Project

General

Profile

Activity

From 06/06/2013 to 07/05/2013

07/05/2013

08:30 PM Revision ae737247: Update services.inc
Turn on AdvManagedFlag and AdvOtherConfigFlag for both 'managed' and 'assist' ramodes. Peter Linss
05:56 PM Revision 51b26242: Actually do this upon entering to get proper ip
Ermal LUÇI
05:56 PM Revision 0007f5b3: Actually do this upon entering to get proper ip
Ermal LUÇI
05:55 PM Revision 4454f1f3: Fixes #2495. On trigering of rc.newwanip remove all ipaliases from the interface since they will be readded later on. This will also make sure to have the correct address order
Ermal LUÇI
05:48 PM Revision b877d635: Fixes #2495. On trigering of rc.newwanip remove all ipaliases from the interface since they will be readded later on. This will also make sure to have the correct address order
Ermal LUÇI
05:29 PM Revision 5fb149ba: Remove unecessary var initialization
Renato Botelho
05:18 PM Revision d7deb24c: Remove unecessary var initialization
Renato Botelho
04:22 PM Bug #3075 (Closed): Can't delete unused Virtual IP "referenced by a least one gateway"
I am working on some minor shuffling around of statics from my /29 block of IPs from my ISP. On 2.0.3 and 2.1 snapsho... Christian McDonald
04:11 PM Bug #2962: IP Aliases cannot be used for routes/gateways
Was the expected result of this revision to prevent the deletion of Virtual IPs that also exist in the same subnet as... Christian McDonald
03:48 PM Revision 9db8c46d: When a CARP VIP transitions to master, we need to bump servers also, otherwise a transition from disabled or init may not properly (re)attach to the IP address.
Jim Pingle
03:46 PM Revision e61a6db2: When a CARP VIP transitions to master, we need to bump servers also, otherwise a transition from disabled or init may not properly (re)attach to the IP address.
Jim Pingle
03:27 PM Revision 0ee96a45: Correct DHCPv6 rules test to also include a check for DHCPv6 relay. Fixes #3074
Jim Pingle
03:27 PM Revision 86573a24: Correct DHCPv6 rules test to also include a check for DHCPv6 relay. Fixes #3074
Jim Pingle
03:27 PM Bug #3057 (Feedback): DHCPv6 not working with Router Advertisements 'Assisted'
It was pushed on master and not on RELENG_2_1, because of that you cannot see the change on 2.1-RC0 snapshots. I appl... Renato Botelho
02:44 PM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
And also with
2.1-RC0 (i386)
built on Fri Jul 5 06:53:51 EDT 2013
FreeBSD 8.3-RELEASE-p8
I need to get ser...
Petri Oksanen
01:55 AM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
This worked, but on build
Version 2.1-RC0 (i386)
built on Thu Jul 4 03:04:00 EDT 2013
FreeBSD 8.3-RELEASE-p8
...
Petri Oksanen
01:59 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
FWIW, tried with @truss /usr/sbin/traceroute6 -w 2 -m 18 www.google.com@ - it looks like it *does* actually make it t... Doktor Notor
01:48 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Looks like the code was last touched (beyond irrelevant cosmetics) almost 4 years ago. Unlikely to have any fix. Doktor Notor
01:37 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
MTR is an entirely different type of test. Useful, but probably not one we'd include by default. And yes its GUI does... Jim Pingle
01:33 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Hmmm well, not sure either, beyond either a shiny red warning (think about remotely managed boxes, cutting yourself o... Doktor Notor
01:29 PM Bug #3069 (New): traceroute6 fails to timeout and hangs the webconfigurator GUI
I was able to reproduce it finally. I tried it on a few different pfSense boxes and FreeBSD systems, and I only could... Jim Pingle
12:40 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
BTW, installed mtr-nox11, no such issue:
HOST: gw.example.com Loss% Snt Last Avg Best Wrst S...
Doktor Notor
12:32 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Not really required to uncomment anything there. It's endlessly visible in the process listing from console, till you... Doktor Notor
12:26 PM Bug #3069 (Feedback): traceroute6 fails to timeout and hangs the webconfigurator GUI
I can't reproduce this on current 2.1 code.
In the GUI we pass "-w 2" which waits a max of two seconds for a reply...
Jim Pingle
01:00 PM Bug #2495: pfsense doesn't seem to know what its WAN IP is
Applied in changeset commit:4454f1f34841b07c2f8e5aa95b3e0d9a9e0ed9a2. Ermal Luçi
12:50 PM Bug #2495 (Feedback): pfsense doesn't seem to know what its WAN IP is
Applied in changeset commit:b877d6351c614f58b68a3ab2c7b04ea7ea282961. Ermal Luçi
12:56 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
Please, revert these patches ASAP. They hard crash the box with FTP! http://forum.pfsense.org/index.php/topic,64144.0... Doktor Notor
12:12 PM Revision abe411ad: Fix a small issue when disable a boolean option and save, it shows option as enabled
Renato Botelho
12:11 PM Revision 6a605eec: Fix a small issue when disable a boolean option and save, it shows option as enabled
Renato Botelho
12:09 PM Revision 277fd8db: Fix whitespaces
Renato Botelho
12:08 PM Revision ae6d9444: Fix whitespaces
Renato Botelho
12:04 PM Revision 80dc15eb: Remove extra { wrongly added on last commit
Renato Botelho
11:56 AM Revision c3cbe91e: Fix whitespaces
Renato Botelho
11:56 AM Revision 810c6a96: Process zipped aliases list
Renato Botelho
11:56 AM Revision 6a9a0736: Remove useless code
Renato Botelho
11:54 AM Revision db0aa52a: Fix whitespaces
Renato Botelho
11:47 AM Revision 6fab0f03: Fix set/unset of checkaliasesurlcert
Renato Botelho
11:47 AM Revision 86ffa26d: Process zipped aliases list
Renato Botelho
11:47 AM Revision 76590ffe: Use download_file() and check ssl certificates
Renato Botelho
11:47 AM Revision abc7b6a2: Remove useless code
Renato Botelho
11:47 AM Revision ffd7802a: Create a function to download a file using curl
Renato Botelho
11:47 AM Revision 08b861a8: Add an option to check certificate for https URL aliases
Renato Botelho
11:20 AM Bug #2951 (Feedback): OpenVPN and alternative monitoring IP in 2.1
This should behave better with tomorrow snapshot due to a fix done in gateway monitoring.
Can you confirm this is th...
Ermal Luçi
10:55 AM Revision 265be6f5: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:53 AM Revision 63356262: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:53 AM Revision f4a8e38c: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:40 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Applied in changeset commit:0ee96a458ab93ff451c9bb32b1b8bc20e13866e6. Jim Pingle
10:40 AM Bug #3074 (Feedback): DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Applied in changeset commit:86573a248608ff5b166eb77e962f97e91df159d2. Jim Pingle
10:18 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
All good now... thumbs up! :) Proper rules generated and DHCPv6 traffic no longer blocked on ifaces with relay enable... Doktor Notor
09:54 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
The attached patch should fix it, but it would be better to test it before committing. Let us know if it helps. Jim Pingle
09:10 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Related forum thread: http://forum.pfsense.org/index.php/topic,64168.0.html Doktor Notor
05:28 AM Bug #3074 (Resolved): DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Looking at this part of filter.inc, I don't think it deals with this configuration correctly.
@
if ((is_array...
Doktor Notor
09:18 AM Bug #1629: invalid state table entries after WAN IP change
I am also affected by this bug in 2.0.3.
In my case not a changed ipadres on my WAN, but a dual Wan setup with failo...
Martin Oosterheert
09:08 AM Feature #1663: DHCPv6 relay
Related forum thread: http://forum.pfsense.org/index.php/topic,64168.0.html Doktor Notor
07:16 AM Feature #1663: DHCPv6 relay
This is very, very broken. It can never be stopped via disabling the checkbox and clicking save. On subsequent enabli... Doktor Notor
07:20 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Glad to report that the firmware update I just installed (details below) seems to work.
Will continue to monitor ...
Anonymous
05:22 AM Bug #2919 (Feedback): IPv6 - WAN and LAN (DHCP-PD) does not renew address
Jun 4 snapshots are even better for this. Ermal Luçi
06:00 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:265be6f5ab7d5546a8f26ae6bcae33712f861102. Ermal Luçi
05:50 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
I pushed some fixes for this.
On newer snapshots it should behave as expected.
Ermal Luçi
05:50 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:63356262a7f3f82b97d029d983fff0132030e539. Ermal Luçi
05:50 AM Bug #2910 (Feedback): monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:f4a8e38c6ed250e9a18c4e472481541198231cdb. Ermal Luçi
05:23 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
The only option for now seems to create rules with allow-option advanced setting set. Ermal Luçi
01:46 AM Bug #3073: Please include PHP MySQL extension!
You can touch /etc/php_dynamodules/module_name and rc.php_ini_setup will pick up on it and load the module (if the mo... Warren Baker

07/04/2013

11:00 PM Bug #3073 (Rejected): Please include PHP MySQL extension!
it's already there Chris Buechler
10:56 PM Bug #3073: Please include PHP MySQL extension!
This is not a bug, sorry for the mistake. Alberto Palau
10:56 PM Bug #3073 (Rejected): Please include PHP MySQL extension!
Would be too much to ask to include the php mysql extension by default in the next snapshoots? I use a custom authent... Alberto Palau
01:42 PM Revision 079d1952: Add a new alias type, URLs containing Ports
Renato Botelho
01:40 PM Revision d9f33a7f: Add group_ports()
Renato Botelho
12:11 PM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
PS: It is not broken or weird behaviour (according to the RFCs). RFC 6145 (translating IPv4 <-> IPv6) specifies:
<...
Sander Steffann
10:20 AM Feature #3070: ova image wan configuration
Hrm seems it should work by default as i was brought to attention.
You sure it asks for interface assignment during b...
Ermal Luçi
09:37 AM Feature #3070: ova image wan configuration
locally I could do it. True. The point is that I'm trying daily to download a snapshot from your snapshot server, run... Victor Pereira
09:26 AM Feature #3070: ova image wan configuration
You can just modify the default config.xml in the repository and that will give you that.
I do not think this will g...
Ermal Luçi
04:11 AM Feature #3070 (Closed): ova image wan configuration
Hi,
there is any possibility to generate the ova image with the WAN already configured to em0? I'm writing Cucumbe...
Victor Pereira
07:52 AM Bug #3072 (Resolved): ova snapshot not available
today I tried to download the last ova snapshot and looks like the virtualization folder is empty
http://snapshot...
Victor Pereira
07:01 AM Revision fae0e098: Remove duplicated line that makes dhcp6c not run correctly
Ermal LUÇI
07:01 AM Revision 0dd5ed7b: Remove duplicated line that makes dhcp6c not run correctly
Ermal LUÇI
06:58 AM Revision 032a3c0a: Do not reconfigure dhcp v6 on v4 ip address event. Only handle 6rd and 6to4 while the former is questionable if needed
Ermal LUÇI
06:58 AM Revision f4d0495e: Copy/pasto does well up to some point
Ermal LUÇI
06:58 AM Revision 74f4a3cc: On every ip change renew the hosts file
Ermal LUÇI
06:54 AM Revision ac086c62: Merge pull request #696 from N0YB/patch-1
Update interfaces.php Ermal Luçi
04:20 AM Feature #3071: build server: link to the last build
While at it, it would be really useful to include /etc/version.lastcommit directly in the snapshots filename. Doktor Notor
04:15 AM Feature #3071 (Resolved): build server: link to the last build
Hi, to do test automation, it would be great to have on your snapshot server a link to the last build version. Today ... Victor Pereira
01:06 AM Revision 3e3aeb8b: Update interfaces.php
Remove errant double quote. N0YB
12:49 AM Revision 77447d9f: Merge pull request #695 from N0YB/Advanced_DHCP_Client_Options
Remove errant double quote. Jim Pingle
12:46 AM Revision e00fafb3: Remove errant double quote.
N0YB

07/03/2013

04:48 PM Bug #3069 (Resolved): traceroute6 fails to timeout and hangs the webconfigurator GUI
As simple as trying to run IPv6 traceroute to www.google.com from the GUI:
@ 2 gige-g2-20.core1.prg1.he.net 3.31...
Doktor Notor
03:52 PM Revision 581fa606: Merge pull request #692 from mgsmith1000/master
Omit IP warning if HTTP_REFERER check is disabled. Renato Botelho
03:50 PM Revision f0f1737b: Merge pull request #691 from mgsmith1000/RELENG_2_1
Omit IP warning if HTTP_REFERER check is disabled. Renato Botelho
03:36 PM Revision 31677598: Omit IP warning if HTTP_REFERER check is disabled.
Matthew Smith
03:32 PM Revision 058bc2a8: Omit IP warning if HTTP_REFERER check is disabled.
Matthew Smith
01:41 PM Revision 2bc45785: Do not reconfigure dhcp v6 on v4 ip address event. Only handle 6rd and 6to4 while the former is questionable if needed
Ermal LUÇI
01:38 PM Revision 9ce0dd12: Copy/pasto does well up to some point
Ermal LUÇI
01:37 PM Revision c9065c1e: On every ip change renew the hosts file
Ermal LUÇI
12:27 PM Revision 5ee53aa1: Enforce the checking of booting up for linkup events
Ermal LUÇI
12:26 PM Revision 84f7e98c: Enforce the checking of booting up for linkup events
Ermal LUÇI
10:01 AM Bug #3037 (Resolved): Unable to delete PRIQ queues
thanks! Renato Botelho
09:46 AM Feature #3068: Notifications/Alerts - custom script
You can provide a patch and it will be evaluated! Ermal Luçi
08:36 AM Feature #3068 (Needs Patch): Notifications/Alerts - custom script
Would be great to have an option in the notifications to execute a custom script. Ricardo Esteves
09:45 AM Bug #2878: radvd does not restart properly
Please test with latest gitsync or tomorrow snapshots.
There were some fixes doen related to this as well.
Ermal Luçi
07:25 AM Bug #2878: radvd does not restart properly
Tom M wrote:
> I am still seeing this issue. I have turned off Track Interface for DHCP on my LAN Interface and ipv6...
Tom M
06:54 AM Revision 51f98d0d: modified radius function to release the pineno
modified radius function to release the pinene if the client is not authenticated properly, and modified function cap... Alberto Palau
06:53 AM Revision e336cd95: Merge pull request #687 from falbertopl/master
Modified radius function to release the pinene Ermal Luçi
03:39 AM Revision d2c98878: modified radius function to release the pineno
modified radius function to release the pinene if the client is not authenticated properly, and modified function cap... Alberto Palau
02:08 AM Bug #1634: Limiter and bridge needs special handling
Not an easy one for 2.1 Ermal Luçi
02:05 AM Bug #3062 (Feedback): Captive Portal NOT re-using PIPENO
Merging of the patch has been done.
Thank you.
Ermal Luçi
12:23 AM Bug #3067 (Rejected): Virtual IP Removal
not a bug, VIPs aren't always necessary for 1:1 NAT so they can't be prohibited from being removed because of 1:1 NAT... Chris Buechler

07/02/2013

11:10 PM Feature #371: Allow moving of bogon and RFC 1918 rules
Can we please do something about this? Or make a checkbox for logging (http://forum.pfsense.org/index.php/topic,34436... Doktor Notor
09:27 PM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Captive portal log also shows successful sync.
Josh Cavalier
09:24 PM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Ok, I have tested this and it works properly. I've setup two VM's with three interfaces each. WAN (192.168.17.0/24), ... Josh Cavalier
09:13 PM Bug #3062: Captive Portal NOT re-using PIPENO
Alberto, it will be much easier if you put the changes in GitHub. Then the developers can easily see the differences,... Phillip Davis
03:58 PM Bug #3062: Captive Portal NOT re-using PIPENO
Only correct a sentence, I meant that I hope will serve out the modification, instead of "I hope you learn the contri... Alberto Palau
03:48 PM Bug #3062: Captive Portal NOT re-using PIPENO
Excuse the mess in the text above, I did not know how to modify it, please if anyone can fix it, thanks Alberto Palau
03:38 PM Bug #3062: Captive Portal NOT re-using PIPENO
Limiters:
02002: unlimited 0 ms burst 0
q133074 100 sl. 0 flows (1 buckets) sched 67538 weight 0 lmax 0 pr...
Alberto Palau
02:09 PM Bug #3062: Captive Portal NOT re-using PIPENO
Ok, I'm working on a solution, and found the problem in the code, I put the fix and I'm probing now, it appears that ... Alberto Palau
09:57 AM Bug #3062: Captive Portal NOT re-using PIPENO
Version 2.0.3 is also affected by this problem. Alberto Palau
08:58 PM Revision c49b7c50: Include both dyndns and rfc2136 hosts in referer check
Jim Pingle
08:58 PM Revision b54ffacc: Include RFC2136 hosts in DNS rebinding checks.
Jim Pingle
08:58 PM Revision 0d7e2478: Add server IP column and cached IP display to RFC2136 host list.
Jim Pingle
08:58 PM Revision c8369c59: Add option to RFC2136 to find/use the public IP if the interface IP is private. (Off by default)
Jim Pingle
08:58 PM Revision 6c38268e: Fix double click row to edit for rfc2136
Jim Pingle
08:58 PM Revision b65492f6: Add cached IP support to RFC2136, add GUI button to force update for single host.
Jim Pingle
08:58 PM Revision 9f0bee02: Include both dyndns and rfc2136 hosts in referer check
Jim Pingle
08:58 PM Revision fa087612: Include RFC2136 hosts in DNS rebinding checks.
Jim Pingle
08:58 PM Revision bcafa618: Add server IP column and cached IP display to RFC2136 host list.
Jim Pingle
08:58 PM Revision 6d8dd98b: Add option to RFC2136 to find/use the public IP if the interface IP is private. (Off by default)
Jim Pingle
08:58 PM Revision a04da9bf: Fix double click row to edit for rfc2136
Jim Pingle
08:58 PM Revision 7c9da7be: Add cached IP support to RFC2136, add GUI button to force update for single host.
Jim Pingle
07:05 PM Revision 92465c6f: Correct variable used to delete symlinks and files delete from CP filemanager. Reported-by: http://forum.pfsense.org/index.php/topic,64016.0/topicseen.html. While here reduce some uneeded extra operations
Ermal LUÇI
07:05 PM Revision bdba4fa7: Correct variable used to delete symlinks and files delete from CP filemanager. Reported-by: http://forum.pfsense.org/index.php/topic,64016.0/topicseen.html. While here reduce some uneeded extra operations
Ermal LUÇI
06:59 PM Bug #3067 (Rejected): Virtual IP Removal
I noticed that pfsense allows you to remove Virtual IPs that are currently in use in a 1:1 NAT which will cause issue... Leon Shadow
06:27 PM Revision 6c2bb4e6: Add the interface's descr after the pool name.
Jim Pingle
06:26 PM Revision 97752da5: Add the interface's descr after the pool name.
Jim Pingle
05:06 PM Bug #3066 (Rejected): Proxy ARP failing with kernel error
Hello, having trouble using Virtual IPs. My problem was worked around by using an Interface alias.
It appeared I w...
Jesse Peterson
04:22 PM Revision 98d5e234: Repect global conf_path
Renato Botelho
04:22 PM Revision 5e3356d7: Repect global conf_path
Renato Botelho
02:30 PM Bug #2878: radvd does not restart properly
I am still seeing this issue. I have turned off Track Interface for DHCP on my LAN Interface and ipv6 is now only tur... Tom M
04:16 AM Bug #2878 (Feedback): radvd does not restart properly
Can you please confirm that this is not anymore an issue? Ermal Luçi
10:51 AM Revision f5035e0b: Merge pull request #680 from Klaws--/RELENG_2_1
Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP Ermal Luçi
10:49 AM Revision fcbef05a: Merge pull request #686 from Klaws--/master
Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP Ermal Luçi
10:45 AM Bug #3065 (Rejected): Firewall rules description - sync
that's intentional for the time being. There's another ticket open on it. Chris Buechler
10:34 AM Bug #3065 (Rejected): Firewall rules description - sync
Hi,
I've just noticed that the sync of firewall rules description "eats" the char ">"
For example, on Firewall1...
Ricardo Esteves
10:37 AM Revision dc63650a: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
10:34 AM Revision 1227101b: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
10:13 AM Revision 492b1314: Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution.
Applied when RRD's are created.
RRA:AVERAGE:0.5:1:1200 = 20 hours of 1 minute data
RRA:AVERAGE:0.5:5:720 ...
N0YB
10:12 AM Revision da9a0ad0: RRD Specify RRA and Resolution
Don't leave it up to RRD Tool to select the RRA and resolution to use.
Specify the RRA and resolution to use per the ...
N0YB
09:50 AM Revision 70d36e38: Adjust archives array values to match sizes for average calculation.
N0YB
09:50 AM Revision 086d941d: Archive start is “now” minus archive length. Not “end” minus archive length. Sometimes "end" is not "now".
N0YB
09:48 AM Revision 5ce5439f: Merge pull request #685 from N0YB/RRD_RRA_Sized_for_Previous_Period
Archive start is “now” minus archive length Renato Botelho
09:27 AM Revision a13acc0e: Add a checkbox that can be used to request only a IPv6 prefix without a IPv6 address. Some ISPs DHCP6 servers will fail the request if both are requested and only a Prefix is allowed.
Conflicts:
usr/local/www/interfaces.php
Seth Mos
08:21 AM Revision 6dcbd1b3: Add a checkbox that can be used to request only a IPv6 prefix without a IPv6 address. Some ISPs DHCP6 servers will fail the request if both are requested and only a Prefix is allowed.
Seth Mos
07:37 AM Bug #3064: Broadcom BCM57780 Nic lights not working (Activity and Link)
The patch link is not correct, here is the correct one - http://svnweb.freebsd.org/base/head/sys/dev/bge/if_bge.c?r1=... Tom Bishop
07:30 AM Bug #3064 (Closed): Broadcom BCM57780 Nic lights not working (Activity and Link)
It appears that the freeBSD 8.x and even the 9.X code has a bug where once the network is configured it turns off the... Tom Bishop
04:51 AM Bug #3063: system will crash after "PowerD" enabled.
Hardware: Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz, Normal PC.
I did not find any obvious message about this f...
tx s
04:18 AM Bug #3063 (Closed): system will crash after "PowerD" enabled.
I am using pfsense as a transparent firewall.
I found the system would be hanged(no any message) in a few minute, ...
tx s
04:15 AM Feature #1836 (New): RFC 5006 support for DNS from RAs
Ermal Luçi
04:11 AM Feature #1836 (Feedback): RFC 5006 support for DNS from RAs
Ermal Luçi
03:59 AM Bug #2650 (Feedback): FTP helper breaks TCP sequence numbers on 2nd WAN
Ermal Luçi
03:59 AM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
Can you try with tomorrows snapshots. Ermal Luçi
01:58 AM Bug #2941 (Resolved): Prohibit adding aliases containing FQDNs in static routes
confirmed fixed Chris Buechler
01:00 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
Also, I have replicated the test by Josh Stompro above (changing an existing alias used by a static route from IP to ... Josh Cavalier
12:35 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
I have tested this with the latest build and it works as intended. I created two aliases, one with a FQDN and one wit... Josh Cavalier
01:43 AM Bug #3037: Unable to delete PRIQ queues
I have tested this and can confirm it works properly (2.1-RC0 - Jul 1 15:22:23 EDT 2013). I created a new shaping rul... Josh Cavalier
01:32 AM Bug #2999 (Resolved): sticky connections are really, really broken w/relayd
confirmed fixed in testing and on customer's production system where problem was discovered.
Chris Buechler

07/01/2013

10:42 PM Revision 24646d57: Adjust archives array values to match sizes for average calculation.
N0YB
10:38 PM Revision 641f2f3c: Archive start is “now” minus archive length. Not “end” minus archive length. Sometimes "end" is not "now".
N0YB
03:42 PM Bug #3062 (Resolved): Captive Portal NOT re-using PIPENO
Captive portal does not correctly release pipe numbers, is continually increasing them until they are exhausted, and ... Alberto Palau
03:41 PM Bug #3024 (Rejected): need a pipe / flowset / sched number
Closed per submitter request Renato Botelho
03:29 PM Bug #3024: need a pipe / flowset / sched number
You can close this bug Alberto Palau
12:24 PM Revision 0bd85300: Merge pull request #684 from N0YB/Advanced_DHCP_Client_Options
Add show/hide to the new "Reject Leases From" row Jim Pingle
10:16 AM Revision c54b4586: fix typos
Renato Botelho
07:46 AM Revision 63c704c3: Add show/hide to the new "Reject Leases From" row
Show for Basic and Advanced. Hide for Config File Override. N0YB
02:31 AM Bug #3061 (Closed): Updating 2.1 snapshots nukes the bogons lists
/etc/bogons is back to the short couple of lines version and /etc/bogonsv6 is empty after every snapshot update. Woul... Doktor Notor
01:16 AM Revision 9e5ae41a: support mitigating BEAST attack
According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30
"...by setting
ssl.cipher-list = "EC...
Dim Hatz

06/30/2013

02:32 PM Revision cafb7dfe: change css & jquery to allow for multiple columns for themes ending in _fs
Charlie Marshall
02:15 PM Revision 60695c6a: update loader.js - add jquery to display additional column button and create/delete columns
Charlie Marshall
02:02 PM Revision c73a2a29: update css to fit full screen
Charlie Marshall
01:58 PM Revision db83bdf9: Merge pull request #676 from N0YB/RRD_RRA_Sized_for_Previous_Period
Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution. Renato Botelho
01:57 PM Revision 1a03f646: Merge pull request #675 from N0YB/RRD_Specify_RRA_Resolution
RRD Specify RRA and Resolution Renato Botelho
01:55 PM Revision bc82e331: Merge pull request #671 from wrboyce/master
allow defining dhcp static mappings using dhcp-client-identifier Renato Botelho
01:50 PM Revision 61ef14bb: Merge branch 'Advanced_DHCP_Client_Options' of https://github.com/N0YB/pfsense into N0YB-Advanced_DHCP_Client_Options
Conflicts:
usr/local/www/interfaces.php
Renato Botelho
01:45 PM Revision ca794dd1: clone pfsense_ng theme
Charlie Marshall
12:21 PM Revision 2cfde694: Handle comma-separated list arg to rc.openvpn
The argument passed to rc.openvpn can be a comma-separated list of gateways - not just 1 gateway. Enhance the code to... Phil Davis
12:19 PM Revision 43d7e83e: Merge pull request #681 from phil-davis/master
Handle comma-separated list arg to rc.openvpn Renato Botelho
07:07 AM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
It was changed only on 2.1, not 2.0.x, because of this you still see the issue on 2.0.3. You can apply the change on ... Renato Botelho
04:09 AM Revision 7ef9de3f: Handle comma-separated list arg to rc.openvpn
The argument passed to rc.openvpn can be a comma-separated list of gateways - not just 1 gateway. Enhance the code to... Phil Davis
03:18 AM Bug #2998: Diffserv Code Point options misleading
I decided to go for the "minimally invasive" approach:
1. I added the CSx itens to the drop-down box.
2. I fixed ...
Klaus Stock

06/29/2013

11:42 AM Revision 216c80dd: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Also removed the ranges 1-64 and 0x04-0xfc, which never ever have worked as expected (the kernel code does not recogn... Klaws--
11:33 AM Revision 6e0d8f82: Added previously missing class selectors cs1-cs7 plaus VA (voice-admit)
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
05:43 AM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
Just updated to 2.0.3; this problem is still here (or came back), with the same cause as before. In my installed copy... Andre LaBranche

06/28/2013

08:14 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I'm also looking forward for the solution of this. I currently halt my 14 sites installation until the bug will be fi... Mel Handumon
06:54 PM Revision 2b125a17: Be a lot more verbose in the logs during package reinstallation.
Jim Pingle
06:54 PM Revision 866b1d61: If the script_name is blank, try another method to locate what our filename is so we don't log an empty script name.
Jim Pingle
06:53 PM Revision b275b658: Be a lot more verbose in the logs during package reinstallation.
Jim Pingle
06:52 PM Revision f09f3d6f: If the script_name is blank, try another method to locate what our filename is so we don't log an empty script name.
Jim Pingle
06:35 PM Bug #3024: need a pipe / flowset / sched number
http://forum.pfsense.org/index.php/topic,63941.0.html Alberto Palau
05:06 PM Bug #3024: need a pipe / flowset / sched number
After several weeks looking for the origin of the problem exposed in this forum, I concluded that the problem occurs ... Alberto Palau
04:37 PM Revision 1e7fa7cd: Fix CP status sorting to properly respect the zone.
Jim Pingle
04:36 PM Revision 210eea2c: Fix CP status sorting to properly respect the zone.
Jim Pingle
01:05 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address

For the very first time, I have been able to go over 4 days without loosing IPv6 addressing. This is very positive...
David Williams
10:08 AM Bug #3060 (Rejected): Post-upgrade screen never goes away and some packages disappear from menu
That happens when a package has failed to reinstall, which is a problem with a specific package in most cases. Check ... Jim Pingle
09:58 AM Bug #3060 (Rejected): Post-upgrade screen never goes away and some packages disappear from menu
1. I have posted this in the forum at http://forum.pfsense.org/index.php/topic,63793.0.html
The upgrade status scr...
GT Zenny
07:04 AM Revision 4023ebb0: Merge pull request #678 from johnbyronent/master
Add Dyn Dns Euro Dns Provider Ermal Luçi

06/27/2013

09:31 PM Revision ec66caa6: DynDns Euro Dns Provider
Add Dyn Dns Euro Dns Provider John Byron
06:35 PM Revision 97c98f19: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
06:34 PM Revision 9d793187: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
06:34 PM Revision 1525fe1f: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
11:23 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
I just updated from a January build to yesterday's build and still get altq errors similar to those above on my lagg0... Steve Kerrison
10:35 AM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
Added support for DHCPv6 reservations and /etc/hosts entries in PR 466 Peter Linss
07:57 AM Bug #1399: rrdtool respawning too fast
Attaching rrdtool.core from 2.1 p13 Todor K
07:22 AM Bug #1399: rrdtool respawning too fast
Same message appeared to me after upgrade from 2.0.3 to 2.1 p13
I have anohter server upgraded to 2.1 p8 (few days e...
Todor K
06:25 AM Bug #2998: Diffserv Code Point options misleading
Forget my bullshit about ipfw above - Goole managed to sneak some ipfw results into my "pf" search, I just a bit conf... Klaus Stock
03:00 AM Bug #3058 (Resolved): Latest 2.1 RC update killed Alix
was a bad snapshot that was removed Chris Buechler
02:27 AM Bug #3058: Latest 2.1 RC update killed Alix
Please close bugreport - seems the problem has not reappeared. Sorry for wasting time, my apologies. Criggie .

06/26/2013

11:50 PM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
Submitted PR #456 as fix.
Turns out the issue isn't IPv6 addresses, it was the duplicate host handling, if both IP...
Peter Linss
06:22 PM Feature #2319: include SSD TRIM option in installer
Apparently the AHCI module may also be required for trim to work properly. See http://forum.pfsense.org/index.php/top... Jim Pingle
01:42 PM Bug #3047: IPSEC remote access broken in 2.03
We're using VMWare PFSense. Upgraded to 2.1 but still no luck with mobile vpn. Micha Ch
06:47 AM Bug #2951: OpenVPN and alternative monitoring IP in 2.1
I was reading the whole story again since I was not able to reproduce the issue, and I have a suspect. Could you plea... Renato Botelho
02:50 AM Bug #3058: Latest 2.1 RC update killed Alix
Craig Falconer wrote:
> If this affects others, can Tuesday's build be pulled before too many people are affected?
...
Doktor Notor
02:30 AM Bug #3058 (Resolved): Latest 2.1 RC update killed Alix
Just updated from Monday to Tuesday's build on my spare alix 2d2.... Criggie .

06/25/2013

02:18 PM Bug #3055: System logs not work right
They are working on current snapshots in our environment. There must be something else wrong in your setup, so please... Jim Pingle
02:10 PM Bug #3055: System logs not work right
Sorry for my english, but maybe I have not explained well.
The problem is server-side logs that not receive the logs...
Claudio Berselli
01:51 PM Bug #2878: radvd does not restart properly
I've been updating a snapshot copy since December 2012 without a full rebuild. I'm wonder if I start with a fresh bet... Tom M
12:57 PM Bug #2878: radvd does not restart properly
Just updated to the same snapshot, and radvd seems to have come up just fine for me. This is also on Comcast, so I wo... Daniel Becker
06:45 AM Bug #2878 (New): radvd does not restart properly
Renato Botelho
01:24 PM Bug #3047: IPSEC remote access broken in 2.03
Not sure if it matters, but I am on an ALIX device. I have since moved back to 2.02 because I cannot afford the down... Robert Holmes
03:55 AM Bug #3047: IPSEC remote access broken in 2.03
@@Jun 24 16:00:18 racoon: ERROR: failed to begin ipsec sa negotication.
Jun 24 16:00:18 racoon: ERROR: no configur...
Micha Ch
12:54 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Robert Guerra wrote:
> Just updated to June 24 release (details below) and IPv6 connectivity -still - does not work....
Daniel Becker
07:54 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Just updated to June 24 release (details below) and IPv6 connectivity -still - does not work. Am on Comcast service a... Anonymous
08:17 AM Bug #2998: Diffserv Code Point options misleading
As the TOS field has an "unstable history" (RFC 3168), a most flexible approach should be imperative. That means that... Klaus Stock
07:46 AM Revision d7df6a6e: Merge pull request #677 from plinss/master
Proposed fix for bug #3057 Ermal Luçi
06:20 AM Bug #3008: custom dynamic dns update with https - curl error
Could you please try a recent snapshot? It should be fixed now. Renato Botelho
06:20 AM Bug #3034 (Resolved): Security FLAW in pfSense Wireless Found
Renato Botelho
04:58 AM Revision 8c78e692: Update services.inc
Turn on AdvManagedFlag and AdvOtherConfigFlag for both 'managed' and 'assist' ramodes. Peter Linss

06/24/2013

11:55 PM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
Proposed fix in https://github.com/pfsense/pfsense/pull/677 Peter Linss
11:42 PM Bug #3057 (Resolved): DHCPv6 not working with Router Advertisements 'Assisted'
When selecting 'Assisted' mode for Router Advertisements, OSX clients use stateless autoconfig and do not obtain DHCP... Peter Linss
08:10 PM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
DHCPv6 reservations don't appear to be added to unbound.conf either (DHCPv4 reservations are added). Peter Linss
07:57 PM pfSense Packages Bug #3056 (Resolved): Unbound not getting IPv6 host overrides
Running latest 2.1RC with unbound 1.4.20_7 installed.
When setting host overrides in Services > DNS Forwarder the ...
Peter Linss
07:33 PM Revision 4efdada8: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
07:32 PM Revision 69937c05: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
06:18 PM Bug #3055 (Rejected): System logs not work right
Not enough information here for a valid bug report. Please start a thread on the forum and if, after assistance and d... Jim Pingle
04:37 PM Bug #3055 (Rejected): System logs not work right
I flag - > "Everything" in "Remote Syslog Contents" but not all event is send to a syslog.
In my case only the login...
Claudio Berselli
05:33 PM Revision fc1f4960: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
05:33 PM Revision 2aacbacf: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
02:40 PM Revision efe42b5a: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:40 PM Revision d13b7363: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:09 PM Bug #2627: Old delegated prefixes are not removed from the LAN interface
Tried with:
2.1-RC0 (amd64)
built on Mon Jun 24 04:05:41 EDT 2013
FreeBSD 8.3-RELEASE-p8
Boot up. WAN & LAN g...
Anonymous
12:55 PM Bug #2627 (Feedback): Old delegated prefixes are not removed from the LAN interface
Could you please check a recent snapshot? Renato Botelho
01:50 PM Bug #2878: radvd does not restart properly
I'm still seeing an issue with RADVD not restarting automatically after a dhcp renew from my internet provider (Comca... Tom M
01:01 PM Bug #2878: radvd does not restart properly
This has been working for me with the past several snapshots I've tested. Daniel Becker
12:55 PM Bug #2878 (Feedback): radvd does not restart properly
Could you please check a recent snapshot? Renato Botelho
12:12 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
This seems to have been working fine for me on Comcast Home for the past few snapshots that I've tried. After > 8 day... Daniel Becker
10:03 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Can you test again with latest snapshots and see if this is fixed? Ermal Luçi
10:00 AM Bug #3039: New vouchers doesn't sync with CARP slave
The system log would be interesting to see here Ermal Luçi
09:40 AM Bug #2887: ppp-linkdown state killing not right
Applied in changeset commit:efe42b5a05dfc7c718b04fb00391f251d846a2f2. Renato Botelho
09:40 AM Bug #2887 (Feedback): ppp-linkdown state killing not right
Applied in changeset commit:d13b7363304390736fa4686b4544319f26bdba92. Renato Botelho
06:44 AM Bug #3054: openBGPd stoped working
frustration is never a good friend :
excuse my p.s. :)
step 1 install: pfSense-LiveCD-2.1-RC0-amd64-20130618-1856...
Svetozar Urumov
06:37 AM Bug #3054: openBGPd stoped working
ok some more info :
step 1 : install pfSense-memstick-2.1-RC0-amd64-20130618-1856.img
step 2 : make all confs in Se...
Svetozar Urumov
06:40 AM Bug #3030 (Feedback): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Applied in changeset pfsense-tools:commit:0416a5113ab777964567fc30b78647b6167f8b75. Renato Botelho

06/23/2013

10:27 PM Bug #3054 (Rejected): openBGPd stoped working
not enough here to be a legit bug report, please post info to the forum or list for help. Chris Buechler
10:57 AM Bug #3054 (Rejected): openBGPd stoped working
After upgrade to :
2.1-RC0 (amd64)
built on Sat Jun 22 15:45:58 EDT 2013
openBGPd stopped working giving follo...
Svetozar Urumov
09:56 PM Revision 211d95a9: Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution.
Applied when RRD's are created.
RRA:AVERAGE:0.5:1:1200 = 20 hours of 1 minute data
RRA:AVERAGE:0.5:5:720 ...
N0YB
04:16 AM Revision 1e86f510: RRD Specify RRA and Resolution
Don't leave it up to RRD Tool to select the RRA and resolution to use.
Specify the RRA and resolution to use per the ...
N0YB
03:53 AM Revision 88ba6d31: Merge branch 'RELENG_2_1' of git://github.com/pfsense/pfsense into RELENG_2_1
N0YB

06/22/2013

11:01 AM Revision 63b69d34: System: Group manager, set max length for groupname to 16 characters
Pi Ba
10:55 AM Revision e06263e1: Merge pull request #674 from PiBa-NL/SystemGroupmanager_16charName
System: Group manager, set max length for groupname to 16 characters Ermal Luçi
12:27 AM Bug #2997: CARP and pfSync traffic issues with traffic shaping
Hi,
this should be already foreseen (http://forum.pfsense.org/index.php/topic,45045.msg344264.html#msg344264), ju...
Michele Di Maria

06/21/2013

11:06 PM Revision 51f1fc58: Use Probe Interval on gateway advanced settings
Phil Davis
10:40 PM Revision 3db408b3: System: Group manager, set max length for groupname to 16 characters
Pi Ba
11:54 AM Feature #3053 (New): Automatically add DHCP static addresses to CP passthru-mac
Add a new option to Captive Portal to automatically add static addresses configured on DHCP server to the list of pas... Wendell Borges
09:06 AM Revision b6aecb27: Merge pull request #673 from phil-davis/master
Use "Probe Interval" to describe this advanced gateway parameter Ermal Luçi
05:03 AM Bug #3052 (Rejected): Adding a static dhcp for mac address dissapears.
Cannot say if its a bug or normal behaviour. This is what i have
1 wan, 3 Vlan's
When i want to add a static ma...
Tom De Coninck
02:48 AM Revision 490cd438: Use Probe Interval on gateway advanced settings
Phil Davis
02:21 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Thanks.
I will test as soon as it's in a snapshot (im currently on 2.1RC0). Backing out the old patch already yielde...
Peter Borföi

06/20/2013

09:27 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I have placed all the changes I have made to racoon up on Github. You can find them "here":https://github.com/duchsc... David Duchscher
12:24 PM pfSense Packages Bug #3051: Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
I can confirm that bug on Snort 2.9.4.6 pkg v. 2.5.9.
pfSense 2.1 RC0
B H
09:18 AM pfSense Packages Bug #3051 (Resolved): Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
Pfsense 2.1 of 06/19/2013 17:23.
If change wansuppress on Snort, is necessary reboot Pfsense to enable the new rule...
Claudio Berselli
11:57 AM Bug #3045: NTPD crash / doesn't come up
Not any single crash with the new file. The OpenNTPD service is running rock-stable. No crash, no error in system-log... B H
04:50 AM Bug #3050 (Resolved): error loading TCP block or reject rule
Renato Botelho
04:44 AM Bug #3050: error loading TCP block or reject rule
Erik Augustsson wrote:
> Works for me
same here
Thomas Rieschl
04:28 AM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Seems correct as a patch as long as you do not get LORs.
I though this was handled in the ioctl patch code already...
Ermal Luçi

06/19/2013

11:11 PM Bug #3024: need a pipe / flowset / sched number
I think I'm close to the problem, I deleted the database files belonging to the captive portal " /var/db " and then r... Alberto Palau
06:02 PM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
It's fine to leave bandwidth blank, altq fills it using the interface bandwidth. On my tests I could reproduce the is... Renato Botelho
12:47 PM Revision 94744c27: Correct gateway down/probe interval text.
Jim Pingle
12:45 PM Revision 94fb9f2d: Correct gateway down/probe interval text.
Jim Pingle
08:42 AM Revision b7d6c7f6: Correct the comments describing the error with correct values
Ermal LUÇI
08:42 AM Revision 6870b5ce: Correct the comments describing the error with correct values
Ermal LUÇI
08:20 AM Bug #2511: DHCPv6 Shows Wrong DUID
I seem to have a similar problem.
A windows 8 client with the DUID 00:01:00:01:18:1c:59:c5:00:25:22:92:f5:43 (veri...
Jeroen van der Wal
07:02 AM Bug #3050: error loading TCP block or reject rule
Works for me Erik Augustsson
02:43 AM Bug #3047: IPSEC remote access broken in 2.03
same Problem since PFSense 2.0.2 with Android 4.1.2, 4.2, iOS 4/5.
Downgrade back to 2.0.1 and everything is fine wi...
Micha Ch
12:20 AM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability
Chris Buechler

06/18/2013

09:57 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I backed the following patch out from ipsec-tools and many of my issues when away.
https://github.com/duchscherd/p...
David Duchscher
08:19 PM Bug #3049: RAM Disk RRD Loss Vulnerability

Fix verified.

RRD backup file rrd.tgz is retained after reboot.

NOYB NOYB
05:50 AM Bug #3049: RAM Disk RRD Loss Vulnerability
Applied in changeset commit:ef01b77f6dc5e2f4ba254739a1792207e7b52a09. Renato Botelho
05:50 AM Bug #3049 (Feedback): RAM Disk RRD Loss Vulnerability
Applied in changeset commit:dc21d4d5618e5190dbc85a479489b230063450f5. Renato Botelho
07:55 PM Revision d5e4f7c9: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
07:54 PM Revision 4f0710f3: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
06:43 PM Revision 40e6086a: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:42 PM Revision 2706c79b: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:03 PM Revision 8744a113: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
06:00 PM Revision 7ddfa922: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
05:31 PM Revision 6743ab28: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:28 PM Revision a27403c4: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:01 PM Revision 850324a2: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
05:00 PM Revision 57c83fd6: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
04:01 PM Revision f03cf892: A better fix for conditionally including burst.
Jim Pingle
04:01 PM Revision c32e0581: A better fix for conditionally including burst.
Jim Pingle
03:57 PM Revision e43fa2ac: Burst of 0 is also valid
Jim Pingle
03:57 PM Revision 012cd3ba: Burst of 0 is also valid
Jim Pingle
03:53 PM Revision f1a17b1a: Only add burst if a burst is defined
Jim Pingle
03:52 PM Revision 11421996: Only add burst if a burst is defined
Jim Pingle
03:02 PM Revision f63733e0: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
03:01 PM Revision 45e12bad: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
02:54 PM Revision 5015ec4c: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:52 PM Revision 57fa7011: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:06 PM Revision bca506d4: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
02:05 PM Revision d17c7b79: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
01:50 PM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:40e6086ada6b73f6432b7ac93d4b376941028b09. Jim Pingle
01:50 PM Bug #3005 (Feedback): cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:2706c79b47373fd294446d7ab0cc25d79bd494a1. Jim Pingle
10:48 AM Revision ef01b77f: Fix #3049, set $config as global to it can be read
Renato Botelho
10:48 AM Revision dc21d4d5: Fix #3049, set $config as global to it can be read
Renato Botelho
10:00 AM Bug #3050: error loading TCP block or reject rule
Applied in changeset commit:5015ec4cd0c497ca1db68e7393d2898ba57efb0b. Jim Pingle
10:00 AM Bug #3050 (Feedback): error loading TCP block or reject rule
Applied in changeset commit:57fa70112a9ab5bec06f5dd64bf0d987dfdae159. Jim Pingle
09:19 AM Bug #3050 (Resolved): error loading TCP block or reject rule
After updating to _2.1-RC0 (amd64) built on Mon Jun 17 17:28:37 EDT 2013_ none of my TCP block rules are working anym... Thomas Rieschl
05:47 AM Bug #3045 (Feedback): NTPD crash / doesn't come up
Renato Botelho
01:02 AM Bug #3045: NTPD crash / doesn't come up
Since implement your new file yesterday, i habe no more ntpd crashes. I will report again at the end of the week. B H
02:21 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Andreas, that's not really relevant to this bug - this is specifically for making altq work with the VLAN driver, tha... Mark Uhde
01:43 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Sorry i use the latest 2.1 RC0 i386 snapshot Andreas Huser
01:41 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Hi
i'm sorry for reopening this ticket.
I have four openvpn connections and try to configure a traffic shaper wit...
Andreas Huser
01:02 AM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
I did a more in-depth analysis with tcpdumps (LAN/WAN) here:
http://forum.pfsense.org/index.php/topic,62237.msg34202...
Anonymous

06/17/2013

10:19 PM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability

When using the RAM disk option for /tmp and /var, after a reboot and RRD data is restored, the RRD backup file /cf...
NOYB NOYB
03:26 PM Revision 9507aa0e: Allow user to set interval between attempts to resolve hostnames configured on aliases
Renato Botelho
03:24 PM Revision ab3ab2ac: Allow user to set interval between attempts to resolve hostnames configured on aliases
Renato Botelho
03:06 PM Feature #3048 (Resolved): Pre-download packages to reduce downtime during upgrade process?
Not sure if this is possible under the current system...
If it is possible to determine what version of [a] package[...
Adam Thompson
01:25 PM Revision b48e2e6b: Include the burst size in the limiter. Submitted-by: http://forum.pfsense.org/index.php/topic,62470.0.html
Ermal LUÇI
01:25 PM Revision 4981f881: Include the burst size in the limiter. Submitted-by: http://forum.pfsense.org/index.php/topic,62470.0.html
Ermal LUÇI
01:11 PM Bug #3047: IPSEC remote access broken in 2.03
As before, same with IOS. Robert Holmes
12:47 PM Bug #3047: IPSEC remote access broken in 2.03
Cisco VPN client is known to be broken when connecting to pfSense (and it's a violation of their license to do so usi... Jim Pingle
12:41 PM Bug #3047: IPSEC remote access broken in 2.03
I don't understand why it doesn't work for me in 2.03 - no config changes whatsoever between 2.02 and 2.03. I also j... Robert Holmes
12:22 PM Bug #3047: IPSEC remote access broken in 2.03
I used your exact IPsec config (aside from fixing the lifetimes to match the documented suggested values), and I am a... Jim Pingle
10:15 AM Bug #2928: Authentication attempts against multiple radius servers should stop when the first reject is received.
For two factor authentication , you need to use Access-Challenge response from your radius server, and use it to proc... Tuyan Ozipek
10:01 AM Revision 84a27e31: fix dhcp static mapping/client identifier validation
Will Boyce
09:27 AM Revision 615d7f0a: Add warning comment about missing IPv6 implementation
Ermal LUÇI
09:25 AM Revision fafcae72: Add used binary
Ermal LUÇI
09:25 AM Revision 70a9e131: Remove referenced binary not used anymore
Ermal LUÇI
09:25 AM Bug #3045: NTPD crash / doesn't come up
OK it's started now. I had to go Services - NTP - press Save button. Then press the restart service button. Now it's ... B H
09:22 AM Bug #3045: NTPD crash / doesn't come up
After this procedure i can't start the NTPD service. B H
09:16 AM Bug #3045: NTPD crash / doesn't come up
I've built ntpd binaries with debug symbols, there are binaries for 2.0.3 and 2.1, i386 and amd64:
ntpd-2.0.3-amd64
...
Renato Botelho
03:33 AM Bug #3045: NTPD crash / doesn't come up
Crashed again. File attached. B H
09:25 AM Revision bf8c7971: Remove referenced binary not used anymore
Ermal LUÇI
09:24 AM Revision 8cea45e4: Remove unused code and spurious alert
Ermal LUÇI
09:23 AM Revision 891dfb24: Use file_put_contents for simplicity and readbility
Ermal LUÇI
09:23 AM Revision 4cbc0ae9: Remove unused code and spurious alert
Ermal LUÇI
09:23 AM Revision de82ec90: Use file_put_contents for simplicity and readbility
Ermal LUÇI
09:00 AM Revision 10054843: * Use when needed the family for get_real_interface
* During dhcp setup use -n for cp to avoid coping uselessly Ermal LUÇI
08:59 AM Revision 06886ae3: * Use when needed the family for get_real_interface
* During dhcp setup use -n for cp to avoid coping uselessly Ermal LUÇI
08:27 AM Revision f960f9dd: Use family parameter for v6 to get correct interface
Ermal LUÇI
08:26 AM Revision be544a5e: Use family parameter for v6 to get correct interface
Ermal LUÇI
08:13 AM Revision 10ce1ac1: Remove useless variable and also correct some style
Ermal LUÇI
08:12 AM Revision 8026f19c: Remove useless variable and also correct some style
Ermal LUÇI
08:06 AM Revision ca2b90ec: Do not do the same tricks here that are done on get_real_interface but just call the function directly
Ermal LUÇI
08:06 AM Revision d90ea5ff: Get interface from inet6 domain
Ermal LUÇI
08:06 AM Revision 08efe4e6: Use trim rather than str_replace. Also no need to sleep anymore since dhcp will configure first the interface
Ermal LUÇI
08:05 AM Revision 81d0281d: Do not do the same tricks here that are done on get_real_interface but just call the function directly
Ermal LUÇI
08:00 AM Revision 314b9b2c: Get interface from inet6 domain
Ermal LUÇI
07:59 AM Revision a432c132: Use trim rather than str_replace. Also no need to sleep anymore since dhcp will configure first the interface
Ermal LUÇI
07:55 AM Revision 6756d9ee: Remove unreferenced binaries. correct some formatting and also to make function clear to track correct the curly placement
Ermal LUÇI
07:55 AM Revision 50a88d93: Provide full path to route binary
Ermal LUÇI
07:55 AM Revision 85a389c9: Provide full path to route binary
Ermal LUÇI
07:54 AM Revision 1944af41: Remove unreferenced binaries. correct some formatting and also to make function clear to track correct the curly placement
Ermal LUÇI
07:44 AM Revision 12f77b03: Provide full path to route binary
Ermal LUÇI
07:43 AM Revision 59b99089: Provide full path to route binary
Ermal LUÇI
06:53 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Hmm, nevermind, it seems to include 'ns-cert-type server' nowadays, that should suffice. Mike Noordermeer
06:46 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Nowadays Pfsense seems to be able to generate server certificates, so I don't see any reason to not add 'remote-cert-... Mike Noordermeer
05:39 AM Revision af600fe2: Don't flip the IPv6 allow setting just because people are upgrading. Just upgrading versions shouldn't change this behavior. As much as most of us would like people to start deploying IPv6, the vast majority aren't going to be immediately post-upgrade, and changing this can change the firewall policy behavior by allowing v6 that previously wasn't allowed. Upgrades should never change the firewall behavior like that. At the time it was done, everyone using the 2.1 code base was using it for IPv6, so of course it tripped up quite a few people.
Chris Buechler
05:32 AM Revision 4cdf35a4: Don't flip the IPv6 allow setting just because people are upgrading. Just upgrading versions shouldn't change this behavior. As much as most of us would like people to start deploying IPv6, the vast majority aren't going to be immediately post-upgrade, and changing this can change the firewall policy behavior by allowing v6 that previously wasn't allowed. Upgrades should never change the firewall behavior like that. At the time it was done, everyone using the 2.1 code base was using it for IPv6, so of course it tripped up quite a few people.
Chris Buechler
05:24 AM Revision 878454b8: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:24 AM Revision 891ecd18: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:23 AM Revision 9a0a9fc1: not true you have to log in again since HTTP basic auth was deprecated.
Chris Buechler
05:16 AM Revision a6c03297: add MSS clamping to setup wizard. Now that MTU and MSS are separate, the MTU description was wrong, and both need to be there.
Chris Buechler
05:15 AM Revision 7b79e0cb: add MSS clamping to setup wizard. Now that MTU and MSS are separate, the MTU description was wrong, and both need to be there.
Chris Buechler

06/16/2013

11:21 PM Revision 5fb01c77: Revert "Revert "Fix gateway quality rrd to have the correct granularity and be consistent with the pfSense graphs set.""
This reverts commit 304ea841cff40aacaac084a0eb6c145ddd034303. N0YB
11:15 PM Revision 304ea841: Revert "Fix gateway quality rrd to have the correct granularity and be consistent with the pfSense graphs set."
This reverts commit a8d262f63c4574f40f5f299a2e9f746986dc966a.
put the create_gateway_quality_rrd function in rrd.inc...
N0YB
08:08 PM Bug #3024: need a pipe / flowset / sched number
Another detail is that when the error happens it creates a single limit like the follow.
Limiters:
00001: 262.140...
Alberto Palau
05:14 PM Bug #3047: IPSEC remote access broken in 2.03
You should have enough to re-create it on a pfSense box, but attached is the info you requested. Also, when the VPN ... Robert Holmes
12:20 PM Bug #3047: IPSEC remote access broken in 2.03
Still not enough information. Most importantly we need the IPsec log entries (I forgot to mention that previously) fr... Jim Pingle
11:33 AM Bug #3047: IPSEC remote access broken in 2.03
Forum link is here: http://forum.pfsense.org/index.php/topic,62209.msg341320.html
I didn't get any feedback so I ope...
Robert Holmes
10:58 AM Bug #3047 (Feedback): IPSEC remote access broken in 2.03
There is not nearly enough information here for a valid bug report. Include details about your exact config (every op... Jim Pingle
10:50 AM Bug #3047 (Closed): IPSEC remote access broken in 2.03
In pfSense 2.0 through 2.02, my configuration for remote IPSEC access (like my iPhone) worked fine. IPSEC with Mobil... Robert Holmes
01:39 PM Bug #3045: NTPD crash / doesn't come up
I'm also seeing this every couple of days and have also attached file. David Williams
07:57 AM Revision 449f1dd2: allow defining dhcp static mappings using dhcp-client-identifier
Will Boyce

06/15/2013

10:35 AM Bug #3045: NTPD crash / doesn't come up
The file is attached. B H
01:12 AM Bug #3045: NTPD crash / doesn't come up
If anyone tells me where the ntpd core crash dump is located, sure. B H
12:07 AM Revision e8ddd3a8: TCP flags are valid on any type of rule, don't skip them on block or reject rules
Chris Buechler
12:06 AM Revision bcd94190: TCP flags are valid on any type of rule, don't skip them on block or reject rules
Chris Buechler

06/14/2013

08:07 PM Bug #3046 (Resolved): Fatal error: Call to undefined function get_interface_ip() in /usr/local/captiveportal/radius_authentication.inc on line 56
When using Radius authentication I get this immediately after logging in. My password is accepted, then I receive an... orangepeel beef
07:48 PM Revision 664f9f3b: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
07:34 PM Revision 2ca43251: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
07:33 PM Revision df78d8cc: Fix max length for wpa passphrase, it fixes #3034
Renato Botelho
06:44 PM Revision c9322c5c: Allow queues to be deleted, it fixes #3037
Renato Botelho
06:44 PM Revision a22537c7: Allow queues to be deleted, it fixes #3037
Renato Botelho
04:32 PM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
not true except where it causes problems with an upstream ARP cache, which we can't do anything about. Disable/enable... Chris Buechler
12:46 AM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
Two nodes with CARP outside and CARP inside.
Outbound SNAT is done via the outside virtual IP.
Changing the vhid of...
Todor K
02:50 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:664f9f3b919f970fb77c66cc4c5c3445081d5f25. Renato Botelho
02:40 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:2ca432514e09e5388f1786f0f6c6d977d3254533. Renato Botelho
02:40 PM Bug #3034 (Feedback): Security FLAW in pfSense Wireless Found
Applied in changeset commit:df78d8cc1890f19702e3e78bb3c5a583ada52356. Renato Botelho
01:50 PM Bug #3037: Unable to delete PRIQ queues
Applied in changeset commit:c9322c5ceb272a3b51a4cd2f737d268cde3584c7. Renato Botelho
01:50 PM Bug #3037 (Feedback): Unable to delete PRIQ queues
Applied in changeset commit:a22537c73c6a1301b9e2656bfaa4382b93314a55. Renato Botelho
12:45 PM Revision d60629b0: Update list of mobile service providers
Renato Botelho
12:44 PM Revision 6b7c0fef: Update list of mobile service providers
Renato Botelho
12:26 PM Bug #3045: NTPD crash / doesn't come up
Is there a ntpd core with crash dump that you can share? It could help us to identify the issue. Renato Botelho
11:11 AM Bug #3045 (Resolved): NTPD crash / doesn't come up
The NTP services crashes a lot, reason unknown for me.
The System Logs says:
_kernel: pid 35663 (ntpd), uid 0: ex...
B H
11:02 AM Bug #3044: SSHD failed to start.
http://forum.pfsense.org/index.php/topic,63435.0.html Basel G.
08:59 AM Bug #3044 (Rejected): SSHD failed to start.
Not enough information here. Please post in the forum for assistance in finding the cause of the error. If a legitima... Jim Pingle
06:11 AM Bug #3044 (Rejected): SSHD failed to start.
php: : The command '/usr/sbin/sshd' returned exit code '1', the output was 'Could not load host key: /etc/ssh/ssh_hos... Basel G.

06/13/2013

08:48 PM Revision 654ed9e0: Update the default firmware URL (it was still pointing to HEAD on RELENG_2_1)
Jim Pingle
05:13 PM Revision 94860e9e: Fix exec perms on mail.php
Jim Pingle
05:12 PM Revision fd5efd38: Fix exec perms on mail.php
Jim Pingle
05:05 PM Revision dd16aadf: Add a simple CLI mail script capable of sending an SMTP message using echo/piped input, e.g. ifconfig -a | mail.php -s"ifconfig output"
Jim Pingle
05:05 PM Revision 7c845149: Split actual SMTP send into its own function.
Jim Pingle
05:03 PM Revision 185f24c3: Add a simple CLI mail script capable of sending an SMTP message using echo/piped input, e.g. ifconfig -a | mail.php -s"ifconfig output"
Jim Pingle
04:52 PM Revision 24160e3d: Merge pull request #670 from francisuk/patch-1
EAOrigin.pat - Traffic Sharping Layer 7 Ermal Luçi
04:52 PM Revision 95dfe4f5: Split actual SMTP send into its own function.
Jim Pingle
04:44 PM Revision 4e79fb9a: EAOrigin.pat - Traffic Sharping Layer 7
The EA Store is now Origin, Tested and works (for now) will make changes if i come to anything useful. francisuk
04:19 PM Revision f0992686: Add the ability to disable Growl or SMTP notifications but keep their settings intact. Remove automatic test messages on save. Add individual test buttons for Growl and SMTP that work even if the service(s) are disabled.
Jim Pingle
04:19 PM Revision 8a0f8732: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
04:17 PM Revision 48b86f62: Add the ability to disable Growl or SMTP notifications but keep their settings intact. Remove automatic test messages on save. Add individual test buttons for Growl and SMTP that work even if the service(s) are disabled.
Jim Pingle
03:39 PM Bug #2882: 6RD not working in latest snapshots
Hi Ermal
Here is the output of the 2 commands you asked me to run on my Jan 18th build where 6RD works:
http://...
Will Wainwright
01:24 PM Bug #2882: 6RD not working in latest snapshots
And that seemed to have been a user error on my part.
My IPv6 firewall rule on LAN had default (ipv4 dhcp) gateway...
Captain Haddock
01:14 PM Bug #2882: 6RD not working in latest snapshots
Ermal Luçi wrote:
> You are talking about tracking interfaces or 6rd tunnel here?
>
> radvd has nothing to do wit...
Captain Haddock
11:51 AM Bug #2882: 6RD not working in latest snapshots
Will Wainwright wrote:
> Hi Chris,
>
> I'm sorry to report that it has not fixed the issue for me.
>
> As alwa...
Ermal Luçi
11:51 AM Bug #2882: 6RD not working in latest snapshots
You are talking about tracking interfaces or 6rd tunnel here?
radvd has nothing to do with 6rd in this ticket.
...
Ermal Luçi
07:49 AM Bug #2882: 6RD not working in latest snapshots
This was seen in log after reboot:
Jun 13 13:29:23 radvd[49436]: resuming normal operation
Jun 13 13:29:23 radvd[...
Captain Haddock
07:47 AM Bug #2882: 6RD not working in latest snapshots
I just tried this out on:
2.1-RC0 (amd64)
built on Wed Jun 12 18:24:47 EDT 2013
FreeBSD 8.3-RELEASE-p8
Afte...
Captain Haddock
03:24 PM Bug #3042: CARP interface handling
This seems like bad news. PfSense with the current carp interface-based failover seemed like an excellent way to do t... Jupiter Vuorikoski
03:10 PM Bug #3042: CARP interface handling
Also newcarp in FreeBSD 10.x does away with the interface notion entirely so I'm not sure it's a viable request for t... Jim Pingle
03:09 PM Bug #3042: CARP interface handling
It's too late for more 2.1 features, removing 2.1 target. Jim Pingle
03:08 PM Bug #3042 (Closed): CARP interface handling
Currently PfSense handles carp interfaces as Layer 3 interfaces with a static IP-address on the created interface. Ho... Jupiter Vuorikoski
02:18 PM Bug #2526: Limiter appears to break IPv6 connectivity
This problem appears to be present in the Wed Jun 12 06:19:03 EDT 2013 build. IPv6 Traffic hits the limiter as shown ... Alex Fox
12:40 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:3e217b8208cdba17060a72a9ccb5fb7ebff9ed25. Renato Botelho
12:30 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:9c0a39f717a04def5d6c0260eb74a7cd0cde8b17. Renato Botelho
11:30 AM Feature #687 (Resolved): Test Button for Growl Notifications
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
11:29 AM Todo #1139 (Resolved): Email notification test button
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
10:17 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Not enough information here for a valid bug report. Please post in the forum where someone can assist you in diagnosi... Jim Pingle
10:15 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Crash report begins. Anonymous machine information:
amd64
8.3-RELEASE-p8
FreeBSD 8.3-RELEASE-p8 #1: Wed Jun 12 ...
Alberto Palau
09:49 AM Feature #2757: CDP/ISDP/LLDP support.
Yeah! It would be great to have CDP in pfsense! Todor K

06/12/2013

10:20 PM Bug #2882: 6RD not working in latest snapshots
Hi Chris,
I'm sorry to report that it has not fixed the issue for me.
As always, please let me know if there's ...
Will Wainwright
01:08 AM Bug #2882: 6RD not working in latest snapshots
confirmed working for me again on the latest snapshot. Will leave this as is for feedback from others for now. Chris Buechler
05:56 PM Revision 00a695c8: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
05:46 PM Revision 46b323f0: Actually do not allow the loop to continue. Related to Ticket #1928
Ermal LUÇI
05:46 PM Revision fb0eb20b: Actually do not allow the loop to continue. Related to Ticket #1928
Ermal LUÇI
05:38 PM Revision 82b7f50a: Don't restrict the content of descr when making CA/Certs, it's free-form.
Jim Pingle
05:16 PM Revision 1f36db1b: Merge pull request #669 from francisuk/patch-1
SWF Ermal Luçi
02:12 PM Feature #3040 (Closed): User friendly firewall log reading
Most of that is already done in 2.1's firewall log view/filtering. The ones that aren't there yet aren't really feasi... Jim Pingle
01:59 PM Feature #3040 (Closed): User friendly firewall log reading
It would be great if the firewall logs could be more debug-friendly:
- have source and destination ports in separate...
Todor K
12:48 PM Bug #3039: New vouchers doesn't sync with CARP slave
Yup, I thought it could be scheduled somehow, but it didn't happen in the next few hours. Todor K
12:45 PM Bug #3039: New vouchers doesn't sync with CARP slave
This is not immediate.
You are sure that you waited enough for the replication to happen?
Ermal Luçi
11:12 AM Bug #3039 (Resolved): New vouchers doesn't sync with CARP slave
Issuing new vouchers on master node is not automatically synced with CARP slave node.
When I go to Services>Captive ...
Todor K
12:16 PM Bug #3015 (Resolved): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Renato Botelho
12:10 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
It's the expected behaviour, if you don't have zones, status menu won't show up. Renato Botelho
11:01 AM Bug #3038 (Resolved): CARP master not stopping slave's Captive portal
Having CARP active with two nodes, when I start Captive service on master it starts it on the slave node too.
But st...
Todor K
07:05 AM Revision 1da5d1d7: Actually try to get the real interface for v6 family to correctly get stf(virtual) interfaces
Ermal LUÇI
07:05 AM Revision 8984529d: Actually try to get the real interface for v6 family to correctly get stf(virtual) interfaces
Ermal LUÇI
02:28 AM Revision 8d1eb49e: SWF
As said on the pFsense forum http://forum.pfsense.org/index.php/topic,62863.0.html It works and tested by me. francisuk

06/11/2013

08:36 PM Revision 43b9f062: Merge pull request #668 from mdima/RELENG_2_1
Status-Queues: Get the stats gauge for PPS or bandwidth Edit (RELENG_2_1) Ermal Luçi
08:18 PM Revision e59bd273: Status-Queues: Get the stats gauge for PPS or bandwidth Edit
Let the user select the values to show in the stats gauge between PPS and bandwidth. Michele Di Maria
07:31 PM Revision 8959f2fc: Correct the command for setting the 6rd gw
Ermal LUÇI
06:33 PM Revision f0f714c5: Correct the command for setting the 6rd gw
Ermal LUÇI
02:08 PM Bug #2882 (Feedback): 6RD not working in latest snapshots
should work with tomorrow's snapshot. Chris Buechler
01:55 PM Bug #3037 (Resolved): Unable to delete PRIQ queues
If you use PRIQ, you cannot delete any queues, even ones that were created manually. The delete button does not appea... Jim Pingle
11:42 AM pfSense Packages Bug #3036 (Resolved): Small web interface bug
Hi there!
That's my first bug report and I hope it's well done :)
Services>Snort
Add or edit interface>Alert Set...
Todor K
10:15 AM Bug #3020: HFSC Priority
Heh that is just a copy/pasto from implementation.
Will probably fix that.
Ermal Luçi
10:02 AM Revision 7fdd0c73: Wait 1 second before starting the other dhcp6c since pkill does not wait for the process to exit
Ermal LUÇI
10:02 AM Revision b90ae531: Wait 1 second before starting the other dhcp6c since pkill does not wait for the process to exit
Ermal LUÇI

06/10/2013

08:43 PM Revision 89784e55: Do better checks and do not include an interface that will be skipped to the known ifaces
Ermal LUÇI
08:43 PM Revision 60c05056: Do better checks and do not include an interface that will be skipped to the known ifaces
Ermal LUÇI
06:56 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I just tested this again on a fresh OVA. I found that starting from a fresh install (i.e. no zones), creating a zone,... Christian McDonald
03:47 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
it shouldn't show up anywhere when there are no zones defined, I've noticed that changed in 2.1. In 2.0.x and previou... Chris Buechler
03:32 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can only reproduce that when I have no zones defined. If I have a zone defined, it always shows up for me. Jim Pingle
03:30 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Christian McDonald wrote:
> I can reproduce this on two pfSense boxes each running:
>
> 2.1-RC0 (amd64)
> built...
Renato Botelho
11:06 AM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can reproduce this on two pfSense boxes each running:
2.1-RC0 (amd64)
built on Thu Jun 6 21:08:57 EDT 2013
Christian McDonald
06:28 AM Bug #3035 (Feedback): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Not reproducible here, as you can see on attached screenshot. Renato Botelho
06:58 AM Revision c848b448: Merge pull request #667 from mdima/master
Status-Queues: Get the stats gauge for PPS or bandwidth Ermal Luçi
06:47 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
Seems like a local issue, I could not reproduce. You should try to get help on forums and mailing lists to try to fig... Renato Botelho
06:30 AM Bug #3034: Security FLAW in pfSense Wireless Found
What is the length of the password you got the issue? Renato Botelho

06/09/2013

10:27 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
!http://i.imgur.com/SgaFqaO.png! Christian McDonald
10:24 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
When viewing the Captive Portal Status, the menu item for Status->Captive Portal Disappears
Steps to reproduce:
...
Christian McDonald
06:43 PM Bug #3034 (Resolved): Security FLAW in pfSense Wireless Found
I have found a security flaw in pfSense wireless. If you enable WPA2 for security and use a password for the pre shar... Steven Anderson
09:33 AM Revision 87428ee8: Status-Queues: Get the stats gauge for PPS or bandwidth
Let the user select the values to show in the stats gauge between PPS and bandwidth. Michele Di Maria

06/08/2013

05:24 PM Revision f57e4181: Replace hardcoded path by vardb_path
Renato Botelho
05:08 PM Bug #3033 (Rejected): Static IPv6 route to OpenVPN tunnel ignored
I have an openvpn tunnel to a remote server which works correctly for IPv4 traffic but not for IPv6. When the remote ... Lakin Lowrey
02:18 PM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
test on 2.1 and report more info on forum if you can still replicate Chris Buechler
03:17 AM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
hi
in my 2.0.3 amd64 captive portal last activity was periodically (every minutes?) reset to the system boot time:...
Fabio Faro
03:32 AM Bug #2752: Captive Portal Last Activity isn't update anymore --> idle timeout just after login
i have two installation with 2.0.3 but the problem still exist.
i opened a new segnalation (3032)
thx
Fabio Faro

06/07/2013

02:27 PM Bug #3020: HFSC Priority
Ermal Luçi wrote:
> HFSC does not have notion of priority.
Ok, sorry for this report but I Sugere remove or corre...
Julien Bénic
11:35 AM Feature #3031 (Resolved): Message is false after changing Hardware Checksum Offloading setting
It seems that appliance needs to reboot after changing the advanced networking setting.
System -> Advanced, click ...
c vt
11:14 AM Bug #3030 (Resolved): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
If you are using LAGG+VLAN interfaces (e.g. lagg0_vlan10) in the shaper wizard, the wizard does not fill in the bandw... Jim Pingle
03:17 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Having similar issues:
2.1 RC0 (symptoms started from 2.03 on as far as i can remember)
Policy Generation > Uni...
Peter Borföi
03:12 AM pfSense Packages Bug #999: vhosts does not show up as started
Hi!
Could you tell us how to fix it.
I think two years it's so much time to fix this little problem (talking ab...
Net Vicious

06/06/2013

11:44 PM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Thanks a lot for your time and sorry for the useless ticket opening. Imrane Dessai
08:45 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
IP Alias VIPs don't work that way, but proxy ARP VIPs are not and cannot be compatible in the way you describe.
On...
Jim Pingle
08:43 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Ip Alias can't expand a whole network withing a single line of conf
When configuring a Proxy ARP you can specify a...
Imrane Dessai
08:28 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
no need. IP alias or more CARP. Chris Buechler
07:46 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
Hi,
We are using a cluster pfSense to NAT 1:1 two network.
I need to make Proxy ARP VIP to bind to CARP Interfa...
Imrane Dessai
05:55 PM Revision 39b84ccc: Allow localhost IP Alias VIPs to sync, too
Jim Pingle
05:55 PM Revision 56bf3ef1: Allow selecting "Localhost" as an interface for IP Alias VIPs - this way you can make IP Alias VIPs to use for binding in a routed scenario with CARP without creating an IP conflict.
Jim Pingle
05:54 PM Revision 48c16cab: Allow localhost IP Alias VIPs to sync, too
Jim Pingle
05:50 PM Revision 19d90bce: Allow selecting "Localhost" as an interface for IP Alias VIPs - this way you can make IP Alias VIPs to use for binding in a routed scenario with CARP without creating an IP conflict.
Jim Pingle
04:53 PM Feature #3029 (Resolved): DHCPv6 Server/RA page should list interfaces that are configured to track DHCP-PD
The configuration page for the DHCPv6 server and router advertisements currently only lists those interfaces that hav... Daniel Becker
04:31 PM Bug #3028 (Resolved): Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
I notice that configuring DHCP-PD starts a dhcpd server on the tracking (LAN) interface that serves up the delegated ... Daniel Becker
04:01 PM Bug #2412 (Resolved): inbound 6to4 traffic does not work in pf
Ermal Luçi
12:55 PM Bug #2412: inbound 6to4 traffic does not work in pf
I can confirm that this is working as intended. Thank you for fixing it. We are mainly using this to test ipv6 capabi... Richard Adams
02:08 PM Bug #3027 (Resolved): input_errors2Ajax function
In various places input_errors2Ajax() is used. However this function doesn't exist.
I'm assuming the original intent...
Warren Baker
10:22 AM Bug #3026: not all interfaces will get their designated IP after I add an IP to an interface
What you are saying is you go and set a static ip to an interface and the interface didn't get that IP address config... Renato Botelho
09:33 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
When I add an IP to an interface my pfsense will become unresponsive for a minute.
On Zabbix I can see the system lo...
frater fenantius
03:36 AM Bug #3016 (Resolved): IPsec client (or branch office) can't access to Internet over VPN gateway
Chris Buechler
03:29 AM Bug #3023 (Rejected): Snort + Intel NIC not working on 2.1 RC0
probably promiscuous broken in the 8.3 fxp driver. There's another ticket open to back port a newer driver. Chris Buechler
02:11 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Same problem here running:
2.0.3-RELEASE (amd64)
Client can connect OK for the first session but then after dis...
Ignat Esso
 

Also available in: Atom