Project

General

Profile

Activity

From 06/17/2015 to 07/16/2015

07/16/2015

11:38 PM Bug #4849 (Not a Bug): ipsec: keepalive not working; wrong source ip used
While debugging ipsec tunnels between two pfsenses I noticed that using ping on the command line does not work out of... Nicki Messerschmidt
11:35 PM Bug #4848 (Feedback): The remote gateway "ip-adres is already used by phase1 "name of phase 1"
The issue as described isn't replicable. You get the same error in that described circumstance. The check there is fo... Chris Buechler
08:14 AM Bug #4848 (Not a Bug): The remote gateway "ip-adres is already used by phase1 "name of phase 1"
If you clone (copy phase 1 entry) a "phase 1" IPsec connection and only change the "P1 Description" and hit the save ... Stefan Kooman
11:25 PM Bug #4845: CARP preemption doesn't switch to backup where connectivity between systems is lost but not NIC link
The issue's been around since the inception of CARP in 2003, so yeah not likely this is going to change in the near f... Chris Buechler
09:20 AM Bug #4845: CARP preemption doesn't switch to backup where connectivity between systems is lost but not NIC link
That other ticket ended up not being related to this, it was a different issue. In that case the "link" was lost from... Jim Pingle
09:12 AM Bug #4845: CARP preemption doesn't switch to backup where connectivity between systems is lost but not NIC link
If that's the case, you are right. The only way I can see this working is sending both sending their 'status' via the... Dan Journo
09:03 AM Bug #4845: CARP preemption doesn't switch to backup where connectivity between systems is lost but not NIC link
We noticed this at one point back in 2012 or so and I swear we already had a ticket open but couldn't find it. It's r... Jim Pingle
10:24 PM Revision a296286b: Revert "myid_data and peerid_data fields are not relevant with asn1dn."
This reverts commit 0e19c4bba659a5f4d28f9c8b20c80717a90964b9. Chris Buechler
10:22 PM Revision d6908784: Contrary to some reports this is actually usable in some cases, just not
mandatory. Revert "myid_data and peerid_data fields are not relevant with asn1dn."
This reverts commit b8754cc85db7e...
Chris Buechler
10:17 PM Revision 0e19c4bb: myid_data and peerid_data fields are not relevant with asn1dn.
Conflicts:
usr/local/www/vpn_ipsec_phase1.php
Chris Buechler
10:16 PM Revision b8754cc8: myid_data and peerid_data fields are not relevant with asn1dn.
Chris Buechler
07:50 PM Todo #4847: NanoBSD Image Flash Block Misalignment
Want to add while I'm here, in case some don't read the linked thread. Per the very first reference listed, the begin... ky41083 -
07:45 PM Todo #4847: NanoBSD Image Flash Block Misalignment
I completely agree.
I would also love to hear about any examples of systems that can currently run pfSense 2.2, bu...
ky41083 -
11:51 AM Todo #4847: NanoBSD Image Flash Block Misalignment
Keith Hough wrote:
> Are there any systems you know of that can boot from NanoBSD slice 1, but fail to boot from sli...
Jim Pingle
02:34 AM Todo #4847: NanoBSD Image Flash Block Misalignment
The boot code and MBR partition tables would remain where they are, in sector 0 / 1. If a system was going to have is... ky41083 -
12:36 AM Todo #4847: NanoBSD Image Flash Block Misalignment
only problem here (assuming it works, and is useful) is that setting to sector 2048 probably renders a lot of old har... Jim Thompson
12:09 AM Todo #4847: NanoBSD Image Flash Block Misalignment
Keith Hough wrote:
> start that partition on sector 64, rather than sector 63 (default) as it is now.
Got ahead o...
ky41083 -
12:03 AM Todo #4847: NanoBSD Image Flash Block Misalignment
The upgrade scenario for NanoBSD...
In the research I've done, as far as moving the entire MBR partition down by o...
ky41083 -
07:03 PM Revision 693c13cb: Restrict serial ports glob to cua followed by alpha
Improve this a little more to match only alpha after /dev/cua (/dev/cuau for example) Phil Davis
07:03 PM Revision 3eed76d7: Make serial ports glob cope with many more possibilities
It originally coped with things like cuau1 cuau1.1
Then I made it cope with things like cuau1 cuau11 but it stopped w...
Phil Davis
06:56 PM Revision d5dd538d: Add leftid and rightid value between double quotes on ipsec config when type is asn1dn. Ticket #4792
Renato Botelho
06:56 PM Revision 31ae45d2: Add leftid and rightid value between double quotes on ipsec config when type is asn1dn. Ticket #4792
Renato Botelho
04:45 PM Revision 348c7c87: Remove old, unused NetUtils.js
Chris Buechler
04:44 PM Revision 088af065: Remove old, unused NetUtils.js
Chris Buechler
03:50 PM Revision 8235e730: Restrict serial ports glob to cua followed by alpha
Improve this a little more to match only alpha after /dev/cua (/dev/cuau for example) Phil Davis
08:30 AM pfSense Packages Bug #4295: stunnel not working in Release 2.2
Applied in changeset commit:06a66c936672073525ea2626b85ccc42db104f16. Anonymous
08:22 AM pfSense Packages Bug #4295 (Feedback): stunnel not working in Release 2.2
Updated to 5.20 and fixed for 2.2.x Renato Botelho
07:38 AM pfSense Packages Feature #1973: Update siproxd to v0.8.1
now in ports, please update? https://www.freshports.org/net/siproxd/ dean hamstead
06:52 AM Todo #4846 (Resolved): Remove isc-dhcp42-server from pfPorts when prefix6 fixed
Fixes are on ports tree - https://svnweb.freebsd.org/ports?view=revision&revision=392293 Renato Botelho
05:07 AM Revision 72b28115: Make serial ports glob cope with many more possibilities
It originally coped with things like cuau1 cuau1.1
Then I made it cope with things like cuau1 cuau11 but it stopped w...
Phil Davis

07/15/2015

11:48 PM Todo #4847: NanoBSD Image Flash Block Misalignment
The change for NanoBSD would be implemented in the build system. The fdisk command that creates the initial MBR parti... ky41083 -
11:21 PM Todo #4847 (Closed): NanoBSD Image Flash Block Misalignment
pfSense NanoBSD images are not flash block aligned. This causes significant slowdown during extended write disk activ... ky41083 -
11:24 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
Done: https://redmine.pfsense.org/issues/4847
Thanks Chris.
ky41083 -
11:17 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
all my comments were re: rw->ro mount time.
Keith, Phil's suggestion to open a todo including those references is...
Chris Buechler
11:00 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
I am happy with the way it is now for 2.2.4. At least it is reliable, even if the speed varies on different cards of ... Phillip Davis
10:35 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
Chris, I'm not sure if you are referring to the alignment issue or the remount issue only effecting 1 of the CF / SD ... ky41083 -
07:05 PM Bug #4814 (Closed): read-only to read-write mount very slow on nanobsd with slow flash media
Updated subject to reflect the root of the issue. Of a whole stack of various CF and SD cards I have here, there is o... Chris Buechler
10:57 PM Bug #4829 (Resolved): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
Works here too. added #4846 todo to remove from pfports when fixed upstream. Chris Buechler
09:15 PM Bug #4829: Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
This is all fixed now. Current snap is OK. DHCPd is running and a client behind obtains a delegation.
Do we want t...
Jim Pingle
05:51 PM Bug #4829 (Feedback): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
This check was also removed, please try next round of snapshots Renato Botelho
04:28 PM Bug #4829 (Confirmed): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
It's better but still fails in a related way. There is an additional check that needs to be patched out:... Jim Pingle
01:43 PM Bug #4829 (Feedback): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
Patch applied to dhcpd-server Renato Botelho
10:56 PM Todo #4846 (Resolved): Remove isc-dhcp42-server from pfPorts when prefix6 fixed
As soon as ISC puts out a release with the prefix6 issue from #4829 fixed, we need to remove our copy from pfports. Chris Buechler
10:40 PM Bug #4840 (Duplicate): Unplugging WAN does not failover LAN
there is an issue here, but not as described. opened #4845 for the root issue. Chris Buechler
08:09 AM Bug #4840 (Duplicate): Unplugging WAN does not failover LAN
Hi,
I followed the guides on the pfsense portal and also the pfsense Gold book.
Using 2.2.3, at the testing sta...
Dan Journo
10:39 PM Bug #4845 (Confirmed): CARP preemption doesn't switch to backup where connectivity between systems is lost but not NIC link
Take a basic WAN and LAN setup, one CARP IP on each interface. If WAN's NIC loses link, the secondary system takes ov... Chris Buechler
10:34 PM Revision 59a3f75e: Revert "Avoid error loading rules for numeric host name in alias"
This reverts commit 81a73bcba3b3a79bb3a7add2e14a46e6af748f50. Renato Botelho
10:34 PM Revision d423b1d7: Revert "Avoid error loading rules for numeric host name in alias"
This reverts commit 6605035f9d2a04d1d4b724f6e993bc3f5c6d173d. Renato Botelho
09:09 PM Bug #4842 (Resolved): Port aliases broken on 2.2.4 snapshots
Looks good now. Jim Pingle
05:34 PM Bug #4842 (Feedback): Port aliases broken on 2.2.4 snapshots
I reverted that commit. Renato Botelho
04:26 PM Bug #4842 (Resolved): Port aliases broken on 2.2.4 snapshots
Port aliases are non-functional on 2.2.4 snapshots, they appear in rules.debug as empty lists and then the rules fail... Jim Pingle
08:54 PM Bug #4844 (Resolved): Error loading rules for numeric host name in alias
Create a host-type alias. Put just a number in "IP or FQDN" - e.g. I made alias name "Zqw" and a single host "23". Th... Phillip Davis
07:58 PM Bug #4843 (Not a Bug): Traffic Shapper Wizard
The traffic_shaper_wizard_multi_all.xml appears to be creating a qLink queue in the incorrect hierarchy for the Lan q... Joshua Kafouros-Parker
07:40 PM Feature #4133: Add GUI setting for VLANs PCP
I tested this patch using 2.2.3-Release:
* https://github.com/pfsense/pfsense-tools/compare/pfsense:RELENG_2_2_3.....
Chris Christensen
05:51 PM Bug #4817: rc.start_packages: Restarting/Starting all packages on config sync
I just discovered the same 'problem', but with a more usual set-up. Sync is from primary to secondary, but secondary ... Seb A
04:50 PM Revision bb68cbbb: Merge pull request #1755 from phil-davis/patch-2
Renato Botelho
04:40 PM Revision dea04167: Display any advanced DHCP server settings RELENG_2_2
Cherry pick of https://github.com/pfsense/pfsense/commit/90ad3a76edae543bcc63252b14660ac4baee291e Phil Davis
04:27 PM Revision 36b622c3: Merge pull request #1754 from phil-davis/cr_2_2
Renato Botelho
03:56 PM Revision 3e415478: Cancel button after input error for RELENG_2_2
Phil Davis
03:49 PM Bug #4346 (Resolved): radiusd process is left running after package uninstall
Renato Botelho
03:39 PM Bug #4346: radiusd process is left running after package uninstall
Thanks! Tested the change and things look good. Paul K
11:45 AM Bug #4346 (Feedback): radiusd process is left running after package uninstall
Pull request has been merged Renato Botelho
03:05 PM Revision f8bcdede: Fix issue_ip_type var name spelling
Actually there was no real problem, but having a mis-spelling like this means that English speakers will waste time (... Phil Davis
03:05 PM Revision 2c6cdcef: Merge pull request #1741 from phil-davis/patch-2
Renato Botelho
03:04 PM Revision 4433cf85: Firewall Aliases Import display error message for invalid alias name
If you open firewall_aliases_import and enter just an invalid Alias Name (e.g. a$b) and press save or press save with... Phil Davis
03:03 PM Revision d8b221eb: Merge pull request #1742 from phil-davis/patch-3
Renato Botelho
03:01 PM Revision 043e61ee: Firewall Aliases Edit ensure input_addresses array exists
If you click "+" to add an alias, then press Save without entering anything, you get:
Warning: Invalid argument suppl...
Phil Davis
03:00 PM Revision 41ec196d: Merge pull request #1743 from phil-davis/patch-4
Renato Botelho
02:46 PM pfSense Packages Feature #3272 (Resolved): pfBlocker: Specific ports to block.
thanks Chris Buechler
01:46 PM pfSense Packages Feature #3272: pfBlocker: Specific ports to block.
Yeah, this is available in pfBlockerNG (Advanced Inbound Firewall Rule Settings). This can be closed. Kill Bill
02:38 PM pfSense Packages Feature #4055: Enable area authentication from GUI
Hmmm, would seem to me that the "Raw Config" feature lets you enable just about anything?
https://github.com/pfsen...
Kill Bill
02:07 PM pfSense Packages Todo #1551 (Resolved): OLSR Version update
yeah this was done at some point Chris Buechler
02:05 PM pfSense Packages Todo #1551: OLSR Version update
Well, the PBI is 0.6.6.2_1 which is latest available port, can be closed. Kill Bill
01:44 PM Revision 6605035f: Avoid error loading rules for numeric host name in alias
Create a host-type alias. Put just a number in "IP or FQDN" - e.g. I made alias name "Zqw" and a single host "23". Th... Phil Davis
01:42 PM Revision 535bf33b: Merge pull request #1744 from phil-davis/patch-5
Renato Botelho
01:38 PM Revision 6b30491f: Interfaces GIF Edit fix do_input_validation
Make the required fields be correct and match thier text names, which should each have their own gettext() cal so as ... Phil Davis
01:30 PM Revision 124bf68c: Merge pull request #1745 from phil-davis/patch-6
Renato Botelho
01:30 PM Revision e3a5f487: Interfaces GRE Edit fix required fields text
The reqdfields had only 4 entries but reqdfieldsn has 5 entries and the field names to text descriptions did not matc... Phil Davis
01:20 PM Revision a9d6ae17: Merge pull request #1746 from phil-davis/patch-7
Renato Botelho
01:19 PM Revision 0d9fe84b: Interfaces PPPs edit avoid foreach() warning
If you go to Interfaces, assign, PPPs, press "+" to add an entry, then press Save without entering anything then you ... Phil Davis
01:18 PM Revision fe05aacf: Merge pull request #1747 from phil-davis/patch-8
Renato Botelho
01:16 PM Revision 5e399979: Merge pull request #1749 from phil-davis/cancel-referer
Renato Botelho
01:14 PM Todo #4841 (Resolved): update AES-GCM/AES-NI bits from FreeBSD -HEAD
Need to update AES-GCM and AES-NI from FreeBSD -HEAD. Chris Buechler
12:34 PM pfSense Packages Bug #999 (Resolved): vhosts does not show up as started
Chris Buechler
12:16 PM pfSense Packages Bug #4561: siproxd listening port redirect rule pulling wrong tag from <siproxdsettings> (config.xml)

Thank You!
Saw this and reported on the forum back in 2011.
https://forum.pfsense.org/index.php?topic=43213.m...
Chris Palmer
11:34 AM pfSense Packages Bug #4561 (Feedback): siproxd listening port redirect rule pulling wrong tag from <siproxdsettings> (config.xml)
Pull request has been merged Renato Botelho
11:38 AM pfSense Packages Bug #4085 (Feedback): Check_mk agent configuration: 'Listen Port' is required, contrary to description
Pull request has been merged Renato Botelho
11:35 AM pfSense Packages Bug #3360 (Feedback): Apache reverse proxy-dev leaves / out of Backend Path
Pull request has been merged Renato Botelho
10:53 AM pfSense Packages Bug #4839 (Not a Bug): Version of squidGuard on pfSense 2.2
Chris Buechler
06:57 AM pfSense Packages Bug #4839: Version of squidGuard on pfSense 2.2
1.9.14 is pfSense package version, not the upstream release version. Kill Bill
06:39 AM pfSense Packages Bug #4839 (Not a Bug): Version of squidGuard on pfSense 2.2
The squidGuard version information in pfSense 2.2 is as 1.9.14, but the correct version is 1.4.7. Tomas Waldow
09:20 AM Bug #4818: IPSec makes worse in some cases - since 2.2.3 Update
Since upgrading to pfSense-Full-Update-2.2.4-DEVELOPMENT-amd64-20150712-1215
I´m able to use all vpn tunnels again! ...
Marvin Kamm

07/14/2015

11:25 PM Revision 36f90078: Fix glob for serial device names
Removing the "." that was in {,.[0-9]} allows it to match /dev/cuau10 and onward.
I added lots of comments on the glo...
Phil Davis
11:25 PM Revision ccf504fc: Merge pull request #1752 from phil-davis/patch-9
Chris Buechler
10:55 PM Revision e65ebe32: Fix adding of VoIP rules from traffic shaper wizard where IP/alias is not
specified. Chris Buechler
10:54 PM Revision 57945fcc: Fix adding of VoIP rules from traffic shaper wizard where IP/alias is not
specified. Chris Buechler
09:55 PM Bug #4838 (Resolved): shaper VoIP match rules not added when no IP/alias specified in wizard
The match floating rule for VoIP was being skipped when no IP or alias was specified in the VoIP screen in the shaper... Chris Buechler
09:52 PM Revision 1cc4c9e3: Fix GratisDNS support, manual merge of commit 3e31a7f82589d3350f111bd7d81cc83a0ab253e2
Chris Buechler
09:49 PM Revision 8795064c: Merge pull request #1753 from mortencombat/patch-1
Chris Buechler
09:43 PM Revision 3e31a7f8: Fix GratisDNS support
The current implementation is not working for me, maybe the interface was changed by GratisDNS? I tested the update U... mortencombat
08:33 PM Bug #4837 (Closed): enabling SSH at console on nanobsd with slow flash ro mounted doesn't generate keys
Since 2.2.3, enabling SSH at the console on nanobsd goes through the process, but keys aren't generated. Chris Buechler
08:10 PM Bug #4836 (Feedback): pfSense does not support more than 10 serial devices for PPPS
Chris Buechler
08:08 PM Bug #4836: pfSense does not support more than 10 serial devices for PPPS
Should be fixed by:
https://github.com/pfsense/pfsense/commit/cc4d13683e50595abc14efc43c91a087f123a979
Awaiting fee...
Phillip Davis
08:06 PM Bug #4836 (Resolved): pfSense does not support more than 10 serial devices for PPPS
Reported on forum:
https://forum.pfsense.org/index.php?topic=96466.0
The glob that matches the serial device name...
Phillip Davis
06:13 PM Bug #4810 (Resolved): Load Balancing GUI does not properly handle port ranges in relayd.conf
works Chris Buechler
05:58 PM Bug #4829 (Confirmed): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
Chris Buechler
04:36 PM Bug #4829: Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
this change in dhcpd seems to be wrong. Posted to their list for feedback with additional details.
https://lists.is...
Chris Buechler
05:57 PM Bug #4806 (Resolved): Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
fixed Chris Buechler
03:11 PM pfSense Packages Bug #3363: TinyDNS does not respond to IPv6 subnet
I am currently not in charge of the router.
However shortly after reporting this issue concerning TinyDNS I changed ...
Anders Lind
04:35 AM pfSense Packages Bug #3363: TinyDNS does not respond to IPv6 subnet
Do you still have this issue with current pfSense version and current tinydns version? Looks like duplicate of Bug #4... Kill Bill
02:02 PM Bug #4523 (Resolved): master.passwd/group file corruption may occur after kernel panic or unclean shut down
sync no longer added to new installs, and confirmed the upgrade code removes it where it's set and doesn't change any... Chris Buechler
02:00 PM Bug #4803 (Resolved): config.xml is empty if power loss or panic happens shortly after config write
I'm confident in this, snapshots including all relevant changes have been through the config_write loop torture test,... Chris Buechler
01:24 PM Revision cc4d1368: Fix glob for serial device names
Removing the "." that was in {,.[0-9]} allows it to match /dev/cuau10 and onward.
I added lots of comments on the glo...
Phil Davis
12:17 PM Bug #4817: rc.start_packages: Restarting/Starting all packages on config sync
I had issues with my bgp and carp configurations also some bugs from version 2.2.1 and 2.2.0.
So for couple of weeks...
Tsvyatko Kriviradev
12:01 PM Bug #4817: rc.start_packages: Restarting/Starting all packages on config sync
this is just how things work currently. That normally doesn't matter because only the system with backup status has t... Chris Buechler
11:56 AM Bug #4817: rc.start_packages: Restarting/Starting all packages on config sync
Hello,
I am sorry for my late response.. It's suck a same...
But I have released I have sync between fw1 and fw...
Tsvyatko Kriviradev
11:19 AM pfSense Packages Bug #4834 (Resolved): vnstat php frontend cannot be accessed after vnstat2 package reinstall
that's been merged, thanks! Chris Buechler
11:18 AM pfSense Packages Bug #1768 (Resolved): DNS Forwarder of Tinydns
Chris Buechler
03:57 AM pfSense Packages Bug #1768: DNS Forwarder of Tinydns
The patches from https://forum.pfsense.org/index.php?topic=44413.msg236701#msg236701 have been merged, looking at the... Kill Bill
11:18 AM pfSense Packages Bug #2355 (Resolved): Tinydns logs won't parse records containing ":0" in the time stamp
Chris Buechler
04:19 AM pfSense Packages Bug #2355: Tinydns logs won't parse records containing ":0" in the time stamp
Fixed by https://github.com/pfsense/pfsense-packages/commit/27ea3affa00297e713a8cf7c18bb81ec96ba500b Kill Bill
10:56 AM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
> But I think there are enough nanoBSD systems out there that can potentially benefit that it is worth doing some res... Jim Thompson
10:46 AM Bug #4835: Configuration changes are slow to save after upgrade
this is probably much better with latest 2.2.4 @ https://snapshots.pfsense.org, would appreciate your feedback if you... Chris Buechler
10:38 AM Bug #4835 (Duplicate): Configuration changes are slow to save after upgrade
Chris Buechler
10:30 AM Bug #4835: Configuration changes are slow to save after upgrade
Duplicate of #4814 Kill Bill
10:28 AM Bug #4835 (Duplicate): Configuration changes are slow to save after upgrade
I have a HA setup (two physical machines with direct crossover connection for the SYNC interface) previously running ... Sean Pappalardo
09:53 AM pfSense Packages Bug #4295: stunnel not working in Release 2.2
And while at it, https://github.com/pfsense/pfsense-packages/pull/894 (the c009c57 commit) is required to be able to ... Kill Bill
09:48 AM pfSense Packages Bug #4295: stunnel not working in Release 2.2
This thing is incredibly outdated. Upstream is at 5.20. Please update the PBI. Kill Bill
08:08 AM Revision f0b41548: mwexec_bg() and mwexec() - transparent change
Slight cleanup with two effects:
1) a bit easier to follow
2) background execution returns PID of started process, wh...
Stilez y
04:09 AM pfSense Packages Bug #4555: Tiny DNS: Service does not start
Virtually no information here. If you have issues with current pfSense version and current tinydns package version, t... Kill Bill
03:33 AM pfSense Packages Bug #2720: TinyDNS does not read nameserver_*
Thanks Kill Bill and Chris Buechler! Yonas Yanfa
12:21 AM pfSense Packages Bug #2720 (Resolved): TinyDNS does not read nameserver_*
fixed, thanks Chris Buechler
01:26 AM Revision 98de735f: manual merge of Phil Davis pull request, commit b45537f75b24bc323987094e459db7b2f75aa405
Chris Buechler
01:22 AM Revision 82921c72: Merge pull request #1748 from phil-davis/patch-9
Chris Buechler

07/13/2015

11:45 PM pfSense Packages Bug #4834: vnstat php frontend cannot be accessed after vnstat2 package reinstall
Pull request https://github.com/pfsense/pfsense-packages/pull/901 Paul K
11:16 PM pfSense Packages Bug #4834 (Resolved): vnstat php frontend cannot be accessed after vnstat2 package reinstall
Every time system is upgraded or vnstat2 package is reinstall, PHP front-end becomes inaccessible. It can be accessed... Paul K
11:09 PM pfSense Packages Bug #2720: TinyDNS does not read nameserver_*
Merged and fixed ;) Kill Bill
06:34 AM pfSense Packages Bug #2720: TinyDNS does not read nameserver_*
https://github.com/pfsense/pfsense-packages/pull/899 - perhaps someone's finally gonna pick it up when added as pull ... Kill Bill
04:03 PM Todo #4832 (Resolved): Upgrade PHP to 5.5.27
confirmed in latest snapshot Chris Buechler
02:57 PM Todo #4832 (Feedback): Upgrade PHP to 5.5.27
next snapshot run, building now, should have it. Chris Buechler
02:09 PM Todo #4832: Upgrade PHP to 5.5.27
port updated, package build running now. Chris Buechler
12:53 PM Revision c4f22962: Add L2TP server's interface to mpd.conf
https://redmine.pfsense.org/issues/4830
https://forum.pfsense.org/index.php?topic=95908.0
Taras Savchuk
12:11 PM Bug #4822 (Resolved): nanobsd corruption issues after unclean shut down when rw mounted and SU
ALIX and APU both made it through 1000 power cycles while rw mounted on the slowest SD/CF I could find with no proble... Chris Buechler
04:58 AM Bug #4822: nanobsd corruption issues after unclean shut down when rw mounted and SU
Today another remote site is reporting similar symptoms. I am in the process of turning around the old Jumla one, put... Phillip Davis
04:54 AM Bug #4822: nanobsd corruption issues after unclean shut down when rw mounted and SU
I got the Alix back from Jumla. The replacement came up first time - thank goodness for AutoConfigBackup and being ab... Phillip Davis
11:11 AM Bug #4483 (Resolved): SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
Chris Buechler
11:10 AM pfSense Packages Bug #4560 (Resolved): apcupsd is missing support for SMTP TLS email and uses old check for SSL setting
Chris Buechler
11:09 AM pfSense Packages Bug #4388 (Duplicate): Squid exits when listening on port 800
Chris Buechler
11:09 AM pfSense Packages Bug #4336 (Resolved): syslog-ng package missing libraries
Chris Buechler
11:09 AM pfSense Packages Bug #1363 (Resolved): Spamd not updating pf tables
Chris Buechler
11:09 AM pfSense Packages Bug #3758 (Resolved): syslog-ng won't save settings nor it service will start
Chris Buechler
11:08 AM pfSense Packages Bug #4285 (Resolved): lcdproc package is PBI-ignorant, writing configuration outside of the PBI root
Chris Buechler
11:08 AM pfSense Packages Bug #2292 (Resolved): DarkStat interface selection needs to only allow single interface
Chris Buechler
11:07 AM pfSense Packages Bug #4421 (Duplicate): Apache reserve proxy, location must specify Site Path, Backend Path or get http 503 error
Chris Buechler
11:06 AM pfSense Packages Bug #4084 (Resolved): Check_mk agent doesn't work: wrong bash path
Chris Buechler
11:00 AM pfSense Packages Bug #4097 (Not a Bug): Unable to restart Postfix
Chris Buechler
10:51 AM pfSense Packages Bug #4609 (Duplicate): squidGuard & pfsense RAM disk compatible
#4608 Chris Buechler
10:50 AM Bug #4833 (Duplicate): android 5 can't login pfsense 2.2.3 ipsec
duplicate of #4806, already fixed in 2.2.4 snapshots @ https://snapshots.pfsense.org Chris Buechler
01:19 AM Bug #4833: android 5 can't login pfsense 2.2.3 ipsec
My pfsense is 2.2.3 akong wu
01:19 AM Bug #4833 (Duplicate): android 5 can't login pfsense 2.2.3 ipsec
Hello,
I have set ipsec for mobile client.But it's always show connecting.And I have fot some message for ipsec.
...
akong wu
10:45 AM pfSense Packages Bug #3109 (Resolved): pfBlocker disables firewall on nanobsd when no there is no internet access at boot time
Chris Buechler
10:43 AM pfSense Packages Bug #3285 (Resolved): spamd.log corrupt/truncated
Chris Buechler
08:54 AM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
JayD - wrote:
> Erm ... clearly a layer 7 issue on my end. FIXED! ;)
// Layer 8
I'll shut up now ...
JD -
08:54 AM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
Erm ... clearly a layer 7 issue on my end. FIXED! ;) JD -
06:13 AM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
Erm. See the pull request above... Kill Bill
06:10 AM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
Running on 2.2.3 the port still has to be defined manually (see screenshot). JD -
07:52 AM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
Thanks Phillip!
Done.
Taras Savchuk
07:34 AM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
It will be easy for the devs to review if you go to https://github.com/pfsense/pfsense and make the edit yourself and... Phillip Davis
07:05 AM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
Can it be included into 2.2.4? Taras Savchuk
06:20 AM pfSense Packages Bug #999: vhosts does not show up as started
Fixed by https://github.com/pfsense/pfsense-packages/commit/266662ff8334da5210ad64f08b050b1167386268 Kill Bill
06:11 AM Bug #1629: invalid state table entries after WAN IP change
I forgot to post that i am using 2.2.3 and using multiple GW's to internet. frank br
06:09 AM Bug #1629: invalid state table entries after WAN IP change
I get the same behavior for my ipsec tunnels.
if my GW (cable modem giving dhcp to pfsense) "resets" itself i do not...
frank br
06:11 AM pfSense Packages Bug #941: vhosts package config error
Fixed ages ago with https://github.com/pfsense/pfsense-packages/commit/7232161e99d60256c51a4ee94ef800f6d4f39764 Kill Bill
05:26 AM Bug #4103: Xen xn NICs can't tag VLANs
FYI, manually adjusting the select box HTML using an inline edit from the browser allows you to create the VLAN on th... Michael Jephcote
05:08 AM Revision 5eabad3d: Cancel button after input error
If there is an input error then the edit page is redrawn showing the
input errors. The HTTP_REFERER becomes the curre...
Phil Davis
05:02 AM pfSense Packages Bug #4717: Asterisk needs workarounds to work properly
Frederic Steinfels wrote:
> It seems the start script is doing more or less the same. I have no clue why the script ...
Kill Bill
03:53 AM pfSense Packages Bug #4717: Asterisk needs workarounds to work properly
It seems the start script is doing more or less the same. I have no clue why the script did not get executed. However... Frederic Steinfels
12:30 AM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
I have watched the back-and-forth on that thread and restrained myself from commenting. Keith, I will be surprised if... Phillip Davis

07/12/2015

11:53 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
Can we safely assume that proper image alignment with slower flash devices that are having issues, will at least help... ky41083 -
07:50 PM pfSense Packages Bug #4097: Unable to restart Postfix
When it's disabled it cannot be started, since the executable bit is removed intentionally - https://github.com/pfsen... Kill Bill
07:40 PM Revision b45537f7: Fix references to Load Balancer Virtual Server redirect_mode
When adding a Virtual Server, if you press Save with blank fields, the validation does not show. That was because the... Phil Davis
07:13 PM pfSense Packages Bug #3638: Radius internal certificate broken in 2.1.12_1/2.2.5 pkg v1.6.7_2 pfSense 2.1.3
greg Bernard wrote:
> Only workaround is to create your own certs using pfSense Cert Manager and apply that to the l...
Kill Bill
07:00 PM Revision ec4112dd: Interfaces PPPs edit avoid foreach() warning
If you go to Interfaces, assign, PPPs, press "+" to add an entry, then press Save without entering anything then you ... Phil Davis
06:43 PM Revision 2f0e31b1: Interfaces GRE Edit fix required fields text
The reqdfields had only 4 entries but reqdfieldsn has 5 entries and the field names to text descriptions did not matc... Phil Davis
06:34 PM pfSense Packages Bug #2695: bandwidthd package writes to RO directory in embedded
Fixed by https://github.com/pfsense/pfsense-packages/commit/65a36bbf84c3401bc79f49290493a0913fdb4936 Kill Bill
06:31 PM Revision e2db25cc: Interfaces GIF Edit fix do_input_validation
Make the required fields be correct and match thier text names, which should each have their own gettext() cal so as ... Phil Davis
06:15 PM pfSense Packages Bug #2944: dansguarian squid proxyport default set to 127.0.0.1
Fixed by https://github.com/pfsense/pfsense-packages/commit/d3ea61231ce09601a855da251e8067686c29646d Kill Bill
05:59 PM pfSense Packages Bug #3942: bind - allow starting named with "-4" argument
Fixed by https://github.com/pfsense/pfsense-packages/commit/fe0163a939023f87b259f3475a89ee632824a973 Kill Bill
05:31 PM pfSense Packages Bug #3530: TinyDNS creates incorrect NS records
My humble suggestion would be to NOT use "Automatic PTR entry" in your highly weird environment that probably noone e... Kill Bill
05:22 PM pfSense Packages Bug #3530: TinyDNS creates incorrect NS records
To better explain: in my PFsense environment, there are two nameservers:
- recursive nameserver bound to the priva...
Chris M
05:06 PM pfSense Packages Bug #3530: TinyDNS creates incorrect NS records
Cannot see how on earth is proper FQDN "incorrect" and localhost "correct" for a NS record anywhere but for localhost... Kill Bill
05:30 PM pfSense Packages Bug #2879: uninstalling Postfix Forwarder leaves widget
@OP: Code examples to remove the widget on uninstall:
https://github.com/pfsense/pfsense-packages/blob/master/conf...
Kill Bill
04:47 PM pfSense Packages Bug #897: Missing DNS record types SRV SPF DOMAINKEYS
SRV was added 4+ years ago: https://github.com/pfsense/pfsense-packages/commit/fceaec0ccf3e2f35959219c5e5498fdfda29a8... Kill Bill
04:18 PM Revision 81a73bcb: Avoid error loading rules for numeric host name in alias
Create a host-type alias. Put just a number in "IP or FQDN" - e.g. I made alias name "Zqw" and a single host "23". Th... Phil Davis
04:06 PM pfSense Packages Bug #4662: zabbixLTS snmpwalk doesn't work
Looks like another round of PBI idiocy. Perhaps try a complete uninstall and reinstall. Kill Bill
04:00 PM pfSense Packages Bug #4717: Asterisk needs workarounds to work properly
Can you post the contents of /usr/local/etc/rc.d/asterisk ? Kill Bill
03:35 PM pfSense Packages Bug #4657: Asterisk not work in ver. 2.2.1 and up
My car won't go. A.k.a. totally useless bug. Likely duplicate of Bug #4717. Kill Bill
03:03 PM pfSense Packages Bug #4419: fatal: open /etc/aliases: No such file or directory
Fixed by https://github.com/pfsense/pfsense-packages/commit/7c10d4029c809d662156d5116be882ba2f8d6af9 Kill Bill
02:45 PM pfSense Packages Bug #4084: Check_mk agent doesn't work: wrong bash path
Fixed. Kill Bill
02:35 PM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
https://github.com/pfsense/pfsense-packages/pull/897 Kill Bill
02:23 PM pfSense Packages Bug #4085: Check_mk agent configuration: 'Listen Port' is required, contrary to description
I don't know what's exactly "evidenced" by bold text, and definitely cannot see how's it required.
https://github....
Kill Bill
02:04 PM pfSense Packages Bug #2292: DarkStat interface selection needs to only allow single interface
Considering we are on 3.0.718, this should be fixed. BTW, 3.0.719 has been released. ;) Kill Bill
01:31 PM pfSense Packages Bug #3360: Apache reverse proxy-dev leaves / out of Backend Path
https://github.com/pfsense/pfsense-packages/pull/896 Kill Bill
01:04 PM pfSense Packages Bug #4421: Apache reserve proxy, location must specify Site Path, Backend Path or get http 503 error
Duplicate of Bug #3360 Kill Bill
12:53 PM pfSense Packages Bug #4561: siproxd listening port redirect rule pulling wrong tag from <siproxdsettings> (config.xml)
https://github.com/pfsense/pfsense-packages/pull/895 Kill Bill
08:53 AM Revision 0c53abc2: Firewall Aliases Edit ensure input_addresses array exists
If you click "+" to add an alias, then press Save without entering anything, you get:
Warning: Invalid argument suppl...
Phil Davis
08:40 AM Revision a3669259: Firewall Aliases Import display error message for invalid alias name
If you open firewall_aliases_import and enter just an invalid Alias Name (e.g. a$b) and press save or press save with... Phil Davis
08:13 AM pfSense Packages Bug #3495: Zabbix2-Agent and Zabbix2-proxy upgrade.
Perhaps test with current packages? Kill Bill
07:55 AM Todo #4832 (Resolved): Upgrade PHP to 5.5.27
2.2.4 PHP needs upgraded to "5.5.27":http://php.net/archive/2015.php#id2015-07-10-2
> The PHP development team ann...
Jim Pingle
07:50 AM pfSense Packages Bug #4243: Last squidguard update prevents squid from starting
Someone kindly remove the dead, unmaintained and unsupported Squid2 package for 2.2+ and consider this fixed with htt... Kill Bill
07:30 AM pfSense Packages Bug #3766: Unhashed plain passwords saved by 2 packages (one a shell login package)
Anyterm package no longer exists. Plus really, https://doc.pfsense.org/index.php/Why_are_some_passwords_stored_in_pla... Kill Bill
07:22 AM pfSense Packages Bug #3779: Zabbix Agent 1.x - ZABBIX_AGENT_BASE not defined
Should be fixed in Zabbix Agent LTS 0.8.5 Kill Bill
07:13 AM pfSense Packages Bug #4285: lcdproc package is PBI-ignorant, writing configuration outside of the PBI root
Fixed by https://github.com/pfsense/pfsense-packages/commit/8b1b7e27646806c6b283f93a62fd59ed6083f97e Kill Bill
07:09 AM pfSense Packages Bug #4415: wrong start script in nrpe2 within 64bit installation
Are you on pfSense 2.1.x or what? Kill Bill
07:05 AM pfSense Packages Bug #4560: apcupsd is missing support for SMTP TLS email and uses old check for SSL setting
Fixed. Kill Bill
07:01 AM pfSense Packages Bug #3758: syslog-ng won't save settings nor it service will start
Fixed long time ago by https://github.com/pfsense/pfsense-packages/commit/8121961c39d71cbf57bd332712e044aa6ea05203 Kill Bill
06:46 AM pfSense Packages Bug #4336: syslog-ng package missing libraries
PBI stupidity "fixed" as noted above, can be closed. Kill Bill
06:30 AM pfSense Packages Bug #3109: pfBlocker disables firewall on nanobsd when no there is no internet access at boot time
Abandoned package, no such issue with pfBlockerNG. Kill Bill
06:29 AM pfSense Packages Bug #3285: spamd.log corrupt/truncated
Fixed for quite some time. Kill Bill
06:25 AM pfSense Packages Bug #1363: Spamd not updating pf tables
This works just fine now; obsolete bug. Kill Bill
06:20 AM pfSense Packages Bug #4388: Squid exits when listening on port 800
System - Advanced - System Tunebles: edit net.inet.ip.portrange.first
Duplicate of #4297
Kill Bill
06:16 AM pfSense Packages Bug #4609: squidGuard & pfsense RAM disk compatible
Duplicate of # 4608 Kill Bill
05:49 AM Revision 9a01d22d: Static routes merge "else" and "if" into "else if"
As suggested by Renato. Phil Davis
05:44 AM pfSense Packages Bug #4831 (Closed): ntopng includes vulnerable net/libzmq4 (CVE-2014-9721)
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=200502
https://github.com/zeromq/libzmq/issues/1273
!http://i.i...
Kill Bill
03:04 AM Revision b03de800: Fix issue_ip_type var name spelling
Actually there was no real problem, but having a mis-spelling like this means that English speakers will waste time (... Phil Davis
01:18 AM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
Diff attached. Taras Savchuk
01:12 AM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
Works for me.
@[2.2.2-RELEASE][admin@gw.localdomain]/etc/inc: diff vpn.inc vpn.inc.orig
1650,1654d1649
< ...
Taras Savchuk

07/11/2015

11:52 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Denis Kozlov wrote:
> I mean, scale the MBUF according to the number of cores and network cards. Job done.
That's...
Kill Bill
05:51 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Once again, why can't this be addressed in pfSense?
I mean, scale the MBUF according to the number of cores and ne...
Denis Kozlov
05:11 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
The original problem here from years back has nothing to do with anything current, that was a 4 year old driver probl... Chris Buechler
04:44 PM Bug #1221: igb driver mbuf allocation problems on multicore machines aka Could not setup receive structures
Still on 2.2.3 this bug is for sure not resolved. Yes there is a manual workaround that needs to be applied on every ... Emanuel Somosan
11:11 PM Bug #4822: nanobsd corruption issues after unclean shut down when rw mounted and SU
SU+J gone -> sanity restored. Good riddance. Kill Bill
09:57 PM Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config
The interface gets saved OK in the config, but in /etc/inc.vpn.inc function vpn_l2tp_configure() there is no mention ... Phillip Davis
04:08 PM Bug #4830 (Resolved): "Interface" selected in GUI for L2TP server are not respected in mpd's config
I have pfSense with 2 WANs (ISPs) and L2TP server on it in head office (HO). I RDR 1701/udp to LAN address of pfSense... Taras Savchuk
09:13 PM Bug #4483: SLAAC and stateful DHCP6 IPs are configured on interface when using DHCP6 config type
This fix was released with v2.2.3. I tested it and it works as expected now. Paul K
02:43 PM pfSense Packages Bug #4567: ntopNG Geo files missing
That /usr/pbi/ntopng-amd64/bin/ntopng-geoipupdate.sh is definitely not a shell script, plus it downloads corrupt crap... Kill Bill
04:42 AM Bug #4827 (Not a Bug): Static phase2 entry requires modeconfig
Thanks for the follow up. Chris Buechler
03:00 AM Bug #4827: Static phase2 entry requires modeconfig
You are right, sorry. Tried again and it generates the proper config. Must have mixed something up. Moritz Bechler
01:03 AM Revision fd29caa1: fix fsync, thanks Phil Davis for noticing
Chris Buechler
01:03 AM Revision 63fcce23: fix fsync, thanks Phil Davis for noticing
Chris Buechler
12:53 AM Bug #4825: Mobile client IPsec config omits peer identifier
Thanks for the report, I'll review. Chris Buechler

07/10/2015

11:21 PM Revision 88f2c335: fix fsync
Chris Buechler
11:21 PM Revision 362245b0: fix fsync
Chris Buechler
11:13 PM Revision 8a811010: fsync after fclose here, clean up some white space while here.
Conflicts:
etc/inc/config.lib.inc
Chris Buechler
11:12 PM Revision 4171affc: fsync after fclose here, clean up some white space while here.
Chris Buechler
10:48 PM Revision d7b97ca3: fsync conf_path here too
Chris Buechler
10:48 PM Revision 601ba542: fsync conf_path here too
Chris Buechler
09:23 PM Revision 89a8d28e: fix typo
Chris Buechler
09:22 PM Revision 224d9d30: fix typo
Chris Buechler
08:40 PM Bug #4237: Error "macro IPsec not defined" once after firmware upgrade
I believe this happens when config.cache is corrupt or truncated because of power loss shortly after writing the file... Chris Buechler
08:27 PM Bug #4822 (Feedback): nanobsd corruption issues after unclean shut down when rw mounted and SU
updated subject to actual issue. SU+J was reverted in nanobsd today after verifying an APU made it through hundreds o... Chris Buechler
08:25 PM Bug #4827: Static phase2 entry requires modeconfig
not sure I'm following what you mean, single address in P2s works as is. What's the circumstance you're referring to? Chris Buechler
07:08 AM Bug #4827 (Not a Bug): Static phase2 entry requires modeconfig
Static phase 2 entries with a single address endpoint are generated with left/rightsourceip which means that strongsw... Moritz Bechler
07:44 PM Revision f9ee8994: system_crlmanager.php Conversion complete
Ready for review
This page has a complex mixture of forms and tables. It needs to be
reviewed for functionality.
Stephen Beaver
04:11 PM Bug #3737: Incoming VLAN traffic fails to reach VLAN interface if PCP not 0
Thanks Clement! Chris Christensen
10:43 AM Bug #3737: Incoming VLAN traffic fails to reach VLAN interface if PCP not 0
Chris, if you're interested in using PCP in your configuration you can take a look at #4133 which is more "up-to-date... Clement Barnier
04:09 AM Bug #3737: Incoming VLAN traffic fails to reach VLAN interface if PCP not 0
I believe this may be related to https://forum.pfsense.org/index.php?topic=87638 (of which I am experiencing the same... Chris Christensen
03:09 PM Bug #4829 (Resolved): Prefix delegation broken by new ISC DHCP Server 4.2.8 subnet check
A previously working IPv6 configuration for prefix delegation is broken on 2.2.3.
In /var/dhcpd/etc/dhcpdv6.conf, ...
Jim Pingle
01:18 PM Revision f17594c7: Add missing <h2> elements to panel-heading's
refs #192 Sjon Hortensius
12:33 PM Revision 11e87d3a: Merge pull request #328 from sbeaver-netgate/Remove-Cancel
remove all "Cancel" buttons on forms SjonHortensius
12:19 PM Revision 40f73fe2: Removal of "Clear" controls
Removal complete from all files Stephen Beaver
11:06 AM Feature #4828 (Duplicate): Advanced option to show hidden firewall rules in web gui
It would be really nice to be able to see the complete ruleset (including hidden rules like the "default pass rules")... Brady Vidovic
10:58 AM Bug #4792: IPSec ASN.1 DN needs double quotes in config file
Moritz Bechler wrote:
> Actually, I think this is a bug in strongswan
Of course not! That's all by (utterly brai...
Kill Bill
06:37 AM Bug #4792: IPSec ASN.1 DN needs double quotes in config file
Actually, I think this is a bug in strongswan (just filed it: https://wiki.strongswan.org/issues/1028), as the asn1dn... Moritz Bechler
07:18 AM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
Seems likely to be this:
"Unfortunately, RSS is usually capable of hashing IPv4 and IPv4 traffic (L3+L4). All other ...
Steve Wheeler
06:59 AM Bug #4824 (Rejected): Filterting firewall logs by port returns excess results
That is expected behavior. It matches based on regex/substrings. You can use regex anchors to limit what it matches, ... Jim Pingle
04:42 AM Bug #4824: Filterting firewall logs by port returns excess results
The bold 25 above should have read asterisk25asterisk (as in wildcard).
Tim Boothby
04:36 AM Bug #4824 (Rejected): Filterting firewall logs by port returns excess results
Hi,
If you filter firewall logs by e.g. port 25, the search results appear to be *25* so results include e.g. 1251...
Tim Boothby
06:57 AM Feature #4826 (Resolved): Allow configuration of multiple phase1 proposals
Phase 1 configuration is currently restricted to specifiying a single algorithm proposal. Shouldn't be too difficult ... Moritz Bechler
06:48 AM Bug #4825 (Resolved): Mobile client IPsec config omits peer identifier
The strongswan connection config generated for a mobile client association does not include the configured peer ident... Moritz Bechler
04:59 AM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
The config.xml portion was fine with Renato's change, but missed other parts of /cf/conf/. Jim T's earlier change get... Chris Buechler
01:07 AM pfSense Packages Bug #4293: Squid 2.7.9 pkg v.4.3.6 i386 won't start
James Snell wrote:
> Thank you Tahar for the ln commands, that got it running again for me after I upgraded to 2.2.3...
Kill Bill

07/09/2015

08:23 PM pfSense Packages Bug #4293: Squid 2.7.9 pkg v.4.3.6 i386 won't start
Thank you Tahar for the ln commands, that got it running again for me after I upgraded to 2.2.3-RELEASE. James Snell
07:24 PM Revision 6e332f7f: Debug removed
Ready for review Stephen Beaver
06:38 PM Bug #4310: Limiters + HA results in hangs on secondary
This is also happening to me. I though the issue with the limiters was fixed in 2.2.2 and 2.2.3, so I posted a duplic... Bernardo Pádua
06:28 PM Revision 3795cc0a: diag_ipsec.php
Conversion complete
DEBUG still in place
sbeaver
04:42 PM Bug #4823 (Duplicate): Kernel Panic on the backup server on a master/backup CARP setup with pfSync enabled
Duplicate of #4310 Jim Pingle
04:40 PM Bug #4823 (Duplicate): Kernel Panic on the backup server on a master/backup CARP setup with pfSync enabled
I'd been running two pfsense firewalls on a master/backup setup with CARP. It was running fine on the 2.1.x branch. N... Bernardo Pádua
03:19 PM Revision 9a044a7e: diag_gmirror.php
Conversion complete sbeaver
11:34 AM Bug #4822: nanobsd corruption issues after unclean shut down when rw mounted and SU
Here's one from my Alix at home that happened a while ago, but I thought it might have had a flakey CF card and I did... Phillip Davis
07:35 AM Bug #4822: nanobsd corruption issues after unclean shut down when rw mounted and SU
http://lists.freebsd.org/pipermail/freebsd-fs/2014-April/019253.html
Can we get rid of the journal "improvement" A...
Kill Bill
07:16 AM Bug #4822 (Resolved): nanobsd corruption issues after unclean shut down when rw mounted and SU
https://forum.pfsense.org/index.php?topic=96326.0... Kill Bill
08:01 AM Bug #4808: Unbound segfaults
Unfortunately not, it seems to crash rather randomly. I'd love to be able to capture a stacktrace or other useful inf... Mark Janssen
06:58 AM Bug #4804: PPPoE Restart won't update IPv6 routing table with gif
> How are you restarting the connection that triggers this?
I've written a script......
Armin Tueting
12:55 AM Bug #4804: PPPoE Restart won't update IPv6 routing table with gif
Updated subject to I think a closer description. But I can't replicate it that much even. Whether via gif, or DHCP6, ... Chris Buechler
06:43 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Maybe my situation is also related to this in some way. We do not get big ping (or I guess other big packets) from br... Phillip Davis
03:14 AM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
Alignment discussed at great length here https://forum.pfsense.org/index.php?topic=95938.0
doktornotor's input can...
ky41083 -
02:50 AM Revision 863094c5: Merge pull request #1739 from yakar/patch-6
Chris Buechler

07/08/2015

11:58 PM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
this looks to be fixed. Up to 15 cycles with no issues in a circumstance that would fail at least 50% of the time bef... Chris Buechler
11:40 PM Bug #4607: Bridge+CARP crashes/freezes pfSense
Thanks 2.2.3 is working smoothly now . Manoj Semwal (RootMd5)
11:38 PM Feature #809: Config sync username change
Thanks,
Added to : https://github.com/pfsense/pfsense/pull/1735
Brett Merrick
01:58 AM Feature #809: Config sync username change
yeah that's fine to remove the username field, no point in having it right now. Pull request welcome. Thanks!
Chris Buechler
01:44 AM Feature #809: Config sync username change
Related:
* Bug #1971 (Rejected): carp sync username not honored
* Bug #1736 (Closed): Allow other users to be used ...
Brett Merrick
05:58 PM Bug #4808 (Feedback): Unbound segfaults
is there any means of replicating? Chris Buechler
05:33 PM Revision a2a5983a: Restore section commented out for testing
sbeaver
01:30 PM Feature #4821 (Closed): PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
On PPPoE WANs packets are only received on one NIC driver queue (queue0) while packets are transmitted from all queue... Jim Pingle
01:01 PM Feature #4796: Support Multiple FIBs in pfSense
I already put in a feature request for this- https://redmine.pfsense.org/issues/4598 Jon Klinck
12:14 PM Revision cffc7ec1: services_captiveportal.php Conversion complete
Conversion complete sbeaver
10:17 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
I can somewhat confirm this with the following scenario:
* *Central Office*
** OVPN Server (TCP, AES-256-CBC, LZO...
JD -
08:46 AM Bug #4820: DHCP Scope at setup
I set LAN and WAN IP info via the console, then completed setup via the webGUI using the wizard. The initial DHCP sco... Andrew Houlne

07/07/2015

08:17 PM Bug #4820 (Feedback): DHCP Scope at setup
ditto Phil's question. The setup wizard in the web interface definitely doesn't do that, and I don't recall the conso... Chris Buechler
11:34 AM Bug #4820: DHCP Scope at setup
How did you do the initial setup - using the webGUI initial wizard, from console menu selections, or?
And how did yo...
Phillip Davis
09:15 AM Bug #4820 (Resolved): DHCP Scope at setup
At initial setup, 192.168.100.1 was used for the LAN IP and a DHCP scope of 192.168.100.0/24 appeared in the interfac... Andrew Houlne
10:57 AM pfSense Packages Bug #4819 (Not a Bug): pfSense IPsec rekey not functional
you have to delete the already-established SAs after making such changes. #4268 Chris Buechler
09:06 AM pfSense Packages Bug #4819: pfSense IPsec rekey not functional
Florian Ganée wrote:
> Solved by deleting and creating VPN entirely again
Florian Ganée
09:06 AM pfSense Packages Bug #4819: pfSense IPsec rekey not functional
Solved by deleting et creating VPN entirely again Florian Ganée
07:11 AM pfSense Packages Bug #4819: pfSense IPsec rekey not functional
Forgot to mention : running 2.2.3-RELEASE (amd64) Florian Ganée
07:08 AM pfSense Packages Bug #4819 (Not a Bug): pfSense IPsec rekey not functional
IPsec rekey is shown as Enabled in VPN phase 1 and in config files, but in Status > IPsec when Phases 1 & 2 are up "R... Florian Ganée
10:42 AM Revision 1a1d9a8c: Update index.php
Aydin Yakar
10:39 AM Revision c4b85119: Update index.php
Aydin Yakar
09:38 AM Bug #4818: IPSec makes worse in some cases - since 2.2.3 Update
Thanks for your quick response Chris!
I tried the last "nighty build" -> pfSense-Full-Update-2.2.4-DEVELOPMENT-amd64...
Marvin Kamm

07/06/2015

10:05 PM Revision f2265d88: Fix dashboard hardware crypto display where AES-NI is enabled. Ticket
Chris Buechler
10:03 PM Revision c9e7807a: Fix dashboard hardware crypto display where AES-NI is enabled. Ticket
Chris Buechler
08:41 PM Revision 10c65c48: Don't check whether the QinQ interface exists when deleting. Unnecessarily
makes QinQ un-deletable where the parent interface no longer exists
(removed, config restored from diff hardware, etc.).
Chris Buechler
08:40 PM Revision ee3b5c15: Don't check whether the QinQ interface exists when deleting. Unnecessarily
makes QinQ un-deletable where the parent interface no longer exists
(removed, config restored from diff hardware, etc.).
Chris Buechler
05:02 PM Bug #4809 (Resolved): Dashboard - Hardware crypto (aesni) display cut off with Netgate ADI Board
fixed, thanks Chris Buechler
04:56 PM Revision 7c771d19: Make sure config.xml is safe on disk when restoring a backup, ticket #4803
Renato Botelho
04:55 PM Revision 38b35612: Make sure config.xml is safe on disk when restoring a backup, ticket #4803
Renato Botelho
04:51 PM Revision a83602e8: Make sure temporary config file is safe on disk before rename, ticket #4803
Renato Botelho
04:51 PM Revision b318432e: Make sure temporary config file is safe on disk before rename, ticket #4803
Renato Botelho
04:49 PM Revision 817d1407: Remove reference to vfs.forcesync
Renato Botelho
04:48 PM Revision bee2f247: Remove reference to vfs.forcesync
Renato Botelho
04:31 PM Bug #4596 (Duplicate): NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
duplicate of #4326 Chris Buechler
04:31 PM Bug #4326 (Confirmed): Limiters on firewall rules where NAT applies drop all traffic
updated subject to root problem, closing out #4596 as duplicate of this. Chris Buechler
06:32 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Like Ryan, I'm still seeing the issue after upgrading to 2.2.3. Adam Hirsch
04:23 PM Bug #4818 (Feedback): IPSec makes worse in some cases - since 2.2.3 Update
this likely overlaps with the changes made as part of fixing #4811, which some have confirmed fixed things for them t... Chris Buechler
10:19 AM Bug #4818 (Resolved): IPSec makes worse in some cases - since 2.2.3 Update
Since updateing pfsense from V2.1.5 to V2.2.3, I´ve some issues with the IPsec VPN.
I´ve configured about 20 IPsec v...
Marvin Kamm
04:01 PM Bug #4817 (Feedback): rc.start_packages: Restarting/Starting all packages on config sync
what packages do you have installed?
That says fw1, but the logs indicate something is config syncing to that sys...
Chris Buechler
05:14 AM Bug #4817 (Closed): rc.start_packages: Restarting/Starting all packages on config sync
Applying configuration of pfsense cause openvpn server restart
When you press apply configuration on DNS TAB or on T...
Tsvyatko Kriviradev
03:43 PM Revision d0577bd2: Use right function pfSense_fsync to make sure config file is safe on disk, ticket #4803
Renato Botelho
03:42 PM Revision de7ae0bb: Use right function pfSense_fsync to make sure config file is safe on disk, ticket #4803
Renato Botelho
11:50 AM Bug #4803 (Feedback): config.xml is empty if power loss or panic happens shortly after config write
Please try next round of snapshots, a pfSense_fsync was implemented and is being used to make config.xml save operati... Renato Botelho
02:46 AM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
Jim Thompson wrote:
> This needs similar work (and a PHP extension, because fsync() isn't possible via PHP) to what ...
Kill Bill
09:00 AM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
Another observation, after some time (30min-60min) its recover from badly filled tables and are filled with proper IP... Tomas Ulicky
08:50 AM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
In the log there is correctly: filterdns: adding entry 1.1.1.1 to table IP_Alias_1 on host fqdn1.server.com
But in ...
Tomas Ulicky
08:37 AM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
Update, it is not working even with filterdns.fixed, after some time, if I reload some firewall rules tables are mism... Tomas Ulicky
02:00 AM Revision 8cbb22c6: fix includes so shellsession restartipsec works.
Chris Buechler
02:00 AM Revision d04b109b: fix includes so shellsession restartipsec works.
Chris Buechler

07/05/2015

09:36 PM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
The sync option was not an *optimal* fix, but it was a proper fix, as it does fix the corruption issue, and was what ... Jim Thompson
11:47 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Thomas X wrote:
> I was just wondering why this could happen although sync was added in 2.2.3.
Probably because t...
Kill Bill
09:16 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
One addition: Filesystem has been in standard NanoBSD mode (ReadOnly) when the loss of power appeared. Thomas X
09:10 AM Bug #4523: master.passwd/group file corruption may occur after kernel panic or unclean shut down
Today I had a power loss with pfSense 2.2.3 AMD64 NanoBSD, which seems to have corrupted the installation. The system... Thomas X
09:34 PM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
This needs similar work (and a PHP extension, because fsync() isn't possible via PHP) to what fixed the corruption of... Jim Thompson
09:32 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
that patch isn't going into pfSense.
We'll investigate 'why' the transition is slow, then attempt to develop a sol...
Jim Thompson
05:48 PM Bug #4816 (Resolved): Do not overwrite custom /etc/dh-parameters.* on upgrade
When people go through the hassle of generating their own set of DH parameters, it'd be nice to not overwrite those a... Kill Bill
05:33 PM Revision 028ff8f8: Fix #4813 validation of enable/disable of gateways and static routes
1) A disabled gateway can always be enabled - no extra validation
needed.
2) When disabling an enabled gateway, check...
Phil Davis
05:21 PM Bug #4237: Error "macro IPsec not defined" once after firmware upgrade
Having the same issue here:
[ There were error(s) loading the rules: /tmp/rules.debug:108: macro IPsec not define...
Johannes Ullrich
12:39 PM Bug #4813: It's not possible to disable a static route that is set to use a gateway that is disabled using the edit dialogue.
Validation of enable/disable of gateways and static routes
Pull request: https://github.com/pfsense/pfsense/pull/173...
Phillip Davis

07/04/2015

10:56 AM Bug #4815: NTP status widget shows truncated IPv6 address
Well, apparently there's the same issue with Status - NTP. This can be solved by using -w option (https://bugs.ntp.or... Kill Bill
10:24 AM Bug #4815 (Resolved): NTP status widget shows truncated IPv6 address
See screenshot. In fact, the IP is 2001:718:801:230::8c as confirmed by ntpq -p.
!http://i62.tinypic.com/2vvmm4p.png!
Kill Bill
06:47 AM Revision 5af64602: remove debug.pfftpproxy, it no longer exists.
Chris Buechler
06:47 AM Revision f39cb6af: remove debug.pfftpproxy, it no longer exists.
Chris Buechler
05:07 AM Bug #4811 (Resolved): keyid identifiers not working
fixed Chris Buechler
04:28 AM Bug #4806 (Feedback): Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
looks to be fixed in 2.2.4 after gitsync, next snapshot will include those changes. Chris Buechler
04:11 AM Revision aaf07882: de-activate sync on upgrade where it's enabled now that the root passwd/group problem is fixed. Ticket #4523
Chris Buechler
04:11 AM Revision 2300307e: de-activate sync on upgrade where it's enabled now that the root passwd/group problem is fixed. Ticket #4523
Chris Buechler
04:09 AM Bug #4791 (Resolved): AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
fixed Chris Buechler
01:06 AM Revision d44e7dc0: Fix keyid identifers, and go back to using %any in ipsec.secrets as in previous versions, fixing a variety of other ID issues. Latter will break some mobile IPsec circumstances, fix for that to come after more testing. Ticket #4811
Chris Buechler
01:03 AM Revision f5aec3e1: Fix keyid identifers, and go back to using %any in ipsec.secrets as in previous versions, fixing a variety of other ID issues. Latter will break some mobile IPsec circumstances, fix for that to come after more testing. Ticket #4811
Chris Buechler

07/03/2015

11:11 PM Bug #4523 (Feedback): master.passwd/group file corruption may occur after kernel panic or unclean shut down
this is adequately worked around in 2.2.3 with the usage of sync. Now that we have a proper fix for pw in 2.2.4, and ... Chris Buechler
06:47 PM Revision a61daab9: Fix put static route destination in config change description
When enabling or disabling a route by using the enable/disable button on the Routes page, the destination network was... Phil Davis
06:47 PM Revision 96f98071: Merge pull request #1736 from phil-davis/patch-1
Renato Botelho
06:35 PM Revision 6135a11f: Fix put static route destination in config change description
When enabling or disabling a route by using the enable/disable button on the Routes page, the destination network was... Phil Davis
05:27 PM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
#4814 opened re: the regression of #2401 for the slow ro->rw mount issue discussed here. Chris Buechler
05:27 PM Bug #4814: read-only to read-write mount very slow on nanobsd with slow flash media
this patch fixes the issue, though apparently isn't good.
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=176169
...
Chris Buechler
05:25 PM Bug #4814 (Closed): read-only to read-write mount very slow on nanobsd with slow flash media
Opening a new issue to track the regression of old bug #2401. The ro->rw mount is so slow on some hardware that it ma... Chris Buechler
01:42 PM Bug #4813: It's not possible to disable a static route that is set to use a gateway that is disabled using the edit dialogue.
I just made a pull request for the first tiny error I noticed:
https://github.com/pfsense/pfsense/pull/1736
I am ...
Phillip Davis
10:58 AM Bug #4813 (Resolved): It's not possible to disable a static route that is set to use a gateway that is disabled using the edit dialogue.
If you attempt to edit a static route to disable it and the gateway set is already disabled you will receive the foll... Steve Wheeler

07/02/2015

11:39 PM Bug #4811: keyid identifiers not working
The likely cause for this is the mishandling of the identity type prefixes, as reported on bug "4792":https://redmine... Jorge Albarenque
08:12 PM Revision 49683954: sync up vpn.inc with master. Mostly white space and style changes
Chris Buechler
07:46 PM Revision 255075c9: sync up ipsec.inc with master. Mostly whitespace and style changes.
Chris Buechler
11:44 AM pfSense Packages Bug #4812 (Duplicate): Layer7 Filter
duplicate of #4309 Chris Buechler
11:43 AM pfSense Packages Bug #4812 (Duplicate): Layer7 Filter
internet stops working after creating layer 7 filter then adding it into firewall rule.
i followed this link - (http...
Aamir Hussain
11:40 AM pfSense Packages Bug #4309: layer7 do not work properly
my internet stops working after creating layer 7 filter then adding it into firewall rule.
i followed this link - (h...
Aamir Hussain
08:19 AM Todo #4672: Update igmpproxy to latest version
Yes, I have used this steps from forum (credit Andrew)
But I did pkg stuff on another pfsense and extracted only bin...
Tomas Ulicky
06:53 AM Bug #4746: captive portal allowed hostnames not loaded into table at boot time
Yes, the 2.2.3 New Features and Changes page says that this is fixed in 2.2.3, but here in Redmine it says target 2.3... Phillip Davis
03:15 AM Bug #4746: captive portal allowed hostnames not loaded into table at boot time
As stated in version 2.2.3 changelog, this bug has to be resolved but now, it doesn't work also if you add FQDN in th... Davide Cottignoli
05:50 AM Bug #4794: Handling of ASN1.DN values for RSA IPsec during upgrades from previous versions
As I've recently explained on an "Ubuntu bug report related to pfSense":https://bugs.launchpad.net/ubuntu/+source/str... Tobias Brunner
02:31 AM Bug #4596: NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
Tested now.
I confirm the problem on 2.2.3, limiters works well on LAN, but if I enable on WAN breaks 1:1 NAT.
Luca De Andreis
12:23 AM Revision e9b65f25: fix part of keyid problem. Ticket #4811
Chris Buechler

07/01/2015

09:03 PM Revision 4af5c0c8: Remove unnecessary deletion of rc.conf. Add an empty rc.conf with a note
so people don't think they should be using it. Chris Buechler
08:10 PM Revision bc5c2e54: Improve handling of port ranges in relayd, fixes #4810
Jim Pingle
08:10 PM Revision 9195a837: Improve handling of port ranges in relayd, fixes #4810
Jim Pingle
08:03 PM Revision 71ffb7bb: Merge branch 'RELENG_2_2' of git.pfmechanics.com:pfsense/pfsense into RELENG_2_2
Chris Buechler
08:01 PM Revision 9924ebd4: Remove the unnecessary deletion of rc.conf. Add an empty rc.conf with a
note so people don't think they should be using it. Chris Buechler
07:18 PM Bug #4811 (Resolved): keyid identifiers not working
keyid identifiers in IPsec stopped working from 2.2.2 -> 2.2.3. Chris Buechler
05:33 PM Revision 45521d7c: Remove $array_keys references and use $pkg_info. Spotted-by: phil-davis
Renato Botelho
03:36 PM Revision b75cdd94: Encode ca/cert descr in system_certmanager.php
Jim Pingle
03:32 PM Revision 362ddda1: Encode ca descr in system_camanager.php
Jim Pingle
03:32 PM Revision b741d2ef: Encode ca/cert descr in system_certmanager.php
Jim Pingle
03:28 PM Revision 97fdd83d: Encode ca/cert descr in system_certmanager.php
Jim Pingle
03:27 PM Revision 234cde4b: Encode ca/cert/crl descr in system_crlmanager.php
Jim Pingle
03:20 PM Revision f08e24a3: Encode ca/cert/crl descr in system_crlmanager.php
Jim Pingle
03:20 PM Bug #4810: Load Balancing GUI does not properly handle port ranges in relayd.conf
Applied in changeset commit:bc5c2e542c7a89ae59f079540ee6fc8f4183b9aa. Jim Pingle
03:20 PM Bug #4810 (Feedback): Load Balancing GUI does not properly handle port ranges in relayd.conf
Applied in changeset commit:9195a8378002ed41b459eb8c53a208f5fc6f8d4c. Jim Pingle
03:05 PM Bug #4810 (Resolved): Load Balancing GUI does not properly handle port ranges in relayd.conf
relayd supports port ranges in the listen directive but the forward directive should only have the first port. Also, ... Jim Pingle
03:19 PM Revision 28bb8178: Encode ca/cert descr in vpn_openvpn_server.php
Jim Pingle
03:18 PM Revision 009bd5fe: Encode ca/cert descr in vpn_openvpn_server.php
Jim Pingle
03:17 PM Revision 8bcc385b: Encode ca/cert descr in vpn_openvpn_client.php
Jim Pingle
03:16 PM Revision f7ca9674: Encode ca/cert descr in vpn_openvpn_client.php
Jim Pingle
03:15 PM Revision d6a94eda: Encode ca/cert descr in vpn_ipsec_phase1.php
Jim Pingle
03:15 PM Revision f9e80e5d: Encode ca/cert descr in vpn_ipsec_phase1.php
Jim Pingle
03:14 PM Revision a1457143: Encode ca/cert descr in system_authservers.php
Jim Pingle
03:13 PM Revision 2ce606e1: Encode ca/cert descr in system_authservers.php
Jim Pingle
03:12 PM Revision 11df0320: Encode ca/cert descr in system_usermanager.php
Jim Pingle
03:11 PM Revision 76e3f194: Encode ca/cert descr in system_usermanager.php
Jim Pingle
03:11 PM Revision 0d458903: Encode cert/ca descr in system_advanced_admin.php
Jim Pingle
03:10 PM Revision d2d45b5f: Encode cert/ca descr in system_advanced_admin.php
Jim Pingle
03:10 PM Revision e67c70a3: Encode cert/ca descr in services_captiveportal.php
Jim Pingle
03:08 PM Revision 0d6b017b: Encode cert/ca descr in services_captiveportal.php
Jim Pingle
03:07 PM Revision 636dfa95: Encode ca/cert info in openvpn_wizard.inc
Jim Pingle
03:06 PM Revision ae142a10: Encode ca/cert info in openvpn_wizard.inc
Jim Pingle
02:29 PM Revision 3d3e30b3: Modify pkg_mgr.php to deal with pkg
Renato Botelho
02:16 PM Bug #4803 (Confirmed): config.xml is empty if power loss or panic happens shortly after config write
This does not appear to be specific to NanoBSD or even sync on the filesystem.
I can replicate this by causing a p...
Jim Pingle
02:15 PM Bug #4809 (Resolved): Dashboard - Hardware crypto (aesni) display cut off with Netgate ADI Board
If aesni is available and enabled, the Dashboard displays a cut off Hardware crypto line
Hardware crypto <AES-CBC
...
Guido Glaus
01:58 PM Revision 29d84dd4: Fix install_package calls and check for failures
Renato Botelho
01:58 PM Revision 5e51b5b9: Simplify logic and use correct calls for install_package
Renato Botelho
01:57 PM Revision fad3ad59: Fix install_package() return for failure
Renato Botelho
01:22 PM Revision 6a3380dd: Remove old and unnecessary code
Renato Botelho
01:20 PM Revision b27ac786: Stop using undefined variable and create a single package debug file
Renato Botelho
01:19 PM Revision 9b1aa8d9: Improve debug messages
Renato Botelho
01:18 PM Revision 666c49ce: Fix call to undefined function read_pkg_config
Renato Botelho
01:18 PM Revision 0d579b59: Only try to remove pkg if it's installed, otherwise just cleanup xml part
Renato Botelho
01:17 PM Revision 65c94077: Implement get_pkg_info()
Renato Botelho
01:17 PM Revision e1382589: Make pkg_delete() more verbose
Renato Botelho
01:16 PM Revision e7553e1b: Remove packages from cache after install, also add debug messages
Renato Botelho
01:15 PM Revision 26994952: Mute call to 'pkg info -e' used to check if pkg is installed
Renato Botelho
01:14 PM Revision 6fd37d04: Re-implement pkg_call() using proc_open() and stream_select() and also implement pkg_exec()
Renato Botelho
01:09 PM Revision 1e8644ca: pfsense-utils.inc is being required, there is no chance of update_status() and update_output_window() don't exist
Renato Botelho
11:54 AM Todo #4672: Update igmpproxy to latest version
Tomas: what are you changing the binary to, just the one from stock FreeBSD ports? Chris Buechler
04:35 AM Todo #4672: Update igmpproxy to latest version
I support this idea, because it is not difficult to implement and solves many problem.
Currently Im changing binary...
Tomas Ulicky
08:30 AM Revision e2451989: Only process Traffic Graph object if it is open
Reduces useless CPU use on the pfSense box when the dashboard is
displayed with the Traffic Graphs widget.
Phil Davis
06:09 AM Bug #4808 (Closed): Unbound segfaults
On one of my pfSense boxes I've seen Unbound segfault a couple of times. Since pfSense doesn't seem to monitor Unboun... Mark Janssen
05:59 AM Bug #4791: AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
I just hit this issue as well, disabling AES-NI did the trick. It's a bit unfortunate that the release notes/blog pos... Mark Janssen
04:22 AM Bug #4806: Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
Chris Buechler wrote:
> this diff will fix iOS.
>
> [... @@ -613,7 +613,7 @@ EOD; ...]
>
I saw this issue bef...
Arno Tilroe
12:35 AM Bug #4806: Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
this diff will fix iOS. ... Chris Buechler
04:04 AM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
Yeah, sorry this is typo, correct one is:
IP_Alias_10 IP_Alias_5, IP_Alias_2, IP_Alias_1, IP_Alias_3, IP_Alias_4
Tomas Ulicky
01:15 AM Bug #4804: PPPoE Restart won't update IPv6 routing table with gif
Chris Buechler wrote:
> what type of v6 connectivity do you have? Looks like a HE.net or similar tunnel?
Connectit...
Armin Tueting
12:40 AM Bug #4807 (Resolved): Unbound interface-automatic not added where interfaces list is empty
adding ticket for tracking, already-fixed issue here:
https://github.com/pfsense/pfsense/commit/342f509028bc675c811...
Chris Buechler

06/30/2015

10:22 PM Bug #4463: Fix the NTPD Access Restrictions / and other NTPD related issues, including GPS
Anything I can do to help move this along? Do I need to clarify anything? Andrew Stuart
10:19 PM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
this ticket is specific to vpnc and only vpnc. iOS PSK issues in 2.2.3 is #4806 Chris Buechler
04:11 AM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
Hi,
Attached are the screenshots of the VPN configuration for this, along with a log file of the connection attemp...
David Harrigan
03:41 AM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
Hi,
I can confirm that this issue is still affecting me - with the disable AES-NI workaround enabled. My iOS clien...
David Harrigan
10:18 PM Bug #4806 (Confirmed): Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
fixing some mobile IPsec scenarios broke iOS PSKs, I'm already looking into it. Chris Buechler
10:11 PM Bug #4806 (Resolved): Mobile IPSec Broken on iOS devices after 2.2.3 Upgrade from 2.2.2
Since others are posting to [[https://redmine.pfsense.org/issues/4784]]. I figured it's worth opening a new ticket in... Andrew Stuart
08:10 PM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
@Tomas - your description of IP_Alias_10 includes IP_Alias_6
But IP_Alias_6 is not mentioned anywhere else.
Is ther...
Phillip Davis
04:51 PM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
And IP_Alias_10 contains only IP address from IP_Alias_5 Tomas Ulicky
04:48 PM Bug #4805: Using FQDN and IP in alias causes static entries to be lost
For better replication this is what happening:
IP_Alias_10 IP_Alias_6, IP_Alias_2, IP_Alias_1, IP_Alias_3, IP_Alias...
Tomas Ulicky
04:41 PM Bug #4805 (Resolved): Using FQDN and IP in alias causes static entries to be lost
Hi, despite of fact that this issue was resolved (https://redmine.pfsense.org/issues/4296), I have problem, that in A... Tomas Ulicky
03:40 PM Revision 0e715186: Make rc.packages deal with fcgicli call
Renato Botelho
03:26 PM Bug #4790: Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!
Hi Chris,
I know, that's why I did - before I opened this bug - at least tried it for two days without Snort... in...
Ingo-Stefan Schilling
11:29 AM Bug #4790 (Not a Bug): Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!
That definitely sounds like you have a Snort signature set enabled that's too touchy, and it blocked the remote endpo... Chris Buechler
05:56 AM Bug #4790: Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!
Thank you for your Update and Feedback, I found meanwhile that https://forum.pfsense.org/index.php?topic=78151.15 did... Ingo-Stefan Schilling
11:50 AM Bug #4804 (Feedback): PPPoE Restart won't update IPv6 routing table with gif
what type of v6 connectivity do you have? Looks like a HE.net or similar tunnel?
Did this work at any previous po...
Chris Buechler
08:15 AM Bug #4804 (Closed): PPPoE Restart won't update IPv6 routing table with gif
Hello,
after rebooting pfSense 2.2.3 ...
Armin Tueting
11:43 AM pfSense Packages Bug #4304: pfflowd non-functional on 2.2.x versions
given some period of time, it also goes nuts and starts logging like mad, to the extent its logging generates over 6 ... Chris Buechler
07:03 AM pfSense Packages Bug #4304 (Confirmed): pfflowd non-functional on 2.2.x versions
Opening this back up. Though pfflowd does not complain about the pfsync version, it does not produce any data. Jim Pingle
11:06 AM Bug #4795 (Not a Bug): IPsec logging is not working
Chris Buechler
04:43 AM pfSense Packages Bug #4799: Emulex OCE11102-NT & PFSENSE 2.2.2 & VLAN TAG
Thank you for your quick answer.
I tested this morning opnsense (the fork from pfsense and based on FreeBSD 10.1)...
Romain Amar
02:33 AM Bug #4803: config.xml is empty if power loss or panic happens shortly after config write
dem co wrote:
> 3 minutes+ waiting time when running conf_mount_ro() on CF card).
That's due to removal of this p...
Kill Bill
01:48 AM Bug #4803 (Resolved): config.xml is empty if power loss or panic happens shortly after config write
When running ver 2.2.3 nanobsd with filesystem kept permanently read-write enabled (due to 3 minutes+ waiting time wh... dem co

06/29/2015

09:07 PM Bug #4795: IPsec logging is not working
I apologize, my issue was not actually with IPsec logging. Syslog was not working at all, even across reboots, on two... Jorge Albarenque
11:03 AM Bug #4795 (Feedback): IPsec logging is not working
where is it not working, what's blank? It works fine in general. Chris Buechler
05:30 PM Revision bdfce2a4: Merge branch 'RELENG_2_2' of git.pfmechanics.com:pfsense/pfsense into RELENG_2_2
Chris Buechler
02:54 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Ermal Luçi wrote:
> This seems affecting only NAT with limiters.
> It should be handled properly now in 2.2.3 i wil...
Ryan Clough
02:19 PM Bug #3096: Limiters problem using Multi WAN
Any news about when this bug will be dealt with ? I don't see it in the roadmap. Jonathan Gibert
01:55 PM Bug #4802 (Duplicate): OpenVPN Client wont start after reboot, when set to a Gateway Group specifing a VIP
duplicate #4661 Chris Buechler
01:52 PM Bug #4802 (Duplicate): OpenVPN Client wont start after reboot, when set to a Gateway Group specifing a VIP
An OpenVPN Client won't start after reboot of the primary node, when set to a Gateway Group specifing a VIP. Cullen Trey
01:55 PM Bug #4661 (Confirmed): OpenVPN client can't assign to GWGroup specifying VIPs
Chris Buechler
01:29 PM Bug #4722: Ralink USB driver yields a double fault panic on pfSense, works on FreeBSD with equivalent config
Spoke too soon, I went back and tried it on the original hardware that was used to replicate the problem and it still... Jim Pingle
12:24 PM Bug #4722: Ralink USB driver yields a double fault panic on pfSense, works on FreeBSD with equivalent config
Apparently so. Moving the sleep down below the other line allows it to function. Occasionally drops an error on the c... Jim Pingle
11:46 AM Bug #4722 (Confirmed): Ralink USB driver yields a double fault panic on pfSense, works on FreeBSD with equivalent config
guessing this is probably all 2.2.x versions.
Does the workaround in #4740 also work around this?
Chris Buechler
01:05 PM Bug #4790 (Feedback): Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!
I'm guessing the IPsec service is one you've restarted in the process? There should be nothing rebooting does that re... Chris Buechler
12:40 PM Bug #4801: IPSec multiple Phase 2 single-phase 1
Chris Buechler wrote:
> no indications of a bug here. If IKEv2, and a Cisco ASA on the other side, that's #4704 (whi...
jose wagner alves da cruz
12:09 PM Bug #4801 (Not a Bug): IPSec multiple Phase 2 single-phase 1
no indications of a bug here. If IKEv2, and a Cisco ASA on the other side, that's #4704 (which is a Cisco problem ult... Chris Buechler
10:18 AM Bug #4801 (Not a Bug): IPSec multiple Phase 2 single-phase 1
I can not connect multiple Phase 2 single-phase 1.
I have an IPSec VPN with a business partner, but I need to have...
jose wagner alves da cruz
11:43 AM Bug #3330 (Confirmed): Load Balancer showing wrong Status when using aliases for the port
Chris Buechler
11:43 AM Feature #4787 (Needs Patch): Time restrictions on Users, for Captive Portal auth
I don't see this being something we integrate into the user manager, given those with these requirements often have o... Chris Buechler
11:39 AM Bug #4738 (Resolved): Setup Wizard can result in invalid LAN DHCP pool calculation
Chris Buechler
11:38 AM Feature #4782 (Feedback): Display monitor IP on Gateways widget
Chris Buechler
11:37 AM Bug #4797 (Feedback): Display any advanced DHCP server settings when opening Services DHCP webGUI page
Thanks Phil. I'll confirm when time permits Chris Buechler
10:31 AM Revision f4f884bc: Merge pull request #1732 from phil-davis/traffic-graphs-widget
Renato Botelho
10:20 AM Bug #4800 (Rejected): IPSec múltiplas fase 2 com uma fase 1
Superseded by #4801 that has description in english. Renato Botelho
09:17 AM Bug #4800 (Rejected): IPSec múltiplas fase 2 com uma fase 1
Não consigo conectar múltiplas fase 2 com uma fase 1.
Possuo uma vpn IPSec com uma empresa parceira, porém necessi...
jose wagner alves da cruz
10:03 AM Bug #4685 (New): Crash/panic "Sleeping thread owns a non-sleepable lock"
Customers are still reporting panics on 2.2.3 with all of the fixes thus far applied. Crash dump looks virtually iden... Jim Pingle
09:36 AM pfSense Packages Bug #4799 (Rejected): Emulex OCE11102-NT & PFSENSE 2.2.2 & VLAN TAG
We can't call this a bug since that isn't a driver we include or have any capability to test. It appears you copied t... Jim Pingle
08:38 AM pfSense Packages Bug #4799 (Rejected): Emulex OCE11102-NT & PFSENSE 2.2.2 & VLAN TAG
Hello,
I bought a 10Gbe Emulex OCE11102-NT. The network card works fine on FreeBSD 10.1. I tried to configured som...
Romain Amar
02:14 AM Feature #4798: Make host and domain overrides available to both DNS Resolver and DNS Forwarder
The code was already there with 2.1.x and the unbound *package*. https://github.com/pfsense/pfsense-packages/blob/mas... Kill Bill

06/28/2015

04:51 AM Feature #4798 (New): Make host and domain overrides available to both DNS Resolver and DNS Forwarder
There have been a few times on the forum when people need to be told to put in their Host or Domain Overrides again w... Phillip Davis
04:11 AM Bug #4797: Display any advanced DHCP server settings when opening Services DHCP webGUI page
Fixed by commit to master:
https://github.com/pfsense/pfsense/commit/90ad3a76edae543bcc63252b14660ac4baee291e
Phillip Davis
04:11 AM Bug #4797 (Resolved): Display any advanced DHCP server settings when opening Services DHCP webGUI page
When the services_dhcp page is shown the contents of advanced settings are not shown to the user - the user has to cl... Phillip Davis
04:05 AM Bug #4738: Setup Wizard can result in invalid LAN DHCP pool calculation
The commit to 2.2 branch was:
https://github.com/pfsense/pfsense/commit/dc6695c3f41f65dd3232e311e589bad217bb4c10
Th...
Phillip Davis
03:58 AM Feature #4783: Add description as a display option on Traffic Graph
Done by commits:
https://github.com/pfsense/pfsense/commit/a7a064f4e523cc94d8570075e8b3b9a9220da3a3
https://github....
Phillip Davis
03:54 AM Feature #4782: Display monitor IP on Gateways widget
Done by commits:
https://github.com/pfsense/pfsense/commit/3d0391f1d843a04ae1072440c8e38bbf392cb4c6
https://github....
Phillip Davis
12:30 AM Feature #4796 (New): Support Multiple FIBs in pfSense
The current default pfSense kernel is not built with multiple FIB support. Multiple FIB support has been in FreeBSD ... Jeremy Porter

06/27/2015

10:23 PM Bug #4795 (Not a Bug): IPsec logging is not working
The IPsec logs stay blank even when setting all options to "highest".
I believe this is an issue on how the syslog...
Jorge Albarenque
10:17 PM Bug #4794 (Resolved): Handling of ASN1.DN values for RSA IPsec during upgrades from previous versions
The certificate CNs are interpreted differently by raccoon and strongSwan, for example:
+raccoon:+
C=US, ST=Whate...
Jorge Albarenque
10:14 PM Bug #4792: IPSec ASN.1 DN needs double quotes in config file
I stumbled upon this today.
If you omit the identity prefix altogether, strongSwan will guess and convert the data...
Jorge Albarenque
12:04 PM Bug #4792: IPSec ASN.1 DN needs double quotes in config file
Cullen Trey wrote:
> Or just throw away the asn1dn identifier...?
Sounds like a plan. Completely craptastic desig...
Kill Bill
05:33 AM Bug #4792: IPSec ASN.1 DN needs double quotes in config file
Okay, understood why it is not possible to specify:
leftid = asn1dn:C=CH/ST=Aargau/L=Baden/O=TechFreak/emailAddres...
Cullen Trey
03:03 AM Bug #4792 (Resolved): IPSec ASN.1 DN needs double quotes in config file
This is a bug #4275 reintroduced in 2.2.3:
Upon upgrade of 2.2.2 to 2.2.3 strongswan did not start and quit with ...
Cullen Trey
01:45 PM Revision 08d1762e: Implement ->toggle(selector, 'disable') + handle adv. globally
handle advanced globally; when an input has .advanced class, it will
automatically be hidden and a button to show all...
Sjon Hortensius
01:09 PM Revision 9801e938: head - specify utf-8 charset
Sjon Hortensius
10:55 AM Revision ea5665c7: firewall_rules; implement sortable for ordering rules
also; remove 'delete selected' and ID column until we know if its
useful; allows buttons and most rules on single li...
Sjon Hortensius
06:45 AM pfSense Packages Bug #4793: squidguard crashes squid when enabled
Shared object "libldap-2.4.so.2" not found, required by "squidGuard"
2015/06/27 11:42:01 kid1| Starting Squid Cache ...
Bipin Chandra
06:34 AM pfSense Packages Bug #4793: squidguard crashes squid when enabled
Jun 27 11:36:36 php-fpm[55499]: /pkg_edit.php: The command '/usr/pbi/squid-i386/sbin/squid -k reconfigure -f /usr/pb... Bipin Chandra
04:32 AM pfSense Packages Bug #4793 (Closed): squidguard crashes squid when enabled
on 2.2.3 squid3 works fine but as soon as u enable squidguard then squid constantly crashes with messages as redirect... Bipin Chandra
05:57 AM Bug #807: Cannot set the keymap to anything other then the default
Hi,
I observed the same thing on the 2.2.3 fresh install
Florent THOMAS
05:56 AM Bug #4387: Installer does not offer choices for keymap, screenmap or video font
In the installer, it was possible to choose something else instead default. In the 2.2.3 no more keymap are availabl... Florent THOMAS
03:15 AM Bug #4661: OpenVPN client can't assign to GWGroup specifying VIPs
Hello,
even worse, if a OpenVPN client in 2.2.3 is set to a GWGroup specifying VIPs, first it is working. Meening ...
Cullen Trey

06/26/2015

05:47 PM Bug #4791: AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
Not sure if it's needed but I can confirm that Disabling AESNI works. Chris Sutcliff
02:02 PM Bug #4791 (Feedback): AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
Patch that broke it (ipsec_aescbc_aesni.diff) was reverted. Should be fine on 2.2.4 snapshots Renato Botelho
11:41 AM Bug #4791: AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
Looks like it's related to the AESNI module now attempting to process all AES rather than only AES-GCM. It works fine... Jim Pingle
11:35 AM Bug #4791 (Resolved): AES-NI on 2.2.3-RELEASE broken with non AES-GCM modes
Hi,
Numerous reports are coming in of IPSec not working correctly with the 2.2.3-RELEASE. Multiple failures on sit...
David Harrigan
02:55 PM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
Jim P wrote:
> Your issue is likely #4791 and not related to this ticket.
Thanks Jim,
That was my first though...
Edward Roper
02:51 PM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
Edward Roper wrote:
> I'm also having this issue. Please let me know if there is any specific information I can prov...
Jim Pingle
02:49 PM Bug #4784: IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
I'm also having this issue. Please let me know if there is any specific information I can provide to assist. Everythi... Edward Roper
01:45 PM Revision 342f5090: Use interface-automatic for Unbound when the interfaces list is empty (same as All) otherwise it breaks with a default CARP config.
Jim Pingle
01:45 PM Revision a2cbbb74: Use interface-automatic for Unbound when the interfaces list is empty (same as All) otherwise it breaks with a default CARP config.
Jim Pingle
11:31 AM Bug #4364: cannot change or set keymap during and after install
Additionnaly I tried to follow this : https://forum.pfsense.org/index.php?topic=52145.msg279761#msg279761
No keymaps...
Florent THOMAS
11:12 AM Bug #4364: cannot change or set keymap during and after install
Hi,
I've just installed the 2.2.3 an it still not working
Florent THOMAS
11:26 AM Bug #4147: IPsec - IPv4 Phase 1 using FQDN resolves to IPv6 IP
https://wiki.strongswan.org/issues/993
Kill Bill
10:55 AM Revision f3ec49e1: Only process Traffic Graph object if it is open
The Traffic Graphs widget puts a graph object for every interface into
the HTML of the widget. Underneath the graph o...
Phil Davis
10:34 AM Bug #4790 (Not a Bug): Established IPSec Tunnel refused transporting further traffic out of sudden.. it than refuses any rule based traffic to anywhere!
*Scenario*
* *In General*
* Everything is IPv4 by now
* *Local office* network which is running PFSense in Hyp...
Ingo-Stefan Schilling
07:07 AM Feature #4789: user interface / text fields are too short to display long alias names
This may be a non-issue in 2.3, the whole GUI is getting a Bootstrap facelift (https://blog.pfsense.org/?p=1773) Jim Pingle
01:27 AM Feature #4789 (Resolved): user interface / text fields are too short to display long alias names
We use a lot of aliases, which are sometimes very long and we face the problem that in the standard template "pfsense... Steven Dale
07:06 AM Feature #4788 (Rejected): Can 8g or larger nanobsd images be made?
The builder has code to make 8 and 16GB images, but we don't generate them ourselves. We do not recommend using NanoB... Jim Pingle
03:22 AM Bug #3330: Load Balancer showing wrong Status when using aliases for the port
Just to bump, this is still the case in 2.2.3. If Daniel Onisoru's ports alias issue above hasn't been made into an i... Murray Crane

06/25/2015

09:24 PM Feature #4788 (Rejected): Can 8g or larger nanobsd images be made?
I am loading a number of ISO images and files onto \tftpboot for use with the TFTP package and pxelinux but find the ... Justin Yendrowich
06:33 PM Feature #4787: Time restrictions on Users, for Captive Portal auth
Confirmed this works as expected. Radius server is relatively complex to set up, I will do a tutorial on it. Criggie .
01:22 PM Revision 608f6828: Merge pull request #1717 from phil-davis/traffic-graph-description
Renato Botelho
12:39 PM Revision 72e2a428: Merge pull request #1725 from phil-davis/gateways-widget
Renato Botelho
11:48 AM Revision 03e4bd0c: Merge pull request #1730 from phil-davis/patch-2
Renato Botelho
11:47 AM Revision 7d6b8b9b: Merge pull request #1729 from phil-davis/widget-iform
Renato Botelho
11:32 AM Revision 763afdaf: Add semicolon
Fix delete Java Script to match valid HTML ID N0YB
11:31 AM Revision 0f383d78: XHTML Compliance
html id's not permitted to begin with a number.
html id's not permitted to contain '/'
add prefix (entry_) and replac...
N0YB
11:29 AM Revision aa676b75: Merge pull request #1719 from N0YB/XHTML_Compliance_Diagnostics_Tables
Renato Botelho
11:10 AM Revision 0828f970: Bump version to 2.2.4-DEVELOPMENT
Renato Botelho

06/24/2015

07:05 PM Feature #3933: Limiter burst doesn't have any effect
Target version is 2.3
https://redmine.pfsense.org/versions/16
http://snapshots.pfsense.org/
Shows 2.2.3 as l...
Web Dawg
06:54 PM Feature #3933: Limiter burst doesn't have any effect
Hi folks,
Any progress on this one? Is there any alpha version that might have this working for me to test .. Thanks!
Ahmed Kamal
05:03 PM Revision fc04a23e: Merge branch 'RELENG_2_2' of git.pfmechanics.com:pfsense/pfsense into RELENG_2_2
Chris Buechler
05:00 PM Revision 90ad3a76: Display any advanced DHCP server settings
when the page is first displayed.
This has annoyed me a few times and it annoyed me again just now. I had some settin...
Phil Davis

06/23/2015

10:24 PM Bug #3858: DynDNS errno 47: Address family not supported by protocol family
I put together a quick test on Linux (using pycurl) that basically does:... Jonathon Reinhart
09:54 PM Bug #3858: DynDNS errno 47: Address family not supported by protocol family
Chris Buechler wrote:
> that's what happens when you're dual stack, the URL has an AAAA, and it's updating a v4 IP.
...
Jonathon Reinhart
09:29 PM Revision 9cbb7fe4: It's time for 2.2.3-RELEASE
Renato Botelho
09:25 PM Revision 5b1844a6: Bump to 2.2.3-RELEASE
Chris Buechler
07:32 PM Revision 47b09af7: Add D1540-XG.
Matthew Smith
07:28 PM Revision 821c6ff7: Add D1540-XG.
Matthew Smith
06:36 PM Revision ba8c6e37: Introduce Netgate RCC-DFF to the list of known platforms
Renato Botelho
06:35 PM Revision 91bbf120: Introduce Netgate RCC-DFF to the list of known platforms
Renato Botelho
05:31 PM Revision 96072f52: rereadall is not enough here, restore reload call to make sure everything works. Ticket #4785
Renato Botelho
05:31 PM Revision 2f898d6a: rereadall is not enough here, restore reload call to make sure everything works. Ticket #4785
Renato Botelho
05:15 PM Revision 8961801d: Replace ipsec rereadsecrets + reload by single rereadall, that will re-read also cert changes. Ticket #4785
Renato Botelho
05:15 PM Revision 9edeadc5: Replace ipsec rereadsecrets + reload by single rereadall, that will re-read also cert changes. Ticket #4785
Renato Botelho
05:12 PM Revision a241d6b5: Instead of sending USR1, just call ipsec reload. And before it, call ipsec rereadsecrets to make sure new secretes are updated. It should fix #4785
Renato Botelho
05:12 PM Revision bc7748f7: Partially revert 019ee2bc8c, this workaround is not necessary. Real fix will be committed after this
Renato Botelho
05:12 PM Revision dbd43cc2: Instead of sending USR1, just call ipsec reload. And before it, call ipsec rereadsecrets to make sure new secretes are updated. It should fix #4785
Renato Botelho
05:11 PM Revision d30038e0: Partially revert 019ee2bc8c, this workaround is not necessary. Real fix will be committed after this
Renato Botelho
03:54 PM Bug #4785 (Resolved): IKEv2 w/PSK not matching where remote is FQDN
confirmed good. Chris Buechler
12:20 PM Bug #4785: IKEv2 w/PSK not matching where remote is FQDN
Applied in changeset commit:a241d6b53ac8d1aefe854d673ed5f41693ce9388. Renato Botelho
12:20 PM Bug #4785: IKEv2 w/PSK not matching where remote is FQDN
Applied in changeset commit:dbd43cc24d6c18f6bf279c4e52a7a01d2bdfb8c5. Renato Botelho
01:22 PM Revision 019ee2bc: Add a workaround for ticket #4785:
There was a regression on strongswan between 5.3.0 and 5.3.2 as reported
at [1]. To workaround this issue, add an ext...
Renato Botelho
12:59 PM Revision 29c9e140: Add a workaround for ticket #4785:
There was a regression on strongswan between 5.3.0 and 5.3.2 as reported
at [1]. To workaround this issue, add an ext...
Renato Botelho
10:53 AM Bug #4642: OpenVPN process status stopped... but its running
Updating:
Ok, 21 days passed, and there it goes... today I have discovered on the monitored nanobsd installs final...
Alejandro Olivan
07:28 AM Revision 9a3ec939: Standardize widget iform and submit names
The log and picture widgets were both using "iforma" and "submita".
Actually it did not break anything because it was...
Phil Davis
06:48 AM Revision c598160a: Fix var name typo in shaper.inc
Chris Buechler
06:45 AM Revision cfc6fd8d: Merge pull request #1728 from devnullity/patch-1
Chris Buechler
05:53 AM Revision 6538d33a: GW widget input form name-id needs to be unique
among all widget forms.
Traffic Graphs widget already uses the vanilla name "iform". Reusing that name causes Traffic...
Phil Davis
03:56 AM Bug #3736: No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
Well, this does not work for the console menu either. Plus, I don't think it's limited to static IPv6. It's broken fo... Kill Bill
02:22 AM Bug #3736 (New): No static IPv6 address for WAN interface in Dashboard for PPPoE+static IPv6
Chris Buechler
02:31 AM Revision 9a8a5e6a: Don't delete /var/tmp/, that was originally done to clear session data at boot, but no longer applicable as session data is no longer in /var/tmp/. Credit to 'aa' on opnsense forum.
Chris Buechler
02:27 AM Revision 5e1ff564: Don't delete /var/tmp/, that was originally done to clear session data at boot, but no longer applicable as session data is no longer in /var/tmp/. Credit to 'aa' on opnsense forum.
Chris Buechler
01:25 AM Feature #4787: Time restrictions on Users, for Captive Portal auth
you can use firewall rules with schedules to accomplish that in some cases. Otherwise you're best off using RADIUS au... Chris Buechler
12:39 AM Feature #4787 (Needs Patch): Time restrictions on Users, for Captive Portal auth
I'd like to let my kids use the net between certain hours, but deny them after bedtime.
Could the pfSense user man...
Criggie .
12:43 AM Revision d812e83e: Use $myid in ipsec.secrets. Ticket #4785
Conflicts:
etc/inc/vpn.inc
Chris Buechler
12:42 AM Revision fe96d725: Use $myid in ipsec.secrets. Ticket #4785
Chris Buechler

06/22/2015

11:03 PM Bug #4778 (Resolved): ADI memstick doesn't setup serial console correctly post-install
all good. Chris Buechler
05:33 PM Bug #4778 (Feedback): ADI memstick doesn't setup serial console correctly post-install
It was happening when wrong kernel was selected during installation. I've changed kernel order for ADI and Embedded i... Renato Botelho
09:49 PM Bug #4784 (Confirmed): IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
there is something wrong here, though it's not clear what. The issue is replicable with Jody's config, and a slightly... Chris Buechler
01:20 PM Bug #4784 (Closed): IPsec mobile fails with VPNC and "Network List" after 2.2.x upgrade
We usually use a wrapper client (Shimo) for vpnc that helps us with some route automation, but for purposes of simpli... Jody Rudolph
09:49 PM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
I think same as Grischa Zengel said!
We need an option to disable xn implementation
Giancarlos Cataldo
12:56 PM Bug #4345: Traffic Shaping doesn't work with Xen netfront driver
I'm installing the next server and need 8+ networks. Because xen can't handle so much NICs I have to use tagging.
...
Grischa Zengel
09:38 PM Bug #4786 (Duplicate): custom dyndns fails with errno 47: Address family not supported by protocol family
duplicate of #3858. that didn't change on upgrade, guessing maybe this is the first you've had IPv6. Changing your pr... Chris Buechler
08:16 PM Bug #4786 (Duplicate): custom dyndns fails with errno 47: Address family not supported by protocol family
I just updated from 2.2.1 to 2.2.2. I have Dynamic DNS enabled for my domain hosted at Google Domains, and DynDNS is... Jonathon Reinhart
09:36 PM Bug #3858 (Confirmed): DynDNS errno 47: Address family not supported by protocol family
that's what happens when you're dual stack, the URL has an AAAA, and it's updating a v4 IP. Chris Buechler
07:48 PM Bug #4729 (Not a Bug): OpenVPN Advanced config fails on double save
the semicolon separators are required, as it says in the notes field there. Some additional input validation there wo... Chris Buechler
07:41 PM Bug #4785 (Feedback): IKEv2 w/PSK not matching where remote is FQDN
should be fixed, need to double check every type of config to verify all still work. Chris Buechler
05:21 PM Bug #4785 (Resolved): IKEv2 w/PSK not matching where remote is FQDN
Where using IKEv2 with PSK on a site to site VPN, where the identifiers are IPs, and the remote is a FQDN, you end up... Chris Buechler
06:34 PM Revision b7316893: This is incomplete. Leaving for 2.3. Revert "Ticket #4683 merge in brainpool for DH parameters"
This reverts commit 7dc35024af3af1d644c25b002ca9f40f1d61c05b. Chris Buechler
04:56 PM Bug #4746: captive portal allowed hostnames not loaded into table at boot time
no change from last comment. filterdns is running with the correct instance ID for -y, logs that it's adding entries ... Chris Buechler
01:32 PM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Thanks for the heads up, Lars. We're short on time for 2.2.3, plus don't generally put features into maintenance rele... Chris Buechler
08:21 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Can see that you have only merged parts of the 1649 pull request. Things like IPsec phase 1 is missing AES GCM suppor... Lars Pedersen
01:23 PM Bug #4779 (Feedback): OPENVPN - Exiting due to fatal error
The "can't assign requested address" means something is already listening on port 10000. You have something else boun... Chris Buechler
01:18 PM Bug #4780 (Confirmed): max_input_vars limit reached with aliases having >1000 members
for aliases that big you're best off using URL Table aliases instead Chris Buechler
07:20 AM Revision be253f60: Add DNS host override descriptions
since we can sometimes provide a useful description from that config
data also.
Fill the $iplookup array with host or...
Phil Davis
12:49 AM Bug #3314 (Resolved): Traffic graph shows 2X the actual traffic on VLAN interfaces.
not seeing any scenario where this still happens. Chris Buechler
12:43 AM Feature #4783 (Resolved): Add description as a display option on Traffic Graph
The traffic graph can already display a choice of IP address, Hostname or FQDN in the table of top bandwidth hogs.
S...
Phillip Davis
12:39 AM Bug #4704 (Confirmed): IKEv2 to Cisco ASA won't bring up multiple P2 networks
splitting con entries will suffice here. this should be straight forward, quick, and low risk, but if there are compl... Chris Buechler
12:35 AM Feature #4782 (Resolved): Display monitor IP on Gateways widget
The RTT and Loss figures on the Gateways widget are for ping responses to the gateway monitor IP, which often is diff... Phillip Davis
12:29 AM Bug #4781 (Resolved): IPsec PSKs from user manager and vpn_ipsec_keys.php incorrect
fixed Chris Buechler
12:25 AM Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock"
Ermal suggested replicating with very low bpf buffers and high ARP traffic. I've had an arp-scan across one /16 and o... Chris Buechler

06/21/2015

11:49 PM Revision 5a147eaf: Fix var name typo in shaper.inc
Fix typo so get_bandwidthtype_scale can do more than default to "1". Ben Cook
10:13 PM Bug #4652 (Resolved): Captive Portal Idle-Timeout causes 2147483647 for acctsessiontime when no data transferred
works from what I can tell. Markus, if you can see any remaining issues here in 2.2.3, please follow up. Chris Buechler
10:10 PM Bug #4719: IKEv2 to Cisco ASA results in TS mismatch when initiation triggered by traffic
this is still replicable as described, but only with ASAs, and only as initiator when triggered by traffic. Manually ... Chris Buechler
09:37 PM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
something's changed in the OS X client since last trying this. I'll revisit for further testing. Chris Buechler
09:01 PM Revision 62102a8b: Specify $myid rather than %any here, otherwise user manager and mobile PSKs won't match. Ticket #4781
Conflicts:
etc/inc/vpn.inc
Chris Buechler
09:00 PM Revision 887093c3: Specify $myid rather than %any here, otherwise user manager and mobile PSKs won't match. Ticket #4781
Chris Buechler
04:06 PM Bug #4689: Panic/Crash "sbflush_internal: cc 4294967166 || mb 0 || mbcnt 0"
no known way to replicate this. Likely fixed with the patch that's been merged but will leave for feedback. Chris Buechler
04:00 PM Bug #4781 (Feedback): IPsec PSKs from user manager and vpn_ipsec_keys.php incorrect
confirmed working on one system Chris Buechler
03:56 PM Bug #4781 (Resolved): IPsec PSKs from user manager and vpn_ipsec_keys.php incorrect
PSKs defined in the user manager and vpn_ipsec_keys.php result in: ... Chris Buechler
01:19 PM Bug #4780: max_input_vars limit reached with aliases having >1000 members
pfSense version 2.2.2 Ravine Pick
01:18 PM Bug #4780 (Resolved): max_input_vars limit reached with aliases having >1000 members
The limit has been reach for long alias lists used in firewall configuration.
firewall_aliases_edit.php
Warning...
Ravine Pick
10:33 AM Bug #4779 (Not a Bug): OPENVPN - Exiting due to fatal error
Since I'm using pfSense 2.2.2 I get the following error, every time the switch is turned off - the device is disconne... Jan-Hendrik Meyer

06/20/2015

08:35 PM Bug #4720 (Resolved): pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
this is fixed, opened #4778 for aforementioned remaining issue. Chris Buechler
08:35 PM Bug #4778 (Resolved): ADI memstick doesn't setup serial console correctly post-install
The serial console on the ADI memstick image isn't setup correctly post-install. Chris Buechler
08:22 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Was just wondering if it's specific to your file, or any similar file. If the one you attached suffices to replicate,... Chris Buechler
08:04 PM Bug #4705 (Resolved): Language selection is not functional
fixed Chris Buechler
07:40 PM Bug #4702: kernel panic with AES-NI
this isn't easily replicable, so not sure whether it's still an issue. Will leave for feedback Chris Buechler
07:38 PM Bug #4310: Limiters + HA results in hangs on secondary
Tried after changing both hosts to use unicast pfsync, which had no impact. It seems to alternate between hanging the... Chris Buechler

06/19/2015

10:31 PM Bug #4777 (Closed): tcpdump causes kernel panic when deleting underlying interface
that triggers a kernel panic in FreeBSD 10.1. Same wifi card in an 11-CURRENT (as of a couple days ago) box, tcpdump ... Chris Buechler
09:37 PM Bug #4777: tcpdump causes kernel panic when deleting underlying interface
pfSense just prompted me, then automatically uploaded a crashreport (approx 2015-Jun-19 21:40 CDT [GMT-5]). Of cours... Adam Thompson
09:28 PM Bug #4777 (Closed): tcpdump causes kernel panic when deleting underlying interface
Cloned ath0 interface.
Ran tcpdump on console against ath0_wlan1.
Deleted ath0_wlan1 from GUI (Interfaces->Wireless...
Adam Thompson
09:34 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
I can't share the IP addresses because they are Tor bridges, which must be kept secret in order to be useful. Does th... badon _
08:29 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
the upgrade issue you noted is fixed for 2.2.3, release coming next week. Upgrading to the latest snapshot from snaps... Chris Buechler
06:04 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
I tested an auto-upgrade again before doing the test you suggested. The auto-upgrade sort of failed somehow because t... badon _
06:33 PM Revision 10a1c51d: Obsolete pt_BR.ISO-88591 in favor of UTF-8
Renato Botelho
06:31 PM Revision a3918e59: Move pt_BR translation from ISO to UTF-8
Renato Botelho
06:29 PM Revision 6b42b02c: Move pt_BR directory, it's moving from ISO to UTF-8
Renato Botelho
06:15 PM Revision 3d0391f1: Display monitor IP on Gateways widget
This change adds a setting for the Gateways dashboard widget so the user
can choose to display the Gateway IP, Monito...
Phil Davis
04:28 PM Feature #4599 (Closed): Traffic shaping - what is in each queue?
Chris Buechler
04:26 PM Bug #4621 (Resolved): OpenVPN server does not bind to IPv6 CARP interface when configured from webgui.
Chris Buechler
04:19 PM Bug #4656 (Not a Bug): cannot connect IPsec VPN via dialup
that's due to a configuration mismatch of some sort. Please post to the forum or mailing list for help troubleshooting Chris Buechler
04:16 PM Bug #4695 (Not a Bug): TAP (OpenVPN) Traffic Blocked
replied back on your forum thread. this works in general, we can troubleshoot further on forum. Chris Buechler
03:35 PM Revision 3378289a: Ticket #4746 Correctly set global variables to be used by hostnames cod epaths
Ermal Luçi
03:33 PM Revision fabb4b03: Ticket #4746 Correctly set global variables to be used by hostnames cod epaths
Ermal Luçi
02:38 PM Bug #4720: pfSense ADI-2.2.2-RELEASE issues with backup/restore config /boot/config.local changed
this issue is fixed. there is a different problem in that it doesn't enable the serial console properly after clean i... Chris Buechler
02:08 PM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
Ok that's a different circumstance from the other I mentioned (which is the same as what Bipin noted). That's never a... Chris Buechler
04:06 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
It's a virtual machine on ESX, using E1000 nics, the NIC isn't locked however as the web interface on the ADSL modem ... Technical Support Brendata (UK) Ltd
04:02 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
for me alix via chipset and 2 full install machines with realtek chipset have this issue Bipin Chandra
01:39 PM Bug #4705 (Feedback): Language selection is not functional
I moved it to UTF-8, it's working now.
For reference commit:6b42b02cc0 commit:a3918e5999 and commit:10a1c51d87
Renato Botelho
01:19 PM Bug #4675 (Confirmed): DHCPv6 DDNS doesn't work properly
Thanks Robert, we'll get that reviewed, tested and merged soon for 2.3. Chris Buechler
12:53 PM Bug #4551: DNS forwarder/resolver - some consistency needed in the WebGUI
The DHCP/DHCPv6 stuff was meanwhile fixed, apparently. System - General Setup and the Captive Portal still remain. Kill Bill
12:37 PM Feature #4260 (Closed): Add ECP DH key groups support
closing in favor of #4683 Chris Buechler
11:51 AM Revision 320ed23c: Merge pull request #1724 from phil-davis/patch-3
Renato Botelho
11:08 AM Feature #4776 (New): Add 802.1x dynamic vlan support
Hi,
as I was creating a WLAN for our company based on pfsense APs, I run into the problem, that pfsense has no opt...
Cullen Trey
10:47 AM Revision 7dc35024: Ticket #4683 merge in brainpool for DH parameters
Ermal Luçi
05:44 AM Feature #4683: Support for elliptic curve for IPsec on webconfigurator
Merged. Ermal Luçi
05:36 AM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
I thought this was due that now unity plugin is not anymore loaded by default. Ermal Luçi
12:08 AM Bug #4418 (Feedback): IPsec mobile clients - bogus "p" appended to search domain
this doesn't appear to be an issue anymore with 2.2.3, though I haven't narrowed down exactly where that changed yet.... Chris Buechler
12:09 AM Bug #4772 (Resolved): L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
works Chris Buechler

06/18/2015

08:50 PM Bug #4775 (Resolved): Add frag limit control to the GUI
works Chris Buechler
09:33 AM Bug #4775 (Feedback): Add frag limit control to the GUI
Jim Pingle
08:26 AM Bug #4775 (Resolved): Add frag limit control to the GUI
By default pf uses a frag limit of 5000. Several customers and users have reported hitting that limit on 2.2+ resulti... Jim Pingle
06:28 PM Bug #4774 (Resolved): hostid missing +x
fixed Chris Buechler
12:26 AM Bug #4774 (Resolved): hostid missing +x
this should be fixed already. adding this to remember to test on new snapshot.
/etc/rc.d/hostid was missing +x, w...
Chris Buechler
06:25 PM Feature #4614 (Resolved): EAP-Radius support for accounting on strongswan
Chris Buechler
05:43 PM Bug #4679 (Resolved): IPsec dashboard widget wrongly shows "REKEYED" SAs as "down"
the REKEYED entries no longer exist since that separate bug was fixed, which leaves this fine. Chris Buechler
05:38 PM Bug #4705 (Confirmed): Language selection is not functional
Turkish works now, though selecting PT-br still leaves you with English. Chris Buechler
04:15 PM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
can't replicate that here either, and that code hasn't changed in quite some time. will leave for feedback for now. Chris Buechler
07:29 AM Bug #4773 (Feedback): Configuration backup - "Do not backup RRD data" is broken
The current code does unset and the code to unset has been in place for ages (3+ years). See source:"usr/local/www/di... Jim Pingle
05:49 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
Hmmm - I guess on restoring from a backup that has RRD data, the system should remove existing RRD data files, build ... Phillip Davis
03:04 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
Well, the problem apparently is this:... Kill Bill
02:48 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
2.2.3-DEVELOPMENT (amd64)
built on Sun Jun 14 19:59:54 CDT 2015
FreeBSD 10.1-RELEASE-p12
With the "do not backup...
Lars Pedersen
02:24 AM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
This is a full install. With the box, I get ~4 MB with huge <rrddata>; without the box, it's ~8 MB with two <rrddata>... Kill Bill
04:01 PM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Guessing it's because we enable certificate validation by default in 2.2.x there, and the default self-signed cert wi... Chris Buechler
02:29 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Perhaps you could post the results of this:... Kill Bill
01:54 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
Let me point out that the "URL Table (IPs)" version of this test does not produce any error messages. Therefore, if i... badon _
01:40 AM Bug #4766: "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
It's a list of IP addresses, one IP on each line. I just tested it in a new install of 2.1.5, and it works fine there... badon _
02:29 PM Bug #4686 (Resolved): Rekeyed SAs are not properly removed
this is correct now in every circumstance I could previously replicate problems. Chris Buechler
01:33 PM Revision 55a1435e: Add a GUI field to increase the pf frag entries limit. Fixes ticket #4775
Jim Pingle
01:30 PM Revision 9e8ce1e2: Add a GUI field to increase the pf frag entries limit. Fixes ticket #4775
Jim Pingle
12:34 PM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
not the modem, what hardware are you running pfSense on, specifically what NICs but other details might help. Chris Buechler
06:54 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
The actual hardware is a BT Voyager 190 Ethernet ADSL modem with the unlocked firmware on it.
I assume that the is...
Technical Support Brendata (UK) Ltd
01:39 AM Bug #4760: PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
https://forum.pfsense.org/index.php?topic=41061.0
long thread but to me it seems the nic drivers is the culprit, t...
Bipin Chandra
12:06 PM Bug #4751 (Resolved): kernel panic after disabling captive portal when idle timeout is in use
fixed Chris Buechler
10:56 AM Bug #4364: cannot change or set keymap during and after install
Hello.
Just installed 2.2.2 x64 and the problema is still here.
Best regards.
Manuel Borges
05:26 AM Revision 41e9efe6: chmod +x hostid
Chris Buechler
05:26 AM Revision f6a4fe06: chmod +x hostid
Chris Buechler
12:33 AM Bug #4730 (Resolved): Firewall Log Dynamic View missing Block/Allowed Reason
fixed, thanks! Chris Buechler

06/17/2015

11:31 PM Bug #3815: Gateway monitoring broken
Tobias: if you have a 2.2.2 (or newer) config that'll replicate, I'd definitely like to check it out. Email to cmb at... Chris Buechler
10:26 PM Bug #4760 (Feedback): PPPoE loses connection to modem, clicking connect does not reconnect but rebooting pfSense does
what hardware?
the only issue along those lines I can recall in any version was some modems combined with some ol...
Chris Buechler
10:24 PM Bug #4766 (Feedback): "URL Table (IPs)" and "URL (IPs)" do not work when text file is hosted on a fresh install of pfSense
what's in some_file.txt? I'm guessing nothing, you're trying to fetch a file that doesn't exist, given it happens aft... Chris Buechler
10:11 PM Bug #4773: Configuration backup - "Do not backup RRD data" is broken
On nanoBSD 32-bit running snap from Wed Jun 17 18:54:23 I can't replicate this. With the box checked I get an ordinar... Phillip Davis
02:32 PM Bug #4773 (Closed): Configuration backup - "Do not backup RRD data" is broken
This worked just fine before the latest batch of commits (i.e., a week ago, or even less).
- I have the "Do not ba...
Kill Bill
09:21 PM Bug #4746 (Confirmed): captive portal allowed hostnames not loaded into table at boot time
no change here. Logs show during boot: ... Chris Buechler
01:30 AM Bug #4746: captive portal allowed hostnames not loaded into table at boot time
this change could also be what completely broke CP (see #4751) Chris Buechler
07:33 PM Revision e932c350: Blacklist invalid "from" sources since they can be picked up accidentally and cause rule errors. Fixes #4772
Jim Pingle
07:32 PM Revision 2e0397e0: Blacklist invalid "from" sources since they can be picked up accidentally and cause rule errors. Fixes #4772
Jim Pingle
04:32 PM Bug #4765: NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
it works fine. keep the discussion of support issues on the forum please. I replied back there again. Chris Buechler
01:43 PM Bug #4765: NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
I don't understand the meaning of "looking for something that won't exist" considering that the rest of your comment ... Granger Godbold
12:52 PM Bug #4765 (Not a Bug): NAT Reflection (Pure NAT) rules not setup for traffic originating from same subnet as final destination
replied back in your forum thread, you're looking for something that won't exist, but where the "Enable automatic out... Chris Buechler
03:35 PM Bug #4770: Packet Filter Reject IPSEC packets
Just what algorithms and what version of ipsec you are using.
Preferably send me /var/etc/ipsec/ipsec.conf and /tm...
Ermal Luçi
03:30 PM Bug #4770: Packet Filter Reject IPSEC packets
How much detail do you want? I'd rather not leak all our info onto the net. Nei Ka
03:24 PM Bug #4770: Packet Filter Reject IPSEC packets
Can you also describe your tunnel configuration here? Ermal Luçi
11:59 AM Bug #4770: Packet Filter Reject IPSEC packets
... Nei Ka
11:55 AM Bug #4770 (Feedback): Packet Filter Reject IPSEC packets
what's the rule that's blocking it? click the red X.
doubt this is a bug, probably something like Snort enabled w...
Chris Buechler
11:32 AM Bug #4770 (Resolved): Packet Filter Reject IPSEC packets
Periodically the firewall starts firewalling traffic coming through one or more IPSEC tunnels. Doing "Filter Reload" ... Nei Ka
02:40 PM Bug #4772: L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
Applied in changeset commit:e932c35017d0c5e35957e01c90dab57a0519f588. Jim Pingle
02:40 PM Bug #4772 (Feedback): L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
Applied in changeset commit:2e0397e05b6168dfcfbd04c9f3629a988744a8b2. Jim Pingle
02:28 PM Bug #4772 (Resolved): L2TP + "Enable automatic outbound NAT for Reflection" + L2TP subnet overlapping + Port forwards can lead to a broken ruleset
If the L2TP subnet overlaps a subnet that contains a port forward target, and automatic outbound NAT for reflection i... Jim Pingle
01:37 PM Bug #4310 (Confirmed): Limiters + HA results in hangs on secondary
no change, as long as you have some traffic passing through a limiter, the secondary hangs within ~1-4 hours. Chris Buechler
01:05 PM Bug #4762: Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
I'll see if I can reproduce this, but the diag_tables showed all IP addresses (I should add that I have applied the p... Technical Support Brendata (UK) Ltd
11:53 AM Bug #4762 (Not a Bug): Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
diag_tables shows what is in the table (""in memory" alias") at the time the page is loaded. filterdns keeps that upd... Chris Buechler
02:33 AM Bug #4762: Check status of items on this page for aliases shows the immediate resolution not the values held in the cache
Yes, sorry, diag_tables.php.
This showed all entries as being correct, however, when looking at the resolver logs ...
Technical Support Brendata (UK) Ltd
11:41 AM Bug #4771 (Duplicate): DHCP Server does not update DNS Forwarder
When the DHCP server issues an IP to a host that provides a name, that name cannot immediately be resolved by the DNS... Nei Ka
10:47 AM Feature #4769: IPv6 support in the Traffic Shaper Wizard
the created rules largely aren't IPv4/IPv6-specific, and will work for both. Chris Buechler
09:30 AM Feature #4769 (Resolved): IPv6 support in the Traffic Shaper Wizard
It would be really nice if Traffic Shaping Wizard could be set to also create IPv6 rules. Ian Grody
08:10 AM Bug #4751 (Feedback): kernel panic after disabling captive portal when idle timeout is in use
Ermal Luçi
08:10 AM Bug #4751: kernel panic after disabling captive portal when idle timeout is in use
Yep this commit broke it by showing that there might have been other issues that now are handled properly.
Next sn...
Ermal Luçi
01:20 AM Bug #4751 (Confirmed): kernel panic after disabling captive portal when idle timeout is in use
This patch (or something else in about the same timeframe) completely broke CP in 2.2.3. No contexts are created.
...
Chris Buechler
03:23 AM Bug #4642: OpenVPN process status stopped... but its running
EDIT:
15 days passed by since I installed watchdog and set it to keep ntp up (ntp crashed all the time).
Since th...
Alejandro Olivan
01:42 AM Bug #4596 (Confirmed): NAT 1:1 vs VIP, limiters works on LAN, but on WAN breaks NAT
no change, but we'll leave as-is for 2.2.3. Limiters in general are better in 2.2.3 than earlier 2.2.*. Chris Buechler
01:26 AM Bug #4653 (Resolved): mtree dies in post_upgrade_command during upgrade from 8.x and earlier
confirmed upgrades on 1.2.3, 2.0.3, 2.1.5, 2.2.2, including both 32 and 64 bit for all 2.x. All fine. Chris Buechler
12:23 AM Bug #4107 (Resolved): Firmware backup restoration via WebUI does not reboot firewall at the end, no logs, no messages
fixed Chris Buechler
12:21 AM Bug #4523 (Resolved): master.passwd/group file corruption may occur after kernel panic or unclean shut down
fixed. We'll again verify as part of the release test matrix on each install type. Chris Buechler
 

Also available in: Atom