Project

General

Profile

Activity

From 05/26/2013 to 06/24/2013

06/24/2013

11:55 PM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
Proposed fix in https://github.com/pfsense/pfsense/pull/677 Peter Linss
11:42 PM Bug #3057 (Resolved): DHCPv6 not working with Router Advertisements 'Assisted'
When selecting 'Assisted' mode for Router Advertisements, OSX clients use stateless autoconfig and do not obtain DHCP... Peter Linss
08:10 PM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
DHCPv6 reservations don't appear to be added to unbound.conf either (DHCPv4 reservations are added). Peter Linss
07:57 PM pfSense Packages Bug #3056 (Resolved): Unbound not getting IPv6 host overrides
Running latest 2.1RC with unbound 1.4.20_7 installed.
When setting host overrides in Services > DNS Forwarder the ...
Peter Linss
07:33 PM Revision 4efdada8: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
07:32 PM Revision 69937c05: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
06:18 PM Bug #3055 (Rejected): System logs not work right
Not enough information here for a valid bug report. Please start a thread on the forum and if, after assistance and d... Jim Pingle
04:37 PM Bug #3055 (Rejected): System logs not work right
I flag - > "Everything" in "Remote Syslog Contents" but not all event is send to a syslog.
In my case only the login...
Claudio Berselli
05:33 PM Revision fc1f4960: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
05:33 PM Revision 2aacbacf: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
02:40 PM Revision efe42b5a: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:40 PM Revision d13b7363: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:09 PM Bug #2627: Old delegated prefixes are not removed from the LAN interface
Tried with:
2.1-RC0 (amd64)
built on Mon Jun 24 04:05:41 EDT 2013
FreeBSD 8.3-RELEASE-p8
Boot up. WAN & LAN g...
Anonymous
12:55 PM Bug #2627 (Feedback): Old delegated prefixes are not removed from the LAN interface
Could you please check a recent snapshot? Renato Botelho
01:50 PM Bug #2878: radvd does not restart properly
I'm still seeing an issue with RADVD not restarting automatically after a dhcp renew from my internet provider (Comca... Tom M
01:01 PM Bug #2878: radvd does not restart properly
This has been working for me with the past several snapshots I've tested. Daniel Becker
12:55 PM Bug #2878 (Feedback): radvd does not restart properly
Could you please check a recent snapshot? Renato Botelho
12:12 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
This seems to have been working fine for me on Comcast Home for the past few snapshots that I've tried. After > 8 day... Daniel Becker
10:03 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Can you test again with latest snapshots and see if this is fixed? Ermal Luçi
10:00 AM Bug #3039: New vouchers doesn't sync with CARP slave
The system log would be interesting to see here Ermal Luçi
09:40 AM Bug #2887: ppp-linkdown state killing not right
Applied in changeset commit:efe42b5a05dfc7c718b04fb00391f251d846a2f2. Renato Botelho
09:40 AM Bug #2887 (Feedback): ppp-linkdown state killing not right
Applied in changeset commit:d13b7363304390736fa4686b4544319f26bdba92. Renato Botelho
06:44 AM Bug #3054: openBGPd stoped working
frustration is never a good friend :
excuse my p.s. :)
step 1 install: pfSense-LiveCD-2.1-RC0-amd64-20130618-1856...
Svetozar Urumov
06:37 AM Bug #3054: openBGPd stoped working
ok some more info :
step 1 : install pfSense-memstick-2.1-RC0-amd64-20130618-1856.img
step 2 : make all confs in Se...
Svetozar Urumov
06:40 AM Bug #3030 (Feedback): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Applied in changeset pfsense-tools:commit:0416a5113ab777964567fc30b78647b6167f8b75. Renato Botelho

06/23/2013

10:27 PM Bug #3054 (Rejected): openBGPd stoped working
not enough here to be a legit bug report, please post info to the forum or list for help. Chris Buechler
10:57 AM Bug #3054 (Rejected): openBGPd stoped working
After upgrade to :
2.1-RC0 (amd64)
built on Sat Jun 22 15:45:58 EDT 2013
openBGPd stopped working giving follo...
Svetozar Urumov
09:56 PM Revision 211d95a9: Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution.
Applied when RRD's are created.
RRA:AVERAGE:0.5:1:1200 = 20 hours of 1 minute data
RRA:AVERAGE:0.5:5:720 ...
N0YB
04:16 AM Revision 1e86f510: RRD Specify RRA and Resolution
Don't leave it up to RRD Tool to select the RRA and resolution to use.
Specify the RRA and resolution to use per the ...
N0YB
03:53 AM Revision 88ba6d31: Merge branch 'RELENG_2_1' of git://github.com/pfsense/pfsense into RELENG_2_1
N0YB

06/22/2013

11:01 AM Revision 63b69d34: System: Group manager, set max length for groupname to 16 characters
Pi Ba
10:55 AM Revision e06263e1: Merge pull request #674 from PiBa-NL/SystemGroupmanager_16charName
System: Group manager, set max length for groupname to 16 characters Ermal Luçi
12:27 AM Bug #2997: CARP and pfSync traffic issues with traffic shaping
Hi,
this should be already foreseen (http://forum.pfsense.org/index.php/topic,45045.msg344264.html#msg344264), ju...
Michele Di Maria

06/21/2013

11:06 PM Revision 51f1fc58: Use Probe Interval on gateway advanced settings
Phil Davis
10:40 PM Revision 3db408b3: System: Group manager, set max length for groupname to 16 characters
Pi Ba
11:54 AM Feature #3053 (New): Automatically add DHCP static addresses to CP passthru-mac
Add a new option to Captive Portal to automatically add static addresses configured on DHCP server to the list of pas... Wendell Borges
09:06 AM Revision b6aecb27: Merge pull request #673 from phil-davis/master
Use "Probe Interval" to describe this advanced gateway parameter Ermal Luçi
05:03 AM Bug #3052 (Rejected): Adding a static dhcp for mac address dissapears.
Cannot say if its a bug or normal behaviour. This is what i have
1 wan, 3 Vlan's
When i want to add a static ma...
Tom De Coninck
02:48 AM Revision 490cd438: Use Probe Interval on gateway advanced settings
Phil Davis
02:21 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Thanks.
I will test as soon as it's in a snapshot (im currently on 2.1RC0). Backing out the old patch already yielde...
Peter Borföi

06/20/2013

09:27 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I have placed all the changes I have made to racoon up on Github. You can find them "here":https://github.com/duchsc... David Duchscher
12:24 PM pfSense Packages Bug #3051: Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
I can confirm that bug on Snort 2.9.4.6 pkg v. 2.5.9.
pfSense 2.1 RC0
B H
09:18 AM pfSense Packages Bug #3051 (Resolved): Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
Pfsense 2.1 of 06/19/2013 17:23.
If change wansuppress on Snort, is necessary reboot Pfsense to enable the new rule...
Claudio Berselli
11:57 AM Bug #3045: NTPD crash / doesn't come up
Not any single crash with the new file. The OpenNTPD service is running rock-stable. No crash, no error in system-log... B H
04:50 AM Bug #3050 (Resolved): error loading TCP block or reject rule
Renato Botelho
04:44 AM Bug #3050: error loading TCP block or reject rule
Erik Augustsson wrote:
> Works for me
same here
Thomas Rieschl
04:28 AM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Seems correct as a patch as long as you do not get LORs.
I though this was handled in the ioctl patch code already...
Ermal Luçi

06/19/2013

11:11 PM Bug #3024: need a pipe / flowset / sched number
I think I'm close to the problem, I deleted the database files belonging to the captive portal " /var/db " and then r... Alberto Palau
06:02 PM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
It's fine to leave bandwidth blank, altq fills it using the interface bandwidth. On my tests I could reproduce the is... Renato Botelho
12:47 PM Revision 94744c27: Correct gateway down/probe interval text.
Jim Pingle
12:45 PM Revision 94fb9f2d: Correct gateway down/probe interval text.
Jim Pingle
08:42 AM Revision b7d6c7f6: Correct the comments describing the error with correct values
Ermal LUÇI
08:42 AM Revision 6870b5ce: Correct the comments describing the error with correct values
Ermal LUÇI
08:20 AM Bug #2511: DHCPv6 Shows Wrong DUID
I seem to have a similar problem.
A windows 8 client with the DUID 00:01:00:01:18:1c:59:c5:00:25:22:92:f5:43 (veri...
Jeroen van der Wal
07:02 AM Bug #3050: error loading TCP block or reject rule
Works for me Erik Augustsson
02:43 AM Bug #3047: IPSEC remote access broken in 2.03
same Problem since PFSense 2.0.2 with Android 4.1.2, 4.2, iOS 4/5.
Downgrade back to 2.0.1 and everything is fine wi...
Micha Ch
12:20 AM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability
Chris Buechler

06/18/2013

09:57 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I backed the following patch out from ipsec-tools and many of my issues when away.
https://github.com/duchscherd/p...
David Duchscher
08:19 PM Bug #3049: RAM Disk RRD Loss Vulnerability

Fix verified.

RRD backup file rrd.tgz is retained after reboot.

NOYB NOYB
05:50 AM Bug #3049: RAM Disk RRD Loss Vulnerability
Applied in changeset commit:ef01b77f6dc5e2f4ba254739a1792207e7b52a09. Renato Botelho
05:50 AM Bug #3049 (Feedback): RAM Disk RRD Loss Vulnerability
Applied in changeset commit:dc21d4d5618e5190dbc85a479489b230063450f5. Renato Botelho
07:55 PM Revision d5e4f7c9: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
07:54 PM Revision 4f0710f3: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
06:43 PM Revision 40e6086a: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:42 PM Revision 2706c79b: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:03 PM Revision 8744a113: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
06:00 PM Revision 7ddfa922: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
05:31 PM Revision 6743ab28: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:28 PM Revision a27403c4: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:01 PM Revision 850324a2: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
05:00 PM Revision 57c83fd6: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
04:01 PM Revision f03cf892: A better fix for conditionally including burst.
Jim Pingle
04:01 PM Revision c32e0581: A better fix for conditionally including burst.
Jim Pingle
03:57 PM Revision e43fa2ac: Burst of 0 is also valid
Jim Pingle
03:57 PM Revision 012cd3ba: Burst of 0 is also valid
Jim Pingle
03:53 PM Revision f1a17b1a: Only add burst if a burst is defined
Jim Pingle
03:52 PM Revision 11421996: Only add burst if a burst is defined
Jim Pingle
03:02 PM Revision f63733e0: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
03:01 PM Revision 45e12bad: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
02:54 PM Revision 5015ec4c: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:52 PM Revision 57fa7011: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:06 PM Revision bca506d4: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
02:05 PM Revision d17c7b79: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
01:50 PM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:40e6086ada6b73f6432b7ac93d4b376941028b09. Jim Pingle
01:50 PM Bug #3005 (Feedback): cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:2706c79b47373fd294446d7ab0cc25d79bd494a1. Jim Pingle
10:48 AM Revision ef01b77f: Fix #3049, set $config as global to it can be read
Renato Botelho
10:48 AM Revision dc21d4d5: Fix #3049, set $config as global to it can be read
Renato Botelho
10:00 AM Bug #3050: error loading TCP block or reject rule
Applied in changeset commit:5015ec4cd0c497ca1db68e7393d2898ba57efb0b. Jim Pingle
10:00 AM Bug #3050 (Feedback): error loading TCP block or reject rule
Applied in changeset commit:57fa70112a9ab5bec06f5dd64bf0d987dfdae159. Jim Pingle
09:19 AM Bug #3050 (Resolved): error loading TCP block or reject rule
After updating to _2.1-RC0 (amd64) built on Mon Jun 17 17:28:37 EDT 2013_ none of my TCP block rules are working anym... Thomas Rieschl
05:47 AM Bug #3045 (Feedback): NTPD crash / doesn't come up
Renato Botelho
01:02 AM Bug #3045: NTPD crash / doesn't come up
Since implement your new file yesterday, i habe no more ntpd crashes. I will report again at the end of the week. B H
02:21 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Andreas, that's not really relevant to this bug - this is specifically for making altq work with the VLAN driver, tha... Mark Uhde
01:43 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Sorry i use the latest 2.1 RC0 i386 snapshot Andreas Huser
01:41 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Hi
i'm sorry for reopening this ticket.
I have four openvpn connections and try to configure a traffic shaper wit...
Andreas Huser
01:02 AM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
I did a more in-depth analysis with tcpdumps (LAN/WAN) here:
http://forum.pfsense.org/index.php/topic,62237.msg34202...
Anonymous

06/17/2013

10:19 PM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability

When using the RAM disk option for /tmp and /var, after a reboot and RRD data is restored, the RRD backup file /cf...
NOYB NOYB
03:26 PM Revision 9507aa0e: Allow user to set interval between attempts to resolve hostnames configured on aliases
Renato Botelho
03:24 PM Revision ab3ab2ac: Allow user to set interval between attempts to resolve hostnames configured on aliases
Renato Botelho
03:06 PM Feature #3048 (Resolved): Pre-download packages to reduce downtime during upgrade process?
Not sure if this is possible under the current system...
If it is possible to determine what version of [a] package[...
Adam Thompson
01:25 PM Revision b48e2e6b: Include the burst size in the limiter. Submitted-by: http://forum.pfsense.org/index.php/topic,62470.0.html
Ermal LUÇI
01:25 PM Revision 4981f881: Include the burst size in the limiter. Submitted-by: http://forum.pfsense.org/index.php/topic,62470.0.html
Ermal LUÇI
01:11 PM Bug #3047: IPSEC remote access broken in 2.03
As before, same with IOS. Robert Holmes
12:47 PM Bug #3047: IPSEC remote access broken in 2.03
Cisco VPN client is known to be broken when connecting to pfSense (and it's a violation of their license to do so usi... Jim Pingle
12:41 PM Bug #3047: IPSEC remote access broken in 2.03
I don't understand why it doesn't work for me in 2.03 - no config changes whatsoever between 2.02 and 2.03. I also j... Robert Holmes
12:22 PM Bug #3047: IPSEC remote access broken in 2.03
I used your exact IPsec config (aside from fixing the lifetimes to match the documented suggested values), and I am a... Jim Pingle
10:15 AM Bug #2928: Authentication attempts against multiple radius servers should stop when the first reject is received.
For two factor authentication , you need to use Access-Challenge response from your radius server, and use it to proc... Tuyan Ozipek
10:01 AM Revision 84a27e31: fix dhcp static mapping/client identifier validation
Will Boyce
09:27 AM Revision 615d7f0a: Add warning comment about missing IPv6 implementation
Ermal LUÇI
09:25 AM Revision fafcae72: Add used binary
Ermal LUÇI
09:25 AM Revision 70a9e131: Remove referenced binary not used anymore
Ermal LUÇI
09:25 AM Bug #3045: NTPD crash / doesn't come up
OK it's started now. I had to go Services - NTP - press Save button. Then press the restart service button. Now it's ... B H
09:22 AM Bug #3045: NTPD crash / doesn't come up
After this procedure i can't start the NTPD service. B H
09:16 AM Bug #3045: NTPD crash / doesn't come up
I've built ntpd binaries with debug symbols, there are binaries for 2.0.3 and 2.1, i386 and amd64:
ntpd-2.0.3-amd64
...
Renato Botelho
03:33 AM Bug #3045: NTPD crash / doesn't come up
Crashed again. File attached. B H
09:25 AM Revision bf8c7971: Remove referenced binary not used anymore
Ermal LUÇI
09:24 AM Revision 8cea45e4: Remove unused code and spurious alert
Ermal LUÇI
09:23 AM Revision 891dfb24: Use file_put_contents for simplicity and readbility
Ermal LUÇI
09:23 AM Revision 4cbc0ae9: Remove unused code and spurious alert
Ermal LUÇI
09:23 AM Revision de82ec90: Use file_put_contents for simplicity and readbility
Ermal LUÇI
09:00 AM Revision 10054843: * Use when needed the family for get_real_interface
* During dhcp setup use -n for cp to avoid coping uselessly Ermal LUÇI
08:59 AM Revision 06886ae3: * Use when needed the family for get_real_interface
* During dhcp setup use -n for cp to avoid coping uselessly Ermal LUÇI
08:27 AM Revision f960f9dd: Use family parameter for v6 to get correct interface
Ermal LUÇI
08:26 AM Revision be544a5e: Use family parameter for v6 to get correct interface
Ermal LUÇI
08:13 AM Revision 10ce1ac1: Remove useless variable and also correct some style
Ermal LUÇI
08:12 AM Revision 8026f19c: Remove useless variable and also correct some style
Ermal LUÇI
08:06 AM Revision ca2b90ec: Do not do the same tricks here that are done on get_real_interface but just call the function directly
Ermal LUÇI
08:06 AM Revision d90ea5ff: Get interface from inet6 domain
Ermal LUÇI
08:06 AM Revision 08efe4e6: Use trim rather than str_replace. Also no need to sleep anymore since dhcp will configure first the interface
Ermal LUÇI
08:05 AM Revision 81d0281d: Do not do the same tricks here that are done on get_real_interface but just call the function directly
Ermal LUÇI
08:00 AM Revision 314b9b2c: Get interface from inet6 domain
Ermal LUÇI
07:59 AM Revision a432c132: Use trim rather than str_replace. Also no need to sleep anymore since dhcp will configure first the interface
Ermal LUÇI
07:55 AM Revision 6756d9ee: Remove unreferenced binaries. correct some formatting and also to make function clear to track correct the curly placement
Ermal LUÇI
07:55 AM Revision 50a88d93: Provide full path to route binary
Ermal LUÇI
07:55 AM Revision 85a389c9: Provide full path to route binary
Ermal LUÇI
07:54 AM Revision 1944af41: Remove unreferenced binaries. correct some formatting and also to make function clear to track correct the curly placement
Ermal LUÇI
07:44 AM Revision 12f77b03: Provide full path to route binary
Ermal LUÇI
07:43 AM Revision 59b99089: Provide full path to route binary
Ermal LUÇI
06:53 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Hmm, nevermind, it seems to include 'ns-cert-type server' nowadays, that should suffice. Mike Noordermeer
06:46 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Nowadays Pfsense seems to be able to generate server certificates, so I don't see any reason to not add 'remote-cert-... Mike Noordermeer
05:39 AM Revision af600fe2: Don't flip the IPv6 allow setting just because people are upgrading. Just upgrading versions shouldn't change this behavior. As much as most of us would like people to start deploying IPv6, the vast majority aren't going to be immediately post-upgrade, and changing this can change the firewall policy behavior by allowing v6 that previously wasn't allowed. Upgrades should never change the firewall behavior like that. At the time it was done, everyone using the 2.1 code base was using it for IPv6, so of course it tripped up quite a few people.
Chris Buechler
05:32 AM Revision 4cdf35a4: Don't flip the IPv6 allow setting just because people are upgrading. Just upgrading versions shouldn't change this behavior. As much as most of us would like people to start deploying IPv6, the vast majority aren't going to be immediately post-upgrade, and changing this can change the firewall policy behavior by allowing v6 that previously wasn't allowed. Upgrades should never change the firewall behavior like that. At the time it was done, everyone using the 2.1 code base was using it for IPv6, so of course it tripped up quite a few people.
Chris Buechler
05:24 AM Revision 878454b8: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:24 AM Revision 891ecd18: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:23 AM Revision 9a0a9fc1: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:16 AM Revision a6c03297: add MSS clamping to setup wizard. Now that MTU and MSS are separate, the MTU description was wrong, and both need to be there.
Chris Buechler
05:15 AM Revision 7b79e0cb: add MSS clamping to setup wizard. Now that MTU and MSS are separate, the MTU description was wrong, and both need to be there.
Chris Buechler

06/16/2013

11:21 PM Revision 5fb01c77: Revert "Revert "Fix gateway quality rrd to have the correct granularity and be consistent with the pfSense graphs set.""
This reverts commit 304ea841cff40aacaac084a0eb6c145ddd034303. N0YB
11:15 PM Revision 304ea841: Revert "Fix gateway quality rrd to have the correct granularity and be consistent with the pfSense graphs set."
This reverts commit a8d262f63c4574f40f5f299a2e9f746986dc966a.
put the create_gateway_quality_rrd function in rrd.inc...
N0YB
08:08 PM Bug #3024: need a pipe / flowset / sched number
Another detail is that when the error happens it creates a single limit like the follow.
Limiters:
00001: 262.140...
Alberto Palau
05:14 PM Bug #3047: IPSEC remote access broken in 2.03
You should have enough to re-create it on a pfSense box, but attached is the info you requested. Also, when the VPN ... Robert Holmes
12:20 PM Bug #3047: IPSEC remote access broken in 2.03
Still not enough information. Most importantly we need the IPsec log entries (I forgot to mention that previously) fr... Jim Pingle
11:33 AM Bug #3047: IPSEC remote access broken in 2.03
Forum link is here: http://forum.pfsense.org/index.php/topic,62209.msg341320.html
I didn't get any feedback so I ope...
Robert Holmes
10:58 AM Bug #3047 (Feedback): IPSEC remote access broken in 2.03
There is not nearly enough information here for a valid bug report. Include details about your exact config (every op... Jim Pingle
10:50 AM Bug #3047 (Closed): IPSEC remote access broken in 2.03
In pfSense 2.0 through 2.02, my configuration for remote IPSEC access (like my iPhone) worked fine. IPSEC with Mobil... Robert Holmes
01:39 PM Bug #3045: NTPD crash / doesn't come up
I'm also seeing this every couple of days and have also attached file. David Williams
07:57 AM Revision 449f1dd2: allow defining dhcp static mappings using dhcp-client-identifier
Will Boyce

06/15/2013

10:35 AM Bug #3045: NTPD crash / doesn't come up
The file is attached. B H
01:12 AM Bug #3045: NTPD crash / doesn't come up
If anyone tells me where the ntpd core crash dump is located, sure. B H
12:07 AM Revision e8ddd3a8: TCP flags are valid on any type of rule, don't skip them on block or reject rules
Chris Buechler
12:06 AM Revision bcd94190: TCP flags are valid on any type of rule, don't skip them on block or reject rules
Chris Buechler

06/14/2013

08:07 PM Bug #3046 (Resolved): Fatal error: Call to undefined function get_interface_ip() in /usr/local/captiveportal/radius_authentication.inc on line 56
When using Radius authentication I get this immediately after logging in. My password is accepted, then I receive an... orangepeel beef
07:48 PM Revision 664f9f3b: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
07:34 PM Revision 2ca43251: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
07:33 PM Revision df78d8cc: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
06:44 PM Revision c9322c5c: Allow queues to be deleted, it fixes #3037
Renato Botelho
06:44 PM Revision a22537c7: Allow queues to be deleted, it fixes #3037
Renato Botelho
04:32 PM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
not true except where it causes problems with an upstream ARP cache, which we can't do anything about. Disable/enable... Chris Buechler
12:46 AM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
Two nodes with CARP outside and CARP inside.
Outbound SNAT is done via the outside virtual IP.
Changing the vhid of...
Todor K
02:50 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:664f9f3b919f970fb77c66cc4c5c3445081d5f25. Renato Botelho
02:40 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:2ca432514e09e5388f1786f0f6c6d977d3254533. Renato Botelho
02:40 PM Bug #3034 (Feedback): Security FLAW in pfSense Wireless Found
Applied in changeset commit:df78d8cc1890f19702e3e78bb3c5a583ada52356. Renato Botelho
01:50 PM Bug #3037: Unable to delete PRIQ queues
Applied in changeset commit:c9322c5ceb272a3b51a4cd2f737d268cde3584c7. Renato Botelho
01:50 PM Bug #3037 (Feedback): Unable to delete PRIQ queues
Applied in changeset commit:a22537c73c6a1301b9e2656bfaa4382b93314a55. Renato Botelho
12:45 PM Revision d60629b0: Update list of mobile service providers
Renato Botelho
12:44 PM Revision 6b7c0fef: Update list of mobile service providers
Renato Botelho
12:26 PM Bug #3045: NTPD crash / doesn't come up
Is there a ntpd core with crash dump that you can share? It could help us to identify the issue. Renato Botelho
11:11 AM Bug #3045 (Resolved): NTPD crash / doesn't come up
The NTP services crashes a lot, reason unknown for me.
The System Logs says:
_kernel: pid 35663 (ntpd), uid 0: ex...
B H
11:02 AM Bug #3044: SSHD failed to start.
http://forum.pfsense.org/index.php/topic,63435.0.html Basel G.
08:59 AM Bug #3044 (Rejected): SSHD failed to start.
Not enough information here. Please post in the forum for assistance in finding the cause of the error. If a legitima... Jim Pingle
06:11 AM Bug #3044 (Rejected): SSHD failed to start.
php: : The command '/usr/sbin/sshd' returned exit code '1', the output was 'Could not load host key: /etc/ssh/ssh_hos... Basel G.

06/13/2013

08:48 PM Revision 654ed9e0: Update the default firmware URL (it was still pointing to HEAD on RELENG_2_1)
Jim Pingle
05:13 PM Revision 94860e9e: Fix exec perms on mail.php
Jim Pingle
05:12 PM Revision fd5efd38: Fix exec perms on mail.php
Jim Pingle
05:05 PM Revision dd16aadf: Add a simple CLI mail script capable of sending an SMTP message using echo/piped input, e.g. ifconfig -a | mail.php -s"ifconfig output"
Jim Pingle
05:05 PM Revision 7c845149: Split actual SMTP send into its own function.
Jim Pingle
05:03 PM Revision 185f24c3: Add a simple CLI mail script capable of sending an SMTP message using echo/piped input, e.g. ifconfig -a | mail.php -s"ifconfig output"
Jim Pingle
04:52 PM Revision 24160e3d: Merge pull request #670 from francisuk/patch-1
EAOrigin.pat - Traffic Sharping Layer 7 Ermal Luçi
04:52 PM Revision 95dfe4f5: Split actual SMTP send into its own function.
Jim Pingle
04:44 PM Revision 4e79fb9a: EAOrigin.pat - Traffic Sharping Layer 7
The EA Store is now Origin, Tested and works (for now) will make changes if i come to anything useful. francisuk
04:19 PM Revision f0992686: Add the ability to disable Growl or SMTP notifications but keep their settings intact. Remove automatic test messages on save. Add individual test buttons for Growl and SMTP that work even if the service(s) are disabled.
Jim Pingle
04:19 PM Revision 8a0f8732: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
04:17 PM Revision 48b86f62: Add the ability to disable Growl or SMTP notifications but keep their settings intact. Remove automatic test messages on save. Add individual test buttons for Growl and SMTP that work even if the service(s) are disabled.
Jim Pingle
03:39 PM Bug #2882: 6RD not working in latest snapshots
Hi Ermal
Here is the output of the 2 commands you asked me to run on my Jan 18th build where 6RD works:
http://...
Will Wainwright
01:24 PM Bug #2882: 6RD not working in latest snapshots
And that seemed to have been a user error on my part.
My IPv6 firewall rule on LAN had default (ipv4 dhcp) gateway...
Captain Haddock
01:14 PM Bug #2882: 6RD not working in latest snapshots
Ermal Luçi wrote:
> You are talking about tracking interfaces or 6rd tunnel here?
>
> radvd has nothing to do wit...
Captain Haddock
11:51 AM Bug #2882: 6RD not working in latest snapshots
Will Wainwright wrote:
> Hi Chris,
>
> I'm sorry to report that it has not fixed the issue for me.
>
> As alwa...
Ermal Luçi
11:51 AM Bug #2882: 6RD not working in latest snapshots
You are talking about tracking interfaces or 6rd tunnel here?
radvd has nothing to do with 6rd in this ticket.
...
Ermal Luçi
07:49 AM Bug #2882: 6RD not working in latest snapshots
This was seen in log after reboot:
Jun 13 13:29:23 radvd[49436]: resuming normal operation
Jun 13 13:29:23 radvd[...
Captain Haddock
07:47 AM Bug #2882: 6RD not working in latest snapshots
I just tried this out on:
2.1-RC0 (amd64)
built on Wed Jun 12 18:24:47 EDT 2013
FreeBSD 8.3-RELEASE-p8
Afte...
Captain Haddock
03:24 PM Bug #3042: CARP interface handling
This seems like bad news. PfSense with the current carp interface-based failover seemed like an excellent way to do t... Jupiter Vuorikoski
03:10 PM Bug #3042: CARP interface handling
Also newcarp in FreeBSD 10.x does away with the interface notion entirely so I'm not sure it's a viable request for t... Jim Pingle
03:09 PM Bug #3042: CARP interface handling
It's too late for more 2.1 features, removing 2.1 target. Jim Pingle
03:08 PM Bug #3042 (Closed): CARP interface handling
Currently PfSense handles carp interfaces as Layer 3 interfaces with a static IP-address on the created interface. Ho... Jupiter Vuorikoski
02:18 PM Bug #2526: Limiter appears to break IPv6 connectivity
This problem appears to be present in the Wed Jun 12 06:19:03 EDT 2013 build. IPv6 Traffic hits the limiter as shown ... Alex Fox
12:40 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:3e217b8208cdba17060a72a9ccb5fb7ebff9ed25. Renato Botelho
12:30 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:9c0a39f717a04def5d6c0260eb74a7cd0cde8b17. Renato Botelho
11:30 AM Feature #687 (Resolved): Test Button for Growl Notifications
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
11:29 AM Todo #1139 (Resolved): Email notification test button
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
10:17 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Not enough information here for a valid bug report. Please post in the forum where someone can assist you in diagnosi... Jim Pingle
10:15 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Crash report begins. Anonymous machine information:
amd64
8.3-RELEASE-p8
FreeBSD 8.3-RELEASE-p8 #1: Wed Jun 12 ...
Alberto Palau
09:49 AM Feature #2757: CDP/ISDP/LLDP support.
Yeah! It would be great to have CDP in pfsense! Todor K

06/12/2013

10:20 PM Bug #2882: 6RD not working in latest snapshots
Hi Chris,
I'm sorry to report that it has not fixed the issue for me.
As always, please let me know if there's ...
Will Wainwright
01:08 AM Bug #2882: 6RD not working in latest snapshots
confirmed working for me again on the latest snapshot. Will leave this as is for feedback from others for now. Chris Buechler
05:56 PM Revision 00a695c8: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
05:46 PM Revision 46b323f0: Actually do not allow the loop to continue. Related to Ticket #1928
Ermal LUÇI
05:46 PM Revision fb0eb20b: Actually do not allow the loop to continue. Related to Ticket #1928
Ermal LUÇI
05:38 PM Revision 82b7f50a: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
05:16 PM Revision 1f36db1b: Merge pull request #669 from francisuk/patch-1
SWF Ermal Luçi
02:12 PM Feature #3040 (Closed): User friendly firewall log reading
Most of that is already done in 2.1's firewall log view/filtering. The ones that aren't there yet aren't really feasi... Jim Pingle
01:59 PM Feature #3040 (Closed): User friendly firewall log reading
It would be great if the firewall logs could be more debug-friendly:
- have source and destination ports in separate...
Todor K
12:48 PM Bug #3039: New vouchers doesn't sync with CARP slave
Yup, I thought it could be scheduled somehow, but it didn't happen in the next few hours. Todor K
12:45 PM Bug #3039: New vouchers doesn't sync with CARP slave
This is not immediate.
You are sure that you waited enough for the replication to happen?
Ermal Luçi
11:12 AM Bug #3039 (Resolved): New vouchers doesn't sync with CARP slave
Issuing new vouchers on master node is not automatically synced with CARP slave node.
When I go to Services>Captive ...
Todor K
12:16 PM Bug #3015 (Resolved): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Renato Botelho
12:10 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
It's the expected behaviour, if you don't have zones, status menu won't show up. Renato Botelho
11:01 AM Bug #3038 (Resolved): CARP master not stopping slave's Captive portal
Having CARP active with two nodes, when I start Captive service on master it starts it on the slave node too.
But st...
Todor K
07:05 AM Revision 1da5d1d7: Actually try to get the real interface for v6 family to correctly get stf(virtual) interfaces
Ermal LUÇI
07:05 AM Revision 8984529d: Actually try to get the real interface for v6 family to correctly get stf(virtual) interfaces
Ermal LUÇI
02:28 AM Revision 8d1eb49e: SWF
As said on the pFsense forum http://forum.pfsense.org/index.php/topic,62863.0.html It works and tested by me. francisuk

06/11/2013

08:36 PM Revision 43b9f062: Merge pull request #668 from mdima/RELENG_2_1
Status-Queues: Get the stats gauge for PPS or bandwidth Edit (RELENG_2_1) Ermal Luçi
08:18 PM Revision e59bd273: Status-Queues: Get the stats gauge for PPS or bandwidth Edit
Let the user select the values to show in the stats gauge between PPS and bandwidth. Michele Di Maria
07:31 PM Revision 8959f2fc: Correct the command for setting the 6rd gw
Ermal LUÇI
06:33 PM Revision f0f714c5: Correct the command for setting the 6rd gw
Ermal LUÇI
02:08 PM Bug #2882 (Feedback): 6RD not working in latest snapshots
should work with tomorrow's snapshot. Chris Buechler
01:55 PM Bug #3037 (Resolved): Unable to delete PRIQ queues
If you use PRIQ, you cannot delete any queues, even ones that were created manually. The delete button does not appea... Jim Pingle
11:42 AM pfSense Packages Bug #3036 (Resolved): Small web interface bug
Hi there!
That's my first bug report and I hope it's well done :)
Services>Snort
Add or edit interface>Alert Set...
Todor K
10:15 AM Bug #3020: HFSC Priority
Heh that is just a copy/pasto from implementation.
Will probably fix that.
Ermal Luçi
10:02 AM Revision 7fdd0c73: Wait 1 second before starting the other dhcp6c since pkill does not wait for the process to exit
Ermal LUÇI
10:02 AM Revision b90ae531: Wait 1 second before starting the other dhcp6c since pkill does not wait for the process to exit
Ermal LUÇI

06/10/2013

08:43 PM Revision 89784e55: Do better checks and do not include an interface that will be skipped to the known ifaces
Ermal LUÇI
08:43 PM Revision 60c05056: Do better checks and do not include an interface that will be skipped to the known ifaces
Ermal LUÇI
06:56 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I just tested this again on a fresh OVA. I found that starting from a fresh install (i.e. no zones), creating a zone,... Christian McDonald
03:47 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
it shouldn't show up anywhere when there are no zones defined, I've noticed that changed in 2.1. In 2.0.x and previou... Chris Buechler
03:32 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can only reproduce that when I have no zones defined. If I have a zone defined, it always shows up for me. Jim Pingle
03:30 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Christian McDonald wrote:
> I can reproduce this on two pfSense boxes each running:
>
> 2.1-RC0 (amd64)
> built...
Renato Botelho
11:06 AM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can reproduce this on two pfSense boxes each running:
2.1-RC0 (amd64)
built on Thu Jun 6 21:08:57 EDT 2013
Christian McDonald
06:28 AM Bug #3035 (Feedback): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Not reproducible here, as you can see on attached screenshot. Renato Botelho
06:58 AM Revision c848b448: Merge pull request #667 from mdima/master
Status-Queues: Get the stats gauge for PPS or bandwidth Ermal Luçi
06:47 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
Seems like a local issue, I could not reproduce. You should try to get help on forums and mailing lists to try to fig... Renato Botelho
06:30 AM Bug #3034: Security FLAW in pfSense Wireless Found
What is the length of the password you got the issue? Renato Botelho

06/09/2013

10:27 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
!http://i.imgur.com/SgaFqaO.png! Christian McDonald
10:24 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
When viewing the Captive Portal Status, the menu item for Status->Captive Portal Disappears
Steps to reproduce:
...
Christian McDonald
06:43 PM Bug #3034 (Resolved): Security FLAW in pfSense Wireless Found
I have found a security flaw in pfSense wireless. If you enable WPA2 for security and use a password for the pre shar... Steven Anderson
09:33 AM Revision 87428ee8: Status-Queues: Get the stats gauge for PPS or bandwidth
Let the user select the values to show in the stats gauge between PPS and bandwidth. Michele Di Maria

06/08/2013

05:24 PM Revision f57e4181: Replace hardcoded path by vardb_path
Renato Botelho
05:08 PM Bug #3033 (Rejected): Static IPv6 route to OpenVPN tunnel ignored
I have an openvpn tunnel to a remote server which works correctly for IPv4 traffic but not for IPv6. When the remote ... Lakin Lowrey
02:18 PM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
test on 2.1 and report more info on forum if you can still replicate Chris Buechler
03:17 AM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
hi
in my 2.0.3 amd64 captive portal last activity was periodically (every minutes?) reset to the system boot time:...
Fabio Faro
03:32 AM Bug #2752: Captive Portal Last Activity isn't update anymore --> idle timeout just after login
i have two installation with 2.0.3 but the problem still exist.
i opened a new segnalation (3032)
thx
Fabio Faro

06/07/2013

02:27 PM Bug #3020: HFSC Priority
Ermal Luçi wrote:
> HFSC does not have notion of priority.
Ok, sorry for this report but I Sugere remove or corre...
Julien Bénic
11:35 AM Feature #3031 (Resolved): Message is false after changing Hardware Checksum Offloading setting
It seems that appliance needs to reboot after changing the advanced networking setting.
System -> Advanced, click ...
c vt
11:14 AM Bug #3030 (Resolved): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
If you are using LAGG+VLAN interfaces (e.g. lagg0_vlan10) in the shaper wizard, the wizard does not fill in the bandw... Jim Pingle
03:17 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Having similar issues:
2.1 RC0 (symptoms started from 2.03 on as far as i can remember)
Policy Generation > Uni...
Peter Borföi
03:12 AM pfSense Packages Bug #999: vhosts does not show up as started
Hi!
Could you tell us how to fix it.
I think two years it's so much time to fix this little problem (talking ab...
Net Vicious

06/06/2013

11:44 PM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Thanks a lot for your time and sorry for the useless ticket opening. Imrane Dessai
08:45 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
IP Alias VIPs don't work that way, but proxy ARP VIPs are not and cannot be compatible in the way you describe.
On...
Jim Pingle
08:43 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Ip Alias can't expand a whole network withing a single line of conf
When configuring a Proxy ARP you can specify a...
Imrane Dessai
08:28 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
no need. IP alias or more CARP. Chris Buechler
07:46 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
Hi,
We are using a cluster pfSense to NAT 1:1 two network.
I need to make Proxy ARP VIP to bind to CARP Interfa...
Imrane Dessai
05:55 PM Revision 39b84ccc: Allow localhost IP Alias VIPs to sync, too
Jim Pingle
05:55 PM Revision 56bf3ef1: Allow selecting "Localhost" as an interface for IP Alias VIPs - this way you can make IP Alias VIPs to use for binding in a routed scenario with CARP without creating an IP conflict.
Jim Pingle
05:54 PM Revision 48c16cab: Allow localhost IP Alias VIPs to sync, too
Jim Pingle
05:50 PM Revision 19d90bce: Allow selecting "Localhost" as an interface for IP Alias VIPs - this way you can make IP Alias VIPs to use for binding in a routed scenario with CARP without creating an IP conflict.
Jim Pingle
04:53 PM Feature #3029 (Resolved): DHCPv6 Server/RA page should list interfaces that are configured to track DHCP-PD
The configuration page for the DHCPv6 server and router advertisements currently only lists those interfaces that hav... Daniel Becker
04:31 PM Bug #3028 (Resolved): Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
I notice that configuring DHCP-PD starts a dhcpd server on the tracking (LAN) interface that serves up the delegated ... Daniel Becker
04:01 PM Bug #2412 (Resolved): inbound 6to4 traffic does not work in pf
Ermal Luçi
12:55 PM Bug #2412: inbound 6to4 traffic does not work in pf
I can confirm that this is working as intended. Thank you for fixing it. We are mainly using this to test ipv6 capabi... Richard Adams
02:08 PM Bug #3027 (Resolved): input_errors2Ajax function
In various places input_errors2Ajax() is used. However this function doesn't exist.
I'm assuming the original intent...
Warren Baker
10:22 AM Bug #3026: not all interfaces will get their designated IP after I add an IP to an interface
What you are saying is you go and set a static ip to an interface and the interface didn't get that IP address config... Renato Botelho
09:33 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
When I add an IP to an interface my pfsense will become unresponsive for a minute.
On Zabbix I can see the system lo...
frater fenantius
03:36 AM Bug #3016 (Resolved): IPsec client (or branch office) can't access to Internet over VPN gateway
Chris Buechler
03:29 AM Bug #3023 (Rejected): Snort + Intel NIC not working on 2.1 RC0
probably promiscuous broken in the 8.3 fxp driver. There's another ticket open to back port a newer driver. Chris Buechler
02:11 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Same problem here running:
2.0.3-RELEASE (amd64)
Client can connect OK for the first session but then after dis...
Ignat Esso

06/05/2013

03:37 PM Bug #3024 (Rejected): need a pipe / flowset / sched number
I am experiencing a bug in the captive portal, it happens every 3 days or so, this ruling requires me to reinstall pf... Alberto Palau
02:54 PM Bug #3023 (Rejected): Snort + Intel NIC not working on 2.1 RC0
I have used Snort + Intel NIC (as WAN interface) successfully on pfSense 2.03 before. I cannot get it to work with 2.... Victor Kwong
02:11 PM Revision 2abd3885: Bump this so it's distinct in case we need it. At the very least so people who have run gitsync to RELENG_2_0 are visibly different from a stock version.
Jim Pingle
02:10 PM Revision 79549465: Fix up invalid/old .tcshrc for 2.0.x.
Jim Pingle
11:05 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Fix looks and works correctly
2.1-RC0 (amd64)
built on Tue Jun 4 20:54:59 EDT 2013
FreeBSD 8.3-RELEASE-p8
Serguei Leontiev
07:48 AM Bug #3022 (Resolved): OpenVPN does not failover to the 2nd configured LDAP auth.server
More details:
http://forum.pfsense.org/index.php/topic,62570.msg337904.html#msg337904
It might be a limitation of...
Alex Kolesnik
07:42 AM Bug #3020 (Rejected): HFSC Priority
HFSC does not have notion of priority. Ermal Luçi
04:27 AM Bug #3020 (Rejected): HFSC Priority
Hi,
The priority range for HFSC is 0 to 7. Priority 0 is the lowest priority for the least important data. When no...
Julien Bénic

06/04/2013

06:46 PM Bug #3019 (Rejected): Realtek 8168 Gigabit Ethernet
no telling whether it's a bug from that, but probably not. Please post to the forum or mailing list for help. Only sp... Chris Buechler
06:35 PM Bug #3019 (Rejected): Realtek 8168 Gigabit Ethernet
I am not sure if this is a bug but you can close this if not.
Whenever I am copying big data from my network to my...
Patrick Vanguardia
06:04 PM Revision 00a7438c: Add the 6rd gateway information
Ermal LUÇI
06:04 PM Revision aa78b769: Add the 6rd gateway information
Ermal LUÇI
11:26 AM Revision 50d3ed9c: Also consider 0.0.0.0/0 here since it fails on is_subnet() but is a valid/special config. Fixes #3016
Renato Botelho
11:25 AM Revision c766d411: Remove extra parenthesis
Renato Botelho
11:24 AM Revision 4eb3ac52: Also consider 0.0.0.0/0 here since it fails on is_subnet() but is a valid/special config. Fixes #3016
Renato Botelho
08:49 AM Feature #3018 (Resolved): Can't disable autogenerate SPD rules
Checkbox "System->Advanced->Anti-lockout" (Disable webConfigurator anti-lockout rule)
don't affect for spd.conf gene...
Serguei Leontiev
06:46 AM Revision 2058ed15: Merge pull request #666 from chrostek/master
Fix for CURL options (Custom DynDNS) Ermal Luçi
06:30 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Applied in changeset commit:50d3ed9c3c76d16a88d801ded20f4db9e7f6e915. Renato Botelho
06:30 AM Bug #3016 (Feedback): IPsec client (or branch office) can't access to Internet over VPN gateway
Applied in changeset commit:4eb3ac52b07533c26a1ebf3e496d25669629a038. Renato Botelho

06/03/2013

05:48 PM Revision d9bdc020: Correction on last commit (CURL options)
My last commit only worked on "Save & Force Update" but not on a
reconnect. Fixed that
Sebastian Chrostek
12:38 PM Revision 50813d24: vpn.inc calls functions from ipsec.inc but doesn't actually include it in all cases where it's needed.
Jim Pingle
12:38 PM Revision 90df9a99: vpn.inc calls functions from ipsec.inc but doesn't actually include it in all cases where it's needed.
Jim Pingle
12:24 PM Revision d4090fbf: Correct mouseover description for adding a certificate. Fixes #3017
Jim Pingle
12:24 PM Revision 6b53736d: Correct mouseover description for adding a certificate. Fixes #3017
Jim Pingle
12:23 PM Revision ae3caa3d: Correct mouseover description for adding a certificate. Fixes #3017
Jim Pingle
07:30 AM Bug #3017: Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:d4090fbfe00f2cdac17a4f7e8f89a43a6d1728eb. Jim Pingle
07:30 AM Bug #3017: Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:6b53736d3beaef6d536bbcaf10b07865fd53248d. Jim Pingle
07:30 AM Bug #3017 (Feedback): Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:ae3caa3d83d5d33ab17cf8a4336621d364c051c5. Jim Pingle
07:03 AM Revision 33682de2: Merge pull request #664 from chrostek/master
Added CURL options to custom DynDNS Ermal Luçi

06/02/2013

11:58 PM Bug #3017 (Resolved): Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
System - Cert Manager - Certificates - +
The hovering text shows "add or import ca" (identical to the CA page) inste...
Uni Tronus
10:09 PM Bug #3012: Bug in full backup size computation and/or display
Sorry I meant gzip 1.3.12 Jerome Alet
10:08 PM Bug #3012: Bug in full backup size computation and/or display
Nothing to do with this particular backup file, since the problem is there each time we do a new full backup. Most pr... Jerome Alet
08:21 PM Bug #3012 (Closed): Bug in full backup size computation and/or display
something wrong with that backup file, or maybe with gzip itself. Nothing we can do either way, it does work correctl... Chris Buechler
07:28 PM Bug #3012: Bug in full backup size computation and/or display
... Jerome Alet
03:47 AM Revision d9f2de9a: DHCP Server enable/disable change needs filter_configure
When DHCP Server is enabled or disabled on an interface, the filter rules should change to include or not mention DHCP. Phil Davis
03:47 AM Revision 91523382: Merge pull request #665 from phil-davis/master
DHCP Server enable/disable change needs filter_configure Chris Buechler

06/01/2013

05:18 PM Revision 6c124212: DHCP Server enable/disable change needs filter_configure
When DHCP Server is enabled or disabled on an interface, the filter rules should change to include or not mention DHCP. Phil Davis
12:37 PM Revision aa79f351: Added CURL options to Custom DynDNS
Added the options for CURLOPT_IPRESOLVE and CURLOPT_SSL_VERIFYPEER in
the webinterface for custom DynDNS
Sebastian Chrostek
07:38 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Sorry:
Main office
Mode: tunnel
Local Subnet: 0.0.0.0/0
Remote Subnet: BRANCH-LAN
: cat /var/etc/ipsec/spd.c...
Serguei Leontiev
07:26 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Don't delete tunnel for main office Serguei Leontiev
07:21 AM Bug #3016 (Resolved): IPsec client (or branch office) can't access to Internet over VPN gateway
Branch office tunnel:
Mode: tunnel
Local Subnet: LAN
Remote Subnet: 0.0.0.0/0
root(1): cat /var/etc/...
Serguei Leontiev
07:32 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
I have been testing with m0n0wall (1.8.1b540) and it does not have this problem. Perhaps the teams can collaborate t... David Williams
03:50 AM Bug #3015: DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Thanks for the fast turn around Jim. That fixed it. Gavin J
01:23 AM Revision 9399370b: Don't use invalid or IPv6 DNS servers when crafting DHCP DDNS Zones. Fixes #3015
Jim Pingle
01:22 AM Revision f79a5df0: Don't use invalid or IPv6 DNS servers when crafting DHCP DDNS Zones. Fixes #3015
Jim Pingle

05/31/2013

08:30 PM Bug #3015: DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Applied in changeset commit:9399370b367df7b73b84d605f4f44599c93b0bbe. Jim Pingle
08:30 PM Bug #3015 (Feedback): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Applied in changeset commit:f79a5df0733fe17d4a938381e9175fa2e2abefb1. Jim Pingle
07:10 PM Bug #3015 (Resolved): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
The process which writes out the /var/dhcpd/etc/dhcpd.conf file just before starting dhcpd is configuring the forward... Gavin J
04:53 PM Feature #3014 (Needs Patch): Add Variomedia to Dyndns providers
Could someone please add Variomedia (german hoster and domain registrar - http://www.variomedia.de) to the Dyndns pro... Klaus Rörig
01:11 PM Revision 5789e9f8: Update pot file
Renato Botelho
11:14 AM Revision 1407f6a8: Remove wrongly added file in commit 75f457856a
Renato Botelho
11:13 AM Revision 9b03b76a: Update pot file
Renato Botelho
10:04 AM pfSense Packages Bug #3003 (Rejected): Freeeadius.xml bug
There is no problems with the message
The value MUST NOT be < 60 and it SHOULD be >= 600.
Renato Botelho
09:49 AM pfSense Packages Bug #3003: Freeeadius.xml bug
http://www.ietf.org/rfc/rfc2869.txt
The Value field contains the number of seconds between each
inter...
Alexander Wilke
08:53 AM Revision 70946b14: Merge pull request #663 from arsenetar/master
Add CloudFlare Dynamic DNS Service Support Ermal Luçi
08:27 AM Bug #3012 (Feedback): Bug in full backup size computation and/or display
Seems there is something wrong with the backup file. I tested it here, GUI says 392.43Mb and I checked the file:
<pr...
Renato Botelho

05/30/2013

08:44 PM Revision 786399e5: Fix license link
Jim Pingle
08:43 PM Revision 3a73f4f6: Fix license link
Jim Pingle
07:30 PM Revision ffa1acdc: Update dyndns.class
Fix Tabs Andrew Senetar
07:21 PM Revision 6bc58a97: Update dyndns.class
Remove unneeded test variable. Andrew Senetar
07:16 PM Revision 3793649f: Update dyndns.class
Minor Style Change Andrew Senetar
07:13 PM Revision e26e1f76: Update dyndns.class add CloudFlare
Add CloudFlare Support to dyndns.class Andrew Senetar
06:26 PM Revision 8780ff35: Update Services.inc add Cloudflare DYNDNS
Add Cloudflare to the list of DYNDNS services Andrew Senetar
06:07 PM Revision b17c09ba: Merge pull request #662 from jean-m-cyr/RELENG_2_1
Back port sharper.inc commit from master to RELENG_2_1 Ermal Luçi
04:25 PM Revision 2fbefad6: Back port sharper.inc commit from master to RELENG_2_1
Jean Cyr
07:46 AM Revision 3740c810: Merge pull request #646 from marcelloc/master
Add dynamic category tabs for better listing all available packages Ermal Luçi
07:40 AM Revision 0a860dda: Merge pull request #628 from technical50/master
WebGUI Auto Codeset and Language Dynamics & pfSense.pot updates Ermal Luçi
07:34 AM Revision 6a188bb9: Merge pull request #655 from jean-m-cyr/master
Simplify shaper.inc for ipv6 Ermal Luçi
06:58 AM Revision c2f351f3: Merge pull request #660 from CharlieMarshall/firewall_log_widget
change interface text entry box to drop down menu Ermal Luçi
06:57 AM Revision 65c6b2e6: Merge pull request #661 from CharlieMarshall/picture_widget
improve look of picture button selector Ermal Luçi
06:35 AM Bug #2409: ipfw - entryzerostats
Using latest snaps
when we use Captive portal, RADIUS_ACCOUNTING_STOP packets are not sent to RADIUS server
Vlad Arakin
02:24 AM Bug #1980 (Closed): RFC 2136 will not update two records for one interface
thanks Chris Buechler
12:59 AM Bug #1980: RFC 2136 will not update two records for one interface
Related to #2068. It now works on i386/amd64 on version 2.0.3.
I.e. this can be closed.
Andreas Winge
01:04 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
so is there any solution to this, like an updated driver or so? Bipin Chandra

05/29/2013

10:55 PM Revision 310bf9e0: improve look of picture button selector
Charlie Marshall
08:55 PM Revision 2a7bfc1f: change interface text entry box to drop down menu
Charlie Marshall
08:45 PM Revision 7586e201: Update help.php with some new files, clean out some old/obsolete ones.
Jim Pingle
08:45 PM Revision b27ec314: Update help.php with some new files, clean out some old/obsolete ones.
Jim Pingle
04:55 PM Feature #3013 (Resolved): Better upgrading for a CARP cluster
Not sure if this is a bug or something we do incorrectly, so I've added this issue as "Feature".
While upgrading a...
Jerome Alet
04:41 PM Bug #3012: Bug in full backup size computation and/or display
Sorry but how could a 30 GB compressed file be extracted and only consume 640 MB ? If restoring is not complete and i... Jerome Alet
04:35 PM Bug #3012: Bug in full backup size computation and/or display
that's the extracted size, not compressed size. Whether it's better to put the compressed size there I'm not sure, pe... Chris Buechler
04:29 PM Bug #3012 (Closed): Bug in full backup size computation and/or display
We have installed several releases of 2.1 on AMD64 since it's in BETA stage over the course of several months, but th... Jerome Alet
04:34 PM Revision dd688269: Fix up gateway advanced option note that was missed from 2.1 but on 2.0.x.
Jim Pingle
04:34 PM Revision 4f30185f: Fix up gateway advanced option note that was missed from 2.1 but on 2.0.x.
Jim Pingle
03:58 PM Revision d345f596: Don't gettext() the example strings.
They must not be translated. Malte S. Stretz
03:56 PM Revision 04cdae54: Improve Authentication Containers examples.
* The first example was wrong (cf. ldap_backed() in auth.inc which
looks for a DC= part to determine a full DN.
* T...
Malte S. Stretz
03:42 PM Revision d57725aa: Fix LDAP Extended Query example.
The old one was not valid LDAP filter syntax. Malte S. Stretz
03:31 PM Bug #3011 (Rejected): Mobile client disconnect but SA not flushing
2.1 - 29 may snapshot.
I use a mutual psk+ xauth for mobile clients with Policy Generation on, Proposal Checking obe...
luca cuzzolin
02:43 PM Bug #2303: SPD on secondary not cleared after config sync
I have same problem with 2.0 and 2.1 - 29 may snapshot.
I use a mutual psk+ xauth for mobile clients with Policy Gen...
luca cuzzolin
01:48 PM Revision 2bba9aef: Fixes #2979
. Change max value for traffic and packets graphs to 20GigE
. Bump config version to 9.6
. Write a config upgrade fun...
Renato Botelho
01:47 PM Revision fa3b33a5: Fixes #2979
. Change max value for traffic and packets graphs to 20GigE
. Bump config version to 9.6
. Write a config upgrade fun...
Renato Botelho
01:27 PM Revision eea88fdd: "block" is also a reserved keyword that can't be an alias name, or pf tosses an error.
Jim Pingle
01:26 PM Revision 7147fcde: "block" is also a reserved keyword that can't be an alias name, or pf tosses an error.
Jim Pingle
01:26 PM Revision e0c7109d: "block" is also a reserved keyword that can't be an alias name, or pf tosses an error.
Jim Pingle
10:07 AM Bug #2627 (New): Old delegated prefixes are not removed from the LAN interface
Renato Botelho
10:05 AM Bug #2910 (New): monitoring-disabled gateway causes wrong tiered gateway in route-to
Renato Botelho
09:24 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
Starting to look a lot more like mine was modem related. Replaced mine on yesterday afternoon, been up since then.
...
Anonymous
08:50 AM Bug #2979: Increase RRD Max values to account for 10Gbit/s Ethernet
Applied in changeset commit:2bba9aefc21a4e173af3626fb5d08516e35ee47a. Renato Botelho
08:50 AM Bug #2979 (Feedback): Increase RRD Max values to account for 10Gbit/s Ethernet
Applied in changeset commit:fa3b33a57e362654551a16a91a5c6b56971ad4c4. Renato Botelho
07:20 AM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:73eee43c2c60f6ffebd507115bbf3c3908f5e5db. Renato Botelho
07:02 AM Revision 5217befe: Update dyndns.class
To remove a curl_setopt line that is unused for "dnsomatic", and to allow for all characters to be used in the userna... Andrew DeFilippis
07:00 AM Revision 6bdbed87: Merge pull request #656 from swatspyder/master
URL encoding the user/pass for dnsomatic, since it accepts all characters. Ermal Luçi
06:59 AM Revision 0cbddf49: Merge pull request #657 from phil-davis/RELENG_2_1
Minor PHP syntax fixes from ExolonDX Ermal Luçi
02:43 AM Revision be47e83c: Deprecate ampersand (by ExolonDX)
Apply this syntax fix to 2.1 branch (already applied in main after 2.1 was branched - https://github.com/pfsense/pfse... Phil Davis
02:41 AM Revision acd8af41: Add missing quotes (by ExolonDX)
Apply this syntax fix to 2.1 branch (already applied in main after 2.1 was branched - https://github.com/pfsense/pfse... Phil Davis
02:07 AM Revision 99438649: Update dyndns.class
To remove a curl_setopt line that is unused for "dnsomatic", and to allow for all characters to be used in the userna... Andrew DeFilippis

05/28/2013

09:30 PM Bug #1553: Dynamic DNS does not allow @ in the password
I placed pull request 656 on git to resolve this issue, by using "rawurlencode":... Andrew DeFilippis
08:34 PM Revision 853030ac: Do not hide IPV6 setting when system->advanced->network->allowipv6 is false
Jean Cyr
10:18 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I managed to reproduce it locally with an ALIX board and can confirm the issue is related to vr driver. It's always r... Renato Botelho
05:44 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I think my issue may be modem related. I thought I had ruled this out but it seems both modems I tested with gave iss... Anonymous
09:22 AM Feature #1855: NAT before IPsec VPN
This is tested and working in several production networks, there are no confirmed issues currently. Please post in th... Jim Pingle
08:59 AM Feature #1855: NAT before IPsec VPN
Hi!
I have a same problem as Michele Di Maria. - Please reopen a ticket.
Dalm Tian
08:26 AM Revision 368d34c3: Fixes #3001, Check the protocol of the webgui to determine if https is being used for custom ports.
Ermal LUÇI
08:26 AM Revision f9d480ff: Fixes #3001, Check the protocol of the webgui to determine if https is being used for custom ports.
Ermal LUÇI
04:45 AM Bug #3004: config upgrade code needs to change VIP binding on IPsec
Ermal Luçi wrote:
> [...]
>
> Seems the [^_] is wrong here it is not present on earlier versions there, no?
[^...
Renato Botelho
03:09 AM Bug #3004: config upgrade code needs to change VIP binding on IPsec
... Ermal Luçi
03:57 AM Bug #2984: IPSec adds route but isn't needed any more
something to be re-evaluated in the future. Chris Buechler
03:53 AM Bug #2984: IPSec adds route but isn't needed any more
I wouldn't make this removed.
The problem is that reply-to/route-to are dynamic based on gateway status.
While stat...
Ermal Luçi
03:51 AM Bug #2993: IPsec in transport mode, tunneled traffic does not flow through enc0
I will take a look at seeing if can make this less tricky. Ermal Luçi
03:50 AM Bug #2999 (Feedback): sticky connections are really, really broken w/relayd
Applied in changeset pfsense-tools:commit:eae00391a109101fc995d3309a6e2d2bdb7be579. Ermal Luçi
03:43 AM Bug #2999: sticky connections are really, really broken w/relayd
that's not how it's ever worked before, it's stayed sticky to a specific rdr in every previous OS version. Chris Buechler
03:38 AM Bug #2999: sticky connections are really, really broken w/relayd
Actually fixed.
I had disabled the per rule src-tracking to mitigate something else.
Though seems it hurts more than ...
Ermal Luçi
03:34 AM Bug #3008 (Feedback): custom dynamic dns update with https - curl error
Please test with new snapshots or gitsync Ermal Luçi
03:05 AM Bug #3008: custom dynamic dns update with https - curl error
Probably just a rebuild of ca_root_nss port is needed on the snapshot builder!
Try to fetch from here http://ftp.f...
Ermal Luçi
03:30 AM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Applied in changeset commit:368d34c31aed69fe5f0c44814367a2658f4b4bc0. Ermal Luçi
03:30 AM Bug #3001 (Feedback): Captive portal Voucher sync on HTTPS with custom port
Applied in changeset commit:f9d480ff0b4a0cbd569a600ba6087770226ddba5. Ermal Luçi

05/27/2013

03:58 PM Bug #3009 (Rejected): Package Manager does not work after updating
This is not a general issue, but typically specific to a certain package being installed. Post on the forum for assis... Jim Pingle
01:02 PM Bug #3009 (Rejected): Package Manager does not work after updating
Updated to 2.1-RC0 (i386) built on Sun May 26 19:31:39 EDT 2013. The Package Manager page showed message that package... Anonymous
03:57 PM Bug #3010 (Rejected): DC ethernet driver seems to have issues with some multiport card and mother board combinations
There really isn't anything we can do about that. Raise it as a FreeBSD PR if you can reproduce it on a stock FreeBSD... Jim Pingle
03:37 PM Bug #3010 (Rejected): DC ethernet driver seems to have issues with some multiport card and mother board combinations
Greetings,
On some mother boards, with multiport 21143 based NIC cards, there seem to be driver problems. Symptoms...
Clif Cox
01:22 PM Revision e434d5c6: Fix whitespace
Renato Botelho
01:17 PM Revision e47d24e4: Fixes to get routes + dns working:
. Simplify code using new parameter of get_staticroutes()
. Check for subnets instead of ip addrs
. Avoid touch filte...
Renato Botelho
11:29 AM Revision 1901463c: Add extra param, off by default, to make get_staticroutes() return hostnames too
Renato Botelho
11:28 AM Revision aa57f965: Last element is always empty, be sure we drop it
Renato Botelho
10:27 AM Revision c82dcc1d: Permit to use aliases containing hostnames on static routes
Renato Botelho
10:23 AM Revision 356e86d4: Use filterdns to update static routes using hostnames
Renato Botelho
10:03 AM Revision 2a2b9eea: Split system_routing_configure() and teach it to deal with hostnames
Renato Botelho
10:03 AM Revision 30ab140a: Add rc.newroutedns to change routes when hosts changes
Renato Botelho
10:03 AM Revision 2d0c5e3e: Make add_hostname_to_watch return ips it's adding to later use
Renato Botelho
10:03 AM Revision 86a5e1a8: Fix whitespace and indent
Renato Botelho
10:03 AM Revision 046583c3: Simplify logic
Renato Botelho
09:42 AM Bug #3004 (Feedback): config upgrade code needs to change VIP binding on IPsec
There is already a function to do it, upgrade_085_to_086. I tested it locally and it worked as expected.
If you ha...
Renato Botelho
06:32 AM Bug #3008 (Resolved): custom dynamic dns update with https - curl error
Hello,
using HTTPS-Urls with Dynamic DNS gives the following error and no update is done....
Klaus Rörig
01:59 AM Feature #3007 (Resolved): "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
I would like to be able to include traffic that leaves over a GIF tunnel in my traffic shaping for the physical inter... Daniel Becker

05/26/2013

11:42 AM Bug #2409: ipfw - entryzerostats
Upgrade to 2.0.3-RELEASE - bug confirmed:
ipfw table 1 entryzerostats 10.0.0.83
ipfw: getsockopt(IP_FW_TABLE_ZERO_E...
Vlad Arakin
 

Also available in: Atom