Project

General

Profile

Activity

From 06/18/2013 to 07/17/2013

07/17/2013

05:48 PM Revision 845adb35: Sync p0f database for OS detection w/current file from FreeBSD
Jim Pingle
05:48 PM Revision 436a9a88: Sync p0f database for OS detection w/current file from FreeBSD
Jim Pingle
03:51 PM Revision bb236920: This is not a percentage
Jim Pingle
03:51 PM Revision 10452f6c: This is not a percentage
Jim Pingle
03:29 PM Revision 09f26fb7: Remove remaining hardcoded theme names
Renato Botelho
03:29 PM Revision 7bc1b968: Remove remaining hardcoded theme names
Renato Botelho
02:53 PM Revision dc3fc54a: Don't blow up the config if someone enters int'l chars in an LDAP attribute/DN field. Ticket #2227
Jim Pingle
02:52 PM Revision bcf4b8cc: Don't blow up the config if someone enters int'l chars in an LDAP attribute/DN field. Ticket #2227
Jim Pingle
02:15 PM Revision 298020b2: Add LDAP server options to control UTF8-encoding of parameters. Fixes #2227. While I'm here, add a checkbox to prevent the stripping of @ from the LDAP username if the user wants the full name transmitted.
Jim Pingle
02:13 PM Revision a5cd1c5a: Add LDAP server options to control UTF8-encoding of parameters. Fixes #2227. While I'm here, add a checkbox to prevent the stripping of @ from the LDAP username if the user wants the full name transmitted.
Jim Pingle
01:55 PM Bug #2484 (Resolved): Serial console speed has no effect on NanoBSD
Jim Pingle
01:54 PM pfSense Packages Bug #2902 (Resolved): Snort does not update snort.org (basic?) rules. Possibly clock blocking by snort.org for basic subscribers.
This resolved itself once the proper rules were open to all. Jim Pingle
01:51 PM Feature #2973 (Resolved): send test mail button
This was added a couple weeks ago. Jim Pingle
01:51 PM pfSense Packages Bug #2992 (Feedback): Boot problem after upgrade
Needs info on how to reproduce it before anything can be done. Jim Pingle
01:49 PM Bug #3011 (Rejected): Mobile client disconnect but SA not flushing
Duplicate of #1351 (which has since been fixed) Jim Pingle
01:45 PM Bug #3072 (Resolved): ova snapshot not available
This was fixed a while back, the directory has snapshots in it now. Jim Pingle
11:12 AM Feature #2989 (Resolved): Changing language english to turkish not effect
Renato Botelho
09:56 AM Bug #3095 (Resolved): Name column uses old (original) interface name
Name column uses old/original interface name (OPT1 in my case) when the interface has been renamed. The interface nam... Patrik Lundquist
09:20 AM Bug #2227: International / UTF-8 characters not working in LDAP configuration
Applied in changeset commit:298020b2b6efa75c863bafef9a078c285a2b9ed6. Jim Pingle
09:20 AM Bug #2227 (Feedback): International / UTF-8 characters not working in LDAP configuration
Applied in changeset commit:a5cd1c5a4286062b84caf32df860f2e2f2e204aa. Jim Pingle
07:18 AM Bug #3094 (Rejected): LDAP authentication, password with non-standard letters
Duplicate of #2227 Jim Pingle
05:44 AM Bug #3094 (Rejected): LDAP authentication, password with non-standard letters
Hello,
I've been using LDAP authentication server for logging to pfSense webinterface for over a year now and everyt...
Pawel Szafer
01:36 AM pfSense Packages Bug #3093: squid3-dev missing libgssapi.so.10
Possibly the AUTH_KERB compile time option should be removed or /usr/ports/security/krb5 built or Kerberos added to b... Warren Baker
12:31 AM pfSense Packages Bug #3093 (Closed): squid3-dev missing libgssapi.so.10
On current snapshots (2.1-RC0 (amd64) built on Tue Jul 16 16:31:05 EDT 2013 FreeBSD 8.3-RELEASE-p8), the squid3-dev p... Adam Thompson

07/16/2013

08:09 PM Revision 2cb760da: Some more tweaks to state and mbuf update/output on dashboard widget.
Jim Pingle
08:09 PM Revision f8b00778: Some more tweaks to state and mbuf update/output on dashboard widget.
Jim Pingle
07:56 PM Revision 97f544d7: Use some easier to distinguish colors for mbuf graph
Jim Pingle
07:56 PM Revision 84962c63: Use some easier to distinguish colors for mbuf graph
Jim Pingle
07:39 PM Revision bdc3d5ca: Add a meter for states, too
Jim Pingle
07:39 PM Revision 48a01496: Fixup mbuf stats function
Jim Pingle
07:39 PM Revision 4a83831c: Add a meter for states, too
Jim Pingle
07:39 PM Revision 2c7f71d9: Fixup mbuf stats function
Jim Pingle
07:34 PM Revision eb8e0aa9: Call interface_ipalias_cleanup() after $interface is initialized, and get current IP after it
Renato Botelho
07:31 PM Revision de8f0075: Call interface_ipalias_cleanup() after $interface is initialized, and get current IP after it
Renato Botelho
07:09 PM Revision 8ff9cc38: Make mbufs update via ajax
Jim Pingle
07:08 PM Revision e4a0be9b: Make mbufs update via ajax
Jim Pingle
07:02 PM Revision bc3e2c14: Fix ids
Jim Pingle
07:02 PM Revision 980b9cc6: Fix ids
Jim Pingle
06:55 PM Revision 47642992: Fix an occasional "blank" cpu freq printing that shouldn't happen.
Jim Pingle
06:55 PM Revision f5c47a7c: Fix an occasional "blank" cpu freq printing that shouldn't happen.
Jim Pingle
06:51 PM Revision bd5629b6: Make mbuf usage a meter, too.
Jim Pingle
06:51 PM Revision e7da8698: Make mbuf usage a meter, too.
Jim Pingle
06:43 PM Revision 7041c01a: Show totals for memory, swap, and disk usage.
Jim Pingle
06:42 PM Revision 0425af72: Show totals for memory, swap, and disk usage.
Jim Pingle
06:24 PM Bug #2882: 6RD not working in latest snapshots
Hi ermal,
I fired up my July 12th pfsense vm and "6RD IPv4 Prefix length" only goes from 0 to 31 bits.
netstat ...
Will Wainwright
04:04 PM Bug #2882: 6RD not working in latest snapshots
Hi ermal,
Charter specifies the following setting for their 6RD service:
6rd Prefix = 2602:100::/32
Bo...
Will Wainwright
03:30 PM Bug #2882: 6RD not working in latest snapshots
I think you should set your prefix to /64 in your wan configuration hence the problems.
Also the netstat command i...
Ermal Luçi
03:15 PM Bug #2882: 6RD not working in latest snapshots
Hi ermal,
Here is the requested command output:
http://pastebin.com/e7QrYfzG
And here are the config.xml sec...
Will Wainwright
06:14 PM Revision 3ed917c7: Add an RRD graph for MBUFs under system. Tweaks welcome.
Jim Pingle
06:14 PM Revision ae9cb658: Add an RRD graph for MBUFs under system. Tweaks welcome.
Jim Pingle
05:27 PM Revision 8a0c14c3: If an account has SSH keys, show them, don't show the checkbox to add keys. Fixes #2729
Jim Pingle
05:27 PM Revision 1c8faa89: If an account has SSH keys, show them, don't show the checkbox to add keys. Fixes #2729
Jim Pingle
03:30 PM Bug #2627 (New): Old delegated prefixes are not removed from the LAN interface
Not fixed yet Renato Botelho
02:08 PM Bug #2627 (Feedback): Old delegated prefixes are not removed from the LAN interface
It should be better on last snapshots Renato Botelho
03:30 PM Bug #2495 (New): pfsense doesn't seem to know what its WAN IP is
Not fixed yet. Renato Botelho
02:36 PM Bug #2495 (Feedback): pfsense doesn't seem to know what its WAN IP is
Please check tomorrow's snapshot Renato Botelho
01:53 PM Revision 241eed1a: Don't generate reflection rules if reflection is disabled for that rule.
Jim Pingle
01:52 PM Revision 7a10e3eb: Don't generate reflection rules if reflection is disabled for that rule.
Jim Pingle
12:52 PM Revision 4e69371b: Do not break ppp type interfaces on v6
Ermal LUÇI
12:52 PM Revision 4cc3bb6c: Do not break ppp type interfaces on v6
Ermal LUÇI
12:30 PM Bug #2729: UserManager has no indication that an account has an authorized_keys key defined
Applied in changeset commit:8a0c14c3e44b3ccf79db2dec4e836a6ca6367f75. Jim Pingle
12:30 PM Bug #2729 (Feedback): UserManager has no indication that an account has an authorized_keys key defined
Applied in changeset commit:1c8faa89b9aab2d7ab7aef9837d9c9e436ada9c7. Jim Pingle
07:47 AM Revision 5128e0fe: For ppp interfaces the real interface is not present anymore in the xml config section of the interface. Due to this do some more work on extracting the real interface when ipv4 is pppoe/ppp/... and ipv6 configuration files will use the wrong interface to request information from provider. Reported-by: http://forum.pfsense.org/index.php/topic,64483.0.html
Ermal LUÇI
07:47 AM Revision 15a73ba8: For ppp interfaces the real interface is not present anymore in the xml config section of the interface. Due to this do some more work on extracting the real interface when ipv4 is pppoe/ppp/... and ipv6 configuration files will use the wrong interface to request information from provider. Reported-by: http://forum.pfsense.org/index.php/topic,64483.0.html
Ermal LUÇI
07:09 AM Bug #2303 (Feedback): SPD on secondary not cleared after config sync
It's not related to this issue, if you still have a problem please open a ticket for it. Renato Botelho

07/15/2013

08:05 PM Revision cd577ebd: Enable filtering on ipfw sysctl not dependent on ipfw module otherwise issue reported here http://forum.pfsense.org/index.php/topic,64412.0.html happens
Ermal LUÇI
08:05 PM Revision 2657f21f: Enable filtering on ipfw sysctl not dependent on ipfw module otherwise issue reported here http://forum.pfsense.org/index.php/topic,64412.0.html happens
Ermal LUÇI
02:02 PM Revision 23c652cd: Ignore errors/warnings from these calls
Ermal LUÇI
01:58 PM Revision 1ed5aaa8: Ignore errors/warnings from these calls
Ermal LUÇI
12:40 PM Revision f3fa5b69: Merge pull request #682 from CharlieMarshall/pfsense_ng_fs
new theme "pfsense_ng_fs" & allow themes to add / delete additional widget columns Renato Botelho
07:00 AM Feature #701: Interface groups with NAT
can this be implemented like under NAT port forward page u select the interface group and the pfsense creates same ru... Bipin Chandra
03:40 AM Bug #1047: Disable TSO, hardware checksum don't work for unassigned but active interfaces
please reopen this bug Zeev Zalessky

07/14/2013

08:15 PM Revision ab17ed4e: support mitigating BEAST attack
According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30
"...by setting
ssl.cipher-list = "EC...
Dim Hatz
08:14 PM Revision 3487a5c2: Merge pull request #683 from dhatz/RELENG_2_1
support mitigating BEAST attack, see http://forum.pfsense.org/index.php/topic,63001.0.html Jim Pingle
06:49 PM Revision 23ea4d2a: services_dhcrelay6_configure developerspew debug text fix
Phil Davis
06:48 PM Revision 64ad3cc8: Start DHCrelay6 on boot
Phil Davis
06:24 PM Revision fa535f75: Correctly decide if dhcrelay is enabled
Phil Davis
06:23 PM Revision da60727c: Merge pull request #712 from phil-davis/master
Correctly decide if dhcrelay (v4) is enabled Jim Pingle
04:15 PM Revision 4701c8de: Correctly decide if dhcrelay is enabled
Phil Davis
02:22 PM Bug #1047: Disable TSO, hardware checksum don't work for unassigned but active interfaces
i have the problem on pfsense 2.1 RC0 latest snapshot Zeev Zalessky
02:18 PM Bug #1047: Disable TSO, hardware checksum don't work for unassigned but active interfaces
the bug is not fixed. i have same problem with Intel X540-T2 and X520-DA cards. attached my configuration and output ... Zeev Zalessky
01:53 PM Bug #3092 (Rejected): Disable LRO not affecting Intel 10G NICs
Duplicate of #1047. Comment there if it's not fixed. Jim Pingle
06:49 AM Bug #3092: Disable LRO not affecting Intel 10G NICs
i found workaround using shellcmd package. i just run ifconfig ix(0-3) -lro using shellcmd, but i don't think that it... Zeev Zalessky
02:12 AM Bug #3092 (Rejected): Disable LRO not affecting Intel 10G NICs
Hello,
i have firewall with 2 dual-port Intel 10G NICs, one X520 DA2 and one X540-T2. i checked disable LRO in web...
Zeev Zalessky

07/13/2013

06:52 PM Revision b5cd5163: Teach service start stop restart about dhcrelay6
Phil Davis
06:52 PM Revision d86ec4e0: Consistent dhcrelay6 pid file location
Phil Davis
06:50 PM Revision 6a4e4405: Merge pull request #711 from phil-davis/master
Teach services code about start stop restart of dhcrelay6 Jim Pingle
04:18 PM Revision 9590e0de: Teach service start stop restart about dhcrelay6
Phil Davis
04:16 PM Revision 54a9d71d: Consistent dhcrelay6 pid file location
Phil Davis
03:01 PM Revision 68bbaf06: Merge pull request #710 from phil-davis/master
Start DHCrelay6 on boot Ermal Luçi
02:42 PM Revision 63b8c4db: Fix #3091, fix bad var assignment
Renato Botelho
02:41 PM Revision 45eb8aeb: Fix #3091, fix bad var assignment
Renato Botelho
01:15 PM Revision 06433d75: Start DHCrelay6 on boot
Phil Davis
01:03 PM Feature #1663: DHCPv6 relay
Grrr, missed one part of the patch... All works now:
- service started on boot
- Pv6 addresses assigned
- the enab...
Doktor Notor
11:46 AM Feature #1663: DHCPv6 relay
Afraid the thing still does not get stopped with 711. Doktor Notor
11:34 AM Feature #1663: DHCPv6 relay
Starting at boot is resolved by https://github.com/pfsense/pfsense/pull/710
Stop/start/restart and enable/disable of...
Phillip Davis
01:02 PM Bug #3075: Can't delete unused Virtual IP "referenced by a least one gateway"
Sent to forum on 9th July
http://forum.pfsense.org/index.php/topic,64326.0.html
I have just updated to the latest...
Dan Lundqvist
12:49 PM Revision 874f099a: services_dhcrelay6_configure developerspew debug text fix
Phil Davis
09:40 AM Bug #3091: Bad variable assignment in apinger setup (gwlb.inc)? Not sure the fix
Applied in changeset commit:63b8c4db3bebb0e203dd6903f310ca87ef3e8061. Renato Botelho
09:40 AM Bug #3091 (Feedback): Bad variable assignment in apinger setup (gwlb.inc)? Not sure the fix
Applied in changeset commit:45eb8aeb5839b52af9f9e82cecdc5ed5579656f5. Renato Botelho
06:57 AM Bug #3091 (Resolved): Bad variable assignment in apinger setup (gwlb.inc)? Not sure the fix
About line 179 gwlb.inc:... Stilez y
07:52 AM Todo #2942: PHP-Growl: Growl Talk Notifications UDP 9887 implementation deprecated. GNTP is the new standard notification protocol.
Devs,
I know this isn't a core feature or functionality but with the research and solutions proposed, I'd apprecia...
Mahdi Hedhli
02:56 AM Bug #3077: FTP patches in revision 39802d4e cause kernel panics on FTP traffic
Well guys, I got another panic when messing with FTP downloads from ftp://ftp-archive.freebsd.org/. (No serial consol... Doktor Notor

07/12/2013

07:59 AM Revision 95cb619c: Substitute Product name in privileges
Warren Baker
07:58 AM Revision 74bd3c3f: Substitute Product name in privileges
Warren Baker
07:57 AM Revision e811fcbe: Substitute Product name in privileges
Warren Baker
06:44 AM Revision c1ecdca2: Merge pull request #709 from razzfazz/RELENG_2_1
properly handle custom-v6 dyndns entries in web interface Ermal Luçi
06:43 AM Revision d57da568: Merge pull request #708 from razzfazz/master
properly handle custom-v6 dyndns entries in web interface Ermal Luçi
03:19 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
Sadly, I keep hitting this with http://snapshots.pfsense.org:... Doktor Notor

07/11/2013

10:49 PM Revision 6acbb7d2: properly handle custom-v6 dyndns entries in web interface
Daniel Becker
10:48 PM Revision e4a62f32: properly handle custom-v6 dyndns entries in web interface
Daniel Becker
07:18 PM Revision fd4fc120: Move variable declaration to the top, declare it global before defining. Fixes #3090
Jim Pingle
07:18 PM Revision 469e3333: Remove irrelevant comment.
Jim Pingle
07:17 PM Revision e09b941d: Move variable declaration to the top, declare it global before defining. Fixes #3090
Jim Pingle
07:17 PM Revision a5a2fc68: Remove irrelevant comment.
Jim Pingle
02:29 PM pfSense Packages Bug #3090: CRL manager - revocation reason dropdown is no-op
Weird... when the poor little thing really gets abused too heavily and runs out of RAM, I get php killed in system lo... Doktor Notor
02:23 PM pfSense Packages Bug #3090 (Resolved): CRL manager - revocation reason dropdown is no-op
For the record, it seems to be that when an ALIX is starved for RAM, somehow globals start disappearing unless they'r... Jim Pingle
02:17 PM pfSense Packages Bug #3090: CRL manager - revocation reason dropdown is no-op
Fixed by... Doktor Notor
01:17 PM pfSense Packages Bug #3090: CRL manager - revocation reason dropdown is no-op
> Once a cert is added to the CRL, the reason column is filled in.
Negative, Captain :-)
!http://i40.tinypic.co...
Doktor Notor
01:15 PM pfSense Packages Bug #3090: CRL manager - revocation reason dropdown is no-op
Tried it on a VM full install and ALIX both on a current snapshot, reason drop-down is always filled in for me. Jim Pingle
01:12 PM pfSense Packages Bug #3090 (Rejected): CRL manager - revocation reason dropdown is no-op
Is there a forum thread for this?
It works fine for me. Once a cert is added to the CRL, the reason column is filled...
Jim Pingle
01:10 PM pfSense Packages Bug #3090 (Resolved): CRL manager - revocation reason dropdown is no-op
As per subject.
!http://i40.tinypic.com/k0ndyu.png!
Doktor Notor
02:03 PM Revision d45fdd2a: Fix copy/pasto introduced in previous commit.
Ermal Luçi
01:59 PM Revision 5b0f7191: Fix copy/pasto introduced in previous commit.
Ermal Luçi
12:57 PM pfSense Packages Bug #2856 (Resolved): OpenVPN Client Export Utility does not handle Spaces in Common Name (CN) of user certificate
Jim Pingle
12:56 PM pfSense Packages Bug #2856: OpenVPN Client Export Utility does not handle Spaces in Common Name (CN) of user certificate
> Of course the best fix is to not stick spaces in a CN. :-)
Kinda troublesome when you already have tens and tens...
Doktor Notor
12:49 PM pfSense Packages Bug #2856: OpenVPN Client Export Utility does not handle Spaces in Common Name (CN) of user certificate
Of course the best fix is to not stick spaces in a CN. :-) Jim Pingle
12:40 PM pfSense Packages Bug #2856 (Feedback): OpenVPN Client Export Utility does not handle Spaces in Common Name (CN) of user certificate
Applied in changeset commit:2916a9051a4e60c64ecd2732b652a12696d3295e. Jim Pingle
11:19 AM pfSense Packages Bug #2856: OpenVPN Client Export Utility does not handle Spaces in Common Name (CN) of user certificate
This is still broken even with latest version. Doktor Notor
08:58 AM pfSense Packages Bug #3088 (Rejected): Squid log rotate
Please post in the forum for assistance in diagnosing the issue before opening a bug report. There isn't nearly enoug... Jim Pingle
08:55 AM pfSense Packages Bug #3088 (Rejected): Squid log rotate
After a system boot, squid don't suceed to rotate logs, so I need stop and restart squid to enable log rotate Marco Tomas
07:02 AM Revision 03ffccb9: Merge pull request #707 from razzfazz/RELENG_2_1
Merge to RELENG_2_1: Support for protocol 41 in rules, support for HE.net AAAA record updates, and support for custom... Ermal Luçi
02:05 AM Revision b54b997d: Add support for custom IPv6 DDNS.
Daniel Becker
02:01 AM Revision c3101e14: Change separator as per JimP's request.
Daniel Becker
02:00 AM Revision 93749c10: Add front-end support for dyndns AAAA updates
Daniel Becker
02:00 AM Revision e4ba18aa: Clean up HE.net AAAA backend support.
Daniel Becker
02:00 AM Feature #3007: "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Applied in changeset commit:26f80aff92ea3f70301273d869d30c68d4b73d48. Daniel Becker
02:00 AM Revision 5a55d9d7: Add backend support for HE.net AAAA record updates.
Defines a new DynDNS provider 'he-net-v6' for updating AAAA entries on
dns.he.net.
Daniel Becker
01:46 AM Revision 26f80aff: Add support for protocol 41 in rules. Fixes #3007.
Daniel Becker

07/10/2013

07:49 PM Revision f34fcff4: Don't automatically add hidden rules to pass all IPv6 traffic to/from delegated prefixes. Default IPv6 from LAN -> any rule covers outbound properly as-is, and WAN rules shouldn't pass in that permissively. Also the prefix length calculation was off and the LAN rule(s) would be too permissive anyhow.
Jim Pingle
07:49 PM Revision ac203513: Don't automatically add hidden rules to pass all IPv6 traffic to/from delegated prefixes. Default IPv6 from LAN -> any rule covers outbound properly as-is, and WAN rules shouldn't pass in that permissively. Also the prefix length calculation was off and the LAN rule(s) would be too permissive anyhow.
Jim Pingle
06:14 PM Feature #3087 (New): Setup Wizard does not include IPv6 options for interfaces
The wizard which runs during the first login to the web-gui does not give options for configuring IPv6 on the LAN or ... Graeme Bragg
03:28 PM Revision bc59bcff: Implement proper releasing of pipes allocated based on CPzone. Keep track of which zone a pipe is and release those pipes during disabling/deleting of zone. Ticket #3062, Pull request #698
Ermal LUÇI
03:27 PM Revision de2fe652: Use empty to cover all needed cases as suggested on #3062. Suggested from pull request #698
Ermal LUÇI
03:26 PM Revision 7fb23399: Implement proper releasing of pipes allocated based on CPzone. Keep track of which zone a pipe is and release those pipes during disabling/deleting of zone. Ticket #3062, Pull request #698
Ermal LUÇI
03:20 PM Revision 0f50d70d: Use empty to cover all needed cases as suggested on #3062. Suggested from pull request #698
Ermal LUÇI
03:01 PM Revision 4624f50f: Merge pull request #703 from razzfazz/dyndns_custom_v6
Add support for HE.net AAAA record updates. Fixes #1825. Ermal Luçi
03:00 PM Bug #3086 (Rejected): OpenVPN tunnel traffic shaping
config issue, not a bug Chris Buechler
02:55 PM Bug #3086 (Rejected): OpenVPN tunnel traffic shaping
I used pfsense to link two remote networks via openvpn. The tunnel will be used to encrypt VOIP between the two netwo... Ioannis Kampolis
01:01 PM Feature #1663: DHCPv6 relay
Also, the service does not start on boot, since there is no mention of services_dhcrelay6_configure() in /etc/rc.bootup Doktor Notor
12:52 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
The problem is still there, but now I have noticed an additional behavior. I have taken the liberty to email you some... Anonymous
12:28 PM Bug #2409 (Feedback): ipfw - entryzerostats
Renato Botelho
12:26 PM Bug #2332 (Feedback): gateways always renamed to "dynamic". Implement proper IPv6 support
This seems the same root cause as #2910 Ermal Luçi
10:01 AM Feature #1825 (New): Dynamic DNS client IPv6 support
Since this works for RFC2136 and he.net now, we can set it to partially done, but not completely done. (Redmine autom... Jim Pingle
10:00 AM Feature #1825 (Feedback): Dynamic DNS client IPv6 support
Applied in changeset commit:4624f50fce5f1f41306d6852ca2922079b9d1694. Ermal Luçi
08:57 AM Feature #371: Allow moving of bogon and RFC 1918 rules
Checkboxes for logging were added yesterday in commit:a19fcb824c8d443cafa42f7d826407e475f40fa8
Moving to "real" ru...
Jim Pingle
08:53 AM Feature #371: Allow moving of bogon and RFC 1918 rules
I'd have to agree with what Doktor Notor wrote above, and I'd rather strongly agree: this takes hours and hours to tr... Hollander Hollander
08:34 AM pfSense Packages Bug #3085 (Resolved): squidguard: problems when importing a blacklist archive containing soft-links
I'm sure it's a quick-solved issue :
when importing a blacklist.tar.gz containing soft-links, the links are lost in...
Greg Lauriol

07/09/2013

04:02 PM Revision 1cf24f0a: Add independent logging choices to disable logging of bogon network rules and private network rules. Add upgrade code to obey the existing behavior for users (if default block logging was disabled, so is bogon/private rule blocking). Also add a checkbox to disable the lighttpd log for people who don't want their system log spammed by lighty.
Jim Pingle
04:00 PM Revision a19fcb82: Add independent logging choices to disable logging of bogon network rules and private network rules. Add upgrade code to obey the existing behavior for users (if default block logging was disabled, so is bogon/private rule blocking). Also add a checkbox to disable the lighttpd log for people who don't want their system log spammed by lighty.
Jim Pingle
03:55 PM Bug #3077: FTP patches in revision 39802d4e cause kernel panics on FTP traffic
> Please do not use redmine as a bug tracking.
Call me confused. Isn't bug tracking the whole purpose of issue tra...
Doktor Notor
03:27 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Jim P wrote:
> That page shows the status of the _previous_ filter reload. If it was successful, it will say so.
> ...
Mark Tiramani
03:01 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
That page shows the status of the _previous_ filter reload. If it was successful, it will say so.
Pressing the butto...
Jim Pingle
02:49 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
> Also, where is it stated that to reload the filter set after a rule change the user must navigate to this page and ... Doktor Notor
02:28 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Doktor Notor wrote:
> Uhm... what do you mean by "manually"? Without clicking the button, the filter does not reload...
Mark Tiramani
02:01 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
> I then did "Status->Filter Reload" but this time I clicked on the "Reload Filter" button manually. Bingo. The rules... Doktor Notor
01:40 PM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Jim P wrote:
> Rather than doing a rule save, reboot, etc, wait a few moments and go to Status > Filter Reload, and ...
Mark Tiramani
10:58 AM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Jim P wrote:
> If you trigger too many filter reloads too fast it's possible that check_reload_status is eating the ...
Mark Tiramani
07:36 AM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
If you trigger too many filter reloads too fast it's possible that check_reload_status is eating the reload events be... Jim Pingle
07:13 AM Bug #3083: Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Chris Buechler wrote:
> not true. Has to be states. Maybe that in combination with something delaying your filter re...
Mark Tiramani
06:16 AM Bug #3083 (Rejected): Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
not true. Has to be states. Maybe that in combination with something delaying your filter reload enough that a new st... Chris Buechler
04:16 AM Bug #3083 (Resolved): Firewall rule toggle fails after several enable/disable cycles : 2.1 RC0 and 2.0.3 release
Please see the description in my forum post for more details:
http://forum.pfsense.org/index.php/topic,64098.0.html
...
Mark Tiramani
03:08 PM Revision e7bc770e: Fix the "use ICMP" function for traceroute.
Jim Pingle
03:01 PM Revision f09c5600: Fix the "use ICMP" function for traceroute.
Jim Pingle
02:45 PM Feature #2704 (Feedback): dhclient refuse certain DHCP offers (e.g. private RFC1918 leases on WAN)
I added an option for this in commit:850324a23e45b3a11231f910290f8ff9b774d9bc a few weeks ago, forgot the ticket exis... Jim Pingle
11:39 AM Feature #3007: "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Would you mind merging this into RELENG_2_1 as well? Daniel Becker
08:56 AM Bug #3084: bsnmpd stopped working when openvpn is activated
just saw this in my log files maybe it will help
@
Jul 9 15:54:47 php: rc.newwanip: pfSense package system has de...
Claudius Badmind
08:42 AM Bug #3084 (Closed): bsnmpd stopped working when openvpn is activated
hi,
when i activate openvpn my bsnmpd service stop working after 10 minutes or less ....
I always have to start i...
Claudius Badmind
07:52 AM Bug #3045 (New): NTPD crash / doesn't come up
Still crashes easily.
I can reproduce it on a VM very easily. I have two test VMs with an OpenVPN tunnel in betwee...
Jim Pingle
07:27 AM Bug #3045: NTPD crash / doesn't come up
Could you confirm if the problem persists on more recent snapshots? Renato Botelho
07:35 AM Bug #2627 (New): Old delegated prefixes are not removed from the LAN interface
Renato Botelho
07:35 AM Bug #2303 (New): SPD on secondary not cleared after config sync
Renato Botelho
07:35 AM Bug #2409 (New): ipfw - entryzerostats
Renato Botelho
07:34 AM Bug #2495 (New): pfsense doesn't seem to know what its WAN IP is
Renato Botelho
07:29 AM Bug #2959 (Resolved): Traffic Shaper: Penalty Network Alias Not Applied to Rule
Renato Botelho
07:28 AM Bug #3001 (Resolved): Captive portal Voucher sync on HTTPS with custom port
Renato Botelho
06:59 AM Bug #3078 (Resolved): NanoBSD upgrade gui confusing!
Jim Pingle
06:18 AM Bug #3082 (Closed): apinger: Error while feeding rrdtool: Broken pipe
this log is only cosmetic, and already has a ticket. the other description is unrelated and not a known problem, but ... Chris Buechler
12:54 AM Bug #3082: apinger: Error while feeding rrdtool: Broken pipe
OK, it looks like a problem with Chrome.
We don't have the problem with IE, pretty weird.
Service -> Load Balancer ...
Jean-Christophe Petit
12:52 AM Bug #3082: apinger: Error while feeding rrdtool: Broken pipe
Tried restarted webconfigurator to no avail
Also rebooted the pfsense but problem still persist??
Jean-Christophe Petit
12:43 AM Bug #3082 (Closed): apinger: Error while feeding rrdtool: Broken pipe
Hello,
looks like the bug on rrdtool from 2.0.2 is still present in 2.0.3
Interface froze when choosing Services-...
Jean-Christophe Petit
12:10 AM Revision e91abcc9: Fix #3079, add a section for DHCPv6 Server backup
Renato Botelho
12:08 AM Revision 63e9efc9: Fix #3079, add a section for DHCPv6 Server backup
Renato Botelho

07/08/2013

07:10 PM Feature #3079: No way to individually backup/restore DHCPv6 config
Applied in changeset commit:e91abcc96e79808b71865d3e91c81ad5501328c3. Renato Botelho
07:10 PM Feature #3079 (Feedback): No way to individually backup/restore DHCPv6 config
Applied in changeset commit:63e9efc92f4eba3a74fcf98ee858b35261d394e0. Renato Botelho
03:38 PM Revision dd042c51: Implement URL Table aliases for ports instead of IP addresses
Renato Botelho
02:20 PM Revision 174e151d: fix description
Chris Buechler
02:19 PM Revision ff6c9852: fix description
Chris Buechler
02:04 PM Bug #3081: multi WAN with pppoe over dhcp interface not working
my FW run pfsense 2.0.3 amd64 Zeev Zalessky
02:01 PM Bug #3081 (Closed): multi WAN with pppoe over dhcp interface not working
Hi,
i have following setup:
em0 - 2 WAN interfaces (vlan 11,12) that receive IP using DHCP from ADSL modem. after...
Zeev Zalessky
01:31 PM Revision df1b3eb7: touch up text
Chris Buechler
01:31 PM Revision e0658637: touch up text
Chris Buechler
11:43 AM Bug #3062: Captive Portal NOT re-using PIPENO
I have put a fix for this part in github *_"There is still a problem, I mean delete the file captiveportaldn.rules Wh... Alberto Palau
09:35 AM Bug #2495: pfsense doesn't seem to know what its WAN IP is
That bug is NOT fixed yet.
It still exists on 2.1-RC0 from "Sun Jul 7 20:34:30"
Please tell me if I can support you.
Christoph Filnkößl
08:12 AM Feature #1831: Captive portal IPv6 support
Great work, and Thanks Cyrill.
Unfortunately I found another bug in the code, while setting up the CP for v6 in my...
Thomas B
07:40 AM Revision 8418a6df: Merge pull request #704 from razzfazz/rules_proto_41
Add support for protocol 41 in rules. Fixes #3007. Ermal Luçi
05:24 AM Bug #3077 (Feedback): FTP patches in revision 39802d4e cause kernel panics on FTP traffic
Please do not use redmine as a bug tracking.
There is already a ticket open for ftp helper.
I pushed some patches...
Ermal Luçi
03:03 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
IPSec with mobile clients on Current 2.1 RC's seems very reliable - various user reports are very positive. Thanks. Peter Borföi
02:40 AM Feature #3007: "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Applied in changeset commit:8418a6df61356f93f95b2a1a6b8e0a9c02890088. Ermal Luçi
02:40 AM Feature #3007 (Feedback): "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Applied in changeset commit:25ce513631d4f1af53886982b0b7c7872e8b8edf. Daniel Becker

07/07/2013

10:40 PM Revision da40615d: Add support for custom IPv6 DDNS.
Daniel Becker
10:36 PM Revision 25ce5136: Add support for protocol 41 in rules. Fixes #3007.
Daniel Becker
10:28 PM Revision b4319c50: Change separator as per JimP's request.
Daniel Becker
09:45 PM Revision 66185fc7: Merge branch 'master' into dyndns_custom_v6
Daniel Becker
09:44 PM Revision ebfe7d20: Add front-end support for dyndns AAAA updates
Daniel Becker
09:44 PM Revision d7e6f573: Clean up HE.net AAAA backend support.
Daniel Becker
08:52 PM Revision fc654f2c: Fix typo in filter.inc. Fixes #3028.
Due to the typo, FilterIfList never got a 'track6-interface' entry,
which in turn prevented the DHCP6-related pass ru...
Daniel Becker
08:51 PM Revision d7fb1715: Merge pull request #702 from razzfazz/master
Fix typo in filter.inc. Fixes #3028. Renato Botelho
07:39 PM Revision b4025ccd: Add backend support for HE.net AAAA record updates.
Defines a new DynDNS provider 'he-net-v6' for updating AAAA entries on
dns.he.net.
Daniel Becker
06:22 PM Revision 14e9b052: Fix typo in filter.inc. Fixes #3028.
Due to the typo, FilterIfList never got a 'track6-interface' entry,
which in turn prevented the DHCP6-related pass ru...
Daniel Becker
05:52 PM Feature #3007: "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Pull request here: https://github.com/pfsense/pfsense/pull/704 Daniel Becker
05:19 PM Feature #3007: "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
Turns out the official name for protocol 41 is "IPV6". Daniel Becker
05:15 PM Bug #3080 (Resolved): 2.1-RC0 (i386) - GRE Interface not getting correct/configured MTU at boot time
I'm having a working GREoverIPSec + OSPF environment (Cisco C876 <-> pfSense). Today I just saw that a GRE interface ... Dirk M
04:56 PM Feature #1825: Dynamic DNS client IPv6 support
Pull requests here: https://github.com/pfsense/pfsense/pull/703 Daniel Becker
03:50 PM Bug #3028: Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
Applied in changeset commit:fc654f2c36186af8aaf59a1feedce5b343df1252. Daniel Becker
03:50 PM Bug #3028: Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
Applied in changeset commit:d7fb1715a17566f1bd9013f88fd9b627479d8767. Anonymous
03:50 PM Bug #3028 (Feedback): Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
Applied in changeset commit:14e9b0526f4d41616994d57b3484c2fa0bf8183f. Daniel Becker
02:46 AM Bug #3028: Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
The existing statement causes the 'track6-interface' entry to never be added to _FilterIfList_, which in turn causes ... Daniel Becker
02:36 AM Bug #3028: Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
I believe the problem is in /etc/inc/filter.inc:870:... Daniel Becker
03:46 PM Feature #3079 (Resolved): No way to individually backup/restore DHCPv6 config
the current backup/restore mechanisms do not allow for the individual backup/restore of DHCPv6 settings.
They are...
Graeme Bragg
03:45 PM Revision ba581f07: Make dashboard update check respect nanobsd-vga, probably fixes #3078
Jim Pingle
03:45 PM Revision 6efe0cae: Make dashboard update check respect nanobsd-vga, probably fixes #3078
Jim Pingle
12:44 PM Revision a35c1cdf: Correct month, quarter (3 months), and 4 year RRD graphs length.
Longest possible month is 31 days, not 32.
Longest possible quarter (3 months) is 92 days (30+31+31), not 93 (31+31+3...
N0YB
12:43 PM Revision c2bf84a1: Merge pull request #701 from N0YB/RRD_Graphs_Size
Correct month, quarter (3 months), and 4 year RRD graphs length. Renato Botelho
10:50 AM Bug #3078: NanoBSD upgrade gui confusing!
Applied in changeset commit:ba581f076acc3068c37bd86c97656bf53b29781b. Jim Pingle
10:50 AM Bug #3078: NanoBSD upgrade gui confusing!
Applied in changeset commit:6efe0caeb3b2ec8ae39ce35aa0663ffa7501a146. Jim Pingle
10:30 AM Bug #3078: NanoBSD upgrade gui confusing!
Jim P wrote:
> I updated my ALIX and it correctly shows on the dashboard and the auto update check that it is curren...
GT Zenny
09:15 AM Bug #3078 (Feedback): NanoBSD upgrade gui confusing!
I updated my ALIX and it correctly shows on the dashboard and the auto update check that it is current. The update ch... Jim Pingle
02:25 AM Bug #3078: NanoBSD upgrade gui confusing!
GT Zenny wrote:
> Also it would be nice to include the changelog of every build to save the life of the CF/USB devic...
Doktor Notor
02:19 AM Bug #3078 (Resolved): NanoBSD upgrade gui confusing!
I think this needs to be fixed to avoid confusion whether an upgrade has been made or not.
http://forum.pfsense.or...
GT Zenny
06:32 AM Revision 91c6c902: Correct month, quarter (3 months), and 4 year RRD graphs length.
Longest possible month is 31 days, not 32.
Longest possible quarter (3 months) is 92 days (30+31+31), not 93 (31+31+3...
N0YB
03:59 AM Revision 63f02995: Merge pull request #699 from evansus/patch-2
DHCP also update Dynamic DNS for static leases Jim Pingle
03:39 AM Revision 2740f12c: Typo in configuration option
Should be 'leases', not 'mappings'. Evan Susarret
03:02 AM Revision 64b299d8: DHCP also update Dynamic DNS for static leases
Previously, Dynamic DNS is only updated for clients that get addresses from the DHCP address pool. Static mappings ar... Evan Susarret
02:17 AM Bug #3077 (Resolved): FTP patches in revision 39802d4e cause kernel panics on FTP traffic
As discussed on a forum thread http://forum.pfsense.org/index.php/topic,64144.0.html the patches introduced in commit... Doktor Notor

07/06/2013

07:38 PM Revision 010639a8: Remove unecessary variable
Renato Botelho
07:38 PM Revision b91d0be3: Remove unecessary variable
Renato Botelho
05:55 PM Revision ee3bc703: Fix #2962, allow to remove VIP if gateway IP is on the interface's subnet
Renato Botelho
05:54 PM Revision ff9f40d5: Fix #2962, allow to remove VIP if gateway IP is on the interface's subnet
Renato Botelho
04:16 PM Bug #3075: Can't delete unused Virtual IP "referenced by a least one gateway"
Thanks Renato! Christian McDonald
12:53 PM Bug #3075 (Feedback): Can't delete unused Virtual IP "referenced by a least one gateway"
The fix for #2962 introduced this issue. I fixed it, please check tomorrow's snapshot. Renato Botelho
11:12 AM Bug #3075: Can't delete unused Virtual IP "referenced by a least one gateway"
I'm not sure that I'm following you. Let's say my block of public IPs is as follows:
1.1.1.30 (gateway)
1.1.1.29
...
Christian McDonald
05:44 AM Bug #3075: Can't delete unused Virtual IP "referenced by a least one gateway"
that input validation should only apply when it's the only VIP that exists in that gateway's subnet. Chris Buechler
11:42 AM Bug #3057 (Resolved): DHCPv6 not working with Router Advertisements 'Assisted'
Renato Botelho
12:18 AM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
Yes, now it's working without having to update services.inc from git. Petri Oksanen
10:46 AM Revision e66c4a0f: fix typo
Chris Buechler
10:26 AM Feature #3076: Gogoc client support
Chris Buechler wrote:
> there are many supported tunneling offerings already that work fine with ISPs that don't sup...
Vladimir Suhhanov
05:40 AM Feature #3076 (Needs Patch): Gogoc client support
there are many supported tunneling offerings already that work fine with ISPs that don't support or block v6. Chris Buechler
03:05 AM Feature #3076: Gogoc client support
This is so extremely slow and unreliable service that I'd say this is a complete waste of time. Been using it for qui... Doktor Notor
12:13 AM Feature #3076 (Needs Patch): Gogoc client support
Some ISP networks completely blocked the IPv6 protocol, so it would be good to have a different and a simple way to c... Vladimir Suhhanov

07/05/2013

08:30 PM Revision ae737247: Update services.inc
Turn on AdvManagedFlag and AdvOtherConfigFlag for both 'managed' and 'assist' ramodes. Peter Linss
05:56 PM Revision 51b26242: Actually do this upon entering to get proper ip
Ermal LUÇI
05:56 PM Revision 0007f5b3: Actually do this upon entering to get proper ip
Ermal LUÇI
05:55 PM Revision 4454f1f3: Fixes #2495. On trigering of rc.newwanip remove all ipaliases from the interface since they will be readded later on. This will also make sure to have the correct address order
Ermal LUÇI
05:48 PM Revision b877d635: Fixes #2495. On trigering of rc.newwanip remove all ipaliases from the interface since they will be readded later on. This will also make sure to have the correct address order
Ermal LUÇI
05:29 PM Revision 5fb149ba: Remove unecessary var initialization
Renato Botelho
05:18 PM Revision d7deb24c: Remove unecessary var initialization
Renato Botelho
04:22 PM Bug #3075 (Closed): Can't delete unused Virtual IP "referenced by a least one gateway"
I am working on some minor shuffling around of statics from my /29 block of IPs from my ISP. On 2.0.3 and 2.1 snapsho... Christian McDonald
04:11 PM Bug #2962: IP Aliases cannot be used for routes/gateways
Was the expected result of this revision to prevent the deletion of Virtual IPs that also exist in the same subnet as... Christian McDonald
03:48 PM Revision 9db8c46d: When a CARP VIP transitions to master, we need to bump servers also, otherwise a transition from disabled or init may not properly (re)attach to the IP address.
Jim Pingle
03:46 PM Revision e61a6db2: When a CARP VIP transitions to master, we need to bump servers also, otherwise a transition from disabled or init may not properly (re)attach to the IP address.
Jim Pingle
03:27 PM Revision 0ee96a45: Correct DHCPv6 rules test to also include a check for DHCPv6 relay. Fixes #3074
Jim Pingle
03:27 PM Revision 86573a24: Correct DHCPv6 rules test to also include a check for DHCPv6 relay. Fixes #3074
Jim Pingle
03:27 PM Bug #3057 (Feedback): DHCPv6 not working with Router Advertisements 'Assisted'
It was pushed on master and not on RELENG_2_1, because of that you cannot see the change on 2.1-RC0 snapshots. I appl... Renato Botelho
02:44 PM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
And also with
2.1-RC0 (i386)
built on Fri Jul 5 06:53:51 EDT 2013
FreeBSD 8.3-RELEASE-p8
I need to get ser...
Petri Oksanen
01:55 AM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
This worked, but on build
Version 2.1-RC0 (i386)
built on Thu Jul 4 03:04:00 EDT 2013
FreeBSD 8.3-RELEASE-p8
...
Petri Oksanen
01:59 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
FWIW, tried with @truss /usr/sbin/traceroute6 -w 2 -m 18 www.google.com@ - it looks like it *does* actually make it t... Doktor Notor
01:48 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Looks like the code was last touched (beyond irrelevant cosmetics) almost 4 years ago. Unlikely to have any fix. Doktor Notor
01:37 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
MTR is an entirely different type of test. Useful, but probably not one we'd include by default. And yes its GUI does... Jim Pingle
01:33 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Hmmm well, not sure either, beyond either a shiny red warning (think about remotely managed boxes, cutting yourself o... Doktor Notor
01:29 PM Bug #3069 (New): traceroute6 fails to timeout and hangs the webconfigurator GUI
I was able to reproduce it finally. I tried it on a few different pfSense boxes and FreeBSD systems, and I only could... Jim Pingle
12:40 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
BTW, installed mtr-nox11, no such issue:
HOST: gw.example.com Loss% Snt Last Avg Best Wrst S...
Doktor Notor
12:32 PM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Not really required to uncomment anything there. It's endlessly visible in the process listing from console, till you... Doktor Notor
12:26 PM Bug #3069 (Feedback): traceroute6 fails to timeout and hangs the webconfigurator GUI
I can't reproduce this on current 2.1 code.
In the GUI we pass "-w 2" which waits a max of two seconds for a reply...
Jim Pingle
01:00 PM Bug #2495: pfsense doesn't seem to know what its WAN IP is
Applied in changeset commit:4454f1f34841b07c2f8e5aa95b3e0d9a9e0ed9a2. Ermal Luçi
12:50 PM Bug #2495 (Feedback): pfsense doesn't seem to know what its WAN IP is
Applied in changeset commit:b877d6351c614f58b68a3ab2c7b04ea7ea282961. Ermal Luçi
12:56 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
Please, revert these patches ASAP. They hard crash the box with FTP! http://forum.pfsense.org/index.php/topic,64144.0... Doktor Notor
12:12 PM Revision abe411ad: Fix a small issue when disable a boolean option and save, it shows option as enabled
Renato Botelho
12:11 PM Revision 6a605eec: Fix a small issue when disable a boolean option and save, it shows option as enabled
Renato Botelho
12:09 PM Revision 277fd8db: Fix whitespaces
Renato Botelho
12:08 PM Revision ae6d9444: Fix whitespaces
Renato Botelho
12:04 PM Revision 80dc15eb: Remove extra { wrongly added on last commit
Renato Botelho
11:56 AM Revision c3cbe91e: Fix whitespaces
Renato Botelho
11:56 AM Revision 810c6a96: Process zipped aliases list
Renato Botelho
11:56 AM Revision 6a9a0736: Remove useless code
Renato Botelho
11:54 AM Revision db0aa52a: Fix whitespaces
Renato Botelho
11:47 AM Revision 6fab0f03: Fix set/unset of checkaliasesurlcert
Renato Botelho
11:47 AM Revision 86ffa26d: Process zipped aliases list
Renato Botelho
11:47 AM Revision 76590ffe: Use download_file() and check ssl certificates
Renato Botelho
11:47 AM Revision abc7b6a2: Remove useless code
Renato Botelho
11:47 AM Revision ffd7802a: Create a function to download a file using curl
Renato Botelho
11:47 AM Revision 08b861a8: Add an option to check certificate for https URL aliases
Renato Botelho
11:20 AM Bug #2951 (Feedback): OpenVPN and alternative monitoring IP in 2.1
This should behave better with tomorrow snapshot due to a fix done in gateway monitoring.
Can you confirm this is th...
Ermal Luçi
10:55 AM Revision 265be6f5: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:53 AM Revision 63356262: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:53 AM Revision f4a8e38c: Resolves #2910. Make apinger write its status file just after starting so that thing work as expected
Ermal LUÇI
10:40 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Applied in changeset commit:0ee96a458ab93ff451c9bb32b1b8bc20e13866e6. Jim Pingle
10:40 AM Bug #3074 (Feedback): DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Applied in changeset commit:86573a248608ff5b166eb77e962f97e91df159d2. Jim Pingle
10:18 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
All good now... thumbs up! :) Proper rules generated and DHCPv6 traffic no longer blocked on ifaces with relay enable... Doktor Notor
09:54 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
The attached patch should fix it, but it would be better to test it before committing. Let us know if it helps. Jim Pingle
09:10 AM Bug #3074: DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Related forum thread: http://forum.pfsense.org/index.php/topic,64168.0.html Doktor Notor
05:28 AM Bug #3074 (Resolved): DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Looking at this part of filter.inc, I don't think it deals with this configuration correctly.
@
if ((is_array...
Doktor Notor
09:18 AM Bug #1629: invalid state table entries after WAN IP change
I am also affected by this bug in 2.0.3.
In my case not a changed ipadres on my WAN, but a dual Wan setup with failo...
Martin Oosterheert
09:08 AM Feature #1663: DHCPv6 relay
Related forum thread: http://forum.pfsense.org/index.php/topic,64168.0.html Doktor Notor
07:16 AM Feature #1663: DHCPv6 relay
This is very, very broken. It can never be stopped via disabling the checkbox and clicking save. On subsequent enabli... Doktor Notor
07:20 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Glad to report that the firmware update I just installed (details below) seems to work.
Will continue to monitor ...
Anonymous
05:22 AM Bug #2919 (Feedback): IPv6 - WAN and LAN (DHCP-PD) does not renew address
Jun 4 snapshots are even better for this. Ermal Luçi
06:00 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:265be6f5ab7d5546a8f26ae6bcae33712f861102. Ermal Luçi
05:50 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
I pushed some fixes for this.
On newer snapshots it should behave as expected.
Ermal Luçi
05:50 AM Bug #2910: monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:63356262a7f3f82b97d029d983fff0132030e539. Ermal Luçi
05:50 AM Bug #2910 (Feedback): monitoring-disabled gateway causes wrong tiered gateway in route-to
Applied in changeset commit:f4a8e38c6ed250e9a18c4e472481541198231cdb. Ermal Luçi
05:23 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
The only option for now seems to create rules with allow-option advanced setting set. Ermal Luçi
01:46 AM Bug #3073: Please include PHP MySQL extension!
You can touch /etc/php_dynamodules/module_name and rc.php_ini_setup will pick up on it and load the module (if the mo... Warren Baker

07/04/2013

11:00 PM Bug #3073 (Rejected): Please include PHP MySQL extension!
it's already there Chris Buechler
10:56 PM Bug #3073: Please include PHP MySQL extension!
This is not a bug, sorry for the mistake. Alberto Palau
10:56 PM Bug #3073 (Rejected): Please include PHP MySQL extension!
Would be too much to ask to include the php mysql extension by default in the next snapshoots? I use a custom authent... Alberto Palau
01:42 PM Revision 079d1952: Add a new alias type, URLs containing Ports
Renato Botelho
01:40 PM Revision d9f33a7f: Add group_ports()
Renato Botelho
12:11 PM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
PS: It is not broken or weird behaviour (according to the RFCs). RFC 6145 (translating IPv4 <-> IPv6) specifies:
<...
Sander Steffann
10:20 AM Feature #3070: ova image wan configuration
Hrm seems it should work by default as i was brought to attention.
You sure it asks for interface assignment during b...
Ermal Luçi
09:37 AM Feature #3070: ova image wan configuration
locally I could do it. True. The point is that I'm trying daily to download a snapshot from your snapshot server, run... Victor Pereira
09:26 AM Feature #3070: ova image wan configuration
You can just modify the default config.xml in the repository and that will give you that.
I do not think this will g...
Ermal Luçi
04:11 AM Feature #3070 (Closed): ova image wan configuration
Hi,
there is any possibility to generate the ova image with the WAN already configured to em0? I'm writing Cucumbe...
Victor Pereira
07:52 AM Bug #3072 (Resolved): ova snapshot not available
today I tried to download the last ova snapshot and looks like the virtualization folder is empty
http://snapshot...
Victor Pereira
07:01 AM Revision fae0e098: Remove duplicated line that makes dhcp6c not run correctly
Ermal LUÇI
07:01 AM Revision 0dd5ed7b: Remove duplicated line that makes dhcp6c not run correctly
Ermal LUÇI
06:58 AM Revision 032a3c0a: Do not reconfigure dhcp v6 on v4 ip address event. Only handle 6rd and 6to4 while the former is questionable if needed
Ermal LUÇI
06:58 AM Revision f4d0495e: Copy/pasto does well up to some point
Ermal LUÇI
06:58 AM Revision 74f4a3cc: On every ip change renew the hosts file
Ermal LUÇI
06:54 AM Revision ac086c62: Merge pull request #696 from N0YB/patch-1
Update interfaces.php Ermal Luçi
04:20 AM Feature #3071: build server: link to the last build
While at it, it would be really useful to include /etc/version.lastcommit directly in the snapshots filename. Doktor Notor
04:15 AM Feature #3071 (Resolved): build server: link to the last build
Hi, to do test automation, it would be great to have on your snapshot server a link to the last build version. Today ... Victor Pereira
01:06 AM Revision 3e3aeb8b: Update interfaces.php
Remove errant double quote. N0YB
12:49 AM Revision 77447d9f: Merge pull request #695 from N0YB/Advanced_DHCP_Client_Options
Remove errant double quote. Jim Pingle
12:46 AM Revision e00fafb3: Remove errant double quote.
N0YB

07/03/2013

04:48 PM Bug #3069 (Resolved): traceroute6 fails to timeout and hangs the webconfigurator GUI
As simple as trying to run IPv6 traceroute to www.google.com from the GUI:
@ 2 gige-g2-20.core1.prg1.he.net 3.31...
Doktor Notor
03:52 PM Revision 581fa606: Merge pull request #692 from mgsmith1000/master
Omit IP warning if HTTP_REFERER check is disabled. Renato Botelho
03:50 PM Revision f0f1737b: Merge pull request #691 from mgsmith1000/RELENG_2_1
Omit IP warning if HTTP_REFERER check is disabled. Renato Botelho
03:36 PM Revision 31677598: Omit IP warning if HTTP_REFERER check is disabled.
Matthew Smith
03:32 PM Revision 058bc2a8: Omit IP warning if HTTP_REFERER check is disabled.
Matthew Smith
01:41 PM Revision 2bc45785: Do not reconfigure dhcp v6 on v4 ip address event. Only handle 6rd and 6to4 while the former is questionable if needed
Ermal LUÇI
01:38 PM Revision 9ce0dd12: Copy/pasto does well up to some point
Ermal LUÇI
01:37 PM Revision c9065c1e: On every ip change renew the hosts file
Ermal LUÇI
12:27 PM Revision 5ee53aa1: Enforce the checking of booting up for linkup events
Ermal LUÇI
12:26 PM Revision 84f7e98c: Enforce the checking of booting up for linkup events
Ermal LUÇI
10:01 AM Bug #3037 (Resolved): Unable to delete PRIQ queues
thanks! Renato Botelho
09:46 AM Feature #3068: Notifications/Alerts - custom script
You can provide a patch and it will be evaluated! Ermal Luçi
08:36 AM Feature #3068 (Needs Patch): Notifications/Alerts - custom script
Would be great to have an option in the notifications to execute a custom script. Ricardo Esteves
09:45 AM Bug #2878: radvd does not restart properly
Please test with latest gitsync or tomorrow snapshots.
There were some fixes doen related to this as well.
Ermal Luçi
07:25 AM Bug #2878: radvd does not restart properly
Tom M wrote:
> I am still seeing this issue. I have turned off Track Interface for DHCP on my LAN Interface and ipv6...
Tom M
06:54 AM Revision 51f98d0d: modified radius function to release the pineno
modified radius function to release the pinene if the client is not authenticated properly, and modified function cap... Alberto Palau
06:53 AM Revision e336cd95: Merge pull request #687 from falbertopl/master
Modified radius function to release the pinene Ermal Luçi
03:39 AM Revision d2c98878: modified radius function to release the pineno
modified radius function to release the pinene if the client is not authenticated properly, and modified function cap... Alberto Palau
02:08 AM Bug #1634: Limiter and bridge needs special handling
Not an easy one for 2.1 Ermal Luçi
02:05 AM Bug #3062 (Feedback): Captive Portal NOT re-using PIPENO
Merging of the patch has been done.
Thank you.
Ermal Luçi
12:23 AM Bug #3067 (Rejected): Virtual IP Removal
not a bug, VIPs aren't always necessary for 1:1 NAT so they can't be prohibited from being removed because of 1:1 NAT... Chris Buechler

07/02/2013

11:10 PM Feature #371: Allow moving of bogon and RFC 1918 rules
Can we please do something about this? Or make a checkbox for logging (http://forum.pfsense.org/index.php/topic,34436... Doktor Notor
09:27 PM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Captive portal log also shows successful sync.
Josh Cavalier
09:24 PM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Ok, I have tested this and it works properly. I've setup two VM's with three interfaces each. WAN (192.168.17.0/24), ... Josh Cavalier
09:13 PM Bug #3062: Captive Portal NOT re-using PIPENO
Alberto, it will be much easier if you put the changes in GitHub. Then the developers can easily see the differences,... Phillip Davis
03:58 PM Bug #3062: Captive Portal NOT re-using PIPENO
Only correct a sentence, I meant that I hope will serve out the modification, instead of "I hope you learn the contri... Alberto Palau
03:48 PM Bug #3062: Captive Portal NOT re-using PIPENO
Excuse the mess in the text above, I did not know how to modify it, please if anyone can fix it, thanks Alberto Palau
03:38 PM Bug #3062: Captive Portal NOT re-using PIPENO
Limiters:
02002: unlimited 0 ms burst 0
q133074 100 sl. 0 flows (1 buckets) sched 67538 weight 0 lmax 0 pr...
Alberto Palau
02:09 PM Bug #3062: Captive Portal NOT re-using PIPENO
Ok, I'm working on a solution, and found the problem in the code, I put the fix and I'm probing now, it appears that ... Alberto Palau
09:57 AM Bug #3062: Captive Portal NOT re-using PIPENO
Version 2.0.3 is also affected by this problem. Alberto Palau
08:58 PM Revision c49b7c50: Include both dyndns and rfc2136 hosts in referer check
Jim Pingle
08:58 PM Revision b54ffacc: Include RFC2136 hosts in DNS rebinding checks.
Jim Pingle
08:58 PM Revision 0d7e2478: Add server IP column and cached IP display to RFC2136 host list.
Jim Pingle
08:58 PM Revision c8369c59: Add option to RFC2136 to find/use the public IP if the interface IP is private. (Off by default)
Jim Pingle
08:58 PM Revision 6c38268e: Fix double click row to edit for rfc2136
Jim Pingle
08:58 PM Revision b65492f6: Add cached IP support to RFC2136, add GUI button to force update for single host.
Jim Pingle
08:58 PM Revision 9f0bee02: Include both dyndns and rfc2136 hosts in referer check
Jim Pingle
08:58 PM Revision fa087612: Include RFC2136 hosts in DNS rebinding checks.
Jim Pingle
08:58 PM Revision bcafa618: Add server IP column and cached IP display to RFC2136 host list.
Jim Pingle
08:58 PM Revision 6d8dd98b: Add option to RFC2136 to find/use the public IP if the interface IP is private. (Off by default)
Jim Pingle
08:58 PM Revision a04da9bf: Fix double click row to edit for rfc2136
Jim Pingle
08:58 PM Revision 7c9da7be: Add cached IP support to RFC2136, add GUI button to force update for single host.
Jim Pingle
07:05 PM Revision 92465c6f: Correct variable used to delete symlinks and files delete from CP filemanager. Reported-by: http://forum.pfsense.org/index.php/topic,64016.0/topicseen.html. While here reduce some uneeded extra operations
Ermal LUÇI
07:05 PM Revision bdba4fa7: Correct variable used to delete symlinks and files delete from CP filemanager. Reported-by: http://forum.pfsense.org/index.php/topic,64016.0/topicseen.html. While here reduce some uneeded extra operations
Ermal LUÇI
06:59 PM Bug #3067 (Rejected): Virtual IP Removal
I noticed that pfsense allows you to remove Virtual IPs that are currently in use in a 1:1 NAT which will cause issue... Leon Shadow
06:27 PM Revision 6c2bb4e6: Add the interface's descr after the pool name.
Jim Pingle
06:26 PM Revision 97752da5: Add the interface's descr after the pool name.
Jim Pingle
05:06 PM Bug #3066 (Rejected): Proxy ARP failing with kernel error
Hello, having trouble using Virtual IPs. My problem was worked around by using an Interface alias.
It appeared I w...
Jesse Peterson
04:22 PM Revision 98d5e234: Repect global conf_path
Renato Botelho
04:22 PM Revision 5e3356d7: Repect global conf_path
Renato Botelho
02:30 PM Bug #2878: radvd does not restart properly
I am still seeing this issue. I have turned off Track Interface for DHCP on my LAN Interface and ipv6 is now only tur... Tom M
04:16 AM Bug #2878 (Feedback): radvd does not restart properly
Can you please confirm that this is not anymore an issue? Ermal Luçi
10:51 AM Revision f5035e0b: Merge pull request #680 from Klaws--/RELENG_2_1
Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP Ermal Luçi
10:49 AM Revision fcbef05a: Merge pull request #686 from Klaws--/master
Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP Ermal Luçi
10:45 AM Bug #3065 (Rejected): Firewall rules description - sync
that's intentional for the time being. There's another ticket open on it. Chris Buechler
10:34 AM Bug #3065 (Rejected): Firewall rules description - sync
Hi,
I've just noticed that the sync of firewall rules description "eats" the char ">"
For example, on Firewall1...
Ricardo Esteves
10:37 AM Revision dc63650a: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
10:34 AM Revision 1227101b: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
10:13 AM Revision 492b1314: Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution.
Applied when RRD's are created.
RRA:AVERAGE:0.5:1:1200 = 20 hours of 1 minute data
RRA:AVERAGE:0.5:5:720 ...
N0YB
10:12 AM Revision da9a0ad0: RRD Specify RRA and Resolution
Don't leave it up to RRD Tool to select the RRA and resolution to use.
Specify the RRA and resolution to use per the ...
N0YB
09:50 AM Revision 70d36e38: Adjust archives array values to match sizes for average calculation.
N0YB
09:50 AM Revision 086d941d: Archive start is “now” minus archive length. Not “end” minus archive length. Sometimes "end" is not "now".
N0YB
09:48 AM Revision 5ce5439f: Merge pull request #685 from N0YB/RRD_RRA_Sized_for_Previous_Period
Archive start is “now” minus archive length Renato Botelho
09:27 AM Revision a13acc0e: Add a checkbox that can be used to request only a IPv6 prefix without a IPv6 address. Some ISPs DHCP6 servers will fail the request if both are requested and only a Prefix is allowed.
Conflicts:
usr/local/www/interfaces.php
Seth Mos
08:21 AM Revision 6dcbd1b3: Add a checkbox that can be used to request only a IPv6 prefix without a IPv6 address. Some ISPs DHCP6 servers will fail the request if both are requested and only a Prefix is allowed.
Seth Mos
07:37 AM Bug #3064: Broadcom BCM57780 Nic lights not working (Activity and Link)
The patch link is not correct, here is the correct one - http://svnweb.freebsd.org/base/head/sys/dev/bge/if_bge.c?r1=... Tom Bishop
07:30 AM Bug #3064 (Closed): Broadcom BCM57780 Nic lights not working (Activity and Link)
It appears that the freeBSD 8.x and even the 9.X code has a bug where once the network is configured it turns off the... Tom Bishop
04:51 AM Bug #3063: system will crash after "PowerD" enabled.
Hardware: Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz, Normal PC.
I did not find any obvious message about this f...
tx s
04:18 AM Bug #3063 (Closed): system will crash after "PowerD" enabled.
I am using pfsense as a transparent firewall.
I found the system would be hanged(no any message) in a few minute, ...
tx s
04:15 AM Feature #1836 (New): RFC 5006 support for DNS from RAs
Ermal Luçi
04:11 AM Feature #1836 (Feedback): RFC 5006 support for DNS from RAs
Ermal Luçi
03:59 AM Bug #2650 (Feedback): FTP helper breaks TCP sequence numbers on 2nd WAN
Ermal Luçi
03:59 AM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
Can you try with tomorrows snapshots. Ermal Luçi
01:58 AM Bug #2941 (Resolved): Prohibit adding aliases containing FQDNs in static routes
confirmed fixed Chris Buechler
01:00 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
Also, I have replicated the test by Josh Stompro above (changing an existing alias used by a static route from IP to ... Josh Cavalier
12:35 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
I have tested this with the latest build and it works as intended. I created two aliases, one with a FQDN and one wit... Josh Cavalier
01:43 AM Bug #3037: Unable to delete PRIQ queues
I have tested this and can confirm it works properly (2.1-RC0 - Jul 1 15:22:23 EDT 2013). I created a new shaping rul... Josh Cavalier
01:32 AM Bug #2999 (Resolved): sticky connections are really, really broken w/relayd
confirmed fixed in testing and on customer's production system where problem was discovered.
Chris Buechler

07/01/2013

10:42 PM Revision 24646d57: Adjust archives array values to match sizes for average calculation.
N0YB
10:38 PM Revision 641f2f3c: Archive start is “now” minus archive length. Not “end” minus archive length. Sometimes "end" is not "now".
N0YB
03:42 PM Bug #3062 (Resolved): Captive Portal NOT re-using PIPENO
Captive portal does not correctly release pipe numbers, is continually increasing them until they are exhausted, and ... Alberto Palau
03:41 PM Bug #3024 (Rejected): need a pipe / flowset / sched number
Closed per submitter request Renato Botelho
03:29 PM Bug #3024: need a pipe / flowset / sched number
You can close this bug Alberto Palau
12:24 PM Revision 0bd85300: Merge pull request #684 from N0YB/Advanced_DHCP_Client_Options
Add show/hide to the new "Reject Leases From" row Jim Pingle
10:16 AM Revision c54b4586: fix typos
Renato Botelho
07:46 AM Revision 63c704c3: Add show/hide to the new "Reject Leases From" row
Show for Basic and Advanced. Hide for Config File Override. N0YB
02:31 AM Bug #3061 (Closed): Updating 2.1 snapshots nukes the bogons lists
/etc/bogons is back to the short couple of lines version and /etc/bogonsv6 is empty after every snapshot update. Woul... Doktor Notor
01:16 AM Revision 9e5ae41a: support mitigating BEAST attack
According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30
"...by setting
ssl.cipher-list = "EC...
Dim Hatz

06/30/2013

02:32 PM Revision cafb7dfe: change css & jquery to allow for multiple columns for themes ending in _fs
Charlie Marshall
02:15 PM Revision 60695c6a: update loader.js - add jquery to display additional column button and create/delete columns
Charlie Marshall
02:02 PM Revision c73a2a29: update css to fit full screen
Charlie Marshall
01:58 PM Revision db83bdf9: Merge pull request #676 from N0YB/RRD_RRA_Sized_for_Previous_Period
Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution. Renato Botelho
01:57 PM Revision 1a03f646: Merge pull request #675 from N0YB/RRD_Specify_RRA_Resolution
RRD Specify RRA and Resolution Renato Botelho
01:55 PM Revision bc82e331: Merge pull request #671 from wrboyce/master
allow defining dhcp static mappings using dhcp-client-identifier Renato Botelho
01:50 PM Revision 61ef14bb: Merge branch 'Advanced_DHCP_Client_Options' of https://github.com/N0YB/pfsense into N0YB-Advanced_DHCP_Client_Options
Conflicts:
usr/local/www/interfaces.php
Renato Botelho
01:45 PM Revision ca794dd1: clone pfsense_ng theme
Charlie Marshall
12:21 PM Revision 2cfde694: Handle comma-separated list arg to rc.openvpn
The argument passed to rc.openvpn can be a comma-separated list of gateways - not just 1 gateway. Enhance the code to... Phil Davis
12:19 PM Revision 43d7e83e: Merge pull request #681 from phil-davis/master
Handle comma-separated list arg to rc.openvpn Renato Botelho
07:07 AM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
It was changed only on 2.1, not 2.0.x, because of this you still see the issue on 2.0.3. You can apply the change on ... Renato Botelho
04:09 AM Revision 7ef9de3f: Handle comma-separated list arg to rc.openvpn
The argument passed to rc.openvpn can be a comma-separated list of gateways - not just 1 gateway. Enhance the code to... Phil Davis
03:18 AM Bug #2998: Diffserv Code Point options misleading
I decided to go for the "minimally invasive" approach:
1. I added the CSx itens to the drop-down box.
2. I fixed ...
Klaus Stock

06/29/2013

11:42 AM Revision 216c80dd: Added previously missing class selectors cs1-cs7 plus VA (voice-admit), plus the TOS values which still work with DSCP
Also removed the ranges 1-64 and 0x04-0xfc, which never ever have worked as expected (the kernel code does not recogn... Klaws--
11:33 AM Revision 6e0d8f82: Added previously missing class selectors cs1-cs7 plaus VA (voice-admit)
Definitely requires my patches to the kernel patches to work (dscp.RELENG_*.diff). OTOH, it is currently broken anywa... Klaws--
05:43 AM Bug #2626: Patch included: syslog.conf allows duplicate logging of daemon.info messages (e.g. from snort or dnsmasq)
Just updated to 2.0.3; this problem is still here (or came back), with the same cause as before. In my installed copy... Andre LaBranche

06/28/2013

08:14 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I'm also looking forward for the solution of this. I currently halt my 14 sites installation until the bug will be fi... Mel Handumon
06:54 PM Revision 2b125a17: Be a lot more verbose in the logs during package reinstallation.
Jim Pingle
06:54 PM Revision 866b1d61: If the script_name is blank, try another method to locate what our filename is so we don't log an empty script name.
Jim Pingle
06:53 PM Revision b275b658: Be a lot more verbose in the logs during package reinstallation.
Jim Pingle
06:52 PM Revision f09f3d6f: If the script_name is blank, try another method to locate what our filename is so we don't log an empty script name.
Jim Pingle
06:35 PM Bug #3024: need a pipe / flowset / sched number
http://forum.pfsense.org/index.php/topic,63941.0.html Alberto Palau
05:06 PM Bug #3024: need a pipe / flowset / sched number
After several weeks looking for the origin of the problem exposed in this forum, I concluded that the problem occurs ... Alberto Palau
04:37 PM Revision 1e7fa7cd: Fix CP status sorting to properly respect the zone.
Jim Pingle
04:36 PM Revision 210eea2c: Fix CP status sorting to properly respect the zone.
Jim Pingle
01:05 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address

For the very first time, I have been able to go over 4 days without loosing IPv6 addressing. This is very positive...
David Williams
10:08 AM Bug #3060 (Rejected): Post-upgrade screen never goes away and some packages disappear from menu
That happens when a package has failed to reinstall, which is a problem with a specific package in most cases. Check ... Jim Pingle
09:58 AM Bug #3060 (Rejected): Post-upgrade screen never goes away and some packages disappear from menu
1. I have posted this in the forum at http://forum.pfsense.org/index.php/topic,63793.0.html
The upgrade status scr...
GT Zenny
07:04 AM Revision 4023ebb0: Merge pull request #678 from johnbyronent/master
Add Dyn Dns Euro Dns Provider Ermal Luçi

06/27/2013

09:31 PM Revision ec66caa6: DynDns Euro Dns Provider
Add Dyn Dns Euro Dns Provider John Byron
06:35 PM Revision 97c98f19: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
06:34 PM Revision 9d793187: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
06:34 PM Revision 1525fe1f: Add a note about the LDAP hostname matching the server cert's CN.
Jim Pingle
11:23 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
I just updated from a January build to yesterday's build and still get altq errors similar to those above on my lagg0... Steve Kerrison
10:35 AM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
Added support for DHCPv6 reservations and /etc/hosts entries in PR 466 Peter Linss
07:57 AM Bug #1399: rrdtool respawning too fast
Attaching rrdtool.core from 2.1 p13 Todor K
07:22 AM Bug #1399: rrdtool respawning too fast
Same message appeared to me after upgrade from 2.0.3 to 2.1 p13
I have anohter server upgraded to 2.1 p8 (few days e...
Todor K
06:25 AM Bug #2998: Diffserv Code Point options misleading
Forget my bullshit about ipfw above - Goole managed to sneak some ipfw results into my "pf" search, I just a bit conf... Klaus Stock
03:00 AM Bug #3058 (Resolved): Latest 2.1 RC update killed Alix
was a bad snapshot that was removed Chris Buechler
02:27 AM Bug #3058: Latest 2.1 RC update killed Alix
Please close bugreport - seems the problem has not reappeared. Sorry for wasting time, my apologies. Criggie .

06/26/2013

11:50 PM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
Submitted PR #456 as fix.
Turns out the issue isn't IPv6 addresses, it was the duplicate host handling, if both IP...
Peter Linss
06:22 PM Feature #2319: include SSD TRIM option in installer
Apparently the AHCI module may also be required for trim to work properly. See http://forum.pfsense.org/index.php/top... Jim Pingle
01:42 PM Bug #3047: IPSEC remote access broken in 2.03
We're using VMWare PFSense. Upgraded to 2.1 but still no luck with mobile vpn. Micha Ch
06:47 AM Bug #2951: OpenVPN and alternative monitoring IP in 2.1
I was reading the whole story again since I was not able to reproduce the issue, and I have a suspect. Could you plea... Renato Botelho
02:50 AM Bug #3058: Latest 2.1 RC update killed Alix
Craig Falconer wrote:
> If this affects others, can Tuesday's build be pulled before too many people are affected?
...
Doktor Notor
02:30 AM Bug #3058 (Resolved): Latest 2.1 RC update killed Alix
Just updated from Monday to Tuesday's build on my spare alix 2d2.... Criggie .

06/25/2013

02:18 PM Bug #3055: System logs not work right
They are working on current snapshots in our environment. There must be something else wrong in your setup, so please... Jim Pingle
02:10 PM Bug #3055: System logs not work right
Sorry for my english, but maybe I have not explained well.
The problem is server-side logs that not receive the logs...
Claudio Berselli
01:51 PM Bug #2878: radvd does not restart properly
I've been updating a snapshot copy since December 2012 without a full rebuild. I'm wonder if I start with a fresh bet... Tom M
12:57 PM Bug #2878: radvd does not restart properly
Just updated to the same snapshot, and radvd seems to have come up just fine for me. This is also on Comcast, so I wo... Daniel Becker
06:45 AM Bug #2878 (New): radvd does not restart properly
Renato Botelho
01:24 PM Bug #3047: IPSEC remote access broken in 2.03
Not sure if it matters, but I am on an ALIX device. I have since moved back to 2.02 because I cannot afford the down... Robert Holmes
03:55 AM Bug #3047: IPSEC remote access broken in 2.03
@@Jun 24 16:00:18 racoon: ERROR: failed to begin ipsec sa negotication.
Jun 24 16:00:18 racoon: ERROR: no configur...
Micha Ch
12:54 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Robert Guerra wrote:
> Just updated to June 24 release (details below) and IPv6 connectivity -still - does not work....
Daniel Becker
07:54 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Just updated to June 24 release (details below) and IPv6 connectivity -still - does not work. Am on Comcast service a... Anonymous
08:17 AM Bug #2998: Diffserv Code Point options misleading
As the TOS field has an "unstable history" (RFC 3168), a most flexible approach should be imperative. That means that... Klaus Stock
07:46 AM Revision d7df6a6e: Merge pull request #677 from plinss/master
Proposed fix for bug #3057 Ermal Luçi
06:20 AM Bug #3008: custom dynamic dns update with https - curl error
Could you please try a recent snapshot? It should be fixed now. Renato Botelho
06:20 AM Bug #3034 (Resolved): Security FLAW in pfSense Wireless Found
Renato Botelho
04:58 AM Revision 8c78e692: Update services.inc
Turn on AdvManagedFlag and AdvOtherConfigFlag for both 'managed' and 'assist' ramodes. Peter Linss

06/24/2013

11:55 PM Bug #3057: DHCPv6 not working with Router Advertisements 'Assisted'
Proposed fix in https://github.com/pfsense/pfsense/pull/677 Peter Linss
11:42 PM Bug #3057 (Resolved): DHCPv6 not working with Router Advertisements 'Assisted'
When selecting 'Assisted' mode for Router Advertisements, OSX clients use stateless autoconfig and do not obtain DHCP... Peter Linss
08:10 PM pfSense Packages Bug #3056: Unbound not getting IPv6 host overrides
DHCPv6 reservations don't appear to be added to unbound.conf either (DHCPv4 reservations are added). Peter Linss
07:57 PM pfSense Packages Bug #3056 (Resolved): Unbound not getting IPv6 host overrides
Running latest 2.1RC with unbound 1.4.20_7 installed.
When setting host overrides in Services > DNS Forwarder the ...
Peter Linss
07:33 PM Revision 4efdada8: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
07:32 PM Revision 69937c05: Add option and code to sync Auth servers with XMLRPC.
Jim Pingle
06:18 PM Bug #3055 (Rejected): System logs not work right
Not enough information here for a valid bug report. Please start a thread on the forum and if, after assistance and d... Jim Pingle
04:37 PM Bug #3055 (Rejected): System logs not work right
I flag - > "Everything" in "Remote Syslog Contents" but not all event is send to a syslog.
In my case only the login...
Claudio Berselli
05:33 PM Revision fc1f4960: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
05:33 PM Revision 2aacbacf: Add AAAA support to RFC2136 updates. Based on http://forum.pfsense.org/index.php/topic,50164.msg269138.html#msg269138
Jim Pingle
02:40 PM Revision efe42b5a: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:40 PM Revision d13b7363: Fix #2887, based on NAT states that will be killed, also kill firewall states for same source and destination
Renato Botelho
02:09 PM Bug #2627: Old delegated prefixes are not removed from the LAN interface
Tried with:
2.1-RC0 (amd64)
built on Mon Jun 24 04:05:41 EDT 2013
FreeBSD 8.3-RELEASE-p8
Boot up. WAN & LAN g...
Anonymous
12:55 PM Bug #2627 (Feedback): Old delegated prefixes are not removed from the LAN interface
Could you please check a recent snapshot? Renato Botelho
01:50 PM Bug #2878: radvd does not restart properly
I'm still seeing an issue with RADVD not restarting automatically after a dhcp renew from my internet provider (Comca... Tom M
01:01 PM Bug #2878: radvd does not restart properly
This has been working for me with the past several snapshots I've tested. Daniel Becker
12:55 PM Bug #2878 (Feedback): radvd does not restart properly
Could you please check a recent snapshot? Renato Botelho
12:12 PM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
This seems to have been working fine for me on Comcast Home for the past few snapshots that I've tried. After > 8 day... Daniel Becker
10:03 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
Can you test again with latest snapshots and see if this is fixed? Ermal Luçi
10:00 AM Bug #3039: New vouchers doesn't sync with CARP slave
The system log would be interesting to see here Ermal Luçi
09:40 AM Bug #2887: ppp-linkdown state killing not right
Applied in changeset commit:efe42b5a05dfc7c718b04fb00391f251d846a2f2. Renato Botelho
09:40 AM Bug #2887 (Feedback): ppp-linkdown state killing not right
Applied in changeset commit:d13b7363304390736fa4686b4544319f26bdba92. Renato Botelho
06:44 AM Bug #3054: openBGPd stoped working
frustration is never a good friend :
excuse my p.s. :)
step 1 install: pfSense-LiveCD-2.1-RC0-amd64-20130618-1856...
Svetozar Urumov
06:37 AM Bug #3054: openBGPd stoped working
ok some more info :
step 1 : install pfSense-memstick-2.1-RC0-amd64-20130618-1856.img
step 2 : make all confs in Se...
Svetozar Urumov
06:40 AM Bug #3030 (Feedback): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Applied in changeset pfsense-tools:commit:0416a5113ab777964567fc30b78647b6167f8b75. Renato Botelho

06/23/2013

10:27 PM Bug #3054 (Rejected): openBGPd stoped working
not enough here to be a legit bug report, please post info to the forum or list for help. Chris Buechler
10:57 AM Bug #3054 (Rejected): openBGPd stoped working
After upgrade to :
2.1-RC0 (amd64)
built on Sat Jun 22 15:45:58 EDT 2013
openBGPd stopped working giving follo...
Svetozar Urumov
09:56 PM Revision 211d95a9: Fix the RRD RRA’s to collect the correct amount of data for the Previous Period view for each resolution.
Applied when RRD's are created.
RRA:AVERAGE:0.5:1:1200 = 20 hours of 1 minute data
RRA:AVERAGE:0.5:5:720 ...
N0YB
04:16 AM Revision 1e86f510: RRD Specify RRA and Resolution
Don't leave it up to RRD Tool to select the RRA and resolution to use.
Specify the RRA and resolution to use per the ...
N0YB
03:53 AM Revision 88ba6d31: Merge branch 'RELENG_2_1' of git://github.com/pfsense/pfsense into RELENG_2_1
N0YB

06/22/2013

11:01 AM Revision 63b69d34: System: Group manager, set max length for groupname to 16 characters
Pi Ba
10:55 AM Revision e06263e1: Merge pull request #674 from PiBa-NL/SystemGroupmanager_16charName
System: Group manager, set max length for groupname to 16 characters Ermal Luçi
12:27 AM Bug #2997: CARP and pfSync traffic issues with traffic shaping
Hi,
this should be already foreseen (http://forum.pfsense.org/index.php/topic,45045.msg344264.html#msg344264), ju...
Michele Di Maria

06/21/2013

11:06 PM Revision 51f1fc58: Use Probe Interval on gateway advanced settings
Phil Davis
10:40 PM Revision 3db408b3: System: Group manager, set max length for groupname to 16 characters
Pi Ba
11:54 AM Feature #3053 (New): Automatically add DHCP static addresses to CP passthru-mac
Add a new option to Captive Portal to automatically add static addresses configured on DHCP server to the list of pas... Wendell Borges
09:06 AM Revision b6aecb27: Merge pull request #673 from phil-davis/master
Use "Probe Interval" to describe this advanced gateway parameter Ermal Luçi
05:03 AM Bug #3052 (Rejected): Adding a static dhcp for mac address dissapears.
Cannot say if its a bug or normal behaviour. This is what i have
1 wan, 3 Vlan's
When i want to add a static ma...
Tom De Coninck
02:48 AM Revision 490cd438: Use Probe Interval on gateway advanced settings
Phil Davis
02:21 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Thanks.
I will test as soon as it's in a snapshot (im currently on 2.1RC0). Backing out the old patch already yielde...
Peter Borföi

06/20/2013

09:27 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I have placed all the changes I have made to racoon up on Github. You can find them "here":https://github.com/duchsc... David Duchscher
12:24 PM pfSense Packages Bug #3051: Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
I can confirm that bug on Snort 2.9.4.6 pkg v. 2.5.9.
pfSense 2.1 RC0
B H
09:18 AM pfSense Packages Bug #3051 (Resolved): Snort 2.9.4.6 pkg v. 2.5.9 -> wansuppress
Pfsense 2.1 of 06/19/2013 17:23.
If change wansuppress on Snort, is necessary reboot Pfsense to enable the new rule...
Claudio Berselli
11:57 AM Bug #3045: NTPD crash / doesn't come up
Not any single crash with the new file. The OpenNTPD service is running rock-stable. No crash, no error in system-log... B H
04:50 AM Bug #3050 (Resolved): error loading TCP block or reject rule
Renato Botelho
04:44 AM Bug #3050: error loading TCP block or reject rule
Erik Augustsson wrote:
> Works for me
same here
Thomas Rieschl
04:28 AM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
Seems correct as a patch as long as you do not get LORs.
I though this was handled in the ioctl patch code already...
Ermal Luçi

06/19/2013

11:11 PM Bug #3024: need a pipe / flowset / sched number
I think I'm close to the problem, I deleted the database files belonging to the captive portal " /var/db " and then r... Alberto Palau
06:02 PM Bug #3030: When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
It's fine to leave bandwidth blank, altq fills it using the interface bandwidth. On my tests I could reproduce the is... Renato Botelho
12:47 PM Revision 94744c27: Correct gateway down/probe interval text.
Jim Pingle
12:45 PM Revision 94fb9f2d: Correct gateway down/probe interval text.
Jim Pingle
08:42 AM Revision b7d6c7f6: Correct the comments describing the error with correct values
Ermal LUÇI
08:42 AM Revision 6870b5ce: Correct the comments describing the error with correct values
Ermal LUÇI
08:20 AM Bug #2511: DHCPv6 Shows Wrong DUID
I seem to have a similar problem.
A windows 8 client with the DUID 00:01:00:01:18:1c:59:c5:00:25:22:92:f5:43 (veri...
Jeroen van der Wal
07:02 AM Bug #3050: error loading TCP block or reject rule
Works for me Erik Augustsson
02:43 AM Bug #3047: IPSEC remote access broken in 2.03
same Problem since PFSense 2.0.2 with Android 4.1.2, 4.2, iOS 4/5.
Downgrade back to 2.0.1 and everything is fine wi...
Micha Ch
12:20 AM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability
Chris Buechler

06/18/2013

09:57 PM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
I backed the following patch out from ipsec-tools and many of my issues when away.
https://github.com/duchscherd/p...
David Duchscher
08:19 PM Bug #3049: RAM Disk RRD Loss Vulnerability

Fix verified.

RRD backup file rrd.tgz is retained after reboot.

NOYB NOYB
05:50 AM Bug #3049: RAM Disk RRD Loss Vulnerability
Applied in changeset commit:ef01b77f6dc5e2f4ba254739a1792207e7b52a09. Renato Botelho
05:50 AM Bug #3049 (Feedback): RAM Disk RRD Loss Vulnerability
Applied in changeset commit:dc21d4d5618e5190dbc85a479489b230063450f5. Renato Botelho
07:55 PM Revision d5e4f7c9: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
07:54 PM Revision 4f0710f3: Use the name of the interface (lan, opt1, etc) rather than a loop-derived number for the DHCP failover peer name. This should be more accurate in cases where DHCP changes for interfaces happen out of order on CARP clusters, or when somehow an interface's configuration exists on one but not the other.
Jim Pingle
06:43 PM Revision 40e6086a: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:42 PM Revision 2706c79b: Allow removing CA and Cert entries that are blank/empty. Fixes #3005
Jim Pingle
06:03 PM Revision 8744a113: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
06:00 PM Revision 7ddfa922: Add an option to force IPsec to reload on failover, which is needed in some cases for IPsec to fail from one interface to another. Ticket #2896
Jim Pingle
05:31 PM Revision 6743ab28: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:28 PM Revision a27403c4: Add a brief description about bandwidth vs bursting.
Jim Pingle
05:01 PM Revision 850324a2: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
05:00 PM Revision 57c83fd6: Add a field to allow rejecting DHCP leases from a specific upstream DHCP server.
Jim Pingle
04:01 PM Revision f03cf892: A better fix for conditionally including burst.
Jim Pingle
04:01 PM Revision c32e0581: A better fix for conditionally including burst.
Jim Pingle
03:57 PM Revision e43fa2ac: Burst of 0 is also valid
Jim Pingle
03:57 PM Revision 012cd3ba: Burst of 0 is also valid
Jim Pingle
03:53 PM Revision f1a17b1a: Only add burst if a burst is defined
Jim Pingle
03:52 PM Revision 11421996: Only add burst if a burst is defined
Jim Pingle
03:02 PM Revision f63733e0: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
03:01 PM Revision 45e12bad: No need for this block of code, it will always have flags by this point if they are needed.
Jim Pingle
02:54 PM Revision 5015ec4c: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:52 PM Revision 57fa7011: Ensure that we only add a state type on pass, and that we only add flags to a TCP reject rule if they were not added previously. Fixes #3050
Jim Pingle
02:06 PM Revision bca506d4: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
02:05 PM Revision d17c7b79: Change test after IPsec apply to check for any value >= 0. If a user has hostnames vpn_ipsec_configure() now returns the number of hostnames, so the previous test failed and the "apply changes" button would never go away.
Jim Pingle
01:50 PM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:40e6086ada6b73f6432b7ac93d4b376941028b09. Jim Pingle
01:50 PM Bug #3005 (Feedback): cant delete or edit unknown CAs and certificate (orphan entries)
Applied in changeset commit:2706c79b47373fd294446d7ab0cc25d79bd494a1. Jim Pingle
10:48 AM Revision ef01b77f: Fix #3049, set $config as global to it can be read
Renato Botelho
10:48 AM Revision dc21d4d5: Fix #3049, set $config as global to it can be read
Renato Botelho
10:00 AM Bug #3050: error loading TCP block or reject rule
Applied in changeset commit:5015ec4cd0c497ca1db68e7393d2898ba57efb0b. Jim Pingle
10:00 AM Bug #3050 (Feedback): error loading TCP block or reject rule
Applied in changeset commit:57fa70112a9ab5bec06f5dd64bf0d987dfdae159. Jim Pingle
09:19 AM Bug #3050 (Resolved): error loading TCP block or reject rule
After updating to _2.1-RC0 (amd64) built on Mon Jun 17 17:28:37 EDT 2013_ none of my TCP block rules are working anym... Thomas Rieschl
05:47 AM Bug #3045 (Feedback): NTPD crash / doesn't come up
Renato Botelho
01:02 AM Bug #3045: NTPD crash / doesn't come up
Since implement your new file yesterday, i habe no more ntpd crashes. I will report again at the end of the week. B H
02:21 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Andreas, that's not really relevant to this bug - this is specifically for making altq work with the VLAN driver, tha... Mark Uhde
01:43 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Sorry i use the latest 2.1 RC0 i386 snapshot Andreas Huser
01:41 AM Bug #2349: vlan(4) needs altq adaption on FreeBSD 8.3++
Hi
i'm sorry for reopening this ticket.
I have four openvpn connections and try to configure a traffic shaper wit...
Andreas Huser
01:02 AM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
I did a more in-depth analysis with tcpdumps (LAN/WAN) here:
http://forum.pfsense.org/index.php/topic,62237.msg34202...
Anonymous
 

Also available in: Atom