Project

General

Profile

Activity

From 01/19/2014 to 02/17/2014

02/17/2014

04:38 PM Bug #2820 (New): Unable to generate CSR in 2.1BETA1
Are you using the latest available snapshot? Could you give more details about how to reproduce it? I tried but could... Renato Botelho
04:30 PM Bug #2820: Unable to generate CSR in 2.1BETA1
Seeing this again on RELENG_2_1 Richard Connon
04:30 PM Bug #3458 (Rejected): Regression of #2820 on latest RELENG_2_1
If you are seeing the same issue of #2820, please add a comment there and we can re-open it, this is good to keep tra... Renato Botelho
01:32 PM Bug #3458 (Rejected): Regression of #2820 on latest RELENG_2_1
Seeing the behaviour in issue #2820 on current RELENG_2_1 code. Can't submit to create a CSR, given error "Please sel... Richard Connon
03:10 PM Bug #3462 (Feedback): RCE - ARPING
Applied in changeset pfsense-packages:commit:ad6e7cb89edbb0849eda4516cb0976fb877bc397. Jim Pingle
02:52 PM Bug #3462 (Resolved): RCE - ARPING
Reviewing http://seclists.org/fulldisclosure/2014/Jan/187 I can see that it's still possible to execute remote comman... Fernando Munoz
02:55 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
we'll re-evaluate for 2.2 Chris Buechler
08:33 AM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Well it is not something to be fixed for 2.1.1 since its an OS issue rather than pfSense collection one. Ermal Luçi
02:36 PM Bug #3461 (Resolved): XSS - package system
pkg parameter isn't encoded properly, it's possible to inject javascript code:
https://ip/pkg_mgr_install.php?mode...
Fernando Munoz
02:31 PM Bug #3460 (Resolved): CSRF Protection - Package manager
The CSRF protection doesn't work on the package manager as it takes the parameters to install/uninstall/reinstall pac... Fernando Munoz
02:22 PM pfSense Packages Bug #3459 (Resolved): XSS - snort package
There is no output encoding for the logfile variable, which leads to two reflected XSS point in the file snort_log_vi... Fernando Munoz
01:41 PM Bug #3457 (Rejected): Regression of
Renato Botelho
01:30 PM Bug #3457 (Rejected): Regression of
Richard Connon
01:40 PM Bug #3250 (Feedback): problems with ixgbe driver in pfsense 2.1 release
Next build will be with previous drivers which are more stable. Ermal Luçi
09:20 AM Bug #3421: dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
Applied in changeset commit:838e1f6342b42c52e21d11942e35561c25194c1d. Renato Botelho
09:20 AM Bug #3421 (Feedback): dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
Applied in changeset commit:bd942860594ecf3383ac39eb203ce3c73d4c59d2. Renato Botelho
08:20 AM Bug #3281: In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function
Applied in changeset commit:2b2d0d545d01a9b21d4350908e73c6ce5b3e1d22. Ermal Luçi
08:20 AM Bug #3281: In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function
Applied in changeset commit:11ad160eae8e9d4e17df6462a1975a36faa1abd8. Ermal Luçi
08:13 AM Bug #3281 (Feedback): In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function
Ermal Luçi
08:10 AM Bug #3234 (Feedback): Captive Portal previously declared getNasIP()
Put this to feedback since the changes will be made when CP functions get merged as system functionality. Ermal Luçi
08:10 AM Bug #3280: Assigning GRE interface and configuring an IP address removes the IP from the underlying gre interface in the OS
Applied in changeset commit:fb92e33201d5572530c8cdaa75635b750a13a4db. Ermal Luçi
08:10 AM Bug #3280: Assigning GRE interface and configuring an IP address removes the IP from the underlying gre interface in the OS
Applied in changeset commit:6191b3215c4e10bfe98e196291c864fb1db3d233. Ermal Luçi
08:07 AM Bug #3280 (Feedback): Assigning GRE interface and configuring an IP address removes the IP from the underlying gre interface in the OS
Ermal Luçi
04:56 AM pfSense Packages Feature #3456: ladvd (lldp/cdp/edp/ndp daemon)
A sample package xml (a bit different from my version: I had to prepare a local repository)... Andrea Tuccia
04:51 AM pfSense Packages Feature #3456 (Resolved): ladvd (lldp/cdp/edp/ndp daemon)
I wrote a simple webconfigurator script from scrath for ladvd (that I prefer over openlldp because it supports also c... Andrea Tuccia
04:40 AM Bug #3340: Captive Portal deletes concurrent sessions even if noconcurrentlogins is not set
Applied in changeset commit:e8b05b83ed12ae7f65021c14686826b5aac96e00. Ermal Luçi
04:40 AM Bug #3340 (Feedback): Captive Portal deletes concurrent sessions even if noconcurrentlogins is not set
Applied in changeset commit:bae729da39079601b262e805a34d3818c3b994dc. Ermal Luçi
04:34 AM Bug #2627: Old delegated prefixes are not removed from the LAN interface
Can you please confirm this happens with latest 2.1.1?
If yes can you post your config.xml?
Ermal Luçi
04:23 AM Bug #829 (Feedback): WAN stays assigned to pppoe0 interface after switching type from PPPoE to Static
I cannot reproduce this.
And there is already code taking care of this since:...
Ermal Luçi
03:59 AM Bug #3409 (Closed): IPv6 gif tunnel not working after reboot on PPPoE
This was related with issues of pfSctl which have been fixed since. Ermal Luçi
03:50 AM Bug #3441: Non-alphanumeric characters cause issues with Captive Portal
Applied in changeset commit:378296af776e28c47652fd1268708be73f5f19ad. Ermal Luçi
03:50 AM Bug #3441 (Feedback): Non-alphanumeric characters cause issues with Captive Portal
Applied in changeset commit:bd369bcfb4499cc91f7de090dbe67daefc635f64. Ermal Luçi
03:30 AM Bug #3447: pfSense 2.1 Captive Portal RADIUS Accouting records not sent to RADIUS Server
Applied in changeset commit:2b76f145e40e47d06c7441ae8a419aeae9cc811b. Ermal Luçi
03:30 AM Bug #3447 (Feedback): pfSense 2.1 Captive Portal RADIUS Accouting records not sent to RADIUS Server
Applied in changeset commit:74a40221d6ad7611bc6182aa506c5d6f5cee8edf. Ermal Luçi

02/16/2014

10:03 AM Bug #3455 (Closed): Selecting interfaces for DNS forwarder breaks auto-update
An interesting intersection of two features...
If the local DNS forwarder is the first DNS server pfSense queries (p...
Adam Thompson
06:40 AM Bug #3447: pfSense 2.1 Captive Portal RADIUS Accouting records not sent to RADIUS Server
Changing to code in captiveportal_disconnect_client() to use column 9 was a bit of a fluke as that column just happen... Richard Gate

02/15/2014

11:12 PM Bug #3454 (Resolved): Acknowledge all notices is presented to users who do not have privilege
I have local users that are just for OpenVPN authentication. They just have access to the System: User Password page,... Phillip Davis
09:12 AM Feature #3453 (Duplicate): Management GUI (lighttpd) interface binding control
Add configuration option to allow/prevent lighttpd from binding to certain interfaces.
In a highly secure environm...
Ted Lum

02/14/2014

11:49 PM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Having limited enabled by default is not appropriate, and it shouldn't be the case.
Having the option to turn it o...
ky41083 -
05:04 PM Bug #3451: Pfsense 2.1 Captive Portal Proxy Transparent
That? Using authenticated proxy?
I think that and a failure of CP when transparent proxy
Gilmar Cabral
11:52 AM Bug #3451 (Rejected): Pfsense 2.1 Captive Portal Proxy Transparent
there are options to work around that Chris Buechler
04:59 AM Bug #3451 (Rejected): Pfsense 2.1 Captive Portal Proxy Transparent
In pfsense 2.1 using captive portal voutcher with transparent proxy to set proxy desktop browser captive portal login... Gilmar Cabral
04:02 PM Bug #3421: dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
Agreed, I think the following was also required to make it work, as seen in the above dhcpv6.conf... Andrew Stuart
12:40 PM Bug #2952: Unvalidated input during system_firmware_check.php
I'd advocate a more appropriate fix than addslashes() for this - slash-escaping is not sufficient to protect against ... Ian Gallagher
06:20 AM Bug #2952: Unvalidated input during system_firmware_check.php
Applied in changeset commit:d210dddff39462019bc9b349cb3322a92d88feca. Renato Botelho
06:20 AM Bug #2952 (Feedback): Unvalidated input during system_firmware_check.php
Applied in changeset commit:dbfa041c1024edf6836058147714cca89267f8f0. Renato Botelho

02/13/2014

05:59 PM Bug #3450 (Rejected): DHCPv6 Lease Status shows no Leases
Viewing DHCPv6 Leases under the Status menu shows no active or configured leases, despite multiple devices on LAN hav... Rob Gormley
02:48 PM Feature #3448: add additional dyndns providers dyndns.fr, dyndnspro.com, dynamicdomain.net
Another one :)
duckdns.org:
https://www.duckdns.org/update?domains=exampledomain&token=<token>
More info: https:...
Doktor Notor
10:38 AM Feature #3448: add additional dyndns providers dyndns.fr, dyndnspro.com, dynamicdomain.net
and there is also a forum request to add zonomi.com
https://forum.pfsense.org/index.php/topic,72326.0.html
so perha...
Phillip Davis
09:13 AM Feature #3448 (Needs Patch): add additional dyndns providers dyndns.fr, dyndnspro.com, dynamicdomain.net
Please add dyndns.fr , dynamicdomain.net and dyndnspro.com in the dynamic dns (dyndns) dns
system.
Urls are :
...
nabilion chan
11:49 AM Bug #3449 (Resolved): IE 8 does not respect disabled CIDR field when editing host alias, leading to filter ruleset syntax errors
IE8 on XP (pause for laughter) does not respect the JavaScript that disables the CIDR field when editing a host alias... Jim Pingle
09:10 AM Bug #3287: RRD. No IPv6 data.
because that's the inside of the tunnel, your WAN graph is the outside. Chris Buechler
03:34 AM Bug #3287: RRD. No IPv6 data.
Chris Buechler wrote:
> not a bug, in that circumstance there is no v6 traffic on your WAN. It's all encapsulated in...
Dmitriy K
06:51 AM Bug #3447 (Resolved): pfSense 2.1 Captive Portal RADIUS Accouting records not sent to RADIUS Server
Code in /etc/inc/cativeportal.inc is referring to the wrong columns in the array returned by captiveportal_read_db().... Richard Gate
05:32 AM Bug #3446 (Closed): NTP server doesn't bind to assigned interfaces on automatic service restart after queriing his assigned master time server
Every morning my pfsense synchronizes with a master timeserver on the internet. The ntpd is taken down while synchron... Michael Noack

02/12/2014

04:53 AM Bug #3176: Hosts file corrupted when using "Register DHCP leases in DNS forwarder"
I'm seeing this too (on 2.0). While the corruption is happening, there are two /usr/local/sbin/dhcpleases processes r... Daniel Sheridan
02:20 AM Bug #3223: pfr_unroute_kentry: delete failed and freeze
Sorry i forget this story. But yes I have very very big tables in my setup where i have this trouble.
But i had some...
xavier Lemaire

02/11/2014

11:43 PM Bug #3263: status_graph.php IP list is limited to interface subnet
I realized how to make the Filter: All and Remote options actually work again in 2.1.1. That code was committed a cou... Phillip Davis
06:48 PM Bug #3421: dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
FYI if you use ... Chris Buechler
05:47 PM Bug #3315 (Rejected): SNMP MIB-2 Strange TCP Stats
It works as it's supposed to. That's connections established by, or from, the firewall itself, not traffic through it... Chris Buechler
05:30 PM Bug #3432 (Feedback): PPPoE (WAN) reconnected, WAN does not updated
Chris Buechler
05:25 PM Bug #3333 (Feedback): usbusX devices show up as NICs.
this was confirmed fixed pre-2.1 release. Does your /boot/loader.conf file contain the following line? ... Chris Buechler
05:20 PM Bug #3384 (Feedback): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
I believe we have adequate solutions in place here, and having discard enabled by default doesn't seem to be appropri... Chris Buechler
05:07 PM Bug #3312: Gateway on IPsec rules is not functional in pf
has this ever worked? Offhand I can't recall seeing anyone doing that. Chris Buechler
05:02 PM Bug #3200 (Feedback): IPv6 bugs
the third bullet point is the same cause as #3394. The fix for that might fix everything else you've noted here. Can ... Chris Buechler
04:59 PM Bug #3394 (Feedback): radvd wrongly binds to *:546 in some circumstances
Ermal committed a fix for this in dhcp6c that was causing radvd to inherit its socket. Chris Buechler
04:57 PM Bug #3287 (Rejected): RRD. No IPv6 data.
not a bug, in that circumstance there is no v6 traffic on your WAN. It's all encapsulated in v4 at that point. Chris Buechler
01:28 PM Bug #3444: IPv6 network alias input validation lacking
Yes, this works, thank you:... Brian Candler
02:54 AM Bug #3444 (Feedback): IPv6 network alias input validation lacking
Ermal Luçi
02:53 AM Bug #3444: IPv6 network alias input validation lacking
Fixed for 2.1 as part of commit:f188be51ae242a6de7f99b0c6206ec24d5296af4 Ermal Luçi
02:53 AM Bug #3444: IPv6 network alias input validation lacking
Fixed as part of ee41ab022d92cf7d0a1b75e1d85aca7162648292 Ermal Luçi
02:18 AM Bug #3444 (Resolved): IPv6 network alias input validation lacking
via Brian Candler on mailing list.
When creating a network alias which contains an IPv6 address, some additional ...
Chris Buechler
01:13 PM Bug #3128: Active voucher status not restored from backup
To sum this up, I posted about the mess at the forum: https://forum.pfsense.org/index.php/topic,72418.0.html
Addit...
Doktor Notor
12:11 PM Bug #3416 (Resolved): [PATCH] PPP/PPPoE link settings not shown
thanks Chris Buechler
12:08 PM Bug #3416: [PATCH] PPP/PPPoE link settings not shown
Fix was merged in 56e75b0. Thank you! Brian Candler
08:53 AM Bug #3445 (Resolved): Proxy URL behaviour for package list - trailing slash
In the System -> Advanced -> Miscellaneous settings, where you enter the proxy URL, if you have a trailing slash then... Adrian James
04:54 AM Bug #3443: run -- Ralink Technology USB
I am wrong, i tested it with the tow options "Yes"
and the driver loaded and worked fine untill i connect my self t...
Muhammed Ismail
03:42 AM Bug #3443: run -- Ralink Technology USB
Mr.Chris as it is said in the FreeBSD Kernel Interfaces Manual
[[http://www.freebsd.org/cgi/man.cgi?query=run&apropo...
Muhammed Ismail
02:16 AM Bug #3443 (Rejected): run -- Ralink Technology USB
The run driver is included. It appears it doesn't work with your card. Probably no solution to that until our 2.2 rel... Chris Buechler
01:09 AM Bug #3443 (Rejected): run -- Ralink Technology USB
*NAME*
run -- Ralink Technology USB IEEE 802.11a/g/n wireless network device
*SYNOPSIS*
To compile thi...
Muhammed Ismail

02/10/2014

08:16 PM pfSense Packages Bug #3442: Stunnel package $config issue?
If stunnel is technically designed as two sub=packages (stunnel and stunnel_certs) then the issue may be that on inst... Stilez y
08:10 PM pfSense Packages Bug #3442 (Closed): Stunnel package $config issue?
Pfsense 2.1.1beta, installed Stunnel, but any attempt to add either a first tunnel or a first cert consistently cause... Stilez y
02:02 PM Bug #3353: Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
FYI: Still happens on a current build.
FreeBSD pfs22.local 10.0-RELEASE FreeBSD 10.0-RELEASE #0 d44ce30(releng/10....
Jim Pingle

02/08/2014

05:51 AM Feature #3426: NanoBSD shorter F1 boot prompt display
In pfsense-tools / builder_scripts / builder_common.sh, line #2202
@boot0cfg -B -b ${CLONEDIR}/${NANO_BOOTLOADER} ...
Max Mustermann
02:01 AM Bug #3441: Non-alphanumeric characters cause issues with Captive Portal
Forgot the forum thread; see https://forum.pfsense.org/index.php?topic=51489.0 Doktor Notor
02:00 AM Bug #3441 (Resolved): Non-alphanumeric characters cause issues with Captive Portal
On trying to enter a message with diacritics (e.g. ěščřžýáíéúů) on a CP Zone - Vouchers - Invalid Voucher Message/Exp... Doktor Notor

02/07/2014

03:09 AM Bug #3438 (Resolved): Cannot restore recent configuration
Renato Botelho
01:55 AM Bug #3440: Aliases, Networks and the vanishing subnets inside of Google Chrome
I think that bug was introduced since 2.1-RELEASE and perhaps it is in that 2.1p1 NetGate version. It has since been ... Phillip Davis

02/06/2014

06:33 PM Bug #3440 (Resolved): Aliases, Networks and the vanishing subnets inside of Google Chrome
When creating an Alias for a network in Google Chrome on OS X Mavericks I have the option of choosing a CIDR represen... Lane Campbell
04:19 PM Bug #3438: Cannot restore recent configuration
Thanks, works now. ;-) Doktor Notor
01:00 PM Bug #3438: Cannot restore recent configuration
Applied in changeset commit:d292bd8d60b1e01702b3654e8bb3ac8fd66c88e6. Jim Pingle
01:00 PM Bug #3438 (Feedback): Cannot restore recent configuration
Applied in changeset commit:8d112d7d51fd55e73a171615b9c075cd04a739d8. Jim Pingle
12:45 PM Bug #3438 (Resolved): Cannot restore recent configuration
... Doktor Notor
02:57 PM Bug #3422: Diagnostics > DNS lookup gives spurious results
OK, this patch is irrelevant in the light of commit e2ffc9d which replaces dig with drill. AFAICS, drill doesn't have... Brian Candler
04:09 AM Bug #3422: Diagnostics > DNS lookup gives spurious results
OK, so I have narrowed this down.
* If I set System > General Setup > DNS Servers to just 8.8.8.8 or 8.8.4.4, it w...
Brian Candler
03:55 AM Bug #3422: Diagnostics > DNS lookup gives spurious results
Here you go - plain dig, dig asking for A, dig asking for AAAA. Of course, what's of interest is what's in the "ANSWE... Brian Candler
03:11 AM Bug #3422 (Feedback): Diagnostics > DNS lookup gives spurious results
can't replicate. What does the output of dig show for psg.com for you?
Chris Buechler
01:39 PM pfSense Packages Bug #3439 (Closed): TFTP - cannot start or restart from Status -> Services
TFTP package installs fine, and is started upon installation.
However, it cannot be restarted or started after sto...
Eduard Rozenberg
11:53 AM Bug #3437 (Resolved): web redirector doesn't listen on IPv6 port 80
Minor issue: when you configure management to be HTTPS, the port 80 redirector only works on the IPv4 address and not... Brian Candler
09:36 AM Feature #3199: Option to accumulate or not IP addresses in Alias table of FQDNs
I don't see any reason to accumulate addresses at all. DNS A records for an FQDN return all valid addresses at once. ... Kurian Thampy
02:44 AM Bug #3436 (Resolved): Cannot save nut settings/enable nut (regression)
Renato Botelho

02/05/2014

06:53 PM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
No no, I get what you're saying, and I don't disagree with it at all in the correct scenario.
But the person who o...
ky41083 -
05:04 PM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Keith, this iburst stuff is suggested on ntp.org site, suggested on tons of distro-specific docs, default in lots of ... Doktor Notor
06:31 PM Bug #3436: Cannot save nut settings/enable nut (regression)
Apparently got way too messed up. I reimaged the box, applied the above patch, now both unbound and nut install prope... Doktor Notor
05:38 PM Bug #3436: Cannot save nut settings/enable nut (regression)
No, that did not work... Still heavily messed up:... Doktor Notor
05:00 PM Bug #3436: Cannot save nut settings/enable nut (regression)
Or you can apply this mannually and reinstall the packages: https://github.com/pfsense/pfsense/commit/dab351f359bb451... Renato Botelho
04:57 PM Bug #3436: Cannot save nut settings/enable nut (regression)
BTW, screwed unbound as well... and probably a whole lot more. :-( Doktor Notor
04:54 PM Bug #3436: Cannot save nut settings/enable nut (regression)
Try to reinstall package with tomorrow's snapshot and let me know if it's fixed or not. Renato Botelho
04:44 PM Bug #3436 (Resolved): Cannot save nut settings/enable nut (regression)
Cannot save nut setting no matter what.... Doktor Notor
12:59 PM Feature #2834: carp+pfsync: add ability to prefer one node as master
I just came to request the same thing. Although I was thinking of a simple check box that said subtrack instead of a... Robert Middleswarth
06:42 AM Feature #3435 (Rejected): aliases do not allow hyphen
Jim Pingle
06:42 AM Feature #3435: aliases do not allow hyphen
Alias names are not hostnames, they are pf macro names which may not contain hyphens. Jim Pingle
05:11 AM Feature #3435 (Rejected): aliases do not allow hyphen
When trying to add hostname foo-bar1 under Firewall > Aliases
"The following input errors were detected:
The al...
Brian Candler

02/04/2014

10:31 PM Bug #3432: PPPoE (WAN) reconnected, WAN does not updated
Ok, looks like it was due reported via forums apinger bug
@
Feb 5 06:30:00 apinger: alarm canceled: WAN_PPPOE(21...
Vladimir Suhhanov
07:50 PM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Hey, that works. I was saying it seems like a lot from the standpoint of a *public* NTP server. Clearly if you have n... ky41083 -
07:26 AM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
_every 5 seconds OR twice in a row. Seems like a lot to me_
Uhm, not really a *lot* when iburst is used. (8 pack...
Doktor Notor
03:15 PM pfSense Packages Bug #3434 (Resolved): widentd
pfSense 2.1, 64bit, widentd 1.03_1
The 'Listening interface' selections don't work the way I expect. I'm testing f...
lynn wilborn
10:33 AM Bug #3433 (Resolved): Case-sensitive detection of link local addresses
Trying to add a gateway address FE80::5:73FF:FEA0:2 (which is a Cisco HSRP address, copy-pasted directly from output ... Brian Candler

02/03/2014

10:44 PM Bug #3432 (Resolved): PPPoE (WAN) reconnected, WAN does not updated
I am connected to ISP via PPPoE with dynamic IP. WAN is configured as PPPoE and this configuration was working about ... Vladimir Suhhanov
08:50 PM Bug #3384: NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
The default values with the "limited" parameter specified only allow a client to NTP sync once every 5 seconds OR twi... ky41083 -
08:28 AM Bug #3384 (New): NTPd should deny service if the packet spacing violates the lower limits specified in the discard command (CVE-2013-5211)
Using limited as-is denies access to NTP clients, so this change is not viable. If you try to sync time against ntpd ... Jim Pingle
08:09 PM Bug #3431 (Closed): IPSec PSK Characters Error
My first report, hope everything is o.k. with it...
Using german Umlaute in the PSK like ö, ä, ü or ß leads on 2.1...
The Buccaneer
09:23 AM Feature #1477: IGMPPROXY spamming the main systemlog
If you make a pull request in GitHub it makes it really easy for the devs to take a look and commit the fix. Phillip Davis
01:31 AM Bug #3429: Modify anti-lockout pf rule to use "no state"
May I ask why? I have been running those filter rules (for SSH) for several years on an OpenBSD gateway without any p... Anonymous

02/02/2014

12:10 PM Feature #1477: IGMPPROXY spamming the main systemlog
Sorry, I forgot to mention. I am using pfSense 2.1-RELEASE (i386) built on Wed Sep 11 18:16:44 EDT 2013 FreeBSD 8.3-R... Willy Tenner
12:08 PM Feature #1477: IGMPPROXY spamming the main systemlog
The patch from https://github.com/pfsense/pfsense-tools/blob/master/pfPorts/igmpproxy/files/patch-verbosity-logs does... Willy Tenner
09:00 AM Bug #3425 (Rejected): Enabling PowerD fails with repeating "kernel: acpi_perf0: Px transition to 774 failed" and "kernel: acpi_perf0: set freq failed, err 6"
FreeBSD issue outside our control. Likely to work better on 2.2/FreeBSD 10.
https://doc.pfsense.org/index.php/Polic...
Chris Buechler
08:59 AM Feature #3427 (Rejected): Shorten 83 second reboot time on NanoBSD class 10 USB device on i3 (2013) PC hardware
There isn't anything we can do with this. No clue if this is because your ISP is slow to respond on a dynamic WAN, or... Chris Buechler
08:55 AM Bug #3429 (Rejected): Modify anti-lockout pf rule to use "no state"
not a good idea. Chris Buechler
04:04 AM Bug #3429: Modify anti-lockout pf rule to use "no state"
+1 Bipin Chandra
01:13 AM Bug #3429 (Rejected): Modify anti-lockout pf rule to use "no state"
When flushing states one gets kicked out of pfSense management (HTTP/SSH).
I would suggest to modify the anti-lockou...
Anonymous
08:54 AM Feature #3430 (Rejected): Service Forwarding: SMTP Forwarding host for each WAN link
this is easily done with firewall rules, doesn't justify its own config section. Chris Buechler
04:50 AM Feature #3430 (Rejected): Service Forwarding: SMTP Forwarding host for each WAN link
Most dutch consumer ISP's don't allow access to TCP port 25 other then on their own network. When having multiple WAN... Max Mustermann
07:51 AM pfSense Packages Bug #3285: spamd.log corrupt/truncated
For a 'quick fix' you can apply this patch with patches package:
https://github.com/PiBa-NL/pfsense/commit/9eac9814a...
Pi Ba

02/01/2014

09:08 PM Bug #3428 (Rejected): Vulnerability: Directory Traversal
Already reported and fixed several days ago. Jim Pingle
07:42 PM Bug #3428 (Rejected): Vulnerability: Directory Traversal
Reference to bug:
http://www.exploit-db.com/exploits/31263/
Alex J.
05:43 PM Feature #3427 (Rejected): Shorten 83 second reboot time on NanoBSD class 10 USB device on i3 (2013) PC hardware
Having current hardware (a 2013 Intel Nuc) running i3-3217U processor, and running pfSense of a class 10 microSDHC de... Max Mustermann
04:54 PM Feature #3426 (Resolved): NanoBSD shorter F1 boot prompt display
The boot process of pfSense-2.1.1-PRERELEASE-4g-amd64-nanobsd_vga-20140131-1030.img is approximately delayed by 12 se... Max Mustermann
01:55 PM Bug #3425 (Rejected): Enabling PowerD fails with repeating "kernel: acpi_perf0: Px transition to 774 failed" and "kernel: acpi_perf0: set freq failed, err 6"
Running pfSense-2.1.1-PRERELEASE-4g-amd64-nanobsd_vga-20140131-1030.img
on
Intel(R) Core(TM) i3-3217U CPU @ 1.80G...
Max Mustermann

01/31/2014

05:13 PM pfSense Packages Feature #3424 (New): SCEP server
pfSense provides a variety of functions such as a Firewall, DHCP server, various types of VPN server, and can also ac... John Lockwood
04:15 PM Bug #3423 (Closed): Kernel Panic with Atheros AR9280 chipset
Hello, I'm using the Compex WLE200NX MiniPCIe card that uses the Atheros AR9280 chipset on pfSense 2.1-RELEASE 64-BIT... Basel G.
09:52 AM Bug #1629: invalid state table entries after WAN IP change
It seems that in recent weeks there have been several related commits in 10-STABLE, e.g.
http://lists.freebsd.org/...
Dim Hatz

01/30/2014

11:19 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
I performed more testing with different configurations and locations for the wait loop today. My plan was to find wh... Jason Crowley
05:10 AM Bug #3422 (Resolved): Diagnostics > DNS lookup gives spurious results
In the DNS lookup diagnostics page
Enter "psg.com" and you get:
147.28.0.62/32, nlns.globnix.net./32, rip.psg.com...
Brian Candler

01/29/2014

09:49 PM Bug #3421: dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
working dhcpv6.conf:... Andrew Stuart
09:43 PM Bug #3421: dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
I've been fiddling around with this more. Having used ps auxw I found dhcpv6 running as:
"/usr/local/sbin/dhcpd -6 -...
Andrew Stuart
07:58 PM Bug #3421 (Resolved): dhcpv6 server Netboot/next-server causes dhcpv6 not to start, and reports an error message.
Attempting to get uEFI boots working across ipv6.
I'm attempting to do this with a private ipv6 range (no native con...
Andrew Stuart
03:28 PM Bug #3420 (Rejected): Phase 1 doesn't start if phase 2 local network doesn't include a locally accessible IP
There is nothing we can do for that currently. It has to be able to source a ping from the firewall to bring up the t... Jim Pingle
03:19 PM Bug #3420 (Rejected): Phase 1 doesn't start if phase 2 local network doesn't include a locally accessible IP
My example to better understand :
- I have an IPsec VPN with the right phase 1 and phase 2 parameters
- In phase 2,...
Benoit Peccatte
03:10 PM Bug #1629: invalid state table entries after WAN IP change
Still a significant issue - causing random VoIP outages. Would be great to get this fixed. Eric Jacksch
03:02 PM Bug #3418 (Rejected): WAN address not updating in NAT
Duplicate of #1629 Jim Pingle
02:28 PM Bug #3418 (Rejected): WAN address not updating in NAT
My Asterisk PBX periodically loses contact with my VoIP provider until I reboot pfSense. The symptoms are that the PB... Eric Jacksch
02:38 PM Bug #3419 (Closed): Traffic shaper wizard doesn't properly populate download speed
I have a 25Mbps down/10 Mbps up VDSL connection.
If I run the traffic shaper wizard and specify:
Connection Upl...
Eric Jacksch
09:08 AM Bug #3311: After enabling save password permission racoon die with (core dumped)
Looks like this might be the same as #3417 Jim Pingle
09:06 AM Bug #3417 (Resolved): racoon crashes after mobile xauth login with fourth DNS server configured
If Mobile IPsec is configured to push DNS servers to clients, and you have four DNS servers configured, racoon will c... Jim Pingle
07:07 AM Bug #3415 (Rejected): vnstat2 not working after pfsense 2.1 upgrade
Duplicate of #3203 Jim Pingle
12:34 AM Bug #3415 (Rejected): vnstat2 not working after pfsense 2.1 upgrade
Hi,
I upgraded to Pfsense 2.1 from Pfsense 2.0.3 and now vnstat2 is no longer working
My issue is similar to th...
Kyle Janse van Rensburg
05:45 AM Bug #3416 (Resolved): [PATCH] PPP/PPPoE link settings not shown
There is a bug in the Javascript which prevents the per-interface settings for bandwidth/MTU/MRU/MRRU from being show... Brian Candler
12:31 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
kernel panic again even without load:
Tracing pid 12 tid 100075 td 0xffffff000b502460
m_copy_nbufs() at m_copy_nbuf...
Zeev Zalessky

01/28/2014

01:00 PM Bug #3414: system.inc variable wrong
Applied in changeset commit:82482a6937d5c75795aa6df3a0c416e3e6a9a3af. Renato Botelho
01:00 PM Bug #3414 (Feedback): system.inc variable wrong
Applied in changeset commit:f4a4bcbc4c45943bbd4734251a145f297a0502d9. Renato Botelho
12:53 PM Bug #3414 (Resolved): system.inc variable wrong
/etc/inc/system.inc
@function get_searchdomains() {
global $config, $g;

$master_list = array();

// Rea...
Sezgin SERPEN
09:49 AM Feature #3413: CARP interface names in WebGUI
Looks okay to me.
But I wonder, is there a reason to have "opt1_vip6" visible at all in the WebGUI, when you have ...
Trond Vindenes
03:16 AM Feature #3413: CARP interface names in WebGUI
This is a simple change. I think the best way to address this is under the CARP Interface column, have something like... Chris Buechler
07:01 AM Bug #742: apinger doesn't recover opt wan when connection returns.
I can confirm this problem. This bug should be reopened.
System:
2.1-RELEASE (i386)
built on Wed Sep 11 18:16:44...
Daniel Bernhardt
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:f70adc82457c038159b4f8edd775bcf1cc498d03. Phillip Davis
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:f71b440bf16ec3cd8164325f287d8c93b5dfd476. Anonymous
03:40 AM Bug #3376: Alias Edit does not display correctly
Applied in changeset commit:4dd00d25d5fc3d5a0b73930cf86685d4c1430a2e. Phillip Davis
03:24 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
looks like kernel panic caused by concurrency in ixgbe driver. i found some patches in freebsd list: http://article.g... Zeev Zalessky

01/27/2014

09:03 PM Bug #3376: Alias Edit does not display correctly
Thanks for spotting that semi-colon - I spent a while trying to work out what going on, and obviously didn't stare ha... Phillip Davis
05:14 PM Bug #3376: Alias Edit does not display correctly
The error is the semicolon after
if (set_value == true);
Grischa Zengel
05:03 PM Bug #3376: Alias Edit does not display correctly
With this patch the subnet field won't be disabled like before.
The form uses <select name="address_subnet0" class="...
Grischa Zengel
05:15 PM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
hi,
i test now firewall on my production load.
MBUFs raze detected on heavy arp load, i have more then 3000 serv...
Zeev Zalessky
04:51 PM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
Hi guys,
If there is anything I can test to help, please let me know.
I can confirm that use case (1) is no lon...
Brenton Denman
03:18 PM Feature #3413 (Resolved): CARP interface names in WebGUI
As mentioned on the forum: https://forum.pfsense.org/index.php/topic,71587.0.html
When you have a lot of CARP inte...
Trond Vindenes
08:24 AM pfSense Packages Bug #3400: apcupsd service config does not allow DEVICE to be set
Unfortunately not for all types you need UPSTYPE and DEVICE.
For example with pcnet, all config needs to be on UPSTY...
Danilo Baio

01/26/2014

07:00 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
Pull request added: https://github.com/pfsense/pfsense/pull/892 Daniel Hazelbaker

01/25/2014

12:15 PM Todo #3399 (Feedback): Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS
Added bind99 nsupdate to the builds Renato Botelho

01/24/2014

08:27 AM Bug #3412 (Resolved): serial console output mess on fetch bogons failure
Tried to upgrade from a previous 2.1.1 snapshot to Thu Jan 23 17:15:05 EST 2014 snapshot on nanobsd x86. All went wel... Doktor Notor
08:07 AM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
Thanks for the help Ermal. When I try to bounce dhcpd in the rc.newwanip script, I run into a problem where it appea... Jason Crowley
06:36 AM Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
Parameter ends up being weird because openvpn is running with IPV4 and IPV6 not. I think this parameter tun-ipv6 can ... Gilmar Cabral
06:29 AM Bug #3402: Bug Interface Virtual Openvpn Route
Utilization of this type of setting and implementing the shapper trafic in openvpn tunnel individually Gilmar Cabral
06:26 AM Bug #3402: Bug Interface Virtual Openvpn Route
Gilmar Cabral wrote:
> Related bug when and ovpns created virtual interface gateway ipv4 ipv4 and ipv6 route creates...
Gilmar Cabral
02:09 AM Bug #3411 (New): Interfaces and statistics dashboard widgets very slow with large numbers of interfaces
The interfaces and statistics dashboard widgets cause the dashboard to take minutes to load where a system has a larg... Chris Buechler

01/23/2014

11:33 PM Bug #3401: Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
it doesn't hurt anything, but yeah that should likely only be there if the VPN is using IPv6. Chris Buechler
11:31 PM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
no idea what you're referring to, routes that OpenVPN creates are those you tell it to, and that all works as it shou... Chris Buechler
11:28 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
duplicate of #2952, we'll keep it on that one. Chris Buechler
11:23 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
could you please submit a pull request on github to master? Chris Buechler
09:29 PM Feature #3410 (Resolved): Patch: Add Apple Open Directory memberUid support in group lookup
This is a patch that adds compatibility to do memberUid style lookups used in Apple's Open Directory. Specifically, w... Daniel Hazelbaker
05:43 PM Bug #3408: IPV6 DHCP not disabling on initial setup
This is what was entered in the config on a fresh install of 2.1 not 2.1.1.
It seems to automatically enter the rang...
Matthew Hoberg
04:15 AM Bug #3408: IPV6 DHCP not disabling on initial setup
I could not reproduce it on a recent 2.1.1 snapshot. I'm wondering how could it put a range on dhcpv6 if you don't ch... Renato Botelho
10:19 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
That's not something I can duplicate under 2.1 or 2.1.1 built on "Wed Jan 22 04:46:20 EST 2014".
If I change a CAR...
Jason Litka
05:49 AM Bug #3407 (Feedback): Changing CARP IP to IP Alias doesn't work until failover is trigered
As you mentioned, when moved from CARP (WAN) to an IP alias (using other CARP IP as interface), the IP stops answerin... Renato Botelho
04:34 AM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
I reproduced it here, will work on a fix. Renato Botelho
02:52 AM Bug #3409 (Closed): IPv6 gif tunnel not working after reboot on PPPoE
I have an Alix box with with WAN connected via VDSL PPPoE link and HE IPv6 tunnel configured here. With 2.1.1 pre-rel... Doktor Notor
02:15 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
getting stuck on reboot with active 3g dongle is getting a serious issue for me, i have tried 3 different 3g dongles ... Bipin Chandra
01:02 AM pfSense Packages Bug #3203: vnstat2 not working after pfsense 2.1 upgrade
Hi,
This is still broken in 2.1.1 Pre-Release
Beginning package installation for vnstat2 .
Downloading package...
Kyle Janse van Rensburg

01/22/2014

07:40 PM Bug #3408 (Closed): IPV6 DHCP not disabling on initial setup
Installing fresh copy of v2.1 with 1 WAN and 1 LAN adapter. Install to hard drive and after rebooting during initial ... Matthew Hoberg
06:31 PM Bug #2952: Unvalidated input during system_firmware_check.php
While I'm a big fan of the updates going over HTTPS for transport security, I would say that this is a different issu... Ian Gallagher
04:29 PM Bug #2952: Unvalidated input during system_firmware_check.php
Netgate Pfsense images 2.1p1 and higher upgrade over HTTPS, making this attack more difficult. Jeremy Porter
02:06 PM Bug #2952: Unvalidated input during system_firmware_check.php
Verified to still be present and exploitable in 2.1p1-RELEASE/nanobsd 4g (Netgate image), by replacing the reported ... Ian Gallagher
01:26 PM Bug #2952: Unvalidated input during system_firmware_check.php
Hi,
I'd like to bring this issue up again, and increase it's priority to critical or high, as I have verified the ...
Ian Gallagher
05:12 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
The config in the UI looks correct on both the master and the backup (listed as IP Alias in Virtual IPs screen, disap... Jason Litka
04:22 PM Bug #3407: Changing CARP IP to IP Alias doesn't work until failover is trigered
you mean on the secondary, the primary, or both? What does ifconfig look like on both systems afterwards? Chris Buechler
03:11 PM Bug #3407 (Resolved): Changing CARP IP to IP Alias doesn't work until failover is trigered
If you change an existing CARP IP Address to an IP Alias it does not work, even after hitting apply. Instead, you ne... Jason Litka
03:07 PM Feature #3406 (Needs Patch): Change Virtual IP & CARP Status screens to a tree view
For those of us that have dozens or more Virtual IPs, it would be helpful to see an alternative view that shows how a... Jason Litka
02:30 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
Please read my comment on the proper solution.
This is a workaround/hack for your local installation.
Ermal Luçi
12:43 PM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
I have attached a patch file for /etc/inc/services.inc
This will have the services_dhcpd_configure() function chec...
Micah Mitchell
10:46 AM Bug #3404: DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
The proper solution for this is to bounce the dhcpd when the openvpn link comes up.
Check rc.newwanip[v6] script on ...
Ermal Luçi
10:12 AM Bug #3404 (New): DHCP Server Fails to Start on Interfaces that are Slow to Come Online During Boot
When the services_dhcpd_configure() function is called during boot, it will skip interfaces that are not fully online... Jason Crowley
02:22 PM Bug #3405 (Rejected): Cross-Site Scripting Vulnerability in system_firmware_check.php
Filing this as a new bug so it doesn't fall under the cracks - the unvalidated input bug in #2952 has been verified t... Ian Gallagher
12:32 PM pfSense Packages Bug #3248 (Resolved): NUT package fails to write config to upsd.users
Thanks Renato Botelho
12:17 PM pfSense Packages Bug #3248: NUT package fails to write config to upsd.users
I've been running this patch for over 3 months without issue. For what it's worth, I've also tested against current 2... Denny Page
09:23 AM Feature #1557: Add the Interface descriptions to the OS interface descriptions
Hi Developers of pfSense.
Is there any status update of this Feature?
2 Years ago the Target version was deleted.
...
Peter Baumann

01/21/2014

02:58 PM Bug #3147: Adding new interface can cause issues
https://forum.pfsense.org/index.php/topic,64704.0.html
As far as I'm concerned, it's a bug. Because I have not hi...
Chris Thomas
10:13 AM Bug #3242 (Resolved): editing alias url table doesnt show full link
Jim Pingle
10:12 AM Bug #3242: editing alias url table doesnt show full link
plz mark this as resolved Bipin Chandra
09:43 AM Bug #3345: Openvpn create route ipv6 default Pfsense 2.1
Chris Buechler wrote:
> OpenVPN creates whatever routes it's configured to create (or that it pulls if pulling is en...
Gilmar Cabral
09:26 AM Bug #3402 (Rejected): Bug Interface Virtual Openvpn Route
Related bug when and ovpns created virtual interface gateway ipv4 ipv4 and ipv6 route creates automaticament. This bu... Gilmar Cabral
09:24 AM Bug #3401 (Resolved): Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
I think using ipv4 in the openvpn conf should not generate the attribute tun-ipv6 attribute and not load the ipv6 mod... Gilmar Cabral
03:31 AM Bug #3350: Disabling and enabling VLAN leaves VLAN interface missing
It would be better to revert this commit now that interface_cofnigure does the right job at detecting if an interface... Ermal Luçi
12:13 AM pfSense Packages Bug #3400 (Resolved): apcupsd service config does not allow DEVICE to be set
When configuring the apcupsd service using pfsense, only the UPSTYPE setting can be changed using the gui but not the... D B

01/20/2014

07:42 PM pfSense Packages Bug #2992: Boot problem after upgrade
This happened to me today. It happened on a fresh install with only bandwidthd and openvpn installed, after I changed... Eric Green
07:25 AM Todo #3399 (Resolved): Implement a replacement for base nsupdate command for RFC2136 Dynamic DNS
Due to FreeBSD 10.x changes, nsupdate is no longer available for inclusion from base. We will need to use a replaceme... Jim Pingle
03:36 AM Bug #3250: problems with ixgbe driver in pfsense 2.1 release
Firewall is updated to 2.1.1-PRERELEASE (amd64) built on Sun Jan 19 03:33:57 EST 2014. After boot MBUF status is 32% ... Zeev Zalessky

01/19/2014

01:13 AM Bug #3321 (Resolved): IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
thanks for the confirmation Chris Buechler
12:36 AM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
This problem has been fixed in 2.1.1-PRERELEASE! :) Christian Borchert
 

Also available in: Atom