Project

General

Profile

Activity

From 05/08/2015 to 06/06/2015

06/06/2015

10:36 AM Bug #4738: Setup Wizard can result in invalid LAN DHCP pool calculation
Committed by https://github.com/pfsense/pfsense/commit/3a19fd4a84d358ff8e6c9eedcad5b11f7f570fa8
and also to 2.2 bran...
Phillip Davis
10:21 AM Bug #4712: Wizard hostname validation rejects upper case letters
Fix committed https://github.com/pfsense/pfsense/commit/16628aa0631bbdceae27f3d2f7ba1fa44ce3b296 Phillip Davis

06/05/2015

08:39 PM Revision 6f62e89f: Clean up, organize, and expand the info presented by status.php. Save the output to individual text files and compress them into a .tgz for later download.
Conflicts:
usr/local/www/status.php
Jim Pingle
08:33 PM Revision 0e7653f4: Clean up, organize, and expand the info presented by status.php. Save the output to individual text files and compress them into a .tgz for later download.
Jim Pingle
03:56 PM Revision eda14265: Fix CARP plugin call for packages, interface was coming through as NULL during CARP events.
Jim Pingle
03:56 PM Revision 49a4a402: Add INIT event for CARP as an alternate for 'backup', otherwise scripts would not take down services during a MASTER->INIT transition.
Jim Pingle
03:55 PM Revision a0be396e: Fix CARP plugin call for packages, interface was coming through as NULL during CARP events.
Jim Pingle
03:55 PM Revision b4aac247: Add INIT event for CARP as an alternate for 'backup', otherwise scripts would not take down services during a MASTER->INIT transition.
Jim Pingle
02:09 PM Bug #4747 (Resolved): DNS Resolver - Insufficient sanity checking for DNS Query Forwarding
When you don't specify any DNS servers, you can still tick the "DNS Query Forwarding" and save the configuration, res... Kill Bill
12:22 PM Revision fd192dbc: Also sanitize OpenVPN static/tls keys in status.php
Jim Pingle
12:22 PM Revision 1557716b: Also sanitize OpenVPN static/tls keys in status.php
Jim Pingle
10:40 AM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
I have experienced a lot of crashes (hard crash that triggers the box to reboot) on 2 different RCC-VE 2440 units (ig... → luckman212
09:32 AM Bug #3973: Route 53 dynamic DNS provider fails to update record
Here is the patch I am using with the System Patches package to work around this issue in 2.1:... Jim Riggs
02:43 AM Bug #4653: mtree dies in post_upgrade_command during upgrade from 8.x and earlier
i attempted 2.1.4 to 2.2.2 48hours ago it ran into this error many times, never rebooted on its own
Jun 3 02:34:3...
James Starowitz
01:46 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Can we please revert the broken commit and fix the description until this is recoded properly? Kill Bill

06/04/2015

09:33 PM Bug #4665 (Resolved): strongswan duplicates reqid at times, causing failures with multi-P2
fixed Chris Buechler
09:23 PM Bug #4739 (Resolved): growl notifications cause excessive delays when configured with non-resolvable hostname
fixed Chris Buechler
08:42 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
this looks to work fine. Will leave for additional feedback.
If anyone else can help test, please try the latest ...
Chris Buechler
08:33 PM Revision db794357: Update "status_interfaces.php"
Move the "break" and the "endforeach" statements so that the DL and DIV tags are closed properly for every interface Colin Fleming
08:16 PM Bug #4746 (Resolved): captive portal allowed hostnames not loaded into table at boot time
Configure CP with one or more passthrough hostnames, and filterdns runs correctly and logs that it's adding entries: ... Chris Buechler
08:08 PM Revision dc6695c3: Setup Wizard can result in invalid LAN DHCP pool calculation
1) consider where the LAN IP is in the subnet range and then put the
DHCP pool in the biggest remaining segment, eith...
Phil Davis
08:07 PM Revision 3a19fd4a: Merge pull request #1706 from phil-davis/setupwizardlan
Renato Botelho
08:06 PM Revision b3bba7fe: Improve setup wizard host name check
Redmine #4712
It seems good enough to make the regex strings here be "reasonable". The full checks are done after pre...
Phil Davis
08:06 PM Revision 16628aa0: Merge pull request #1707 from phil-davis/patch-1
Renato Botelho
06:48 PM Revision 1b245100: Merge pull request #310 from ExolonDX/patch-3
Tidy up HTML5 "label" in login page SjonHortensius
06:47 PM Revision 93c1b984: Merge pull request #311 from ExolonDX/bootstrap
Update "interfaces_qinq.php" SjonHortensius
03:05 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
FreeBSD PR is https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200323 Chris Buechler
03:04 PM Revision de4a1c84: Update "interfaces_qinq.php"
Remove "colon" character at beginning of the file Colin Fleming
02:49 PM Revision 17ef09c3: Tidy up HTML5 "label" in login page
The "for" attribute of the "label" element must refer to a form control.
http://www.w3.org/TR/html-markup/label.html...
Colin Fleming
02:25 PM Revision 4701e802: Merge pull request #308 from ExolonDX/bootstrap
Remove duplicate closing bracket SjonHortensius
02:23 PM Revision 7ac86a5f: Remove duplicate closing bracket
Remove duplicate closing bracket Colin Fleming
02:17 PM Revision d719fdd1: Merge pull request #307 from ExolonDX/patch-1
Remove duplicate closing bracket SjonHortensius
02:16 PM Revision bf980226: Remove duplicate closing bracket
Remove duplicate closing bracket Colin Fleming
07:48 AM Bug #4653: mtree dies in post_upgrade_command during upgrade from 8.x and earlier
I was testing a 2.1.5 to 2.2.3 upgrade for something else and noticed that mtree ran OK (see the attached upgrade log... Jim Pingle
02:05 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Well, I tested the pfBNG case (i.e., restore the config with tons of URL aliases on a new box). Down to under 2 minut... Kill Bill

06/03/2015

06:10 PM Bug #4703: Inconsistent availability of direction on CP IP/MAC/hostname passthrough
there is a related issue in that icon_pass.gif is shown for direction "both", so configs from older versions where th... Chris Buechler
05:15 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Kill Bill: mind sharing any specifics on what you've seen? How long did it take to boot before, and how long does it ... Chris Buechler
01:58 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
*Much* better now... ;) Kill Bill
01:05 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
A big portion of the issue with URL table aliases is file_download can be attempted many times during filter reload w... Chris Buechler
03:08 PM Bug #4745 (Not a Bug): Reassignment of devices after config restore
After a configuration restore on new hardware with new physical interface names whiach doesn't mtch the old ones the ... mete *
02:30 PM Bug #4742: nfe0 NIC shows no carrier after interface configuration
There are multiple Ion 330 BIOS updates mentioning "improve LAN compatibility" on the ASUS website. Perhaps start th... Kill Bill
11:43 AM Bug #4742: nfe0 NIC shows no carrier after interface configuration
Is there a way to tell what is being done to the interface when it is being configured? I can install and replicate ... Adrien Carlyle
11:40 AM Bug #4742 (Needs Patch): nfe0 NIC shows no carrier after interface configuration
looks to be a driver issue of some sort that needs to be replicated on stock FreeBSD and reported upstream. Chris Buechler
09:01 AM Bug #4742: nfe0 NIC shows no carrier after interface configuration
I was able to get the device working properly by manually restoring my alix config.xml to the device. On bootup I w... Adrien Carlyle
08:56 AM Bug #4742 (Needs Patch): nfe0 NIC shows no carrier after interface configuration
I am able to use the 2.2.2 memstick image to boot up an asrock ion330 based computer. I am able to install pfsense ... Adrien Carlyle
11:42 AM Todo #4744 (Resolved): Replace pecl-APC by opcache
Pecl APC is deprecated and should be replaced by php55-opcache Renato Botelho
11:39 AM Bug #4741 (Feedback): IPSEC mobile client problem
this is probably the Android racoon bug with NAT-D. what does the client log show? Chris Buechler
08:35 AM Bug #4741 (Not a Bug): IPSEC mobile client problem
Problem with mobile client connection.
I seted up IPSEC vpn with this instruction (https://doc.pfsense.org/index.ph...
ruben rpuserh
09:43 AM Bug #4743 (Rejected): unexpected end of file in /etc/inc/captiveportal.inc on line 248
Please post on the forum for assistance. Most of the time this error is from a dangerous function in the squid 3 pack... Jim Pingle
09:41 AM Bug #4743 (Rejected): unexpected end of file in /etc/inc/captiveportal.inc on line 248
Hi, I'm new to BSD family
I recently replaced my network utm to pfsese
but a message containing the bug below is sh...
Mehrdad Vesal
06:44 AM Bug #4740 (New): Intel wireless kernel panic in infrastructure mode with WPA
I've got permanent kernel panic and reboot with intel wireless 4965 minipcie card in WAN infrastructure mode when wpa... Vladimir Chernyshov
06:05 AM Revision a320af18: A number of things block waiting for file download timeouts, sometimes multiple times across multiple files (many URL Table aliases, for instance). The long timeout causes very long boot times (10-20+ minutes) on many configs with pfblocker if booted disconnected from the Internet. This is strictly the timeout for the HTTP/HTTPS connection attempt. Once connected, it can run past that. 5 seconds should be more than enough for any properly-functioning network. Part of Ticket #4442.
Conflicts:
etc/inc/pfsense-utils.inc
Chris Buechler
05:57 AM Revision eefd7773: A number of things block waiting for file download timeouts, sometimes multiple times across multiple files (many URL Table aliases, for instance). The long timeout causes very long boot times (10-20+ minutes) on many configs with pfblocker if booted disconnected from the Internet. This is strictly the timeout for the HTTP/HTTPS connection attempt. Once connected, it can run past that. 5 seconds should be more than enough for any properly-functioning network. Part of Ticket #4442.
Chris Buechler
04:43 AM Bug #4377: pfSense boot freezes after restart in QEMU/KVM
I have the same pb. FreeBSD guests fail to reboot properly if they have more than one CPU (socket, core, and/or threa... Yann Autissier
04:37 AM Revision 9f390fb8: device_type isn't used here
Chris Buechler
04:36 AM Revision 7112bcc8: device_type isn't used here
Chris Buechler
12:33 AM Revision b532745a: Don't call growl if the configured address isn't an IP or resolvable
hostname. Avoids 1 minute timeout delay in fsockopen in growl.class. Cuts
that down to about a 20 second timeout. Tic...
Chris Buechler
12:30 AM Revision dbd919ec: Don't call growl if the configured address isn't an IP or resolvable
hostname. Avoids 1 minute timeout delay in fsockopen in growl.class. Cuts
that down to about a 20 second timeout. Tic...
Chris Buechler

06/02/2015

11:36 PM Bug #4370 (Resolved): ntpd does nothing with selected carp interfaces.
fixed Chris Buechler
01:03 AM Bug #4370: ntpd does nothing with selected carp interfaces.
should be fixed by what I just pushed, leaving for further verification Chris Buechler
07:31 PM Bug #4739 (Feedback): growl notifications cause excessive delays when configured with non-resolvable hostname
pushed a change that takes the delay down from 1 minute to about 20 seconds, which is probably about the best we can ... Chris Buechler
07:28 PM Bug #4739 (Resolved): growl notifications cause excessive delays when configured with non-resolvable hostname
When growl notifications are configured to go to a hostname, and that hostname doesn't resolve, it causes a 1 minute ... Chris Buechler
04:56 PM Revision f135a010: trigger a reboot after restoration of full backup. Ticket #4107
Chris Buechler
04:53 PM Revision 813d71c1: trigger a reboot after restoration of full backup. Ticket #4107
Chris Buechler
04:39 PM Revision 239f204b: Improve setup wizard host name check
Redmine #4712
It seems good enough to make the regex strings here be "reasonable". The full checks are done after pre...
Phil Davis
01:12 PM Revision 8c288bce: Deprecate /usr/local/bin/3gstat
Renato Botelho
01:12 PM Revision 6aab8d87: Deprecate /usr/local/bin/3gstat
Renato Botelho
12:29 PM Bug #4113: multiple instances of /var/db/rrd/updaterrd.sh
I can't update this system: #4345.
That and other fixes have high prio for me to get #4345 fixed fast.
Grischa Zengel
11:53 AM Bug #4107 (Feedback): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
fixed, leaving to verify again once it's in a snapshot build. Chris Buechler
11:41 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Denny Page wrote:
> Wow, there's a name I haven't heard in 20+ years.
Yes, and cmb shouldn't have quoted a privat...
Jim Thompson
11:38 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Kill Bill wrote:
> Updated ZFS howto for people who are on full install and are simply tired of this... https://foru...
Jim Thompson
11:38 AM Bug #4712: Wizard hostname validation rejects upper case letters
Suggested good-enough fix https://github.com/pfsense/pfsense/pull/1707 Phillip Davis
11:33 AM Revision b7cf171b: Minor wizard text fixups
Phil Davis
11:33 AM Revision 379dc6f2: Supply current WAN gateway name to wizard
As the name of the WAN gateway is not always WANGW.
Should fix redmine #4713
Phil Davis
11:33 AM Revision 9f5e6dc5: Merge pull request #1705 from phil-davis/wizard-text
Renato Botelho
11:31 AM Revision 6faaecf9: Merge pull request #1704 from phil-davis/bug4713
Renato Botelho
10:52 AM Bug #4028: Wireless Obytes counter always 0
Merged even for 2.2.3 the patch. Ermal Luçi
09:33 AM Revision aa181833: Setup Wizard can result in invalid LAN DHCP pool calculation
1) consider where the LAN IP is in the subnet range and then put the
DHCP pool in the biggest remaining segment, eith...
Phil Davis
07:12 AM Bug #4515: Unable To Set MTU on LAGG Interface If No VLANs Assigned
I hit this issue this morning.
There seems to be no way to set the MTU of a LAGG interface without adding a VLAN, o...
Steve Wheeler
07:12 AM Bug #4642: OpenVPN process status stopped... but its running
Hi guys.
No... I do not have watchdog on any system... overall pfsense stabitlity as a router is superb.
BUt you'...
Alejandro Olivan
03:33 AM Bug #4642: OpenVPN process status stopped... but its running
This also happens to me on "random" systems. I have an example on an APU 64-bit nanoBSD 2.2.2 system now. This is the... Phillip Davis
03:25 AM Bug #4642: OpenVPN process status stopped... but its running
Install the Service Watchdog package to keep your ntpd running. Kill Bill
03:10 AM Bug #4642: OpenVPN process status stopped... but its running
OK... ntpd NTP clock sync is stopped.
NTP clock sync stops after hours or just few days up... this is something we...
Alejandro Olivan
03:00 AM Bug #4642: OpenVPN process status stopped... but its running
OK... I will track those routers behaviour, and report on them.
I updated here talking about openvpn just because it...
Alejandro Olivan
07:06 AM Bug #3815: Gateway monitoring broken
That might all be for naught - I saw over at "#4081":https://redmine.pfsense.org/issues/4081#note-14 that in 2.3 apin... → luckman212
04:33 AM Bug #3815: Gateway monitoring broken
Customer's still rather keen on 2.1, I can possible set up a similar setup soon and try if it still behaves similarly... Tobias Wolter
06:24 AM Revision 75eef6ca: Clarify DNS Forwarder and Resolver both apply in these places. partially Ticket #3730
Chris Buechler
06:22 AM Revision 796cc218: Clarify DNS Forwarder and Resolver both apply in these places. partially Ticket #3730
Chris Buechler
06:06 AM Revision c4b3bd50: Use CARP IPs that are configured. Ticket #4370
Chris Buechler
06:06 AM Revision 729f899f: Use CARP IPs that are configured. Ticket #4370
Chris Buechler
04:42 AM Bug #4738: Setup Wizard can result in invalid LAN DHCP pool calculation
Pull request https://github.com/pfsense/pfsense/pull/1706 Phillip Davis
03:52 AM Bug #4738 (Resolved): Setup Wizard can result in invalid LAN DHCP pool calculation
The DHCP pool automatic calculation on LAN done by the Setup Wizard always starts the pool at ".10" in relation to th... Phillip Davis
04:33 AM Revision 4f514c63: Minor wizard text fixups
Phil Davis
03:16 AM Feature #4260: Add ECP DH key groups support
This is the same a #4683 Ermal Luçi
03:14 AM Feature #4260 (Feedback): Add ECP DH key groups support
These are merged in as from pull request just the ticket was not mentioned in the commit log. Ermal Luçi
01:50 AM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
Grischa Zengel wrote:
> Will be there a real solution in next time or should I add an extra nic to these servers?
...
Chris Buechler
01:36 AM Revision 42a55691: Supply current WAN gateway name to wizard
As the name of the WAN gateway is not always WANGW.
Should fix redmine #4713
Phil Davis
01:23 AM Bug #3730 (Resolved): Router advertisement advertises gateway address as dns server even if the dns forwarder is disabled
this works as it should. If DNS Forwarder or Resolver are enabled, and the boxes are blank, the interface IP will be ... Chris Buechler
01:08 AM Bug #4210: Bring back a FTP proxy
the FTP Proxy package suffices for 2.2.x. Should consider whether to build it in by default for 2.3 or future versions. Chris Buechler
12:46 AM Bug #4678 (Resolved): DHCPv6 with static entries, Apply configuration button never goes away
works, thanks Chris Buechler

06/01/2015

11:58 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Wow, there's a name I haven't heard in 20+ years. Denny Page
10:59 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
sync definitely avoids the root issue. I have a system that's now upwards of 1000 power cycles with 0 issues with syn... Chris Buechler
12:06 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
It was apparently an error in my notes... I looked back at a forum post I made when I first tested that mid-April and... Jim Pingle
11:58 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Does sync actually avoid the issue? Update 4 suggested that this was not the case...
Sync for root fs generally se...
Denny Page
11:15 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Updated ZFS howto for people who are on full install and are simply tired of this... https://forum.pfsense.org/index.... Kill Bill
06:39 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
"sync" seems like "a good thing" on root file system "/" for pfSense use cases anyway. pfSense uses would not modify ... Phillip Davis
02:25 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
It's not fsck.
it's likely a bug in SU (with or without journaling.)
the fix (for now) is to mount / "sync" on all ...
Jim Thompson
11:51 PM Bug #4701 (Resolved): WebGUI alias name changes does not reflect in NAT-Outbound
works. Thanks! Chris Buechler
11:50 PM Revision b4576c90: really fix botched manual merge request. Ticket #4720
Chris Buechler
11:42 PM Bug #3872 (Resolved): Enabling a disabled VLAN subinterface with multiple CARP VIPs configured causes system crash
I created a config matching Stuart's description, and could easily replicate the panic after disabling and enabling a... Chris Buechler
11:09 PM Revision 78b0dd57: fix manual merge mistake. Ticket #4720
Chris Buechler
11:02 PM Bug #1884 (Confirmed): Lacking update validation on console upgrade
this needs the platform check same as manual update in web interface. Chris Buechler
10:50 PM Revision ba79655c: set the serial port appropriately for RCC-VE platforms. sync from factory
repo. Ticket #4720
Conflicts:
etc/inc/pfsense-utils.inc
Chris Buechler
10:45 PM Revision f877f77f: set the serial port appropriately for RCC-VE platforms. sync from factory
repo. Ticket #4720 Chris Buechler
10:40 PM Bug #4081 (Needs Patch): Apinger reporting incorrect latency
apinger is being replaced in 2.3, which will resolve outstanding issues here. Chris Buechler
10:38 PM Bug #4235 (Resolved): missing 'reply-to' in rules for mobile-ipsec
works. having route-to and reply-to the way it is now is fine. Chris Buechler
10:37 PM Revision 89953fe7: Return IP correctly in get_interface_ip for gateway groups specifying a
VIP. Ticket #4661 Chris Buechler
10:36 PM Revision e6807c5a: Return IP correctly in get_interface_ip for gateway groups specifying a
VIP. Ticket #4661 Chris Buechler
10:35 PM Feature #2770 (Rejected): add "device mptable" to amd64 builds to make pfsense boot on soekris6501
has potential to break other things, and we don't really care about Soekris hardware Chris Buechler
10:31 PM Bug #2675 (Resolved): /tmp/.rc.prunecaptiveportal.running can be present on boot
fixed Chris Buechler
10:29 PM Bug #3836 (Confirmed): field redirect target port must be quit in a specific way to keep conntent
Chris Buechler
10:24 PM Bug #3815 (Feedback): Gateway monitoring broken
It's definitely not as simple as gateway monitoring being broken, as it works fine in general. Might be some edge cas... Chris Buechler
10:16 PM Feature #2885 (Closed): loadbalancing should be more tweakable
haproxy is available for such needs Chris Buechler
10:16 PM Bug #3027 (Confirmed): input_errors2Ajax function
Chris Buechler
10:15 PM Bug #3116 (Confirmed): IPsec peer identifiers - ASN.1 does not take options
Chris Buechler
09:48 PM Bug #3205 (Resolved): Partial system freeze when disconnecting USB 3G stick
thanks for the feedback, Bipin. Chris Buechler
09:47 PM Bug #3307 (Closed): rc.update_bogons.sh doesn't filter out all private address space
this works as intended. Private networks is meant for RFC 1918, bogons has the remainder. Chris Buechler
09:45 PM Feature #2439 (Resolved): XEN Para-virtualized Drivers Support
this came along with the FreeBSD 10.1 base OS in 2.2.x versions Chris Buechler
09:44 PM Feature #2035 (Needs Patch): Add hw.intr_storm_threshold in sysctl tunning list.
users can always add it themselves if necessary. Chris Buechler
09:42 PM Feature #1859 (Resolved): default SSH-key should at least use 2048 bit RSA-keys
this has been the case for some time Chris Buechler
09:40 PM Feature #1858 (Resolved): default SSL-cert should at least use 2048 bit RSA-keys
this was done quite some time ago Chris Buechler
09:38 PM Feature #1450 (Closed): XMLRPC syncs all VPN types *except* PPTP
PPTP is dead. Chris Buechler
09:37 PM Feature #1258 (Needs Patch): dyndns - DNS Made Easy
if you could submit this as a pull request on github, we could get that added.
Chris Buechler
09:35 PM Feature #1170 (Resolved): Certificates tab should have revoke option in addition to delete
this was implemented years ago Chris Buechler
09:34 PM Bug #4113 (Feedback): multiple instances of /var/db/rrd/updaterrd.sh
is this replicable for you on 2.2.2? Chris Buechler
09:33 PM Feature #4264 (Closed): Make distinction between general & security updates, while applying the latter automatically
some of that falls into work Renato's doing for 2.3 and newer in improving the update system in general. The remainde... Chris Buechler
07:43 PM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
Will be there a real solution in next time or should I add an extra nic to these servers? Grischa Zengel
06:22 PM Bug #4241 (Needs Patch): Installer display glitch on "Install Bootblocks" screen
bsdinstaller is on borrowed time, won't fix this since it should be replaced in 2.3. Chris Buechler
06:18 PM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
Matt: haven't heard of it on ALIX but same could impact it also. does disabling the host resources MIB prevent the is... Chris Buechler
06:15 PM Feature #4732: Add MS-CHAPv2 option to L2TP Configuration
thanks, we'll review for 2.3. Chris Buechler
06:14 PM Bug #754 (Needs Patch): hifn driver and AES192 and 256
if someone wants to put the efforts into fixing this (if it isn't already on 2.2x with FreeBSD 10.1 base), please pur... Chris Buechler
06:07 PM Bug #4720 (Feedback): pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
that should fix in 2.2.3 and newer, leaving for further verification. Chris Buechler
06:04 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
This commit is also required to get the QinQ interface selection correct:
https://github.com/stephenw10/pfsense/comm...
Steve Wheeler
05:29 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
I have a set if patches that attempt to address the three points above. They seem to allow QinQ to work in my testing... Steve Wheeler
05:42 PM Bug #4735 (Duplicate): Serial console doesn't work anymore after config restore on RCC-VE systems
duplicate of #4720 Chris Buechler
05:36 PM Bug #4661 (Feedback): OpenVPN client can't assign to GWGroup specifying VIPs
fixed by what I just pushed, leaving for feedback. Will be in June 2 and newer 2.2.3 snapshots, or can gitsync to REL... Chris Buechler
04:53 PM Revision e1eee3d2: Use 'host!' flag when setting CURLOPT_INTERFACE, as recommended by CURL docs
Renato Botelho
04:53 PM Revision 84522eba: Pass interface to CURLOPT_INTERFACE instead of IP addres, also use 'if!' flag to avoid CURL trying to resolve the interface name
Renato Botelho
04:53 PM Revision 3e8ee192: Use 'host!' flag when setting CURLOPT_INTERFACE, as recommended by CURL docs
Renato Botelho
04:52 PM Revision 4486b751: Pass interface to CURLOPT_INTERFACE instead of IP addres, also use 'if!' flag to avoid CURL trying to resolve the interface name
Renato Botelho
01:16 PM Bug #4642: OpenVPN process status stopped... but its running
it's not a general service status problem. The issue described here is with OpenVPN. An issue there with FreeRADIUS, ... Chris Buechler
03:35 AM Bug #4642: OpenVPN process status stopped... but its running
Hi... I got some time to play a little bit with a pair of pfsense boxes updated to 2.2.1, nanobsd installs, suffering... Alejandro Olivan
01:10 PM Bug #4607: Bridge+CARP crashes/freezes pfSense
it appears this works fine in 2.2.3. It's at least not replicable in the same way it is in previous releases. Vasco, ... Chris Buechler
11:18 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
it's in 2.2.3 snapshots @ snapshots.pfsense.org. Chris Buechler
11:04 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
Is the patch publicly available? Vasco Freire
12:33 PM Revision 96f2b118: Removed debugging accidentally left in place
sbeaver
12:29 PM Revision 37436633: Removed unneeded form as suggested
Thanks sbeaver
12:25 PM Revision 44e84786: Removed unneeded form as suggested and retested
Thanks sbeaver
12:09 PM Revision d014442c: <tt> => <pre>
Class changed from ‘notes’ to ‘help-block’ as suggested to accommodate
future global “verbose help” setting.
sbeaver
11:55 AM Todo #4737 (Resolved): Update CloudFlare dyndns to use new API
Current implementation is using a deprecated API, defined here: https://www.cloudflare.com/docs/client-api.html Renato Botelho
02:44 AM Bug #4519: Disk Corruption
so much for "never happens on reboot"... Jim Thompson
01:20 AM Bug #4028: Wireless Obytes counter always 0
Phil,
We need to sync the patch to the RELENG_2_2 branch. (This work is in progress, but not done.)
Jim Thompson

05/31/2015

01:38 PM Revision 7f8f8808: widget fixes; remove subpanel & show save() when collapsing too
Sjon Hortensius
12:24 PM Revision b144d13d: Merge pull request #1703 from phil-davis/code-style-more
Renato Botelho
05:10 AM Revision 086cf944: Code style bits and pieces from etc
Phil Davis

05/30/2015

09:43 PM pfSense Packages Bug #4736 (Resolved): ladvd crashes, dumps core
ladvd consistently dumps core on my firewall.
See attached core file (bzip'd).
I have only seen this happen on one ...
Adam Thompson
04:40 PM Revision 5be30604: Merge pull request #1702 from phil-davis/system-usermanger
Renato Botelho
03:57 PM Revision 73fa304b: Code style system user manager
Phil Davis
03:08 PM Revision 3b9dfaf2: Allow option to specify just 1 of user and pass in OpenVPN .up file
As per comment in https://redmine.pfsense.org/issues/3633 sometimes the
server end only requires a password, no usern...
Phil Davis
03:07 PM Revision 5e50c5b3: Merge pull request #1701 from phil-davis/openvpn-user-pass
Renato Botelho
03:01 PM Revision 7304c023: Allow option to specify just 1 of user and pass in OpenVPN .up file
As per comment in https://redmine.pfsense.org/issues/3633 sometimes the
server end only requires a password, no usern...
Phil Davis
02:39 PM Revision 19a12e06: Replae backtickes by mwexec()
Renato Botelho
02:39 PM Revision d6daed60: We need to at least setup the serial port before we try to blast
config data to it. My system was hanging during boot because cat
was couldn't output gps.init to the port.
Robert Noland
02:37 PM Revision 417008f7: Replae backtickes by mwexec()
Renato Botelho
02:33 PM Revision 6d9f1df4: Merge pull request #1551 from rnoland/master
Renato Botelho
01:59 PM Revision 139ca549: remove pointless filter on dhcp static mappings table
Will Boyce
01:57 PM Revision 4199bda9: remove pointless filter on dhcp static mappings table
Will Boyce
01:48 PM Revision 241c1dab: Merge pull request #219 from sbeaver-netgate/services_dhcp_edit
Convert services_dhcp_edit SjonHortensius
01:45 PM Revision 8dbf14e3: correct setHelp calls to use variables #218
Sjon Hortensius
01:44 PM Revision df4e04b6: mini typo
Sjon Hortensius
01:40 PM Revision 8b870edb: Merge pull request #218 from sbeaver-netgate/services_captiveportal_vouchers_edit
Convert services_captiveportal_vouchers_edit SjonHortensius
01:36 PM Revision a47eec85: Merge pull request #1585 from jlduran/dnsmadeeasy
Renato Botelho
01:34 PM Revision ae2d7e0a: Implement working generate-key button, fix useless escaping #217
Sjon Hortensius
01:26 PM Revision c92203a9: Merge pull request #1700 from phil-davis/system-hr
Renato Botelho
01:25 PM Revision 927eecf3: Return link-local address when we are only requesting IPv6 prefix only if there is no global IPv6 address. In some cases global SLAAC IPv6 address might be present when using DHCPv6. Fixes #4483
k-paulius
01:07 PM Revision b5249aa3: Fix whitespace in textareas, remove it from tpl
Sjon Hortensius
01:05 PM Revision d9ed341d: Removed unneeded gettext/htmlspecialcharacter
sbeaver
01:05 PM Revision 1657ed6a: services_captiveportal_vouchers.php Conversion complete
Ready for review sbeaver
01:05 PM Revision d9509b6e: Remove debug
sbeaver
01:05 PM Revision 3ac0f8a1: Merge pull request #1590 from k-paulius/fix-4483v2
Renato Botelho
01:01 PM Revision d38bd840: Code style system h and r
Phil Davis
12:57 PM Revision b033e297: Merge pull request #1699 from phil-davis/system-g
Renato Botelho
12:57 PM Revision 5d15bda8: Merge pull request #1698 from phil-davis/system-firmware
Renato Botelho
12:56 PM Revision a90bc47a: Merge pull request #1697 from phil-davis/patch-3
Renato Botelho
12:55 PM Revision e4a1022d: Merge pull request #1696 from phil-davis/system-c
Renato Botelho
12:55 PM Revision b3405d87: Merge pull request #1695 from phil-davis/system-a
Renato Botelho
12:54 PM Revision 031d0bbb: Merge pull request #1694 from phil-davis/patch-2
Renato Botelho
12:53 PM Revision e1cfbede: Merge pull request #1693 from phil-davis/patch-1
Renato Botelho
12:44 PM Revision e2cf6001: Merge pull request #212 from sbeaver-netgate/services_captiveportal_ip_edit
Convert services_captiveportal_ip_edit SjonHortensius
12:41 PM Revision 5a9aa88c: Merge pull request #210 from sbeaver-netgate/services_captiveportal_hostname_edit
Convert services_captiveportal_hostname_edit SjonHortensius
12:32 PM Revision 632c94b3: Merge pull request #203 from sbeaver-netgate/interfaces_wireless_edit
Convert interfaces_wireless_edit SjonHortensius
12:31 PM Revision 60da85fb: Merge pull request #205 from sbeaver-netgate/pkg_mgr_settings
Convert pkg_mgr_settings SjonHortensius
12:30 PM Revision e0c7b2fe: Code style system g
Phil Davis
12:28 PM Revision 0704fb22: Merge branch 'bootstrap' of ssh://github.com/SjonHortensius/pfsense into bootstrap
Sjon Hortensius
12:26 PM Revision 5b884ab2: Merge pull request #200 from sbeaver-netgate/interfaces_lagg_edit
Convert interfaces_lagg_edit SjonHortensius
12:25 PM Revision d3e10bf9: correct indenting #199
Sjon Hortensius
12:24 PM Revision 9d20294d: Merge pull request #199 from sbeaver-netgate/interfaces_gre_edit
Convert interfaces_gre_edit SjonHortensius
12:23 PM Revision 9e38e8bd: fix indenting, remove htmlspecialchars refs #198
Sjon Hortensius
12:22 PM Revision aa429c34: Merge pull request #198 from sbeaver-netgate/interfaces_gif_edit
Convert interfaces_gif_edit SjonHortensius
12:17 PM Revision a41fd4a7: remove unwanted/needed caption
Sjon Hortensius
12:16 PM Revision 69ddae89: Fixed $tab_array[], added NAV tags
sbeaver
12:16 PM Revision e78276d8: interfaces_vlan.php Conversion complete
Page updated for consistency with the other interface_* pages. sbeaver
12:14 PM Revision 4cde9954: remove unwanted ondblclick
Sjon Hortensius
12:14 PM Revision 28f697ab: Fixed $tab_array[], added NAV tags
sbeaver
12:14 PM Revision 719e4eeb: interfaces_wireless.php Conversion complete
Ready for review sbeaver
12:13 PM Revision 006d23d4: Fixed tab_array[], wrapped 'Add" button in <nav>
sbeaver
12:13 PM Revision 68a7712c: interfaces_ppps.php Conversion complete
Ready for review sbeaver
12:11 PM Revision fb455ab4: emulating 9c7a4bcf but without converting back to spaces... #185
Sjon Hortensius
12:09 PM Revision 620e28a7: interfaces_lagg.php Conversion complete
Ready for review sbeaver
12:05 PM Revision 461f8fd1: Fixed $tab_array. Removed unneeded class
sbeaver
12:05 PM Revision cf46aed2: <nav> tags added as suggested
The ability to double-click on a table row to edit that entry seemed
like a useful feature. Are you sure we should re...
sbeaver
12:05 PM Revision 77d42518: Added missing gettext()
And zapped some &nbsp; sbeaver
12:05 PM Revision 34998435: interfaces_bridge.php Conversion complete
Ready for review sbeaver
12:03 PM Revision 360d6b44: remove unused variables refs #173
Sjon Hortensius
12:02 PM Revision 9ec9f2a0: Trivial formatting changes. removed unneeded script
sbeaver
12:02 PM Revision b6596595: Updated as suggested
Thanks sbeaver
12:02 PM Revision 310cb51f: Add table-responsive div
sbeaver
12:02 PM Revision 8edfd911: diag_logs_filter.php Conversion complete
Ready for review.
This conversion was fairly involved due to the in-line controls, dual
filter forms and the resolvin...
sbeaver
11:59 AM Revision e13a5434: Removed debugging
sbeaver
11:59 AM Revision d946c026: Fixed $tab_array[]
sbeaver
11:59 AM Revision 62707e1a: diag_ipsec_sad.php conversion complete
Ready for review. sbeaver
11:57 AM Revision 7a90e30f: Merge pull request #158 from sbeaver-netgate/system_firmware_settings
Convert system_firmware_settings.php SjonHortensius
11:56 AM Revision a3f6729f: Merge pull request #154 from sbeaver-netgate/diag_resetstate
Convert diag_resetstates.php SjonHortensius
11:55 AM Revision dee9fb08: Merge pull request #152 from sbeaver-netgate/status_rrd_graph
Convert status_rrd_graph.php SjonHortensius
11:51 AM Revision 93bd9e70: Merge pull request #206 from sbeaver-netgate/services_captiveportal_edit
Convert services_captiveportal_edit SjonHortensius
11:26 AM Revision 0e88de0c: Code style system firmware
Phil Davis
10:51 AM Revision e26ad18a: system_firmware_restorefullbackup add missing p end tag
and format this block so it is clear which tags start and end where. Phil Davis
08:30 AM Bug #4483: SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
Applied in changeset commit:927eecf3e31eea8ce431317664ab78e8bea524da. Anonymous
08:30 AM Bug #4483 (Feedback): SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
Applied in changeset commit:60802fadefe83c445f79f8889c0b57c301ee8128. Anonymous
08:22 AM Revision 56b1ed39: Code style system C
Phil Davis
07:07 AM Revision 2ee8dea1: Code style system a
Phil Davis
05:33 AM Revision a880f8b8: system_authservers text typo
Phil Davis
05:00 AM Revision efa92471: system_advanced_network small grammar changes
"to tunnel" instead of "to tunneling"
Text for "prefer IPv4" reads better as 2 sentences.
Phil Davis
02:12 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Chris Buechler wrote:
> That's after fsck (including after multiple runs).
Well what I meant is actually whether ...
Kill Bill
01:57 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
That's after fsck (including after multiple runs). They aren't "constantly damaged", only after unclean shut downs, a... Chris Buechler
01:49 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Chris Buechler wrote:
> If using SU, you'll end up with 0 byte files. Without SU, you'll have corrupted files contai...
Kill Bill
01:33 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
updated subject to narrowed down problem.
With SU, with or without J, you end up with 0 byte master.passwd, passw...
Chris Buechler

05/29/2015

11:21 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Nano using SU+J = bad. Either go back to plain sync or just SU. All journaling does is *double all meta-data writes* ... ky41083 -
12:23 PM Revision 5dcec9f2: Merge pull request #1692 from phil-davis/services-unbound
Renato Botelho
12:07 AM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
I've just hit this issue myself using an ALIX 2D13. There are no other devices except for the CF card. Matt Meyer

05/28/2015

05:30 PM Revision e92ee598: Code style services unbound
Phil Davis
02:05 PM Revision a8e31a33: Merge pull request #1471 from Talyrius/master
Renato Botelho
02:01 PM Revision 193b6834: L7 protocols: add rtmp, sync bittorrent, finger and quake-halflife with l7-protocols
Renato Botelho
01:43 PM Revision ebddb936: Adding the Appropriate RA Flags for "Stateless DHCP"
Aqueeb Qadri
01:43 PM Revision a450c443: Added the Stateless DHCP Dropdown here
Aqueeb Qadri
01:40 PM Revision 001914d1: Merge pull request #1444 from oliwel/feature/easyrule-unblock
Renato Botelho
01:35 PM Revision c6872b3e: Merge pull request #1033 from aqueeb/master
Renato Botelho
01:28 PM Revision 146d20bd: Merge pull request #1691 from phil-davis/services-rsw
Renato Botelho
11:18 AM Bug #4686: Rekeyed SAs are not properly removed
Tried with this image:
pfSense-2.2.3-DEVELOPMENT-1g-amd64-nanobsd-upgrade-20150521-0706.img.gz
It broke IPsec con...
Ivo B
10:01 AM Bug #4735 (Duplicate): Serial console doesn't work anymore after config restore on RCC-VE systems
Hi,
I installed pfsense from the NETGATE ADI RCC-VE memstick image onto a RCC-VE 2440. Everything worked perfectly...
Dominic Blais
08:50 AM Bug #4233 (Feedback): Inconsistent handling of seperators in easyrule cli
Applied in changeset commit:e4d8943c59cfceba229e2689d67601127e8ceb1a. Anonymous
12:07 AM Bug #4523 (Confirmed): master.passwd/group file corruption may occur after kernel panic or unclean shut down
still an issue Chris Buechler

05/27/2015

10:07 PM Feature #4734 (Needs Patch): SSHD Logs, select facility to log to
Hi,
It would be handy to have the ability to log sshd to a different facility (like local4). Just one item in the ...
Russell Morris
04:54 PM Revision 56463a6c: Code style services r s w
Phil Davis
03:10 PM Bug #4733 (Not a Bug): Soekris Boot Problem
please post to the forum or mailing list for assistance. Chris Buechler
03:05 PM Bug #4733 (Not a Bug): Soekris Boot Problem
Hi
After a fresh and successful installation on my soekris net6501 on the internal harddrive, pfSense won't boot.
...
A B
02:52 PM Revision a6f973a1: Fix comment style
Oliver Welter
02:14 PM Revision face47a5: Revert "Disable this tunable for now. Ticket #4523"
This reverts commit 85a37985b15c7a7c935d0028aa7a520110c2e649. Ermal Luçi
02:13 PM Revision 36314cba: Revert "Disable this tunable for now. Ticket #4523"
This reverts commit ab37f56f404a41dc5c5c26a83d594f0f883bd88d. Ermal Luçi
12:37 PM Revision e3230c0a: Merge pull request #1081 from PiBa-NL/cert_usage
Ermal Luçi
11:35 AM Bug #4028: Wireless Obytes counter always 0
I am not clear - is the fix coming just in 2.3, or also in he 2.2.3 builds? Phillip Davis
11:05 AM Revision 790bab08: Merge pull request #1690 from phil-davis/diag
Renato Botelho
10:40 AM Revision 699737d9: Code style www diag more bits
Phil Davis
08:51 AM Revision 427d36b4: Ticket #4523 Major changes to how fsck is done.
Follow best practice of using fsck from FreeBSD rc.d/fsck script.
This means run preen mode first and later on tr...
Ermal Luçi
08:50 AM Revision fc123231: Ticket #4523 Run fsck with -C flag and alway in foreground during bootup to prevent any issues that might schedule background mode.
Ermal Luçi
08:49 AM Revision 7fd93993: Ticket #4523 Major changes to how fsck is done.
Follow best practice of using fsck from FreeBSD rc.d/fsck script.
This means run preen mode first and later on try fo...
Ermal Luçi
08:20 AM Revision f2e36920: Ticket #4523 Run fsck with -C flag and alway in foreground during bootup to prevent any issues that might schedule background mode.
Ermal Luçi
03:54 AM Bug #4523 (Feedback): master.passwd/group file corruption may occur after kernel panic or unclean shut down
Improvements on how filesystem check/correction is being done have been merged which should help with corruption to n... Ermal Luçi

05/26/2015

11:30 PM Bug #4674: invalid state table entries after WAN IP change
Interesting workaround! I will have to try this myself as we've had similar problems with SIP devices & Asterisk. → luckman212
08:17 PM Feature #4732: Add MS-CHAPv2 option to L2TP Configuration
I have opened a Pull Request (#"1689":https://github.com/pfsense/pfsense/pull/1689) to discuss this subject. Jose Luis Duran
08:12 PM Feature #4732 (Resolved): Add MS-CHAPv2 option to L2TP Configuration
If you need to validate L2TP/IPSec users with a Windows-based RADIUS Server (NPS/IAS), choosing *CHAP* from *VPN:L2TP... Jose Luis Duran
06:24 PM Revision cedb9a77: Merge pull request #1688 from phil-davis/diag-logs
Renato Botelho
05:40 PM Bug #4028 (Feedback): Wireless Obytes counter always 0
Merged stack from HEAD with the fix on 2.3 Ermal Luçi
05:05 PM Revision 4e3b667c: Code style diag logs again
while making a fix today I noticed that I had done these early-on and
had not tabbed out the HTML nicely...
Phil Davis
11:41 AM Bug #4459 (Resolved): Tzdata is too old (needs to be updated for Russia)
thanks Dmitriy Chris Buechler
11:39 AM Feature #4683 (Feedback): Support for elliptic curve for IPsec on webconfigurator
Chris Buechler
12:41 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Can be closed: Solved with https://github.com/pfsense/pfsense/pull/1649 Lars Pedersen
09:53 AM Revision 9eb84e63: Add tracker rule number to dynamic firewall log
Bug #4730 - the code was not there yet. Phil Davis
09:53 AM Revision 8882e40f: Merge pull request #1687 from phil-davis/patch-1
Renato Botelho
08:45 AM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
Me too, as I also wrote here: https://forum.pfsense.org/index.php?topic=92387.msg511674#msg511674
Hollander Hollander
04:09 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
Yesterday I discovered the same problem. Any chance to fix it in nearest release?
Thanks in advance!
Krzysztof Szczesniak
03:30 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
I have this same issue.
I want to create MultiWan CARP, but when I choice Interface (GW Group Wan1FailoverWan2) on O...
Grzegorz Sliwa
01:31 AM Revision 84e9e531: Add tracker rule number to dynamic firewall log
Bug #4730 - the code was not there yet. Phil Davis

05/25/2015

08:29 PM Bug #4730: Firewall Log Dynamic View missing Block/Allowed Reason
The code was not there in the dynamic firewall log.
This should do it: https://github.com/pfsense/pfsense/pull/1687
Phillip Davis
09:09 AM Bug #4730 (Resolved): Firewall Log Dynamic View missing Block/Allowed Reason
If you hover over the the (Allow/Block) icon in the Dynamic Firewall Log, it only show Block/Allow, and not the rule ... Marc Riley
02:27 PM Revision c5ecdc25: Add support for DNS Made Easy
Documentation:
http://www.dnsmadeeasy.com/dynamic-dns/
Jose Luis Duran
02:10 PM Revision 7d2af373: Call htmlspecialchars() to remove dangerouns chars from zone parameter. Also redirect user to services_captiveportal_zones.php when an invalid zone is passed
Renato Botelho
02:10 PM Revision ac880ee7: Call htmlspecialchars() to remove dangerouns chars from zone parameter. Also redirect user to services_captiveportal_zones.php when an invalid zone is passed
Renato Botelho
12:25 PM Revision 85a37985: Disable this tunable for now. Ticket #4523
Ermal Luçi
12:25 PM Revision ab37f56f: Disable this tunable for now. Ticket #4523
Ermal Luçi
11:28 AM Revision 81e5adb0: Merge pull request #1686 from phil-davis/service-rfc2136
Renato Botelho
11:28 AM Revision 6fac4c26: Merge pull request #1685 from phil-davis/services-ntp
Renato Botelho
11:27 AM Revision f46172c5: Merge pull request #1684 from phil-davis/services-igmp
Renato Botelho
11:27 AM Revision 73346505: Merge pull request #1683 from phil-davis/www-services-dyndns
Renato Botelho
11:25 AM Revision 5f16d0ba: Merge pull request #1682 from phil-davis/www-services-dnsmasq
Renato Botelho
11:25 AM Revision b58e1cec: Unbalanced td tag in services_dnsmasq
Phil Davis
11:25 AM Revision 6e67bc43: Merge pull request #1681 from phil-davis/patch-2
Renato Botelho
11:24 AM Revision fc10b44a: Merge pull request #1680 from phil-davis/www-services-cp
Renato Botelho
11:23 AM Revision 5751d1bc: Merge pull request #1679 from phil-davis/services_dhcp
Renato Botelho
11:22 AM Revision 3ccb7fc3: Consistent clear_subsystem_dirty after unbound restart
from services_dhcp.
This looks like it is wanting curlies to put all clear_subsytem_dirty inside the "if".
Phil Davis
11:22 AM Revision dbc03d71: Merge pull request #1678 from phil-davis/patch-1
Renato Botelho
11:20 AM Revision bf8f9acc: Merge pull request #1677 from phil-davis/vpn_ipsec
Renato Botelho
11:16 AM Revision 891d8ff8: Merge pull request #1676 from phil-davis/www_openvpn
Renato Botelho
11:08 AM pfSense Packages Bug #4731 (Resolved): softflowd process gets started twice during bootup
When rebooting the firewall, the softflowd process(s) can get started twice. I did some investigation and believe wh... Cody Howell
10:09 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
The installer and nano has been switched to SU+J same as default FreeBSD.
Ermal Luçi
04:56 AM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Looks like the issue has been successfully fixed, thanks Chris Dmitriy K

05/24/2015

02:14 PM Feature #3377: OAuth2 authentication in captive portal
Chris Buechler wrote:
> there will be publicly-available 2.2 snapshots in the not too distant future. At this point,...
bamidele Amire
09:38 AM Revision efdf8358: Code style services RFC2136
Phil Davis
09:17 AM Revision 7a6f0ebc: Code style services NTP
Phil Davis
07:09 AM Revision c0bf7858: Code style services igmpproxy
Phil Davis
06:53 AM Revision 9c12c130: Code style services dyndns
Phil Davis
06:04 AM Revision 966ed611: Code style services dnsmasq
Phil Davis
05:48 AM Revision c09b1947: Unbalanced td tag in services_dnsmasq
Phil Davis
05:23 AM Revision 5fcc3079: Code style www services captive portal
Phil Davis
05:14 AM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
I have expanded the server directive as per the openvpn manpage: https://github.com/apollo13/pfsense/commit/137498be7... Florian Apolloner

05/23/2015

06:21 PM Bug #4729: OpenVPN Advanced config fails on double save
Oh, separating the options by a semicolon makes it work -- I guess the UI could be a little bit more forgiving here… Florian Apolloner
06:19 PM Bug #4729 (Not a Bug): OpenVPN Advanced config fails on double save
Saving ... Florian Apolloner
06:01 PM Revision 8f8682f7: Code style services DHCP
Phil Davis
06:00 PM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
Hmm, I guess the easiest option would be to just remove the "address pool setting" and make "tunnel network optional"... Florian Apolloner
05:55 PM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
I am currently running my pfsense install with this patch:... Florian Apolloner
05:31 PM Feature #4728 (Pull Request Review): Expose ``nopool`` server option in the OpenVPN Server GUI
Openvpn has a checkbox to enable an address pool, but that one seems to be pretty useless (pool_enable is used nowher... Florian Apolloner
03:00 PM Revision 4230ad16: Consistent clear_subsystem_dirty after unbound restart
from services_dhcp.
This looks like it is wanting curlies to put all clear_subsytem_dirty inside the "if".
Phil Davis
01:41 PM Bug #4727 (Not a Bug): Rules on L2TP VPN Tab are ignored. All traffic from clients always allowed.
https://forum.pfsense.org/index.php?topic=94108.25
Created L2TP/IPsec remote access VPN as per https://doc.pfsense...
Chris Linstruth
11:59 AM Bug #4686: Rekeyed SAs are not properly removed
Sadly I cannot easily upgrade to a snapshot currently and test this, but will provide feedback as soon as 2.2.3 is re... Florian Apolloner
09:04 AM Revision a1d55e81: Code style VPN IPsec
Phil Davis
02:59 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Reading this like this:
- https://forums.freebsd.org/threads/freebsd-on-ufs-preventing-data-loss-on-crash.30683/
...
Kill Bill

05/22/2015

09:49 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
this is replicable with just an unclean shut down Chris Buechler
11:28 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
I thought I added this here a while back but apparently not.
I have tried combinations of:
* Soft updates
* SU+J...
Jim Pingle
08:33 PM Bug #4725 (Not a Bug): alc(4) may need an update
we'll get that for 2.3 where we're on 10.2. If someone would like to submit a backported patch for 10.1, we could add... Chris Buechler
08:12 PM Bug #4725 (Not a Bug): alc(4) may need an update
alc(4) in FreeBSD 10 stable was updated with r273366 to support more atheros LAN chips, not sure if that made it into... Charlie m
08:30 PM Todo #4726 (Resolved): Remove zoneinfo.tgz, use stock FreeBSD's
Need to remove zoneinfo.tgz and just rely on FreeBSD's instead. It was brought over that way from m0n0wall, which did... Chris Buechler
08:11 PM Revision e38c75a8: Code style www vpn_openvpn
Phil Davis
08:05 PM Revision 88cbd004: Update/correct wireless status flags and capabilities list.
There are many more possible flags, documented on the wiki: https://doc.pfsense.org/index.php/Wireless_Status Jim Pingle
08:03 PM Revision e2c20d52: Update/correct wireless status flags and capabilities list.
There are many more possible flags, documented on the wiki: https://doc.pfsense.org/index.php/Wireless_Status Jim Pingle
07:53 PM Revision 5a0d15b1: Merge pull request #1672 from phil-davis/patch-1
Renato Botelho
07:53 PM Revision b0d7ce73: Merge pull request #1673 from phil-davis/patch-2
Renato Botelho
07:51 PM Revision 626fab04: Merge pull request #1674 from phil-davis/vpn_pppoe
Renato Botelho
07:51 PM Revision cdeae576: Merge pull request #1675 from jlduran/editorconfig
Renato Botelho
06:07 PM Revision f6fe9035: Remove unneeded gettext
sbeaver
06:05 PM Revision 875a8496: Remove unneeded gettext
sbeaver
06:00 PM Revision f1cef2a2: Remove one get text
sbeaver
05:58 PM Revision 299364a4: Remove unneeded htmlspecialcharacters
sbeaver
05:56 PM Revision 934c7d58: Added spacing
sbeaver
05:48 PM Revision ea6649f7: Removed htmlspecialcharacters
sbeaver
05:41 PM Revision cffe7e71: Remove htmlspecialcharacters
sbeaver
05:35 PM Revision 4b5a2e6c: Remove htmlspecialcharacters and gettext
sbeaver
05:19 PM Revision 1de4da38: Removed unneeded htmlspecialcharacters
sbeaver
05:16 PM Revision 227bf9cf: Trivial whitespace edits
sbeaver
05:13 PM Revision 1735cd7d: Remove unneeded htmlspecialcharacters, tabs, button
sbeaver
05:10 PM Revision 3d1bc0f0: Removed a tab
sbeaver
05:08 PM Revision 5dc5f197: Remove unneeded htmlspecialcharacteres
sbeaver
05:05 PM Revision 07306e62: One tab too many
sbeaver
04:59 PM Revision 69279988: remove unneeded gettext/htmlspecialcharacters
sbeaver
04:49 PM Revision ea06fb00: Remove unneeded gettext
sbeaver
04:45 PM Revision 2a2df02f: Remove unneeded gettext
sbeaver
04:41 PM Revision 9e097d78: Remove unneeded gettext
sbeaver
04:37 PM Revision fae9a73c: Removed unneeded gettext
sbeaver
04:29 PM Revision e6844dd9: Removed unneeded htmlspecialcharacters
sbeaver
04:26 PM Revision aae2d55e: Remove unneeded htmlspecialcharacters
sbeaver
04:24 PM Revision 814b5184: Trivial whitespace changes
sbeaver
03:40 PM Revision e6e1ba01: Trivial format changes
sbeaver
03:28 PM Revision a564b6e7: status_rrd_graph.pgp Conversion complete
GET form converted to POST. Date/time controls revised. Tested with all
graph types and control options.
sbeaver
03:05 PM Bug #4028: Wireless Obytes counter always 0
https://reviews.freebsd.org/D2621 Ermal Luçi
02:16 PM Bug #4623: Carp not working under bhyve
Ermal Luçi wrote:
> Did you try from the GUI since carp should not differ from FreeBSD at least in this regard!
Y...
Matthias Breddin
01:30 PM Revision ddb753db: Add .inc files to editorconfig
Jose Luis Duran
11:51 AM Revision 2e98fc4c: Add .editorconfig file
To start with just `.php` files. According to the [Developer Style Guide](https://doc.pfsense.org/index.php/Developer... Jose Luis Duran
10:56 AM Revision b7856e58: Code style vpn_pppoe
Phil Davis
08:38 AM Feature #4724 (New): Captive Portal Status Add Client Hostname
It would be very useful to include the client hostname in the captive portal status list, so it is easy to identify w... Josh Stompro
07:58 AM Bug #1974: Captive Portal RADIUS accounting bytes wrong
I can confirm that this behaviour is the same in 2.2.2 for 32bit. Fran Secs
06:48 AM Bug #4311: aPinger service gets higher ping. Resolves for short period after restart aPinger service
Duplicate of https://redmine.pfsense.org/issues/4081 and probably some others. Kill Bill
01:36 AM Revision 8d610380: Be smarter about combinations of combinedfields and usecolspan2
a) When we are doing combined fields and usecolspan2 is in effect, then usecolspan2 is also a signal that we want to ... Phil Davis

05/21/2015

10:07 PM Revision d105d6f7: Update zoneinfo from FreeBSD 10.1-REL. Ticket #4459
Chris Buechler
10:07 PM Revision 826e1524: Update zoneinfo from FreeBSD 10.1-REL. Ticket #4459
Chris Buechler
08:15 PM Revision a1398968: services_rfc2136_edit.php Conversion complete
Ready for review sbeaver
08:13 PM Revision bec3f925: Update pkg_edit.php
a) When we are doing combined fields and usecolspan2 is in effect, then usecolspan2 is also a signal that we want to ... Phil Davis
07:05 PM Revision a5d5b1f7: services_rfc2136.php Conversion complete
Ready for review sbeaver
07:03 PM Revision fec2a89a: Revert "services_rfc2136.php Conversion complete"
This reverts commit fa0f5f67222839a3456351aec8eb963bd43e67b9. sbeaver
07:00 PM Revision fa0f5f67: services_rfc2136.php Conversion complete
Ready for review
Like services_dyndns the interleaving of PHP and HTML makes print()
sternest the cleanest way :(
sbeaver
06:04 PM Revision 26fe7b98: Corrected filed values
sbeaver
06:00 PM Revision b993931c: services_ntpd_pps.php Conversion complete
Ready for review sbeaver
05:48 PM Revision 5df4f971: Added missing 'if(!empty($serialports)) . .
sbeaver
05:30 PM Revision 4b7289a3: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
05:30 PM Revision b20e03b2: services_ntpd_gps.php Conversion complete
Ready for review
Al lot of Javascript in the page. Converting it to jQuery and removing
redundant code has made it a...
sbeaver
05:05 PM Bug #4459 (Feedback): Tzdata is too old (needs to be updated for Russia)
zoneinfo has been updated with latest from FreeBSD, should be fine in 2.2.3. Chris Buechler
04:35 AM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Chris Buechler wrote:
> I mean in stock FreeBSD 10.1, have you checked it?
https://bugs.freebsd.org/bugzilla/show...
Victor Danilkin
04:43 PM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Just thought that random-id will apply to all packets incoming another interface (LAN..etc..) prior to exit WAN. So, ... Dominic Blais
03:43 PM Bug #4723 (Resolved): Can't forward UDP fragmented packets with scrubbing enabled.
I have a use case where I couldn't forward UDP fragmented packets thru a site to site OpenVPN tunnel. The issue isn't... Dominic Blais
12:21 PM Revision 08d56bd1: services_ntpd.php Conversion complete
Ready for review sbeaver
12:05 PM Revision 633df926: Correct descriptions on Key Rotation and Master Key Regeneration for wireless.
Jim Pingle
12:04 PM Revision 8a736fae: Correct descriptions on Key Rotation and Master Key Regeneration for wireless.
Jim Pingle
08:27 AM Bug #4722 (Needs Patch): Ralink USB driver yields a double fault panic on pfSense, works on FreeBSD with equivalent config
I've got a Ralink USB wireless adapter (Buffalo WLI-UC-GNM) that works perfectly on stock FreeBSD (10.1-STABLE) but w... Jim Pingle
08:09 AM Revision a13c317e: Fix but where value in Textarea wasn't processed. Fixes #216
Sjon Hortensius
08:07 AM Bug #4718: "BTX halted" error with 2.2.2
Memstick installation does not work either. It fails with the same error:... James Dietrich
06:58 AM Bug #4721 (Rejected): Can't assign same monitor ip twice
Currently that is impossible. You must have different monitor IP addresses for each WAN even if they have different g... Jim Pingle
04:44 AM Bug #4721: Can't assign same monitor ip twice
Correction: "They are both having the same gateway, and I would like to monitor that gateway ip." => the same gateway... Sander Naudts
04:43 AM Bug #4721 (Rejected): Can't assign same monitor ip twice
We have 2 cable connections from the same ISP. They are both on seperate routers in front of Pfsense.
So in Pfsens...
Sander Naudts
06:54 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Understand.
How do i solve this in pFsense then? I need to duplicate conX in ipsec.conf with different p2 entries?
Roman H
12:49 AM Bug #4720 (Resolved): pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
After loading an ADI RCC-VE with pfSense-memstick-ADI-2.2.2-RELEASE-amd64.img the system works fine. Once the config... Cliff Skolnick

05/20/2015

10:16 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Cisco already has CSCue42170 linked above open on the issue as an enhancement. Not sure you can do anything to push t... Chris Buechler
01:53 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
I don't know where to "hack those validations"
Edit ipsec.conf sounds much easier to me ... in case if ipsec stron...
Roman H
01:50 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
there isn't a way to configure that in the GUI right now. You can hack the input validation that checks for duplicate... Chris Buechler
01:32 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Is it possible to split ikev2 via GUI ?
Or its only by editing conf file?
What you may advice in current situation?
Roman H
10:13 PM Bug #4719 (Resolved): IKEv2 to Cisco ASA results in TS mismatch when initiation triggered by traffic
IKEv2 to Cisco ASA won't come up when initiation is triggered by traffic matching the P2. It results in the following... Chris Buechler
06:34 PM Revision 3a44f4a2: Merge pull request #1670 from phil-davis/patch-1
Renato Botelho
06:34 PM Revision 51c26808: Merge pull request #1671 from phil-davis/patch-2
Renato Botelho
06:11 PM Revision 26d785bb: More combinedfields and usecolspan2 fixes
Actually the "tr" tag needs to be a single tag-pair that encloses all of the set of fields with combinedfields specif... Phil Davis
06:02 PM Revision f6014228: More combinedfields and usecolspan2 fixes
Actually the "tr" tag needs to be a single tag-pair that encloses all of the set of fields with combinedfields specif... Phil Davis
03:51 PM Revision 244f5927: services_icmpproxy_edit.php Conversion complete
Ready for review sbeaver
03:35 PM Feature #4322: Add Google Domains DDNS
Adding a vote for this... have manually added it using Custom, but would like to get full status support (rather than... Anonymous
01:51 PM Revision c4973f3e: Merge branch 'bootstrap' of ssh://github.com/SjonHortensius/pfsense into bootstrap
Sjon Hortensius
01:40 PM Revision e5db68d2: Merge pull request #1668 from phil-davis/patch-1
Renato Botelho
01:39 PM Revision 67e7ae85: Merge pull request #1669 from phil-davis/patch-2
Renato Botelho
01:30 PM Revision cbd3fef9: Revised as suggested
Thanks!
It would be very helpful to have a phpdoc to document the Forms
framework.
I had not noticed the setPatter ...
sbeaver
01:24 PM Revision ec996cd7: Use toggles as suggested
Thanks,
The toggle system was a WIP when I did this page I think. It works
nicely now in this instance.
sbeaver
01:20 PM Revision b021e2c6: Fix tr use for combinedfields in pkg xml
When specifying combinedfields begin and end in a package XML file, IE reports some unexpected start tag messages. Th... Phil Davis
01:15 PM Revision 0259757c: Updated as suggested
Thanks! sbeaver
01:13 PM Revision 53895ce8: Merge pull request #204 from sbeaver-netgate/load_balancer_settings
Convert load_balancer_setting SjonHortensius
01:10 PM Revision e10dd978: remove deprecated align attribute #195
Sjon Hortensius
01:10 PM Revision 9029879d: Merge pull request #195 from sbeaver-netgate/diag_ipsec_leases.php
Convert diag_ipsec_leases.php SjonHortensius
01:08 PM Revision 3d0f579f: services_igmpproxy.php Conversion complete
Ready for review sbeaver
01:03 PM Revision e3167a84: Fix tr use for combinedfields in pkg xml
Phil Davis
12:59 PM Bug #3314 (Feedback): Traffic graph shows 2X the actual traffic on VLAN interfaces.
A patch to fix it was pushed, new snapshots will contain the fix Renato Botelho
12:39 PM Revision ea54560e: services_dyndns_edit.php Conversion complete
Ready for review sbeaver
12:15 PM Bug #4718: "BTX halted" error with 2.2.2
Does memstick installation work on this machine? Ermal Luçi
10:56 AM Bug #4718 (Closed): "BTX halted" error with 2.2.2
This was discussed on the forum at https://forum.pfsense.org/index.php?topic=94104.0
I have a machine that boots o...
James Dietrich
09:17 AM Bug #4685 (Confirmed): Crash/panic "Sleeping thread owns a non-sleepable lock"
One user still reports crashes with the new daemon. Updated crash dump is in the projects repo. Jim Pingle

05/19/2015

11:23 PM Bug #4310 (Confirmed): Limiters + HA results in hangs on secondary
no change, still hangs secondary within a couple hours Chris Buechler
11:11 PM Bug #4622 (Not a Bug): /var/dhcpd/var/db/dhcpd6.leases grows to enormous size, cpu usage high
seriously broken DHCPv4 or v6 clients like this will cause issues along these lines Chris Buechler
09:16 PM Revision f5606ded: services_dyndns.php Conversion complete
Ready for review
This page contains only a very simple table but with a lot of PHP logic
and not much HTML. Retainin...
sbeaver
08:07 PM Revision b9f8695e: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
08:03 PM Revision ca4d3b80: proper indenting; reveals redundant </div>. Warning; gettext madness..
refs #202 Sjon Hortensius
08:01 PM Revision 18231f7b: Enable add new row if no rows yet exist
sbeaver
08:01 PM Revision 02ad8777: Merge pull request #202 from sbeaver-netgate/license
Converted License SjonHortensius
07:58 PM Revision 3150f4a4: removed enormous form toggle, that's meant for smaller sections.
Also implemented new MultiCheckboxes. Refs #163 Sjon Hortensius
07:53 PM Revision cce0e08f: You are so right!
Thanks sbeaver
07:52 PM Revision a03c4756: Toggle action updated
The toggles initial states were initially inconsistent after saving the
form. Several js remedies were tried but the ...
sbeaver
07:52 PM Revision a7f5d4b9: service_snmp.php WIP
Help required with nested toggles sbeaver
07:49 PM Revision cafb914a: Merge pull request #194 from sbeaver-netgate/diag_ipsec_spd.php
Converted diag_ipsec_spd.php SjonHortensius
07:46 PM Revision ff846cb9: Fixup interfaces_qinq refs #187
Sjon Hortensius
07:43 PM Revision b104d092: interfaces_qinq Conversion completed
Ready for review sbeaver
07:40 PM Revision 158732bd: services_dnsmasq_edit.php Conversion complete
Ready for review sbeaver
07:27 PM Revision 8986ff32: Converted diag_nanobsd.php, clean manual commit #178
Stephen Beaver
07:03 PM Revision 9d9a1d38: Merge pull request #159 from sbeaver-netgate/system_firmware_restorefullbackup
Converted system_firmware_restorefullbackup.php SjonHortensius
06:35 PM Revision 6b2aa80f: services_dnsmasq_domainoverride_edit.php Conversion complete
Ready for review sbeaver
06:15 PM Revision e6363160: services_dnsmasq.php COnversion complete
Ready for review sbeaver
04:41 PM Revision 4ed45f24: Merge pull request #1649 from baxeno/master
Ermal Luçi
04:37 PM Bug #4704 (Feedback): IKEv2 to Cisco ASA won't bring up multiple P2 networks
this is actually a Cisco bug/lacking feature. https://tools.cisco.com/bugsearch/bug/CSCue42170/?referring_site=bugqui... Chris Buechler
03:50 PM Revision 2f8d3544: Merge pull request #1667 from phil-davis/patch-1
Renato Botelho
03:27 PM Revision 3b1525f9: Too many left curlies in pkg_edit.php
I broke the syntax! Phil Davis
02:10 PM Bug #3314 (Confirmed): Traffic graph shows 2X the actual traffic on VLAN interfaces.
http://fxr.watson.org/fxr/source/net/if_vlan.c?v=FREEBSD10#L1182 is the issue.
To be decided how to solve.
Ermal Luçi
01:18 PM Todo #4353 (Feedback): Review IPsec reloading when strongswan.conf is changed
This have been fixed with the code change to use the starter pid for events rather than charon one. Ermal Luçi
01:17 PM Bug #4699 (Not a Bug): IPsec panic with MSS clamping
This was a false positive. Ermal Luçi
12:47 PM Revision 546d4b34: Add toggle on enable
sbeaver
12:36 PM Revision 4b9f0203: services_dhcpv6_edit.php Conversion complete
Ready for review sbeaver
11:43 AM Revision cd2c7940: services_dhcpv6.php Conversion complete
Ready for review sbeaver
11:12 AM pfSense Packages Bug #4717 (Resolved): Asterisk needs workarounds to work properly
In order to have the asterisk package working, I needed to install the "shellcmd" package with this configuration:
...
Frederic Steinfels
11:10 AM Revision 2898abf9: Merge pull request #1662 from phil-davis/www-pkg
Renato Botelho
10:07 AM Bug #4716: "DNS Resolver" lacks SOA for ".local" domain setups
Leander Schäfer wrote:
> Therefore it is a very important feature of pfSense to support this scenario.
It support...
Kill Bill
09:35 AM Bug #4716: "DNS Resolver" lacks SOA for ".local" domain setups
This is a Guide to change unbound for ".local" domain support by adding SOA support
Go to "Diagnostics" ==> "Edit ...
Leander Schäfer
08:05 AM Bug #4716: "DNS Resolver" lacks SOA for ".local" domain setups
- unbound +doesn't need+ to be an authoritative DNS server for this to work mighty fine. So this should not be up for... Leander Schäfer
07:51 AM Bug #4716: "DNS Resolver" lacks SOA for ".local" domain setups
Uh.
- Nowhere in RFC6762 is suggested than .local should contain SOA. To the contrary, mDNS by definition have no...
Kill Bill
06:47 AM Bug #4716 (Closed): "DNS Resolver" lacks SOA for ".local" domain setups
It turns out pfSense does not setup the localdomain set under "General Setup" ==> "domain" as SOA. Instead pfSense cu... Leander Schäfer
04:14 AM Bug #4686 (Feedback): Rekeyed SAs are not properly removed
Patches are merged so you can test with latest snaps. Ermal Luçi
02:42 AM Bug #4686: Rekeyed SAs are not properly removed
As of this morning I have weird chils SAs again. Attaching a file. Ivo B
02:56 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
This packages for install Aleksei Aksenov
02:55 AM pfSense Packages Feature #4503: GNUGateKeeper H.323 Proxy Package
I did it! H323 now WORK!!!
https://forum.pfsense.org/index.php?topic=94085.0
If somebody would undertake make packa...
Aleksei Aksenov

05/18/2015

10:39 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Squid2 has been disabled for pfSense 2.3 onwards - https://github.com/pfsense/pfsense-packages/commit/5be0199960c6d8f... Phillip Davis
06:43 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Solved! Squid 3 seems to have solved the issue! Why not mark Squid 2 as "deprecated"? Anonymous
10:30 PM Bug #4704 (Confirmed): IKEv2 to Cisco ASA won't bring up multiple P2 networks
Chris Buechler
07:52 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
I mean in stock FreeBSD 10.1, have you checked it? Chris Buechler
03:58 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Chris Buechler wrote:
> is the tzdata in FreeBSD 10.1 not correct? We use stock FreeBSD tzdata.
Nope, still only ...
Dmitriy K
07:30 PM Revision 77f67782: Merge pull request #1665 from phil-davis/www-vpn-l2tp
Renato Botelho
07:24 PM Bug #4713 (Confirmed): Gateway added via console menu option 2 is not picked up by the setup wizard
Chris Buechler
02:21 PM Bug #4713: Gateway added via console menu option 2 is not picked up by the setup wizard
Adding diff between the console added gateway (First) and GUI added gateway (second) Jim Pingle
02:20 PM Bug #4713 (Resolved): Gateway added via console menu option 2 is not picked up by the setup wizard
If the user configures their static WAN information using the console, and later runs through the setup wizard, the g... Jim Pingle
07:23 PM Bug #4714: syslogd unable to start with 'mixed' log types present
could you narrow it down to a specific log file that's problematic and get us that file? suspect the cause is a corru... Chris Buechler
04:12 PM Bug #4714 (Closed): syslogd unable to start with 'mixed' log types present
Syslogd fails to fully start on boot,
This started over a month ago on April 17 it would appear (based on the lat...
Benjamin Hodgens
07:20 PM Revision e383f744: Merge pull request #1663 from jlduran/utf8-latin1
Renato Botelho
05:24 PM Revision a3e00d53: Code style vpn_l2tp
Phil Davis
05:11 PM Bug #4715 (Duplicate): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Chris Buechler
05:09 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Shoot. I did look, but I didn't find that one. Yes, it appears to be the same issue. Adam Thompson
05:01 PM Bug #4715 (Feedback): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
VLANs I'm guessing? that'd be #3314 Chris Buechler
04:37 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Attached RRD graphs for current period; these look right, I think. Adam Thompson
04:35 PM Bug #4715: Dashboard WAN traffic graph shows twice as much as RRD traffic graph
Whoops, I'm on 2.2.2 amd64, not 2.2.3.
Adam Thompson
04:35 PM Bug #4715 (Duplicate): Dashboard WAN traffic graph shows twice as much as RRD traffic graph
I've noticed that for my WAN interface, the traffic graph on the dashboard shows double the throughput it should (I t... Adam Thompson
05:08 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
As a temporary workaround, would it not be possible to detect VLANs and do something like disabling the graph, automa... Adam Thompson
03:43 PM Todo #4576 (Resolved): Write a tool to create port reading data from xmlrpc
Done. update_package_pfPorts.php on tools/builder_scripts. Renato Botelho
02:08 PM Bug #4712 (Resolved): Wizard hostname validation rejects upper case letters
The setup wizard has some JavaScript to validate the hostname. This script does not accept upper case letters in the ... Jim Pingle
12:58 PM Bug #4710 (Confirmed): System Log - Firewall Fails to 'Click to Resolve' for IPv6 Addresses
Chris Buechler
12:45 PM Bug #4708 (Not a Bug): LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
it's correct all around as is. the default deny is what blocks them, logging of default deny can be user-controlled. Chris Buechler
12:21 PM Bug #3736: No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
I am sorry but it is not fixed with pfsense 2.2.2-RELEASE Eric Boudrand
10:54 AM Bug #4686: Rekeyed SAs are not properly removed
I see that the first one is already integrated as of cbc1f411604e0d5f608439db7b4f16303b03dcf2. Mind adding the second... Florian Apolloner
10:29 AM Bug #4686: Rekeyed SAs are not properly removed
Would it be possible to apply those two patches:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200282
https://b...
Florian Apolloner
06:41 AM Bug #4686: Rekeyed SAs are not properly removed
Ivo B wrote:
> Let me also add that remote subnets are in public range. Legacy reasons. Perhaps a routing issue?
> ...
Florian Apolloner
06:26 AM Bug #4686: Rekeyed SAs are not properly removed
Florian Apolloner wrote:
> I am getting weird behaviour on some IPSec connections since 2.2.2. It looks as if CHILD_...
Ivo B
10:30 AM Bug #4607 (Feedback): Bridge+CARP crashes/freezes pfSense
Patches committed to solve this. Ermal Luçi
08:57 AM Bug #4711 (Rejected): DHCP static mapping DNS servers do not override correctly
Duplicate of #3915
It's a bug in ISC DHCP server, not our code. Supposedly will be fixed in a newer version of the...
Jim Pingle
08:49 AM Bug #4711 (Rejected): DHCP static mapping DNS servers do not override correctly
1) On the DHCP Server page, enter 4 different DNS Servers. Make sure the first one is the pfSense LAN interface. Fo... Jeremy  99

05/17/2015

04:07 PM Bug #4702 (Feedback): kernel panic with AES-NI
PAtches committed. Ermal Luçi
10:16 AM Bug #4710 (Duplicate): System Log - Firewall Fails to 'Click to Resolve' for IPv6 Addresses
When looking through Firewall Logs, I can resolve IPv4 addresses, but IPv6 will not resolve.
Love this feature, W...
Marc Riley
08:22 AM Bug #4708: LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
Okay, that link makes sense, so is there a way to Stop Logging these packets that arrive after the connection has bee... Marc Riley
02:46 AM Feature #4542: Support for PPPoE with MTU/MRU > 1492 (i.e. 1500)
A bounty has been started.
h1. Link
* https://forum.pfsense.org/index.php?topic=93902.0
Greg B
02:31 AM Bug #4709 (Resolved): Correct "State Killing on Gateway Failure" description
In Advanced/Miscellaneous/Gateway Monitoring it says:
"The monitoring process will flush states for a gateway that...
Duncan Sands

05/16/2015

09:28 PM Bug #4708: LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
[[https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection]] Phillip Davis
03:44 PM Bug #4708 (Not a Bug): LAN Firewall Blocking 443 out on Default deny rule IPv4 (IPv6 Enabled Router)
I'm using pfSense 2.2.2-RELEASE (amd64), and have configured IPv6 through a tunnel broker. Everything is working fin... Marc Riley
07:05 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
and part 2:
@May 17 02:57:00 charon: 06[ENC] <con4|18> 48: 07 00 00 10 00 00 FF FF 0A 0E 43 00 0A 0E 43 FF ............
Roman H
07:04 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Here it comes, with "Highest" settings, without Unity.
@May 17 02:57:01 charon: 01[JOB] next event in 2s 621ms, wait...
Roman H
07:02 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Hmmm. Can't post somewhy.
This is test only
Roman H
02:55 PM Revision d98a2e6a: Remove artifacts from latin1 to utf8 conversions
String replacement:
s/Ermal L.../Ermal Luçi/g
Jose Luis Duran
09:51 AM Feature #4707 (New): Can't override block port 0 rules in filter.inc

Sometimes legitimate traffic is blocked by the default/quick rules in filter.inc. However, these cannot be overridd...
Andrew -
09:49 AM Bug #4673: Can't override rules in filter.inc from the GUI
OK. I'll re-post as a feature request. Either way you should be able to override these rules from the GUI should you... Andrew -
05:16 AM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
Well, it still hangs here exactly the same as ever. I tried _pfctl -d_ before running this and it did not help in any... Kill Bill
04:55 AM Todo #4706 (Resolved): MPD needs to be upgraded to version 5 even for the various other tunnels
MPD 4 is still being used for PPPoE/PPtP/L2TP... it needs to converted for those protocols to MPD5 Ermal Luçi
12:14 AM Revision b96d6738: create /var/spool/lock on nano so tip works without hassles. Ticket #4532
Chris Buechler
12:13 AM Revision d71cded0: create /var/spool/lock on nano so tip works without hassles. Ticket #4532
Chris Buechler

05/15/2015

08:44 PM Feature #3325 (Closed): MTU Option for PPTP VPN
PPTP is dead Chris Buechler
08:42 PM Bug #3069 (Feedback): traceroute6 fails to timeout and hangs the webconfigurator GUI
this doesn't seem to be an issue in 2.2.x Chris Buechler
08:42 PM Bug #3063 (Closed): system will crash after "PowerD" enabled.
not likely this is still a problem in 2.2x versions, with FreeBSD 10.1. if it is, it needs to be reported upstream Chris Buechler
08:39 PM Bug #2734 (Closed): Mobile IPsec AES128 fails with glxsb on Alix, iOS client
this definitely works in current versions Chris Buechler
08:21 PM Feature #2152 (Needs Patch): Pass-through MAC and Vouchers
unusual case, not worth messing with. in many cases should be achievable with separate CP zones. Chris Buechler
08:18 PM Feature #1962 (Closed): disconnect specific pptpd interface from command line
PPTP is dead Chris Buechler
08:13 PM Bug #3736 (Resolved): No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
this was fixed at some point long ago Chris Buechler
07:17 PM Bug #4673 (Not a Bug): Can't override rules in filter.inc from the GUI
subject isn't a legit bug. Port 0 isn't valid, and isn't what was causing the issue in question Chris Buechler
07:16 PM Bug #4459: Tzdata is too old (needs to be updated for Russia)
is the tzdata in FreeBSD 10.1 not correct? We use stock FreeBSD tzdata. Chris Buechler
07:15 PM Bug #4700 (Duplicate): Wrong time from Russia
duplicate of #4459 Chris Buechler
07:14 PM Bug #4377 (Rejected): pfSense boot freezes after restart in QEMU/KVM
I suspect you have a QEMU/KVM config issue of some sort given that doesn't happen to anyone else that I've seen. It's... Chris Buechler
07:12 PM Bug #4532 (Resolved): /var/spool/lock Directory missing on nanobsd
only missing on nano since its /var/ is a RAM disk. I added its creation and ownership setting to rc.embedded Chris Buechler
07:02 PM Bug #4520 (Resolved): IPsec loglevel settings broken
this was fixed in 2.2.1 release (and newer) Chris Buechler
07:01 PM Bug #4494 (Needs Patch): axge bug - AX88179 chipset (network interface reseting)
not something we'll fix. Should work in 2.3 release, based on FreeBSD 10.2, and if someone wants to submit a patch to... Chris Buechler
07:00 PM Bug #4249 (Not a Bug): virtual ips backup/restore bug
no bug here Chris Buechler
06:59 PM Bug #4107 (Confirmed): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
it just needs to kick off a reboot upon completion Chris Buechler
06:54 PM Bug #4671 (Not a Bug): Add "net.inet.ip.portrange.reservedhigh" to system tunable GUI
it can be user-defined. if there is a problem with what squid references there, bring that up on the packages board o... Chris Buechler
06:52 PM Bug #4603 (Resolved): Log files used by packages are reinitialized on every boot
Chris Buechler
06:51 PM Bug #4651 (Confirmed): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
the tracker on negate rules always ends up as "1" now. Chris Buechler
05:36 PM Revision b92af7ab: Disable defering in pfsync which is used for active-active deployments not useble in FreeBSD. This should fix hangs reported on some machines wiht pfsync
Ermal Luçi
05:36 PM Revision fd07693e: Disable defering in pfsync which is used for active-active deployments not useble in FreeBSD. This should fix hangs reported on some machines wiht pfsync
Ermal Luçi
03:27 PM Bug #3996 (Needs Patch): Solarflare NIC panic with LACP
not hardware we sell, so not something we'll deal with. if someone wants to pursue, report and get it fixed in FreeBS... Chris Buechler
03:17 PM Bug #4596 (Feedback): NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
Patch submitted for 2.2.x branch will be updated for the 2.3(master) one. Ermal Luçi
02:56 PM Bug #4607: Bridge+CARP crashes/freezes pfSense
Still an issue after recent related changes. One clarification - it only happens when hosts are using the CARP IP as ... Chris Buechler
02:44 PM Bug #4705 (Confirmed): Language selection is not functional
Jim Pingle
08:24 AM Bug #4705 (Resolved): Language selection is not functional
Selecting a different language under *System > General Setup* has no effect. Selecting an alternate language and then... Jim Pingle
02:43 PM Bug #4633 (Resolved): CARP not enabled upon creation of first CARP IP
fixed Chris Buechler
01:47 PM Bug #4310: Limiters + HA results in hangs on secondary
Patch was committed for this on tools repo and also the defer option in pfsync is now not used.
Both can be consider...
Ermal Luçi
12:31 PM Bug #4623: Carp not working under bhyve
Did you try from the GUI since carp should not differ from FreeBSD at least in this regard! Ermal Luçi
12:02 PM Revision f8ac4407: Code style WWW pkg
The syntax of these all seems good. Because the 2.3-DEVELOPMENT master
does not currently have get_pkg_info implement...
Phil Davis
11:02 AM Revision 83c380c3: Merge pull request #1660 from phil-davis/www-status-rrd
Renato Botelho
10:57 AM Revision 38145b9b: Remove excess tabs status_rrd_graph
Phil Davis
10:57 AM Revision 0922c015: Merge pull request #1659 from phil-davis/www-status
Renato Botelho
10:42 AM Revision 45e96815: Use correct variable to fix pagination
Renato Botelho
10:42 AM Revision 5402c8fc: Fix startingat var name typo in pkp.php
Even with this fix, the code does not make sense. The first test is:
if ($startingat > -1)
if it gets into the else,...
Phil Davis
10:41 AM Revision e7a9ad78: Use correct variable to fix pagination
Renato Botelho
10:40 AM Revision 119213c4: Merge pull request #1661 from phil-davis/patch-1
Renato Botelho
07:38 AM Bug #4424: Adding and removing shaper repeatedly causing interface crash
I frequently see this bug as well.
A reliable work-around I use is to first Disable/Uncheck & Apply then finally "...
Ben Cook
07:12 AM Revision a5d6bf80: Fix startingat var name typo in pkp.php
Even with this fix, the code does not make sense. The first test is:
if ($startingat > -1)
if it gets into the else,...
Phil Davis
06:27 AM Revision f1df36e5: Code style WWW Status RRD
Phil Davis
05:55 AM Revision 42b0c921: Code style WWW Status
Phil Davis
03:42 AM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Louis-Philippe Allard wrote:
> SO I assume squid's package in pfsense is WAYYY old?
Yeah, when you install Squid ...
Kill Bill
02:22 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Can you increase the debug level and send me the log.
I want to see what the ASA side is sending as matching traffic...
Ermal Luçi
12:11 AM Revision 83e0a56a: services_dhcp_edit.php Conversion complete
Ready for review sbeaver

05/14/2015

11:39 PM Revision f037eeb7: Fixed MAC address calculation
sbeaver
10:32 PM Revision af664996: Remove the "insert my MAC" feature from interfaces.php. It hasn't worked in a while (credit sbeaver for noticing), and the only thing it tends to accomplish is breaking people's connectivity from the system where they end up duplicating the MAC of their local system.
Conflicts:
usr/local/www/interfaces.php
Chris Buechler
10:30 PM Revision c8f1c7bd: Remove the "insert my MAC" feature from interfaces.php. It hasn't worked in a while (credit sbeaver for noticing), and the only thing it tends to accomplish is breaking people's connectivity from the system where they end up duplicating the MAC of their local system.
Chris Buechler
07:03 PM Revision c58879a9: Add some error checking to avoid warning during boot
Ermal Luçi
07:03 PM Revision 380ae020: Add some error checking to avoid warning during boot
Ermal Luçi
06:52 PM Revision 5f17dff7: services_captiveportal_vouchers_edit.php Conversion complete
Ready for review sbeaver
05:46 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
I posted on squid's maillist and their answer was:
"The Ubuntu problem is a combination of pacage manager assuming...
Anonymous
02:43 PM Revision 429112ac: Move pt_BR translation from ISO to UTF-8
Renato Botelho
02:39 PM Revision 75625610: Remove unneeded hidden input
sbeaver
02:38 PM Revision 20c87211: Revert "Remove unneeded hidden input"
This reverts commit 0e40f0f1d9d95e997430ec0a00a305a3cf3a5943. sbeaver
02:36 PM Revision 0e40f0f1: Remove unneeded hidden input
sbeaver
02:35 PM Revision af64370b: Move pt_BR directory, it's moving from ISO to UTF-8
Renato Botelho
02:34 PM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Package 1.0.3 contains the fix Renato Botelho
12:45 PM pfSense Packages Bug #4304 (Feedback): pfflowd non-functional on 2.2.x versions
Fix committed need to try with new binaries. Ermal Luçi
08:37 AM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Can we please get this fixed soon. Jeremy Porter
02:04 PM Revision 075dc8b7: services_captiveportal_mac_edit.php Conversion complete
Ready for review sbeaver
12:27 PM Revision 3dde9235: services_captiveportal_mac.php Conversion complete
Ready for review sbeaver
11:53 AM Revision 448161ba: Add some curlies in status_rrd_graph_img
These "if data" tests look like they should apply to all 4 lines below them.
After sorting out this real-looking issu...
Phil Davis
11:51 AM Revision 861f0124: Merge pull request #1658 from phil-davis/patch-4
Renato Botelho
11:50 AM Revision db7d66e7: Cleanup code logic status_upnp
1) Variable $i is was set, incremented and not used.
2) "if preg_match" at line 94 had no curlies after it, so it was...
Phil Davis
11:50 AM Revision 1ab739c7: Merge pull request #1657 from phil-davis/patch-3
Renato Botelho
11:49 AM Revision e240d261: Merge pull request #1656 from phil-davis/patch-2
Renato Botelho
11:48 AM Revision 8119bdb3: Merge pull request #1655 from phil-davis/patch-1
Renato Botelho
11:44 AM Revision 34f3165b: Fix alias rename and delete bug #4701
The old advancedoutbound key in config.xml is now called outbound. Phil Davis
11:31 AM Revision c364b1e6: Merge pull request #1654 from phil-davis/nat-outbound-fix
Renato Botelho
11:04 AM Revision fa201d63: Add some curlies in status_rrd_graph_img
These "if data" tests look like they should apply to all 4 lines below them.
After sorting out this real-looking issu...
Phil Davis
06:43 AM Bug #4701: WebGUI alias name changes does not reflect in NAT-Outbound
Pull request has been merged Renato Botelho
06:33 AM Revision 037d118f: Cleanup code logic status_upnp
1) Variable $i is was set, incremented and not used.
2) "if preg_match" at line 94 had no curlies after it, so it was...
Phil Davis
05:50 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Dont be confused by :
May 14 13:42:48 charon: 10[CFG] <con4|7> config: 10.9.73.0/24|/0, received: 10.9.73.0/24|/0 ...
Roman H
05:47 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Ermal Luçi wrote:
> Can you also put the logs of the exchange from pfSense.
>
> Can you also please test by disab...
Roman H
05:29 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Can you also put the logs of the exchange from pfSense.
Can you also please test by disabling the unity plugin and...
Ermal Luçi
04:01 AM Bug #4704 (Resolved): IKEv2 to Cisco ASA won't bring up multiple P2 networks
Setup is following:
pFsense firewall - have subnet 192.168.23.0/24 subnet, where host itself have 192.168.23.55
...
Roman H
05:17 AM Revision b1f56807: Remove unused nentries from status_lb_pool
Phil Davis
04:16 AM Revision 1bc6fa03: Remove unused var from status_gateways.php
I cannot see where "counter" is used. Phil Davis
12:57 AM Revision 682b8f12: Fix alias rename and delete bug #4701
The old advancedoutbound key in config.xml is now called outbound. Phil Davis

05/13/2015

10:06 PM Revision 68ceb463: services_captiveportal_ip_edit.php Conversion completes
Ready for review sbeaver
09:20 PM Bug #4701 (Feedback): WebGUI alias name changes does not reflect in NAT-Outbound
thanks Phil.
the second issue I thought had another ticket, but not seeing it at the moment.
Chris Buechler
07:56 PM Bug #4701: WebGUI alias name changes does not reflect in NAT-Outbound
This fixes number 1:
https://github.com/pfsense/pfsense/pull/1654
The key in the config changed from "advancedoutbo...
Phillip Davis
07:26 AM Bug #4701 (Resolved): WebGUI alias name changes does not reflect in NAT-Outbound
Just found two little bugs in the WEBgui:
Changing the name of an existing alias in "Firewall: Alias" will also ch...
Willy Tenner
08:27 PM Revision ef548f98: services_captiveportal_ip.php Conversion complete
Ready for review sbeaver
08:00 PM Revision 62f82bbd: Removed debug line
sbeaver
07:56 PM Revision 148c59ee: services_captiveportal_hostname_edit Conversion complete
Ready for review sbeaver
07:54 PM Revision 440e8604: Revert "services_captiveportal_hostname_edit.php Conversion complete"
This reverts commit 8d66660a6869d33a3c9a34fa4bc8c5a9fed5a9bf. sbeaver
07:52 PM Revision 8d66660a: services_captiveportal_hostname_edit.php Conversion complete
Ready for review sbeaver
07:04 PM Revision 54f8c617: Fixed indent
sbeaver
06:59 PM Revision cbdd2dd3: services_captiveportal_hostname.php Conversion complete
Ready for review sbeaver
06:17 PM Revision 10439116: ipsec: psk keyid bugfix
IPsec/IKEv2 PSK currently generates an invalid strongswan ipsec.conf file.
The local IKE ID is not inserted correctly...
Bruno Thomsen
05:48 PM Bug #4703 (Closed): Inconsistent availability of direction on CP IP/MAC/hostname passthrough
CP MAC and IP passthrough used to have a direction (in/out/both) on each entry, which is potentially useful in a vari... Chris Buechler
05:22 PM Revision 01cced78: Delete load_balancer_relay*.php, they are not being used
Renato Botelho
05:16 PM Revision 9eeaf458: Merge pull request #1653 from phil-davis/lb-work
Renato Botelho
05:14 PM Revision 4040b302: Merge pull request #1651 from phil-davis/interfaces-other
Renato Botelho
05:13 PM Revision 62a9a5d0: Merge pull request #1650 from phil-davis/interfaces-php
Renato Botelho
05:12 PM Revision caa7230e: Slash-select should be inside if in load_balancer_pool_edit
otherwise there is an unbalanced slash-select when the else happens (if there are no load-balancer monitors defined) Phil Davis
05:11 PM Revision 101258eb: Merge pull request #1652 from phil-davis/patch-1
Renato Botelho
04:50 PM Revision 0d102fcd: ipsec: added ecc brainpool to vpn_ipsec_convert_to_modp()
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com> Bruno Thomsen
04:47 PM Revision 58453574: services_captieveportal_filemanager.php Conversion complete
Ready for review sbeaver
03:27 PM Bug #4689 (Feedback): Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0"
Merged patch. Ermal Luçi
12:57 PM Bug #4702 (Resolved): kernel panic with AES-NI
Crash dump attached. Not reliably replicable on the system this came from, but this is similar to what a few others h... Chris Buechler
12:18 PM Revision b45e428c: No need to deal with hw.usb.no_pf anymore, it's part of default loader.conf
Renato Botelho
12:06 PM Revision 421b5e1c: services_captiveportal_zones_edit.php Conversion complete
Ready for review sbeaver
10:51 AM Revision 0162f9a1: Code style Load Balancer
Phil Davis
09:42 AM Revision 68962573: Slash-select should be inside if in load_balancer_pool_edit
otherwise there is an unbalanced slash-select when the else happens (if there are no load-balancer monitors defined) Phil Davis
07:21 AM Revision 2af86dda: Code style interfaces miscellaneous files
Phil Davis
07:12 AM Revision 1caf2209: Code style interfaces.php
Phil Davis

05/12/2015

11:11 PM Revision 6f667945: Remove debug statement
sbeaver
11:00 PM Revision 6e979933: pkg_mgr_settings Conversion complete
Ready for review sbeaver
09:15 PM Revision b8e6729f: ipsec: pfs ecc brainpool curve support
Use brainpool curves as perfect forward security.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
09:11 PM Revision 3922114b: ipsec: pfs ecc nist curve support
Use nist curves as perfect forward security.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
08:44 PM Revision c55ec98a: ipsec: IKEv2 Diffie-Hellman ECC Brainpool support
Use of ECC Brainpool curves for IKEv2 is define in RFC6954.
Signed-off-by: Bruno Thomsen <bruno.thomsen@gmail.com>
Bruno Thomsen
08:10 PM Revision 7b826864: ipsec: IKE phase one AES-GCM support
Use of Galois/Counter Mode (GCM) during IKE phase-1 is defined in RFC4106.
Signed-off-by: Bruno Thomsen <bruno.thoms...
Bruno Thomsen
07:53 PM Revision 50ed1824: bugfix: ipsec: nist ecp521 elliptic curve support
There was a small typo the vpn_ipsec_convert_to_modp() function.
Bug introduced in commit 7a747654e9ef5b4cec7184c770...
Bruno Thomsen
07:50 PM Revision cfe5eeab: load_balancer_setting.php Conversion complete
Ready for review sbeaver
07:17 PM Revision 09d2448a: interfaces_wireless_edit.php Conversion complete
Ready for review sbeaver
03:32 PM Bug #4686: Rekeyed SAs are not properly removed
After looking at patch-ipsec_nat.diff in the pfsense-tools repo, does this patch do anything aside from making the st... Florian Apolloner
02:53 PM Bug #4686: Rekeyed SAs are not properly removed
So upstream says, that you are using a somewhat invalid syntax for leftsubnet (I have binat selected), might that be ... Florian Apolloner
01:17 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
For those who would like to test a version of choparp including Ermal's fixes, following this procedure:
1. Stop t...
Jim Pingle
12:49 PM Bug #4685 (Feedback): Crash/panic "Sleeping thread owns a non-sleepable lock"
choparp was blocking on bpf mutex and making full buffers on BPF and panicing due to context of ISR routines on drivers. Ermal Luçi
06:33 AM Bug #4700 (Duplicate): Wrong time from Russia
see #4459 (this task is double), and https://forum.pfsense.org/index.php?topic=93757.0
Menu -> Diagnostics -> Comm...
Victor Danilkin
02:21 AM Bug #4699 (Not a Bug): IPsec panic with MSS clamping
This is reported here https://forum.pfsense.org/index.php?topic=93742.0 and is not always reproducible.
Normally t...
Ermal Luçi
12:51 AM Revision e568873f: license.php Conversion complete
Converted spaces to tabs, corrected indenting, added missing </p>,
added panel divs, corrected missing spaces in copy...
sbeaver
12:26 AM Bug #3205: Partial system freeze when disconnecting USB 3G stick
ys seems fixed Bipin Chandra

05/11/2015

09:52 PM Bug #4696: OpenVPN Status / Client List
Hi,
I admit, not sure ... ;). The issue is that Load Balancer is showing an incorrect status for OpenVPN, when I a...
Russell Morris
01:24 PM Bug #4696 (Feedback): OpenVPN Status / Client List
what does load balancer have to do with your OpenVPN? Chris Buechler
09:51 PM Bug #4694: Load Balancing Failing
NP, will dig into it further. Unfortunately it has been working fine for 6-8 months, only stopped working when I upgr... Russell Morris
12:41 PM Bug #4694 (Not a Bug): Load Balancing Failing
there are no such general issues, this is a config or testing methodology issue. please use one of our support resour... Chris Buechler
08:44 PM Bug #4208 (Resolved): P1 rekeying with IKEv1 failing with no proposal chosen / invalid ID info
this was fixed in strongswan 5.3.0 Chris Buechler
08:38 PM Bug #3205: Partial system freeze when disconnecting USB 3G stick
I suspect this is probably fixed in 2.2x versions because of FreeBSD 10.1 base. Anyone who was seeing this able to co... Chris Buechler
08:36 PM Bug #1421 (Needs Patch): Disconnecting PPTP VPNs drops IPsec when using wrong PPTP server IP
I suspect this isn't an issue with strongswan in the way it was with racoon. Also not concerned with PPTP anything at... Chris Buechler
08:33 PM Bug #2803 (Resolved): igmp version reset
the linked thread in Vasyl's comment has the solution on 8.1, and 10.x doesn't appear to have same issue. Chris Buechler
08:29 PM Bug #2990 (Not a Bug): Clarify wording of services_dnsmasq.php and move its Webconfigurator node
all the settings are specific to the service on whose page you're configuring them, and they can operate independentl... Chris Buechler
08:26 PM Bug #2650 (Closed): FTP helper breaks TCP sequence numbers on 2nd WAN
FTP helper in question no longer exists. Chris Buechler
08:21 PM Revision 922bf65c: interfaces_lagg_edit Conversion complete
Ready for review sbeaver
08:18 PM pfSense Packages Feature #4489 (Needs Patch): Add Varnish 4 Plugin
Chris Buechler
08:14 PM Bug #4670 (Not a Bug): pkg - ELF interpreter /libexec/ld-elf.so.1 not found
Chris Buechler
07:22 PM Revision 13393817: interfaces_gre_edit.php Conversion complete
Ready for review sbeaver
07:13 PM Revision c1c09523: Corrected input name
sbeaver
07:03 PM Revision 2686a780: interfces_gif_edit.php Conversion complete
Ready for review sbeaver
04:43 PM Revision c8f7068d: Merge pull request #1648 from phil-davis/floating-tab
Renato Botelho
04:12 PM Revision 0c469044: Handle extra column on floating rules tab
when there are no floating rules to display.
The box needs to span 11 columns.
Phil Davis
03:43 PM Revision a9741c0c: Merge pull request #1646 from phil-davis/firewall-rules
Renato Botelho
03:34 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Reports from customers indicate that crashes still occur even with net.bpf.zerocopy_enable=0
and net.isr.dispatch=de...
Jim Pingle
03:23 PM Revision 7a2cb2f2: Merge with master
Phil Davis
02:57 PM Revision fa61d033: Merge pull request #1647 from phil-davis/firewall-shaper
Renato Botelho
02:49 PM Revision 6aaec445: Code style firewall shaper
Phil Davis
02:36 PM Revision 7bf0ce52: fixed indent according to the style guide.
Berger Alexander
02:36 PM Revision 32749275: Currently pfsense enforces unique unqualified hostnames for static dhcp leases, which is not correct as only the fully qualified hostname (hostname + domainname) must be unique. With this commit the old validation logic for uniqeness is modified such that hostnames no longer need to be unique and at the same time the fully qualified hostname hast to be unique.
This change makes it possible to have host with identical hostnames in different (sub)domains. For example myhost.sal... Berger Alexander
02:36 PM Revision 8efea69a: Merge pull request #1637 from alex-berger/dhcp-staticleases-unique-check
Renato Botelho
01:27 PM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
the squid users mailing list is probably your best bet to start. Chris Buechler
01:16 PM Revision 250f6436: Merge pull request #1616 from Robert-Nelson/floating-interfaces
Renato Botelho
01:10 PM Revision 603d3c16: Code style Firewall Rules
Phil Davis
01:06 PM Feature #4697 (Closed): Load Balancing by Hostname
the built-in load balancer relayd doesn't have that ability. haproxy is available for those who need it. Chris Buechler
01:04 PM Bug #4693 (Duplicate): php warning when applying changes after change Resolver service|Access List
Chris Buechler
12:51 PM Bug #4686: Rekeyed SAs are not properly removed
The many phase 2 entries might be a result of: https://wiki.strongswan.org/issues/951 Florian Apolloner
12:42 PM Bug #4592 (Resolved): FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
thanks for confirming. Chris Buechler
12:40 PM Revision efd081de: Merge pull request #1645 from phil-davis/wizard
Renato Botelho
12:39 PM Revision a4042967: Merge pull request #1644 from phil-davis/firewall-virtual-ip
Renato Botelho
12:38 PM Revision 2fa098a0: Merge pull request #1643 from phil-davis/firewall-schedule
Renato Botelho
12:36 PM Revision 3be6106f: Merge pull request #1642 from phil-davis/firewall-nat
Renato Botelho
12:34 PM Revision 58c8900e: Merge pull request #1641 from phil-davis/firewall-aliases
Renato Botelho
12:33 PM Revision 1c0b7c8a: Merge pull request #1640 from phil-davis/patch-2
Renato Botelho
12:31 PM Revision 55395a83: Firewall Rules Edit missing slash
This should be the end of a "tr" here.
Browsers seem to be forgiving of this stuff - I don't see any difference in re...
Phil Davis
12:31 PM Revision 047c8758: Merge pull request #1639 from phil-davis/patch-1
Renato Botelho
12:09 PM Revision c00152f3: diag_ipsec_leases.php Conversion complete
Ready for review sbeaver
12:03 PM Revision ae36a9e5: diag_ipsec_spd conversion complete
Ready for review sbeaver
09:55 AM Bug #4698 (Resolved): XSS in system_authservers.php
Reported by Nicholas Starke:
> I found an XSS vulnerability in PFSense 2.2.2. Here are my notes on the vuln:
>
...
Jim Pingle
08:37 AM Revision f566451e: Code style Wizard
Phil Davis
06:43 AM Revision 760b1df9: Code style Firewall VIP
Phil Davis
06:32 AM Revision a4edef21: fixed indent according to the style guide.
Berger Alexander
06:27 AM Revision bedc00c8: Code style Firewall Schedule
Phil Davis
06:21 AM Revision 37ba954d: Code style Firewall NAT
Phil Davis
06:07 AM Revision 95a40ac0: Code style firewall_aliases
Phil Davis
03:22 AM Revision accb5756: Minor changes to firewall_shaper_layer7
The tabbing of this code is not so good, so it is difficult to see what is going on. I will format that in a later pu... Phil Davis
03:17 AM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
Hello
as advised in the forum : https://forum.pfsense.org/index.php?topic=88441.0
I have uninstalled pfflowd pac...
Didier Richard

05/10/2015

07:29 PM Bug #4592: FreeBSD 10.1-RELEASE-p6 signal handling problems with squid (FreeBSD bug 195802)
Just did a firmware update to the latest 2.2.3 snapshot and shutdown works. Looking forward to the full 2.2.3 release. Christopher Taylor
06:09 PM Bug #4431: Bandwidth not reported correctly in "Status: Traffic shaper: Queues"
I'm seeing this also. Screenshot attached. I'm running 2.2.2 Andre LaBranche
05:27 PM Feature #4697 (Closed): Load Balancing by Hostname
Hi,
It would be handy to be able to Load Balance by hostname, not only by hard-coded IP Address.
Thanks!
Russell Morris
05:26 PM Bug #4696 (Not a Bug): OpenVPN Status / Client List
Hi,
More info at the attached link, but basically - when OpenVPN is up and running, if I am connected to it Load B...
Russell Morris
05:24 PM Bug #4695 (Not a Bug): TAP (OpenVPN) Traffic Blocked
Hi,
More details at the attached link, but basically ... in v2.2.2 I can't seem to get traffic from OpenVPN (TAP c...
Russell Morris
05:20 PM Bug #4694 (Not a Bug): Load Balancing Failing
Hi,
I have been struggling to figure this out (and no luck so far) ... but in v2.2.2 I seem to be having issues wi...
Russell Morris
04:41 PM Revision e9a88707: Firewall Rules Edit missing slash
This should be the end of a "tr" here.
Browsers seem to be forgiving of this stuff - I don't see any difference in re...
Phil Davis
11:59 AM Revision 69f65caf: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
11:41 AM Revision 38e06c66: Support new Form('text') too, convert existing custom buttons
+ fix html @system_firmware Sjon Hortensius
11:40 AM Revision 6135e79f: Convert diag_dump_states_sources
Sjon Hortensius
10:56 AM Revision 9f10fa7b: PROGRESS.md updated, removed windows enters from script
Sjon Hortensius
10:49 AM Revision 256f418c: Minor tweaks, hellip in interf_gif, typo in rss.widget
plus rewrote traffic_graphs.widget to new format Sjon Hortensius
10:32 AM Revision 3fadcdfe: Merge pull request #191 from Bouwdie/services_dhcpv6_relay
Converted services_dhcpv6_relay SjonHortensius
10:30 AM Revision 31f048d4: Merge pull request #190 from Bouwdie/services_dhcp_relay
Re-introduced incidentally removed interface filter. SjonHortensius
10:29 AM Revision e49ce81d: Added panel-body
The ... sbeaver
10:29 AM Revision ea02edef: diag_logs.vpn.php Conversion complete
Ready for review.
In guiconfig.inc dump_clog_no_tables() now returns the number of log
lines printed allowing for an...
sbeaver

05/09/2015

01:31 PM Revision dbf6bf9f: Re-introduced incidentally removed interface filter.
Peter Bouwdewijn
01:26 PM Revision 5caa70ec: Revert "Re-introduced incidentally removed interface filter."
This reverts commit e3d953d5f4eac06672d1331c6ff9fe88f88a3c51. Peter Bouwdewijn
01:19 PM Revision e3d953d5: Re-introduced incidentally removed interface filter.
Peter Bouwdewijn
01:13 PM Revision bb466f49: Copied util functions from services_dhcp_relay.php.
Migrated to form class. Peter Bouwdewijn
01:00 PM Revision f0a108f2: Append button to control group instead of control label
Refs. #142 Sander van Leeuwen
12:35 PM Revision 916a2d71: Clean.sh
Peter Bouwdewijn
12:15 PM Revision ead9fa43: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
12:01 PM Revision 52d7947c: Implemented new MultiCheckbox feature, refs #142
Sjon Hortensius
11:58 AM Revision 85033097: Form - introduce MultiCheckbox(+Group) #142
Sjon Hortensius
11:38 AM Revision d390bbf7: Minor edits per SH
Thanks! sbeaver
11:32 AM Revision 458a6879: Minor edits as suggested
Thanks sbeaver
10:42 AM Revision b148c54a: Make consistent #183
Sjon Hortensius
10:40 AM Revision 1332ace6: interface_gre.php Conversion complete
Ready for review sbeaver
10:37 AM Revision 5ff01d01: Oops, move NAV to correct location #184
Sjon Hortensius
10:36 AM Revision c8610c74: Make consistent #182
Sjon Hortensius
10:33 AM Revision 6a2a3416: interface_gif.php Conversion complete
Ready for review sbeaver
10:31 AM Revision 719da9a2: fixed typo, correct $tab_array in interfaces_groups.php #184
Sjon Hortensius
10:30 AM Revision e41d7a1c: cleanup interfaces_groups.php
Sjon Hortensius
10:26 AM Revision 2ec0d736: interfaces_groups.php Conversion complete
Page updated for compatibility with the other interface_* pages sbeaver
10:21 AM Revision 174722ac: diag_patterns.pgp Conversion complete
Ready for review.
Note: The “Browse” button has some alignment issues that should be
addressed.
sbeaver
10:09 AM Revision 0074384f: guiconfig.inc updated
dump_clog_no_table() now returns the number of log lines printed so
that the caller can display a message if there we...
sbeaver
09:59 AM Revision f849a29f: diag_logs_filter_dynamic.php conversion complete
Ready for review
Table can be popularized both on initial load and at timed intervals,
hence the button needed to be...
sbeaver
09:44 AM Revision cb77470a: Put something usefull in placeholder for Filter expression
Sjon Hortensius
09:40 AM Revision f2731e42: Merge pull request #172 from sbeaver-netgate/diag_logs_filter_summary
Convert diag_logs_filter_summary SjonHortensius
09:33 AM Revision fe0d6189: Merge pull request #165 from Bouwdie/services_dhcp_relay
Covnert services_dhcp_relay + bugfix in IpAddress SjonHortensius
09:31 AM Revision 1c306cd0: If a btn-danger has a title, use that instead of generic for confirm()
Sjon Hortensius
09:30 AM Revision 6717d1fc: simplify xhr delete button
Sjon Hortensius
09:12 AM Revision 645086f8: Merge pull request #155 from sbeaver-netgate/diag_dump_states
Convert diag_dump_states.php SjonHortensius
08:48 AM Revision cbda5c13: Merge pull request #162 from sbeaver-netgate/system_hasync
Converted system_hasync SjonHortensius
08:34 AM Revision 0ea606c9: Merge pull request #151 from sbeaver-netgate/status_rrd_graph_settings
Converted status_rrd_graph_settings.php SjonHortensius
08:28 AM Bug #4693: php warning when applying changes after change Resolver service|Access List
This was already reported at least 3 times and fixed almost 1 month ago...
https://redmine.pfsense.org/projects/pf...
Kill Bill
06:54 AM Bug #4693: php warning when applying changes after change Resolver service|Access List
Note the difference betwwen $sysdnsserver and $sys_dnsserver*s* Alvaro Sedano
06:48 AM Bug #4693 (Duplicate): php warning when applying changes after change Resolver service|Access List
php warning when applying changes after change Resolver service|Access List
The php warning is:
"Warning: in_ar...
Alvaro Sedano
05:32 AM pfSense Packages Bug #4690: Squid cache needs to be flushed periodically or package managers on LAN clients wont work
Chris, thanks for the response. YOu suggest to follow up with the responsible parties (I assume squid's devs) but d... Anonymous

05/08/2015

11:23 PM Bug #4602 (Not a Bug): Captive Portal pfSense 2.2 not working as before when used with CARP
this is a configuration that never should have worked, would have never worked reliably in a variety of possible fail... Chris Buechler
11:19 PM pfSense Packages Bug #4690 (Rejected): Squid cache needs to be flushed periodically or package managers on LAN clients wont work
this is almost certainly a problem within squid itself, or a problem on the servers in question, none of which we hav... Chris Buechler
01:41 PM pfSense Packages Bug #4690 (Rejected): Squid cache needs to be flushed periodically or package managers on LAN clients wont work
I have experienced the same issue about 6 months ago when after having installed squid+SG I noticed that package mana... Anonymous
08:43 PM Revision 801cbbf7: Unmatched td in firewall_nat
This file seems to have an unmatched "td" ending. Adding the line here matches the "td" at line 320 and this embraces... Phil Davis
08:43 PM Revision ca9a4e2b: Call clear_subsystem_dirty('staticmaps') if using Unbound
Robert Nelson
08:43 PM Revision d0c28e66: Merge pull request #1635 from Robert-Nelson/staticmap-bug
Renato Botelho
08:40 PM Revision 897a4c6b: Merge pull request #1636 from phil-davis/patch-1
Renato Botelho
07:50 PM Bug #4692: CODELQ scheduler defaults to incorrect "target" and "interval" values.
My apologies if this patch is incorrect or causes a fire. I figured I would try. It modifies pfsense-tools/patches/st... Ben Cook
06:19 PM Bug #4692: CODELQ scheduler defaults to incorrect "target" and "interval" values.
Perhaps it is obvious, but it looks like the calls to "@codel_alloc(100, 5, 0);@" in one/all of the "altq_codel.diff"... Ben Cook
05:38 PM Bug #4692 (Resolved): CODELQ scheduler defaults to incorrect "target" and "interval" values.
If I setup CODELQ as my WAN's queue scheduler, when I run "@pfctl -vsq | grep -i codel@" the returned string is "@alt... Ben Cook
07:25 PM Revision fa6cb13a: Remove 'form-control' class from file inputs
Refs. #180 Sander van Leeuwen
04:18 PM Revision 3ba1e728: Keep verify_all_package_servers() and check_package_server_ssl() around until GUI is finished
Renato Botelho
04:17 PM Revision e6b4c39d: Fix syntax
Renato Botelho
04:10 PM Bug #4682 (Resolved): invalid return payload crash on primary on filter reload
Chris Buechler
03:47 PM Revision 5b275f2d: xmlrpc is not being used anymore
Renato Botelho
03:46 PM Revision 481aa701: diag_logs_filter_summary improved per SH
Thanks for the suggestion. Can’t believe I didn’t see that :( sbeaver
03:42 PM Revision e0d24d88: Keep get_pkg_id() around since a couple of packages are using them
Renato Botelho
03:27 PM Revision b7e9afc0: Escape entire command to avoid breaking parameters
Renato Botelho
03:26 PM Revision dfa9759a: ASSUME_ALWAYS_YES is boolean
Renato Botelho
03:23 PM Revision 7a643e58: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
03:03 PM Revision d78c4a27: Install regular git-lite package
Renato Botelho
01:58 PM Revision 50ec85d6: Merge pull request #161 from sbeaver-netgate/diag_logs
diag_logs - Added warning for DHCP SjonHortensius
12:28 PM Bug #4689 (Resolved): Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0"
Exact cause yet unknown, but a panic can be triggered with the above condition. It appears to be a "FreeBSD bug":http... Jim Pingle
08:27 AM Bug #4103: Xen xn NICs can't tag VLANs
Hello Chris,
I've read many reports about this issue and this one is the best by far. But I still think the proble...
Eduardo Stelmaszczyk
06:06 AM Feature #4688 (New): Missing TFC Traffic Flow Confidentiality support
Got a IPSEC IKEv2 Tunnel up and running where a linux client connects to the pfsense 2.2.2 server. When connecting i ... Lars Pedersen
05:07 AM Bug #4686: Rekeyed SAs are not properly removed
Yeh, you might be right. I will leave it for more knowledgeable persons to comment further. Phillip Davis
01:48 AM Bug #4686: Rekeyed SAs are not properly removed
From the looks of it this should only affect connections with multiple P2 entries defined, no? I am having a single s... Florian Apolloner
03:55 AM Bug #2762: PF drops IPv6 packets with fragment header followed by a last fragment only
What is the time frame for fixing this? I was hit by this bug now by adding dnssec NSEC3 to my DNS which enlarged th... Klaus Steinberger
 

Also available in: Atom