Project

General

Profile

Activity

From 06/26/2016 to 07/25/2016

07/25/2016

11:05 PM Bug #6640 (Feedback): DHCPv6 Server Time Format Change Reversed
merged, thanks Phil Chris Buechler
10:46 PM Bug #6640: DHCPv6 Server Time Format Change Reversed
That looks like a bug that has been around for a while - it is not reversed, it is doubled.
If you have the checkbox...
Phillip Davis
09:14 PM Bug #6640 (Resolved): DHCPv6 Server Time Format Change Reversed
The DHCPv6 Server Time Format Change setting "Change DHCPv6 display lease time from UTC to local time" is reversed. W... Daryl Morse
10:43 PM Feature #6641 (Closed): Please add DHCPv4 Server Time Format Change Setting
it's already there, has been for a long time. Chris Buechler
09:16 PM Feature #6641 (Closed): Please add DHCPv4 Server Time Format Change Setting
The DHCPv6 server has a Time Format Change setting to allow display of leases in local time or UTC. Please add a simi... Daryl Morse
08:26 PM Bug #5993: dhcp6c not started until an RA received
Chris Buechler wrote:
> merged this for 2.4 as it needs more baking time in snapshots than we're going to have for 2...
Daryl Morse
01:38 PM Feature #6639 (Resolved): Utilize nextboot to control the behavior of the next firewall reboot
Now that we include nextboot, we can use it to control the properties of the next firewall boot sequence.
Two idea...
Jim Pingle
10:24 AM pfSense Packages Feature #5434: Let's Encrypt pfSense support
Sory, but now it's working via some simple manual steps...
https://thedevops.party/lets-encrypt-ssl-certificate-on...
Ernesto Victor Villarreal
01:44 AM Bug #6637: pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
Chris Buechler wrote:
> this seems like it's probably the issue here?
> https://bugs.freebsd.org/bugzilla/show_bug...
Remko Lodder

07/24/2016

06:16 PM pfSense Packages Feature #6196 (Closed): APU2 Thermal sensor
patch is already upstream (by us, not OPNsense).
Jim Thompson
01:19 AM pfSense Packages Feature #6196: APU2 Thermal sensor
This has already been committed upstream:
https://github.com/freebsd/freebsd/commit/cf2857955cc43bf478bbb4716641d1...
Jose Luis Duran
05:26 PM Bug #6422: PHP Fatal error: Call to undefined function gettext() in /etc/inc/rrd.inc on line 60
I've been getting this consistently on two new installs that are both dual-WAN load balanced (Gateway Groups).
Mos...
Jeffrey Posluns

07/23/2016

05:18 PM Bug #6505: dpinger - socket name too large
I've pushed a hotfix for this commit. Somehow i checked the wrong variable ... Please check
https://github.com/pfs...
Daniel Hoffend
03:44 PM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
IMO this function should be combined with the ipsec tunnel reload. This way you can combine point2point ipsec connect... Daniel Hoffend
09:26 AM Feature #3718: radvd - enhancement proposal: ability to advertise routes and some fixes - patches attached
Hi,
I have upgraded my pfsense box to 2.3.1 finally, since I have seen that there were major changes in the web in...
Marc Posch

07/22/2016

11:27 PM Bug #6635 (Not a Bug): Dyndns not updating for no-ip
It works fine as-is. Their old API apparently accepts either hostname or h[] there, since it worked before, and it st... Chris Buechler
12:24 PM Bug #6635: Dyndns not updating for no-ip

My updates on several boxes are working fine. 2.3.1 p5 (I use noip for my primary server dns also so have the ...
Chris Palmer
02:56 AM Bug #6635: Dyndns not updating for no-ip
Could have sworn I'd used my no-ip account for testing since that commit. Though my account isn't working either way ... Chris Buechler
11:23 PM Todo #6638 (Resolved): Update no-ip DDNS to new API
no-ip's API has changed (sometime in 2011 apparently), though they still accept updates using the old URL, it should ... Chris Buechler
03:20 PM Bug #6637: pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
this seems like it's probably the issue here?
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207598
we haven'...
Chris Buechler
03:25 AM Bug #6637: pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
I can narrow this down to the 'block out' rule. (And I believe there is no configurable option, perhaps except on the... Remko Lodder
03:19 AM Bug #6637 (Resolved): pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
Dear people,
I am setting up a host where I have my AP's connecting to the pfSense box over IPSEC.
I use the "tra...
Remko Lodder
09:25 AM Bug #6433: "TFTP Server" field on DHCP server page does not allow hyphen character.

New ticket now open.
See TICKET #6634
Shane Poteet
03:03 AM Bug #6634 (Confirmed): DHCP Server "TFTP Server" field should allow URLs
different issue, we'll keep this here. Chris Buechler
02:47 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Chris Buechler wrote:
> I hit this issue with a customer last week. Worked fine after disabling scrub. I have pcaps ...
Remko Lodder

07/21/2016

09:50 PM pfSense Packages Bug #6636 (Resolved): Squid Reverse Proxy with Additional IP and compatibility="Intermediate" writes bad squid.conf
I use a CARP config, actual IP on this box is x.x.x.135, Virtual IP x.x.x.133. When compatibility="Intermediate" the... Marc Skarshinski
08:38 PM Bug #6635: Dyndns not updating for no-ip
It was "&hostname=" for many years up until 30 Jan 2016, when this commit changed it for some reason:
https://github...
Phillip Davis
07:51 PM Bug #6635 (Not a Bug): Dyndns not updating for no-ip
There's a typo on line 431 of dyndns.class where '&h[]=' should be '&hostname='. As is, it doesn't update and logs a... Terry T
02:42 PM Bug #6572: Config sync hangs php-fpm on secondary
Hi Chris,
I have the same problem. I do 1-2 config changes and everything works just fine. If I do a couple more I...
Bogdan Cornea
02:04 PM Bug #6634 (Resolved): DHCP Server "TFTP Server" field should allow URLs
Please reopen bug #6433. Not familiar with system here or I would try.
The filter on the web interface is not allo...
Shane Poteet
01:55 PM Bug #6433: "TFTP Server" field on DHCP server page does not allow hyphen character.
This still does not have the necessary functionality as it did on 2.2.x as of 2.3.1-5. I need to be able to populate ... Shane Poteet
07:07 AM Bug #6631: vesa_configure error on boot
In that case we'll get the change automatically when we switch to a FreeBSD 11 base for pfSense 2.4, which is only a ... Jim Pingle
02:25 AM Bug #6631: vesa_configure error on boot
I've verified that it's already fixed. Not that the bug still persists. This means that the pfSense kernel should be ... Thijs Cramer
03:56 AM Bug #6558: Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
Chris Buechler wrote:
> No, it's not a bug in our code and doesn't affect any of the hardware we sell or have sold, ...
Atlante Informatica

07/20/2016

07:59 PM Bug #6633 (Feedback): redirect-gateway duplicated in client specific overrides
fix pushed Chris Buechler
07:58 PM Bug #6633 (Resolved): redirect-gateway duplicated in client specific overrides
as reported here.
https://forum.pfsense.org/index.php?topic=115429.0
Chris Buechler
07:55 PM pfSense Packages Bug #6632 (Confirmed): siproxd hosts_allow_reg should be configurable
if you open siproxd on WAN in firewall rules, you get what you're asking for security-wise. No shortage of potential ... Chris Buechler
05:09 PM pfSense Packages Bug #6632 (Resolved): siproxd hosts_allow_reg should be configurable
siproxd is providing a configuration option "hosts_allow_reg" which
implements a positive access control list for ho...
Robert Jordan
02:48 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
this is from the use of dummynet in pf, which doesn't exist in stock FreeBSD. And the implementation apparently leave... Chris Buechler
02:23 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Chris Buechler wrote:
> There isn't one because the code/feature in question doesn't exist there.
Now I'm confuse...
→ luckman212
01:55 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Andrew Maslin wrote:
> Can someone share the FreeBSD bug # so we can track the progress of the root of the issue? L...
Chris Buechler
11:29 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Can someone share the FreeBSD bug # so we can track the progress of the root of the issue? Like Luke, I would like t... Andrew Maslin
06:48 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Have you guys tried using a queue inside the limiter instead of the limiter itself? It could make a difference since ... Jose Duarte
02:47 PM Bug #6558: Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
No, it's not a bug in our code and doesn't affect any of the hardware we sell or have sold, so not something we'll ad... Chris Buechler
06:15 AM Bug #6558: Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
Atlante Informatica wrote:
> Chris Buechler wrote:
> > subject isn't true in general, 82574L in the FW-7541 correc...
Atlante Informatica
01:56 PM Bug #6629: Can't update to "update" update (e.g. 2.3.1_5)
which is correct, guessing it's no longer showing as described? As that output would give you 2.3.1_5 as an update av... Chris Buechler
08:13 AM Bug #6629: Can't update to "update" update (e.g. 2.3.1_5)
Chris Buechler wrote:
> not replicable. Those two pages use the same function to obtain their data, so no apparent m...
Jonathon Reinhart
01:54 PM Bug #6631 (Closed): vesa_configure error on boot
The change that's in reference to was only in 11, what you're seeing there isn't the same thing. Not a bug in our cod... Chris Buechler
01:03 PM Bug #6631 (Closed): vesa_configure error on boot
I have the same issue as this FreeBSD Mailing List thread: http://markmail.org/message/aoq6ub636ainxcxe#query:+page:1... Thijs Cramer
10:44 AM pfSense Packages Todo #6443 (Resolved): Add ntopng package back into pfSense 2.3.x
ntopng will be in the pfSense 2.3.2 release. New tickets should be opened if there are issues with the package upon r... Jared Dillard

07/19/2016

08:51 PM Bug #5993: dhcp6c not started until an RA received
Chris Buechler wrote:
> merged this for 2.4 as it needs more baking time in snapshots than we're going to have for 2...
Daryl Morse
08:12 PM Bug #6629: Can't update to "update" update (e.g. 2.3.1_5)
I observed the same thing about a week ago. Performing an update from the console resolved the issue. Anonymous
07:27 PM Bug #6629 (Feedback): Can't update to "update" update (e.g. 2.3.1_5)
not replicable. Those two pages use the same function to obtain their data, so no apparent means for one to show an u... Chris Buechler
05:31 PM Bug #6629 (Resolved): Can't update to "update" update (e.g. 2.3.1_5)
It appears that there is an update available, but when I try to install it, pfSense says it's up-to-date.
I just i...
Jonathon Reinhart
06:00 PM Bug #6630 (Assigned): Set Defaults for Graphs - Traffic/WAN + Packets/WAN doesn't work
Jared Dillard
05:39 PM Bug #6630 (Resolved): Set Defaults for Graphs - Traffic/WAN + Packets/WAN doesn't work
Tested on two installations.
2.3.2-DEVELOPMENT (amd64)
built on Mon Jul 18 13:42:01 CDT 2016
FreeBSD 10.3-RELE...
Jordan Heinz
03:55 PM Bug #6628 (Resolved): extensions.ini can end up missing required items
In some currently-unknown edge case, extensions.ini can end up missing lines, breaking things.
One example post-2...
Chris Buechler
03:51 PM Bug #6578: Filter reload hangs with IPsec hostnames that don't resolve configured
This gets very ugly in circumstances where DNS servers aren't reachable at all. resolve_retry takes extremely long in... Chris Buechler
07:05 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Now that the target version bumped to 2.4 (FREEBSD-11) can anyone at least say whether the bug has been fixed in Free... → luckman212
04:27 AM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Confirmed that it works with IKEv2 PSK mobile client using:
ike = aes256gcm128-sha512-ecp512bp!
esp = aes256gcm...
Lars Pedersen
02:11 AM Bug #6625: firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Chris Buechler wrote:
> Hi Remko,
> This seems like a duplicate of #1136, is the VPN in this case reachable via a s...
Remko Lodder
12:25 AM Bug #6625 (Feedback): firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
Hi Remko,
This seems like a duplicate of #1136, is the VPN in this case reachable via a static route?
Chris Buechler
12:50 AM Bug #6437 (Resolved): CBQ queues are not displaying options for bandwidth or borrowing
works, thanks Steve Chris Buechler

07/18/2016

07:44 PM pfSense Packages Bug #6571: NUT service can not start sometimes after boot when SNMP UPS interface is down
The new NUT package allows for a nut supported way to retry the startup of the driver. Denny Page
03:52 PM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Jose Luis Duran wrote:
> Is this going to be backported?
>
> As this was a breaking change from 2.2 to 2.3 (not a...
Renato Botelho
03:35 PM Bug #5990 (Resolved): AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
fixed
Nothing to back port it to, 2.3.2 is the next release.
Chris Buechler
03:16 PM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Is this going to be backported?
As this was a breaking change from 2.2 to 2.3 (not appearing in the Change log).
Jose Luis Duran
02:59 PM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Lars Pedersen wrote:
> Chris Buechler wrote:
> > fix pushed
>
> Looks good. Will verify it when the next snapsho...
Renato Botelho
03:46 AM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Chris Buechler wrote:
> fix pushed
Looks good. Will verify it when the next snapshot is being build.
Lars Pedersen
11:45 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
And now I've had gpsmon SIGSEGV on me. It doesn't happen often, but it has happened from time to time.
gpsd itself...
Bruce Simpson
09:28 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I think there may also be (benign) bugs in the gpsmon monitor for UBX in gpsd.
I just swapped out a car antenna (S...
Bruce Simpson
10:20 AM Bug #6437: CBQ queues are not displaying options for bandwidth or borrowing
Applied in changeset commit:2e2ffafc35f73282f0a40132de4949cae2dbf4bf. Anonymous
10:13 AM Bug #6437: CBQ queues are not displaying options for bandwidth or borrowing
Form section containing bandwidth and borrow was not being added to the composed form. Anonymous
10:10 AM Bug #6437 (Feedback): CBQ queues are not displaying options for bandwidth or borrowing
Applied in changeset commit:7bba13e8d53adfe4beb03c8444e60848ae6e25e9. Anonymous
09:15 AM Bug #1629: invalid state table entries after WAN IP change
I posted "over on the forum":https://forum.pfsense.org/index.php?topic=108895.msg639527#msg639527 but I am not sure w... → luckman212
08:22 AM Bug #6627 (New): floating tab match rules ignore quick action so should be removed
i noticed since queue rules in floating tab was removed and just match in list or maybe queue renamed to match, the q... Bipin Chandra
07:51 AM Feature #6626 (Closed): Support for IPv6 firewall entries with dynamic delegated prefix and static host address
When using an ISP with dynamic prefix delegation, the prefix may change at any time, resulting in a change of the IP ... Anonymous
06:44 AM Bug #6625 (Duplicate): firewall forwards all traffic through wan interface, via default gateway, even if alternative route had been installed
We have setup a new pfSense box that will route our VPN traffic between endpoints.
That goes out on our WAN interfac...
Remko Lodder
06:02 AM Bug #6487: PfSense crashes during boot at configuring LAGG interfacess
Possibly related:
* https://forum.pfsense.org/index.php?topic=112042.msg623929#msg623929
* https://forum.pfsense.or...
Kilian H
12:24 AM Bug #4268 (Closed): changes in strongswan config don't apply to SAD or SPD
when this started, it was a much bigger issue. The worst of it was fixed, but the remaining part with the SAD is stil... Chris Buechler
12:22 AM Bug #6624 (Confirmed): changes in IPsec config should down the connection
The fact that strongswan doesn't take down an established connection after changing the config has lead to a number o... Chris Buechler

07/17/2016

11:19 PM Bug #5990 (Feedback): AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
fix pushed Chris Buechler
09:28 PM Bug #6622 (Resolved): DHCP Server: Dynamic DNS required fields are ambiguous
Thanks, committed clarification to description. Chris Buechler
01:10 PM Bug #6622 (Resolved): DHCP Server: Dynamic DNS required fields are ambiguous
This is a screenshot of the current DHCP Server's advanced Dynamic DNS options, as of 2.3.1-p5:
!http://i.imgur.co...
Thomas Ward
09:21 PM Feature #6623 (Resolved): Cloudflare DDNS IPv6 support
merged to master from PR 3061.
https://github.com/pfsense/pfsense/pull/3061
Chris Buechler
09:16 PM Bug #5993 (Feedback): dhcp6c not started until an RA received
merged this for 2.4 as it needs more baking time in snapshots than we're going to have for 2.3.2. Chris Buechler
09:10 PM Bug #6355 (Resolved): DHCP relay listens for dhcp requests on the upstream interface.
works Chris Buechler
09:00 PM Bug #6589 (Resolved): dhcpd.leases missing hostnames in some cases
works Chris Buechler
08:37 PM Bug #6619 (Not a Bug): NAT - Outbound - Edit/Add: Can't enter alias in source/destination network field
the stable version of Opera works fine. They broke something in the development release, report it there. Chris Buechler
10:16 AM Bug #6619: NAT - Outbound - Edit/Add: Can't enter alias in source/destination network field
This happens in Opera 40. In Edge everything works fine. Dmitriy K
09:57 AM Bug #6619: NAT - Outbound - Edit/Add: Can't enter alias in source/destination network field
The same "bug" goes for Firewall rule Add/Edit page: There is no way to use an alias.
Looks like a certain commit...
Dmitriy K
09:38 AM Bug #6619 (Not a Bug): NAT - Outbound - Edit/Add: Can't enter alias in source/destination network field
Mayday mayday: There is no way to use network(s) alias in network field on the Outbound NAT Add/Edit page.
Tested...
Dmitriy K
08:32 PM Bug #6617 (Resolved): "UNKNOWN" links in package manager
fixed Chris Buechler
01:11 PM Feature #6621: Permit DHCP Server Dynamic DNS server key algorithm type selection and use
Related bug report on the ambiguity of the algorithm currently needed for the DNS secret key: #6622 (https://redmine.... Thomas Ward
01:10 PM Feature #6621 (Resolved): Permit DHCP Server Dynamic DNS server key algorithm type selection and use
Under the DHCP Server page, you are able to do advanced configuration of Dynamic DNS with an internal nameserver (not... Thomas Ward
10:01 AM Feature #6620 (Resolved): CoDel, FQ-CoDel, PIE and FQ-PIE AQMs
Patches for new AQMs CoDel, FQ-CoDel, PIE and FQ-PIE were submitted to CURRENT a few months ago and are now in 10-STA... qubit nano
09:37 AM Bug #6437: CBQ queues are not displaying options for bandwidth or borrowing
well i hit into this today Bipin Chandra

07/16/2016

05:28 PM Feature #6618 (Duplicate): Alert when reboot required for updates
duplicate of #6411 Chris Buechler
04:41 PM Feature #6618 (Duplicate): Alert when reboot required for updates
Hi,
When new updates, the user is not notified if the reboot is required to complete the update.
Why not add a ...
Frederic Lietart
11:11 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
An apparently identical uBlox5 MiniPCIe module (on site at a client's0 stops responding after CFG-PRT to UBX only.
...
Bruce Simpson
01:04 AM Bug #6594: Package reinstallation post-config restore hangs if no Internet connectivity
It's still the package reinstall that gets hung up, regardless of whether or not you have packages installed. It sets... Chris Buechler
12:30 AM Bug #6617 (Resolved): "UNKNOWN" links in package manager
From Luke Hamburg on PR 3060:
"I noticed recently that many packages do not have the 'www' field in the database f...
Chris Buechler
12:25 AM Bug #6139 (Resolved): vpn_openvpn_server.php - When saving a server, all CSCs should be resynced
fixed Chris Buechler
12:06 AM Bug #6613 (Resolved): Interface mismatch allows applying changes without saving them
works, now doesn't allow applying until after you save, so people can't get confused.
This same bug actually goes...
Chris Buechler

07/15/2016

10:56 PM Bug #4639 (Resolved): NAT fails to correctly translate udp port numbers embedded in certain ICMP error packets
Pretty sure this overlaps with PR 201519, which is confirmed fixed.
Daniel: if you're still seeing issues on 2.3....
Chris Buechler
09:50 PM Bug #6450 (Resolved): Deleting yourself in User Manager results in an empty user tag in the config
Thanks Phil, setting the target was overlooked after the merge. Just double checked 2.3.2 and it's good. Chris Buechler
08:33 PM Bug #6450: Deleting yourself in User Manager results in an empty user tag in the config
This was committed to master, RELENG_2_3 and RELENG_2_3_1 around 23 June 2016.
That looks like it is later than the ...
Phillip Davis
05:50 PM pfSense Packages Feature #6204: Integrate ntopng with pfSense - assistance required by ntopng developer
Wow, this would be incredible (being able to mark traffic based on ntop filters) - did not even know that was theoret... → luckman212
02:20 PM Bug #6139: vpn_openvpn_server.php - When saving a server, all CSCs should be resynced
Applied in changeset commit:1f954318266fc0da7ee41bb532da969ec9da8b95. Jim Pingle
01:15 PM Bug #6589 (Feedback): dhcpd.leases missing hostnames in some cases
this is a bug with the dhcp-cache-threshold feature.
https://lists.isc.org/pipermail/dhcp-users/2016-July/020183.ht...
Chris Buechler
11:18 AM Bug #6495: No default route on PPPoE after reconnect or IP change in some cases
Hi Chris,
> I brought back the behavior of 2.2.6 and earlier here, as the root cause isn't readily apparent. The rou...
Mario Lener
12:15 AM Bug #6495: No default route on PPPoE after reconnect or IP change in some cases
I brought back the behavior of 2.2.6 and earlier here, as the root cause isn't readily apparent. The router file ends... Chris Buechler
05:04 AM pfSense Packages Bug #6616 (Duplicate): Client Export list empty when using intermediate CA
Certificate setup:
A Root CA which has signed a VPN CA certificate.
This VPN CA signed the VPN server certificate...
Johan Braeken
04:29 AM pfSense Packages Bug #6571: NUT service can not start sometimes after boot when SNMP UPS interface is down
I think the reason why this feature is not implemented by NUT team is because it should be implemented on the OS side... Vladimir Suhhanov
03:50 AM Feature #6615 (New): new DHCP server option
Some hardware can't receive a dhcp lease until they has been configured with a valid IP address.
In that circumstanc...
Fabien Duay

07/14/2016

11:54 PM Bug #6613: Interface mismatch allows applying changes without saving them
"The way it worked in 2.2.X was when you hit apply changes it saved and rebooted the pfsense at the same time."
Hm...
Phillip Davis
10:30 PM Bug #6613: Interface mismatch allows applying changes without saving them
Applied in changeset commit:1602106bf511e91c8d8f371ff8d5a92cfa70879a. Phillip Davis
10:25 PM Bug #6613 (Feedback): Interface mismatch allows applying changes without saving them
merged, thanks Phil. Chris Buechler
09:17 PM Bug #6613: Interface mismatch allows applying changes without saving them
Phillip Davis wrote:
> The Apply Changes button is being shown too early in the workflow.
> PR https://github.com/p...
Adam Piasecki
06:17 PM Bug #6613: Interface mismatch allows applying changes without saving them
The Apply Changes button is being shown too early in the workflow.
PR https://github.com/pfsense/pfsense/pull/3058 s...
Phillip Davis
10:19 AM Bug #6613 (Resolved): Interface mismatch allows applying changes without saving them
When selecting Apply Changes after fixing a interface mismatch. The button does not save the changes, and asks again ... Adam Piasecki
11:27 PM pfSense Packages Bug #6571: NUT service can not start sometimes after boot when SNMP UPS interface is down
I've taken a look at this, and this behavior appears to be an intentional choice on the part of the NUT team. I agree... Denny Page
10:42 PM Feature #3254 (Closed): Add DNS controls for radvd on tracking interfaces
this was addressed in 2.3 Chris Buechler
10:38 PM Feature #3366 (Duplicate): Diagnostics: DNS Lookup does not return AAAA records
this was implemented in 2.3.2 on a diff ticket Chris Buechler
10:38 PM pfSense Packages Feature #3685 (Resolved): haproxy listener ip from alias
Chris Buechler
10:30 PM Todo #1934 (Resolved): Add input validation for interface addresses in GUI and console
this was done quite some time ago Chris Buechler
07:41 PM Bug #6481: loading EAP_RADIUS method failed
happened to encounter this with a support customer today. It appears a reload of strongswan doesn't correctly enable ... Chris Buechler
03:17 PM Bug #6494 (Resolved): Hang during bootup on lock('filter.lock')
thanks for the feedback Chris Buechler
11:57 AM Bug #6494: Hang during bootup on lock('filter.lock')
I've never tried a 'snapshot' before this.
So... here goes.... While I'm waiting for 2.3.2.a.20160714.0044:
T...
Harry Coin
03:04 PM Bug #6614 (Confirmed): Dashboard high CPU usage
the number of things that dynamically update is significantly higher than it was in 2.2.x and prior. Still, something... Chris Buechler
01:16 PM Bug #6614: Dashboard high CPU usage
I visit the package manager listing, loads hover around 1, processor 98% idle. Back to the dashboard: wait 20 sec fo... Harry Coin
12:32 PM Bug #6614 (Confirmed): Dashboard high CPU usage
In a very low traffic sandbox environment, the new 2.3.2 snapshot of today hums along with a load average of 0.48 or ... Harry Coin
02:11 PM pfSense Packages Todo #6443: Add ntopng package back into pfSense 2.3.x
Rich Murphey wrote:
> I've installed snapshot 2.3.2.a.20160606.1543, and ntopng via the web UI package manager.
>
...
Jim Pingle
10:03 AM Bug #6610: Restore Config Interface Mismatch asks again on boot.
Once i fix the interface mismatch, and hit *apply changes* it reboots, and asks again at boot. Apply changes is not s... Adam Piasecki
03:48 AM Bug #6607: OpenVPN server won't start after reboot, when set to a Gateway Group specifing CARP VIPs
See: VPA-15570 Steve Wheeler
03:14 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Using gpsctl to initialize the GPS is rather slow, due to the repeated auto-detection (even when the device type is f... Bruce Simpson
03:09 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
uBlox5 1PPS modifications. From memory, I believe green is TX data (at 3.3V level), grey is 1PPS (also 3.3V; configur... Bruce Simpson
02:21 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Woops. Forgot to update the comment about 1PPS. We need it to supply only UTC seconds, and that's what the blob does.... Bruce Simpson
02:10 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
This !ublox5-boot.sh! is a bit ugly to embed in Shellcmd, but good enough to copy to /root and invoke from there. Bruce Simpson
01:19 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I now have a fix. I traced this back to an error in the NAVX5 message.
There is a 2-byte version (0000) in front wh...
Bruce Simpson
12:20 AM Bug #4544: PD not requested if no interfaces set to track6
The code here is at fault.
https://github.com/pfsense/pfsense/blob/master/src/etc/inc/interfaces.inc#L3927
It sh...
Chris Buechler
12:09 AM Bug #6609 (Feedback): OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
Thanks, merged to master for 2.4. Chris Buechler

07/13/2016

11:43 PM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
bumping net.inet.raw.maxdgram, net.inet.raw.recvspace, net.raw.recvspace and net.raw.sendspace even further seems to ... Chris Buechler
11:39 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Success pushing uBlox5 into binary mode; but don't let gpsd write to
the GPS (-b switch) just in case. I got NMEA a...
Bruce Simpson
10:17 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I hate little endian. Endian little hate I. This is the endian-fixed CFG-PRT packet. I get only UBX now, but I don't ... Bruce Simpson
10:04 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
According to Pg. 10 of [[http://www.pcengines.ch/schema/alix6b.pdf]], there is no way to power-cycle the MiniPCIe USB... Bruce Simpson
09:37 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Indeed, UBX messages are little-endian by definition. I'll have to revisit this -- being dragged into other things at... Bruce Simpson
09:07 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
OK. I'm having trouble with the uBlox5. Specifically, it is difficult to force the unit into a binary-only mode; it d... Bruce Simpson
11:40 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Picture of modified u-Blox5 unit -- pictures of modification (on lower side PCB) to follow !P1010540.jpeg! Bruce Simpson
09:29 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I am pivoting back to working on u-Blox 5 with GPSD, now that the SUT for Rockwell Jupiter is being soak-tested with ... Bruce Simpson
11:23 PM Bug #6548 (Resolved): Enclosed delimiters not protected in DHCP client advanced options
works Chris Buechler
02:57 PM Bug #6548 (Feedback): Enclosed delimiters not protected in DHCP client advanced options
PR #3020 merged, thanks! Renato Botelho
02:05 PM Bug #6548: Enclosed delimiters not protected in DHCP client advanced options
I'll handle this Renato Botelho
10:09 PM Bug #6494: Hang during bootup on lock('filter.lock')
That seems to work.
Harry: could you please try the latest 2.3.2 snapshot ASAP (we're looking to build release on...
Chris Buechler
03:30 PM Bug #6494 (Feedback): Hang during bootup on lock('filter.lock')
Yes, this looks correct. In addition to this fix I would like to open the files with FD_CLOEXEC set, but I could not ... Luiz Souza
07:43 PM pfSense Packages Bug #6612: squid Multi segmented downloading is broken
likely an issue in squid itself that should be reported there. They don't seem fond of download managers Chris Buechler
07:22 PM pfSense Packages Bug #6612 (Closed): squid Multi segmented downloading is broken
it looks like that squid Multi segmented downloading is broken again in squid.
TCP_MISS_ABORTED/206
It was fixe...
ageekhere ageekhere
07:43 PM Bug #6607 (Not a Bug): OpenVPN server won't start after reboot, when set to a Gateway Group specifing CARP VIPs
subject isn't true. That was all fully verified in 2.3.1, and just checked again to verify on 2.3.1_5 and 2.3.2, and ... Chris Buechler
02:17 AM Bug #6607: OpenVPN server won't start after reboot, when set to a Gateway Group specifing CARP VIPs
Affected version is 2.3.1-RELEASE-p1. I am using SG-4860 hardware. r00 00m
02:14 AM Bug #6607 (Not a Bug): OpenVPN server won't start after reboot, when set to a Gateway Group specifing CARP VIPs
No problem for OpenVPN clients.
When OpenVPN server is set to a simple CARP VIP, it will start after reboot.
Wh...
r00 00m
07:02 PM Bug #6611: Kernel panic when running PPPoE Server on tun/tap interface
Setting it to ovpn interface was just an attempt to see the result. Frank Schmied
06:57 PM Bug #6611 (Confirmed): Kernel panic when running PPPoE Server on tun/tap interface
also makes no sense to run on OpenVPN. That should be prohibited. other ticket is #4510 Chris Buechler
06:45 PM Bug #6611: Kernel panic when running PPPoE Server on tun/tap interface
I've seen the other ticket. The first attempt was on wan interface, which has a fixed ip (no PPPoE client). The secon... Frank Schmied
06:10 PM Bug #6611 (Feedback): Kernel panic when running PPPoE Server on tun/tap interface
what's the parent interface of the PPPoE? only way I know of doing something like this is making a PPPoE server inter... Chris Buechler
06:01 PM Bug #6611 (Closed): Kernel panic when running PPPoE Server on tun/tap interface
2.3.1-RELEASE-p5, running in 64 bit kvm vm.
After updating PPPoE settings and confirmation by clicking the green s...
Frank Schmied
06:22 PM Bug #6050 (Resolved): services_dhcp.php: "Network booting" section default style is confusing/easy to overlook
Looks good, thanks Phil Chris Buechler
05:02 PM Bug #6050 (Feedback): services_dhcp.php: "Network booting" section default style is confusing/easy to overlook
Merged, thanks Phil! Renato Botelho
04:32 PM Bug #6609: OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
I fixed the lines that reverted the recent changes. My bad for committing things that really aren't part of the patch... Kacper Boström
04:08 PM Bug #6609: OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
Thanks Kacper. Looks reasonable, outside the one line I left a comment on where a recent change was reverted, but som... Chris Buechler
03:57 PM Bug #6609: OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
I've submitted a github pull request (#3057) fixing this issue. Kacper Boström
03:53 PM Bug #6609 (Confirmed): OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
Chris Buechler
11:31 AM Bug #6609 (Resolved): OpenVPN Radius auth doesn't send NAS attributes and is not consistent with how strongSwan does it
OpenVPN Radius auth doesn't send NAS Port-Type (which should be "Virtual") and NAS Port (which preferably should be t... Kacper Boström
04:09 PM Bug #4804 (Closed): PPPoE Restart won't update IPv6 routing table with gif
Chris Buechler
11:06 AM Bug #4804: PPPoE Restart won't update IPv6 routing table with gif
Chris,
no, I''m afraid as I don't use pfSense anymore!
Armin Tueting
03:51 PM Bug #6610 (Not a Bug): Restore Config Interface Mismatch asks again on boot.
only if you didn't correct the interface mismatch and save that change. That only comes up when there are assigned in... Chris Buechler
12:04 PM Bug #6610 (Not a Bug): Restore Config Interface Mismatch asks again on boot.
When restoring a config with a interface mismatch, it prompts to fix the mismatch, after this it reboots the system. ... Adam Piasecki
03:21 PM Bug #6315 (Resolved): tftp-proxy is not functioning properly through xinetd
works Renato Botelho
02:59 PM Bug #6315 (Feedback): tftp-proxy is not functioning properly through xinetd
Luiz pushed a fix fot xinetd - https://github.com/pfsense/FreeBSD-ports/commit/eeb3abaa71905ccaec35b0bee7bc4dcc40cfc306 Renato Botelho
12:00 PM Bug #6594: Package reinstallation post-config restore hangs if no Internet connectivity
This happens even without packages installed. I restored a config without any package information in it. Even selecte... Adam Piasecki
11:41 AM Bug #6074 (Resolved): Odd wrap behavior on sortable tables
works Renato Botelho
10:02 AM Bug #4031: Notifications mail bomb in some gateway failure circumstances
I too have seen this I shut off emails cause it makes gui inaccessible when it starts bombing no coding skills here b... Michael Kellogg
09:47 AM Bug #4031: Notifications mail bomb in some gateway failure circumstances
Luke Hamburg wrote:
> I noticed the target version was bumped to 2.4.0 and the assignee is still cmb — this one bit ...
Jim Thompson
07:58 AM Bug #4031: Notifications mail bomb in some gateway failure circumstances
I noticed the target version was bumped to 2.4.0 and the assignee is still cmb — this one bit me again this morning s... → luckman212
05:52 AM Feature #6608 (New): backup and restore dhcp
good morning people,
I'm with a problem in dhcp backup restoration, I will explain the case.
My client has 3 ...
caio dias de souza
01:49 AM pfSense Packages Todo #6443: Add ntopng package back into pfSense 2.3.x
I'm still having the issue with ntopng not restarting after a reboot, with the following errors in the log.
Jul 13...
Andrew -
01:40 AM pfSense Packages Feature #6204: Integrate ntopng with pfSense - assistance required by ntopng developer
Hi
I think this ticket is different to #6443.
#6443 is simply about getting ntopng back into pfSense 2.3, follo...
Andrew -

07/12/2016

11:08 PM pfSense Packages Bug #4634 (Resolved): Still broken openbgpd config generation logic in 2.2
fixed last year Chris Buechler
11:07 PM pfSense Packages Bug #3605 (Closed): Dansguardian not saving groups config files with correct PICS paths.
package no longer exists, and Dansguardian itself is not maintained Chris Buechler
11:07 PM pfSense Packages Bug #3439 (Closed): TFTP - cannot start or restart from Status -> Services
package no longer exists Chris Buechler
11:00 PM pfSense Packages Bug #2920 (Not a Bug): OSPF on interfaces with IP Alias and carp unpredictable
Chris Buechler
10:54 PM Bug #4500 (Confirmed): UPnP/NAT-PMP status page does not display all port mappings
Chris Buechler
10:53 PM Feature #4495 (Duplicate): IPv6 support for DynDNS client
duplicate of #1825 Chris Buechler
10:53 PM pfSense Packages Feature #6204 (Duplicate): Integrate ntopng with pfSense - assistance required by ntopng developer
duplicate of #6443 Chris Buechler
08:15 PM Bug #2800 (Feedback): OpenVPN doesn't work properly with intermediate/chained CAs
Merged PR 2966 for 2.4 to address this.
https://github.com/pfsense/pfsense/pull/2966
If OpenVPN Client Export ne...
Chris Buechler
08:03 PM Todo #6606 (Resolved): Adapt captive portal to work without multi-instance ipfw
Captive portal needs to be adapted to work minus the multi-instance ipfw capabilities. Chris Buechler
07:46 PM Bug #6605 (Confirmed): rc.linkup logic issues with actions taken
The actions taken by rc.linkup differ depending on whether the interface has a static or no IPv4 and IPv6 IP, and eve... Chris Buechler
06:14 PM Bug #6074 (Feedback): Odd wrap behavior on sortable tables
I added a CSS nowrap property and a "table-responsive" div to the captive portal widget as well as styled the sortabl... Jared Dillard
03:12 PM Bug #6227 (Feedback): LAGG MTU not set correctly when it has child QinQ interfaces
PR merged Chris Buechler
03:06 PM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
Any idea? Is there any hook we can bind to? Like change of interface ip addresses? Which could get our tunnels reconf... Daniel Hoffend
01:17 PM Bug #6044: system>monitoring tooltip unit "null" for some graphs
works Renato Botelho
01:16 PM Bug #6044 (Resolved): system>monitoring tooltip unit "null" for some graphs
fixed Chris Buechler
01:13 PM Bug #6181 (Resolved): Updating url alias tables fails when remote server returns empty document.
works Renato Botelho
12:51 PM Bug #6291 (Resolved): Serial console data fields not displayed on nanobsd VGA
works Renato Botelho
11:24 AM Bug #6315: tftp-proxy is not functioning properly through xinetd
I reproduced it on stock FreeBSD and opened a ticket on FreeBSD's bugzilla - https://bugs.freebsd.org/bugzilla/show_b... Renato Botelho
09:30 AM Bug #4754 (Resolved): enabling net.inet.ipsec.directdispatch on 32 bit results in kernel panics
Renato Botelho
09:16 AM Bug #6402 (Resolved): Monitoring won't save default configuration of 8 hours with 1 minute resolution, resets resolution to 5 minutes when switching from 1 hour, 1 minute resolution
works Renato Botelho
05:23 AM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
Oh, and - the original problem is much worse on nanobsd - no config restore needed. This breaks on every system upgra... Kill Bill
05:17 AM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
Rather than such ad hoc hacks - cannot we get something like the sanity checking from pfBNG to Unbound itself? Like, ... Kill Bill
03:57 AM Bug #6572: Config sync hangs php-fpm on secondary
Hi Chris,
Any updates please? Kindly ask should you require further information if needed from our end, thanks.
...
Brian Stivala

07/11/2016

11:19 PM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
It can get complicated if a user adds other *include: /blah/blah.conf* lines, but splits it into two lines.... For th... BBcan177 .
11:13 PM pfSense Packages Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
Yes, this is a known issue... I can't fix it in the package as it needs to be addressed in unbound.inc.
I can add ...
BBcan177 .
05:22 PM pfSense Packages Bug #6603 (Resolved): pfblockerng's Unbound modifications leave system broken post-config restore
pfblocker's "include: /var/unbound/pfb_dnsbl.conf" in the Unbound config leaves you with a broken system after config... Chris Buechler
11:06 PM Feature #6388 (Resolved): Status / Dashboard save changes for all users
works Chris Buechler
10:47 PM Bug #6601 (Confirmed): Horizontal scroll bar on Installed Packages
Chris Buechler
04:04 PM Bug #6601 (Resolved): Horizontal scroll bar on Installed Packages
On Installed Packages page horizontal bottom scroll bar appears. Jared has all the information. Ivor Kreso
10:20 PM Feature #6604: Allow NTP server list to be overridden by DHCP/PPP
Enabling this option would of course enable the ntp service to use the DHCP supplied NTP servers (section 8.3 of http... Danny Schuh
10:11 PM Feature #6604 (New): Allow NTP server list to be overridden by DHCP/PPP
In the System / General Setup page, there is a DNS Server Settings option to "Allow DNS server list to be overridden ... Danny Schuh
10:19 PM Todo #6586 (Resolved): interfaces_gre_edit.php: Checkbox options that set link0, link1, and link2 appear to be no-ops on FreeBSD now
works Chris Buechler
11:52 AM Todo #6586 (Feedback): interfaces_gre_edit.php: Checkbox options that set link0, link1, and link2 appear to be no-ops on FreeBSD now
Tested OK here. Leaving open for another run once it's in snapshots. Jim Pingle
10:16 PM Todo #6587 (Resolved): interfaces_gif_edit.php: Link flag changes need to catch up with FreeBSD
all good Chris Buechler
11:52 AM Todo #6587 (Feedback): interfaces_gif_edit.php: Link flag changes need to catch up with FreeBSD
Tested OK here. Leaving open for another run once it's in snapshots. Jim Pingle
10:08 PM Bug #6595 (Resolved): Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
fixed Chris Buechler
10:04 PM Bug #6464 (Resolved): X axis ticks don't respond to resolution for custom time periods
fixed Chris Buechler
10:03 PM Bug #6138 (Confirmed): Long hostnames overlap the "time" title in the Monitoring graphs
Chris Buechler
10:00 PM Bug #6139: vpn_openvpn_server.php - When saving a server, all CSCs should be resynced
same order change made on vpn_openvpn_client.php
JimP: can you confirm whether this fixed the issue you were seein...
Chris Buechler
09:55 PM Bug #6597 (Resolved): "PPPoE clients" placeholder wrong in firewall rules, floating rules on PPPoE creates broken ruleset
works Chris Buechler
09:41 PM Bug #5993: dhcp6c not started until an RA received
Martin Wasley wrote:
> I finally managed to get back to this after several weeks having to work for a living. The fi...
Kevin Morse
09:22 PM Bug #6400 (Confirmed): assign_interfaces.php issues with large numbers of interfaces
Not seeing any issues with 200 assigned interfaces (somewhat slower than 2.2.x, but still usable), but take it up to ... Chris Buechler
08:44 PM Bug #6520 (Duplicate): Time out when trying to look at interfaces_assign.php
same as #6400 Chris Buechler
04:57 PM Feature #6602 (New): Config writes denied via "deny config write" permission should notify as such
If you have a group set with the deny config write privilege, its config saves look to the user to have been successf... Chris Buechler
02:51 PM Feature #6600: DHCP Server - Primary DDNS Address won't accept IPv6 address
the way that field is used, it must be an IPv4 IP. 'primary' is where it's specified in dhcpd.conf, which must be IPv... Chris Buechler
10:04 AM Feature #6600 (Resolved): DHCP Server - Primary DDNS Address won't accept IPv6 address
For the DDNS feature in the DHCP Server one cannot enter an IPv6 address. The error message is: ... Pim Pish
02:23 PM Bug #6315 (Assigned): tftp-proxy is not functioning properly through xinetd
working on that Renato Botelho
01:35 PM Bug #6355 (Feedback): DHCP relay listens for dhcp requests on the upstream interface.
Patch imported from debian, also submitted the fix for FreeBSD at https://reviews.freebsd.org/D7190 and opened a bug ... Renato Botelho
12:42 PM Bug #6355 (Confirmed): DHCP relay listens for dhcp requests on the upstream interface.
Working on it Renato Botelho
12:28 PM Feature #6172 (Resolved): Restore the traffic totals previously displayed in RRD graphs data summary.
Status_Traffic_Totals package is now available Renato Botelho
07:29 AM Bug #5934: When two distinct Phase 1 are configured, only the first one connects ar startup
Hi Chris,
I said to Renato that 2.3.x fixed the issue, but forgot to update the ticket here, my bad!
But just f...
Luiz Fernando Cavalcanti
02:32 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
OMG.
The NAT 1:1 problem using limiters persist.
Works well on 2.1.5, 2.2.x = BAD, 2.3.x = BAD sigh ! We are forc...
Luca De Andreis

07/10/2016

11:51 PM Bug #6595: Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
Minor description correction: ...is no longer included in the actual DHCP server config file.. should read ...is no ... Nash Kaminski
07:21 PM Bug #6595 (Feedback): Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
PR fixes, merged. leaving to confirm once it hits a snapshot Chris Buechler
07:19 PM Bug #6595 (Confirmed): Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
Chris Buechler
04:24 AM Bug #6595: Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
This bug also appears to a regression from 2.2.x since the "DHCP Advanced configuration" option did not exist and the... Nash Kaminski
04:20 AM Bug #6595 (Resolved): Checking advanced DHCP config checkbox breaks option to ignore DHCP lease from specific IP
When the advanced DHCP configuration option checkbox is checked for an interface setup as a DHCP client, such as the ... Nash Kaminski
11:30 PM Bug #6599 (Not a Bug): Routing problem with IKE v2
Please post to the forum for assistance, this isn't a bug. Chris Buechler
09:00 PM Bug #6599 (Not a Bug): Routing problem with IKE v2
Following a suggestion to use IKE v2 instead of L2TP/IPsec, I have set up an IKE v2 IPsec connection following https:... Bruno Grossmann
08:24 PM Bug #6139 (Feedback): vpn_openvpn_server.php - When saving a server, all CSCs should be resynced
Saving a server triggers openvpn_resync_all which runs openvpn_resync_csc: ... Chris Buechler
08:10 PM Bug #4630 (Not a Bug): OpenVPN Client Limiting Download Speeds
there aren't any general performance regressions in OpenVPN. Chris Buechler
07:43 PM Bug #6598 (Resolved): "PPPoE clients" placeholder in rules only includes first PPPoE server instance
The "PPPoE clients" placeholder in firewall rules only includes the client subnet of the first instance of the PPPoE ... Chris Buechler
07:40 PM Bug #6597 (Resolved): "PPPoE clients" placeholder wrong in firewall rules, floating rules on PPPoE creates broken ruleset
Couple issues with firewall rules and PPPoE server.
1) the "PPPoE Clients" network wrongly fills in the server IP...
Chris Buechler
01:55 PM Bug #6494: Hang during bootup on lock('filter.lock')
Corrected patch (ln -s terms swapped)... Harry Coin
11:58 AM Bug #6596: Not able to connect from Windows 7 to L2TP/IPsec
Thanks. The strongswan ticket seems to indicate the issue was fixed 4 years ago though so I am not quite sure what I ... Bruno Grossmann
11:44 AM Bug #6596 (Closed): Not able to connect from Windows 7 to L2TP/IPsec
There isn't anything we can do for that. It's an issue in Windows when connecting to strongSwan. https://wiki.strongs... Jim Pingle
10:31 AM Bug #6596: Not able to connect from Windows 7 to L2TP/IPsec
Log for IPsec is displayed in ipsec_log0.png. Tcpdump log is in tcpdump_enc0.png
Do not hesitate to contact me if ...
Bruno Grossmann
10:28 AM Bug #6596 (Closed): Not able to connect from Windows 7 to L2TP/IPsec
Hello,
First, thanks for all your work. This is a fine product that I have used numerous times and it usually works ...
Bruno Grossmann
07:29 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
It may be that the best way forward is to go with GPSD instead of NTPD refclock_nmea. The NTPsec people broadly overl... Bruce Simpson
07:25 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Ironically, IEEE 1588 provides for this loss of fix by allowing a clock to advertise that it's lost its primary refer... Bruce Simpson
07:20 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Here's a picture of the Rockwell-based SUT: !P1010521.jpeg!
It is occasionally losing the fix. That's kind of a pr...
Bruce Simpson
06:06 AM Feature #6573: /var/run/dmesg.boot
Perfect.
Thank you!
Jose Luis Duran
03:49 AM Feature #6573 (Resolved): /var/run/dmesg.boot
works Chris Buechler
03:53 AM Bug #6335 (Confirmed): Status > IPsec shows both connected and disconnected with Split Connections enabled
Chris Buechler
03:48 AM Feature #6002 (Resolved): UPNP presentation_url and model_number
works Chris Buechler
12:10 AM Feature #6002 (Feedback): UPNP presentation_url and model_number
PR was merged for this a couple weeks ago Chris Buechler
03:41 AM Feature #6533 (Resolved): Allow configuration of Min and MaxRtrAdvInterval, AdvDefaultLifetime
fixed Chris Buechler
03:41 AM Bug #6581 (Resolved): Router Advertisement forces (possibly empty) interface subnet contrary to GUI text, can crash radavd on boot.
fixed Chris Buechler
01:01 AM Bug #6297 (Resolved): rc.linkup doesn't trigger filter reload
works Chris Buechler
12:58 AM Bug #3027 (Resolved): input_errors2Ajax function
removed all references to input_errors2Ajax. Chris Buechler
12:49 AM Feature #2969 (Closed): Automatic config.xml recovery / reinstallation
the "rescue config" option in the installer works for this. Chris Buechler
12:45 AM Bug #3355 (Resolved): Interface monitor logic changes firewall tables too late for DynDNS
the fix for #4066 also addresses this Chris Buechler
12:39 AM Bug #4710 (Duplicate): System Log - Firewall Fails to 'Click to Resolve' for IPv6 Addresses
addressed in #6585 Chris Buechler
12:36 AM Bug #4528 (Duplicate): no DynDNS RFC2136 Updates are done on some pfSense-installations
duplicates #6357 Chris Buechler
12:33 AM Bug #3626 (Not a Bug): rc.start_packages called twice on startup if WAN is set to DHCP
It's correct that it does so. There is another ticket to improve which packages restart on dynamic WAN reconnection Chris Buechler
12:31 AM Bug #3965 (Confirmed): dhcp6c started before bridge configured at boot, preventing interface tracking
Chris Buechler
12:24 AM Bug #5791 (Confirmed): tftp-proxy functionality is easilly broken by unrelated rules
Chris Buechler
12:22 AM Bug #5378 (Closed): Intel x710 10GbE NIC doesn't work (no carrier)
Likely this is fine on 2.3.x with the latest driver. If not, should be reported upstream to FreeBSD. Chris Buechler
12:21 AM Bug #4749 (Duplicate): DHCPv6 server not disabling after initial setup
duplicate of other that was fixed in 2.3.x Chris Buechler
12:17 AM Bug #5890 (Resolved): "External config loader" not loading config.xml from USB at boot
fixed in 2.3.0 and newer Chris Buechler
12:16 AM Bug #5934 (Not a Bug): When two distinct Phase 1 are configured, only the first one connects ar startup
no apparent issues here, and no feedback Chris Buechler
12:13 AM Bug #6275 (Confirmed): Disconnected IPsec phase 2 entries are not shown in IPsec status
Pre-strongswan, each P2 showed as its own entry on status_ipsec.php, so you could see which defined P2s were up and d... Chris Buechler

07/09/2016

09:26 PM Bug #3069 (Resolved): traceroute6 fails to timeout and hangs the webconfigurator GUI
works Chris Buechler
09:11 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Since we are not getting a solution any time soon, i guess we can use 2 pfsense boxes in line one with limiter and t... oscar velazquez
08:54 PM Bug #6594 (Resolved): Package reinstallation post-config restore hangs if no Internet connectivity
If you restore a config, and upon reboot the system doesn't have Internet connectivity when trying to update metadata... Chris Buechler
08:16 PM Bug #6582 (Resolved): Import on Firewall/Aliases Only Works for IPs
works Chris Buechler
07:19 PM Bug #6590 (Resolved): Services - NTP: leap seconds file upload does not work
Chris Buechler
02:40 AM Bug #6590: Services - NTP: leap seconds file upload does not work
Works, thanks. ;) Kill Bill
02:30 AM Bug #6590: Services - NTP: leap seconds file upload does not work
Applied in changeset commit:76763c4c5a3d537b778243524a15ee9204f68c6f. Phillip Davis
02:22 AM Bug #6590 (Feedback): Services - NTP: leap seconds file upload does not work
Thanks Phil, PR merged. Chris Buechler
01:33 AM Bug #6590: Services - NTP: leap seconds file upload does not work
This is easy to fix - just a bit of magic code is missing to enable file uploads on this page.
PR https://github.com...
Phillip Davis
07:18 PM Bug #6110 (Resolved): Default gateway switching not always working with PPP
Thanks Greg. Going to consider this fixed then, one of the other gateway-related tickets target 2.3.1 must have resol... Chris Buechler
02:48 AM Bug #6110: Default gateway switching not always working with PPP
Hi!
Nope, all fine here.
Tested multiple times...
Greg M
07:17 PM Bug #4754 (Feedback): enabling net.inet.ipsec.directdispatch on 32 bit results in kernel panics
I removed that directdispatch sysctl from 2.4 entirely since 32 bit is gone there, and changed RELENG_2_3 to net.isr.... Chris Buechler
11:59 AM Bug #4754: enabling net.inet.ipsec.directdispatch on 32 bit results in kernel panics
Apparently this can also affect 2.3.x and that tunable is no longer present. To work around the issue, use @net.isr.d... Jim Pingle
07:08 PM Feature #6533 (Feedback): Allow configuration of Min and MaxRtrAdvInterval, AdvDefaultLifetime
added Min and MaxRtrAdvInterval as well as AdvDefaultLifetime.
Greg: if there are other options you'd like to see...
Chris Buechler
02:47 AM Feature #6533: Allow configuration of Min and MaxRtrAdvInterval, AdvDefaultLifetime
Hi Chris!
Great news, are those Router lifetime, Route lifetime etc.. also added to be able to configure them?
Greg M
02:19 AM Feature #6533 (Assigned): Allow configuration of Min and MaxRtrAdvInterval, AdvDefaultLifetime
this mostly done, want to review with fresh eyes tomorrow before committing though. Chris Buechler
02:31 PM pfSense Packages Bug #6592: squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation
Seems to focus oon reverse proxy only. Alexander Wilke
12:56 PM pfSense Packages Bug #6592: squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation
Already covered by https://github.com/pfsense/FreeBSD-ports/pull/110 when someone gets to it. Kill Bill
11:05 AM pfSense Packages Bug #6592 (Resolved): squid does NOT use EDH and EECDH cipher suites because "tls-dh" is not configured and so these ciphers are silently dropped - see squid documentation
Here it is documented how "http_port" can be configured:
http://www.squid-cache.org/Doc/config/http_port/
EDH and...
Alexander Wilke
02:03 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I seem to have a stable fix with 5-6 PRNs now. This is comparable to the uBlox5 unit (pfSense 2.3.1, i386, ALIX 6D2) ... Bruce Simpson
12:44 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
P.S. Those of us who are only using NTPD for reference clock support (and time distribution), and/or plan to run IEEE... Bruce Simpson
12:33 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I'm still having some receiver issues, however...
I can get the higher quality SHM refclock derived from PPS in GP...
Bruce Simpson
07:29 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Proceeding under the assumption that refclock_jupiter.c may have bitrotted, I discovered that there is not a snowball... Bruce Simpson
12:48 PM pfSense Packages Feature #6593: squid: allow user to configure DH key size, SINGLE_DH_USE, NO-SSLv3, Cipher-Suites - performance improvement hint
Alexander Wilke wrote:
> For the user it would be good to have the possibility to modify "NO_SSLv3" using the WebUI ...
Kill Bill
11:18 AM pfSense Packages Feature #6593 (Resolved): squid: allow user to configure DH key size, SINGLE_DH_USE, NO-SSLv3, Cipher-Suites - performance improvement hint
Squid has some additional options set like:
options=NO_SSLv2,NO_SSLv3,SINGLE_DH_USE (and should have "SINGLE_ECDH_...
Alexander Wilke
02:37 AM Bug #6050: services_dhcp.php: "Network booting" section default style is confusing/easy to overlook
I have made 2 PRs with different ways to organize the page:
https://github.com/pfsense/pfsense/pull/3051
https://gi...
Phillip Davis
01:18 AM Bug #6577 (Resolved): pkg_edit.php: rowhelper data not preserved on validation error
works Chris Buechler

07/08/2016

11:58 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Something in the mix keeps setting the baud rate to 4800, though -- overriding /dev/cuau0.lock settings. My guess is ... Bruce Simpson
11:37 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I have a shell script which configures the unit for 9600 baud binary operation. [[gpsdo-boot.sh]]
This requires th...
Bruce Simpson
09:22 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Swapping out the cables DID help. Always ensure you're using a high-quality, shielded serial cable for talking to a G... Bruce Simpson
11:28 PM Bug #6590 (Confirmed): Services - NTP: leap seconds file upload does not work
Chris Buechler
10:46 AM Bug #6590 (Resolved): Services - NTP: leap seconds file upload does not work
Grab the ftp://tycho.usno.navy.mil/pub/ntp/leap-seconds.list, try to upload it via Services - NTP - Leap seconds file... Kill Bill
11:25 PM Feature #6591 (Duplicate): Configurable DDNS check IP services
merged from PR 3037
https://github.com/pfsense/pfsense/pull/3037
ticket for tracking
Chris Buechler
10:37 PM Bug #6153 (Confirmed): RFC 2136 Client fails to update more than 1 record
Chris Buechler
10:34 PM Bug #4843 (Not a Bug): Traffic Shapper Wizard
the hierarchy is correct Chris Buechler
10:31 PM Bug #4804: PPPoE Restart won't update IPv6 routing table with gif
Armin: you still seeing this on 2.3.1_5 (or newer)? Chris Buechler
10:30 PM pfSense Packages Bug #5511 (Resolved): quagga zebra.conf and openvpn interface
works Chris Buechler
10:29 PM Bug #5355: on Dynamic WAN IP (DHCP Client) it takes 10 minutes before Phase1 reconnects
The root cause here is likely that the SA that exists at the time of the IP change is still hanging around afterwards... Chris Buechler
10:20 PM Bug #6132 (Confirmed): race condition in OpenVPN startup
The root issue can still be a problem. Probably ought to put a lock around it, but long-term needs a better service m... Chris Buechler
10:13 PM Bug #6064 (Feedback): non-fully qualified hostnames included in hosts file and Unbound local-data
fix pushed to master/2.4 only, as that'll need more widespread testing than 2.3.2 will get before release. Chris Buechler
09:58 PM Bug #6297 (Feedback): rc.linkup doesn't trigger filter reload
fix pushed Chris Buechler
09:55 PM Bug #6249 (Confirmed): OpenVPN widget does not show client instance's IPv6 address
Chris Buechler
09:55 PM Bug #6416 (Resolved): wrong number for speed in /usr/local/www/services_ntpd_gps.php
fixed Chris Buechler
09:54 PM Bug #6581 (Feedback): Router Advertisement forces (possibly empty) interface subnet contrary to GUI text, can crash radavd on boot.
fix pushed Chris Buechler
05:19 AM Bug #6581 (Confirmed): Router Advertisement forces (possibly empty) interface subnet contrary to GUI text, can crash radavd on boot.
Needs to verify it's a valid subnet and prefix before getting into this block, and skip it if it's not.
https://git...
Chris Buechler
09:26 PM Bug #6543 (Resolved): Some leases do not show up in DHCPv6 Lease status
works.
Whether systems show online or offline depends on whether the DHCPv6 leased IP is in the NDP cache. If the...
Chris Buechler
05:28 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Renato Botelho wrote:
> You can install the package "System Patches" and then apply following patch to you system:
...
Axel Taferner
03:21 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Axel Taferner wrote:
> Sorry, I can't confirm if the fix worked for me as I'm not running the snapshots. I'll open a...
Renato Botelho
02:59 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Sorry, I can't confirm if the fix worked for me as I'm not running the snapshots. I'll open another bug for the separ... Axel Taferner
01:47 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Axel Taferner wrote:
> Awesome. Should I open another bug for the problem I mentioned where hosts who have staticall...
Renato Botelho
11:12 AM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Awesome. Should I open another bug for the problem I mentioned where hosts who have statically assigned dhcpv6 leases... Axel Taferner
09:50 AM Bug #6543 (Feedback): Some leases do not show up in DHCPv6 Lease status
Applied in changeset commit:1f9c2cb696f493aaaa3512f29c080b7e422b24f2. Renato Botelho
09:48 AM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Pushed a fix on RELENG_2_3, 2.3.2 snapshots will be fine Renato Botelho
09:21 PM Bug #6110 (Feedback): Default gateway switching not always working with PPP
Greg M: does this still happen for you?
James M: you're referring to something entirely unrelated.
Chris Buechler
09:19 PM Feature #6504 (Resolved): services_dhcp.php: DHCP Static Mappings table should be sortable
works Chris Buechler
08:19 PM Feature #6573 (Feedback): /var/run/dmesg.boot
PR merged Chris Buechler
11:22 AM Feature #6573: /var/run/dmesg.boot
https://github.com/pfsense/pfsense/pull/3049 Kill Bill
08:08 PM Bug #6557 (Resolved): nanobsd upgrades may fail from lacking resolv.conf
confirmed fixed on multiple upgrades Chris Buechler
10:37 AM Feature #6415 (Duplicate): Restore "Period" data summary column (Status > Monitoring) in pfSense 2.3
This is a duplicate of #6172 Jared Dillard
10:35 AM Bug #6366 (Not a Bug): Status monitoring custom resolution quirkiness
Closing by submitter's request Renato Botelho
10:31 AM Bug #6582 (Feedback): Import on Firewall/Aliases Only Works for IPs
Merged, thanks! Renato Botelho
08:40 AM Bug #6585 (Resolved): status_logs_filter.php ipv6 support (reverse lookup)
Renato Botelho
08:26 AM Bug #6585: status_logs_filter.php ipv6 support (reverse lookup)
This issue could be changed from "feature" to "bug". Phillip Davis
04:40 AM Bug #6585: status_logs_filter.php ipv6 support (reverse lookup)
Applied in changeset commit:30df6b722d577fe8c1b38476244bfb797ec89b5a. Phillip Davis
04:38 AM Bug #6585 (Feedback): status_logs_filter.php ipv6 support (reverse lookup)
Merged, thanks Phil. Chris Buechler
04:25 AM Bug #6585: status_logs_filter.php ipv6 support (reverse lookup)
Thanks for testing.
The Firewall Log Dynamic view does not have the reverse lookup buton, so it won't be broken!
Th...
Phillip Davis
02:19 AM Bug #6585: status_logs_filter.php ipv6 support (reverse lookup)
It works!
Now for ipv6 addresses ptr records are returned,
and in case of no prt "Cannot resolve".
Great work, tha...
Luca Moncelli
03:35 AM Bug #6394 (Resolved): INCORRECT OUTPUT OF TRANSLATION
fixed, thanks NewEraCracker Chris Buechler
12:59 AM Bug #6437 (Confirmed): CBQ queues are not displaying options for bandwidth or borrowing
Steve: don't think this is extremely involved, if you can get it addressed in the next few days we can get it in for ... Chris Buechler
12:09 AM Bug #6589 (Resolved): dhcpd.leases missing hostnames in some cases
Since the upgrade to ISC dhcpd 4.3 in 2.3x, several users have reported missing hostnames in the dhcpd.leases file. T... Chris Buechler

07/07/2016

08:58 PM Bug #6588 (Closed): PHP suhosin max value length prevents Quagga OSPF from storing a very large zebra.conf
pfsense 2.3.1-RELEASE-p5 (amd64)
Quagga_OSPF net 0.6.14
I tried to add some static routes in Services>Quagga OSP...
Fisher Wei
08:39 PM Bug #6585: status_logs_filter.php ipv6 support (reverse lookup)
The IPv6 addresses there are displayed using the [1:2::3]:80 format with [IPv6-address]:port which is good for displa... Phillip Davis
01:31 PM Bug #6585 (Resolved): status_logs_filter.php ipv6 support (reverse lookup)
status_logs_filter.php reverse lookup lacks IPv6 support,
"i" click to resolve doesn't returs any info for IPv6 addr...
Luca Moncelli
05:54 PM Bug #6543 (Confirmed): Some leases do not show up in DHCPv6 Lease status
Forwarded it to you, Renato. Chris Buechler
08:37 AM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Axel Taferner wrote:
> I sent the email last week, I hope you received it.
Hello Axel,
Can you also send it to...
Renato Botelho
04:17 PM Bug #6584 (Not a Bug): FirewallTraffic ShaperLimiters on in/out rule mixed up
That's correct. Upload is in on LAN, download is out on LAN. Chris Buechler
06:31 AM Bug #6584 (Not a Bug): FirewallTraffic ShaperLimiters on in/out rule mixed up
When apply traffic rule on the lan interface default any rule. the in and out is mixed up.
in= upstream (upload)
...
danny van aalstede
03:22 PM Todo #6587 (Resolved): interfaces_gif_edit.php: Link flag changes need to catch up with FreeBSD
link0 is no longer supported on gif, it used to be multi-destination behavior, we had it labeled as "route caching" -... Jim Pingle
03:16 PM Todo #6586 (Resolved): interfaces_gre_edit.php: Checkbox options that set link0, link1, and link2 appear to be no-ops on FreeBSD now
gre(4) in FreeBSD 10.3 (and 10.2) no longer appears to support the link0/link1/link2 tweaks it used to have for route... Jim Pingle
01:07 PM Bug #6334 (Resolved): No data periods in monitoring are represented as 0 (zero). Skewing averages.
Renato Botelho
12:44 PM Feature #6561 (Resolved): diag_dns.php IPv6 support
Renato Botelho
12:42 PM Feature #6561: diag_dns.php IPv6 support
now works on 2.3.2.a.20160707.1019 : ipv4/ipv6 name lookup and reverse. Luca Moncelli
12:43 PM Bug #3069 (Feedback): traceroute6 fails to timeout and hangs the webconfigurator GUI
Imported traceroute6 patch to FreeBSD-src repo. It'll be available on next round of snapshots Renato Botelho
09:32 AM Bug #3069: traceroute6 fails to timeout and hangs the webconfigurator GUI
I'll make some tests and import the patch to our tree Renato Botelho
12:32 PM Feature #5498: RRD needs a makeover
Period data is now available in 2.3.2 snapshots in the new Traffic Totals package, based on the vnstat database.
h...
Jared Dillard
12:30 PM Feature #6172 (Feedback): Restore the traffic totals previously displayed in RRD graphs data summary.
There is now a Traffic Totals package in 2.3.2 snapshots that shows traffic totals for hours/days/months, using the v... Jared Dillard
12:18 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Bug in present patch: '$PRWIINIT,A,,,,,,,,,,,,,\r\n' is an absolute reset, losing the date. This may have caused inte... Bruce Simpson
11:39 AM Bug #5990: AES-GCM should be an allowed encryption algorithm for IKEv2 in P1
Can I suggest that in the meantime, there shouldn't be a default selection made for encryption algorithm? And further... Michael Newton
10:28 AM Bug #6395 (Resolved): Comments are not removed from URL Table (Ports) links
Renato Botelho
10:05 AM Bug #6395: Comments are not removed from URL Table (Ports) links
FYI - I need this update to be rolled up into 2.3.2 as I cannot upgrade to 2.3.1_5 directly without breaking firewall... Alex Vergilis
10:03 AM Bug #6395: Comments are not removed from URL Table (Ports) links
2.3.1_5 appears to have fixed it. Thank you. Alex Vergilis
09:18 AM Bug #6395: Comments are not removed from URL Table (Ports) links
Alex Vergilis wrote:
> Phillip/Chris/Renato,
>
> I've noticed that I had to save the URL several times before the...
Renato Botelho
10:00 AM Bug #6291 (Feedback): Serial console data fields not displayed on nanobsd VGA
Applied in changeset commit:2a8849119c7c48976161faeaedc477c347e9b724. Renato Botelho
09:55 AM Bug #6291: Serial console data fields not displayed on nanobsd VGA
It was replaced by $g['enableserial_force']. I've pushed a fix for System Advanced page Renato Botelho
09:20 AM Feature #6045: Updates that do not require a reboot should run reroot
All updates are requiring reboot nowadays while we didn't test reroot accordingly. IMO it's a big change for 2.3 seri... Renato Botelho
08:59 AM Bug #6582: Import on Firewall/Aliases Only Works for IPs
Yes, agree. It is new functionality that does not need to risk breaking something in 2.3.1_* Phillip Davis
08:55 AM Bug #6582: Import on Firewall/Aliases Only Works for IPs
Such a big change for 2.3.1, pushing it to 2.3.2 Renato Botelho
02:01 AM Bug #6582: Import on Firewall/Aliases Only Works for IPs
Suggested combination fix and enhancement pull request https://github.com/pfsense/pfsense/pull/3046 Phillip Davis
08:57 AM Bug #6583 (Not a Bug): Unbound Query Logging
Definitely works, no bug here.
Depending on your other selected options you may need to have a line before it for ...
Jim Pingle
08:51 AM Bug #6583 (Feedback): Unbound Query Logging
I've added it to custom options without any problem. Make sure any extra char was not added by accident, check if unb... Renato Botelho
02:22 AM Bug #6583 (Not a Bug): Unbound Query Logging
It is not possible to configure query logging in the DNS Resolver UI page; adding "log-queries: yes" to the custom op... Chris Kuethe
08:34 AM pfSense Packages Bug #5713 (Rejected): SSHDCond package broken - Incorrect path in /etc/sshd file
sshdcond package was deprecated in pfSense 2.3 Renato Botelho
01:12 AM pfSense Packages Bug #6246 (Resolved): pfBlockerNG - filter rule error if all entries in a block list de-dupe out
thanks BBcan Chris Buechler

07/06/2016

11:19 PM pfSense Packages Bug #6246: pfBlockerNG - filter rule error if all entries in a block list de-dupe out
Can be closed BBcan177 .
09:41 PM Bug #6582 (Resolved): Import on Firewall/Aliases Only Works for IPs
In the firewall alias section, the import button only enters values into IP aliases despite the import button being p... Daniel Subert
08:07 PM pfSense Packages Todo #6443 (Assigned): Add ntopng package back into pfSense 2.3.x
Jim Thompson
04:36 PM Feature #6561: diag_dns.php IPv6 support
fix pushed for the PTR lookups Chris Buechler
03:57 PM Bug #6581: Router Advertisement forces (possibly empty) interface subnet contrary to GUI text, can crash radavd on boot.
Might have got the version wrong there, this occurs on the latest release.
The patch I put in was:...
Harry Coin
03:53 PM Bug #6581 (Resolved): Router Advertisement forces (possibly empty) interface subnet contrary to GUI text, can crash radavd on boot.
On the "Router Advertisements" page in the GUI we have:
RA Subnets: ... If no subnets are specified here, the Route...
Harry Coin
10:00 AM Bug #6577: pkg_edit.php: rowhelper data not preserved on validation error
Applied in changeset commit:a654d899cd5d288501fea1ec52dba2e3f0e479ba. Anonymous
09:57 AM Bug #6577 (Feedback): pkg_edit.php: rowhelper data not preserved on validation error
Read values from POST data on validation error
Re-factor some duplicated code
Anonymous
09:26 AM Bug #6543: Some leases do not show up in DHCPv6 Lease status
I sent the email last week, I hope you received it. Axel Taferner
08:59 AM Bug #5993: dhcp6c not started until an RA received
I finally managed to get back to this after several weeks having to work for a living. The first thing I did was to u... Martin Wasley
05:50 AM Bug #6557 (Feedback): nanobsd upgrades may fail from lacking resolv.conf
Applied in changeset commit:5fac13aafdc335864082fd2e3f5a843d33859fe4. Renato Botelho
12:51 AM pfSense Packages Bug #6084: Snort custom rule page does not update on apply
Thanks Bill Chris Buechler
12:51 AM pfSense Packages Bug #6084 (Resolved): Snort custom rule page does not update on apply
Chris Buechler
12:50 AM Feature #4881: Allow NPt to use dynamic IPv6 networks
NPT ought to allow specifying "LAN subnet", "OPT1 subnet", etc. like firewall rules and other NAT pages for source an... Chris Buechler
12:47 AM Bug #2913 (Resolved): OpenVPN servers and clients not reevaluated when gateway groups settings are saved and applied
Even further back, this was fixed by Phil via PR in 2013 and works. ... Chris Buechler
12:43 AM Bug #6181 (Feedback): Updating url alias tables fails when remote server returns empty document.
fix pushed to prevent ruleset errors in that case. It just leaves an empty file there and still includes it in the ru... Chris Buechler

07/05/2016

06:10 PM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
Phillip Davis wrote:
> Firstly the back-end implementation code should Net_IPv6:compress all IPv6 addresses in order...
Chris Buechler
05:48 PM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
Firstly the back-end implementation code should Net_IPv6:compress all IPv6 addresses in order to make sure the addres... Phillip Davis
05:19 PM Bug #6579 (Resolved): IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
If you have IPv6 CARP VIPs specified with non-significant zeros, such as fdaa:1234:0012::1, the secondary will see th... Chris Buechler
05:40 PM Bug #6580 (Confirmed): Bridge with down member interface sends ICMP unreachables where it shouldn't
Take the scenario of:
LAN: bridge0
OPT1: igb1
OPT2: igb2
where bridge0 has igb1 and igb2 members. The LAN IP ...
Chris Buechler
04:03 PM Bug #6578 (Closed): Filter reload hangs with IPsec hostnames that don't resolve configured
If you have IPsec P1s configured with a FQDN as the remote endpoint, and those don't resolve, the filter reload proce... Chris Buechler
03:49 PM Bug #5737: Traffic Graph Table and Graph Inverted Values
I was just getting ready to report this as a bug myself.
I guess my question is: how is this not considered a bug...
johnny inc
02:55 PM Bug #6260 (Resolved): Namecheap Dynamic DNS does not accept * for hostname even though it is valid
Thanks Luke.
The delay there is from dyndns's checkip service being very slow to respond, there is another ticket...
Chris Buechler
02:53 PM Bug #6399 (Resolved): Alias type not available from config during alias url table creation
works.
Thanks NOYB
Chris Buechler
01:05 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
This area could use some more work anyhow. I have to fight to get my USB GPS to be recognized at all. It appears we n... Jim Pingle
01:01 PM Feature #6573: /var/run/dmesg.boot
It was relocated because /var/run is a tiny memory disk used for some very volatile files to save disk writes, and th... Jim Pingle
12:59 PM Feature #6546: pfSense should support logging to e.g. ELK stacks
The Python prototype we have internally is now plug-and-play as filebeat and topbeat are. It uses the bulk posting AP... Bruce Simpson
09:03 AM Feature #6546: pfSense should support logging to e.g. ELK stacks
We have Python pushing log records to ELK as a rough prototype. The code is dog simple, and should be relatively easy... Bruce Simpson
11:20 AM Bug #6577 (Resolved): pkg_edit.php: rowhelper data not preserved on validation error
e.g.: Install pfBlockerNG and visit pkg_edit.php?xml=/pfblockerng/pfblockerng_v4lists.xml&id=2
Add an IPV4 list sour...
Anonymous

07/04/2016

11:23 AM Feature #6546: pfSense should support logging to e.g. ELK stacks
We have a candidate library. [[https://github.com/QHedgeTech/cpp-elasticsearch]] requires only libcurl, already in ba... Bruce Simpson
11:01 AM Feature #6546: pfSense should support logging to e.g. ELK stacks
Not as such, but we've raised CCLAs with ESF so we can get onto it.
Also, the relatively large binary footprint of...
Bruce Simpson
09:54 AM Bug #6566: Cloudflare DnyDNS Update with subdomains
Looking at this again - I don't think this would work for a subdomain such as ip.test.example.com.
It might be pos...
Euan Kerr
02:18 AM Bug #6572: Config sync hangs php-fpm on secondary
Hi Chris,
Also forgot to mention that both PFSense boxes are installed in a VMware environment. We followed the fo...
Brian Stivala
01:54 AM Bug #6572: Config sync hangs php-fpm on secondary
Hi Chris,
We would like to thank you for your reply, please find my replies in line. Do not hesitate to contact us...
Brian Stivala
12:10 AM Bug #6572 (Feedback): Config sync hangs php-fpm on secondary
The issue is php-fpm on the secondary is getting hung up on something. Going to need more info.
Does it happen on...
Chris Buechler
01:18 AM Feature #6533: Allow configuration of Min and MaxRtrAdvInterval, AdvDefaultLifetime
Hi!
Can we also set the:
Router lifetime (now 60 seconds, this is way too low)
Route lifetime, also 60 seconds a...
Greg M

07/03/2016

08:34 PM Bug #6575 (Closed): GEOM Mirror Status Change Re-sync notices
Every 1% re-sync creates a notice (and an email alert if configured as such).
Suggest re-sync start, re-sync error...
Walt McDonald
02:06 PM Feature #6574: Support USB RNDIS network interfaces
Here is the USB config descriptor as seen by Linux. Bruce Simpson
02:05 PM Feature #6574 (New): Support USB RNDIS network interfaces
TL;DR -- the FreeBSD urndis(4) driver needs some serious attention.
People cannot buy discrete ADSL2+ modem cards ...
Bruce Simpson
11:33 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Yup. I have the u-Blox 5 also in an ALIX 6D2 (older rev) and have the necessary leads soldered for 1PPS and UART. But... Bruce Simpson
11:22 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Chris Buechler wrote:
> Michael OBrien wrote:
> >
> > Still having this issue (running OpenBGPd + IPSec - transpo...
Michael OBrien
09:41 AM Feature #6573 (Resolved): /var/run/dmesg.boot
Is it possible to have a @ln -s /var/log/dmesg.boot /var/run/dmesg.boot@? The @vm-bhyve@ package expects the file at ... Jose Luis Duran

07/02/2016

11:25 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Assigned to Pingle.
Note as well that we have a (I believe) U-blox GPS receiver that interfaces to the Minnowboard...
Jim Thompson
08:29 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
I notice that there is no way to set the termios bits directly w/o hacking code. It's a possibility I may have to do ... Bruce Simpson
08:18 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
Swapped out PSU rail on my GPSDO for a discrete external PSU. I think it's still losing characters, however pfSense's... Bruce Simpson
07:57 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
See NTPD refclock 31 page: [[https://www.eecis.udel.edu/~mills/ntp/html/drivers/driver31.html]] Bruce Simpson
07:50 PM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
(This isn't working for me right now -- could be power or cabling issues)
This is just a quick and dirty patch to ...
Bruce Simpson
07:32 PM Bug #6568: NanoBSD image unconditionally enables comconsole.
NanoBSD won't be around for much longer, you're better off with a full install anyhow in the long run. If you activat... Jim Pingle
07:09 PM Bug #6568: NanoBSD image unconditionally enables comconsole.
This isn't nearly as much of a problem for me right now -- the offending system has been upgraded to use mSATA, throu... Bruce Simpson
01:46 PM Bug #6572 (Duplicate): Config sync hangs php-fpm on secondary
Hi All,
We have 2x PFSense boxes with version 2.3.1-p5 configured with CARP protocol. We have noticed and this is ...
Brian Stivala
12:11 PM pfSense Packages Bug #6571 (Resolved): NUT service can not start sometimes after boot when SNMP UPS interface is down
If NUT is started with SNMP UPS configured and UPS network or card is currently down, an error message appears
"ER...
Vladimir Suhhanov
09:39 AM Bug #6260: Namecheap Dynamic DNS does not accept * for hostname even though it is valid
Tested with pfSense-CE-2.3.2-DEVELOPMENT-amd64-20160702-0342 + Namecheap DDNS using `*` wildcard. Works! Testing was... → luckman212
04:50 AM Bug #6399: Alias type not available from config during alias url table creation
It's fixed. NOYB NOYB
04:09 AM Bug #6399 (Feedback): Alias type not available from config during alias url table creation
PR was merged Chris Buechler
04:14 AM Bug #4544 (Confirmed): PD not requested if no interfaces set to track6
updated subject is the issue. That case shouldn't cause it to skip requesting PD, for cases where the PD is actually ... Chris Buechler
02:00 AM Bug #4639 (Feedback): NAT fails to correctly translate udp port numbers embedded in certain ICMP error packets
I believe this is the issue in FreeBSD PR 201519.
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=201519
Luiz ...
Chris Buechler
12:36 AM Bug #6505 (Resolved): dpinger - socket name too large
works Chris Buechler

07/01/2016

04:35 PM Bug #6570 (Confirmed): Unbound breaks DNSSEC for pfSense's own hostname
It probably shouldn't write out anything to /etc/hosts or host_entries.conf for the host's own hostname if DHCP Regis... Chris Buechler
05:14 AM Bug #6570 (Closed): Unbound breaks DNSSEC for pfSense's own hostname
During config update, pfSense writes its own FQDN in /etc/hosts, such as:... Mantas Mikulėnas
02:07 PM Bug #3369 (Not a Bug): Captive vouchers expire too quickly
appears to be a date/time issue within the VM in this case Chris Buechler
12:25 PM Feature #6561: diag_dns.php IPv6 support
seems that now ipv4/ipv6 reverse lookup is broken Luca Moncelli
10:56 AM Feature #6546: pfSense should support logging to e.g. ELK stacks
Have you made any progress on this? I am trying to get filebeat set up on pfsense right now and ran into CLOG. :-( Nathan Stocks
10:48 AM Feature #6155: shipment of logs using e.g. filebeat
Martin Hansen wrote:
> Hi, first ever bug report, bare with me.
>
> Running filebeat on a pfsense to ship logs to...
Nathan Stocks
08:40 AM Feature #6569: Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
This is mentioned at [[http://support.ntp.org/bin/view/Support/ConfiguringJupiterRefclocks]] Bruce Simpson
03:54 AM Bug #6534: DNS resolver doesn't returns AAAA records
Resolved: now (tested on 2.3.2.a.20160630.1832) "Diagnostics / DNS Lookup" returns AAAA records.
Note: still on f...
Luca Moncelli
12:26 AM pfSense Packages Feature #6141: Convert apcupsd package to 2.3
I'm working on catching up on PRs, this one coming soon. Chris Buechler

06/30/2016

11:49 PM pfSense Packages Feature #6141: Convert apcupsd package to 2.3
Apparently someone has updated the package and it's been waiting on approval here for over a month: https://github.co... Charles Sprickman
09:14 PM pfSense Packages Bug #5511 (Feedback): quagga zebra.conf and openvpn interface
fix pushed Chris Buechler
09:02 PM Bug #6317 (Resolved): vlan/track interface generates error "Can't assign requested address" during boot
works Chris Buechler
08:57 PM Bug #6552 (Resolved): Invalid IPv6 address formats possible
looks good, validation is correct in those cases now, no apparent regressions. Thanks Phil! Chris Buechler
12:02 AM Bug #6552 (Feedback): Invalid IPv6 address formats possible
PR merged Chris Buechler
08:15 PM Bug #6530 (Resolved): Kill states doesn't work for 'in' direction
works Chris Buechler
08:15 PM Bug #6531 (Resolved): Kill states doesn't work for states with translated destination
works Chris Buechler
07:25 PM Feature #6560 (Resolved): Add php shell sessions to enable and disable Persistent CARP Maintenance Mode
works Chris Buechler
06:21 PM Feature #6569 (New): Support Rockwell ZODIAC binary protocol (Jupiter receiver) for high precision
(I will probably have a crack at doing this when time permits... I'm bedding in a GPSDO unit based on the Jupiter, wi... Bruce Simpson
06:05 PM Bug #6568 (Not a Bug): NanoBSD image unconditionally enables comconsole.
OK, first of all, I appreciate the hard work you guys have done on cleaning up the backend implementation.
However...
Bruce Simpson
04:59 PM Bug #6538: tcpdump needs update -- cannot decode most IPv6 RA options
OK, so having run headfirst into the bsdconfig wall, I had a rethink about how to express what this ticket is really ... Bruce Simpson
09:09 AM Bug #6538: tcpdump needs update -- cannot decode most IPv6 RA options
(From a strictly "consumer of tech" point of view, relying on the base system for this is probably going to cause mor... Bruce Simpson
04:22 PM Bug #6553 (Resolved): net.inet.ip.dummynet.pipe_slot_limit can't be set manually, should be automatic
works Chris Buechler
02:40 PM Bug #6364 (Resolved): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted (tried to allocate 32 bytes) in /usr/local/www/status_carp.php on line 261
works.
Thanks for the additional confirmation, Zeev.
Chris Buechler
02:14 AM Bug #6364: PHP Fatal error: Allowed memory size of 268435456 bytes exhausted (tried to allocate 32 bytes) in /usr/local/www/status_carp.php on line 261
Hello,
i added your changes and looks like it works. Chris you are the king :)
Zeev Zalessky
01:34 PM Bug #6564 (Duplicate): Alias URL TABLE(IP) failed loading when WebGUI set to HTTPS
duplicate of #4766 Chris Buechler
03:54 AM Bug #6564 (Duplicate): Alias URL TABLE(IP) failed loading when WebGUI set to HTTPS
After setting System -> Advanced -> Protocol to HTTPS
the download of Alias URL TABLES(ip) does not work anymore whe...
Stefan Heck
01:26 PM Bug #2005 (Resolved): URL aliases need validation of fetched data
this was done in pieces across several releases since then, especially in 2.3x+. Chris Buechler
01:13 PM Bug #6567 (Not a Bug): Dual Wan Gateway Monitor is offline
probably just need to set the ping payload.
https://forum.pfsense.org/index.php?topic=110043.0
no indication of ...
Chris Buechler
10:20 AM Bug #6567 (Not a Bug): Dual Wan Gateway Monitor is offline
Hello, i am running on pfsense 2.3.1_5_amd64 (latest) and when i switch on dual gateway, the gateways status is offli... Jacob Green
01:09 PM Feature #6561: diag_dns.php IPv6 support
The create alias stuff is still broken due to gethostbyname() usage. Kill Bill
11:08 AM Bug #6495: No default route on PPPoE after reconnect or IP change in some cases
Hi Chris,
system log added. :)
Thanks,
Mario (Marlenio)
Mario Lener
09:05 AM pfSense Packages Feature #6555: Support IEEE 1588
See also [[https://redmine.pfsense.org/issues/6554]] Bruce Simpson
09:01 AM pfSense Packages Feature #6555: Support IEEE 1588
Here is how I get around the lack of GUI integration at the moment.
(Requires mode7 support on loopback is re-enable...
Bruce Simpson
09:04 AM Feature #6554: Reintroduce NTP mode7 for IEEE 1588 PTPd interop
See attached hack. Bruce Simpson
07:18 AM Bug #6566 (Duplicate): Cloudflare DnyDNS Update with subdomains
If a host such as ip.example.co.uk is used for the cloudflare dynamic dns update the zone_id will fail to be returned... Euan Kerr
04:32 AM Bug #6565: OpenVPN calculates incorrect TCP checksums when running in bridged/tap mode with 'mode server'
Chris Buechler wrote:
> with tap I'm guessing? That's not the case with tun. Any IP assigned to the server itself is...
Geoff Jones
04:31 AM Bug #6565: OpenVPN calculates incorrect TCP checksums when running in bridged/tap mode with 'mode server'
with tap I'm guessing? That's not the case with tun. Any IP assigned to the server itself is affected (tap IP, LAN IP... Chris Buechler
04:17 AM Bug #6565 (Closed): OpenVPN calculates incorrect TCP checksums when running in bridged/tap mode with 'mode server'
When a connected OpenVPN client attempts to establish a TCP connection with a pfSense OpenVPN server, the server resp... Geoff Jones
04:09 AM Bug #6559: OpenVPN 'mode server' directive missing
Generated config:... Geoff Jones
04:06 AM Bug #6559: OpenVPN 'mode server' directive missing
Chris Buechler wrote:
> The config either ends up with "mode server" or "server-bridge" depending on the specifics o...
Geoff Jones
02:59 AM Bug #6515 (Resolved): link_interface_to_vips slow with large numbers of VIPs
works Chris Buechler
02:48 AM Bug #6506 (Resolved): IPv6 static routes omit interface scope of link-local gateways
works Chris Buechler
02:46 AM pfSense Packages Bug #6562: Bug/Wrong description in the squid settings
Screenshot Author: http://docs.diladele.com/ Richard Eberhard
02:39 AM pfSense Packages Bug #6562 (Not a Bug): Bug/Wrong description in the squid settings
I think there is a wrong description or maybe a bug in the "certificate adapt" option in the squid https settings. He... Richard Eberhard
02:41 AM pfSense Packages Bug #6563 (Resolved): Squid still accepts sha1 certificates
Squid still accepts sha1 certificates.(Man in the middle proxy) I think this should be blocked by default for securit... Richard Eberhard
02:39 AM Bug #6558: Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
Chris Buechler wrote:
> subject isn't true in general, 82574L in the FW-7541 correctly detects link down and up. e10...
Atlante Informatica
01:30 AM Feature #4044 (Resolved): Add UEFI support
exists and works in 2.4 Chris Buechler
01:23 AM Bug #6260 (Feedback): Namecheap Dynamic DNS does not accept * for hostname even though it is valid
merged a slightly modified fix from PR 2770
https://github.com/pfsense/pfsense/pull/2770
Not sure that suffices t...
Chris Buechler
12:23 AM Feature #6388 (Feedback): Status / Dashboard save changes for all users
merged, thanks Phil Chris Buechler

06/29/2016

11:35 PM Feature #6561 (Resolved): diag_dns.php IPv6 support
diag_dns.php lacks IPv6 support. Merged from PR 3028
https://github.com/pfsense/pfsense/pull/3028
Thought we had ...
Chris Buechler
10:46 PM Bug #6552: Invalid IPv6 address formats possible
Pull request https://github.com/pfsense/pfsense/pull/3029
Fixes handling of (what should be invalid) formats:
1:2...
Phillip Davis
10:27 PM Feature #6560 (Feedback): Add php shell sessions to enable and disable Persistent CARP Maintenance Mode
added. Since it's a trivial addition and not a feature that can introduce regressions, merged to 2_3_1 as well. Chris Buechler
07:15 PM Feature #6560 (Resolved): Add php shell sessions to enable and disable Persistent CARP Maintenance Mode
It would be very useful to be able to do this from the CLI when the GUI is unavailable. Steve Wheeler
07:42 PM Bug #6364 (Feedback): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted (tried to allocate 32 bytes) in /usr/local/www/status_carp.php on line 261
restored 2.2.x and prior's method of obtaining the nodes, which will prevent it from running out of memory. Chris Buechler
07:31 PM Bug #6551 (Resolved): Invalid IPv6 address can be entered
This all looks good now. All the test cases that were wrong previously are correct now, and no apparent regressions. Chris Buechler
04:02 PM Bug #6495: No default route on PPPoE after reconnect or IP change in some cases
Hi Chris,
new update in thread-
--
Mario (Marlenio)
Mario Lener
02:50 PM Bug #6558 (Not a Bug): Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
subject isn't true in general, 82574L in the FW-7541 correctly detects link down and up. e1000 in VMware ESX and Work... Chris Buechler
10:24 AM Bug #6558 (Not a Bug): Pf-sense 2.3 doesn't detect shutdow event with em driver and Intel Chipset 82574L
Hi All,
as described in the title, with the 2.3 version of PF-Sense when you unplug an Ethernet cable from a gigab...
Atlante Informatica
02:45 PM Bug #6559 (Feedback): OpenVPN 'mode server' directive missing
The config either ends up with "mode server" or "server-bridge" depending on the specifics of your config. That's in ... Chris Buechler
12:32 PM Bug #6559: OpenVPN 'mode server' directive missing
Jim Pingle wrote:
> What are the exact settings in use on the OpenVPN server that lead to it being omitted when yo...
Geoff Jones
12:15 PM Bug #6559: OpenVPN 'mode server' directive missing
It's not quite that simple. There are cases when it must be omitted as well, such as some tap bridge scenarios, or Op... Jim Pingle
12:09 PM Bug #6559: OpenVPN 'mode server' directive missing
Workaround is to set 'mode server' in the advanced options section. Geoff Jones
12:01 PM Bug #6559 (Not a Bug): OpenVPN 'mode server' directive missing
When creating a new OpenVPN server, the "server mode" web interface drop down does not influence the written configur... Geoff Jones
01:19 PM Bug #6557: nanobsd upgrades may fail from lacking resolv.conf
The situation where they fail is where DNS Forwarder or Resolver are not bound to localhost. If resolv.conf doesn't e... Chris Buechler
08:15 AM Bug #6540: Virtual IPs -> Edit does not allow upper-case IPv6 digits
At the moment the user can input a "full" IPv6 address "uncompressed" and it is saved just like that, e.g.:
1:2:3:4:...
Phillip Davis
04:52 AM Feature #336: Option to create lagg under assign interfaces
Just to chime in, we're in the process of upgrading loads of our pfSense installs to use LAGG from single links; this... Rob Emery
12:59 AM Bug #6317 (Feedback): vlan/track interface generates error "Can't assign requested address" during boot
PR confirmed and merged Chris Buechler

06/28/2016

11:14 PM Bug #6468: Firewall scheduler allows you to set invalid time range
@Erik: If someone puts the validation code in place to check text-entries in those boxes for validity, then they coul... Phillip Davis
04:07 PM Bug #6468: Firewall scheduler allows you to set invalid time range
@Philip: Even if it was not an intention, it was best what happened. It was definitively easier to modify one single ... Erik Ruedin
10:00 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Axel: could you email me an unsanitized copy of your dhcpd6.leases? cmb at pfsense dot org. Nothing immediately stick... Chris Buechler
04:26 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
I like to statically assign DHCPv6 addresses to some devices on my network. But finding the DUID can sometimes be cha... Axel Taferner
01:42 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
I'd have to get back to you on that -- e.g. putting a watch on the file contents. There have clearly been leases miss... Bruce Simpson
01:13 PM Bug #6543: Some leases do not show up in DHCPv6 Lease status
Need some examples, what's shown in dhcpd6.leases that doesn't show on the status page?
Chris Buechler
10:37 AM Bug #6543: Some leases do not show up in DHCPv6 Lease status
I've experienced this same issue, in my case it is not limited to mobile devices. I've had this happen with a Macbook... Axel Taferner
09:17 PM Bug #6557 (Resolved): nanobsd upgrades may fail from lacking resolv.conf
resolv.conf may not exist or be populated in the chroot of nanobsd upgrades on 2.3.x+. pkg uses that for fetching the... Chris Buechler
09:15 PM Bug #6505 (Feedback): dpinger - socket name too large
Thanks Daniel! Looks good, merged to all 3 branches. Chris Buechler
06:13 PM Bug #6505: dpinger - socket name too large
The bug has been traced down and fixed. Pull Request is up (ICLA already signed).
https://github.com/pfsense/pfsense...
Daniel Hoffend
05:10 PM Feature #6556 (Duplicate): Support Duo Security two-factor authentication for local user database
We have started evaluating Duo Security, starting with the duo-unix PAM module package.
It would be extremely usef...
Bruce Simpson
05:05 PM pfSense Packages Feature #6555 (New): Support IEEE 1588
pfSense should include a package (and GUI) for driving IEEE 1588 PTPd. This is currently available as a FreeBSD packa... Bruce Simpson
05:03 PM Feature #6554 (New): Reintroduce NTP mode7 for IEEE 1588 PTPd interop
It should be possible to selectively re-enable Mode 7 packets. This allows PTPd to take time from NTPd on the node. T... Bruce Simpson
03:46 PM Bug #6553 (Feedback): net.inet.ip.dummynet.pipe_slot_limit can't be set manually, should be automatic
fix pushed Chris Buechler
03:44 PM Bug #6553 (Resolved): net.inet.ip.dummynet.pipe_slot_limit can't be set manually, should be automatic
net.inet.ip.dummynet.pipe_slot_limit only exists after dummynet is kldloaded, which comes after the sysctls are appli... Chris Buechler
01:29 PM Bug #6551 (Feedback): Invalid IPv6 address can be entered
Chris Buechler
02:50 AM Bug #6551: Invalid IPv6 address can be entered
Pull request https://github.com/pfsense/pfsense/pull/3026 has a proposed fix and longer explanation. Phillip Davis
02:49 AM Bug #6551 (Resolved): Invalid IPv6 address can be entered
For example, add a host alias, in the IP Address or FQDN box of the 1st entry put:
1:2:3:xy:4:5:6:7:8
This is acc...
Phillip Davis
07:31 AM Bug #6552 (Resolved): Invalid IPv6 address formats possible
Add a host alias, in the IP Address or FQDN box of the 1st entry put:
1:2:3:::4:5:6:8 or 1:2:3:4:5:6:::8 or simila...
Phillip Davis
06:51 AM Bug #6550 (Not a Bug): Bandwidth LAN IN/OUT reversed
As noted above, it is correct as-is. Jim Pingle
02:46 AM Bug #6550: Bandwidth LAN IN/OUT reversed
It is correct - there is ~10 MB/s of data (download) coming in WAN (from the internet) and then that ~10 MB/s is goin... Phillip Davis
02:20 AM Bug #6550 (Not a Bug): Bandwidth LAN IN/OUT reversed
See attached screen shot.
WAN IN 10.14 MB/s
LAN OUT 10.11 MB/s
LAN IN 292.99 KB/s
LAN IN should be 10.11 MB/s
Byron Johnson

06/27/2016

08:06 PM Bug #6549 (Resolved): fstab is missing post-install
There is no /etc/fstab post-install on 2.4. Chris Buechler
08:03 PM Bug #6548 (Confirmed): Enclosed delimiters not protected in DHCP client advanced options
I was already looking at those, taking Chris Buechler
07:44 PM Bug #6548 (Resolved): Enclosed delimiters not protected in DHCP client advanced options
Issue:
Interface advanced dhcp client configuration
https://forum.pfsense.org/index.php?topic=87570
Two Availabl...
NOYB NOYB
05:53 PM Bug #6505: dpinger - socket name too large
Looking at the code from dpinger it seems that this is not something we really can count on.
https://github.com/de...
Daniel Hoffend
05:19 PM Bug #6506: IPv6 static routes omit interface scope of link-local gateways
Manuelly applied the change to my system.inc file. Seems to work. The static routes using a dynamic IPv6 WAN Gateway ... Daniel Hoffend
03:17 PM Bug #6540: Virtual IPs -> Edit does not allow upper-case IPv6 digits
Specific text is in https://tools.ietf.org/html/rfc5952#section-4.3
Kicking back to ISP (who may blame their IPAM ...
Bruce Simpson
03:09 PM Bug #6540: Virtual IPs -> Edit does not allow upper-case IPv6 digits
Good point re RFC -- I'll have to kick that back to them. It is a Standards Track RFC after all.
Bruce Simpson
01:51 PM Bug #6540: Virtual IPs -> Edit does not allow upper-case IPv6 digits
RFC 5952, uppercase is forbidden. This is true in all the screens that accept IPv6 addresses or networks.
We ough...
Chris Buechler
05:57 AM Bug #6540 (Resolved): Virtual IPs -> Edit does not allow upper-case IPv6 digits
I noticed that the address fields in the Virtual IPs edit screen reject upper-case hex digits in IPv6 addresses.
T...
Bruce Simpson
02:09 PM Bug #6535 (Not a Bug): github pullrequests, please pull or comment
we're working through them. Chris Buechler
02:01 PM Bug #6534 (Not a Bug): DNS resolver doesn't returns AAAA records
subject isn't true, there is a separate ticket for the DNS lookup page not supporting IPv6. Chris Buechler
01:53 PM pfSense Packages Feature #6537: Suricata does not autopopulate IP Reputation list from Emerging Threats on rules update
Tried importing manually, this does not work the way one would expect. Please close. John Silva
01:46 PM Bug #6538 (Not a Bug): tcpdump needs update -- cannot decode most IPv6 RA options
we ship what's included in the FreeBSD version used. Chris Buechler
05:51 AM Bug #6538 (Not a Bug): tcpdump needs update -- cannot decode most IPv6 RA options
The version of tcpdump/libpcap in 2.3.1-x is lagging; this makes debugging IPv6 turn-ups slightly more difficult.
...
Bruce Simpson
11:23 AM pfSense Packages Bug #6547 (Resolved): syslog-ng log browser only shows the first few lines
The log browser in the package tab only shows the first few lines for each log target.
Right now, it's easier to u...
Bruce Simpson
11:21 AM Feature #6546 (Closed): pfSense should support logging to e.g. ELK stacks
pfSense logging is based around the FreeBSD base system's syslogd logging daemon.
This can be tricky to integrate ...
Bruce Simpson
07:04 AM Feature #6545 (Needs Patch): Show active sessions and manually disconnect option to PPPoE server
As far as I can see, this is not currently possible with mpd. If you need this sort of functionality, you'll have to ... Jim Pingle
06:57 AM Feature #6545 (Needs Patch): Show active sessions and manually disconnect option to PPPoE server
Hello,
It will be great to have "Users Logged In" option to PPPoE server services as Captive portal.
It could h...
Joel AGBESSI
06:55 AM Bug #6541: IPv6 RAs always include on-link prefix; clients may not use DHCPv6 managed addresses
First two sentences above are reversed -- my bad.
TL;DR -- a Cisco will let you advertise 'M' *and only 'M'*, caus...
Bruce Simpson
06:04 AM Bug #6541 (New): IPv6 RAs always include on-link prefix; clients may not use DHCPv6 managed addresses
pfSense IPv6 RA support in 2.3.1-x correctly includes the 'M' (Managed) bit in its advertisements.
By contrast, Ci...
Bruce Simpson
06:12 AM Feature #6544 (New): RFC 3046 DHCP Option 82 support (and RFC 3315/4649/4580 for IPv6)
We use an HPE switch to implement MAC layer security. It is configured to snoop DHCP request & inject Option 82 (RFC ... Bruce Simpson
06:07 AM Bug #6543 (Resolved): Some leases do not show up in DHCPv6 Lease status
I have noticed from time-to-time that some IPv6 devices have taken a DHCPv6 dynamic lease, and do not show up in the ... Bruce Simpson
06:05 AM Bug #6542 (Closed): Cannot revoke DHCPv6 leases from the GUI
(We understand there's a fix in progress for this, at least for IPv4.)
The DHCPv6 lease status tab lacks an option...
Bruce Simpson
05:55 AM Feature #6539 (New): ICMPv6 filtering requires multiple rules - no range support
(This may also be a shortcoming in PF itself).
Currently there is no way to specify an ICMPv6 type range in the GU...
Bruce Simpson

06/26/2016

01:31 PM Bug #6534: DNS resolver doesn't returns AAAA records
oh.. maybe for the same reason is not possible to resolve ipv6 addresses in firewall log... Luca Moncelli
11:43 AM Bug #6536 (Resolved): update + reboot, did not trigger the webgui 90 second countdown
Anonymous
10:23 AM Bug #6536: update + reboot, did not trigger the webgui 90 second countdown
Oké thanks, confirmed fixed when i updated today to "built on Sun Jun 26 08:40:49 CDT 2016" it worked as expected. Pi Ba
 

Also available in: Atom