Project

General

Profile

Activity

From 04/19/2015 to 05/18/2015

05/18/2015

10:39 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Squid2 has been disabled for pfSense 2.3 onwards - https://github.com/pfsense/pfsense-packages/commit/5be0199960c6d8f... Phillip Davis
06:43 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Solved! Squid 3 seems to have solved the issue! Why not mark Squid 2 as "deprecated"? Anonymous
10:30 PM Bug #4704 (Confirmed): IKEv2 to Cisco ASA won't bring up multiple P2 networks
Chris Buechler
07:52 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
I mean in stock FreeBSD 10.1, have you checked it? Chris Buechler
03:58 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Chris Buechler wrote:
> is the tzdata in FreeBSD 10.1 not correct? We use stock FreeBSD tzdata.
Nope, still only ...
Dmitriy K
07:30 PM Revision 77f67782: Merge pull request #1665 from phil-davis/www-vpn-l2tp
Renato Botelho
07:24 PM Bug #4713 (Confirmed): Gateway added via console menu option 2 is not picked up by the setup wizard
Chris Buechler
02:21 PM Bug #4713: Gateway added via console menu option 2 is not picked up by the setup wizard
Adding diff between the console added gateway (First) and GUI added gateway (second) Jim Pingle
02:20 PM Bug #4713 (Resolved): Gateway added via console menu option 2 is not picked up by the setup wizard
If the user configures their static WAN information using the console, and later runs through the setup wizard, the g... Jim Pingle
07:23 PM Bug #4714: syslogd unable to start with 'mixed' log types present
could you narrow it down to a specific log file that's problematic and get us that file? suspect the cause is a corru... Chris Buechler
04:12 PM Bug #4714 (Closed): syslogd unable to start with 'mixed' log types present
Syslogd fails to fully start on boot,
This started over a month ago on April 17 it would appear (based on the lat...
Benjamin Hodgens
07:20 PM Revision e383f744: Merge pull request #1663 from jlduran/utf8-latin1
Renato Botelho
05:24 PM Revision a3e00d53: Code style vpn_l2tp
Phil Davis
05:11 PM Bug #4715 (Duplicate): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Chris Buechler
05:09 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Shoot. I did look, but I didn't find that one. Yes, it appears to be the same issue. Adam Thompson
05:01 PM Bug #4715 (Feedback): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
VLANs I'm guessing? that'd be #3314 Chris Buechler
04:37 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Attached RRD graphs for current period; these look right, I think. Adam Thompson
04:35 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Whoops, I'm on 2.2.2 amd64, not 2.2.3.
Adam Thompson
04:35 PM Bug #4715 (Duplicate): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
I've noticed that for my WAN interface, the traffic graph on the dashboard shows double the throughput it should (I t... Adam Thompson
05:08 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
As a temporary workaround, would it not be possible to detect VLANs and do something like disabling the graph, automa... Adam Thompson
03:43 PM Todo #4576 (Resolved): Write a tool to create port reading data from xmlrpc
Done. update_package_pfPorts.php on tools/builder_scripts. Renato Botelho
02:08 PM Bug #4712 (Resolved): Wizard hostname validation rejects upper case letters
The setup wizard has some JavaScript to validate the hostname. This script does not accept upper case letters in the ... Jim Pingle
12:58 PM Bug #4710 (Confirmed): System Log - Firewall Fails to 'Click to Resolve' for IPv6 Addresses
Chris Buechler
12:45 PM Bug #4708 (Not a Bug): LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
it's correct all around as is. the default deny is what blocks them, logging of default deny can be user-controlled. Chris Buechler
12:21 PM Bug #3736: No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
I am sorry but it is not fixed with pfsense 2.2.2-RELEASE Eric Boudrand
10:54 AM Bug #4686: Rekeyed SAs are not properly removed
I see that the first one is already integrated as of cbc1f411604e0d5f608439db7b4f16303b03dcf2. Mind adding the second... Florian Apolloner
10:29 AM Bug #4686: Rekeyed SAs are not properly removed
Would it be possible to apply those two patches:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200282
https://b...
Florian Apolloner
06:41 AM Bug #4686: Rekeyed SAs are not properly removed
Ivo B wrote:
> Let me also add that remote subnets are in public range. Legacy reasons. Perhaps a routing issue?
> ...
Florian Apolloner
06:26 AM Bug #4686: Rekeyed SAs are not properly removed
Florian Apolloner wrote:
> I am getting weird behaviour on some IPSec connections since 2.2.2. It looks as if CHILD_...
Ivo B
10:30 AM Bug #4607 (Feedback): Bridge+CARP crashes/freezes pfSense
Patches committed to solve this. Ermal Luçi
08:57 AM Bug #4711 (Rejected): DHCP static mapping DNS servers do not override correctly
Duplicate of #3915
It's a bug in ISC DHCP server, not our code. Supposedly will be fixed in a newer version of the...
Jim Pingle
08:49 AM Bug #4711 (Rejected): DHCP static mapping DNS servers do not override correctly
1) On the DHCP Server page, enter 4 different DNS Servers. Make sure the first one is the pfSense LAN interface. Fo... Jeremy  99

05/17/2015

04:07 PM Bug #4702 (Feedback): kernel panic with AES-NI
PAtches committed. Ermal Luçi
10:16 AM Bug #4710 (Duplicate): System Log - Firewall Fails to 'Click to Resolve' for IPv6 Addresses
When looking through Firewall Logs, I can resolve IPv4 addresses, but IPv6 will not resolve.
Love this feature, W...
Marc Riley
08:22 AM Bug #4708: LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
Okay, that link makes sense, so is there a way to Stop Logging these packets that arrive after the connection has bee... Marc Riley
02:46 AM Feature #4542: Support for PPPoE with MTU/MRU > 1492 (i.e. 1500)
A bounty has been started.
h1. Link
* https://forum.pfsense.org/index.php?topic=93902.0
Greg B
02:31 AM Bug #4709 (Resolved): Correct "State Killing on Gateway Failure" description
In Advanced/Miscellaneous/Gateway Monitoring it says:
"The monitoring process will flush states for a gateway that...
Duncan Sands

05/16/2015

09:28 PM Bug #4708: LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
[[https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection]] Phillip Davis
03:44 PM Bug #4708 (Not a Bug): LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
I'm using pfSense 2.2.2-RELEASE (amd64), and have configured IPv6 through a tunnel broker. Everything is working fin... Marc Riley
07:05 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
and part 2:
@May 17 02:57:00 charon: 06[ENC] <con4|18> 48: 07 00 00 10 00 00 FF FF 0A 0E 43 00 0A 0E 43 FF ............
Roman H
07:04 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Here it comes, with "Highest" settings, without Unity.
@May 17 02:57:01 charon: 01[JOB] next event in 2s 621ms, wait...
Roman H
07:02 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Hmmm. Can't post somewhy.
This is test only
Roman H
02:55 PM Revision d98a2e6a: Remove artifacts from latin1 to utf8 conversions
String replacement:
s/Ermal L.../Ermal Luçi/g
Jose Luis Duran
09:51 AM Feature #4707 (New): Can't override block port 0 rules in filter.inc

Sometimes legitimate traffic is blocked by the default/quick rules in filter.inc. However, these cannot be overridd...
Andrew -
09:49 AM Bug #4673: Can't override rules in filter.inc from the GUI
OK. I'll re-post as a feature request. Either way you should be able to override these rules from the GUI should you... Andrew -
05:16 AM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Well, it still hangs here exactly the same as ever. I tried _pfctl -d_ before running this and it did not help in any... Kill Bill
04:55 AM Todo #4706 (Resolved): MPD needs to be upgraded to version 5 even for the various other tunnels
MPD 4 is still being used for PPPoE/PPtP/L2TP... it needs to converted for those protocols to MPD5 Ermal Luçi
12:14 AM Revision b96d6738: create /var/spool/lock on nano so tip works without hassles. Ticket #4532
Chris Buechler
12:13 AM Revision d71cded0: create /var/spool/lock on nano so tip works without hassles. Ticket #4532
Chris Buechler

05/15/2015

08:44 PM Feature #3325 (Closed): MTU Option for PPTP VPN
PPTP is dead Chris Buechler
08:42 PM Bug #3069 (Feedback): traceroute6 fails to timeout and hangs the webconfigurator GUI
this doesn't seem to be an issue in 2.2.x Chris Buechler
08:42 PM Bug #3063 (Closed): system will crash after "PowerD" enabled.
not likely this is still a problem in 2.2x versions, with FreeBSD 10.1. if it is, it needs to be reported upstream Chris Buechler
08:39 PM Bug #2734 (Closed): Mobile IPsec AES128 fails with glxsb on Alix, iOS client
this definitely works in current versions Chris Buechler
08:21 PM Feature #2152 (Needs Patch): Pass-through MAC and Vouchers
unusual case, not worth messing with. in many cases should be achievable with separate CP zones. Chris Buechler
08:18 PM Feature #1962 (Closed): disconnect specific pptpd interface from command line
PPTP is dead Chris Buechler
08:13 PM Bug #3736 (Resolved): No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
this was fixed at some point long ago Chris Buechler
07:17 PM Bug #4673 (Not a Bug): Can't override rules in filter.inc from the GUI
subject isn't a legit bug. Port 0 isn't valid, and isn't what was causing the issue in question Chris Buechler
07:16 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
is the tzdata in FreeBSD 10.1 not correct? We use stock FreeBSD tzdata. Chris Buechler
07:15 PM Bug #4700 (Duplicate): Wrong time from Russia
duplicate of #4459 Chris Buechler
07:14 PM Bug #4377 (Rejected): pfSense boot freezes after restart in QEMU/KVM
I suspect you have a QEMU/KVM config issue of some sort given that doesn't happen to anyone else that I've seen. It's... Chris Buechler
07:12 PM Bug #4532 (Resolved): /var/spool/lock Directory missing on nanobsd
only missing on nano since its /var/ is a RAM disk. I added its creation and ownership setting to rc.embedded Chris Buechler
07:02 PM Bug #4520 (Resolved): IPsec loglevel settings broken
this was fixed in 2.2.1 release (and newer) Chris Buechler
07:01 PM Bug #4494 (Needs Patch): axge bug - AX88179 chipset (network interface reseting)
not something we'll fix. Should work in 2.3 release, based on FreeBSD 10.2, and if someone wants to submit a patch to... Chris Buechler
07:00 PM Bug #4249 (Not a Bug): virtual ips backup/restore bug
no bug here Chris Buechler
06:59 PM Bug #4107 (Confirmed): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
it just needs to kick off a reboot upon completion Chris Buechler
06:54 PM Bug #4671 (Not a Bug): Add "net.inet.ip.portrange.reservedhigh" to system tunable GUI
it can be user-defined. if there is a problem with what squid references there, bring that up on the packages board o... Chris Buechler
06:52 PM Bug #4603 (Resolved): Log files used by packages are reinitialized on every boot
Chris Buechler
06:51 PM Bug #4651 (Confirmed): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
the tracker on negate rules always ends up as "1" now. Chris Buechler
05:36 PM Revision b92af7ab: Disable defering in pfsync which is used for active-active deployments not useble in FreeBSD. This should fix hangs reported on some machines wiht pfsync
Ermal Luçi
05:36 PM Revision fd07693e: Disable defering in pfsync which is used for active-active deployments not useble in FreeBSD. This should fix hangs reported on some machines wiht pfsync
Ermal Luçi
03:27 PM Bug #3996 (Needs Patch): Solarflare NIC panic with LACP
not hardware we sell, so not something we'll deal with. if someone wants to pursue, report and get it fixed in FreeBS... Chris Buechler
03:17 PM Bug #4596 (Feedback): NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
Patch submitted for 2.2.x branch will be updated for the 2.3(master) one. Ermal Luçi
02:56 PM Bug #4607: Bridge+CARP crashes/freezes pfSense
Still an issue after recent related changes. One clarification - it only happens when hosts are using the CARP IP as ... Chris Buechler
02:44 PM Bug #4705 (Confirmed): Language selection is not functional
Jim Pingle
08:24 AM Bug #4705 (Resolved): Language selection is not functional
Selecting a different language under *System > General Setup* has no effect. Selecting an alternate language and then... Jim Pingle
02:43 PM Bug #4633 (Resolved): CARP not enabled upon creation of first CARP IP
fixed Chris Buechler
01:47 PM Bug #4310: Limiters + HA results in hangs on secondary
Patch was committed for this on tools repo and also the defer option in pfsync is now not used.
Both can be consider...
Ermal Luçi
12:31 PM Bug #4623: Carp not working under bhyve
Did you try from the GUI since carp should not differ from FreeBSD at least in this regard! Ermal Luçi
12:02 PM Revision f8ac4407: Code style WWW pkg
The syntax of these all seems good. Because the 2.3-DEVELOPMENT master
does not currently have get_pkg_info implement...
Phil Davis
11:02 AM Revision 83c380c3: Merge pull request #1660 from phil-davis/www-status-rrd
Renato Botelho
10:57 AM Revision 38145b9b: Remove excess tabs status_rrd_graph
Phil Davis
10:57 AM Revision 0922c015: Merge pull request #1659 from phil-davis/www-status
Renato Botelho
10:42 AM Revision 45e96815: Use correct variable to fix pagination
Renato Botelho
10:42 AM Revision 5402c8fc: Fix startingat var name typo in pkp.php
Even with this fix, the code does not make sense. The first test is:
if ($startingat > -1)
if it gets into the else,...
Phil Davis
10:41 AM Revision e7a9ad78: Use correct variable to fix pagination
Renato Botelho
10:40 AM Revision 119213c4: Merge pull request #1661 from phil-davis/patch-1
Renato Botelho
07:38 AM Bug #4424: Adding and removing shaper repeatedly causing interface crash
I frequently see this bug as well.
A reliable work-around I use is to first Disable/Uncheck & Apply then finally "...
Ben Cook
07:12 AM Revision a5d6bf80: Fix startingat var name typo in pkp.php
Even with this fix, the code does not make sense. The first test is:
if ($startingat > -1)
if it gets into the else,...
Phil Davis
06:27 AM Revision f1df36e5: Code style WWW Status RRD
Phil Davis
05:55 AM Revision 42b0c921: Code style WWW Status
Phil Davis
03:42 AM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Louis-Philippe Allard wrote:
> SO I assume squid's package in pfsense is WAYYY old?
Yeah, when you install Squid ...
Kill Bill
02:22 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Can you increase the debug level and send me the log.
I want to see what the ASA side is sending as matching traffic...
Ermal Luçi
12:11 AM Revision 83e0a56a: services_dhcp_edit.php Conversion complete
Ready for review sbeaver

05/14/2015

11:39 PM Revision f037eeb7: Fixed MAC address calculation
sbeaver
10:32 PM Revision af664996: Remove the "insert my MAC" feature from interfaces.php. It hasn't worked in a while (credit sbeaver for noticing), and the only thing it tends to accomplish is breaking people's connectivity from the system where they end up duplicating the MAC of their local system.
Conflicts:
usr/local/www/interfaces.php
Chris Buechler
10:30 PM Revision c8f1c7bd: Remove the "insert my MAC" feature from interfaces.php. It hasn't worked in a while (credit sbeaver for noticing), and the only thing it tends to accomplish is breaking people's connectivity from the system where they end up duplicating the MAC of their local system.
Chris Buechler
07:03 PM Revision c58879a9: Add some error checking to avoid warning during boot
Ermal Luçi
07:03 PM Revision 380ae020: Add some error checking to avoid warning during boot
Ermal Luçi
06:52 PM Revision 5f17dff7: services_captiveportal_vouchers_edit.php Conversion complete
Ready for review sbeaver
05:46 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
I posted on squid's maillist and their answer was:
"The Ubuntu problem is a combination of pacage manager assuming...
Anonymous
02:43 PM Revision 429112ac: Move pt_BR translation from ISO to UTF-8
Renato Botelho
02:39 PM Revision 75625610: Remove unneeded hidden input
sbeaver
02:38 PM Revision 20c87211: Revert "Remove unneeded hidden input"
This reverts commit 0e40f0f1d9d95e997430ec0a00a305a3cf3a5943. sbeaver
02:36 PM Revision 0e40f0f1: Remove unneeded hidden input
sbeaver
02:35 PM Revision af64370b: Move pt_BR directory, it's moving from ISO to UTF-8
Renato Botelho
02:34 PM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Package 1.0.3 contains the fix Renato Botelho
12:45 PM pfSense Packages Bug #4304 (Feedback): pfflowd non-functional on 2.2.x versions
Fix committed need to try with new binaries. Ermal Luçi
08:37 AM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Can we please get this fixed soon. Jeremy Porter
02:04 PM Revision 075dc8b7: services_captiveportal_mac_edit.php Conversion complete
Ready for review sbeaver
12:27 PM Revision 3dde9235: services_captiveportal_mac.php Conversion complete
Ready for review sbeaver
11:53 AM Revision 448161ba: Add some curlies in status_rrd_graph_img
These "if data" tests look like they should apply to all 4 lines below them.
After sorting out this real-looking issu...
Phil Davis
11:51 AM Revision 861f0124: Merge pull request #1658 from phil-davis/patch-4
Renato Botelho
11:50 AM Revision db7d66e7: Cleanup code logic status_upnp
1) Variable $i is was set, incremented and not used.
2) "if preg_match" at line 94 had no curlies after it, so it was...
Phil Davis
11:50 AM Revision 1ab739c7: Merge pull request #1657 from phil-davis/patch-3
Renato Botelho
11:49 AM Revision e240d261: Merge pull request #1656 from phil-davis/patch-2
Renato Botelho
11:48 AM Revision 8119bdb3: Merge pull request #1655 from phil-davis/patch-1
Renato Botelho
11:44 AM Revision 34f3165b: Fix alias rename and delete bug #4701
The old advancedoutbound key in config.xml is now called outbound. Phil Davis
11:31 AM Revision c364b1e6: Merge pull request #1654 from phil-davis/nat-outbound-fix
Renato Botelho
11:04 AM Revision fa201d63: Add some curlies in status_rrd_graph_img
These "if data" tests look like they should apply to all 4 lines below them.
After sorting out this real-looking issu...
Phil Davis
06:43 AM Bug #4701: WebGUI alias name changes does not reflect in NAT-Outbound
Pull request has been merged Renato Botelho
06:33 AM Revision 037d118f: Cleanup code logic status_upnp
1) Variable $i is was set, incremented and not used.
2) "if preg_match" at line 94 had no curlies after it, so it was...
Phil Davis
05:50 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Dont be confused by :
May 14 13:42:48 charon: 10[CFG] <con4|7> config: 10.9.73.0/24|/0, received: 10.9.73.0/24|/0 ...
Roman H
05:47 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Ermal Luçi wrote:
> Can you also put the logs of the exchange from pfSense.
>
> Can you also please test by disab...
Roman H
05:29 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Can you also put the logs of the exchange from pfSense.
Can you also please test by disabling the unity plugin and...
Ermal Luçi
04:01 AM Bug #4704 (Resolved): IKEv2 to Cisco ASA won't bring up multiple P2 networks
Setup is following:
pFsense firewall - have subnet 192.168.23.0/24 subnet, where host itself have 192.168.23.55
...
Roman H
05:17 AM Revision b1f56807: Remove unused nentries from status_lb_pool
Phil Davis
04:16 AM Revision 1bc6fa03: Remove unused var from status_gateways.php
I cannot see where "counter" is used. Phil Davis
12:57 AM Revision 682b8f12: Fix alias rename and delete bug #4701
The old advancedoutbound key in config.xml is now called outbound. Phil Davis

05/13/2015

10:06 PM Revision 68ceb463: services_captiveportal_ip_edit.php Conversion completes
Ready for review sbeaver
09:20 PM Bug #4701 (Feedback): WebGUI alias name changes does not reflect in NAT-Outbound
thanks Phil.
the second issue I thought had another ticket, but not seeing it at the moment.
Chris Buechler
07:56 PM Bug #4701: WebGUI alias name changes does not reflect in NAT-Outbound
This fixes number 1:
https://github.com/pfsense/pfsense/pull/1654
The key in the config changed from "advancedoutbo...
Phillip Davis
07:26 AM Bug #4701 (Resolved): WebGUI alias name changes does not reflect in NAT-Outbound
Just found two little bugs in the WEBgui:
Changing the name of an existing alias in "Firewall: Alias" will also ch...
Willy Tenner
08:27 PM Revision ef548f98: services_captiveportal_ip.php Conversion complete
Ready for review sbeaver
08:00 PM Revision 62f82bbd: Removed debug line
sbeaver
07:56 PM Revision 148c59ee: services_captiveportal_hostname_edit Conversion complete
Ready for review sbeaver
07:54 PM Revision 440e8604: Revert "services_captiveportal_hostname_edit.php Conversion complete"
This reverts commit 8d66660a6869d33a3c9a34fa4bc8c5a9fed5a9bf. sbeaver
07:52 PM Revision 8d66660a: services_captiveportal_hostname_edit.php Conversion complete
Ready for review sbeaver
07:04 PM Revision 54f8c617: Fixed indent
sbeaver
06:59 PM Revision cbdd2dd3: services_captiveportal_hostname.php Conversion complete
Ready for review sbeaver
06:17 PM Revision 10439116: ipsec: psk keyid bugfix
IPsec/IKEv2 PSK currently generates an invalid strongswan ipsec.conf file.
The local IKE ID is not inserted correctly...
Bruno Thomsen
05:48 PM Bug #4703 (Closed): Inconsistent availability of direction on CP IP/MAC/hostname passthrough
CP MAC and IP passthrough used to have a direction (in/out/both) on each entry, which is potentially useful in a vari... Chris Buechler
05:22 PM Revision 01cced78: Delete load_balancer_relay*.php, they are not being used
Renato Botelho
05:16 PM Revision 9eeaf458: Merge pull request #1653 from phil-davis/lb-work
Renato Botelho
05:14 PM Revision 4040b302: Merge pull request #1651 from phil-davis/interfaces-other
Renato Botelho
05:13 PM Revision 62a9a5d0: Merge pull request #1650 from phil-davis/interfaces-php
Renato Botelho
05:12 PM Revision caa7230e: Slash-select should be inside if in load_balancer_pool_edit
otherwise there is an unbalanced slash-select when the else happens (if there are no load-balancer monitors defined) Phil Davis
05:11 PM Revision 101258eb: Merge pull request #1652 from phil-davis/patch-1
Renato Botelho
04:50 PM Revision 0d102fcd: ipsec: added ecc brainpool to vpn_ipsec_convert_to_modp()
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com> Bruno Thomsen
04:47 PM Revision 58453574: services_captieveportal_filemanager.php Conversion complete
Ready for review sbeaver
03:27 PM Bug #4689 (Feedback): Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0"
Merged patch. Ermal Luçi
12:57 PM Bug #4702 (Resolved): kernel panic with AES-NI
Crash dump attached. Not reliably replicable on the system this came from, but this is similar to what a few others h... Chris Buechler
12:18 PM Revision b45e428c: No need to deal with hw.usb.no_pf anymore, it's part of default loader.conf
Renato Botelho
12:06 PM Revision 421b5e1c: services_captiveportal_zones_edit.php Conversion complete
Ready for review sbeaver
10:51 AM Revision 0162f9a1: Code style Load Balancer
Phil Davis
09:42 AM Revision 68962573: Slash-select should be inside if in load_balancer_pool_edit
otherwise there is an unbalanced slash-select when the else happens (if there are no load-balancer monitors defined) Phil Davis
07:21 AM Revision 2af86dda: Code style interfaces miscellaneous files
Phil Davis
07:12 AM Revision 1caf2209: Code style interfaces.php
Phil Davis

05/12/2015

11:11 PM Revision 6f667945: Remove debug statement
sbeaver
11:00 PM Revision 6e979933: pkg_mgr_settings Conversion complete
Ready for review sbeaver
09:15 PM Revision b8e6729f: ipsec: pfs ecc brainpool curve support
Use brainpool curves as perfect forward security.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
09:11 PM Revision 3922114b: ipsec: pfs ecc nist curve support
Use nist curves as perfect forward security.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
08:44 PM Revision c55ec98a: ipsec: IKEv2 Diffie-Hellman ECC Brainpool support
Use of ECC Brainpool curves for IKEv2 is define in RFC6954.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
08:10 PM Revision 7b826864: ipsec: IKE phase one AES-GCM support
Use of Galois/Counter Mode (GCM) during IKE phase-1 is defined in RFC4106.
Signed-off-by: Bruno Thomsen <bruno.thoms...
Bruno Thomsen
07:53 PM Revision 50ed1824: bugfix: ipsec: nist ecp521 elliptic curve support
There was a small typo the vpn_ipsec_convert_to_modp() function.
Bug introduced in commit 7a747654e9ef5b4cec7184c770...
Bruno Thomsen
07:50 PM Revision cfe5eeab: load_balancer_setting.php Conversion complete
Ready for review sbeaver
07:17 PM Revision 09d2448a: interfaces_wireless_edit.php Conversion complete
Ready for review sbeaver
03:32 PM Bug #4686: Rekeyed SAs are not properly removed
After looking at patch-ipsec_nat.diff in the pfsense-tools repo, does this patch do anything aside from making the st... Florian Apolloner
02:53 PM Bug #4686: Rekeyed SAs are not properly removed
So upstream says, that you are using a somewhat invalid syntax for leftsubnet (I have binat selected), might that be ... Florian Apolloner
01:17 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
For those who would like to test a version of choparp including Ermal's fixes, following this procedure:
1. Stop t...
Jim Pingle
12:49 PM Bug #4685 (Feedback): Crash/panic "Sleeping thread owns a non-sleepable lock"
choparp was blocking on bpf mutex and making full buffers on BPF and panicing due to context of ISR routines on drivers. Ermal Luçi
06:33 AM Bug #4700 (Duplicate): Wrong time from Russia
see #4459 (this task is double), and https://forum.pfsense.org/index.php?topic=93757.0
Menu -> Diagnostics -> Comm...
Victor Danilkin
02:21 AM Bug #4699 (Not a Bug): IPsec panic with MSS clamping
This is reported here https://forum.pfsense.org/index.php?topic=93742.0 and is not always reproducible.
Normally t...
Ermal Luçi
12:51 AM Revision e568873f: license.php Conversion complete
Converted spaces to tabs, corrected indenting, added missing </p>,
added panel divs, corrected missing spaces in copy...
sbeaver
12:26 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
ys seems fixed Bipin Chandra

05/11/2015

09:52 PM Bug #4696: OpenVPN Status / Client List
Hi,
I admit, not sure ... ;). The issue is that Load Balancer is showing an incorrect status for OpenVPN, when I a...
Russell Morris
01:24 PM Bug #4696 (Feedback): OpenVPN Status / Client List
what does load balancer have to do with your OpenVPN? Chris Buechler
09:51 PM Bug #4694: Load Balancing Failing
NP, will dig into it further. Unfortunately it has been working fine for 6-8 months, only stopped working when I upgr... Russell Morris
12:41 PM Bug #4694 (Not a Bug): Load Balancing Failing
there are no such general issues, this is a config or testing methodology issue. please use one of our support resour... Chris Buechler
08:44 PM Bug #4208 (Resolved): P1 rekeying with IKEv1 failing with no proposal chosen / invalid ID info
this was fixed in strongswan 5.3.0 Chris Buechler
08:38 PM Bug #3205: Partial system freeze when disconnecting USB 3G stick
I suspect this is probably fixed in 2.2x versions because of FreeBSD 10.1 base. Anyone who was seeing this able to co... Chris Buechler
08:36 PM Bug #1421 (Needs Patch): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I suspect this isn't an issue with strongswan in the way it was with racoon. Also not concerned with PPTP anything at... Chris Buechler
08:33 PM Bug #2803 (Resolved): igmp version reset
the linked thread in Vasyl's comment has the solution on 8.1, and 10.x doesn't appear to have same issue. Chris Buechler
08:29 PM Bug #2990 (Not a Bug): Clarify wording of services_dnsmasq.php and move its Webconfigurator node
all the settings are specific to the service on whose page you're configuring them, and they can operate independentl... Chris Buechler
08:26 PM Bug #2650 (Closed): FTP helper breaks TCP sequence numbers on 2nd WAN
FTP helper in question no longer exists. Chris Buechler
08:21 PM Revision 922bf65c: interfaces_lagg_edit Conversion complete
Ready for review sbeaver
08:18 PM pfSense Packages Feature #4489 (Needs Patch): Add Varnish 4 Plugin
Chris Buechler
08:14 PM Bug #4670 (Not a Bug): pkg - ELF interpreter /libexec/ld-elf.so.1 not found
Chris Buechler
07:22 PM Revision 13393817: interfaces_gre_edit.php Conversion complete
Ready for review sbeaver
07:13 PM Revision c1c09523: Corrected input name
sbeaver
07:03 PM Revision 2686a780: interfces_gif_edit.php Conversion complete
Ready for review sbeaver
04:43 PM Revision c8f7068d: Merge pull request #1648 from phil-davis/floating-tab
Renato Botelho
04:12 PM Revision 0c469044: Handle extra column on floating rules tab
when there are no floating rules to display.
The box needs to span 11 columns.
Phil Davis
03:43 PM Revision a9741c0c: Merge pull request #1646 from phil-davis/firewall-rules
Renato Botelho
03:34 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Reports from customers indicate that crashes still occur even with net.bpf.zerocopy_enable=0
and net.isr.dispatch=de...
Jim Pingle
03:23 PM Revision 7a2cb2f2: Merge with master
Phil Davis
02:57 PM Revision fa61d033: Merge pull request #1647 from phil-davis/firewall-shaper
Renato Botelho
02:49 PM Revision 6aaec445: Code style firewall shaper
Phil Davis
02:36 PM Revision 7bf0ce52: fixed indent according to the style guide.
Berger Alexander
02:36 PM Revision 32749275: Currently pfsense enforces unique unqualified hostnames for static dhcp leases, which is not correct as only the fully qualified hostname (hostname + domainname) must be unique. With this commit the old validation logic for uniqeness is modified such that hostnames no longer need to be unique and at the same time the fully qualified hostname hast to be unique.
This change makes it possible to have host with identical hostnames in different (sub)domains. For example myhost.sal... Berger Alexander
02:36 PM Revision 8efea69a: Merge pull request #1637 from alex-berger/dhcp-staticleases-unique-check
Renato Botelho
01:27 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
the squid users mailing list is probably your best bet to start. Chris Buechler
01:16 PM Revision 250f6436: Merge pull request #1616 from Robert-Nelson/floating-interfaces
Renato Botelho
01:10 PM Revision 603d3c16: Code style Firewall Rules
Phil Davis
01:06 PM Feature #4697 (Closed): Load Balancing by Hostname
the built-in load balancer relayd doesn't have that ability. haproxy is available for those who need it. Chris Buechler
01:04 PM Bug #4693 (Duplicate): php warning when applying changes after change Resolver service|Access List
Chris Buechler
12:51 PM Bug #4686: Rekeyed SAs are not properly removed
The many phase 2 entries might be a result of: https://wiki.strongswan.org/issues/951 Florian Apolloner
12:42 PM Bug #4592 (Resolved): FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
thanks for confirming. Chris Buechler
12:40 PM Revision efd081de: Merge pull request #1645 from phil-davis/wizard
Renato Botelho
12:39 PM Revision a4042967: Merge pull request #1644 from phil-davis/firewall-virtual-ip
Renato Botelho
12:38 PM Revision 2fa098a0: Merge pull request #1643 from phil-davis/firewall-schedule
Renato Botelho
12:36 PM Revision 3be6106f: Merge pull request #1642 from phil-davis/firewall-nat
Renato Botelho
12:34 PM Revision 58c8900e: Merge pull request #1641 from phil-davis/firewall-aliases
Renato Botelho
12:33 PM Revision 1c0b7c8a: Merge pull request #1640 from phil-davis/patch-2
Renato Botelho
12:31 PM Revision 55395a83: Firewall Rules Edit missing slash
This should be the end of a "tr" here.
Browsers seem to be forgiving of this stuff - I don't see any difference in re...
Phil Davis
12:31 PM Revision 047c8758: Merge pull request #1639 from phil-davis/patch-1
Renato Botelho
12:09 PM Revision c00152f3: diag_ipsec_leases.php Conversion complete
Ready for review sbeaver
12:03 PM Revision ae36a9e5: diag_ipsec_spd conversion complete
Ready for review sbeaver
09:55 AM Bug #4698 (Resolved): XSS in system_authservers.php
Reported by Nicholas Starke:
> I found an XSS vulnerability in PFSense 2.2.2. Here are my notes on the vuln:
>
...
Jim Pingle
08:37 AM Revision f566451e: Code style Wizard
Phil Davis
06:43 AM Revision 760b1df9: Code style Firewall VIP
Phil Davis
06:32 AM Revision a4edef21: fixed indent according to the style guide.
Berger Alexander
06:27 AM Revision bedc00c8: Code style Firewall Schedule
Phil Davis
06:21 AM Revision 37ba954d: Code style Firewall NAT
Phil Davis
06:07 AM Revision 95a40ac0: Code style firewall_aliases
Phil Davis
03:22 AM Revision accb5756: Minor changes to firewall_shaper_layer7
The tabbing of this code is not so good, so it is difficult to see what is going on. I will format that in a later pu... Phil Davis
03:17 AM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Hello
as advised in the forum : https://forum.pfsense.org/index.php?topic=88441.0
I have uninstalled pfflowd pac...
Didier Richard

05/10/2015

07:29 PM Bug #4592: FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
Just did a firmware update to the latest 2.2.3 snapshot and shutdown works. Looking forward to the full 2.2.3 release. Christopher Taylor
06:09 PM Bug #4431: Bandwidth not reported correctly in "Status: Traffic shaper: Queues"
I'm seeing this also. Screenshot attached. I'm running 2.2.2 Andre LaBranche
05:27 PM Feature #4697 (Closed): Load Balancing by Hostname
Hi,
It would be handy to be able to Load Balance by hostname, not only by hard-coded IP Address.
Thanks!
Russell Morris
05:26 PM Bug #4696 (Not a Bug): OpenVPN Status / Client List
Hi,
More info at the attached link, but basically - when OpenVPN is up and running, if I am connected to it Load B...
Russell Morris
05:24 PM Bug #4695 (Not a Bug): TAP (OpenVPN) Traffic Blocked
Hi,
More details at the attached link, but basically ... in v2.2.2 I can't seem to get traffic from OpenVPN (TAP c...
Russell Morris
05:20 PM Bug #4694 (Not a Bug): Load Balancing Failing
Hi,
I have been struggling to figure this out (and no luck so far) ... but in v2.2.2 I seem to be having issues wi...
Russell Morris
04:41 PM Revision e9a88707: Firewall Rules Edit missing slash
This should be the end of a "tr" here.
Browsers seem to be forgiving of this stuff - I don't see any difference in re...
Phil Davis
11:59 AM Revision 69f65caf: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
11:41 AM Revision 38e06c66: Support new Form('text') too, convert existing custom buttons
+ fix html @system_firmware Sjon Hortensius
11:40 AM Revision 6135e79f: Convert diag_dump_states_sources
Sjon Hortensius
10:56 AM Revision 9f10fa7b: PROGRESS.md updated, removed windows enters from script
Sjon Hortensius
10:49 AM Revision 256f418c: Minor tweaks, hellip in interf_gif, typo in rss.widget
plus rewrote traffic_graphs.widget to new format Sjon Hortensius
10:32 AM Revision 3fadcdfe: Merge pull request #191 from Bouwdie/services_dhcpv6_relay
Converted services_dhcpv6_relay SjonHortensius
10:30 AM Revision 31f048d4: Merge pull request #190 from Bouwdie/services_dhcp_relay
Re-introduced incidentally removed interface filter. SjonHortensius
10:29 AM Revision e49ce81d: Added panel-body
The ... sbeaver
10:29 AM Revision ea02edef: diag_logs.vpn.php Conversion complete
Ready for review.
In guiconfig.inc dump_clog_no_tables() now returns the number of log
lines printed allowing for an...
sbeaver

05/09/2015

01:31 PM Revision dbf6bf9f: Re-introduced incidentally removed interface filter.
Peter Bouwdewijn
01:26 PM Revision 5caa70ec: Revert "Re-introduced incidentally removed interface filter."
This reverts commit e3d953d5f4eac06672d1331c6ff9fe88f88a3c51. Peter Bouwdewijn
01:19 PM Revision e3d953d5: Re-introduced incidentally removed interface filter.
Peter Bouwdewijn
01:13 PM Revision bb466f49: Copied util functions from services_dhcp_relay.php.
Migrated to form class. Peter Bouwdewijn
01:00 PM Revision f0a108f2: Append button to control group instead of control label
Refs. #142 Sander van Leeuwen
12:35 PM Revision 916a2d71: Clean.sh
Peter Bouwdewijn
12:15 PM Revision ead9fa43: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
12:01 PM Revision 52d7947c: Implemented new MultiCheckbox feature, refs #142
Sjon Hortensius
11:58 AM Revision 85033097: Form - introduce MultiCheckbox(+Group) #142
Sjon Hortensius
11:38 AM Revision d390bbf7: Minor edits per SH
Thanks! sbeaver
11:32 AM Revision 458a6879: Minor edits as suggested
Thanks sbeaver
10:42 AM Revision b148c54a: Make consistent #183
Sjon Hortensius
10:40 AM Revision 1332ace6: interface_gre.php Conversion complete
Ready for review sbeaver
10:37 AM Revision 5ff01d01: Oops, move NAV to correct location #184
Sjon Hortensius
10:36 AM Revision c8610c74: Make consistent #182
Sjon Hortensius
10:33 AM Revision 6a2a3416: interface_gif.php Conversion complete
Ready for review sbeaver
10:31 AM Revision 719da9a2: fixed typo, correct $tab_array in interfaces_groups.php #184
Sjon Hortensius
10:30 AM Revision e41d7a1c: cleanup interfaces_groups.php
Sjon Hortensius
10:26 AM Revision 2ec0d736: interfaces_groups.php Conversion complete
Page updated for compatibility with the other interface_* pages sbeaver
10:21 AM Revision 174722ac: diag_patterns.pgp Conversion complete
Ready for review.
Note: The “Browse” button has some alignment issues that should be
addressed.
sbeaver
10:09 AM Revision 0074384f: guiconfig.inc updated
dump_clog_no_table() now returns the number of log lines printed so
that the caller can display a message if there we...
sbeaver
09:59 AM Revision f849a29f: diag_logs_filter_dynamic.php conversion complete
Ready for review
Table can be popularized both on initial load and at timed intervals,
hence the button needed to be...
sbeaver
09:44 AM Revision cb77470a: Put something usefull in placeholder for Filter expression
Sjon Hortensius
09:40 AM Revision f2731e42: Merge pull request #172 from sbeaver-netgate/diag_logs_filter_summary
Convert diag_logs_filter_summary SjonHortensius
09:33 AM Revision fe0d6189: Merge pull request #165 from Bouwdie/services_dhcp_relay
Covnert services_dhcp_relay + bugfix in IpAddress SjonHortensius
09:31 AM Revision 1c306cd0: If a btn-danger has a title, use that instead of generic for confirm()
Sjon Hortensius
09:30 AM Revision 6717d1fc: simplify xhr delete button
Sjon Hortensius
09:12 AM Revision 645086f8: Merge pull request #155 from sbeaver-netgate/diag_dump_states
Convert diag_dump_states.php SjonHortensius
08:48 AM Revision cbda5c13: Merge pull request #162 from sbeaver-netgate/system_hasync
Converted system_hasync SjonHortensius
08:34 AM Revision 0ea606c9: Merge pull request #151 from sbeaver-netgate/status_rrd_graph_settings
Converted status_rrd_graph_settings.php SjonHortensius
08:28 AM Bug #4693: php warning when applying changes after change Resolver service|Access List
This was already reported at least 3 times and fixed almost 1 month ago...
https://redmine.pfsense.org/projects/pf...
Kill Bill
06:54 AM Bug #4693: php warning when applying changes after change Resolver service|Access List
Note the difference betwwen $sysdnsserver and $sys_dnsserver*s* Alvaro Sedano
06:48 AM Bug #4693 (Duplicate): php warning when applying changes after change Resolver service|Access List
php warning when applying changes after change Resolver service|Access List
The php warning is:
"Warning: in_ar...
Alvaro Sedano
05:32 AM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Chris, thanks for the response. YOu suggest to follow up with the responsible parties (I assume squid's devs) but d... Anonymous

05/08/2015

11:23 PM Bug #4602 (Not a Bug): Captive Portal pfSense 2.2 not working as before when used with CARP
this is a configuration that never should have worked, would have never worked reliably in a variety of possible fail... Chris Buechler
11:19 PM pfSense Packages Bug #4690 (Rejected): Squid cache needs to be flushed periodically or package managers on LAN clients wont work
this is almost certainly a problem within squid itself, or a problem on the servers in question, none of which we hav... Chris Buechler
01:41 PM pfSense Packages Bug #4690 (Rejected): Squid cache needs to be flushed periodically or package managers on LAN clients wont work
I have experienced the same issue about 6 months ago when after having installed squid+SG I noticed that package mana... Anonymous
08:43 PM Revision 801cbbf7: Unmatched td in firewall_nat
This file seems to have an unmatched "td" ending. Adding the line here matches the "td" at line 320 and this embraces... Phil Davis
08:43 PM Revision ca9a4e2b: Call clear_subsystem_dirty('staticmaps') if using Unbound
Robert Nelson
08:43 PM Revision d0c28e66: Merge pull request #1635 from Robert-Nelson/staticmap-bug
Renato Botelho
08:40 PM Revision 897a4c6b: Merge pull request #1636 from phil-davis/patch-1
Renato Botelho
07:50 PM Bug #4692: CODELQ scheduler defaults to incorrect "target" and "interval" values.
My apologies if this patch is incorrect or causes a fire. I figured I would try. It modifies pfsense-tools/patches/st... Ben Cook
06:19 PM Bug #4692: CODELQ scheduler defaults to incorrect "target" and "interval" values.
Perhaps it is obvious, but it looks like the calls to "@codel_alloc(100, 5, 0);@" in one/all of the "altq_codel.diff"... Ben Cook
05:38 PM Bug #4692 (Resolved): CODELQ scheduler defaults to incorrect "target" and "interval" values.
If I setup CODELQ as my WAN's queue scheduler, when I run "@pfctl -vsq | grep -i codel@" the returned string is "@alt... Ben Cook
07:25 PM Revision fa6cb13a: Remove 'form-control' class from file inputs
Refs. #180 Sander van Leeuwen
04:18 PM Revision 3ba1e728: Keep verify_all_package_servers() and check_package_server_ssl() around until GUI is finished
Renato Botelho
04:17 PM Revision e6b4c39d: Fix syntax
Renato Botelho
04:10 PM Bug #4682 (Resolved): invalid return payload crash on primary on filter reload
Chris Buechler
03:47 PM Revision 5b275f2d: xmlrpc is not being used anymore
Renato Botelho
03:46 PM Revision 481aa701: diag_logs_filter_summary improved per SH
Thanks for the suggestion. Can’t believe I didn’t see that :( sbeaver
03:42 PM Revision e0d24d88: Keep get_pkg_id() around since a couple of packages are using them
Renato Botelho
03:27 PM Revision b7e9afc0: Escape entire command to avoid breaking parameters
Renato Botelho
03:26 PM Revision dfa9759a: ASSUME_ALWAYS_YES is boolean
Renato Botelho
03:23 PM Revision 7a643e58: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
03:03 PM Revision d78c4a27: Install regular git-lite package
Renato Botelho
01:58 PM Revision 50ec85d6: Merge pull request #161 from sbeaver-netgate/diag_logs
diag_logs - Added warning for DHCP SjonHortensius
12:28 PM Bug #4689 (Resolved): Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0"
Exact cause yet unknown, but a panic can be triggered with the above condition. It appears to be a "FreeBSD bug":http... Jim Pingle
08:27 AM Bug #4103: Xen xn NICs can't tag VLANs
Hello Chris,
I've read many reports about this issue and this one is the best by far. But I still think the proble...
Eduardo Stelmaszczyk
06:06 AM Feature #4688 (New): Missing TFC Traffic Flow Confidentiality support
Got a IPSEC IKEv2 Tunnel up and running where a linux client connects to the pfsense 2.2.2 server. When connecting i ... Lars Pedersen
05:07 AM Bug #4686: Rekeyed SAs are not properly removed
Yeh, you might be right. I will leave it for more knowledgeable persons to comment further. Phillip Davis
01:48 AM Bug #4686: Rekeyed SAs are not properly removed
From the looks of it this should only affect connections with multiple P2 entries defined, no? I am having a single s... Florian Apolloner
03:55 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
What is the time frame for fixing this? I was hit by this bug now by adding dnssec NSEC3 to my DNS which enlarged th... Klaus Steinberger

05/07/2015

10:05 PM pfSense Packages Feature #4687 (Duplicate): OpenVPN Client Export - Use the VPN description when producing the exported file (instead of host-proto-port combination)
I found the default <hostname>-<protocol>-<port>-<user/certname> combination a bit unfriendly for my users, so I adde... David Young
08:06 PM Bug #4686: Rekeyed SAs are not properly removed
There are some changes coming for 2.2.3 like https://github.com/pfsense/pfsense/commit/afd0c1f2c9c46eaa8e496e98bea8a8... Phillip Davis
03:24 PM Bug #4686 (Resolved): Rekeyed SAs are not properly removed
I am getting weird behaviour on some IPSec connections since 2.2.2. It looks as if CHILD_SA are not cleaned up which ... Florian Apolloner
06:22 PM Revision 5f3a0fc3: Drop verify_all_package_servers() verify_package_server() check_package_server_ssl() package_server_ssl_failure_message() and package_server_mismatch_message()
Renato Botelho
06:21 PM Revision fa0a84cd: Drop pkg_fetch_config_file() and pkg_fetch_additional_files()
Renato Botelho
06:16 PM Revision 84d0ea1c: Remove package_skip_tests(), it won't be necessary anymore with pkg
Renato Botelho
06:15 PM Revision 3c4392ee: Add a note to implement pkg_reinstall_all later
Renato Botelho
06:11 PM Revision eb9cc943: Make rc.packages ready to deal with pkg install/deinstall scripts calls
Renato Botelho
06:10 PM Revision 3bb7e3e8: Rework delete_package_xml() for pkg migration
Renato Botelho
06:07 PM Revision 8af4dd4c: Fix delete_package for pkg
Renato Botelho
06:04 PM Revision 801fcf24: Modify install_package and install_package_xml to work with new pkg flow
Renato Botelho
04:37 PM Revision 4d4e9b06: Fix git path and use pkg_install() to install it on gitsync
Renato Botelho
04:37 PM Revision 7379d80f: Implement pkg_install()
Renato Botelho
04:28 PM Revision d69bbc8b: Remove unused function get_pbi_binaries()
Renato Botelho
04:27 PM Revision 57a608c5: Remove unused function pkg_fetch_recursive()
Renato Botelho
04:27 PM Revision 04dd9b04: Do not try to install package since it's already installed at this point
Renato Botelho
04:24 PM Revision d1a8f050: Adjust uninstall_package() for pkg
Renato Botelho
04:17 PM Revision 82917ea2: Remove unnecessary function get_pkg_depends()
Renato Botelho
04:16 PM Revision a0d4336f: Rework sync_package, remove unused parameters, remove sync_depends, sanitize returns
Renato Botelho
04:07 PM Revision eafe02a2: Remove global variables declared but not used
Renato Botelho
03:51 PM Revision a4f585c0: Return a blank array on get_pkg_info for now, will be implemented later when I touch GUI
Renato Botelho
03:49 PM Feature #3029: DHCPv6 Server/RA page should list interfaces that are configured to track DHCP-PD
I've add PR # 1638 to fix this issue. Robert Nelson
03:08 PM Revision 78c61a75: Remove unused function expand_to_bytes() get_pkg_db() and get_pkg_interfaces_select_source()
Renato Botelho
03:08 PM Revision b27c5cbf: Use 'interfaces_selection' type to miniupnp fields
Renato Botelho
03:03 PM Revision 22b88bc4: Currently pfsense enforces unique unqualified hostnames for static dhcp leases, which is not correct as only the fully qualified hostname (hostname + domainname) must be unique. With this commit the old validation logic for uniqeness is modified such that hostnames no longer need to be unique and at the same time the fully qualified hostname hast to be unique.
This change makes it possible to have host with identical hostnames in different (sub)domains. For example myhost.sal... Berger Alexander
02:53 PM Revision 79b0035d: Remove unused function does_package_depend()
Renato Botelho
02:52 PM Revision 106574d1: Remove unecessary function force_remove_package()
Renato Botelho
02:50 PM Revision 24fa00fc: Drop is_freebsd_pkg_installed() in favour of is_pkg_installed()
Renato Botelho
02:48 PM Revision 97c88dfa: Remove unused function walk_depends()
Renato Botelho
02:48 PM Revision ae786f03: Remove unused function squash_from_bytes()
Renato Botelho
02:47 PM Revision 45cd5fcd: Remove unused functions get_pkg_sizes() and get_package_install_size()
Renato Botelho
02:02 PM Revision af5d93f6: Rename get_pkg_id() to get_package_id() and get_pkg_internal_name() to get_package_internal_name(). Try to use more standard parameter names and simplify logic while here
Renato Botelho
01:53 PM Revision c2eb2508: Rename remove_freebsd_package() to pkg_delete() and introduce pkg_remove_prefix() pkg_call() and is_pkg_installed()
Renato Botelho
01:45 PM Bug #4685 (Resolved): Crash/panic "Sleeping thread owns a non-sleepable lock"
Several reported similar panics have been happening to users. There appears to be an issue with BPF/ARP resolution at... Jim Pingle
01:33 PM Revision d2caff9b: Cleanup old and unecessary directory creation
Renato Botelho
01:27 PM Revision 8341eb47: Remove unused function add_text_to_file()
Renato Botelho
01:26 PM Revision ffa04fc2: Remove use of obsolete packages tag 'modify_system'
Renato Botelho
01:20 PM Revision 7d11138e: Merge pull request #150 from sbeaver-netgate/diag_pkglogs.php
Converted diag_pkglogs.php SjonHortensius
01:02 PM Revision fdae0912: Pass correct package name to add_package_tabs()
Renato Botelho
01:01 PM Revision 253b37d8: Read tab information from package xml file instead of config.xml
Renato Botelho
12:58 PM Revision 0bd239d9: Define pkg_prefix global var
Renato Botelho
12:00 PM Revision 3e19c704: Display inner tabs as tabs
sbeaver
11:20 AM Revision f18fa98d: Unmatched td in firewall_nat
This file seems to have an unmatched "td" ending. Adding the line here matches the "td" at line 320 and this embraces... Phil Davis
09:55 AM pfSense Packages Bug #4684 (Resolved): WebGUI: siproxd disabled in menu but still running as service
Just found a little bug in the siproxd package:
The start situation is: pfSense 2.2.2 (32bit), package siproxd 1.0...
Willy Tenner
06:48 AM Feature #4683 (Resolved): Support for elliptic curve for IPsec on webconfigurator
In pfSense 2.2.2 strongswan runs with version 5.3.0 and it looks like it supports elliptic curves in the dh-group:
...
Lars Pedersen
06:41 AM Revision 135ad35b: - Fixed indenting
- Fixed matching closing tags
- Moved action buttons to separate <nav>
Refs. #22
Sander van Leeuwen

05/06/2015

10:14 PM Revision 25955c6e: Removed unneeded var
sbeaver
10:00 PM Revision f2fd5978: Converted img to btn-xs button
sbeaver
09:09 PM Revision 46d1a381: diag_logs_filter_summary conversion complete
Ready for review
The previous charing system is not compatible with JQuery (because it
makes use of its own $() macr...
sbeaver
08:09 PM Revision 9a9c8e25: Make save button for widget configuration better visible
Refs. #48 Sander van Leeuwen
03:06 PM Revision 9ca6cf48: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
07:44 AM Revision e14400b2: Revert button>input so we can keep using $name
refs #101 Sjon Hortensius
07:30 AM Bug #4682: invalid return payload crash on primary on filter reload
Looks like a different manifestation of the issue fixed here: https://redmine.pfsense.org/projects/pfsense/repository... Ansley Barnes
07:14 AM Bug #4682 (Resolved): invalid return payload crash on primary on filter reload
After upgrading to 2.2.2 a crash occurs on CARP primary machines after syncing their config to the secondary. It appe... Ansley Barnes
03:20 AM Feature #4681 (Resolved): AutoConfigBackup make a way to easily download a saved backup
From the Stats and Restore tabs you can easily see all the stored backups for any host belonging to your account - gr... Phillip Davis

05/05/2015

11:42 PM pfSense Packages Bug #4677 (Not a Bug): pfsync bulk fail
you have one on HTTP and one on HTTPS it appears, or some other non-matching config. Not a bug, please post to the fo... Chris Buechler
02:38 PM pfSense Packages Bug #4677 (Not a Bug): pfsync bulk fail
I set up two firewalls with CARP, using dedicated interfaces SYNC, when the master tries to send firewall settings, t... Eleandro Araujo
09:25 PM Bug #4675: DHCPv6 DDNS doesn't work properly
For the second issue I updated my PR to allow it to be configured between allow, deny and ignore. Robert Nelson
03:32 AM Bug #4675 (Resolved): DHCPv6 DDNS doesn't work properly
There are three issues:
- The wrong domain was being used, domain instead of ddnsdomain.
- The option "deny client-...
Robert Nelson
08:59 PM Revision 6877666e: Call clear_subsystem_dirty('staticmaps') if using Unbound
Robert Nelson
07:02 PM Revision ff916cd2: Fix print_info_box_np with apply button
- Wrap message in container to float button to the right
- Fix syntax error
Refs. #101
Sander van Leeuwen
06:55 PM Bug #4680 (New): DHCP relay does not work with DHCP server on other end of OpenVPN tunnel
It is currently documented at https://doc.pfsense.org/index.php/DHCP_Relay that DHCP Relays don't work over IPsec tun... Per von Zweigbergk
06:44 PM Revision 0ce45fdf: Replace td's with th's and make table responsive
Refs. #168 Sander van Leeuwen
06:28 PM Revision d55a8692: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
06:28 PM Revision 12c82b37: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
05:49 PM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
Is there something to test or something else to do?
I'm still on 2.1.5 and want to update.
Grischa Zengel
04:54 PM Bug #4679 (Resolved): IPsec dashboard widget wrongly shows "REKEYED" SAs as "down"
Where you have an SA in status REKEYED in 'ipsec statusall', similar to: ... Chris Buechler
04:00 PM Bug #4678 (Resolved): DHCPv6 with static entries, Apply configuration button never goes away
If you add a static entry and you are using Unbound with register DHCP static entries, then the Apply configuration b... Robert Nelson
02:52 PM Revision f6f04195: Remove make_dirs(), it was only being used by packages but now all calls were replaced by mkdir()
Renato Botelho
02:29 PM Revision 6d27296b: Combined two if($curcat . . blocks
sbeaver
02:24 PM Revision cccdc5ce: Updated per SH suggestions
Thanks! sbeaver
02:03 PM Revision 59efb129: Improved as suggested
Thanks sbeaver
01:47 PM Revision 3865efd1: Merge pull request #157 from sbeaver-netgate/system_firmware
Convert system_firmware conversion SjonHortensius
01:43 PM Revision 607b1c39: Rewrote xhr javascript, applied .form-inline refs #153
Sjon Hortensius
12:52 PM Revision a906772a: Merge pull request #153 from sbeaver-netgate/status_graph
Inital conversion of status_graph.php SjonHortensius
12:35 PM Revision be736a44: Merge pull request #146 from sbeaver-netgate/status_ntpd
Converted status_ntpd update SjonHortensius
12:35 PM Revision 7366071d: Merge pull request #145 from sbeaver-netgate/status_interfaces
Converted status_interfaces.php SjonHortensius
12:32 PM Revision b95ce5a5: removed red. indenting + unused variable refs #139
Sjon Hortensius
12:31 PM Revision 7aae81d2: Merge pull request #139 from sbeaver-netgate/status_gateway_groups
Converted status_gateway_groups SjonHortensius
12:19 PM Revision 684a1dbc: Use default array_filter callback.
Moved adding of section down for clarity.
Wrapped message in an alert (same as print_input errors but without the ext...
Peter Bouwdewijn
11:51 AM Revision 4889ed28: Added fix in IpAddress to check if a mask is set to prevent a method call on a non object.
Migrated form.
Moved server input to an array form value.
Peter Bouwdewijn
10:06 AM pfSense Packages Bug #4676 (Rejected): Avahi & .local domain in config file
I can't manage to get Avahi to work out of the box. When I restart it on commandline I get the message:... Adrian Gschwend
09:16 AM Revision c50cdaa0: Merge branch 'bootstrap' of https://github.com/Bouwdie/pfsense into services_dhcp_relay
Caught up with main repo. Peter Bouwdewijn
07:04 AM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Markus Tellian wrote:
> The change applied in "120acbae8c2edd2e60685dd7ca16966cd988afc7":https://redmine.pfsense.org...
Markus Tellian
07:01 AM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
The change applied in "120acbae8c2edd2e60685dd7ca16966cd988afc7":https://redmine.pfsense.org/projects/pfsense/reposit... Markus Tellian
02:21 AM Bug #2582: OpenVPN service won't start after changing the IP of interface
I was running into this when selecting a Failover Gateway Group as the outbound device for the OpenVPN connection, ru... Jan SH

05/04/2015

09:23 PM Bug #4607 (Confirmed): Bridge+CARP crashes/freezes pfSense
It doesn't appear specific to VLANs. A CARP IP on an interface that's a member of the bridge, or on the bridge itself... Chris Buechler
07:02 PM Revision cb7b3761: system_hasync.php - Conversion complete
Ready for review sbeaver
04:17 PM Revision 5d7a0cca: diag_logs.php Added DBCP warning
Warning notice is required when viewing DHCP logs
Reduced unneeded indenting in HTML
sbeaver
02:50 PM Revision 560723a4: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
02:50 PM Revision 7e0b4ccf: ensure gettext and htmlspecialchars are correctly called
sbeaver
02:44 PM Revision f4b10abe: Merge pull request #160 from sbeaver-netgate/logs-consolidation
Converted diag_logs_* SjonHortensius
02:31 PM Revision 566b1e7f: dig_settings updated
Switched to my master branch, updated with pull from SH fork, updated
tab array and committed.
This version should c...
sbeaver
02:19 PM Revision cb578e18: diag_logs.php Minor edit per SH suggestion
Substitute in_array() for long ‘if’ statement
Thanks for the suggestion
sbeaver
02:07 PM Revision 0a5d0b7b: diag_logs - log file consolidation
A GET argument has been added to dig_logs.php so that the log file to
displayed can be specified.
Minor edits to the...
sbeaver
01:47 PM Bug #4671: Add "net.inet.ip.portrange.reservedhigh" to system tunable GUI
AFAIK, you can add ANY tuneable in System: Advanced: System Tunables
that's what the "< + >" button at the bottom ...
jeroen van breedam
12:42 PM Revision 84942ddd: system_firmware_settings detailed changes per SH
Thanks for the suggestions. sbeaver
12:22 PM Revision 1180c752: status_rrd_graph_settings detail changes per SH
Thanks for the suggestions. sbeaver
12:01 PM Revision 1e314e79: status_ntpd.pnp detailed changes
Removed unneeded printCell funtion sbeaver
11:56 AM Revision 45e630d7: system_firmware detailed changes
Removed unneeded placeholders
Forced firmware upgrades to be disabled on atoll page load.
sbeaver
11:46 AM Revision fb6c7bb8: status_interfaces detailed changes per SH
Useful suggestions. Thank you.
htmlspecialchars() moved to showDef[Btn] functions
Minor formatting changes
sbeaver
11:16 AM Revision 4ed05874: status_gateway_groups
Detailed changed per SH sbeaver
08:53 AM Bug #4674 (Resolved): invalid state table entries after WAN IP change
This is similar to Bug #1629. I have a SIP client behind pfsense 2.2.2. When the WAN IP changes, there is a state tab... Daniel Haid
02:38 AM Bug #4670: pkg - ELF interpreter /libexec/ld-elf.so.1 not found
Hmmm, wonderful. Now, someone tell me how to fix this.... Kill Bill
02:37 AM Bug #4670: pkg - ELF interpreter /libexec/ld-elf.so.1 not found
Well, figured out. Another corpse left after accidental cross-arch upgrade (kindly see Bug #4636 and fix the braindea... Kill Bill
12:14 AM Bug #1629: invalid state table entries after WAN IP change
taking out the filter reload doesn't influence this, and will break things in a number of circumstances. There seemin... Chris Buechler

05/03/2015

11:10 PM Bug #3710: Adding static DHCP leases doesn't cause BIND zones to update
Affected by this as well on pfSense 2.2.2; BIND plugin 0.3.9.
Is there a good workaround for this issue?
The si...
Rob Millner
07:19 PM Bug #1629: invalid state table entries after WAN IP change
I have checked again, with the patch, it seems to work even without ip_change_kill_states. I do not know whether I sa... Daniel Haid
06:05 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
There appear to be three distinct issues here. Documenting it before I forget.
1. The generated netgraphcmd file see...
Steve Wheeler
12:16 PM Revision 53be3e0d: Merge pull request #147 from sbeaver-netgate/status_lb_vs
Converted status_lb_vs.php SjonHortensius
09:21 AM Bug #4673 (Not a Bug): Can't override rules in filter.inc from the GUI
Sometimes legitimate traffic is blocked by the default/quick rules in filter.inc. However, these cannot be overridde... Andrew -
09:11 AM Todo #4672 (Resolved): Update igmpproxy to latest version
The currently installed version of igmpproxy is an early beta version from 2005, and has a number of issues. For exa... Andrew -

05/02/2015

10:09 PM Bug #1629: invalid state table entries after WAN IP change
I have the same issue with a SIP client. It seems that the SIP client creates a new entry in the short time after flu... Daniel Haid
06:38 PM Bug #4671 (Not a Bug): Add "net.inet.ip.portrange.reservedhigh" to system tunable GUI
*Background:*
To be able to bind squid for reverse proxy to port under 1024 the _net.inet.ip.portrange.reservedhigh_...
Elias Gabrielsson
01:20 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
Having run some tests this appears to be broken beyond just exposing the raw interface names.
Choosing the QinQ name...
Steve Wheeler
12:41 PM Revision e22512fc: ensure gettext and htmlspecialchars are correctly called
Sjon Hortensius
12:33 PM Revision 103fab1d: head.inc - don't include modal if there are no notices
Sjon Hortensius
12:20 PM Revision a2143951: update bootstrap to 3.3.4, jquery to 1.11.2
Sjon Hortensius
12:13 PM Revision 44d906ca: system_authservers - fix toggle by making it explicit fixes #108
also allow calling toggles without any arguments Sjon Hortensius
09:34 AM Revision 5d571dee: Cherry-pick 'sbeaver-netgate-status_gateways' into bootstrap, excl. _groups
fixes #137 Sjon Hortensius
09:33 AM Revision 0843bc20: status_gateways updated as requested
nbsp was not found. Perhaps I forgot to sync
Column widths were removed. You were right :)
sbeaver
09:33 AM Revision 961ffe14: Added thead/tbody tabs and removed unneeded div id
sbeaver
09:33 AM Revision a023d257: status_gateways.php conversion complete
Two tables eliminated
Colors defined to eliminate magic
Bootstrap column width specified
All obsolescent classes and ...
sbeaver
09:33 AM Revision d696dd1f: Corrected background color
sbeaver
09:33 AM Revision fff68385: status_gateways.php Bootstrap conversion
sbeaver
09:27 AM Revision 563ffd03: updated, fixes #111
Sjon Hortensius
09:19 AM Revision a3a38ffc: Merge branch 'sbeaver-netgate-diag_traceroute' into bootstrap
Sjon Hortensius
09:18 AM Revision 444381d1: diag_traceroute updated as requested
sbeaver
09:18 AM Revision a7420eba: Corrected typo
sbeaver
09:18 AM Revision cd7d902d: Updated per SH comments
sbeaver
09:18 AM Revision 77af9793: Page ready for review
sbeaver
08:58 AM Revision eb500b85: removed unneeded attributes, rewrote xhr-delete, made form not auto-submit
Sjon Hortensius
05:25 AM Bug #4670 (Not a Bug): pkg - ELF interpreter /libexec/ld-elf.so.1 not found
Latest 2.2.3-DEVELOPMENT snapshot.... Kill Bill
04:16 AM Bug #4131 (Resolved): CP RADIUS accounting not working
Ermal Luçi

05/01/2015

08:48 PM Revision fd252629: Encode server name before displaying back to the user.
Jim Pingle
08:48 PM Revision e29271f2: Encode server name before displaying back to the user.
Jim Pingle
08:36 PM Revision 3ce84694: Ticket #4652 actually return value as expected!
Ermal Luçi
08:36 PM Revision be754c8b: Ticket #4652 actually return value as expected!
Ermal Luçi
07:57 PM Revision c26de127: Ticket #4235 put reply-to/route-to rules even for mobile-ipsec.
Ermal Luçi
07:55 PM Revision 620c4df1: Ticket #4235 put reply-to/route-to rules even for mobile-ipsec.
Ermal Luçi
07:44 PM Revision 3a09e0d9: Fixes #4633 Enable carp packets to flow on the first carp interface creation. This is needed only when the system is booted up without any carp vip configured
Ermal Luçi
07:44 PM Revision 6e4c8e92: Fixes #4633 Enable carp packets to flow on the first carp interface creation. This is needed only when the system is booted up without any carp vip configured
Ermal Luçi
07:32 PM Revision 6a15be3f: Ticket #4131 before formatting the mac extract the needed statistics from below
Ermal Luçi
07:32 PM Revision f539af76: Ticket #4131 before formatting the mac extract the needed statistics from below
Ermal Luçi
07:09 PM Revision b5140307: Ticket #4651 Oops correct name of var
Ermal Luçi
07:08 PM Revision 65ceb82d: Fixes #4651 Assign a proper tracker for NEGATE rules
Ermal Luçi
07:07 PM Revision be8b480e: Fixes #4651 Assign a proper tracker for NEGATE rules
Ermal Luçi
07:01 PM Revision 120acbae: Fixes #4652 put workaround for bogus timestamp until real data are cosnumed.
Ermal Luçi
07:00 PM Revision 2842c8d4: Fixes #4652 put workaround for bogus timestamp until real data are cosnumed.
Ermal Luçi
06:34 PM Bug #4131: CP RADIUS accounting not working
Confirmed working. Michael Newton
02:30 PM Bug #4131 (Feedback): CP RADIUS accounting not working
Pushed the fix on pfSense as well. Ermal Luçi
02:19 PM Bug #4131: CP RADIUS accounting not working
Can you please try this change?... Ermal Luçi
02:01 PM Bug #4131: CP RADIUS accounting not working
Thanks, confirmed that is the issue.
[01-May-2015 15:03:56 America/Toronto] Running pfSense_ipfw_getTablestats(2, ...
Michael Newton
01:46 PM Bug #4131: CP RADIUS accounting not working
I think your problem is on the mac address format it should be specified by : rather than - Ermal Luçi
12:51 PM Bug #4131: CP RADIUS accounting not working
# ipfw -x 2 table 1 entrystats 10.10.8.139
10.10.8.139/32 0 1 1 0
Michael Newton
12:48 PM Bug #4131: CP RADIUS accounting not working
Can you run the same request but from CLI with ipsec -x 2 table 1 entrystats 10.10.8.139?
Tell me what do you see?
Ermal Luçi
12:34 PM Bug #4131: CP RADIUS accounting not working
I put some debug code into /etc/inc/captiveportal.inc and got this result:
[01-May-2015 13:35:43 America/Toronto] ...
Michael Newton
11:43 AM Bug #4131: CP RADIUS accounting not working
This is still a problem in 2.2.2. Byte counts are all still zero!
I'm about to start digging through the code now,...
Michael Newton
06:21 PM Bug #4669 (Resolved): QinQ virtual interfaces available for assignment where they shouldn't be
Creating a QinQ VLAN adds 3 interfaces to the assign interfaces tab. For instance, add a QinQ on em1 with tag 5, QinQ... Chris Buechler
03:38 PM Revision c6d6ee9e: system_firmware_restorefullbackup.php conversion complete
Ready for review
This page was best converted by retaining one HTML form. The buttons
embedded in the table made thi...
sbeaver
03:12 PM Bug #4268 (Feedback): changes in strongswan config don't apply to SAD or SPD
There is a commit done on how charon daemon was restarted.
Now it goes and signals starter which does the right thin...
Ermal Luçi
03:00 PM Bug #4633: CARP not enabled upon creation of first CARP IP
Applied in changeset commit:3a09e0d96e63e5a8fafcad9199ab2c1d657d68b9. Ermal Luçi
03:00 PM Bug #4633: CARP not enabled upon creation of first CARP IP
Applied in changeset commit:6e4c8e92f8f0407468eccb4c76f4f5affc598d1d. Ermal Luçi
02:42 PM Bug #4633 (Feedback): CARP not enabled upon creation of first CARP IP
Ermal Luçi
02:55 PM Bug #4235 (Feedback): missing 'reply-to' in rules for mobile-ipsec
This should be fixed.
Though to be checked if only reply-to is desired instead of both reply-to and route-to being g...
Ermal Luçi
02:10 PM Bug #4651: Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
Applied in changeset commit:65ceb82d1e0727c0b0c2dcd3f8aa65277171ea33. Ermal Luçi
02:10 PM Bug #4651 (Feedback): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
Applied in changeset commit:be8b480ed1ab787d35f2e8cfeb471b5b898b0fff. Ermal Luçi
02:10 PM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Applied in changeset commit:120acbae8c2edd2e60685dd7ca16966cd988afc7. Ermal Luçi
02:10 PM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Applied in changeset commit:2842c8d407e34a9183908a1677ec162a7b0ea209. Ermal Luçi
01:58 PM Bug #4652 (Feedback): Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Committed. Ermal Luçi
01:47 PM Bug #4665 (Feedback): strongswan duplicates reqid at times, causing failures with multi-P2
The reqid is now removed and let to Strongswan to manage.
It seems to improve things.
Leaving as feedback to be c...
Ermal Luçi
09:00 AM Revision 36a0cfe8: Tweak initial state for toggleable checkboxes
- When iterating over a jQuery object, just use $(this) for the current value
- Use the .data() method to fetch data ...
Sander van Leeuwen
01:05 AM Revision 491c5dba: system_firmware_settings.php conversion complete
Ready for review sbeaver

04/30/2015

10:30 PM Revision d55e91c1: comment out trailing } on these ifs also.
Chris Buechler
08:53 PM Revision b27fdc8b: Seems strongswan 5.3.0 has improved the situation on putting multiple phase2 on IKEv1 behaviour and it behaves even better with reqid not defined in config.
Ermal Luçi
08:53 PM Revision afd0c1f2: Seems strongswan 5.3.0 has improved the situation on putting multiple phase2 on IKEv1 behaviour and it behaves even better with reqid not defined in config.
Ermal Luçi
08:50 PM Revision 1e92a236: Revert "Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet"
This reverts commit 7d5add01e48bab8d82d5a5699325fa7b6aeb4e5c. Ermal Luçi
08:50 PM Revision 6bc6a727: Revert "Provide a description for the dirty hack to not come back scratching.... on it"
This reverts commit 6d7e7c0c5cd8ec613235cd9f2a01f60bb7c32c79. Ermal Luçi
08:49 PM Revision 2f52fcbe: Revert "Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet"
This reverts commit 54dd568af28ebe7b4905fedd3cdf48269e63f001. Ermal Luçi
08:49 PM Revision 626f2cba: Revert "Provide a description for the dirty hack to not come back scratching.... on it"
This reverts commit 7bc36682339693dd10aa53e361f00ab7358115e1. Ermal Luçi
07:46 PM Revision 1be02f50: Detailed changes per SH
sbeaver
07:37 PM Revision 5387537e: system_firmware conversion complete
Ready for review sbeaver
03:47 PM Bug #4668 (Closed): ID Column in Firewall Rules
The ID column under firewall rules is always blank (v.2.2.2). Is it supposed to display @$i@? Jose Luis Duran
02:44 PM Bug #4655 (New): IPsec: Enable bypass for LAN interface IP behaviour is reversed
I shouldn't test at 2 AM apparently. Chris Buechler
05:35 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Yes. The only way to fix this without reversing the evil logic would be reverting this commit and changing the descri... Kill Bill
05:33 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Yes, Chris seems to have reversed the fix I made for the "flip every save" problem. The whole thing needs some re-eng... Phillip Davis
01:51 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
No, sorry, sir. We are back to the flip every save. This no logic MUST go away. Kill Bill
01:25 AM Bug #4655 (Resolved): IPsec: Enable bypass for LAN interface IP behaviour is reversed
fixed, thanks Chris Buechler
12:51 PM Revision 4b219dfd: introduce Form::setMultipartEncoding() for uploading files
Sjon Hortensius
06:41 AM Bug #4592 (Feedback): FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
I've backported revisions from stable/10 and applied on 2.2.x snapshots Renato Botelho
01:43 AM Bug #4592 (Confirmed): FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
Chris Buechler
06:24 AM Revision 43f83ab4: Show correct selection for noshuntlan option. Ticket #4655
Chris Buechler
06:23 AM Revision ee72e2ca: Show correct selection for noshuntlan option. Ticket #4655
Chris Buechler
04:02 AM Feature #4667 (Closed): DNS Resolver - ability to save/restore cache went missing
In the 2.1.x unbound package, there is this dumpcache variable to control saving and restoring the cache (https://git... Kill Bill
03:09 AM Bug #4666: Restore full backup
There is nothing suggesting that it does not work. The function is poorly implemented, with no progress bar or anythi... Kill Bill
02:48 AM Bug #4666 (Not a Bug): Restore full backup
Hi. I upgrade pfsense 2.1.5 to 2.2.2/ every thing is good/ but restore full backup dont work/ why?
Thanks guys
Royal Amrah
01:49 AM Bug #4266 (Resolved): Rekeying issues with IKEv1 and multiple P2s under some circumstances
the original issue in this ticket no longer exists in 2.2.1 and newer. The remaining multi-P2 issues are covered by #... Chris Buechler
01:26 AM Bug #4640 (Resolved): "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
last bit fixed under #4655 Chris Buechler
12:34 AM Bug #4665 (Resolved): strongswan duplicates reqid at times, causing failures with multi-P2
Where a system has a number of P2s on a single P1 with IKEv1, strongswan at times assigns the same reqid across multi... Chris Buechler

04/29/2015

06:00 PM Feature #4664 (Resolved): Separate Processor (CPU) and Processes graphs
Currently, the Processor graph contains both CPU usage information (User/Nice/System/Interrupt) mixed with the number... Denny Page
01:03 PM Revision 3032b29b: dig_dump_states.php conversion complete
Ready for review sbeaver
12:15 PM Revision 4f2192e6: diag_resetstates.php conversion complete
Ready for review. sbeaver
08:31 AM pfSense Packages Bug #4663 (Resolved): pfsense 2.2.2-RELEASE + squid3 + squidGuard = Breaking squid.conf when using c-icap
Squid + SquidGuard will break squid.conf when changes are made if using C-ICAP due to some parameters missing the ON ... yunior alvarez
07:18 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
WAN1 and WAN2 — static IP. May want to try it in my "virtual machine":https://yadi.sk/d/PWSuNbZhgK47P for test. z z
07:10 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
As I remember, when creating or editing an OpenVPN instance, the interface or highest tier of the gateway group to wh... Phillip Davis
04:03 AM Bug #4661 (Resolved): OpenVPN client can't assign to GWGroup specifying VIPs
# Failover pfSense with CARP —> OpenVPN client autostart OK.
# Failover multi-WAN —> OpenVPN client autostart OK.
#...
z z
05:27 AM pfSense Packages Bug #4662 (Closed): zabbixLTS snmpwalk doesn't work
[2.2.2-RELEASE][root@pfsense]/usr/pbi/zabbix22-proxy-i386/local/bin: find / -iname 'snmpwalk' | xargs ls -l
lrwxr-xr...
Heðin Ejdesgaard Møller

04/28/2015

07:55 PM Revision e31aa678: status_graph.php conversion complete
Tis page has a very clever presentation that I did not want to loose.
So one table remains.
Otherwise tit has been c...
sbeaver
06:32 PM Revision 501d7904: Merge pull request #88 from sbeaver-netgate/diag_sockets
Convert diag_sockets SjonHortensius
04:46 PM Revision 3c44b044: status_rd_graph.php updated
This page has been extensively updated, but it could do with bing
revised further at some time in the future.
For no...
sbeaver
01:51 PM Revision fcad7ca1: Merge pull request #1632 from cfazendin/googledomains
Ermal Luçi
12:01 PM Revision bef0adce: Updated for consistency with reboot.php
sbeaver
11:54 AM Revision 45d6ada5: Revert "Merge pull request #100 from sbeaver-netgate/halt"
This reverts commit 5bd406696ae634b3993d79a8b9aef03eeab42488, reversing
changes made to b9bd62735f2afb818d9ff3afd399c...
Sjon Hortensius
11:52 AM Bug #4658 (Resolved): Quick/easy install fails with gmirror and SATA disks
fixed Chris Buechler
10:21 AM Bug #4658 (Feedback): Quick/easy install fails with gmirror and SATA disks
I've pushed a patch to fix it, please confirm. Renato Botelho
10:02 AM Bug #4658: Quick/easy install fails with gmirror and SATA disks
installer log attached Chris Buechler
06:04 AM Bug #4658: Quick/easy install fails with gmirror and SATA disks
Could you send me /tmp/installer.log? I tried to reproduce it but couldn't Renato Botelho
11:46 AM Bug #4633 (Confirmed): CARP not enabled upon creation of first CARP IP
Chris Buechler
09:59 AM Bug #4660 (Not a Bug): Unbound DOsent Display IPSEC interface
The enc interface never has an IP, and all those interface selections require IPs in the Unbound config, hence it's n... Chris Buechler
08:04 AM Bug #4660 (Not a Bug): Unbound DOsent Display IPSEC interface
This prevents DNS requests from exclusion zones from being forwaded across an IPSEC VPN to the root private DNS server Andrew Owen
03:02 AM Revision 404ff523: removed unnecessary curl options.
Christopher Fazendin
02:46 AM Revision 6c92b378: Add Google Domains to Dynamic DNS service.
Christopher Fazendin
01:16 AM Bug #4571: scheduled firewall reboot crashes
inspite of the crosstalk on the adapter, 2.1.5 still allows to select slice and press any key or enter to continue wh... Bipin Chandra

04/27/2015

10:53 PM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
One thing I would add is that this behavior is particular to the Unity plug-in. With the Unity plug-in disabled, the ... Denny Page
10:40 PM Bug #4659: Enabling Unity plugin adds garbage to the last domain name
Sorry Chris, I guess I didn't search deep enough in the bug list.
Denny Page
10:36 PM Bug #4659 (Duplicate): Enabling Unity plugin adds garbage to the last domain name
duplicate of #4418 Chris Buechler
10:28 PM Bug #4659 (Duplicate): Enabling Unity plugin adds garbage to the last domain name
If the Unity plugin is enabled, garbage is added to the last domain listed in Split DNS. In my case, it's always the ... Denny Page
08:18 PM Revision 42c94540: status_rrd_graph_settings.php conversion complete
Ready for review sbeaver
06:59 PM Bug #4658 (Resolved): Quick/easy install fails with gmirror and SATA disks
Where you have a system with SATA disks, setup a GEOM mirror with them, and then try to do the quick/easy install, it... Chris Buechler
06:44 PM Revision 3c2c32b3: diag_pkglog.php conversion complete
Ready for review sbeaver
05:27 PM Revision 663e75cd: status_b_vs.php updated
Ready for review
Many nested tables and their old classes removed
Added warning when no LBs have been configured
Stan...
sbeaver
03:50 PM Revision 8dff26ce: status_ntpd update complete
Ready for review
This conversion has no forms so lent itself to the removal off the
outer tables (3) the provision o...
sbeaver
01:49 PM Revision bd06568f: status_interfaces - WIP for discussion
This is one way to present the information without the 600 lines of
HTML that were in the file.
Comments or suggesti...
sbeaver
01:19 PM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
Now set PFSense 2.2.2 x32 and for him, set GNUGateKeeper ver. 3.8. Now I am engaged with the settings for simple oper... Aleksei Aksenov
01:12 PM pfSense Packages Bug #4657 (Closed): Asterisk not work in ver. 2.2.1 and up
Asterisk not work in ver 2.2.1 and up Aleksei Aksenov
12:13 PM Revision cf3aff59: Add static mapping interface not set when IP in a pool
If the DHCP IP address is in a pool (not in the main DHCP range for the interface) then the interface that correspond... Phil Davis
12:12 PM Revision 60dee68b: Merge pull request #1631 from phil-davis/patch-5
Renato Botelho
12:09 PM Revision d7d6342c: Fall back to getting local user pages and groups
if the groups could not be found from LDAP and there is a local user. Phil Davis
12:08 PM Revision 437799b8: Merge pull request #1628 from phil-davis/patch-2
Renato Botelho
12:03 PM Revision 73bbcaed: Do not process dhcpd implementation if input errors
If I go to Service->DHCP Server, make some edits that are invalid (e.g. change range start or end to some invalid str... Phil Davis
12:03 PM Revision 03a1d3f6: Merge pull request #1630 from phil-davis/patch-4
Renato Botelho
12:02 PM Revision 1fa1a40b: Tidy up "services_unbound.php" XHTML
Add missing closing TD tag Colin Fleming
12:02 PM Revision 9dded879: Tidy up "status_upnp.php" XHTML
Remove double line from table Colin Fleming
12:01 PM Revision 3bc13e79: Merge pull request #1629 from ExolonDX/master
Renato Botelho
12:00 PM Revision 89f89d73: Merge pull request #1625 from phil-davis/www-e
Renato Botelho
11:58 AM Revision 58befbf8: Merge pull request #1623 from phil-davis/code-style-diag
Renato Botelho
11:55 AM Revision 701833bb: Merge pull request #1622 from phil-davis/usr-local-www
Renato Botelho
11:50 AM Revision daac712a: Merge pull request #1618 from phil-davis/www-widgets
Renato Botelho
11:32 AM Bug #4081: Apinger reporting incorrect latency
Sending ping #1584 to GWPDP (200.160.6.214)
Recently lost packets: 0
Sending ping *#3607* to GWEBT (200.230.251....
Heiler Bemerguy
08:10 AM Bug #4656 (Not a Bug): cannot connect IPsec VPN via dialup
I have had an VPN up and running but suddenly it disconnected and gets stuck on connecting. I have done plenty of tro... Mattias Thorsén
03:14 AM Bug #4571: scheduled firewall reboot crashes
i did some research and it seems there is some issue relating to crosstalk between the TX and RX lines as the alix se... Bipin Chandra
02:56 AM Bug #4276: Layer 7 not working / ipfw-classifyd high load
Hy folks, any chance to hav a patch for the 2.2.2?
regards
Florent THOMAS

04/26/2015

02:08 PM Revision 01752a98: Fix "Apply" button in dialogs #101
Sjon Hortensius
01:33 PM Revision 11486640: Add nav-wrapper to loose buttons
Sjon Hortensius
01:21 PM Revision 3e607d0e: Don't use $section2, toggle all remote-options when disabled
pfSense.js - Force correct initial state for toggleable checkboxes #143 Sjon Hortensius
11:41 AM Revision c2518204: Prepare for different width, make widths static
refs #141 Sjon Hortensius
10:22 AM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
Just adding a "me too". I have default rule logging turned off, but still seeing lots of entries in firewall log of "... Arion Lawrence
10:13 AM Revision 687456e3: Merge pull request #134 from sbeaver-netgate/diag_logs_settings.php
Converted diag_logs_settings.php SjonHortensius
09:32 AM Bug #4571: scheduled firewall reboot crashes
i got the new usb to serial adapter and tried with my alix, still the issue persists, cant press any key on keyboard ... Bipin Chandra
01:59 AM Bug #4655 (Resolved): IPsec: Enable bypass for LAN interface IP behaviour is reversed
Before this gets lost again: After the commits related to Bug #4640, the checkbox does the exact opposite of what'd d... Kill Bill

04/25/2015

05:24 PM Revision 891b61a4: Merge branch 'master' into floating-interfaces
Robert Nelson
02:17 PM Revision 9ba6f708: Form - show all global Buttons in a single wrapper
fixes #135 Sjon Hortensius
01:59 PM Revision 4705fa62: Replaced js with toggles
Also eliminated unneeded gettext from help sbeaver
01:37 PM Revision b49f31d0: Converted system_certmanager
fixes #106 Sjon Hortensius
12:43 PM Revision 6755cfe8: Replace js with addClass to set button class
Also removed htmlspecialcharacters() where not required sbeaver
12:24 PM Revision b56b1321: Ran clean.sh.
Peter Bouwdewijn
11:48 AM Revision b0f52526: diag_logs_settings replace ugly help with staticText
sbeaver
11:17 AM Revision 4d79f95e: diag_logs_settings Removed bogus print_r
Also removed unneeded gettext sbeaver
10:57 AM Revision 88627531: dig_sockets updated as requested
Also fixed an incorrect </div> placement
I have retained the “$class = 'info’;” for now as I believe it
significantly...
sbeaver
10:56 AM Revision 6393afea: Merge pull request #87 from sbeaver-netgate/diag_tables
Converted diag_tables.php SjonHortensius
08:56 AM Revision 2445bf60: Merge pull request #138 from sbeaver-netgate/system
Bugfix: properly store timezone + don't close <a> twice SjonHortensius
08:47 AM Revision 5ff28acd: Merge pull request #109 from sbeaver-netgate/diag_logs
Converted diag_logs.php SjonHortensius
08:42 AM Revision 5bd40669: Merge pull request #100 from sbeaver-netgate/halt
Updated halt.php for consistency with reboot.php SjonHortensius
08:17 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
one easy way this could be done is, add the extra box but store the values of both in the same field in the xml but j... Bipin Chandra
07:50 AM Feature #809: Config sync username change
Problem still exist Version 2.2.2 Manfred Bongard
03:38 AM Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot
ALso had the sam issue with 2.1.5 to 2.2.2 with a Vmware cluster of 2 machines in CARP. I saw it hung on reboot in th... Peter Allebone

04/24/2015

11:15 PM Bug #4650 (Resolved): some crash reports containing symlinks fail to submit
fixed Chris Buechler
09:05 PM Bug #4081: Apinger reporting incorrect latency
I never saw this happen on several 2.1.5 installs but it happened on every (3) 2.2.0 install I tried.
I'll have a ...
Stuart Wyatt
08:56 PM Bug #4081: Apinger reporting incorrect latency
I must add that this always happened, with 2.1.4, 2.1.5, 2.2.0, 2.2.1 and 2.2.2. In a XEN or VMWare environment. Heiler Bemerguy
08:54 PM Bug #4081: Apinger reporting incorrect latency
I have this bug here. It screws up our Multi-WAN setup. Ideally we should use losses/highping to switch gateways, but... Heiler Bemerguy
07:56 PM Revision 306b9d00: Remove the DHCP static lease overlap cleanup and associated function and kill, as it can cause problems with failover scenarios.
Jim Pingle
07:56 PM Revision d9e5a931: Remove the DHCP static lease overlap cleanup and associated function and kill, as it can cause problems with failover scenarios.
Jim Pingle
03:44 PM Revision 58f592e6: status_gateway_groups conversion complete
This page had three nested tables. It now has two, but this seems to be
the best way to display the information. Sugg...
sbeaver
03:33 PM Revision 7bc36682: Provide a description for the dirty hack to not come back scratching.... on it
Ermal Luçi
03:33 PM Revision 6d7e7c0c: Provide a description for the dirty hack to not come back scratching.... on it
Ermal Luçi
03:30 PM Revision 7d5add01: Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet
Ermal Luçi
03:30 PM Revision 54dd568a: Use a dirty hack to make IKEv1 with multiple phase2 to work correctly with one IKE SA for each subnet
Ermal Luçi
03:11 PM pfSense Packages Bug #4654 (Closed): mod_security 0.43 generates a syntax error when "ModSecurity protection" is enabled.
Running under 2.2.2-RELEASE (amd64) with the "Apache with mod_security-dev 0.42" package installed. When "ModSecurit... Michael Matrix
02:55 PM Revision 7370c469: Is better to send the signal to starter rather than to charon directly. Starter manager charon properly. This should fix a lot of issues with configuration reloading that before sometimes did not work especially when changing phase2 entries
Ermal Luçi
02:54 PM Revision 6ed34650: Is better to send the signal to starter rather than to charon directly. Starter manager charon properly. This should fix a lot of issues with configuration reloading that before sometimes did not work especially when changing phase2 entries
Ermal Luçi
02:39 PM Revision 64c3b4cd: system.php bugfix
$timezonelist was an indexed array, causing the page to save the index
in the config, not the value.
sbeaver
11:53 AM Bug #4653 (Resolved): mtree dies in post_upgrade_command during upgrade from 8.x and earlier
When running the mtree post-upgrade from 2.1x or earlier, mtree will run partially through but eventually die with a ... Chris Buechler
09:46 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
Maybe somebody can make a package for web interface on base gatekeeper? I am ready to sponsor this direction, I want ... Aleksei Aksenov
09:37 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
I very much hope that this problem will be solved in version 2.2.3.
Aleksei Aksenov
09:33 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
pkg_add -r ftp://ftp-archive.freebsd.org/pub/FreeBSD-Archive/ports/i386/packages-8.3-release/Latest/gatekeeper.tbz
A...
Aleksei Aksenov
07:34 AM Revision b9bd6273: Merge pull request #136 from Bouwdie/services_wol
Converted services_wol SjonHortensius
04:44 AM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Accidentally I posted the code from my dev PfSense, here is the working code:... Markus Tellian
04:21 AM Bug #4652: Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
If you log in to captive portal and a Idle-Timeout is set (in my setup from radius)
the function captiveportal_get_l...
Markus Tellian
04:01 AM Bug #4652 (Resolved): Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
Markus Tellian

04/23/2015

06:17 PM Revision edda5d0b: This was meant to remove duplicates here, even though charon will do by itself but better do it since it was meant to.
Ermal Luçi
06:16 PM Revision 2334aff9: This was meant to remove duplicates here, even though charon will do by itself but better do it since it was meant to.
Ermal Luçi
03:24 PM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
I too have ran into this. Very irritating. :)
Bill Crowder
03:22 PM Revision 42328d90: Removed double newlines.
Removed onclick event. Peter Peter
02:56 PM Revision 49878b9e: Add static mapping interface not set when IP in a pool
If the DHCP IP address is in a pool (not in the main DHCP range for the interface) then the interface that correspond... Phil Davis
02:55 PM Revision 45b99bb6: Remove unneeded gettext in setHelp() call
sbeaver
02:37 PM Revision 3a652703: Removed unneeded table elements and HTML input elements
Ready for review sbeaver
02:25 PM Revision 48ac0aa0: Do not process dhcpd implementation if input errors
If I go to Service->DHCP Server, make some edits that are invalid (e.g. change range start or end to some invalid str... Phil Davis
12:27 PM Revision a6ff5ea1: Removed unneeded class and fixed tabs/spaces
sbeaver
11:58 AM Revision c9be8d9f: #126
Link_interface_to_bridge check also applied to wol_edit.
Inverted link_interface_to_bridge check to be more clear.
Peter Peter
10:00 AM Bug #4649: Add static mapping for this mac address button links to wrong page
So I don't know what your bug is - that is really weird if the link has "if=" with no interface, but then the interfa... Phillip Davis
09:40 AM Bug #4649: Add static mapping for this mac address button links to wrong page
Yes, they are all fine. If I hover over the plus button for more than a few MSEC, the URL fills out completely and t... David Gessel
08:29 AM Bug #4649: Add static mapping for this mac address button links to wrong page
Have you defined DHCP pools?
Do the effected entries have DHCP addresses issued from the pool(s)?
I can see that th...
Phillip Davis
06:59 AM Bug #4649: Add static mapping for this mac address button links to wrong page
A little testing - I can get it to happen pretty reliably in both Chrome and Firefox. What I noticed was that the de... David Gessel
08:05 AM Revision 2c20e3e9: Re-enstate copyright that got lost in pull request
Refs. #99 Sander van Leeuwen
07:37 AM Bug #4651 (Resolved): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
If the policy route negation rules are active, the automatic negation rule receives the same tracker ID as the rule i... Jim Pingle
04:56 AM Bug #4639: NAT fails to correctly translate udp port numbers embedded in certain ICMP error packets
I found the pf-rule that causes the problem:
pass out route-to ( pppoe0 2.2.2.2 ) from 1.1.1.1 to !1.1.1.1/32 tra...
Daniel Haid
04:03 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
I installed this package openh323-1.19.0.1_8 . PFsense 2.1.5 i386.
pkg_add -r ftp://ftp-archive.freebsd.org/pub/Fre...
Aleksei Aksenov
03:24 AM Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot
i had the exact same issue when i upgraded one box from 2.1.5 to 2.2.2, it didnt reboot, ssh was lost, only web gui w... Bipin Chandra
01:56 AM Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot
Braden McGrath wrote:
> This also happens on 2.1.5, and just occurred for me on a 2.1.5 -> 2.2.2 upgrade (x64/AMD64)...
Braden McGrath
01:44 AM Bug #3749: Upgrade from 2.1.4 to 2.2 does not automatically reboot
This also happens on 2.1.5, and just occurred for me on a 2.1.5 -> 2.2.2 upgrade (x64/AMD64).
I have remote web ac...
Braden McGrath

04/22/2015

10:16 PM Bug #4649 (Not a Bug): Add static mapping for this mac address button links to wrong page
services_dhcp.php doesn't exist in that file at all. Don't see how that would be possible.
Definitely report back...
Chris Buechler
09:08 PM Bug #4649: Add static mapping for this mac address button links to wrong page
well that is very weird. I opened chrome and tested, it worked correctly. I switched to a firefox tab, selected DHC... David Gessel
08:14 PM Bug #4649: Add static mapping for this mac address button links to wrong page
It works fine on my 2.2.2 systems. I have attached a screen shot of Status->DHCP Leases while hovering over the butto... Phillip Davis
01:59 PM Bug #4649 (Not a Bug): Add static mapping for this mac address button links to wrong page
The add static mapping for this mac address button used to take one to the static mapping entry page at /services_dhc... David Gessel
10:08 PM Revision 0c9eb13b: #126
Added required classes to table. Peter Bouwdewijn
10:03 PM Revision f0b20c3f: #126
Wrapped table in table responsive div. Peter Bouwdewijn
09:50 PM Revision ba8749ed: #126
Removed gettext calls when creation form parts; this is done by the form class
Removed obsolete submit button on edit...
Peter Bouwdewijn
09:15 PM Revision ea96b189: - Fix broken source address input & replace one-time method with array_merge
- Removed redundant htmlspecialchar and gettext methods; the form class itself takes care of this
- Slightly modified...
Sander van Leeuwen
08:52 PM Revision 7aac3413: Merge pull request #99 from sbeaver-netgate/diag_testport
Diag testport Sander van Leeuwen
08:15 PM Revision d6f74188: Trying to submit a symlink as part of crash reports will cause a failed
submission. Remove symlinks first. Also properly set user agent while
here, consistent with others. Fix some style an...
Chris Buechler
08:14 PM Revision bc28e0e4: Trying to submit a symlink as part of crash reports will cause a failed
submission. Remove symlinks first. Also properly set user agent while
here, consistent with others. Fix some style an...
Chris Buechler
08:11 PM Revision 8c10899b: Replace +- with explanatory buttons
Refs. #45 Sander van Leeuwen
07:19 PM Revision 50715ba1: diag_logs_settings.php conversion complete
sbeaver
03:13 PM Bug #4650 (Feedback): some crash reports containing symlinks fail to submit
Chris Buechler
03:11 PM Bug #4650 (Resolved): some crash reports containing symlinks fail to submit
Some crash reports that have symlinks in /var/crash will fail to submit. Fix coming momentarily Chris Buechler
12:53 PM pfSense Packages Bug #4491 (Resolved): Incorrect module location in start up script for Open-VM-Tools
fixed (by removing the modules entirely for now at least, they mostly aren't necessary, and cause stability issues) Chris Buechler
12:18 PM pfSense Packages Bug #4160 (Resolved): First shutdown attempt of guest fails with open-vm-tools
fixed Chris Buechler
12:17 PM pfSense Packages Bug #4638 (Resolved): not able to install or update open-vmware-tools package
fixed Chris Buechler
11:54 AM Revision 301eb34f: Tidy up "status_upnp.php" XHTML
Remove double line from table Colin Fleming
11:51 AM Revision 57e15e41: Tidy up "services_unbound.php" XHTML
Add missing closing TD tag Colin Fleming
10:12 AM Todo #1940: Integrate rSyslogd
I need to send my syslog through internet and for security reason I need TLS/SSL to do that.
Please switch syslogd t...
Florian Cristina
09:50 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
The main problem isn't if the domain is 2 or 3 part. It's that hard coding the number of parts breaks it for anythin... Trel S
09:40 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
well then the current logic uses 3 parts when on domain.co.uk whereas namecheap has other domains with 3 parts like x... Bipin Chandra
09:29 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
>There are cases when the domain has more than two parts, specifically the case in the test with .uk, so the domain i... Trel S
09:19 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
Trel S wrote:
> "parta.partb" is a valid A record. Using the logic you said, there would be no possibility of updat...
Jim Pingle
09:07 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
The safest solution would be the two input boxes to allow the user to define how much is the host name, and how much ... Trel S
09:04 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
But that would then break in scenarios such as
parta.partb.domain.tld
"parta.partb" is a valid A record. Using...
Trel S
09:04 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
Modifying that test would break other domains that function correctly now. That may be an "easy fix" for this specifi... Jim Pingle
09:01 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
easy fix would be to edit the /etc/inc/dyndns.class file on line 537
replace
$domain_part_count = ($dparts[count(...
Bipin Chandra
08:52 AM Feature #4366: Namecheap Dynamic DNS updates fail on subdomain formatted domains
rather than having to modify gui and the xml values separately, its better to modify the logic such that u consider o... Bipin Chandra
09:20 AM pfSense Packages Bug #4277: squidGuard-squid3 installation Failed after pfSense Update to 2.2
squid3 fails to install on a fresh 2.2 install too, here is the error:
Beginning package installation for squid3 ....
Ricardo Klein
07:39 AM Bug #4648 (Resolved): ifconfig syncpeer fails with IPv6 address
When running CARP in an IPv6 only environment I get this error during bootup:
Apr 22 14:11:32 fw002-ac php: rc.boo...
Pim Pish
02:40 AM Bug #4592: FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
I just wanted to bump this bug report: I tested with 2.2.2, and it still dumps core (as Chris mentioned above).
I'...
Christopher Taylor
02:02 AM pfSense Packages Bug #4561: siproxd listening port redirect rule pulling wrong tag from <siproxdsettings> (config.xml)
Good day! Tell me, is it possible to expand the functions of the package ,siproxd, so that he could translate the pro... Aleksei Aksenov

04/21/2015

11:01 PM Bug #3022: OpenVPN does not failover to the 2nd configured LDAP auth.server
two years has passed.. any chances to have that fixed in near future? Alex Kolesnik
10:00 PM Revision bc3fa9f1: #126
Ran clear.sh.
Replaced forms with Form builder.
Introduced an extra panel for the WOL devices.
Peter Bouwdewijn
06:06 PM Revision 201c0361: Added btn-sm class to buttons.
sbeaver
05:59 PM Feature #4647 (Resolved): Services: DHCP server should default to LAN, not WAN
When you click on Services-DHCP Server the first tab to open is the WAN tab, where you're very unlikely to be serving... David Gessel
05:54 PM Revision 33d52df1: daig_logs.php conversion complete
This conversion relies on a change to guiconfig.inc.
A new function was added: dump_clog_no_table() which performs t...
sbeaver
05:43 PM Revision 26b94b87: Merge manually pull request #1626 to this branch
Ermal Luçi
05:42 PM Revision 1f5ac937: Merge pull request #1626 from gogglespisano/apinger
Ermal Luçi
05:40 PM Revision e1bcb659: s/;/:/
Ermal Luçi
05:39 PM Revision 7b9d7eac: Revert "Revert "Move to specifically specifying the ID type apart when an ip address to have strongswan do proper behaviour. Also for DynDNS names use the dns type id so strongswan does the resolving by its own.""
This reverts commit 4e8eacfd7c0f1909c15d85b4cae2302b0ba3f0fc.
Conflicts:
etc/inc/ipsec.inc
Ermal Luçi
01:09 PM pfSense Packages Feature #4581: Add dshield-sensor port to pfPorts
Is there something more I need to do to get this processed? Robert Nelson
12:20 PM Bug #4639: NAT fails to correctly translate udp port numbers embedded in certain ICMP error packets
I have now tried to reproduce this on a pure FreeBSD 10.1 installation, but everything seems to be working correctly ... Daniel Haid
11:15 AM Revision 2e101d89: Toggle classes should be attached to group, not input (so that help toggles with group)
Refs. #18 Sander van Leeuwen
09:35 AM Revision 748cbea6: Update display_top_tabs to use pills as default
Refs. #107 Sander van Leeuwen
06:53 AM Revision fe65bb3a: Fall back to getting local user pages and groups
if the groups could not be found from LDAP and there is a local user. Phil Davis

04/20/2015

11:25 PM pfSense Packages Bug #4160: First shutdown attempt of guest fails with open-vm-tools
there was still some work in progress there. The _12 version is available now. Chris Buechler
06:53 PM pfSense Packages Bug #4160: First shutdown attempt of guest fails with open-vm-tools
I note that you recently made some changes. Were these released in the _11 release of VMWare_Tools. However, after ... Greg Siemon
10:43 PM pfSense Packages Bug #4567: ntopNG Geo files missing
Still receiving the following GeoIP related errors...
On startup:
ntopng: [Geolocation.cpp:59] WARNING: Unable to...
Denny Page
09:51 PM Bug #4645 (Duplicate): Very,very, slow boot and halt (not first time) - nanobsd
duplicate of #4617
The nano images weren't updated as they're generally not affected (most enable the serial cons...
Chris Buechler
04:17 PM Bug #4645: Very,very, slow boot and halt (not first time) - nanobsd
Disable the serial port. Kill Bill
03:48 PM Bug #4645 (Duplicate): Very,very, slow boot and halt (not first time) - nanobsd
I'm trying pfsense 2.2.2 in this hardware:
http://linitx.com/product/fabiatech-fx5625-intel-atom-18ghz-8-nic-firew...
JAume Ponsa
09:26 PM Revision 3be781e7: Add new bios product id string
Jeremy Porter
08:37 PM Revision be2191af: Add new bios product id string
Jeremy Porter
07:46 PM Feature #4646 (New): Recover valuable vertical screen real estate in dashboard
Vertical screen real estate tends to be quite valuable.
The dashboard page uses about 1/2" at the top of the page ...
B. Derman
07:04 PM Revision 9cf1dbff: Remove duplicate 'ppp' case in switch statement
Stuart Wyatt
06:54 PM Revision a75d1a5f: Allow to configure new modes for phase1 according to RFC 5903 by manually merging pull request #1501 partially. While here preserve style.
Ermal Luçi
06:53 PM Revision 7a747654: Allow to configure new modes for phase1 according to RFC 5903 by manually merging pull request #1501 partially. While here preserve style.
Ermal Luçi
06:40 PM Revision 868a62be: Fix #4640 IPsec Auto-exclude LAN address toggles every time save is pressed.
Actually the GUI is displaying the opposite setting to what is in the config. When the user pressed save that opposit... Ermal Luçi
06:38 PM Revision 162d7d23: Merge pull request #1624 from phil-davis/patch-1
Ermal Luçi
06:37 PM Revision 905e1156: Fixes #4625, manual merge of pull request #1617 for RELENG_2_2 branch on fixing voucher disconnection.
Ermal Luçi
06:34 PM Revision 0fa9acb7: Merge pull request #1617 from Gertjanpfsense/master
Ermal Luçi
05:47 PM Revision ad9e2a90: dig_tables.php revised to use Form.classe
Would you please review these changes and let me have your comments.
I will remove the “echo” statements once I have...
sbeaver
04:04 PM Revision 41b1ff89: More www code style oddments
Phil Davis
04:01 PM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Errr... let me repeat this once again: this does the exact opposite of what's described in the GUI! When you enable t... Kill Bill
01:40 PM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Applied in changeset commit:868a62be4c27860aef9f3fd939beee5a6f26090a. Ermal Luçi
01:40 PM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Applied in changeset commit:75d072be3a10949ead88a82ecec51ae0e5490fbe. Phillip Davis
01:38 PM Bug #4640 (Feedback): "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Merged pull request. Ermal Luçi
01:40 AM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Indeed confirmed. The GUI description is totally inverted to the actual behaviour. Stuff like noshuntlaninterfaces, n... Kill Bill
01:29 AM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
I am totally confused. So I applied this, checked the checkbox and the bypasslan connection got deleted.... Kill Bill
02:11 PM Feature #4644 (Resolved): Dyndns Loopia Wildcard
Add wildcard support for Loopia dynamic dns.
My changes in /etc/inc/dyndns.class
case 'loopia':
$needsIP = TRU...
Andreas Tunberg
01:40 PM Bug #4625: Expiring a voucher doesn't disconnect a user who is using that voucher
Applied in changeset commit:905e1156680129b3c49fe380b4e821f9eb02362a. Ermal Luçi
01:35 PM Bug #4625: Expiring a voucher doesn't disconnect a user who is using that voucher
Pull request merged. Ermal Luçi
11:19 AM Bug #4571: scheduled firewall reboot crashes
i have ordered another serial adapter so once i get that ill test that and report as well as i have few other alix bo... Bipin Chandra
10:59 AM Bug #4571 (Not a Bug): scheduled firewall reboot crashes
this is something specific to probably your serial console setup, maybe in combination with something to do with the ... Chris Buechler
05:29 AM pfSense Packages Feature #4643 (Needs Patch): munin-node package?
Hi again!
I extensively use munin-node to centrally monitor a bunch of pfsense devices, overall it runs fantastic!...
Alejandro Olivan
05:17 AM Bug #4642 (Resolved): OpenVPN process status stopped... but its running
Hi again...
This is something i suffer consistently on my nanobsd installs since... don't remember, maybe from the...
Alejandro Olivan
04:15 AM Revision 75d072be: Fix #4640 IPsec Auto-exclude LAN address toggles
every time save is pressed.
Actually the GUI is displaying the opposite setting to what is in the config. When the us...
Phil Davis
02:49 AM Bug #4641 (Duplicate): Restored config loses IPv6 Link-Local DNS Forwarder Settings
Restoring a config that contains selected "Services -> DNS Forwarder -> Interfaces" which are "IPv6 Link-Local" doesn... B. Derman

04/19/2015

11:16 PM Bug #4640: "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
Actually the "Auto-exclude LAN address" setting is being displayed opposite to what is in the config. Every time you ... Phillip Davis
08:30 PM Bug #4640 (Resolved): "Disable Cisco Extensions" change toggles "Auto-exclude LAN address" setting
After updating from 2.2.1 to 2.2.2, in VPN -> IPsec -> Advanced Settings, the check-box setting for "Disable Cisco Ex... B. Derman
06:26 PM Revision 6e69ebef: Merge branch 'bootstrap' into halt
Conflicts:
usr/local/www/halt.php
sbeaver
06:22 PM Revision 40d263e7: Merge branch 'bootstrap' of https://github.com/SjonHortensius/pfsense into bootstrap
Sander van Leeuwen
06:22 PM Revision 94596324: Add title to separate form and table
Refs. #22 Sander van Leeuwen
03:18 PM Revision b21e49ed: fix last line
refs #95 Sjon Hortensius
03:17 PM Revision efcc4fd4: Merge pull request #95 from sbeaver-netgate/reboot
Converted reboot.php SjonHortensius
03:16 PM Revision 6073137f: Updated for consistency with reboot.php
Updated for consistency with reboot.php sbeaver
03:09 PM Revision c9f0fd77: Fixed bad copy/paste :(
sbeaver
02:44 PM Revision a2a10102: appended some missing fixes in system_camanager.php
Sjon Hortensius
02:41 PM Revision 5d2edeca: Converted system_camanager
Sjon Hortensius
02:36 PM Revision 50ea0588: bindCollapseToOptions - support multiple options targeting single section
fix #96 Sjon Hortensius
02:24 PM Revision 6ea2ea99: Supdated per SH
Good suggestions. Thank you. sbeaver
01:32 PM Revision 17219182: Remove alternative version
sbeaver
01:27 PM Revision 0ba2494e: IpAddress - set correct validationpattern, toggle mask based on family
Sjon Hortensius
12:59 PM Revision 709754ab: Skip inline gw creation; it should be a Modal that inlines /gw_edit
Sjon Hortensius
12:56 PM Revision 3c128b8c: IpAddress - move from max mask=32 to 128, removed method-default @ fw_edit
Sjon Hortensius
12:55 PM Revision f3bb71cf: Converted system_routes*, pending implementation of direct gw addition
Sjon Hortensius
12:15 PM Revision 5f601060: Code style usr-local-www diag
Phil Davis
11:21 AM Revision 0b456cf7: pfSense.js - add confirm to .btn-danger elements; removed onclicks
Sjon Hortensius
10:47 AM Revision 67c3b90b: Merge branch 'bootstrap' of ssh://github.com/SjonHortensius/pfsense into bootstrap
Sjon Hortensius
10:42 AM Revision 249fc764: use foot.inc instead of custom footer on login screen
Sjon Hortensius
06:39 AM Revision 962f215d: Code style xmlrpc
Phil Davis
06:38 AM Revision 45b4ffc6: Code style usr-local-www back-end
files that do stuff in mostly in the background. Phil Davis
06:15 AM Bug #4571: scheduled firewall reboot crashes
well u use a usb to serial adapter or the above setup, the result is the same, not to mention not many new PC have a ... Bipin Chandra
04:16 AM Bug #4571: scheduled firewall reboot crashes
Bipin Chandra wrote:
> actually i use like this as my PC doesnt have a serial port
> USB to TTL adapter -> TTL to R...
Kill Bill
04:03 AM Bug #4571: scheduled firewall reboot crashes
plus during pfsense boot it gives option to enter slice to boot from, that time using tera term not able to type 1 or... Bipin Chandra
03:59 AM Bug #4571: scheduled firewall reboot crashes
actually i use like this as my PC doesnt have a serial port
USB to TTL adapter -> TTL to RS232 (serial) adapter ->...
Bipin Chandra
02:12 AM Bug #4571: scheduled firewall reboot crashes
Huh? Powered? Never seen a externally powered null modem cable. Kill Bill
01:37 AM Bug #4571: scheduled firewall reboot crashes
i mean the serial cable needs to be removed then if i unplug power and replug or the schedule runs then it reboots fine Bipin Chandra
12:50 AM Bug #4571: scheduled firewall reboot crashes
still having issues in reboot, when serial console is attached and conencted then it reboots fine, when serial consol... Bipin Chandra
 

Also available in: Atom