Project

General

Profile

Activity

From 03/21/2014 to 04/19/2014

04/19/2014

11:38 PM Feature #1189: Gateway: Multiple monitor ips
Think we can get this implemented by 2.2? That would be awesome Jorge Albarenque
02:26 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Note that this only affects the SVG based graphs (on the dashboard or Status -> Traffic Graph), the RRD based ones (S... Bernhard Schmidt
02:23 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Same problem with 2.1.2 x64 on vmxnet3 interfaces. Input rate is always doubled regardless of the direction, see the ... Bernhard Schmidt
01:43 PM Bug #3611 (Resolved): DHCP relay to a server behind the gateway does not work
We have the following setup
WAN: 192.168.15.16/29
LAN: 172.16.18.0/24
DHCP server: 10.156.33.53
iow, the DHC...
Bernhard Schmidt
09:40 AM Bug #3610: Network Connection Problem
Hi,
i think i found the Problem.
I Think its 50% a configuration problem and 50% a bug.
I Configured the DNS...
Florian Asche

04/18/2014

10:52 PM Bug #3597: Package reinstall on system upgrades needs some fallback handling
Definitely some improvements to be made here.
One that'd go a long way is before doing anything, see if you can f...
Chris Buechler
10:49 PM Bug #3592 (Rejected): DynDNS
Chris Buechler
06:43 PM Bug #3592: DynDNS
Please Close this Issue! Florian Asche
10:48 PM Bug #3609 (Rejected): ppoe in virtual machines sometimes dont receive signal
You have an issue of some sort but nothing indicates it's a bug. Please post to the forum or mailing list for further... Chris Buechler
11:59 AM Bug #3609 (Rejected): ppoe in virtual machines sometimes dont receive signal
pfsense 2.1.2 using vmware workstation
i get a lot of
Apr 18 13:18:30 apinger: No usable targets found, ex...
Luis Couto
10:44 PM Bug #3610 (Rejected): Network Connection Problem
Nothing mentioned here appears to be a bug, rather you have some configuration issues you need to correct. Please uti... Chris Buechler
06:52 PM Bug #3610 (Rejected): Network Connection Problem
Hi,
i installed PFSense Version 2.1.2, amd64.
I have 4 interfaces:
WAN: IPv4 Internet
WAN3G IPv4 Backup Inter...
Florian Asche
07:38 AM Bug #1629: invalid state table entries after WAN IP change
This week i have done some more testing on this issue nr #1629.
Everybody in that issue is talking that the stat...
Tom De Coninck
05:03 AM Bug #3607: apinger misconfigured when using PPPoE link
Phillip Davis wrote:
> Go to https://github.com/pfsense/pfsense and make yourself an account and submit the code cha...
Gilles Compienne

04/17/2014

12:51 PM Bug #3607: apinger misconfigured when using PPPoE link
Go to https://github.com/pfsense/pfsense and make yourself an account and submit the code change there. It will be mu... Phillip Davis
08:21 AM Bug #3607: apinger misconfigured when using PPPoE link
Posting the source code on the bug report does not seems to have gone well (missing bits and the like, escape issues ... Gilles Compienne
08:17 AM Bug #3607 (Resolved): apinger misconfigured when using PPPoE link
When using a PPoE link for a WAN then the script configuring apinger (i.e. /etc/inc/gwlb.inc) will not configure apin... Gilles Compienne
10:56 AM Bug #3443: run -- Ralink Technology USB
OK. There is something else wrong, not just "freebsd 10" needed.
On boot I have that (newest on top)
@
Apr 17 18:3...
Vladimir Suhhanov
09:44 AM pfSense Packages Feature #3608 (Rejected): new package: puppet
A puppet agent for pfSense. Please review the pull-request and add the
package to the official repository.
https...
Frank Wall
07:59 AM Bug #3550: [IPv6] wizard not pointing to the right IPv6 address after first setup.
*pfSense-LiveCD-2.1.2-RELEASE-i386*.
* got the same issue with it;
* steps to install and setup were just the sa...
Vinícius Zavam
04:50 AM Feature #3599 (Resolved): missing kernel option / kernel module in 2.2 (mount_nullfs)
Renato Botelho
04:41 AM Feature #3599: missing kernel option / kernel module in 2.2 (mount_nullfs)
Downloaded the latest snapshot. It worked. Thanks guys! Dreamcat Four

04/16/2014

04:12 PM Bug #3223: pfr_unroute_kentry: delete failed and freeze
2.1.1-RELEASE (amd64) built on Tue Apr 1 15:22:32 EDT 2014 FreeBSD 8.3-RELEASE-p14 on new hp server 360 G6
Intel(R)...
xavier Lemaire
11:29 AM pfSense Packages Bug #3606 (Resolved): can't use content scanner in Dansguardian 2.12.0.3_2 pkg v.0.1.8 pfsense 2.1.2-RELEASE (amd64)
i have those messages in system logs
Apr 16 16:17:15 root: /usr/local/etc/rc.d/dansguardian.sh: WARNING: failed to ...
sylvain sylvain
08:48 AM pfSense Packages Bug #3605 (Closed): Dansguardian not saving groups config files with correct PICS paths.
Either that, or the PICS files are saved as the wrong files.
When saving a PICS list, it saves the file as /usr/pb...
Calvin Kruse
08:18 AM pfSense Packages Bug #3525: Dansguardian Writing Script Garbage (CsrfMagic.end)
I am also seeing this bug. I wish I knew where to submit a report to the dansguardian package maintainer, though. Calvin Kruse
02:28 AM Bug #3604: Traffic shaper wizard rules can't be deleted
I forgot to indicate that it's version:
2.1.2-RELEASE (i386)
built on Thu Apr 10 05:23:34 EDT 2014
FreeBSD 8.3-...
badon _
02:25 AM Bug #3604 (Rejected): Traffic shaper wizard rules can't be deleted
Here:
https://192.168.1.1/firewall_shaper_wizards.php
I first tried to use the "Single Wan multi Lan" wizard, ...
badon _

04/15/2014

01:27 PM Bug #3281 (New): In certain cases, GRE interfaces are missing the "RUNNING" flag at bootup and will not function
Have a config from a customer that can replicate on all 2.1x versions. In projects git repo, redmine-3281.xml. That's... Chris Buechler
01:18 PM Bug #3579 (Resolved): Limiter rules causing syntax errors
Jim Pingle
01:18 PM Bug #3579: Limiter rules causing syntax errors
Confirmed fixed. Anonymous
02:43 AM Bug #3579: Limiter rules causing syntax errors
Fixed in my limited (padon the pun) testing with 2.2-ALPHA (i386) built on Mon Apr 14 15:07:07 CDT 2014 Phillip Davis
01:17 PM Bug #3596: OpenVPN being passed bad arguments
Confirmed working here also. Anonymous
12:00 PM Bug #3596 (Resolved): OpenVPN being passed bad arguments
Confirmed fixed on current code (snap+gitsync), no error and the process is running. Interface is there also. Jim Pingle
12:25 PM Feature #3413 (Resolved): CARP interface names in WebGUI
This is a bit of a moot point on 2.2 as the names already appear differently and use the configured interface descrip... Jim Pingle
12:17 PM Bug #3573: tun/tap interfaces not available for assignment in 2.2
The OpenVPN interfaces do appear for assignment in current code.
For interfaces made outside of OpenVPN:
tunX in...
Jim Pingle
12:06 PM Bug #3593 (Resolved): pfSsh.php playback gitsync master not working on 2.2 ALPHA
Works OK on current snapshots (I just used it) Jim Pingle
08:56 AM Feature #3599 (Feedback): missing kernel option / kernel module in 2.2 (mount_nullfs)
Already added to kernel Renato Botelho
08:18 AM Feature #3393: AS filtering support in aliases
+1
that would be great indeed to allow, for example, filtering and policy routing by AS.
Fabrice Vincent
12:40 AM Bug #3603 (Rejected): Outbound NAT failure on Carp VIP after editing firewall rule.
this is a network problem of sorts, not a bug. continue the discussion on the forum. Chris Buechler

04/14/2014

06:05 PM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
This is broken again in 2.1.2 Christian Borchert
03:32 PM Bug #3579 (Feedback): Limiter rules causing syntax errors
Fixed please test new snapshots. Ermal Luçi
09:11 AM Bug #3603: Outbound NAT failure on Carp VIP after editing firewall rule.
If it helps;
When this problem occurs and I edit the interface, I see (on the console):
wan_vip2: 2 Link states...
Tony Rogers
05:37 AM Bug #3603 (Rejected): Outbound NAT failure on Carp VIP after editing firewall rule.
pfSense version 2.1.1-RELEASE (amd64).
Hardware: HP DL380 G5 server with on board Broadcom nics and additional HP ...
Tony Rogers

04/13/2014

03:41 PM Bug #3595 (Feedback): OpenVPN TAP/TUN <--> interface bridge not working after reeboot
This has been solved on latest 2.1 cod ein github.
If you gitsync it will solve the issues.
It will be discussed ...
Ermal Luçi
02:43 PM Bug #3595: OpenVPN TAP/TUN <--> interface bridge not working after reeboot
Issue confirmed: OpenVPN tap connection is initiated successfully, but no traffic passes through.
Affected version...
Christian Baerike
01:56 PM Feature #2960: Add queue length adjustment capabilities to traffic shaper based on network size
Actually, after some research and a better understanding of queuing, this is not practical.
Queue lengths need to ...
Shawn Iverson
10:48 AM Bug #3602 (Rejected): OpenVPN can authenticate via a broken certificate
That is correct. OpenVPN only checks that the cert is a valid cert (not expired, not revoked) from the same CA as the... Jim Pingle
07:20 AM Bug #3602: OpenVPN can authenticate via a broken certificate
I am not sure what's the bug here? AFAICT OpenVPN only tries to match user against Common Name (not SAN!) in the clie... Doktor Notor
07:37 AM Bug #3249: DHCP Server/DHCP Relay both say the other is started
I am not across the update code but the problem definitely occurred. I have just manually edited the server's /conf/c... Scott Smith

04/12/2014

08:08 PM Bug #3470: IPSec VPN not recognizing alternative IP name
Since OpenVPN accepts a certificate that was created with a common name that doesn't match the IP address to which Op... B. Derman
06:05 PM Bug #3470: IPSec VPN not recognizing alternative IP name
If you take the certificate and look at it via OpenSSL, you can clearly see the extensions are completely missing. If... Doktor Notor
01:08 PM Bug #3470: IPSec VPN not recognizing alternative IP name
#3347 claims that SANs don't work at all but, in my configuration, they do work for OpenVPN where the SAN is of type ... B. Derman
05:02 AM Bug #3470: IPSec VPN not recognizing alternative IP name
Duplicate of Bug #3347, SubjectAltNames are completely broken. Doktor Notor
08:05 PM Bug #3602 (Rejected): OpenVPN can authenticate via a broken certificate
See bug 3470 (https://redmine.pfsense.org/issues/3470). B. Derman
03:53 PM Bug #3601 (Closed): Assigning a PPP Interface failed
Assigning a PPPs Interface via Webconfigurator fails. The Link https://pfsense.localdomain/interfaces_ppps_edit.php s... Tobias Kuehn

04/11/2014

08:30 PM Bug #3598 (Resolved): AutoConfigBackup restore not working
this is resolved in the latest version of the package. Chris Buechler
07:31 PM pfSense Packages Bug #3580 (Closed): Stunnel mangled cert on upgrade
Chris Buechler
09:08 AM pfSense Packages Bug #3580: Stunnel mangled cert on upgrade
I have just upgraded to 2.1.2-RELEASE (amd64) and the certificates look fine this time so possibly something else got... jeffrey Smith
10:39 AM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
It's not a general issue currently, please post on the forum for assistance. Jim Pingle
10:38 AM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
I cannot use the auto updater via the web GUI or the CLI. I am still at 2.1 upon reboot. Gabriel Latour
07:57 AM Bug #3596: OpenVPN being passed bad arguments
I pulled this from /var/etc/openvpn/server1.conf:... Anonymous
07:02 AM pfSense Packages Bug #3600 (Rejected): Snort rules update causes 'Last config change' in Status: Dashboard
Please post in the forum to discuss and confirm before opening a bug.
You can always see what updated the configurat...
Jim Pingle
06:00 AM pfSense Packages Bug #3600 (Rejected): Snort rules update causes 'Last config change' in Status: Dashboard
I updated one of my pfSense 2.1 systems to snort pkg v 3.0.6 last night. Logging in this morning, I saw this in Statu... Toomas Aas
04:00 AM Feature #3599 (Resolved): missing kernel option / kernel module in 2.2 (mount_nullfs)
Hi there.
I understand that pfSense doesn't come with a lot of the standard (FreeBSD-GENERIC) modules and kernel o...
Dreamcat Four

04/10/2014

09:13 PM Bug #3598 (Resolved): AutoConfigBackup restore not working
It always gives an error like:
The following input errors were detected:
SHA256 values do not match, cannot r...
Phillip Davis
04:56 PM Bug #3597 (Resolved): Package reinstall on system upgrades needs some fallback handling
Lost all packages on upgrade. No idea if the process was killed or what, does not exactly matter. Result:
- Instal...
Doktor Notor
04:46 PM Bug #3592: DynDNS
Hm no, sorry, the bug must be somewhere else.
The pull i send was just a output improovement.
i think the dyndn...
Florian Asche
03:55 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Chris Buechler wrote:
> fixed.
PFSense 2.1.2 fixes CVE-2014-0160.
David Smid
02:35 PM pfSense Packages Bug #3588 (Resolved): Heartbleed bug in OpenSSL
fixed. Chris Buechler
02:26 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Frederic MEYER wrote:
> I am on 2.1 and did not upgrade to 2.1.1 (obviously waiting for 2.1.2 now...).
> Nor did I ...
David Smid
02:10 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
I am on 2.1 and did not upgrade to 2.1.1 (obviously waiting for 2.1.2 now...).
Nor did I have to reboot to see the p...
Frederic MEYER
01:56 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Frederic MEYER wrote:
> That's my point!
> So I don't understand David's output even though he claims to have updat...
David Smid
11:45 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
We're looking into a way to do that but the version numbers are controlled by the FreeBSD port versions and not direc... Jim Pingle
11:32 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Don't get me wrong, but "if the version number on the PBI file itself did not change" is just something that *never* ... Doktor Notor
10:36 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
No, but you may have to uninstall and reinstall the package if the version number on the PBI file itself did not change. Jim Pingle
10:31 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Frederic MEYER wrote:
> That's my point!
> So I don't understand David's output even though he claims to have updat...
David Smid
10:20 AM pfSense Packages Bug #3588 (Feedback): Heartbleed bug in OpenSSL
Ah, well he's looking at output without considering the wrappers. He's checking the base system and not the self-cont... Jim Pingle
10:17 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
That's my point!
So I don't understand David's output even though he claims to have updated his system.
Frederic MEYER
10:14 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
What is wrong in that output? 1.0.1g is the updated/fixed/correct version. Jim Pingle
10:11 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Correct.
And, as Jeremy said,
> "Please note that haproxy-devel seems to ship its own instance own instance of o...
Frederic MEYER
10:04 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
PBI packages are run using wrappers such that they see the libraries present inside of their own PBI dir. Checking wi... Jim Pingle
09:52 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Frederic MEYER wrote:
> FWIW, haproxy-devel package seems to have been updated a few hours ago and bumped to 1.5-dev...
David Smid
03:54 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Agreed. Not the best place.
Will look at the development forum.
Frederic MEYER
03:48 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Not really the place for a long off-topic discussion in a bug. I'll support Lane's suggestion to sign up for pfSense ... Phillip Davis
03:02 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
FWIW, haproxy-devel package seems to have been updated a few hours ago and bumped to 1.5-dev22 pkg v 0.8.
I did the ...
Frederic MEYER
02:09 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Since others are pointing me to this ticket to keep tabs I thought it best to comment with something useful.
If yo...
Lane Campbell
02:01 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
To everyone involved, is there anything we can do to assist with getting this released? Rather keen to get this patch... Ross Williamson
02:40 PM Bug #3591 (Resolved): Impossible to edit CRLs in 2.1.1
Chris Buechler
02:38 PM Bug #3585 (Resolved): CVE-2014-0160 - OpenSSL Heartbleed Bug
fixed Chris Buechler
10:20 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
FYI- 2.1.2 images are being tested now. So far, so good.
As a reminder, this bug is for Heartbleed in the base syste...
Jim Pingle
02:36 PM Bug #3596: OpenVPN being passed bad arguments
What arguments does it have after those parameters in the conf file? Chris Buechler
08:01 AM Bug #3596 (Resolved): OpenVPN being passed bad arguments
Basic OpenVPN configuration (Remote Access SSL/TLS) yields the following result in system log:
openvpn[34830]: Opt...
Anonymous
07:58 AM Bug #1629: invalid state table entries after WAN IP change
Friends, Developers
i have been doing some extensive testing on this issue yesterday evening.. yes i know ...get a l...
Tom De Coninck
02:58 AM Bug #3595 (Resolved): OpenVPN TAP/TUN <--> interface bridge not working after reeboot
After building Tap OpenVPN tunnel with bridged interfaces between 2 sites with pfsense 2.1.1
That looks like :
...
Marcin Nowak

04/09/2014

07:35 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Jim Thompson wrote:
> And you registered only today to tell us that?
>
> Hi Jim,
> I do not think comments like this ...
Sam McLeod
07:29 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Jim Thompson wrote:
> Justin Foreman wrote:
> > Agreed with Sam. I've had to make the call to disable our VPN. The ...
Justin Foreman
07:05 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
in any case, yes, this bug had to be fixed.
and while we were in there, the ECDSA bug had to be fixed (note that i...
Jim Thompson
06:59 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Note: This bug is for Heartbleed in _packages_, and many (if not all) of those have already been updated and bumped s... Jim Pingle
06:58 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Justin Foreman wrote:
> Agreed with Sam. I've had to make the call to disable our VPN. The natives are getting restl...
Jim Thompson
06:56 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
We know its vulnerable, but for what its worth.. I have tested the POC available here: https://gist.github.com/mpdavi... Josh Cavalier
06:55 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
The release will be done when its done.
I release involves some 80+ variants all of which have to be built.
Build...
Jeremy Porter
06:45 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Agreed with Sam. I've had to make the call to disable our VPN. The natives are getting restless. This is a *security*... Justin Foreman
05:49 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Any update with this?
It's pretty critical...
Sam McLeod
06:23 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Guys, can someone fix the CRLs in 2.1.1 *before* releasing 2.1.2? A LOT of people will want/need to revoke certificat... Doktor Notor
04:52 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
When will haproxy-devel be available as a separate update? This would solve my problem. David Smid
04:29 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
I don't know more than you, but once Chris and the US wakes up, by the look of the above. ie sometime on Apr 9: US ti... Oliver Schonrock
04:27 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Is there any ETA on new release? A realistic one, not 1 hour then 10+ :)
I need to patch but I'd rather wait and ...
Arr0way .
04:15 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Phil Jaenke wrote:
> Lot's of PolarSSL stuff and about how awesome it is ....
Don't think a bug report is the r...
Oliver Loch
05:35 PM Bug #3594 (Resolved): Captive portal inconsistancy - "Allowed IP addresses" vs "Allowed Hostnames"
When editing an entry under Services --> Captive Portal --> Allowed IP Addresses
the note on screen refers to dire...
Criggie .
03:57 PM Bug #3593 (Resolved): pfSsh.php playback gitsync master not working on 2.2 ALPHA
pull request pushed with a fix.
https://github.com/pfsense/pfsense/pull/1072
Marcello Silva Coutinho
03:54 PM Bug #3569: pkg_edit.php jquery 'add' and 'delete' action scrolls page to top.
Pull request merged to 2.2 and 2.1 branch.
Marcello Silva Coutinho
12:24 PM Bug #3592 (Rejected): DynDNS
Hi Guys,
the RFC 2136 Update Script didnt work right.
It sends again and again a mail "DynDNS updated IP Address ...
Florian Asche
08:32 AM Bug #3591: Impossible to edit CRLs in 2.1.1
OK, fix works, thanks. It is indeed correct that starting with a completely new CA is best solution in this case, but... Doktor Notor
08:00 AM Bug #3591: Impossible to edit CRLs in 2.1.1
Applied in changeset commit:80f48850307dea4ceb08dc1a785dd24322b5283d. Jim Pingle
08:00 AM Bug #3591 (Feedback): Impossible to edit CRLs in 2.1.1
Applied in changeset commit:d22169cfd68a26c04ca6d1aa997575f1b3e4cc80. Jim Pingle
07:48 AM Bug #3591: Impossible to edit CRLs in 2.1.1
A fix is coming but ideally you'd create a whole new CA and Cert structure if you believe yours has been compromised.... Jim Pingle
06:30 AM Bug #3591 (Resolved): Impossible to edit CRLs in 2.1.1
See https://forum.pfsense.org/index.php?topic=74935.msg408977#msg408977
Since lots of people will want/need to rev...
Doktor Notor
05:27 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
Unfortunately.
Check the https://redmine.pfsense.org/issues/3588 to watch the progress.
Frederic MEYER
05:26 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
that's true only for the base system.
but several packages including lighttpd for the webfrontend use /usr/local/...
Oliver Schonrock
05:25 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
OK, my fault: find / -type f -name 'openssl' -exec \{\} version \;
>OpenSSL 1.0.1e 11 Feb 2013
>OpenSSL 0.9.8y 5 Fe...
Nils Bernhardt
05:19 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
PFsense 2.1 uses openssl 0.9.8y, which is NOT VULNERABLE. Nils Bernhardt

04/08/2014

10:11 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Please note that haproxy-devel seems to ship its own instance own instance of openssl, so will need to be reviewed as... Jeremy B
08:53 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Chris Buechler wrote:
> "actually been audited", "has a vastly better track record"? Uh, no. OpenSSL has had a lot m...
Phil Jaenke
06:29 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
oh that. 1 hour, hah! I wish. We've burned easily 20+ man hours in the last day on this. Chris Buechler
06:27 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
nothing says "1 hour", it takes 4-5 times that long just to build a release, much less actually test it and push it o... Chris Buechler
06:16 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Revised time estimate? Says "1 hour" up top, which strikes me as overly optimistic.
Thanks,
-danny
Daniel Howard
06:10 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
"actually been audited", "has a vastly better track record"? Uh, no. OpenSSL has had a lot more eyes on it than Polar... Chris Buechler
02:20 PM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
At this point, I would vastly prefer to see OpenSSL kicked to the curb as unceremoniously as possible in favor of Pol... Phil Jaenke
11:15 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Not exactly. The problem in packages is distinct from the one in base. The base firmware update won't fix package and... Jim Pingle
11:12 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
Additionally, already reported in #3585 Doktor Notor
10:42 AM pfSense Packages Bug #3588: Heartbleed bug in OpenSSL
It's known and we're already working on it. Jim Pingle
10:35 AM pfSense Packages Bug #3588 (Resolved): Heartbleed bug in OpenSSL
http://heartbleed.com reports a serious defect in OpenSSL 1.0.1 that has been fixed in 1.0.1g
haproxy is vulnerable.
David Smid
05:14 PM pfSense Packages Bug #3590 (Resolved): Snort package missing
fixed Chris Buechler
01:52 PM pfSense Packages Bug #3590 (Resolved): Snort package missing
When attempting to install snort from PFsense, the package is missing from the repo.
Beginning package installatio...
Adriel Desautels
11:50 AM Feature #3589 (Resolved): OpenVPN client: GUI option for "route-nopull"
The current OpenVPN client has no GUI option corresponding to the "route-nopull" argument. This is definitely an opt... Dan Matsuma
09:21 AM Bug #3587 (Resolved): postfix packag requires pfSense 2.1
After latest commits, this requires features only available on 2.1.x, like IPv6 stuff. Ref: https://forum.pfsense.org... Doktor Notor
09:07 AM Bug #3585: CVE-2014-0160 - OpenSSL Heartbleed Bug
+1111111 Steve Thomas
04:32 AM Bug #3585 (Resolved): CVE-2014-0160 - OpenSSL Heartbleed Bug
Marking as urgent, see http://heartbleed.com/ Doktor Notor
08:27 AM Bug #3586 (Rejected): Gateway monitoring issue when 2 PPPoE WANs share the same gateway
Hi,
I have 2 DSL connections plugged into my Pfsense. I use 2 PPPoE interface in Pfsense to establish the link.
...
Mathieu Déom
05:53 AM pfSense Packages Bug #3584: arpwatch package fails to start in pfsense 2.1.1
Thanks for the quick response which was right on the spot.
I made the proposed change to /usr/local/pkg/arpwatch.xml...
Max Frames
04:36 AM pfSense Packages Bug #3584: arpwatch package fails to start in pfsense 2.1.1
This recent commit introduced those quotes to the arpwatch package: https://github.com/pfsense/pfsense-packages/commi... Phillip Davis
02:11 AM pfSense Packages Bug #3584 (Resolved): arpwatch package fails to start in pfsense 2.1.1
I'm not sure if this is a bug with arpwatch or with pfsense 2.1.1, it did not happen in pfsense 2.1 though, with the ... Max Frames
01:05 AM pfSense Packages Feature #3583 (Closed): haproxy-devel: individual backend for each acl
To define several backends based on acl's for one frontend a backend selection iten is recommended for each acl - cur... Andreas Morf

04/07/2014

11:27 PM Bug #3582 (Closed): webConfigurator redirect rule not working
Chris Buechler
10:16 PM Bug #3582: webConfigurator redirect rule not working
RESOLVED
Not a pfSense issue, errors experienced only on clients running Windows 8
James Morgan
09:36 PM Bug #3582 (Closed): webConfigurator redirect rule not working
after updating from 2.1 to 2.1.1, the port 80 redirect to a listening port of 4434 for HTTPS failed, redirects to 443... James Morgan
07:00 PM Bug #1629: invalid state table entries after WAN IP change
I'm still experiencing this issue with pfsense 2.1 on an ALIX platform and an Cisco SPA112 ATA.
pfsense is configure...
Andy Lawson
06:52 PM Bug #3573: tun/tap interfaces not available for assignment in 2.2
tun and tap interfaces should be available for assignment, whether tunX/tapX or ovpnsX/ovpncX. Chris Buechler
12:45 PM Bug #3575: OPT interfaces on GRE tunnels do not accept IPv6 or IPv4 addresses to be set.
GRE addresses should be configured only on the GRE itself, not its assigned interface. Sounds like this is the proper... Chris Buechler
12:40 PM Bug #3581 (Rejected): Create Option to either password protech just 1 option or remove it from the console.
Password protecting the console doesn't disable ctrl-alt-del to reboot. Chris Buechler
09:41 AM Bug #3581: Create Option to either password protech just 1 option or remove it from the console.
And then you also accidentally pressed Y? ... Doktor Notor
08:29 AM Bug #3581 (Rejected): Create Option to either password protech just 1 option or remove it from the console.
We have had issue with instead of rebooting they will hit option 4) Reset to factory default. That option need to be... Robert Middleswarth
12:31 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
hi,
I have similar trouble but on almost all interface VLAN and not VLAN in 2.1.1 x64
Information for SNMP are fals...
xavier Lemaire
07:43 AM Bug #742: apinger doesn't recover opt wan when connection returns.
Chris Buechler wrote:
> It's not that easy to replicate, none of mine do that. What kind of WANs?
on my system th...
Sharif Al Motawally
07:12 AM pfSense Packages Bug #3580: Stunnel mangled cert on upgrade
https://forum.pfsense.org/index.php?topic=60009.msg322825#msg322825
I raised the above post on the forum over a ye...
jeffrey Smith
06:31 AM pfSense Packages Bug #3580 (Closed): Stunnel mangled cert on upgrade
I had pfsense 2.1 installed with stunnel 4.43 installed and added a certificate.
I upgraded to 2.1.1-RELEASE(amd64...
jeffrey Smith
06:04 AM Bug #3572: Can't set IPv6 gateway
Hello,
I use a Sixxs tunnel. I found my fault. The Subnet Mask of the GIF-Interface must set to 128. Then the GW w...
Samuel Schmidt
02:35 AM Bug #3572 (Rejected): Can't set IPv6 gateway
not a bug Chris Buechler
04:00 AM Bug #3062: Captive Portal NOT re-using PIPENO
The patch was merged Dsi. Ermal Luçi
03:18 AM Bug #3062: Captive Portal NOT re-using PIPENO
When a user is already authenticated and re-send an authentication, a new pipeno is created (function radius). The al... Dsi Unicaen
02:34 AM Bug #3578 (Rejected): Upgrade from 2.1 to 2.1.1 causes Fatal trap 12 - 0x4c
not a replicable issue Chris Buechler
02:31 AM Bug #3571 (Resolved): Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
was fixed yesterday Chris Buechler

04/06/2014

09:13 PM Bug #3544: Inbound IPv6 connections over PPPoE, replies do not route through the tunnel.
I have just upgraded to
@2.1.1-RELEASE (i386)
built on Tue Apr 1 15:27:01 EDT 2014
FreeBSD 8.3-RELEASE-p14@
a...
Criggie .
12:55 PM Bug #3579 (Resolved): Limiter rules causing syntax errors
Creating and applying a limiter rule in 2.2 causes an error similar to the below:
There were error(s) loading the ...
Anonymous
12:00 PM Bug #3577 (Feedback): SMTP Notifications not working when using SMTPS
Applied in changeset commit:d269747b358f6e8f844e88d39fe36b8f33343d24. Warren Baker
06:19 AM Bug #3577 (Resolved): SMTP Notifications not working when using SMTPS
h3. Configuration:
* E-Mail server: example.com
* SMTP Port of E-Mail server: 2525
* Secure SMTP Connection: Ena...
Anonymous
07:08 AM Bug #3578: Upgrade from 2.1 to 2.1.1 causes Fatal trap 12 - 0x4c
Removing the virtual CDROM from the settings allows it to boot correctly. Anonymous
06:51 AM Bug #3578 (Rejected): Upgrade from 2.1 to 2.1.1 causes Fatal trap 12 - 0x4c
Host: Oracle VM Virtualbox @ Windows 7
Steps: Upgrade via web interface, seems successful and reboots automaticly.
...
Anonymous

04/05/2014

09:13 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
I am currently seeing this issue without VLANs. 2.1.1 64-bit
Jason Litka
02:22 PM Bug #3576 (Resolved): Console upgrade automatically skips hash check if no hash file found
When performing an upgrade via the console, if no hash file for the downloaded image is found at the expected locatio... Daniel Becker
01:21 PM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
FWIW, doing a command line upgrade (with ".img.gz" removed from the default URL) seems to have worked fine. It did ju... Daniel Becker
09:17 AM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
Certainly *NOT* fixed. Doktor Notor
03:56 AM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
The file names of the images at http://updates.pfsense.org/_updaters/amd64 still seem to be messed up (missing the .i... Daniel Becker
12:47 AM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
"The image file is corrupt. Update cannot continue" Daniel Becker
12:34 AM Bug #3571 (Feedback): Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
I'm going through and testing now to fully confirm, but should be ok. If you can also confirm that'd be appreciated. Chris Buechler
12:12 PM Bug #3575: OPT interfaces on GRE tunnels do not accept IPv6 or IPv4 addresses to be set.
This applies to 2.1.1, it worked on 2.1. Mix Room
12:07 PM Bug #3575 (Resolved): OPT interfaces on GRE tunnels do not accept IPv6 or IPv4 addresses to be set.
I have set up a GRE tunnel over an IPSec tunnel. I can ping the IPv4 end-points with no problem.
I have added an ...
Mix Room
08:43 AM Bug #3572: Can't set IPv6 gateway
Are you creating a tunnel? See #3484 - you should just leave the GW as dynamic instead of creating one manually. Doktor Notor
05:57 AM Bug #3572: Can't set IPv6 gateway
I'm on pfsense 2.1.1 Samuel Schmidt
05:51 AM Bug #3572 (Rejected): Can't set IPv6 gateway
Hello,
when i set a „IPv6 Upstream Gateway“ with the link „or add a new one“ on the Interface GUI. It works fine! ...
Samuel Schmidt
07:43 AM Bug #3573 (Closed): tun/tap interfaces not available for assignment in 2.2
Version 2.2 Alpha options not create virtual interface.
Pfsense Version 2.1.1 is possible create virtual interface u...
Gilmar Cabral

04/04/2014

10:10 PM Bug #3570 (Rejected): Configuring OPT1 interface IPV4 create IPV6 route Pfsense 2.1.1
no apparent bug here, please post to the forum or list for assistance. Chris Buechler
01:12 PM Bug #3570 (Rejected): Configuring OPT1 interface IPV4 create IPV6 route Pfsense 2.1.1
In pfsense 2.1.1 setup creates an interface OPT1 only ipv4 ipv6 route is created automatically.
Attached Images
Gilmar Cabral
10:01 PM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
that's my bad, fixing it right now. Chris Buechler
09:56 PM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
Comparing to the listing in http://updates.pfsense.org/_updaters/ (without amd64), I noticed another oddity: The amd6... Daniel Becker
09:44 PM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
Also, for some reason, there appear to be two sets of identically named copies of the hash files for the NanoBSD imag... Daniel Becker
09:42 PM Bug #3571: Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
Looking at http://updates.pfsense.org/_updaters/amd64/ in a browser, I noticed that all the NanoBSD images have a tim... Daniel Becker
09:38 PM Bug #3571 (Resolved): Upgrade from 2.1-RELEASE to 2.1.1-RELEASE on NanoBSD/4G/amd64 results in system still being at 2.1-RELEASE
I've gone through the update wizard in the web interface twice now on my NanoBSD/4G/amd64 system, and I keep ending u... Daniel Becker
07:58 AM Bug #3569 (Resolved): pkg_edit.php jquery 'add' and 'delete' action scrolls page to top.
On packages that uses row_helper when user clicks on add or delete button, the page scrolls to top.
It seems somet...
Marcello Silva Coutinho
06:51 AM pfSense Packages Bug #3565 (Rejected): package blinkLED not working on the APU1C board from PC Engines
We don't have FreeBSD drivers for the APU LEDs generally available yet. There isn't anything the package can do about... Jim Pingle
01:09 AM pfSense Packages Bug #3565 (Rejected): package blinkLED not working on the APU1C board from PC Engines
Install is done correctly.
blinkLED process cannot start.
Apr 4 08:09:42 php: /pkg_edit.php: The command '/usr/lo...
Nicolas Scheffer
06:50 AM pfSense Packages Bug #3564 (Rejected): package gwled not working on the APU1C board from PC Engines
We don't have FreeBSD drivers for the APU LEDs generally available yet. There isn't anything the package can do about... Jim Pingle
01:01 AM pfSense Packages Bug #3564 (Rejected): package gwled not working on the APU1C board from PC Engines
Install is done correctly.
gwled process cannot start.
Apr 4 08:02:33 php: /pkg_edit.php: New alert found: An err...
Nicolas Scheffer
06:45 AM Bug #3568 (Resolved): DynDNS: Hostname '@' not accepted for Namecheap
When you try to create a dynamic DNS entry for '@' as per Namecheap's DNS configuration, pfSense gives an error "The ... Anonymous
03:14 AM Feature #3567 (Resolved): Option to disable NTP
At the moment the only way I can find to stop ntpd is working is put some invalid value in the ntp server field.
I...
Fred Cox
02:35 AM Bug #3566: Gateway monitoring 6TO4 Bug
Sorry, it's working now !
Still a newbie with pfSense....
Nicolas Scheffer
02:28 AM Bug #3566 (Rejected): Gateway monitoring 6TO4 Bug
set monitor IP to something that will respond to pings. Doesn't look like a bug Chris Buechler
01:39 AM Bug #3566 (Rejected): Gateway monitoring 6TO4 Bug
I am using an APU1C board from PC Engines running pfSense (was 2.1 and 2.1.1 since this morning with the same result)... Nicolas Scheffer

04/03/2014

05:49 PM Bug #3074 (Resolved): DHCPv6 traffic blocked on LAN with DHCPv6 relay enabled
Chris Buechler
05:44 PM Bug #3562 (Feedback): Wireless Radius Setup Fails - partially due to empty config strings
Chris Buechler

04/02/2014

07:53 AM pfSense Packages Bug #2581: Snort unexpectedly terminates / signal 11 error
Hi All. I found that snort builded for pfsense have one nasty future. All your rulse must have classtype specified. A... Dmitry Aleksandrov

04/01/2014

08:28 PM Bug #3563 (Feedback): Wireless reconfig generates unnecessary error
should be what Phil noted there, already fixed in 2.1.1. Chris Buechler
07:53 PM Bug #3563: Wireless reconfig generates unnecessary error
This sort of thing was fixed here https://github.com/pfsense/pfsense/commit/0d8fc8ec415ace48f7963b83224fc8ee186c9a48 ... Phillip Davis
11:21 AM Bug #3563 (Resolved): Wireless reconfig generates unnecessary error
While debugging some WPA2 Enterprise issues I kept getting an error:
php: /interfaces.php The command '/sbin/ifcon...
not george
07:31 PM Bug #3562: Wireless Radius Setup Fails - partially due to empty config strings
Are you testing with 2.1.1 snapshots? It looks like this is fixed by https://github.com/pfsense/pfsense/commit/26ea40... Phillip Davis
11:15 AM Bug #3562 (Resolved): Wireless Radius Setup Fails - partially due to empty config strings
Been trying to get WPA2-Enterprise with freeradius auth setup with an onboard wireless interface. The settings were ... not george
01:15 PM Bug #3557 (Feedback): module runfw.ko is missing in 2.2 alpha
I enabled it again, should be fine on next snapshots Renato Botelho
01:39 AM Bug #3561 (Resolved): PPTP VPN broken without RADIUS - always requires RADIUS server configuration.
Upgrading from 1.2.3 to 2.1 and importing config, that includes PPTP VPN, I had problems with bringing it up, because... Jānis Veinbergs

03/31/2014

05:03 PM Bug #3182: VMware vmxnet interfaces are not detected as VLAN capable
ifconfig list caps shouldn't be used any longer. Case in point, also doesn't work for em(4) on 10.0-RELEASE. Should c... Phil Jaenke
04:28 PM Bug #3549: Reported issues with VMware guests on ESX 5.1 patch 201402001
Concur on leaving it as monitoring for now, since it's self-corrected. The calcru issues have been around since first... Phil Jaenke
03:05 PM Bug #3555 (Resolved): Editing firewall schedules is seriously buggy
Thanks Renato Botelho
02:47 PM Bug #3555: Editing firewall schedules is seriously buggy
Fixed in Chrome and IE as well here. Thanks! Doktor Notor
02:40 PM Bug #3555: Editing firewall schedules is seriously buggy
Applied in changeset commit:2def89a2ddff8d7183a03c385fba8394c5bbf08e. Renato Botelho
02:40 PM Bug #3555 (Feedback): Editing firewall schedules is seriously buggy
Applied in changeset commit:5c757d82d84c5363cd5c3d1b3df7d8bf1c641388. Renato Botelho
02:23 PM Bug #3555 (New): Editing firewall schedules is seriously buggy
On Chrome I was able to replicate, will work on a fix Renato Botelho
02:19 PM Bug #3555: Editing firewall schedules is seriously buggy
Well, that one is broken at least in Chrome 33+ and IE11. Does not happen in FF (27/28). Doktor Notor
02:11 PM Bug #3555: Editing firewall schedules is seriously buggy
I couldn't replicate this one, what browser/version are you using? Renato Botelho
02:06 PM Bug #3555: Editing firewall schedules is seriously buggy
OK, after gitsync, all fixed except for the issue described in the last comment. Doktor Notor
08:00 AM Bug #3555 (Feedback): Editing firewall schedules is seriously buggy
Applied in changeset commit:02b29d72f91d5fe4e9d9a2d4a4f7be3b4db119a1. Renato Botelho
01:24 PM Bug #3560: Disabled Static Route not fully disabled
After doing testing, I deleted my static route. But there was no subsystem-dirty prompt to apply the change. The pf r... Phillip Davis
01:18 PM Bug #3560: Disabled Static Route not fully disabled
I didn't bother putting a target version on this, IMHO I wouldn't hold up any release for this! The simple workaround... Phillip Davis
01:05 PM Bug #3560 (Resolved): Disabled Static Route not fully disabled
Add a gateway to an internal router behind LAN. Add a static route to some private IPv4 subnet behind that gateway. A... Phillip Davis
09:28 AM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
This should fix it: https://github.com/pfsense/pfsense/pull/1043 Per von Zweigbergk
07:11 AM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
I'm going to see if I can't just make a fix for this myself. Per von Zweigbergk
07:06 AM Bug #1681 (New): OpenVPN tun IPs fail HTTP REFERER checks
Jim Pingle
05:29 AM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
This bug has not been correctly resolved, as tested with pfSense 2.1-RELEASE.
The changeset listed earlier does re...
Per von Zweigbergk
03:26 AM Bug #3518: Sometimes DHCP hostname registration does not work for a newly registered host
Unfortunately, i don't have other deployment or replication method. I am suspecting that maybe one of the hostnames t... Florent Thiery
01:09 AM Bug #3558: Schedule States in System - Advanced - Misc not working
Best thing would be to add a checkbox to the firewall rules "reset state(s) when activated".
This would also resolve...
Dig dug3

03/30/2014

10:07 PM Bug #3447: pfSense 2.1 Captive Portal RADIUS Accouting records not sent to RADIUS Server
should be fixed in 2.1.1 but will leave for feedback for now. Chris Buechler
10:04 PM Bug #3545: OpenVPN Clients don't reconnect after dynamic WAN IPv4 changes
The subject isn't true in all cases at least. Needs testing to see if it's replicable and find the actual specific ca... Chris Buechler
09:54 PM Bug #3519: IPv6 - Dynamic IPv6-prefix - After reconnect no new IPv6 prefix
needs testing to see if it's replicable, and find the actual specific issue if so. Chris Buechler
09:51 PM Bug #3518 (Feedback): Sometimes DHCP hostname registration does not work for a newly registered host
Generally speaking, it works. Do you have a specific scenario where it's replicable? Chris Buechler
09:48 PM Bug #3549: Reported issues with VMware guests on ESX 5.1 patch 201402001
A timing issue causing a variety of other issues is definitely a more likely cause if you were getting calcru runtime... Chris Buechler
09:23 PM Feature #3559 (Resolved): add option for backup ddns ( dynamic dns ) in restore area
add option for backup ddns ( dynamic dns ) in restore area
ty
hugs
Luis Couto
03:40 AM Bug #3558 (Resolved): Schedule States in System - Advanced - Misc not working
Simply does not work, the states of existing connections are *NOT* cleared on expiration time
https://forum.pfsen...
Doktor Notor
03:04 AM Bug #3557 (Resolved): module runfw.ko is missing in 2.2 alpha
As Jimp propose i open a ticket about this little problem.
https://forum.pfsense.org/index.php?topic=74293.msg406140
xavier Lemaire

03/29/2014

08:23 AM Bug #3556: WAN interface status missing data for pppoe ipv6 connection
Forgot to mention that the interface widget on the dashboard is also missing IPv6 information for the interface. I ... Adrien Carlyle
08:21 AM Bug #3556 (Resolved): WAN interface status missing data for pppoe ipv6 connection
When looking at status -> interfaces data is missing for WAN connection with native IPv6 over pppoe.
Web interfa...
Adrien Carlyle
06:02 AM Bug #3555: Editing firewall schedules is seriously buggy
And yet another one. When you select Start Time ending with 00 Min, click Add Time, the Min dropdown gets empty, then... Doktor Notor
05:53 AM Bug #3555: Editing firewall schedules is seriously buggy
Additionally, upon deleting the buggy schedule (example two above), the selected days stays selected, however when yo... Doktor Notor
05:47 AM Bug #3555 (Resolved): Editing firewall schedules is seriously buggy
Forum thread: https://forum.pfsense.org/index.php?topic=74101.0
Even after some previous fixes
- clicking edit on...
Doktor Notor
01:21 AM Bug #3549: Reported issues with VMware guests on ESX 5.1 patch 201402001
Yep, on both hosts - related (and very relevant) VMware KB is 2072654 and 2072652: http://kb.vmware.com/selfservice/m... Phil Jaenke
12:04 AM Bug #3549: Reported issues with VMware guests on ESX 5.1 patch 201402001
Is it strictly ESX 5.1 with update 201402001? Chris Buechler

03/28/2014

08:29 PM Bug #3549: Reported issues with VMware guests on ESX 5.1 patch 201402001
I have two physical boxes reproducing this, so yes, it is legit. I agree there doesn't seem to be any change that wou... Phil Jaenke
08:04 PM Bug #3549 (Feedback): Reported issues with VMware guests on ESX 5.1 patch 201402001
not seeing anything along those lines, nor is anyone else it appears. The supposed introduction dates have no even re... Chris Buechler
11:21 AM Bug #3554: apinger and OpenVPN: Gateway down after OpenVPN client service restart
Hi,
it seems to happen, if the openvpn interface comes up but encounters an error: in my configuration, a route ad...
Cullen Trey
07:48 AM Bug #3554 (Closed): apinger and OpenVPN: Gateway down after OpenVPN client service restart
Hi,
when i restart the OpenVPN client service, which has an interface assigned, the correspondig gateway is going ...
Cullen Trey
06:56 AM Feature #3553 (Rejected): Multi Wan FTP Server
I've read the forums and on some sites that the pfsense (specifically ftp-proxy) can not handle external connections ... Kelsen Cristiano P.de Faria
04:03 AM Feature #3552 (New): Allow configuring link keep-alive value in PPP
Please give us one more option to edit the PPPoE Connection for the WAN Interface
set link keep-alive 10 60
i...
Claudius Badmind
02:33 AM Feature #3551 (Rejected): add option for select multiples types of backup
if you need more than one config area, you should just backup the entire config. You can always split things out manu... Chris Buechler

03/27/2014

10:48 PM Feature #3551 (Rejected): add option for select multiples types of backup
maybe a control for select + them 1
sorry bad english
thanks
Luis Couto
05:21 PM Bug #715: RRD Graph on Throughput Contains No Info
Overand: has absolutely nothing to do with this ticket, please post to the forum or list with more specifics. Chris Buechler
04:13 PM Bug #3550 (Resolved): [IPv6] wizard not pointing to the right IPv6 address after first setup.
*pfSense-LiveCD-2.2-ALPHA-i386-20140327-0415*
* fresh installed as a guest OS into a linux-based machine using virtu...
Vinícius Zavam
04:12 PM Bug #3549 (Closed): Reported issues with VMware guests on ESX 5.1 patch 201402001
I can't find the commit that did it, but I've confirmed it on two hosts with four installs of 2.1.1-PRE using snapsho... Phil Jaenke
12:43 PM Bug #3548 (Resolved): Diagnostics - Backup/Restore - Reinstall Packages does nothing useful
Renato Botelho
12:40 PM Bug #3548: Diagnostics - Backup/Restore - Reinstall Packages does nothing useful
Fixed, thanks. Doktor Notor
09:20 AM Bug #3548: Diagnostics - Backup/Restore - Reinstall Packages does nothing useful
Applied in changeset commit:544a89c5d12228374b873fda0096f2b4f01f3503. Jim Pingle
09:20 AM Bug #3548 (Feedback): Diagnostics - Backup/Restore - Reinstall Packages does nothing useful
Applied in changeset commit:013b4695d00a8bced4dff8693b1487bfa9013573. Jim Pingle
04:16 AM Bug #3548 (Resolved): Diagnostics - Backup/Restore - Reinstall Packages does nothing useful
Regression: Diagnostics - Backup/Restore - Reinstall Packages used to reinstall everything with one click. While the ... Doktor Notor
10:00 AM pfSense Packages Bug #3527: NRPEv2 package distributing empty xml and missing files
Using 'fetch -4' results in similar behavior, but a different error:
@/root(4): fetch -4 https://packages.pfsense....
Gyles Garber

03/26/2014

11:35 PM Bug #3547 (Closed): When using LDAP Groups, user is authenticated and granted xauth ipsec irrespective of group permissions
When using LDAP Groups for IPSec auth, user is authenticated and granted x-auth IPSec access when the user is in no g... Ignat Esso
01:52 PM Bug #715: RRD Graph on Throughput Contains No Info
Just going to note here, I do *not* find this to be resolved in this corner case:
pfSense 2.0 on 32 bit (hardware)...
Overand IRC-Priv
01:59 AM Feature #3546 (Resolved): AWS EC2 User data option to permit RFC1918 addresses on WAN interface
Using the current pfSense AWS AMI (ami-6fdf4055), it is not currently possible to connect to a pfsense firewall that ... tall tree

03/25/2014

07:20 PM Bug #3176: Hosts file corrupted when using "Register DHCP leases in DNS forwarder"
I am unfamiliar with this forum so I apologize for my messed up formatting. Andrew Newell
07:19 PM Bug #3176: Hosts file corrupted when using "Register DHCP leases in DNS forwarder"
Sorry, I don't have much to add as far as content, but I would like to say that my pfSense box has had the same behav... Andrew Newell
10:08 AM Bug #3545 (Rejected): OpenVPN Clients don't reconnect after dynamic WAN IPv4 changes
Some times, when the ISP changes the WAN IP address and pfSense reconnects to Internet, the OpenVPN client connection... Muchacha Grande
09:57 AM Bug #3528 (Resolved): Internally generated automatic outbound NAT rules not the same as those generated when Manual is clicked
Renato Botelho
09:57 AM Bug #3538 (Resolved): CaptivePortal passthrumac delete captiveportal_get_ipfw_passthru_ruleno and captiveportal_get_dn_passthru_ruleno functions
Renato Botelho
09:55 AM Bug #3337 (Resolved): Dashboard Thermal Sensors use "unfriendly names" for Core >= 4
Renato Botelho

03/24/2014

09:47 PM Bug #3544: Inbound IPv6 connections over PPPoE, replies do not route through the tunnel.
Well that was messed up - sorry here's the better one... Criggie .
09:12 PM Bug #3544: Inbound IPv6 connections over PPPoE, replies do not route through the tunnel.
As requested:
[2.1.1-PRERELEASE][root@pfsense.criggie.org.nz]/root(1): ndp -na
Neighbor ...
Criggie .
05:17 PM Bug #3544: Inbound IPv6 connections over PPPoE, replies do not route through the tunnel.
Can you show the ouput of the command ... Ermal Luçi
05:02 PM Bug #3544 (Resolved): Inbound IPv6 connections over PPPoE, replies do not route through the tunnel.
Short version - I have a PPPoE link from my ISP, which is delivered tagged as VLAN 10 by the local telco.
Outbound...
Criggie .
04:57 PM Bug #3540 (Feedback): 100% CPU-Issue when IPv6 DHCP with stateless addresses is active
Ermal Luçi
04:57 PM Bug #3540: 100% CPU-Issue when IPv6 DHCP with stateless addresses is active
This needs to be confirmed again when the 2.2 snapshots are active. Ermal Luçi
04:55 PM Bug #3350 (Feedback): Disabling and enabling VLAN leaves VLAN interface missing
This should be fixed already by me since long now. Ermal Luçi
04:54 PM Bug #3297: IPsec log parsing code does not skip disabled Phase 1 entries
Now you can identify the related logs with the connection name.
So this should be a less of an issue.
The page of...
Ermal Luçi
04:47 PM Feature #2151 (Feedback): Add IPv6 support to the pfSense module
This has been completed for the addresses part. Ermal Luçi
04:44 PM Bug #2122 (Closed): pf log output slightly different in FreeBSD 10
A different implementation has been performed to not depend on this anymore. Ermal Luçi
03:42 PM Bug #3543 (Resolved): Typo in /etc/inc/captiveportal.inc
Corrected thanks. Ermal Luçi
03:31 PM Bug #3543 (Resolved): Typo in /etc/inc/captiveportal.inc
Regarding latest two commits:... Doktor Notor
02:59 PM pfSense Packages Feature #3303: Allow quagga ospf stub, not so stub and totally stub areas
Peter Allgeyer wrote:
> I've implemented it, patch attached.
Thanks for that. Will this fix be available in the n...
Andre Luiz Paiz
02:27 PM pfSense Packages Feature #3303: Allow quagga ospf stub, not so stub and totally stub areas
Please send it as using github pull request on https://github.com/pfsense/pfsense-packages repo Renato Botelho
10:56 AM pfSense Packages Feature #3303: Allow quagga ospf stub, not so stub and totally stub areas
I've implemented it, patch attached. Peter Allgeyer
02:30 PM Bug #3538: CaptivePortal passthrumac delete captiveportal_get_ipfw_passthru_ruleno and captiveportal_get_dn_passthru_ruleno functions
Applied in changeset commit:dae77fe374ebaf1f97d2835ef0f52daff3b26be9. Renato Botelho
02:30 PM Bug #3538 (Feedback): CaptivePortal passthrumac delete captiveportal_get_ipfw_passthru_ruleno and captiveportal_get_dn_passthru_ruleno functions
Applied in changeset commit:c4fb986b27a6b6e81d7605ae48eda169a7d680cf. Renato Botelho
12:10 PM Bug #3353 (Resolved): Changing IPv6 from None to DHCP6 or vice-versa causes a panic+reboot
This works fine now. I can run through the wizard and also change WAN from DHCP6 to none, apply, change it back to DH... Jim Pingle
10:22 AM Bug #3535: Selecting "LAN" as "WAN" in Multi-WAN Traffic Shaper wizard breaks the ruleset
Fixing description and pushing to 2.2. Jim Pingle
02:57 AM Bug #3542: cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name
Pull request 1034:
https://github.com/pfsense/pfsense/pull/1034
Vladimir Voskoboynikov
02:42 AM Bug #3542 (Resolved): cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name
cert_get_issuer() doesn't work properly when a certificate's issuer has several attributes of the same type.
e.g.
...
Vladimir Voskoboynikov

03/23/2014

08:13 PM Feature #3508: DNS Lookup - Additional links

The following *+additional+* lookups would be beneficial for *Mail Server* users.
SenderScore
Spamhaus Blocklis...
BBcan177 .

03/22/2014

07:00 AM Bug #3200: IPv6 bugs
Mar 22 13:03:30 wan php: rc.newwanipv6: rc.newwanipv6: Failed to update wan IPv6, restarting...
Mar 22 13:03:32 wa...
Wouter Snels
06:36 AM Bug #3200: IPv6 bugs
Maybe this is usefull..... Wouter Snels
06:19 AM Bug #3200: IPv6 bugs
... Wouter Snels
06:16 AM Bug #3200: IPv6 bugs
It is still valid... Wouter Snels
06:03 AM Feature #3541 (Closed): Add "Stateless DHCP" to Router Advertisements
Renato Botelho

03/21/2014

11:27 PM Feature #3541: Add "Stateless DHCP" to Router Advertisements
Please delete this request. I have figured out how to use Github pull request and submitted a pull request to have my... Aqueeb Qadri
06:45 PM Feature #3541 (Closed): Add "Stateless DHCP" to Router Advertisements
Hi,
I just wanted to add Stateless DHCP as an option to the drop down list of Router Advertisement modes. Its a fa...
Aqueeb Qadri
10:29 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
On 2.2 the default DNS Resolver will be Unbound, so you may want to test using that package and if the behavior is st... Jim Pingle
10:27 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Jim, Chris and Doktor Notor,
Thanks for all your focus here. It has led to a discovery and a suggested change to ...
Harry Coin
08:50 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
All pointing to pfSense for DNS (hostnames replaced with OS):
Pointing to my edge router (127.0.0.1 localhos...
Jim Pingle
08:47 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Afraid we'd have to go back to "fix your domain to NOT use .local", or fix your Debian/Ubuntu boxes. Since:... Doktor Notor
08:38 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Doktor Notor, if it was just my little box I would be pleased to do as you suggest.
However in situations where pe...
Harry Coin
08:26 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Well, now, let's see, what the braindead script does:... Doktor Notor
08:24 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
To Chris's point:
root@server1:~# host -t SOA local. 8.8.8.8
Using domain server:
Name: 8.8.8.8
Address: 8.8....
Harry Coin
08:08 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Is the response:
root@server1:~# host -t SOA local.
local has SOA record local. nobody.localhost. 42 86400 43200 ...
Harry Coin
08:00 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Gentlemen:
1. Every single ubuntu, debian, gnome, xfce and other linux distro that packages the "Network Manager" ...
Harry Coin
07:17 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
Oh, and BTW, the proper thing to do would be to check for NXDOMAIN, not doing utter nonsense such as... Doktor Notor
07:10 AM Bug #3539: dnsmasq responds to domain 'local', breaks avahi
BTW, there are multiple bug reports against this BS script check, like
- https://bugs.debian.org/cgi-bin/bugreport...
Doktor Notor
06:52 AM Bug #3539 (Rejected): dnsmasq responds to domain 'local', breaks avahi
The entire description here isn't true. I suspect as Doktor noted you're using .local as your domain. Otherwise you h... Chris Buechler
07:41 AM pfSense Packages Bug #3527: NRPEv2 package distributing empty xml and missing files
I suspect it's trying to get there via v6 for some reason, given the "no route to host" when you clearly have a v4 ro... Chris Buechler
07:31 AM pfSense Packages Bug #3533: bind package restores outdated config.xml
I've never seen a config.xml.bad.
Besides, the erroneously restored config is way older than the last known good, ma...
Andreas Pflug
07:20 AM pfSense Packages Bug #3533: bind package restores outdated config.xml
You can also check if a /conf/config.xml.bad file is present when it happens, this file would be the broken XML that ... Renato Botelho
07:17 AM pfSense Packages Bug #3533: bind package restores outdated config.xml
All I can see from the config history is that after my last sane change "(system): save result config file for zone o... Andreas Pflug
06:57 AM pfSense Packages Bug #3533: bind package restores outdated config.xml
That's what would happen if the package corrupted the XML, it would restore from the last good backup. Is it logging ... Chris Buechler
07:30 AM Bug #3337: Dashboard Thermal Sensors use "unfriendly names" for Core >= 4
Applied in changeset commit:9ebe5b7c271939a4e48e9cd3f0fdb8f3ebeee432. Renato Botelho
07:30 AM Bug #3337 (Feedback): Dashboard Thermal Sensors use "unfriendly names" for Core >= 4
Applied in changeset commit:a6bb4e06551224137312b60dfc7db5c06581d35f. Renato Botelho
07:25 AM Bug #3531 (Rejected): WAN to VIP on WAN traffic routing.
that's the expected and correct behavior where you don't have IP alias (or CARP, though don't use that in this scenar... Chris Buechler
07:22 AM Feature #3515: Windows OpenVPN clients require register-dns to properly use a DNS server set by Pfsense
Feature since it works as it should. Probably a good idea to add as a checkbox so people realize it exists without di... Chris Buechler
07:18 AM Bug #3517 (Feedback): VPN re
The service gets restarted when the NIC comes back up. That definitely works in general. The failure to start in your... Chris Buechler
07:12 AM Feature #3522: Option to set CARP interfaces to 'maintenance mode', persisting through a reboot so the primary machines stays as backup/inactive
It hasn't been rejected because it's not needed (though Ermal said that initially, I know that's not the case from ex... Chris Buechler
07:03 AM Bug #3524 (Feedback): [IPv6] SSDP and LLMNR multicast traffic blocked on LANs
That seems to be the appropriate behavior unless I'm missing something. What do you think it should do? You can alway... Chris Buechler
06:59 AM Feature #3532 (Rejected): please add a option for set time for pdate Dynanimc dns
This isn't necessary, every time an IP changes, it checks whether it's changed and updates if needed. Maybe something... Chris Buechler
06:41 AM Feature #3534: DDNS using arbitrary zone primary
Please submit the pull request on the master branch, the RELENG_2_1 branch is for bug fixes only. Chris Buechler
06:16 AM Feature #3534: DDNS using arbitrary zone primary
Please submit proposed patches using github pull request tool. It's much easier to developers to review and apply cha... Renato Botelho
04:26 AM Bug #3540 (Resolved): 100% CPU-Issue when IPv6 DHCP with stateless addresses is active
The process check_reload_status takes 100% CPU-Load
if the following conditions are given:
Pfsense Relase:
2.1-...
Ph. T
 

Also available in: Atom