Project

General

Profile

Activity

From 06/08/2014 to 07/07/2014

07/07/2014

11:13 PM Revision 7b15d229: Avoid reseting firewall hostname by WAN DHCP. It should fix #3746
Renato Botelho
11:12 PM Revision 2d34e81a: Avoid reseting firewall hostname by WAN DHCP. It should fix #3746
Renato Botelho
11:06 PM Revision 971de1f9: Convert almost all /sbin/sysctl calls to php functions
Renato Botelho
09:54 PM Bug #3558: Schedule States in System - Advanced - Misc not working
@Phillip: I confirmed that your fix was in my test unit. The states still do not get cleared.
There are some subt...
Richard Coyote
06:29 PM Bug #3744: CARP IPs stuck in INIT on 2.2
Also sounds like a corrupted system Renato Botelho
06:28 PM Bug #3743: CARP status page broken on 2.2
This also sounds like a corrupted system, CARP IPs are on the same interface on 2.2, like this output:... Renato Botelho
06:21 PM Bug #3740: IPsec issues post-2.2 upgrade
Are racoon binaries available after upgrade? They should be removed by pfSense.obsoletedfiles. Based on the other tic... Renato Botelho
06:20 PM Bug #3746: Firewall hostname being reset by DHCP WAN client
Applied in changeset commit:7b15d22967a9f9fefe7b8b11fa2d68c762c55219. Renato Botelho
06:20 PM Bug #3746 (Feedback): Firewall hostname being reset by DHCP WAN client
Applied in changeset commit:2d34e81a9f80f556fa28d3a5ef30a7a7cad5285a. Renato Botelho
01:33 PM Bug #3746 (Resolved): Firewall hostname being reset by DHCP WAN client
If the firewall has a DHCP WAN, and the DHCP server on WAN supplies a hostname to the client, the firewall will take ... Jim Pingle
06:19 PM Bug #3742: SSH doesn't answer post-2.2 upgrade
What is the snapshot timestamp? I tested on Sun Jul 06 14:26:03 CDT 2014 and it's ok
About the sshd keys being reg...
Renato Botelho
06:16 PM Bug #3741: states output is broken on 2.2
What is the snapshot timestamp? I tested on Sun Jul 06 14:26:03 CDT 2014 and it's ok Renato Botelho
06:13 PM Bug #3739: netstat missing IP info in 2.2
What is the snapshot timestamp? I tested on Sun Jul 06 14:26:03 CDT 2014 and it's ok Renato Botelho
06:12 PM Bug #3738: sockstat broken on 2.2
What is the snapshot timestamp? I tested on Sun Jul 06 14:26:03 CDT 2014 and it's ok Renato Botelho
06:08 PM Bug #3369: Captive vouchers expire too quickly
Wolfgang Niggl wrote:
> I have the same problem. No solution or is it solved in 2.1.1 ?
> Where in the code could b...
Nick L
05:54 PM Bug #3187: LiveCD boot issue on multicore systems.
I can't speak to having tested this _exhaustedly_ this time, since two out of four of the original listed systems are... Christopher Sherman
03:52 PM Revision 79cd8239: Fix sysctl name
Renato Botelho
02:05 PM Revision 82f75815: Add set_single_sysctl(), a wrapper to set_sysctl() to make it simple to set value of a single sysctl
Renato Botelho
01:57 PM Revision ff23363d: Add get_single_sysctl(), a wrapper to get_sysctl() to make it simple to get value of a single sysctl
Renato Botelho
01:52 PM Revision aae16684: Fix indent
Renato Botelho
11:42 AM Revision 42bb1bee: Remove extra spaces and tabs
Renato Botelho
11:19 AM Bug #3745 (Resolved): VLANs are not ALTQ capable on 2.2 (missing patches?)
Trying to enable traffic shaping on VLANs with 2.2 does not work. The GUI allows them to be selected but pf generates... Jim Pingle

07/06/2014

11:41 PM Bug #3728: Cancel Button Doesn't Work - Firewall Aliases Edit
Fix confirmed in 2.2.
Still broken in 2.1.4.
NOYB NOYB
07:25 PM Revision e7f65689: Remove extra quote and fix syntax
Renato Botelho
05:24 PM Bug #3744 (Rejected): CARP IPs stuck in INIT on 2.2
On at least 32 bit. ... Chris Buechler
04:21 PM Bug #3743 (Rejected): CARP status page broken on 2.2
Where CARP IPs are in INIT (at a minimum), Status>CARP shows nothing under the "Status" column. ifconfig: ... Chris Buechler
04:09 PM Bug #3742 (Rejected): SSH doesn't answer post-2.2 upgrade
After upgrade from 2.1.4, on at least 32 bit, SSH is running properly but sends a RST back when attempting to connect... Chris Buechler
04:04 PM Bug #3741 (Rejected): states output is broken on 2.2
Partial state table dump.... Chris Buechler
03:50 PM Bug #3740 (Rejected): IPsec issues post-2.2 upgrade
Something not right with IPsec after upgrade to 2.2 (and maybe when starting clean on 2.2, haven't entirely confirmed... Chris Buechler
03:43 PM Bug #3739 (Rejected): netstat missing IP info in 2.2
"netstat -an" for instance in prior versions and stock FreeBSD lists "Active Internet connections" among the output. ... Chris Buechler
03:41 PM Bug #3738 (Rejected): sockstat broken on 2.2
results in: ... Chris Buechler
03:37 PM Bug #3723 (Feedback): URL Table based rules may pass blocked IP
what's in the table works as configured, it's likely the way outdated country data in the pfblocker package and/or a ... Chris Buechler
01:31 AM Bug #3624: "ppp: OpenConfFile: Can't open file '/var/etc/mpd_wan.conf': No such file or directory"
Forgot to say, I was having this problem on 2.1.3-RELEASE (amd64) but now am having the same problem on 2.1.4-RELEASE... Gareth Davies
01:29 AM Bug #3624: "ppp: OpenConfFile: Can't open file '/var/etc/mpd_wan.conf': No such file or directory"
Have tried the suggested work-around but it doesn't work for me. In case my symptoms are different I'm adding a short... Gareth Davies

07/05/2014

09:00 PM Revision 64746cf6: use HTTPS for dyndns providers that support it
Chris Buechler
09:00 PM Revision 9b8c7295: use HTTPS for dyndns providers that support it
Chris Buechler
04:33 PM Bug #3723: URL Table based rules may pass blocked IP
As an FYI, The pfBlocker Country Codes has been obsolete for almost two years now.
It still shouldn't be allowing ...
BBcan177 .
02:43 PM Bug #3554: apinger and OpenVPN: Gateway down after OpenVPN client service restart
Cullen Trey wrote:
> Hi,
>
> it seems to happen, if the openvpn interface comes up but encounters an error: in my...
Michael Sparks
03:57 AM Bug #3692: apinger loss % gets stuck
I'm having the same issue with 2.1.4.
I have to restart the entire pfsense box to correct it, just restarting the ...
Anonymous
01:16 AM Bug #3737 (Duplicate): Incoming VLAN traffic fails to reach VLAN interface if PCP not 0
On ESXi, incoming VLAN traffic fails to reach the related VLAN interface if PCP is set to anything else than the defa... Clement Barnier

07/04/2014

07:53 PM Revision 3fe260c2: Use a php function rather tan using exec. Suggested-by: garga
Ermal LUÇI
02:51 PM Revision 95cdee87: Remove all .xml file generated from upgrade since it makes /var full
Ermal LUÇI
01:18 PM Bug #3725 (Resolved): Firewall Logs Widget Filters Not Working
Renato Botelho
01:11 PM Bug #3725: Firewall Logs Widget Filters Not Working
Fix confirmed in both 2.1.4 and 2.2 Alpha. Thanks
NOYB NOYB
12:44 PM Revision 2e906a1a: Add one more seatbelt to prevent tar to attempt to overwrite /dev items
Renato Botelho
07:23 AM Bug #3736 (Resolved): No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
The IPv6 is not displayed in the Dashboard page when using a static IPv6 on WAN interface.
Steps for reproducing t...
Eric Boudrand
07:21 AM Bug #3735 (Rejected): No default route when using WAN static IPv6 address
No default route is created when using a static IPv6 on WAN interface.
Steps for reproducing the issue :
- enable...
Eric Boudrand
06:43 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I am not entirely sure...
Chris Buechler seemed to know a little about this, as stated above "This has been worked...
Stuart Lamble
04:37 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
How do we get it in the next update? Eric Tol

07/03/2014

09:07 PM Revision be0af33e: Add missing $g to global, as noted on pull request 1249
Renato Botelho
03:09 PM Feature #785: DNS servers over gateways
it's possible. That's a support request, which isn't appropriate here, please use one of our available support resour... Chris Buechler
12:32 PM Feature #785: DNS servers over gateways
Chris Buechler wrote:
> yes that's all possible. You can do that manually as well, with floating rules.
I just ga...
Zoo Mer
01:17 PM Feature #484 (Feedback): Add a warning if users are using non-official package repo
This is now in current snapshots and may be good enough for 2.2.
I did find that the XML_RPC code is in need of an...
Jim Pingle
01:15 PM Todo #3734 (Resolved): Remove PHP static pear modules from repo and use ports
The current XML_RPC code from PEAR in /etc/inc/xmlrpc_client.inc and /etc/inc/xmlrpc_server.inc is a bit behind. XML_... Jim Pingle
12:52 PM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
One of my sites that relies on radio-based Internet connectivity is experiencing this misbehavior. We are very, VERY... Chris Largent
12:36 PM Bug #3647 (Resolved): Serial console input is sent to system log as kernel messages
Renato Botelho
12:31 PM Bug #3647: Serial console input is sent to system log as kernel messages
I am no longer seeing the console input in the logs on current snapshots, this appears to be fixed now. Jim Pingle
12:26 PM Revision d461583b: Change Cancel button to call history.back() as done in Firewall Rules, the current method has issues with IE 11, it should fix #3728
Renato Botelho
07:30 AM Bug #3728 (Feedback): Cancel Button Doesn't Work - Firewall Aliases Edit
Applied in changeset commit:d461583b18b84b47ba0a398b9138085fa8eb47c8. Renato Botelho
04:33 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Just for info, no change with release 2.1.4
As said above, the workaround did not make it into this release.
Stuart Lamble
04:31 AM Bug #2945: Installation stucks at 36%: /usr/local/bin/cpdup -vvv -I -o /usr /mnt/usr
Hi Frenel
How has the GB J1900n-d3v been going? I also managed to get pfsense installed, but if the system reboots...
Stuart Lamble
04:18 AM Bug #3733 (Resolved): Certificate manager doesn't allow wildcards in Subject Alternative Names
Hi there,
Having a wildcard certificate in the DNS Subject Alternative Name is valid, but the pfSense webinterfa...
Johan Braeken
03:13 AM Feature #3732 (Rejected): Request: a small info about the pfSense kernel build - to help build 3rd party software for pfSense
The source is not closed, it's under an open source license and anyone can obtain it.
https://forum.pfsense.org/inde...
Chris Buechler
02:47 AM Feature #3732 (Rejected): Request: a small info about the pfSense kernel build - to help build 3rd party software for pfSense
For building certain 3rd party software - For example the "virtualbox-ose" port. Or "cuse4bsd".
These programs (an...
Dreamcat Four
02:23 AM Feature #3731 (Closed): request: kernel module "zfs.ko" for optional zfs file support, and options VIMAGE
I am aware that ZFS is a storage feature and not required by Router / Firewalls. However to include gives more option... Dreamcat Four

07/02/2014

09:46 PM Bug #3147: Adding new interface can cause issues
The issue affects more than just VIPs. Whatever auto-populates the 'Network Port' field after the new Interface is a... Chris Thomas
08:46 PM Bug #3558: Schedule States in System - Advanced - Misc not working
@Richard: I fixed up the timing of the schedule end, so now the state clearing code should be executed at the correct... Phillip Davis
08:24 PM Revision d4b1e549: Back to cons25 for now since we found some issues with xterm on serial console
Renato Botelho
08:24 PM Revision 23c01a69: un-obsolete gettytab.bak
Renato Botelho
07:20 PM Revision 6916360e: Also check and verify the package server's SSL certificate if using HTTPS. Issue 484
Our current XMLRPC client version doesn't have support on its own to validate this in a way we can use to test in a u... Jim Pingle
04:07 PM Revision 7c8f3711: More refinements to the unofficial package repository warning ( Issue #484 ) -- Now also shows on Dashboard and installed package list. Cleaned up some code and shuffled things around to avoid unnecessary repetition.
Jim Pingle
12:02 PM Bug #3728: Cancel Button Doesn't Work - Firewall Aliases Edit
Tried again on 2 machines. Neither works. Though the other (NAT & Rules) edit cancel buttons work fine. But the Al... NOYB NOYB
06:51 AM Bug #3728: Cancel Button Doesn't Work - Firewall Aliases Edit
It works fine for me, on 2.1.4 and 2.2 snapshot Renato Botelho
09:35 AM Bug #3730 (Resolved): Router advertisement advertises gateway address as dns server even if the dns forwarder is disabled
When using 6to4 on wan and assigning an interface tracking that, the radvd advertises the interface address as a dns ... Jupiter Vuorikoski
08:30 AM pfSense Packages Bug #3729 (Resolved): Bacula-client Services not running
Version: 2.1.4-RELEASE (amd64)
Package: bacula-client 5.2.12_3 pkg v 1.0.3
The service was not running because th...
Anonymous
07:01 AM Bug #3717 (Resolved): Adding an IPv6 rule on an interface with IPv6 gateway does not add "reply-to" in the resulting rule - fix proposal attached
It was already fixed in commit:93f1d233b27d9aa3347050b2e7138660a23e28f9 Renato Botelho
02:15 AM Bug #3724 (Resolved): Jumbo frames not being honoured with vmxnet3 driver
that is indeed an issue with FreeBSD 8.3, confirmed fixed in 2.2.
Chris Buechler
01:45 AM Bug #3669 (Resolved): WAN IPs not being cached causing unnecessary "rc.start_packages: Restarting/Starting all packages"
Chris Buechler
01:44 AM Bug #3695 (Resolved): CVE-2014-0224 - OpenSSL SSL/TLS MITM vulnerability
was fixed in 2.1.4, ticket never got closed out. Chris Buechler

07/01/2014

08:28 PM Revision 38c7d42e: Set proper serial parameters on boot.config and loader.conf for nanobsd without vga
Renato Botelho
07:22 PM Revision c55dfc4a: Detect if an unofficial package repository is in use and warn the user. Part of issue #484 (more to go)
Jim Pingle
05:11 PM Revision c5f9fb72: Make proper checks to check if we should or not enable serial console
Renato Botelho
05:11 PM Revision e6e3e0ee: Fix typo on var name
Renato Botelho
04:43 PM Revision 1053983c: Obsolete ttys_wrap and gettytab.bak
Renato Botelho
04:37 PM Revision edb4b657: Fix #3647 and other improvements:
- Remove auto_login(), now gettytab is a constant file
- Add reload_ttys(), that will send a SIGHUP to init and make ...
Renato Botelho
04:37 PM Revision 6f9a191d: Change default console from cons25 to xterm, while I'm here, simplify the check
Renato Botelho
04:35 PM Revision 7f394d3e: Stop calling auto_login() here since it's already called inside setup_serial_port()
Renato Botelho
04:35 PM Revision 3c72e984: Stop restoring gettytab.bak since it doesn't exist anymore
Renato Botelho
04:34 PM Revision d8f123b8: Sync etc/ttys with FreeBSD 10-STABLE, change default console for al.Pc and default serial for al.115200
Renato Botelho
04:33 PM Revision 025ad9ef: Sync gettytab with FreeBSD 10-STABLE, also reduce customizations, the only difference is al.Pc entry, for Pc with auto login
Renato Botelho
04:32 PM Revision a9e595cc: Remove unused function color()
Renato Botelho
04:31 PM Revision e6974dfe: Delete gettytab.bak and ttys_wrap, they are not needed anymore
Renato Botelho
04:10 PM Bug #3198: IPSEC, when nating to a different size subnet a invalid natting rule is made.
I confirm this bug for 2.1.4
https://forum.pfsense.org/index.php?topic=78637 (in Spanish)
Difficult to understa...
Josep Pujadas-Jubany
12:20 PM Bug #3728 (Resolved): Cancel Button Doesn't Work - Firewall Aliases Edit
Cancel button in Firewall Aliases Edit does not work. NOYB NOYB
12:20 PM Bug #3647 (Feedback): Serial console input is sent to system log as kernel messages
Applied in changeset commit:edb4b65732d76810e5610bcece85571f13969fc0. Renato Botelho

06/30/2014

08:18 PM Revision 8ff231b4: fixes #3713
Dmitriy K.
04:44 PM Bug #3558: Schedule States in System - Advanced - Misc not working
Here is a workaround that works on 2.1.4-RELEASE (i386) for the benefit of those who find this bug report. (I acciden... Richard Coyote
03:10 PM Bug #3727 (Resolved): PPP config loses "on-demand" setting when configured via interfaces tab
I configured a PPP interface to run a verizon LTE modem plugged into a USB port. It is assigned as "WANVZ"
If I go...
Vick Khera
01:57 PM Revision c69e813c: Fix #3725:
- Fix match_filter_field() and also simplify logic
- Fix $filterfieldsarray initialization
- Avoid to have double spa...
Renato Botelho
01:47 PM Revision 939f4e39: Fix #3725:
- Fix match_filter_field() and also simplify logic
- Fix $filterfieldsarray initialization
- Avoid to have double spa...
Renato Botelho
12:54 PM Bug #3647: Serial console input is sent to system log as kernel messages
It was happening with a recent snapshot on my 7551 at home as well. Jim Thompson
11:02 AM Bug #3647 (New): Serial console input is sent to system log as kernel messages
This is still happening on a current snapshot on my ALIX running NanoBSD on i386.
Serial terminal:...
Jim Pingle
10:39 AM Bug #3647 (Feedback): Serial console input is sent to system log as kernel messages
I couldn't reproduce it on an updated VM running amd64 snapshot (Full install) from Mon Jun 30 05:10:01 CDT 2014 Renato Botelho
10:46 AM Bug #3726 (Not a Bug): Firewall Rule with Diffserv Code Point not matching properly
I am using 2.1.4.
I have set up some simple traffic-shaping, and have several Floating firewall rules to send vari...
James Dietrich
09:40 AM Bug #3688 (Resolved): firewall rule syntax error with Diffserv Code Point
Renato Botelho
09:38 AM Bug #3688: firewall rule syntax error with Diffserv Code Point
I updated to 2.1.4 a few days ago, and now I do not get this syntax any more.
Thank you!
James
James Dietrich
09:00 AM Bug #3725: Firewall Logs Widget Filters Not Working
Applied in changeset commit:c69e813c8420f2db40fcbd2f418cae8553852d66. Renato Botelho
09:00 AM Bug #3725 (Feedback): Firewall Logs Widget Filters Not Working
Applied in changeset commit:939f4e39278d8acc1709bae76f51ec6551091fec. Renato Botelho

06/29/2014

05:09 PM Bug #3725 (Resolved): Firewall Logs Widget Filters Not Working
The Pass, Block, Reject and Interface filters in the Firewall Logs Widget are not working/filtering.
This issue is...
NOYB NOYB
01:06 AM Bug #3724 (Resolved): Jumbo frames not being honoured with vmxnet3 driver
Hi
I tried asking in the forum but I guess its not a common problem.
I will very happily try to help track this...
Alex Needham

06/28/2014

10:30 PM Bug #475: L2TP is not functional in the way users will expect
Slava Bendersky wrote:
> Just stop using racoon ? Why not start using libreswan base on netkey or klips. Libreswan m...
Slava Bendersky
10:29 PM Bug #475: L2TP is not functional in the way users will expect
Why do not stop using racoon ? Why not start using libreswan base on netkey or klips. Libreswan match match more suti... Slava Bendersky
09:59 AM Bug #3714: Session cookie inconsistent behavior when switching GUI protocols
Unfortunately, yes. I found this on a 2.1.4 image while confirming that the other bugs had been fixed. Jim Pingle
09:01 AM Bug #3723 (Rejected): URL Table based rules may pass blocked IP
I've noticed that bug few days ago when was inspecting my mail server. My first block rule was using an URL table (a ... Dmitriy K

06/27/2014

09:42 PM Bug #3714: Session cookie inconsistent behavior when switching GUI protocols
does this still happen with the recent GUI fixes in 2.1.4? Jim Thompson
09:41 PM Bug #3640: Sierra Wireless 3G Modem support driver
I can't assign this to anyone unless we have hardware in-house. Jim Thompson
07:21 PM Revision 6d74e3e9: Merge pull request #1244 from phil-davis/patch-11
Renato Botelho
02:56 PM Revision 0ffc4a7b: Add a BETA key for PBI signature check, this will be replaced by the final one before RELEASE. Ticket #3365
Renato Botelho
02:44 PM Revision 485cc436: Fix dir name
Renato Botelho
09:58 AM pfSense Packages Bug #3645 (Feedback): Many Call-time Pass-by-reference instances in packages need fixed for PHP 5.5
I believe they are all fixed Renato Botelho
08:25 AM Bug #3722 (Rejected): OpenVPN Client Especific Overrides Advanced field
As the text under the option says, place a semicolon (";") between statements. Jim Pingle
08:23 AM Bug #3722 (Rejected): OpenVPN Client Especific Overrides Advanced field
I have a problem after upgrades in "Client Specific Overrides".
In the "Advanced" field put two rules, where each...
Felipe Nogueira Oliva

06/26/2014

07:44 PM Revision 4887afa1: Set default serial speed to 115200 for 2.2, fixes #3715
Renato Botelho
03:24 PM Revision 2bf2a1c4: Fix a regression introduced on 8d6c5f6621 that broke CARP+IP alias
Renato Botelho
02:50 PM Todo #3715 (Feedback): Change default serial speed to 115200
Applied in changeset commit:4887afa18b1cef26ed28b44ded38afc8b344767b. Renato Botelho
09:32 AM Revision 0ee60267: Handle no dhcpd settings when upgrading
This minor fix was in master but not 2.1 branch. I noticed the warning message when doing a fresh install/test of 2.1... Phil Davis
04:25 AM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Tried now with a ZTE MF668 it does start the u3g fine but it does not get an IP address from the mobile provider.
Christophe Prevotaux

06/25/2014

03:18 PM Revision 4b167dcd: Merge pull request #1238 from DasTestament/master
Renato Botelho
10:55 AM Bug #3721 (Rejected): UDP port 53 is locked by DNS Forwarder even if interface is not selected
You must use the "Strict Interface Binding" option to force dnsmasq to change its binding in the way you describe. Ot... Jim Pingle
10:46 AM Bug #3721 (Rejected): UDP port 53 is locked by DNS Forwarder even if interface is not selected
Hello
Currently running the latest pfsense 2.1.3-RELEASE (amd64).
Currently I have some Virtual IPs setup for o...
Gio M
10:30 AM Bug #3401 (Feedback): Openvpn Server IPV4 generating attribute TUN-IPV6 this right?
Applied in changeset commit:b9e9903ddb21665023c9fcc241099476a42a9dbd. Anonymous
08:24 AM Bug #3361: DHCP6 WAN is not obtaining a default gateway
There was a little more info #3649 about this. Specifically, Ermal's comment on that ticket that "rtsold is not passi... Jim Pingle
02:31 AM Bug #3720 (Resolved): Captive portal on httpS redirect to a http page
When you set your captive portal to use httpS and set a after authentication url (redirect) to a http (not S) url, th... Sander Naudts

06/24/2014

09:06 PM Revision b0cbebeb: Add the AESGCM and XCBC on the list of algos availble
Ermal LUÇI
07:18 PM Revision b176474b: Update vpn_openvpn_server.php
Dmitriy K.
07:15 PM Revision 4be2bfed: Update vpn_openvpn_client.php
Dmitriy K.
06:09 PM Revision 649b6b85: Actually use ph1ent ikeid here otherwise will duplicate ids here.
Ermal LUÇI
04:44 PM Bug #2038: Some 3G WANs on 2.0.x do not come up on cold boot
Just had this problem with a HUAWEI E1752 on cuaU0.0
running on a :
* 2.1.3-RELEASE (amd64)
* built on Thu May 0...
Christophe Prevotaux
04:40 PM Bug #781: Entering sim code problem on a Huawei E1752
running a PC Engines APU Christophe Prevotaux
04:40 PM Bug #781: Entering sim code problem on a Huawei E1752
I forgot to mention this is with a
2.1.3-RELEASE (amd64)
built on Thu May 01 15:52:13 EDT 2014
FreeBSD 8.3-RELE...
Christophe Prevotaux
04:38 PM Bug #781: Entering sim code problem on a Huawei E1752
I had a similar problem with a HUAWEI E1752 after a cold boot.
Warm reboot works everytime.
Not sure what the p...
Christophe Prevotaux
03:06 PM Revision 0d26e77c: Merge pull request #1241 from Gertjanpfsense/master
Renato Botelho
03:00 PM Revision c15b5ed8: Fix dscp values and provide a config upgrade to fix values stored in config.xml. This is a proper fix for #3688
Renato Botelho
12:42 PM Revision 5a145a54: Delete README.md
Gertjan KROEB
12:27 PM Revision b1e8e675: Update openvpn.inc
Dmitriy K.
08:23 AM Bug #3719 (Not a Bug): vmware cpu host extraordinary high usage
pfSense is installed as VM in VMware ESXi (4, 5.1, 5.5), when pfSense is under high traffic (bandwidth or numerous co... Kenshiro TheFist

06/23/2014

10:26 PM Revision fbe0c5ff: Tidy up misc. XHTML
"diag_dns.php"
Tidy up "equals sign"
"services_captiveportal.php"
Add space to OPTION tag
Update HTML Boolean operat...
Colin Fleming
05:41 PM Revision 5d792074: Update status_captiveportal.php
Don't ask to select a zone if there is only ONE. Gertjan KROEB
04:58 PM Revision fc227e34: Create README.md
Gertjan KROEB
12:32 PM Revision 6c87714d: Add local/www to the list of directories that needs to be symlink'd to reduce PBI differences between 2.1 and 2.2
Renato Botelho

06/22/2014

08:24 PM Bug #3716: Adding IPv6 alias to IPv6 CARP IP throws error - fix proposal attached
It will be easy for the devs to review this if you go to github - https://github.com/pfsense/pfsense - and make the c... Phillip Davis
04:36 PM Bug #3716 (Resolved): Adding IPv6 alias to IPv6 CARP IP throws error - fix proposal attached
Hi,
Adding an IPv6 alias to an IPv6 CARP IP throws the following error:
"...Could not find a matching real interf...
Marc Posch
05:23 PM Feature #3718 (New): radvd - enhancement proposal: ability to advertise routes and some fixes - patches attached
Hi,
I was configuring radvd on two back-to-back firewalls with an in-between subnet and I was missing the feature ...
Marc Posch
04:55 PM Bug #3717 (Resolved): Adding an IPv6 rule on an interface with IPv6 gateway does not add "reply-to" in the resulting rule - fix proposal attached
Hi,
I had problems with Multi-WAN and two IPv6 tunnelbrokers - incoming traffic would "work" only when coming thro...
Marc Posch

06/21/2014

09:23 PM Revision 1657cfd2: oops, that wasn't supposed to be removed.
N0YB
09:16 PM Revision 60a5f9de: Use count($array) where applicable, instead of a $rowIndex increment.
N0YB

06/20/2014

07:14 PM Revision 1a7ed9d0: Don't use pfsense name in comment
Adam Gibson
06:53 PM Revision 05b69065: Use $product instead of pfSense when logging the version to syslog
Adam Gibson
04:06 PM Revision 5b3c0116: Update openvpn.inc
Added verbosity check in case when verbosity_level is absent in config.xml Dmitriy K.
03:59 PM Revision bfa22b15: Update vpn_openvpn_server.php
removed comments Dmitriy K.
03:56 PM Revision 34c0adfc: Update vpn_openvpn_client.php
removed comments Dmitriy K.
02:57 PM Revision 0e678da7: Update openvpn.inc
Removed unnecessary "else {"; Dmitriy K.
02:25 PM Revision efac3a13: Only include a scheduled rule if it is strictly before the end time
The exact moment of the end time is the end of the schedule. We do not want to include a rule when filter_configure_s... Phil Davis
02:25 PM Revision 9f5de694: Merge pull request #1239 from phil-davis/patch-9
Jim Pingle
01:36 PM Revision 052dfa93: Remove extra data after space and fix pf rule syntax. It should fix #3688
Renato Botelho
01:35 PM Revision e792ac36: Remove extra data after space and fix pf rule syntax. It should fix #3688
Renato Botelho
12:36 PM Revision 1c9a521b: Merge pull request #1208 from razzfazz/nat_add_missing_protocols
Renato Botelho
12:35 PM Revision df203cb8: Merge pull request #1218 from razzfazz/nat_add_missing_protocols_master
Renato Botelho
12:05 PM Todo #3715 (Resolved): Change default serial speed to 115200
The default serial console speed should be changed to 115200 to be more in line with current hardware.
To ensure b...
Jim Pingle
10:29 AM Bug #3714 (Resolved): Session cookie inconsistent behavior when switching GUI protocols
The session cookie can end up being non-secure on HTTPS in a specific set of circumstances:
1. Set GUI to HTTPS
2...
Jim Pingle
09:30 AM Bug #3558: Schedule States in System - Advanced - Misc not working
Applied in changeset commit:efac3a1346867481d6cfcea62c131ad0c0de391b. Phillip Davis
09:30 AM Bug #3558 (Feedback): Schedule States in System - Advanced - Misc not working
Applied in changeset commit:a43c5bdea7ee07a5075d8c22a7a247424669e6f3. Phillip Davis
08:50 AM Bug #3688: firewall rule syntax error with Diffserv Code Point
Applied in changeset commit:052dfa9346e716d63fbd85735c4a8784e6ed07e2. Renato Botelho
08:50 AM Bug #3688 (Feedback): firewall rule syntax error with Diffserv Code Point
Applied in changeset commit:e792ac36324e3376763699344742d5dc49eab99c. Renato Botelho
07:34 AM Bug #3689 (Feedback): Filter logs Input Validation Failure
Pull request merged Renato Botelho
07:32 AM Bug #3707 (Resolved): pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Renato Botelho
07:31 AM Bug #3712 (Feedback): missing protocols in NAT edit page
Pull requests merged. Renato Botelho

06/19/2014

07:29 PM Revision 96fcabaa: Replace some backticks by exec ans simplify commands
Renato Botelho
07:20 PM Revision 692c21fd: Remove more backtick abuse
Renato Botelho
06:58 PM Revision 3f0c20c3: Add -n for 2 remaining sysctl calls, also replace backtick by exec
Renato Botelho
06:57 PM Revision c69d32f6: Add full path for dmesg and replace backtick by exec
Renato Botelho
04:05 PM Revision 4f380b62: Remove also . and / from graph
Renato Botelho
04:04 PM Revision 902da388: Remove also . and / from graph
Renato Botelho
03:29 PM Revision bc27c6d1: Remove more backticks
Renato Botelho
03:26 PM Revision 57627d9f: Fix status_rrd_graph_img.php and also improve it:
- Remove escapeshellarg that broke command line
- Only remove dangerous chars to avoid command injection
- Replace al...
Renato Botelho
03:23 PM Revision 2d1e985d: Fix status_rrd_graph_img.php and also improve it:
- Remove escapeshellarg that broke command line
- Only remove dangerous chars to avoid command injection
- Replace al...
Renato Botelho
02:30 PM Revision bef10560: Make sure single quotes are encoded and avoid javascript injection
Renato Botelho
02:29 PM Revision daeab6c4: Fix indent and whitespaces
Renato Botelho
02:29 PM Revision 8aca755a: Make sure single quotes are encoded and avoid javascript injection
Renato Botelho
01:37 PM Revision cedd0705: Use CDATA for javascript
Renato Botelho
01:37 PM Revision 559929c2: Fix indent and whitespaces
Renato Botelho
01:29 PM Bug #3692: apinger loss % gets stuck
I noticed this yesterday. For a period of time I had a bad episode of packetloss on a WAN gateway and even though th... Jason Ross
04:47 AM Revision a43c5bde: Only include a scheduled rule if it is strictly before the end time
The exact moment of the end time is the end of the schedule. We do not want to include a rule when filter_configure_s... Phil Davis
04:47 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
A response.... and the last gigabyte anything I ever buy!
"
Thank you for your kindly mail and inquiry. Accordi...
Stuart Lamble
03:17 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I doubt you'll get a reply in any reasonable amount of time from motherboard manufacturers, but maybe if enough peopl... Chris Buechler
03:11 AM Bug #3558: Schedule States in System - Advanced - Misc not working
yeah the 59 was originally added so you can do 23:59. Chris Buechler
02:59 AM Bug #3558: Schedule States in System - Advanced - Misc not working
and I think the "59" minute end time option is so that a schedule can go to 23:59 - there is no way to specify 24:00 ... Phillip Davis
01:30 AM Bug #3683: pfSense Not Blocking Pre-Auth Captive Portal DNS Requests
where you actually have a block all rule, or no pass rules, connections cannot be established.
The pre-auth conne...
Chris Buechler

06/18/2014

11:45 PM Bug #3558: Schedule States in System - Advanced - Misc not working
I looked at this a while ago and then had trouble replicating the problem. I suspect it only occurs when the filter_c... Phillip Davis
10:22 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Still no reply from Gigabyte... Stuart Lamble
07:54 PM Revision aba02f65: Simplify logic, add some protection to user input parameters
Renato Botelho
07:39 PM Revision d1dda498: Simplify logic, add some protection to user input parameters
Renato Botelho
06:41 PM Revision f1a13a7f: Fix whitespaces and indent
Renato Botelho
06:38 PM Revision f334f8bf: Fix whitespaces and indent
Renato Botelho
04:46 PM Revision bef9f697: We need to allow subdirectories under /usr/local/pkg, here is the proper fix
Renato Botelho
04:46 PM Revision 811baa9b: We need to allow subdirectories under /usr/local/pkg, here is the proper fix
Renato Botelho
11:21 AM Revision 08f30320: Change the option for webconfig login autocomplete from opt-in to opt-out, also bump config version and write a function to keep the current status on upgrades
Renato Botelho
10:52 AM Revision e8abc4a7: Set 'Disable webConfigurator login autocomplete' as on by default
Renato Botelho
10:38 AM Revision 16789caa: Always set httponly attribute on cookies
Renato Botelho
10:38 AM Revision fa73c7cd: Always set httponly attribute on cookies
Renato Botelho
01:37 AM Revision 56bd2035: Fix syntax error
Jim Pingle
12:33 AM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Just to make sure things are as working as last week as per 18 june 05:30 UTC, the current commit I get is dated from... Mathieu Simon

06/17/2014

06:38 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I have logged a call with Gigabyte siting the BIOS ACPI issues and that F3 bios update does not address this problem.... Stuart Lamble
07:58 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Someone "pointed out":https://forum.pfsense.org/index.php?topic=72305.msg426782#msg426782 that this appears to be a B... Ken Masterson
04:05 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Same problem here on the Gigabyte J1900N-D3V motherboard.
Also put some info up on this link on the forum:
https://...
Stuart Lamble
06:13 PM Revision 2b641a08: Protect servicestatusfilter parameter with htmlspecialchars()
Renato Botelho
06:13 PM Revision ce9d5d72: Protect servicestatusfilter parameter with htmlspecialchars()
Renato Botelho
05:53 PM Revision e4921058: Protect rssfeed parameters with htmlspecialchars()
Renato Botelho
05:53 PM Revision 860b102a: Protect rssfeed parameters with htmlspecialchars()
Renato Botelho
05:28 PM Revision 526f5b11: Add comment I forgot on last commit
Renato Botelho
05:27 PM Revision 3034b371: Add comment I forgot on last commit
Renato Botelho
05:27 PM Revision 8588095f: Re-generate session ID on a successful login to avoid session fixation
Renato Botelho
05:26 PM Revision ff9b30ec: Re-generate session ID on a successful login to avoid session fixation
Renato Botelho
04:47 PM Revision 62480a44: Avoid directory traversal on restorefullbackup
Renato Botelho
04:47 PM Revision 5de32d52: Avoid directory traversal on restorefullbackup
Renato Botelho
04:37 PM Revision b67cdd05: Fix core dump on viewing invalid package log
Matthew Smith
04:30 PM Revision 7be297a2: Fix core dump on viewing invalid package log
Matthew Smith
02:17 PM Revision 7145cd87: Remove . and / from pkg name to avoid directory traversal
Renato Botelho
02:17 PM Revision 1cfe5490: Remove . and / from pkg name to avoid directory traversal
Renato Botelho
01:48 PM Revision c3936caf: Remove id=0 from miniupnpd menu and shortcut
Renato Botelho
01:48 PM Revision 73944f68: Remove id=0 from miniupnpd menu and shortcut
Renato Botelho
01:33 PM Revision 69eb2e29: Avoid directory traversal when reading package xml files, also check if file exists before try to read it
Renato Botelho
01:33 PM Revision 9ddd3418: Avoid directory traversal when reading package xml files, also check if file exists before try to read it
Renato Botelho
01:19 PM Revision d09ff9ef: Make sure variables are escaped, also replace exec calls to run rm by unlink_if_exists()
Renato Botelho
01:19 PM Revision 65eb0f61: Remove useless code, variable is set again on next line
Renato Botelho
01:19 PM Revision aa27de6e: Make sure variables are escaped, also replace exec calls to run rm by unlink_if_exists()
Renato Botelho
01:18 PM Revision 592abfa4: Remove useless code, variable is set again on next line
Renato Botelho
12:40 PM Revision 45438fd3: Escape parameters passed to shell_exec()
Renato Botelho
12:40 PM Revision e41ab9aa: Escape parameters passed to shell_exec()
Renato Botelho
12:31 PM Revision 76c4ff0e: Be more careful with host parameter and make sure it's escaped when call shell functions
Renato Botelho
12:28 PM Revision ee4ba9fb: Be more careful with host parameter and make sure it's escaped when call shell functions
Renato Botelho
10:34 AM Revision 54a9da9f: Validate starttime and stoptime format
Renato Botelho
10:33 AM Revision 65f815dd: Validate starttime and stoptime format
Renato Botelho
07:38 AM Revision c7264382: Default values for verb if it is not set when edit
Dmitriy K.
07:09 AM Revision caf58ced: a bit of refactoring
forgot to sync _server.php with _client.php naming style Dmitriy K.
07:01 AM Revision b9e9903d: patchpack1
-Fix #3401 (Added tun option "Disable IPv6"
-Added new options: route-nopull, route-noexec, verb;
Dmitriy K.

06/16/2014

10:14 PM Revision 2464e353: XHTML Compliance - System Menu
Enforce select option N0YB
07:39 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I'm having no luck getting pfsense to boot on my Intel NUC DN2820. Kernel panics with "Bogus interrupt trigger mode.". Aaron Fields
07:26 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
So this looks like a BIOS bug (bad ACPI table) that would be possible to workaround.
Those of you with the Gigabyte ...
Steve Wheeler
05:06 AM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
I can confirm the same issue with ASUS J1900I-C. Both with pfsense 2.1.3 and with pfSense-memstick-serial-2.2-DEVELOP... Joel Larsson
06:10 PM Revision 7860191a: Create some symlinks inside pbi dir to reduce differences between 2.1 and 2.2 and avoid the need to change a lot of PBI scripts
Renato Botelho
06:00 PM Revision ef462f25: Make the byte counts on OpenVPN status human readable rather than huge unformatted numbers.
Jim Pingle
03:30 PM Bug #3558: Schedule States in System - Advanced - Misc not working
This is definitely a problem. It appears to be due to the timing and boundaries of the schedules.
If you end a sch...
Jim Pingle
02:18 PM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
I could not find an ICLA or CCLA in the database.
@Per von Zweigbergk:
If you could please sign either the Indiv...
Jim Pingle
02:12 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
The ICLA looks OK, I show that it was signed and submitted. Thanks!
I added some comments on the pull request for ...
Jim Pingle
07:50 AM Bug #3321: IPSEC failure on modem reset, automatic reconnection is broken, must manually restart racoon service
Seems to be broken in 2.1.3 with Draytek Vigor 2200E. Need Cronjob to restart periodically. Matthias Heer
07:14 AM Revision b4e9a4da: XHTML Compliance - System Menu
Advanced - Admin Access Tab
Advanced - Firewall / NAT Tab
Cert Manager - Certificate Revocation Tab
User Manager - Us...
N0YB
05:47 AM Bug #3637 (Resolved): Incorrect interface matching on bridge edit page
Renato Botelho
02:28 AM Bug #3637: Incorrect interface matching on bridge edit page
Seems to be working correctly now Peter O
02:19 AM Bug #2882: 6RD not working in latest snapshots
I've put up a bounty for this issue to be fixed in the near future (3 months of I dont update the post): https://foru... Rune Darrud

06/15/2014

11:51 PM Bug #3713 (Resolved): Gateways missing for OpenVPN server (shared key or /30s)
Dmitriy K
09:26 PM Bug #1629: invalid state table entries after WAN IP change
assigned to Ermal, either fix this or push it to 2.3 Jim Thompson
09:24 PM Feature #484: Add a warning if users are using non-official package repo
bumped priority
assigned to Pingle.
I'd like this implemented in 2.2.
I'd also like it displayed both on Main -> Pa...
Jim Thompson
09:24 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
I believe I signed one in the correct place just now (portal.pfsense.org). Please let me know if I need to do anythin... Daniel Hazelbaker
09:17 PM Feature #3410: Patch: Add Apple Open Directory memberUid support in group lookup
assigned to Pingle. Once a CLA has been signed, we can look at incorporating this. Jim Thompson
09:23 PM Feature #983: Improve/Enhance IP Alias VIP handling in GUI
assigned to Renato.
see other comments on possible security issues in the Alias code.
Jim Thompson
09:22 PM Bug #1186: When in pure routing mode the rrd graphs are blank
pushed to 2.3 Jim Thompson
09:21 PM Bug #1681: OpenVPN tun IPs fail HTTP REFERER checks
pull request received 3 months ago. assigned to Pingle.
please ensure that a CLA is on-file before reviewing the ...
Jim Thompson
09:20 PM Bug #2218: CARP VIPs can become master too early at boot time
pushed to 2.3 Jim Thompson
09:19 PM Bug #2625: Inconsistent behavior with Alias info popup
Assigned to Renato.
While you're in there, I suspect security issues in the Alias code.
Jim Thompson
09:18 PM Feature #3365: Implement package signing
assigned to Renato, increased priority.
please work with porter on how this gets done.
Jim Thompson
09:16 PM Bug #3558: Schedule States in System - Advanced - Misc not working
Assigned to Pingle for evaluation and resolution. Jim Thompson
09:15 PM Feature #3667: Hook for user shutdown script - "/etc/rc.custom_shutdown"
assigned to Renato for evaluation. Jim Thompson
09:14 PM Bug #3597: Package reinstall on system upgrades needs some fallback handling
assigned to Renato.
on full installs, it might be nice to cache the packages.
Jim Thompson
09:09 PM Bug #2984: IPSec adds route but isn't needed any more
assigned to Ermal for final evaluation. Fix it or close it. Jim Thompson
09:08 PM Bug #3125: hifn on 2.1 breaks certain ciphers w/openssl
I'm not sure this is a bug we should attempt to fix in 2.2. Marked as 'future'. Jim Thompson
09:50 AM Revision 959c12cf: Remove Status Verbiage. Consumes too much realestate in widget. Status icon without the verbiage is sufficient in widget view.
N0YB
01:18 AM Feature #3699: Log pfsense version after bootup
I cancelled the previous pull request and a new one submitted.
https://github.com/pfsense/pfsense/pull/1234
I r...
Adam Gibson
12:36 AM Revision f1a34790: Hostnames are not case restrictive.
N0YB

06/14/2014

06:52 AM Revision 01deca6a: Log pfsense version to syslog after bootup
Adam Gibson

06/13/2014

10:14 PM Bug #3712: missing protocols in NAT edit page
Please advise if there is any concern with merging these. I'll happily modify the pull requests as necessary. Daniel Becker
10:13 PM Bug #3712: missing protocols in NAT edit page
I created pull requests for this a few weeks back:
- "1208 for RELENG_2_1":https://github.com/pfsense/pfsense/pull...
Daniel Becker
10:12 PM Bug #3712: missing protocols in NAT edit page
I created pull requests for this a few weeks back:
"1208 for RELENG_2_1":https://github.com/pfsense/pfsense/pull/12...
Daniel Becker
10:10 PM Bug #3712 (Resolved): missing protocols in NAT edit page
The protocol selection on the NAT edit page is missing some protocols that are available for selection on other pages... Daniel Becker
08:46 PM Revision bc388533: Avoid keeping old files from previous sessions on /tmp/configbak
Renato Botelho
07:13 PM Revision 828da370: cf/ dir is removed below, do not need to remove the file here
Renato Botelho
07:08 PM Revision dc86f24d: Fix path for trigger_initial_wizard
Renato Botelho
06:11 PM Revision 061ac3f3: Better string check
N0YB
12:25 PM Revision c352b9d1: Merge pull request #1034 from vsquared56/master
Renato Botelho
11:59 AM Revision 6f3d2063: Replace Header() calls by lowercase
Renato Botelho
11:37 AM Revision 44b79ffb: Merge pull request #1222 from phil-davis/patch-8
Renato Botelho
11:36 AM Revision bcfd894e: Merge pull request #1229 from ExolonDX/branch-master_06
Renato Botelho
11:36 AM Revision 718af29d: Merge pull request #1228 from ExolonDX/branch_master_05
Renato Botelho
08:17 AM Revision f5b26faa: Remove htmlspecialchars() call for a fixed string.
N0YB
07:21 AM Bug #3542 (Feedback): cert_get_issuer() in certs.inc doesn't always return the full Distinguished Name
Pull request merged Renato Botelho

06/12/2014

09:06 PM Revision cbe38717: Bring the code of captiveportal up to speed with its module counterpart requirments
Ermal LUÇI
05:24 PM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Ok there was a missing path option in the crontab. This appears to be running normally now.
Jeremy Porter
03:25 PM Bug #3707: pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
The tools repo was trying to update with the wrong key. Its also having trouble running form cron. Its manually upda... Jeremy Porter
12:16 AM Bug #3707 (Resolved): pfsense-tools: No sync for > 1month between ESF-internal and git.pfsense.org
Related to my report in #3693 the pfsense-tools repository on git.pfsense.org hasn't been updated since 20th may whil... Mathieu Simon
04:27 PM pfSense Packages Bug #3711 (Resolved): bind package not starting after update
Hello,
We reinstalled bind package after an update, but now the named service is not starting up. we restarted our...
Anonymous
02:55 PM Bug #3710 (Resolved): Adding static DHCP leases doesn't cause BIND zones to update
Adding static DHCP leases doesn't cause BIND zones to update with "Register DHCP static mappings" on.
This one mus...
Dmitriy K
02:48 PM pfSense Packages Bug #897: Missing DNS record types SRV SPF DOMAINKEYS
I believe "Custom Zone Domain records" is enough to implement any idea you want. Just add there mail._domainkey.<doma... Dmitriy K
02:42 PM pfSense Packages Bug #3323: BIND, Reverse Zones and Register DHCP static mappings.
I have performed some tests with pfSense 2.2 and seems like #3323 has been successfully fixed. Dmitriy K
01:22 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
Issue persists on 2.2 Renato Botelho
12:53 PM Revision 1d8b3cdd: Fix i386 default URL for snapshots
Renato Botelho
12:31 PM Revision e7eeb5ce: Do not expire already disabled users, it fixes #3644
Renato Botelho
12:31 PM Revision 11eaf7bf: Do not expire already disabled users, it fixes #3644
Renato Botelho
11:59 AM Revision 859a5304: Fix #3665, show IPSec tunnel description on status page
Renato Botelho
11:33 AM Revision bd757043: Fix a typo on variable name
Renato Botelho
11:16 AM Revision 6186c00a: Fix td class
Renato Botelho
08:48 AM Bug #3665: IPsec tunnel description not displayed on status output
Looks good to me. Might be nice to have the P2 descriptions in the Child SA list as well if it's not too much trouble. Jim Pingle
07:00 AM Bug #3665 (Feedback): IPsec tunnel description not displayed on status output
Applied in changeset commit:859a53045631abf3844efda55a3169186618746a. Renato Botelho
07:50 AM Bug #3644: rc.expireaccounts expires every expired account every time it runs
Applied in changeset commit:e7eeb5ceac07f83630ced5e9cf18b10083a9aca8. Renato Botelho
07:50 AM Bug #3644 (Feedback): rc.expireaccounts expires every expired account every time it runs
Applied in changeset commit:11eaf7bfe6ba02d39e08d3c7541cb5d2b181d686. Renato Botelho
04:36 AM Bug #2882: 6RD not working in latest snapshots
I am also running in to this issue using the Dutch fiber ISP 'OnsBrabantnet'. If there is anything I can do or provid... Wouter van Rooy
03:05 AM Bug #3709 (Resolved): Disabled static route entries trigger 'route delete' error at boot
I've got a site to site openvpn setup. On the server i've got "remote networks" setup. On system reboot, this remote ... Maarten Bakker
02:32 AM pfSense Packages Bug #3708 (Closed): Error with order field while creating the first entry in "groups ACL" for squidGuard package
While creating the first ACL in "Groups ACL" for squidGuard package the following message is shown in the "Order" fie... Anonymous

06/11/2014

05:56 PM Revision f01c3b59: Fix #3702, make sure tunnel inside IP is set when interface changes
Renato Botelho
03:49 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
When I look back at what I wrote and on the logs, I see that all NAT have the checksum error. But for some reason the... Andreas Winge
03:17 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
As long as this problem has existed, NAT out WAN via PPTP on amd64 has been broken, that was the easiest problem to r... Jim Pingle
03:13 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
Oh 2.1.3 that I am running now is so much worse than when I reported this. As said in 2.1.3 NAT out to the WAN wasn't... Andreas Winge
12:43 PM Bug #1107: mpd on AMD64 generates invalid checksums with NAT
Your description of what you did is something that has worked all along.
It was when the pfsense had an outgoing ...
Andreas Winge
01:00 PM Bug #3702 (Feedback): gif interface assignment removes tunnel's inside IPv6 IPs
Applied in changeset commit:f01c3b5973e96502b787d282cc508a95f3a40d38. Renato Botelho
09:11 AM Bug #3706 (New): Permission order affects default page on limited accounts, but can't reorder
1. Make an account
2. Assign dashboard permission
3. save
4. Assign reboot permission
5. save
6. log in with tha...
Trel S
05:59 AM Bug #3666: PMTUD is broken for NATed traffic
I think you're on to something there. This: ... Chris Buechler
05:47 AM Feature #973 (Resolved): OpenVPN client in GUI cannot connect to a server requiring username/password
yep, this one's been implemented. Chris Buechler
12:27 AM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
And now I looked in the code for 2.2 and saw that it was there. Awesome! Andreas Winge
05:23 AM Revision daa169f7: remove extra .
Chris Buechler

06/10/2014

11:42 PM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
Sorry, I misread the description. Ignore that last comment.
Will there ever be a possibility to provide user/pass ...
Andreas Winge
11:36 PM Feature #973: OpenVPN client in GUI cannot connect to a server requiring username/password
This one can be closed. It has been working for years now. Andreas Winge
05:21 PM Revision f5629ea6: Be more precise to match members of a bridge interface, it should fix #3637
Renato Botelho
05:20 PM Revision f2c86031: Be more precise to match members of a bridge interface, it should fix #3637
Renato Botelho
03:15 PM Bug #3666: PMTUD is broken for NATed traffic
not identical, no. Had the same basic components - scrub all, pass all, nat on. I can throw the completely identical ... Chris Buechler
05:37 AM Bug #3666: PMTUD is broken for NATed traffic
You used the same ruleset on stock FreeBSD as pfSense? Ermal Luçi
02:25 AM Bug #3666: PMTUD is broken for NATed traffic
Additional data point. This seemingly isn't an issue in stock FreeBSD 10-STABLE. One I had handy: ... Chris Buechler
12:36 AM Bug #3666 (New): PMTUD is broken for NATed traffic
no change. I did confirm it's specific to NATed traffic and updated subject accordingly. Send any packet > egress int... Chris Buechler
03:13 PM Bug #3703 (Resolved): MTU not applied on reboot
the root issue is the link route MTUs in FreeBSD 8.3 aren't correctly updated. That works in 10.x, and hence 2.2 (I'v... Chris Buechler
12:59 PM Bug #3703: MTU not applied on reboot
fwiw, in UI going from mtu 9000 to mtu 'blank', after multiple save/apply, ifconfig, netstat, and ping all still show... Steve Russell
12:49 PM Bug #3703: MTU not applied on reboot
Netstat -rnW output after first save/apply, while ifconfig says mtu 9000
$ netstat -rnW
Routing tables
Interne...
Steve Russell
12:30 PM Bug #3703: MTU not applied on reboot
Please also include "netstat -rnW" -- watch the mtu column there. Jim Pingle
12:27 PM Bug #3703: MTU not applied on reboot
This is the ifconfig output after first save/apply:
$ ifconfig
em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTI...
Steve Russell
12:00 PM Bug #3703: MTU not applied on reboot
Also be sure to specify any additional configurations you have on the interfaces such as lagg, vlans, bridges, gif/gr... Jim Pingle
11:57 AM Bug #3703: MTU not applied on reboot
Are you sure the MTU is not being set? Could you paste the output of ifconfig? I tried it both on 2.1.3 and 2.2 and i... Renato Botelho
10:48 AM Bug #3703 (Resolved): MTU not applied on reboot
Set MTU on LAN to 9000. Save. Apply. 'Ping -f -l 8972 pfsense' from windows box. Timed out.
Save LAN settings aga...
Steve Russell
02:28 PM Revision b2821f7d: Revert "Revert "Fix #3700 and other syntax issues:""
This reverts commit 4cc2ae78d3027c349969437f08a88b1fb88c9de8. Renato Botelho
02:28 PM Revision ab3c1e24: Revert "Fix sh syntax"
This reverts commit cd49f9cd5d21a6592ba690cd315f19266092bee5. Renato Botelho
01:54 PM Revision cd49f9cd: Fix sh syntax
Renato Botelho
01:54 PM Revision 4cc2ae78: Revert "Fix #3700 and other syntax issues:"
This reverts commit e912bfae186b6b657daf52607f9d027f46be0478. Renato Botelho
01:42 PM Revision ff3da5db: Fix #3700 and other syntax issues:
- Remove -G parameter from pfctl since it doesn't exist anymore
- Initialize $old_router
- Fix sh syntax on variable ...
Renato Botelho
01:40 PM Revision e912bfae: Fix #3700 and other syntax issues:
- Remove -G parameter from pfctl since it doesn't exist anymore
- Initialize $old_router
- Fix sh syntax on variable ...
Renato Botelho
12:30 PM Bug #3637: Incorrect interface matching on bridge edit page
Applied in changeset commit:f5629ea6b83572ae8fa681b7bfd0c2e05844b290. Renato Botelho
12:30 PM Bug #3637 (Feedback): Incorrect interface matching on bridge edit page
Applied in changeset commit:f2c86031649e5f199ef10e848593ba38429694da. Renato Botelho
12:03 PM Todo #3705 (Resolved): use HTTPS for rc.update_bogons.sh
The *rc.Update_bogons.sh* script should reference the *HTTPS* site instead of the HTTP one.
v4url=${v4url:-"http:/...
BBcan177 .
12:03 PM pfSense Packages Bug #3704 (Closed): spamd whitelist/blacklist bug
1 - I've create a white list with google IP's range but I'm still get connections from Google IP's in GREY when I cli... Ricardson Williams
09:00 AM Bug #3700: pfctl: illegal option -- G
Applied in changeset commit:ff3da5dba67c64514808e86165e92362f3ff8b33. Renato Botelho
09:00 AM Bug #3700 (Feedback): pfctl: illegal option -- G
Applied in changeset commit:e912bfae186b6b657daf52607f9d027f46be0478. Renato Botelho

06/09/2014

06:32 PM Revision 6da518fc: Do not allow interface group name to be bigger than 15 chars, helps ticket #3208
Renato Botelho
06:32 PM Revision 6a0f34b8: Do not allow interface group name to be bigger than 15 chars, helps ticket #3208
Renato Botelho
05:35 PM Bug #3678: Kernel panic: "Bogus interrupt trigger mode" on Intel J1900
Dan E wrote:
> I can confirm this issue on a Gigabyte GA-J1900N-D3V. I've tried AMD64/i386 builds of 2.1.3 as well a...
Eric Tol
01:05 PM Bug #3125: hifn on 2.1 breaks certain ciphers w/openssl
Confirmed same on an ALIX with: ... Chris Buechler
12:59 AM Bug #3514: IPv6 - LAN looses Prefix after link event
Derek Ivey wrote:
> I seem to be running into this bug in pfSense 2.1.3-RELEASE. It seems like a SIGHUP is properly ...
Derek Ivey
12:14 AM Bug #3514: IPv6 - LAN looses Prefix after link event
I seem to be running into this bug in pfSense 2.1.3-RELEASE. It seems like a SIGHUP is properly being sent to the dhc... Derek Ivey

06/08/2014

09:50 PM Revision 529ba86a: Populate gateway address field with tilde if there is no address or friendly interface.
This is to match the update data. N0YB
09:47 PM Revision 1f47798a: Fix gateway widget size change on first update.
Inner table size changes on the first update because the table in update data does not have the same attributes as th... N0YB
12:42 AM Bug #3701 (Rejected): IPv6 address assignment inside gif only functions with 128 prefixlen
the actual bug at fault here is #3702. We do actually ignore prefixlen there and set it to 128, so maybe shouldn't gi... Chris Buechler
12:23 AM Bug #3701 (Rejected): IPv6 address assignment inside gif only functions with 128 prefixlen
This used to work, but I'm not entirely sure at what point - 2.1.4 behaves the same. On the most current 2.2 snapshot... Chris Buechler
12:41 AM Bug #3702 (Resolved): gif interface assignment removes tunnel's inside IPv6 IPs
Normally removing an IP from an interface where that type is "none" is appropriate. But not with gif (or tun or tap o... Chris Buechler
 

Also available in: Atom