Project

General

Profile

Activity

From 08/29/2016 to 09/27/2016

09/27/2016

03:54 PM Revision e936f18c: Bump PRODUCT_REVISION
Renato Botelho
12:38 PM Revision 580bef1e: Fix static blackhole routes. Bug was introduced in
8be135cd114fbc9294ec9dafed2125d0e553956c (February, 2013). Leland Roach
12:21 PM Revision 9b42c1ff: Make serial/UUID bold
Renato Botelho
12:21 PM Revision ba868cff: Make serial/UUID bold
Renato Botelho
12:20 PM Revision 6972e2fc: Make serial/UUID bold
Renato Botelho
12:09 PM Revision 27663052: Show system platform and serial / UUID
Renato Botelho
12:09 PM Revision e093cb8e: Show system platform and serial / UUID
Renato Botelho
12:09 PM Revision d91d2bbc: Show system platform and serial / UUID
Renato Botelho
11:21 AM Revision c746f6b5: If umount fails, use umount -f
Renato Botelho
11:21 AM Revision 32918935: If umount fails, use umount -f
Renato Botelho
09:17 AM pfSense Packages Bug #6818: WAN traffic graph displays inverted bandwidth columns
Phillip Davis wrote:
> And that image is correct for the current traffic graph system (2.3.2). For example, the 3rd ...
Daniele Sorrenti
09:15 AM pfSense Packages Bug #6818: WAN traffic graph displays inverted bandwidth columns
Jim Pingle wrote:
> Check again on a 2.3.3 or 2.4 snapshot those graphs have been replaced.
Thank you. It is a cr...
Daniele Sorrenti
07:43 AM pfSense Packages Bug #6818: WAN traffic graph displays inverted bandwidth columns
And that image is correct for the current traffic graph system (2.3.2). For example, the 3rd host down in the table i... Phillip Davis
07:19 AM pfSense Packages Bug #6818 (Feedback): WAN traffic graph displays inverted bandwidth columns
Check again on a 2.3.3 or 2.4 snapshot those graphs have been replaced. Jim Pingle
04:00 AM pfSense Packages Bug #6818 (Not a Bug): WAN traffic graph displays inverted bandwidth columns
Open Traffic Graph and select WAN interface.
On the graph, BW IN and OUT values are correct. In the Bandwidth In / B...
Daniele Sorrenti
06:32 AM Feature #6817 (Duplicate): DHCP server service that can serve leases on networks that are not directly connected to pfsense or "central dhcp server"
Jim Pingle
01:58 AM Feature #6817: DHCP server service that can serve leases on networks that are not directly connected to pfsense or "central dhcp server"
Duplicate of #2774 Kill Bill
06:29 AM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Updated subject to match error message/condition. Jim Pingle
06:28 AM Bug #6819 (Duplicate): Cannot edit rules using Google Chrome
Duplicate of #6762 Jim Pingle
05:04 AM Bug #6819 (Duplicate): Cannot edit rules using Google Chrome
After upgrade from 2.2.6 to 2.3.2, I'm not more able to edit a rule using Google Chrome. When I press save, the addre... Daniele Sorrenti
04:02 AM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
As a follow up - it appears that after openvpn_resync_all(), nothing else below that function call could run from the... Kill Bill
02:20 AM Feature #2774: Extend DHCP Pools code to allow using different subnets
The first time I used pfsense I was surprised to see that it can do dhcp relay but not the other side of the coin tha... david stievenard

09/26/2016

11:42 PM Feature #6817 (Duplicate): DHCP server service that can serve leases on networks that are not directly connected to pfsense or "central dhcp server"

I prefer keeping 'unfiltered vlans' traffic being routed by a l3 switch that is connected to pfsense with a /29 or ...
david stievenard
06:29 PM pfSense Packages Bug #6814: pfBlockerNG cannot define table pfB_Europe_v6 after pfsense upgrade to 2.3.2-RELEASE (amd64)
Thank you @BBcan177, my pfsense Firewall Maximum Table Entries were set on default (20mb) I increased the entries to... yunior alvarez
06:15 PM Revision 406a904b: Obscure RADIUS shared secret.
Jim Pingle
06:15 PM Revision ebeddac7: Obscure RADIUS shared secret.
Jim Pingle
06:14 PM Revision 66f6f151: Obscure RADIUS shared secret.
Jim Pingle
06:14 PM Revision 49db5ba1: Obscured password field in system_authservers.php bind section
Fixed #6759
(cherry picked from commit 1c1f08f92e8841f7282280caeed7613edd810453)
Stephen Beaver
04:14 PM Revision e67157be: wbr tag needs a css compatibility fix for some browsers
See comment in the PR Stilez y
04:07 PM Feature #6816 (New): Status and/or Diagnostics page for radvd
Would be nice to have a status or diagnostics page for radvd Corey Boyle
02:31 PM Bug #6813 (Resolved): 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Renato Botelho
02:11 PM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Fixed, thanks. Kill Bill
07:30 AM Bug #6813 (Feedback): 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
A fix was committed in FreeBSD and now imported to our repo. Next round of snapshots should be fixed
https://svnwe...
Renato Botelho
11:10 AM Bug #6637 (Feedback): pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
Patch from FreeBSD ticket 207598 was imported to pfSense/FreeBSD-src. Today's 2.3.3-DEVELOPMENT snapshot already has ... Renato Botelho
10:27 AM Bug #6815 (Duplicate): Form validation for DNS entries on /services_router_advertisements.php
Duplicate of #6762 Jim Pingle
10:26 AM Bug #6815 (Duplicate): Form validation for DNS entries on /services_router_advertisements.php
Keep getting "Please match the requested format" when trying to enter my addresses. Corey Boyle

09/25/2016

11:28 PM pfSense Packages Bug #6814: pfBlockerNG cannot define table pfB_Europe_v6 after pfsense upgrade to 2.3.2-RELEASE (amd64)
Increase the pfSense Advanced / Firewall-NAT / Firewall Maximum Table Entries to 10M entries... BBcan177 .
05:59 AM pfSense Packages Bug #6814: pfBlockerNG cannot define table pfB_Europe_v6 after pfsense upgrade to 2.3.2-RELEASE (amd64)
You either don't have enough RAM, or you don't have large-enough limit set for tables. Either way, nothing that could... Kill Bill
01:55 AM pfSense Packages Bug #6814 (Not a Bug): pfBlockerNG cannot define table pfB_Europe_v6 after pfsense upgrade to 2.3.2-RELEASE (amd64)
Pfsense version:
2.3.2-RELEASE (amd64)
built on Tue Jul 19 12:44:43 CDT 2016
FreeBSD 10.3-RELEASE-p5
Package
p...
yunior alvarez
02:01 PM Revision 9a2d3fe1: Simplify logic
Stilez y
10:00 AM Revision b9b6841f: Remove unused arg in get_pkg_info()
The 2nd argument ($info) isn't used in that function, and doesn't seem to be used anywhere else in the codebase. Stilez y

09/24/2016

03:08 PM Revision 6db038f7: Ensure a mobile P2 is marked as such when saving.
Jim Pingle
03:08 PM Revision 778fc728: Ensure a mobile P2 is marked as such when saving.
Jim Pingle
03:08 PM Revision 9033b17c: Ensure a mobile P2 is marked as such when saving.
Jim Pingle
02:34 PM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
All the crashes here seem to be OpenVPN related.
Calling openvpn_resync_all() causes php-cgi to crash on boot, whi...
Kill Bill
11:54 AM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Pull it :| Greg M
11:09 AM Bug #6813 (Confirmed): 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Setup a new VM as a clean test. Works on a snap from the 22nd, same one updated to the 23rd breaks in various ways. T... Jim Pingle
09:14 AM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Also, OpenVPN is completely no-op, producing just segfaults.
https://forum.pfsense.org/index.php?topic=118709.0
Kill Bill
09:02 AM Bug #6813: 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
Err, "only via IPv4". Whatever. Kill Bill
09:02 AM Bug #6813 (Resolved): 2.3.3 built on Fri Sep 23 11:34:50 CDT 2016 - segfaulting processes result in non-functional system
https://forum.pfsense.org/index.php?topic=118714.0
No default routes configured, I can SSH in remotely only via IP...
Kill Bill
08:56 AM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Phillip Davis wrote:
> Of course, anyone can upgrade to the 2.3.3-DEVELOPMENT snapshots. Actually they are really go...
Kill Bill
08:43 AM Bug #6812 (Not a Bug): IPsec filterdns crash
This appears intermittently in the system logs:
Sep 24 00:27:13 php-fpm 73703 /rc.newipsecdns: The command '/us...
Anonymous

09/23/2016

07:52 PM Bug #6751: Route53 DynDNS Problems / Replace Route53 DynDNS Module
Filed a pull request in Github Jason McCormick
07:27 PM Revision 348fae16: Format file_notice alerts in webgui with newline characters as <br/> for easier reading.
Pi Ba
07:20 PM Revision 9a966125: Use wider display for pftop to fill up dead area. Output still looks OK with narrower terminals as well.
Some views were omitting important info at the narrower width Jim Pingle
07:20 PM Revision 5ae2585b: Use wider display for pftop to fill up dead area. Output still looks OK with narrower terminals as well.
Some views were omitting important info at the narrower width Jim Pingle
07:19 PM Revision 4281c964: Use wider display for pftop to fill up dead area. Output still looks OK with narrower terminals as well.
Some views were omitting important info at the narrower width Jim Pingle
02:44 PM Bug #6811 (Resolved): pkg_edit.php rowhelper is broken with multiple distinct rowhelpers per page.
A Row Helper Name is hardcoded in pkg_edit.php.
I don't know why, but the effect of this is that a single page can...
Josh Galvez
01:14 PM Revision 5116a8aa: Fix bug where CARP vip status is incorrent in the interface when more
than one CARP vip is configured for an interface. Fredrik Rönnvall
11:19 AM Bug #6724 (Resolved): VLAN interface displayed wrong through interface assignment
Works, following the example given it prints the interface name correctly. Jim Pingle
11:16 AM Bug #6505 (Resolved): dpinger - socket name too large
Jim Pingle
10:51 AM Bug #6713 (Resolved): diag_tables table or alias or database?
Fixed Jim Pingle
10:47 AM Bug #6798 (Rejected): pevent_ctx_main: poll: Invalid argument
Please start a forum thread for discussion and troubleshooting, there isn't enough information here to classify it as... Jim Pingle
10:32 AM Bug #6788 (Resolved): [2.3.3] Services - NTP - Settings: Prefer/No Select checkboxes invisible when adding entries
Works Jim Pingle
10:30 AM Bug #6780 (Resolved): status_logs_settings.php / system.inc: Remote syslog options need to catch up with changes in syslog config
Done, working. Jim Pingle
10:25 AM Bug #6762 (Resolved): "Please match the requested format" error in Chrome when editing certain form fields
Confirmed fixed by multiple sources. Jim Pingle
10:23 AM Bug #6737 (Resolved): diag_dns.php: DNS results printed without encoding, leading to an XSS
Jim Pingle
10:22 AM Bug #6720 (Resolved): DHCPD Options in "Sub-"Pools ignored, dhcpd.conf does not contain informations, dhcpd therefore not serving
Fixed, per above feedback Jim Pingle
10:21 AM Bug #6715 (Resolved): diag_traceroute.php suggestions
Fixed Jim Pingle
10:21 AM Bug #6708 (Resolved): diag_sockets wrong info
Fixed Jim Pingle
10:16 AM Bug #6652 (Resolved): Filtering system logs doesn't include all log entries
Works here. Jim Pingle
10:16 AM Bug #6646 (Resolved): "Reject leases from" on interfaces.php only accepts IPs
I fixed the description. The underlying daemon does not accept subnets, only IP addresses, so the description has bee... Jim Pingle
10:14 AM Bug #6810 (Duplicate): bsnmpd logspam - hrPrinterTable: printcap entry for <noname?> has errors, skipping
hrPrinterTable: printcap entry for <noname?> has errors, skipping
Been flooding the logs since 2007 at least. Perh...
Kill Bill
10:13 AM Bug #6643 (Resolved): /usr/bin/install missing from new 2.3.2 installations
New installs on snapshots are fine, fixes are on existing packages for current versions so it's addressed from a user... Jim Pingle
10:13 AM Bug #6640 (Resolved): DHCPv6 Server Time Format Change Reversed
Resolved per above feedback Jim Pingle
10:11 AM Bug #6601 (Resolved): Horizontal scroll bar on Installed Packages
Works. Jim Pingle
09:39 AM Revision b2ee641c: Add a workaround to umount virtual image directories
Renato Botelho
09:39 AM Revision ed245829: Add a workaround to umount virtual image directories
Renato Botelho
07:54 AM pfSense Packages Bug #6807: Softflowd + multiplie interfaces
OK, the project is dead
What are the alternatives? (netFlow)
Konstantin Ab
06:55 AM pfSense Packages Bug #6807 (Rejected): Softflowd + multiplie interfaces
That would be a bug in softflowd, not one we can fix. We are passing all of the correct parameters to it. If it's usi... Jim Pingle
01:52 AM pfSense Packages Bug #6807 (Rejected): Softflowd + multiplie interfaces
There are problems in the softflowd.
Always send information only from one interface. And his number is always 0.
...
Konstantin Ab
07:32 AM Bug #6809 (Rejected): IPSEC connection does not pass the state "CONNECTING"
Please post on the forum for help diagnosing the issue until a definite bug can be identified. It could still be a co... Jim Pingle
07:27 AM Bug #6809 (Rejected): IPSEC connection does not pass the state "CONNECTING"
i have a have a IPSEC connection to fortigate, this connection not work after the upgrade to 2.3, 2.2 versions worked... Andres Gomez
06:51 AM Bug #6808 (Duplicate): Can't add firewall rule
Jim Pingle
06:05 AM Bug #6808: Can't add firewall rule
Duplicate of #6762.
Kill Bill
02:15 AM Bug #6808 (Duplicate): Can't add firewall rule
Hi,
I can't add firewall rule when using Network or IP,alias distination.
The chrome console show me a regex er...
Fabien Duay
06:16 AM Bug #5319: Error message "No config named" in charon daemon
I can confirm this issue that is still present in 2.3.1-RELEASE-p5 :... Stephen Morri
04:12 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Hey all,
Do we know exactly what causes this yet?
Reason i ask is i have just had a 2.2.6 machine have this (be...
Jon Hayward

09/22/2016

10:15 PM Revision c52bf794: Revert "Implement _umount() for cases where filesystem umount doesn't work"
This reverts commit 89e9960e34737c027d7fb0516d7183dc0a37f391. Renato Botelho
10:15 PM Revision 6da18e2a: Revert "Use _umount()"
This reverts commit c09203c2ba6bf10332fe432b72e7e57c2f20cf18. Renato Botelho
10:15 PM Revision 5084361d: Revert "Implement _umount() for cases where filesystem umount doesn't work"
This reverts commit be1eff2b4ba57c8f97128dacefb5271549c16d51. Renato Botelho
09:38 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
I made a suggestion that it is a good time to cut a 2.3.3 release:
https://forum.pfsense.org/index.php?topic=118670....
Phillip Davis
03:09 AM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Notably, this gets triggered on : as well, complete no go with IPv6. Kill Bill
03:08 AM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
This needs to be released. Damn annoying and Chrome fix nowhere in sight - https://bugs.chromium.org/p/chromium/issue... Kill Bill
09:37 PM Revision c09203c2: Use _umount()
Renato Botelho
09:36 PM Revision 89e9960e: Implement _umount() for cases where filesystem umount doesn't work
Renato Botelho
09:36 PM Revision be1eff2b: Implement _umount() for cases where filesystem umount doesn't work
Renato Botelho
03:39 PM Bug #6803: CSRF timeout occurs when it (probably) shouldn't
I was wondering about it too. I don't know if either of these ideas go anywhere.....
* The value set by csrf_conf(...
Stilez y
02:14 PM Bug #6803: CSRF timeout occurs when it (probably) shouldn't
Yeah I see that now. I tested it earlier by setting $config['system']['webgui']['session_timeout']=2 at the top of th... Jim Pingle
02:06 PM Bug #6803: CSRF timeout occurs when it (probably) shouldn't
@jimp - the fix above doesn't work, because $config only becomnes defined when authgui.inc is included, which is afte... Stilez y
07:24 AM Bug #6803: CSRF timeout occurs when it (probably) shouldn't
One bug to be fixed at least - it's now clear why CSRF times out incorrectly:
In guiconfig.inc, csrf_startup() che...
Stilez y
03:20 PM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
Ok, I am using pfSense 2.3.2 (latest) and I get the silly p appended to the default domain. Can someone look into th... Mario Jauvin
01:16 PM Revision 4011b716: Declare $config as a global in guiconfig.inc csrf_startup() function, to properly respect the timeouts. Ticket #6803
Jim Pingle
01:16 PM Revision e0d81869: Declare $config as a global in guiconfig.inc csrf_startup() function, to properly respect the timeouts. Ticket #6803
Jim Pingle
01:15 PM Revision efa9174a: Declare $config as a global in guiconfig.inc csrf_startup() function, to properly respect the timeouts. Ticket #6803
Jim Pingle
04:54 AM Revision c68dbfc7: Allow Hyphens in DHCP NTP Server form validation
Also removes the ability to have underscores `_` in ntp server
FQDNs.
Closes #6806
Eddie Hurtig
12:00 AM Bug #6806: Form validation for DHCP NTP Servers does not allow hyphens
https://github.com/pfsense/pfsense/pull/3151 (CLA was just signed so might not be labeled appropriately yet) Edward Hurtig

09/21/2016

11:38 PM Bug #6806 (Resolved): Form validation for DHCP NTP Servers does not allow hyphens
Form validation in the dashboard does not use the proper regex for FQDNs (it doesn't allow hyphens)... Edward Hurtig
11:31 PM Bug #6239: DHCP server NTP fields should allow hostnames
Chris Buechler wrote:
> works
Form validation does now allow hyphens in the NTP server name
Separate Issue Inc...
Edward Hurtig
09:41 PM pfSense Packages Bug #6805 (Duplicate): Freeradius + OTP sometimes auth failed when auth openvpn.
Hello,
I have test freeradius + OTP to auth openvpn connect.It's can connect and auth it.But it's has sometimes auth...
akong wu
09:23 PM Feature #6804 (New): Add row counter into Diagnostics -> Edit File
Will be extremely helpful if the rows in the Diagnostics -> Edit File window are presented with a number.
In this ...
TCI User
07:39 PM Revision 47180823: Spelling mistake "system_gateways.php"
Fix spelling mistake in "system_gateways.php" Colin Fleming
05:47 PM Revision c2b72200: Apply #601 fix to firewall_nat.php
(cherry picked from commit 4b0815f38a8a0f98519ca0c2bff7c81b6464e579) Steve Beaver
05:46 PM Revision baa6302a: Apply #601 fix to firewall_nat.php
(cherry picked from commit 4b0815f38a8a0f98519ca0c2bff7c81b6464e579) Steve Beaver
05:46 PM Revision 4b0815f3: Apply #601 fix to firewall_nat.php
Steve Beaver
04:10 PM Revision 7dd9db77: Fixed #6801
(cherry picked from commit 00098bc80b6f85eb74f2f3bc2b4eb7430614110d) Steve Beaver
04:10 PM Revision 83b4b514: Fixed #6801
(cherry picked from commit 00098bc80b6f85eb74f2f3bc2b4eb7430614110d) Steve Beaver
04:09 PM Revision 00098bc8: Fixed #6801
Steve Beaver
03:26 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Steve Allison wrote:
> FYI, this "[a-zA-Z0-9_.:]+" is the same as ".+". Perhaps only : or _ needs escaping?
No it...
Jim Pingle
03:20 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
FYI, this "[a-zA-Z0-9_.:]+" is the same as ".+". Perhaps only : or _ needs escaping? Steve Allison
03:12 PM Bug #6657: Unable to add network in the source section of a LAN firewall rule
It is not a bug in our code. It is a bug in Chrome that we have worked around by removing escaping from the regular e... Jim Pingle
03:08 PM Bug #6657: Unable to add network in the source section of a LAN firewall rule
So from Jon Gerdes explanation, this should be adjusted to "Bug" as pfSense is using invalid HTML5? Just not apparent... Steve Allison
12:50 PM pfSense Packages Bug #6182: HAProxy not supporting ALPN
That doesn't however allow access to new openssl 1.1 features like ALPN.
Haproxy used to build not using the freebsd...
Pi Ba
12:44 PM pfSense Packages Bug #6182: HAProxy not supporting ALPN
We use the OpenSSL version provided in the base system of FreeBSD 10.3, which is maintained by FreeBSD. If/when FreeB... Jim Pingle
12:17 PM pfSense Packages Bug #6182: HAProxy not supporting ALPN
This is not a HAProxy issue, this is an entire pfSense issue. Because openssl in pfSense was reverted from 1.0.2 to 1... Vincent Milum
12:48 PM Bug #6801 (Resolved): Rule separators are moving when multiple firewall rules are deleted together
Thanks for confirming. Fix has now been applied to firewall_nat.php as well. Anonymous
12:15 PM Bug #6801: Rule separators are moving when multiple firewall rules are deleted together
Thank you Steve / Jim.
I found it safer to apply the changes through Diagnostics -> Edit file.
Confirming that ...
TCI User
11:49 AM Bug #6801: Rule separators are moving when multiple firewall rules are deleted together
The wiki doc for the System Patches package explains how to use the commit ID from the above comment to apply the pat... Jim Pingle
11:43 AM Bug #6801: Rule separators are moving when multiple firewall rules are deleted together
Probably easiest to just wait from the next snapshot and update. Alternatively you could access the updated file here... Anonymous
11:25 AM Bug #6801: Rule separators are moving when multiple firewall rules are deleted together
Steve Beaver wrote:
> Applied in changeset commit:00098bc80b6f85eb74f2f3bc2b4eb7430614110d.
Steve, would you prov...
TCI User
11:20 AM Bug #6801: Rule separators are moving when multiple firewall rules are deleted together
Applied in changeset commit:00098bc80b6f85eb74f2f3bc2b4eb7430614110d. Anonymous
11:11 AM Bug #6801 (Feedback): Rule separators are moving when multiple firewall rules are deleted together
Fixed and tested. Please confirm. Anonymous
08:36 AM Bug #6801 (Resolved): Rule separators are moving when multiple firewall rules are deleted together
Steps to reproduce:
1. Select multiple firewall rules
2. Delete together
3. The rule separators changed their po...
TCI User
12:48 PM Bug #6803 (New): CSRF timeout occurs when it (probably) shouldn't
+Expected behaviour and error+
A feature/change in release 2.1 was that CSRF timeout was changed to be the same as...
Stilez y
12:32 PM Revision 02a4d858: Do not show certificates in drop-down list that are already contained in this CRL.
skrude61
12:32 PM Revision 419cfa1e: Do not show certificates in drop-down list that are already contained in this CRL.
skrude61
12:31 PM Revision 8b52bd15: Merge pull request #3148 from skrude61/certificate_revocation
Jim Pingle
11:25 AM Bug #6802 (Rejected): GUI does not respond and vpn stops working
Since I update the firewall to 2.3.x (actualy 2.3.2) Some times GUI does't respond and VPN client are disconnected un... Ricardo ot
06:32 AM Feature #6800 (Rejected): Feature request: Logon to remember the URL that initiated the logon sequence and return to it
We used to do that, but ultimately decided against it as it was a potential security issue. We might be able to revis... Jim Pingle
06:03 AM Feature #6800 (Rejected): Feature request: Logon to remember the URL that initiated the logon sequence and return to it
When not logged on and entering my pfSense on a specific URL like https://192.168.99.254/status_dhcp_leases.php it sh... Jeroen Pluimers

09/20/2016

07:45 PM Revision 70567933: lowercasing and sprintf of setHelp
Stilez y
05:30 PM Revision 3c2b0a83: Move pkg repo templates to main repo
Renato Botelho
05:25 PM Revision c6a531b8: Move pkg repo templates to main repo
Renato Botelho
01:02 PM Revision 31cade55: Add missing \) and fix syntax
Renato Botelho
01:02 PM Revision e237bddb: Add missing \) and fix syntax
Renato Botelho
01:02 PM Revision ad49da1b: Add missing \) and fix syntax
Renato Botelho
12:52 PM Revision 63844c33: Do not show certificates in drop-down list that are already contained in this CRL.
skrude61
12:39 PM Revision 99f3f2ee: Extra "S" fixed - thanks @rbgarga
(cherry picked from commit d20b69c529654f2b5d4adf9ab2bba5116f980c64) Stilez y
12:39 PM Revision 1ee8e01b: Add OpenVPN key lengths to Wizard - missed in original PRs
Original PRs and rationale:
* https://github.com/pfsense/pfsense/pull/2944 ("Add missing recommended key lengths/dig...
Stilez y
12:39 PM Revision d73092b2: Merge pull request #3142 from stilez/patch-40
Renato Botelho
10:27 AM Bug #6799 (Resolved): Negating ``<interface> net`` when a VIP exists on the interface results in unintended behavior
LAN Interface: 172.25.232.1/24
IP Alias VIP on LAN: 10.10.10.10/32
OPT1 Interface: 192.168.1.1/24
Some users lik...
Chris Linstruth
10:16 AM Revision e9c8e24e: Sanitize 'zone' parameter on CP pages
Renato Botelho
10:16 AM Revision 35372937: Sanitize 'zone' parameter on CP pages
Renato Botelho
10:16 AM Revision ab4b6ea4: Sanitize 'zone' parameter on CP pages
Renato Botelho
08:40 AM pfSense Packages Bug #6797 (Feedback): Shared Key Export - just one server in list
Fix pushed, will show up next time the packages are built. Jim Pingle
08:22 AM pfSense Packages Bug #6797 (Assigned): Shared Key Export - just one server in list
Jim Pingle
04:14 AM pfSense Packages Bug #6797 (Resolved): Shared Key Export - just one server in list
There is a typo error in vpn_openvpn_export_shared.php line 191 that causes just one server to be displayed in the Sh... Vitaly Virkunen
08:26 AM Revision df8ebedc: Allow snmpd to bind to multiple interfaces.
skrude61
04:49 AM Bug #6798 (Rejected): pevent_ctx_main: poll: Invalid argument
After reboot PPPoE connection wasn't established. See attached log.
pfSense 2.3.2 x64.
Dmitriy K

09/19/2016

09:05 PM Revision d20b69c5: Extra "S" fixed - thanks @rbgarga
Stilez y
07:31 PM Revision 377898f1: Show a little more key info in main info table
* Key crypto info shown
* TAP/TUN appended to description (important descriptive distinction)
(cherry picked from com...
Stilez y
07:31 PM Revision 8117e7fb: Merge pull request #3143 from stilez/patch-41
Renato Botelho
05:24 PM Feature #6796 (New): Allow hostnames as GRE and GIF endpoints
Currently only IP endpoints are allowed. The hostnames need to be resolved and the interfaces updated on a regular ba... Jorge Albarenque
10:02 AM Feature #6795 (Duplicate): User certificate for webGUI login
It would be practical to allow the administrator to enable user certificate required for webGUI signin.
This would a...
Andrew Webster
03:02 AM Feature #6794 (Resolved): Chinese Version Language Translation
mkdir
/src/usr/local/share/locale/cn/LC_MESSAGES/
Dear Administrator
Given China's administrator easy to use, c...
jeans bear

09/18/2016

08:25 PM Revision b1919bc7: Show a little more key info in main info table
* Key crypto info shown
* TAP/TUN appended to description (important descriptive distinction)
Stilez y
07:30 PM Revision f8d6f99d: Add OpenVPN key lengths to Wizard - missed in original PRs
Original PRs and rationale:
* https://github.com/pfsense/pfsense/pull/2944 ("Add missing recommended key lengths/dig...
Stilez y
02:48 PM Bug #6725: DHCP Server > TFTP server name and custom dhcp options in GUI and in dhcpd.conf but missing on the wire
Looks like there may have been a problem with my client not requesting the custom attribute. After messing with dhcli... Jules Hoehn
02:27 PM Feature #6793 (Resolved): Add pound package to the pfSense repository
Dear devs,
Please add the "pound" package to the pfSense's own repository so that anyone can install it without ha...
robi robi
11:24 AM Bug #6099: igmpproxy does not recognize upstream interface
Hi,
first of all, thank you very much for your hard work!
Due to missing IPTV (I just ordered it last week) I i...
Dora Paula
07:55 AM Revision 91822dc6: move implode() to same line as previous change
Stilez y
07:52 AM Revision 16b91b19: simplify avoiding loop. Also localise with gettext()
Stilez y
05:04 AM Bug #6507: GRE and GIF tunnels on dynamic IPv6 interface are not brought up during boot
I've tried to dig into this again. There some things I've noticed.
1) it looks like the binary "check_reload_statu...
Daniel Hoffend

09/16/2016

08:01 PM Revision a309ffa5: label src/dst incorrect - fixed (minor)
Stilez y
07:31 PM Revision a5e6c252: Prepare pfSense-upgrade to work with new major OS upgrade
Renato Botelho
07:31 PM Revision 3a4bae52: Add 'now' parameter do do_reboot() to force it to happen immediately
Renato Botelho
07:31 PM Revision 0fd71e83: Make pkg_lock() and pkg_unlock() work with wildcards
Renato Botelho
07:31 PM Revision 05100687: Prepare pfSense-upgrade to work with new major OS upgrade
Renato Botelho
07:29 PM Revision 6656b888: Add 'now' parameter do do_reboot() to force it to happen immediately
Renato Botelho
07:23 PM Revision d5be878f: Make pkg_lock() and pkg_unlock() work with wildcards
Renato Botelho
06:57 PM Revision d99ceeac: UI improvement - src port button label and src port help msgs
1. Rename "srcportadv" to "srcporttoggle" - not ideal to have 2 fields both labelled "advanced options". This present... Stilez y
04:40 PM Revision bb8e381a: Merge pull request #3137 from NOYB/Secure_SMTP_Connection_Modes_-_Mutually_Exclusive
Renato Botelho
03:13 PM Revision 561463d2: Do not obsolete extensions.ini to avoid lots of noise on pkg deinstall scripts
Renato Botelho
03:07 PM Revision 678004ce: Remove pre/post upgrade scripts
Thise scripts were used on tarball upgrade before pkg(8). Users running
pfSense < 2.3 will need to go to 2.3 first an...
Renato Botelho
03:05 PM Bug #6792: Cannot edit or add firewall rules, error: Please match the requested format
No problem in latest Firefox 48.0.2.
Problem exists for me in latest Chrome Version 53.0.2785.116 m both normal an...
Amy Alvarez
03:01 PM Bug #6792 (Duplicate): Cannot edit or add firewall rules, error: Please match the requested format
Duplicate of #6762 (applies to multiple pages)
It is a bug in Chrome's regex parsing that they let into their late...
Jim Pingle
02:58 PM Bug #6792 (Duplicate): Cannot edit or add firewall rules, error: Please match the requested format
Suddenly I'm getting an error of "Please match the requested format" when I try to use an alias or ip address for a t... Amy Alvarez
03:02 PM Bug #6762 (Feedback): "Please match the requested format" error in Chrome when editing certain form fields
Setting to Feedback since the relevant fix has already been committed. Jim Pingle
07:55 AM Bug #6791 (Rejected): Upgrade 2.2.6 > 2.3.2 had broken LDAP authentication
The bind credentials field is covered by #6759 and has already been fixed in the repository.
If your LDAP users ca...
Jim Pingle
07:43 AM Bug #6791 (Rejected): Upgrade 2.2.6 > 2.3.2 had broken LDAP authentication
Hi,
I jut want to declare the following bug that we had discovered:
We upgraded one of our test firewall from...
m de crevoisier
07:02 AM Bug #6790 (Duplicate): Password is in plain text under "System -> User -> ManagerAuthentication" Type LDAP under "Bind credentials"
Already fixed in the repository. This is a duplicate of #6759 Jim Pingle
06:57 AM Bug #6790 (Duplicate): Password is in plain text under "System -> User -> ManagerAuthentication" Type LDAP under "Bind credentials"
Hello,
There is a plain text box input for password field.
As such it's letting the password readable by anyone.
...
Basile Caillens

09/15/2016

08:28 PM Revision 8d1b677a: Create also an altabi file on repo package
Renato Botelho
08:28 PM Revision 3cd56f54: Create also an altabi file on repo package
Renato Botelho
08:27 PM Revision 8da986eb: Replace %%ARCH%% by arch on ABI file
Renato Botelho
08:27 PM Revision 16a48677: Replace %%ARCH%% by arch on ABI file
Renato Botelho
06:27 PM Revision c3eaf962: Correct indentation.
NOYB NOYB
05:29 PM Revision 1f8f4c49: Fix variable name
Renato Botelho
05:28 PM Revision c91a9922: Fix variable name
Renato Botelho
05:12 PM Revision 640462d2: Bugfixes
1. On creating a new rule, $pconfig['ipprotocol'] is undefined, rather than defaults to what is seen in GUI (IPv4). F... Stilez y
05:02 PM Revision 3f492b85: Fixed #6786 by making table sortable
(cherry picked from commit e846d7f882d57331d7ead5fcf593e7e4daf7e247) Steve Beaver
04:41 PM Revision e846d7f8: Fixed #6786 by making table sortable
Steve Beaver
04:04 PM Revision 04e21f3e: Distribute a file containing ABI of each repo
Renato Botelho
04:04 PM Revision 1c535323: Simplify logic and remove duplicated code
Renato Botelho
04:04 PM Revision 5f49bd63: Distribute a file containing ABI of each repo
Renato Botelho
04:01 PM Revision 1ca26242: Simplify logic and remove duplicated code
Renato Botelho
03:12 PM Bug #6788: [2.3.3] Services - NTP - Settings: Prefer/No Select checkboxes invisible when adding entries
Works, thanks. Kill Bill
02:17 PM pfSense Packages Feature #6789 (New): disgest_ldap_auth
We are deploying pfsense the company as proxy using squid + squidguard and authenticating in our openldap base (linux... Jose Luis Pissin
12:48 PM Revision 6779b24d: Simplify icmp conversion
pprior code "converts" every icmp type - of which only 3 actually get changed (rest keep same value anyhow!). If also... Stilez y
12:48 PM Revision 16efbe4e: Merge pull request #3136 from stilez/patch-37
Renato Botelho
12:44 PM Revision 49f5e806: Use !empty() instead of isset()
(cherry picked from commit 6a9d1bfc5c90011af10a1704231340a42fa9f51d) Fredrik Rönnvall
12:44 PM Revision 080e2967: Improve handling of source-hash key
- Store the source-hash key in its own config field.
- Validate the provided source-hash key. Check that hex string i...
Fredrik Rönnvall
12:44 PM Revision d7b0d492: Add field to specify source-hash key
The source-hash pool option uses a hash of the source address to
determine the translation address. This hashing algo...
Fredrik Rönnvall
12:44 PM Revision 2e8d34a6: Merge pull request #2782 from fredronnv/master
Renato Botelho
12:11 PM Feature #6786: Sortable Description Captive Portal MACs list
Click the column headers to sort the table as required.
Should be in the next snapshot
Anonymous
12:10 PM Feature #6786 (Feedback): Sortable Description Captive Portal MACs list
Applied in changeset commit:e846d7f882d57331d7ead5fcf593e7e4daf7e247. Anonymous
10:33 AM Bug #6760: Editing WAN bridge interface breaks routing until reboot
I am having a similar issue whenever my WAN link goes down and then recovers. Basically I lose some kind of routing ... Jay Janssen
09:50 AM Revision 0e782e9f: Improve icmptype input sanitising
Stilez y
08:57 AM Revision cf1aaf9c: Enhance ICMP types in rules
See main PR for details Stilez y
08:54 AM Revision 7a4b11b6: Enhance ICMP type handling in rules
See main PR for details Stilez y
08:28 AM Revision 6a9d1bfc: Use !empty() instead of isset()
Fredrik Rönnvall
08:25 AM Revision 58aa4d7c: typo
Stilez y
08:14 AM Revision 4784d8ce: Enhance ICMP rules
See main PR details Stilez y
08:00 AM Bug #4937: RRD graphs with mixed quantities are unreadable
Hi, the issue is exactly the same on 2.3. Packet loss and latency still share the same scale, so one can definitely d... Guillaume Pothier
01:20 AM Revision 6f141058: Merged #2975
Stephen Beaver
01:18 AM Revision d969f54a: Merged #2975
Stephen Beaver
12:58 AM Revision 9493b957: Revised service running/stopped icons
(cherry picked from commit a03162c874c4e52e6cae52c2eefce87118fd90d2) Stephen Beaver
12:57 AM Revision f1f43826: Revised service running/stopped icons
(cherry picked from commit a03162c874c4e52e6cae52c2eefce87118fd90d2) Stephen Beaver
12:52 AM Revision a03162c8: Revised service running/stopped icons
Stephen Beaver
12:36 AM Revision 0ae0f1f0: Fixed #6788 by clearing only the first label in the cloned row
(cherry picked from commit d38d215d1d9429d3a1a15708f92b14cf3a15b247) Stephen Beaver
12:36 AM Revision 10fca5ac: Fixed #6788 by clearing only the first label in the cloned row
(cherry picked from commit d38d215d1d9429d3a1a15708f92b14cf3a15b247) Stephen Beaver
12:34 AM Revision d38d215d: Fixed #6788 by clearing only the first label in the cloned row
Stephen Beaver

09/14/2016

08:18 PM Revision 176b8f78: Merge branch 'master' of git.pfmechanics.com:pfsense/pfsense
Stephen Beaver
07:40 PM Bug #6788: [2.3.3] Services - NTP - Settings: Prefer/No Select checkboxes invisible when adding entries
Applied in changeset commit:d38d215d1d9429d3a1a15708f92b14cf3a15b247. Anonymous
07:39 PM Bug #6788 (Feedback): [2.3.3] Services - NTP - Settings: Prefer/No Select checkboxes invisible when adding entries
Javascript revised to clear only the first label in the cloned row Anonymous
03:10 AM Bug #6788 (Resolved): [2.3.3] Services - NTP - Settings: Prefer/No Select checkboxes invisible when adding entries
Best described with a picture:
!http://image.prntscr.com/image/73931c990d7f4757a8d5d62023e4db6a.png!
Note:
- ...
Kill Bill
07:32 PM Revision 1c402413: Merge pull request #2975 from NOYB/Services_Status
Stephen Beaver
06:49 PM Bug #6749: Still responds to ARP after removing one of several Virtual IP - choparp not reconfigured
It does not look like the proper PID files are being created in /var/run. -p PIDFILE arguments are not being added to... Chris Linstruth
05:22 AM Revision 69cb4d5a: Secure SMTP Connection Modes - Mutually Exclusive
Secure SMTP Connection modes are mutually exclusive. Select only one. NOYB NOYB

09/13/2016

09:03 PM Feature #6787 (Resolved): NTP GUI sync/poll interval
Id like to be able to set the minpoll and maxpoll in the pfsense NTP service within the GUI. I noticed that prior to... Adam Esslinger
07:49 PM Feature #6786 (Resolved): Sortable Description Captive Portal MACs list
Hi!
Pfsense is awesome. We use the Captive Portal MACs feature a lot, on top of the voucher system.
While the list...
ep spk
07:11 PM Revision 0ce1667b: Simplify icmp conversion
pprior code "converts" every icmp type - of which only 3 actually get changed (rest keep same value anyhow!). If also... Stilez y
06:56 PM Revision 0ae266af: Merge pull request #3131 from PiBa-NL/20160906-generic-xmlrpc_client
Renato Botelho
06:44 PM Revision eecfac71: XMLRPC, xmlrpc_client set new Netgate copyright.
Pi Ba
06:36 PM Revision 786d411d: Fix #6768 IPv6 static mapping on delegated prefixes
For example, WAN receives a /48 delegated from the upstream (ISP...),
e.g. "2001:470:abcd::" pfSense then uses this a...
Phil Davis
06:36 PM Revision 96ca183a: Merge pull request #3135 from phil-davis/pdlen
Renato Botelho
05:42 PM Revision e3b0eeb2: XMLRPC, xmlrpc_client remove extended class and define setConnectionData(.) function instead.
Pi Ba
05:34 PM Revision 4d09ffde: Code style changes
(cherry picked from commit b2836666a8e7fc021ea750fafc8fc6e8097d52ff) k-paulius
05:34 PM Revision 7066f0cc: Allow packages to request syslogd log socket to be created inside chroot by specifying it in /package/logging/logsocket element. Implements #4898.
Example:
<package>
<logging>
<logsocket>/var/appname/var/run/log</logsocket>
</loggin...
k-paulius
05:34 PM Revision c1973ae9: Merge pull request #2616 from k-paulius/patch-pkg-syslog-v2
Renato Botelho
03:30 PM pfSense Packages Feature #6785 (Resolved): Allow setting of suricata's meta-field-limt libhtp parameter
... Orion Poplawski
03:24 PM Revision 3cd1b969: XMLRPC, xmlrpc_client remove xmlrpc_client.inc from pfSense.obsoletedfiles
Pi Ba
01:50 PM Bug #6768 (Feedback): DNS Resolver entry for DHCPv6 static mapping has wrong IP address
Applied in changeset commit:e89a17fbf04aae89f60f13baf293f397ca21c303. Phillip Davis
01:23 PM Revision 6a764447: Enable cellular pkg build
Renato Botelho
01:23 PM Revision efae02fc: Enable cellular pkg build
Renato Botelho
12:40 PM Feature #4898 (Feedback): Allow packages to request syslogd socket to be created inside chroot
Applied in changeset commit:ab31acb937792bdedef11fcdbd1d98ad126ebc0b. Anonymous
12:38 PM Revision ec51be45: dnsresolver, make interface boxes resizable, to allow for easier picking/checking of multiple selected interfaces
(cherry picked from commit 57625777c88603f1d2ca55cc981c5ec538c3770f) Pi Ba
12:38 PM Revision a9a60118: Merge pull request #3104 from PiBa-NL/resizable-selectionbox
Renato Botelho
12:37 PM Revision 6002af93: Fix diag_dns regressions
After testing diag_dns behaviour some regressions have been noticed.
1) Looking up ipv6.google.com (it only has AAAA...
NewEraCracker
12:37 PM Revision 0417767d: Merge pull request #3129 from NewEraCracker/patch-dns
Renato Botelho
12:31 PM Revision 03505b3a: Merge pull request #3134 from stilez/patch-36
Renato Botelho
12:26 PM Revision a016674e: Remove empty concatenation.
(cherry picked from commit a25c797a44e5cd2480947eb5ae427dcb8e0c031c) NOYB NOYB
12:26 PM Revision 99896968: Check IP Services - Info Box
Change warning box with dismissal to collapsible info box.
(cherry picked from commit 6f3ac947b2a83f18ade12ad9876fb8...
NOYB NOYB
12:26 PM Revision 9a20fb44: Merge pull request #3133 from NOYB/Check_IP_Services_-_Info_Box
Renato Botelho
09:04 AM Feature #5825: Allow EAP-RADIUS for authentication servers
Adam Thompson wrote:
> Supposedly this exists, per https://doc.pfsense.org/index.php/IKEv2_with_EAP-RADIUS, but I'm ...
Joe McNolan

09/12/2016

06:31 PM Revision a25c797a: Remove empty concatenation.
NOYB NOYB
09:22 AM Bug #6783 (Not a Bug): Bootstrap code compatibility/rendering failure with SELECT MULTIPLE boxes
The jQuery "begins with" syntax works with this type of control. Try:... Anonymous
05:01 AM Bug #6769: Crash PacketFilter in bridge mode
Ok, without advanced settings set in the rules on the firewall not more crash. Now it's stable. Johann MONNIER
04:53 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Applied attached patch, but that only pushes the problem in the near future. Still fails after x amount of days or ho... Per Hodneland
01:20 AM Revision e89a17fb: Fix #6768 IPv6 static mapping on delegated prefixes
For example, WAN receives a /48 delegated from the upstream (ISP...),
e.g. "2001:470:abcd::" pfSense then uses this a...
Phil Davis

09/11/2016

08:24 PM Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address
Pull request: https://github.com/pfsense/pfsense/pull/3135
Phillip Davis
02:53 PM Bug #6783: Bootstrap code compatibility/rendering failure with SELECT MULTIPLE boxes
(also it's not clear to me if all browsers add "[]" and if there's a remaining compatibility issue in here) Stilez y
02:52 PM Bug #6783: Bootstrap code compatibility/rendering failure with SELECT MULTIPLE boxes
For anyone needing a workaround, or if it's useful, I just googled "jquery square brackets" and found two syntaxes th... Stilez y
09:46 AM Bug #6783 (Not a Bug): Bootstrap code compatibility/rendering failure with SELECT MULTIPLE boxes
Source code:... Stilez y
01:40 PM pfSense Packages Bug #6784 (New): HAProxy version .48 will not use URL Table Alias for front end listener
I use HAProxy with an alias of ports to listen on. The backend has the ports set to blank so it just does a pass thro... Aaron Smith
02:44 AM pfSense Packages Feature #2170: Enable AirPrint mdns via Avahi
Stilez y wrote:
> There is an active FreeBSD port of "mdns-repeater". Its args are a list of interfaces optionally p...
Kill Bill
02:20 AM Revision 58325912: Simplify another loop
Stilez y
02:13 AM Revision e23a4173: simplify code a bit more
Stilez y

09/10/2016

05:30 PM pfSense Packages Feature #2170: Enable AirPrint mdns via Avahi
Forgot the links
Port is in usual place. If anyone's in a hurry and just wants the FreeBSD 10.x binary to upload t...
Stilez y
05:26 PM pfSense Packages Feature #2170: Enable AirPrint mdns via Avahi
Much faster solution if anyone looks at this.
There is an active FreeBSD port of "mdns-repeater". Its args are a l...
Stilez y
07:28 AM Revision a8b0fc78: error messages again
Stilez y
07:11 AM Revision b9004e46: gateway error messages - standardise text and clarify "both"
Stilez y
07:01 AM Revision cff60fef: More redundant logic
Stilez y
06:53 AM Revision 667fd2b7: Redundant comparison
if it's a numeric integer (hence non-empty [0-9]+ ) and the first char isn't "0" then the value will always be >0, so... Stilez y
01:00 AM Revision 6f3ac947: Check IP Services - Info Box
Change warning box with dismissal to collapsible info box. NOYB NOYB

09/09/2016

06:59 PM Bug #6782 (Resolved): pkg update can trigger multiple updates per second
From Renato:
"I took a look on pkg src and did some tests. Every time a remote operation is executed (pkg search, pk...
Jeremy Porter
06:52 PM Revision d2013d12: Fix up/catch up remote syslog areas. Fixes #6780
Jim Pingle
06:52 PM Revision b78f03f4: Fix up/catch up remote syslog areas. Fixes #6780
Jim Pingle
06:51 PM Revision ff1af69d: Fix up/catch up remote syslog areas. Fixes #6780
Jim Pingle
06:13 PM Revision 6e5f31c7: More pptp bits
Jim Pingle
06:13 PM Revision b1a4f3b3: More pptp bits
Jim Pingle
06:12 PM Revision c1b86deb: More pptp bits
Jim Pingle
03:59 PM Revision 8acd1331: Remove some more dangling PPTP bits.
Jim Pingle
03:58 PM Revision 54d3b4ba: Remove some more dangling PPTP bits.
Jim Pingle
03:57 PM Revision 657baf78: Remove some more dangling PPTP bits.
Jim Pingle
02:00 PM Bug #6780 (Feedback): status_logs_settings.php / system.inc: Remote syslog options need to catch up with changes in syslog config
Applied in changeset commit:ff1af69dd513b123238f149193d565f5d83658fb. Jim Pingle
01:49 PM Bug #6780 (Resolved): status_logs_settings.php / system.inc: Remote syslog options need to catch up with changes in syslog config
The resolver, ppp, routing, and ntpd logs are not individually selectable on status_logs_settings.php, and the other ... Jim Pingle
01:51 PM Bug #6781 (Resolved): OpenBSD description links are broken in Traffic Shaper
Links made for some function/option descriptions in pfSense are broken.
For example "Random Early Detection" goes t...
Vladimir Suhhanov
01:50 PM Bug #6099: igmpproxy does not recognize upstream interface
Victor Toni wrote:
> This version does solve the interfaces issue already and some other minor bugs, too:
> https:/...
Jorge M. Oliveira
01:47 PM Bug #6779 (Resolved): Traffic shaper wizard uses decimals instead of whole numbers
After using traffic shaper wizard when you completed it you can get decimals in "Max bandwidth for queue" and other v... Vladimir Suhhanov
09:25 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Yes, it is exactly as you described.
ONLY PFSense 2.1.5 works fine on this configuration. I use several CRITICAL f...
Luca De Andreis
08:09 AM Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address
The issue isn't with DHCP... it's with DNS (unbound, in my case) resolution of a DHCPv6 static mapping.
Looking in...
Anonymous
03:25 AM Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address
I tried this in a VM. I delegated a /56 (out of the /48 I have from he.net) from my real router to the WAN of the VM ... Phillip Davis

09/08/2016

08:46 PM Revision 9c1f564c: Fix description of the VPN remote log setting
Jim Pingle
08:46 PM Revision f12264ef: Fix description of the VPN remote log setting
Jim Pingle
08:46 PM Revision 1d6f957f: Fix description of the VPN remote log setting
Jim Pingle
05:39 PM Revision 57625777: dnsresolver, make interface boxes resizable, to allow for easier picking/checking of multiple selected interfaces
Pi Ba
04:43 PM Bug #6778 (Resolved): CloudFlare Dynamic DNS fails when domain name uses a Second Level TLD
When using Dynamic DNS with CloudFlare if the domain name used has a second level TLD such as .co.uk the update will ... James Thresher
02:49 PM Revision df7f65a3: Fix diag_dns regressions
After testing diag_dns behaviour some regressions have been noticed.
1) Looking up ipv6.google.com (it only has AAAA...
NewEraCracker
10:16 AM Revision c0f87bd1: Move copyright from ESF to Netgate
Renato Botelho
10:16 AM Revision 01a3b0c5: Revert "Remove unused file browser.php"
This reverts commit 48ffade7502839380cc6046187e0c1447723d67a. Renato Botelho
10:16 AM Revision cb437d39: Move copyright from ESF to Netgate
Renato Botelho
10:15 AM Revision 39aa6d81: Revert "Remove unused file browser.php"
This reverts commit 8dee84f4cef55a2f008a319022a762b92e00117e. Renato Botelho
12:09 AM pfSense Packages Bug #6777: squid cant redirect ssl website correctly to squidguard error page in a denied category
here is the same error reported in pfsense forum without a solution
https://forum.pfsense.org/index.php?topic=1093...
Albert Albert

09/07/2016

11:09 PM Revision 4d7522bf: XMLRPC, xmlrpc_client simplify construction parameters where possible + cleanup
Pi Ba
08:37 PM Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address
Likely reason for this is because in entering the DHCPv6 static mapping, you're entering ONLY the host portion of the... Anonymous
07:06 PM pfSense Packages Bug #6777 (Not a Bug): squid cant redirect ssl website correctly to squidguard error page in a denied category
h1. When you use "squid" with "squidguard" set in *"NO"* transparent mode, any category denied previously (squidguard... Albert Albert
02:51 PM Feature #6776 (New): Allow disabling of "filter rule association" by default
This setting is inherently insecure, as it opens a hole in your firewall for the world to get into. Fine for public-f... Michael Newton
01:22 PM pfSense Packages Bug #6774 (Rejected): al usar la categoria in-addr en squidguard bloquea cualquier web en https
You'll have to post on the forum and find someone who is interested in looking into transparent SSL -- it isn't an of... Jim Pingle
01:38 AM pfSense Packages Bug #6774: al usar la categoria in-addr en squidguard bloquea cualquier web en https
Sorry for my english.
If I want to enable the next option in common acl, squidguard block all traffic from https
...
Albert Albert
01:31 AM pfSense Packages Bug #6774 (Rejected): al usar la categoria in-addr en squidguard bloquea cualquier web en https
al tener el proxy en modo transparente usando tanto pfsense 2.3.2 y 2.3.3, e inspeccionando trafico ssl, si se activa... Albert Albert
12:04 PM Bug #6766: Docs give wrong method of disabling ixgbe flow control
I just checked and dev.ix.0.fc=0 has no effect when placed in /boot/loader.conf.local. Also, sysctl -T -a doesn't li... Duncan Sands
07:40 AM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
That function is a part of the pfSense PHP module, so if it's missing, then either the PHP module package is missing,... Jim Pingle
05:57 AM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
I have seen the same error. I think in my case it was related to remove DHCP IPv6 from WAN interface. Ph. T
04:28 AM Bug #6769: Crash PacketFilter in bridge mode
I confirm than crash if you set advanced parameter but randomly... for unknow reason. I have reboot five time pfsense... Johann MONNIER
03:46 AM Feature #6775 (Closed): Strongswan PKCS#11 Support
We developed a Smart Cards based authentication of StrongSwan-IPsec-VPN peers.
This already works on pfSense 2.2.6 b...
Anonymous

09/06/2016

09:19 PM Revision 2a2396a6: Move copyright from ESF to Netgate
Renato Botelho
07:24 PM Revision 48ffade7: Remove unused file browser.php
Renato Botelho
07:23 PM Revision 81299b5c: Move copyright from ESF to Netgate
Renato Botelho
07:19 PM Revision 8dee84f4: Remove unused file browser.php
Renato Botelho
04:13 PM Revision 292bd9c6: css: Fix jQuery UI widgets' font
Use the main font with jQuery UI widgets (e.g. autocomplete forms)
(cherry picked from commit e540a9d774f5dfcdd18bf5...
Jose Luis Duran
04:13 PM Revision 1b9fa643: Merge pull request #3119 from jlduran/fix-font-jquery-ui-widgets
Renato Botelho
04:12 PM Revision 848aeb80: [theme] Compact-RED: improve hovered table rows visibility
(cherry picked from commit e5bc38d21b6ac6c419758ecab7b31f7c06a5c53d) Alexander Moisseev
04:12 PM Revision be3cfc58: [theme] Compact-RED: compact panel titles
(cherry picked from commit 953a88a4482e72764ba6ab7ed9f0ce2b21748506) Alexander Moisseev
04:12 PM Revision cfe6c5fa: [theme] Compact-RED: make drop-down menus not too "compact"
and improve hovered element visibility
(cherry picked from commit b8916dccad084ffaa4b402c535f4047fb7a51f3c)
Alexander Moisseev
04:12 PM Revision c9af58c7: [theme] Compact-RED: get rid of anti-aliased fonts
(cherry picked from commit 9e1208e5833a81c05f86db31078b0fe6901b70ac) Alexander Moisseev
04:12 PM Revision d5b628cb: Merge pull request #3120 from moisseev/compact-red
Renato Botelho
04:07 PM Revision 75d5738c: Remove some obsolete code from globals.inc
Jim Pingle
04:07 PM Revision 6ffb27fc: Remove some obsolete code from globals.inc
Jim Pingle
03:47 PM Bug #6773 (Rejected): Pfsense Version 2.3.2 doesn't handle rules when gateway is down - Skip rules when gateway is down
I tested this recently and it worked fine. Do you have a forum thread with more in-depth discussion/diagnosis? If not... Jim Pingle
03:41 PM Bug #6773 (Rejected): Pfsense Version 2.3.2 doesn't handle rules when gateway is down - Skip rules when gateway is down
Hello.
I have two vpn's configured between two pfsense's with the same versions.
I added a interface for every vpn'...
Felipe Diefenabch
03:42 PM Revision 9d626618: Fix handling of backup config count. Fixes #6771
Jim Pingle
03:41 PM Revision 8c5b9920: Fix handling of backup config count. Fixes #6771
Jim Pingle
03:40 PM Revision caec0e97: Fix handling of backup config count. Fixes #6771
Jim Pingle
03:39 PM Bug #6658: DHCP Relay not working on 2.3.2
Jim Pingle wrote:
> Does that particular configuration involve a bridge?
> The "cannot forward" message reminds me ...
Kill Bill
03:07 PM Bug #6658: DHCP Relay not working on 2.3.2
Just found it (it was from the IPv6 address):... Jim Pingle
03:00 PM Bug #6658: DHCP Relay not working on 2.3.2
Thanks; managed to find the related crash dump I submitted today? (Should be either from 188.75.x.x or 2001:470:6e:xx... Kill Bill
11:13 AM Bug #6658: DHCP Relay not working on 2.3.2
Rather than reinvent the wheel I updated the description on this ticket instead. Jim Pingle
10:53 AM Bug #6658: DHCP Relay not working on 2.3.2
I don't think we have any left, unless you count 2.3.1 which isn't so helpful in that area. If you do still have a 2.... Jim Pingle
09:49 AM Bug #6658: DHCP Relay not working on 2.3.2
@jimp: Well if you can link a pre-6355 binary for download, I can test that for sure with multiple boxes. I might hav... Kill Bill
09:42 AM Bug #6658: DHCP Relay not working on 2.3.2
OK so the real issue of this ticket is actually DHCP Relay breaking. Given the info in the description and such I'm t... Jim Pingle
09:16 AM Bug #6658: DHCP Relay not working on 2.3.2
And finally - the DHCP relay issues are so bad that it actually crashes pfSense when reconfiguring the service. I sub... Kill Bill
09:14 AM Bug #6658: DHCP Relay not working on 2.3.2
OK. After a lot of further testing and messing with various stuff, here is some mixed news:
- as for 2.3.x, the *DHC...
Kill Bill
08:09 AM Bug #6658: DHCP Relay not working on 2.3.2
I'll make a fresh ticket for 2.4 with the above on it so it doesn't get lost here. Jim Pingle
07:58 AM Bug #6658: DHCP Relay not working on 2.3.2
Looks like on 11 you have to clone the interface. The wireless device (e.g. ath0) won't show in ifconfig.
Somehow ...
Jim Pingle
03:20 PM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
Anyone who can reproduce this: Try feeding the attached patch into the system patches package, which will add in the ... Jim Pingle
03:09 PM Bug #6766: Docs give wrong method of disabling ixgbe flow control
We don't recommend doing that for hardware directives. It may work, but depending on what is being done it's safer to... Jim Pingle
03:05 PM Bug #6766: Docs give wrong method of disabling ixgbe flow control
At the top of the section it says "All of these go in /boot/loader.conf.local", but dev... can be done in System Tuna... Duncan Sands
03:00 PM Bug #6766 (Resolved): Docs give wrong method of disabling ixgbe flow control
Fixed the doc referenced Jim Pingle
02:57 PM pfSense Packages Bug #4731: softflowd process gets started twice during bootup
The problem with that "fix" is that with that sort of change, it no longer starts the daemon when it's stopped and th... Jim Pingle
02:31 PM Bug #6771 (Resolved): Configuration backup count is not respected
Works Jim Pingle
10:50 AM Bug #6771 (Feedback): Configuration backup count is not respected
Applied in changeset commit:caec0e97220d3702214c6b30f7008960f77a857e. Jim Pingle
10:39 AM Bug #6771 (Resolved): Configuration backup count is not respected
If a backup count other than the default is entered on diag_confback.php it is not respected.
To me, I have a fix.
Jim Pingle
01:52 PM Bug #6759 (Resolved): system_authservers.php - LDAP "Bind Credentials" password is not masked
Looks good now, it's masked. Jim Pingle
12:23 PM Bug #6772: ipv6 alias do not work
I did that exactly as described, and the rules worked and there was no crash. Please discuss on the forum before open... Jim Pingle
12:20 PM Bug #6772: ipv6 alias do not work
For reproduce :
1. create alias with IPV6: one for source, one for destination
2. Create rules use alias created ...
Johann MONNIER
12:15 PM Bug #6772 (Rejected): ipv6 alias do not work
I am unable to reproduce any of this. IPv6 rules using aliases or "this firewall" all work OK. Make sure you actually... Jim Pingle
12:03 PM Bug #6772: ipv6 alias do not work
And if after add your rules with alias created before with ipv6 and you try change this rule in replace alias by addr... Johann MONNIER
11:32 AM Bug #6772: ipv6 alias do not work
And it's same if you select "This Firewall" with rules ipv6, doent work Johann MONNIER
11:27 AM Bug #6772 (Rejected): ipv6 alias do not work
Hi,
If you create alias with ipv6 and use in the rules firewall doent work.
Johann MONNIER
09:25 AM Bug #6769: Crash PacketFilter in bridge mode
i think the problem is with all parameter set and the scenario most probability than is if number connexion over the ... Johann MONNIER
09:04 AM Bug #6769: Crash PacketFilter in bridge mode
Can you isolate it to just one of those options then? Or does it require them all? Can you disable/enable them to see... Jim Pingle
09:02 AM Bug #6769: Crash PacketFilter in bridge mode
Synproxy is not the setting that problem because I left it on and I do not have the problem.
and for information syn...
Johann MONNIER
07:28 AM Bug #6769 (Feedback): Crash PacketFilter in bridge mode
Does it require that specific combination of settings? Or does it still crash with only one of them active? or two? o... Jim Pingle
04:39 AM Bug #6769 (Resolved): Crash PacketFilter in bridge mode
Hi,
I have configured pfsense in bridge mode on the Vmware Vsphere. The VM of Pfsense have 8Go of memory and one s...
Johann MONNIER
08:16 AM Bug #6770 (Resolved): 802.11 stack on FreeBSD 11 requires changes to support its new device creation method
On FreeBSD 11 you have to clone the interface and the wireless device (e.g. ath0) does not show in ifconfig.
The l...
Jim Pingle
12:37 AM Revision a8620841: XMLRPC, generic xmlrpc_client implementation + bugfixes in voucher sync
Pi Ba

09/05/2016

08:38 PM pfSense Packages Bug #4731: softflowd process gets started twice during bootup
I just wanted to chime in that the issue still exists with: pfSense 2.3.2 / softflow 1.2.1_2
I was having the same...
Aaron Shaffer
08:13 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Redmine is still the issue tracker - the code (and pull requests...) is in GitHub. Phillip Davis
02:43 AM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
OK thanks - you can close this issue.
(BTW: is redmine or github now the preferred tracker to use?)
Brian Candler
07:42 PM Bug #6768: DNS Resolver entry for DHCPv6 static mapping has wrong IP address
No, the asterisks aren't part of the address. Apparently bold text isn't supported here, despite the button above the... Anonymous
07:40 PM Bug #6768 (Resolved): DNS Resolver entry for DHCPv6 static mapping has wrong IP address
I have added two DHCPv6 static mappings for two hosts on my network. But when resolving the hostname to IP address, t... Anonymous
06:01 PM Todo #6767 (Resolved): Change logout from GET to POST request
We currently use @index.php?logout@ instead of a POST request to log the current user out.
There are several reaso...
Jared Dillard
03:57 PM Bug #6099: igmpproxy does not recognize upstream interface
Jorge M. Oliveira wrote:
> No, my purpose was only to fix this long standing bug and (attempt) to make it work again...
Victor Toni
03:24 PM Bug #6099: igmpproxy does not recognize upstream interface
No, my purpose was only to fix this long standing bug and (attempt) to make it work again as it should.
I leave th...
Jorge M. Oliveira
01:06 PM Bug #6099: igmpproxy does not recognize upstream interface
Jorge M. Oliveira wrote:
> New version based on the reviewed patch. I believe my work in this area is complete (for ...
Victor Toni
12:33 PM Bug #6099: igmpproxy does not recognize upstream interface
*EDIT:* This version is bugged. Please use the previous. kthxbye.
New version based on the reviewed patch. I belie...
Jorge M. Oliveira
04:51 AM Bug #6099: igmpproxy does not recognize upstream interface
*EDIT:* igmproxy_all.zip is somewhat good, except no IGMPv3 support. The version on pfSense 2.2 supported those packe... Jorge M. Oliveira
03:37 PM Revision aa1c6774: Fix bandwidth limitation in mac passthrough auth
Jonatan Ramos
02:42 PM pfSense Packages Bug #6763: Squid ClamAv wrong redirect URL
Richard Eberhard wrote:
> I also tried adding a redirect command in the custom squid config: no effect.
Why? It'...
Kill Bill
01:22 AM pfSense Packages Bug #6763 (Not a Bug): Squid ClamAv wrong redirect URL
After changing the pfsense hostname the squid proxy still redirects to the old hostname if it finds a virus. I also t... Richard Eberhard
02:25 PM pfSense Packages Bug #5594: Captive portal patch does not work anymore
Hello,
I've applied Marcello's patch to pfSense 2.3.2. The patch needs to be applied a couple of lines lower than ...
Orsiris de Jong
12:21 PM Bug #6766 (Resolved): Docs give wrong method of disabling ixgbe flow control
According to https://doc.pfsense.org/index.php/Tuning_and_Troubleshooting_Network_Cards#Flow_Control, to disable flow... Duncan Sands
12:16 PM Bug #6765 (Resolved): CP: "Enable per-user bandwidth restriction"
Hi all, in CP I see "Enable per-user bandwidth restriction" and:
- Default download (Kbit/s)
- Default upload (...
Pol Hallen
11:42 AM Revision fa32e8fa: Enable apcupsd build
Renato Botelho
07:03 AM Bug #6764 (Rejected): No traffic http with pfSense in VM PROXMOX and network interface VirtIO
That thread is very old and likely irrelevant. Please start a new thread to diagnose your issue before opening a bug ... Jim Pingle
05:45 AM Bug #6764: No traffic http with pfSense in VM PROXMOX and network interface VirtIO
Topic related:
https://forum.pfsense.org/index.php?topic=87856.0
Olivier LAHOUZE
05:44 AM Bug #6764 (Rejected): No traffic http with pfSense in VM PROXMOX and network interface VirtIO
Hello.
I have installed pfSense in VM on PROXMOX serveur with 2 networks interfaces.
I used 2 "virtIO" networks i...
Olivier LAHOUZE

09/04/2016

06:34 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
That has been addressed by commit https://github.com/pfsense/pfsense/commit/8ea3fd0569ac2b1681de5ba3fbc2a2cc20981ad6
...
Phillip Davis
01:20 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Looking at http://www.ecma-international.org/ecma-262/5.1/#sec-7.8.5 I'd say that Chrome is at fault:... Brian Candler
01:13 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
I made the following patch to the live system, and now it works fine with Chrome.... Brian Candler
12:46 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Interesting idea.
This is using Chrome 53 under OSX. By positioning the cursor at both ends of the string I can se...
Brian Candler
12:28 PM Bug #6762: "Please match the requested format" error in Chrome when editing certain form fields
Sounds like your browser is inserting whitespace junk or whatever on "autocomplete". Kill Bill
12:13 PM Bug #6762 (Resolved): "Please match the requested format" error in Chrome when editing certain form fields
I created an alias called "firewall_management"
There was an existing rule which said allow inbound SSH on WAN (fr...
Brian Candler
03:03 PM Bug #6099: igmpproxy does not recognize upstream interface
Some brand new patches for the version that ships on freebsd-ports:
patch-src__os-freebsd.h is based on https://gi...
Jorge M. Oliveira
11:03 AM Bug #6761: Limiter doesn't limit at correct bandwidth
Michael Knowles wrote:
> Hi,
>
> As per my Reddit thread here (with the relevant screenshots), I am seeing reliab...
Michael Knowles
11:03 AM Bug #6761 (Not a Bug): Limiter doesn't limit at correct bandwidth
Hi,
As per my Reddit thread here (with the relevant screenshots), I am seeing reliable-but-wrong inbound bandwidth...
Michael Knowles
09:57 AM Bug #6011: IPv6 link local fails HTTP REFERER check
This PR has been merged a few months ago. Bug can be marked as resolved. Jorge M. Oliveira
09:50 AM Bug #6662: pkg_edit.php checkbox alignment issue when using the sethelp xml tag
This issue can be set to feedback.
This PR has been merged and should deal with the problem: https://github.com/pfse...
Jorge M. Oliveira
09:48 AM Bug #6686: PHP extensions.ini cannot be read by non root users
This PR has been merged on pfSense 2.3 branch: https://github.com/pfsense/pfsense/pull/3095
This ticket can be set t...
Jorge M. Oliveira
07:54 AM Bug #6435 (Duplicate): Unable to edit PPTP using interfaces_ppps_edit.php
Jim Pingle
05:04 AM Bug #6435: Unable to edit PPTP using interfaces_ppps_edit.php
seems to be a duplicate of #6732 Thomas Rieschl
07:22 AM Bug #6658: DHCP Relay not working on 2.3.2
And FWIW - this does not appear to be limited to AR9280. I managed to rescue some oldie 802.11a/b/g mini-PCIe card w... Kill Bill
07:03 AM Bug #6658: DHCP Relay not working on 2.3.2
I temporarily installed 2.4 alpha on a test box, and the wireless is completely broken there, the entire interface go... Kill Bill
06:41 AM Bug #6760: Editing WAN bridge interface breaks routing until reboot
Jim Pingle wrote:
> What do "netstat -rn" and "ifconfig -a" look like before and after? Any notable differences?
...
Kill Bill

09/03/2016

07:27 PM Bug #6658: DHCP Relay not working on 2.3.2
Hi Jim,
I have installed
https://snapshots.pfsense.org/amd64/pfSense_master/installer/pfSense-CE-memstick-serial-...
martin wüthrich
02:29 PM Bug #6658: DHCP Relay not working on 2.3.2
Could one or both of you try this on 2.4? Jim Thompson
01:16 PM Bug #6658: DHCP Relay not working on 2.3.2
I'm in the same Situation like described, except I have an "APU1" and my clients stay connected (they even authentica... martin wüthrich
06:48 PM Bug #6099: igmpproxy does not recognize upstream interface
By the way, I've coded a very hackish workaround (for version 2.3.3) that one can execute via Diagnostics > Command P... Jorge M. Oliveira
04:53 PM Bug #6099: igmpproxy does not recognize upstream interface
(I'm using original version of igmpproxy without any changes)
There is one thing I find very interesting.
On my t...
Jorge M. Oliveira
07:16 AM Bug #6760: Editing WAN bridge interface breaks routing until reboot
What do "netstat -rn" and "ifconfig -a" look like before and after? Any notable differences? Jim Pingle
04:59 AM Bug #6760 (Not a Bug): Editing WAN bridge interface breaks routing until reboot
Say you have a setup like this:... Kill Bill

09/02/2016

08:14 PM Revision 6df9b5cb: Obscured password field in system_authservers.php bind section
Fixed #6759
(cherry picked from commit 1c1f08f92e8841f7282280caeed7613edd810453)
Stephen Beaver
08:12 PM Revision 1c1f08f9: Obscured password field in system_authservers.php bind section
Fixed #6759 Stephen Beaver
07:31 PM Bug #6688: Special characters in a password cause problems
Have a look at the end of https://github.com/pfsense/pfsense/blob/master/src/etc/inc/upgrade_config.inc
You can add ...
Phillip Davis
05:05 PM Bug #6688: Special characters in a password cause problems
Although I don't really know PHP, I can dive into the code and poke around. It looks like it's pretty easy to do base... John Dickinson
07:19 PM Revision f02b8916: Merge pull request #3071 from phil-davis/Check_IP_Services
Renato Botelho
07:18 PM Revision d37c6564: Force changes in routing to be detected by the system
When dhcp6c without RA is enabled, dhcp6c isn't killed and respawned, this causes the system not being able to pick u... NewEraCracker
07:18 PM Revision e0bc2a6c: DHCP6 Before RA. Additions and ammendments
Replaced posix_kill() in kill_dhcp6client_process() with mwexec("kill -9 $pid"), this is because the posix_kill call ... Martin Wasley
07:18 PM Revision 455be09a: Merge pull request #3102 from NewEraCracker/patch-dhcp6
Renato Botelho
06:21 PM Revision f2c9194c: Force changes in routing to be detected by the system
When dhcp6c without RA is enabled, dhcp6c isn't killed and respawned, this causes the system not being able to pick u... NewEraCracker
06:21 PM Revision c4ddb03a: DHCP6 Before RA. Additions and ammendments
Replaced posix_kill() in kill_dhcp6client_process() with mwexec("kill -9 $pid"), this is because the posix_kill call ... Martin Wasley
03:20 PM Bug #6759: system_authservers.php - LDAP "Bind Credentials" password is not masked
Applied in changeset commit:1c1f08f92e8841f7282280caeed7613edd810453. Anonymous
03:14 PM Bug #6759 (Feedback): system_authservers.php - LDAP "Bind Credentials" password is not masked
Anonymous
02:54 PM Bug #6759 (Resolved): system_authservers.php - LDAP "Bind Credentials" password is not masked
On system_authservers.php when configuring an LDAP server, uncheck "Bind Anonymous" and there is a username and passw... Jim Pingle
02:36 PM Bug #6747: pfctl - getting high cpu usage
Remove one widget at a time from the Dashboard and test with:
top -SH
Then see which is causing the high cp...
BBcan177 .
08:38 AM Bug #6747: pfctl - getting high cpu usage
It only happens with firewall log widget and pfblockerng widget. The resources consumption (I'm not 100% sure if it's... Rafael Cunha
02:07 PM Feature #4606: PKI : CA signing external CSR
+1, would love to be able to sign external CSRs from within pfSense. (For both certificates and intermediate-CAs) Peter Bosgraaf
01:31 PM Revision 1e0d9c89: Improve dhcpd and dhcpleases reload
1) Avoid running services_dhcpd_configure() more times than needed.
2) Always restart dhcpleases after it's killed du...
NewEraCracker
01:31 PM Revision b85d0e03: Merge pull request #3122 from NewEraCracker/patch-11
Renato Botelho
01:30 PM Revision 8221f09c: Call services_dhcpd_configure with the right parameter
Previously code segment for v4 would call both v4 and v6. Fixed to call v4 and v6 where appropriate.
(cherry picked ...
NewEraCracker
01:30 PM Revision 59900c5c: Merge pull request #3105 from NewEraCracker/patch-8
Renato Botelho
01:28 PM Revision b9e9778a: Uniformize memory limits and remove old code (revised)
1) Allow setting a memory_limit up to 768M (Suhosin)
2) Remove old workarounds. Memory limits on config.inc will be n...
NewEraCracker
01:28 PM Revision e477e23b: Merge pull request #3101 from NewEraCracker/patch-5
Renato Botelho
11:54 AM Revision 02809cc6: Ensure only one instance of services_dhcpd_configure runs concurrently
This way kill and respawn will behave as they should for the dhcpd processes
(cherry picked from commit c69ea0051c55...
NewEraCracker
11:54 AM Revision 9f0679ef: Merge pull request #3103 from NewEraCracker/patch-7
Renato Botelho
11:51 AM Revision 8402a8de: Fix diag_dns ipaddr set to use in IP WHOIS and IP Info
- Do not call resolve_host_addresses() when hostname cannot be resolved
by gethostbyname(). The old check was consi...
Renato Botelho
11:47 AM Revision 7829c6d5: Fix diag_dns ipaddr set to use in IP WHOIS and IP Info
- Do not call resolve_host_addresses() when hostname cannot be resolved
by gethostbyname(). The old check was consi...
Renato Botelho
11:43 AM Revision 3c09378e: Removed unused variable $hostname
Renato Botelho
11:43 AM Revision 917e9c73: Removed unused variable $hostname
Renato Botelho
11:34 AM Revision 83469e50: Input boxes with setPattern validation should not contain escape characters as they are already properly considered 'lists of characters' even when not escaped.
(cherry picked from commit 8ea3fd0569ac2b1681de5ba3fbc2a2cc20981ad6) Pi Ba
11:34 AM pfSense Packages Bug #6740: https filtering with squid + squidguard error (ssl bump)
Looks like Diladele filter also has a problem with pfsense/squid combo.
[[https://groups.google.com/forum/#!topic/...
C Wood
11:34 AM Revision a7272e31: Input boxes with setPattern validation should not contain escape characters as they are already properly considered 'lists of characters' even when not escaped.
(cherry picked from commit 8ea3fd0569ac2b1681de5ba3fbc2a2cc20981ad6) Pi Ba
11:34 AM Revision cf62c4a8: Merge pull request #3127 from PiBa-NL/20160902_pattern
Renato Botelho
11:33 AM Revision 54bf6953: Outbound nat overview, show alias popup and edit options on source and destination, for both the address and port.
(cherry picked from commit d98e54b215a7798aa0cd9d8432340d6e6df762f5) Pi Ba
11:33 AM Revision bfe658f6: Outbound nat overview, show alias popup and edit options on source and destination, for both the address and port.
(cherry picked from commit d98e54b215a7798aa0cd9d8432340d6e6df762f5) Pi Ba
11:31 AM Revision 53e8071a: Merge pull request #3128 from PiBa-NL/20160902-outboundnat-aliashints
Renato Botelho
11:09 AM Bug #6758 (Resolved): 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
I have a second installation running on i386 10.3-RELEASE-p5 FreeBSD 10.3-RELEASE-p5 v2.3.2 on AMD Athlon(tm) 64 X2 D... Dan Lundqvist
11:06 AM Bug #6099: igmpproxy does not recognize upstream interface
Victor Toni wrote:
> It's the way the interfaces are looked up (internally) so its not directly related to your conf...
Lars Veldcholte
07:55 AM Bug #6757 (Not a Bug): nginx 504 Gateway Time-out when acces to system_certmanager.php
Using the firewall for that many certificates is an atypical use case for which it was not designed. From reading the... Jim Pingle
05:32 AM Bug #6757 (Not a Bug): nginx 504 Gateway Time-out when acces to system_certmanager.php
Sorry for my english ...
It's now impossible for us to acces our certificat listing. php-fpm use 100% of 1CPU and ...
Damien OBLETTE
03:11 AM pfSense Packages Bug #6756 (Resolved): Updating cloned backend in WebGUI updates the original backend instead of the cloned backend
This bug has appeared for me 3 times now when I clone an existing https to a new backend.
I have multiple SSL sites ...
Goran Tornqvist

09/01/2016

11:56 PM Revision d98e54b2: Outbound nat overview, show alias popup and edit options on source and destination, for both the address and port.
Pi Ba
10:59 PM Revision 8ea3fd05: Input boxes with setPattern validation should not contain escape characters as they are already properly considered 'lists of characters' even when not escaped.
Pi Ba
06:04 PM Revision 8d50c07c: Convert L2TP Server code to mpd5
Renato Botelho
03:00 PM Revision 2ce5cd33: Remove references to glxsb as it is not relevant to current supported platforms. Fixes #6755
Jim Pingle
01:30 PM Revision e4191be8: Add ng interface to pppoe group on mpd.conf and remove dead code from vpn-linkup script
Renato Botelho
12:23 PM Revision 2c0a3677: Convert PPPoE Server code to mpd5
Renato Botelho
10:10 AM Todo #6755 (Feedback): Remove GLXSB references from 2.4
Applied in changeset commit:2ce5cd33ef6434d3eb265c59f06e6ffb4930f0d9. Jim Pingle
09:53 AM Todo #6755 (Resolved): Remove GLXSB references from 2.4
Since 2.4 will not support i386, any references to glxsb in the GUI and build scripts can be removed as that was spec... Jim Pingle
02:08 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
I recommend changing this to a high priority bug as it impacts anyone using IPsec and BGP together which are two ubiq... Aaron Marks

08/31/2016

10:10 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Using pfsense 2.3.2-RELEASE (amd64)
I can confirm disabling the upload limiter solves an issue with limiters and 1...
Steve Tibbetts
08:36 PM Feature #6754: Use of aliases in OpenVPN configuration
Have a read of https://redmine.pfsense.org/issues/2668
It is a similar feature request I put in a while ago.
Phillip Davis
02:08 PM Feature #6754 (Duplicate): Use of aliases in OpenVPN configuration
OpenVPN has options where network groups can be specified. See these:
- Tunnel Settings > IPv4 Local Network/s and I...
robi robi
03:31 PM Bug #6747: pfctl - getting high cpu usage
egrep is very memory aggressive...
The pfBlockerNG widget runs this line which doesn't use egrep:
pfctl -vv...
BBcan177 .
02:50 PM Bug #6747: pfctl - getting high cpu usage
Pi Ba, does this edition include pfblockerng widget problem too? Rafael Cunha
01:59 PM Feature #6753 (Resolved): Interfaces list order not consistent
The order the interfaces are listed in several places:
- Status > Interfaces
- Dashboard Interfaces widget
- Inter...
robi robi
11:48 AM Revision de645734: Ticket #3734: Add function to convert IPv6 address <-> binary
- ip6_to_bin() and bin_to_ip6() are copies obtained from pear-Net_IPv6
since the version available in the class is ...
Renato Botelho
11:33 AM Revision 4aa5f0fd: Prevent accessing undefined offset in IPv6.inc
On perfectly good IPs (eg. 1:2::3:4) this code could cause the following notice:
Notice: Undefined offset: 2 in IPv6....
NewEraCracker
11:32 AM Revision beb7a698: Merge pull request #3125 from NewEraCracker/patch-net_ipv6
Renato Botelho
11:10 AM Revision 526d962d: -resolved syntax error
(cherry picked from commit 0a6ab475d80b580b09fefaf3ca346b08ec6a23c9) hamnur
11:10 AM Revision 99179710: -resolved syntax error
(cherry picked from commit 0a6ab475d80b580b09fefaf3ca346b08ec6a23c9) hamnur
11:10 AM Revision 23745038: Merge pull request #3126 from hamnur/master
Renato Botelho
10:26 AM Bug #6528: The captive portal cannot be used on interface lan since it is part of a bridge but works anyway
Hi, sorry for the late answer.
The download speed of everything that goes through the CP isn't enforced when in brid...
Orsiris de Jong
09:55 AM Revision 0a6ab475: -resolved syntax error
hamnur
06:22 AM Bug #6099: igmpproxy does not recognize upstream interface
Lars Veldcholte wrote:
> What is the status on this? I believe I have the same issue (pfSense 2.3).
>
> [...]
>
...
Victor Toni
05:07 AM pfSense Packages Todo #6752 (New): Traffic Totals Data Summary Graph
Please can you change the Time header in the data summary to Date for the monthly & top 10 days, its not a time it's ... Andy Kniveton
04:09 AM Revision 16b16366: move back to r53.class for license continuity
Jason McCormick
03:11 AM Revision 26022814: note inspiration/sanity check from r53.class code
Jason McCormick
03:01 AM Revision 8d8405ba: fix testing headers for bad data
Jason McCormick
02:57 AM Revision c4641295: noted testing for Route53
Jason McCormick
02:54 AM Revision 166f4a4c: Fixed status success message typo and cleaned up
Jason McCormick
02:48 AM Revision 616a2482: fix auth header and minor XML tag issue
Jason McCormick
02:06 AM Revision cc5adcaa: initial commit of code -- having a signing error
Jason McCormick

08/30/2016

09:51 PM Feature #6728: Route53 API mod and Geolocation
Figured out my bug and an XML tag error. This now works so far in my testing - https://github.com/pfsense/pfsense/com... Jason McCormick
09:10 PM Feature #6728: Route53 API mod and Geolocation
The code is at https://github.com/jxmx/pfsense/commit/cc5adcaa679686e54e4035fa5bc283b1cac085a2. The code has an AWS s... Jason McCormick
06:34 PM Feature #6728: Route53 API mod and Geolocation
Okay. I'm hoping to finish the original replacement code tonight and I will pass along a GitHub repo. I guess a diffe... Jason McCormick
03:41 PM Feature #6728: Route53 API mod and Geolocation
I agree; r53.class is overkill compared to the updated API. I've been busy at work and haven't finished rewriting. If... Matt Williams
09:50 PM Bug #6751: Route53 DynDNS Problems / Replace Route53 DynDNS Module
Here is a diff against the current master for the change: https://github.com/pfsense/pfsense/compare/master...jxmx:67... Jason McCormick
07:20 PM Bug #6751 (Resolved): Route53 DynDNS Problems / Replace Route53 DynDNS Module
With pfSense 2.3.2, the DynDNS system does not work with Amazon Route53 services. In looking through the logs and the... Jason McCormick
08:09 PM Revision 8fe8ceff: Prevent accessing undefined offset in IPv6.inc
On perfectly good IPs (eg. 1:2::3:4) this code could cause the following notice:
Notice: Undefined offset: 2 in IPv6....
NewEraCracker
12:03 PM Bug #6750 (Resolved): dhcpleases shouldn't start when DHCP Relay is configured
As well, unbound's config page (Services->"DNS Resolver"->"General Settings") shouldn't allow the "register DHCP leas... Gary Dezern
01:15 AM Bug #6749: Still responds to ARP after removing one of several Virtual IP - choparp not reconfigured
Actually, I found two more choparp processes:
root 22202 0.0 0.1 14604 2248 - S Tue04PM 0:05.67 /u...
Oskar Berggren
01:11 AM Bug #6749 (Duplicate): Still responds to ARP after removing one of several Virtual IP - choparp not reconfigured
At the start, there were four Virtual IPs defined in pfSense. I removed two of them through the GUI, yet the machine ... Oskar Berggren

08/29/2016

10:41 PM pfSense Packages Bug #6748 (Resolved): rrd_fetch_json.php returns html when user is unauthorized (causes "Error: SyntaxError: Unexpected token <")
The rrd_fetch_json.php endpoint should always return json, as it normally is being requested by js or something that ... Stephen Smith
09:52 PM Feature #6728: Route53 API mod and Geolocation
I started looking through the dyndns.class and the Route53 is really non-standard for how pfSense is trying to do thi... Jason McCormick
07:48 PM Feature #6728: Route53 API mod and Geolocation
Does this require an updated r53.class file? Keeping what looks like an unmaintaned (upstream) legacy file seems like... Jason McCormick
07:07 PM Revision ad0fccda: system_dhcpleases_configure() - Improve pidfile handling
1) Set the pidfile variable in the correct place.
pidfile variable is required in both 'if' and 'else' blocks.
2)...
NewEraCracker
07:07 PM Revision 48759936: system_dhcpleases_configure() - Improve pidfile handling
1) Set the pidfile variable in the correct place.
pidfile variable is required in both 'if' and 'else' blocks.
2)...
NewEraCracker
07:07 PM Revision b947efe8: Merge pull request #3106 from NewEraCracker/patch-9
Renato Botelho
07:06 PM Revision 866abc91: Apply the fix for ticket #6589 also into dhcpdv6 config
(cherry picked from commit 20350989db5d66ffb827beaed5ef5738cd62fc9d) NewEraCracker
06:19 PM Revision 77669294: Apply the fix for ticket #6589 also into dhcpdv6 config
(cherry picked from commit 20350989db5d66ffb827beaed5ef5738cd62fc9d) NewEraCracker
06:19 PM Revision 3843c34a: Merge pull request #3107 from NewEraCracker/patch-10
Renato Botelho
06:05 PM Revision 5d892fd8: Indent dhcpd.conf option custom
(cherry picked from commit c507161d557817c1f6f0adbef9ffdbad82115ee8) Phil Davis
06:05 PM Revision 9a1ae6e6: Fix #6720 DHCP options by pool
It is a little bit tricky having to generate the unique "option custom-if-n-m code ..." lines at first where n = pool... Phil Davis
06:05 PM Revision 34a8cebe: Indent dhcpd.conf option custom
(cherry picked from commit c507161d557817c1f6f0adbef9ffdbad82115ee8) Phil Davis
06:05 PM Revision dc13f5e0: Fix #6720 DHCP options by pool
It is a little bit tricky having to generate the unique "option custom-if-n-m code ..." lines at first where n = pool... Phil Davis
06:04 PM Revision 067c8f54: Merge pull request #3112 from phil-davis/patch-1
Renato Botelho
06:03 PM Revision 93adc650: Fix double domain-name-servers for pool
Add a pool and specify something in 1 or more of the DNS servers boxes for the pool.
The "option domain-name-servers ...
Phil Davis
06:02 PM Revision 959f2bb8: Fix double domain-name-servers for pool
Add a pool and specify something in 1 or more of the DNS servers boxes for the pool.
The "option domain-name-servers ...
Phil Davis
06:02 PM Revision 2dfbd10f: Merge pull request #3110 from phil-davis/patch-2
Renato Botelho
05:59 PM Revision f2ac72d6: Fix #6724 VLAN interface displayed wrong
in interface assignment script dialog.
The str_replace() calls were not smart enough to just get rid of bare "igb1" ...
Phil Davis
05:57 PM Revision f851e667: Fix #6724 VLAN interface displayed wrong
in interface assignment script dialog.
The str_replace() calls were not smart enough to just get rid of bare "igb1" ...
Phil Davis
05:56 PM Revision 628fc6b6: Merge pull request #3114 from phil-davis/patch-3
Renato Botelho
03:27 PM Bug #6747: pfctl - getting high cpu usage
As discussed on IRC, his original pfctl usage was caused by the line below:... Pi Ba
02:10 PM Bug #6747: pfctl - getting high cpu usage
When pfblockerng counter widget is enabled too.
`-- sh -c /sbin/pfctl -vv -sr | /usr/bin/grep 'pfB_'
Rafael Cunha
01:53 PM Bug #6747: pfctl - getting high cpu usage
In case anyone need:
pfctl -sr | wc -l
8707
Rafael Cunha
01:50 PM Bug #6747 (Closed): pfctl - getting high cpu usage
When firewall logs is enabled on dashboard and update interval is set to a small time (5 seconds, ie), pfctl starts t... Rafael Cunha
01:10 PM Bug #6720: DHCPD Options in "Sub-"Pools ignored, dhcpd.conf does not contain informations, dhcpd therefore not serving
Applied in changeset commit:285987208f31f38abe35b984b08645d43c11b001. Phillip Davis
01:05 PM Bug #6720 (Feedback): DHCPD Options in "Sub-"Pools ignored, dhcpd.conf does not contain informations, dhcpd therefore not serving
Pull request has been merged. Thanks! Renato Botelho
12:59 PM Bug #6724 (Feedback): VLAN interface displayed wrong through interface assignment
Renato Botelho
 

Also available in: Atom