Project

General

Profile

Activity

From 12/12/2013 to 01/10/2014

01/10/2014

04:41 PM Revision 706ba0e4: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
Jim Pingle
04:41 PM Revision 3e146089: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
Jim Pingle
07:40 AM Revision c349f263: Merge pull request #884 from dotike/master
Phase 1 ja_JA.UTF8 Translation Chris Buechler
03:08 AM Feature #3393: AS filtering support in aliases
An example of retrieving facebook ips from their AS number
[code]
whois -h whois.radb.net -- '-i origin AS32934' | ...
Ermal Luçi
03:06 AM Feature #3393 (Resolved): AS filtering support in aliases
It would be nice to have an option to define a type of AS number in the aliasesand retrieve all the ips from the whoi... Ermal Luçi
01:38 AM Feature #3377: OAuth2 authentication in captive portal
there will be publicly-available 2.2 snapshots in the not too distant future. At this point, I think you might be ok ... Chris Buechler

01/09/2014

08:23 AM Revision 43656206: Should to go master, not RELENG_2_1. Revert "Merge pull request #882 from derelict-pf/cp-nohttpsforwards"
This reverts commit f8d1587b6e2cd8441fa16733a02af25257fc7708, reversing
changes made to 51922cb793b83bf7d22fdaa47205f...
Chris Buechler
08:18 AM Revision f8d1587b: Merge pull request #882 from derelict-pf/cp-nohttpsforwards
Add checkbox and logic to disable forwarding HTTPS/SSL (Port 443) Chris Buechler
04:42 AM Feature #3377: OAuth2 authentication in captive portal
Here is a proof of concept, for a OAuth2 captive portal authentication with Google accounts :
https://github.com/...
Thomas NOEL
03:05 AM Revision fadfef2b: removing my fork README
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision e424ca74: bug address
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 93847971: Machine Translation (Phase 1) Complete.
Next steps:
- generate the .mo files and try loading it up
- Japanese Native Speaker(s) sanity pass through
(roughl...
Isaac (.ike) Levy
03:05 AM Revision 04571fb6: Machine generation used Google Translate API, translate.google.com, and Mort Yao's goog le-translate-cli
Wrapped some parsing around the following utility by Mort Yao,
https://github.com/soimort/google-translate-cli
Sig...
Isaac (.ike) Levy
03:05 AM Revision fe8747ed: first full machine run
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision a2e31d7d: workspot: great, but this process requires tedious re-running the program.
Next step: wrap the translation step in a timeout, and print some simple hook in the output so you can find it for th... Isaac (.ike) Levy
03:05 AM Revision 5e269b45: workspot: cleanup and continued translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 20c5f316: X-Generator: vim(1), awk(1), sed(1) - for real.
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 7a716fa2: workspot: trying to speed up machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 21e23bc2: workspot: pass through to correct minor syntax
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
Signed-off-by: Kiyo Takami <foof@blackskyresearch.net>
Isaac (.ike) Levy
03:05 AM Revision 0cd6ed3b: workspot: mechincal first pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision f8c3f30d: workspot: continuing with machine translation, several heavily repeated phrases scrutinized
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 60644dad: workspot: plowing ahead with machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 5f01b774: workspot: continuing machine translation first pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision c7056c99: workspot: carp and interface bits, continued first pass machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 5d2b2df0: workspot: firewall, interfaces, still plowing through machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision fbf5a7d8: workspot: RADIUS and Captive Portal messages, machine translations
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision cd134df7: Temporary README for GitHub fork
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 2129ac6a: workspot: country names
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 826cfb5c: jp syntax change
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 8908eeed: workspot, continuing to run through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 086689be: workspot, continuing to run through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 25ae07d0: workspot- plowing through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 002722b7: start by copying pt_BR locale
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 1023edb2: encoding change, and wrapping up LDAP sections rough pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 70d8b7b0: continued cumulative machine translations
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
02:52 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
duplicate of #2859.
this isn't the place to ask questions, please take those to the forum or mailing list.
Chris Buechler
02:50 AM Bug #3392: Allow to configure different mac addresses for multiple VLANs on same physical interface
Feature #2859
how to do that coz i have just one nic and 4 VLANS configured on it, 2 WAN and 2 LAN
Nikita Drachev
02:48 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
I had to beg to change the MAC of the provider.
Very important! I can make a few NIC VMware on, but I can not create...
Nikita Drachev

01/08/2014

09:18 AM Feature #972: Allow adding gateways outside of interface subnet
Hi Dan,
I felt in the same trouble, and I the idea I have found to survive reboot is using the ShellCmd package : ...
Dédé D
07:41 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
It works fine in a test VM here that never had Quagga, and also in a separate VM that had it previously and reinstall... Jim Pingle
02:46 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
Hello,
I have several pfSense firewalls, all having Quagga OSPF and running without issues.
They where installed ...
Johan Braeken
05:28 AM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
You mean you essentially created a cert chain yourself in the Certificate Authority Manager and then it worked? Malte Stretz

01/07/2014

07:20 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
that's reasonable, submit that as a pull request in github and we'll get it merged. Chris Buechler
04:15 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
You're still misunderstanding. If the initial connection by the user prior to CP authentication is to, say, https://... Chris Linstruth
02:19 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Use a signed certificate on your CP!!! Ermal Luçi
10:37 AM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
I believe you are missing the point.
This enables administrators to utilize HTTPS CP authentication, which might b...
Chris Linstruth
05:05 AM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Just do not configure https authentication! Ermal Luçi
04:39 PM Feature #3387: process_alias_urltable Frequency
Ah never mind. I forgot about the ability to change the type on the fly... Shawn Bruce
04:12 PM Feature #3387: process_alias_urltable Frequency
Shawn Bruce wrote:
> I have created a diff for firewall_aliases_edit.php against the latest git version. Would this ...
Shawn Bruce
04:11 PM Feature #3387: process_alias_urltable Frequency
I have created a diff for firewall_aliases_edit.php against the latest git version. Would this be acceptable?
I am...
Shawn Bruce
04:12 AM Feature #3387: process_alias_urltable Frequency
A code to upgrade current config to new format will be necessary too Renato Botelho
03:59 PM Revision 33e72874: Merge pull request #880 from phil-davis/master
Check for vertical bars in alias detail descriptions Ermal Luçi
03:05 PM Revision 7d14b000: Check for vertical bar at start or end of description
Phil Davis
02:59 PM Revision 24445691: Check for vertical bars in alias detail descriptions
The descriptions of each entry in an alias are stored in config.xml as a list delimited by "||". So you cannot have "... Phil Davis
10:58 AM Revision 51922cb7: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
Renato Botelho
10:58 AM Revision 6b660731: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
Renato Botelho
09:41 AM Revision 7c2ea0cc: Update reserved_keywords checks to match firewall_aliases_edit
firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real...
Phil Davis
09:39 AM Revision fe56417f: Merge pull request #879 from phil-davis/master
Update reserved_keywords checks to match firewall_aliases_edit Renato Botelho
07:39 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
It seems like maybe the authentication fallback that allows a person to login using local auth when their LDAP server... Jim Pingle
04:59 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
On pfSense 2.2 you will be able to revert GUI auth backend to Local Database on the same option you use to restore GU... Renato Botelho
06:51 AM Bug #3389 (Resolved): GUI allows to configure ICMPv4 types for ICMPv6 firewall rules
When I try to create a firewall rule that handles only certain types of IPv6 ICMP traffic, the interface lets me sele... Andreas Peetz
05:00 AM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Applied in changeset commit:51922cb793b83bf7d22fdaa47205fd59b4d70e87. Renato Botelho
05:00 AM Bug #3384 (Feedback): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Applied in changeset commit:6b6607316481aacaa055f8e4bce2ce1e520d3b1b. Renato Botelho

01/06/2014

05:09 PM Revision 4410f699: This might also say "icmpv6" here and lead to a bad rule.
Jim Pingle
05:08 PM Revision 0959b4d3: This might also say "icmpv6" here and lead to a bad rule.
Jim Pingle
04:48 PM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/e98daec5960b7ecdd18bc461003df3a18d2adbe7
Chris Linstruth
04:45 PM Bug #3340: Captive Portal deletes concurrent sessions even if noconcurrentlogins is not set
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/ae6c69833f34d8f14b1c6a9508126905328340bc
Chris Linstruth
04:42 PM Bug #3124: portal_reply_page called twice in specific circumstance
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/4fd56afe541a0a350dfe52b20521a551edd9f276
Chris Linstruth
04:11 PM Revision 81f19476: Add an option to force a gateway to be down, it fixes #2847
Renato Botelho
03:02 PM Revision de3987e5: Update reserved_keywords checks to match firewall_aliases_edit
firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real...
Phil Davis
02:35 PM Revision 30e2adbc: Merge pull request #871 from phildd/master
Dynamic DNS: List GWGs in Interface to send update from Ermal Luçi
11:35 AM Feature #3387 (New): process_alias_urltable Frequency
Currently the urltable design only allows for updates on a daily interval and is processed via crontab every 12 hours... Shawn Bruce
10:10 AM Feature #2847 (Feedback): Add a checkbox to flag a gateway as "down"
Applied in changeset commit:81f1947666ebbe19f1f6579a1e5293c42c6d1c04. Renato Botelho
09:13 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
Ermal Luçi
07:31 AM Revision 7ad4b9b7: Merge pull request #878 from phil-davis/master
Bulk Import: fix copy-paste var name error Ermal Luçi
02:43 AM Revision 3b4e6952: Bulk Import: fix copy-paste var name error
Phil Davis

01/05/2014

11:18 AM Revision b760fd31: Merge pull request #877 from phil-davis/master
Allow individual line descriptions on alias bulk import Ermal Luçi
09:35 AM Revision 8c470066: Allow individual line descriptions on alias bulk import
This enhancement allows the user to make a text file of IP addresses, IP subnets and/or IP ranges, like they have alw... Phil Davis
08:54 AM Bug #3386: apinger not picking up 2nd OpenVPN tunnel
I did another reboot and now it worked. You can close this issue (did not find button to close it myself). Schlomo Schapiro
08:48 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
When adding a 2nd OpenVPN tunnel (client side, shared key static setup) and the corresponding Interface and Gateway i... Schlomo Schapiro

01/04/2014

10:32 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
After I posted the above, I have a new idea.
I just copied the Root CA certificate to the Intermediate CA's certif...
Tim Lau
10:18 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
I am hit with the same bug.
Also, if you set the Peer Certificate Authority to the Root CA, 2 things happen:
1....
Tim Lau
02:49 PM Feature #3385: Accommodate static routes for PPTP connections
correction :
When the VPN reconnects, the static route is not reinstated and must be re-instated to bring the rou...
James Mills
02:47 PM Feature #3385 (Closed): Accommodate static routes for PPTP connections
Creating a static route on the pfSense box allows routing from the 10.20.2.0 network back across the (pptp) vpn to th... James Mills
07:00 AM Bug #3384 (Resolved): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
ntp.conf(5):
limited
Deny service if the packet spacing violates the lower limits specified
in ...
Jeroen Roovers
04:29 AM Bug #3383 (Resolved): Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
Hy,
This one have been difficult to find.
I set up a ldap server in user manager through the web gui. Everything ...
Florent THOMAS

01/03/2014

10:00 PM Revision f05bf59b: Merge pull request #875 from dotike/spellcheck
minor spelling correction for pfSense master branch Ermal Luçi
09:41 PM Revision 41681aa6: minor spelling correction for pfSense master branch
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:56 PM Revision 4e6405b9: Oops correct php syntax
Ermal LUÇI
03:38 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
I've also run into this problem. I didn't want it to get so buried in the pile that it never got looked at again. Rene Churchill
03:05 PM Revision 21f82ab6: Do not allocate the same pipe to everyone rather give each person its own!
Ermal LUÇI
03:05 PM Revision 762b34c4: Do not allocate the same pipe to everyone rather give each person its own!
Ermal LUÇI
02:53 PM Revision f38b383b: Use empty here for testing even if the setting is unset
Ermal LUÇI
02:52 PM Revision c8d611ed: Use empty here for testing even if the setting is unset
Ermal LUÇI
01:24 PM Revision a3a1b24e: Move to zerocopy_enbale for bpf to optimize bpf logging which uses bpf interface. This should increase the general performance since pflog is always enabled.
Ermal LUÇI
11:21 AM Bug #3382 (New): IGMPPROXY fails with more than 32 interfaces
Hi,
I have a problem with the igmpproxy:
I am using pfSense in an enviroment of round about 120 users, and every ...
Thomas Levi
08:33 AM Revision 723f0ac9: Merge pull request #873 from tuyan/patch/copyright_years
Update product_copyright_years end to be calculated on the fly. Chris Buechler

01/02/2014

09:54 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
Further to this, the " Borrow from other queues when available" doesn't work when you go 1 level deeper than the root... Ignat Esso
08:25 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
FYI - The WAN interface seems to be 100% correct all the time. Ignat Esso
08:25 PM Bug #3381 (Resolved): LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues. This looks to b... Ignat Esso
03:57 PM Revision 2bb93345: Update copyright_years to be calculated on the fly.
Tuyan Ozipek
03:25 PM pfSense Packages Bug #3380 (Not a Bug): FreeRadius-User-Option "Expiration Date" kills the FreeRadius-Server
Hi,
after adding an User-Expiration-Option to an user of FreeRadius Service, radius tries to restart but breaks:
...
Thomas Levi
11:58 AM Revision 8f56dd27: DyndDNS edit: unset vars when no longer used
phildd
11:13 AM Revision 0350084d: fix syntax
Renato Botelho
10:41 AM Revision 2a45e05f: Fix filter regex
Renato Botelho
09:20 AM Revision 52311f0c: Merge pull request #870 from blagynchy/patch-1
Happy New Year 2014! Renato Botelho

01/01/2014

11:54 PM Revision 9dc3f2bb: Happy New Year 2014!
Optimal: Just updating the copyright years;
I wish to all of you all of health, happiness and good luck of earth to ...
Valentin Georgiev

12/31/2013

12:28 PM Revision 31dce430: Upgrade all firewall rules to include a tracker field. Add a tracker field even for nat for later usage while here.
Ermal LUÇI
12:23 PM Revision 2006d7a4: Generate a tracker id for the filter rules for now. Maybe for nat rules as well?
Ermal LUÇI
09:52 AM Feature #3377: OAuth2 authentication in captive portal
Sure go ahead. Ermal Luçi
04:56 AM Feature #3377 (New): OAuth2 authentication in captive portal
In Captive Portal we have native, ldap and radius authentication. Today, a lot of authentication systems provide OAut... Thomas NOEL

12/30/2013

04:14 PM Revision ba1c86d9: Remove scrub as well
Ermal LUÇI
03:45 PM Revision 31300a95: List GWGs in Interface to send update from
phildd
03:27 PM Revision 32fd1703: Remove even negating nat rules
Ermal LUÇI
02:47 PM Revision a03dfc60: Correct matching for single rule. Somehow the egrep did not work there!
Ermal LUÇI
02:34 PM Revision b80e29e4: Speed up a bit rule number identification by avoiding going into kernel but using the rules parsing of pf which gives the same effect.
Ermal LUÇI
11:56 AM Revision 239024ee: Merge pull request #866 from andrespetralli/master
Enabling advanced RFC 2136 configuration for DHCPd service Renato Botelho
09:23 AM Revision 44b72c67: Fix display of CIDR/Update Freq in Alias Edit
Fixes #3376. I have no idea what the "^" characters were meant to do, but removing them makes the CIDR/Update Freq va... Phil Davis
09:23 AM Revision d564ed24: Validate IP address ranges correctly on Alias Bulk Import
The code was there to attempt to validate and implement IP address range lines in Alias Bulk Import e.g.
10.20.0.0-10...
phildd
08:07 AM Revision 737f26e9: Merge pull request #868 from phildd/master
Validate IP address ranges correctly on Alias Bulk Import Ermal Luçi
08:06 AM Revision ef1c9f09: Merge pull request #867 from phil-davis/master
Fix display of CIDR/Update Freq in Alias Edit Ermal Luçi
03:30 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:44b72c67ec3331ecd3a6430697ad47dbeac7c450. Phillip Davis
02:10 AM Bug #3376 (Feedback): Alias Edit does not display correctly
Applied in changeset commit:1b9ab14ad23e1f66a11801fbe7a24423ab8529a0. Phillip Davis

12/29/2013

04:05 PM Revision 54e81df0: Validate IP address ranges correctly on Alias Bulk Import
The code was there to attempt to validate and implement IP address range lines in Alias Bulk Import e.g.
10.20.0.0-10...
phildd
02:12 PM Revision 1b9ab14a: Fix display of CIDR/Update Freq in Alias Edit
Fixes #3376. I have no idea what the "^" characters were meant to do, but removing them makes the CIDR/Update Freq va... Phil Davis
08:13 AM Bug #3376: Alias Edit does not display correctly
I have no idea what I am doing with the jQuery stuff, but I pulled out some "^" marks in pull request https://github.... Phillip Davis
07:54 AM Bug #3376 (Resolved): Alias Edit does not display correctly
I had a 2.1-RELEASE system and GitSync'd to the 2.1 release branch. I was using Alias Bulk Import, but then also real... Phillip Davis

12/27/2013

09:51 PM Revision 5a890490: Modernize a bit the sshd sart file
Ermal LUÇI
09:38 PM Revision 9be0ec8a: Use the check properly!
Ermal LUÇI
09:35 PM Revision 635c00d3: Correct the check to what was intended
Ermal LUÇI
09:34 PM Revision d68494e6: Correct the check to what was intended
Ermal LUÇI
08:50 PM Revision 57b02731: Remove not needed code
Ermal LUÇI
08:49 PM Revision f6d89471: Make sense of interface mtu handling code. No need to do unneeded operations. This fixes slow boot times and proper handling of mtu for vlans though some work or better model is needed for other interface types. Manual merge of 53555bf2f796cd53cf649410fe1827a9a45fc4a7
Ermal LUÇI
08:37 PM Revision 53555bf2: Make sense of interface mtu handling code. No need to do unneeded operations. This fixes slow boot times and proper handling of mtu for vlans though some work or better model is needed for other interface types.
Ermal LUÇI
06:10 PM Revision aaa78416: Add sshd service to list (if enabled)
Jim Pingle
02:58 PM Revision 1a4ef44e: Delete static route when monitor IP is removed, also save monitor IP even when it's disabled
Renato Botelho
02:58 PM Revision 14be28af: No reason to set the same value to ipprotocol
Renato Botelho
02:12 PM Revision fcd01c8a: Delete static route when monitor IP is removed, also save monitor IP even when it's disabled
Renato Botelho
02:02 PM Revision ee574a9e: Fix a bug introduced in commit 06b8d43c that breaks return_gateways_array() called with $disabled == false
Renato Botelho
01:55 PM Revision 63fee576: No reason to set the same value to ipprotocol
Renato Botelho
09:11 AM Bug #2514: static routes for monitor IPs should be removed
There was an attempt to remove it in the past but seems it had side-effects (see ticket #3179 and commit:32a9eb1873).... Renato Botelho
05:05 AM pfSense Packages Bug #3375 (Closed): BIND, ACLs: Incorrect code is being generated for empty range ACL.
BIND 9.9.4 pkg v 0.3.2;
Steps to reproduce:
1. Create an ACL "Test";
2. Follow the advise and leave "Enter IP .....
Dmitriy K
04:58 AM Bug #3374: Firewall logs shows incorrect rules
I see. Pretty understandable reason.
Basically speaking, if my pfsense box will go berserk with "reload fw filter"...
Dmitriy K
03:22 AM Revision ffe6f371: fix typo
Chris Buechler
02:06 AM Bug #3353: Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
This is probably related to an issue fixed in head of pf and probably the MFC is missed.
Not related to the previous...
Ermal Luçi

12/26/2013

09:52 PM Revision 2aff8089: Fix wording/spacing
Jim Pingle
09:41 PM Revision 5c427ce7: Add support for local (push route) and remote (iroute) network definitions in an OpenVPN client-specific override entry.
Jim Pingle
09:11 PM Revision 9bc68540: Make this box a little narrow so it doesn't force the descriptions to wrap.
Jim Pingle
08:54 PM Revision 141254eb: Use empty even here
Ermal LUÇI
08:47 PM Revision 7cbfc265: Add a "status" subcommand to the svc php shell script.
Jim Pingle
08:28 PM Revision fed1b372: Check if there is a value before trying to do any operation
Ermal LUÇI
08:27 PM Revision c7a3356e: Add a setting to allow the user to specify the clog file size so more (or less) entries may be kept in the raw logs. Retain previous default size values if the user has not specified a preferred size. Files can only be resized when initialized, so provide a "Reset All Logs" button as well to force clear all logs and set them up at the new size.
Jim Pingle
07:27 PM Revision 7b03748b: Correct the php-fpm configuration generation
Ermal LUÇI
06:10 PM Revision 3f248cb6: Fix #3354, savecore -C only expects dumpdev
Renato Botelho
05:53 PM Revision e1ebe9e2: Add an option for users to be able to adjust how many configuration revisions are kept in the local backup cache.
Jim Pingle
04:07 PM Revision bfe615ee: Show backup file size in config history.
Jim Pingle
03:51 PM Revision 57671f81: Fix syntax, unbreak dashboard
Jim Pingle
03:45 PM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
Same problem here with pfsense 2.1 and cisco router with IOS 12.4(15)T15 as remote endpoint.
IPSEC tunnel doesn't co...
Francesco Lotti
12:11 PM Bug #3353 (New): Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
This still happens on a current build. Jim Pingle
12:10 PM Bug #3354 (Feedback): Savecore error during bootup
Applied in changeset commit:3f248cb65a25189f7cff8f6ad4321998caaab073. Renato Botelho

12/24/2013

05:27 PM Revision fd34b8b5: Fix syntax
Renato Botelho
04:28 PM Revision 9e63dca9: Use intval even here
Ermal LUÇI
04:25 PM Revision b0ae5213: Use intval here to not trust php and also use empty which gives more protections
Ermal LUÇI
03:51 PM Revision 59257969: Sprinkle some more unsets
Ermal LUÇI
03:06 PM Revision e6756251: Remove /var/run/booting early to be consistent with $g['booting']
Renato Botelho
03:04 PM Revision f9dfaeae: Revert "Make sure functions called by rc.start_packages can see $g['booting'] when we are booting"
This reverts commit 5eb99ec9fae6b6ff077559b3feab8565701f2635. Renato Botelho
03:04 PM Revision 0450ae55: Revert "Only unset $g['booting'] when it was set here"
This reverts commit 73abb573feae03b164d3ed4284db4ed4ff26a256. Renato Botelho
03:04 PM Revision 5551d818: Remove /var/run/booting early to be consistent with $g['booting']
Renato Botelho
03:01 PM Revision 677a6426: Revert "Make sure functions called by rc.start_packages can see $g['booting'] when we are booting"
This reverts commit 8a461f41db7907b310171b6e0fb901b2f5e7e2fe. Renato Botelho
03:01 PM Revision afd33d68: Revert "Only unset $g['booting'] when it was set here"
This reverts commit 47493bd326cd7141df7df708b69e10479ed800af. Renato Botelho
02:43 PM Revision 73abb573: Only unset $g['booting'] when it was set here
Renato Botelho
02:42 PM Revision 47493bd3: Only unset $g['booting'] when it was set here
Renato Botelho
02:17 PM Revision 5eb99ec9: Make sure functions called by rc.start_packages can see $g['booting'] when we are booting
Renato Botelho
02:16 PM Revision e2edc30d: When WANTIME is empty, there is nothing to do here
Renato Botelho
02:16 PM Revision 811ecea4: test only does integer comparison, use bc to compare float
Renato Botelho
02:16 PM Revision 8f105c8a: Save status even if no script is executed
Renato Botelho
02:16 PM Revision 98864780: On first run REVIOUSSTATUS doesn't exist, so it cannot be UP or DOWN, invert the logic to fix this. While I'm here, check if file exists before cat it
Renato Botelho
02:15 PM Revision 8a461f41: Make sure functions called by rc.start_packages can see $g['booting'] when we are booting
Renato Botelho
02:09 PM Revision 72a95734: When WANTIME is empty, there is nothing to do here
Renato Botelho
02:08 PM Revision 67e86129: test only does integer comparison, use bc to compare float
Renato Botelho
02:07 PM Revision 128cc1f4: Save status even if no script is executed
Renato Botelho
02:06 PM Revision cd14bb19: On first run REVIOUSSTATUS doesn't exist, so it cannot be UP or DOWN, invert the logic to fix this. While I'm here, check if file exists before cat it
Renato Botelho
10:52 AM Revision 15bec718: While here unset some variables even on vouchers side
Ermal LUÇI
10:45 AM Revision 1f965b69: Merge manually 4fd85b115e2550969ddeadd43a2bc6dafff21779 3f2ae9d58f5ea3d9de175e8daa9c8902b3f23440 and e049c5e74f009430e22e446f149a552d00846d7a
Ermal LUÇI
10:34 AM Revision a2a42c72: Remove not relevant comment now. Also make the operation clear to avoid priority issues.
Ermal LUÇI
10:28 AM Revision e049c5e7: unset these values to not confuse php
Ermal LUÇI
10:23 AM Revision 3f2ae9d5: Properly initialize this
Ermal LUÇI
10:22 AM Revision 4fd85b11: Switch to a while loop to make things clear and readble. Also properly set zone dedicated rules in the rules/pipes DBs to properly release when a zone is deactivated
Ermal LUÇI
10:00 AM Revision 27cea9a3: Remove not relevant comment now. Also make the operation clear to avoid priority issues.
Ermal LUÇI
09:30 AM Bug #3374 (Rejected): Firewall logs shows incorrect rules
It isn't random, it's just using what it knew at the time.
The rules are matched using what is recorded in the act...
Jim Pingle
04:59 AM Bug #3374 (Rejected): Firewall logs shows incorrect rules
Over time, Firewall log is going crazy and picking random rule to show.
Reason to this bug is unknown to me.
Dmitriy K
06:59 AM Revision 9172982d: Merge pull request #863 from dhiltonp/master
/usr/local/www/system.php: strip excess whitespace from ntp field Chris Buechler
04:20 AM Revision 87019fc4: Enabling advanced RFC 2136 configuration for DHCPd service
This change adds the ability to configure RFC 2136 domain name updates
using a hmac-md5 keyname/key.
Andres Petralli

12/23/2013

07:28 PM Revision 56301bed: Fix DHCP lease time display, strftime already convert it to local timezone, so we no need to calc offset
Renato Botelho
07:27 PM Revision d8b37f91: Fix DHCP lease time display, strftime already convert it to local timezone, so we no need to calc offset
Renato Botelho
05:44 PM Feature #972: Allow adding gateways outside of interface subnet
What would be the "correct" way to make this survive reboots, please? Dan F
06:34 AM Feature #972: Allow adding gateways outside of interface subnet
because accommodating 1 in 100,000 scenarios isn't a priority, especially when there is an easy manual work around. P... Chris Buechler
04:40 PM Revision f2aa8287: Remove 'deny unknown clients' option from DHCPv6 since it's not supported, it fixes #3364
Renato Botelho
04:40 PM Revision 079c2927: Remove 'deny unknown clients' option from DHCPv6 since it's not supported, it fixes #3364
Renato Botelho
04:16 PM Revision 26b6e758: Make sure to give the zone a name during the upgrade, or else it comes through with a blank/null name.
Jim Pingle
04:15 PM Revision db817c93: Make sure to give the zone a name during the upgrade, or else it comes through with a blank/null name.
Jim Pingle
02:57 PM Revision 66cc4d43: Correct displaying states status and avoid divison by zero due to wrong data collected
Ermal LUÇI
10:40 AM Bug #3364: DHCPv6 "Deny unknown clients" does not work
Applied in changeset commit:f2aa8287545d45ed22c44b5e2c102fb7a22658b0. Renato Botelho
10:40 AM Bug #3364 (Feedback): DHCPv6 "Deny unknown clients" does not work
Applied in changeset commit:079c2927622510cf34b3ccc225b9193143534c76. Renato Botelho

12/22/2013

02:39 PM Feature #972: Allow adding gateways outside of interface subnet
Three years and counting... How is this still not implemented / patched?
Oliver K.
01:37 PM Revision e20a0af7: Avoid dashboard divide by zero errors
phildd
01:35 PM Revision 0b5d55b7: Merge pull request #865 from phildd/master
Avoid dashboard divide by zero errors Chris Buechler
12:20 PM Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs
Normally this will be fixed when filterdns supports reloading with TTL of the DNS record.
This will come soon.
Ermal Luçi
11:49 AM Revision 15183bcb: Avoid dashboard divide by zero errors
phildd
01:28 AM Bug #3373: Sun Quad fast Ethernet ports constantly resetting
I'm guessing it may be fixed already in FreeBSD 10, in which case there isn't anything that needs to be done for 2.2.... Chris Buechler

12/21/2013

10:33 PM Bug #3373: Sun Quad fast Ethernet ports constantly resetting
This driver has worked in all previous versions. There are hundreds of units in operations now with this hardware in ... Charlie Singleton
09:09 PM Bug #3373 (Rejected): Sun Quad fast Ethernet ports constantly resetting
we don't control or develop drivers.
https://doc.pfsense.org/index.php/Policy_on_FreeBSD_issues
Chris Buechler
11:11 AM Bug #3373 (Rejected): Sun Quad fast Ethernet ports constantly resetting
Using the hme driver in version 2.1 with part# 501-5406-07 Sun Quad Fast Ethernet PCI card. Once configured, the por... Charlie Singleton
01:25 AM Revision e98daec5: Add checkbox and logic to disable forwarding HTTPS/SSL (Port 443)
connections to the captive portal if HTTPS logins is enabled. derelict-pf

12/20/2013

10:50 PM Revision 3e5933f2: Use return rather than exit to be friendly on CGI
Ermal LUÇI
10:49 PM Revision af8251cc: Addapt rc.newwanipv6 to FCGI calling
Ermal LUÇI
10:45 PM Revision e800a773: Call rc.newwanipv6 efficently through FCGI
Ermal LUÇI
10:32 PM Revision 362ec35d: Do not register the _ENV superglobal since its not required and probably not very useful in a [F]CGI world and its limit is restricted nowdays in pfSense.
Ermal LUÇI
10:08 PM Revision aa205c3b: Rmoeve register_long_arrays from php.ini and from php code the use of HTTP_*_VARS as its deprecated and luckily low use in pfSense to win memory and compativility
Ermal LUÇI
03:14 AM Bug #3372 (Rejected): Router advertisements originating from VLANs not forwarded correctly
this isn't true, RAs on VLANs are widely used with no issues. Tagging VLAN 1 is generally a bad idea, I suspect your ... Chris Buechler

12/19/2013

03:20 PM Bug #3372 (Rejected): Router advertisements originating from VLANs not forwarded correctly
With a simple _OPT1_ configured for IPv6 and 'unmanaged' router advertisements, the (ICMP6) RA packages are (1) *meas... Mich MSvB
02:52 PM Revision cc263020: Provide a setting to disable the auto added LAN SPDs in the DB
Ermal LUÇI
09:20 AM Revision 85d0e959: Make even ipsec script ready for GET arguments but later on it will be used as such
Ermal LUÇI
09:12 AM Revision b2af12ad: Use closelog to explicitly close open resource.
Ermal LUÇI
09:10 AM Revision b95b40a1: Move also tls-verify to fcgicli to avoid forking php process. Maybe even this should be done as a plugin to avoid overhead of forking.
Ermal LUÇI
08:53 AM Revision 5e28dad4: Migrate openvpn authentication to use fcgicli rather than forking a php process. Maybe should could consider to write a short library todo this
Ermal LUÇI
06:48 AM Feature #3371 (Rejected): Permit reorder the IPSec Tunnels
Duplicate of #3328 Jim Pingle
05:30 AM Feature #3371 (Rejected): Permit reorder the IPSec Tunnels
When using IPSec and set 2 networks match is not possible "take" the second network even the netmask is more "closed"... Alisson Oliveira
05:06 AM Feature #3370 (Resolved): Permit reorder gateways
When using "Allow default gateway switching", pfSense will change to next gateway avaliable. Isn't possible choose wh... Alisson Oliveira
03:35 AM Bug #3182: VMware vmxnet interfaces are not detected as VLAN capable
From what i see the driver has proper flags defined.
The code of fetching the capabilities is generic.
Probably t...
Ermal Luçi
03:27 AM Bug #3353 (Resolved): Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
Ermal Luçi
03:25 AM Bug #3361: DHCP6 WAN is not obtaining a default gateway
You expect RA on em0 but receive one from em1 not sure if you have 2 interfaces with DHCPv6?
Can you confirm that?
Ermal Luçi

12/18/2013

10:00 PM Revision 27a01557: Use proper function to check for ipaddr and also do not call the module ip set function since its only v4 fro now
Ermal LUÇI
09:59 PM Revision 6a3b4601: Correct removing the ip addresses from an interface!
Ermal LUÇI
09:57 PM Revision 00e8315b: Correct issues not only with vlans but all other clonable interfaces(related to Ticket #3270. Also correct removing old ip addresses from the interface and handling the right interface on interface renabling.
Ermal LUÇI
09:45 PM Revision 78c36733: Use does_interface_exist rather than calling ifconfig directly
Ermal LUÇI
08:56 PM Feature #1938: Filter messages broken into multiple syslog messages
There is a patch that will add a GUI option to enable this behavior:
http://files.pfsense.org/jimp/patches/pf-log-on...
Jim Pingle
08:52 PM Feature #1938: Filter messages broken into multiple syslog messages
The workaround for this bug has changed in version 2.1. The affected section has been slightly rewritten so the posit... Ted Lum
02:34 PM Bug #3369 (Not a Bug): Captive vouchers expire too quickly
It happens that one week vouchers bagan to expire in less than 24h after their activation.
That's all I see in the l...
Todor K
01:53 PM Feature #2439: XEN Para-virtualized Drivers Support
+10000 for XENSERVER PV driver support. freebsd 10 is supporting it already. Alex Alex
01:51 PM Revision e677dd06: Set latest config version
Ermal LUÇI
01:50 PM Revision e7d35d84: Convert ipaliases over carp to new world order
Ermal LUÇI
04:16 AM pfSense Packages Bug #3368 (Resolved): ProxyPassReverse / balancer://cluster/ adds extra slash to redirect
See bug report on https://issues.apache.org/bugzilla/show_bug.cgi?id=51982
Solution: update apache package to 2.2....
Anton Bontes

12/17/2013

07:41 PM Revision f3512fca: Reduce the total minutes by the remote minutes used, do not use the value directly. Otherwise the voucher will be cut short or listed invalid when it otherwise should have time left over.
Jim Pingle
07:38 PM Revision e183e1ce: Reduce the total minutes by the remote minutes used, do not use the value directly. Otherwise the voucher will be cut short or listed invalid when it otherwise should have time left over.
Jim Pingle
06:17 AM Feature #3367 (Resolved): Remove restriction that IPv4+IPv6 rules limited to TCP, UDP, ICMP only
[pfSense 2.1]
If you try to create a rule which is IPv4+IPv6 with protocol "any", it is rejected with the followin...
Brian Candler
06:05 AM Feature #3366 (Duplicate): Diagnostics: DNS Lookup does not return AAAA records
(1) diag_dns.php shows only A records for the given name.
(2) When called with createalias=true, it creates the alia...
Brian Candler

12/16/2013

08:12 PM Revision 1848a25e: Fix saving of voucher sync settings.
Jim Pingle
08:11 PM Revision c1d5f0ef: Fix saving of voucher sync settings.
Jim Pingle
05:34 PM Feature #3365 (Resolved): Implement package signing
Need to implement PBI signing for 2.2. Chris Buechler
01:57 PM Revision 00e55088: Register a function to unset certain globals after requests finish processing to release memory early
Ermal LUÇI
01:34 PM Revision 5be2085a: Rely on memory rather than LOWMEM boolean
Ermal LUÇI

12/15/2013

09:26 PM Revision 6d7ee1ab: Use same value consistently for configuration and tolerate a bit more
Ermal LUÇI
09:15 PM Revision 08b64f79: Use events to start sshd rather than relying on forking
Ermal LUÇI
08:43 PM Revision 815f1f77: Support if called from fastcgi
Ermal LUÇI
08:41 PM Revision 1c3d2cd3: Send events to check_reload_status for carp master/backup
Ermal LUÇI
07:11 PM Revision 1590947b: Call all php scripts in bootup with fcgicli. For rc.bootup only the part needing input needs to be abstracted
Ermal LUÇI
12:12 AM Bug #3364 (Resolved): DHCPv6 "Deny unknown clients" does not work
While experimenting with IPv6 I noticed that the "Deny unknown clients" option in "Services - DHCPv6 server" does not... Anders Lind

12/14/2013

11:24 PM pfSense Packages Bug #3363 (Needs Patch): TinyDNS does not respond to IPv6 subnet
TinyDNS seems not respond to IPv6 addresses when trying DNS Server - Settings - Respond to IP.
I have tried to make ...
Anders Lind
09:42 PM Revision 83e46727: Mute the output of the command since its not really useful
Ermal LUÇI
09:39 PM Revision 73c3eed8: Remove deprecated sysctls. vfs.forcesync needs to be seen if the patch needs to be put in place again!
Ermal LUÇI
09:21 PM Revision 9e0fb701: Use system ident rather than php-fpm for system logs
Ermal LUÇI
07:20 PM Revision 4aea91d8: Switch to php-fpm for lighty and check_reload_status will use it. Step by step will migrate the other calls
Ermal LUÇI
11:22 AM Revision da49fd89: Remove a probably bad copy/paste line
Renato Botelho
01:29 AM Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs
Thanks for the confirmation. Sorry, forgot to mention that I'm running 2.1-RELEASE as well.
It seems like a bug t...
Steve Reinhardt

12/13/2013

11:09 PM Revision c71b14fd: Make scripts able to react when called from FCGI with GET method
Ermal LUÇI
10:58 PM Revision a1007e19: Properly detect if an ip is already configured for VIP. Remove useless checks for carp
Ermal LUÇI
06:34 PM Revision 92603e27: Add an option to restore default logout/error/portal custom pages on Captive Portal. Fixes #3362
Renato Botelho
12:40 PM Feature #3362 (Feedback): Add a means to reset CP HTML/Error Page/Logout Page to default
Applied in changeset commit:92603e27d98bb89f63b2c0581f2fad2c39a9b09e. Renato Botelho
11:17 AM Feature #3362 (Resolved): Add a means to reset CP HTML/Error Page/Logout Page to default
While testing #3339 it hit me that we don't have any way to clear the defined pages for a captive portal instance. To... Jim Pingle
11:11 AM Feature #3339 (Resolved): Add a button to allow downloading the Captive Portal HTML text, error text, and logout page text
This works as expected, I can download the raw html/php source of the uploaded CP page. Jim Pingle
11:04 AM Bug #3195 (Resolved): CP MAC allows duplication
This appears to properly check now, adding a duplicate with different case is not allowed and produces an error in th... Jim Pingle
10:55 AM Feature #2416 (Resolved): Hybrid NAT mode that is a mix of Auto+Manual
This all appears to work as expected now. Jim Pingle
10:51 AM Bug #3361: DHCP6 WAN is not obtaining a default gateway
Additional info:
ifconfig shows ACCEPT_RTADV on for the WAN NIC.
Adding the gateawy manually does allow it to w...
Jim Pingle
09:54 AM Bug #3361 (Resolved): DHCP6 WAN is not obtaining a default gateway
On a 2.2 image the firewall pulls a WAN IP and even a LAN delegation, but does not get an IPv6 default route.
An i...
Jim Pingle
10:44 AM pfSense Packages Feature #3320: HAVP does not honor FW Gateway rules
My bad...
Found a nice piece of documentation for those who like experience this:
http://securite-ti.com/pfSense_We...
Orsiris de Jong
10:20 AM Bug #2833 (Resolved): Add a knob to prefer IPv4 over IPv6 for rare situations that require it
This works as expected on 2.2.
With it unchecked, IPv6 is preferred. Check it and try again, it uses IPv4. Unchec...
Jim Pingle
09:48 AM Bug #3122 (Resolved): CP Pass-through MAC entry must deny entering the firewall's own MAC address
This appears to work fine, it rejects any firewall MAC I attempt to add. Jim Pingle
08:49 AM Feature #3327 (Resolved): Allow reordering of 1:1 NAT entries
Looks like it all works as expected now, thanks! Jim Pingle
02:28 AM Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs
I just double-checked this now that 2.1-RELEASE has been out an running for ages. I have a table of the IPs of all my... Phillip Davis
12:54 AM Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs
I just ran into this problem, and I'd consider it a bug that needs to be fixed, not a feature request. I was using a... Steve Reinhardt

12/12/2013

07:32 PM Revision 940ef0e3: Fix parsing of the rule number in the pf log on FreeBSD 10.x, part of Bug #2122
Jim Pingle
11:21 AM Revision 8adb814b: /usr/local/www/system.php: strip excess whitespace from ntp field before processing
David P Hilton
10:38 AM Bug #2121: pfctl -ss output has changed on FreeBSD 10
The format is slightly different on 10.x than 9.x examples above.
In this sample output, 192.0.2.x is WAN on em0, 19...
Jim Pingle
08:43 AM Bug #3353 (New): Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
Still crashes on a current snapshot at the end of the wizard.... Jim Pingle
12:56 AM Bug #3046: Fatal error: Call to undefined function get_interface_ip() in /usr/local/captiveportal/radius_authentication.inc on line 56
I can confirm that this is also happening in 2.1-RELEASE with free radius2 2.1.12_1/2.2.0 pkg v1.6.7_2 Ozzy Schoonover
 

Also available in: Atom