Project

General

Profile

Activity

From 10/03/2016 to 11/01/2016

11/01/2016

03:32 PM Todo #4706 (Feedback): MPD needs to be upgraded to version 5 even for the various other tunnels
PPPoE and L2TP were converted to use mpd5 in commit:8d50c07c8bfdd2692a0c7d3ca3489977b528aecc and commit:2c0a3677de6b6... Renato Botelho
02:53 PM Bug #6850 (Confirmed): FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
Renato Botelho
01:31 PM pfSense Packages Bug #5868 (Feedback): Quagga OSPF Priority value "0" (zero) is being ignored - DR election doesnt work properly.
I pushed a fix for this in package version 0.6.15. Jim Pingle
12:05 PM Bug #6883 (Confirmed): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
Jim Pingle
12:02 PM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
I ran some tests and can confirm the issue on 2.4 only.
2.3.3 and 2.4 run the same version of OpenVPN and have ide...
Jim Pingle
11:41 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
when i try to connect to pfsense web interface, there is block entry in firewall log:
lo0 10.10.111.231:81 _(pfsen...
Dmitry Ivanov
08:32 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
dev ovpns7
verb 1
dev-type tun
dev-node /dev/tun7
writepid /var/run/openvpn_server7.pid
#user nobody
#group nob...
Dmitry Ivanov
08:15 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
Still not enough info. Need to know all settings all the way down the page, especially the topology type. Would also ... Jim Pingle
07:57 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
it works on 2.3.*
i installed 2.4, and restored config from 2.3.3
openvpn server UDP/TUN
Server mode - Remote Ac...
Dmitry Ivanov
07:11 AM Bug #6883 (Feedback): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
Unless this was a working configuration on a previous version, it's more likely to be a configuration error. There is... Jim Pingle
05:11 AM Bug #6883 (Resolved): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
openvpn - UDP/TUN (TAP works)
clients connect to server, in the logs everything is fine, but no access anywhere.
wi...
Dmitry Ivanov
10:22 AM Bug #4723 (Feedback): Can't forward UDP fragmented packets with scrubbing enabled.
I tested the forwarding of fragmented ICMP and UDP packets and they seem to be working as expected on 2.4.
Could s...
Luiz Souza
10:19 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Remko Lodder wrote:
> Chris Buechler wrote:
> > I hit this issue with a customer last week. Worked fine after disab...
Luiz Souza
04:35 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
This is a workaround, not a clean solution.
Better than nothing, but a native, specific and definitive resolution is...
Luca De Andreis

10/31/2016

09:04 PM Revision 9d29322d: Do not attempt to remove interfaces from CP zone, captiveportal_configure_zone() will take care of it
Renato Botelho
08:31 PM Revision 0b8b5069: Check if pidfile is valid before try to send signal
Renato Botelho
03:36 PM pfSense Packages Bug #5868 (Confirmed): Quagga OSPF Priority value "0" (zero) is being ignored - DR election doesnt work properly.
Looks like it's a classic case of PHP returning "true" for empty() when passed a string of "0". I'll look into it. Jim Pingle
03:15 PM Bug #6882 (Resolved): bsnmpd uses all available CPU with hostres module active in some cases
Running 2.4, bsnmpd will consume all available CPU time when the hostres module is active. The CPU usage for geom als... Jim Pingle
12:19 PM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
Remko Lodder wrote:
> Chris Buechler wrote:
> > I hit this issue with a customer last week. Worked fine after disab...
Dominic Blais
10:04 AM Bug #6856: "Force Config Settings" buton on master causes slave to loss IP alises on lo0
Confirmed in 2.2.6 and 2.3.2_1 64bit. Steve Wheeler
07:12 AM Feature #6881 (Duplicate): services_unbound_host_edit.php: DNS Resolver Add V4 and V6 host override at the same time
Is there any chance of changing the setup of the Edit Host Overide page so you can add IPv4 and IPv6 addresses for th... Andy Kniveton

10/30/2016

01:08 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
So far I am happy with 2.4 running on ZFS, even it highly experimental, I use on one non so critical production firew... Vladimir Suhhanov

10/29/2016

10:12 PM Revision e8517c7c: interfaces, show error message if adding duplicate gateway
Pi Ba
10:08 PM Revision 33927941: ipsec mobile clients, don't check mobile leases if mobile client isn't enabled to begin with
Pi Ba
07:50 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic

Solution
fix Limiters on firewall rules where NAT applies drop all traffic
and
Problem Limiter blocks in...
gmar almnsoor
05:31 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Also affected... is there any plan to fix this in an upcoming release as it's a common use case jake keeys
04:03 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
Managed to completely destruct entire system by a _single_ power cycle. Unbootable, kernel panic, endless reboot cycl... Kill Bill

10/28/2016

08:17 PM Bug #6880 (Resolved): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
When configuring multiple interfaces as DHCP6, such as PPPoE DSL and Cable, multiple dhcp6c processes get started, on... Roy Hooper
05:47 PM Revision 393c1317: Always create a pipe for each allowed MAC or IP
Renato Botelho
05:44 PM Revision aab966f2: host_ips tables is not supposed to use pipes
Renato Botelho
03:11 PM Bug #6879 (Resolved): GUI doesn't show rebooting notification after upgrading
During upgrade to the latest version, GUI doesn't update fast enough and does not write a rebooting notification. To ... Ivor Kreso
06:18 AM pfSense Packages Bug #6875: dpinger not switching icmp id automatically
Luiz Otavio O Souza wrote:
> This is the same behaviour of ping (the icmp_id comes from the PID).
>
> So, when yo...
Tiziano Bacocco
12:52 AM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
So far the only thing I got from Martin was that -9 is not a nice way to stop quagga and could cause the issues... Al... Reqlez Guy

10/27/2016

05:26 PM Revision aa9cf3fa: Fix #6758
extensions.ini must be readable by any users otherwise any php script
called by a non-root user will not be able to u...
Renato Botelho
12:57 PM pfSense Packages Bug #6878 (Resolved): how to use snort, squid and squid_guard with a ram disk
create 2 directories in /root
mkdir /root/sauv_db_clamav/
mkdir /root/sauv_db_squidGuard/
you need to create a f...
sylvain sylvain
12:40 PM Bug #6758 (Feedback): 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
Applied in changeset commit:aa9cf3fa4d532e9f2dbd05d38ca438980b21e06b. Renato Botelho
12:37 PM Bug #6686 (Resolved): PHP extensions.ini cannot be read by non root users
Renato Botelho
09:33 AM Revision fc0e31d7: Import a patch to fix Net_IPv6::compress("::")
Obtained from: https://github.com/phil-davis/Net_IPv6/commit/638b96a253164b65c63825c38e79812b6c5f448d
Submitted by: ...
Renato Botelho
09:32 AM Revision f5febd77: Import a patch to fix Net_IPv6::compress("::")
Obtained from: https://github.com/phil-davis/Net_IPv6/commit/638b96a253164b65c63825c38e79812b6c5f448d
Submitted by: ...
Renato Botelho

10/26/2016

10:59 PM Revision 013110a1: 80 character lines ftw :)
Just because it was asked nicely :) Stilez y
10:12 PM Revision 97eebb23: coding layout fix
Stilez y
10:11 PM Revision c7e31e37: remove gettext() not needed
Stilez y
10:09 PM Revision fa16b2f9: add gettext() to icmptype descriptions
Stilez y
06:17 PM Revision 3e80d64e: Make sure we consume staging packages on build process after pfSense-repo became a package
Renato Botelho
06:16 PM Revision c497ae1d: Make sure we consume staging packages on build process after pfSense-repo became a package
Renato Botelho
06:16 PM Revision a014cf62: Make sure we consume staging packages on build process after pfSense-repo became a package
Renato Botelho
05:07 PM Revision 349b2102: ARM kernel is not compressed, deal with that
Renato Botelho
02:37 PM Bug #6802: GUI does not respond and vpn stops working
I too have seen this issue.
I bought a new newgate sg2440 running 2.3.2_1 and 1 week ago I used it to replace my o...
Adam Saint
09:03 AM Bug #6877: nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
That means nothing to how it's used on pfSense. One of the primary uses of certificates on pfSense is OpenVPN, and Op... Jim Pingle
08:41 AM Bug #6877: nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
OK. However, let me point out that, according to https://www.openssl.org/docs/manmaster/apps/x509v3_config.html, the ... Bruno Grossmann
08:28 AM Bug #6877 (Rejected): nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
Those are both authentication attributes, not the server property.
The GUI checks the cert to see if the nsCertTyp...
Jim Pingle
08:23 AM Bug #6877 (Resolved): nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
Using a GoDaddy server certificate. The server has both TLS Web Server Authentication and TLS Web Client Authenticati... Bruno Grossmann

10/25/2016

06:33 PM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
Note: This fix has been applied to RELENG_2_3 to fix the issue on FreeBSD 10.3/pfSense 2.3.*
In FreeBSD 11.0 (upco...
Phillip Davis
10:40 AM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
Applied in changeset commit:ed893ee55a248bea3a03d69a7e80b905a39a4f94. Phillip Davis
10:29 AM Bug #6869 (Feedback): Diagnostics / Routes Truncates Destination and Gateway Names
PR has been merged, thanks! Renato Botelho
03:56 PM Revision e37ecea9: Improve IPv4 address validation for services_dhcp
The input pattern that goes with Form_IpAddress by default allows for IPv4 and IPv6 valid characters. The back-end va... Phil Davis
03:55 PM Revision 892d8816: Merge pull request #3201 from phil-davis/patch-3
Renato Botelho
03:49 PM Revision b6417760: dyndns: add header processing in curl
some dyndns implementations rely on the correct HTTP header being set. the information was lost and now fixed. Christoph Filnkößl
03:47 PM Revision 0e0f580d: dyndns: add header processing in curl
some dyndns implementations rely on the correct HTTP header being set. the information was lost and now fixed. Christoph Filnkößl
03:42 PM Revision f85a1e53: Merge pull request #3192 from PiBa-NL/xmlrpc-auth
Renato Botelho
03:38 PM Revision bddeb146: Fix display advanced after input error for system_gateways_edit
Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo...
Phil Davis
03:38 PM Revision 06493ae0: Fix display advanced after input error for system_gateways_edit
Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo...
Phil Davis
03:37 PM Revision 1ace41be: Merge pull request #3200 from phil-davis/patch-2
Renato Botelho
03:35 PM Revision 7f798f24: Better handle no dhcpv6 leases file
(cherry picked from commit 2355c154b7598f937ba2121429659f5676ce4d96) Phil Davis
03:34 PM Revision 3e598cc9: Better handle no dhcpv6 leases file
(cherry picked from commit 2355c154b7598f937ba2121429659f5676ce4d96) Phil Davis
03:34 PM Revision bc6cefb7: Merge pull request #3197 from phil-davis/dhcp6
Renato Botelho
03:26 PM Revision 2674bfad: Merge pull request #3204 from phil-davis/patch-6
Renato Botelho
03:25 PM Revision 0b1715e9: Fix #6872 CP bandwidth 0 is no valid
The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit.
(cherry pick...
Phil Davis
03:25 PM Revision 4f131b02: Fix #6872 CP bandwidth 0 is no valid
The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit.
(cherry pick...
Phil Davis
03:25 PM Revision 4a1dc683: Merge pull request #3205 from phil-davis/patch-7
Renato Botelho
11:06 AM Revision 99a537e1: Make sure filterdns is disabled when CP zone is disabled
Renato Botelho
10:49 AM Bug #6874 (Feedback): Dynamic DNS w/ DNSimple
PR has been merged, thanks! Renato Botelho
10:35 AM Bug #6717 (Feedback): Status / DHCPv6 Leases Issues
PR has been merged, thanks! Renato Botelho
10:28 AM Bug #6872 (Feedback): Captive Portal per user bandwidth field no longer accepts 0.
PR has been merged Renato Botelho
08:15 AM Bug #6876 (Resolved): Firewall alias issue after adding a wrong alias

***** ALREADY POSTED ON FORUM : https://forum.pfsense.org/index.php?topic=119811.msg662795#msg662795 **************...
m de crevoisier
05:20 AM Feature #1219: Ship DTRACE enabled kernels in the images
+100500
Please, implement!
Alex Kolesnik
01:22 AM Revision 9945720f: Fix the ipfw rule to use the table cp_ifaces and not the interface cp_ifaces.
Luiz Souza

10/24/2016

09:26 PM Revision a4aebf44: Stop using -y on filterdns call
Renato Botelho
09:22 PM Revision 517b893e: Rework captive portal to run with stock IPFW (round 1)
- Remove use of IPFW context
- Create a rule that will skip to proper rule for each cp zone
- Use new PHP module func...
Renato Botelho
09:09 PM Revision 6344be46: REmove accidental text
Steve Beaver
09:08 PM Revision 2c38c5de: Remove accidental code
Steve Beaver
05:48 PM Bug #6272: Wrong numbers in state column of /firewall_rules.php
Ok thanks for the explanation Jo S
05:44 PM Bug #6272: Wrong numbers in state column of /firewall_rules.php
RELENG_2_3 is the development path towards (a possible) 2.3.3. It should therefore be fixed in recent builds of 2.3.3... Phillip Davis
03:03 AM Bug #6272: Wrong numbers in state column of /firewall_rules.php
Hi, by "RELENG_2_3" do you mean this should be already fixed in current stable 2.3.2-RELEASE-p1 ? Because the problem... Jo S
05:35 PM Bug #6874: Dynamic DNS w/ DNSimple
I stumbled on to the same problem just now when implementing a new dyndns provider.
The code was wrong for both the ...
Christoph Filnkößl
01:34 AM Bug #6874 (Resolved): Dynamic DNS w/ DNSimple
Around line 1380 in src/etc/inc/dyndns.class is a chunk of code that looks like this:... Michael Lustfield
03:46 PM Revision 3a5a205d: Revise login hostname dispaly
Steve Beaver
03:44 PM Revision c1077a75: Revert "Allow login hostname to be controlled via system.php"
This reverts commit cd6b99147a673b6bd0313fff55cab7eb6879608f. Steve Beaver
03:42 PM Revision cd6b9914: Allow login hostname to be controlled via system.php
Steve Beaver
03:37 PM Revision dd56aa5d: Added hostname to login page.
Option control required
(cherry picked from commit 616724395ae00a74fac4cf960ac2261b486e9dae)
Steve Beaver
03:36 PM Revision 506fe755: Provide conrol on system.php to allow display of hostname on login banner
(cherry picked from commit a22947a4980a9f8beb294d6bad039495164ff1aa) Steve Beaver
03:30 PM Revision a22947a4: Provide conrol on system.php to allow display of hostname on login banner
Steve Beaver
03:06 PM Revision 61672439: Added hostname to login page.
Option control required Steve Beaver
02:18 PM pfSense Packages Bug #6875: dpinger not switching icmp id automatically
This is the same behaviour of ping (the icmp_id comes from the PID).
So, when you have an issue with your ISP ping...
Luiz Souza
11:46 AM pfSense Packages Bug #6875 (Not a Bug): dpinger not switching icmp id automatically
I'm having a problem with dpinger that's not switching ICMP id when there's packet loss, for example in a CGNAT scena... Tiziano Bacocco
07:59 AM Bug #6870 (Closed): Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
@relayd@ is a part of the FreeBSD ports tree. It's not a piece of software that pfSense has ported or maintained. You... Jim Pingle
07:50 AM pfSense Packages Bug #6871 (Not a Bug): Squid Proxy Reports bug
Jim Pingle
04:16 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
I can word in on this, major issue. Martin Hansen
04:11 AM Revision 71bb3f01: Update the variable with the round() return otherwise it does not has any effect.
Found while testing Ticket #6272.
(cherry picked from commit 92130da3b5fb55588d351c22042c9ce8ab5883d7)
Luiz Souza
04:09 AM Revision 92130da3: Update the variable with the round() return otherwise it does not has any effect.
Found while testing Ticket #6272. Luiz Souza
12:32 AM Revision b7f2ebb5: Fix #6872 CP bandwidth 0 is no valid
The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit. Phil Davis

10/23/2016

11:58 PM Bug #5317: CSR signed certificates shows issuer as external
Seeing this as well, quite problematic for VPN usage. pfSense 2.3.2-RELEASE-p1. Andrew M
11:33 PM Bug #6272 (Resolved): Wrong numbers in state column of /firewall_rules.php
Fixed on 2.4 and RELENG_2_3.
pfSense_get_pf_states() now return the packet counters as doubles.
Luiz Souza
07:34 PM Bug #6872: Captive Portal per user bandwidth field no longer accepts 0.
The front-end validation is stopping a zero from being entered, so "Leave empty" is the (only) way to specify "no lim... Phillip Davis
11:00 AM Bug #6872 (Resolved): Captive Portal per user bandwidth field no longer accepts 0.
The text says "Leave empty or set to 0 for no limit." However input error checking in the browser now no-longer allow... Steve Wheeler
03:05 PM Bug #6873 (New): radvd - Too many addresses in RDNSS section when previously using DHCPv6
I have come across a bug within the IPv6 Router Advertising Daemon where you receive the following errors in the logs... Dominic McKeown
03:03 PM Feature #4259: Port forward NAT rules with "any" protocol
Could be it implemented with the new 2.4 release ? Giuanin Piemunteis
10:14 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
Turns out causing pfsense to not drop fragmented 'do not fragment' packets creates more problems than it solves. For... Harry Coin

10/22/2016

12:25 PM pfSense Packages Bug #6871: Squid Proxy Reports bug
I'm sorry but I'm a fool ... is necessarily open ports on your firewall application ( ports 7445 and 3000)
ALL OK
Claudio Berselli
05:28 AM pfSense Packages Bug #6871 (Not a Bug): Squid Proxy Reports bug

Installed from scratch pfsense, Proxy Server, Squid Proxy Reports.
If you try to access the page https: // pfSen...
Claudio Berselli
10:07 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
To be clear:
The workaround for relayd / DNS protocol failing or being seemingly intermittent when load balancing...
Harry Coin
10:04 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC

Update: dig and other dns query engines set the DF 'do not fragment' bit -- then go on to issue DNSSEC DNS querie...
Harry Coin
05:31 AM Revision ed893ee5: Fix #6869 diag_routes resolve names for RELENG_2_3
This code to parse the netstat output and use gethostbyaddr() to reverse resolve names is only needed in RELENG_2_3, ... Phil Davis

10/21/2016

08:15 PM Revision 8fc25403: Revert "Revert "Enable IPFW on PHP module""
This reverts commit 9fdd0c7ebb966df9b566acac091390c4a97fa8c7. Renato Botelho
03:29 PM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
Unlikely we can do much if anything for this, it's probably an issue in relayd itself and not the way we set it up. Y... Jim Pingle
03:25 PM Bug #6870 (Closed): Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
The built-in load balancer (relayd) has a protocol 'dns' that manages UDP dns queries. The purpose is to load balanc... Harry Coin
11:32 AM Revision 9fdd0c7e: Revert "Enable IPFW on PHP module"
This reverts commit c04887d8fc440e769ed987f993d34bc8f20fbf64. Renato Botelho
10:02 AM Bug #6863: pf states reset by CARP neighbor
Jim, thanks for your explanation! This what I'm trying to detect - what exactly clearing the states. I know, Redmine ... Alex Kolesnik
09:50 AM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
Discussion: https://forum.pfsense.org/index.php?topic=118679.0 → luckman212

10/20/2016

09:23 PM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
That is a "feature" of the netstat command, which has annoyed me too. With "-W" it does output the full data in some ... Phillip Davis
12:58 PM Bug #6869 (Resolved): Diagnostics / Routes Truncates Destination and Gateway Names
When "resolve names" is enabled, resolved destination and gateway names are truncated to 18 characters (e.g., pfSense... Daryl Morse
05:50 PM Revision c04887d8: Enable IPFW on PHP module
Renato Botelho
12:34 PM Bug #6868 (Resolved): Interface MTU Setting not applied to all IPv6 routes
Running 2.3.2_1 using an HE/64 tunnel. Adjusting MTU to troubleshoot possible PMTUD problem. Found that setting for M... Daryl Morse
10:47 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
I also use limiters and NAT reflection in combination. So I am stuck on 2.1.4 and 2.1.5 until a release where this co... Anders Tillebeck
09:50 AM pfSense Packages Bug #6129: zabbix agent/proxy 2.4 not ported to pfSense 2.3
Is there any way i can help with this. Or is there anything i can do to make this happen? Pim Janssen
08:35 AM Bug #4031: Notifications mail bomb in some gateway failure circumstances
Looking at a customer box today it made me realize a good path here would be to queue up the notifications in a file ... Jim Pingle
08:09 AM pfSense Packages Bug #6867 (Closed): Please update quagga to version 1.1
Quagga 1.1 fixes a lot of bugs:
http://mirror.yannic-bonenberger.com/nongnu/quagga/quagga-1.1.0.changelog.txt
N...
Cullen Trey
08:04 AM Revision eb01f065: Improve IPv4 address validation for services_dhcp
The input pattern that goes with Form_IpAddress by default allows for IPv4 and IPv6 valid characters. The back-end va... Phil Davis
07:18 AM Revision ebfcfeb5: Fix display advanced after input error for system_gateways_edit
Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo...
Phil Davis
05:48 AM Revision c982fdbc: Fix is_macaddr().
Hexadecimal numbers without the '0' padding are also valid, e.g:
a:b:c:d:e:f
Luiz Souza
05:47 AM Revision 6a546985: Remove "use lowercase" hint
As it is no longer relevant, because the code now automatically converts
to lowercase.
Phil Davis
04:21 AM Revision d461ff40: Fix #6864 automatically convert IPv6 input to lowercase
1) As the user leaves the field, or presses Save, onChange will fire and
convert the input string to lowercase. This ...
Phil Davis

10/19/2016

11:24 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
This one also automatically converts the input to lowercase as the user leaves the IP Address field, or presses a but... Phillip Davis
11:18 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
While I think it is cool to convert the characters as you type, the GUI has to accept upper case letters as well.
...
Luiz Souza
10:18 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
Pull request: https://github.com/pfsense/pfsense/pull/3198
That makes the "Please match the requested format:" text ...
Phillip Davis
09:20 AM Bug #6864 (Resolved): Error checking rejects IPv6 addresses with upper case A-F.
Recent browser changes mean this is rejected before the form is submitted and the error tool tip shown is unhelpful.
...
Steve Wheeler
05:38 PM Bug #6717: Status / DHCPv6 Leases Issues
I can confirm that this fixes the issue where the file exists but contains no leases. The lease file is still being p... Daryl Morse
04:30 PM pfSense Packages Feature #6866 (Rejected): Suricata multiple interfaces
I've set up Suricata on the WAN interface. When an alert happen I don't see what internal address caused the alert. I... Idar Lund
03:14 PM Bug #6865 (Rejected): DNS resolver : old issue returns
Please start a forum thread for discussion and diagnosis before opening a ticket. Also, upgrade to 2.3.2_1 first to e... Jim Pingle
03:11 PM Bug #6865 (Rejected): DNS resolver : old issue returns
2.3.2-RELEASE (i386)
built on Tue Jul 19 13:09:39 CDT 2016
FreeBSD 10.3-RELEASE-p5
nanobsd (4g)
When trying to...
mark allen
12:49 PM Feature #2358: NAT64 support
Too late for 2.4.0... Luiz Souza
04:39 AM Feature #2358: NAT64 support
UPVOTE Greg M
02:16 AM Feature #2358: NAT64 support
UPVOTE, word up on this. It should be prioritized significantly. Martin Hansen
08:32 AM Bug #6863 (Rejected): pf states reset by CARP neighbor
That is normal and expected when the two units are properly synchronizing states. Find what is clearing the states an... Jim Pingle
02:43 AM Revision 2355c154: Better handle no dhcpv6 leases file
Phil Davis

10/18/2016

09:53 PM Bug #6717: Status / DHCPv6 Leases Issues
https://github.com/pfsense/pfsense/pull/3197
That fixes the little side issue, where in fact the leases file exists ...
Phillip Davis
04:31 PM Bug #6717: Status / DHCPv6 Leases Issues
With regards to item 1, testing with one windows 10 client and no active leases, Status / DHCPv6 Leases reports "No l... Daryl Morse
01:20 PM Bug #6862: mode 0444 for /var/etc/cert.crt leads to nginx crit error: 13: Permission denied
title should have had protection of 0600, workaround changes it to 0644
Harry Coin
11:23 AM Bug #6862 (Resolved): mode 0444 for /var/etc/cert.crt leads to nginx crit error: 13: Permission denied
/var/etc/cert.crt has mode 0444, leading to
/var/log/nginx-error.log entries like
2016/10/16 16:06:14 [crit] 61476#...
Harry Coin
01:01 PM Revision 94bd7fb3: Fix #6828
Until 2.3.x pfSense carried a patch that changed the behavior of 'route
change' command, making it add the route when...
Renato Botelho
12:30 PM Bug #6863 (Rejected): pf states reset by CARP neighbor
There are two pfsense routers (version 2.3.2-RELEASE-p1, but I've faced this issue 1st time on 2.2.5/2.2.6) in HA mod... Alex Kolesnik
12:24 PM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
I started having this crash frequently as well. I'm running 2.3.2_p1. I do have DHCPv6 on one of my WANs (but I nee... → luckman212
12:04 PM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
Ken Sim wrote:
> Anytime I try and change any of the gateways that are checked non-local on the current snapshot it ...
Renato Botelho
11:43 AM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
Anytime I try and change any of the gateways that are checked non-local on the current snapshot it locks up pfsense a... Ken Sim
08:35 AM Bug #6850 (Feedback): FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
I couldn't replicate it after fixes I pushed for #6828. Can you try the next round of snapshots? Renato Botelho
11:16 AM Bug #6858: 2.3.X is not properly updating packages
Renato, thank you for the write up.
Does this cover file /usr/local/lib/php/20131226/suhosin.so? This shared objec...
Denny Page
05:16 AM Bug #6858 (Not a Bug): 2.3.X is not properly updating packages
Actually it's not a bug, it's expected and it's how pkg is designed to work.
When we moved to 2.3.2_1 we cherry-pi...
Renato Botelho
08:10 AM Bug #6828 (Feedback): Patch for "route change" is not present on 2.4 builds using FreeBSD 11
Applied in changeset commit:94bd7fb3a52e375dcd25c416e36389f96060a8fd. Renato Botelho
07:46 AM pfSense Packages Bug #6861 (New): Ha-Proxy duplicated backend used in place of original backend
Hello,
Find hereafter a problem on ha-proxy 0.48 / 1.6.6 package.
Steps to reproduce :
- Create a configurati...
Stéphane DAGUET

10/17/2016

04:01 PM Bug #6860 (Resolved): Monitoring (RRD) graphs return "unknown" step value
There seem to be cases where rrd_fetch_json.php returns a step value that isn't located in the javascript lookup tabl... Jared Dillard
12:56 PM pfSense Packages Feature #6859 (Resolved): have an includedir by default (sudo package)
I'm trying to customize sudo and the options I'm looking for aren't in the GUI. Is there a way to include this line i... Brendon Baumgartner
04:33 AM Bug #6099: igmpproxy does not recognize upstream interface
I have the same problem with the 20160905_1818 version.
The _all version works fine on ISP XS4All in The Netherlands...
Michiel Lowijs
03:14 AM Feature #2573: Captive Portal support of RADIUS POD (Packet of Disconnect)
POD is useful when replacing Expiration date in Pfsense user manager.
The Option " re-authenticate users every minu...
Muhammed Ismail
12:10 AM Bug #6858 (Not a Bug): 2.3.X is not properly updating packages
2.3.X is not updating files properly. See forum thread https://forum.pfsense.org/index.php?topic=119344.msg662359#msg... Denny Page

10/16/2016

10:37 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
The patch you posted only prevents Unbound from being restarted by performing GUI actions, not automatically when a n... Anonymous
10:50 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
Note this potentially related bug report:
https://github.com/opnsense/core/issues/1184
"
Adding an IPv6 CARP V...
Harry Coin
10:47 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
The issue manifests as the 'backup' machine in the carp set being unable to ping6 (or otherwise pass packets to) the ... Harry Coin
01:08 AM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
It would be good to make target version 2.4 instead of nothing. Thanks. Vladimir Suhhanov

10/15/2016

11:16 PM Bug #6856: "Force Config Settings" buton on master causes slave to loss IP alises on lo0
Sent pull-request: https://github.com/pfsense/pfsense/pull/3195 Pablo Ruiz
12:08 PM Bug #6856 (Duplicate): "Force Config Settings" buton on master causes slave to loss IP alises on lo0
Hi,
We have a two couple of node HA setup with pfsense latests version running (2.3.2p1). This cluster has a few v...
Pablo Ruiz
10:07 PM Bug #6857: local_sync_accounts fails during boot when using ldap on a non-local network or hostname
I've just sent a pull-req: https://github.com/pfsense/pfsense/pull/3194 Pablo Ruiz
08:54 PM Bug #6857 (Resolved): local_sync_accounts fails during boot when using ldap on a non-local network or hostname
Hi,
When using an LDAP server on a non-local (ie. accesible thru a gateway) network, the system takes 10+ minutes ...
Pablo Ruiz
03:06 PM Revision b77a6394: increase webgui usability when the remote ldap server isn't available
Pi Ba
03:04 PM Revision ae346354: php fatal error logging
Pi Ba
02:58 PM Revision dc5f639f: xmlrpc, use authentication through the basic auth header instead of extra user/pass parameters
Pi Ba

10/14/2016

11:29 PM Revision d672403c: Added STARTTLS to LDAP Auth Server Config
derelict-pf
06:53 PM Feature #6855 (Resolved): Support STARTTLS in LDAP Server Configuration
Add STARTTLS to the available LDAP Server modes.
Chris Linstruth
02:32 PM Bug #6854 (Rejected): webconfig error with LDAP authenticated users for certmgr
The local admin user is the only user that can successfully work with certificates.
Other users authenticating off o...
Scott Fulkerson
02:04 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
Nate Baker wrote:
> Jim Pingle wrote:
> > Someone who can reproduce it reliably needs to get the details of how to ...
Reqlez Guy
12:56 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
Jim Pingle wrote:
> Someone who can reproduce it reliably needs to get the details of how to reproduce it reported t...
Nate Baker
12:15 PM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain

Also I am having the same problem in versãoo 2.3.2-RELEASE-p1. For some in the forum saw what worked the Place hum ...
Pablo Santos
12:05 PM Revision 80762aaa: Make setup_serial_port() write config files safely
This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po...
Renato Botelho
12:05 PM Revision 1a6cb937: Change safe_write_file $content parameter to accept an array
Renato Botelho
12:05 PM Revision a942d5b2: Make $force_binary parameter optional, default to false
Renato Botelho
12:05 PM Revision 72ca7e40: Prevent /etc/ttys to miss essential lines
We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason...
Renato Botelho
12:04 PM Revision 6172f3de: Make setup_serial_port() write config files safely
This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po...
Renato Botelho
11:51 AM Revision 406ced77: Change safe_write_file $content parameter to accept an array
Renato Botelho
11:51 AM Revision e717f161: Make $force_binary parameter optional, default to false
Renato Botelho
11:51 AM Revision 237d29c4: Prevent /etc/ttys to miss essential lines
We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason...
Renato Botelho
11:49 AM Revision 4e3bf4aa: Make setup_serial_port() write config files safely
This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po...
Renato Botelho
11:49 AM Revision 952ff2cb: Change safe_write_file $content parameter to accept an array
Renato Botelho
11:49 AM Revision e9c60f20: Make $force_binary parameter optional, default to false
Renato Botelho
11:49 AM Revision 7fa3bcae: Prevent /etc/ttys to miss essential lines
We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason...
Renato Botelho

10/13/2016

08:49 PM Bug #6717: Status / DHCPv6 Leases Issues
Phillip Davis wrote:
> As part of removing nanobsd support, it was noticed that dhcp6 leases were not being restored...
Daryl Morse
06:17 PM Bug #6717: Status / DHCPv6 Leases Issues
As part of removing nanobsd support, it was noticed that dhcp6 leases were not being restored on systems with use_mfs... Phillip Davis
03:47 PM Bug #6717: Status / DHCPv6 Leases Issues
Daryl Morse wrote:
> I'm running 2.3.3.a.20160815.2144 with PR 3102/1, 3102/2, 3103, 3105, 3106 and 3107, testing th...
Daryl Morse
04:36 PM Bug #6099: igmpproxy does not recognize upstream interface
I have the same issue like Dora Paule with the version: igmpproxy_20160905_1818.zip
There is no such problem with t...
Philipp Haefelfinger
03:51 PM Bug #5993: dhcp6c not started until an RA received
Updating this issue based on 2.4 development snapshot.
The dhcp6 before RA feature has been working perfectly sinc...
Daryl Morse
03:08 PM Revision a4cd0c5f: Fix up help text on outbound NAT.
Jim Pingle
03:08 PM Revision b533da85: Fix up help text on outbound NAT.
Jim Pingle
02:43 PM Revision 3d69cce5: Clarify source port warning when editing a firewall rule.
Jim Pingle
02:42 PM Revision 7ea6dabe: Clarify source port warning when editing a firewall rule.
Jim Pingle
02:21 PM Revision 00fc1317: In the setup wizard, do not change the DHCP range if it is already set inside the new subnet. Otherwise it will overwrite a range set manually from the DHCP settings or the console when the wizard is run later. Fixes #4820
Jim Pingle
02:21 PM Revision d02ee138: In the setup wizard, do not change the DHCP range if it is already set inside the new subnet. Otherwise it will overwrite a range set manually from the DHCP settings or the console when the wizard is run later. Fixes #4820
Jim Pingle
01:39 PM Revision 2329b5a8: DHCPV6 only check VIPs in range if range valid
If the user has input invalid values into range from and to, then there
is no point checking any IPv6 VIPs to see if ...
Phil Davis
01:39 PM Revision 77179b26: Merge pull request #3190 from phil-davis/dhcpv6
Renato Botelho
01:38 PM Revision 004b752e: Add extra validations on is_inrange_v[46]
Verify if addresses are valid IP address before convert them to make
numeric comparison.
While here, adjust indent.
...
Renato Botelho
01:36 PM Revision 8c48089f: Add extra validations on is_inrange_v[46]
Verify if addresses are valid IP address before convert them to make
numeric comparison.
While here, adjust indent.
...
Renato Botelho
01:25 PM Revision ef30fa51: Replace underscore with hyphen in option names
Thanks Jorge
(cherry picked from commit 30786a9d2486d88cb92cbb0ecb10586b39c32c65)
NOYB NOYB
01:25 PM Revision 8e4af832: Merge pull request #3188 from NOYB/GitSync_Min_Diff_Combo
Renato Botelho
01:24 PM Revision b4415260: Make unlink_if_exists return true/false
This allows the caller to do a single "atomic" call to unlink_if_exists.
If it returns true, then they know that the ...
Phil Davis
01:24 PM Revision bd9e1327: Merge pull request #3186 from phil-davis/unlink_if_exists
Renato Botelho
01:20 PM Revision e90ca528: Restore dhcp6 leases on full install when using MFS /tmp. While here, fix indent
Renato Botelho
01:15 PM Revision 42ebf952: Restore accidentally removed block
On dc61252ae the code used to restore dhcp6 leases when platform was
nanobsd was removed, but this code is supposed t...
Renato Botelho
12:48 PM Revision a5562d72: Remove commented code
(cherry picked from commit 0186b761e05d6f707ddc9cf1898d20ffb7ef9405) Valentin Neacsu
12:48 PM Revision 40ce5d72: Bring up the wifi interface only after setting up all the other arguments. This prevents issues when using VAPs.
(cherry picked from commit 6416317a239e082b7702957263a51b4052ae43b5) Valentin Neacsu
12:48 PM Revision b76b52ae: Merge pull request #3180 from valneacsu/fix_wifi_1st_VAP_params
Renato Botelho
09:30 AM Bug #4820 (Feedback): DHCP Scope at setup
Applied in changeset commit:d02ee1387fdb159bfb7cb9495003f66545d97989. Jim Pingle
09:13 AM Bug #4820 (Assigned): DHCP Scope at setup
What appears to happen is that the wizard resets the range even if the existing range is valid. So if you have x.x.x.... Jim Pingle
02:22 AM Revision 3707ffc4: DHCPV6 only check VIPs in range if range valid
If the user has input invalid values into range from and to, then there
is no point checking any IPv6 VIPs to see if ...
Phil Davis
01:51 AM Revision 30786a9d: Replace underscore with hyphen in option names
Thanks Jorge NOYB NOYB
01:31 AM Revision d96a39ba: Make unlink_if_exists return true/false
This allows the caller to do a single "atomic" call to unlink_if_exists.
If it returns true, then they know that the ...
Phil Davis

10/12/2016

08:38 PM Revision 0186b761: Remove commented code
Valentin Neacsu
07:30 PM Revision 4b65536a: Update pot
Renato Botelho
07:29 PM Revision dc61252a: Deprecate nanobsd platform and remove all conditionals that uses it
Renato Botelho
07:23 PM Revision 9ed7f8f6: Retire rc.nanobsd_switch_boot_slice
Renato Botelho
07:23 PM Revision 0c2dffb0: Define a single value for 'default_config_backup_count'
Renato Botelho
07:23 PM Revision b55c6b82: Remove unused global var 'hidebackupbeforeupgrade'
Renato Botelho
07:23 PM Revision 1289c0c1: Remove all calls to conf_mount_r* functions
Renato Botelho
07:23 PM Revision eec44c64: Retire restart_httpd.php
Renato Botelho
06:27 PM Revision 60f164f3: Retire cdrom platform support
Renato Botelho
06:12 PM Revision f68a881c: Remove unused global config item 'update_manifest'
Renato Botelho
06:10 PM Revision 3f4a0df9: Remove hideplatform global config and all uses of it
Renato Botelho
06:09 PM Revision 337e6a26: Remove unused global item 'nopkg_platform'
Renato Botelho
06:03 PM Revision a5e59e25: Retire refcount functions. They are not used anymore
Renato Botelho
06:02 PM Revision 9f08c2b0: Retire diag_nanobsd.php
Renato Botelho
05:59 PM Revision ffab5cb4: Obsolete conf_mount_ro() and conf_mount_rw()
Now that nanobsd is gone these functions are not necessary anymore.
Keep them around until all calls are cleaned up
Renato Botelho
04:20 PM Revision 87fb4454: Allow Hyphens in DHCP NTP Server form validation
Also removes the ability to have underscores `_` in ntp server
FQDNs.
Closes #6806
(cherry picked from commit c68db...
Eddie Hurtig
04:20 PM Revision dd3d6c8a: Merge pull request #3151 from EdHurtig/eng/6806
Renato Botelho
04:18 PM Revision ab4d9c9b: Format file_notice alerts in webgui with newline characters as <br/> for easier reading.
(cherry picked from commit 348fae16e4c4735afef619184fba76b97effd875) Pi Ba
04:18 PM Revision bc0a0c2e: Merge pull request #3154 from PiBa-NL/filenoticeBR
Renato Botelho
04:15 PM Revision ebcb7042: Simplify tcsh prompt and respect default terminal colors
Renato Botelho
04:15 PM Revision 4e04d896: Simplify tcsh prompt and respect default terminal colors
Renato Botelho
04:02 PM Bug #6828: Patch for "route change" is not present on 2.4 builds using FreeBSD 11
Jim Pingle wrote:
> On 2.3 we have a patch to alter the behavior of "route change" so that it adds a route if it's n...
Daryl Morse
03:51 PM Revision b9f6e351: lowercasing and sprintf of setHelp
(cherry picked from commit 705679339705657832422f5fdc336b5e39d48b79) Stilez y
03:51 PM Revision 59db5c43: label src/dst incorrect - fixed (minor)
(cherry picked from commit a309ffa5cc1e8682bb083f9288f73f43a2a9c282) Stilez y
03:51 PM Revision 9a211d3a: UI improvement - src port button label and src port help msgs
1. Rename "srcportadv" to "srcporttoggle" - not ideal to have 2 fields both labelled "advanced options". This present... Stilez y
03:51 PM Revision d8746bc0: Merge pull request #3140 from stilez/patch-39
Renato Botelho
03:49 PM Revision 9a3261c1: Merge pull request #3153 from NewEraCracker/RELENG_2_3_2+
Renato Botelho
03:45 PM Revision c58cdd42: Remove unused arg in get_pkg_info()
The 2nd argument ($info) isn't used in that function, and doesn't seem to be used anywhere else in the codebase.
(che...
Stilez y
03:45 PM Revision ceea9d9c: Merge pull request #3156 from stilez/patch-43
Renato Botelho
03:41 PM Revision 53b9a2ac: Report quantity of files being installed by minimal and diff options.
Also consolidate some unset commands.
(cherry picked from commit 32912ae833a016784cbb4813c45960cefc2d896b)
NOYB NOYB
03:41 PM Revision b19c8033: Support minimal and diff options combo rather than diff superseding minimal (sync both updated and diff files).
Break verbose option in two for showing files and/or constructed command. (--show_files, --show_command)
Don't save ...
NOYB NOYB
03:41 PM Revision f725a312: Merge pull request #3168 from NOYB/GitSync_Min_Diff_Combo
Renato Botelho
03:39 PM Revision 257120b9: Use tabs consistently
(cherry picked from commit 553de3973dfdb0539a64510666976d523a21f2f9) Valentin Neacsu
03:39 PM Revision e11a24f8: Re-enable executing the wifi mode command first. This fixes channel changing, which broke in d325e90818db2b22fc2562c38493769f217230f2.
(cherry picked from commit 8318da5192905a400076d5539ae86afeae82ee03) Valentin Neacsu
03:39 PM Revision 9eab8448: Merge pull request #3169 from valneacsu/fix_wifi_channel_change
Renato Botelho
03:37 PM Revision 9fc8273a: Fixup ntpd IPv6 restrict clauses.
This should eliminate the following errors from the ntpd log file when
using IPv6 or dual-stack networks:
"syntax err...
Leland Roach
03:37 PM Revision 836bb622: Fixup ntpd IPv6 restrict clauses.
This should eliminate the following errors from the ntpd log file when
using IPv6 or dual-stack networks:
"syntax err...
Leland Roach
03:37 PM Revision ec6e6666: Merge pull request #3171 from phroggster/patch-2
Renato Botelho
03:33 PM Revision 66ee91c2: add array index how value for authserver list
(cherry picked from commit db0c1e142c98a6253204d69218557b91a8754337) Bruno Ferri
03:33 PM Revision 83f7fabd: Merge pull request #3177 from brunostein/fix_authmode_translated
Renato Botelho
03:30 PM Revision 74dd2936: Only configure wireless MAC address if a spoofed MAC address is set
(cherry picked from commit a6c4a66da2ee8b0d4d54480dd690700b8c16bb13) Valentin Neacsu
03:30 PM Revision 90d0e0e0: Merge pull request #3179 from valneacsu/fix_wifi_settings_overwrite
Renato Botelho
03:22 PM Revision a3a89277: Improve gwlb.inc notification mechanisms
1) Unlink earlier to reduce the chances of any concurrency issues;
2) Translate and improve output of available notif...
NewEraCracker
03:21 PM Revision 58c0e164: Merge pull request #3184 from NewEraCracker/gwlb-fix
Renato Botelho
03:12 PM Todo #6755 (Resolved): Remove GLXSB references from 2.4
All gone. Jim Pingle
03:11 PM Bug #6821 (Resolved): Static ARP attribute not applied when saving a DHCP static mapping
Works Jim Pingle
03:06 PM Feature #6822 (Resolved): diag_arp.php: Teach the ARP Table display to also display the status
Works great Jim Pingle
03:02 PM Bug #6849 (Resolved): OpenVPN cipher list output changed, breaking the GUI list of ciphers
Appears to be working correctly on 2.3.3 and 2.4 snapshots. Jim Pingle
02:49 PM Bug #6739 (Resolved): OpenVPN compression settings in the GUI are no longer translated into the correct running options.
This seems to be OK now. The comp-noadapt change was confirmed to work on an affected system (remote client had no LZ... Jim Pingle
02:49 PM Bug #6719 (Resolved): OpenVPN DNS Leak Windows 10
New options are being pushed correctly when selected. Jim Pingle
02:48 PM Revision d3007fbe: Remove invalid parameter --flash-size
Renato Botelho
02:34 PM Todo #6853 (Resolved): Convert nanobsd installation to full install during upgrade
2.4 doesn't support nanobsd anymore, convert all nanobsd installations to full install during upgrade from 2.3 to 2.4... Renato Botelho
02:08 PM Revision 54596b88: Improve gwlb.inc notification mechanisms
1) Unlink earlier to reduce the chances of any concurrency issues;
2) Translate and improve output of available notif...
NewEraCracker
11:44 AM Bug #6650: Option needed to disable HSTS
Having same issue, all HTTP sites are also broken like the original example. Need option in pfsense to disable HSTS. Adam Piasecki
11:30 AM Bug #6806 (Feedback): Form validation for DHCP NTP Servers does not allow hyphens
Applied in changeset commit:c68dbfc7580180cd9d47bdbecaeeb6cf835fe210. Anonymous
10:34 AM Revision e01e164c: Backport save_widget_settings with 3 arguments from RELENG_2_3
Commit 6f1410582412fe771f51bd8b67bcbb952da97db6 introduced code relying on this NewEraCracker

10/11/2016

11:19 PM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
Travis Erdmann wrote:
> Now that FreeBSD 11 is out and PPPoE Gig internet is becoming more available, can we take an...
Sebastian Foss
09:11 PM Bug #6852: Commit 8f86722 breaks DHCPv6 leases status page
Also see #6543 Nick Venenga
09:00 PM Bug #6852: Commit 8f86722 breaks DHCPv6 leases status page
Affected version 2.3.2 (bug introduced in 2.3.2) Nick Venenga
08:56 PM Bug #6852 (Duplicate): Commit 8f86722 breaks DHCPv6 leases status page
The commit in question changed the awk pattern used when getting DHCPv6 information from the lease file. The pattern ... Nick Venenga
07:07 PM Bug #4669: QinQ virtual interfaces available for assignment where they shouldn't be
The patch 1. is missing on 2.3.2-RELEASE-p1. Booting system with QinQ interfaces assigned will only trigger vlan assi... Timo Nieminen
06:58 PM Revision 3154be54: Simplify TARGET and TARGET_ARCH initialization
Renato Botelho
06:57 PM Revision 2ac4be3a: Remove nanobsd related code from build scripts
Renato Botelho
04:38 PM Revision bd4e0194: Remove unused variable
Renato Botelho
03:47 PM Revision 4fd1130f: Adjust parsing of OpenVPN ciphers to new output format. Fixes #6849
Jim Pingle
03:47 PM Revision 2002cf66: Adjust parsing of OpenVPN ciphers to new output format. Fixes #6849
Jim Pingle
02:19 PM Feature #6851 (Resolved): System Information Widget
Just some feedback, it seems a bit redundant to show "pfSense" under System and Platform, would it not make more sens... Ken Sim
01:34 PM Bug #4820: DHCP Scope at setup
Chris Buechler wrote:
> can't replicate any issues here. Change the LAN IP and DHCP scope at the console, and it imm...
Al Lotufo
01:05 PM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
I am not sure if this is related or not, all I know is on 2.4 the option does not work, and the only way I am able to... Ken Sim
12:31 PM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
It's also possible you were hitting #6828 which needs to be solved first before other routing issues. Jim Pingle
12:29 PM Bug #6850 (Resolved): FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
Upon testing out one of the 2.4 snapshots a few weeks ago, I was unable to get network connectivity with a gateway th... Ken Sim
11:06 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
Kill Bill wrote:
> @Derek: If you are willing to go back to <=2.2.2 for initial full install, you could try this: ht...
Derek Jackson
11:00 AM Bug #6849 (Feedback): OpenVPN cipher list output changed, breaking the GUI list of ciphers
Applied in changeset commit:2002cf6636b2d29c066ee58511dce2baf5167b97. Jim Pingle
10:46 AM Bug #6849 (Resolved): OpenVPN cipher list output changed, breaking the GUI list of ciphers
The output for @openvpn --show-ciphers@ changed which broke the GUI parsing of the list, leaving only "None" as an op... Jim Pingle
08:50 AM Feature #6847: Register CN of OpenVPN clients in DNS Resolver
PR here: https://github.com/pfsense/pfsense/pull/3183 znerol znerol
01:32 AM Bug #3330: Load Balancer showing wrong Status when using aliases for the port
Can confirm the bug still exists in pfsense 2.3.2-RELEASE-p1 Kilian Ries
12:40 AM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
BBcan177 . wrote:
> Some users have also reported issues with the Unbound Resolver and pfBlockerNG DNSBL. I am not a...
ky41083 -
12:17 AM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
Patch Posted: https://forum.pfsense.org/index.php?topic=119467.0 ky41083 -

10/10/2016

11:50 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
Some users have also reported issues with the Unbound Resolver and pfBlockerNG DNSBL. I am not able to reproduce, but... BBcan177 .
09:32 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
If the dev's won't / can't answer you, I will. Due to changes in 2.3 (I tested with 2.3.2p1), restarting of the Unbou... ky41083 -
11:44 PM Revision 64651a20: Do not try to build grub2-bhyve on i386
Renato Botelho
11:44 PM Revision e9252aef: Fix filename
Renato Botelho
11:43 PM Revision 65de9b93: Make it possible to create a exclude list for each architecture for poudriere bulk list
Renato Botelho
11:38 PM Revision c8021930: Revert "Do not try to build grub2-bhyve on i386"
No more i386 on this branch. Reverting unnecessary change
This reverts commit 22558bc3011c10fc86c45b7ca795227bc9a4137c.
Renato Botelho
11:36 PM Revision 22558bc3: Do not try to build grub2-bhyve on i386
Renato Botelho
10:58 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
Jim Pingle wrote:
> Someone who can reproduce it reliably needs to get the details of how to reproduce it reported t...
Reqlez Guy
10:55 PM Revision 98a1a30d: Disable next repo on i386
Renato Botelho
06:59 PM Feature #4821: PPPoE WANs do not take full advantage of NIC driver queues for receiving traffic
Now that FreeBSD 11 is out and PPPoE Gig internet is becoming more available, can we take another look at this? Travis Erdmann
05:15 PM Revision ce6e6519: Create pkg.conf with ABI settings
Renato Botelho
05:15 PM Revision f09b1eb2: Create pkg.conf with ABI settings
Renato Botelho
03:27 PM Bug #6823: No connectivity after changing link state to UP
Patch for review here:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=213283
C S
12:02 PM Bug #6848 (Resolved): Do not create an IPv4/6 gateway for an interface without according IPv4/6 address
This issue has been fixed for GIF/GRE tunnels some time ago but wasn't fixed other kind of interfaces.
Once, I had...
Dmitriy K
12:01 PM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
@Derek: If you are willing to go back to <=2.2.2 for initial full install, you could try this: https://forum.pfsense.... Kill Bill
10:46 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
Thank you for your quick reply. I'll just need to wait to see what comes of all of this. Derek Jackson
11:11 AM Feature #6847: Register CN of OpenVPN clients in DNS Resolver
There is an error in the script. @case "$1" in@ should read @case "$OP" in@. znerol znerol
11:10 AM Feature #6847 (Resolved): Register CN of OpenVPN clients in DNS Resolver
Use case: Serial port servers deployed in the field connect to the office via OpenVPN. In order to collect the data, ... znerol znerol
09:36 AM Feature #6832: [PATCH] Add the USB ID for the Sierra MC7430
stable/11:
https://github.com/freebsd/freebsd/commit/da55bad8726390191aad745ef726a492885d7422
stable/10 (just i...
Jose Luis Duran
08:29 AM Revision f84c1e1e: [theme] Compact-RED: fix `sortable` table fonts
Alexander Moisseev

10/09/2016

08:39 PM Bug #6846 (Resolved): System misreporting Super Micro C2558 platform as Super Micro C2758
On my Dashboard system reads
"System Super Micro C2758"
but under CPU (and the correct info)
"CPU Type Int...
Travis Erdmann
07:48 PM Revision 6416317a: Bring up the wifi interface only after setting up all the other arguments. This prevents issues when using VAPs.
Valentin Neacsu
04:50 PM Feature #4372: dnscrypt support
Chris Buechler wrote:
> It'd be nice to have dnscrypt support built-in so people don't need hacks like
> https://do...
Steve Thomas
03:33 PM Feature #5616: Incorrect Wireless Channel
I ran into the same issue when using an ath interface and virtual interfaces in hostap mode (VAPs). I have a similar ... Anonymous
02:05 PM Revision 2b0bcf38: Repo package is not part of core repository anymore
Renato Botelho
02:05 PM Revision 5e6d8f6a: Move pfSense-upgrade to FreeBSD-ports
Renato Botelho
02:04 PM Revision 8570b109: Move pfSense-repo package to FreeBSD-ports repo
Renato Botelho
09:05 AM Feature #6845 (New): DHCP / DHCPv6 WAN client status page
Would be nice to have a status page that provides all the details of client leases and PDs. Corey Boyle

10/08/2016

05:55 PM pfSense Packages Bug #6756: Updating cloned backend in WebGUI updates the original backend instead of the cloned backend
I think it fixed in 0.50 .
https://github.com/pfsense/FreeBSD-ports/commit/36e0556b6b19a8a524a4ba3a7c55f87e9a6bd6a...
Pi Ba
05:51 PM pfSense Packages Bug #6784: HAProxy version .48 will not use URL Table Alias for front end listener
Imho a 'feature request' indeed. The support for 'fixed' lists of ports and ip's is ok for easy configuration with th... Pi Ba
05:36 PM Revision e10d25b4: Added support for CloudFlares Proxy.
Included a checkbox to enable and disable this feature when CloudeFlare
type is selected.
Included proxied variable i...
CarlGill
08:58 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
Derek, I cannot see any fix until the installer brings back the possibility to install on ZFS, and/or use a time-prov... Kill Bill
08:58 AM pfSense Packages Feature #6844 (Closed): Web configuration for quagga ospf6d
The quagga package includes the ospf6d binary, but there is no way to configure it via the admin GUI Brian Candler
02:45 AM Bug #6843 (Not a Bug): Version inconsistency after updating to 2.3.2_1
Looking at the dashboard view It doesn't look like I've upgraded to 2.3.2_1. Update page says that I have. See attach... Ivan Pedersen

10/07/2016

08:37 PM Revision 215c86be: Repo package is not part of core repository anymore
Renato Botelho
07:11 PM Revision b6355bdc: Latest nginx requires /var/log/nginx/ to exist, so for users with /var in RAM it needs created.
Jim Pingle
07:11 PM Revision f56f6565: Latest nginx requires /var/log/nginx/ to exist, so for users with /var in RAM it needs created.
Jim Pingle
07:06 PM Revision 0a1daa73: Fix typo: The input field is named source_hash_key
(cherry picked from commit 870b9bc11b993ce8122b448083d29a04bcb30151) NewEraCracker
07:05 PM Revision 9b9065d1: Fix static blackhole routes. Bug was introduced in
8be135cd114fbc9294ec9dafed2125d0e553956c (February, 2013).
(cherry picked from commit 580bef1ee3052437487553fcc5dc84...
Leland Roach
07:05 PM Revision b65bfb62: Spelling mistake "system_gateways.php"
Fix spelling mistake in "system_gateways.php"
(cherry picked from commit 47180823dc0560801085a227abf512e265363b16)
Colin Fleming
06:29 PM Revision 7bc886c6: Move pfSense-upgrade to FreeBSD-ports
Renato Botelho
05:20 PM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
Kill Bill,
We have been effected by this issue as we have boxes all around America running that are bricking at r...
Derek Jackson
04:18 PM Revision 39f2cfd1: Move pfSense-repo package to FreeBSD-ports repo
Renato Botelho
03:45 PM Feature #6842: Package Manager progress bar should indicate overall progress
To provide an "overall" progress would require that we know the exact size of everything that has to be downloaded ah... Anonymous
03:06 PM Feature #6842 (New): Package Manager progress bar should indicate overall progress
When installing a package with dependencies, and particularly when upgrading the base system made up of dozens of pac... Christian Ullrich
01:36 PM Bug #6557: nanobsd upgrades may fail from lacking resolv.conf
Sorry, but it seems not to be solved. I just upgraded from 2.3.2 to 2.3.2-p1 (NanoBSD) and the procedure still hangs ... Andrew Hotlab
12:56 PM Feature #6626: Support for IPv6 firewall entries with dynamic delegated prefix and static host address
Another place this would be handy is when configuring server options in DCHPv6 and RAs. Corey Boyle
10:16 AM Bug #6810 (Duplicate): bsnmpd logspam - hrPrinterTable: printcap entry for <noname?> has errors, skipping
Duplicate of #6838 (which has a workaround on it) Jim Pingle
10:16 AM Bug #6838: bsnmpd logs errors when /etc/printcap is missing
Somehow I completely missed that ticket when looking into this. I'll close the older one out since this one has a via... Jim Pingle
10:15 AM Bug #6838: bsnmpd logs errors when /etc/printcap is missing
Yeah, filed this as #6810, please close that one as duplicate. Kill Bill
07:35 AM Bug #6064: non-fully qualified hostnames included in hosts file and Unbound local-data
This didn't make it into 2.3.2_p1 right? Just checking. FWIW I have been running a couple of patched systems with t... → luckman212
05:50 AM pfSense Packages Bug #4756: OpenVPN Client Export fails when using "real" certificate
A scenario not so bizarre:
* Company has an internal PKI that they use to issue certificates for workers (and other ...
David Santos
05:31 AM Feature #6841 (Resolved): reduce numeric precision in Gateways Widget
Currently the v2.3.x Gateways Widget is displaying 3 digits after the decimal point for the gateway RTT & RTTsd value... David Burns
02:04 AM Feature #3506: Firewall:Aliases - Sort/Move Function
+1 for me too. We have aliases with more than 50 hosts and it's a nightmare to find what you need. Same thing goes f... Lars Jorgensen

10/06/2016

06:21 PM Revision 54612e2c: Merge pull request #3141 from PiBa-NL/xmlrpc_seturl
Renato Botelho
06:12 PM Revision dfbd0052: XMLRPC, xmlrpc_client, add new scheme parameter in setConnectionData(syncip,port,user,pass,schema), for use by packages that sync to custom locations, set public/private on all functions
Pi Ba
06:03 PM Revision 7779e6ce: Select PRIQ by default in the shaper wizards, rather than HFSC.
Jim Pingle
06:03 PM Revision 5e4d3374: Use the full "netstat -s" command so we also get pfkey, ipsec, esp, and other stats.
Jim Pingle
06:03 PM Revision ddbc5875: Use tree-style ps output in status.php
Jim Pingle
06:03 PM Revision e1776d71: Fix static blackhole routes. Bug was introduced in
8be135cd114fbc9294ec9dafed2125d0e553956c (February, 2013).
(cherry picked from commit 580bef1ee3052437487553fcc5dc84...
Leland Roach
06:03 PM Revision 0fb0fcd9: Merge pull request #3161 from phroggster/patch-1
Renato Botelho
06:01 PM Revision cc2c4d16: Simplify logic
(cherry picked from commit 9a2d3fe1bf9bdad73fbffca44d5c1f02aa9825ae) Stilez y
06:01 PM Revision 0876cbed: Merge pull request #3158 from stilez/patch-45
Renato Botelho
05:49 PM Revision b5e73640: Spelling mistake "system_gateways.php"
Fix spelling mistake in "system_gateways.php"
(cherry picked from commit 47180823dc0560801085a227abf512e265363b16)
Colin Fleming
05:49 PM Revision 255da151: Merge pull request #3150 from ExolonDX/master
Renato Botelho
04:09 PM Revision 0ff0f44d: Remove workarounds to sort extensions.ini since ports tree now has a better solution in place to track PHP modules dependencies
Renato Botelho
03:42 PM Feature #6839: Mechanism to prevent flooding log with entries from blocked packets
>Phillip Davis wrote:
> You can create your own Private Networks alias, and then make an ordinary block rule on WAN ...
Daryl Morse
01:49 PM Bug #6637 (Resolved): pfSense blocks return traffic (mostly TCP) on 2.3.1-RELEASE-p5
Jim Pingle

10/05/2016

10:00 PM Bug #6840 (Resolved): Upgrade ISC dhcpd to 4.3.5 to address missing hostname workaround
ISC DHCP Server 4.3.0 introduced a bug which caused hostnames to go missing in pfSense 2.3.x. This was addressed thro... Michael Vincent
06:18 PM Feature #6839: Mechanism to prevent flooding log with entries from blocked packets
You can create your own Private Networks alias, and then make an ordinary block rule on WAN to block that. Then you c... Phillip Davis
05:30 PM Feature #6839 (Closed): Mechanism to prevent flooding log with entries from blocked packets
The firewall log is being filled with thousands entries from blocked packets: WAN / 10.197.248.27 / 224.0.0.1 / IGMP.... Daryl Morse
02:06 PM Revision db0c1e14: add array index how value for authserver list
Bruno Ferri
09:13 AM Bug #6838 (Resolved): bsnmpd logs errors when /etc/printcap is missing
We do not ship with an /etc/printcap file but it appears that bsnmpd does not like that fact. When probed in various ... Jim Pingle
06:19 AM Feature #2358: NAT64 support
UPVOTE
My new ISP provides native IPv6 and I would prefere not to have configuring my hole network with IPv4 if I co...
Nicolas Vollmar

10/04/2016

02:51 PM Bug #6835 (Closed): firewall_nat_out_edit.php Translation section hidden
Anonymous
01:16 AM Bug #6835: firewall_nat_out_edit.php Translation section hidden
Looks good here. Thanks. Chris Linstruth
02:37 PM Bug #6837 (Rejected): Gateway Failover does not failback
It depends on whether or not one or both of your WANs is a PPP type WAN. Default gateway switching is still an experi... Jim Pingle
02:09 PM Bug #6837 (Rejected): Gateway Failover does not failback
I'm using default gateway failover, not gateway groups.
When my primary wan connection goes down, it's properly de...
Mark Wiater
11:05 AM Bug #5999: IPv6 IP Alias prevents Track Interface from working with DHCPv6 and RA
Any update on this? I would really like to be able to use ULA and GUA IPv6 addresses at the same time on my network,... Anonymous
11:04 AM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
Is there any update on when this might get worked on? It has been almost a year now. Anonymous
08:43 AM Feature #6800: Feature request: Logon to remember the URL that initiated the logon sequence and return to it
Jim Pingle wrote:
> We used to do that, but ultimately decided against it as it was a potential security issue. We m...
Jeroen Pluimers
05:34 AM Bug #6263: Encryption options for every P2 on a given P1 are written to each P2 individually inside ipsec.conf with multiple P2 entries + split conn entries
might be always been that way but this is very painful... all other brand do support this properly.
I just start usi...
si lec

10/03/2016

09:00 PM Revision f9416ab2: standardise old code ("or" -> "||")
Stilez y
07:40 PM Revision ee9a44e7: Fix typo: The input field is named source_hash_key
(cherry picked from commit 870b9bc11b993ce8122b448083d29a04bcb30151) NewEraCracker
07:38 PM Revision 00ae2254: Merge pull request #3174 from NewEraCracker/nat-out-fix-typo
Steve Beaver
06:38 PM Revision 870b9bc1: Fix typo: The input field is named source_hash_key
NewEraCracker
04:17 PM Revision 12190b7c: Revise merge error
Steve Beaver
03:59 PM Revision 0300c960: Applied PR #3173 to correct merge error
Steve Beaver
01:33 PM Revision 5c4c1fe5: Fixed #6835 by revising Javascript show/hide
(cherry picked from commit 850c3d8b9352e7467beca8502c24ca8d4fbbbd29) Steve Beaver
01:32 PM Revision 25383c9a: Fixed #6835 by revising Javascript show/hide
(cherry picked from commit 850c3d8b9352e7467beca8502c24ca8d4fbbbd29) Steve Beaver
01:29 PM Revision 850c3d8b: Fixed #6835 by revising Javascript show/hide
Steve Beaver
08:40 AM Bug #6835: firewall_nat_out_edit.php Translation section hidden
Applied in changeset commit:850c3d8b9352e7467beca8502c24ca8d4fbbbd29. Anonymous
08:35 AM Bug #6835 (Feedback): firewall_nat_out_edit.php Translation section hidden
Revised Javascript to correct element show/hide Anonymous
08:05 AM Feature #3652: OpenVPN - Dynamic IPv6 Tunnel Network
I 2nd this. Would be a nice addition. Corey Boyle
 

Also available in: Atom