Project

General

Profile

Activity

From 09/05/2012 to 10/04/2012

10/04/2012

09:16 PM Bug #2582: OpenVPN service won't start after changing the IP of interface
I should clarify. We have 4 OpenVPN server instances total on this particular pfSense box, with the remote access se... Tyler Merrill
09:14 PM Bug #2582: OpenVPN service won't start after changing the IP of interface
I also had this same issue, although I'm using 2.0.1 AMD64 release on a virtual machine under VMWare ESXi 5.0.0. We ... Tyler Merrill
08:55 PM Revision 050fd8ad: Rather use the system constants as defined
Ermal LUÇI
08:51 PM Revision e4d7130d: Use integer rather than hex to put these values. AMD64 builds do rather awkward problems
Ermal LUÇI
06:37 PM Revision 3c107b76: Add a NAT entry for configuring NAT on ipsec phase2. It will add nat rules on enc interface
Ermal LUÇI
04:53 PM Todo #2652: Add edit function for imported CRLs
Might be nice as a separate feature request for the future, but not something I'm thinking of doing now. Jim Pingle
04:44 PM Todo #2652: Add edit function for imported CRLs
Normally should be added even an option to update CRL from some web source. This is very common on many platforms. Ermal Luçi
11:07 AM Todo #2652 (Resolved): Add edit function for imported CRLs
Currently imported CRLs can't be edited to paste in a new/fresh CRL, which makes updating them cumbersome (have to ad... Jim Pingle
02:29 PM Revision 6f663992: Eliminate system calls here, use PHP instead.
Jim Pingle
02:28 PM Revision 80ff6bfe: Eliminate system calls here, use PHP instead.
Jim Pingle
01:24 PM Revision f5acd065: Sanitize some variables
Discovered-By: Yann CAM Jim Pingle
01:14 PM Revision 33ba4131: Sanitize some variables
Discovered-By: Yann CAM Jim Pingle
12:55 PM Revision fa9f5ff9: Verify posted kernel type against a defined list of good values.
Discovered-By: Yann CAM Jim Pingle
12:55 PM Revision 73b9d3c6: Verify posted kernel type against a defined list of good values.
Discovered-By: Yann CAM Jim Pingle
12:20 PM Revision d729dbeb: Fix reference to limitrules
Jim Pingle

10/03/2012

05:17 PM Revision 7b27db03: Add restrict lines to limit what local clients are allowed to do to the ntp server.
Jim Pingle
05:17 PM Revision 6162b068: Only attempt to unset this if it has been set.
Jim Pingle
12:47 AM Bug #2293 (Resolved): Associated NAT rules for TCP missing flags
Chris Buechler
12:45 AM Bug #2651 (Resolved): traffic RRDs broken after upgrade to 2.1
None of the traffic graphs work after upgrading 2.0.x->2.1. In system log: ... Chris Buechler

10/02/2012

10:08 PM Revision 7f835f3c: Merge pull request #235 from PiBa-NL/master
openvpn-widget layout drawing fix Jim Pingle
07:20 PM Revision e18343fb: another openvpn-widget layout drawing fix, sorry.
Pi Ba
02:44 PM Bug #2645: stristr() warning repeated dozens of times during boot
Previous was not the 'possibly fixed' function it was the 'original' here is the 'fixed' one..:... Pi Ba
02:42 PM Bug #2645: stristr() warning repeated dozens of times during boot
Found same issue and mailed to dev@lists a 'possible solution', maybe Ermal Luçi can take another look?
p.s. the l...
Pi Ba
01:25 PM Revision a9f0df69: Make sure that the limits are included in the normal ruleset, otherwise pf will use the defaults.
Seth Mos
01:25 PM Revision fdcc1b82: Don't die silently if the time is too far off. Fix from: dhatz
Jim Pingle
04:05 AM Bug #2643: OpenVPN Server not deletable
Thanks. I tested on the latest snapshot:
2.1-BETA0 (i386)
built on Mon Oct 1 14:51:06 EDT 2012
Adding, editing an...
Phillip Davis

10/01/2012

03:04 PM Revision 6646c0f9: Merge pull request #233 from bcyrill/rfc3168_flags
Add ECE and CWR TCP flags as defined in RFC 3168 Jim Pingle
02:59 PM Revision b4147482: Fixup processing of IPv6 IPs for EasyRule. Fixes #2649
Jim Pingle
02:20 PM Revision 51271f74: Merge pull request #234 from PiBa-NL/master
OpenVPN allow changing TUN/TAP, firewall-log filter on interface. carp show vip desciption in notification Jim Pingle
01:46 PM Revision f062f033: firewall log, show cell border when using 'column descriptions'
Pi Ba
12:48 PM Revision dcbafe17: Fix typo
Cyrill B
12:45 PM Revision da601f8e: Allow for changing OpenVPN TUN to TAP device mode without reboot.
Pi Ba
12:44 PM Revision 79cc9e6b: Add ECE and CWR TCP flags as defined in RFC 3168
Cyrill B
12:38 PM Revision d8cdfd3e: Merge branch 'master' of git://github.com/bsdperimeter/pfsense
Pi Ba
12:36 PM Revision 90763c7f: Firewall log, allow filtering by interface.
Pi Ba
10:10 AM Bug #2649 (Feedback): Ipv6 Easy rule creation failing
Applied in changeset commit:b4147482efca1524c423df5219e612332444e540. Jim Pingle
03:46 AM Bug #2649 (Resolved): Ipv6 Easy rule creation failing
when trying to create an easy rule from the system firewall log for an ipv6 entry
(url :- http://192.168.x.x/easyrul...
Mark Wharton
09:37 AM Bug #2643: OpenVPN Server not deletable
Hi, sorry for introducing the issue, i recommitted my original patch (allow TUN to TAP change without reboot) with a ... Pi Ba
07:05 AM Bug #2650 (Closed): FTP helper breaks TCP sequence numbers on 2nd WAN
I am running a dual WAN setup. WAN1 is type WAN and is the default WAN, while WAN2 is type OPT. I have a FTP server o... Anonymous
06:40 AM Revision 19d61d27: Add UA support for BB PlayBook - patch by Pho Bia. Fixes #2648
Warren Baker
01:40 AM Feature #2648 (Feedback): Add "PlayBook" to the $lowres_ua check in head.inc
Applied in changeset commit:19d61d2731c1fb0baf877632e8e482bf3ff57bdd. Warren Baker

09/30/2012

10:46 PM Feature #2648: Add "PlayBook" to the $lowres_ua check in head.inc
Thanks, we'll get that added. Chris Buechler
09:44 PM Feature #2648 (Resolved): Add "PlayBook" to the $lowres_ua check in head.inc
Hello,
I've searched and learned how to manually patch /usr/local/www/head.inc (after trying the now depreciated g...
Pho Bia
09:13 PM Bug #2643: OpenVPN Server not deletable
On the new snapshot:
2.1-BETA0 (i386)
built on Sun Sep 30 11:13:36 EDT 2012
the revert is done, and the extra bla...
Phillip Davis
10:12 AM Bug #2643: OpenVPN Server not deletable
I reverted that commit. It's not such an important fix that it's worth debugging if it causes that bad of a problem. ... Jim Pingle
10:09 AM Bug #2643 (New): OpenVPN Server not deletable
Jim Pingle
02:02 AM Bug #2643: OpenVPN Server not deletable
This problem seems to have been introduced in another recent commit: https://github.com/bsdperimeter/pfsense/commit/c... Phillip Davis
03:11 PM Revision 193a8e1f: Revert "Allow for changing OpenVPN TUN to TAP device mode without reboot." -- Adds blank OpenVPN servers, see ticket #2643
This reverts commit c8bb7f1527a99c69784ab6c01d9050adcde6a8a0. Jim Pingle
02:38 PM Bug #2647 (Feedback): rc.newwanip discovers wrong WAN IP when using DHCP
Please try to reproduce this on a 2.1 snapshot. rc.newwanip and the dhclient-script have been changed quite a bit on ... Jim Pingle
12:54 PM Bug #2647 (Closed): rc.newwanip discovers wrong WAN IP when using DHCP
It seems that pfSense's _rc.newwanip_ has got problems discovering the right WAN IP after running some time.
We ar...
Christoph Filnkößl
04:09 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
+1
works in link loss situations and i think it should be implemented rather having to apply patch after every update
Bipin Chandra

09/29/2012

08:01 PM Bug #1399: rrdtool respawning too fast
post to the forum or mailing list, that doesn't have any relation to this. Chris Buechler
07:40 PM Bug #1399: rrdtool respawning too fast
Hi,
I'm using pfsense 2.0.1 on embedded (ALIX).
RRD Graphs no longer works.
System logs show :
Sep 29 20:...
Julien Desrosiers
05:39 PM Revision e3449857: CARP notifications show vip description, 'Virtual IP Addresses' page shows interface.
Pi Ba
04:38 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
The provided fix above works. Please implement this fix. Anonymous
08:10 AM Bug #2401: Mounting read-only after mounting read-write can be very slow on NanoBSD
i have a 2GB SLC based CF card and i installed the 1GB nanobsd, when using without much changes its fast but as soon ... Bipin Chandra

09/27/2012

04:55 PM Revision 680d543d: Add forgotten part of the IPsec split dns fix from yesterday
Jim Pingle
01:18 PM Revision 7a058f06: Add option to disable the dashboard auto-update check
Jim Pingle
04:43 AM Revision 96f7a687: Some more state killing refinements.
Jim Pingle

09/26/2012

07:41 PM Revision d7402222: Add option to separately specify the split dns domain list for IPsec mobile clients.
Jim Pingle
05:55 PM pfSense Packages Feature #2646 (Rejected): openvpn-client-export UAC prompt solution
People can implement that hack on their own, or use surun. The proper solution is coming with the new OpenVPN client ... Chris Buechler
03:52 PM pfSense Packages Feature #2646: openvpn-client-export UAC prompt solution
And apparently the new GUI -- https://community.openvpn.net/openvpn/wiki/RelatedProjects#WindowsclientGUI and http://... Jim Pingle
03:40 PM pfSense Packages Feature #2646: openvpn-client-export UAC prompt solution
Seems too limited, not allowing multiple configs. I wouldn't want that as the default.
Other solutions like surun ...
Jim Pingle
03:27 PM pfSense Packages Feature #2646 (Rejected): openvpn-client-export UAC prompt solution
In addition to not built-in (like PPTP) OpenVPN client has the additional UAC prompt issue.
Apparently the followi...
Dim Hatz
05:32 PM Revision 3b15c32c: Refine LB entry deletion to make sure blank entries can be removed.
Jim Pingle
05:20 PM Revision 6e9b046e: Due to the DHCP pool tag needing to be an array, rename the old LB "pool" variable to something else so it's not interpreted as an array.
Jim Pingle
01:43 PM Revision fd3515f2: Separate default gateway switching code to its own function, fix it to only operate on one address family at a time. Old method wouldn't re-set inet gateway if there was an inet6 default.
Jim Pingle
12:48 PM Revision 766cd450: Try a little harder to clear the states for the old PPP gateway
Jim Pingle
12:47 PM Revision 80c043fa: Remove states before removing the old address, or the file will be gone and the code to kill the states won't ever run.
Jim Pingle

09/25/2012

09:14 PM Bug #2645: stristr() warning repeated dozens of times during boot
I put in some basic CARP settings (and maybe not a consistent/valid set?) and got the same PHP warnings from these co... Phillip Davis
05:34 PM Bug #2645 (Resolved): stristr() warning repeated dozens of times during boot
During boot, the message:
Warning: stristr(): Empty delimiter in /etc/inc/interfaces.inc on line 3872
is repeat...
Adam Thompson
08:54 PM Revision 1be1a67a: while booting do not let carp wait for pfsync synchronization if pfsync is not enabled
Pi Ba
05:14 PM Bug #2644 (Rejected): unbound package needs re-enabled on 2.1
no idea what this even means, Unbound will not make 2.1. Chris Buechler
02:08 PM Bug #2644 (Rejected): unbound package needs re-enabled on 2.1
with unbound disabled up grade loosed gui for unbound Michael Kellogg
03:50 PM Revision 767cf960: Refine OpenVPN client/server deletion to allow for removing invalid empty entries. Fixes #2643
Jim Pingle
12:18 PM Revision f00278f1: Ticket #2635: during ipsec reload, do not generate spd for disabled ph1
Pierre POMES
11:10 AM Bug #2643 (Feedback): OpenVPN Server not deletable
Applied in changeset commit:767cf960f4f7f6f525d971f6247c663590c1637e. Jim Pingle
11:09 AM Bug #2643: OpenVPN Server not deletable
That is what the commit fixes - it will allow you to delete those entries. Jim Pingle
11:09 AM Bug #2643: OpenVPN Server not deletable

I can not delete it because, unfortunately, nothing happens. :-(. When i press to oft the X that crash my openvpn s...
Sven Timmermann
10:53 AM Bug #2643: OpenVPN Server not deletable
OK, I committed a fix, next new snapshot dated after this commit should be OK. You can then just click the X on those... Jim Pingle
07:28 AM Bug #2643: OpenVPN Server not deletable
you can e-mail it to jimp (at) pfsense (dot) org. Jim Pingle
07:19 AM Bug #2635 (Feedback): Disabling IPsec leaves SPD
This should be fixed now. Pierre POMES

09/24/2012

07:55 PM Revision 687dbc35: Merge pull request #232 from bcyrill/patch-2
Make tables sortable Jim Pingle
07:38 PM Revision 5b42a459: Make tables sortable
Cyrill B
06:50 PM Revision 4f98a4a0: Merge pull request #231 from bcyrill/patch-1
Update etc/inc/priv.defs.inc Jim Pingle
06:48 PM Revision 14551ae0: Update etc/inc/priv.defs.inc
Include privileges for Diagnostics Sockets page Cyrill B
04:51 PM Revision 4087a5f5: Merge pull request #230 from phil-davis/master
Separate backend keywords from GUI language display in captive portal Jim Pingle
04:11 PM Revision eafb21b3: Separate backend keywords from GUI language display in captive portal
When the GUI language was set to Portuguese, keywords like "default" and "unformatted" would be translated into Portu... Phil Davis
04:08 PM Bug #2643: OpenVPN Server not deletable
Jim P wrote:
> We'll need to see the openvpn-server section of your config.xml - you can remove the IPs and certs/ke...
Sven Timmermann
03:30 PM Bug #2643: OpenVPN Server not deletable
We'll need to see the openvpn-server section of your config.xml - you can remove the IPs and certs/keys if needed but... Jim Pingle
03:25 PM Bug #2643 (Resolved): OpenVPN Server not deletable
Hi,
my Version:
2.1-BETA0 (amd64)
built on Sun Sep 23 21:11:43 EDT 2012
FreeBSD 8.3-RELEASE-p4
i have tr...
Sven Timmermann
10:10 AM Feature #2629 (Resolved): Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Jim Pingle
10:08 AM Feature #2629: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Think this issue can be closed now.
Im happy with how it works now. And it has an option for pretty much everyone....
Pi Ba
12:18 AM Revision 489a6e7f: Merge pull request #228 from PiBa-NL/master
fix few issues in virtual IP edit page Jim Pingle
12:05 AM Revision 26a5f8c8: fix warning message for CARP /32 /128 masks added /31 /127 as these are also not applicable for carp which needs at least 3 IP's to function.
Pi Ba

09/23/2012

11:21 PM Revision 362c9bb0: Don't die silently if the time is too far off. Fix from: dhatz
Jim Pingle
11:05 PM Revision 9e0f8e23: fix for breaking editing carp edit selection setting.
Pi Ba
08:55 PM Revision f665130d: Merge pull request #227 from PiBa-NL/master
Diagnose\Sockets page improvements. Jim Pingle
07:52 PM Revision c75fd3db: Diagnose\Sockets page renamed and now also has button to show all socket connections, explanation moved to bottom.
Pi Ba
06:43 PM Feature #2642 (Feedback): Change ntpd config so it doesn't silently exit if time is substantially off
Committed in commit:362c9bb0 Jim Pingle
12:03 PM Feature #2642 (Resolved): Change ntpd config so it doesn't silently exit if time is substantially off
pfsense 2.1-BETA0 w/ ntpd 4.2.6p5 in a VBox VM: If host system is "suspended" overnight, the clock of the FreeBSD/pfs... Dim Hatz
11:43 AM Bug #2641 (Resolved): mac spoof on wan (pppoe) doesnt spoof
i have a pppoe connection and my isp requires to spoof a fixed mac but it doesnt seem to work on latest nanobsd alix ... Bipin Chandra
01:46 AM Revision 5dc66dff: Merge pull request #225 from PiBa-NL/master
Virtual IP Edit consistent options, "Sockets listening" page, openVPN allow change mode Jim Pingle

09/22/2012

10:44 PM Revision d41bb447: Add a "Sockets listening" page to the Diagnostics menu.
This for easy viewing of what services are bound to which interface and port.
( based on the file diag_sockets.php fr...
Pi Ba
09:26 PM Revision b1aa3804: changed "Firewall: Virtual IP Address: Edit" page to always have the same options available (if applicable) for IPalias/CARP/ProxyArp/other
Pi Ba
09:23 PM Revision c8bb7f15: Allow for changing OpenVPN TUN to TAP device mode without reboot.
Pi Ba

09/19/2012

11:58 PM Bug #2633: Captive Portal timeouts cause users to be stuck in limbo
Here's my suggested fix to it. I know it isn't pretty, but it helps
Carlos Pereira
11:43 PM Bug #2633: Captive Portal timeouts cause users to be stuck in limbo
The fix for this lies in /etc/rc.prunecaptiveportal
The script has to check not only for running instances of the ...
Carlos Pereira
11:20 PM Bug #2633: Captive Portal timeouts cause users to be stuck in limbo
After a lot of researching and poking through the code, I think I have identified the source of the problems.
It see...
Carlos Pereira
12:36 PM Feature #2640 (Needs Patch): Add a way to find where an alias is used
It would be very nice to have a way to find where an alias is used in the config. I'm currently searching for a rule... Ugo Bellavance
12:19 PM Revision ea68f6cc: We should also resync openvpn clients since they can use gateway groups too.
Jim Pingle
12:16 PM Bug #2639 (Resolved): Selecting a Country under Interfaces > (assign), PPPs tab, PPP Link type populates provider list with javascript code.
Under Interfaces > (assign), PPPs tab, add an entry, select PPP Link type, then choose a country such as United State... Jim Pingle
10:26 AM Bug #2619 (Resolved): DHCP lease delete doesnt work
Jim Pingle
03:35 AM Bug #2619: DHCP lease delete doesnt work
u can close this, its solved in the 18th September snapshot Bipin Chandra
07:57 AM Feature #1189: Gateway: Multiple monitor ips
me too would want this as i have had the same issue from long but simply tried to avoid it by disabling the monitor c... Bipin Chandra
07:22 AM Feature #1189: Gateway: Multiple monitor ips
I also would like to see the possibility to add multiple Monitor IPs. This would be a great improvement. Andreas Heckmann
12:17 AM Revision 7e3891ff: don't log here, users can define their own logging rules if they want logging
Chris Buechler

09/18/2012

04:27 PM Revision 15f47319: Merge pull request #223 from PiBa-NL/master
Firewall log, alternating color rows & sorting improvements. Jim Pingle
01:17 PM Bug #2638 (Resolved): Captive portal status widget on the Dashboard is not working
This is due to the fact that in 2.1 zones were introduced and this widget still has code like (in /usr/local/www/widg... Yuri Keren
12:07 PM Revision f6e4341d: Merge pull request #224 from phil-davis/master
Fix deleting DHCP leases Jim Pingle
09:35 AM Feature #2637 (Closed): Add ability to define dnsmasq cache size
Dnsmasq supports a maximum cache size of up to 10,000 records, but defaults to only 150. On most pfSense platforms, t... Chris Wadge
05:38 AM Revision f6fef11d: Fix deleting DHCP leases
This broke when the code was changed to suck the whole leases file into an array with:
$leases_contents = file($lease...
Phil Davis
02:56 AM Bug #2514: static routes for monitor IPs should be removed
I have just upgraded a 2.0 Final installation to "Sun Sep 16 19:35:57 EDT 2012" and everything seems to work fine now... Peter O

09/17/2012

10:41 PM Bug #2636 (Resolved): state mismatch issue on enc0 with amd64
There's some kind of state mismatch issue on enc0 with amd64. Potentially related, tcpdump on enc0 doesn't show any i... Chris Buechler
09:48 PM Feature #2634: No IPv6 networks in firewall NAT rules
Thanks for the response Seth,
You understand correctly, I'm wanting to redirect IP6 traffic. I understand with squ...
Guy B
07:34 PM Revision db4fb430: Safety belt
Jim Pingle
04:33 PM Revision 00c0720a: gitsync: Improve parameter handling to allow hyphenated options anywhere in the parameter list. (previously only allowed them at the end)
Erik Fonnesbeck
01:47 PM Revision 147b2be1: gitsync: Add --minimal parameter that installs only the updated files.
Erik Fonnesbeck
12:38 PM Revision 6fda15a9: fix for: Output from CSRF magic mangles files in Diagnostics > Edit File
http://redmine.pfsense.org/issues/2294 Darren Embry
12:33 PM Revision c578fb0f: Fix special build_commit tag that was broken from previous change to how it read the file with the commit ID.
Erik Fonnesbeck
06:49 AM Bug #2635 (Resolved): Disabling IPsec leaves SPD
After disabling a phase 1, the SPD is left in place where it should be cleared. Chris Buechler

09/16/2012

11:55 PM Feature #2634: No IPv6 networks in firewall NAT rules
Yeah, we'll need to block any ipv6 addresses in a redirect rule, it won't work.
Any nat or rdr can not span address ...
Seth Mos
05:23 PM Feature #2634 (Resolved): No IPv6 networks in firewall NAT rules
I'm using snapshot:
2.1-BETA0 (i386)
built on Sat Sep 15 16:38:08 EDT 2012
I tried adding a port forward rule t...
Guy B
11:33 PM Revision cba980f6: Add support for multiple DHCP pools within the interface's subnet, and allow most of the settings for the main range to be set specific inside the pool. (e.g. it allows setting different gateways and DNS for different pools). Still needs improved input validation to prevent overlapping ranges/pools.
Jim Pingle
10:17 AM Revision f06f7cc0: (line endings UNIX format..)
Firewall log alternating colored rows
Firewall log sortable
Fixed several sorting issues in widgets and other pages
S...
Pi Ba

09/15/2012

01:52 PM Bug #2633 (Resolved): Captive Portal timeouts cause users to be stuck in limbo
Hi Guys,
I run the internet service for a 350+ user student residence and I'm trying out the 2.1 snapshots.
Follo...
Carlos Pereira

09/14/2012

04:36 PM Revision 611b65a8: Force resync of vpns and dns even if the IP doesn't change in rc.newwanip, since we could be doing failover/failback for these services.
Jim Pingle
04:36 PM Revision 140f30ea: Add note about mac matching and media type.
Jim Pingle
12:10 PM Revision 80d30a83: Add some safety checks against empty entries
Jim Pingle
07:42 AM Feature #2241 (Feedback): DHCP - prevent dhcpd from handing out leases to certain MAC addresses
Implemented in commit:1f1a08c (and a fix in commit:80d30a8) Jim Pingle
02:26 AM pfSense Packages Bug #2632 (Rejected): Intel Quad Gigabit ET2 & Intel Quad Gigabit I350 igb could not setup receive structures
we don't control the drivers, test with newer base FreeBSD versions and report the issues to the mailing list net at ... Chris Buechler
01:55 AM pfSense Packages Bug #2632: Intel Quad Gigabit ET2 & Intel Quad Gigabit I350 igb could not setup receive structures
I forgot to mention for each interface that is active we recieve random "igb(x) could not setup receive structures" e... Matt Lehman
01:51 AM pfSense Packages Bug #2632 (Rejected): Intel Quad Gigabit ET2 & Intel Quad Gigabit I350 igb could not setup receive structures
There appears to be some sort of igb driver malfunction with 2.0.1 AMD64. We are using the 4GB NanoBSD vga build. We ... Matt Lehman
01:15 AM Revision 1f1a08c8: Allow/deny access to DHCP by partial MAC matching.
Jim Pingle

09/13/2012

04:52 PM Revision e288ddb1: Make the openvpn resync less intrusive, only trigger this if the OpenVPN interface is actually a gateway group name. Otherwise we skip.
Seth Mos
04:49 PM Revision 017817c2: Make the gateway group member check a boolean, might convert to something else at a later time so we could check group memberships.
Also launch the dyndns configure if the dyndns interface is a gateway group name, could check membership later if we ... Seth Mos
04:49 PM Revision 2223aa95: Always prepend the hostname we are working on
Seth Mos
03:46 PM Feature #2631: Highlight unapplied changes
This would be extremely hard to do.
You can always see a diff of the existing config to the previous - Diag > Back...
Jim Pingle
03:43 PM Feature #2631: Highlight unapplied changes
Sorry for forgetting to include the version. It is version: 2.0.2-RC4 (amd64), and this is specifically a request fo... Christopher Peters
03:37 PM Feature #2631 (Needs Patch): Highlight unapplied changes
I have multiple users with access to our pfsense system, and this morning I found a large red warning in the GUI indi... Christopher Peters
05:18 AM Revision 768eb89c: Make sure we process dyndns interfaces that use a failover group when processed from rc.newwanip, which just passes a interface.
Seth Mos
05:04 AM Revision cdb0df65: Add function that checks if the interface is part of a gateway group.
Seth Mos
05:02 AM Revision 1be0e2da: Reference the correct variable here, it was broken before and could never have worked.
Seth Mos

09/12/2012

04:45 PM Revision ed6df99c: Use a better link here.
Jim Pingle
04:45 PM Revision 82f6b8e0: Use a better link here.
Jim Pingle
04:26 PM Revision bca84dfb: Don't skip over wrap_vga here.
Jim Pingle
04:23 PM Revision c832f6bf: Remove the filter configure call as this could otherwise lead to a recursive filter configure.
Seth Mos
04:18 PM Revision 0066932f: Print a nice large warning on the PPTP page about it no longer being considered secure.
Jim Pingle
04:18 PM Revision 0888bdfa: Print a nice large warning on the PPTP page about it no longer being considered secure.
Jim Pingle
03:44 PM Revision 1a6f5266: Bail here so we don't make invalid rules for IPsec if this is empty.
Jim Pingle
11:47 AM Feature #2552 (Resolved): Set the timezone in setup_php_ini.sh
Seth Mos

09/11/2012

04:47 PM Revision 8736e7a1: Merge pull request #221 from j-white/master
Fixed the rendering in IE for the password management page. Jim Pingle
03:03 PM Revision fa6a3d4d: Fixed the rendering in IE. Moved the head section out of the body.
Jesse White
08:32 AM Feature #2630 (Rejected): Add SSHD logging on a new SSHD tab under STATUS > SYSTEM LOG
Per jimp's request in forum: http://forum.pfsense.org/index.php/topic,53503.0.html
Please add a new SSHD tab that ...
Jason Miles

09/10/2012

06:45 PM Revision 2643df8d: Merge pull request #220 from PiBa-NL/master
firewall log, allowing the showing of applied rule description with optional setting Jim Pingle
03:32 PM Revision 32f8552e: Show/hide toggle
Pi Ba
02:32 PM Revision 52b27268: Added a setting for configuring the firewall log to either:
-Not load descriptions
-Show descriptions in a column
-Show descriptions on a second row (after a click on 'show desc...
Pi Ba
01:59 PM Feature #2629 (Feedback): Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
I approved the request, it looks good now, thanks!
The show/hide toggle is also a good addition, and the three-way...
Jim Pingle
10:35 AM Feature #2629: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Thanks for your comments.
Made a few modifications and added a setting to allow for keeping old behavior.
And mad...
Pi Ba
01:55 AM Revision 18be4037: remove bunk input validation
Chris Buechler

09/09/2012

05:19 PM Feature #2629: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
There are people with thousands of rules in the evaluated ruleset, and there are also people on very slow hardware (t... Jim Pingle
03:31 PM Feature #2629: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Would layout attached as new screenshot be ok? !New layout proposal!
As for the performance, there is a 2000 max r...
Pi Ba
11:12 AM Feature #2629: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
I'm not opposed to having that information readily accessible, but that format isn't very easy to read. I don't know ... Jim Pingle
10:39 AM Feature #2629 (Resolved): Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw ... Pi Ba
07:15 AM Bug #2527: Miniupnpd starts but isn't working
jim thank you for staying on top of this!!! Works great now Cino .
07:12 AM pfSense Packages Bug #1907: snort
its there for 2.1 beta Cino .
07:10 AM pfSense Packages Bug #2002: snort
this has been resolved as far as I know Cino .

09/08/2012

09:41 PM pfSense Packages Bug #2602: BandwidthD - Reported Traffic / Usage is approximately Double real amount
Yup. Problem is still there.
Is this the right bug tracker to be addressing issues with the BandwidthD package for p...
Brock Prozeniuk
12:41 PM Revision a6d5e043: Changed firewall log to show the applied rule description directly on screen, also layout optimization for "Show raw filter logs".
Pi Ba

09/07/2012

05:40 PM Bug #2628 (Rejected): Lost Conection Wan
This is not a support ticket system. Please use the forum or mailing list for support issues. Jim Pingle
05:35 PM Bug #2628 (Rejected): Lost Conection Wan
Hello good afternoon I have a problem I get disconnected from the WAN side of the probe reinstalling pfsense and leav... Eduvaldo Zapata
03:51 PM Bug #2627 (Resolved): Old delegated prefixes are not removed from the LAN interface
When the LAN tracks the WAN via DHCPv6 Prefix Delegation and the WAN bounces, thus receiving a new delegated prefix, ... Anonymous
02:48 PM Feature #972: Allow adding gateways outside of interface subnet
AT&T is doing this now on their network handing off DHCP with a /32 mask with certain uverse gear like the NVG510, so... Jim Pingle
02:45 PM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
Haha, ok I had it right the first time. The key sentence from the syslog.conf man page is:
If a received message ...
Andre LaBranche
05:26 AM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
Er... upon further consideration, I don't actually know what is going on. Snort emits daemon.notice, and dnsmasq emit... Andre LaBranche
05:08 AM Bug #2626 (Resolved): Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
Took me a while to hunt this down, and it's the same issue as reported in:
http://forum.pfsense.org/index.php?topi...
Andre LaBranche

09/06/2012

06:47 PM Revision c184fa27: fix imbalanced HTML tags
hopefully continues to fix #2625 but no guarantees. Darren Embry
06:47 PM Revision 00ad21b9: fix more imbalanced HTML tags.
hopefully continues to fix #2625 but no guarantees. Darren Embry
06:47 PM Revision 59167b10: fix some imbalanced HTML tags
hopefully this will fix #2625 but this needs to be done anyway. Darren Embry
06:46 PM Revision d329d587: a few coding indentation/style fixes.
Darren Embry
06:27 PM Revision b9144088: Correct this function call, OpenVPN client killing works again, fixes #2554
Jim Pingle
05:46 PM Revision 17c0bb50: Inconsistent behavior with Alias info popup
hopefully fixes #2625
http://redmine.pfsense.org/issues/2625
Darren Embry
05:08 PM Revision 73567959: never call parseInt without a radix.
Darren Embry
02:48 PM Bug #2074 (Feedback): Changing interface IP changes interface assignment as well
This may have been corrected by the fixes for ticket #2490 - please re-test on a current snapshot. Jim Pingle
02:06 PM Bug #2625: Inconsistent behavior with Alias info popup
Those popups contain Edit links. If you somehow get a mouseout event handler on the link to close the tooltip [which... Darren Embry
01:50 PM Bug #2625: Inconsistent behavior with Alias info popup
Applied in changeset commit:c184fa273f8f575266addc38f838a31b763d3d1d. Darren Embry
01:50 PM Bug #2625: Inconsistent behavior with Alias info popup
Applied in changeset commit:00ad21b9d71a5b5cda116a6a30293999847e39e4. Darren Embry
01:50 PM Bug #2625: Inconsistent behavior with Alias info popup
Applied in changeset commit:59167b10fbe27b37c3fe9683bd58c24a4abdb732. Darren Embry
12:50 PM Bug #2625: Inconsistent behavior with Alias info popup
Applied in changeset commit:17c0bb50f81011cba034af5593efa0be3d27df1a. Darren Embry
12:48 PM Bug #2625 (Feedback): Inconsistent behavior with Alias info popup
Hopefully commit:17c0bb50 fixes this.
Darren Embry
12:17 PM Bug #2625 (Rejected): Inconsistent behavior with Alias info popup
When you mouseover an alias when viewing firewall rules, nat rules, and so on, the info box pops up showing the addre... Jim Pingle
01:44 PM Feature #2622: Allow DHCP without a range so that only static mappings may be used on an interface
Sure, we'd be open to including the patch. Jim Pingle
04:31 AM Feature #2622: Allow DHCP without a range so that only static mappings may be used on an interface
Hello,
Thanks for your response.
If I provide a patch and test this feature (dhcp without pool), is there any cha...
Aris Adamantiadis
01:40 PM Bug #2554 (Feedback): "kill client" functionality broken on OpenVPN status page
Applied in changeset commit:b91440888e0c2bd398c89155d36c4a9d050c5caa. Jim Pingle
12:22 PM Revision 9500537d: Don't add ldapcfg to racoon.conf since we're not using racoon's built-in LDAP support now. Moving to external script-based auth, see ticket #1112
Jim Pingle
04:45 AM pfSense Packages Bug #2624 (Resolved): Varnish3 Package + GUI seems broken
The Varnish3 Package + GUI seems broken. ACL is Corrupt.
Version: Latest PFSense 2.1 DEVELOPMENT snapshot
When cl...
Julian Sternberg

09/05/2012

06:52 PM Revision b16d666d: No need for these other lines on nanobsd, and it can interfere with booting on some devices.
Jim Pingle
06:36 PM Feature #1009: Active Directory group membership checking
Hi,
ive made a new auth.inc that works for me on "2.1-BETA0 (i386) built on Sun Sep 2 18:21:50 EDT 2012 " based on s...
Pi Ba
06:19 PM Bug #2623 (Closed): IPsec VPN - Phase-2 entries count wrong for disabled entries
webGUI IPsec VPN
On disabled (greyed-out) VPN tunnels, the count of Phase-2 entries is incorrect (it always shows ...
Dim Hatz
05:27 PM Bug #2555: check_reload_status consumes 100% CPU usage
I confirm the bug at least on all recent 64bit builds and in the last too:
2.1-BETA0 (amd64)
built on Tue Sep 4 16:...
Gianluca Toso
09:06 AM pfSense Packages Bug #2621: Update NUT due to CVE-2012-2944
I posted a HEADS UP message on the package forum.
http://forum.pfsense.org/index.php/topic,53308.0.html
Addition...
Jim Pingle
08:57 AM pfSense Packages Bug #2621: Update NUT due to CVE-2012-2944
(the box that I'd need to use NUT) Mathieu Simon
08:57 AM pfSense Packages Bug #2621: Update NUT due to CVE-2012-2944
Awesome Jim - I try to catch all of your explanations :-)
Let me know if you need a guinea pig, the box won't arri...
Mathieu Simon
08:54 AM pfSense Packages Bug #2621 (Feedback): Update NUT due to CVE-2012-2944
Updated binaries, reinstalled, works fine for me with my APC Back-UPS ES 450. I imagine it should work for others als... Jim Pingle
07:17 AM pfSense Packages Bug #2621: Update NUT due to CVE-2012-2944
No objections, but someone would need to check/test to ensure the config file is compatible and make any necessary ch... Jim Pingle
02:53 AM pfSense Packages Bug #2621 (Resolved): Update NUT due to CVE-2012-2944
NUT can be remotely crashed as of CVE-2012-2944
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2944
Any o...
Mathieu Simon
09:01 AM Feature #2622: Allow DHCP without a range so that only static mappings may be used on an interface
Not a bug, but a missing feature.
Allowing DHCP without a defined range would be the only feasible way to do this,...
Jim Pingle
08:53 AM Feature #2622 (Needs Patch): Allow DHCP without a range so that only static mappings may be used on an interface
Hello,
I have a range managed by a DHCP server. All the hosts in this range have a static DHCP assignment.
Each t...
Aris Adamantiadis
04:13 AM pfSense Packages Bug #2618: High CPU load, low troughput - VMware ESXi (vSphere 5.0)
Hi Robin,
You opened the bug for ESXi 5.0 and above you're talking about VMware build 768111 which seems to be VMWar...
Peter Baumann
01:10 AM pfSense Packages Bug #2618: High CPU load, low troughput - VMware ESXi (vSphere 5.0)
I see, but these people seem to have the same problem:
http://forum.pfsense.org/index.php?topic=41647.0
Robin Friberg
 

Also available in: Atom