Activity
From 12/25/2013 to 01/23/2014
01/23/2014
-
11:33 PM Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
- it doesn't hurt anything, but yeah that should likely only be there if the VPN is using IPv6.
-
11:31 PM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
- no idea what you're referring to, routes that OpenVPN creates are those you tell it to, and that all works as it shou...
-
11:28 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
- duplicate of #2952, we'll keep it on that one.
-
11:23 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
- could you please submit a pull request on github to master?
-
09:29 PM Feature #3410 (Resolved): Patch: Add Apple Open Directory memberUid support in group lookup
- This is a patch that adds compatibility to do memberUid style lookups used in Apple's Open Directory. Specifically, w...
-
05:43 PM Bug #3408: IPV6 DHCP not disabling on initial setup
- This is what was entered in the config on a fresh install of 2.1 not 2.1.1.
It seems to automatically enter the rang... -
04:15 AM Bug #3408: IPV6 DHCP not disabling on initial setup
- I could not reproduce it on a recent 2.1.1 snapshot. I'm wondering how could it put a range on dhcpv6 if you don't ch...
- 12:05 PM Revision 8467c588: Do not list the same CARP ip as an option for Interface
-
10:19 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
- That's not something I can duplicate under 2.1 or 2.1.1 built on "Wed Jan 22 04:46:20 EST 2014".
If I change a CAR... -
05:49 AM Bug #3407 (Feedback): Changing CARP IP to IP Alias doesn't work until failover is trigered
- As you mentioned, when moved from CARP (WAN) to an IP alias (using other CARP IP as interface), the IP stops answerin...
-
04:34 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
- I reproduced it here, will work on a fix.
-
02:52 AM Bug #3409 (Closed): IPv6 gif tunnel not working after reboot on PPPoE
- I have an Alix box with with WAN connected via VDSL PPPoE link and HE IPv6 tunnel configured here. With 2.1.1 pre-rel...
-
02:15 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
- getting stuck on reboot with active 3g dongle is getting a serious issue for me, i have tried 3 different 3g dongles ...
-
01:02 AM pfSense Packages Bug #3203: vnstat2 not working after pfsense 2.1 upgrade
- Hi,
This is still broken in 2.1.1 Pre-Release
Beginning package installation for vnstat2 .
Downloading package...
01/22/2014
-
07:40 PM Bug #3408 (Closed): IPV6 DHCP not disabling on initial setup
- Installing fresh copy of v2.1 with 1 WAN and 1 LAN adapter. Install to hard drive and after rebooting during initial ...
-
06:31 PM Bug #2952: Unvalidated input during system_firmware_check.php
- While I'm a big fan of the updates going over HTTPS for transport security, I would say that this is a different issu...
-
04:29 PM Bug #2952: Unvalidated input during system_firmware_check.php
- Netgate Pfsense images 2.1p1 and higher upgrade over HTTPS, making this attack more difficult.
-
02:06 PM Bug #2952: Unvalidated input during system_firmware_check.php
- Verified to still be present and exploitable in 2.1p1-RELEASE/nanobsd 4g (Netgate image), by replacing the reported ...
-
01:26 PM Bug #2952: Unvalidated input during system_firmware_check.php
- Hi,
I'd like to bring this issue up again, and increase it's priority to critical or high, as I have verified the ... -
05:12 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
- The config in the UI looks correct on both the master and the backup (listed as IP Alias in Virtual IPs screen, disap...
-
04:22 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
- you mean on the secondary, the primary, or both? What does ifconfig look like on both systems afterwards?
-
03:11 PM Bug #3407 (Resolved): Changing CARP IP to IP Alias doesn't work until failover is trigered
- If you change an existing CARP IP Address to an IP Alias it does not work, even after hitting apply. Instead, you ne...
-
03:07 PM Feature #3406 (Needs Patch): Change Virtual IP & CARP Status screens to a tree view
- For those of us that have dozens or more Virtual IPs, it would be helpful to see an alternative view that shows how a...
-
02:30 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
- Please read my comment on the proper solution.
This is a workaround/hack for your local installation. -
12:43 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
- I have attached a patch file for /etc/inc/services.inc
This will have the services_dhcpd_configure() function chec... -
10:46 AM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
- The proper solution for this is to bounce the dhcpd when the openvpn link comes up.
Check rc.newwanip[v6] script on ... -
10:12 AM Bug #3404 (New): DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
- When the services_dhcpd_configure() function is called during boot, it will skip interfaces that are not fully online...
-
02:22 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
- Filing this as a new bug so it doesn't fall under the cracks - the unvalidated input bug in #2952 has been verified t...
-
12:32 PM pfSense Packages Bug #3248 (Resolved): NUT package fails to write config to upsd.users
- Thanks
-
12:17 PM pfSense Packages Bug #3248: NUT package fails to write config to upsd.users
- I've been running this patch for over 3 months without issue. For what it's worth, I've also tested against current 2...
-
09:23 AM Feature #1557: Add the Interface descriptions to the OS interface descriptions
- Hi Developers of pfSense.
Is there any status update of this Feature?
2 Years ago the Target version was deleted.
...
01/21/2014
- 06:49 PM Revision 54597012: Replace regex by explode as suggested by Ermal
- 06:40 PM Revision 505d5c7a: Fix typo on variable name
- 06:38 PM Revision 613a94b3: Fix typo on variable name
-
02:58 PM Bug #3147: Adding new interface can cause issues
- https://forum.pfsense.org/index.php/topic,64704.0.html
As far as I'm concerned, it's a bug. Because I have not hi... - 12:38 PM Revision 43045948: Revert "Fix #3350. Do not destroy an interface when it's being disabled"
- Ermal reported issues when changes are made on VLAN parent interface
with this patch. He did other changes and interf... - 12:36 PM Revision d9797fd6: Revert "Fix #3350. Do not destroy an interface when it's being disabled"
- Ermal reported issues when changes are made on VLAN parent interface
with this patch. He did other changes and interf... -
10:13 AM Bug #3242 (Resolved): editing alias url table doesnt show full link
-
10:12 AM Bug #3242: editing alias url table doesnt show full link
- plz mark this as resolved
-
09:43 AM Bug #3345: Openvpn create route ipv6 default Pfsense 2.1
- Chris Buechler wrote:
> OpenVPN creates whatever routes it's configured to create (or that it pulls if pulling is en... -
09:26 AM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
- Related bug when and ovpns created virtual interface gateway ipv4 ipv4 and ipv6 route creates automaticament. This bu...
-
09:24 AM Bug #3401 (Resolved): Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
- I think using ipv4 in the openvpn conf should not generate the attribute tun-ipv6 attribute and not load the ipv6 mod...
-
03:31 AM Bug #3350: Disabling and enabling VLAN leaves VLAN interface missing
- It would be better to revert this commit now that interface_cofnigure does the right job at detecting if an interface...
-
12:13 AM pfSense Packages Bug #3400 (Resolved): apcupsd service config does not allow DEVICE to be set
- When configuring the apcupsd service using pfsense, only the UPSTYPE setting can be changed using the gui but not the...
01/20/2014
-
07:42 PM pfSense Packages Bug #2992: Boot problem after upgrade
- This happened to me today. It happened on a fresh install with only bandwidthd and openvpn installed, after I changed...
-
06:59 PM Revision b4d772dc: Correct this i thought i already did. Thanks-to: Phil Davis for spotting
-
03:09 PM Revision d760445e: Do not need to go in the internet world to start a package
-
03:00 PM Revision 44b19298: * Do not call stop service in the start command.
- * Add some more checks into the functions to avoid errors
* Also silence some output that can cause issues - 12:53 PM Revision 770a7759: Fix FreeBSD version detection for 10.x
- 11:36 AM Revision aefc6bc2: Obsolete old ntp binaries
- 11:35 AM Revision c42d721b: Obsolete old ntp binaries
-
07:25 AM Todo #3399 (Resolved): Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS
- Due to FreeBSD 10.x changes, nsupdate is no longer available for inclusion from base. We will need to use a replaceme...
-
03:36 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
- Firewall is updated to 2.1.1-PRERELEASE (amd64) built on Sun Jan 19 03:33:57 EST 2014. After boot MBUF status is 32% ...
01/19/2014
-
01:13 AM Bug #3321 (Resolved): IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
- thanks for the confirmation
-
12:36 AM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
- This problem has been fixed in 2.1.1-PRERELEASE! :)
01/17/2014
-
04:46 AM Feature #3398 (Needs Patch): Notifications - information about errors
- I test the pfsense on HP DL360 G5
CPU: Intel(R) Xeon(R) E5410
Ram: 8GB
Disk controller: P400i (RAID5 4x hdd)
Wh... -
02:50 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
- i got the same situation as well as with the 3g stick connected if i reboot pfsense then it would just get stuck when...
01/16/2014
-
02:13 PM Revision 93a79543: Bump version
-
01:30 PM Revision 254df317: Merge pull request #887 from brunostein/tracker_firewall_rule
- added input hidden with tracker value
-
12:31 PM Revision 72b774aa: added input hidden with tracker value
-
02:28 AM Bug #3397 (Needs Patch): Cannot load builtin or external firmware for mwl driver
- Hello,
I've tried to get a marvell wireless card to work a long time before posting this.
Here's the output of pf...
01/15/2014
-
05:35 PM Revision fdfa8f43: ports ntp moved to sbin, follow
-
05:28 PM Revision 3d54553b: ports ntp moved to sbin, follow
01/14/2014
- 11:34 PM Revision 096f73b4: Merge pull request #886 from dotike/master
- locale path name clarification
-
09:15 PM Todo #3396 (Resolved): Replace dnsmasq with Unbound
- The replacement of dnsmasq with unbound needs to be completed for 2.2.
-
08:40 PM Bug #3214 (Rejected): bogons/bogonsv6 include stupid things
- #3395 addresses the only problem here. none of that impacts DHCP4 clients.
-
08:39 PM Bug #3395 (Resolved): DHCPv6 client pass rules need to come before bogons
- 8000::/1 is included in Cymru's v6 bogons list. That's sane, since it shouldn't be in the Internet routing table, but...
-
08:17 PM Bug #3394: radvd wrongly binds to *:546 in some circumstances
- I'll provide further details privately to the person working on the issue, it's on a customer system and not somethin...
-
08:16 PM Bug #3394 (Resolved): radvd wrongly binds to *:546 in some circumstances
- I can't seem to determine why, as different systems with seemingly identical radvd.conf files don't consistently disp...
-
07:34 AM Bug #3045: NTPD crash / doesn't come up
- simply one line contining:
-0.056
(or other numbers) -
04:03 AM Bug #3045: NTPD crash / doesn't come up
- Fabio Giudici wrote:
> Good morning
> Just one more question: is it ntpd running in jail/chroot?
>
> Just to ... -
01:01 AM Bug #3045: NTPD crash / doesn't come up
- Good morning
Just one more question: is it ntpd running in jail/chroot?
Just to restrict the issue...but it se... -
07:10 AM Todo #765: Patch: Add custom DHCP configuration
- Hello,
I am aware that this Feature Request is 3 years old but I feel that the last comment by Jonathan Diete is t... -
05:40 AM Bug #2706 (Feedback): Padlock may need some adjustments for FreeBSD 10.x
- Applied in changeset pfsense-tools:commit:3b8d3adb58956d7415f52bcc81cfb1eca84e80b0.
-
03:05 AM Revision 7219bde6: include gettext locales in line encoding list
- portable object (.po) and portable object translation (.pot) files
Signed-off-by: Isaac (.ike) Levy <ike@blackskyres... -
03:05 AM Revision 2459a956: Cleanup- most languages simply need the ascii abreviation.
- Ful country code and encoding was necessary for pt_BR.ISO8859-1, (Brazilian Portuguese), and since it was the first t...
01/13/2014
-
11:14 AM Bug #3045: NTPD crash / doesn't come up
- I see a problem on my 2.1 64-bit system with NTPD that may be related to the issues reported here. Anytime the WAN i...
-
09:50 AM Bug #3045: NTPD crash / doesn't come up
- Fabio Giudici wrote:
> I did just a series of test, and the core dump of ntpd seems strictly related to the presence... - 08:56 AM Revision d2dd5794: updates to license.php
- 08:54 AM Revision c80f2b44: updates to license.php
01/12/2014
-
08:21 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
- And another one on the broken scrub: http://www.freebsd.org/cgi/query-pr.cgi?pr=172648
-
08:16 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
- Erm, guys, what's up with this?! Upstream apparently does NOT intend to fix this in any way, cf. http://www.freebsd.o...
01/11/2014
-
01:26 PM Feature #2358: NAT64 support
- UPVOTE. I really like to be able to run my network with IPv6 only and make legacy IPv4 site available through NAT64.
-
03:38 AM Bug #3045: NTPD crash / doesn't come up
- I did just a series of test, and the core dump of ntpd seems strictly related to the presence of the file /var/db/ntp...
01/10/2014
-
04:41 PM Revision 706ba0e4: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
-
04:41 PM Revision 3e146089: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
- 07:40 AM Revision c349f263: Merge pull request #884 from dotike/master
- Phase 1 ja_JA.UTF8 Translation
-
03:08 AM Feature #3393: AS filtering support in aliases
- An example of retrieving facebook ips from their AS number
[code]
whois -h whois.radb.net -- '-i origin AS32934' | ... -
03:06 AM Feature #3393 (Resolved): AS filtering support in aliases
- It would be nice to have an option to define a type of AS number in the aliasesand retrieve all the ips from the whoi...
-
01:38 AM Feature #3377: OAuth2 authentication in captive portal
- there will be publicly-available 2.2 snapshots in the not too distant future. At this point, I think you might be ok ...
01/09/2014
- 08:23 AM Revision 43656206: Should to go master, not RELENG_2_1. Revert "Merge pull request #882 from derelict-pf/cp-nohttpsforwards"
- This reverts commit f8d1587b6e2cd8441fa16733a02af25257fc7708, reversing
changes made to 51922cb793b83bf7d22fdaa47205f... - 08:18 AM Revision f8d1587b: Merge pull request #882 from derelict-pf/cp-nohttpsforwards
- Add checkbox and logic to disable forwarding HTTPS/SSL (Port 443)
-
04:42 AM Feature #3377: OAuth2 authentication in captive portal
- Here is a proof of concept, for a OAuth2 captive portal authentication with Google accounts :
https://github.com/... -
03:05 AM Revision fadfef2b: removing my fork README
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision e424ca74: bug address
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 93847971: Machine Translation (Phase 1) Complete.
- Next steps:
- generate the .mo files and try loading it up
- Japanese Native Speaker(s) sanity pass through
(roughl... -
03:05 AM Revision 04571fb6: Machine generation used Google Translate API, translate.google.com, and Mort Yao's goog le-translate-cli
- Wrapped some parsing around the following utility by Mort Yao,
https://github.com/soimort/google-translate-cli
Sig... -
03:05 AM Revision fe8747ed: first full machine run
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision a2e31d7d: workspot: great, but this process requires tedious re-running the program.
- Next step: wrap the translation step in a timeout, and print some simple hook in the output so you can find it for th...
-
03:05 AM Revision 5e269b45: workspot: cleanup and continued translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 20c5f316: X-Generator: vim(1), awk(1), sed(1) - for real.
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 7a716fa2: workspot: trying to speed up machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 21e23bc2: workspot: pass through to correct minor syntax
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
Signed-off-by: Kiyo Takami <foof@blackskyresearch.net> -
03:05 AM Revision 0cd6ed3b: workspot: mechincal first pass
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision f8c3f30d: workspot: continuing with machine translation, several heavily repeated phrases scrutinized
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 60644dad: workspot: plowing ahead with machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 5f01b774: workspot: continuing machine translation first pass
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision c7056c99: workspot: carp and interface bits, continued first pass machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 5d2b2df0: workspot: firewall, interfaces, still plowing through machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision fbf5a7d8: workspot: RADIUS and Captive Portal messages, machine translations
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision cd134df7: Temporary README for GitHub fork
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 2129ac6a: workspot: country names
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 826cfb5c: jp syntax change
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 8908eeed: workspot, continuing to run through with rough human-augmented machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 086689be: workspot, continuing to run through with rough human-augmented machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 25ae07d0: workspot- plowing through with rough human-augmented machine translation
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 002722b7: start by copying pt_BR locale
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 1023edb2: encoding change, and wrapping up LDAP sections rough pass
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:05 AM Revision 70d8b7b0: continued cumulative machine translations
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
02:52 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
- duplicate of #2859.
this isn't the place to ask questions, please take those to the forum or mailing list. -
02:50 AM Bug #3392: Allow to configure different mac addresses for multiple VLANs on same physical interface
- Feature #2859
how to do that coz i have just one nic and 4 VLANS configured on it, 2 WAN and 2 LAN -
02:48 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
- I had to beg to change the MAC of the provider.
Very important! I can make a few NIC VMware on, but I can not create...
01/08/2014
-
09:18 AM Feature #972: Allow adding gateways outside of interface subnet
- Hi Dan,
I felt in the same trouble, and I the idea I have found to survive reboot is using the ShellCmd package : ... -
07:41 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
- It works fine in a test VM here that never had Quagga, and also in a separate VM that had it previously and reinstall...
-
02:46 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
- Hello,
I have several pfSense firewalls, all having Quagga OSPF and running without issues.
They where installed ... -
05:28 AM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
- You mean you essentially created a cert chain yourself in the Certificate Authority Manager and then it worked?
01/07/2014
-
07:20 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- that's reasonable, submit that as a pull request in github and we'll get it merged.
-
04:15 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- You're still misunderstanding. If the initial connection by the user prior to CP authentication is to, say, https://...
-
02:19 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- Use a signed certificate on your CP!!!
-
10:37 AM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- I believe you are missing the point.
This enables administrators to utilize HTTPS CP authentication, which might b... -
05:05 AM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- Just do not configure https authentication!
-
04:39 PM Feature #3387: process_alias_urltable Frequency
- Ah never mind. I forgot about the ability to change the type on the fly...
-
04:12 PM Feature #3387: process_alias_urltable Frequency
- Shawn Bruce wrote:
> I have created a diff for firewall_aliases_edit.php against the latest git version. Would this ... -
04:11 PM Feature #3387: process_alias_urltable Frequency
- I have created a diff for firewall_aliases_edit.php against the latest git version. Would this be acceptable?
I am... -
04:12 AM Feature #3387: process_alias_urltable Frequency
- A code to upgrade current config to new format will be necessary too
-
03:59 PM Revision 33e72874: Merge pull request #880 from phil-davis/master
- Check for vertical bars in alias detail descriptions
- 03:05 PM Revision 7d14b000: Check for vertical bar at start or end of description
- 02:59 PM Revision 24445691: Check for vertical bars in alias detail descriptions
- The descriptions of each entry in an alias are stored in config.xml as a list delimited by "||". So you cannot have "...
- 10:58 AM Revision 51922cb7: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
- 10:58 AM Revision 6b660731: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
- 09:41 AM Revision 7c2ea0cc: Update reserved_keywords checks to match firewall_aliases_edit
- firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real... - 09:39 AM Revision fe56417f: Merge pull request #879 from phil-davis/master
- Update reserved_keywords checks to match firewall_aliases_edit
-
07:39 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
- It seems like maybe the authentication fallback that allows a person to login using local auth when their LDAP server...
-
04:59 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
- On pfSense 2.2 you will be able to revert GUI auth backend to Local Database on the same option you use to restore GU...
-
06:51 AM Bug #3389 (Resolved): GUI allows to configure ICMPv4 types for ICMPv6 firewall rules
- When I try to create a firewall rule that handles only certain types of IPv6 ICMP traffic, the interface lets me sele...
-
05:00 AM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
- Applied in changeset commit:51922cb793b83bf7d22fdaa47205fd59b4d70e87.
-
05:00 AM Bug #3384 (Feedback): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
- Applied in changeset commit:6b6607316481aacaa055f8e4bce2ce1e520d3b1b.
01/06/2014
-
05:09 PM Revision 4410f699: This might also say "icmpv6" here and lead to a bad rule.
-
05:08 PM Revision 0959b4d3: This might also say "icmpv6" here and lead to a bad rule.
-
04:48 PM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
- Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/e98daec5960b7ecdd18bc461003df3a18d2adbe7 -
04:45 PM Bug #3340: Captive Portal deletes concurrent sessions even if noconcurrentlogins is not set
- Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/ae6c69833f34d8f14b1c6a9508126905328340bc -
04:42 PM Bug #3124: portal_reply_page called twice in specific circumstance
- Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/4fd56afe541a0a350dfe52b20521a551edd9f276 - 04:11 PM Revision 81f19476: Add an option to force a gateway to be down, it fixes #2847
- 03:02 PM Revision de3987e5: Update reserved_keywords checks to match firewall_aliases_edit
- firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real... -
02:35 PM Revision 30e2adbc: Merge pull request #871 from phildd/master
- Dynamic DNS: List GWGs in Interface to send update from
-
11:35 AM Feature #3387 (New): process_alias_urltable Frequency
- Currently the urltable design only allows for updates on a daily interval and is processed via crontab every 12 hours...
-
10:10 AM Feature #2847 (Feedback): Add a checkbox to flag a gateway as "down"
- Applied in changeset commit:81f1947666ebbe19f1f6579a1e5293c42c6d1c04.
-
09:13 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
-
07:31 AM Revision 7ad4b9b7: Merge pull request #878 from phil-davis/master
- Bulk Import: fix copy-paste var name error
- 02:43 AM Revision 3b4e6952: Bulk Import: fix copy-paste var name error
01/05/2014
-
11:18 AM Revision b760fd31: Merge pull request #877 from phil-davis/master
- Allow individual line descriptions on alias bulk import
- 09:35 AM Revision 8c470066: Allow individual line descriptions on alias bulk import
- This enhancement allows the user to make a text file of IP addresses, IP subnets and/or IP ranges, like they have alw...
-
08:54 AM Bug #3386: apinger not picking up 2nd OpenVPN tunnel
- I did another reboot and now it worked. You can close this issue (did not find button to close it myself).
-
08:48 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
- When adding a 2nd OpenVPN tunnel (client side, shared key static setup) and the corresponding Interface and Gateway i...
01/04/2014
-
10:32 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
- After I posted the above, I have a new idea.
I just copied the Root CA certificate to the Intermediate CA's certif... -
10:18 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
- I am hit with the same bug.
Also, if you set the Peer Certificate Authority to the Root CA, 2 things happen:
1.... -
02:49 PM Feature #3385: Accommodate static routes for PPTP connections
- correction :
When the VPN reconnects, the static route is not reinstated and must be re-instated to bring the rou... -
02:47 PM Feature #3385 (Closed): Accommodate static routes for PPTP connections
- Creating a static route on the pfSense box allows routing from the 10.20.2.0 network back across the (pptp) vpn to th...
-
07:00 AM Bug #3384 (Resolved): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
- ntp.conf(5):
limited
Deny service if the packet spacing violates the lower limits specified
in ... -
04:29 AM Bug #3383 (Resolved): Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
- Hy,
This one have been difficult to find.
I set up a ldap server in user manager through the web gui. Everything ...
01/03/2014
-
10:00 PM Revision f05bf59b: Merge pull request #875 from dotike/spellcheck
- minor spelling correction for pfSense master branch
-
09:41 PM Revision 41681aa6: minor spelling correction for pfSense master branch
- Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
-
03:56 PM Revision 4e6405b9: Oops correct php syntax
-
03:38 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
- I've also run into this problem. I didn't want it to get so buried in the pile that it never got looked at again.
-
03:05 PM Revision 21f82ab6: Do not allocate the same pipe to everyone rather give each person its own!
-
03:05 PM Revision 762b34c4: Do not allocate the same pipe to everyone rather give each person its own!
-
02:53 PM Revision f38b383b: Use empty here for testing even if the setting is unset
-
02:52 PM Revision c8d611ed: Use empty here for testing even if the setting is unset
-
01:24 PM Revision a3a1b24e: Move to zerocopy_enbale for bpf to optimize bpf logging which uses bpf interface. This should increase the general performance since pflog is always enabled.
-
11:21 AM Bug #3382 (New): IGMPPROXY fails with more than 32 interfaces
- Hi,
I have a problem with the igmpproxy:
I am using pfSense in an enviroment of round about 120 users, and every ... - 08:33 AM Revision 723f0ac9: Merge pull request #873 from tuyan/patch/copyright_years
- Update product_copyright_years end to be calculated on the fly.
01/02/2014
-
09:54 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
- Further to this, the " Borrow from other queues when available" doesn't work when you go 1 level deeper than the root...
-
08:25 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
- FYI - The WAN interface seems to be 100% correct all the time.
-
08:25 PM Bug #3381 (Resolved): LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
- LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues. This looks to b...
- 03:57 PM Revision 2bb93345: Update copyright_years to be calculated on the fly.
-
03:25 PM pfSense Packages Bug #3380 (Not a Bug): FreeRadius-User-Option "Expiration Date" kills the FreeRadius-Server
- Hi,
after adding an User-Expiration-Option to an user of FreeRadius Service, radius tries to restart but breaks:
... - 11:58 AM Revision 8f56dd27: DyndDNS edit: unset vars when no longer used
- 11:13 AM Revision 0350084d: fix syntax
- 10:41 AM Revision 2a45e05f: Fix filter regex
- 09:20 AM Revision 52311f0c: Merge pull request #870 from blagynchy/patch-1
- Happy New Year 2014!
01/01/2014
-
11:54 PM Revision 9dc3f2bb: Happy New Year 2014!
- Optimal: Just updating the copyright years;
I wish to all of you all of health, happiness and good luck of earth to ...
12/31/2013
-
12:28 PM Revision 31dce430: Upgrade all firewall rules to include a tracker field. Add a tracker field even for nat for later usage while here.
-
12:23 PM Revision 2006d7a4: Generate a tracker id for the filter rules for now. Maybe for nat rules as well?
-
09:52 AM Feature #3377: OAuth2 authentication in captive portal
- Sure go ahead.
-
04:56 AM Feature #3377 (New): OAuth2 authentication in captive portal
- In Captive Portal we have native, ldap and radius authentication. Today, a lot of authentication systems provide OAut...
12/30/2013
-
04:14 PM Revision ba1c86d9: Remove scrub as well
- 03:45 PM Revision 31300a95: List GWGs in Interface to send update from
-
03:27 PM Revision 32fd1703: Remove even negating nat rules
-
02:47 PM Revision a03dfc60: Correct matching for single rule. Somehow the egrep did not work there!
-
02:34 PM Revision b80e29e4: Speed up a bit rule number identification by avoiding going into kernel but using the rules parsing of pf which gives the same effect.
- 11:56 AM Revision 239024ee: Merge pull request #866 from andrespetralli/master
- Enabling advanced RFC 2136 configuration for DHCPd service
- 09:23 AM Revision 44b72c67: Fix display of CIDR/Update Freq in Alias Edit
- Fixes #3376. I have no idea what the "^" characters were meant to do, but removing them makes the CIDR/Update Freq va...
- 09:23 AM Revision d564ed24: Validate IP address ranges correctly on Alias Bulk Import
- The code was there to attempt to validate and implement IP address range lines in Alias Bulk Import e.g.
10.20.0.0-10... -
08:07 AM Revision 737f26e9: Merge pull request #868 from phildd/master
- Validate IP address ranges correctly on Alias Bulk Import
-
08:06 AM Revision ef1c9f09: Merge pull request #867 from phil-davis/master
- Fix display of CIDR/Update Freq in Alias Edit
-
03:30 AM Bug #3376: Alias Edit does not display correctly
- Applied in changeset commit:44b72c67ec3331ecd3a6430697ad47dbeac7c450.
-
02:10 AM Bug #3376 (Feedback): Alias Edit does not display correctly
- Applied in changeset commit:1b9ab14ad23e1f66a11801fbe7a24423ab8529a0.
12/29/2013
- 04:05 PM Revision 54e81df0: Validate IP address ranges correctly on Alias Bulk Import
- The code was there to attempt to validate and implement IP address range lines in Alias Bulk Import e.g.
10.20.0.0-10... - 02:12 PM Revision 1b9ab14a: Fix display of CIDR/Update Freq in Alias Edit
- Fixes #3376. I have no idea what the "^" characters were meant to do, but removing them makes the CIDR/Update Freq va...
-
08:13 AM Bug #3376: Alias Edit does not display correctly
- I have no idea what I am doing with the jQuery stuff, but I pulled out some "^" marks in pull request https://github....
-
07:54 AM Bug #3376 (Resolved): Alias Edit does not display correctly
- I had a 2.1-RELEASE system and GitSync'd to the 2.1 release branch. I was using Alias Bulk Import, but then also real...
12/27/2013
-
09:51 PM Revision 5a890490: Modernize a bit the sshd sart file
-
09:38 PM Revision 9be0ec8a: Use the check properly!
-
09:35 PM Revision 635c00d3: Correct the check to what was intended
-
09:34 PM Revision d68494e6: Correct the check to what was intended
-
08:50 PM Revision 57b02731: Remove not needed code
-
08:49 PM Revision f6d89471: Make sense of interface mtu handling code. No need to do unneeded operations. This fixes slow boot times and proper handling of mtu for vlans though some work or better model is needed for other interface types. Manual merge of 53555bf2f796cd53cf649410fe1827a9a45fc4a7
-
08:37 PM Revision 53555bf2: Make sense of interface mtu handling code. No need to do unneeded operations. This fixes slow boot times and proper handling of mtu for vlans though some work or better model is needed for other interface types.
-
06:10 PM Revision aaa78416: Add sshd service to list (if enabled)
- 02:58 PM Revision 1a4ef44e: Delete static route when monitor IP is removed, also save monitor IP even when it's disabled
- 02:58 PM Revision 14be28af: No reason to set the same value to ipprotocol
- 02:12 PM Revision fcd01c8a: Delete static route when monitor IP is removed, also save monitor IP even when it's disabled
- 02:02 PM Revision ee574a9e: Fix a bug introduced in commit 06b8d43c that breaks return_gateways_array() called with $disabled == false
- 01:55 PM Revision 63fee576: No reason to set the same value to ipprotocol
-
09:11 AM Bug #2514: static routes for monitor IPs should be removed
- There was an attempt to remove it in the past but seems it had side-effects (see ticket #3179 and commit:32a9eb1873)....
-
05:05 AM pfSense Packages Bug #3375 (Closed): BIND, ACLs: Incorrect code is being generated for empty range ACL.
- BIND 9.9.4 pkg v 0.3.2;
Steps to reproduce:
1. Create an ACL "Test";
2. Follow the advise and leave "Enter IP ..... -
04:58 AM Bug #3374: Firewall logs shows incorrect rules
- I see. Pretty understandable reason.
Basically speaking, if my pfsense box will go berserk with "reload fw filter"... - 03:22 AM Revision ffe6f371: fix typo
-
02:06 AM Bug #3353: Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
- This is probably related to an issue fixed in head of pf and probably the MFC is missed.
Not related to the previous...
12/26/2013
-
09:52 PM Revision 2aff8089: Fix wording/spacing
-
09:41 PM Revision 5c427ce7: Add support for local (push route) and remote (iroute) network definitions in an OpenVPN client-specific override entry.
-
09:11 PM Revision 9bc68540: Make this box a little narrow so it doesn't force the descriptions to wrap.
-
08:54 PM Revision 141254eb: Use empty even here
-
08:47 PM Revision 7cbfc265: Add a "status" subcommand to the svc php shell script.
-
08:28 PM Revision fed1b372: Check if there is a value before trying to do any operation
-
08:27 PM Revision c7a3356e: Add a setting to allow the user to specify the clog file size so more (or less) entries may be kept in the raw logs. Retain previous default size values if the user has not specified a preferred size. Files can only be resized when initialized, so provide a "Reset All Logs" button as well to force clear all logs and set them up at the new size.
-
07:27 PM Revision 7b03748b: Correct the php-fpm configuration generation
- 06:10 PM Revision 3f248cb6: Fix #3354, savecore -C only expects dumpdev
-
05:53 PM Revision e1ebe9e2: Add an option for users to be able to adjust how many configuration revisions are kept in the local backup cache.
-
04:07 PM Revision bfe615ee: Show backup file size in config history.
-
03:51 PM Revision 57671f81: Fix syntax, unbreak dashboard
-
03:45 PM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
- Same problem here with pfsense 2.1 and cisco router with IOS 12.4(15)T15 as remote endpoint.
IPSEC tunnel doesn't co... -
12:11 PM Bug #3353 (New): Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
- This still happens on a current build.
-
12:10 PM Bug #3354 (Feedback): Savecore error during bootup
- Applied in changeset commit:3f248cb65a25189f7cff8f6ad4321998caaab073.
Also available in: Atom