Project

General

Profile

Activity

From 05/05/2012 to 06/03/2012

06/03/2012

11:54 PM Revision 42db9f7b: Change style of this jquery call, the method that was used did not work properly.
Jim Pingle
10:00 PM Revision f2f721e2: Merge pull request #125 from marcelloc/patch-20
Include github changelog link to package version when $g['disablepackage... Jim Pingle
09:57 PM Revision 8b19e1b3: Include github changelog link to package version when $g['disablepackagehistory'] is not set, domtt titles, remove package info column and move package info to description tab
Marcello Silva Coutinho
09:54 PM Revision 16aa29e4: Merge pull request #124 from marcelloc/patch-19
Include github changelog link to package version when $g['disablepackage... Jim Pingle
09:52 PM Revision 36d82968: Include github changelog link to package version when $g['disablepackagehistory'] is not set , domtt titles, remove package info column and move package info to description tab
Marcello Silva Coutinho
07:48 PM Revision c5e53ee6: Unbreak php errors on login form
Jim Pingle
05:39 PM Revision 6a1ff0fe: Merge pull request #120 from ccesario/master
Change jQuery function: attr() to prop() Scott Ullrich
05:29 PM Revision 88dda5ed: Change jQuery function attr() to prop()
Carlos Cesario
02:11 PM Revision e3b14bbe: Include the gateway functions in rc.banner to prevent throwing a error
Seth Mos
11:32 AM Revision 6dbffeda: Add Gateway Group support to the IPsec interface drop down.
Edit of gateway group correctly reflects the new IP Address.
We need to make a blacklist for interface names in the g...
Seth Mos
11:00 AM Revision bf001dec: Allow for failover DynDNS hostnames.
replace get_real_interface() calls with get_failover_interface. If it isn't a group we call get_real_interface() anyh... Seth Mos
09:53 AM Bug #2469: Assign interfaces prompt is going WAN -> LAN -> OPT10
Could be related to the changes from Darren who is working on the console menu.
I'll assign to Darren since he is ...
Seth Mos

06/02/2012

10:12 PM Bug #2469 (Resolved): Assign interfaces prompt is going WAN -> LAN -> OPT10
After prompting for WAN, then LAN, a current snapshot then asks the user about "Optional 10 interface", instead of "O... Jim Pingle
10:10 PM Bug #2468 (Resolved): Interface does not exist warning during a network interface mismatch
Instead of reporting that a network interface mismatch happened, then proceeding to the assign interfaces prompt, cur... Jim Pingle
07:48 PM Revision 3e1eec58: Allow for selection of a gateway group as a interface to monitor
Redmine ticket #1965 Seth Mos
07:27 PM Revision ab1112da: The gateway groups array now knows about vips to be tied into that gateway group so we can tie the groups into services.
Redmine ticket #1965 Seth Mos
04:50 PM Revision 27a79802: Add a virtual IP field to a interface in the gateway groups edit screen.
Redmine ticket #1965 Seth Mos
02:25 PM Revision 4adf752c: Add statistic functions for the ZTE modems
Seth Mos
02:10 PM Revision 284101d3: Add support for the ZTE modem stats
Should be generic enough for other modems too. Seth Mos
01:18 PM Feature #2467 (Resolved): AJAX enhancement: only show gateways from same address families upon creation
When creating a new gateway group all gateways are showm, both ipv4 and ipv6. Add some ajax glue that will hide the o... Seth Mos
11:38 AM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Checked in support for the ZTE modem stats.
Should be easier to add new ones now too.
Do note that the ZTE modem will...
Seth Mos
11:18 AM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
With includes changes ZTE 3G dongle now comes up correctly.
Rewrote the stats utility to poke at the application p...
Seth Mos
10:59 AM Revision 75e89498: Move the SIM Pin and APN settings to the modem setup since we need these only once.
Seth Mos
10:37 AM Revision aa7504e0: Fix the PinReady command not found error.
Add a log command to show where you are dialing to. Seth Mos
10:12 AM Revision 5100c2de: Unbreak tree, add }
Seth Mos
09:49 AM Revision 117f8e6f: We are on FreeBSD 8.3 now
Seth Mos
08:38 AM Feature #2413 (New): Allow IPv6 interface configuration from the menu
OPtion 2 Set interface IP address.
When configuring interface WAN, as dhcp and dhcp6 I get the url http://dhcp/ disp...
Seth Mos
08:19 AM Revision 488595df: Escape the shell variable
Seth Mos

06/01/2012

09:34 PM Revision d27a8a3d: Merge pull request #119 from marcelloc/patch-15
include more features to interfaces_selection Scott Ullrich
09:34 PM Revision e14fbca4: include more features to interfaces_selection
<showips>
<showvirtualips>
<showlistenall>
<hideinterfaceregex>
New features will show only with these new options o...
Marcello Silva Coutinho
07:51 PM Revision 85a236e9: Fixes #2428. Reference limiters in rules by name to avoid issues. Also put upgrade code for existing configs. The same fix is necessary for 2.0.x though not sure how this should be committed there.
Ermal LUÇI
05:10 PM Bug #2278 (Feedback): IPv6 Carp vip both master on FreeBSD 8.3
Andrew working on this Chris Buechler
03:50 PM Bug #2428 (Feedback): Removing a limiter breaks any references to limiters after it
Applied in changeset commit:85a236e9dd5db87197ed6855995da609bf310bff. Ermal Luçi
02:50 PM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Any update on this issue? I haven't tried since it was reported broken.. Its a show stopper for me to update freebsd ... Cino .
12:25 PM Revision 730b6148: Include util.inc and IPv6.inc before config.lib.inc.
Several parts of the config upgrade relay on functions in these. Seth Mos
12:25 PM Revision 4a5fbf61: Make sure we include "util.inc" during config upgrade. We need is_ipaddrv4() during upgrade which is triggered from gwlb.inc
Seth Mos
12:16 PM Revision 06392e40: Fix function call name
Jim Pingle
10:23 AM Bug #1974: Captive Portal RADIUS accounting bytes wrong
Thanks, however the captive portal in the latest snapshots doesn't work, I believe there is a bug open about that: 24... Yuri Keren
06:10 AM Revision 31bdb9e5: Make sure to get the real interface in case we get passed a friendly interface
Redmine ticket #2463 Seth Mos
05:46 AM Revision e02caf4a: Actually save the IPprotocol variable into the config, otherwise it stil won't work.
People will likely need to edit and save their gateways now if they have double entries.
e.g. both manual and automat...
Seth Mos
02:59 AM Bug #2463: system_gateways_edit.php rejects correct configurations with dynamic or vpn interfaces
I just checked in more code, and the fix that allows you to actually save the ipprotocol value.
So edit and save t...
Seth Mos

05/31/2012

10:51 PM Revision 4473e33c: Merge pull request #116 from marcelloc/patch-14
Show current/updated repo package description instead of local/cached de... Scott Ullrich
10:47 PM Revision e83a9ff7: Show current/updated repo package description instead of local/cached description.
Marcello Silva Coutinho
09:50 PM Revision 53fde3ce: Merge pull request #115 from marcelloc/patch-13
new pkg_edit.php code with revised functions, no 0-99 loop on row_helper... Scott Ullrich
09:49 PM Revision 55c846c4: new pkg_edit.php code with revised functions, no 0-99 loop on row_helper, movable rows, tootip with domtt.
new field types button, info as well combinefileds working and colspan2 on nodisplaname option.
jquery code improved ...
Marcello Silva Coutinho
06:34 PM Revision d4d5f7b4: Rename old RRD quality database to the new GW name so we continue the graph.
Seth Mos
06:09 PM Bug #2458: Pfsense not registering DNS servers found by PPP
ThorstenK code, posted in forum, works flawlessly for me (I use IPv4 only) Vladimir Suhhanov
02:24 AM Bug #2458: Pfsense not registering DNS servers found by PPP
2.1-BETA0 (i386)
built on Wed May 30 19:35:31 EDT 2012
FreeBSD 8.3-RELEASE-p2
The script IS NOT working for me...
Vladimir Suhhanov
06:08 PM Revision 05a4cebd: Add a inet46 filter type on the firewall rules page. I have locked down a few of the most common limitations.
Still arguing if we should lock this down even further to aliases only.
Redmine ticket #2466
Seth Mos
05:41 PM Bug #2373 (Resolved): There were error(s) loading the rules... (Floating rules bug)
Ermal Luçi
05:37 PM Feature #2436: Enhance the restore section of the Backup/Restore section
If you want to make a new ticket for the memory issue I guess you can do that. :-) Darren Embry
05:36 PM Feature #2436: Enhance the restore section of the Backup/Restore section
Should I still look into the memory issue? My understanding is some of that XML parsing code we've been using has bi... Darren Embry
03:32 PM Feature #2436 (Resolved): Enhance the restore section of the Backup/Restore section
Seth Mos
03:28 PM Feature #2436: Enhance the restore section of the Backup/Restore section
I can confirm that restoring an entire RRD file from a i386 onto a amd64 works as expected. Great work!
I must have ...
Seth Mos
03:25 PM Feature #2436 (Assigned): Enhance the restore section of the Backup/Restore section
When trying to restore just the RRD section on a current 31-5-2012 snapshots I get the following error.... Seth Mos
05:02 PM Bug #2465 (Closed): Values reported by 'ipfw table 1 entrystats' reports a much higher value of transfered bytes, 6-7 times more
Duplicate of #1974 Ermal Luçi
11:03 AM Bug #2465 (Closed): Values reported by 'ipfw table 1 entrystats' reports a much higher value of transfered bytes, 6-7 times more
Thus the radius reported bytes-in / bytes-out values are incorrect which leads to incorrect traffic stats recorded fo... Yuri Keren
05:01 PM Bug #1974: Captive Portal RADIUS accounting bytes wrong
This has been fixed on latest snapshots.
Please try those.
Ermal Luçi
04:28 PM Revision c1d36d26: Finally give in and sprout a Internet Protocol drop down on the gateways edit screen.
With added validation and multiple detection parts to work when the value is not set yet.
Redmine ticket #2463
Seth Mos
03:20 PM Feature #2466 (Resolved): Allow single firewall rules to apply to both IPv4 and IPv6 simultaneously
I've added code that allows for setting a firewall rule to IPv4+IPv6
Limitations:
- only allows tcp/udp and icmp
...
Seth Mos
01:42 PM Bug #2463 (Feedback): system_gateways_edit.php rejects correct configurations with dynamic or vpn interfaces
Code checked in, I finally gave in and added a drop down for the internet protocol. There is just too much that could... Seth Mos
05:04 AM Bug #2463: system_gateways_edit.php rejects correct configurations with dynamic or vpn interfaces
Confirmed Seth Mos

05/30/2012

08:51 PM Revision 88165371: Do not allow empty passwords since this might cause problems for some authentication servers like ldap. Fixes #2326
Ermal LUÇI
08:50 PM Revision d427980c: Do not allow empty passwords since this might cause problems for some authentication servers like ldap. Fixes #2326
Ermal LUÇI
08:15 PM Revision a5011585: Rather than doig a string search do a proper matching of selected interfaces. Fixes #2378
Ermal LUÇI
08:14 PM Revision 17103056: Rather than doig a string search do a proper matching of selected interfaces. Fixes #2378
Ermal LUÇI
07:59 PM Revision 4dc04853: Clarify comment. Fixes #2270
Ermal LUÇI
07:58 PM Revision 03bbddae: Clarify comment. Fixes #2270
Ermal LUÇI
05:10 PM Revision 46ca7f3d: Fix copy/paste-o
Jim Pingle
05:10 PM Revision 18172eca: Fix copy/paste-o
Jim Pingle
04:59 PM Revision f56a60e7: Fix input validation and import test.
Jim Pingle
04:59 PM Revision 58168f4e: Fix input validation and import test.
Jim Pingle
04:59 PM Bug #2437 (Resolved): PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
Chris Buechler
03:14 PM Bug #2437: PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
Running bcmod() works now.
Thanks.
Yuri Keren
04:50 PM Bug #2326 (Feedback): Erroneous successful webGUI authentication with blank password and AD authentication backend
Applied in changeset commit:88165371efbc79fdc0194de26814eacca68d2a5c. Ermal Luçi
04:47 PM Revision bb39c283: Switch to ntpd from ports, add Services > NTP to select interfaces for binding. Respect old ntp settings in the process.
Conflicts:
etc/inc/system.inc
usr/local/www/fbegin.inc
Jim Pingle
04:44 PM Revision cf180ccc: Switch to ntpd from ports, add Services > NTP to select interfaces for binding. Respect old ntp settings in the process.
Jim Pingle
04:36 PM Bug #2446: pfSense fails to queue UDP packets
Please put the file on /tmp/rules.debug after anonymizing addresses here to verify what you say. Ermal Luçi
04:29 PM Bug #1931 (Closed): Status: Captive portal: Test Vouchers tab summary issue
Its by design that you will not be granted access to the portal if you submitted multiple vouchers and one of them is... Ermal Luçi
04:10 PM Bug #2378 (Feedback): Captive portal selects additional interfaces where it shouldn't
Applied in changeset commit:1710305617db80cde51a961077c3d18959c238d3. Ermal Luçi
04:00 PM Bug #2270 (Feedback): CP - default value of "Maximum concurrent connections per client IP address"
Applied in changeset commit:4dc04853f4588043bd39a6e304cbb33388937744. Ermal Luçi
03:03 PM Bug #1974: Captive Portal RADIUS accounting bytes wrong
Does not seem like the fix is working.
I am running pfSense 2.1 built on April 24 and the reported bytes-in and by...
Yuri Keren
02:17 PM Revision 829fd8c1: Don't display a "mobile" user without a username.
Jim Pingle
02:09 PM Revision 0551a524: Bump to 2.1-BETA0, let the fun begin.
Jim Pingle
02:08 PM Revision db2243e7: Bump to 2.0.2-RC2 after FreeBSD-SA-12:01 v1.1 and FreeBSD-SA-12:02
Jim Pingle
02:02 PM Revision 52ec5df8: Don't display a "mobile" user without a username.
Jim Pingle
01:39 PM Revision 13fc6fb9: Fix filename (Ticket #2459)
Jim Pingle
01:19 PM Revision fec04267: Disable autocomplete on all but the login form. Fixes #2459
Jim Pingle
12:56 PM Bug #2464: The traffic graph permission does not allow a user to load the graph.
Please use the forum to discuss such issues. If you need to start a new ticket for a new issue, that's fine, but this... Jim Pingle
12:48 PM Bug #2464: The traffic graph permission does not allow a user to load the graph.
Actually this is becoming more complicated than I hoped. I gave the user the permission you mentioned, and now graph.... Jeff Shaw
12:13 PM Bug #2464: The traffic graph permission does not allow a user to load the graph.
I would like to reopen this as a feature request, then, that Status: Traffic Graph implies Diagnostics: Interface Tra... Jeff Shaw
11:10 AM Bug #2464 (Closed): The traffic graph permission does not allow a user to load the graph.
You also need to assign the permission for graph.php (the actual graph), which is "Diagnostics: Interface Traffic pag... Jim Pingle
11:06 AM Bug #2464 (Closed): The traffic graph permission does not allow a user to load the graph.
I wanted a user to be allowed to view the traffic graph, so I created a user for her, and assigned her only the permi... Jeff Shaw
12:33 PM Revision 69b6c2b5: Skip a few pieces of code earlier. Perform file test on dhcpd logs.
Seth Mos
12:17 PM Revision 8dfb0c00: Add a few micro optimizations, bail out when the file does not exist.
Seth Mos
10:08 AM Feature #1361: DNSMasq, source interface and IPSec VPNs
Sorry a beginner at this. The patch file was the wrong way around. Hugh Blandford
10:03 AM Feature #1361: DNSMasq, source interface and IPSec VPNs
Sorry this update has taken so long. I have checked the file still applies and added the capability to handle the _m... Hugh Blandford
09:20 AM Bug #2459 (Feedback): Adding autocomplete=off in the webGUI forms
Applied in changeset commit:fec04267ea5303333839a45149e3cc2edc8250ff. Jim Pingle
07:50 AM Feature #1986: Find a way to list logged in IPsec xauth users
After the last commit, racoon no longer crashes, but now it's listing all tunnels in the 'show-users' output, but non... Jim Pingle
05:19 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
For my current configuration and settings issue is fixed. Vladimir Suhhanov

05/29/2012

09:46 PM Revision b0115477: Fix a couple misdirected form submissions
Jim Pingle
08:02 PM Bug #2459: Adding autocomplete=off in the webGUI forms
Apparently you can do this in jQuery by sticking one line in the file somewhere:... Jim Pingle
09:39 AM Bug #2459 (Resolved): Adding autocomplete=off in the webGUI forms
Doing a diff between config.xml versions, I noticed that my pfsense's password was stored in plaintext format in
<pr...
Dim Hatz
07:57 PM Feature #1241 (Resolved): Custom Dynamic DNS
thanks Chris Buechler
07:53 PM Feature #1241: Custom Dynamic DNS
This was merged, and can be closed. Matt Corallo
07:56 PM Feature #336: Option to create lagg under assign interfaces
*+1* This is important to me. Although, right now I am about to try and figure out how to do it manually since I need... Ted Lum
07:52 PM Bug #2463 (Resolved): system_gateways_edit.php rejects correct configurations with dynamic or vpn interfaces
eg. Gateway of dynamic makes the "Monitor IP" setting reject everything as having a "different Address Family"
Addit...
Matt Corallo
05:25 PM Revision 0350b814: Up the default for tables to 3000
Jim Pingle
05:24 PM Revision 4e2f4c18: Up the default for tables to 3000
Jim Pingle
03:11 PM Feature #2462 (Resolved): New 3G (PPP) provider
pfSense currently doesn't include the 3G provider I'm using. Here's the provider's data:
Country: Slovenia
Provid...
Jernej Simončič
02:52 PM Revision d57f6f21: Add a knob to tune the maximum number of tables that can be defined, the pf default of 1000 is too low for systems with >500 aliases.
Jim Pingle
02:51 PM Revision 84aea606: Add a knob to tune the maximum number of tables that can be defined, the pf default of 1000 is too low for systems with >500 aliases.
Conflicts:
etc/inc/filter.inc
Jim Pingle

05/28/2012

08:34 PM Bug #2458: Pfsense not registering DNS servers found by PPP
Using snap built on Mon May 28 10:16:21 EDT 2012 I cannot reproduce the log from using the ppp-linkup (Revision 70317... royden yates
04:14 PM Bug #2458: Pfsense not registering DNS servers found by PPP
My comment may be invalid as I have a different response from snap 2.1-DEVELOPMENT (i386)
built on Mon May 28 10:16...
royden yates
03:32 PM Bug #2458: Pfsense not registering DNS servers found by PPP
My modem is a Huawei LTE e398
The modified ppp-linkup script fails for me and results in the modem being unrespon...
royden yates
10:09 AM Bug #2458 (Feedback): Pfsense not registering DNS servers found by PPP
I committed a fixed ppp-linkup script. It looks like what used to be 2 different variables is now a single variable.
...
Seth Mos
09:33 AM Bug #2458 (Resolved): Pfsense not registering DNS servers found by PPP
2.1-DEVELOPMENT (i386) - built May 27 05:31:49 EDT 2012 on i386
If system general DNS settings are left empty no d...
royden yates
05:54 PM Revision 30b9b160: Add missing div tag
Jim Pingle
05:53 PM Revision 454ea767: Add missing div tag
Jim Pingle
03:35 PM Bug #2038 (New): Some 3G WANs on 2.0.x do not come up on cold boot
The ZTE MF190 I have here doesn't like pfSense at all. Although the /dev/cuaU0.2 responds to AT and is willing to wor... Seth Mos
03:02 PM Bug #2455 (Resolved): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Chris Buechler
10:18 AM Bug #2455: IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Yep, the GUI bug seems to be fixed.
I can even get an AH tunnel up (but so far no traffic goes through it, but if it...
Ronald Antony
12:55 PM Revision 703173f2: Update the link script to parse the arguments 6 and 7 differently.
Previously mpd supplied the dns1 string as $6 and the IP as $7. It is now a single argument $6.
Apparently this chang...
Seth Mos
10:14 AM Bug #2415: Fallout from CARP vip interface names changes
It's supposed to be selectable there for IP Alias type VIPs, so they can ride on top of the carp interface. (As a mea... Jim Pingle
10:12 AM Bug #2415 (Feedback): Fallout from CARP vip interface names changes
Changes have been committed but I still see Carp vips showing up in different places.
E.g. Add a carp vip on the v...
Seth Mos
08:48 AM Bug #2377: Captive portal fails on empty RADIUS password
Why do you need an empty pass? Ermal Luçi
08:30 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
Cold boot on the alix with 2.0.2 RC1 works. However, the moment the link goes down it enters the up down cycle simila... Seth Mos
08:28 AM Bug #2450 (Resolved): Unable to use a ports alias on a firewall rule.
Through some miracle the alias type was not set in the config.
[2] => Array
(
...
Seth Mos

05/27/2012

08:11 AM Revision 8fe0f2d3: Do not add link-local address on carp interface manually. It causes them to go double master.
Redmine ticket #2278 Seth Mos

05/26/2012

04:59 PM Feature #1986: Find a way to list logged in IPsec xauth users
A bit better info now, the i386/amd64 bit was a red herring, it can crash on both. They key factor is that you have t... Jim Pingle
12:50 PM Feature #1986 (New): Find a way to list logged in IPsec xauth users
Ermal - running the show-users command with no users connected seems to crash racoon with no logged error, just a cor... Jim Pingle
01:10 PM Bug #2455: IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
I'll check it out as soon as a snapshot is live that incorporates the change... Ronald Antony
08:41 AM Bug #2455 (Feedback): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Should be ok now, could you test again ?
Thanks.
Pierre
Pierre POMES
08:19 AM Bug #2455 (Assigned): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
Pierre POMES
12:43 PM Revision b20a5cdb: Ticket #2455: do not check encryption algo for AH protocol
Pierre POMES
10:44 AM Bug #1629: invalid state table entries after WAN IP change
Same deal, 2.0.1-RELEASE and this happens every so often, but not on every IP change. I can delete the 2 state entri... Akom Benevolent
08:06 AM Revision 730c6494: do a direct return, it will not find the PinReady command
Seth Mos
07:54 AM Revision f94eb529: Adjust the +CPIN? cmd so it works for huawei 3G sticks too
Seth Mos
07:28 AM Revision 2f8782fe: More validation for ejecting CDrom devices for 3G sticks, needs extra manufacturers. Less typos in variable names also helps a lot.
Seth Mos
07:24 AM Revision 17d656fc: Only attempt to remove stale LCK files if they exist.
Seth Mos
03:20 AM pfSense Packages Bug #2457 (Resolved): Lightsquid 1.8.2 pkg v.2.32 logpath is wrong in lightsquid.cfg
In my pfSense router:
2.1-DEVELOPMENT (amd64)
built on Mon May 14 10:01:41 EDT 2012
FreeBSD 8.3-RELEASE-p1
...
Gabriel Paniagua Castro

05/25/2012

10:32 PM Feature #2456 (Resolved): Option to choose default tab in IPsec status Dashboard widget
There are two things that would massively increase the usefulness of that widget:
a) remember or allow to be confi...
Ronald Antony
08:42 PM Revision 6e0b68bf: List logged-in IPsec xauth users and provide a mechanism to disconnect them. Implements #1986
Jim Pingle
08:36 PM Revision bf3da811: List logged-in IPsec xauth users and provide a mechanism to disconnect them. Implements #1986
Conflicts:
usr/local/www/diag_ipsec.php
Jim Pingle
08:01 PM Revision 2e9b8f61: Merge pull request #114 from marcelloc/patch-12
drag and drop function to reorder lists on pkg framework using jquery. Scott Ullrich
08:00 PM Revision 05a42cce: drag and drop function to reorder lists on pkg framework using jquery.
also new features like base64,description, tooltip custom texts.
tested with sorting features too.
related post on fo...
Marcello Silva Coutinho
07:59 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Thanks Jim, sorry I was a bit frustrated - not with you guys, with myself for not testing the build before running it... Mark Uhde
11:15 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
OK, iff there are PPTP issues, that would be a new/separate ticket. Try to confirm with others on the forum first. Th... Jim Pingle
10:52 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
At least I have no annoying error messages anymore and looks like shaping is working, but i need more time to test it... Vladimir Suhhanov
05:38 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
This bug appears fixed Ermal, BUT the changes seem to have broken the PPTP server *and* traffic shaping still doesn't... Mark Uhde
07:16 PM Revision 88810240: Allow for atleast 15 seconds before considering it a timeout, 60 would mean try once, since it would immediately hit the 60 second timeout
Seth Mos
07:16 PM Revision 13ea7caa: Make sure that we only perform validation if the GW name is filled as well as a IP address
Seth Mos
06:18 PM Revision 020ba5fe: Clarify the error message to something useful
Seth Mos
05:12 PM Bug #2440 (New): Wireless client nic set for DHCP does not start dhclient
Ok, this is definitely not fixed, I can't make sense of it. Deferring. Seth Mos
04:40 PM Feature #1986: Find a way to list logged in IPsec xauth users
Applied in changeset commit:6e0b68bfdea29b2943b6f104373f43cc56537bd8. Jim Pingle
04:33 PM Bug #2455 (Resolved): IPSec Phase 2 settings GUI doesn't take into account AH vs ESP selection properly
On the VPN:IPsec:Edit Phase 2 page there is the section Phase 2 proposal (SA/Key Exchange)
If under Protocol ESP i...
Ronald Antony
04:14 PM Revision 31f0ef21: Switch to a common function to determine anti-lockout ports, and fix a bug that was getting the ports wrong with custom https+redirect on.
Jim Pingle
04:13 PM Revision 55cfe813: Switch to a common function to determine anti-lockout ports, and fix a bug that was getting the ports wrong with custom https+redirect on.
Jim Pingle
02:39 PM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Now that the traffic shaper itself is fixed, this is the bug I run up against, LOL. Thanks for your hard work Ermal! ... Mark Uhde
10:11 AM Revision ac10faad: Ensure there is a '.' between hostname and domain. Partially fixes #2454
Warren Baker
06:10 AM Bug #2454 (Feedback): Captive portal return wrong authentication URL
Applied in changeset commit:ac10faad42081ccfe48a37aa9814bc4684ffb701. Warren Baker
05:45 AM Bug #2454 (Resolved): Captive portal return wrong authentication URL
Since the last update "Built On: Sun May 13 02:42:10 EDT 2012" our captive portal doesn't work anymore.
The redir...
Mathieu Déom
12:07 AM Bug #2452 (Rejected): Reject type rules only allowed for TCP
not a bug, and this isn't a place to ask questions, please post to the forum or mailing list. Chris Buechler

05/24/2012

10:23 PM Revision 1b9aff45: Merge pull request #113 from vizvayu/load_average
Added load average information to System Information widget Jim Pingle
09:56 PM Revision 2bae7ce3: Removed extra line :)
Cristian Feldman
09:52 PM Revision 25a46a3c: Added load average information to the System Information widget
Cristian Feldman
08:37 PM Revision 29c70782: Don't resolve on ipsec_get_phase1_dst() results, because ipsec_get_phase1_dst() already does that before returning output.
Conflicts:
etc/inc/ipsec.inc
Jim Pingle
08:36 PM Revision fd97f40c: Test for empty here, rather than !, so a blank value (as from mobile clients) doesn't fall to the other tests.
Jim Pingle
08:35 PM Revision a55be495: Don't do resolve_retry on ipsec_get_phase1_dst() results, because ipsec_get_phase1_dst() already does that before returning output.
Jim Pingle
08:33 PM Revision a6222c03: Test for empty here, rather than !, so a blank value (as from mobile clients) doesn't fall to the other tests.
Jim Pingle
01:47 PM Feature #2453 (Resolved): [ER] allow renaming of network interfaces without enabling them
In Interfaces>(assign) you can create a new interface. The first one is WAN, the second is LAN, and then it starts wi... Ronald Antony
11:15 AM Bug #2012: 4th+ CARP member will not work with default automatic skew
Additional information:
http://forum.pfsense.org/index.php/topic,49745.0.html
Brian Scholer
11:11 AM Bug #2451: IPv6 rule: 'add network' becomes 'add single host'
block return in quick on $WIRED inet6 from any to 2a00:1450:: label "USER_RULE: TmpReject YouTube" Charles Orus
07:39 AM Bug #2451: IPv6 rule: 'add network' becomes 'add single host'
can you include what ends up in the /tmp/rules.debug? Seth Mos
07:13 AM Bug #2451 (Resolved): IPv6 rule: 'add network' becomes 'add single host'
I tried to add a reject rule for a range of IPv6 addresses:
"Reject TCP IPv6 to type network 2a00:1450:: CIDR ...
Charles Orus
09:50 AM Bug #2446: pfSense fails to queue UDP packets
Also note, as I wrote in the original post, that ICMP echo request packets are correctly assigned to the queue for sp... Torgeir Skjøtskift
09:46 AM Bug #2446: pfSense fails to queue UDP packets
PBX is an alias consisting of two public IP addresses belonging to a public IP subnet defined on the interface opt1 a... Torgeir Skjøtskift
07:29 AM Revision 310ce280: Merge pull request #2 from TheBlueMatt/master
Custom Dynamic DNS Ermal LUÇI
07:20 AM Feature #1477: IGMPPROXY spamming the main systemlog
It's igmpproxy doing it. I get it too. As a workaround for myself I have just added igmpproxy to syslog and yes I agr... Charles Orus
07:17 AM Bug #2452 (Rejected): Reject type rules only allowed for TCP
I am sorry if I report intended behaviour. But I don't understand why rules of type reject only are allowed with TCP.... Charles Orus
02:25 AM Bug #2450: Unable to use a ports alias on a firewall rule.
Note that a existing rule on a different interface with the same alias actually works and is successfully expanded.
...
Seth Mos
02:24 AM Bug #2450 (Resolved): Unable to use a ports alias on a firewall rule.
The following input errors were detected:
mngtports is not a valid start destination port. It must be a port a...
Seth Mos
02:23 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
I performed more devd.conf changes, the media type is not recognized so I made it act on the _wlan subsystem now.
I ...
Seth Mos

05/23/2012

11:01 PM Revision e820da2a: Fix reference updating for when more than one carp vip exists. Skip the upgrade code if no carp vip defined. Ticket #2445
Erik Fonnesbeck
10:16 PM Revision 79f4bb0b: Disable logging for now since it will spam every 60secs * #users * #zones
Ermal LUÇI
10:14 PM Revision 90d4bccd: Disable logging for now since it will spam every 60secs * #users
Ermal LUÇI
09:49 PM Revision 879f7db7: Add missing declaration for global variable $g where it is used.
Erik Fonnesbeck
09:11 PM Revision 12766374: Fix name of the config section for virtual IPs in upgrade code. Ticket #2445
Erik Fonnesbeck
09:11 PM Revision d39a2fc6: Check the surrounding characters to not allow partial matches. Ticket #2445
Erik Fonnesbeck
08:35 PM Revision fe47f1f2: Revert "Rather do a fix by going through vips in reverse order"
This reverts commit d996dfeab2ec40cf3fb44b51811333b40ed5073f. Erik Fonnesbeck
08:26 PM Revision d01de40f: Fix easyrule duplicate destination for pass - Fixes #2447
Jim Pingle
07:48 PM Revision db461915: Don't skip "lan" as a possible WAN for shaper, since someone could have renamed/repurposed it. Someone may shoot themselves in the foot if they pick it accidentally, but otherwise some valid configs may be prevented accidentally.
Jim Pingle
07:47 PM Revision bd4c21fe: Don't skip "lan" as a possible WAN for shaper, since someone could have renamed/repurposed it. Someone may shoot themselves in the foot if they pick it accidentally, but otherwise some valid configs may be prevented accidentally.
Jim Pingle
07:26 PM Revision c714a1af: Fixes #2364. On busy pppoe servers it might take some time before mpd exits. Check for this before trying to restart
Ermal LUÇI
07:25 PM Revision 062676f8: Fixes #2364. On busy pppoe servers it might take some time before mpd exits. Check for this before trying to restart
Ermal LUÇI
06:56 PM Revision fbda07b9: Do this only for carp type vips
Ermal LUÇI
06:55 PM Revision d996dfea: Rather do a fix by going through vips in reverse order
Ermal LUÇI
06:54 PM Revision 909b0a91: Reflect naming changes, work around broken media type for wireless
Seth Mos
06:49 PM Revision e27d337d: Since this is an interface to avoid issues arising from vip1 and vip11 existing and replacing vip1 will replace even vip11, put on the regex <(starting close tag).
Ermal LUÇI
06:25 PM Revision b45d6db6: Round off the values.
Seth Mos
06:08 PM Revision 5e13bc84: Convert the Bytes per Second into kilobits per second like the status page says
Seth Mos
05:35 PM Revision 6805d2d2: Fixes #2209. Obey the mtu value set on the interfaces.php page. Though this value will be overwritten if there is a configuration under PPP settings tab. Maybe a good idea is to set MRU at the same value if not set?
Ermal LUÇI
05:33 PM Revision e39b6feb: Fixes #2209. Obey the mtu value set on the interfaces.php page. Though this value will be overwritten if there is a configuration under PPP settings tab. Maybe a good idea is to set MRU at the same value if not set?
Ermal LUÇI
05:16 PM Feature #1986 (Feedback): Find a way to list logged in IPsec xauth users
This mostly works.
Just destination which is the system itself needs some more fixes, though its useable.
Ermal Luçi
05:01 PM Feature #1965: Support Multiple IPsec Peers
we currently already have rc.newipsecdns which does purging and reloading of tunnels. You can pass the function the o... Seth Mos
04:36 PM Revision 323954b1: Unset the IP protocol tag while processing this array. This prevents a log message
Seth Mos
04:30 PM Bug #2447 (Feedback): Duplicated destination IPs in easy rule.
Applied in changeset commit:d01de40fa6d6a05e03351f0ccd83c64f82a4a2e5. Jim Pingle
04:00 PM Revision e313da37: Be a bit smarter about the stats interface for the huawei cards. Some of the K series have the stats on 0.2, the E series on 0.3
Some of the older E series only have 0.2 too. The new K3770 I got today is too new. Seth Mos
03:35 PM Revision b22fc825: Move vip upgrade code to be later, since it was backed out of 2.0.x it no longer needs to be so early, and otherwise there can be some breakage/fallout. Ticket #2445
Jim Pingle
03:31 PM Bug #1874: Captive Portal Login dies on empty input
I am sorry but you can use no authentication for empty passwords.
It works as its expected.
Ermal Luçi
03:30 PM Bug #2364 (Feedback): PPPoE Server doesn't restart correctly
Applied in changeset commit:062676f880878f788315991de861a71ccb86a478. Ermal Luçi
03:29 PM Revision 617244c7: Ooops use correct name for vips
Ermal LUÇI
03:14 PM Revision d23e157a: Add more functions and expand the 3G status interfaces screen.
List the SIM state, service, speeds and mode Seth Mos
03:12 PM Revision 35b71459: Oops this should be sed and not sh. Fixes #2445
Ermal LUÇI
03:12 PM Bug #2446: pfSense fails to queue UDP packets
I wonder if you are not being bitten by the order of events happening.
If PBX has internal LAN addresses than this r...
Ermal Luçi
03:24 AM Bug #2446: pfSense fails to queue UDP packets
Sorry about that, her it is, properly unformatted:... Torgeir Skjøtskift
03:24 AM Bug #2446: pfSense fails to queue UDP packets
yes, the config for the rule in question is:
<rule>
<id/>
- <type>pass</type>
- <interface>opt1</inte...
Torgeir Skjøtskift
03:08 PM Bug #2423 (Closed): OpenNTPD seems to fail over time and can cause unintended clock skew.
We switched to ntp.org's ntpd so this is no longer of concern.
Jim Pingle
02:24 PM Revision 7e631290: clean up old lock files for modem ports if a stale is left behind
Seth Mos
02:19 PM pfSense Packages Bug #2449 (Closed): Console "Filesystem is full" on NanoBSD version
I just updated a NanoBSD install and it's fine, /tmp is at 0% used. GUI login is OK.
I'd have to guess that squid ...
Jim Pingle
12:56 PM pfSense Packages Bug #2449: Console "Filesystem is full" on NanoBSD version
Apologies for not giving more information Jim. Let me tell you what ive done:
1. I am currently running a build fr...
Warren Bird
12:13 PM pfSense Packages Bug #2449 (Feedback): Console "Filesystem is full" on NanoBSD version
Not nearly enough information here - specifically we need to know at least what size nanobsd image you're running and... Jim Pingle
12:04 PM pfSense Packages Bug #2449 (Closed): Console "Filesystem is full" on NanoBSD version
Tried to upgrade the NanoBSD embedded version and now getting an error on console saying /tmp write failed: Filesyste... Warren Bird
02:15 PM Bug #2373 (Feedback): There were error(s) loading the rules... (Floating rules bug)
With new snapshots this should be resolved.
Issue was patch missing on 8.3 snaps
Ermal Luçi
01:30 PM Bug #2209 (Feedback): PPPoE MTU is not correctly set from values on interfaces.php
Applied in changeset commit:6805d2d25f75ccb6d9b1da3814ba2244b3e3107e. Ermal Luçi
12:59 PM Revision bf58398c: Specify correct attribute where to read the setting from.
Ermal LUÇI
12:58 PM Revision 8e53abfa: If specified use the default settings for bw limitation rather than 0
Ermal LUÇI
12:57 PM Revision c5b0298f: If specified use the default settings for bw limitation rather than 0
Ermal LUÇI
12:55 PM Revision 64053339: Prevent 2 instances of rc.prunecaptiveportal from running in parallell since this might be a bad thing
Ermal LUÇI
12:53 PM Revision 3807002c: Prevent 2 instances of rc.prunecaptiveportal from running in parallell since this might be a bad thing
Ermal LUÇI
12:30 PM Bug #2012: 4th+ CARP member will not work with default automatic skew
I am using it for HAProxy in a virtualized environment where we have two sites which are part of the same vCenter (we... Brian Scholer
11:45 AM Bug #2012: 4th+ CARP member will not work with default automatic skew
I am unsure why you'd want more than 3 members! Ermal Luçi
11:25 AM Revision d535507a: Add more fields to the 3g stats
Seth Mos
11:10 AM Bug #2445 (Feedback): Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
Applied in changeset commit:35b714597c8947376b350681c361b38e2569747a. Ermal Luçi
11:04 AM Bug #2445: Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
This is the upgrade code existing there.
Normally the section with s///g should have taken care of that.
Probably y...
Ermal Luçi
10:50 AM Revision 739808f7: Make file names match to make this work. Also use zone name in the file to not mix things
Ermal LUÇI
10:48 AM Revision 6b517c76: Make file names match to make this work
Ermal LUÇI
10:15 AM Revision 99f95f7d: Add the 3G mode display, really needs a function that translates these into sane display numbers for strength and mode.
The mode is actually a combination of LED color 4 = blue(idle), 5 = cyan(connected), and submode 7 = HSDPA
I need to ...
Seth Mos
09:47 AM Revision fe7fef64: Fix command, remove spurious '
Seth Mos
09:41 AM Revision 7efe5ac5: Initialize the statistics, also parse on MODE messages
Seth Mos
09:35 AM Revision d1796d06: Kill the old 3gstats collector. Clarify the log message
Seth Mos
08:53 AM Revision 71f4a2b7: Unbreak adding IPv6 static routes
Seth Mos
08:00 AM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Chapter 7.5 of the "HUAWEI UMTS Datacard Modem AT Command Interface Specification" lists the ^MODE messages to determ... Seth Mos
07:21 AM Revision 73ce6909: Make sure to bail the stats script if we can not open the modem device.
Seth Mos

05/22/2012

09:58 PM Revision 6bb73ce6: Remove dead code.
Matt Corallo
09:58 PM Revision fffbfef0: Fix DynDNS issue introduced by f3b2b2a (_dnsIP was not set).
Matt Corallo
09:58 PM Revision 37f3e704: Add the option to use a custom Dynamic DNS Provider via an Update URL and Result Match.
Matt Corallo
09:39 PM pfSense Packages Bug #2448 (Rejected): Snort pfPort is breaking a full package builder run
may just be bad timing/false alarm... will open if I can reproduce it again. Jim Pingle
09:36 PM pfSense Packages Bug #2448 (Rejected): Snort pfPort is breaking a full package builder run
Packages are not being built on the nightly run properly because snort is causing the build to fail.
Observe:
<pr...
Jim Pingle
09:00 PM Revision 6bab92aa: Oops add forgotten global for config
Ermal LUÇI
08:59 PM Revision aec0f2fd: If extra bw attributes are supplied during reauthentication apply and log them
Ermal LUÇI
08:57 PM Revision 9261915b: If extra bw attributes are supplied during reauthentication apply and log them
Ermal LUÇI
07:18 PM Revision 5c0b5f64: Unlock if error occurs
Ermal LUÇI
07:17 PM Revision 66c18912: Unlock if error occurs
Ermal LUÇI
06:19 PM Bug #2446: pfSense fails to queue UDP packets
Can you detail the rule you say assigns the traffic to your desired queue? Ermal Luçi
10:13 AM Bug #2446: pfSense fails to queue UDP packets
Some extra details:
The floating rule assigning traffic A to the special queue should be set to "apply the action ...
Torgeir Skjøtskift
10:06 AM Bug #2446 (Closed): pfSense fails to queue UDP packets
Replication instructions:
Create CBQ or PRIQ shaper on WAN interface and create a default queue and another queue ...
Torgeir Skjøtskift
06:19 PM Bug #2447 (Resolved): Duplicated destination IPs in easy rule.
On snapshot released Tue May 22 08:05:51 EDT 2012
Easy rule adds duplicated "destination" IPs instead of "source"...
greg Bernard
01:26 PM Revision 43d735de: Use "proto 112" instead of tcpdump's vrrp keyword since it's a little behind the times and doesn't realize that ip6+vrrp is valid. And since we're not using the vrrp keyword directly anymore, let's call it CARP instead.
Jim Pingle
06:13 AM Revision 5a61fd69: Make sure that we match multiple characters.
Ticket #2415 Seth Mos
05:49 AM Revision e7de69fb: First round of CARP vip renaming changes
Ticket #2415 Seth Mos
05:10 AM Bug #2409: ipfw - entryzerostats
in version 2.1.0 (bild 18May2012) an error is confirmed. Vlad Arakin
04:18 AM Bug #2038 (Resolved): Some 3G WANs on 2.0.x do not come up on cold boot
This turned out to be a specific issue with ZTE modems and pin lock.
I've switched to a huawei modem and found a g...
Seth Mos
03:54 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Ermal - you can put the time to Coltex Chris Buechler
03:51 AM Bug #2278 (New): IPv6 Carp vip both master on FreeBSD 8.3
Chris Buechler
03:50 AM Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3
Still hitting the double master issue in the Xs4all DC carp Seth Mos
02:39 AM Bug #2445: Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
$i = 0;
foreach($config['ipsec']['phase1'] as $phase1) {
if($phase1['interface'] == "vip131")
$config['ipsec'][...
Seth Mos
02:34 AM Bug #2445 (Resolved): Carp vip renaming broken IPsec VPN tunnels that reference carp interfaces.
Because of the vip renaming per interface any IPsec VPN tunnels, or endpoints referencing a CARP vip are now broken a... Seth Mos

05/21/2012

05:01 PM Revision ee8c34f4: Properly test for the address family now that the array says what it's supposed to be.
Seth Mos
04:57 PM Revision 44b054ce: Add the address family tag to the gateway groups array
Seth Mos
02:10 PM Revision c0ae3bfb: Don't auto-toggle the "do not backup rrd" setting - we do not want this on unless the user explicitly selects it. It makes for very, very large backup files and must default to off.
Jim Pingle
01:41 PM Revision 2b095a33: Correct the rrd update command
Seth Mos
01:35 PM Revision 852171dd: Read in the correct interface file
Seth Mos
01:31 PM Revision 5e589685: Add 3G statistics for Huawei modems, split the Cellular stats out to per interface instead of global.
Seth Mos

05/20/2012

11:52 PM Revision 612f5198: Modify the tar parameters to exclude .git
Erik Fonnesbeck
09:11 PM Bug #2444: DynamicDNS doesn't update on WAN IP change
I am not 100% sure what you mean,
my DSL modem is connected to PF and DSL_WAN PF interface manages the PPPoE
connec...
themisa themisa
08:49 PM Bug #2444 (Feedback): DynamicDNS doesn't update on WAN IP change
is the public IP actually on the firewall, not the modem? That's usually the cause, since in such cases it's impossib... Chris Buechler
08:14 PM Bug #2444 (Closed): DynamicDNS doesn't update on WAN IP change
I have a DSL WAN whose IP changes often.
If i manually make a change to the DSL_WAN interface, DynamicDNC updates ...
themisa themisa
07:15 PM Revision c6d0f00b: Allow modification of gateway groups even if the gateways are down.
Seth Mos
06:57 PM Revision 96cd928b: Allow saving on system.php if the gateways are down.
Seth Mos
06:01 PM Revision 793d3c96: Attempt to Eject the CD device on 3G sticks for Huawei and ZTE devices.
Seth Mos
06:01 PM Revision 1de3cd87: Act on wireless interfaces too for linkup.
Redmine ticket #2440 Seth Mos
05:37 PM Feature #2443 (New): Automatically start 3G usb interfaces upon plugin
And cleanup the old LCK files from /var/spool/lock/LCK..cuaU0.0
devd should be able to do this for us. It says it ...
Seth Mos
05:10 PM Bug #2440 (Feedback): Wireless client nic set for DHCP does not start dhclient
Seth Mos
05:10 PM Bug #2440: Wireless client nic set for DHCP does not start dhclient
Hoping the devd changes resolve this, hoping for the best. Wireless is 802.11, not ethernet Seth Mos
12:15 PM Bug #2440 (New): Wireless client nic set for DHCP does not start dhclient
Helps in most cases but can still cause it to take too long making the dhcp client fail. Needs proper check_reload_st... Seth Mos
08:47 AM Bug #2440 (Resolved): Wireless client nic set for DHCP does not start dhclient
Seth Mos
07:44 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
The wireless interface reconfigure (Even with persist settings toggled) causes the interface to go down which then ne... Seth Mos
07:32 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
check_reload_status is firing off for vr1, but not for ural0_wlan0 eventhough the kernel is marking it as up.... Seth Mos
07:10 AM Bug #2440: Wireless client nic set for DHCP does not start dhclient
Error output only lists:... Seth Mos
04:28 PM Revision e4834b57: Merge pull request #111 from vizvayu/bug2374
Fix of bug #2374 "When entering values in firewall rules leading and trailing spaces are not deleted" bis Jim Pingle
03:51 PM Revision 03f7925a: Fix variable test
Jim Pingle
12:50 PM Revision 2a210730: Initialize variable if it's not set
Seth Mos
12:48 PM Revision ffd2059b: This command works better with Huawei modems. Needs more testing
Seth Mos
11:21 AM Revision 1cba5c58: Make sure we don't accidentaly clobber the v4 dns servers with empty fields from v6
Seth Mos
11:13 AM Revision 3930a9c0: Prevent duplicate gateways from showing up if the interface is down. Redmine ticket #2442
Seth Mos
10:38 AM Revision d23ef852: Set the retry value to 60 seconds, this is not attempts, this is seconds before it needs a reply. So if the DHCP server was any sort of slow it would fail to aquire a lease. This was true for my wireless network at home. Plus, on various other lossy links, even cable modems this could be true.
Redmine ticket #2440
retry time;
The retry statement determines the time that must pass after the
...
Seth Mos
10:34 AM Bug #2437 (Feedback): PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
Change just checked in, let me know how it goes. Seth Mos
10:09 AM Revision b2ff5d17: Add the PPP automatic interface type. This would show the _PPP gateways.
Seth Mos
08:46 AM Bug #2442 (Resolved): Duplicate gateways showing for down interfaces
Should be resolved properly, or atleast for now, pretty sure we'll run into something new at some point. When adding ... Seth Mos
07:55 AM Bug #2442 (Resolved): Duplicate gateways showing for down interfaces
When dynamic interfaces are down, these will show up even if there is already a manual entry for it too.
I have a ...
Seth Mos

05/19/2012

06:03 PM Bug #2441 (Closed): Setting up a new PPP interface (3g) hangs the webUI
Trying to add a new PPP interface on a system that has no such configuration results in the UI hanging.
A system t...
Seth Mos
06:01 PM Bug #2440 (Resolved): Wireless client nic set for DHCP does not start dhclient
I've configured a wireless nic as a client (infrastructure) on Opt3. It is set for DHCP but although the link comes u... Seth Mos
05:00 PM Feature #2148: Dynamic DNS Update Frequency
I've been able to reproduce it.
When i open WAN_DSL connection and apply changes it does force a DynDNS update.
H...
themisa themisa
04:38 PM Feature #2148: Dynamic DNS Update Frequency
I've yet to see it update on WAN IP change.
My WAN_DSL ip has changed, the dsl modem is connected directly to PF.
D...
themisa themisa
12:06 PM Feature #2439 (Resolved): XEN Para-virtualized Drivers Support
It's possible to include the xen DomU driver in pfsense 2.1 ? Jan Koester
02:22 AM Revision fd86d829: Overcome laziness to avoid unnecessary loop
Cristian Feldman
01:57 AM Revision 90f90934: Fix of bug #2374 "When entering values in firewall rules leading and
trailing spaces are not deleted" Cristian Feldman

05/18/2012

07:49 PM Revision 1346306c: Allow 802.1p tags to be controlled from firewall rules edit screen
Ermal LUÇI
05:58 PM Feature #2438 (Duplicate): Inbound traffic shaping on unpredictable ADSL - the qosmon approach
I've been using pfSense for some time now, and it's wonderful. I've never been able to solve a problem, anyway: QoS o... Stefano Marinelli
05:12 PM Bug #2437 (Resolved): PHP missing bcmath (that was solved for pfSense 2.0 two years ago, re-discovered in the latest pfSense 2.1)
1.
When "Radius Accounting" is enabled and trying to disconnect a connected client in the captive portal gui - the f...
Yuri Keren
05:10 PM Revision 26c31b86: Merge pull request #109 from marcelloc/patch-11
Patch 11 Scott Ullrich
05:09 PM Revision 38026252: Include movable code to reorder list,save button, domtt title messages, also base64 decode option, description and custom text to checkbox fields.
New options need xml config to be included on package xml files, so no changes to packages that do not use these func... Marcello Silva Coutinho
03:36 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Also worth noting, though similar to the fact that it happens if you upgrade from 2.0.1 (noted above) is that loading... Mark Uhde
04:11 AM Revision 9c408ade: Merge pull request #108 from vizvayu/dashboard-cpufreq-update
System info widget on dashboard now updates CPU Frequency automatically Scott Ullrich
03:53 AM Revision 4dedd18a: System info widget on dashboard now updates CPU Frequency automatically
Cristian Feldman
03:41 AM Revision 735021f5: Merge pull request #94 from vizvayu/master
Added description text for IPSec tunnel status in "Status: IPsec" page Chris Buechler
01:37 AM Revision a425a28b: Moved status text to img title (tooltip)
Cristian Feldman
01:37 AM Revision 4976f453: Added description text for IPSec tunnel status in "Status: IPsec" page
Cristian Feldman
12:17 AM Revision c1361a9f: feature #2413 Allow IPv6 interface configuration from the menu
Darren Embry

05/17/2012

11:17 PM Revision 416e1530: normalize indentation
Darren Embry
11:02 PM Revision cd485c4f: remove some log_error calls
Darren Embry
11:00 PM Revision 283d78c6: bug fix for #2426
Input validaton on interface gateway creation box needs to reject duplicate names Darren Embry
10:33 PM Revision a0edece9: report errors adding a gateway through ajax calls
Darren Embry
09:32 PM Revision 8dcca9b5: - also rename $section arg to $section_name in some functions to clarify
- also robustify parsing for <tagname> and bulletproof the handling of
certain errors
Darren Embry
09:30 PM Revision 428c289f: allow null to be passed as 2nd arg to parse_config_xml*
in which case entire config is returned Darren Embry
09:14 PM Revision ff9fbc7b: fix 'XML error: no Array object found!' errors
Darren Embry
08:49 PM Revision 976d0213: fix cosmetic bug when developer was turned on.
highlight the hidden menu item differently. Darren Embry
08:13 PM Feature #2413 (Feedback): Allow IPv6 interface configuration from the menu
implemented in commit:c1361a9f
I've done basic testing but this needs a lot more testing than i'm able to do so i'...
Darren Embry
07:43 PM Revision dcb94db5: fix for #2231
Don't activate master "Save Settings" button on traffic graph min/max. Darren Embry
07:22 PM Revision f757431d: more verbose log_error on rrdtool restore failure
Darren Embry
07:22 PM Revision 5d51f00e: log_error if rrdtool restore calls fail
Darren Embry
07:16 PM Revision 08877746: restore_rrddata() adds log_error calls and uses -f
Darren Embry
07:13 PM Revision 7a865f03: add -f to 'rrdtool restore' call
Darren Embry
06:58 PM Bug #2426 (Resolved): Input validaton on interface gateway creation box needs to reject duplicate names
fixed in commit:283d78c6 Darren Embry
04:53 PM Bug #2426: Input validaton on interface gateway creation box needs to reject duplicate names
Darren, do you think you can prevent this duplicate name issue in the Ajax call?
Seth Mos
06:55 PM Revision 7eead1fc: add rrddata to backup/restore dropdowns.
Darren Embry
06:05 PM Revision c9a19238: indentation cleanup
Darren Embry
06:03 PM Revision 754b75d0: move certain code to new function restore_rrddata()
Darren Embry
05:46 PM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
I just want to say, that amd64 architecture is affected also.
Have just tried it.
Vladimir Suhhanov
05:30 PM Feature #2356: Fill the "Track Interface" prefix drop down list asynchronously
Seth, reassigning to you for you to test/close/assign back to me as needed. Darren Embry
05:29 PM Feature #2436 (Feedback): Enhance the restore section of the Backup/Restore section
Fixed in commit:428c289f and commit:8dcca9b5.
Reassigning to you so you can do further testing.
Please close if e...
Darren Embry
03:48 PM Feature #2436 (Resolved): Enhance the restore section of the Backup/Restore section
If restoring a partial config, we currently assume that only that section is uploaded. This is somewhat counterintuit... Seth Mos
04:37 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 90164860 bytes) in /usr/local/www/di... Seth Mos
03:21 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
I've also added "RRD Data" as a backup option in the dropdowns. Requires a little special handling in diag_backup.ph... Darren Embry
03:18 PM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
I've confirmed that -f is actually necessary anyway and added -f and log_error calls on failure to all the rrdtool re... Darren Embry
10:12 AM Feature #2123: Backup RRD files using the xml dump and restore from RRD tools
The quick test I just did, backup config.xml on i386, upgrade to amd64, then restore config.xml didn't fix the RRD fi... Seth Mos
04:17 PM Bug #2231 (Resolved): Dashboard: Traffic Graph: Unable to save settings
Darren Embry
03:38 PM Bug #2231: Dashboard: Traffic Graph: Unable to save settings
fixed in commit:dcb94db5 Darren Embry
12:25 AM pfSense Packages Bug #2435 (Resolved): SquidGuard: Deprecated function 'eregi' warnings
In squidguard_configurator.inc, there are a number of uses of @eregi()@ which is now deprecated in PHP 5.3. This cau... Moshe Katz

05/16/2012

06:03 PM Revision b61e8960: Teach mwexec and mwexec_bg how to optionally clear signal masks, and use that when launching ntp or ntpdate.
Jim Pingle
05:21 PM Revision 10e741d5: ntpdate was hanging, use the same hacky fix that works for ntpd and it works too. All happy, even from a cold boot on ALIX 2d3 with no RTC battery.
Jim Pingle
05:17 PM Revision 9cf11774: Fixup halt and reboot to catch the output from the shutdown process properly.
Conflicts:
usr/local/www/halt.php
usr/local/www/reboot.php
Jim Pingle
05:15 PM Revision b40e9b1c: Fixup halt and reboot to catch the output from the shutdown process properly.
Jim Pingle
02:57 PM Revision b3f2cc0f: Fixup ntpd logging
Jim Pingle
02:49 PM Revision 90df3bd8: On its own, ntpd does not sync fast enough at bootup, so bring back the ntpdate sync but improve it so it can't get stuck forever.
Conflicts:
etc/rc.newwanipv6
Jim Pingle
02:48 PM Revision 0b8e9d38: On its own, ntpd does not sync fast enough at bootup, so bring back the ntpdate sync but improve it so it can't get stuck forever.
Jim Pingle
09:48 AM Bug #2231 (New): Dashboard: Traffic Graph: Unable to save settings
Something still isn't 100% here - When you activate a drop-down to expand one of the closed graphs, it also activates... Jim Pingle

05/15/2012

09:01 PM Revision 317d1c0b: Hackish workaround for ntpd failing to move away from init when called from within PHP 5.2, PHP 5.3 has a better workaround.
Jim Pingle
08:50 PM Revision df973fcb: Revert "Clear process signals before exec() or ntpd misbehaves if called from PHP on i386." -- this only works on PHP 5.3
This reverts commit ac4bc5853f75a8f8467f5c53704f33e2066c3da6. Jim Pingle
08:42 PM Revision 82deea60: Fix syntax here too in case we need to revive it.
Jim Pingle
08:41 PM Revision 11e06906: Fix syntax here too in case we need to revive it.
Jim Pingle
08:37 PM Revision 7dab8995: Clear process signals before exec() or ntpd misbehaves if called from PHP on i386.
Jim Pingle
08:36 PM Revision ac4bc585: Clear process signals before exec() or ntpd misbehaves if called from PHP on i386.
Jim Pingle
08:08 PM Revision d80eae9a: Update gitsync with latest changes from master branch
feef287ead62815b1a67bac15ebaa2d36226d4e2 - Remove obsolete files after gitsync
26b8990538c71c99df8e95fd5fada57f79465d...
Erik Fonnesbeck
07:26 PM Revision ae26412f: Move git package name/URL to the configuration variables section.
Erik Fonnesbeck
06:27 PM Revision da5b3e83: Merge pull request #107 from bcyrill/patch-1
correct closing tags Jim Pingle
06:22 PM Revision ec18e696: correct closing tags
Cyrill B
05:45 PM Revision e37eeb49: Only process this if it's an array
Jim Pingle
05:05 PM Revision ac911619: Use a text description instead of a code.
Jim Pingle
05:04 PM Revision 0770e603: Add NTP status page using ntpq.
Jim Pingle
05:04 PM Revision 321f3076: Use FreeBSD's ntpd instead in the backend
Jim Pingle
05:04 PM Revision 49551bbf: With FreeBSD's ntpd, the current options are irrelevant, but we can have a nice status page
Conflicts:
usr/local/www/fbegin.inc
Jim Pingle
05:01 PM Revision a0c16779: Fix ntp name here too
Conflicts:
etc/inc/priv.defs.inc
Jim Pingle
05:00 PM Revision 02414e3a: s/OpenNTPD/NTP/ for log pages and menu entry, to save space (and make it easier if we switch)
Conflicts:
usr/local/www/diag_logs.php
usr/local/www/diag_logs_auth.php
usr/local/www/diag_l...
Jim Pingle
03:44 PM Revision c886fed9: As suggested by wagonza, using SAMEORIGIN for X-Frame-Options is sufficient here, and does allow the traffic graphs to work. Fixes #2419
Jim Pingle
03:11 PM Revision 29c2c1db: Fix quoting - can't use ' if we want to expand a variable inside the string.
Jim Pingle
02:35 PM Revision 25890c50: Use a text description instead of a code.
Jim Pingle
11:40 AM Bug #2419 (Feedback): Possible Clickjacking Vunerability
Applied in changeset commit:c886fed9ba6a19fface58c918be5d7b111cca1f3. Jim Pingle
10:56 AM Bug #2419 (New): Possible Clickjacking Vunerability
Adding this bit in auth.inc broke the realtime traffic graphs:
@Header("X-Frame-Options: DENY");@
We either nee...
Jim Pingle

05/14/2012

08:30 PM Revision e078c882: Add NTP status page using ntpq.
Jim Pingle
07:44 PM Revision 42135f07: Use FreeBSD's ntpd instead in the backend
Jim Pingle
06:50 PM Revision a8543b59: With FreeBSD's ntpd, the current options are irrelevant, but we can have a nice status page
Jim Pingle
06:17 PM Revision ffc7d2c4: Fix ntp name here too
Jim Pingle
06:11 PM Revision ae2c143a: s/OpenNTPD/NTP/ for log pages and menu entry, to save space (and make it easier if we switch)
Jim Pingle
04:39 PM Revision 547c56c4: Create $altnames earlier, and also fix a bracing issue with this if statement. Fixes certificate importing.
Jim Pingle
04:27 PM Revision e052047d: Whoops, don't flip these since I negated the test.
Jim Pingle
03:09 PM Revision d9c96fb1: Flip this test around since it's safer to assume the dev mode is tun. Ticket #2432
Jim Pingle
02:03 PM Revision 93efafec: Fix redirect when saving settings in the widget, it was landing on the widget page instead of returning to the dashboard.
Jim Pingle
02:02 PM Revision e6b16f89: Fix redirect when saving settings in the widget, it was landing on the widget page instead of returning to the dashboard.
Jim Pingle
01:08 PM Revision 310c29c6: Make the ppp-linkup script understand both address families.
Seth Mos
12:54 PM Revision e32cb5d0: Make the ppp-linkup script understand both address families.
Seth Mos
12:23 PM Bug #2432: OpenVPN Client Specific Override ifconfig-push
Yeah you're right I started to fix it one way then changed my mind halfway, but didn't back out the original change. ... Jim Pingle
12:19 PM Bug #2432: OpenVPN Client Specific Override ifconfig-push
I understand your concern about upgrade users since i appreciate when upgrade runs smoothly.
I've looked at the ...
Davy Gigan
11:03 AM Bug #2432: OpenVPN Client Specific Override ifconfig-push
Not sure that making them server-specific will be feasible. At the very least, that will cause problems for upgrade u... Jim Pingle
10:48 AM Bug #2432 (Closed): OpenVPN Client Specific Override ifconfig-push
Hello,
I'm using a snapshot of pfSense 2.1 (20120419-1059). My pfSense installation holds two distinct VPN serve...
Davy Gigan
11:25 AM pfSense Packages Bug #2429: Hostname issues in OpenVPN Client Export
I replaced the two {{ with { in /usr/local/pkg/openvpn-client-export.inc on two lines in the file.
It works perfectly!
Thomas Svedin
10:20 AM pfSense Packages Bug #2429 (Feedback): Hostname issues in OpenVPN Client Export
Applied in changeset commit:0d639e580d2fc2651a4386a4248ac9e9b97d949d. Jim Pingle
05:14 AM pfSense Packages Bug #2429 (Resolved): Hostname issues in OpenVPN Client Export
When i select installation hostname when i export it looks like this in the configuration file:
remote host.{domain....
Thomas Svedin
09:44 AM Bug #2431 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
This has already been fixed in 2.0.2/2.1. Jim Pingle
06:02 AM Bug #2431 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Warning message displayed :... Xavier Romain
09:43 AM Bug #2430 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Duplicate Jim Pingle
06:36 AM Bug #2430: Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Sorry for duplicate submit. Xavier Romain
06:02 AM Bug #2430 (Rejected): Receiving warning message when adding/modifiyng exclude list in Services Status widget (dashboard)
Warning message displayed :... Xavier Romain

05/11/2012

04:49 PM Revision bbdc5919: remove the stuff triggering display of relay protocol row
Darren Embry
04:49 PM Revision 06d84cf3: allow port in virtual servers to be left blank
in which case listening port would be inherited from the pool Darren Embry
04:49 PM Revision 183ea34c: allow aliases for the ipaddr field in virtual servers (PEV-394754)
Darren Embry
03:16 PM Revision 777c202f: make use of the correct file to send notifications
Warren Baker
03:12 PM Revision 62fc138e: make use of the correct file to send notifications
Warren Baker
03:04 PM Revision 937cec84: fix for bug #2422 could not remove entries from CP Allowed Hostnames
Darren Embry
11:34 AM Bug #2428 (Resolved): Removing a limiter breaks any references to limiters after it
It appears that the limiters are referenced only by their index in the current list of limiters, instead of by name o... Jim Pingle
11:08 AM Bug #2427 (Feedback): /etc/rc.firmware_notify
Wrong file been referenced. Fix in commit:62fc138e7096d9b28026a86244baad56980494f4 Warren Baker
06:36 AM Bug #2427 (Resolved): /etc/rc.firmware_notify
When doing an upgrade the shell script /etc/rc.firmware is executed. As part of the upgrade process this script execu... Warren Baker
10:59 AM Bug #2422 (Resolved): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
fixed in commit:937cec84
Darren Embry
07:29 AM Bug #2426: Input validaton on interface gateway creation box needs to reject duplicate names
[Edit: the ticket system seems to have chopped off all my text except the last line...]
The real issue is making a d...
Jim Pingle
04:31 AM Bug #2426 (Resolved): Input validaton on interface gateway creation box needs to reject duplicate names
If two gateways are created with the same name/label, and one of them is set as default for an interface, it's not po... Max Frames

05/10/2012

07:17 PM Revision 4dfd930e: cleanup: code for building arrays for autocompleted fields
Darren Embry
06:25 PM Revision c9649cf8: Merge pull request #106 from irvingpop/master
max_procs adjustments for small memory systems, attempt 2 Scott Ullrich
06:17 PM Revision 98f20e35: max_procs adjustments for small memory systems, attempt 2
Per Jim P's feedback, move max_procs completely out of
system_webgui_start() and move all of the memory/procs decis...
Irving Popovetsky
06:00 PM Revision 5b84bd65: add autocomplete for port (PEV-394754)
Darren Embry
05:51 PM Revision 04d4bcdf: use get_alias_list for port field in load_balancer_pool_edit
Darren Embry
05:48 PM Revision a0539faa: prep work: function get_alias_list()
I wrote this function primarily to remove a lot of duplicate code
that's there because of a lot of those autocomplete...
Darren Embry
04:39 PM Revision a1f77238: add autocomplete to load_balancer_pool_edit.php (PEV-394754)
we also enable the json extension here. Darren Embry
04:05 PM Revision 9b420daf: fix a bug in anti-clickjack that made all pages blank
https://github.com/bsdperimeter/pfsense/commit/babac37a3b9a676525fff422011b9f3c0f9bd39f Darren Embry
03:54 PM Revision f3d7f30e: update help text in port fields to Firewall -> Aliases (PEV-394754)
Darren Embry
03:51 PM Revision babac37a: Add click jacking support. Ticket #2419
Scott Ullrich
02:15 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)
pull request attempt number 2: https://github.com/bsdperimeter/pfsense/pull/106 Irving Popovetsky
12:35 PM Bug #2063: PHP Memory Usage too high for 128MB RAM Systems (like ALIX)
Pull request to set the number of web configurator processes to 1 on ALIX systems with 256MB RAM or less
https://...
Irving Popovetsky
12:56 PM Revision 970934dc: Revert "Bump config version to take care of new vips" - forgot to revert this when I reverted the main vip commit.
This reverts commit ccf346ddb80997a4426484c25e5c3bd8a223990f. Jim Pingle
12:02 PM Bug #2359 (Resolved): Typo: OpenVPN Configuration Page has two items "Server DHCP Bridge Start"
Jim Pingle
11:49 AM Bug #2359: Typo: OpenVPN Configuration Page has two items "Server DHCP Bridge Start"
This is already fixed for 2.1: https://github.com/bsdperimeter/pfsense/pull/96 Irving Popovetsky
11:46 AM Bug #2328: Numerous non-CP logs ending up in CP logs
http://www.php.net/manual/en/function.openlog.php#98307 suggests an alternate way of specifying the facility that may... Jim Pingle
11:35 AM Bug #2328: Numerous non-CP logs ending up in CP logs
That looks like anything in PHP that uses log_error() is doing that.
However log_error is doing this:...
Jim Pingle
11:45 AM Bug #2419 (Feedback): Possible Clickjacking Vunerability
Scott Ullrich
09:57 AM Feature #2424 (Resolved): Allow masking of pass-thru MACs
ipfw supports masking MACs, sort of like a CIDR, and this could be a useful feature to allow, for example, all phones... Jim Pingle
09:34 AM Bug #2423 (Closed): OpenNTPD seems to fail over time and can cause unintended clock skew.
Over time, NTP eventually loses the ability to keep the clock in sync and sometimes will actually set the wrong time,... Jim Pingle
07:07 AM Revision 5b5c9911: Add _ to the list of are allowed characters
Warren Baker
07:02 AM Revision 06f746c3: Add _ to the list of are allowed characters
Warren Baker
06:51 AM Bug #2373: There were error(s) loading the rules... (Floating rules bug)
Some error
Snap 2.1-DEVELOPMENT built on Wed May 9 21:13:38 EDT 2012 ...
Yan Triary
02:34 AM Feature #2418 (Closed): HttpOnly and Secure flag are not set in the HTTP response header
Awesome stuff. Warren Baker
02:27 AM Feature #2418: HttpOnly and Secure flag are not set in the HTTP response header
Wow.. Fantastic
Works as i had hoped
thank you for the quick fix
Laterpay Gmbh
01:57 AM Revision 82618bec: fix typo
Chris Buechler
01:57 AM Revision b1aa904f: fix typo
Chris Buechler

05/09/2012

08:55 PM Revision 2f65de89: Add initial support for subjectAltName - still needs some select love for the "type" field, freetext for now for testing (it does work, cert gets the specified subjectAltName).
Jim Pingle
05:51 PM Revision ddb71e4c: Handle HTTPOnly and Secure flags on cookies
Warren Baker
05:25 PM Revision ca88c37e: Include TCP flags in CLI filter parser output (if present)
Jim Pingle
05:08 PM Revision 49ddf9a1: Handle HTTPOnly and Secure flags on cookies
Warren Baker
04:49 PM Bug #2422 (Assigned): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
Chris Buechler
04:38 PM Bug #2422 (Resolved): Captive Portal: Allowed Hostnames tab - cannot remove a previously added hostname
When trying to delete a previously added hostname from a Captive Portal zone - nothing happens. There is no error, bu... Yuri Keren
01:49 PM Feature #2418 (Feedback): HttpOnly and Secure flag are not set in the HTTP response header
Change committed in commit:49ddf9a10ff3379162d437622f664cfe924b4552 - let us know if you happy this please. Warren Baker
09:47 AM Feature #2418 (Closed): HttpOnly and Secure flag are not set in the HTTP response header
According to our tests for PCI-DSS certification by a professional security auditing team.
PfSense lacks the HttpO...
Laterpay Gmbh
01:34 PM Bug #2421 (Resolved): Filter log parser misinterprets some rare lines resulting in TCP:lo for the proto/flags
The following raw log entry:... Jim Pingle
12:08 PM Feature #2416: Hybrid NAT mode that is a mix of Auto+Manual
While we're doing this, may as well add a fourth outbound NAT option
* Off (all outbound NAT disabled)
Then someo...
Jim Pingle
09:52 AM Bug #2419 (Resolved): Possible Clickjacking Vunerability
According to our tests for PCI-DSS certification by a professional security auditing team.
PfSense has a possible ...
Laterpay Gmbh

05/08/2012

10:22 PM Revision 30274157: Revert "Make vips vhid be unique per parent interface!" - per cmb, this should not have been on RELENG_2_0 see ticket #2415
This reverts commit 4d0c032c528b10221a2ef894b5eca34f6fda39a7.
Conflicts:
etc/inc/openvpn.inc
etc/in...
Jim Pingle
07:43 PM Revision 8a4b381f: Update zoneinfo using latest zones from FreeBSD
Jim Pingle
07:42 PM Revision 23b1fc49: Update zoneinfo using latest zones from FreeBSD
Jim Pingle
07:05 PM Revision b80e57d4: Pull in fix for Ticket #1917 to RELENG_2_0 as well.
Jim Pingle
07:02 PM Revision 84931046: Back out duplicated fix from 107e8acc - Ticket #1917 was already fixed before this was added.
Jim Pingle
06:20 PM Bug #2415: Fallout from CARP vip interface names changes
I reverted that commit, had to adjust a few things since it didn't come out cleanly, but it should be out of RELENG_2... Jim Pingle
06:02 PM Bug #2415: Fallout from CARP vip interface names changes
this needs to be backed out entirely from RELENG_2_0, it wasn't supposed to be there. Chris Buechler
12:19 PM Bug #2415 (Resolved): Fallout from CARP vip interface names changes
Now that CARP VIP interfaces have been renamed, some issues have come up. They are now named, for example, wan_vip241... Jim Pingle
05:15 PM Revision 7ff663d3: Respect ['upload_path'] for upload_tmp_dir for PHP
Warren Baker
04:54 PM Revision 1e476e11: $realif only exists on apply, which this code path would never touch. Change to use the configured interface instead. Fixes #2212
Jim Pingle
04:49 PM Revision 76ac460b: $realif only exists on apply, which this code path would never touch. Change to use the configured interface instaed. Fixes #2212
Jim Pingle
04:15 PM Feature #1986: Find a way to list logged in IPsec xauth users
Also this does not seem to work.
[2.1-DEVELOPMENT][root@pfsense-amd64.localdomain]/root(68): racoonctl show-sa isa...
Jim Pingle
09:17 AM Feature #1986 (New): Find a way to list logged in IPsec xauth users
Setting this back to New since we still need code in the GUI to read this yet. Jim Pingle
03:40 PM Bug #2030 (Feedback): Timezones need to update for Russia
Updated zoneinfo in commit:23b1fc4 and commit:8a4b381 Jim Pingle
03:29 PM Bug #2030 (New): Timezones need to update for Russia
We do keep a copy of zoneinfo.tgz in the git repo. Hasn't been touched since 2008, and our code pulls the zones from ... Jim Pingle
03:37 PM Revision 76db94c2: Add last check timestamp to gateway status (actually just fix it, since the code was there, but not functional) Fixes #1155
Jim Pingle
02:53 PM Feature #1917: DHCP server support for multiple domains in search list
Looks like someone also checked in a fix in commit:107e8acc that broke this again. It appears the fix on this ticket ... Jim Pingle
02:46 PM Bug #2348 (Resolved): rc.filter_synchronize is broken
This appears to be properly fixed and functional on current snapshots. Jim Pingle
02:38 PM Bug #2332: gateways always renamed to "dynamic". Implement proper IPv6 support
This seems mostly OK but I discovered one case the other day that is still problematic.
If you have a PPPoE interf...
Jim Pingle
02:34 PM Bug #2144 (Resolved): pfSense dyndns for Namecheap doesn't work with hostnames containing "."
I added a hostname with a . to one of my domains using Namecheap DNS and it updated fine, so this is fixed. Jim Pingle
02:21 PM Feature #2416 (Resolved): Hybrid NAT mode that is a mix of Auto+Manual
Often we suggest people switch to manual outbound NAT to make some very basic adjustments (such as a static port for ... Jim Pingle
01:03 PM Revision cb01726c: Move the stop_packages code to a function, and call the function from the shell script, and call the function directly for a reboot. Fixes #2402 and ticket #1564
Jim Pingle
12:50 PM Bug #2212 (Feedback): dhclient not stopped after changing interface from DHCP to other type
Applied in changeset commit:76ac460bd4a95a8600b05cecebd8d66f20feed70. Jim Pingle
12:20 PM Bug #2300: Static routes for IPsec peers missing when attached to IP Alias VIP
The problem seems to be, in part, that this checks for an interface name of carp or vip, but with IP alias it would a... Jim Pingle
11:55 AM Feature #2347 (Resolved): Add routes into the routing table for delegated IPv6 prefixes.
Closing this as the routing for PD nets is working great now, I plugged my ALIX in with a stock config and it pulled ... Jim Pingle
11:55 AM Bug #2414 (Resolved): IPv6 DHCP WAN, issue routing firewall-generated traffic
From Seth:
> There is a problem where pfSense itself can not reach the ipv6 internet [with a DHCPv6 WAN] leading to ...
Jim Pingle
11:40 AM Bug #1155: [patch] status_gateways.php doesn't show last check time
Applied in changeset commit:76db94c28d3cabe38f0b0921c21f80dfddcf93fc. Jim Pingle
11:32 AM Bug #1155 (Feedback): [patch] status_gateways.php doesn't show last check time
The code was already there to show that timestamp, so I fixed it up to show it (not quite how this patch was, better ... Jim Pingle
09:46 AM Feature #2413: Allow IPv6 interface configuration from the menu
That second bit about v4 already has a ticket - #2074 Jim Pingle
03:23 AM Feature #2413 (Resolved): Allow IPv6 interface configuration from the menu
The current console menu only allows for IPv4 interface configuration. We need to add support for IPv6 interface conf... Seth Mos
09:39 AM Feature #2242 (Resolved): Add status of lagg(4) member interfaces to Status > Interfaces
Jim Pingle
09:38 AM Bug #2127 (Resolved): Full Update Image Size is too large on 2.1
This has been OK for a while, the images are now under 90MB, which is down considerably from where they started. Jim Pingle
09:13 AM Bug #1112 (New): IPsec GUI/backend missing RADIUS support
Setting this back to New only since we still need to code up GUI support for this. The backend part should be OK. Jim Pingle
09:05 AM Bug #1427 (Resolved): Typo? in /tmp/post_upgrade_command prevents UP kernel upgrade
Jim Pingle
09:03 AM Bug #2314 (Resolved): Members to bridge not added
Tested newest snapshots and it works for me. Jim Pingle
08:58 AM Bug #2370 (Resolved): syslog.conf requires IPv6 literal
This has been working fine for me since that last commit. Logs are coming across IPv6 and are targeted at an IPv6 IP ... Jim Pingle
08:58 AM Bug #2402 (Resolved): rc.stop_packages synxtax error when executed
This has been working fine for me since my last fix. No errors, and it runs as expected during shutdown. Jim Pingle
08:53 AM Bug #2360 (Resolved): OpenVPN "tap" mode not working
Jim Pingle
07:35 AM Bug #2360: OpenVPN "tap" mode not working
appears to be working now. Thanks! Johannes Ullrich

05/07/2012

10:53 PM Revision c8deb624: Merge pull request #102 from marcelloc/patch-9
Fix missing description in rowhelper. Scott Ullrich
10:48 PM Revision 31366121: Fix missing description in rowhelper.
Marcello Silva Coutinho
08:58 PM Revision 58d642df: Use a better default update url
Jim Pingle
07:57 PM Revision 8358b341: Whoops, typo. Fixed now.
Jim Pingle
07:57 PM Revision 45eb5e65: Whoops, typo. Fixed now.
Jim Pingle
07:04 PM Bug #1667: L2TP server does not respond properly from a CARP VIP
This seems to be the classic UDP problem where the system will source the reply from the "closest" address rather tha... Jim Pingle
07:01 PM Revision 17113cea: Don't pass a shell escaped version of $realifl to pfSense_bridge_add_member(). Fixes bridging
Jim Pingle
07:00 PM Revision e5e88403: Don't pass a shell escaped version of $realifl to pfSense_bridge_add_member(). Fixes bridging
Jim Pingle
06:36 PM Revision c4ac3144: Fix missing paren
Jim Pingle
06:21 PM Bug #1892 (Resolved): Cannot static add static IPv6 route.
Chris Buechler
06:20 PM Revision fe7d855d: Bump to 2.0.2-RC1 for testing.
Jim Pingle
06:17 PM Feature #1184 (Resolved): Certificate Manager - Ability to add nsCertType=SERVER extension to certificates
Chris Buechler
06:16 PM Feature #1258: dyndns - DNS Made Easy
make a merge request on github and this will make 2.1. Chris Buechler
06:14 PM Feature #1801: Intermediate SSL certs box
easily worked around by pasting in the cert chain for the CA cert. Chris Buechler
06:12 PM Bug #2336 (Resolved): PHP extensions missing in amd64 builds (at least)
Chris Buechler
06:03 PM Bug #1662 (Resolved): DNS server gateway selection missing input validation
Chris Buechler
05:27 PM Revision cd619518: Merge pull request #101 from marcelloc/patch-8
Patch 8 Scott Ullrich
05:27 PM Revision 9a1a0fac: Merge pull request #100 from marcelloc/patch-7
Stop service needs to wait process to be stopped before trying to restar... Scott Ullrich
04:06 PM Revision 9a1248b3: Stop service needs to wait process to be stopped before trying to restart it.
Marcello Silva Coutinho
03:53 PM Revision 6ae78f08: Stop service needs to wait process to be stopped before trying to restart/start it.
Marcello Silva Coutinho
03:52 PM Bug #2314: Members to bridge not added
Ah you're right, I didn't copy/paste or save from the test box to the repo like I usually do. Easy to miss in the fon... Jim Pingle
03:47 PM Bug #2314: Members to bridge not added
I think it works, with one small typo fixed:
pfSense_bridge_add_member($bridgeif, $realifl);
last later should ...
Johannes Ullrich
03:29 PM Bug #2314 (Feedback): Members to bridge not added
This should be fixed now by commit:e5e8840356e1f9ac2cd0e12f511599b5df84ace9 Jim Pingle
03:29 PM Bug #2360 (Feedback): OpenVPN "tap" mode not working
This may be fixed now with commit:e5e8840356e1f9ac2cd0e12f511599b5df84ace9 Jim Pingle

05/06/2012

06:07 PM Revision 89341b50: fix vouchers
Chris Buechler
04:02 PM Revision 5db4d1eb: Test if this is an array before using it as an array.
Jim Pingle
12:06 PM Revision 18e89fd6: Merge pull request #99 from znerol/feature/master/dns-host-alias
Support name based aliasing via CNAMEs or some other mechanism. Jim Pingle
08:10 AM Feature #2410 (Feedback): Support name based aliasing via CNAMEs or some other mechanism.
Applied in changeset commit:5a2a83493cdb3f647b4913f3b84ef864103148f5. Anonymous
04:35 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
https://github.com/bsdperimeter/pfsense/pull/99 znerol znerol
03:17 AM Bug #2412 (Resolved): inbound 6to4 traffic does not work in pf
With the WAN configured as 6to4 it is possible to browse the internet but it is not possible to initiate traffic from... Seth Mos

05/05/2012

07:47 PM Revision 85d1b51b: Fix whitespace: use spaces in services_dnsmasq_edit.php in order to match coding style of surrounding html
Lorenz Schori
05:51 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
The code seems to work fine for me. I added a host, gave it an alias, and it was populated in /etc/hosts as expected.... Jim Pingle
05:46 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Whitespace could use some cleanup, but usually patches will work so long as they are clean. It may have been that the... Jim Pingle
03:45 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Whitespace is handled somewhat inconsistently throughout the pfsense codebase. I tried hard to mimic the style of exi... znerol znerol
03:16 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Done. https://github.com/znerol/pfsense Branch: feature/master/dns-host-alias znerol znerol
12:40 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
mater is 2.1 (for now)
Interesting, I just did another gitsync to bring my VM up to the most current code and it s...
Jim Pingle
12:22 PM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Actually the patch is against the master branch on github. The last commit i see in my git log is https://github.com/... znerol znerol
11:30 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Was that patched against 2.0.1 or 2.1? It doesn't appear to apply to 2.1. Jim Pingle
07:35 AM Feature #2410: Support name based aliasing via CNAMEs or some other mechanism.
Patch attached. It applies on an installed pfsense 2.0.1 as well as onto git master.
In order to patch a running s...
znerol znerol
11:07 AM Revision 5a2a8349: Add support for aliases in DNS Forwarder, fixes #2410
Lorenz Schori
 

Also available in: Atom