against, LOL. Thanks for your hard work Ermal! ... Mark Uhde
06:10 AM Bug #2454 (Feedback): Captive portal return wrong authentication URL
Applied in changeset commit:ac10faad42081ccfe48a37aa9814bc4684ffb701. Warren Baker
05:45 AM Bug #2454 (Resolved): Captive portal return wrong authentication URL
Since the last update "Built On: Sun May 13 02:42:10 EDT 2012" our captive portal doesn't work anymore.
The redir...
Mathieu Déom
12:07 AM Bug #2452 (Rejected): Reject type rules only allowed for TCP
not a bug, and this isn't a place to ask questions, please post to the forum or mailing list. Chris Buechler

05/24/2012

01:47 PM Feature #2453 (Resolved): [ER] allow renaming of network interfaces without enabling them
In Interfaces>(assign) you can create a new interface. The first one is WAN, the second is LAN, and then it starts wi... Ronald Antony
11:15 AM Bug #2012: 4th+ CARP member will not work with default automatic skew
Additional information:
http://forum.pfsense.org/index.php/topic,49745.0.html
Brian Scholer
11:11 AM Bug #2451: IPv6 rule: 'add network' becomes 'add single host'
block return in quick on $WIRED inet6 from any to 2a00:1450:: label "USER_RULE: TmpReject YouTube" Charles Orus
07:39 AM Bug #2451: IPv6 rule: 'add network' becomes 'add single host'
can you include what ends up in the /tmp/rules.debug? Seth Mos
07:13 AM Bug #2451 (Resolved): IPv6 rule: 'add network' becomes 'add single host'
I tried to add a reject rule for a range of IPv6 addresses:
"Reject TCP IPv6 to type network 2a00:1450:: CIDR ...
Charles Orus
09:50 AM Bug #2446: pfSense fails to queue UDP packets
Also note, as I wrote in the original post, that ICMP echo request packets are correctly assigned to the queue for sp... Torgeir Skjøtskift
09:46 AM Bug #2446: pfSense fails to queue UDP packets
PBX is an alias consisting of two public IP addresses belonging to a public IP subnet defined on the interface opt1 a... Torgeir Skjøtskift
07:20 AM Feature #1477: IGMPPROXY spamming the main systemlog
It's igmpproxy doing it. I get it too. As a workaround for myself I have just added igmpproxy to syslog and yes I agr... Charles Orus
07:17 AM Bug #2452 (Rejected): Reject type rules only allowed for TCP
I am sorry if I report intended behaviour. But I don't understand why rules of type reject only are allowed with TCP.... Charles Orus
02:25 AM Bug #2450: Unable to use a ports alias on a firewall rule.
Note that a existing rule on a different interface with the same alias actually works and is successfully expanded.
...
Seth Mos
02:24 AM Bug #2450 (Resolved): Unable to use a ports alias on a firewall rule.
The following input errors were detected:
mngtports is not a valid start destination port. It must be a port a...
Seth Mos
02:23 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
I performed more devd.conf changes, the media type is not recognized so I made it act on the _wlan subsystem now.
I ...
Seth Mos

05/23/2012

05:16 PM Feature #1986 (Feedback): Find a way to list logged in IPsec xauth users
This mostly works.
Just destination which is the system itself needs some more fixes, though its useable.
Ermal Luçi
05:01 PM Feature #1965: Support Multiple IPsec Peers
we currently already have rc.newipsecdns which does purging and reloading of tunnels. You can pass the function the o... Seth Mos
04:30 PM Bug #2447 (Feedback): Duplicated destination IPs in easy rule.
Applied in changeset commit:d01de40fa6d6a05e03351f0ccd83c64f82a4a2e5. Jim Pingle
03:31 PM Bug #1874: Captive Portal Login dies on empty input
I am sorry but you can use no authentication for empty passwords.
It works as its expected.
Ermal Luçi
03:30 PM Bug #2364 (Feedback): PPPoE Server doesn't restart correctly
Applied in changeset commit:062676f880878f788315991de861a71ccb86a478. Ermal Luçi
03:12 PM Bug #2446: pfSense fails to queue UDP packets
I wonder if you are not being bitten by the order of events happening.
If PBX has internal LAN addresses than this r...
Ermal Luçi
03:24 AM Bug #2446: pfSense fails to queue UDP packets
Sorry about that, her it is, properly unformatted:... Torgeir Skjøtskift
03:24 AM Bug #2446: pfSense fails to queue UDP packets
yes, the config for the rule in question is:
<rule>
<id/>
- <type>pass</type>
- <interface>opt1</inte...
Torgeir Skjøtskift
03:08 PM Bug #2423 (Closed): OpenNTPD seems to fail over time and can cause unintended clock skew.
We switched to ntp.org's ntpd so this is no longer of concern.
Jim Pingle
02:19 PM pfSense Packages Bug #2449 (Closed): Console "Filesystem is full" on NanoBSD version
I just updated a NanoBSD install and it's fine, /tmp is at 0% used. GUI login is OK.
I'd have to guess that squid ...
Jim Pingle
12:56 PM pfSense Packages Bug #2449: Console "Filesystem is full" on NanoBSD version
Apologies for not giving more information Jim. Let me tell you what ive done:
1. I am currently running a build fr...
Warren Bird
12:13 PM pfSense Packages Bug #2449 (Feedback): Console "Filesystem is full" on NanoBSD version
Not nearly enough information here - specifically we need to know at least what size nanobsd image you're running and... Jim Pingle
12:04 PM pfSense Packages Bug #2449 (Closed): Console "Filesystem is full" on NanoBSD version
Tried to upgrade the NanoBSD embedded version and now getting an error on console saying /tmp write failed: Filesyste... Warren Bird
02:15 PM Bug #2373 (Feedback): There were error(s) loading the rules... (Floating rules bug)
With new snapshots this should be resolved.
Issue was patch missing on 8.3 snaps
Ermal Luçi
01:30 PM Bug #2209 (Feedback): PPPoE MTU is not correctly set from values on interfaces.php
Applied in changeset commit:6805d2d25f75ccb6d9b1da3814ba2244b3e3107e. Ermal Luçi
12:30 PM Bug #2012: 4th+ CARP member will not work with default automatic skew
I am using it for HAProxy in a virtualized environment where we have two sites which are part of the same vCenter (we... Brian Scholer
11:45 AM Bug #2012: 4th+ CARP member will not work with default automatic skew
I am unsure why you'd want more than 3 members! Ermal Luçi
11:10 AM Bug #2445 (Feedback): Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
Applied in changeset commit:35b714597c8947376b350681c361b38e2569747a. Ermal Luçi
11:04 AM Bug #2445: Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
This is the upgrade code existing there.
Normally the section with s///g should have taken care of that.
Probably y...
Ermal Luçi
08:00 AM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Chapter 7.5 of the "HUAWEI UMTS Datacard Modem AT Command Interface Specification" lists the ^MODE messages to determ... Seth Mos

05/22/2012

09:39 PM pfSense Packages Bug #2448 (Rejected): Snort pfPort is breaking a full package builder run
may just be bad timing/false alarm... will open if I can reproduce it again. Jim Pingle
09:36 PM pfSense Packages Bug #2448 (Rejected): Snort pfPort is breaking a full package builder run
Packages are not being built on the nightly run properly because snort is causing the build to fail.
Observe:
<pr...
Jim Pingle
06:19 PM Bug #2446: pfSense fails to queue UDP packets
Can you detail the rule you say assigns the traffic to your desired queue? Ermal Luçi
10:13 AM Bug #2446: pfSense fails to queue UDP packets
Some extra details:
The floating rule assigning traffic A to the special queue should be set to "apply the action ...
Torgeir Skjøtskift
10:06 AM Bug #2446 (Closed): pfSense fails to queue UDP packets
Replication instructions:
Create CBQ or PRIQ shaper on WAN interface and create a default queue and another queue ...
Torgeir Skjøtskift
06:19 PM Bug #2447 (Resolved): Duplicated destination IPs in easy rule.
On snapshot released Tue May 22 08:05:51 EDT 2012
Easy rule adds duplicated "destination" IPs instead of "source"...
greg Bernard
05:10 AM Bug #2409: ipfw - entryzerostats
in version 2.1.0 (bild 18May2012) an error is confirmed. Vlad Arakin
04:18 AM Bug #2038 (Resolved): Some 3G WANs on 2.0.x do not come up on cold boot
This turned out to be a specific issue with ZTE modems and pin lock.
I've switched to a huawei modem and found a g...
Seth Mos
03:54 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Ermal - you can put the time to Coltex Chris Buechler
03:51 AM Bug #2278 (New): IPv6 Carp vip both master on FreeBSD 8.3
Chris Buechler
03:50 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Still hitting the double master issue in the Xs4all DC carp Seth Mos
02:39 AM Bug #2445: Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
$i = 0;
foreach($config['ipsec']['phase1'] as $phase1) {
if($phase1['interface'] == "vip131")
$config['ipsec'][...
Seth Mos
02:34 AM Bug #2445 (Resolved): Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
Because of the vip renaming per interface any IPsec VPN tunnels, or endpoints referencing a CARP vip are now broken a... Seth Mos

05/20/2012

09:11 PM Bug #2444: DynamicDNS doesn't update on WAN IP change
I am not 100% sure what you mean,
my DSL modem is connected to PF and DSL_WAN PF interface manages the PPPoE
connec...
themisa themisa
08:49 PM Bug #2444 (Feedback): DynamicDNS doesn't update on WAN IP change
is the public IP actually on the firewall, not the modem? That's usually the cause, since in such cases it's impossib... Chris Buechler
08:14 PM Bug #2444 (Closed): DynamicDNS doesn't update on WAN IP change
I have a DSL WAN whose IP changes often.
If i manually make a change to the DSL_WAN interface, DynamicDNC updates ...
themisa themisa
05:37 PM Feature #2443 (New): Automatically start 3G usb interfaces upon plugin
And cleanup the old LCK files from /var/spool/lock/LCK..cuaU0.0
devd should be able to do this for us. It says it ...
Seth Mos
05:10 PM Bug #2440 (Feedback): Wireless client nic set for DHCP does not start dhclient
Seth Mos
05:10 PM Bug #2440: Wireless client nic set for DHCP does not start dhclient
Hoping the devd changes resolve this, hoping for the best. Wireless is 802.11, not ethernet Seth Mos
12:15 PM Bug #2440 (New): Wireless client nic set for DHCP does not start dhclient
Helps in most cases but can still cause it to take too long making the dhcp client fail. Needs proper check_reload_st... Seth Mos
08:47 AM Bug #2440 (Resolved): Wireless client nic set for DHCP does not start dhclient
Seth Mos
07:44 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
The wireless interface reconfigure (Even with persist settings toggled) causes the interface to go down which then ne... Seth Mos
07:32 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
check_reload_status is firing off for vr1, but not for ural0_wlan0 eventhough the kernel is marking it as up.... Seth Mos
07:10 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
Error output only lists:... Seth Mos
10:34 AM Bug #2437 (Feedback): PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
Change just checked in, let me know how it goes. Seth Mos
08:46 AM Bug #2442 (Resolved): Duplicate gateways showing for down interfaces
Should be resolved properly, or atleast for now, pretty sure we'll run into something new at some point. When adding ... Seth Mos
07:55 AM Bug #2442 (Resolved): Duplicate gateways showing for down interfaces
When dynamic interfaces are down, these will show up even if there is already a manual entry for it too.
I have a ...
Seth Mos

05/19/2012

06:03 PM Bug #2441 (Closed): Setting up a new PPP interface (3g) hangs the webUI
Trying to add a new PPP interface on a system that has no such configuration results in the UI hanging.
A system t...
Seth Mos
06:01 PM Bug #2440 (Resolved): Wireless client nic set for DHCP does not start dhclient
I've configured a wireless nic as a client (infrastructure) on Opt3. It is set for DHCP but although the link comes u... Seth Mos
05:00 PM Feature #2148: Dynamic DNS Update Frequency
I've been able to reproduce it.
When i open WAN_DSL connection and apply changes it does force a DynDNS update.
H...
themisa themisa
04:38 PM Feature #2148: Dynamic DNS Update Frequency
I've yet to see it update on WAN IP change.
My WAN_DSL ip has changed, the dsl modem is connected directly to PF.
D...
themisa themisa
12:06 PM Feature #2439 (Resolved): XEN Para-virtualized Drivers Support
It's possible to include the xen DomU driver in pfsense 2.1 ? Jan Koester

05/18/2012

05:58 PM Feature #2438 (Duplicate): Inbound traffic shaping on unpredictable ADSL - the qosmon approach
I've been using pfSense for some time now, and it's wonderful. I've never been able to solve a problem, anyway: QoS o... Stefano Marinelli
05:12 PM Bug #2437 (Resolved): PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
1.
When "Radius Accounting" is enabled and trying to disconnect a connected client in the captive portal gui - the f...
Yuri Keren
03:36 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Also worth noting, though similar to the fact that it happens if you upgrade from 2.0.1 (noted above) is that loading... Mark Uhde

05/17/2012

08:13 PM Feature #2413 (Feedback): Allow IPv6 interface configuration from the menu
implemented in commit:c1361a9f
I've done basic testing but this needs a lot more testing than i'm able to do so i'...
Darren Embry
06:58 PM Bug #2426 (Resolved): Input validaton on interface gateway creation box needs to reject duplicate names
fixed in commit:283d78c6 Darren Embry
04:53 PM Bug #2426: Input validaton on interface gateway creation box needs to reject duplicate names
Darren, do you think you can prevent this duplicate name issue in the Ajax call?
Seth Mos
05:46 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
I just want to say, that amd64 architecture is affected also.
Have just tried it.
Vladimir Suhhanov
05:30 PM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
Seth, reassigning to you for you to test/close/assign back to me as needed. Darren Embry
05:29 PM Feature #2436 (Feedback): Enhance the restore section of the Backup/Restore section
Fixed in commit:428c289f and commit:8dcca9b5.
Reassigning to you so you can do further testing.
Please close if e...
Darren Embry
03:48 PM Feature #2436 (Resolved): Enhance the restore section of the Backup/Restore section
If restoring a partial config, we currently assume that only that section is uploaded. This is somewhat counterintuit... Seth Mos
04:37 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 90164860 bytes) in /usr/local/www/di... Seth Mos
03:21 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
I've also added "RRD Data" as a backup option in the dropdowns. Requires a little special handling in diag_backup.ph... Darren Embry
03:18 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
I've confirmed that -f is actually necessary anyway and added -f and log_error calls on failure to all the rrdtool re... Darren Embry
10:12 AM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
The quick test I just did, backup config.xml on i386, upgrade to amd64, then restore config.xml didn't fix the RRD fi... Seth Mos
04:17 PM Bug #2231 (Resolved): Dashboard: Traffic Graph: Unable to save settings
Darren Embry
03:38 PM Bug #2231: Dashboard: Traffic Graph: Unable to save settings
fixed in commit:dcb94db5 Darren Embry
12:25 AM pfSense Packages Bug #2435 (Resolved): SquidGuard: Deprecated function 'eregi' warnings
In squidguard_configurator.inc, there are a number of uses of @eregi()@ which is now deprecated in PHP 5.3. This cau... Moshe Katz

05/16/2012

09:48 AM Bug #2231 (New): Dashboard: Traffic Graph: Unable to save settings
Something still isn't 100% here - When you activate a drop-down to expand one of the closed graphs, it also activates... Jim Pingle

05/15/2012

11:40 AM Bug #2419 (Feedback): Possible Clickjacking Vunerability
Applied in changeset commit:c886fed9ba6a19fface58c918be5d7b111cca1f3. Jim Pingle
10:56 AM Bug #2419 (New): Possible Clickjacking Vunerability
Adding this bit in auth.inc broke the realtime traffic graphs:
@Header("X-Frame-Options: DENY");@
We either nee...
Jim Pingle

05/14/2012

12:23 PM Bug #2432: OpenVPN Client Specific Override ifconfig-push
Yeah you're right I started to fix it one way then changed my mind halfway, but didn't back out the original change. ... Jim Pingle
12:19 PM Bug #2432: OpenVPN Client Specific Override ifconfig-push
I understand your concern about upgrade users since i appreciate when upgrade runs smoothly.
I've looked at the ...
Davy Gigan
11:03 AM Bug #2432: OpenVPN Client Specific Override ifconfig-push
Not sure that making them server-specific will be feasible. At the very least, that will cause problems for upgrade u... Jim Pingle
10:48 AM Bug #2432 (Closed): OpenVPN Client Specific Override ifconfig-push
Hello,
I'm using a snapshot of pfSense 2.1 (20120419-1059). My pfSense installation holds two distinct VPN serve...
Davy Gigan
11:25 AM pfSense Packages Bug #2429: Hostname issues in OpenVPN Client Export
I replaced the two {{ with { in /usr/local/pkg/openvpn-client-export.inc on two lines in the file.
It works perfectly!
Thomas Svedin
10:20 AM pfSense Packages Bug #2429 (Feedback): Hostname issues in OpenVPN Client Export
Applied in changeset commit:0d639e580d2fc2651a4386a4248ac9e9b97d949d. Jim Pingle
05:14 AM pfSense Packages Bug #2429 (Resolved): Hostname issues in OpenVPN Client Export
When i select installation hostname when i export it looks like this in the configuration file:
remote host.{domain....
Thomas Svedin
09:44 AM Bug #2431 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
This has already been fixed in 2.0.2/2.1. Jim Pingle
06:02 AM Bug #2431 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Warning message displayed :... Xavier Romain
09:43 AM Bug #2430 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Duplicate Jim Pingle
06:36 AM Bug #2430: Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Sorry for duplicate submit. Xavier Romain
06:02 AM Bug #2430 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Warning message displayed :... Xavier Romain

05/11/2012

11:34 AM Bug #2428 (Resolved): Removing a limiter breaks any references to limiters after it
It appears that the limiters are referenced only by their index in the current list of limiters, instead of by name o... Jim Pingle
11:08 AM Bug #2427 (Feedback): /etc/rc.firmware_notify
Wrong file been referenced. Fix in commit:62fc138e7096d9b28026a86244baad56980494f4 Warren Baker
06:36 AM Bug #2427 (Resolved): /etc/rc.firmware_notify
When doing an upgrade the shell script /etc/rc.firmware is executed. As part of the upgrade process this script execu... Warren Baker
10:59 AM Bug #2422 (Resolved): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
fixed in commit:937cec84
Darren Embry
07:29 AM Bug #2426: Input validaton on interface gateway creation box needs to reject duplicate names
[Edit: the ticket system seems to have chopped off all my text except the last line...]
The real issue is making a d...
Jim Pingle
04:31 AM Bug #2426 (Resolved): Input validaton on interface gateway creation box needs to reject duplicate names
If two gateways are created with the same name/label, and one of them is set as default for an interface, it's not po... Max Frames

05/10/2012

02:15 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)
pull request attempt number 2: https://github.com/bsdperimeter/pfsense/pull/106 Irving Popovetsky
12:35 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)
Pull request to set the number of web configurator processes to 1 on ALIX systems with 256MB RAM or less
https://...
Irving Popovetsky
12:02 PM Bug #2359 (Resolved): Typo: OpenVPN Configuration Page has two items "Server DHCP Bridge Start"
Jim Pingle
11:49 AM Bug #2359: Typo: OpenVPN Configuration Page has two items "Server DHCP Bridge Start"
This is already fixed for 2.1: https://github.com/bsdperimeter/pfsense/pull/96 Irving Popovetsky
11:46 AM Bug #2328: Numerous non-CP logs ending up in CP logs
http://www.php.net/manual/en/function.openlog.php#98307 suggests an alternate way of specifying the facility that may... Jim Pingle
11:35 AM Bug #2328: Numerous non-CP logs ending up in CP logs
That looks like anything in PHP that uses log_error() is doing that.
However log_error is doing this:...
Jim Pingle
11:45 AM Bug #2419 (Feedback): Possible Clickjacking Vunerability
Scott Ullrich
09:57 AM Feature #2424 (Resolved): Allow masking of pass-thru MACs
ipfw supports masking MACs, sort of like a CIDR, and this could be a useful feature to allow, for example, all phones... Jim Pingle
09:34 AM Bug #2423 (Closed): OpenNTPD seems to fail over time and can cause unintended clock skew.
Over time, NTP eventually loses the ability to keep the clock in sync and sometimes will actually set the wrong time,... Jim Pingle
06:51 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Some error
Snap 2.1-DEVELOPMENT built on Wed May 9 21:13:38 EDT 2012 ...
Yan Triary
02:34 AM Feature #2418 (Closed): HttpOnly and Secure flag are not set in the HTTP response header
Awesome stuff. Warren Baker
02:27 AM Feature #2418: HttpOnly and Secure flag are not set in the HTTP response header
Wow.. Fantastic
Works as i had hoped
thank you for the quick fix
Laterpay Gmbh

05/09/2012

04:49 PM Bug #2422 (Assigned): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
Chris Buechler
04:38 PM Bug #2422 (Resolved): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
When trying to delete a previously added hostname from a Captive Portal zone - nothing happens. There is no error, bu... Yuri Keren
01:49 PM Feature #2418 (Feedback): HttpOnly and Secure flag are not set in the HTTP response header
Change committed in commit:49ddf9a10ff3379162d437622f664cfe924b4552 - let us know if you happy this please. Warren Baker
09:47 AM Feature #2418 (Closed): HttpOnly and Secure flag are not set in the HTTP response header
According to our tests for PCI-DSS certification by a professional security auditing team.
PfSense lacks the HttpO...
Laterpay Gmbh
01:34 PM Bug #2421 (Resolved): Filter log parser misinterprets some rare lines resulting in TCP:lo for the proto/flags
The following raw log entry:... Jim Pingle
12:08 PM Feature #2416: Hybrid NAT mode that is a mix of Auto+Manual
While we're doing this, may as well add a fourth outbound NAT option
* Off (all outbound NAT disabled)
Then someo...
Jim Pingle
09:52 AM Bug #2419 (Resolved): Possible Clickjacking Vunerability
According to our tests for PCI-DSS certification by a professional security auditing team.
PfSense has a possible ...
Laterpay Gmbh

05/08/2012

06:20 PM Bug #2415: Fallout from CARP vip interface names changes
I reverted that commit, had to adjust a few things since it didn't come out cleanly, but it should be out of RELENG_2... Jim Pingle
06:02 PM Bug #2415: Fallout from CARP vip interface names changes
this needs to be backed out entirely from RELENG_2_0, it wasn't supposed to be there. Chris Buechler
12:19 PM Bug #2415 (Resolved): Fallout from CARP vip interface names changes
Now that CARP VIP interfaces have been renamed, some issues have come up. They are now named, for example, wan_vip241... Jim Pingle
04:15 PM Feature #1986: Find a way to list logged in IPsec xauth users
Also this does not seem to work.
[2.1-DEVELOPMENT][root@pfsense-amd64.localdomain]/root(68): racoonctl show-sa isa...
Jim Pingle
09:17 AM Feature #1986 (New): Find a way to list logged in IPsec xauth users
Setting this back to New since we still need code in the GUI to read this yet. Jim Pingle
03:40 PM Bug #2030 (Feedback): Timezones need to update for Russia
Updated zoneinfo in commit:23b1fc4 and commit:8a4b381 Jim Pingle
03:29 PM Bug #2030 (New): Timezones need to update for Russia
We do keep a copy of zoneinfo.tgz in the git repo. Hasn't been touched since 2008, and our code pulls the zones from ... Jim Pingle
02:53 PM Feature #1917: DHCP server support for multiple domains in search list
Looks like someone also checked in a fix in commit:107e8acc that broke this again. It appears the fix on this ticket ... Jim Pingle
02:46 PM Bug #2348 (Resolved): rc.filter_synchronize is broken
This appears to be properly fixed and functional on current snapshots. Jim Pingle
02:38 PM Bug #2332: gateways always renamed to "dynamic". Implement proper IPv6 support
This seems mostly OK but I discovered one case the other day that is still problematic.
If you have a PPPoE interf...
Jim Pingle
02:34 PM Bug #2144 (Resolved): pfSense dyndns for Namecheap doesn't work with hostnames containing "."
I added a hostname with a . to one of my domains using Namecheap DNS and it updated fine, so this is fixed. Jim Pingle
02:21 PM Feature #2416 (Resolved): Hybrid NAT mode that is a mix of Auto+Manual
Often we suggest people switch to manual outbound NAT to make some very basic adjustments (such as a static port for ... Jim Pingle
12:50 PM Bug #2212 (Feedback): dhclient not stopped after changing interface from DHCP to other type
Applied in changeset commit:76ac460bd4a95a8600b05cecebd8d66f20feed70. Jim Pingle
12:20 PM Bug #2300: Static routes for IPsec peers missing when attached to IP Alias VIP
The problem seems to be, in part, that this checks for an interface name of carp or vip, but with IP alias it would a... Jim Pingle
11:55 AM Feature #2347 (Resolved): Add routes into the routing table for delegated IPv6 prefixes.
Closing this as the routing for PD nets is working great now, I plugged my ALIX in with a stock config and it pulled ... Jim Pingle
11:55 AM Bug #2414 (Resolved): IPv6 DHCP WAN, issue routing firewall-generated traffic
From Seth:
> There is a problem where pfSense itself can not reach the ipv6 internet [with a DHCPv6 WAN] leading to ...
Jim Pingle
11:40 AM Bug #1155: [patch] status_gateways.php doesn't show last check time
Applied in changeset commit:76db94c28d3cabe38f0b0921c21f80dfddcf93fc. Jim Pingle
11:32 AM Bug #1155 (Feedback): [patch] status_gateways.php doesn't show last check time
The code was already there to show that timestamp, so I fixed it up to show it (not quite how this patch was, better ... Jim Pingle
09:46 AM Feature #2413: Allow IPv6 interface configuration from the menu
That second bit about v4 already has a ticket - #2074 Jim Pingle
03:23 AM Feature #2413 (Resolved): Allow IPv6 interface configuration from the menu
The current console menu only allows for IPv4 interface configuration. We need to add support for IPv6 interface conf... Seth Mos
09:39 AM Feature #2242 (Resolved): Add status of lagg(4) member interfaces to Status > Interfaces
Jim Pingle
09:38 AM Bug #2127 (Resolved): Full Update Image Size is too large on 2.1
This has been OK for a while, the images are now under 90MB, which is down considerably from where they started. Jim Pingle
09:13 AM Bug #1112 (New): IPsec GUI/backend missing RADIUS support
Setting this back to New only since we still need to code up GUI support for this. The backend part should be OK. Jim Pingle
09:05 AM Bug #1427 (Resolved): Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
Jim Pingle
09:03 AM Bug #2314 (Resolved): Members to bridge not added
Tested newest snapshots and it works for me. Jim Pingle
08:58 AM Bug #2370 (Resolved): syslog.conf requires IPv6 literal
This has been working fine for me since that last commit. Logs are coming across IPv6 and are targeted at an IPv6 IP ... Jim Pingle
08:58 AM Bug #2402 (Resolved): rc.stop_packages synxtax error when executed
This has been working fine for me since my last fix. No errors, and it runs as expected during shutdown. Jim Pingle
08:53 AM Bug #2360 (Resolved): OpenVPN "tap" mode not working
Jim Pingle
07:35 AM Bug #2360: OpenVPN "tap" mode not working
appears to be working now. Thanks! Johannes Ullrich

05/07/2012

07:04 PM Bug #1667: L2TP server does not respond properly from a CARP VIP
This seems to be the classic UDP problem where the system will source the reply from the "closest" address rather tha... Jim Pingle
06:21 PM Bug #1892 (Resolved): Cannot static add static IPv6 route.
Chris Buechler
06:17 PM Feature #1184 (Resolved): Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
Chris Buechler
06:16 PM Feature #1258: dyndns - DNS Made Easy
make a merge request on github and this will make 2.1. Chris Buechler
06:14 PM Feature #1801: Intermediate SSL certs box
easily worked around by pasting in the cert chain for the CA cert. Chris Buechler
06:12 PM Bug #2336 (Resolved): PHP extensions missing in amd64 builds (at least)
Chris Buechler
06:03 PM Bug #1662 (Resolved): DNS server gateway selection missing input validation
Chris Buechler
03:52 PM Bug #2314: Members to bridge not added
Ah you're right, I didn't copy/paste or save from the test box to the repo like I usually do. Easy to miss in the fon... Jim Pingle
03:47 PM Bug #2314: Members to bridge not added
I think it works, with one small typo fixed:
pfSense_bridge_add_member($bridgeif, $realifl);
last later should ...
Johannes Ullrich
03:29 PM Bug #2314 (Feedback): Members to bridge not added
This should be fixed now by commit:e5e8840356e1f9ac2cd0e12f511599b5df84ace9 Jim Pingle
03:29 PM Bug #2360 (Feedback): OpenVPN "tap" mode not working
This may be fixed now with commit:e5e8840356e1f9ac2cd0e12f511599b5df84ace9 Jim Pingle

05/06/2012

08:10 AM Feature #2410 (Feedback): Support name based aliasing via CNAMEs or some other mechanism.
Applied in changeset commit:5a2a83493cdb3f647b4913f3b84ef864103148f5. Anonymous
04:35 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
https://github.com/bsdperimeter/pfsense/pull/99 znerol znerol
03:17 AM Bug #2412 (Resolved): inbound 6to4 traffic does not work in pf
With the WAN configured as 6to4 it is possible to browse the internet but it is not possible to initiate traffic from... Seth Mos

05/05/2012

05:51 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
The code seems to work fine for me. I added a host, gave it an alias, and it was populated in /etc/hosts as expected.... Jim Pingle
05:46 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Whitespace could use some cleanup, but usually patches will work so long as they are clean. It may have been that the... Jim Pingle
03:45 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Whitespace is handled somewhat inconsistently throughout the pfsense codebase. I tried hard to mimic the style of exi... znerol znerol
03:16 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Done. https://github.com/znerol/pfsense Branch: feature/master/dns-host-alias znerol znerol
12:40 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
mater is 2.1 (for now)
Interesting, I just did another gitsync to bring my VM up to the most current code and it s...
Jim Pingle
12:22 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Actually the patch is against the master branch on github. The last commit i see in my git log is https://github.com/... znerol znerol
11:30 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Was that patched against 2.0.1 or 2.1? It doesn't appear to apply to 2.1. Jim Pingle
07:35 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Patch attached. It applies on an installed pfsense 2.0.1 as well as onto git master.
In order to patch a running s...
znerol znerol

05/04/2012

10:37 PM Bug #2411 (Closed): OpenVPN Automatic Rule Generation does not update TCP/UDP
The only place that makes a firewall rule for OpenVPN is in the wizard, and that's a one-time deal. There isn't an au... Jim Pingle
10:06 PM Bug #2411 (Closed): OpenVPN Automatic Rule Generation does not update TCP/UDP
When changing the protocol type of an OpenVPN connection, the automatic firewall rule generation does not update the ... Phil Jaenke
10:27 AM Bug #2398: tftpd and tftp-proxy (inetd?) dies after WAN periodic reset
Anyone can confirm this issue ? Xavier Romain
08:02 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Hosts file would work great I suspect, interface mock looks good too. Thanks! allen landsidel
05:42 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Hi. I probably could put together something for pfSense 2.0. Instead of implementing "real" CNAME support I'd like to... znerol znerol

05/03/2012

12:55 PM Feature #2410 (New): Support name based aliasing via CNAMEs or some other mechanism.
Resubmission of feature request 129 from 1.2.2
I would like to request that this feature reconsidered. Regardless ...
allen landsidel
12:42 PM Feature #129: CNAME support for dnsmasq
Cancel that, entering new ticket for this in 2.x. allen landsidel
11:50 AM Feature #129: CNAME support for dnsmasq
I would like to request that this ticket be reopened and the feature reconsidered. Regardless of what DJB may think,... allen landsidel
12:39 PM Bug #2409 (Resolved): ipfw - entryzerostats
I apologize for my english...
pfSense 2.0.1
When logging in CaptivePortal (auth Radius, Accounting Updates - Start/...
Vlad Arakin
10:49 AM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
aggh, stupid dumb idiot darren forgot to commit changes.
they're there now in commit:6b2d4b5a .
Darren Embry
07:01 AM Bug #2408 (Rejected): Wireless run driver crashes kernel
we don't create or control drivers, report the problems upstream to FreeBSD, after testing with a newer base stock Fr... Chris Buechler
06:52 AM Bug #2408 (Rejected): Wireless run driver crashes kernel
The run driver for a common 11n Ralink chipset casues severe system instability and kernel crashes. I have tested tha... Volker Kuhlmann

05/01/2012

01:20 AM Bug #2330 (Resolved): vouchers disappear when saving
fixed Chris Buechler
12:25 AM Bug #2406 (Resolved): No IP alias within the subnet of a CARP IP can be deleted
The input validation that triggers: ... Chris Buechler

04/30/2012

03:30 PM Bug #2402 (Feedback): rc.stop_packages synxtax error when executed
Applied in changeset commit:60dd7649d02e4a82f9d57953359bf312038f174a. Jim Pingle
03:07 PM Bug #2402: rc.stop_packages synxtax error when executed
Looks like that syntax:... Jim Pingle
01:03 PM Bug #2405 (Rejected): Lack of traffic shaping queue parent can take firewall down (pass no traffic)
Simple: create a Traffic Shaper queue but forget to choose a queue parent.
from: http://tech.akom.net/archives/59...
Scott Ullrich

04/28/2012

02:54 PM Bug #2402 (Resolved): rc.stop_packages synxtax error when executed
PHP appears to be choking on the new changed syntax in /etc/rc.stop_packages. It's giving a syntax error when execute... Jim Pingle

04/27/2012

11:02 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
I've done some testing and I think the patch to add the "match" action must be missing. Erik Fonnesbeck
02:52 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Found this issue and have following observation:
It is always the first match rule that gives the syntax error, no m...
Beat Siegenthaler
02:44 PM Bug #2401 (Resolved): Mounting read-only after mounting read-write can be very slow on NanoBSD
Mounting read-only after mounting read-write can be very slow on recent NanoBSD images on 2.1, based on FreeBSD 8.3
...
Jim Pingle
08:08 AM Feature #2400 (Closed): GUI options for WPA Enterprise with identity/password
WebCfg WiFi Interfaces allows one to connect to just about anything, but connecting to a AD network with identity/pas... Mattias Ingered
08:04 AM Feature #1825: Dynamic DNS client IPv6 support
Just noticed that https://dns.he.net/ supports IPv6 for DynDNS now. Update format is identical to IPv4, just send the... Jim Pingle
04:07 AM Bug #2399: Typo from IGMP proxy service in system log
I confirm, "ERRO" is in igmpproxy daemon. Xavier Romain
 

Also available in: Atom