Project

General

Profile

Activity

From 12/30/2013 to 01/28/2014

01/28/2014

07:01 PM Revision 82482a69: Fix typo on variable name, it fixes #3414
Renato Botelho
07:01 PM Revision f4a4bcbc: Fix typo on variable name, it fixes #3414
Renato Botelho
01:00 PM Bug #3414: system.inc variable wrong
Applied in changeset commit:82482a6937d5c75795aa6df3a0c416e3e6a9a3af. Renato Botelho
01:00 PM Bug #3414 (Feedback): system.inc variable wrong
Applied in changeset commit:f4a4bcbc4c45943bbd4734251a145f297a0502d9. Renato Botelho
12:53 PM Bug #3414 (Resolved): system.inc variable wrong
/etc/inc/system.inc
@function get_searchdomains() {
global $config, $g;

$master_list = array();

// Rea...
Sezgin SERPEN
09:49 AM Feature #3413: CARP interface names in WebGUI
Looks okay to me.
But I wonder, is there a reason to have "opt1_vip6" visible at all in the WebGUI, when you have ...
Trond Vindenes
03:16 AM Feature #3413: CARP interface names in WebGUI
This is a simple change. I think the best way to address this is under the CARP Interface column, have something like... Chris Buechler
09:37 AM Revision f70adc82: Really fix #3376
Thanks to Grischa Zengel for spotting the semi-colon at the end of the "if" line that was the real cause. Please als... Phil Davis
09:36 AM Revision f71b440b: Merge pull request #896 from phil-davis/master
Really fix #3376 Alias Edit does not display correctly Renato Botelho
07:01 AM Bug #742: apinger doesn't recover opt wan when connection returns.
I can confirm this problem. This bug should be reopened.
System:
2.1-RELEASE (i386)
built on Wed Sep 11 18:16:44...
Daniel Bernhardt
06:49 AM Revision 93dcedc1: XHTML Compliance - Status: System logs: Firewall
An attribute value specification must be an attribute value literal unless SHORTTAG YES is specified
Quote (or escape...
N0YB
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:f70adc82457c038159b4f8edd775bcf1cc498d03. Phillip Davis
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:f71b440bf16ec3cd8164325f287d8c93b5dfd476. Anonymous
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:4dd00d25d5fc3d5a0b73930cf86685d4c1430a2e. Phillip Davis
03:24 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
looks like kernel panic caused by concurrency in ixgbe driver. i found some patches in freebsd list: http://article.g... Zeev Zalessky
03:04 AM Revision 4dd00d25: Really fix #3376
Thanks to Grischa Zengel for spotting the semi-colon at the end of the "if" line that was the real cause. Please als... Phil Davis

01/27/2014

09:03 PM Bug #3376: Alias Edit does not display correctly
Thanks for spotting that semi-colon - I spent a while trying to work out what going on, and obviously didn't stare ha... Phillip Davis
05:14 PM Bug #3376: Alias Edit does not display correctly
The error is the semicolon after
if (set_value == true);
Grischa Zengel
05:03 PM Bug #3376: Alias Edit does not display correctly
With this patch the subnet field won't be disabled like before.
The form uses <select name="address_subnet0" class="...
Grischa Zengel
07:03 PM Revision 886926e0: Merge pull request #895 from N0YB/RELENG_2_1
Also make the dialog_output query string option XHTML compliant. Jim Pingle
06:59 PM Revision 4efc1c8d: Also make the dialog_output query string option XHTML compliant.
N0YB
06:58 PM Revision a43bdc39: Merge pull request #894 from N0YB/RELENG_2_1
Make select option XHTML compliant for "Number of lines to display". Jim Pingle
06:45 PM Revision df5501dc: Make select option XHTML compliant for "Number of lines to display".
http://validator.w3.org/check
"SELECTED" is not a member of a group specified for any attribute
<option value="7" SEL...
N0YB
05:15 PM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
hi,
i test now firewall on my production load.
MBUFs raze detected on heavy arp load, i have more then 3000 serv...
Zeev Zalessky
04:51 PM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
Hi guys,
If there is anything I can test to help, please let me know.
I can confirm that use case (1) is no lon...
Brenton Denman
03:18 PM Feature #3413 (Resolved): CARP interface names in WebGUI
As mentioned on the forum: https://forum.pfsense.org/index.php/topic,71587.0.html
When you have a lot of CARP inte...
Trond Vindenes
10:10 AM Revision 2704796a: Merge pull request #893 from N0YB/RELENG_2_1
The service status icon is not always in a table. Renato Botelho
08:24 AM pfSense Packages Bug #3400: apcupsd service config does not allow DEVICE to be set
Unfortunately not for all types you need UPSTYPE and DEVICE.
For example with pcnet, all config needs to be on UPSTY...
Danilo Baio
06:53 AM Revision 30469c9b: Missing a couple table element end tags.
N0YB
05:58 AM Revision cd6173f4: The service status icon (get_service_status_icon) is not always in a table.
So the caller should apply table td element, rather than the function.
Document type does not allow element "td" her...
N0YB

01/26/2014

07:00 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
Pull request added: https://github.com/pfsense/pfsense/pull/892 Daniel Hazelbaker

01/25/2014

08:49 PM Revision ec5c28cd: Gateway Monitor Advanced Settings
Recommended changes made to calculated value input behavior.
Restrict interval to integer of 1 or greater.
N0YB
08:06 PM Revision 452eb31e: captive portal, don't generate rules for disabled portal
Pi Ba
06:26 PM Revision fbdd0466: Obsolete openssl from ports files and also base nsupdate
Renato Botelho
04:56 PM Revision 22cc6582: Fix nsupdate path
Renato Botelho
12:15 PM Todo #3399 (Feedback): Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS
Added bind99 nsupdate to the builds Renato Botelho
06:28 AM Revision 3c6787ed: Gateway Monitor Advanced Settings
Exposes 3 additional apinger configuration options in the gateway monitor advanced section which can either be set ma... N0YB
01:33 AM Revision c241a3e8: Merge pull request #888 from PiBa-NL/pkg-utils-append-log
pkg-utils do not clear first part of installation log. Renato Botelho

01/24/2014

11:14 PM Revision 206c15cc: pkg-utils do not clear first part of installation log.
Pi Ba
10:33 AM Revision 2ec95f1f: Fix openssl path
Renato Botelho
08:27 AM Bug #3412 (Resolved): serial console output mess on fetch bogons failure
Tried to upgrade from a previous 2.1.1 snapshot to Thu Jan 23 17:15:05 EST 2014 snapshot on nanobsd x86. All went wel... Doktor Notor
08:07 AM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
Thanks for the help Ermal. When I try to bounce dhcpd in the rc.newwanip script, I run into a problem where it appea... Jason Crowley
06:36 AM Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
Parameter ends up being weird because openvpn is running with IPV4 and IPV6 not. I think this parameter tun-ipv6 can ... Gilmar Cabral
06:29 AM Bug #3402: Bug Interface Virtual Openvpn Route
Utilization of this type of setting and implementing the shapper trafic in openvpn tunnel individually Gilmar Cabral
06:26 AM Bug #3402: Bug Interface Virtual Openvpn Route
Gilmar Cabral wrote:
> Related bug when and ovpns created virtual interface gateway ipv4 ipv4 and ipv6 route creates...
Gilmar Cabral
02:09 AM Bug #3411 (New): Interfaces and statistics dashboard widgets very slow with large numbers of interfaces
The interfaces and statistics dashboard widgets cause the dashboard to take minutes to load where a system has a larg... Chris Buechler

01/23/2014

11:33 PM Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
it doesn't hurt anything, but yeah that should likely only be there if the VPN is using IPv6. Chris Buechler
11:31 PM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
no idea what you're referring to, routes that OpenVPN creates are those you tell it to, and that all works as it shou... Chris Buechler
11:28 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
duplicate of #2952, we'll keep it on that one. Chris Buechler
11:23 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
could you please submit a pull request on github to master? Chris Buechler
09:29 PM Feature #3410 (Resolved): Patch: Add Apple Open Directory memberUid support in group lookup
This is a patch that adds compatibility to do memberUid style lookups used in Apple's Open Directory. Specifically, w... Daniel Hazelbaker
05:43 PM Bug #3408: IPV6 DHCP not disabling on initial setup
This is what was entered in the config on a fresh install of 2.1 not 2.1.1.
It seems to automatically enter the rang...
Matthew Hoberg
04:15 AM Bug #3408: IPV6 DHCP not disabling on initial setup
I could not reproduce it on a recent 2.1.1 snapshot. I'm wondering how could it put a range on dhcpv6 if you don't ch... Renato Botelho
12:05 PM Revision 8467c588: Do not list the same CARP ip as an option for Interface
Renato Botelho
10:19 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
That's not something I can duplicate under 2.1 or 2.1.1 built on "Wed Jan 22 04:46:20 EST 2014".
If I change a CAR...
Jason Litka
05:49 AM Bug #3407 (Feedback): Changing CARP IP to IP Alias doesn't work until failover is trigered
As you mentioned, when moved from CARP (WAN) to an IP alias (using other CARP IP as interface), the IP stops answerin... Renato Botelho
04:34 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
I reproduced it here, will work on a fix. Renato Botelho
02:52 AM Bug #3409 (Closed): IPv6 gif tunnel not working after reboot on PPPoE
I have an Alix box with with WAN connected via VDSL PPPoE link and HE IPv6 tunnel configured here. With 2.1.1 pre-rel... Doktor Notor
02:15 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
getting stuck on reboot with active 3g dongle is getting a serious issue for me, i have tried 3 different 3g dongles ... Bipin Chandra
01:02 AM pfSense Packages Bug #3203: vnstat2 not working after pfsense 2.1 upgrade
Hi,
This is still broken in 2.1.1 Pre-Release
Beginning package installation for vnstat2 .
Downloading package...
Kyle Janse van Rensburg

01/22/2014

07:40 PM Bug #3408 (Closed): IPV6 DHCP not disabling on initial setup
Installing fresh copy of v2.1 with 1 WAN and 1 LAN adapter. Install to hard drive and after rebooting during initial ... Matthew Hoberg
06:31 PM Bug #2952: Unvalidated input during system_firmware_check.php
While I'm a big fan of the updates going over HTTPS for transport security, I would say that this is a different issu... Ian Gallagher
04:29 PM Bug #2952: Unvalidated input during system_firmware_check.php
Netgate Pfsense images 2.1p1 and higher upgrade over HTTPS, making this attack more difficult. Jeremy Porter
02:06 PM Bug #2952: Unvalidated input during system_firmware_check.php
Verified to still be present and exploitable in 2.1p1-RELEASE/nanobsd 4g (Netgate image), by replacing the reported ... Ian Gallagher
01:26 PM Bug #2952: Unvalidated input during system_firmware_check.php
Hi,
I'd like to bring this issue up again, and increase it's priority to critical or high, as I have verified the ...
Ian Gallagher
05:12 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
The config in the UI looks correct on both the master and the backup (listed as IP Alias in Virtual IPs screen, disap... Jason Litka
04:22 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
you mean on the secondary, the primary, or both? What does ifconfig look like on both systems afterwards? Chris Buechler
03:11 PM Bug #3407 (Resolved): Changing CARP IP to IP Alias doesn't work until failover is trigered
If you change an existing CARP IP Address to an IP Alias it does not work, even after hitting apply. Instead, you ne... Jason Litka
03:07 PM Feature #3406 (Needs Patch): Change Virtual IP & CARP Status screens to a tree view
For those of us that have dozens or more Virtual IPs, it would be helpful to see an alternative view that shows how a... Jason Litka
02:30 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
Please read my comment on the proper solution.
This is a workaround/hack for your local installation.
Ermal Luçi
12:43 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
I have attached a patch file for /etc/inc/services.inc
This will have the services_dhcpd_configure() function chec...
Micah Mitchell
10:46 AM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
The proper solution for this is to bounce the dhcpd when the openvpn link comes up.
Check rc.newwanip[v6] script on ...
Ermal Luçi
10:12 AM Bug #3404 (New): DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
When the services_dhcpd_configure() function is called during boot, it will skip interfaces that are not fully online... Jason Crowley
02:22 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
Filing this as a new bug so it doesn't fall under the cracks - the unvalidated input bug in #2952 has been verified t... Ian Gallagher
12:32 PM pfSense Packages Bug #3248 (Resolved): NUT package fails to write config to upsd.users
Thanks Renato Botelho
12:17 PM pfSense Packages Bug #3248: NUT package fails to write config to upsd.users
I've been running this patch for over 3 months without issue. For what it's worth, I've also tested against current 2... Denny Page
09:23 AM Feature #1557: Add the Interface descriptions to the OS interface descriptions
Hi Developers of pfSense.
Is there any status update of this Feature?
2 Years ago the Target version was deleted.
...
Peter Baumann

01/21/2014

06:49 PM Revision 54597012: Replace regex by explode as suggested by Ermal
Renato Botelho
06:40 PM Revision 505d5c7a: Fix typo on variable name
Renato Botelho
06:38 PM Revision 613a94b3: Fix typo on variable name
Renato Botelho
02:58 PM Bug #3147: Adding new interface can cause issues
https://forum.pfsense.org/index.php/topic,64704.0.html
As far as I'm concerned, it's a bug. Because I have not hi...
Chris Thomas
12:38 PM Revision 43045948: Revert "Fix #3350. Do not destroy an interface when it's being disabled"
Ermal reported issues when changes are made on VLAN parent interface
with this patch. He did other changes and interf...
Renato Botelho
12:36 PM Revision d9797fd6: Revert "Fix #3350. Do not destroy an interface when it's being disabled"
Ermal reported issues when changes are made on VLAN parent interface
with this patch. He did other changes and interf...
Renato Botelho
10:13 AM Bug #3242 (Resolved): editing alias url table doesnt show full link
Jim Pingle
10:12 AM Bug #3242: editing alias url table doesnt show full link
plz mark this as resolved Bipin Chandra
09:43 AM Bug #3345: Openvpn create route ipv6 default Pfsense 2.1
Chris Buechler wrote:
> OpenVPN creates whatever routes it's configured to create (or that it pulls if pulling is en...
Gilmar Cabral
09:26 AM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
Related bug when and ovpns created virtual interface gateway ipv4 ipv4 and ipv6 route creates automaticament. This bu... Gilmar Cabral
09:24 AM Bug #3401 (Resolved): Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
I think using ipv4 in the openvpn conf should not generate the attribute tun-ipv6 attribute and not load the ipv6 mod... Gilmar Cabral
03:31 AM Bug #3350: Disabling and enabling VLAN leaves VLAN interface missing
It would be better to revert this commit now that interface_cofnigure does the right job at detecting if an interface... Ermal Luçi
12:13 AM pfSense Packages Bug #3400 (Resolved): apcupsd service config does not allow DEVICE to be set
When configuring the apcupsd service using pfsense, only the UPSTYPE setting can be changed using the gui but not the... D B

01/20/2014

07:42 PM pfSense Packages Bug #2992: Boot problem after upgrade
This happened to me today. It happened on a fresh install with only bandwidthd and openvpn installed, after I changed... Eric Green
06:59 PM Revision b4d772dc: Correct this i thought i already did. Thanks-to: Phil Davis for spotting
Ermal Luçi
03:09 PM Revision d760445e: Do not need to go in the internet world to start a package
Ermal LUÇI
03:00 PM Revision 44b19298: * Do not call stop service in the start command.
* Add some more checks into the functions to avoid errors
* Also silence some output that can cause issues
Ermal LUÇI
12:53 PM Revision 770a7759: Fix FreeBSD version detection for 10.x
Renato Botelho
11:36 AM Revision aefc6bc2: Obsolete old ntp binaries
Renato Botelho
11:35 AM Revision c42d721b: Obsolete old ntp binaries
Renato Botelho
07:25 AM Todo #3399 (Resolved): Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS
Due to FreeBSD 10.x changes, nsupdate is no longer available for inclusion from base. We will need to use a replaceme... Jim Pingle
03:36 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
Firewall is updated to 2.1.1-PRERELEASE (amd64) built on Sun Jan 19 03:33:57 EST 2014. After boot MBUF status is 32% ... Zeev Zalessky

01/19/2014

01:13 AM Bug #3321 (Resolved): IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
thanks for the confirmation Chris Buechler
12:36 AM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
This problem has been fixed in 2.1.1-PRERELEASE! :) Christian Borchert

01/17/2014

04:46 AM Feature #3398 (Needs Patch): Notifications - information about errors
I test the pfsense on HP DL360 G5
CPU: Intel(R) Xeon(R) E5410
Ram: 8GB
Disk controller: P400i (RAID5 4x hdd)
Wh...
Przemysław W
02:50 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
i got the same situation as well as with the 3g stick connected if i reboot pfsense then it would just get stuck when... Bipin Chandra

01/16/2014

02:13 PM Revision 93a79543: Bump version
Jim Pingle
01:30 PM Revision 254df317: Merge pull request #887 from brunostein/tracker_firewall_rule
added input hidden with tracker value Ermal Luçi
12:31 PM Revision 72b774aa: added input hidden with tracker value
Bruno Ferri
02:28 AM Bug #3397 (Needs Patch): Cannot load builtin or external firmware for mwl driver
Hello,
I've tried to get a marvell wireless card to work a long time before posting this.
Here's the output of pf...
Orsiris de Jong

01/15/2014

05:35 PM Revision fdfa8f43: ports ntp moved to sbin, follow
Jim Pingle
05:28 PM Revision 3d54553b: ports ntp moved to sbin, follow
Jim Pingle

01/14/2014

11:34 PM Revision 096f73b4: Merge pull request #886 from dotike/master
locale path name clarification Renato Botelho
09:15 PM Todo #3396 (Resolved): Replace dnsmasq with Unbound
The replacement of dnsmasq with unbound needs to be completed for 2.2.
Chris Buechler
08:40 PM Bug #3214 (Rejected): bogons/bogonsv6 include stupid things
#3395 addresses the only problem here. none of that impacts DHCP4 clients. Chris Buechler
08:39 PM Bug #3395 (Resolved): DHCPv6 client pass rules need to come before bogons
8000::/1 is included in Cymru's v6 bogons list. That's sane, since it shouldn't be in the Internet routing table, but... Chris Buechler
08:17 PM Bug #3394: radvd wrongly binds to *:546 in some circumstances
I'll provide further details privately to the person working on the issue, it's on a customer system and not somethin... Chris Buechler
08:16 PM Bug #3394 (Resolved): radvd wrongly binds to *:546 in some circumstances
I can't seem to determine why, as different systems with seemingly identical radvd.conf files don't consistently disp... Chris Buechler
07:34 AM Bug #3045: NTPD crash / doesn't come up
simply one line contining:
-0.056
(or other numbers)
Fabio Giudici
04:03 AM Bug #3045: NTPD crash / doesn't come up
Fabio Giudici wrote:
> Good morning
> Just one more question: is it ntpd running in jail/chroot?
>
> Just to ...
Renato Botelho
01:01 AM Bug #3045: NTPD crash / doesn't come up
Good morning
Just one more question: is it ntpd running in jail/chroot?
Just to restrict the issue...but it se...
Fabio Giudici
07:10 AM Todo #765: Patch: Add custom DHCP configuration
Hello,
I am aware that this Feature Request is 3 years old but I feel that the last comment by Jonathan Diete is t...
Florent Poinsaut
05:40 AM Bug #2706 (Feedback): Padlock may need some adjustments for FreeBSD 10.x
Applied in changeset pfsense-tools:commit:3b8d3adb58956d7415f52bcc81cfb1eca84e80b0. Renato Botelho
03:05 AM Revision 7219bde6: include gettext locales in line encoding list
portable object (.po) and portable object translation (.pot) files
Signed-off-by: Isaac (.ike) Levy <ike@blackskyres...
Isaac (.ike) Levy
03:05 AM Revision 2459a956: Cleanup- most languages simply need the ascii abreviation.
Ful country code and encoding was necessary for pt_BR.ISO8859-1, (Brazilian Portuguese), and since it was the first t... Isaac (.ike) Levy

01/13/2014

11:14 AM Bug #3045: NTPD crash / doesn't come up
I see a problem on my 2.1 64-bit system with NTPD that may be related to the issues reported here. Anytime the WAN i... Bill Meeks
09:50 AM Bug #3045: NTPD crash / doesn't come up
Fabio Giudici wrote:
> I did just a series of test, and the core dump of ntpd seems strictly related to the presence...
Renato Botelho
08:56 AM Revision d2dd5794: updates to license.php
Chris Buechler
08:54 AM Revision c80f2b44: updates to license.php
Chris Buechler

01/12/2014

08:21 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
And another one on the broken scrub: http://www.freebsd.org/cgi/query-pr.cgi?pr=172648 Doktor Notor
08:16 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
Erm, guys, what's up with this?! Upstream apparently does NOT intend to fix this in any way, cf. http://www.freebsd.o... Doktor Notor

01/11/2014

01:26 PM Feature #2358: NAT64 support
UPVOTE. I really like to be able to run my network with IPv6 only and make legacy IPv4 site available through NAT64. Andreas Peetz
03:38 AM Bug #3045: NTPD crash / doesn't come up
I did just a series of test, and the core dump of ntpd seems strictly related to the presence of the file /var/db/ntp... Fabio Giudici

01/10/2014

04:41 PM Revision 706ba0e4: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
Jim Pingle
04:41 PM Revision 3e146089: Use "disable monitor" in NTP config to mitigate CVE-2013-5211.
Jim Pingle
07:40 AM Revision c349f263: Merge pull request #884 from dotike/master
Phase 1 ja_JA.UTF8 Translation Chris Buechler
03:08 AM Feature #3393: AS filtering support in aliases
An example of retrieving facebook ips from their AS number
[code]
whois -h whois.radb.net -- '-i origin AS32934' | ...
Ermal Luçi
03:06 AM Feature #3393 (Resolved): AS filtering support in aliases
It would be nice to have an option to define a type of AS number in the aliasesand retrieve all the ips from the whoi... Ermal Luçi
01:38 AM Feature #3377: OAuth2 authentication in captive portal
there will be publicly-available 2.2 snapshots in the not too distant future. At this point, I think you might be ok ... Chris Buechler

01/09/2014

08:23 AM Revision 43656206: Should to go master, not RELENG_2_1. Revert "Merge pull request #882 from derelict-pf/cp-nohttpsforwards"
This reverts commit f8d1587b6e2cd8441fa16733a02af25257fc7708, reversing
changes made to 51922cb793b83bf7d22fdaa47205f...
Chris Buechler
08:18 AM Revision f8d1587b: Merge pull request #882 from derelict-pf/cp-nohttpsforwards
Add checkbox and logic to disable forwarding HTTPS/SSL (Port 443) Chris Buechler
04:42 AM Feature #3377: OAuth2 authentication in captive portal
Here is a proof of concept, for a OAuth2 captive portal authentication with Google accounts :
https://github.com/...
Thomas NOEL
03:05 AM Revision fadfef2b: removing my fork README
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision e424ca74: bug address
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 93847971: Machine Translation (Phase 1) Complete.
Next steps:
- generate the .mo files and try loading it up
- Japanese Native Speaker(s) sanity pass through
(roughl...
Isaac (.ike) Levy
03:05 AM Revision 04571fb6: Machine generation used Google Translate API, translate.google.com, and Mort Yao's goog le-translate-cli
Wrapped some parsing around the following utility by Mort Yao,
https://github.com/soimort/google-translate-cli
Sig...
Isaac (.ike) Levy
03:05 AM Revision fe8747ed: first full machine run
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision a2e31d7d: workspot: great, but this process requires tedious re-running the program.
Next step: wrap the translation step in a timeout, and print some simple hook in the output so you can find it for th... Isaac (.ike) Levy
03:05 AM Revision 5e269b45: workspot: cleanup and continued translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 20c5f316: X-Generator: vim(1), awk(1), sed(1) - for real.
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 7a716fa2: workspot: trying to speed up machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 21e23bc2: workspot: pass through to correct minor syntax
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net>
Signed-off-by: Kiyo Takami <foof@blackskyresearch.net>
Isaac (.ike) Levy
03:05 AM Revision 0cd6ed3b: workspot: mechincal first pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision f8c3f30d: workspot: continuing with machine translation, several heavily repeated phrases scrutinized
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 60644dad: workspot: plowing ahead with machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 5f01b774: workspot: continuing machine translation first pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision c7056c99: workspot: carp and interface bits, continued first pass machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 5d2b2df0: workspot: firewall, interfaces, still plowing through machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision fbf5a7d8: workspot: RADIUS and Captive Portal messages, machine translations
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision cd134df7: Temporary README for GitHub fork
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 2129ac6a: workspot: country names
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 826cfb5c: jp syntax change
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 8908eeed: workspot, continuing to run through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 086689be: workspot, continuing to run through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 25ae07d0: workspot- plowing through with rough human-augmented machine translation
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 002722b7: start by copying pt_BR locale
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 1023edb2: encoding change, and wrapping up LDAP sections rough pass
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:05 AM Revision 70d8b7b0: continued cumulative machine translations
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
02:52 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
duplicate of #2859.
this isn't the place to ask questions, please take those to the forum or mailing list.
Chris Buechler
02:50 AM Bug #3392: Allow to configure different mac addresses for multiple VLANs on same physical interface
Feature #2859
how to do that coz i have just one nic and 4 VLANS configured on it, 2 WAN and 2 LAN
Nikita Drachev
02:48 AM Bug #3392 (Rejected): Allow to configure different mac addresses for multiple VLANs on same physical interface
I had to beg to change the MAC of the provider.
Very important! I can make a few NIC VMware on, but I can not create...
Nikita Drachev

01/08/2014

09:18 AM Feature #972: Allow adding gateways outside of interface subnet
Hi Dan,
I felt in the same trouble, and I the idea I have found to survive reboot is using the ShellCmd package : ...
Dédé D
07:41 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
It works fine in a test VM here that never had Quagga, and also in a separate VM that had it previously and reinstall... Jim Pingle
02:46 AM pfSense Packages Bug #3391 (Rejected): Quagga OSPF doesn't install properly
Hello,
I have several pfSense firewalls, all having Quagga OSPF and running without issues.
They where installed ...
Johan Braeken
05:28 AM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
You mean you essentially created a cert chain yourself in the Certificate Authority Manager and then it worked? Malte Stretz

01/07/2014

07:20 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
that's reasonable, submit that as a pull request in github and we'll get it merged. Chris Buechler
04:15 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
You're still misunderstanding. If the initial connection by the user prior to CP authentication is to, say, https://... Chris Linstruth
02:19 PM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Use a signed certificate on your CP!!! Ermal Luçi
10:37 AM Feature #3388: Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
I believe you are missing the point.
This enables administrators to utilize HTTPS CP authentication, which might b...
Chris Linstruth
05:05 AM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Just do not configure https authentication! Ermal Luçi
04:39 PM Feature #3387: process_alias_urltable Frequency
Ah never mind. I forgot about the ability to change the type on the fly... Shawn Bruce
04:12 PM Feature #3387: process_alias_urltable Frequency
Shawn Bruce wrote:
> I have created a diff for firewall_aliases_edit.php against the latest git version. Would this ...
Shawn Bruce
04:11 PM Feature #3387: process_alias_urltable Frequency
I have created a diff for firewall_aliases_edit.php against the latest git version. Would this be acceptable?
I am...
Shawn Bruce
04:12 AM Feature #3387: process_alias_urltable Frequency
A code to upgrade current config to new format will be necessary too Renato Botelho
03:59 PM Revision 33e72874: Merge pull request #880 from phil-davis/master
Check for vertical bars in alias detail descriptions Ermal Luçi
03:05 PM Revision 7d14b000: Check for vertical bar at start or end of description
Phil Davis
02:59 PM Revision 24445691: Check for vertical bars in alias detail descriptions
The descriptions of each entry in an alias are stored in config.xml as a list delimited by "||". So you cannot have "... Phil Davis
10:58 AM Revision 51922cb7: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
Renato Botelho
10:58 AM Revision 6b660731: Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384
Renato Botelho
09:41 AM Revision 7c2ea0cc: Update reserved_keywords checks to match firewall_aliases_edit
firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real...
Phil Davis
09:39 AM Revision fe56417f: Merge pull request #879 from phil-davis/master
Update reserved_keywords checks to match firewall_aliases_edit Renato Botelho
07:39 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
It seems like maybe the authentication fallback that allows a person to login using local auth when their LDAP server... Jim Pingle
04:59 AM Bug #3383: Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
On pfSense 2.2 you will be able to revert GUI auth backend to Local Database on the same option you use to restore GU... Renato Botelho
06:51 AM Bug #3389 (Resolved): GUI allows to configure ICMPv4 types for ICMPv6 firewall rules
When I try to create a firewall rule that handles only certain types of IPv6 ICMP traffic, the interface lets me sele... Andreas Peetz
05:00 AM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Applied in changeset commit:51922cb793b83bf7d22fdaa47205fd59b4d70e87. Renato Botelho
05:00 AM Bug #3384 (Feedback): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Applied in changeset commit:6b6607316481aacaa055f8e4bce2ce1e520d3b1b. Renato Botelho

01/06/2014

05:09 PM Revision 4410f699: This might also say "icmpv6" here and lead to a bad rule.
Jim Pingle
05:08 PM Revision 0959b4d3: This might also say "icmpv6" here and lead to a bad rule.
Jim Pingle
04:48 PM Feature #3388 (Rejected): Add checkbox and logic to disable forwarding of HTTPS requests to captive portal
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/e98daec5960b7ecdd18bc461003df3a18d2adbe7
Chris Linstruth
04:45 PM Bug #3340: Captive Portal deletes concurrent sessions even if noconcurrentlogins is not set
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/ae6c69833f34d8f14b1c6a9508126905328340bc
Chris Linstruth
04:42 PM Bug #3124: portal_reply_page called twice in specific circumstance
Candidate patch here:
https://github.com/derelict-pf/pfsense/commit/4fd56afe541a0a350dfe52b20521a551edd9f276
Chris Linstruth
04:11 PM Revision 81f19476: Add an option to force a gateway to be down, it fixes #2847
Renato Botelho
03:02 PM Revision de3987e5: Update reserved_keywords checks to match firewall_aliases_edit
firewall_aliases_import should have the same checks for reserved names as firewall_aliases_edit
This code should real...
Phil Davis
02:35 PM Revision 30e2adbc: Merge pull request #871 from phildd/master
Dynamic DNS: List GWGs in Interface to send update from Ermal Luçi
11:35 AM Feature #3387 (New): process_alias_urltable Frequency
Currently the urltable design only allows for updates on a daily interval and is processed via crontab every 12 hours... Shawn Bruce
10:10 AM Feature #2847 (Feedback): Add a checkbox to flag a gateway as "down"
Applied in changeset commit:81f1947666ebbe19f1f6579a1e5293c42c6d1c04. Renato Botelho
09:13 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
Ermal Luçi
07:31 AM Revision 7ad4b9b7: Merge pull request #878 from phil-davis/master
Bulk Import: fix copy-paste var name error Ermal Luçi
02:43 AM Revision 3b4e6952: Bulk Import: fix copy-paste var name error
Phil Davis

01/05/2014

11:18 AM Revision b760fd31: Merge pull request #877 from phil-davis/master
Allow individual line descriptions on alias bulk import Ermal Luçi
09:35 AM Revision 8c470066: Allow individual line descriptions on alias bulk import
This enhancement allows the user to make a text file of IP addresses, IP subnets and/or IP ranges, like they have alw... Phil Davis
08:54 AM Bug #3386: apinger not picking up 2nd OpenVPN tunnel
I did another reboot and now it worked. You can close this issue (did not find button to close it myself). Schlomo Schapiro
08:48 AM Bug #3386 (Closed): apinger not picking up 2nd OpenVPN tunnel
When adding a 2nd OpenVPN tunnel (client side, shared key static setup) and the corresponding Interface and Gateway i... Schlomo Schapiro

01/04/2014

10:32 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
After I posted the above, I have a new idea.
I just copied the Root CA certificate to the Intermediate CA's certif...
Tim Lau
10:18 PM Bug #2800: OpenVPN doesn't work properly with intermediate/chained CAs
I am hit with the same bug.
Also, if you set the Peer Certificate Authority to the Root CA, 2 things happen:
1....
Tim Lau
02:49 PM Feature #3385: Accommodate static routes for PPTP connections
correction :
When the VPN reconnects, the static route is not reinstated and must be re-instated to bring the rou...
James Mills
02:47 PM Feature #3385 (Closed): Accommodate static routes for PPTP connections
Creating a static route on the pfSense box allows routing from the 10.20.2.0 network back across the (pptp) vpn to th... James Mills
07:00 AM Bug #3384 (Resolved): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
ntp.conf(5):
limited
Deny service if the packet spacing violates the lower limits specified
in ...
Jeroen Roovers
04:29 AM Bug #3383 (Resolved): Web GUI becomes slow or unusable if the LDAP server used for GUI auth is unreachable
Hy,
This one have been difficult to find.
I set up a ldap server in user manager through the web gui. Everything ...
Florent THOMAS

01/03/2014

10:00 PM Revision f05bf59b: Merge pull request #875 from dotike/spellcheck
minor spelling correction for pfSense master branch Ermal Luçi
09:41 PM Revision 41681aa6: minor spelling correction for pfSense master branch
Signed-off-by: Isaac (.ike) Levy <ike@blackskyresearch.net> Isaac (.ike) Levy
03:56 PM Revision 4e6405b9: Oops correct php syntax
Ermal LUÇI
03:38 PM Bug #2650: FTP helper breaks TCP sequence numbers on 2nd WAN
I've also run into this problem. I didn't want it to get so buried in the pile that it never got looked at again. Rene Churchill
03:05 PM Revision 21f82ab6: Do not allocate the same pipe to everyone rather give each person its own!
Ermal LUÇI
03:05 PM Revision 762b34c4: Do not allocate the same pipe to everyone rather give each person its own!
Ermal LUÇI
02:53 PM Revision f38b383b: Use empty here for testing even if the setting is unset
Ermal LUÇI
02:52 PM Revision c8d611ed: Use empty here for testing even if the setting is unset
Ermal LUÇI
01:24 PM Revision a3a1b24e: Move to zerocopy_enbale for bpf to optimize bpf logging which uses bpf interface. This should increase the general performance since pflog is always enabled.
Ermal LUÇI
11:21 AM Bug #3382 (New): IGMPPROXY fails with more than 32 interfaces
Hi,
I have a problem with the igmpproxy:
I am using pfSense in an enviroment of round about 120 users, and every ...
Thomas Levi
08:33 AM Revision 723f0ac9: Merge pull request #873 from tuyan/patch/copyright_years
Update product_copyright_years end to be calculated on the fly. Chris Buechler

01/02/2014

09:54 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
Further to this, the " Borrow from other queues when available" doesn't work when you go 1 level deeper than the root... Ignat Esso
08:25 PM Bug #3381: LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
FYI - The WAN interface seems to be 100% correct all the time. Ignat Esso
08:25 PM Bug #3381 (Resolved): LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues
LAN interface root Queue Bandwidth calculation is exactly double the total of the other child queues. This looks to b... Ignat Esso
03:57 PM Revision 2bb93345: Update copyright_years to be calculated on the fly.
Tuyan Ozipek
03:25 PM pfSense Packages Bug #3380 (Not a Bug): FreeRadius-User-Option "Expiration Date" kills the FreeRadius-Server
Hi,
after adding an User-Expiration-Option to an user of FreeRadius Service, radius tries to restart but breaks:
...
Thomas Levi
11:58 AM Revision 8f56dd27: DyndDNS edit: unset vars when no longer used
phildd
11:13 AM Revision 0350084d: fix syntax
Renato Botelho
10:41 AM Revision 2a45e05f: Fix filter regex
Renato Botelho
09:20 AM Revision 52311f0c: Merge pull request #870 from blagynchy/patch-1
Happy New Year 2014! Renato Botelho

01/01/2014

11:54 PM Revision 9dc3f2bb: Happy New Year 2014!
Optimal: Just updating the copyright years;
I wish to all of you all of health, happiness and good luck of earth to ...
Valentin Georgiev

12/31/2013

12:28 PM Revision 31dce430: Upgrade all firewall rules to include a tracker field. Add a tracker field even for nat for later usage while here.
Ermal LUÇI
12:23 PM Revision 2006d7a4: Generate a tracker id for the filter rules for now. Maybe for nat rules as well?
Ermal LUÇI
09:52 AM Feature #3377: OAuth2 authentication in captive portal
Sure go ahead. Ermal Luçi
04:56 AM Feature #3377 (New): OAuth2 authentication in captive portal
In Captive Portal we have native, ldap and radius authentication. Today, a lot of authentication systems provide OAut... Thomas NOEL

12/30/2013

04:14 PM Revision ba1c86d9: Remove scrub as well
Ermal LUÇI
03:45 PM Revision 31300a95: List GWGs in Interface to send update from
phildd
03:27 PM Revision 32fd1703: Remove even negating nat rules
Ermal LUÇI
02:47 PM Revision a03dfc60: Correct matching for single rule. Somehow the egrep did not work there!
Ermal LUÇI
02:34 PM Revision b80e29e4: Speed up a bit rule number identification by avoiding going into kernel but using the rules parsing of pf which gives the same effect.
Ermal LUÇI
11:56 AM Revision 239024ee: Merge pull request #866 from andrespetralli/master
Enabling advanced RFC 2136 configuration for DHCPd service Renato Botelho
09:23 AM Revision 44b72c67: Fix display of CIDR/Update Freq in Alias Edit
Fixes #3376. I have no idea what the "^" characters were meant to do, but removing them makes the CIDR/Update Freq va... Phil Davis
09:23 AM Revision d564ed24: Validate IP address ranges correctly on Alias Bulk Import
The code was there to attempt to validate and implement IP address range lines in Alias Bulk Import e.g.
10.20.0.0-10...
phildd
08:07 AM Revision 737f26e9: Merge pull request #868 from phildd/master
Validate IP address ranges correctly on Alias Bulk Import Ermal Luçi
08:06 AM Revision ef1c9f09: Merge pull request #867 from phil-davis/master
Fix display of CIDR/Update Freq in Alias Edit Ermal Luçi
03:30 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:44b72c67ec3331ecd3a6430697ad47dbeac7c450. Phillip Davis
02:10 AM Bug #3376 (Feedback): Alias Edit does not display correctly
Applied in changeset commit:1b9ab14ad23e1f66a11801fbe7a24423ab8529a0. Phillip Davis
 

Also available in: Atom