Project

General

Profile

Activity

From 05/26/2014 to 06/24/2014

06/24/2014

09:06 PM Revision b0cbebeb: Add the AESGCM and XCBC on the list of algos availble
Ermal LUÇI
07:18 PM Revision b176474b: Update vpn_openvpn_server.php
Dmitriy K.
07:15 PM Revision 4be2bfed: Update vpn_openvpn_client.php
Dmitriy K.
06:09 PM Revision 649b6b85: Actually use ph1ent ikeid here otherwise will duplicate ids here.
Ermal LUÇI
04:44 PM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Just had this problem with a HUAWEI E1752 on cuaU0.0
running on a :
* 2.1.3-RELEASE (amd64)
* built on Thu May 0...
Christophe Prevotaux
04:40 PM Bug #781: Entering sim code problem on a Huawei E1752
running a PC Engines APU Christophe Prevotaux
04:40 PM Bug #781: Entering sim code problem on a Huawei E1752
I forgot to mention this is with a
2.1.3-RELEASE (amd64)
built on Thu May 01 15:52:13 EDT 2014
FreeBSD 8.3-RELE...
Christophe Prevotaux
04:38 PM Bug #781: Entering sim code problem on a Huawei E1752
I had a similar problem with a HUAWEI E1752 after a cold boot.
Warm reboot works everytime.
Not sure what the p...
Christophe Prevotaux
03:06 PM Revision 0d26e77c: Merge pull request #1241 from Gertjanpfsense/master
Renato Botelho
03:00 PM Revision c15b5ed8: Fix dscp values and provide a config upgrade to fix values stored in config.xml. This is a proper fix for #3688
Renato Botelho
12:42 PM Revision 5a145a54: Delete README.md
Gertjan KROEB
12:27 PM Revision b1e8e675: Update openvpn.inc
Dmitriy K.
08:23 AM Bug #3719 (Not a Bug): vmware cpu host extraordinary high usage
pfSense is installed as VM in VMware ESXi (4, 5.1, 5.5), when pfSense is under high traffic (bandwidth or numerous co... Kenshiro TheFist

06/23/2014

10:26 PM Revision fbe0c5ff: Tidy up misc. XHTML
"diag_dns.php"
Tidy up "equals sign"
"services_captiveportal.php"
Add space to OPTION tag
Update HTML Boolean operat...
Colin Fleming
05:41 PM Revision 5d792074: Update status_captiveportal.php
Don't ask to select a zone if there is only ONE. Gertjan KROEB
04:58 PM Revision fc227e34: Create README.md
Gertjan KROEB
12:32 PM Revision 6c87714d: Add local/www to the list of directories that needs to be symlink'd to reduce PBI differences between 2.1 and 2.2
Renato Botelho

06/22/2014

08:24 PM Bug #3716: Adding IPv6 alias to IPv6 CARP IP throws error - fix proposal attached
It will be easy for the devs to review this if you go to github - https://github.com/pfsense/pfsense - and make the c... Phillip Davis
04:36 PM Bug #3716 (Resolved): Adding IPv6 alias to IPv6 CARP IP throws error - fix proposal attached
Hi,
Adding an IPv6 alias to an IPv6 CARP IP throws the following error:
"...Could not find a matching real interf...
Marc Posch
05:23 PM Feature #3718 (New): radvd - enhancement proposal: ability to advertise routes and some fixes - patches attached
Hi,
I was configuring radvd on two back-to-back firewalls with an in-between subnet and I was missing the feature ...
Marc Posch
04:55 PM Bug #3717 (Resolved): Adding an IPv6 rule on an interface with IPv6 gateway does not add "reply-to" in the resulting rule - fix proposal attached
Hi,
I had problems with Multi-WAN and two IPv6 tunnelbrokers - incoming traffic would "work" only when coming thro...
Marc Posch

06/21/2014

09:23 PM Revision 1657cfd2: oops, that wasn't supposed to be removed.
N0YB
09:16 PM Revision 60a5f9de: Use count($array) where applicable, instead of a $rowIndex increment.
N0YB

06/20/2014

07:14 PM Revision 1a7ed9d0: Don't use pfsense name in comment
Adam Gibson
06:53 PM Revision 05b69065: Use $product instead of pfSense when logging the version to syslog
Adam Gibson
04:06 PM Revision 5b3c0116: Update openvpn.inc
Added verbosity check in case when verbosity_level is absent in config.xml Dmitriy K.
03:59 PM Revision bfa22b15: Update vpn_openvpn_server.php
removed comments Dmitriy K.
03:56 PM Revision 34c0adfc: Update vpn_openvpn_client.php
removed comments Dmitriy K.
02:57 PM Revision 0e678da7: Update openvpn.inc
Removed unnecessary "else {"; Dmitriy K.
02:25 PM Revision efac3a13: Only include a scheduled rule if it is strictly before the end time
The exact moment of the end time is the end of the schedule. We do not want to include a rule when filter_configure_s... Phil Davis
02:25 PM Revision 9f5de694: Merge pull request #1239 from phil-davis/patch-9
Jim Pingle
01:36 PM Revision 052dfa93: Remove extra data after space and fix pf rule syntax. It should fix #3688
Renato Botelho
01:35 PM Revision e792ac36: Remove extra data after space and fix pf rule syntax. It should fix #3688
Renato Botelho
12:36 PM Revision 1c9a521b: Merge pull request #1208 from razzfazz/nat_add_missing_protocols
Renato Botelho
12:35 PM Revision df203cb8: Merge pull request #1218 from razzfazz/nat_add_missing_protocols_master
Renato Botelho
12:05 PM Todo #3715 (Resolved): Change default serial speed to 115200
The default serial console speed should be changed to 115200 to be more in line with current hardware.
To ensure b...
Jim Pingle
10:29 AM Bug #3714 (Resolved): Session cookie inconsistent behavior when switching GUI protocols
The session cookie can end up being non-secure on HTTPS in a specific set of circumstances:
1. Set GUI to HTTPS
2...
Jim Pingle
09:30 AM Bug #3558: Schedule States in System - Advanced - Misc not working
Applied in changeset commit:efac3a1346867481d6cfcea62c131ad0c0de391b. Phillip Davis
09:30 AM Bug #3558 (Feedback): Schedule States in System - Advanced - Misc not working
Applied in changeset commit:a43c5bdea7ee07a5075d8c22a7a247424669e6f3. Phillip Davis
08:50 AM Bug #3688: firewall rule syntax error with Diffserv Code Point
Applied in changeset commit:052dfa9346e716d63fbd85735c4a8784e6ed07e2. Renato Botelho
08:50 AM Bug #3688 (Feedback): firewall rule syntax error with Diffserv Code Point
Applied in changeset commit:e792ac36324e3376763699344742d5dc49eab99c. Renato Botelho
07:34 AM Bug #3689 (Feedback): Filter logs Input Validation Failure
Pull request merged Renato Botelho
07:32 AM Bug #3707 (Resolved): pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Renato Botelho
07:31 AM Bug #3712 (Feedback): missing protocols in NAT edit page
Pull requests merged. Renato Botelho

06/19/2014

07:29 PM Revision 96fcabaa: Replace some backticks by exec ans simplify commands
Renato Botelho
07:20 PM Revision 692c21fd: Remove more backtick abuse
Renato Botelho
06:58 PM Revision 3f0c20c3: Add -n for 2 remaining sysctl calls, also replace backtick by exec
Renato Botelho
06:57 PM Revision c69d32f6: Add full path for dmesg and replace backtick by exec
Renato Botelho
04:05 PM Revision 4f380b62: Remove also . and / from graph
Renato Botelho
04:04 PM Revision 902da388: Remove also . and / from graph
Renato Botelho
03:29 PM Revision bc27c6d1: Remove more backticks
Renato Botelho
03:26 PM Revision 57627d9f: Fix status_rrd_graph_img.php and also improve it:
- Remove escapeshellarg that broke command line
- Only remove dangerous chars to avoid command injection
- Replace al...
Renato Botelho
03:23 PM Revision 2d1e985d: Fix status_rrd_graph_img.php and also improve it:
- Remove escapeshellarg that broke command line
- Only remove dangerous chars to avoid command injection
- Replace al...
Renato Botelho
02:30 PM Revision bef10560: Make sure single quotes are encoded and avoid javascript injection
Renato Botelho
02:29 PM Revision daeab6c4: Fix indent and whitespaces
Renato Botelho
02:29 PM Revision 8aca755a: Make sure single quotes are encoded and avoid javascript injection
Renato Botelho
01:37 PM Revision cedd0705: Use CDATA for javascript
Renato Botelho
01:37 PM Revision 559929c2: Fix indent and whitespaces
Renato Botelho
01:29 PM Bug #3692: apinger loss % gets stuck
I noticed this yesterday. For a period of time I had a bad episode of packetloss on a WAN gateway and even though th... Jason Ross
04:47 AM Revision a43c5bde: Only include a scheduled rule if it is strictly before the end time
The exact moment of the end time is the end of the schedule. We do not want to include a rule when filter_configure_s... Phil Davis
04:47 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
A response.... and the last gigabyte anything I ever buy!
"
Thank you for your kindly mail and inquiry. Accordi...
Stuart Lamble
03:17 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I doubt you'll get a reply in any reasonable amount of time from motherboard manufacturers, but maybe if enough peopl... Chris Buechler
03:11 AM Bug #3558: Schedule States in System - Advanced - Misc not working
yeah the 59 was originally added so you can do 23:59. Chris Buechler
02:59 AM Bug #3558: Schedule States in System - Advanced - Misc not working
and I think the "59" minute end time option is so that a schedule can go to 23:59 - there is no way to specify 24:00 ... Phillip Davis
01:30 AM Bug #3683: pfSense Not Blocking Pre-Auth Captive Portal DNS Requests
where you actually have a block all rule, or no pass rules, connections cannot be established.
The pre-auth conne...
Chris Buechler

06/18/2014

11:45 PM Bug #3558: Schedule States in System - Advanced - Misc not working
I looked at this a while ago and then had trouble replicating the problem. I suspect it only occurs when the filter_c... Phillip Davis
10:22 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Still no reply from Gigabyte... Stuart Lamble
07:54 PM Revision aba02f65: Simplify logic, add some protection to user input parameters
Renato Botelho
07:39 PM Revision d1dda498: Simplify logic, add some protection to user input parameters
Renato Botelho
06:41 PM Revision f1a13a7f: Fix whitespaces and indent
Renato Botelho
06:38 PM Revision f334f8bf: Fix whitespaces and indent
Renato Botelho
04:46 PM Revision bef9f697: We need to allow subdirectories under /usr/local/pkg, here is the proper fix
Renato Botelho
04:46 PM Revision 811baa9b: We need to allow subdirectories under /usr/local/pkg, here is the proper fix
Renato Botelho
11:21 AM Revision 08f30320: Change the option for webconfig login autocomplete from opt-in to opt-out, also bump config version and write a function to keep the current status on upgrades
Renato Botelho
10:52 AM Revision e8abc4a7: Set 'Disable webConfigurator login autocomplete' as on by default
Renato Botelho
10:38 AM Revision 16789caa: Always set httponly attribute on cookies
Renato Botelho
10:38 AM Revision fa73c7cd: Always set httponly attribute on cookies
Renato Botelho
01:37 AM Revision 56bd2035: Fix syntax error
Jim Pingle
12:33 AM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Just to make sure things are as working as last week as per 18 june 05:30 UTC, the current commit I get is dated from... Mathieu Simon

06/17/2014

06:38 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I have logged a call with Gigabyte siting the BIOS ACPI issues and that F3 bios update does not address this problem.... Stuart Lamble
07:58 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Someone "pointed out":https://forum.pfsense.org/index.php?topic=72305.msg426782#msg426782 that this appears to be a B... Ken Masterson
04:05 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Same problem here on the Gigabyte J1900N-D3V motherboard.
Also put some info up on this link on the forum:
https://...
Stuart Lamble
06:13 PM Revision 2b641a08: Protect servicestatusfilter parameter with htmlspecialchars()
Renato Botelho
06:13 PM Revision ce9d5d72: Protect servicestatusfilter parameter with htmlspecialchars()
Renato Botelho
05:53 PM Revision e4921058: Protect rssfeed parameters with htmlspecialchars()
Renato Botelho
05:53 PM Revision 860b102a: Protect rssfeed parameters with htmlspecialchars()
Renato Botelho
05:28 PM Revision 526f5b11: Add comment I forgot on last commit
Renato Botelho
05:27 PM Revision 3034b371: Add comment I forgot on last commit
Renato Botelho
05:27 PM Revision 8588095f: Re-generate session ID on a successful login to avoid session fixation
Renato Botelho
05:26 PM Revision ff9b30ec: Re-generate session ID on a successful login to avoid session fixation
Renato Botelho
04:47 PM Revision 62480a44: Avoid directory traversal on restorefullbackup
Renato Botelho
04:47 PM Revision 5de32d52: Avoid directory traversal on restorefullbackup
Renato Botelho
04:37 PM Revision b67cdd05: Fix core dump on viewing invalid package log
Matthew Smith
04:30 PM Revision 7be297a2: Fix core dump on viewing invalid package log
Matthew Smith
02:17 PM Revision 7145cd87: Remove . and / from pkg name to avoid directory traversal
Renato Botelho
02:17 PM Revision 1cfe5490: Remove . and / from pkg name to avoid directory traversal
Renato Botelho
01:48 PM Revision c3936caf: Remove id=0 from miniupnpd menu and shortcut
Renato Botelho
01:48 PM Revision 73944f68: Remove id=0 from miniupnpd menu and shortcut
Renato Botelho
01:33 PM Revision 69eb2e29: Avoid directory traversal when reading package xml files, also check if file exists before try to read it
Renato Botelho
01:33 PM Revision 9ddd3418: Avoid directory traversal when reading package xml files, also check if file exists before try to read it
Renato Botelho
01:19 PM Revision d09ff9ef: Make sure variables are escaped, also replace exec calls to run rm by unlink_if_exists()
Renato Botelho
01:19 PM Revision 65eb0f61: Remove useless code, variable is set again on next line
Renato Botelho
01:19 PM Revision aa27de6e: Make sure variables are escaped, also replace exec calls to run rm by unlink_if_exists()
Renato Botelho
01:18 PM Revision 592abfa4: Remove useless code, variable is set again on next line
Renato Botelho
12:40 PM Revision 45438fd3: Escape parameters passed to shell_exec()
Renato Botelho
12:40 PM Revision e41ab9aa: Escape parameters passed to shell_exec()
Renato Botelho
12:31 PM Revision 76c4ff0e: Be more careful with host parameter and make sure it's escaped when call shell functions
Renato Botelho
12:28 PM Revision ee4ba9fb: Be more careful with host parameter and make sure it's escaped when call shell functions
Renato Botelho
10:34 AM Revision 54a9da9f: Validate starttime and stoptime format
Renato Botelho
10:33 AM Revision 65f815dd: Validate starttime and stoptime format
Renato Botelho
07:38 AM Revision c7264382: Default values for verb if it is not set when edit
Dmitriy K.
07:09 AM Revision caf58ced: a bit of refactoring
forgot to sync _server.php with _client.php naming style Dmitriy K.
07:01 AM Revision b9e9903d: patchpack1
-Fix #3401 (Added tun option "Disable IPv6"
-Added new options: route-nopull, route-noexec, verb;
Dmitriy K.

06/16/2014

10:14 PM Revision 2464e353: XHTML Compliance - System Menu
Enforce select option N0YB
07:39 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I'm having no luck getting pfsense to boot on my Intel NUC DN2820. Kernel panics with "Bogus interrupt trigger mode.". Aaron Fields
07:26 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
So this looks like a BIOS bug (bad ACPI table) that would be possible to workaround.
Those of you with the Gigabyte ...
Steve Wheeler
05:06 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I can confirm the same issue with ASUS J1900I-C. Both with pfsense 2.1.3 and with pfSense-memstick-serial-2.2-DEVELOP... Joel Larsson
06:10 PM Revision 7860191a: Create some symlinks inside pbi dir to reduce differences between 2.1 and 2.2 and avoid the need to change a lot of PBI scripts
Renato Botelho
06:00 PM Revision ef462f25: Make the byte counts on OpenVPN status human readable rather than huge unformatted numbers.
Jim Pingle
03:30 PM Bug #3558: Schedule States in System - Advanced - Misc not working
This is definitely a problem. It appears to be due to the timing and boundaries of the schedules.
If you end a sch...
Jim Pingle
02:18 PM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
I could not find an ICLA or CCLA in the database.
@Per von Zweigbergk:
If you could please sign either the Indiv...
Jim Pingle
02:12 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
The ICLA looks OK, I show that it was signed and submitted. Thanks!
I added some comments on the pull request for ...
Jim Pingle
07:50 AM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
Seems to be broken in 2.1.3 with Draytek Vigor 2200E. Need Cronjob to restart periodically. Matthias Heer
07:14 AM Revision b4e9a4da: XHTML Compliance - System Menu
Advanced - Admin Access Tab
Advanced - Firewall / NAT Tab
Cert Manager - Certificate Revocation Tab
User Manager - Us...
N0YB
05:47 AM Bug #3637 (Resolved): Incorrect interface matching on bridge edit page
Renato Botelho
02:28 AM Bug #3637: Incorrect interface matching on bridge edit page
Seems to be working correctly now Peter O
02:19 AM Bug #2882: 6RD not working in latest snapshots
I've put up a bounty for this issue to be fixed in the near future (3 months of I dont update the post): https://foru... Rune Darrud

06/15/2014

11:51 PM Bug #3713 (Resolved): Gateways missing for OpenVPN server (shared key or /30s)
Dmitriy K
09:26 PM Bug #1629: invalid state table entries after WAN IP change
assigned to Ermal, either fix this or push it to 2.3 Jim Thompson
09:24 PM Feature #484: Add a warning if users are using non-official package repo
bumped priority
assigned to Pingle.
I'd like this implemented in 2.2.
I'd also like it displayed both on Main -> Pa...
Jim Thompson
09:24 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
I believe I signed one in the correct place just now (portal.pfsense.org). Please let me know if I need to do anythin... Daniel Hazelbaker
09:17 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
assigned to Pingle. Once a CLA has been signed, we can look at incorporating this. Jim Thompson
09:23 PM Feature #983: Improve/Enhance IP Alias VIP handling in GUI
assigned to Renato.
see other comments on possible security issues in the Alias code.
Jim Thompson
09:22 PM Bug #1186: When in pure routing mode the rrd graphs are blank
pushed to 2.3 Jim Thompson
09:21 PM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
pull request received 3 months ago. assigned to Pingle.
please ensure that a CLA is on-file before reviewing the ...
Jim Thompson
09:20 PM Bug #2218: CARP VIPs can become master too early at boot time
pushed to 2.3 Jim Thompson
09:19 PM Bug #2625: Inconsistent behavior with Alias info popup
Assigned to Renato.
While you're in there, I suspect security issues in the Alias code.
Jim Thompson
09:18 PM Feature #3365: Implement package signing
assigned to Renato, increased priority.
please work with porter on how this gets done.
Jim Thompson
09:16 PM Bug #3558: Schedule States in System - Advanced - Misc not working
Assigned to Pingle for evaluation and resolution. Jim Thompson
09:15 PM Feature #3667: Hook for user shutdown script - "/etc/rc.custom_shutdown"
assigned to Renato for evaluation. Jim Thompson
09:14 PM Bug #3597: Package reinstall on system upgrades needs some fallback handling
assigned to Renato.
on full installs, it might be nice to cache the packages.
Jim Thompson
09:09 PM Bug #2984: IPSec adds route but isn't needed any more
assigned to Ermal for final evaluation. Fix it or close it. Jim Thompson
09:08 PM Bug #3125: hifn on 2.1 breaks certain ciphers w/openssl
I'm not sure this is a bug we should attempt to fix in 2.2. Marked as 'future'. Jim Thompson
09:50 AM Revision 959c12cf: Remove Status Verbiage. Consumes too much realestate in widget. Status icon without the verbiage is sufficient in widget view.
N0YB
01:18 AM Feature #3699: Log pfsense version after bootup
I cancelled the previous pull request and a new one submitted.
https://github.com/pfsense/pfsense/pull/1234
I r...
Adam Gibson
12:36 AM Revision f1a34790: Hostnames are not case restrictive.
N0YB

06/14/2014

06:52 AM Revision 01deca6a: Log pfsense version to syslog after bootup
Adam Gibson

06/13/2014

10:14 PM Bug #3712: missing protocols in NAT edit page
Please advise if there is any concern with merging these. I'll happily modify the pull requests as necessary. Daniel Becker
10:13 PM Bug #3712: missing protocols in NAT edit page
I created pull requests for this a few weeks back:
- "1208 for RELENG_2_1":https://github.com/pfsense/pfsense/pull...
Daniel Becker
10:12 PM Bug #3712: missing protocols in NAT edit page
I created pull requests for this a few weeks back:
"1208 for RELENG_2_1":https://github.com/pfsense/pfsense/pull/12...
Daniel Becker
10:10 PM Bug #3712 (Resolved): missing protocols in NAT edit page
The protocol selection on the NAT edit page is missing some protocols that are available for selection on other pages... Daniel Becker
08:46 PM Revision bc388533: Avoid keeping old files from previous sessions on /tmp/configbak
Renato Botelho
07:13 PM Revision 828da370: cf/ dir is removed below, do not need to remove the file here
Renato Botelho
07:08 PM Revision dc86f24d: Fix path for trigger_initial_wizard
Renato Botelho
06:11 PM Revision 061ac3f3: Better string check
N0YB
12:25 PM Revision c352b9d1: Merge pull request #1034 from vsquared56/master
Renato Botelho
11:59 AM Revision 6f3d2063: Replace Header() calls by lowercase
Renato Botelho
11:37 AM Revision 44b79ffb: Merge pull request #1222 from phil-davis/patch-8
Renato Botelho
11:36 AM Revision bcfd894e: Merge pull request #1229 from ExolonDX/branch-master_06
Renato Botelho
11:36 AM Revision 718af29d: Merge pull request #1228 from ExolonDX/branch_master_05
Renato Botelho
08:17 AM Revision f5b26faa: Remove htmlspecialchars() call for a fixed string.
N0YB
07:21 AM Bug #3542 (Feedback): cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name
Pull request merged Renato Botelho

06/12/2014

09:06 PM Revision cbe38717: Bring the code of captiveportal up to speed with its module counterpart requirments
Ermal LUÇI
05:24 PM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Ok there was a missing path option in the crontab. This appears to be running normally now.
Jeremy Porter
03:25 PM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
The tools repo was trying to update with the wrong key. Its also having trouble running form cron. Its manually upda... Jeremy Porter
12:16 AM Bug #3707 (Resolved): pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Related to my report in #3693 the pfsense-tools repository on git.pfsense.org hasn't been updated since 20th may whil... Mathieu Simon
04:27 PM pfSense Packages Bug #3711 (Resolved): bind package not starting after update
Hello,
We reinstalled bind package after an update, but now the named service is not starting up. we restarted our...
Anonymous
02:55 PM Bug #3710 (Resolved): Adding static DHCP leases doesn't cause BIND zones to update
Adding static DHCP leases doesn't cause BIND zones to update with "Register DHCP static mappings" on.
This one mus...
Dmitriy K
02:48 PM pfSense Packages Bug #897: Missing DNS record types SRV SPF DOMAINKEYS
I believe "Custom Zone Domain records" is enough to implement any idea you want. Just add there mail._domainkey.<doma... Dmitriy K
02:42 PM pfSense Packages Bug #3323: BIND, Reverse Zones and Register DHCP static mappings.
I have performed some tests with pfSense 2.2 and seems like #3323 has been successfully fixed. Dmitriy K
01:22 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Issue persists on 2.2 Renato Botelho
12:53 PM Revision 1d8b3cdd: Fix i386 default URL for snapshots
Renato Botelho
12:31 PM Revision e7eeb5ce: Do not expire already disabled users, it fixes #3644
Renato Botelho
12:31 PM Revision 11eaf7bf: Do not expire already disabled users, it fixes #3644
Renato Botelho
11:59 AM Revision 859a5304: Fix #3665, show IPSec tunnel description on status page
Renato Botelho
11:33 AM Revision bd757043: Fix a typo on variable name
Renato Botelho
11:16 AM Revision 6186c00a: Fix td class
Renato Botelho
08:48 AM Bug #3665: IPsec tunnel description not displayed on status output
Looks good to me. Might be nice to have the P2 descriptions in the Child SA list as well if it's not too much trouble. Jim Pingle
07:00 AM Bug #3665 (Feedback): IPsec tunnel description not displayed on status output
Applied in changeset commit:859a53045631abf3844efda55a3169186618746a. Renato Botelho
07:50 AM Bug #3644: rc.expireaccounts expires every expired account every time it runs
Applied in changeset commit:e7eeb5ceac07f83630ced5e9cf18b10083a9aca8. Renato Botelho
07:50 AM Bug #3644 (Feedback): rc.expireaccounts expires every expired account every time it runs
Applied in changeset commit:11eaf7bfe6ba02d39e08d3c7541cb5d2b181d686. Renato Botelho
04:36 AM Bug #2882: 6RD not working in latest snapshots
I am also running in to this issue using the Dutch fiber ISP 'OnsBrabantnet'. If there is anything I can do or provid... Wouter van Rooy
03:05 AM Bug #3709 (Resolved): Disabled static route entries trigger 'route delete' error at boot
I've got a site to site openvpn setup. On the server i've got "remote networks" setup. On system reboot, this remote ... Maarten Bakker
02:32 AM pfSense Packages Bug #3708 (Closed): Error with order field while creating the first entry in "groups ACL" for squidGuard package
While creating the first ACL in "Groups ACL" for squidGuard package the following message is shown in the "Order" fie... Anonymous

06/11/2014

05:56 PM Revision f01c3b59: Fix #3702, make sure tunnel inside IP is set when interface changes
Renato Botelho
03:49 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
When I look back at what I wrote and on the logs, I see that all NAT have the checksum error. But for some reason the... Andreas Winge
03:17 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
As long as this problem has existed, NAT out WAN via PPTP on amd64 has been broken, that was the easiest problem to r... Jim Pingle
03:13 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
Oh 2.1.3 that I am running now is so much worse than when I reported this. As said in 2.1.3 NAT out to the WAN wasn't... Andreas Winge
12:43 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
Your description of what you did is something that has worked all along.
It was when the pfsense had an outgoing ...
Andreas Winge
01:00 PM Bug #3702 (Feedback): gif interface assignment removes tunnel's inside IPv6 IPs
Applied in changeset commit:f01c3b5973e96502b787d282cc508a95f3a40d38. Renato Botelho
09:11 AM Bug #3706 (New): Permission order affects default page on limited accounts, but can't reorder
1. Make an account
2. Assign dashboard permission
3. save
4. Assign reboot permission
5. save
6. log in with tha...
Trel S
05:59 AM Bug #3666: PMTUD is broken for NATed traffic
I think you're on to something there. This: ... Chris Buechler
05:47 AM Feature #973 (Resolved): OpenVPN client in GUI cannot connect to a server requiring username/password
yep, this one's been implemented. Chris Buechler
12:27 AM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
And now I looked in the code for 2.2 and saw that it was there. Awesome! Andreas Winge
05:23 AM Revision daa169f7: remove extra .
Chris Buechler

06/10/2014

11:42 PM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
Sorry, I misread the description. Ignore that last comment.
Will there ever be a possibility to provide user/pass ...
Andreas Winge
11:36 PM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
This one can be closed. It has been working for years now. Andreas Winge
05:21 PM Revision f5629ea6: Be more precise to match members of a bridge interface, it should fix #3637
Renato Botelho
05:20 PM Revision f2c86031: Be more precise to match members of a bridge interface, it should fix #3637
Renato Botelho
03:15 PM Bug #3666: PMTUD is broken for NATed traffic
not identical, no. Had the same basic components - scrub all, pass all, nat on. I can throw the completely identical ... Chris Buechler
05:37 AM Bug #3666: PMTUD is broken for NATed traffic
You used the same ruleset on stock FreeBSD as pfSense? Ermal Luçi
02:25 AM Bug #3666: PMTUD is broken for NATed traffic
Additional data point. This seemingly isn't an issue in stock FreeBSD 10-STABLE. One I had handy: ... Chris Buechler
12:36 AM Bug #3666 (New): PMTUD is broken for NATed traffic
no change. I did confirm it's specific to NATed traffic and updated subject accordingly. Send any packet > egress int... Chris Buechler
03:13 PM Bug #3703 (Resolved): MTU not applied on reboot
the root issue is the link route MTUs in FreeBSD 8.3 aren't correctly updated. That works in 10.x, and hence 2.2 (I'v... Chris Buechler
12:59 PM Bug #3703: MTU not applied on reboot
fwiw, in UI going from mtu 9000 to mtu 'blank', after multiple save/apply, ifconfig, netstat, and ping all still show... Steve Russell
12:49 PM Bug #3703: MTU not applied on reboot
Netstat -rnW output after first save/apply, while ifconfig says mtu 9000
$ netstat -rnW
Routing tables
Interne...
Steve Russell
12:30 PM Bug #3703: MTU not applied on reboot
Please also include "netstat -rnW" -- watch the mtu column there. Jim Pingle
12:27 PM Bug #3703: MTU not applied on reboot
This is the ifconfig output after first save/apply:
$ ifconfig
em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTI...
Steve Russell
12:00 PM Bug #3703: MTU not applied on reboot
Also be sure to specify any additional configurations you have on the interfaces such as lagg, vlans, bridges, gif/gr... Jim Pingle
11:57 AM Bug #3703: MTU not applied on reboot
Are you sure the MTU is not being set? Could you paste the output of ifconfig? I tried it both on 2.1.3 and 2.2 and i... Renato Botelho
10:48 AM Bug #3703 (Resolved): MTU not applied on reboot
Set MTU on LAN to 9000. Save. Apply. 'Ping -f -l 8972 pfsense' from windows box. Timed out.
Save LAN settings aga...
Steve Russell
02:28 PM Revision b2821f7d: Revert "Revert "Fix #3700 and other syntax issues:""
This reverts commit 4cc2ae78d3027c349969437f08a88b1fb88c9de8. Renato Botelho
02:28 PM Revision ab3c1e24: Revert "Fix sh syntax"
This reverts commit cd49f9cd5d21a6592ba690cd315f19266092bee5. Renato Botelho
01:54 PM Revision cd49f9cd: Fix sh syntax
Renato Botelho
01:54 PM Revision 4cc2ae78: Revert "Fix #3700 and other syntax issues:"
This reverts commit e912bfae186b6b657daf52607f9d027f46be0478. Renato Botelho
01:42 PM Revision ff3da5db: Fix #3700 and other syntax issues:
- Remove -G parameter from pfctl since it doesn't exist anymore
- Initialize $old_router
- Fix sh syntax on variable ...
Renato Botelho
01:40 PM Revision e912bfae: Fix #3700 and other syntax issues:
- Remove -G parameter from pfctl since it doesn't exist anymore
- Initialize $old_router
- Fix sh syntax on variable ...
Renato Botelho
12:30 PM Bug #3637: Incorrect interface matching on bridge edit page
Applied in changeset commit:f5629ea6b83572ae8fa681b7bfd0c2e05844b290. Renato Botelho
12:30 PM Bug #3637 (Feedback): Incorrect interface matching on bridge edit page
Applied in changeset commit:f2c86031649e5f199ef10e848593ba38429694da. Renato Botelho
12:03 PM Todo #3705 (Resolved): use HTTPS for rc.update_bogons.sh
The *rc.Update_bogons.sh* script should reference the *HTTPS* site instead of the HTTP one.
v4url=${v4url:-"http:/...
BBcan177 .
12:03 PM pfSense Packages Bug #3704 (Closed): spamd whitelist/blacklist bug
1 - I've create a white list with google IP's range but I'm still get connections from Google IP's in GREY when I cli... Ricardson Williams
09:00 AM Bug #3700: pfctl: illegal option -- G
Applied in changeset commit:ff3da5dba67c64514808e86165e92362f3ff8b33. Renato Botelho
09:00 AM Bug #3700 (Feedback): pfctl: illegal option -- G
Applied in changeset commit:e912bfae186b6b657daf52607f9d027f46be0478. Renato Botelho

06/09/2014

06:32 PM Revision 6da518fc: Do not allow interface group name to be bigger than 15 chars, helps ticket #3208
Renato Botelho
06:32 PM Revision 6a0f34b8: Do not allow interface group name to be bigger than 15 chars, helps ticket #3208
Renato Botelho
05:35 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Dan E wrote:
> I can confirm this issue on a Gigabyte GA-J1900N-D3V. I've tried AMD64/i386 builds of 2.1.3 as well a...
Eric Tol
01:05 PM Bug #3125: hifn on 2.1 breaks certain ciphers w/openssl
Confirmed same on an ALIX with: ... Chris Buechler
12:59 AM Bug #3514: IPv6 - LAN looses Prefix after link event
Derek Ivey wrote:
> I seem to be running into this bug in pfSense 2.1.3-RELEASE. It seems like a SIGHUP is properly ...
Derek Ivey
12:14 AM Bug #3514: IPv6 - LAN looses Prefix after link event
I seem to be running into this bug in pfSense 2.1.3-RELEASE. It seems like a SIGHUP is properly being sent to the dhc... Derek Ivey

06/08/2014

09:50 PM Revision 529ba86a: Populate gateway address field with tilde if there is no address or friendly interface.
This is to match the update data. N0YB
09:47 PM Revision 1f47798a: Fix gateway widget size change on first update.
Inner table size changes on the first update because the table in update data does not have the same attributes as th... N0YB
12:42 AM Bug #3701 (Rejected): IPv6 address assignment inside gif only functions with 128 prefixlen
the actual bug at fault here is #3702. We do actually ignore prefixlen there and set it to 128, so maybe shouldn't gi... Chris Buechler
12:23 AM Bug #3701 (Rejected): IPv6 address assignment inside gif only functions with 128 prefixlen
This used to work, but I'm not entirely sure at what point - 2.1.4 behaves the same. On the most current 2.2 snapshot... Chris Buechler
12:41 AM Bug #3702 (Resolved): gif interface assignment removes tunnel's inside IPv6 IPs
Normally removing an IP from an interface where that type is "none" is appropriate. But not with gif (or tun or tap o... Chris Buechler

06/07/2014

11:34 PM Bug #3700 (Resolved): pfctl: illegal option -- G
we're either missing a patch or doing it wrong here. ... Chris Buechler
10:15 PM Feature #3699: Log pfsense version after bootup
Pull request submitted.
https://github.com/pfsense/pfsense/pull/1230
Adam Gibson
08:34 PM Feature #3699: Log pfsense version after bootup
I posted a discussion about it several days ago where someone else mentioned it would be nice to log the version.
...
Adam Gibson
08:21 PM Feature #3699 (Resolved): Log pfsense version after bootup
I have had trouble trying to keep track of what version of pfSense I was running in the past to submit bug reports an... Adam Gibson
01:59 PM Todo #3698 (Rejected): Design flaw in floating rules ui
javascript updates them accordingly after you put an address in the field. If you want to submit a pull request so th... Chris Buechler
12:45 PM Todo #3698: Design flaw in floating rules ui
This is on 2.1.3 x64 Oliver Loch
12:44 PM Todo #3698 (Rejected): Design flaw in floating rules ui
Hi,
as you can see on the attached picture, the available subnets are a bit "out of range" for the selected protoc...
Oliver Loch

06/06/2014

05:48 PM Bug #3517 (Closed): VPN re
Chris Buechler
05:44 PM Bug #3669 (Feedback): WAN IPs not being cached causing unnecessary "rc.start_packages: Restarting/Starting all packages"
Chris Buechler
02:54 PM Revision ad03afb6: Escape argument on call to is_process_running too, also remove some unecessary mwexec() calls
Renato Botelho
02:53 PM Revision 4cc34245: Add some protection to parameters that come through _GET
Renato Botelho
02:48 PM Revision 2f9951fe: Add some protection to parameters that come through _GET
Renato Botelho
02:33 PM Feature #3522 (Feedback): Option to set CARP interfaces to 'maintenance mode', persisting through a reboot so the primary machines stays as backup/inactive
Jim Pingle
02:32 PM Bug #3649 (Closed): IPv6 Gateway is not functioning when using DHCPv6
Oops, duplicate of #3361 Jim Pingle
01:16 PM Todo #3396 (Feedback): Replace dnsmasq with Unbound
Needs more testing though Warren Baker
12:26 PM Revision cbf16c30: Escape this before running.
Jim Pingle
04:50 AM Feature #3697 (New): New backup/restore area: Certificates
It would be nice if we could backup / restore all certificates only. Dmitriy K
02:57 AM Bug #2945: Installation stucks at 36%: /usr/local/bin/cpdup -vvv -I -o /usr /mnt/usr
Seems pretty random to me.
When I faced the same issue, I tried various advises about BIOS settings (CPU VT, Energy ...
Игорь Горьков
12:57 AM Feature #3696 (New): Multiple items backup/restore
It would be great if we could choose what areas we want to backup/restore. Backuping/Restoring area 1 by 1 is a bad a... Dmitriy K

06/05/2014

10:00 PM Feature #3693: pfPorts: Sync lighttpd with FreeBSD ports
Hi, let's see if it needs some additional waiting time but I still get last commit being from may 20th.
(I messed up...
Mathieu Simon
06:28 PM Feature #3693: pfPorts: Sync lighttpd with FreeBSD ports
It should be fixed now. Thanks! Renato Botelho
05:20 PM Feature #3693: pfPorts: Sync lighttpd with FreeBSD ports
Hi Renato
*bummer* ;-)
However I guess that there must be some issues with the replication between ESF's internal...
Mathieu Simon
03:01 PM Feature #3693 (Closed): pfPorts: Sync lighttpd with FreeBSD ports
It was already done a week ago. Thanks anyway. Renato Botelho
01:21 AM Feature #3693 (Closed): pfPorts: Sync lighttpd with FreeBSD ports
Syncs our lighttpd port with FreeBSD ports tree at r355995
Let's see if this can be used as procedure for contribu...
Mathieu Simon
09:44 PM Revision 56898132: Tidy up misc. widgets XHTML
captive_portal_status.widget.php
Remove NAME from TABLE tag, not valid in XHTML
carp_status.widget.php
Add missing c...
Colin Fleming
06:41 PM Revision 2690afba: Update "pkg_edit.,php"
"custom_php_after_head_command", if the PHP code also contains
JavaScript ("squid_auth.xml" for example) then this wi...
Colin Fleming
06:36 PM Revision 3bbc23b8: Bump version to 2.1.4
Renato Botelho
11:55 AM Revision 764ac8c7: Fix #3691, use curl instead of fetch to download update files
Renato Botelho
11:55 AM Revision 1c52509c: Fix #3691, use curl instead of fetch to download update files
Renato Botelho
11:38 AM Bug #3695: CVE-2014-0224 - OpenSSL SSL/TLS MITM vulnerability
More links with info:
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:14.openssl.asc
https://www.imperialv...
Jim Pingle
11:37 AM Bug #3695: CVE-2014-0224 - OpenSSL SSL/TLS MITM vulnerability
We're already aware and investigating.
As far as we can tell it may not be critical for most. As with Heartbleed i...
Jim Pingle
11:30 AM Bug #3695 (Resolved): CVE-2014-0224 - OpenSSL SSL/TLS MITM vulnerability
This newly released exploit affects all versions of OpenSSL and allows a MITM attacker to decrypt and modify traffic ... Adam Gauthier
11:21 AM Bug #3125: hifn on 2.1 breaks certain ciphers w/openssl
Testing this on 2.2 I am still unable to set lighttpd to use BEAST protection. I receive the same error as before, in... Jim Pingle
10:04 AM Bug #3694: Some certificates not in CRL is also blocked
OK, thanks for your quick answer.
You're right, 2 certificates have the same serial number.
Forum topic for furth...
Laurent Legendre
09:02 AM Bug #3694 (Rejected): Some certificates not in CRL is also blocked
Most likely explanation is that you somehow have a serial number collision, so both certs have the same serial number... Jim Pingle
08:48 AM Bug #3694 (Rejected): Some certificates not in CRL is also blocked
Hi,
I've an OpenVPN server with many users. 3 of them are in a CRL which is used by the openvpn server.
Another u...
Laurent Legendre
07:00 AM Bug #3691: Fetch error on HTTPS console update by URL
Applied in changeset commit:764ac8c73a7529740b80773d6c8bf44c3a2244df. Renato Botelho
07:00 AM Bug #3691 (Feedback): Fetch error on HTTPS console update by URL
Applied in changeset commit:1c52509cabc014ca55e07548338b3990bfc2ace9. Renato Botelho
03:20 AM Bug #3691: Fetch error on HTTPS console update by URL
just needs a symlink. ... Chris Buechler
12:55 AM Bug #3208: interface name over 17 characters long results in pf errors
The problem persists in 2.1.3 release, if interface is an Interface Group of more than 15 characters Damien Montalan

06/04/2014

07:25 PM Revision 88e545b4: Whitespace fixes
Jim Pingle
07:22 PM Revision 2da48592: Allow the user to select "None" for OpenVPN client certificate, so long as they supply and auth user/pass. Ticket #3633
Jim Pingle
06:17 PM Revision df13b077: Just use ID here instead.
Jim Pingle
06:13 PM Revision 5344099a: Various fixes to diag_dump_states.php (Add interface column, some extra validation safety, etc). Should fix #2121
Jim Pingle
04:43 PM Bug #3692 (Resolved): apinger loss % gets stuck
I have noticed on multiple (5) independent pfSense installs/locations/ISPs (both active/passive and single-node, x86 ... Jeroen van Gelderen
02:31 PM Feature #3633 (Feedback): OpenVPN client's "Client Certificate" should be optional
I added a commit to allow this with some input validation to make sure that if they leave it on 'none' that they must... Jim Pingle
01:30 PM Bug #2121 (Feedback): pfctl -ss output has changed on FreeBSD 10
Applied in changeset commit:5344099abc7e490e63c9dacfb311c3fb3cc38de7. Jim Pingle
10:56 AM Bug #1107 (Feedback): mpd on AMD64 generates invalid checksums with NAT
This does appear to be fixed on 2.2 snapshots. I connected up a PPTP client to and amd64 VM running 2.2 and it could ... Jim Pingle
10:32 AM Bug #3187 (Feedback): LiveCD boot issue on multicore systems.
Needs feedback from affected users now that we have 2.2 snapshots. Jim Pingle
10:28 AM Feature #620: No privilege choice to allow access to Dashboard
The current permission seems to be fine for most everyone. If we need to improve upon this, it can wait until after 2.2 Jim Pingle
10:20 AM Bug #3690 (Resolved): php-fpm blocks (stops the boot, prevents webgui startup, etc)
This was resolved yesterday. Jim Pingle
09:23 AM Bug #3691 (Resolved): Fetch error on HTTPS console update by URL
When performing a console update by URL from an HTTPS URL, fetch displays an error validating the certificate.
<pr...
Jim Pingle
05:07 AM Bug #3624: "ppp: OpenConfFile: Can't open file '/var/etc/mpd_wan.conf': No such file or directory"
Temporal solution to this problem is to check "Use RAM Disks" box in System: Advanced: Miscellaneous. Dmitriy K

06/03/2014

06:18 PM Revision 466cabed: allow ipaliases to be configured on lo0
Matthew Smith
06:15 PM Revision e9490019: Silent pbi_info
Renato Botelho
05:39 PM Revision 29732bc3: Update csrf-magic to 1.0.4
Renato Botelho
01:59 PM Revision bc29d9fd: Reduce possible noise
Renato Botelho
12:33 PM Revision ee7f5e7a: Merge pull request #1226 from ExolonDX/branch_master_04
Renato Botelho
12:33 PM Revision f1330391: Merge pull request #1225 from ExolonDX/branch_master_03
Renato Botelho
12:33 PM Revision ccc3b027: Merge pull request #1224 from ExolonDX/branch_master_02
Renato Botelho
12:33 PM Revision 960ed83f: Merge pull request #1223 from ExolonDX/branch_master_01
Renato Botelho
12:12 PM Revision 580a6561: Tidy up "status_queues.php" XHTML
Add closing BODY and closing HTML tags if "traffic shaping is not
configured."
Colin Fleming
12:08 PM Revision 2a351d32: Tidy up "status_openvpn.php" XHTML
Move the closing FORM tag after the PHP check if there are any OpenVPN
instances.
Colin Fleming
11:52 AM Revision e6f98d5b: Tidy up "diag_dns.php" XHTML
Move the "=" sign into the first table cell, this allows the output to
line up in the second cell,
Tidy up the table ...
Colin Fleming
11:28 AM Revision 26509223: Tidy up "crash_reporter.php" XHTML
Tidy up Paragraph tags
Close INPUT tags
Colin Fleming
09:34 AM Feature #3522: Option to set CARP interfaces to 'maintenance mode', persisting through a reboot so the primary machines stays as backup/inactive
This has been pushed into the 2.2 Alpha from what I read on the forums. Correct? The status probably can be changed... Adam Gibson
09:24 AM Revision c4107752: Handle firewall log filter regex input better bug #3689
If the user inputs an invalid regex in any of the filter fields, then a page full of "warning" messages appear in the... Phil Davis
04:28 AM Bug #3689: Filter logs Input Validation Failure
I submitted pull request https://github.com/pfsense/pfsense/pull/1222
This will be nice to this type of input, escap...
Phillip Davis
02:37 AM Bug #3690: php-fpm blocks (stops the boot, prevents webgui startup, etc)
Given that this is a showstopper bug, I feel it should be given a high priority. Anonymous
02:30 AM Feature #3687: Multi sources,destinations,ports on single rule

I know that aliases can do that. i only report my experience with customers who insert/edit policies often don't l...
Anonymous

06/02/2014

08:55 PM Bug #3690 (Resolved): php-fpm blocks (stops the boot, prevents webgui startup, etc)
Since about 29-May, php-fpm has been apparently blocking. This prevents the webgui from starting up, and also stops ... Charlie m
08:46 PM Revision ed10564b: allow ipaliases to be configured on lo0
Matthew Smith
07:54 PM Feature #3687 (Closed): Multi sources,destinations,ports on single rule
aliases and aliases containing aliases can do all that already. Chris Buechler
07:53 PM Bug #3679 (Closed): Wrong values Current Traffic Graph Dashboard WAN
same issue as another ticket with this general problem Chris Buechler
06:50 PM Bug #3417 (Feedback): racoon crashes after mobile xauth login with fourth DNS server configured
ran into this one today. Presume this is not an issue with 2.2 given racoon is gone, setting target version 2.2 to co... Chris Buechler
11:55 AM Bug #3689 (Resolved): Filter logs Input Validation Failure
In
diag_logs_filter.php
entering a source or destination in the format 1.1.1.0/24 causes the below error to be rep...
Mark Wharton
11:27 AM Revision 0db055f0: Merge pull request #1219 from nagyrobi/patch-13
Renato Botelho
07:36 AM Bug #3688 (Resolved): firewall rule syntax error with Diffserv Code Point
I am using 2.1.3.
I am getting a syntax error when creating a floating firewall rule with a particular Diffserv Co...
James Dietrich
01:49 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
As a developer, I don't understand why pmd config is being generated EACH time on connect?! It's so hard to add a che... Dmitriy K

06/01/2014

12:55 PM Bug #3679: Wrong values Current Traffic Graph Dashboard WAN
ok,
error on version 2.1.3
Let me try with version 2.2 snaps
Gilberto Tunon

05/31/2014

05:12 PM Feature #3687 (Closed): Multi sources,destinations,ports on single rule
hello,
it would be fine if it could be possible to create or to edit a policy adding more than 1 source,destination ...
Anonymous
02:40 PM Revision 0bb15b99: Fix filename
Jim Pingle
02:40 PM Revision 2fc7b003: Fix variable name
Jim Pingle
01:01 AM Revision cac386b6: remove openbgpd bits from system_gateways_edit and system.inc. The package
match is case-sensitive and hasn't matched the openbgpd package's name in
at least 5 years, so it doesn't do anything...
Chris Buechler
12:57 AM Revision bc76b18e: remove openbgpd bits from system_gateways_edit and system.inc. The package
match is case-sensitive and hasn't matched the openbgpd package's name in
at least 5 years, so it doesn't do anything...
Chris Buechler

05/30/2014

11:14 PM Feature #3686 (Resolved): Distinguish services when sending authentication request to RADIUS server
I use RADIUS for authenticating users on different services on pfSense: Captive Portal, multiple OpenVPN servers, Web... Jocelyn Viau
06:40 PM Revision 24c57e72: Drop a note on the page about how to repair a failed mirror.
Jim Pingle
06:15 PM Revision 52398a6b: Bring in proper gmirror support for the GUI and notifications.
Made a general gmirror library to perform various gmirror tasks and get information, using some of the former widget ... Jim Pingle
03:00 PM pfSense Packages Feature #3685 (Resolved): haproxy listener ip from alias
If there are too many IPs in listener list (100+) haproxy_listener.php is very slow viewing.
Perhaps it's related ...
Atıf CEYLAN
01:18 PM Revision 8490ba0f: glob() is already called by unlink_if_exists
Renato Botelho
01:08 PM Bug #3684 (Rejected): Openvpn not routing incomming traffic correct when using tap device
Will try this again and it is *NOT* a config issue
I have 2 openvpn clients on my server 1 running with tun as dev...
Lars Jensen
12:45 PM Revision 7d363e57: client-config-dir is also useful when using OpenVPN's internal DHCP while bridging.
Jim Pingle
12:45 PM Revision cb4f4ea9: client-config-dir is also useful when using OpenVPN's internal DHCP while bridging.
Jim Pingle
12:30 PM Revision 5125c746: Add @ to silent any possible return of posix_kill
Renato Botelho
12:05 PM Revision 33b42689: Fix typo
Renato Botelho
12:01 PM Revision 2d6e7bfb: Improve /etc/sshd:
. Create ed25519 key for ssh and silent daemon
. Remove some exec() calls
. We do not need to re-create all keys if /...
Renato Botelho
09:39 AM Bug #3649: IPv6 Gateway is not functioning when using DHCPv6
Seems rtsold is not passing the gateway as second argument!
Looking more on how to fix this
Ermal Luçi
09:20 AM Bug #3654 (Feedback): Outbound IPsec rules do not exclude WAN subnet
Pushed a patch for this!
It is the same as for reply-to.
Ermal Luçi
07:56 AM Bug #3666 (Feedback): PMTUD is broken for NATed traffic
Patch put in to try to handle this case.
For record this is happening due to NAT being applied on packets and the ...
Ermal Luçi

05/29/2014

10:58 PM Bug #3683: pfSense Not Blocking Pre-Auth Captive Portal DNS Requests
Even with the first rule on the interface as "IPv4 TCP/UDP * * * * * none (Block Al)" the client is still getting "es... Kyle Fergusson
10:37 PM Bug #3683 (Rejected): pfSense Not Blocking Pre-Auth Captive Portal DNS Requests
It's not getting out to the Internet, the DNS forwarder can though and supplies responses. It's possible to block via... Chris Buechler
05:25 PM Bug #3683 (Rejected): pfSense Not Blocking Pre-Auth Captive Portal DNS Requests
pfSense appears to be susceptible to DNS Tunneling attacks. I've got a neighbor who's dishTV keeps associating with m... Kyle Fergusson
08:07 PM Revision 7a47edcc: Include the v4 prefix on the v6 netmask to make routing more sane and alos tracking interface configurations work!
Ermal LUÇI
02:29 PM Revision ae73fcb1: Merge pull request #1220 from ExolonDX/branch_master_01
Renato Botelho
02:18 PM Revision 7786daaa: Tidy up "diag_tables.php" XHTML
Add BODY tag
Add ACTION to FORM tag
Add CDATA section to SCRIPTS
Remove NAME from OPTION tag, not valid in XHTML
Upda...
Colin Fleming
02:09 PM Bug #3682: Openvpn not routing incomming traffic correct when using tap device
and the reply-to:
pass in quick on $PRQTUNNEL reply-to ( ovpnc2 88.80.28.129 ) inet proto icmp from any to any...
Lars Jensen
01:58 PM Bug #3682: Openvpn not routing incomming traffic correct when using tap device
from rules.debug:
pass out route-to ( ovpnc2 88.80.28.129 ) from 88.80.yyy.xxx to !88.80.28.128/25 keep state allo...
Lars Jensen
01:51 PM Bug #3682 (Rejected): Openvpn not routing incomming traffic correct when using tap device
traffic is routed by where the routing table says it should go, or via reply-to if you assign the VPN interface. Conf... Chris Buechler
12:33 PM Bug #3682 (Rejected): Openvpn not routing incomming traffic correct when using tap device
I have 2 openvpn clients on my server 1 running with tun as device and 1 running with tap as device,
traffic comin...
Lars Jensen
01:53 PM Revision 268258b5: Unset iflist and iflist_disabled
Renato Botelho
01:53 PM Revision 36b9bb28: Unset iflist and iflist_disabled
Renato Botelho
12:20 PM Revision 4e6b0a0e: Update services_ntpd.php
Add validation for the case of no server specified, fall back to pool.ntp.org robi robi
11:53 AM Revision 22ed6e3e: Show disabled interface when it was already part of interface group, it avoids to show a random interface instead and let user to add it by mistake. It should fix #3680
Renato Botelho
11:52 AM Revision 6e73977b: Show disabled interface when it was already part of interface group, it avoids to show a random interface instead and let user to add it by mistake. It should fix #3680
Renato Botelho
07:00 AM Bug #3680: disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead
Applied in changeset commit:22ed6e3eab85f55e993c75a28a772b6e1fc870d8. Renato Botelho
07:00 AM Bug #3680 (Feedback): disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead
Applied in changeset commit:6e73977bd7a542e703d1b05587c434880ef727a9. Renato Botelho
06:41 AM Revision 5635eec8: bring protocols on NAT edit page more in line with rule edit page
Daniel Becker

05/28/2014

08:48 PM Revision 1930a63e: Convert protocol ssl:// to https:// when creating http headers
Manuel Silvoso
08:14 PM Revision 499f6e20: Merge pull request #1217 from nagyrobi/patch-15
Renato Botelho
08:08 PM Revision 40c75329: Merge pull request #1216 from nagyrobi/patch-14
Renato Botelho
08:01 PM Revision 612b6ad6: Merge pull request #1212 from ExolonDX/branch_master_04
Renato Botelho
08:01 PM Revision 4f280a4a: Merge pull request #1211 from ExolonDX/branch_master_03
Renato Botelho
08:00 PM Revision 0e1a4b55: Merge pull request #1210 from ExolonDX/branch_master_02
Renato Botelho
08:00 PM Revision e2935a75: Merge pull request #1209 from ExolonDX/branch_master_01
Renato Botelho
07:52 PM Revision 151693da: Update services_ntpd_gps.php
Fixed MRC->RMC typos in sentence types, display and fine-tuning for SureGPS card. robi robi
07:39 PM Revision a88376d9: Update rrd.inc
fixed NTPd graphs resetting when service restarts or reconfigured (thanks charliem https://forum.pfsense.org/index.ph... robi robi
06:00 PM Revision 504e5fd4: Use script-friendly gmirror status output to build this info, old method was breaking output when the mirror was being rebuilt.
Jim Pingle
03:47 PM Bug #3612 (Feedback): Packages through proxy doesn't work since change to HTTPS
A fix was pushed few weeks ago on branch master commit:81c8b51db2
I cherry-picked it to RELENG_2_1 today - commit:...
Renato Botelho
12:31 PM Revision 1c847e5e: Make sure check_reload_status is stopped so it can be upgraded and no events disturb the upgrade.
Ermal LUÇI
11:05 AM Bug #2610: Whole-disk gmirror may break when upgraded to a FreeBSD 10.x base
Another relevant bit of info: The installer option works OK on 2.2 as well. Jim Pingle
11:02 AM Bug #2610 (Closed): Whole-disk gmirror may break when upgraded to a FreeBSD 10.x base
Non-issue. Ran some tests and a gmirror installed using our installer gmirror option on 2.1.x or before upgraded OK, ... Jim Pingle

05/27/2014

11:43 PM Bug #3681: Email notifications don't work with IPv6-only SMTP servers
our smtp.inc (looks to be from elsewhere, phpmailer maybe) uses gethostbyname to check whether a hostname is valid. g... Chris Buechler
07:45 PM Bug #3681 (Closed): Email notifications don't work with IPv6-only SMTP servers
The email notifications system does not function with an ipv6 only mail server.
@php: /system_advanced_notifications...
William Jagels
07:44 PM Revision 9cc22856: Remove the space here which probably is preventing from calling sshd from fcgi
Ermal LUÇI
03:34 PM Bug #3679 (Feedback): Wrong values Current Traffic Graph Dashboard WAN
on what version? You'll have to try the most recent 2.2 snapshot and report back. Chris Buechler
01:34 PM Revision aa7ec418: Make logging of pass rules opt-in rather than opt-out
Ermal LUÇI
01:14 PM Revision 1fd46d44: Split the setting of logging pass and block into 2 separate settings. Maybe this can be extended to control even the user rules?
Ermal LUÇI
12:59 PM Revision d7582888: Trim whitespaces from options text and fix #3674
Renato Botelho
12:35 PM Revision efa26483: Add ICMP to filter parser, it should fix #3663
Renato Botelho
11:57 AM Bug #3680: disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead
I can reproduce the problem in my 2.1.3 productive installation (tried again right now to verify), but I see now ther... Lukas Zeller
09:41 AM Bug #3680: disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead
I couldn't reproduce it on 2.1.3 and 2.2 recent snapshots. When an interface is disabled, it's removed from group, an... Renato Botelho
11:39 AM Revision 587ecd08: Tidy up "system_firware" XHTML
Remove WRAP from TEXTAREA and add Javascript to add wrap hard Colin Fleming
11:33 AM Revision b3733e10: Tidy up Ampersand XHTML
Deprecate Ampersand in Anchor tags Colin Fleming
11:22 AM Revision 2a74f9d7: Tidy up misc. XHTML
Close FORM tag correctly
Add missing TD and TR tags
Move NOWRAP into CLASS statement
Colin Fleming
11:11 AM Revision 9ef4289c: Tidy up "system_usermanager.php" XHTML
Add CLOSEHEAD varialbe and manually close HEAD
Add CDATA sections to SCRIPTS
Deprecate Ampersand in Anchor tags
Remov...
Colin Fleming
10:53 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
After an upgrade from a rock-stable 2.0.3 to 2.1.3, I experience the same link lost problem with the PPP daemon.
My ...
Philippe P
05:06 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
i just tried it on 2.1.3 nanobsd alix and after the last time this was patched, it works fine, it was able to reconne... Bipin Chandra
09:43 AM Bug #3615 (Closed): /etc/rc.d/*.sh start" is executed during bootup, but equivalent "stop" cmd is never issued during shutdown
Closing by submitter request Renato Botelho
09:31 AM Bug #3569 (Feedback): pkg_edit.php jquery 'add' and 'delete' action scrolls page to top.
Pull requests merged Renato Botelho
09:29 AM Bug #3676 (Resolved): Some typos in the build log text output
Fixed, thanks! Renato Botelho
08:01 AM Bug #3648 (Feedback): Filter logs broken on amd64, working on i386
It should be fine now Renato Botelho
08:00 AM Bug #3669: WAN IPs not being cached causing unnecessary "rc.start_packages: Restarting/Starting all packages"
You can always use gitsync to sync your installation with latest changes made on branch, in this case RELENG_2_1.
...
Renato Botelho
08:00 AM Bug #3674 (Feedback): Subnet options do not activate on manual outbound NAT rule edit page
Applied in changeset commit:d758288839b46bc09507cdb9236d7cd110c0a01a. Renato Botelho
07:50 AM Bug #3663 (Feedback): Filter parser does not display ICMP log messages
Applied in changeset commit:efa26483ee517f6f5087631ef895cdc1f48c17e2. Renato Botelho

05/26/2014

06:19 PM Bug #3670: IPv6 DHCP-PD over PPPoE non functional + radvd core dump + solution
I have access to an Internode connection and can confirm Nic's findings.
The system is 2.1.3-RELEASE and I have appl...
Josh Cavalier
05:00 PM Bug #3680 (Resolved): disabling an interface which is part of an interface group puts another (arbitrary) interface into the group instead
Preconditions:
- Assume WAN interface W and VLAN interfaces A,B,C configured.
- Assume an interface group called G ...
Lukas Zeller
03:19 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I can confirm this issue on a Gigabyte GA-J1900N-D3V. I've tried AMD64/i386 builds of 2.1.3 as well as 2.2-DEVELOPMEN... Dan E
02:20 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I have the very same problem on 2.1.3 amd64: after series of disconnects pppoe daemon stops reconnecting;
ppp log:...
Dmitriy K
02:17 PM Bug #3679 (Closed): Wrong values Current Traffic Graph Dashboard WAN
I have bge0 and vr0 U300M linksys usb. On status RRD graph, is righ, but dashboard show wrong values. I enable traffi... Gilberto Tunon
10:03 AM Bug #3664 (Feedback): "IPsec" not displayed in firewall log interface column
This should have been fixed by the applied patch. Ermal Luçi
07:57 AM Bug #3619 (Feedback): ipfw/dummynet not always loaded when required in 2.2
This has been fixed with the bug on kldstat on 10. Ermal Luçi
 

Also available in: Atom