Project

General

Profile

Activity

From 05/20/2015 to 06/18/2015

06/18/2015

08:50 PM Bug #4775 (Resolved): Add frag limit control to the GUI
works Chris Buechler
09:33 AM Bug #4775 (Feedback): Add frag limit control to the GUI
Jim Pingle
08:26 AM Bug #4775 (Resolved): Add frag limit control to the GUI
By default pf uses a frag limit of 5000. Several customers and users have reported hitting that limit on 2.2+ resulti... Jim Pingle
06:28 PM Bug #4774 (Resolved): hostid missing +x
fixed Chris Buechler
12:26 AM Bug #4774 (Resolved): hostid missing +x
this should be fixed already. adding this to remember to test on new snapshot.
/etc/rc.d/hostid was missing +x, w...
Chris Buechler
06:25 PM Feature #4614 (Resolved): EAP-Radius support for accounting on strongswan
Chris Buechler
05:43 PM Bug #4679 (Resolved): IPsec dashboard widget wrongly shows "REKEYED" SAs as "down"
the REKEYED entries no longer exist since that separate bug was fixed, which leaves this fine. Chris Buechler
05:38 PM Bug #4705 (Confirmed): Language selection is not functional
Turkish works now, though selecting PT-br still leaves you with English. Chris Buechler
04:15 PM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
can't replicate that here either, and that code hasn't changed in quite some time. will leave for feedback for now. Chris Buechler
07:29 AM Bug #4773 (Feedback): Configuration backup - "Do not backup RRD data" is broken
The current code does unset and the code to unset has been in place for ages (3+ years). See source:"usr/local/www/di... Jim Pingle
05:49 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
Hmmm - I guess on restoring from a backup that has RRD data, the system should remove existing RRD data files, build ... Phillip Davis
03:04 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
Well, the problem apparently is this:... Kill Bill
02:48 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
2.2.3-DEVELOPMENT (amd64)
built on Sun Jun 14 19:59:54 CDT 2015
FreeBSD 10.1-RELEASE-p12
With the "do not backup...
Lars Pedersen
02:24 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
This is a full install. With the box, I get ~4 MB with huge <rrddata>; without the box, it's ~8 MB with two <rrddata>... Kill Bill
04:01 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Guessing it's because we enable certificate validation by default in 2.2.x there, and the default self-signed cert wi... Chris Buechler
02:29 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Perhaps you could post the results of this:... Kill Bill
01:54 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Let me point out that the "URL Table (IPs)" version of this test does not produce any error messages. Therefore, if i... badon _
01:40 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
It's a list of IP addresses, one IP on each line. I just tested it in a new install of 2.1.5, and it works fine there... badon _
02:29 PM Bug #4686 (Resolved): Rekeyed SAs are not properly removed
this is correct now in every circumstance I could previously replicate problems. Chris Buechler
01:33 PM Revision 55a1435e: Add a GUI field to increase the pf frag entries limit. Fixes ticket #4775
Jim Pingle
01:30 PM Revision 9e8ce1e2: Add a GUI field to increase the pf frag entries limit. Fixes ticket #4775
Jim Pingle
12:34 PM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
not the modem, what hardware are you running pfSense on, specifically what NICs but other details might help. Chris Buechler
06:54 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
The actual hardware is a BT Voyager 190 Ethernet ADSL modem with the unlocked firmware on it.
I assume that the is...
Technical Support Brendata (UK) Ltd
01:39 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
https://forum.pfsense.org/index.php?topic=41061.0
long thread but to me it seems the nic drivers is the culprit, t...
Bipin Chandra
12:06 PM Bug #4751 (Resolved): kernel panic after disabling captive portal when idle timeout is in use
fixed Chris Buechler
10:56 AM Bug #4364: cannot change or set keymap during and after install
Hello.
Just installed 2.2.2 x64 and the problema is still here.
Best regards.
Manuel Borges
05:26 AM Revision 41e9efe6: chmod +x hostid
Chris Buechler
05:26 AM Revision f6a4fe06: chmod +x hostid
Chris Buechler
12:33 AM Bug #4730 (Resolved): Firewall Log Dynamic View missing Block/Allowed Reason
fixed, thanks! Chris Buechler

06/17/2015

11:31 PM Bug #3815: Gateway monitoring broken
Tobias: if you have a 2.2.2 (or newer) config that'll replicate, I'd definitely like to check it out. Email to cmb at... Chris Buechler
10:26 PM Bug #4760 (Feedback): PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
what hardware?
the only issue along those lines I can recall in any version was some modems combined with some ol...
Chris Buechler
10:24 PM Bug #4766 (Feedback): "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
what's in some_file.txt? I'm guessing nothing, you're trying to fetch a file that doesn't exist, given it happens aft... Chris Buechler
10:11 PM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
On nanoBSD 32-bit running snap from Wed Jun 17 18:54:23 I can't replicate this. With the box checked I get an ordinar... Phillip Davis
02:32 PM Bug #4773 (Closed): Configuration backup - "Do not backup RRD data" is broken
This worked just fine before the latest batch of commits (i.e., a week ago, or even less).
- I have the "Do not ba...
Kill Bill
09:21 PM Bug #4746 (Confirmed): captive portal allowed hostnames not loaded into table at boot time
no change here. Logs show during boot: ... Chris Buechler
01:30 AM Bug #4746: captive portal allowed hostnames not loaded into table at boot time
this change could also be what completely broke CP (see #4751) Chris Buechler
07:33 PM Revision e932c350: Blacklist invalid "from" sources since they can be picked up accidentally and cause rule errors. Fixes #4772
Jim Pingle
07:32 PM Revision 2e0397e0: Blacklist invalid "from" sources since they can be picked up accidentally and cause rule errors. Fixes #4772
Jim Pingle
04:32 PM Bug #4765: NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
it works fine. keep the discussion of support issues on the forum please. I replied back there again. Chris Buechler
01:43 PM Bug #4765: NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
I don't understand the meaning of "looking for something that won't exist" considering that the rest of your comment ... Granger Godbold
12:52 PM Bug #4765 (Not a Bug): NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
replied back in your forum thread, you're looking for something that won't exist, but where the "Enable automatic out... Chris Buechler
03:35 PM Bug #4770: Packet Filter Reject IPSEC packets
Just what algorithms and what version of ipsec you are using.
Preferably send me /var/etc/ipsec/ipsec.conf and /tm...
Ermal Luçi
03:30 PM Bug #4770: Packet Filter Reject IPSEC packets
How much detail do you want? I'd rather not leak all our info onto the net. Nei Ka
03:24 PM Bug #4770: Packet Filter Reject IPSEC packets
Can you also describe your tunnel configuration here? Ermal Luçi
11:59 AM Bug #4770: Packet Filter Reject IPSEC packets
... Nei Ka
11:55 AM Bug #4770 (Feedback): Packet Filter Reject IPSEC packets
what's the rule that's blocking it? click the red X.
doubt this is a bug, probably something like Snort enabled w...
Chris Buechler
11:32 AM Bug #4770 (Resolved): Packet Filter Reject IPSEC packets
Periodically the firewall starts firewalling traffic coming through one or more IPSEC tunnels. Doing "Filter Reload" ... Nei Ka
02:40 PM Bug #4772: L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
Applied in changeset commit:e932c35017d0c5e35957e01c90dab57a0519f588. Jim Pingle
02:40 PM Bug #4772 (Feedback): L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
Applied in changeset commit:2e0397e05b6168dfcfbd04c9f3629a988744a8b2. Jim Pingle
02:28 PM Bug #4772 (Resolved): L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
If the L2TP subnet overlaps a subnet that contains a port forward target, and automatic outbound NAT for reflection i... Jim Pingle
01:37 PM Bug #4310 (Confirmed): Limiters + HA results in hangs on secondary
no change, as long as you have some traffic passing through a limiter, the secondary hangs within ~1-4 hours. Chris Buechler
01:05 PM Bug #4762: Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
I'll see if I can reproduce this, but the diag_tables showed all IP addresses (I should add that I have applied the p... Technical Support Brendata (UK) Ltd
11:53 AM Bug #4762 (Not a Bug): Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
diag_tables shows what is in the table (""in memory" alias") at the time the page is loaded. filterdns keeps that upd... Chris Buechler
02:33 AM Bug #4762: Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
Yes, sorry, diag_tables.php.
This showed all entries as being correct, however, when looking at the resolver logs ...
Technical Support Brendata (UK) Ltd
11:41 AM Bug #4771 (Duplicate): DHCP Server does not update DNS Forwarder
When the DHCP server issues an IP to a host that provides a name, that name cannot immediately be resolved by the DNS... Nei Ka
10:47 AM Feature #4769: IPv6 support in the Traffic Shaper Wizard
the created rules largely aren't IPv4/IPv6-specific, and will work for both. Chris Buechler
09:30 AM Feature #4769 (Resolved): IPv6 support in the Traffic Shaper Wizard
It would be really nice if Traffic Shaping Wizard could be set to also create IPv6 rules. Ian Grody
08:10 AM Bug #4751 (Feedback): kernel panic after disabling captive portal when idle timeout is in use
Ermal Luçi
08:10 AM Bug #4751: kernel panic after disabling captive portal when idle timeout is in use
Yep this commit broke it by showing that there might have been other issues that now are handled properly.
Next sn...
Ermal Luçi
01:20 AM Bug #4751 (Confirmed): kernel panic after disabling captive portal when idle timeout is in use
This patch (or something else in about the same timeframe) completely broke CP in 2.2.3. No contexts are created.
...
Chris Buechler
03:23 AM Bug #4642: OpenVPN process status stopped... but its running
EDIT:
15 days passed by since I installed watchdog and set it to keep ntp up (ntp crashed all the time).
Since th...
Alejandro Olivan
01:42 AM Bug #4596 (Confirmed): NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
no change, but we'll leave as-is for 2.2.3. Limiters in general are better in 2.2.3 than earlier 2.2.*. Chris Buechler
01:26 AM Bug #4653 (Resolved): mtree dies in post_upgrade_command during upgrade from 8.x and earlier
confirmed upgrades on 1.2.3, 2.0.3, 2.1.5, 2.2.2, including both 32 and 64 bit for all 2.x. All fine. Chris Buechler
12:23 AM Bug #4107 (Resolved): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
fixed Chris Buechler
12:21 AM Bug #4523 (Resolved): master.passwd/group file corruption may occur after kernel panic or unclean shut down
fixed. We'll again verify as part of the release test matrix on each install type. Chris Buechler

06/16/2015

10:33 PM Bug #4757 (Not a Bug): Failing to boot Asrock Q1900M with LiveCD 2.2.2 and Dev 2.2.3 2015 -04 -13
Chris Buechler
10:32 PM Feature #4763: Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
there isn't a way to backup/restore only limiters at this time. Chris Buechler
02:33 PM Feature #4763: Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
Chris Buechler wrote:
> by traffic shaper in that context it means ALTQ, so this does work as designed.
So how co...
Srdjan Jovanovich
02:31 PM Feature #4763: Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
Title should be 'Restore from backup that contains only area Traffic Shaper doesn't restores Limiters'. Srdjan Jovanovich
02:30 PM Feature #4763: Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
by traffic shaper in that context it means ALTQ, so this does work as designed. Chris Buechler
02:29 PM Feature #4763: Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
Dear admins,
please delete Bug #4763, I have the error in the title. I've posted it again in Bug #4764.
Srdjan Jovanovich
02:25 PM Feature #4763 (Resolved): Restore from backup that contains only area Traffic Shaper doesn't restore Limiters
When I try to Backup only area Traffic Shaper the shaper-config*.xml doesn't contains Limiters. All the data from pag... Srdjan Jovanovich
10:31 PM Bug #4762: Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
which page are you referring to? diag_tables.php? Chris Buechler
09:00 AM Bug #4762 (Not a Bug): Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
Not sure whether this is a bug in the existing functionality or really a request for additional functionality.
Wou...
Technical Support Brendata (UK) Ltd
08:09 PM Bug #4768 (Duplicate): Operation not supported by device
this is a symptom of #4653, because the system didn't reboot post-upgrade in that case. Just power cycle the system a... Chris Buechler
08:03 PM Bug #4768 (Duplicate): Operation not supported by device
pfsense update from 2.1.5 to 2.2.2
php: rc.filter_configure_sync: New alert found: There were error(s) loading th...
tianyi939 meng
08:08 PM Bug #2526 (Resolved): Limiter appears to break IPv6 connectivity
works here too, looks good all around. Chris Buechler
05:44 PM Revision bc8adf7e: Say what is happening when reinstalling package GUI XML
At the confirmation dialog after pressing the "Reinstall XML" button, the text does not distinguish between having pr... Phil Davis
05:42 PM Revision a7c28e99: Say what is happening when reinstalling package GUI XML
At the confirmation dialog after pressing the "Reinstall XML" button, the text does not distinguish between having pr... Phil Davis
05:41 PM Revision f128ee22: Remove load_balancer_relay_* -- They are not used, not linked, not functional, not maintained, and have potential security issues.
Jim Pingle
05:41 PM Revision c28ab88c: Add load_balancer_relay_* to obsolete files. They were removed from the master branch already.
Jim Pingle
05:40 PM Revision 4fabdca7: Why is break missing for reinstallxml
I thought that "reinstallxml" should do less than "reinstallpkg" but actually it was getting stuff here, then falling... Phil Davis
05:40 PM Revision c28a785a: Merge pull request #1723 from phil-davis/patch-2
Renato Botelho
05:28 PM Bug #4767 (Duplicate): When renaming an IP alias at "Firewall: Aliases" the rules created at "Firewall: NAT: Outbound" are not updated accordingly
already fixed, duplicate of #4701 Chris Buechler
05:26 PM Bug #4767 (Duplicate): When renaming an IP alias at "Firewall: Aliases" the rules created at "Firewall: NAT: Outbound" are not updated accordingly
Hello,
I ran into a problem after renaming an IP Alias. The Alias was used in an outbound NAT rule as well as in a...
Maurits van de Lande
05:06 PM Revision b9455916: Say what is happening when reinstalling package GUI XML
At the confirmation dialog after pressing the "Reinstall XML" button, the text does not distinguish between having pr... Phil Davis
04:57 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Note: This was i386 hardware, but I'm not sure if that matters or not. badon _
04:55 PM Bug #4766 (Resolved): "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
I ran into this problem on a fresh DVD install of pfSense. An automated upgrade did not experience this problem. On t... badon _
04:55 PM Revision 84a2e915: Why is break missing for reinstallxml
I thought that "reinstallxml" should do less than "reinstallpkg" but actually it was getting stuff here, then falling... Phil Davis
04:35 PM Bug #4765 (Not a Bug): NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
On "System: Advanced: Firewall and NAT", in the "Network Address Translation" section, the checkbox labeled "Automati... Granger Godbold
04:11 PM Revision ab2fd59d: Encoding in services_unbound_advanced.php
Jim Pingle
04:11 PM Revision e9885763: Encoding in services_unbound_advanced.php
Jim Pingle
04:02 PM Revision a5e950ae: Encoding in system_advanced_sysctl.php
Jim Pingle
04:00 PM Revision de5f0b61: Encoding in system_advanced_sysctl.php
Jim Pingle
03:54 PM Revision df6a9c6d: Encoding in interfaces.php
Jim Pingle
03:54 PM Revision 0ec282d4: Encoding in interfaces.php
Jim Pingle
03:45 PM Revision e0829812: Encoding in services_unbound.php
Jim Pingle
03:45 PM Revision d674c38d: Encoding in services_unbound.php
Jim Pingle
03:42 PM Revision 55f6b38b: Encoding in pkg_mgr_settings.php
Jim Pingle
03:41 PM Revision 3642b348: Encoding in pkg_mgr_settings.php
Jim Pingle
03:38 PM Revision b29a65a4: Encoding in system_advanced_admin.php
Jim Pingle
03:37 PM Revision 1d92e91f: Encoding in system_advanced_admin.php
Jim Pingle
03:36 PM Revision f727f257: Encoding in interfaces_ppps_edit.php
Jim Pingle
03:34 PM Revision faa91642: Encoding in interfaces_ppps_edit.php
Jim Pingle
03:31 PM Revision 05dea4b7: Encoding in diag_packet_capture.php
Jim Pingle
03:30 PM Revision f4bbd64d: Encoding in diag_packet_capture.php
Jim Pingle
03:27 PM Revision f68e2f9f: Encoding in interfaces_qinq_edit.php
Jim Pingle
03:27 PM Revision 9162143f: Encoding in interfaces_qinq_edit.php
Jim Pingle
03:22 PM Revision dd5ec20f: Encoding in services_dnsmasq.php
Jim Pingle
03:18 PM Revision e959a567: Encoding in services_dnsmasq.php
Jim Pingle
03:17 PM Bug #4541 (Not a Bug): Manual FW upgrade bug with perform full backup before upgrade checkbox
thanks Chris Buechler
01:41 PM Bug #4541: Manual FW upgrade bug with perform full backup before upgrade checkbox
Some whacky Chrome bug, fixed itself in v41.something. Can be safely closed. Kill Bill
03:11 PM Revision 5b8c4101: Encoding in vpn_ipsec_settings.php
Jim Pingle
03:10 PM Revision 7a29e654: Encoding in vpn_ipsec_settings.php
Jim Pingle
03:10 PM Revision b18d2108: More encoding
Jim Pingle
03:05 PM Revision 5ef9708e: More encoding
Jim Pingle
02:57 PM Revision 2debaf5c: Fix some low-hanging potential security issues.
Jim Pingle
02:53 PM Revision d213c485: Fix some low-hanging potential security issues.
Jim Pingle
02:29 PM Bug #4764 (Duplicate): Restore from backup that contains only area Traffic Shaper doesn't restores Limiters
duplicate of #4763 Chris Buechler
02:27 PM Bug #4764 (Duplicate): Restore from backup that contains only area Traffic Shaper doesn't restores Limiters
When I try to Backup only area Traffic Shaper the shaper-config*.xml doesn't contains Limiters. All the data from pag... Srdjan Jovanovich
02:13 PM Revision 621baeb6: Be more careful with encoding on pages that use single quotes around HTML attributes
Jim Pingle
02:10 PM Revision 3aef3ad0: Be more careful with encoding on pages that use single quotes around HTML attributes
Jim Pingle
01:29 PM Bug #4107: Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
Works. Kill Bill
01:24 PM Revision 1cdfcaf4: Additional encoding for system_advanced_misc.php
Jim Pingle
01:24 PM Revision 6dbe58e1: Additional encoding for system_advanced_misc.php
Jim Pingle
01:12 PM Revision ee3de7b1: Protect single quotes as well to prevent JS injection, due to the way this page uses single quotes for attributes.
Jim Pingle
01:11 PM Revision 1a44770d: Protect single quotes as well to prevent JS injection, due to the way this page uses single quotes for attributes.
Jim Pingle
12:57 PM Revision 034620d6: Encode parameters in system_advanced_firewall.php before displaying back to the user.
Jim Pingle
12:56 PM Revision 2a1b44c9: Encode parameters in system_advanced_firewall.php before displaying back to the user.
Jim Pingle
12:34 PM Revision 9fced93c: Keep a copy of old mtree binary during upgrade and use it to avoid crashing. Fixes #4563
Renato Botelho
12:34 PM Revision 8f102b09: Check also for old FreeBSD release versions
Renato Botelho
12:34 PM Revision 0e40454d: Keep a copy of old mtree binary during upgrade and use it to avoid crashing. Fixes #4563
Renato Botelho
12:34 PM Revision 0ab90dd0: Check also for old FreeBSD release versions
Renato Botelho
11:56 AM Feature #4761: Add an option per alias entry to keep if the DNS server goes away
I've just checked and the TTL is 1 hour, we rebooted the server the other day and it took about 10 minutes to reboot,... Technical Support Brendata (UK) Ltd
11:42 AM Feature #4761 (Rejected): Add an option per alias entry to keep if the DNS server goes away
It'll hang onto it as long as the TTL is valid. Doing anything other than that would be broken behavior. If your DNS ... Chris Buechler
08:51 AM Feature #4761 (Rejected): Add an option per alias entry to keep if the DNS server goes away
It would be useful to be able to tick on a per entry basis in aliases whether an entry should remain if the DNS serve... Technical Support Brendata (UK) Ltd
08:48 AM Bug #4760 (Closed): PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
On a number of occasions I have seen the PPPoE connection between pfSense and our ADSL modem go down, the modem still... Technical Support Brendata (UK) Ltd
08:01 AM Bug #4653 (Feedback): mtree dies in post_upgrade_command during upgrade from 8.x and earlier
Fixed by commit:9fced93c25 and commit:0e40454d52 with a wrong ticket number on commit log. Renato Botelho
12:00 AM Bug #4653: mtree dies in post_upgrade_command during upgrade from 8.x and earlier
Renato's proposed patch looks to work fine here in circumstances where problems were previously replicable. That shou... Chris Buechler
01:39 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Ermal Luçi wrote:
> It is already in 2.2.3 since the merge.
> I merged it manually.
I'm still not convinced that...
Lars Pedersen

06/15/2015

09:47 PM Bug #4655 (Resolved): IPsec: Enable bypass for LAN interface IP behaviour is reversed
fixed Chris Buechler
07:25 PM Revision 7d8dd0b7: Add semicolon
Fix delete Java Script to match valid HTML ID N0YB
04:34 PM Bug #2526: Limiter appears to break IPv6 connectivity
Well I think it looks good now.
Tested with bunch of speedtest stuff like http://ipv6-test.com/speedtest/, http:/...
Kill Bill
04:18 PM Revision 6d85358c: Merge manullay pull/1722
Ermal Luçi
04:13 PM Revision 86bc5c1a: Merge pull request #1722 from chapmajs/fix_hughesnet_pd
Ermal Luçi
03:28 PM Bug #1629: invalid state table entries after WAN IP change
Hi Kevin,
when the cable modem does weird or reboots i have also seen this behaviour with the 0.0.0.0 address.
...
Tom De Coninck
08:50 AM Bug #1629: invalid state table entries after WAN IP change
I have been hitting this issue for over a year. Finally getting tired of manually killing the stale UDP states. I am ... Kevin Trace
02:50 PM Revision 4d474c09: Remove the GUI for the pc-sysinstaller as well and add it to obsoletee files
Ermal Luçi
02:48 PM Revision 353cd816: Remove pc-sysinstall since it was never finished and probably will be not the choice. If needed can be resurrected. It already is in obsoleted files
Ermal Luçi
02:46 PM Revision b8ceb344: Fixing PD size selection for HughesNet
Jonathan
02:46 PM Revision ce817bdb: Remove the GUI for the pc-sysinstaller as well and add it to obsoletee files
Ermal Luçi
02:42 PM Revision f80e099f: Remove pc-sysinstall since it was never finished and probably will be not the choice. If needed can be resurrected
Ermal Luçi
02:36 PM Revision d20f28db: Merge pull request #1721 from phil-davis/style
Renato Botelho
02:34 PM Revision 6622518b: status_queues missing semi-colon
This really looks like it should have a semi-colon. Somehow the PHP interpreter is not being fussy about it in this c... Phil Davis
02:32 PM Revision 98e7d680: Merge pull request #1718 from phil-davis/patch-2
Renato Botelho
10:37 AM Bug #4326 (Feedback): Limiters on firewall rules where NAT applies drop all traffic
This seems affecting only NAT with limiters.
It should be handled properly now in 2.2.3 i will re-test this again as...
Ermal Luçi
09:52 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
It is already in 2.2.3 since the merge.
I merged it manually.
Ermal Luçi
04:04 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Chris Buechler wrote:
> confirmed. Thanks!
Can see that you have set the target version to 2.2.3. Will you cherry...
Lars Pedersen
08:34 AM Revision 6c07db48: Code spacing
and other random stuff I noticed.
I think this finishes messing with code style. The codebase should match
the develo...
Phil Davis
07:53 AM Bug #4757: Failing to boot Asrock Q1900M with LiveCD 2.2.2 and Dev 2.2.3 2015 -04 -13
Kill Bill assessment is accurate it doesnt work with UEFI. Sorry for using your time guys.
Iain McAtear
07:04 AM pfSense Packages Bug #4759 (Rejected): DHCP return wrong GW
Please post in the forum or on the mailing list for assistance before opening a bug report. It is much more likely th... Jim Pingle
06:37 AM pfSense Packages Bug #4759 (Rejected): DHCP return wrong GW
hi
in fact I setup DHCP server but some clients gets wrong GW from it and some client get right GW. the config is he...
hamed dash
05:51 AM Feature #4758: DNS Resolver - Add GUI to configure reverse zone overrides
Not really sure what support you need, it works.
!http://i60.tinypic.com/syv8rr.png!...
Kill Bill
04:58 AM Feature #4758 (Closed): DNS Resolver - Add GUI to configure reverse zone overrides
It would be nice to have GUI option to configure overrides for reverse DNS zones in DNS resolver/Unbound. Currently c... Juraj Binka
05:39 AM Revision bf2dba75: XHTML Compliance
html id's not permitted to begin with a number.
html id's not permitted to contain '/'
add prefix (entry_) and replac...
N0YB
05:22 AM Revision 6bb817b4: status_queues missing semi-colon
This really looks like it should have a semi-colon. Somehow the PHP interpreter is not being fussy about it in this c... Phil Davis
05:10 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
Sorry, didn't have the opportunity to test the fix yet (encountered the problem on a production installation), but am... Vasco Freire
01:40 AM Feature #4542: Support for PPPoE with MTU/MRU > 1492 (i.e. 1500)
a pf 3000
01:39 AM Feature #4542: Support for PPPoE with MTU/MRU > 1492 (i.e. 1500)
Bug... pf 3000
12:58 AM Revision d26955ff: Ticket #4655 well manually merge pull/1715. Thanks: Phil
Ermal Luçi
12:58 AM Revision da6faa2b: Ticket #4655 well manually merge pull/1715. Thanks: Phil
Ermal Luçi

06/14/2015

09:35 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Ermal merge pull 1715, and as far as I can see that resolves the remaining issue. Phillip Davis
11:26 AM Bug #4757: Failing to boot Asrock Q1900M with LiveCD 2.2.2 and Dev 2.2.3 2015 -04 -13
You cannot use UEFI boot. You need to turn on the legacy boot and disable Secure Boot (if relevant). Kill Bill
10:55 AM Bug #4757 (Not a Bug): Failing to boot Asrock Q1900M with LiveCD 2.2.2 and Dev 2.2.3 2015 -04 -13
Failing to boot an Asrock Q1900M, bios v1.5 dated 31/10/2104.
Affects released version 2.2.2 amd64 and Development...
Iain McAtear
07:19 AM Revision 26b8101b: add input validation for proxy URL, port, user.
Conflicts:
usr/local/www/system_advanced_misc.php
Chris Buechler
06:01 AM Bug #4442 (Resolved): Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
this is good. Chris Buechler
05:48 AM Revision fd90a77f: add input validation for proxy URL, port, user.
Chris Buechler
05:16 AM Bug #4712 (Resolved): Wizard hostname validation rejects upper case letters
works Chris Buechler
04:19 AM Todo #4755 (Resolved): upgrade PHP to 5.5.26
confirmed Chris Buechler

06/13/2015

11:45 PM pfSense Packages Bug #4426: NUT fails to start or restart until NUT's settings are (re)saved
I have been unable to start NUT on my 2.2.2-RELEASE (amd64) install since creating an openvpn client and therefore re... Jason Warren
09:32 PM Revision 71dbcc11: services_dyndns - use tr.disabled instead of font-color
Sjon Hortensius
02:35 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Jim P wrote:
> Without seeing the full crash report it's impossible to say if it's related. If you haven't already, ...
→ luckman212
02:30 PM Bug #4685 (Feedback): Crash/panic "Sleeping thread owns a non-sleepable lock"
Patch put on the tree.
Those who want to test need to update to snapshot coming out next.
Ermal Luçi
12:57 PM Revision c72237ee: correct 2 syntax errors
Sjon Hortensius
12:44 PM Revision a326e955: updated progress
Sjon Hortensius
12:39 PM Revision d8e0d425: remove useless form+wrapper #211
Sjon Hortensius
12:38 PM Revision cfc607f3: Merge pull request #211 from sbeaver-netgate/services_captiveportal_ip
Convert services_captiveportal_ip SjonHortensius
12:37 PM Revision f107fd31: status_filter_reload.php Conversion complete
Ready for review sbeaver
12:36 PM Revision 311c0f32: Merge pull request #312 from ExolonDX/patch-4
Move the break & endforeach statements so the DL and DIV tags are properly closed SjonHortensius
12:35 PM Revision d6084ab0: Ok another round of this which unbreaks input error validation messages
Ermal Luçi
12:35 PM Revision 67d96856: Ok another round of this which unbreaks input error validation messages
Ermal Luçi
12:34 PM Revision cd225cb5: vpn_ipsec_phase2.php Conversion complete
Ready for review sbeaver
12:33 PM Revision 75fd7984: vpn_ipsec_phase1.php Conversion complete
Ready for review sbeaver
12:31 PM Revision c284c8a2: system_firmware_check.php Conversion complete
Table converted to panel with heading color indicating status.
jQuery functions provided for formatted writes to pan...
sbeaver
12:30 PM Revision 727047a6: system_firmware_auto.php Conversion complete
Page has been changed to use a panel heading for status and a panel
body for output.
Functions have been provided to...
sbeaver
12:30 PM Revision bea9e9d6: vpn_openvpn_client.php Conversioncomplete
Ready for review sbeaver
12:28 PM Revision 01ab50fd: vpn_openvpn_server.php Conversion complete
Ready for review sbeaver
12:27 PM Revision 155d9450: diag_smart.php Conversion complete
Ready for review sbeaver
12:23 PM Revision 9ee2cac1: interfaces_ppps_edit.php Conversion complete
Ready for review
This was a very challenging conversion due to the external javascript
libraries (no longer availabl...
sbeaver
12:21 PM Revision ee3af113: firewall_virtual_ip_edit.php Conversion complete
Ready for review sbeaver
12:21 PM Revision 781b2b7f: firewall_virtual_ip_edit.php
Form complete. Need to add Javascript actions sbeaver
12:20 PM Revision e4f5ae71: firewall_virtual_ip.php Conversion couplete
Ready for review sbeaver
12:19 PM Revision d7770192: firewall_shaper_wizards.php Conversion complete
Ready for review sbeaver
12:18 PM Revision 416b6a09: Removed unneeded form
sbeaver
12:18 PM Revision 416cbf3c: firewall_schedule.php Conversion complete
Ready for review sbeaver
12:16 PM Revision 8d9f7a80: IpAddress.class.php
Updated to allow the addMask() method to accept a maximum value so that
it can be used for IPv4 and IPv6 addresses. e...
sbeaver
12:16 PM Revision cf51b119: firewall_nat_npt_edit.php Converion complete
Ready for review sbeaver
12:14 PM Revision 3cc272c0: remove useless form+wrapper #301
Sjon Hortensius
12:12 PM Revision 5e4b485f: firewall_nat_npt.php Conversion complete
Ready for review sbeaver
12:11 PM Revision 325cdc5d: diag_packet_capture.php Conversion complete
Ready for review sbeaver
12:09 PM Revision 9d11418f: system_gateway_groups_edit.php Conversion complete
Ready for review sbeaver
12:08 PM Revision b83e61e4: vpn_openvpn_csc.php COnversion complete
Ready for review sbeaver
12:07 PM Revision 16eef6f9: vpn_pppoe_edit.php Conversion complete
Ready for review sbeaver
12:06 PM Revision 7778a458: system_usermanager_passwordmg.php COnversion complete
Ready for review sbeaver
12:02 PM Revision 66bbb1b5: remove useless form+wrapper #296
Sjon Hortensius
12:00 PM Revision 4c8c4fc2: vpn_pppoe Conversion complete
Ready for review sbeaver
11:59 AM Revision aa3c6f56: system_usermanager_addprovs.php Conversion complete
Ready for review sbeaver
11:56 AM Revision a742c95a: removed useless form+panel wrapper #293
Sjon Hortensius
11:54 AM Revision b9b44f94: system_gateway_groups.php Conversion complete
Ready for review sbeaver
11:53 AM Revision 454f52f9: status_wireless.php Conversion complete
Ready for review sbeaver
11:52 AM Revision 18e020bd: status_upnp.php Conversion complete
Ready for review sbeaver
11:51 AM Revision 517d3109: status_services.php Conversion complete
Ready for review sbeaver
11:50 AM Revision b33c73ff: no need for reference #289
Sjon Hortensius
11:25 AM Revision af66ad8d: status_lb_pool.php Conversion complete
Ready for review sbeaver
11:24 AM Revision ca583944: status_graph_cpu Conversion complete
Ready for review sbeaver
11:23 AM Revision 3c7787df: status_captiveportal_vocher_rolls.php Conversion complete
Ready for review sbeaver
11:22 AM Revision e3a24020: status_captiveportal_vouchers.php Conversion complete
Ready for review sbeaver
11:21 AM Revision f200e233: status_captiveportal_test.php Conversion complete
Ready for review sbeaver
11:20 AM Revision aeb33e05: status_captiveportal_expire.php Conversion complete
Ready for review sbeaver
11:19 AM Revision 12debece: status_captiveportal.php Conversion complete
Ready for review sbeaver
11:19 AM Revision 454cec57: status.php Conversion coplete
Ready for review sbeaver
11:18 AM Revision a777cf18: services_unbound_host_edit Conversion complete
Ready for review sbeaver
11:17 AM Revision c3e03a35: services_unbound_domainoverride_edit.php Conversion complete
Ready for review sbeaver
11:16 AM Revision 0a98e31b: services_unbound_advanved.php Conversion complete
Ready for review sbeaver
11:15 AM Revision 6e3bd9d2: servies_unbound_acls.php Conversion complete
Ready for review sbeaver
11:11 AM Revision 51c224bc: services_unbound Conversion complete
Ready for review sbeaver
11:10 AM Revision 9f35c891: Merge pull request #236 from sbeaver-netgate/services_rfc2136_edit
Convert services_rfc2136_edit SjonHortensius
11:08 AM Revision fcded4cf: Merge pull request #235 from sbeaver-netgate/services_rfc2136
Convert services_rfc2136 SjonHortensius
11:08 AM Revision 63f127aa: Merge pull request #233 from sbeaver-netgate/services_ntpd_pps
Convert services_ntpd_pps SjonHortensius
11:07 AM Revision ffe0ae40: Merge pull request #232 from sbeaver-netgate/serviecs_ntpd_gps
Convert services_ntpd_gps SjonHortensius
11:05 AM Revision 135200fa: Merge pull request #231 from sbeaver-netgate/services_ntpd
Convert services_ntpd SjonHortensius
11:05 AM Revision 49475b89: Merge pull request #230 from sbeaver-netgate/services_igmpproxy_edit
Convert services_igmpproxy_edit SjonHortensius
11:02 AM Revision c4952ad6: Merge pull request #228 from sbeaver-netgate/services_igmpproxy
Convert services_igmpproxy SjonHortensius
11:01 AM Revision 9fe3ffb2: fix load of syntax errors, give 'Disable' a proper label #227
Sjon Hortensius
10:54 AM Revision 348ee54d: Merge pull request #227 from sbeaver-netgate/services_dyndns_edit.php
Convert services_dyndns_edit SjonHortensius
10:50 AM Revision 565098a7: Merge pull request #226 from sbeaver-netgate/services_dyndns
Convert services_dyndns (contains syntax-errors I'll fix) SjonHortensius
10:48 AM Revision c39d178c: Remove help-text from hidden input #225
Sjon Hortensius
10:47 AM Revision 52863715: Merge pull request #225 from sbeaver-netgate/services_dnsmasq_edit
Convert services_dnsmasq_edit SjonHortensius
10:46 AM Revision 07b5a68e: Merge pull request #224 from sbeaver-netgate/services_dnsmasq_domainoverride_edit
Convert services_dnsmasq_domainoverride_edit SjonHortensius
10:44 AM Revision 626e821e: Merge pull request #223 from sbeaver-netgate/services_dnsmasq
Convert services_dnsmasq SjonHortensius
10:43 AM Revision 72e4aa0e: Merge pull request #222 from sbeaver-netgate/services_dhcpv6_edit
Convert services_dhcpv6_edit SjonHortensius
10:43 AM Revision 28ab6a92: Merge pull request #221 from sbeaver-netgate/services_dhcpv6
Converted services_dhcpv6 SjonHortensius
09:35 AM pfSense Packages Bug #4567: ntopNG Geo files missing
Issue is still there is 2.2.2 package version 1.2.1 v0.5
/usr/pbi/ntopng-amd64/bin/ntopng-geoipupdate.sh doesn't cor...
Basile Caillens
08:06 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
My setup was affected by this since I tried 2.2-RC (https://forum.pfsense.org/index.php?topic=85285.0)
I tried again...
Régis Belson
02:31 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Chris Buechler wrote:
> I'm kidding...point being, why would you want additional lines in the default config that ar...
Kill Bill
01:35 AM Bug #4655 (Feedback): IPsec: Enable bypass for LAN interface IP behaviour is reversed
Phil, thanks for the additional pull request. Putting this back to Feedback to review later. It's BSDCan and 2 AM whi... Chris Buechler
01:30 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Top secret reasons, sorry. The NSA won't let us tell.
I'm kidding...point being, why would you want additional li...
Chris Buechler
01:26 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
I still would love to hear why exactly do we desperately need to spare one line in default config.xml and why the set... Kill Bill
12:24 AM pfSense Packages Bug #4756 (Confirmed): OpenVPN Client Export fails when using "real" certificate
Yes you have to import the chain in that case. It's stupid to use "real" certificates with OpenVPN, it's actually *le... Chris Buechler

06/12/2015

09:55 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
The fish-slapping drama continues here https://github.com/pfsense/pfsense/pull/1715
That pull request is closed, but...
Phillip Davis
02:35 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
https://www.youtube.com/watch?v=kWmbXMXns28 Kill Bill
01:37 PM Bug #4655 (Resolved): IPsec: Enable bypass for LAN interface IP behaviour is reversed
Thanks Phil!
We were heading out to dinner shortly after Ermal's commit yesterday, and came up with the idea on t...
Chris Buechler
11:03 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
It works now... (The time wasted here would be enough of a hint to not ever do things like this again. There's a foru... Kill Bill
10:36 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Kill Bill wrote:
> And let me say, it was just fine until this evil commit that twisted the logic into this stupidit...
Ermal Luçi
02:47 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Phillip Davis wrote:
> https://github.com/pfsense/pfsense/pull/1715
Applied your pull request on top of the whole...
Kill Bill
08:46 PM pfSense Packages Bug #4756: OpenVPN Client Export fails when using "real" certificate
I just figured out that if I import every cert in the chain individually into the "CA" tab, it finally works.
That's...
Adam Thompson
08:44 PM pfSense Packages Bug #4756 (Not a Bug): OpenVPN Client Export fails when using "real" certificate
Still having what appears to be the same problem as issue #1538, but in 2.2.2-RELEASE i386.
Generate a CSR from pf...
Adam Thompson
08:38 PM pfSense Packages Bug #1538: openvpn-client-export.inc -- issue with ca.crt lookup
Still having what *appears* to be the same issue.
Generate a CSR from pfSense, get a signed cert (from StartSSL) for...
Adam Thompson
06:35 PM Revision f7531032: Make this right finally :). Thanks-ti: Phil-davis
Ermal Luçi
06:35 PM Revision 60fc27e0: Make this right finally :). Thanks-ti: Phil-davis
Ermal Luçi
04:11 PM Revision 4b03b906: Add hostid script in the source to solve the issue with platforms that do not have proper uuid or duplicate uuid which breaks carp/pfsync and other things in HA setup.
Ermal Luçi
04:01 PM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
Ermal Luçi wrote:
> https://github.com/ocochard/BSDRP/blob/master/EINE/patches/freebsd.bsnmpd.hostres
>
> Seems t...
Renato Botelho
03:30 PM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
Chris Buechler wrote:
> Matt: haven't heard of it on ALIX but same could impact it also. does disabling the host res...
Matt Meyer
03:03 PM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
https://github.com/ocochard/BSDRP/blob/master/EINE/patches/freebsd.bsnmpd.hostres
Seems to have a patch for this i...
Ermal Luçi
03:58 PM Revision e5bdc656: Add hostid script in the source to solve the issue with platforms that do not have proper uuid or duplicate uuid which breaks carp/pfsync and other things in HA setup.
Ermal Luçi
03:41 PM Revision c3a47539: Merge pull request #1716 from edwinlee11/patch-1
Ermal Luçi
03:37 PM Revision b5d102e7: Activate the redirection that for some reason got disabled
Ermal Luçi
03:36 PM Revision 7144515b: Activate the redirection that for some reason got disabled
Ermal Luçi
10:52 AM Revision a7a064f4: Add description as a display option on Traffic Graph
This is handy at sites where lots of the LAN clients have static-mapped
DHCP IP addresses. Depending on the site host...
Phil Davis
09:42 AM Todo #4755 (Feedback): upgrade PHP to 5.5.26
Done. Renato Botelho
09:08 AM Todo #4755 (Assigned): upgrade PHP to 5.5.26
I found the announcement, nvm. Renato Botelho
09:06 AM Todo #4755 (Feedback): upgrade PHP to 5.5.26
I couldn't find this release, according with PHP website 5.5.25 is the latest one - http://php.net/releases/ Renato Botelho
09:15 AM Revision a75aa2ca: Remove track6-interface and track6-prefix-id from interfaces->lan in default config.xml
1. <track6-interface>wan</track6-interface> and <track6-prefix-id>0</track6-prefix-id> of interfaces->lan from /conf.... Edwin Lee
07:46 AM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Still seeing a steady stream of crashes on certain systems, I've added more crash reports to the repo. Two of them ha... Jim Pingle
07:45 AM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Luke Hamburg wrote:
> I have experienced a lot of crashes (hard crash that triggers the box to reboot) on 2 differen...
Jim Pingle
02:57 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
No more undefined macros and errors when loading the rules on boot with latest snapshot. I'm with Chris here, looks l... Kill Bill

06/11/2015

09:57 PM Revision 71f29f44: Ticket #4655 Do not behave against the logic of checkbox and description.
Ermal Luçi
09:56 PM Revision 1c7fd09e: Ticket #4655 Do not behave against the logic of checkbox and description.
Ermal Luçi
09:50 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
https://github.com/pfsense/pfsense/pull/1715
Ermal's change/fix seems good (although the whole thing screws with peo...
Phillip Davis
05:33 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
And let me say, it was just fine until this evil commit that twisted the logic into this stupidity.
https://github...
Kill Bill
05:21 PM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
This does NOT work. Keep clicking Save and watch the checkbox and ipsec.conf flip. Not really sure what to say here. ... Kill Bill
04:55 PM Bug #4655 (Feedback): IPsec: Enable bypass for LAN interface IP behaviour is reversed
Fixed to be natural to the checkbox and comment. Ermal Luçi
07:21 PM Revision c66a327b: Merge pull request #1710 from stilez/patch-4
Renato Botelho
07:18 PM Revision be37ac8f: fix checking for overlaps of NAT destination port
Bruno Ferri
07:17 PM Revision 52bdb9b0: Merge pull request #1714 from brunostein/fix_checking_nat_destination_port
Renato Botelho
06:43 PM Revision ed899400: fix checking for overlaps of NAT destination port
Bruno Ferri
05:19 PM Bug #4607 (Resolved): Bridge+CARP crashes/freezes pfSense
fixed, original problem case is no longer replicable, things otherwise seem fine on a system that's been running in a... Chris Buechler
05:12 PM Todo #4755 (Resolved): upgrade PHP to 5.5.26
2.2.3 needs PHP upgraded to 5.5.26. Chris Buechler
05:06 PM Feature #4683 (Resolved): Support for elliptic curve for IPsec on webconfigurator
confirmed. Thanks! Chris Buechler
04:42 PM Bug #4537 (Resolved): Crash and reboot when accessing the web UI from the IPsec mobile client or over the tunnel on 32 bit
that works around the issue. For tracking purposes we'll mark this resolved. I opened #4754 to investigate the root c... Chris Buechler
04:41 PM Bug #4754 (Resolved): enabling net.inet.ipsec.directdispatch on 32 bit results in kernel panics
Starting this for the root problem in #4537. We have a workaround for the issue and hence closed that ticket, but the... Chris Buechler
04:18 PM Bug #4625 (Resolved): Expiring a voucher doesn't disconnect a user who is using that voucher
fixed Chris Buechler
03:50 PM Bug #4268: changes in strongswan config don't apply to SAD or SPD
They will not go away from what i recall until the SA expires.
But the new SPD will be used for new packets.
Ermal Luçi
03:32 PM Bug #4268 (Confirmed): changes in strongswan config don't apply to SAD or SPD
no change. SPD and SAD both remain in place. For example, bring up an IPsec connection of any type. Verify its SAD an... Chris Buechler
03:39 PM Todo #4353 (New): Review IPsec reloading when strongswan.conf is changed
Chris Buechler
03:37 PM Feature #4626 (Resolved): Ability to set charon.make_before_break in strongswan.conf
works Chris Buechler
12:39 PM pfSense Packages Feature #4581: Add dshield-sensor port to pfPorts
This can be closed, I submitted a pull request now that I have access to the repository. Robert Nelson
10:05 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
I've created the pull request @ https://github.com/pfsense/pfsense/pull/1713 Daniel Schultheis
09:39 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
It will be easy if you submit a pull request at https://github.com/pfsense/pfsense
Then the devs can easily review, ...
Phillip Davis
09:07 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
I made a silly mistake which is now fixed. Here is an updated patch. Daniel Schultheis
09:00 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
I've just optimized the patch a bit to revert back to the original functions which now have an additional $allow_wild... Daniel Schultheis
08:54 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
I've created a patch which now wraps this whole behaviour in a seperate function call.
In /usr/local/www/system_ce...
Daniel Schultheis
08:34 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
That change is unlikely to make it in unless it's in a separate function or a separate option to the function to acti... Jim Pingle
08:31 AM Bug #3733: Certificate manager doesn't allow wildcards in Subject Alternative Names
You can achive this behaviour by modifying the file /etc/inc/util.inc
The problem lies within the is_domain() meth...
Daniel Schultheis
09:57 AM Bug #4383 (Resolved): Firewall log contains IGMP for rules that do not have logging on
fixed Chris Buechler
12:52 AM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
Hooray! I finally can see something useful in firewall logs on the previously affected site once again! Sanity restor... Kill Bill
09:55 AM Bug #4651 (Resolved): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
fixed Chris Buechler
09:44 AM Todo #4750 (Resolved): Upgrade to strongswan 5.3.2 for pfsense 2.2.3
done Chris Buechler
01:46 AM Revision 2e7ea107: Make the host uuid opt-out
Ermal Luçi
01:42 AM Revision bfc15aca: Make the host uuid opt-out
Ermal Luçi
12:58 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Ermal Luçi wrote:
> You DNS is busted what do you get blocked that was not blocked before?
No. That'd make packag...
Kill Bill
12:14 AM Revision 894d01b6: Revert "Ticket #4442 Do not process URL aliases during bootup but trigger it just after finished booting. This completely solves the bootup delays without lowering the timeout as before. Probably need to increase a bit the timeouts now to be friendly to other connections"
This reverts commit 0d44aca64623da5a3eeef0619704a10b3cfda7a5. Chris Buechler
12:14 AM Revision bab606ee: Revert "Ticket #4442 Do not process URL aliases during bootup but trigger it just after finished booting. This completely solves the bootup delays without lowering the timeout as before. Probably need to increase a bit the timeouts now to be friendly to other connections"
This reverts commit ec9eb7891780e5f142838c03203ad8ce267ed89e. Chris Buechler

06/10/2015

10:17 PM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
2.2.3-DEVELOPMENT (i386)
built on Wed Jun 10 19:49:59 CDT 2015
FreeBSD 10.1-RELEASE-p11
No more flood of unasked...
Phillip Davis
12:31 PM Bug #4383 (Feedback): Firewall log contains IGMP for rules that do not have logging on
Patched. Ermal Luçi
08:11 PM Bug #4028 (Resolved): Wireless Obytes counter always 0
here as well Chris Buechler
03:56 PM Bug #4028: Wireless Obytes counter always 0
WFM as well. Kill Bill
01:15 PM Bug #4028: Wireless Obytes counter always 0
Fixed for me on Alix with WiFi card with pfSense-2.2.3-DEVELOPMENT-2g-i386-nanobsd-upgrade-20150610-1048.img.gz
Now ...
Phillip Davis
07:16 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
It's definitely worse to skip it during boot in a variety of cases, and I don't see any circumstances where that help... Chris Buechler
06:58 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
You DNS is busted what do you get blocked that was not blocked before?
If your boot takes 1-2 minutes than this is...
Ermal Luçi
04:23 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Hmmmm. Not exactly convinced this is better. This seems to be blocking all traffic from LANs until the boot is comple... Kill Bill
07:04 PM Bug #4523 (Feedback): master.passwd/group file corruption may occur after kernel panic or unclean shut down
Installer has been updated for new snaps and upgrade code been put in place. Ermal Luçi
06:12 PM Revision 3474e299: Send the machine uuid with the headers requesting the version file
Ermal Luçi
06:11 PM Revision 9c189bee: Send the machine uuid with the headers requesting the version file
Ermal Luçi
06:10 PM Revision 7e3bdaa9: Send the machine uuid with the headers requesting the version file
Ermal Luçi
06:02 PM Revision fb36bccf: Send the host uuid with the request for package
Ermal Luçi
05:44 PM Revision 8b8a4630: Fixes #4537 On 32bit platform do not enable direct dispatch on IPsec since it crashes the system
Ermal Luçi
05:44 PM Revision 05591613: Fixes #4537 On 32bit platform do not enable direct dispatch on IPsec since it crashes the system
Ermal Luçi
04:54 PM Revision b8947f8f: Activate sync for the root slice in fstab during upgrade. Ticket #4523
Jim Pingle
04:49 PM Revision ed97bf78: Activate sync for the root slice in fstab during upgrade. Ticket #4523
Jim Pingle
12:50 PM Bug #4537: Crash and reboot when accessing the web UI from the IPsec mobile client or over the tunnel on 32 bit
Applied in changeset commit:8b8a4630542156b160e22cf3921f0be5a4563179. Ermal Luçi
12:50 PM Bug #4537: Crash and reboot when accessing the web UI from the IPsec mobile client or over the tunnel on 32 bit
Applied in changeset commit:0559161320438f942e48c50263043d975be6fc21. Ermal Luçi
12:42 PM Bug #4537 (Feedback): Crash and reboot when accessing the web UI from the IPsec mobile client or over the tunnel on 32 bit
Done for non amd64. Ermal Luçi
11:45 AM Bug #4751 (Feedback): kernel panic after disabling captive portal when idle timeout is in use
Patch has been updated to solve this issue. Ermal Luçi
07:17 AM Bug #4753: Can't access to the Internet on Pfsense 2.0 with VLAN+CARP
Ok thank you Greg CHALVIGNAC
07:15 AM Bug #4753 (Rejected): Can't access to the Internet on Pfsense 2.0 with VLAN+CARP
"WAN Net" means the subnet of the WAN interface, not the Internet in general.
Please post on the forum for assista...
Jim Pingle
07:13 AM Bug #4753 (Rejected): Can't access to the Internet on Pfsense 2.0 with VLAN+CARP
When I set a rule like this :
Proto:IPv4 | source: VlanX Net | p_source: * | Dest : WAN Net | p_dest : (Alias) 80,...
Greg CHALVIGNAC
06:43 AM pfSense Packages Feature #4581: Add dshield-sensor port to pfPorts
Don't give up, I want this feature for one, but adding to FreeBSD will help everyone
maybe post here https://forum...
Mark M
02:44 AM pfSense Packages Feature #4752 (Resolved): SQUID. Exception for speed limits
Good day to all people!I am submitting for your consideration the idea (the request).
It would be good if in the sec...
Aleksei Aksenov
02:29 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
Hello Chris.
I tested this twice,and it's not working properly.
I used version 2.2.3-DEVELOPMENT (amd64) built ...
Grzegorz Sliwa

06/09/2015

03:00 PM Bug #4523 (Confirmed): master.passwd/group file corruption may occur after kernel panic or unclean shut down
Moving this back to Confirmed since the upgrade code is still missing for existing installations, and it appears as t... Jim Pingle
01:00 PM Bug #4605: OpenVPN user/pass fails if usernames and/or passwords contain special characters (reopen bugs 4177 and 4340)
Edin Sarajlic wrote:
> Testing:
> Username (provided in OP): *00>00?0*
I think you should read the fine POSIX. S...
Kill Bill
08:03 AM Bug #4605: OpenVPN user/pass fails if usernames and/or passwords contain special characters (reopen bugs 4177 and 4340)
Sorry, my original pull request (#1711) referenced the wrong bug number.
Please see this Github Pull Request: http...
Edin Sarajlic
07:41 AM Bug #4605: OpenVPN user/pass fails if usernames and/or passwords contain special characters (reopen bugs 4177 and 4340)
Github Pull Request: https://github.com/pfsense/pfsense/pull/1711 Edin Sarajlic
07:36 AM Bug #4605: OpenVPN user/pass fails if usernames and/or passwords contain special characters (reopen bugs 4177 and 4340)
I can confirm that the issue still exists in pfSense 2.2.2.
I can also confirm that Dave Crane's solution works.
...
Edin Sarajlic
01:01 AM Bug #4218: Bridge does not have AUTO_LINKLOCAL flag
I too can confirm this behaviour.
As a workaround, I have added the following to /etc/inc/interfaces.inc (As per p...
Chris Malton
12:43 AM Revision 472669b6: If the filesystem is corrupted i do not think fixing pwd DB is a good thing..
Ermal Luçi
12:37 AM Revision 2895e606: No need to do the same exercise twice.
Ermal Luçi
12:36 AM Revision 7cf09b9e: No need to do the same exercise twice.
Ermal Luçi
12:35 AM Revision d32c16bc: Do not call fsck just out of nowhere here since it cannot be the problem or fix.
Ermal Luçi
12:31 AM Revision e14e38c1: Do not disable APc here
Ermal Luçi
12:31 AM Revision 8da92d29: Do not disable APc here
Ermal Luçi
12:30 AM Revision 3ab88f32: Restore the file system in R/W mode during most of rc script seems required on nano. Should unbreak nanobsd
Ermal Luçi
12:30 AM Revision 217935fe: Restore the file system in R/W mode during most of rc script seems required on nano. Should unbreak nanobsd
Ermal Luçi

06/08/2015

11:36 PM Revision 9976544b: Add a space to the script to avoid that appended parameters seem the same as existing one
Ermal Luçi
11:36 PM Revision ad1e7a8c: Add a space to the script to avoid that appended parameters seem the same as existing one
Ermal Luçi
11:13 PM Bug #4751 (Resolved): kernel panic after disabling captive portal when idle timeout is in use
If you have a CP config with an idle timeout, have a user logged in, and disable CP, when the idle timeout is reached... Chris Buechler
09:07 PM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
this makes the firewall logs basically completely useless in some networks. Sounds like it shouldn't be too difficult... Chris Buechler
09:05 PM Bug #4747 (Confirmed): DNS Resolver - Insufficient sanity checking for DNS Query Forwarding
same is true of dnsmasq. It's not as simple as just checking for user-defined DNS servers, as those with dynamic WANs... Chris Buechler
08:48 PM Bug #4537: Crash and reboot when accessing the web UI from the IPsec mobile client or over the tunnel on 32 bit
For 2.2.3, let's set net.inet.ipsec.directdispatch=0 where IPsec is enabled and running on 32 bit. Chris Buechler
06:52 PM Todo #4750 (Feedback): Upgrade to strongswan 5.3.2 for pfsense 2.2.3
Updated on tools, will be available on next snapshots Renato Botelho
01:51 PM Todo #4750: Upgrade to strongswan 5.3.2 for pfsense 2.2.3
I think they fixed some edge cases with manual reqid as you had in 2.2.1/2: https://wiki.strongswan.org/issues/976 Florian Apolloner
01:49 PM Todo #4750: Upgrade to strongswan 5.3.2 for pfsense 2.2.3
Florian: what reqid fix are you referring to? I don't see anything in the change log for 5.3.1 or 5.3.2 that's relate... Chris Buechler
01:46 PM Todo #4750 (Assigned): Upgrade to strongswan 5.3.2 for pfsense 2.2.3
Chris Buechler
12:09 PM Todo #4750 (Resolved): Upgrade to strongswan 5.3.2 for pfsense 2.2.3
Strongswan 5.3.2 fixes a CVE and the reqid assignment, so an upgrade would be nice for 2.2.3. Florian Apolloner
06:11 PM Bug #4310 (Feedback): Limiters + HA results in hangs on secondary
I'm pretty sure it doesn't happen anymore, still have the test setup running to make sure. Given another ~48 hours, i... Chris Buechler
06:06 PM Bug #4310: Limiters + HA results in hangs on secondary
Chris need to confirm this happens still or not. Ermal Luçi
06:05 PM Bug #4686: Rekeyed SAs are not properly removed
I corrected the patch to the one in FreeBSD.
Should be on newer snapshots.
Ermal Luçi
11:52 AM Bug #4686: Rekeyed SAs are not properly removed
After reading it more carefully it looks as if:... Florian Apolloner
11:39 AM Bug #4686: Rekeyed SAs are not properly removed
Mhm, to be honest, the diff looks quite different from what upstream has, not sure if there was an error during copyi... Florian Apolloner
02:11 PM Revision 0dabc434: Corrected as suggested
Thanks sbeaver
02:08 PM Revision 30a40ca8: Revised as suggested
That’s a much better solution. Thanks! sbeaver
12:25 PM Revision d9692996: Use skel as the source of new user files rather than copying from root.
Reported-By: https://twitter.com/fitchitis/status/607850849172373504 Jim Pingle
12:24 PM Revision 33861014: Use skel as the source of new user files rather than copying from root.
Reported-By: https://twitter.com/fitchitis/status/607850849172373504 Jim Pingle
12:15 PM Revision 6c7384b7: Removed debug
sbeaver
10:56 AM Bug #4329: OpenVPN Server returns an error message while validating selfsigned certificate with a deep of 2
Any progress so far
Will it go into GA 2.2.3
Armin Tueting
10:11 AM Bug #4296 (Resolved): Using the same FQDN in multiple aliases causes static entries to be lost
Looks good. All of my former problem test cases check out, all of the entries are present at boot time, after filter ... Jim Pingle
01:28 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
There's something badly broken on nanobsd with this...
https://forum.pfsense.org/index.php?topic=94900.0
Kill Bill
12:49 AM Bug #4749: DHCPv6 server not disabling after initial setup
No, both LAN and WAN interfaces use static IPv6 and IPv4 addresses. IPv6 routing is done for a public /64 network (an... Andreas Peetz

06/07/2015

10:30 PM Revision 5b2b1f4e: Do not synchronize alias url during filter reload rather trigger one if needed
Ermal Luçi
09:35 PM Revision 0d44aca6: Ticket #4442 Do not process URL aliases during bootup but trigger it just after finished booting. This completely solves the bootup delays without lowering the timeout as before. Probably need to increase a bit the timeouts now to be friendly to other connections
Ermal Luçi
09:34 PM Revision ec9eb789: Ticket #4442 Do not process URL aliases during bootup but trigger it just after finished booting. This completely solves the bootup delays without lowering the timeout as before. Probably need to increase a bit the timeouts now to be friendly to other connections
Ermal Luçi
07:17 PM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
This needs a patching on pf(4) that forces logging on packets with ip options dropped if not allowed and does not che... Ermal Luçi
07:04 PM Bug #4178: IPsec leftsubnet changed to 0.0.0.0 with Cisco unity plugin active
Its not something to be fixed for now. Ermal Luçi
06:55 PM Bug #4523 (Feedback): master.passwd/group file corruption may occur after kernel panic or unclean shut down
Ermal Luçi
06:54 PM Revision cba32cb1: Fixes #4651 use proper var name on global to have the correct id put on the rule
Ermal Luçi
06:53 PM Revision 8c9216d5: Fixes #4651 use proper var name on global to have the correct id put on the rule
Ermal Luçi
06:52 PM Bug #4296 (Feedback): Using the same FQDN in multiple aliases causes static entries to be lost
A conditional branch did not have the proper test.
Ermal Luçi
06:40 PM Revision 7a923e09: Re-generate broken .mo files, it fixes #4705
Renato Botelho
06:39 PM Revision 422fabbc: Remove duplicate message
Renato Botelho
06:38 PM Revision 5f61deb3: Re-generate broken .mo files, it fixes #4705
Renato Botelho
06:37 PM Revision 313e8ab0: Obsolete old pt_BR ISO8859 directory and not current one
Renato Botelho
05:49 PM Bug #2526 (Feedback): Limiter appears to break IPv6 connectivity
To be retested with a new snapshot there might have been issue with operator precedence in previous patch. Ermal Luçi
04:14 PM Bug #2526: Limiter appears to break IPv6 connectivity
Can you specify the scenario to check it?
Normally the only thing i see might be missing some parameter passing to d...
Ermal Luçi
05:27 PM Bug #4745 (Not a Bug): Reassignment of devices after config restore
when an interface mismatch exists, it prompts with the normal interface reassignment which includes all interfaces. T... Chris Buechler
05:19 PM Bug #4749: DHCPv6 server not disabling after initial setup
do you have an interface set to track for PD? Chris Buechler
11:52 AM Bug #4749: DHCPv6 server not disabling after initial setup
Also, ENabling and DISabling the service again in the WebGUI does not change the behaviour: The DHCPv6 server is stil... Andreas Peetz
05:34 AM Bug #4749 (Duplicate): DHCPv6 server not disabling after initial setup
Fresh install of pfSense 2.2.2 with 1x LAN and 1x WAN interface.
Used the console menu to (#1) assign interfaces and...
Andreas Peetz
04:45 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Also one this to consider here probably as another issue is that update of urlaliases should not be done inline durin... Ermal Luçi
04:43 PM Bug #4442 (Feedback): Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
I pushed a fix that do not processes URL aliases until bootup is finished.
This should fix properly the issue.
Ma...
Ermal Luçi
04:12 PM Bug #4746 (Feedback): captive portal allowed hostnames not loaded into table at boot time
Actually filterdns was not updated with changes done to ipfw patches for 10.1.
Now it should properly do its task.
Ermal Luçi
02:00 PM Bug #4651: Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
Applied in changeset commit:cba32cb1d87b813792a0f8caaf68a22f66af76e3. Ermal Luçi
02:00 PM Bug #4651: Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
Applied in changeset commit:8c9216d5f2be3dda86032b24b187aba3328db0a8. Ermal Luçi
01:52 PM Bug #4651 (Feedback): Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser
Just a global correction. Ermal Luçi
01:53 PM Bug #4712 (Feedback): Wizard hostname validation rejects upper case letters
Ermal Luçi
01:50 PM Bug #4705: Language selection is not functional
Applied in changeset commit:7a923e09da7a668b56842fb86cb2871f2131c2e5. Renato Botelho
01:50 PM Bug #4705 (Feedback): Language selection is not functional
Applied in changeset commit:5f61deb33367d428357c2d873ea22818c2813dcd. Renato Botelho
12:59 PM pfSense Packages Feature #4581: Add dshield-sensor port to pfPorts
Okay I give up you can close this. Robert Nelson
10:09 AM Revision c3b3e9c7: simplify is_ipaddrv4() and fix zero-padding issue
Fixes these two issues:
1) The historical workaround of testing IPv4 for validity by (a) converting to long (b) conv...
Stilez y
09:41 AM Revision 85616372: Add a note that these files don't have to be converted as they'll be removed from the next release.
Refs. #229 Sander van Leeuwen
09:30 AM Revision e5cb3cf8: - Resize form-control (inputs, selects, etc.) with CSS
- Use default width (100%) for smaller viewports
Refs. #141
Sander van Leeuwen
08:23 AM Revision a6901ee1: Merge pull request #215 from sbeaver-netgate/services_captiveportal_mac_edit
Services captiveportal mac edit SjonHortensius
08:23 AM Revision 71c259e7: Merge pull request #213 from sbeaver-netgate/services_captiveportal_mac
Services captiveportal mac SjonHortensius
08:22 AM Revision 60ef8f2b: Merge pull request #208 from sbeaver-netgate/services_captiveportal_hostname
Services captiveportal hostname SjonHortensius
08:22 AM Revision 0ee99643: Merge pull request #207 from sbeaver-netgate/services_captiveportal_filemanager
Services captiveportal filemanager SjonHortensius
08:19 AM Revision 7d876cdf: convert type=text to number with valid min, max, placeholder & step #196
Sjon Hortensius
08:01 AM Revision 79955084: Removed unneeded htmlspecialcharacters()
sbeaver
08:01 AM Revision 49c46b6a: interfaces_bridge_edit.php Conversion complete
Ready for review
Notes:
toggles action to be reviewed once toggle JS finalized
sbeaver
04:59 AM Bug #4748 (Not a Bug): Calculation error for disk usage
it's correct, see that FreeBSD disk FAQ. Chris Buechler
03:39 AM Bug #4748: Calculation error for disk usage
https://www.freebsd.org/doc/en_US.ISO8859-1/books/faq/disks.html#idp59442000 Kill Bill
02:09 AM Bug #4748 (Not a Bug): Calculation error for disk usage
take a look at the picture please...
109% of...
Matthias Matthias

06/06/2015

10:36 AM Bug #4738: Setup Wizard can result in invalid LAN DHCP pool calculation
Committed by https://github.com/pfsense/pfsense/commit/3a19fd4a84d358ff8e6c9eedcad5b11f7f570fa8
and also to 2.2 bran...
Phillip Davis
10:21 AM Bug #4712: Wizard hostname validation rejects upper case letters
Fix committed https://github.com/pfsense/pfsense/commit/16628aa0631bbdceae27f3d2f7ba1fa44ce3b296 Phillip Davis

06/05/2015

08:39 PM Revision 6f62e89f: Clean up, organize, and expand the info presented by status.php. Save the output to individual text files and compress them into a .tgz for later download.
Conflicts:
usr/local/www/status.php
Jim Pingle
08:33 PM Revision 0e7653f4: Clean up, organize, and expand the info presented by status.php. Save the output to individual text files and compress them into a .tgz for later download.
Jim Pingle
03:56 PM Revision eda14265: Fix CARP plugin call for packages, interface was coming through as NULL during CARP events.
Jim Pingle
03:56 PM Revision 49a4a402: Add INIT event for CARP as an alternate for 'backup', otherwise scripts would not take down services during a MASTER->INIT transition.
Jim Pingle
03:55 PM Revision a0be396e: Fix CARP plugin call for packages, interface was coming through as NULL during CARP events.
Jim Pingle
03:55 PM Revision b4aac247: Add INIT event for CARP as an alternate for 'backup', otherwise scripts would not take down services during a MASTER->INIT transition.
Jim Pingle
02:09 PM Bug #4747 (Resolved): DNS Resolver - Insufficient sanity checking for DNS Query Forwarding
When you don't specify any DNS servers, you can still tick the "DNS Query Forwarding" and save the configuration, res... Kill Bill
12:22 PM Revision fd192dbc: Also sanitize OpenVPN static/tls keys in status.php
Jim Pingle
12:22 PM Revision 1557716b: Also sanitize OpenVPN static/tls keys in status.php
Jim Pingle
10:40 AM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
I have experienced a lot of crashes (hard crash that triggers the box to reboot) on 2 different RCC-VE 2440 units (ig... → luckman212
09:32 AM Bug #3973: Route 53 dynamic DNS provider fails to update record
Here is the patch I am using with the System Patches package to work around this issue in 2.1:... Jim Riggs
02:43 AM Bug #4653: mtree dies in post_upgrade_command during upgrade from 8.x and earlier
i attempted 2.1.4 to 2.2.2 48hours ago it ran into this error many times, never rebooted on its own
Jun 3 02:34:3...
James Starowitz
01:46 AM Bug #4655: IPsec: Enable bypass for LAN interface IP behaviour is reversed
Can we please revert the broken commit and fix the description until this is recoded properly? Kill Bill

06/04/2015

09:33 PM Bug #4665 (Resolved): strongswan duplicates reqid at times, causing failures with multi-P2
fixed Chris Buechler
09:23 PM Bug #4739 (Resolved): growl notifications cause excessive delays when configured with non-resolvable hostname
fixed Chris Buechler
08:42 PM Bug #3314: Traffic graph shows 2X the actual traffic on VLAN interfaces.
this looks to work fine. Will leave for additional feedback.
If anyone else can help test, please try the latest ...
Chris Buechler
08:33 PM Revision db794357: Update "status_interfaces.php"
Move the "break" and the "endforeach" statements so that the DL and DIV tags are closed properly for every interface Colin Fleming
08:16 PM Bug #4746 (Resolved): captive portal allowed hostnames not loaded into table at boot time
Configure CP with one or more passthrough hostnames, and filterdns runs correctly and logs that it's adding entries: ... Chris Buechler
08:08 PM Revision dc6695c3: Setup Wizard can result in invalid LAN DHCP pool calculation
1) consider where the LAN IP is in the subnet range and then put the
DHCP pool in the biggest remaining segment, eith...
Phil Davis
08:07 PM Revision 3a19fd4a: Merge pull request #1706 from phil-davis/setupwizardlan
Renato Botelho
08:06 PM Revision b3bba7fe: Improve setup wizard host name check
Redmine #4712
It seems good enough to make the regex strings here be "reasonable". The full checks are done after pre...
Phil Davis
08:06 PM Revision 16628aa0: Merge pull request #1707 from phil-davis/patch-1
Renato Botelho
06:48 PM Revision 1b245100: Merge pull request #310 from ExolonDX/patch-3
Tidy up HTML5 "label" in login page SjonHortensius
06:47 PM Revision 93c1b984: Merge pull request #311 from ExolonDX/bootstrap
Update "interfaces_qinq.php" SjonHortensius
03:05 PM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
FreeBSD PR is https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200323 Chris Buechler
03:04 PM Revision de4a1c84: Update "interfaces_qinq.php"
Remove "colon" character at beginning of the file Colin Fleming
02:49 PM Revision 17ef09c3: Tidy up HTML5 "label" in login page
The "for" attribute of the "label" element must refer to a form control.
http://www.w3.org/TR/html-markup/label.html...
Colin Fleming
02:25 PM Revision 4701e802: Merge pull request #308 from ExolonDX/bootstrap
Remove duplicate closing bracket SjonHortensius
02:23 PM Revision 7ac86a5f: Remove duplicate closing bracket
Remove duplicate closing bracket Colin Fleming
02:17 PM Revision d719fdd1: Merge pull request #307 from ExolonDX/patch-1
Remove duplicate closing bracket SjonHortensius
02:16 PM Revision bf980226: Remove duplicate closing bracket
Remove duplicate closing bracket Colin Fleming
07:48 AM Bug #4653: mtree dies in post_upgrade_command during upgrade from 8.x and earlier
I was testing a 2.1.5 to 2.2.3 upgrade for something else and noticed that mtree ran OK (see the attached upgrade log... Jim Pingle
02:05 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Well, I tested the pfBNG case (i.e., restore the config with tons of URL aliases on a new box). Down to under 2 minut... Kill Bill

06/03/2015

06:10 PM Bug #4703: Inconsistent availability of direction on CP IP/MAC/hostname passthrough
there is a related issue in that icon_pass.gif is shown for direction "both", so configs from older versions where th... Chris Buechler
05:15 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
Kill Bill: mind sharing any specifics on what you've seen? How long did it take to boot before, and how long does it ... Chris Buechler
01:58 PM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
*Much* better now... ;) Kill Bill
01:05 AM Bug #4442: Boot sits at "Configuring firewall" for long time with hostnames, URL Tables, where DNS non-functional
A big portion of the issue with URL table aliases is file_download can be attempted many times during filter reload w... Chris Buechler
03:08 PM Bug #4745 (Not a Bug): Reassignment of devices after config restore
After a configuration restore on new hardware with new physical interface names whiach doesn't mtch the old ones the ... mete *
02:30 PM Bug #4742: nfe0 NIC shows no carrier after interface configuration
There are multiple Ion 330 BIOS updates mentioning "improve LAN compatibility" on the ASUS website. Perhaps start th... Kill Bill
11:43 AM Bug #4742: nfe0 NIC shows no carrier after interface configuration
Is there a way to tell what is being done to the interface when it is being configured? I can install and replicate ... Adrien Carlyle
11:40 AM Bug #4742 (Needs Patch): nfe0 NIC shows no carrier after interface configuration
looks to be a driver issue of some sort that needs to be replicated on stock FreeBSD and reported upstream. Chris Buechler
09:01 AM Bug #4742: nfe0 NIC shows no carrier after interface configuration
I was able to get the device working properly by manually restoring my alix config.xml to the device. On bootup I w... Adrien Carlyle
08:56 AM Bug #4742 (Needs Patch): nfe0 NIC shows no carrier after interface configuration
I am able to use the 2.2.2 memstick image to boot up an asrock ion330 based computer. I am able to install pfsense ... Adrien Carlyle
11:42 AM Todo #4744 (Resolved): Replace pecl-APC by opcache
Pecl APC is deprecated and should be replaced by php55-opcache Renato Botelho
11:39 AM Bug #4741 (Feedback): IPSEC mobile client problem
this is probably the Android racoon bug with NAT-D. what does the client log show? Chris Buechler
08:35 AM Bug #4741 (Not a Bug): IPSEC mobile client problem
Problem with mobile client connection.
I seted up IPSEC vpn with this instruction (https://doc.pfsense.org/index.ph...
ruben rpuserh
09:43 AM Bug #4743 (Rejected): unexpected end of file in /etc/inc/captiveportal.inc on line 248
Please post on the forum for assistance. Most of the time this error is from a dangerous function in the squid 3 pack... Jim Pingle
09:41 AM Bug #4743 (Rejected): unexpected end of file in /etc/inc/captiveportal.inc on line 248
Hi, I'm new to BSD family
I recently replaced my network utm to pfsese
but a message containing the bug below is sh...
Mehrdad Vesal
06:44 AM Bug #4740 (New): Intel wireless kernel panic in infrastructure mode with WPA
I've got permanent kernel panic and reboot with intel wireless 4965 minipcie card in WAN infrastructure mode when wpa... Vladimir Chernyshov
06:05 AM Revision a320af18: A number of things block waiting for file download timeouts, sometimes multiple times across multiple files (many URL Table aliases, for instance). The long timeout causes very long boot times (10-20+ minutes) on many configs with pfblocker if booted disconnected from the Internet. This is strictly the timeout for the HTTP/HTTPS connection attempt. Once connected, it can run past that. 5 seconds should be more than enough for any properly-functioning network. Part of Ticket #4442.
Conflicts:
etc/inc/pfsense-utils.inc
Chris Buechler
05:57 AM Revision eefd7773: A number of things block waiting for file download timeouts, sometimes multiple times across multiple files (many URL Table aliases, for instance). The long timeout causes very long boot times (10-20+ minutes) on many configs with pfblocker if booted disconnected from the Internet. This is strictly the timeout for the HTTP/HTTPS connection attempt. Once connected, it can run past that. 5 seconds should be more than enough for any properly-functioning network. Part of Ticket #4442.
Chris Buechler
04:43 AM Bug #4377: pfSense boot freezes after restart in QEMU/KVM
I have the same pb. FreeBSD guests fail to reboot properly if they have more than one CPU (socket, core, and/or threa... Yann Autissier
04:37 AM Revision 9f390fb8: device_type isn't used here
Chris Buechler
04:36 AM Revision 7112bcc8: device_type isn't used here
Chris Buechler
12:33 AM Revision b532745a: Don't call growl if the configured address isn't an IP or resolvable
hostname. Avoids 1 minute timeout delay in fsockopen in growl.class. Cuts
that down to about a 20 second timeout. Tic...
Chris Buechler
12:30 AM Revision dbd919ec: Don't call growl if the configured address isn't an IP or resolvable
hostname. Avoids 1 minute timeout delay in fsockopen in growl.class. Cuts
that down to about a 20 second timeout. Tic...
Chris Buechler

06/02/2015

11:36 PM Bug #4370 (Resolved): ntpd does nothing with selected carp interfaces.
fixed Chris Buechler
01:03 AM Bug #4370: ntpd does nothing with selected carp interfaces.
should be fixed by what I just pushed, leaving for further verification Chris Buechler
07:31 PM Bug #4739 (Feedback): growl notifications cause excessive delays when configured with non-resolvable hostname
pushed a change that takes the delay down from 1 minute to about 20 seconds, which is probably about the best we can ... Chris Buechler
07:28 PM Bug #4739 (Resolved): growl notifications cause excessive delays when configured with non-resolvable hostname
When growl notifications are configured to go to a hostname, and that hostname doesn't resolve, it causes a 1 minute ... Chris Buechler
04:56 PM Revision f135a010: trigger a reboot after restoration of full backup. Ticket #4107
Chris Buechler
04:53 PM Revision 813d71c1: trigger a reboot after restoration of full backup. Ticket #4107
Chris Buechler
04:39 PM Revision 239f204b: Improve setup wizard host name check
Redmine #4712
It seems good enough to make the regex strings here be "reasonable". The full checks are done after pre...
Phil Davis
01:12 PM Revision 8c288bce: Deprecate /usr/local/bin/3gstat
Renato Botelho
01:12 PM Revision 6aab8d87: Deprecate /usr/local/bin/3gstat
Renato Botelho
12:29 PM Bug #4113: multiple instances of /var/db/rrd/updaterrd.sh
I can't update this system: #4345.
That and other fixes have high prio for me to get #4345 fixed fast.
Grischa Zengel
11:53 AM Bug #4107 (Feedback): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
fixed, leaving to verify again once it's in a snapshot build. Chris Buechler
11:41 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Denny Page wrote:
> Wow, there's a name I haven't heard in 20+ years.
Yes, and cmb shouldn't have quoted a privat...
Jim Thompson
11:38 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Kill Bill wrote:
> Updated ZFS howto for people who are on full install and are simply tired of this... https://foru...
Jim Thompson
11:38 AM Bug #4712: Wizard hostname validation rejects upper case letters
Suggested good-enough fix https://github.com/pfsense/pfsense/pull/1707 Phillip Davis
11:33 AM Revision b7cf171b: Minor wizard text fixups
Phil Davis
11:33 AM Revision 379dc6f2: Supply current WAN gateway name to wizard
As the name of the WAN gateway is not always WANGW.
Should fix redmine #4713
Phil Davis
11:33 AM Revision 9f5e6dc5: Merge pull request #1705 from phil-davis/wizard-text
Renato Botelho
11:31 AM Revision 6faaecf9: Merge pull request #1704 from phil-davis/bug4713
Renato Botelho
10:52 AM Bug #4028: Wireless Obytes counter always 0
Merged even for 2.2.3 the patch. Ermal Luçi
09:33 AM Revision aa181833: Setup Wizard can result in invalid LAN DHCP pool calculation
1) consider where the LAN IP is in the subnet range and then put the
DHCP pool in the biggest remaining segment, eith...
Phil Davis
07:12 AM Bug #4515: Unable To Set MTU on LAGG Interface If No VLANs Assigned
I hit this issue this morning.
There seems to be no way to set the MTU of a LAGG interface without adding a VLAN, o...
Steve Wheeler
07:12 AM Bug #4642: OpenVPN process status stopped... but its running
Hi guys.
No... I do not have watchdog on any system... overall pfsense stabitlity as a router is superb.
BUt you'...
Alejandro Olivan
03:33 AM Bug #4642: OpenVPN process status stopped... but its running
This also happens to me on "random" systems. I have an example on an APU 64-bit nanoBSD 2.2.2 system now. This is the... Phillip Davis
03:25 AM Bug #4642: OpenVPN process status stopped... but its running
Install the Service Watchdog package to keep your ntpd running. Kill Bill
03:10 AM Bug #4642: OpenVPN process status stopped... but its running
OK... ntpd NTP clock sync is stopped.
NTP clock sync stops after hours or just few days up... this is something we...
Alejandro Olivan
03:00 AM Bug #4642: OpenVPN process status stopped... but its running
OK... I will track those routers behaviour, and report on them.
I updated here talking about openvpn just because it...
Alejandro Olivan
07:06 AM Bug #3815: Gateway monitoring broken
That might all be for naught - I saw over at "#4081":https://redmine.pfsense.org/issues/4081#note-14 that in 2.3 apin... → luckman212
04:33 AM Bug #3815: Gateway monitoring broken
Customer's still rather keen on 2.1, I can possible set up a similar setup soon and try if it still behaves similarly... Tobias Wolter
06:24 AM Revision 75eef6ca: Clarify DNS Forwarder and Resolver both apply in these places. partially Ticket #3730
Chris Buechler
06:22 AM Revision 796cc218: Clarify DNS Forwarder and Resolver both apply in these places. partially Ticket #3730
Chris Buechler
06:06 AM Revision c4b3bd50: Use CARP IPs that are configured. Ticket #4370
Chris Buechler
06:06 AM Revision 729f899f: Use CARP IPs that are configured. Ticket #4370
Chris Buechler
04:42 AM Bug #4738: Setup Wizard can result in invalid LAN DHCP pool calculation
Pull request https://github.com/pfsense/pfsense/pull/1706 Phillip Davis
03:52 AM Bug #4738 (Resolved): Setup Wizard can result in invalid LAN DHCP pool calculation
The DHCP pool automatic calculation on LAN done by the Setup Wizard always starts the pool at ".10" in relation to th... Phillip Davis
04:33 AM Revision 4f514c63: Minor wizard text fixups
Phil Davis
03:16 AM Feature #4260: Add ECP DH key groups support
This is the same a #4683 Ermal Luçi
03:14 AM Feature #4260 (Feedback): Add ECP DH key groups support
These are merged in as from pull request just the ticket was not mentioned in the commit log. Ermal Luçi
01:50 AM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
Grischa Zengel wrote:
> Will be there a real solution in next time or should I add an extra nic to these servers?
...
Chris Buechler
01:36 AM Revision 42a55691: Supply current WAN gateway name to wizard
As the name of the WAN gateway is not always WANGW.
Should fix redmine #4713
Phil Davis
01:23 AM Bug #3730 (Resolved): Router advertisement advertises gateway address as dns server even if the dns forwarder is disabled
this works as it should. If DNS Forwarder or Resolver are enabled, and the boxes are blank, the interface IP will be ... Chris Buechler
01:08 AM Bug #4210: Bring back a FTP proxy
the FTP Proxy package suffices for 2.2.x. Should consider whether to build it in by default for 2.3 or future versions. Chris Buechler
12:46 AM Bug #4678 (Resolved): DHCPv6 with static entries, Apply configuration button never goes away
works, thanks Chris Buechler

06/01/2015

11:58 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Wow, there's a name I haven't heard in 20+ years. Denny Page
10:59 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
sync definitely avoids the root issue. I have a system that's now upwards of 1000 power cycles with 0 issues with syn... Chris Buechler
12:06 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
It was apparently an error in my notes... I looked back at a forum post I made when I first tested that mid-April and... Jim Pingle
11:58 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Does sync actually avoid the issue? Update 4 suggested that this was not the case...
Sync for root fs generally se...
Denny Page
11:15 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Updated ZFS howto for people who are on full install and are simply tired of this... https://forum.pfsense.org/index.... Kill Bill
06:39 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
"sync" seems like "a good thing" on root file system "/" for pfSense use cases anyway. pfSense uses would not modify ... Phillip Davis
02:25 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
It's not fsck.
it's likely a bug in SU (with or without journaling.)
the fix (for now) is to mount / "sync" on all ...
Jim Thompson
11:51 PM Bug #4701 (Resolved): WebGUI alias name changes does not reflect in NAT-Outbound
works. Thanks! Chris Buechler
11:50 PM Revision b4576c90: really fix botched manual merge request. Ticket #4720
Chris Buechler
11:42 PM Bug #3872 (Resolved): Enabling a disabled VLAN subinterface with multiple CARP VIPs configured causes system crash
I created a config matching Stuart's description, and could easily replicate the panic after disabling and enabling a... Chris Buechler
11:09 PM Revision 78b0dd57: fix manual merge mistake. Ticket #4720
Chris Buechler
11:02 PM Bug #1884 (Confirmed): Lacking update validation on console upgrade
this needs the platform check same as manual update in web interface. Chris Buechler
10:50 PM Revision ba79655c: set the serial port appropriately for RCC-VE platforms. sync from factory
repo. Ticket #4720
Conflicts:
etc/inc/pfsense-utils.inc
Chris Buechler
10:45 PM Revision f877f77f: set the serial port appropriately for RCC-VE platforms. sync from factory
repo. Ticket #4720 Chris Buechler
10:40 PM Bug #4081 (Needs Patch): Apinger reporting incorrect latency
apinger is being replaced in 2.3, which will resolve outstanding issues here. Chris Buechler
10:38 PM Bug #4235 (Resolved): missing 'reply-to' in rules for mobile-ipsec
works. having route-to and reply-to the way it is now is fine. Chris Buechler
10:37 PM Revision 89953fe7: Return IP correctly in get_interface_ip for gateway groups specifying a
VIP. Ticket #4661 Chris Buechler
10:36 PM Revision e6807c5a: Return IP correctly in get_interface_ip for gateway groups specifying a
VIP. Ticket #4661 Chris Buechler
10:35 PM Feature #2770 (Rejected): add "device mptable" to amd64 builds to make pfsense boot on soekris6501
has potential to break other things, and we don't really care about Soekris hardware Chris Buechler
10:31 PM Bug #2675 (Resolved): /tmp/.rc.prunecaptiveportal.running can be present on boot
fixed Chris Buechler
10:29 PM Bug #3836 (Confirmed): field redirect target port must be quit in a specific way to keep conntent
Chris Buechler
10:24 PM Bug #3815 (Feedback): Gateway monitoring broken
It's definitely not as simple as gateway monitoring being broken, as it works fine in general. Might be some edge cas... Chris Buechler
10:16 PM Feature #2885 (Closed): loadbalancing should be more tweakable
haproxy is available for such needs Chris Buechler
10:16 PM Bug #3027 (Confirmed): input_errors2Ajax function
Chris Buechler
10:15 PM Bug #3116 (Confirmed): IPsec peer identifiers - ASN.1 does not take options
Chris Buechler
09:48 PM Bug #3205 (Resolved): Partial system freeze when disconnecting USB 3G stick
thanks for the feedback, Bipin. Chris Buechler
09:47 PM Bug #3307 (Closed): rc.update_bogons.sh doesn't filter out all private address space
this works as intended. Private networks is meant for RFC 1918, bogons has the remainder. Chris Buechler
09:45 PM Feature #2439 (Resolved): XEN Para-virtualized Drivers Support
this came along with the FreeBSD 10.1 base OS in 2.2.x versions Chris Buechler
09:44 PM Feature #2035 (Needs Patch): Add hw.intr_storm_threshold in sysctl tunning list.
users can always add it themselves if necessary. Chris Buechler
09:42 PM Feature #1859 (Resolved): default SSH-key should at least use 2048 bit RSA-keys
this has been the case for some time Chris Buechler
09:40 PM Feature #1858 (Resolved): default SSL-cert should at least use 2048 bit RSA-keys
this was done quite some time ago Chris Buechler
09:38 PM Feature #1450 (Closed): XMLRPC syncs all VPN types *except* PPTP
PPTP is dead. Chris Buechler
09:37 PM Feature #1258 (Needs Patch): dyndns - DNS Made Easy
if you could submit this as a pull request on github, we could get that added.
Chris Buechler
09:35 PM Feature #1170 (Resolved): Certificates tab should have revoke option in addition to delete
this was implemented years ago Chris Buechler
09:34 PM Bug #4113 (Feedback): multiple instances of /var/db/rrd/updaterrd.sh
is this replicable for you on 2.2.2? Chris Buechler
09:33 PM Feature #4264 (Closed): Make distinction between general & security updates, while applying the latter automatically
some of that falls into work Renato's doing for 2.3 and newer in improving the update system in general. The remainde... Chris Buechler
07:43 PM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
Will be there a real solution in next time or should I add an extra nic to these servers? Grischa Zengel
06:22 PM Bug #4241 (Needs Patch): Installer display glitch on "Install Bootblocks" screen
bsdinstaller is on borrowed time, won't fix this since it should be replaced in 2.3. Chris Buechler
06:18 PM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
Matt: haven't heard of it on ALIX but same could impact it also. does disabling the host resources MIB prevent the is... Chris Buechler
06:15 PM Feature #4732: Add MS-CHAPv2 option to L2TP Configuration
thanks, we'll review for 2.3. Chris Buechler
06:14 PM Bug #754 (Needs Patch): hifn driver and AES192 and 256
if someone wants to put the efforts into fixing this (if it isn't already on 2.2x with FreeBSD 10.1 base), please pur... Chris Buechler
06:07 PM Bug #4720 (Feedback): pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
that should fix in 2.2.3 and newer, leaving for further verification. Chris Buechler
06:04 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
This commit is also required to get the QinQ interface selection correct:
https://github.com/stephenw10/pfsense/comm...
Steve Wheeler
05:29 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
I have a set if patches that attempt to address the three points above. They seem to allow QinQ to work in my testing... Steve Wheeler
05:42 PM Bug #4735 (Duplicate): Serial console doesn't work anymore after config restore on RCC-VE systems
duplicate of #4720 Chris Buechler
05:36 PM Bug #4661 (Feedback): OpenVPN client can't assign to GWGroup specifying VIPs
fixed by what I just pushed, leaving for feedback. Will be in June 2 and newer 2.2.3 snapshots, or can gitsync to REL... Chris Buechler
04:53 PM Revision e1eee3d2: Use 'host!' flag when setting CURLOPT_INTERFACE, as recommended by CURL docs
Renato Botelho
04:53 PM Revision 84522eba: Pass interface to CURLOPT_INTERFACE instead of IP addres, also use 'if!' flag to avoid CURL trying to resolve the interface name
Renato Botelho
04:53 PM Revision 3e8ee192: Use 'host!' flag when setting CURLOPT_INTERFACE, as recommended by CURL docs
Renato Botelho
04:52 PM Revision 4486b751: Pass interface to CURLOPT_INTERFACE instead of IP addres, also use 'if!' flag to avoid CURL trying to resolve the interface name
Renato Botelho
01:16 PM Bug #4642: OpenVPN process status stopped... but its running
it's not a general service status problem. The issue described here is with OpenVPN. An issue there with FreeRADIUS, ... Chris Buechler
03:35 AM Bug #4642: OpenVPN process status stopped... but its running
Hi... I got some time to play a little bit with a pair of pfsense boxes updated to 2.2.1, nanobsd installs, suffering... Alejandro Olivan
01:10 PM Bug #4607: Bridge+CARP crashes/freezes pfSense
it appears this works fine in 2.2.3. It's at least not replicable in the same way it is in previous releases. Vasco, ... Chris Buechler
11:18 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
it's in 2.2.3 snapshots @ snapshots.pfsense.org. Chris Buechler
11:04 AM Bug #4607: Bridge+CARP crashes/freezes pfSense
Is the patch publicly available? Vasco Freire
12:33 PM Revision 96f2b118: Removed debugging accidentally left in place
sbeaver
12:29 PM Revision 37436633: Removed unneeded form as suggested
Thanks sbeaver
12:25 PM Revision 44e84786: Removed unneeded form as suggested and retested
Thanks sbeaver
12:09 PM Revision d014442c: <tt> => <pre>
Class changed from ‘notes’ to ‘help-block’ as suggested to accommodate
future global “verbose help” setting.
sbeaver
11:55 AM Todo #4737 (Resolved): Update CloudFlare dyndns to use new API
Current implementation is using a deprecated API, defined here: https://www.cloudflare.com/docs/client-api.html Renato Botelho
02:44 AM Bug #4519: Disk Corruption
so much for "never happens on reboot"... Jim Thompson
01:20 AM Bug #4028: Wireless Obytes counter always 0
Phil,
We need to sync the patch to the RELENG_2_2 branch. (This work is in progress, but not done.)
Jim Thompson

05/31/2015

01:38 PM Revision 7f8f8808: widget fixes; remove subpanel & show save() when collapsing too
Sjon Hortensius
12:24 PM Revision b144d13d: Merge pull request #1703 from phil-davis/code-style-more
Renato Botelho
05:10 AM Revision 086cf944: Code style bits and pieces from etc
Phil Davis

05/30/2015

09:43 PM pfSense Packages Bug #4736 (Resolved): ladvd crashes, dumps core
ladvd consistently dumps core on my firewall.
See attached core file (bzip'd).
I have only seen this happen on one ...
Adam Thompson
04:40 PM Revision 5be30604: Merge pull request #1702 from phil-davis/system-usermanger
Renato Botelho
03:57 PM Revision 73fa304b: Code style system user manager
Phil Davis
03:08 PM Revision 3b9dfaf2: Allow option to specify just 1 of user and pass in OpenVPN .up file
As per comment in https://redmine.pfsense.org/issues/3633 sometimes the
server end only requires a password, no usern...
Phil Davis
03:07 PM Revision 5e50c5b3: Merge pull request #1701 from phil-davis/openvpn-user-pass
Renato Botelho
03:01 PM Revision 7304c023: Allow option to specify just 1 of user and pass in OpenVPN .up file
As per comment in https://redmine.pfsense.org/issues/3633 sometimes the
server end only requires a password, no usern...
Phil Davis
02:39 PM Revision 19a12e06: Replae backtickes by mwexec()
Renato Botelho
02:39 PM Revision d6daed60: We need to at least setup the serial port before we try to blast
config data to it. My system was hanging during boot because cat
was couldn't output gps.init to the port.
Robert Noland
02:37 PM Revision 417008f7: Replae backtickes by mwexec()
Renato Botelho
02:33 PM Revision 6d9f1df4: Merge pull request #1551 from rnoland/master
Renato Botelho
01:59 PM Revision 139ca549: remove pointless filter on dhcp static mappings table
Will Boyce
01:57 PM Revision 4199bda9: remove pointless filter on dhcp static mappings table
Will Boyce
01:48 PM Revision 241c1dab: Merge pull request #219 from sbeaver-netgate/services_dhcp_edit
Convert services_dhcp_edit SjonHortensius
01:45 PM Revision 8dbf14e3: correct setHelp calls to use variables #218
Sjon Hortensius
01:44 PM Revision df4e04b6: mini typo
Sjon Hortensius
01:40 PM Revision 8b870edb: Merge pull request #218 from sbeaver-netgate/services_captiveportal_vouchers_edit
Convert services_captiveportal_vouchers_edit SjonHortensius
01:36 PM Revision a47eec85: Merge pull request #1585 from jlduran/dnsmadeeasy
Renato Botelho
01:34 PM Revision ae2d7e0a: Implement working generate-key button, fix useless escaping #217
Sjon Hortensius
01:26 PM Revision c92203a9: Merge pull request #1700 from phil-davis/system-hr
Renato Botelho
01:25 PM Revision 927eecf3: Return link-local address when we are only requesting IPv6 prefix only if there is no global IPv6 address. In some cases global SLAAC IPv6 address might be present when using DHCPv6. Fixes #4483
k-paulius
01:07 PM Revision b5249aa3: Fix whitespace in textareas, remove it from tpl
Sjon Hortensius
01:05 PM Revision d9ed341d: Removed unneeded gettext/htmlspecialcharacter
sbeaver
01:05 PM Revision 1657ed6a: services_captiveportal_vouchers.php Conversion complete
Ready for review sbeaver
01:05 PM Revision d9509b6e: Remove debug
sbeaver
01:05 PM Revision 3ac0f8a1: Merge pull request #1590 from k-paulius/fix-4483v2
Renato Botelho
01:01 PM Revision d38bd840: Code style system h and r
Phil Davis
12:57 PM Revision b033e297: Merge pull request #1699 from phil-davis/system-g
Renato Botelho
12:57 PM Revision 5d15bda8: Merge pull request #1698 from phil-davis/system-firmware
Renato Botelho
12:56 PM Revision a90bc47a: Merge pull request #1697 from phil-davis/patch-3
Renato Botelho
12:55 PM Revision e4a1022d: Merge pull request #1696 from phil-davis/system-c
Renato Botelho
12:55 PM Revision b3405d87: Merge pull request #1695 from phil-davis/system-a
Renato Botelho
12:54 PM Revision 031d0bbb: Merge pull request #1694 from phil-davis/patch-2
Renato Botelho
12:53 PM Revision e1cfbede: Merge pull request #1693 from phil-davis/patch-1
Renato Botelho
12:44 PM Revision e2cf6001: Merge pull request #212 from sbeaver-netgate/services_captiveportal_ip_edit
Convert services_captiveportal_ip_edit SjonHortensius
12:41 PM Revision 5a9aa88c: Merge pull request #210 from sbeaver-netgate/services_captiveportal_hostname_edit
Convert services_captiveportal_hostname_edit SjonHortensius
12:32 PM Revision 632c94b3: Merge pull request #203 from sbeaver-netgate/interfaces_wireless_edit
Convert interfaces_wireless_edit SjonHortensius
12:31 PM Revision 60da85fb: Merge pull request #205 from sbeaver-netgate/pkg_mgr_settings
Convert pkg_mgr_settings SjonHortensius
12:30 PM Revision e0c7b2fe: Code style system g
Phil Davis
12:28 PM Revision 0704fb22: Merge branch 'bootstrap' of ssh://github.com/SjonHortensius/pfsense into bootstrap
Sjon Hortensius
12:26 PM Revision 5b884ab2: Merge pull request #200 from sbeaver-netgate/interfaces_lagg_edit
Convert interfaces_lagg_edit SjonHortensius
12:25 PM Revision d3e10bf9: correct indenting #199
Sjon Hortensius
12:24 PM Revision 9d20294d: Merge pull request #199 from sbeaver-netgate/interfaces_gre_edit
Convert interfaces_gre_edit SjonHortensius
12:23 PM Revision 9e38e8bd: fix indenting, remove htmlspecialchars refs #198
Sjon Hortensius
12:22 PM Revision aa429c34: Merge pull request #198 from sbeaver-netgate/interfaces_gif_edit
Convert interfaces_gif_edit SjonHortensius
12:17 PM Revision a41fd4a7: remove unwanted/needed caption
Sjon Hortensius
12:16 PM Revision 69ddae89: Fixed $tab_array[], added NAV tags
sbeaver
12:16 PM Revision e78276d8: interfaces_vlan.php Conversion complete
Page updated for consistency with the other interface_* pages. sbeaver
12:14 PM Revision 4cde9954: remove unwanted ondblclick
Sjon Hortensius
12:14 PM Revision 28f697ab: Fixed $tab_array[], added NAV tags
sbeaver
12:14 PM Revision 719e4eeb: interfaces_wireless.php Conversion complete
Ready for review sbeaver
12:13 PM Revision 006d23d4: Fixed tab_array[], wrapped 'Add" button in <nav>
sbeaver
12:13 PM Revision 68a7712c: interfaces_ppps.php Conversion complete
Ready for review sbeaver
12:11 PM Revision fb455ab4: emulating 9c7a4bcf but without converting back to spaces... #185
Sjon Hortensius
12:09 PM Revision 620e28a7: interfaces_lagg.php Conversion complete
Ready for review sbeaver
12:05 PM Revision 461f8fd1: Fixed $tab_array. Removed unneeded class
sbeaver
12:05 PM Revision cf46aed2: <nav> tags added as suggested
The ability to double-click on a table row to edit that entry seemed
like a useful feature. Are you sure we should re...
sbeaver
12:05 PM Revision 77d42518: Added missing gettext()
And zapped some &nbsp; sbeaver
12:05 PM Revision 34998435: interfaces_bridge.php Conversion complete
Ready for review sbeaver
12:03 PM Revision 360d6b44: remove unused variables refs #173
Sjon Hortensius
12:02 PM Revision 9ec9f2a0: Trivial formatting changes. removed unneeded script
sbeaver
12:02 PM Revision b6596595: Updated as suggested
Thanks sbeaver
12:02 PM Revision 310cb51f: Add table-responsive div
sbeaver
12:02 PM Revision 8edfd911: diag_logs_filter.php Conversion complete
Ready for review.
This conversion was fairly involved due to the in-line controls, dual
filter forms and the resolvin...
sbeaver
11:59 AM Revision e13a5434: Removed debugging
sbeaver
11:59 AM Revision d946c026: Fixed $tab_array[]
sbeaver
11:59 AM Revision 62707e1a: diag_ipsec_sad.php conversion complete
Ready for review. sbeaver
11:57 AM Revision 7a90e30f: Merge pull request #158 from sbeaver-netgate/system_firmware_settings
Convert system_firmware_settings.php SjonHortensius
11:56 AM Revision a3f6729f: Merge pull request #154 from sbeaver-netgate/diag_resetstate
Convert diag_resetstates.php SjonHortensius
11:55 AM Revision dee9fb08: Merge pull request #152 from sbeaver-netgate/status_rrd_graph
Convert status_rrd_graph.php SjonHortensius
11:51 AM Revision 93bd9e70: Merge pull request #206 from sbeaver-netgate/services_captiveportal_edit
Convert services_captiveportal_edit SjonHortensius
11:26 AM Revision 0e88de0c: Code style system firmware
Phil Davis
10:51 AM Revision e26ad18a: system_firmware_restorefullbackup add missing p end tag
and format this block so it is clear which tags start and end where. Phil Davis
08:30 AM Bug #4483: SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
Applied in changeset commit:927eecf3e31eea8ce431317664ab78e8bea524da. Anonymous
08:30 AM Bug #4483 (Feedback): SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
Applied in changeset commit:60802fadefe83c445f79f8889c0b57c301ee8128. Anonymous
08:22 AM Revision 56b1ed39: Code style system C
Phil Davis
07:07 AM Revision 2ee8dea1: Code style system a
Phil Davis
05:33 AM Revision a880f8b8: system_authservers text typo
Phil Davis
05:00 AM Revision efa92471: system_advanced_network small grammar changes
"to tunnel" instead of "to tunneling"
Text for "prefer IPv4" reads better as 2 sentences.
Phil Davis
02:12 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Chris Buechler wrote:
> That's after fsck (including after multiple runs).
Well what I meant is actually whether ...
Kill Bill
01:57 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
That's after fsck (including after multiple runs). They aren't "constantly damaged", only after unclean shut downs, a... Chris Buechler
01:49 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Chris Buechler wrote:
> If using SU, you'll end up with 0 byte files. Without SU, you'll have corrupted files contai...
Kill Bill
01:33 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
updated subject to narrowed down problem.
With SU, with or without J, you end up with 0 byte master.passwd, passw...
Chris Buechler

05/29/2015

11:21 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Nano using SU+J = bad. Either go back to plain sync or just SU. All journaling does is *double all meta-data writes* ... ky41083 -
12:23 PM Revision 5dcec9f2: Merge pull request #1692 from phil-davis/services-unbound
Renato Botelho
12:07 AM Bug #4403: Enabling SNMP causes kernel panic with APU with empty SD card slot
I've just hit this issue myself using an ALIX 2D13. There are no other devices except for the CF card. Matt Meyer

05/28/2015

05:30 PM Revision e92ee598: Code style services unbound
Phil Davis
02:05 PM Revision a8e31a33: Merge pull request #1471 from Talyrius/master
Renato Botelho
02:01 PM Revision 193b6834: L7 protocols: add rtmp, sync bittorrent, finger and quake-halflife with l7-protocols
Renato Botelho
01:43 PM Revision ebddb936: Adding the Appropriate RA Flags for "Stateless DHCP"
Aqueeb Qadri
01:43 PM Revision a450c443: Added the Stateless DHCP Dropdown here
Aqueeb Qadri
01:40 PM Revision 001914d1: Merge pull request #1444 from oliwel/feature/easyrule-unblock
Renato Botelho
01:35 PM Revision c6872b3e: Merge pull request #1033 from aqueeb/master
Renato Botelho
01:28 PM Revision 146d20bd: Merge pull request #1691 from phil-davis/services-rsw
Renato Botelho
11:18 AM Bug #4686: Rekeyed SAs are not properly removed
Tried with this image:
pfSense-2.2.3-DEVELOPMENT-1g-amd64-nanobsd-upgrade-20150521-0706.img.gz
It broke IPsec con...
Ivo B
10:01 AM Bug #4735 (Duplicate): Serial console doesn't work anymore after config restore on RCC-VE systems
Hi,
I installed pfsense from the NETGATE ADI RCC-VE memstick image onto a RCC-VE 2440. Everything worked perfectly...
Dominic Blais
08:50 AM Bug #4233 (Feedback): Inconsistent handling of seperators in easyrule cli
Applied in changeset commit:e4d8943c59cfceba229e2689d67601127e8ceb1a. Anonymous
12:07 AM Bug #4523 (Confirmed): master.passwd/group file corruption may occur after kernel panic or unclean shut down
still an issue Chris Buechler

05/27/2015

10:07 PM Feature #4734 (Needs Patch): SSHD Logs, select facility to log to
Hi,
It would be handy to have the ability to log sshd to a different facility (like local4). Just one item in the ...
Russell Morris
04:54 PM Revision 56463a6c: Code style services r s w
Phil Davis
03:10 PM Bug #4733 (Not a Bug): Soekris Boot Problem
please post to the forum or mailing list for assistance. Chris Buechler
03:05 PM Bug #4733 (Not a Bug): Soekris Boot Problem
Hi
After a fresh and successful installation on my soekris net6501 on the internal harddrive, pfSense won't boot.
...
A B
02:52 PM Revision a6f973a1: Fix comment style
Oliver Welter
02:14 PM Revision face47a5: Revert "Disable this tunable for now. Ticket #4523"
This reverts commit 85a37985b15c7a7c935d0028aa7a520110c2e649. Ermal Luçi
02:13 PM Revision 36314cba: Revert "Disable this tunable for now. Ticket #4523"
This reverts commit ab37f56f404a41dc5c5c26a83d594f0f883bd88d. Ermal Luçi
12:37 PM Revision e3230c0a: Merge pull request #1081 from PiBa-NL/cert_usage
Ermal Luçi
11:35 AM Bug #4028: Wireless Obytes counter always 0
I am not clear - is the fix coming just in 2.3, or also in he 2.2.3 builds? Phillip Davis
11:05 AM Revision 790bab08: Merge pull request #1690 from phil-davis/diag
Renato Botelho
10:40 AM Revision 699737d9: Code style www diag more bits
Phil Davis
08:51 AM Revision 427d36b4: Ticket #4523 Major changes to how fsck is done.
Follow best practice of using fsck from FreeBSD rc.d/fsck script.
This means run preen mode first and later on tr...
Ermal Luçi
08:50 AM Revision fc123231: Ticket #4523 Run fsck with -C flag and alway in foreground during bootup to prevent any issues that might schedule background mode.
Ermal Luçi
08:49 AM Revision 7fd93993: Ticket #4523 Major changes to how fsck is done.
Follow best practice of using fsck from FreeBSD rc.d/fsck script.
This means run preen mode first and later on try fo...
Ermal Luçi
08:20 AM Revision f2e36920: Ticket #4523 Run fsck with -C flag and alway in foreground during bootup to prevent any issues that might schedule background mode.
Ermal Luçi
03:54 AM Bug #4523 (Feedback): master.passwd/group file corruption may occur after kernel panic or unclean shut down
Improvements on how filesystem check/correction is being done have been merged which should help with corruption to n... Ermal Luçi

05/26/2015

11:30 PM Bug #4674: invalid state table entries after WAN IP change
Interesting workaround! I will have to try this myself as we've had similar problems with SIP devices & Asterisk. → luckman212
08:17 PM Feature #4732: Add MS-CHAPv2 option to L2TP Configuration
I have opened a Pull Request (#"1689":https://github.com/pfsense/pfsense/pull/1689) to discuss this subject. Jose Luis Duran
08:12 PM Feature #4732 (Resolved): Add MS-CHAPv2 option to L2TP Configuration
If you need to validate L2TP/IPSec users with a Windows-based RADIUS Server (NPS/IAS), choosing *CHAP* from *VPN:L2TP... Jose Luis Duran
06:24 PM Revision cedb9a77: Merge pull request #1688 from phil-davis/diag-logs
Renato Botelho
05:40 PM Bug #4028 (Feedback): Wireless Obytes counter always 0
Merged stack from HEAD with the fix on 2.3 Ermal Luçi
05:05 PM Revision 4e3b667c: Code style diag logs again
while making a fix today I noticed that I had done these early-on and
had not tabbed out the HTML nicely...
Phil Davis
11:41 AM Bug #4459 (Resolved): Tzdata is too old (needs to be updated for Russia)
thanks Dmitriy Chris Buechler
11:39 AM Feature #4683 (Feedback): Support for elliptic curve for IPsec on webconfigurator
Chris Buechler
12:41 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Can be closed: Solved with https://github.com/pfsense/pfsense/pull/1649 Lars Pedersen
09:53 AM Revision 9eb84e63: Add tracker rule number to dynamic firewall log
Bug #4730 - the code was not there yet. Phil Davis
09:53 AM Revision 8882e40f: Merge pull request #1687 from phil-davis/patch-1
Renato Botelho
08:45 AM Bug #4383: Firewall log contains IGMP for rules that do not have logging on
Me too, as I also wrote here: https://forum.pfsense.org/index.php?topic=92387.msg511674#msg511674
Hollander Hollander
04:09 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
Yesterday I discovered the same problem. Any chance to fix it in nearest release?
Thanks in advance!
Krzysztof Szczesniak
03:30 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
I have this same issue.
I want to create MultiWan CARP, but when I choice Interface (GW Group Wan1FailoverWan2) on O...
Grzegorz Sliwa
01:31 AM Revision 84e9e531: Add tracker rule number to dynamic firewall log
Bug #4730 - the code was not there yet. Phil Davis

05/25/2015

08:29 PM Bug #4730: Firewall Log Dynamic View missing Block/Allowed Reason
The code was not there in the dynamic firewall log.
This should do it: https://github.com/pfsense/pfsense/pull/1687
Phillip Davis
09:09 AM Bug #4730 (Resolved): Firewall Log Dynamic View missing Block/Allowed Reason
If you hover over the the (Allow/Block) icon in the Dynamic Firewall Log, it only show Block/Allow, and not the rule ... Marc Riley
02:27 PM Revision c5ecdc25: Add support for DNS Made Easy
Documentation:
http://www.dnsmadeeasy.com/dynamic-dns/
Jose Luis Duran
02:10 PM Revision 7d2af373: Call htmlspecialchars() to remove dangerouns chars from zone parameter. Also redirect user to services_captiveportal_zones.php when an invalid zone is passed
Renato Botelho
02:10 PM Revision ac880ee7: Call htmlspecialchars() to remove dangerouns chars from zone parameter. Also redirect user to services_captiveportal_zones.php when an invalid zone is passed
Renato Botelho
12:25 PM Revision 85a37985: Disable this tunable for now. Ticket #4523
Ermal Luçi
12:25 PM Revision ab37f56f: Disable this tunable for now. Ticket #4523
Ermal Luçi
11:28 AM Revision 81e5adb0: Merge pull request #1686 from phil-davis/service-rfc2136
Renato Botelho
11:28 AM Revision 6fac4c26: Merge pull request #1685 from phil-davis/services-ntp
Renato Botelho
11:27 AM Revision f46172c5: Merge pull request #1684 from phil-davis/services-igmp
Renato Botelho
11:27 AM Revision 73346505: Merge pull request #1683 from phil-davis/www-services-dyndns
Renato Botelho
11:25 AM Revision 5f16d0ba: Merge pull request #1682 from phil-davis/www-services-dnsmasq
Renato Botelho
11:25 AM Revision b58e1cec: Unbalanced td tag in services_dnsmasq
Phil Davis
11:25 AM Revision 6e67bc43: Merge pull request #1681 from phil-davis/patch-2
Renato Botelho
11:24 AM Revision fc10b44a: Merge pull request #1680 from phil-davis/www-services-cp
Renato Botelho
11:23 AM Revision 5751d1bc: Merge pull request #1679 from phil-davis/services_dhcp
Renato Botelho
11:22 AM Revision 3ccb7fc3: Consistent clear_subsystem_dirty after unbound restart
from services_dhcp.
This looks like it is wanting curlies to put all clear_subsytem_dirty inside the "if".
Phil Davis
11:22 AM Revision dbc03d71: Merge pull request #1678 from phil-davis/patch-1
Renato Botelho
11:20 AM Revision bf8f9acc: Merge pull request #1677 from phil-davis/vpn_ipsec
Renato Botelho
11:16 AM Revision 891d8ff8: Merge pull request #1676 from phil-davis/www_openvpn
Renato Botelho
11:08 AM pfSense Packages Bug #4731 (Resolved): softflowd process gets started twice during bootup
When rebooting the firewall, the softflowd process(s) can get started twice. I did some investigation and believe wh... Cody Howell
10:09 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
The installer and nano has been switched to SU+J same as default FreeBSD.
Ermal Luçi
04:56 AM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Looks like the issue has been successfully fixed, thanks Chris Dmitriy K

05/24/2015

02:14 PM Feature #3377: OAuth2 authentication in captive portal
Chris Buechler wrote:
> there will be publicly-available 2.2 snapshots in the not too distant future. At this point,...
bamidele Amire
09:38 AM Revision efdf8358: Code style services RFC2136
Phil Davis
09:17 AM Revision 7a6f0ebc: Code style services NTP
Phil Davis
07:09 AM Revision c0bf7858: Code style services igmpproxy
Phil Davis
06:53 AM Revision 9c12c130: Code style services dyndns
Phil Davis
06:04 AM Revision 966ed611: Code style services dnsmasq
Phil Davis
05:48 AM Revision c09b1947: Unbalanced td tag in services_dnsmasq
Phil Davis
05:23 AM Revision 5fcc3079: Code style www services captive portal
Phil Davis
05:14 AM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
I have expanded the server directive as per the openvpn manpage: https://github.com/apollo13/pfsense/commit/137498be7... Florian Apolloner

05/23/2015

06:21 PM Bug #4729: OpenVPN Advanced config fails on double save
Oh, separating the options by a semicolon makes it work -- I guess the UI could be a little bit more forgiving here… Florian Apolloner
06:19 PM Bug #4729 (Not a Bug): OpenVPN Advanced config fails on double save
Saving ... Florian Apolloner
06:01 PM Revision 8f8682f7: Code style services DHCP
Phil Davis
06:00 PM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
Hmm, I guess the easiest option would be to just remove the "address pool setting" and make "tunnel network optional"... Florian Apolloner
05:55 PM Feature #4728: Expose ``nopool`` server option in the OpenVPN Server GUI
I am currently running my pfsense install with this patch:... Florian Apolloner
05:31 PM Feature #4728 (Pull Request Review): Expose ``nopool`` server option in the OpenVPN Server GUI
Openvpn has a checkbox to enable an address pool, but that one seems to be pretty useless (pool_enable is used nowher... Florian Apolloner
03:00 PM Revision 4230ad16: Consistent clear_subsystem_dirty after unbound restart
from services_dhcp.
This looks like it is wanting curlies to put all clear_subsytem_dirty inside the "if".
Phil Davis
01:41 PM Bug #4727 (Not a Bug): Rules on L2TP VPN Tab are ignored. All traffic from clients always allowed.
https://forum.pfsense.org/index.php?topic=94108.25
Created L2TP/IPsec remote access VPN as per https://doc.pfsense...
Chris Linstruth
11:59 AM Bug #4686: Rekeyed SAs are not properly removed
Sadly I cannot easily upgrade to a snapshot currently and test this, but will provide feedback as soon as 2.2.3 is re... Florian Apolloner
09:04 AM Revision a1d55e81: Code style VPN IPsec
Phil Davis
02:59 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Reading this like this:
- https://forums.freebsd.org/threads/freebsd-on-ufs-preventing-data-loss-on-crash.30683/
...
Kill Bill

05/22/2015

09:49 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
this is replicable with just an unclean shut down Chris Buechler
11:28 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
I thought I added this here a while back but apparently not.
I have tried combinations of:
* Soft updates
* SU+J...
Jim Pingle
08:33 PM Bug #4725 (Not a Bug): alc(4) may need an update
we'll get that for 2.3 where we're on 10.2. If someone would like to submit a backported patch for 10.1, we could add... Chris Buechler
08:12 PM Bug #4725 (Not a Bug): alc(4) may need an update
alc(4) in FreeBSD 10 stable was updated with r273366 to support more atheros LAN chips, not sure if that made it into... Charlie m
08:30 PM Todo #4726 (Resolved): Remove zoneinfo.tgz, use stock FreeBSD's
Need to remove zoneinfo.tgz and just rely on FreeBSD's instead. It was brought over that way from m0n0wall, which did... Chris Buechler
08:11 PM Revision e38c75a8: Code style www vpn_openvpn
Phil Davis
08:05 PM Revision 88cbd004: Update/correct wireless status flags and capabilities list.
There are many more possible flags, documented on the wiki: https://doc.pfsense.org/index.php/Wireless_Status Jim Pingle
08:03 PM Revision e2c20d52: Update/correct wireless status flags and capabilities list.
There are many more possible flags, documented on the wiki: https://doc.pfsense.org/index.php/Wireless_Status Jim Pingle
07:53 PM Revision 5a0d15b1: Merge pull request #1672 from phil-davis/patch-1
Renato Botelho
07:53 PM Revision b0d7ce73: Merge pull request #1673 from phil-davis/patch-2
Renato Botelho
07:51 PM Revision 626fab04: Merge pull request #1674 from phil-davis/vpn_pppoe
Renato Botelho
07:51 PM Revision cdeae576: Merge pull request #1675 from jlduran/editorconfig
Renato Botelho
06:07 PM Revision f6fe9035: Remove unneeded gettext
sbeaver
06:05 PM Revision 875a8496: Remove unneeded gettext
sbeaver
06:00 PM Revision f1cef2a2: Remove one get text
sbeaver
05:58 PM Revision 299364a4: Remove unneeded htmlspecialcharacters
sbeaver
05:56 PM Revision 934c7d58: Added spacing
sbeaver
05:48 PM Revision ea6649f7: Removed htmlspecialcharacters
sbeaver
05:41 PM Revision cffe7e71: Remove htmlspecialcharacters
sbeaver
05:35 PM Revision 4b5a2e6c: Remove htmlspecialcharacters and gettext
sbeaver
05:19 PM Revision 1de4da38: Removed unneeded htmlspecialcharacters
sbeaver
05:16 PM Revision 227bf9cf: Trivial whitespace edits
sbeaver
05:13 PM Revision 1735cd7d: Remove unneeded htmlspecialcharacters, tabs, button
sbeaver
05:10 PM Revision 3d1bc0f0: Removed a tab
sbeaver
05:08 PM Revision 5dc5f197: Remove unneeded htmlspecialcharacteres
sbeaver
05:05 PM Revision 07306e62: One tab too many
sbeaver
04:59 PM Revision 69279988: remove unneeded gettext/htmlspecialcharacters
sbeaver
04:49 PM Revision ea06fb00: Remove unneeded gettext
sbeaver
04:45 PM Revision 2a2df02f: Remove unneeded gettext
sbeaver
04:41 PM Revision 9e097d78: Remove unneeded gettext
sbeaver
04:37 PM Revision fae9a73c: Removed unneeded gettext
sbeaver
04:29 PM Revision e6844dd9: Removed unneeded htmlspecialcharacters
sbeaver
04:26 PM Revision aae2d55e: Remove unneeded htmlspecialcharacters
sbeaver
04:24 PM Revision 814b5184: Trivial whitespace changes
sbeaver
03:40 PM Revision e6e1ba01: Trivial format changes
sbeaver
03:28 PM Revision a564b6e7: status_rrd_graph.pgp Conversion complete
GET form converted to POST. Date/time controls revised. Tested with all
graph types and control options.
sbeaver
03:05 PM Bug #4028: Wireless Obytes counter always 0
https://reviews.freebsd.org/D2621 Ermal Luçi
02:16 PM Bug #4623: Carp not working under bhyve
Ermal Luçi wrote:
> Did you try from the GUI since carp should not differ from FreeBSD at least in this regard!
Y...
Matthias Breddin
01:30 PM Revision ddb753db: Add .inc files to editorconfig
Jose Luis Duran
11:51 AM Revision 2e98fc4c: Add .editorconfig file
To start with just `.php` files. According to the [Developer Style Guide](https://doc.pfsense.org/index.php/Developer... Jose Luis Duran
10:56 AM Revision b7856e58: Code style vpn_pppoe
Phil Davis
08:38 AM Feature #4724 (New): Captive Portal Status Add Client Hostname
It would be very useful to include the client hostname in the captive portal status list, so it is easy to identify w... Josh Stompro
07:58 AM Bug #1974: Captive Portal RADIUS accounting bytes wrong
I can confirm that this behaviour is the same in 2.2.2 for 32bit. Fran Secs
06:48 AM Bug #4311: aPinger service gets higher ping. Resolves for short period after restart aPinger service
Duplicate of https://redmine.pfsense.org/issues/4081 and probably some others. Kill Bill
01:36 AM Revision 8d610380: Be smarter about combinations of combinedfields and usecolspan2
a) When we are doing combined fields and usecolspan2 is in effect, then usecolspan2 is also a signal that we want to ... Phil Davis

05/21/2015

10:07 PM Revision d105d6f7: Update zoneinfo from FreeBSD 10.1-REL. Ticket #4459
Chris Buechler
10:07 PM Revision 826e1524: Update zoneinfo from FreeBSD 10.1-REL. Ticket #4459
Chris Buechler
08:15 PM Revision a1398968: services_rfc2136_edit.php Conversion complete
Ready for review sbeaver
08:13 PM Revision bec3f925: Update pkg_edit.php
a) When we are doing combined fields and usecolspan2 is in effect, then usecolspan2 is also a signal that we want to ... Phil Davis
07:05 PM Revision a5d5b1f7: services_rfc2136.php Conversion complete
Ready for review sbeaver
07:03 PM Revision fec2a89a: Revert "services_rfc2136.php Conversion complete"
This reverts commit fa0f5f67222839a3456351aec8eb963bd43e67b9. sbeaver
07:00 PM Revision fa0f5f67: services_rfc2136.php Conversion complete
Ready for review
Like services_dyndns the interleaving of PHP and HTML makes print()
sternest the cleanest way :(
sbeaver
06:04 PM Revision 26fe7b98: Corrected filed values
sbeaver
06:00 PM Revision b993931c: services_ntpd_pps.php Conversion complete
Ready for review sbeaver
05:48 PM Revision 5df4f971: Added missing 'if(!empty($serialports)) . .
sbeaver
05:30 PM Revision 4b7289a3: Merge https://github.com/SjonHortensius/pfsense into bootstrap
sbeaver
05:30 PM Revision b20e03b2: services_ntpd_gps.php Conversion complete
Ready for review
Al lot of Javascript in the page. Converting it to jQuery and removing
redundant code has made it a...
sbeaver
05:05 PM Bug #4459 (Feedback): Tzdata is too old (needs to be updated for Russia)
zoneinfo has been updated with latest from FreeBSD, should be fine in 2.2.3. Chris Buechler
04:35 AM Bug #4459: Tzdata is too old (needs to be updated for Russia)
Chris Buechler wrote:
> I mean in stock FreeBSD 10.1, have you checked it?
https://bugs.freebsd.org/bugzilla/show...
Victor Danilkin
04:43 PM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Just thought that random-id will apply to all packets incoming another interface (LAN..etc..) prior to exit WAN. So, ... Dominic Blais
03:43 PM Bug #4723 (Resolved): Can't forward UDP fragmented packets with scrubbing enabled.
I have a use case where I couldn't forward UDP fragmented packets thru a site to site OpenVPN tunnel. The issue isn't... Dominic Blais
12:21 PM Revision 08d56bd1: services_ntpd.php Conversion complete
Ready for review sbeaver
12:05 PM Revision 633df926: Correct descriptions on Key Rotation and Master Key Regeneration for wireless.
Jim Pingle
12:04 PM Revision 8a736fae: Correct descriptions on Key Rotation and Master Key Regeneration for wireless.
Jim Pingle
08:27 AM Bug #4722 (Needs Patch): Ralink USB driver yields a double fault panic on pfSense, works on FreeBSD with equivalent config
I've got a Ralink USB wireless adapter (Buffalo WLI-UC-GNM) that works perfectly on stock FreeBSD (10.1-STABLE) but w... Jim Pingle
08:09 AM Revision a13c317e: Fix but where value in Textarea wasn't processed. Fixes #216
Sjon Hortensius
08:07 AM Bug #4718: "BTX halted" error with 2.2.2
Memstick installation does not work either. It fails with the same error:... James Dietrich
06:58 AM Bug #4721 (Rejected): Can't assign same monitor ip twice
Currently that is impossible. You must have different monitor IP addresses for each WAN even if they have different g... Jim Pingle
04:44 AM Bug #4721: Can't assign same monitor ip twice
Correction: "They are both having the same gateway, and I would like to monitor that gateway ip." => the same gateway... Sander Naudts
04:43 AM Bug #4721 (Rejected): Can't assign same monitor ip twice
We have 2 cable connections from the same ISP. They are both on seperate routers in front of Pfsense.
So in Pfsens...
Sander Naudts
06:54 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Understand.
How do i solve this in pFsense then? I need to duplicate conX in ipsec.conf with different p2 entries?
Roman H
12:49 AM Bug #4720 (Resolved): pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
After loading an ADI RCC-VE with pfSense-memstick-ADI-2.2.2-RELEASE-amd64.img the system works fine. Once the config... Cliff Skolnick

05/20/2015

10:16 PM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Cisco already has CSCue42170 linked above open on the issue as an enhancement. Not sure you can do anything to push t... Chris Buechler
01:53 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
I don't know where to "hack those validations"
Edit ipsec.conf sounds much easier to me ... in case if ipsec stron...
Roman H
01:50 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
there isn't a way to configure that in the GUI right now. You can hack the input validation that checks for duplicate... Chris Buechler
01:32 AM Bug #4704: IKEv2 to Cisco ASA won't bring up multiple P2 networks
Is it possible to split ikev2 via GUI ?
Or its only by editing conf file?
What you may advice in current situation?
Roman H
10:13 PM Bug #4719 (Resolved): IKEv2 to Cisco ASA results in TS mismatch when initiation triggered by traffic
IKEv2 to Cisco ASA won't come up when initiation is triggered by traffic matching the P2. It results in the following... Chris Buechler
06:34 PM Revision 3a44f4a2: Merge pull request #1670 from phil-davis/patch-1
Renato Botelho
06:34 PM Revision 51c26808: Merge pull request #1671 from phil-davis/patch-2
Renato Botelho
06:11 PM Revision 26d785bb: More combinedfields and usecolspan2 fixes
Actually the "tr" tag needs to be a single tag-pair that encloses all of the set of fields with combinedfields specif... Phil Davis
06:02 PM Revision f6014228: More combinedfields and usecolspan2 fixes
Actually the "tr" tag needs to be a single tag-pair that encloses all of the set of fields with combinedfields specif... Phil Davis
03:51 PM Revision 244f5927: services_icmpproxy_edit.php Conversion complete
Ready for review sbeaver
03:35 PM Feature #4322: Add Google Domains DDNS
Adding a vote for this... have manually added it using Custom, but would like to get full status support (rather than... Anonymous
01:51 PM Revision c4973f3e: Merge branch 'bootstrap' of ssh://github.com/SjonHortensius/pfsense into bootstrap
Sjon Hortensius
01:40 PM Revision e5db68d2: Merge pull request #1668 from phil-davis/patch-1
Renato Botelho
01:39 PM Revision 67e7ae85: Merge pull request #1669 from phil-davis/patch-2
Renato Botelho
01:30 PM Revision cbd3fef9: Revised as suggested
Thanks!
It would be very helpful to have a phpdoc to document the Forms
framework.
I had not noticed the setPatter ...
sbeaver
01:24 PM Revision ec996cd7: Use toggles as suggested
Thanks,
The toggle system was a WIP when I did this page I think. It works
nicely now in this instance.
sbeaver
01:20 PM Revision b021e2c6: Fix tr use for combinedfields in pkg xml
When specifying combinedfields begin and end in a package XML file, IE reports some unexpected start tag messages. Th... Phil Davis
01:15 PM Revision 0259757c: Updated as suggested
Thanks! sbeaver
01:13 PM Revision 53895ce8: Merge pull request #204 from sbeaver-netgate/load_balancer_settings
Convert load_balancer_setting SjonHortensius
01:10 PM Revision e10dd978: remove deprecated align attribute #195
Sjon Hortensius
01:10 PM Revision 9029879d: Merge pull request #195 from sbeaver-netgate/diag_ipsec_leases.php
Convert diag_ipsec_leases.php SjonHortensius
01:08 PM Revision 3d0f579f: services_igmpproxy.php Conversion complete
Ready for review sbeaver
01:03 PM Revision e3167a84: Fix tr use for combinedfields in pkg xml
Phil Davis
12:59 PM Bug #3314 (Feedback): Traffic graph shows 2X the actual traffic on VLAN interfaces.
A patch to fix it was pushed, new snapshots will contain the fix Renato Botelho
12:39 PM Revision ea54560e: services_dyndns_edit.php Conversion complete
Ready for review sbeaver
12:15 PM Bug #4718: "BTX halted" error with 2.2.2
Does memstick installation work on this machine? Ermal Luçi
10:56 AM Bug #4718 (Closed): "BTX halted" error with 2.2.2
This was discussed on the forum at https://forum.pfsense.org/index.php?topic=94104.0
I have a machine that boots o...
James Dietrich
09:17 AM Bug #4685 (Confirmed): Crash/panic "Sleeping thread owns a non-sleepable lock"
One user still reports crashes with the new daemon. Updated crash dump is in the projects repo. Jim Pingle
 

Also available in: Atom