Activity
From 10/12/2016 to 11/10/2016
11/10/2016
-
11:07 PM Feature #6914 (Resolved): unbound access-control lists
- Hello! In
Services -> DNS Resolver -> Access Lists -> Add -> Actions
we have only 4 options "Deny", "Refuse", "Allo... -
04:04 PM Bug #6099: igmpproxy does not recognize upstream interface
- That's interesting. But unfortunately this is not the case for my system. Swisscom transmits everything on vlan10 and...
- 02:49 PM Revision 3ad0f9b6: Update setup_wizard.xml
-
01:30 PM Bug #6906: Issues with /tmp and /var in RAM on 2.4
- The prompt when booting appears to be due to the fact that /var was not cleaned out when switching to RAM disk, and t...
-
12:32 PM Bug #6913 (Resolved): install on Hyper-v R2
- can't install 2.4 on Hyper-V 2012 R2
fix... -
12:27 PM pfSense Packages Bug #4608: squidGuard & pfsense RAM disk compatible
- Better fix is in now, see #6878
-
12:27 PM pfSense Packages Bug #6279 (Rejected): squidguard blacklist update not working after initial update
- Works here, must be something local or site-specific.
-
12:23 PM pfSense Packages Bug #6878: how to use snort, squid and squid_guard with a ram disk
- Each of these changes was made on 2.4 only, as some assumptions were made that could conflict in some cases (e.g. Nan...
-
12:23 PM pfSense Packages Bug #6878 (Feedback): how to use snort, squid and squid_guard with a ram disk
- I pushed a change to teach squidGuard to keep its databases in a persistent directory when /var is in RAM. The files ...
-
11:10 AM pfSense Packages Bug #6878: how to use snort, squid and squid_guard with a ram disk
- Pushed a change for squid to teach clamav to keep its DB in a persistent location if /var is a RAM disk. It doesn't c...
-
12:23 PM Bug #6912 (Closed): install on Hyper-v R2
- can't install 2.4 on Hyper-v R2 (all updates installed)
fix:... -
11:17 AM Bug #6910: Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- But the details you mention are not solved by this suggestion. The interface is already filled/selected when you crea...
-
11:14 AM Bug #6910: Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- I mean it constructively, btw, not to whine or something.
-
11:08 AM Bug #6910: Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- I'm assuming people want to work efficient.
What is wrong with copying a field into a field to make sure people do... -
10:08 AM Bug #6910: Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- You're assuming everyone uses it the same way you use it, which isn't the case. Removing functionality to prevent foo...
-
10:05 AM Bug #6910: Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- 1. Button: 'copy'
2. Popup: which fields to change (interface);
3. Save = copied with altered values. -
09:44 AM Bug #6910 (Rejected): Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- Being able to edit the interface allows you to move a rule from one interface to another. (e.g. copy LAN rule, edit L...
-
09:05 AM Bug #6910 (Rejected): Pre-fill 'interface' field when creating firewall rule on interface -> efficiency
- Now it is possible to create a firewall rule on a vlan tab, and fill in the wrong interface in that rule. Aside from ...
-
11:02 AM Bug #6781 (Resolved): OpenBSD description links are broken in Traffic Shaper
- Thanks for the feedback!
-
11:00 AM Bug #6781: OpenBSD description links are broken in Traffic Shaper
- I think you should mark it as "resolved/closed". Thanks!
-
10:49 AM Bug #6911 (Rejected): no network on hyperv-v 2012 R1
- i have installed 2.4 on hyper-v 2012 R1, set ip. no network.. no ping.. have updated drivers, enabled and disabled hw...
-
10:03 AM Revision 09cc19c2: Consider the IPv6 checksum options when dealing with "Disable hardware checksum offload".
- Ticket #5321
(cherry picked from commit 411d4e6e55475cc66b997ca3e47478dbe10b4e1b) - 10:03 AM Revision 1c9bf396: Fix bug where CARP vip status is incorrent in the interface when more
- than one CARP vip is configured for an interface.
(cherry picked from commit 5116a8aa60ad87c0a47aafeca422cc323147ea14) - 10:03 AM Revision 16bdba73: Remove "use lowercase" hint
- As it is no longer relevant, because the code now automatically converts
to lowercase.
(cherry picked from commit 6a... - 10:03 AM Revision 3a66c0da: Fix #6864 automatically convert IPv6 input to lowercase
- 1) As the user leaves the field, or presses Save, onChange will fire and
convert the input string to lowercase. This ... -
10:01 AM Revision ebc4a441: Consider the IPv6 checksum options when dealing with "Disable hardware checksum offload".
- Ticket #5321
(cherry picked from commit 411d4e6e55475cc66b997ca3e47478dbe10b4e1b) - 10:01 AM Revision 5ad69855: Fix bug where CARP vip status is incorrent in the interface when more
- than one CARP vip is configured for an interface.
(cherry picked from commit 5116a8aa60ad87c0a47aafeca422cc323147ea14) -
10:01 AM Revision 0cc7eec5: 80 character lines ftw :)
- Just because it was asked nicely :)
(cherry picked from commit 013110a19b90698cd521fc120b06b7cc37b531e5) -
10:01 AM Revision 68de92f2: standardise old code ("or" -> "||")
- (cherry picked from commit f9416ab2bdaae5ca41e70db1c846ab3419fd0cee)
- 10:01 AM Revision b68edd49: Remove "use lowercase" hint
- As it is no longer relevant, because the code now automatically converts
to lowercase.
(cherry picked from commit 6a... - 10:01 AM Revision 6df432c3: Fix #6864 automatically convert IPv6 input to lowercase
- 1) As the user leaves the field, or presses Save, onChange will fire and
convert the input string to lowercase. This ... -
08:48 AM Feature #6909 (Duplicate): Copy FW rules to new interface efficiency
- Example: I want to copy ALL FW rules from VLAN100 to VLAN110 at once.
Then, in that copy, or (see previous issue r... -
08:16 AM Feature #6908 (Resolved): Alias copy, sort, search/replace functions
- For example: copy one alias (the content of course) into another alias (like in FW rules), sort alias, filter alias, ...
-
04:08 AM Revision 7798eb1e: Fix a 'divide by zero' bug in traffic_shaper_wizard_multi_all.inc.
11/09/2016
- 11:27 PM Revision 694872ae: Comment typos alphabet
- (cherry picked from commit d622a62eb4f3ec8535ead494a863f10bbc409f41)
- 11:27 PM Revision 2f8f3cb3: Merge pull request #3221 from phil-davis/patch-2
- 11:23 PM Revision d622a62e: Comment typos alphabet
-
10:51 PM Bug #6907 (Duplicate): DNS Resolver does not use domain name set in DHCP subnet, only the global one
- Ran into this myself & found a relevant forum post here: https://forum.pfsense.org/index.php?topic=119717.0
In sho... -
10:28 PM Bug #6761 (Feedback): Limiter doesn't limit at correct bandwidth
- Many bugs were fixed in 2.4.
2.3.2 is very broken with respect to limiters.
Could you try a recent 2.4 snapshot ? - 07:55 PM Revision 0eb2512f: update conditional re:LAN dhcp
- 06:05 PM Revision b20a6d67: Fix #6899
- (cherry picked from commit c766ac7dd723f6e36980c48b0dd156b492556616)
-
06:05 PM Revision 5e105459: Merge pull request #3218 from kernelbug/master
-
06:02 PM Revision abc9b886: ipsec, apply routes also for IP-aliases with carp parents
- (cherry picked from commit ee908e93671fddb38f8cca5d3d19a28791934878)
-
06:02 PM Revision 8d8cd372: Merge pull request #3220 from PiBa-NL/ipsec-routes
-
05:33 PM Revision 6f012614: syslogd, create configured logsocket directories
- (cherry picked from commit 4406922edb1000ef79f4fccfb484aa1103105ac0)
-
05:32 PM Revision b256751e: Merge pull request #3211 from PiBa-NL/syslogd-logsocket
-
04:41 PM Bug #6099: igmpproxy does not recognize upstream interface
- Found sth on different site:
[[https://sourceforge.net/p/igmpproxy/bugs/4/#472a]]
So for at least with DE-Telekom ... -
03:23 PM pfSense Packages Bug #6878: how to use snort, squid and squid_guard with a ram disk
- Fixed the snort directories in commit:ce8fedd
Will look into squidGuard soon. -
02:57 PM Revision 59537908: err() expects a single parameter
-
02:57 PM Bug #6906: Issues with /tmp and /var in RAM on 2.4
- Checking deeper, @pkg info@ is empty after switching, which explains why the installed packages showed damaged, but a...
-
02:49 PM Bug #6906 (Resolved): Issues with /tmp and /var in RAM on 2.4
- I set /tmp and /var to be in RAM on a test box running 2.4 and hit a couple issues:
1. I had two packages installe... - 02:57 PM Revision dcae03a3: Fixed #6903
- hosts and domains sorted on display, not on save to config
- 02:56 PM Revision 8e7fea67: Fixed #6903
- hosts and domains sorted on display, not on save to config
-
02:23 PM Feature #6881: services_unbound_host_edit.php: DNS Resolver Add V4 and V6 host override at the same time
- In addition any aliases created would have to include both the V4 and V6 addresses.
-
02:06 PM Bug #1813 (Confirmed): Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
- It is still an issue but it can be easily worked around by adding a floating rule to pass outbound to the destination...
-
01:57 PM pfSense Packages Bug #6900 (Feedback): OpenVPN + OTP auth failure
- The verify script is in @/usr/local/etc/raddb/scripts/otpverify.sh@ on current versions. The FreeRADIUS package code ...
-
01:08 PM Revision b8b0fab1: Merge pull request #3215 from PiBa-NL/xmlrpc-loopback
-
12:06 PM Feature #6899 (Feedback): Can't specify PPTP/L2TP gateway as FQDN
- Pull request has been merged. Thanks!
-
11:01 AM Bug #6769 (Resolved): Crash PacketFilter in bridge mode
- I can reproduce this somewhat here on 2.3.2. With a WAN/LAN style bridge, putting @synproxy@ on a TCP rule will event...
-
10:03 AM Bug #6760 (Not a Bug): Editing WAN bridge interface breaks routing until reboot
- I can't reproduce this here on 2.3.2_1. I can make edits to the bridge and the MAC stays the same and I can still rou...
-
09:00 AM Bug #6903: services_dnsmasq_edit.php: Configuration XML hosts section order appears randomized
- Applied in changeset commit:8e7fea674a34ab217c9b9821c608639ca45bd281.
-
08:18 AM Bug #6903 (Feedback): services_dnsmasq_edit.php: Configuration XML hosts section order appears randomized
- It is certainly not "randomized", but since the two tables may be sorted (by clicking the column headers) the hosts c...
-
08:56 AM Bug #6883 (Resolved): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- The route now appears on the OpenVPN interface as expected, and clients can connect/pass traffic with static addresse...
-
07:57 AM Bug #5319: Error message "No config named" in charon daemon
- I've just been hit by this as well and like the last comment, restarting ipsec from the cmd line fixes the problem fo...
-
07:15 AM Bug #6905: XMLRPC Loop detection broken, secondary refuses to accept sync data
- Merge is in commit:b8b0fab1a4ef44758ff7fdd9cbfcc8bab2fe49b9
-
07:08 AM Bug #6905 (Feedback): XMLRPC Loop detection broken, secondary refuses to accept sync data
- Merged PR
-
07:06 AM Bug #6905 (Resolved): XMLRPC Loop detection broken, secondary refuses to accept sync data
- When trying to perform an XMLRPC between two 2.4 HA systems, the secondary won't accept new settings, believing it ha...
-
06:26 AM Revision 1267b787: The IPv6 packets are always blocked.
- Ticket #6206
-
06:21 AM Revision c603770d: Fix a 'divide by zero' bug on shaper wizard when PRIQ is used and no bandwitdth is entered (the correct setting for a PRIQ scheduler).
-
01:21 AM Bug #6904: PRIQ Queue Priority Limited To 7
- Dirty patch attached to thread above, restores old behavior...
Correct way would be to determine parent interface ...
11/08/2016
-
09:46 PM Bug #6904 (Resolved): PRIQ Queue Priority Limited To 7
- Set parent interface to PRIQ. Set child queue priority to anything greater than 7. Receive "Please select a value tha...
-
09:20 PM Bug #6779 (Resolved): Traffic shaper wizard uses decimals instead of whole numbers
-
09:18 PM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- Looks like fixed.
-
08:38 PM Revision ee908e93: ipsec, apply routes also for IP-aliases with carp parents
- 06:53 PM Revision e5f9360f: Fixed #6893
- Null configuration settings are now written as <tag></tag> instead of <tag /> for consistency
- 06:53 PM Revision da7054b7: Fixed #6893
- Null configuration settings are now written as <tag></tag> instead of <tag /> for consistency
-
06:07 PM Bug #6903 (Resolved): services_dnsmasq_edit.php: Configuration XML hosts section order appears randomized
- Related to #6893 - when I view the diff of the configuration XML after a change to DNS Resolver's Host Overrides sect...
-
05:08 PM Revision 92db4492: Set root password for installation media
-
04:26 PM Bug #6893: Configuration XML is inconsistent with self closing tags
- Awesome, thanks for the quick fix!
-
01:00 PM Bug #6893: Configuration XML is inconsistent with self closing tags
- Applied in changeset commit:da7054b7cf77d9322307c52d8340fb30486ce25e.
-
12:54 PM Bug #6893 (Feedback): Configuration XML is inconsistent with self closing tags
- Null configuration settings are now written as <tag></tag> instead of <tag /> for consistency
-
01:06 PM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- thank you very much!)
-
01:02 PM Bug #6883 (Feedback): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- I've imported a patch from OpenVPN development list:
https://github.com/pfsense/FreeBSD-ports/commit/153999c431c59... -
09:46 AM Bug #6902 (Not a Bug): webConfigurator not using new certificate and won't disable SSL
- The certificate won't take full effect until the web server is restarted, and restarting the web server from a proces...
-
06:00 AM Bug #6902: webConfigurator not using new certificate and won't disable SSL
- Bob Hannent wrote:
> Restarting the pfSense box has now locked me out of the UI, neither HTTPS or HTTP work now. Sli... -
05:46 AM Bug #6902 (Not a Bug): webConfigurator not using new certificate and won't disable SSL
- Method:
* I had the web UI using the default self-signed certificate and I used an alternate port number just in cas... -
07:38 AM Bug #3075: Can't delete unused Virtual IP "referenced by a least one gateway"
- I've got this error on 2.3.2_1, on a CARP VIP I just added for a test. I'm 100% sure that VIP is not being used for a...
11/07/2016
-
10:53 PM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
- Still seeing system lockup on 2.4.0-BETA when dealing with non-local gateways.
-
10:13 PM Revision d36ea867: 2.4.0 is now BETA
- 08:26 PM Revision 32980f32: update LAN regex for case insensitivity
- 07:14 PM Revision 4c7ec3de: Fixed 6901
- 07:13 PM Revision 6bd09ca2: Fixed 6901
-
06:49 PM Revision 86584ded: Store Dynamic DNS passwords in Base64 to protect special characters. Fixes #6688
- 06:00 PM Revision 4606b548: Fixed #6898
- 06:00 PM Revision 10b262b4: Fixed #6898
- 04:24 PM Revision cde63e73: Merge branch 'RELENG_2_3' of git.netgate.com:pfsense/pfsense into RELENG_2_3
- 04:22 PM Revision a4a0f8db: Fixed #6779 by rounding bandwidth down to nearest integer
- 04:19 PM Revision 16625f3c: Fixed #6779 by roundinf bandwidth down to nearest integer
-
03:56 PM Revision a6b5014d: So, PHP eats the last '\n' and we need an additional new line...
- Fix the generated pf rules.
-
03:51 PM Bug #6119 (Closed): Alias entry causes filterdns core dumps
- > While creating an alias containing multiple networks, I used copy/paste and (unthinkingly) pasted 18 of the 22 entr...
- 03:36 PM Revision 7c3a9ded: Fixed #6779
- Round calculated bandwidth down to nearest integer
-
03:18 PM Bug #6200: LACP with em driver does not work with cisco active lacp setup
- I don't have a Cisco switch to test against, and the only piece of hardware I have left with em0 that works is 32-bit...
-
02:57 PM Bug #6880 (Confirmed): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
- Confirmed. The daemon is binding to all interfaces, which prevents the second one from operating properly.
Changin... - 02:39 PM Revision 7c9f724c: Correct part of #6779
- Setting input "step" value to "any" alows hte element to accept decimal (float) values, not just integers.
- 02:38 PM Revision 54a217f0: Correct part of #6779
- Setting input "step" value to "any" alows hte element to accept decimal (float) values, not just integers.
-
02:33 PM Bug #6663 (Confirmed): IPv6 OpenVPN client is down after reboot
- Confirmed, doesn't need PPPoE. An OpenVPN instance on an assigned GIF interface is enough. It's acting as though the ...
-
02:21 PM pfSense Packages Bug #6721: Incorrect OpenBGPd package scripts prevent use of both IPv4 and IPv6
- Hi Jim,
Leaving "Listen on IP" blank makes the default IPv4 address "0.0.0.0" to be put on both IPv4 *and IPv6* "l... -
11:14 AM pfSense Packages Bug #6721 (Needs Patch): Incorrect OpenBGPd package scripts prevent use of both IPv4 and IPv6
- Unless there is a compelling need to set it to listen on two specific addresses manually, leave "Listen on IP" blank ...
-
01:12 PM Bug #6901 (Feedback): services_unbound_host_edit.php: "Delete" button should be suppressed if < 2 host aliases listed
- checkLastRow() Javascript added to page
-
01:12 PM Bug #6901 (Resolved): services_unbound_host_edit.php: "Delete" button should be suppressed if < 2 host aliases listed
-
01:00 PM Bug #6688 (Feedback): Special characters in a password cause problems
- Applied in changeset commit:86584ded30c27b9ad1b017fb743399dc01180f02.
-
12:50 PM Bug #6688: Special characters in a password cause problems
- I committed a fix to store the passwords in base64. Worked fine here but could use more testing. 2.4 only for the tim...
-
12:10 PM Bug #6898: Suggestion: reword "VPN > IPsec > Tunnels > Edit Phase 1" "Key Exchange version" popup contents
- Applied in changeset commit:10b262b409c9b4170785948b9e73bdfc7edc2eae.
-
12:01 PM Bug #6898 (Feedback): Suggestion: reword "VPN > IPsec > Tunnels > Edit Phase 1" "Key Exchange version" popup contents
- Pull-down text changed as suggested.
-
09:40 AM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- Applied in changeset commit:7c3a9dede96552233fbe1da35ac4126aa524711b.
-
08:56 AM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- Fix part 1: HTML inputs that specify the bandwidth have been updated to accept decimal values.
Part 2: Calcualted ba... -
09:39 AM pfSense Packages Feature #6859 (Feedback): have an includedir by default (sudo package)
- Seems useful and was simple to add. I pushed it to the 2.4 version of the package.
-
08:20 AM pfSense Packages Bug #6867 (Closed): Please update quagga to version 1.1
- We'll pick it up naturally when it comes through FreeBSD ports. I don't think it's worth going out of our way to pick...
-
05:22 AM pfSense Packages Bug #6900 (Resolved): OpenVPN + OTP auth failure
- Hi guys. In pfsense 2.3.2 after any changes (firewall rules, reboot, etc...), I cannot access the server via OpenVPN ...
-
04:17 AM Revision 55fcc035: Do not generate IPv6 rules when IPv6 is disabled.
- Ticket #6206
-
03:51 AM Revision 411d4e6e: Consider the IPv6 checksum options when dealing with "Disable hardware checksum offload".
- Ticket #5321
-
03:18 AM Revision a227ecef: Merge pull request #3164 from fredronnv/master
- * 'master' of https://github.com/fredronnv/pfsense:
Fix bug where CARP vip status is incorrent in the interface whe... -
02:57 AM Revision 068ec0b1: Merge pull request #3176 from stilez/patch-49
- * 'patch-49' of https://github.com/stilez/pfsense:
80 character lines ftw :)
standardise old code ("or" -> "||") -
02:49 AM Revision 81cc31e1: Merge pull request #3199 from phil-davis/ipv6lower
- * 'ipv6lower' of https://github.com/phil-davis/pfsense:
Remove "use lowercase" hint
Fix #6864 automatically conve...
11/06/2016
-
10:25 PM Bug #6206 (Feedback): Default icmp6 pass-rules are added even when ipv6 is "disabled" by user
-
10:12 PM Feature #3859: Make it possible to set the source IP address for gateway monitoring
- is there any updates on this feature ?
With lack of ipv4, being able to use only one public ip is a pretty common co... -
10:00 PM Bug #5321 (Feedback): rxcsum6, txcsum6 not considered by "Disable hardware checksum offload"
- Fixed in 2.4.
- 09:32 PM Revision c766ac7d: Fix #6899
-
09:10 PM Bug #6864 (Feedback): Error checking rejects IPv6 addresses with upper case A-F.
- Applied in changeset commit:d461ff40e364fc0ecc003b9f673cbad7c6a08f2f.
-
06:05 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
- Note: The pull request generated discussion about whether users should have the option to record IPv6 addresses with ...
-
12:37 AM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
- Take a look at Phil's patch. If it needs rework kick back to either he or I.
-
01:07 AM Bug #6200: LACP with em driver does not work with cisco active lacp setup
- Eval, please
-
01:06 AM Bug #6119: Alias entry causes filterdns core dumps
- Please retest on 2.3. Close if possible. Let me know if it's still an issue
-
01:03 AM Bug #1813: Static routes on WAN interfaces overridden by route-to for firewall-initiated traffic
- Can't be "high", it's five years old.
JimP, please reeval to see if this is still and issue. -
01:00 AM Bug #4424: Adding and removing shaper repeatedly causing interface crash
- With luck recent work has closed this.
-
12:59 AM Todo #6606: Adapt captive portal to work without multi-instance ipfw
- Believe this should be closed
-
12:57 AM Bug #6663: IPv6 OpenVPN client is down after reboot
- Pingle pls confirm
-
12:42 AM Bug #6688: Special characters in a password cause problems
- Please look at Phil'a patch
-
12:31 AM Bug #6896 (Feedback): unbound root.key file corruption possibly related to full file system
-
12:27 AM pfSense Packages Feature #6859: have an includedir by default (sudo package)
- Pingle for eval.
-
12:26 AM pfSense Packages Bug #6867: Please update quagga to version 1.1
- Needs serious evaluation first.
11/05/2016
-
02:03 PM Todo #6332: Upgrade encryption options to cover current range of recommendations
- In general I agree that we could do a better job here. Beaver can look into that.
Things like md5 have to stay u... -
12:04 PM Todo #6332: Upgrade encryption options to cover current range of recommendations
- Jim Pingle wrote:
> We can't outright purge md5 and other weak options because people are frequently forced to use t... -
11:04 AM Todo #6332: Upgrade encryption options to cover current range of recommendations
- We can't outright purge md5 and other weak options because people are frequently forced to use them for third party v...
-
10:09 AM Todo #6332: Upgrade encryption options to cover current range of recommendations
- I was about to file a similar bug, but found this one searching the bugbase for "md5".
I'm new to pfsense and just... -
12:56 PM Feature #6899 (Needs Patch): Can't specify PPTP/L2TP gateway as FQDN
- Thanks for the proposal. This would be considered a feature request (I changed the type for you). Code submissions sh...
-
12:51 PM Feature #6899 (Resolved): Can't specify PPTP/L2TP gateway as FQDN
- Actually I don't know that's a bug report or a feature request actually.
Nevertheless I'm using the following workar... -
12:30 PM Bug #6898 (Resolved): Suggestion: reword "VPN > IPsec > Tunnels > Edit Phase 1" "Key Exchange version" popup contents
- In the "VPN > IPsec > Tunnels > Edit Phase 1" screen, there is a "Key Exchange version" popup, its contents are:
V1... -
07:45 AM pfSense Packages Feature #6226: Add usb_modeswitch to the pfSense package repo
- Has this feature request stalled ?
There is a package that that could handle this, it is only a matter of the corr... -
04:26 AM Revision 3c3f9397: Fix the port assigment on SG-4860 or SG-8860.
11/04/2016
-
08:50 PM Feature #6897 (Duplicate): Use a dedicated favicon for the webConfigurator (one that differs from *.pfsense.org)
- I think webConfigurator should use a favicon that differs from the one used on any *.pfsense.org.
I often have mul... - 08:26 PM Revision d5cf0b70: Fixed #6895
- by setting overflow-x: visible; in CSS
- 08:25 PM Revision 7da65ab7: Fixed #6895
- by setting overflow-x: visible; in CSS
-
07:17 PM Revision 0bddde7f: Enable ALTQ for cxl. Fixes #6830
-
07:17 PM Revision 0ea7b83e: Enable ALTQ for cxl. Fixes #6830
-
07:16 PM Revision 7ac34d65: Enable ALTQ for cxl. Fixes #6830
-
07:08 PM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- Thanks!
I updated you instructions a little since "default" is not always the same in the Wizard. -
11:31 AM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- Yes, calculated values.
Run wizard, select Multiple Lan/Wan traffic_shaper_wizard_multi_all.xml
*First step:*
LA... -
10:47 AM Bug #6779 (Feedback): Traffic shaper wizard uses decimals instead of whole numbers
- Would you please clarify for me?
Does the problem occur when you enter decimals in the wizard, or when values you ... - 06:43 PM Revision 01fb4340: Fixed $6811
-
06:39 PM Revision cbd61636: When deleting or disabling a non-dynamic gateway, if that gateway was set as default then remove the corresponding default route to respect the user's decision. Fixes #6659
- (cherry picked from commit 1be1b87b5f9ab8d0a259b888aab08ec6babad568)
-
06:06 PM Revision 1be1b87b: When deleting or disabling a non-dynamic gateway, if that gateway was set as default then remove the corresponding default route to respect the user's decision. Fixes #6659
-
05:19 PM Bug #6896: unbound root.key file corruption possibly related to full file system
- The logs cannot fill up anything. They are circular and fixed size - see Status - System Logs - Settings. Simply make...
-
05:19 PM Bug #6896: unbound root.key file corruption possibly related to full file system
- Just following up, I traced it down to the suricata package. My DNS log is gigabytes in length. What is strange is t...
-
05:13 PM Bug #6896 (Not a Bug): unbound root.key file corruption possibly related to full file system
- My root.key becomes corrupt and unbound crashes and no longer will start. This bug is likely related to #5334 and has...
- 04:51 PM Revision f92d44da: Fixed #6811
-
04:28 PM Revision 3b55b54e: Improved error message to explicitly state allowable characters
- Related to Bug #6432.
-
03:30 PM Bug #6895: Moving rules does not scroll
- Applied in changeset commit:7da65ab7dc9a1b55624de9fb6eb9a4a272440573.
-
03:29 PM Bug #6895 (Feedback): Moving rules does not scroll
- Matt Fine to test.
-
03:23 PM Bug #6895 (Resolved): Moving rules does not scroll
- Dragging firewall rules does not automatically scroll the page when dragging to the top or bottom of hte visible window
-
03:05 PM Revision 2446fffa: Convert CloudFlare and GratisDNS dynamic DNS over to split hostname and domain name fields, like Namecheap. Otherwise they could both break with subdomains or international TLDs with many parts. Fixes #6778
-
02:58 PM pfSense Packages Bug #6777 (Not a Bug): squid cant redirect ssl website correctly to squidguard error page in a denied category
-
02:56 PM pfSense Packages Bug #6777: squid cant redirect ssl website correctly to squidguard error page in a denied category
- NOT A BUG.
This is caused by a behavior on Browsers, check this link for more information about it: https://bugzil... - 02:38 PM Revision 96ff627f: Fixed #6753
- Interface menu entries no longer sorted for consistency with other GUI instances
(cherry picked from commit e5d33973... - 02:38 PM Revision e5d33973: Fixed #6753
- Interface menu entries no longer sorted for consistency with other GUI instances
-
02:34 PM Todo #6894: Improvements and fixes on 2.4 installer
- - It's not rebooting after auto ZFS installation on 4860
-
02:04 PM Todo #6894 (Resolved): Improvements and fixes on 2.4 installer
- - Remove extra options for auto UFS leaving only MBR and GPT
- Use labels to particions on UFS -
02:22 PM Revision 46800f85: OpenBSD removed the pf FAQ page for shaping, so link to the proper page on archive.org since they offer no current equivalent and no other suitable replacement page is immediately available. Fixes #6781
-
02:22 PM Revision 7a48a7f7: OpenBSD removed the pf FAQ page for shaping, so link to the proper page on archive.org since they offer no current equivalent and no other suitable replacement page is immediately available. Fixes #6781
-
02:20 PM Revision 79e50e97: OpenBSD removed the pf FAQ page for shaping, so link to the proper page on archive.org since they offer no current equivalent and no other suitable replacement page is immediately available. Fixes #6781
-
02:20 PM Bug #6830 (Feedback): Chelsio T4/T5 CXGBE drivers not loaded as ALTq capable in the PfSense UI
- Applied in changeset commit:7ac34d65a4f3f8561c8156ae75630aa71c8a88f2.
-
01:18 PM Bug #2800 (Resolved): OpenVPN doesn't work properly with intermediate/chained CAs
- This works fine in the base system and in the export package. I can make a CA, then make an intermediate CA, then mak...
-
01:10 PM Bug #6659 (Feedback): Default routes are not being removed after deletion
- Applied in changeset commit:1be1b87b5f9ab8d0a259b888aab08ec6babad568.
-
12:13 PM Bug #6876: Firewall alias issue after adding a wrong alias
- I do confirm that affected version are 2.3.2 and 2.2, even if screenshot is 2.2.x. Purpose of screenshot was just to ...
-
09:11 AM Bug #6876 (Feedback): Firewall alias issue after adding a wrong alias
- Affected version has been set to 2.3.2, yet your screenshots are from a 2.2.x version. Would you please confirm that ...
-
12:00 PM Bug #6811: pkg_edit.php rowhelper is broken with multiple distinct rowhelpers per page.
- Applied in changeset commit:f92d44da5a4958372c7fb925043abc34588143e3.
-
11:51 AM Bug #6811 (Feedback): pkg_edit.php rowhelper is broken with multiple distinct rowhelpers per page.
- Changes made to pkg_edit.php appear to have resolved this, but more testing is required. Many packages use rowhelpers...
-
11:22 AM Bug #6432: Relative distinguished names should accept unicode during CA creation.
- I hit this exact problem too.
It would be nice to at least improve the error message to state which characters are... -
11:05 AM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- First, I really did not intend to start a bikeshedding flame war. :) I honestly thought it would be non-controversia...
-
10:51 AM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- In the typical firewall use case, a reboot or halt only happens when there is a problem that needs correcting, which ...
-
10:42 AM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- Shrug; not sure how common action is rebooting a NAS:
QNAP: !https://s22.postimg.org/4aznct5kh/Screenshot_1.png! S... -
10:26 AM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- Because it's a bikeshed discussion that will never please everyone. Making reboot and halt more accessible is not a g...
-
10:18 AM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- I think all the current locations simply suck. Why not have a menu in place of the current logout button that offers ...
-
10:39 AM Bug #6668 (Feedback): IPSec tunnel + L2TP/IPSec VPN - wrong PSK chosen by pfSense
- I'm hesitant to commit changes to the ordering without lots of testing first, so can you try the attached patch to se...
-
10:14 AM Bug #6893: Configuration XML is inconsistent with self closing tags
- Here's another example. I only deleted some L2TP users, but the XML has changed for these values (screenshot from Sou...
-
09:39 AM Bug #6893 (Resolved): Configuration XML is inconsistent with self closing tags
- Whenever I make changes I do "Download configuration as XML" and store the file in a git repository, so I always view...
-
10:10 AM Bug #6778 (Feedback): CloudFlare Dynamic DNS fails when domain name uses a Second Level TLD
- Applied in changeset commit:2446fffa5932e8debcaf165bfaf5492cea429c60.
-
10:06 AM Bug #6778 (Confirmed): CloudFlare Dynamic DNS fails when domain name uses a Second Level TLD
- Both CloudFlare and GratisDNS used the same logic that Namecheap used to use, which has several potential problems. I...
-
10:04 AM Bug #6406: Web process becomes unresponsive producing 502 Bad Gateway nginx
- There is no known consistent single cause. Some have it with nothing else installed, some other pfBlocker, some with ...
-
09:59 AM Bug #6406: Web process becomes unresponsive producing 502 Bad Gateway nginx
- Sorry to re-hash this, but since it has just been assigned to me I need an update.
Some of the above responses wou... -
09:50 AM Feature #6753: Interfaces list order not consistent
- Applied in changeset commit:e5d339735836fd55b0fa944d5d7e472793785e30.
-
09:43 AM Feature #6753 (Feedback): Interfaces list order not consistent
- Sorting has been removed from the Interface menu.
Adding msort to all other occurrences would obviously involve mo... -
09:35 AM Bug #6826: DNS forwarder is sending packets with link-local IPv6 source address to global unicast address
- Thanks. ping is a special case since it is protocol-aware (separate ping, ping6), but it looks like FreeBSD doesn't i...
-
08:49 AM Bug #6826 (Rejected): DNS forwarder is sending packets with link-local IPv6 source address to global unicast address
- This appears to be how FreeBSD behaves and is not specific to the DNS resolver or forwarder, the same happens even wi...
-
09:30 AM Bug #6781 (Feedback): OpenBSD description links are broken in Traffic Shaper
- Applied in changeset commit:79e50e9768f32b75817a28021d051c79cb44fdec.
-
09:13 AM Bug #6711 (Closed): diag_states_summary # States and # States twice (explain one is per protocol)
-
09:06 AM Bug #6802 (Rejected): GUI does not respond and vpn stops working
- Duplicate of #6406 and others that are all the same base issue: PHP gets wedged and don't respond.
-
09:04 AM Bug #6868 (Confirmed): Interface MTU Setting not applied to all IPv6 routes
- I can reproduce the behavior on 2.3.x. If I adjust the MTU of an assigned interface, only the default and/or link rou...
-
08:58 AM Bug #6812 (Feedback): IPsec filterdns crash
- The two events are not related.
The first is an issue with an IPsec tunnel peer address that was entered as a full... -
02:09 AM Bug #6843: Version inconsistency after updating to 2.3.2_1
- I should add that I've since this was reported upgraded via the command line and it now shows 2.3.2_1 on both pages.
11/03/2016
-
11:00 PM Bug #6892 (Resolved): CARP VIPs Deleted entering CARP Maintenance Mode
- There is an issue both upgrading CARP HA cluster and subsequent entering and leaving CARP maintenance mode.
When e... -
10:09 PM Bug #6884 (Rejected): "Reboot" option should be under "System" menu, not "Diagnostics"
- This debate pops up every now and then and there hasn't been a compelling argument for moving it. Rebooting and shutt...
-
10:01 PM Bug #6884: "Reboot" option should be under "System" menu, not "Diagnostics"
- When I first came to pfSense I had the same trouble finding the Reboot entry and Halt entry.
The flip side to this i... -
10:08 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- OK. I don't use this so it doesn't effect systems that I have that will be stuck on 2.3.* (32-bit Alix). If it is not...
-
09:43 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- Given all the work that's happened on 2.4 with IPFW, I'd say it's best to not attempt a backport. 2.4 is not that far...
-
07:36 PM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- I guess the fix is in the pf port or...?
Is it something that easily applies back to 2.3.* FreeBSD 10.3 and thus cou... -
05:10 PM Bug #4326 (Feedback): Limiters on firewall rules where NAT applies drop all traffic
- Fixed in 2.4.
-
09:42 PM Bug #6812: IPsec filterdns crash
- Assigned to Pingle for analysis.
-
09:41 PM Bug #6823: No connectivity after changing link state to UP
We would have to provide the ports of the Intel drivers as packages, and then allow people to load the package on d...-
09:22 PM Bug #6868: Interface MTU Setting not applied to all IPv6 routes
- assigned to Pingle for analysis.
-
08:54 PM Bug #6891: Improper shutdown causes irrecoverable filesystem corruption, unable to boot or fsck
- Some related forum threads...
https://forum.pfsense.org/index.php?topic=120019.0
https://forum.pfsense.org/index.ph... -
08:47 PM Bug #6891 (Duplicate): Improper shutdown causes irrecoverable filesystem corruption, unable to boot or fsck
- I've had this happen 4 times so far that I can remember. That is definitely more than I would like but out of ~85 fi...
-
07:42 PM Bug #6406: Web process becomes unresponsive producing 502 Bad Gateway nginx
- FYI - Still happening on 2.3.2-RELEASE-p1 systems.
-
07:00 PM Revision 8d44b2cb: xmlrpc, fix loopback detection
-
06:55 PM Feature #6775: Strongswan PKCS#11 Support
- https://wiki.strongswan.org/projects/strongswan/wiki/PKCS11plugin
no idea what this needs in the GUI, etc.
OP s... -
05:34 PM Bug #6890 (Resolved): PPP service name error
- Hi,
I've just updated a virtual appliance to the new 2.3.2_1 version, and now, i can't add ppp connection (3G backu... -
03:56 PM Bug #1819: DNS Resolver Not Registering DHCP Server Specified Domain Name
- Any updates on this? It also seems to be affecting unbound on 2.3.2-p1. Until this is fixed, perhaps removing the d...
-
12:20 PM Bug #6887 (Rejected): Carp status widget doesn't work, show wrong IPs status
- I can't reproduce this. If I create a similar setup, the VIP status is reflected properly on both units.
That said... -
05:45 AM Bug #6887 (Rejected): Carp status widget doesn't work, show wrong IPs status
- In a two nodes cluster with 3 carp IPs, carp widget doesn't show correctly which node is master or backup for each ip...
-
10:21 AM Todo #6889 (Resolved): Improve router mode help text
- *Current*
Select the Operating Mode for the Router Advertisement (RA) Daemon. Use:
Router Only to only advertise th... -
09:24 AM Bug #6888 (Rejected): openVPN - Client Specific Overrides
- Don't use a manual "ifconfig-push" line, that's what the "Tunnel Network" option in the override sets up automaticall...
-
09:19 AM Bug #6888 (Rejected): openVPN - Client Specific Overrides
- System: 2.3.2-RELEASE-p1
On WebGUI i put 'ifconfig-push 172.50.0.10 255.255.255.0' but client gets this IP: 172.50... -
07:40 AM Bug #3330: Load Balancer showing wrong Status when using aliases for the port
- Indeed, is still there in 2.3.2-RELEASE-p1, is not assigned to anybody unfortunately and I need to do load balancing ...
11/02/2016
-
06:48 PM Revision 4406922e: syslogd, create configured logsocket directories
-
04:15 PM Feature #6886 (Resolved): Allow Dual-Stack IPSec VPN
- It would be nice to have a third option in the web interface for creating IPSec mobile configs, allowing you to selec...
-
04:10 PM Todo #6885 (Resolved): Add vectorized logo in web interface
- The logo used on the pfSense web interface should be a scalable vector graphics file (SVG), allowing it to automatica...
-
04:01 PM pfSense Packages Bug #6410: when PFSENSE after server restart,openvpn+motp not login
- Hello,
this seems to be a solid hazard preventing the use of motp based 2 factor auth.
see also https://forum.pfs... -
11:43 AM Bug #6884 (Rejected): "Reboot" option should be under "System" menu, not "Diagnostics"
- I'm new to pfsense, and this is my first bug report. Please be gentle. :)
I had to google how to reboot pfsense, b... -
07:16 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- This appears to be a general problem with OpenVPN on FreeBSD 11:
https://forums.freebsd.org/threads/58019/
https:...
11/01/2016
-
03:32 PM Todo #4706 (Feedback): MPD needs to be upgraded to version 5 even for the various other tunnels
- PPPoE and L2TP were converted to use mpd5 in commit:8d50c07c8bfdd2692a0c7d3ca3489977b528aecc and commit:2c0a3677de6b6...
-
02:53 PM Bug #6850 (Confirmed): FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
-
01:31 PM pfSense Packages Bug #5868 (Feedback): Quagga OSPF Priority value "0" (zero) is being ignored - DR election doesnt work properly.
- I pushed a fix for this in package version 0.6.15.
-
12:05 PM Bug #6883 (Confirmed): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
-
12:02 PM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- I ran some tests and can confirm the issue on 2.4 only.
2.3.3 and 2.4 run the same version of OpenVPN and have ide... -
11:41 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- when i try to connect to pfsense web interface, there is block entry in firewall log:
lo0 10.10.111.231:81 _(pfsen... -
08:32 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- dev ovpns7
verb 1
dev-type tun
dev-node /dev/tun7
writepid /var/run/openvpn_server7.pid
#user nobody
#group nob... -
08:15 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- Still not enough info. Need to know all settings all the way down the page, especially the topology type. Would also ...
-
07:57 AM Bug #6883: OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- it works on 2.3.*
i installed 2.4, and restored config from 2.3.3
openvpn server UDP/TUN
Server mode - Remote Ac... -
07:11 AM Bug #6883 (Feedback): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- Unless this was a working configuration on a previous version, it's more likely to be a configuration error. There is...
-
05:11 AM Bug #6883 (Resolved): OpenVPN puts subnet on lo0 on FreeBSD 11, breaks in certain cases
- openvpn - UDP/TUN (TAP works)
clients connect to server, in the logs everything is fine, but no access anywhere.
wi... -
10:22 AM Bug #4723 (Feedback): Can't forward UDP fragmented packets with scrubbing enabled.
- I tested the forwarding of fragmented ICMP and UDP packets and they seem to be working as expected on 2.4.
Could s... -
10:19 AM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
- Remko Lodder wrote:
> Chris Buechler wrote:
> > I hit this issue with a customer last week. Worked fine after disab... -
04:35 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- This is a workaround, not a clean solution.
Better than nothing, but a native, specific and definitive resolution is...
10/31/2016
-
09:04 PM Revision 9d29322d: Do not attempt to remove interfaces from CP zone, captiveportal_configure_zone() will take care of it
-
08:31 PM Revision 0b8b5069: Check if pidfile is valid before try to send signal
-
03:36 PM pfSense Packages Bug #5868 (Confirmed): Quagga OSPF Priority value "0" (zero) is being ignored - DR election doesnt work properly.
- Looks like it's a classic case of PHP returning "true" for empty() when passed a string of "0". I'll look into it.
-
03:15 PM Bug #6882 (Resolved): bsnmpd uses all available CPU with hostres module active in some cases
- Running 2.4, bsnmpd will consume all available CPU time when the hostres module is active. The CPU usage for geom als...
-
12:19 PM Bug #4723: Can't forward UDP fragmented packets with scrubbing enabled.
- Remko Lodder wrote:
> Chris Buechler wrote:
> > I hit this issue with a customer last week. Worked fine after disab... -
10:04 AM Bug #6856: "Force Config Settings" buton on master causes slave to loss IP alises on lo0
- Confirmed in 2.2.6 and 2.3.2_1 64bit.
-
07:12 AM Feature #6881 (Duplicate): services_unbound_host_edit.php: DNS Resolver Add V4 and V6 host override at the same time
- Is there any chance of changing the setup of the Edit Host Overide page so you can add IPv4 and IPv6 addresses for th...
10/30/2016
-
01:08 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
- So far I am happy with 2.4 running on ZFS, even it highly experimental, I use on one non so critical production firew...
10/29/2016
-
10:12 PM Revision e8517c7c: interfaces, show error message if adding duplicate gateway
-
10:08 PM Revision 33927941: ipsec mobile clients, don't check mobile leases if mobile client isn't enabled to begin with
-
07:50 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
Solution
fix Limiters on firewall rules where NAT applies drop all traffic
and
Problem Limiter blocks in...-
05:31 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- Also affected... is there any plan to fix this in an upcoming release as it's a common use case
-
04:03 AM Bug #6340: fsck hangs boot in background, fails to produce any action, resulting in broken firewall
- Managed to completely destruct entire system by a _single_ power cycle. Unbootable, kernel panic, endless reboot cycl...
10/28/2016
-
08:17 PM Bug #6880 (Resolved): Multiple DHCP6 WAN connections leads to multiple dhcp6c clients
- When configuring multiple interfaces as DHCP6, such as PPPoE DSL and Cable, multiple dhcp6c processes get started, on...
-
05:47 PM Revision 393c1317: Always create a pipe for each allowed MAC or IP
-
05:44 PM Revision aab966f2: host_ips tables is not supposed to use pipes
-
03:11 PM Bug #6879 (Resolved): GUI doesn't show rebooting notification after upgrading
- During upgrade to the latest version, GUI doesn't update fast enough and does not write a rebooting notification. To ...
-
06:18 AM pfSense Packages Bug #6875: dpinger not switching icmp id automatically
- Luiz Otavio O Souza wrote:
> This is the same behaviour of ping (the icmp_id comes from the PID).
>
> So, when yo... -
12:52 AM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
- So far the only thing I got from Martin was that -9 is not a nice way to stop quagga and could cause the issues... Al...
10/27/2016
-
05:26 PM Revision aa9cf3fa: Fix #6758
- extensions.ini must be readable by any users otherwise any php script
called by a non-root user will not be able to u... -
12:57 PM pfSense Packages Bug #6878 (Resolved): how to use snort, squid and squid_guard with a ram disk
- create 2 directories in /root
mkdir /root/sauv_db_clamav/
mkdir /root/sauv_db_squidGuard/
you need to create a f... -
12:40 PM Bug #6758 (Feedback): 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
- Applied in changeset commit:aa9cf3fa4d532e9f2dbd05d38ca438980b21e06b.
-
12:37 PM Bug #6686 (Resolved): PHP extensions.ini cannot be read by non root users
-
09:33 AM Revision fc0e31d7: Import a patch to fix Net_IPv6::compress("::")
- Obtained from: https://github.com/phil-davis/Net_IPv6/commit/638b96a253164b65c63825c38e79812b6c5f448d
Submitted by: ... -
09:32 AM Revision f5febd77: Import a patch to fix Net_IPv6::compress("::")
- Obtained from: https://github.com/phil-davis/Net_IPv6/commit/638b96a253164b65c63825c38e79812b6c5f448d
Submitted by: ...
10/26/2016
-
10:59 PM Revision 013110a1: 80 character lines ftw :)
- Just because it was asked nicely :)
-
10:12 PM Revision 97eebb23: coding layout fix
-
10:11 PM Revision c7e31e37: remove gettext() not needed
-
10:09 PM Revision fa16b2f9: add gettext() to icmptype descriptions
-
06:17 PM Revision 3e80d64e: Make sure we consume staging packages on build process after pfSense-repo became a package
-
06:16 PM Revision c497ae1d: Make sure we consume staging packages on build process after pfSense-repo became a package
-
06:16 PM Revision a014cf62: Make sure we consume staging packages on build process after pfSense-repo became a package
-
05:07 PM Revision 349b2102: ARM kernel is not compressed, deal with that
-
02:37 PM Bug #6802: GUI does not respond and vpn stops working
- I too have seen this issue.
I bought a new newgate sg2440 running 2.3.2_1 and 1 week ago I used it to replace my o... -
09:03 AM Bug #6877: nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
- That means nothing to how it's used on pfSense. One of the primary uses of certificates on pfSense is OpenVPN, and Op...
-
08:41 AM Bug #6877: nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
- OK. However, let me point out that, according to https://www.openssl.org/docs/manmaster/apps/x509v3_config.html, the ...
-
08:28 AM Bug #6877 (Rejected): nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
- Those are both authentication attributes, not the server property.
The GUI checks the cert to see if the nsCertTyp... -
08:23 AM Bug #6877 (Resolved): nsCertType "Server" property of a certificate is not detected if additional nsCertType flags are also set
- Using a GoDaddy server certificate. The server has both TLS Web Server Authentication and TLS Web Client Authenticati...
10/25/2016
-
06:33 PM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
- Note: This fix has been applied to RELENG_2_3 to fix the issue on FreeBSD 10.3/pfSense 2.3.*
In FreeBSD 11.0 (upco... -
10:40 AM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
- Applied in changeset commit:ed893ee55a248bea3a03d69a7e80b905a39a4f94.
-
10:29 AM Bug #6869 (Feedback): Diagnostics / Routes Truncates Destination and Gateway Names
- PR has been merged, thanks!
- 03:56 PM Revision e37ecea9: Improve IPv4 address validation for services_dhcp
- The input pattern that goes with Form_IpAddress by default allows for IPv4 and IPv6 valid characters. The back-end va...
-
03:55 PM Revision 892d8816: Merge pull request #3201 from phil-davis/patch-3
-
03:49 PM Revision b6417760: dyndns: add header processing in curl
- some dyndns implementations rely on the correct HTTP header being set. the information was lost and now fixed.
-
03:47 PM Revision 0e0f580d: dyndns: add header processing in curl
- some dyndns implementations rely on the correct HTTP header being set. the information was lost and now fixed.
-
03:42 PM Revision f85a1e53: Merge pull request #3192 from PiBa-NL/xmlrpc-auth
- 03:38 PM Revision bddeb146: Fix display advanced after input error for system_gateways_edit
- Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo... - 03:38 PM Revision 06493ae0: Fix display advanced after input error for system_gateways_edit
- Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo... -
03:37 PM Revision 1ace41be: Merge pull request #3200 from phil-davis/patch-2
- 03:35 PM Revision 7f798f24: Better handle no dhcpv6 leases file
- (cherry picked from commit 2355c154b7598f937ba2121429659f5676ce4d96)
- 03:34 PM Revision 3e598cc9: Better handle no dhcpv6 leases file
- (cherry picked from commit 2355c154b7598f937ba2121429659f5676ce4d96)
-
03:34 PM Revision bc6cefb7: Merge pull request #3197 from phil-davis/dhcp6
-
03:26 PM Revision 2674bfad: Merge pull request #3204 from phil-davis/patch-6
- 03:25 PM Revision 0b1715e9: Fix #6872 CP bandwidth 0 is no valid
- The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit.
(cherry pick... - 03:25 PM Revision 4f131b02: Fix #6872 CP bandwidth 0 is no valid
- The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit.
(cherry pick... -
03:25 PM Revision 4a1dc683: Merge pull request #3205 from phil-davis/patch-7
-
11:06 AM Revision 99a537e1: Make sure filterdns is disabled when CP zone is disabled
-
10:49 AM Bug #6874 (Feedback): Dynamic DNS w/ DNSimple
- PR has been merged, thanks!
-
10:35 AM Bug #6717 (Feedback): Status / DHCPv6 Leases Issues
- PR has been merged, thanks!
-
10:28 AM Bug #6872 (Feedback): Captive Portal per user bandwidth field no longer accepts 0.
- PR has been merged
-
08:15 AM Bug #6876 (Resolved): Firewall alias issue after adding a wrong alias
***** ALREADY POSTED ON FORUM : https://forum.pfsense.org/index.php?topic=119811.msg662795#msg662795 **************...-
05:20 AM Feature #1219: Ship DTRACE enabled kernels in the images
- +100500
Please, implement! -
01:22 AM Revision 9945720f: Fix the ipfw rule to use the table cp_ifaces and not the interface cp_ifaces.
10/24/2016
-
09:26 PM Revision a4aebf44: Stop using -y on filterdns call
-
09:22 PM Revision 517b893e: Rework captive portal to run with stock IPFW (round 1)
- - Remove use of IPFW context
- Create a rule that will skip to proper rule for each cp zone
- Use new PHP module func... - 09:09 PM Revision 6344be46: REmove accidental text
- 09:08 PM Revision 2c38c5de: Remove accidental code
-
05:48 PM Bug #6272: Wrong numbers in state column of /firewall_rules.php
- Ok thanks for the explanation
-
05:44 PM Bug #6272: Wrong numbers in state column of /firewall_rules.php
- RELENG_2_3 is the development path towards (a possible) 2.3.3. It should therefore be fixed in recent builds of 2.3.3...
-
03:03 AM Bug #6272: Wrong numbers in state column of /firewall_rules.php
- Hi, by "RELENG_2_3" do you mean this should be already fixed in current stable 2.3.2-RELEASE-p1 ? Because the problem...
-
05:35 PM Bug #6874: Dynamic DNS w/ DNSimple
- I stumbled on to the same problem just now when implementing a new dyndns provider.
The code was wrong for both the ... -
01:34 AM Bug #6874 (Resolved): Dynamic DNS w/ DNSimple
- Around line 1380 in src/etc/inc/dyndns.class is a chunk of code that looks like this:...
- 03:46 PM Revision 3a5a205d: Revise login hostname dispaly
- 03:44 PM Revision c1077a75: Revert "Allow login hostname to be controlled via system.php"
- This reverts commit cd6b99147a673b6bd0313fff55cab7eb6879608f.
- 03:42 PM Revision cd6b9914: Allow login hostname to be controlled via system.php
- 03:37 PM Revision dd56aa5d: Added hostname to login page.
- Option control required
(cherry picked from commit 616724395ae00a74fac4cf960ac2261b486e9dae) - 03:36 PM Revision 506fe755: Provide conrol on system.php to allow display of hostname on login banner
- (cherry picked from commit a22947a4980a9f8beb294d6bad039495164ff1aa)
- 03:30 PM Revision a22947a4: Provide conrol on system.php to allow display of hostname on login banner
- 03:06 PM Revision 61672439: Added hostname to login page.
- Option control required
-
02:18 PM pfSense Packages Bug #6875: dpinger not switching icmp id automatically
- This is the same behaviour of ping (the icmp_id comes from the PID).
So, when you have an issue with your ISP ping... -
11:46 AM pfSense Packages Bug #6875 (Not a Bug): dpinger not switching icmp id automatically
- I'm having a problem with dpinger that's not switching ICMP id when there's packet loss, for example in a CGNAT scena...
-
07:59 AM Bug #6870 (Closed): Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
- @relayd@ is a part of the FreeBSD ports tree. It's not a piece of software that pfSense has ported or maintained. You...
-
07:50 AM pfSense Packages Bug #6871 (Not a Bug): Squid Proxy Reports bug
-
04:16 AM Bug #6223: IPsec + OpenBGPD fails with "PF_KEY socket: No buffer space available"
- I can word in on this, major issue.
-
04:11 AM Revision 71bb3f01: Update the variable with the round() return otherwise it does not has any effect.
- Found while testing Ticket #6272.
(cherry picked from commit 92130da3b5fb55588d351c22042c9ce8ab5883d7) -
04:09 AM Revision 92130da3: Update the variable with the round() return otherwise it does not has any effect.
- Found while testing Ticket #6272.
- 12:32 AM Revision b7f2ebb5: Fix #6872 CP bandwidth 0 is no valid
- The front-end validation prevents zero from being entered. "Leave empty" is the way to specify no limit.
10/23/2016
-
11:58 PM Bug #5317: CSR signed certificates shows issuer as external
- Seeing this as well, quite problematic for VPN usage. pfSense 2.3.2-RELEASE-p1.
-
11:33 PM Bug #6272 (Resolved): Wrong numbers in state column of /firewall_rules.php
- Fixed on 2.4 and RELENG_2_3.
pfSense_get_pf_states() now return the packet counters as doubles. -
07:34 PM Bug #6872: Captive Portal per user bandwidth field no longer accepts 0.
- The front-end validation is stopping a zero from being entered, so "Leave empty" is the (only) way to specify "no lim...
-
11:00 AM Bug #6872 (Resolved): Captive Portal per user bandwidth field no longer accepts 0.
- The text says "Leave empty or set to 0 for no limit." However input error checking in the browser now no-longer allow...
-
03:05 PM Bug #6873 (New): radvd - Too many addresses in RDNSS section when previously using DHCPv6
- I have come across a bug within the IPv6 Router Advertising Daemon where you receive the following errors in the logs...
-
03:03 PM Feature #4259: Port forward NAT rules with "any" protocol
- Could be it implemented with the new 2.4 release ?
-
10:14 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
- Turns out causing pfsense to not drop fragmented 'do not fragment' packets creates more problems than it solves. For...
10/22/2016
-
12:25 PM pfSense Packages Bug #6871: Squid Proxy Reports bug
- I'm sorry but I'm a fool ... is necessarily open ports on your firewall application ( ports 7445 and 3000)
ALL OK -
05:28 AM pfSense Packages Bug #6871 (Not a Bug): Squid Proxy Reports bug
Installed from scratch pfsense, Proxy Server, Squid Proxy Reports.
If you try to access the page https: // pfSen...-
10:07 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
- To be clear:
The workaround for relayd / DNS protocol failing or being seemingly intermittent when load balancing... -
10:04 AM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
Update: dig and other dns query engines set the DF 'do not fragment' bit -- then go on to issue DNSSEC DNS querie...- 05:31 AM Revision ed893ee5: Fix #6869 diag_routes resolve names for RELENG_2_3
- This code to parse the netstat output and use gethostbyaddr() to reverse resolve names is only needed in RELENG_2_3, ...
10/21/2016
-
08:15 PM Revision 8fc25403: Revert "Revert "Enable IPFW on PHP module""
- This reverts commit 9fdd0c7ebb966df9b566acac091390c4a97fa8c7.
-
03:29 PM Bug #6870: Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
- Unlikely we can do much if anything for this, it's probably an issue in relayd itself and not the way we set it up. Y...
-
03:25 PM Bug #6870 (Closed): Load balancer DNS (relayd) can't handle fragmented udp, breaks DNSSEC
- The built-in load balancer (relayd) has a protocol 'dns' that manages UDP dns queries. The purpose is to load balanc...
-
11:32 AM Revision 9fdd0c7e: Revert "Enable IPFW on PHP module"
- This reverts commit c04887d8fc440e769ed987f993d34bc8f20fbf64.
-
10:02 AM Bug #6863: pf states reset by CARP neighbor
- Jim, thanks for your explanation! This what I'm trying to detect - what exactly clearing the states. I know, Redmine ...
-
09:50 AM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
- Discussion: https://forum.pfsense.org/index.php?topic=118679.0
10/20/2016
-
09:23 PM Bug #6869: Diagnostics / Routes Truncates Destination and Gateway Names
- That is a "feature" of the netstat command, which has annoyed me too. With "-W" it does output the full data in some ...
-
12:58 PM Bug #6869 (Resolved): Diagnostics / Routes Truncates Destination and Gateway Names
- When "resolve names" is enabled, resolved destination and gateway names are truncated to 18 characters (e.g., pfSense...
-
05:50 PM Revision c04887d8: Enable IPFW on PHP module
-
12:34 PM Bug #6868 (Resolved): Interface MTU Setting not applied to all IPv6 routes
- Running 2.3.2_1 using an HE/64 tunnel. Adjusting MTU to troubleshoot possible PMTUD problem. Found that setting for M...
-
10:47 AM Bug #4326: Limiters on firewall rules where NAT applies drop all traffic
- I also use limiters and NAT reflection in combination. So I am stuck on 2.1.4 and 2.1.5 until a release where this co...
-
09:50 AM pfSense Packages Bug #6129: zabbix agent/proxy 2.4 not ported to pfSense 2.3
- Is there any way i can help with this. Or is there anything i can do to make this happen?
-
08:35 AM Bug #4031: Notifications mail bomb in some gateway failure circumstances
- Looking at a customer box today it made me realize a good path here would be to queue up the notifications in a file ...
-
08:09 AM pfSense Packages Bug #6867 (Closed): Please update quagga to version 1.1
- Quagga 1.1 fixes a lot of bugs:
http://mirror.yannic-bonenberger.com/nongnu/quagga/quagga-1.1.0.changelog.txt
N... - 08:04 AM Revision eb01f065: Improve IPv4 address validation for services_dhcp
- The input pattern that goes with Form_IpAddress by default allows for IPv4 and IPv6 valid characters. The back-end va...
- 07:18 AM Revision ebfcfeb5: Fix display advanced after input error for system_gateways_edit
- Use case:
1) Edit a gateway that has no advanced settings (i.e. the Advanced section does not need to open on page lo... -
05:48 AM Revision c982fdbc: Fix is_macaddr().
- Hexadecimal numbers without the '0' padding are also valid, e.g:
a:b:c:d:e:f - 05:47 AM Revision 6a546985: Remove "use lowercase" hint
- As it is no longer relevant, because the code now automatically converts
to lowercase. - 04:21 AM Revision d461ff40: Fix #6864 automatically convert IPv6 input to lowercase
- 1) As the user leaves the field, or presses Save, onChange will fire and
convert the input string to lowercase. This ...
10/19/2016
-
11:24 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
- This one also automatically converts the input to lowercase as the user leaves the IP Address field, or presses a but...
-
11:18 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
- While I think it is cool to convert the characters as you type, the GUI has to accept upper case letters as well.
... -
10:18 PM Bug #6864: Error checking rejects IPv6 addresses with upper case A-F.
- Pull request: https://github.com/pfsense/pfsense/pull/3198
That makes the "Please match the requested format:" text ... -
09:20 AM Bug #6864 (Resolved): Error checking rejects IPv6 addresses with upper case A-F.
- Recent browser changes mean this is rejected before the form is submitted and the error tool tip shown is unhelpful.
... -
05:38 PM Bug #6717: Status / DHCPv6 Leases Issues
- I can confirm that this fixes the issue where the file exists but contains no leases. The lease file is still being p...
-
04:30 PM pfSense Packages Feature #6866 (Rejected): Suricata multiple interfaces
- I've set up Suricata on the WAN interface. When an alert happen I don't see what internal address caused the alert. I...
-
03:14 PM Bug #6865 (Rejected): DNS resolver : old issue returns
- Please start a forum thread for discussion and diagnosis before opening a ticket. Also, upgrade to 2.3.2_1 first to e...
-
03:11 PM Bug #6865 (Rejected): DNS resolver : old issue returns
- 2.3.2-RELEASE (i386)
built on Tue Jul 19 13:09:39 CDT 2016
FreeBSD 10.3-RELEASE-p5
nanobsd (4g)
When trying to... -
12:49 PM Feature #2358: NAT64 support
- Too late for 2.4.0...
-
04:39 AM Feature #2358: NAT64 support
- UPVOTE
-
02:16 AM Feature #2358: NAT64 support
- UPVOTE, word up on this. It should be prioritized significantly.
-
08:32 AM Bug #6863 (Rejected): pf states reset by CARP neighbor
- That is normal and expected when the two units are properly synchronizing states. Find what is clearing the states an...
- 02:43 AM Revision 2355c154: Better handle no dhcpv6 leases file
10/18/2016
-
09:53 PM Bug #6717: Status / DHCPv6 Leases Issues
- https://github.com/pfsense/pfsense/pull/3197
That fixes the little side issue, where in fact the leases file exists ... -
04:31 PM Bug #6717: Status / DHCPv6 Leases Issues
- With regards to item 1, testing with one windows 10 client and no active leases, Status / DHCPv6 Leases reports "No l...
-
01:20 PM Bug #6862: mode 0444 for /var/etc/cert.crt leads to nginx crit error: 13: Permission denied
- title should have had protection of 0600, workaround changes it to 0644
-
11:23 AM Bug #6862 (Resolved): mode 0444 for /var/etc/cert.crt leads to nginx crit error: 13: Permission denied
- /var/etc/cert.crt has mode 0444, leading to
/var/log/nginx-error.log entries like
2016/10/16 16:06:14 [crit] 61476#... -
01:01 PM Revision 94bd7fb3: Fix #6828
- Until 2.3.x pfSense carried a patch that changed the behavior of 'route
change' command, making it add the route when... -
12:30 PM Bug #6863 (Rejected): pf states reset by CARP neighbor
- There are two pfsense routers (version 2.3.2-RELEASE-p1, but I've faced this issue 1st time on 2.2.5/2.2.6) in HA mod...
-
12:24 PM Bug #6758: 2 x Crash with "PHP Fatal error: Call to undefined function pfSense_interface_listget() in /etc/inc/interfaces.inc on line 80"
- I started having this crash frequently as well. I'm running 2.3.2_p1. I do have DHCPv6 on one of my WANs (but I nee...
-
12:04 PM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
- Ken Sim wrote:
> Anytime I try and change any of the gateways that are checked non-local on the current snapshot it ... -
11:43 AM Bug #6850: FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
- Anytime I try and change any of the gateways that are checked non-local on the current snapshot it locks up pfsense a...
-
08:35 AM Bug #6850 (Feedback): FreeBSD 11.0 Route Syntax Change For Non-Local Gateway
- I couldn't replicate it after fixes I pushed for #6828. Can you try the next round of snapshots?
-
11:16 AM Bug #6858: 2.3.X is not properly updating packages
- Renato, thank you for the write up.
Does this cover file /usr/local/lib/php/20131226/suhosin.so? This shared objec... -
05:16 AM Bug #6858 (Not a Bug): 2.3.X is not properly updating packages
- Actually it's not a bug, it's expected and it's how pkg is designed to work.
When we moved to 2.3.2_1 we cherry-pi... -
08:10 AM Bug #6828 (Feedback): Patch for "route change" is not present on 2.4 builds using FreeBSD 11
- Applied in changeset commit:94bd7fb3a52e375dcd25c416e36389f96060a8fd.
-
07:46 AM pfSense Packages Bug #6861 (New): Ha-Proxy duplicated backend used in place of original backend
- Hello,
Find hereafter a problem on ha-proxy 0.48 / 1.6.6 package.
Steps to reproduce :
- Create a configurati...
10/17/2016
-
04:01 PM Bug #6860 (Resolved): Monitoring (RRD) graphs return "unknown" step value
- There seem to be cases where rrd_fetch_json.php returns a step value that isn't located in the javascript lookup tabl...
-
12:56 PM pfSense Packages Feature #6859 (Resolved): have an includedir by default (sudo package)
- I'm trying to customize sudo and the options I'm looking for aren't in the GUI. Is there a way to include this line i...
-
04:33 AM Bug #6099: igmpproxy does not recognize upstream interface
- I have the same problem with the 20160905_1818 version.
The _all version works fine on ISP XS4All in The Netherlands... -
03:14 AM Feature #2573: Captive Portal support of RADIUS POD (Packet of Disconnect)
- POD is useful when replacing Expiration date in Pfsense user manager.
The Option " re-authenticate users every minu... -
12:10 AM Bug #6858 (Not a Bug): 2.3.X is not properly updating packages
- 2.3.X is not updating files properly. See forum thread https://forum.pfsense.org/index.php?topic=119344.msg662359#msg...
10/16/2016
-
10:37 PM Bug #5413: Reduce disruptions when changing DNS records from DHCP leases in Unbound
- The patch you posted only prevents Unbound from being restarted by performing GUI actions, not automatically when a n...
-
10:50 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
- Note this potentially related bug report:
https://github.com/opnsense/core/issues/1184
"
Adding an IPv6 CARP V... -
10:47 AM Bug #6579: IPv6 CARP VIPs lost upon config sync where they include non-significant zeros
- The issue manifests as the 'backup' machine in the carp set being unable to ping6 (or otherwise pass packets to) the ...
-
01:08 AM Bug #6779: Traffic shaper wizard uses decimals instead of whole numbers
- It would be good to make target version 2.4 instead of nothing. Thanks.
10/15/2016
-
11:16 PM Bug #6856: "Force Config Settings" buton on master causes slave to loss IP alises on lo0
- Sent pull-request: https://github.com/pfsense/pfsense/pull/3195
-
12:08 PM Bug #6856 (Duplicate): "Force Config Settings" buton on master causes slave to loss IP alises on lo0
- Hi,
We have a two couple of node HA setup with pfsense latests version running (2.3.2p1). This cluster has a few v... -
10:07 PM Bug #6857: local_sync_accounts fails during boot when using ldap on a non-local network or hostname
- I've just sent a pull-req: https://github.com/pfsense/pfsense/pull/3194
-
08:54 PM Bug #6857 (Resolved): local_sync_accounts fails during boot when using ldap on a non-local network or hostname
- Hi,
When using an LDAP server on a non-local (ie. accesible thru a gateway) network, the system takes 10+ minutes ... -
03:06 PM Revision b77a6394: increase webgui usability when the remote ldap server isn't available
-
03:04 PM Revision ae346354: php fatal error logging
-
02:58 PM Revision dc5f639f: xmlrpc, use authentication through the basic auth header instead of extra user/pass parameters
10/14/2016
- 11:29 PM Revision d672403c: Added STARTTLS to LDAP Auth Server Config
-
06:53 PM Feature #6855 (Resolved): Support STARTTLS in LDAP Server Configuration
- Add STARTTLS to the available LDAP Server modes.
-
02:32 PM Bug #6854 (Rejected): webconfig error with LDAP authenticated users for certmgr
- The local admin user is the only user that can successfully work with certificates.
Other users authenticating off o... -
02:04 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
- Nate Baker wrote:
> Jim Pingle wrote:
> > Someone who can reproduce it reliably needs to get the details of how to ... -
12:56 PM pfSense Packages Bug #6305: Quagga problems updating routes / mistakenly showing "kernel"-routes while they are not
- Jim Pingle wrote:
> Someone who can reproduce it reliably needs to get the details of how to reproduce it reported t... -
12:15 PM Bug #4418: IPsec mobile clients - bogus "p" appended to search domain
Also I am having the same problem in versãoo 2.3.2-RELEASE-p1. For some in the forum saw what worked the Place hum ...-
12:05 PM Revision 80762aaa: Make setup_serial_port() write config files safely
- This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po... -
12:05 PM Revision 1a6cb937: Change safe_write_file $content parameter to accept an array
-
12:05 PM Revision a942d5b2: Make $force_binary parameter optional, default to false
-
12:05 PM Revision 72ca7e40: Prevent /etc/ttys to miss essential lines
- We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason... -
12:04 PM Revision 6172f3de: Make setup_serial_port() write config files safely
- This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po... -
11:51 AM Revision 406ced77: Change safe_write_file $content parameter to accept an array
-
11:51 AM Revision e717f161: Make $force_binary parameter optional, default to false
-
11:51 AM Revision 237d29c4: Prevent /etc/ttys to miss essential lines
- We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason... -
11:49 AM Revision 4e3bf4aa: Make setup_serial_port() write config files safely
- This function used to replace /boot.conf, /boot/loader.conf and
/etc/ttys on every call. Depending of the moment a po... -
11:49 AM Revision 952ff2cb: Change safe_write_file $content parameter to accept an array
-
11:49 AM Revision e9c60f20: Make $force_binary parameter optional, default to false
-
11:49 AM Revision 7fa3bcae: Prevent /etc/ttys to miss essential lines
- We do not create /etc/ttys from scratch but we change it on every boot.
If original file is corrupted for some reason...
10/13/2016
-
08:49 PM Bug #6717: Status / DHCPv6 Leases Issues
- Phillip Davis wrote:
> As part of removing nanobsd support, it was noticed that dhcp6 leases were not being restored... -
06:17 PM Bug #6717: Status / DHCPv6 Leases Issues
- As part of removing nanobsd support, it was noticed that dhcp6 leases were not being restored on systems with use_mfs...
-
03:47 PM Bug #6717: Status / DHCPv6 Leases Issues
- Daryl Morse wrote:
> I'm running 2.3.3.a.20160815.2144 with PR 3102/1, 3102/2, 3103, 3105, 3106 and 3107, testing th... -
04:36 PM Bug #6099: igmpproxy does not recognize upstream interface
- I have the same issue like Dora Paule with the version: igmpproxy_20160905_1818.zip
There is no such problem with t... -
03:51 PM Bug #5993: dhcp6c not started until an RA received
- Updating this issue based on 2.4 development snapshot.
The dhcp6 before RA feature has been working perfectly sinc... -
03:08 PM Revision a4cd0c5f: Fix up help text on outbound NAT.
-
03:08 PM Revision b533da85: Fix up help text on outbound NAT.
-
02:43 PM Revision 3d69cce5: Clarify source port warning when editing a firewall rule.
-
02:42 PM Revision 7ea6dabe: Clarify source port warning when editing a firewall rule.
-
02:21 PM Revision 00fc1317: In the setup wizard, do not change the DHCP range if it is already set inside the new subnet. Otherwise it will overwrite a range set manually from the DHCP settings or the console when the wizard is run later. Fixes #4820
-
02:21 PM Revision d02ee138: In the setup wizard, do not change the DHCP range if it is already set inside the new subnet. Otherwise it will overwrite a range set manually from the DHCP settings or the console when the wizard is run later. Fixes #4820
- 01:39 PM Revision 2329b5a8: DHCPV6 only check VIPs in range if range valid
- If the user has input invalid values into range from and to, then there
is no point checking any IPv6 VIPs to see if ... -
01:39 PM Revision 77179b26: Merge pull request #3190 from phil-davis/dhcpv6
-
01:38 PM Revision 004b752e: Add extra validations on is_inrange_v[46]
- Verify if addresses are valid IP address before convert them to make
numeric comparison.
While here, adjust indent.
... -
01:36 PM Revision 8c48089f: Add extra validations on is_inrange_v[46]
- Verify if addresses are valid IP address before convert them to make
numeric comparison.
While here, adjust indent.
... -
01:25 PM Revision ef30fa51: Replace underscore with hyphen in option names
- Thanks Jorge
(cherry picked from commit 30786a9d2486d88cb92cbb0ecb10586b39c32c65) -
01:25 PM Revision 8e4af832: Merge pull request #3188 from NOYB/GitSync_Min_Diff_Combo
- 01:24 PM Revision b4415260: Make unlink_if_exists return true/false
- This allows the caller to do a single "atomic" call to unlink_if_exists.
If it returns true, then they know that the ... -
01:24 PM Revision bd9e1327: Merge pull request #3186 from phil-davis/unlink_if_exists
-
01:20 PM Revision e90ca528: Restore dhcp6 leases on full install when using MFS /tmp. While here, fix indent
-
01:15 PM Revision 42ebf952: Restore accidentally removed block
- On dc61252ae the code used to restore dhcp6 leases when platform was
nanobsd was removed, but this code is supposed t... - 12:48 PM Revision a5562d72: Remove commented code
- (cherry picked from commit 0186b761e05d6f707ddc9cf1898d20ffb7ef9405)
- 12:48 PM Revision 40ce5d72: Bring up the wifi interface only after setting up all the other arguments. This prevents issues when using VAPs.
- (cherry picked from commit 6416317a239e082b7702957263a51b4052ae43b5)
-
12:48 PM Revision b76b52ae: Merge pull request #3180 from valneacsu/fix_wifi_1st_VAP_params
-
09:30 AM Bug #4820 (Feedback): DHCP Scope at setup
- Applied in changeset commit:d02ee1387fdb159bfb7cb9495003f66545d97989.
-
09:13 AM Bug #4820 (Assigned): DHCP Scope at setup
- What appears to happen is that the wizard resets the range even if the existing range is valid. So if you have x.x.x....
- 02:22 AM Revision 3707ffc4: DHCPV6 only check VIPs in range if range valid
- If the user has input invalid values into range from and to, then there
is no point checking any IPv6 VIPs to see if ... -
01:51 AM Revision 30786a9d: Replace underscore with hyphen in option names
- Thanks Jorge
- 01:31 AM Revision d96a39ba: Make unlink_if_exists return true/false
- This allows the caller to do a single "atomic" call to unlink_if_exists.
If it returns true, then they know that the ...
10/12/2016
- 08:38 PM Revision 0186b761: Remove commented code
-
07:30 PM Revision 4b65536a: Update pot
-
07:29 PM Revision dc61252a: Deprecate nanobsd platform and remove all conditionals that uses it
-
07:23 PM Revision 9ed7f8f6: Retire rc.nanobsd_switch_boot_slice
-
07:23 PM Revision 0c2dffb0: Define a single value for 'default_config_backup_count'
-
07:23 PM Revision b55c6b82: Remove unused global var 'hidebackupbeforeupgrade'
-
07:23 PM Revision 1289c0c1: Remove all calls to conf_mount_r* functions
-
07:23 PM Revision eec44c64: Retire restart_httpd.php
-
06:27 PM Revision 60f164f3: Retire cdrom platform support
-
06:12 PM Revision f68a881c: Remove unused global config item 'update_manifest'
-
06:10 PM Revision 3f4a0df9: Remove hideplatform global config and all uses of it
-
06:09 PM Revision 337e6a26: Remove unused global item 'nopkg_platform'
-
06:03 PM Revision a5e59e25: Retire refcount functions. They are not used anymore
-
06:02 PM Revision 9f08c2b0: Retire diag_nanobsd.php
-
05:59 PM Revision ffab5cb4: Obsolete conf_mount_ro() and conf_mount_rw()
- Now that nanobsd is gone these functions are not necessary anymore.
Keep them around until all calls are cleaned up - 04:20 PM Revision 87fb4454: Allow Hyphens in DHCP NTP Server form validation
- Also removes the ability to have underscores `_` in ntp server
FQDNs.
Closes #6806
(cherry picked from commit c68db... -
04:20 PM Revision dd3d6c8a: Merge pull request #3151 from EdHurtig/eng/6806
-
04:18 PM Revision ab4d9c9b: Format file_notice alerts in webgui with newline characters as <br/> for easier reading.
- (cherry picked from commit 348fae16e4c4735afef619184fba76b97effd875)
-
04:18 PM Revision bc0a0c2e: Merge pull request #3154 from PiBa-NL/filenoticeBR
-
04:15 PM Revision ebcb7042: Simplify tcsh prompt and respect default terminal colors
-
04:15 PM Revision 4e04d896: Simplify tcsh prompt and respect default terminal colors
-
04:02 PM Bug #6828: Patch for "route change" is not present on 2.4 builds using FreeBSD 11
- Jim Pingle wrote:
> On 2.3 we have a patch to alter the behavior of "route change" so that it adds a route if it's n... -
03:51 PM Revision b9f6e351: lowercasing and sprintf of setHelp
- (cherry picked from commit 705679339705657832422f5fdc336b5e39d48b79)
-
03:51 PM Revision 59db5c43: label src/dst incorrect - fixed (minor)
- (cherry picked from commit a309ffa5cc1e8682bb083f9288f73f43a2a9c282)
-
03:51 PM Revision 9a211d3a: UI improvement - src port button label and src port help msgs
- 1. Rename "srcportadv" to "srcporttoggle" - not ideal to have 2 fields both labelled "advanced options". This present...
-
03:51 PM Revision d8746bc0: Merge pull request #3140 from stilez/patch-39
-
03:49 PM Revision 9a3261c1: Merge pull request #3153 from NewEraCracker/RELENG_2_3_2+
-
03:45 PM Revision c58cdd42: Remove unused arg in get_pkg_info()
- The 2nd argument ($info) isn't used in that function, and doesn't seem to be used anywhere else in the codebase.
(che... -
03:45 PM Revision ceea9d9c: Merge pull request #3156 from stilez/patch-43
-
03:41 PM Revision 53b9a2ac: Report quantity of files being installed by minimal and diff options.
- Also consolidate some unset commands.
(cherry picked from commit 32912ae833a016784cbb4813c45960cefc2d896b) -
03:41 PM Revision b19c8033: Support minimal and diff options combo rather than diff superseding minimal (sync both updated and diff files).
- Break verbose option in two for showing files and/or constructed command. (--show_files, --show_command)
Don't save ... -
03:41 PM Revision f725a312: Merge pull request #3168 from NOYB/GitSync_Min_Diff_Combo
- 03:39 PM Revision 257120b9: Use tabs consistently
- (cherry picked from commit 553de3973dfdb0539a64510666976d523a21f2f9)
- 03:39 PM Revision e11a24f8: Re-enable executing the wifi mode command first. This fixes channel changing, which broke in d325e90818db2b22fc2562c38493769f217230f2.
- (cherry picked from commit 8318da5192905a400076d5539ae86afeae82ee03)
-
03:39 PM Revision 9eab8448: Merge pull request #3169 from valneacsu/fix_wifi_channel_change
-
03:37 PM Revision 9fc8273a: Fixup ntpd IPv6 restrict clauses.
- This should eliminate the following errors from the ntpd log file when
using IPv6 or dual-stack networks:
"syntax err... -
03:37 PM Revision 836bb622: Fixup ntpd IPv6 restrict clauses.
- This should eliminate the following errors from the ntpd log file when
using IPv6 or dual-stack networks:
"syntax err... -
03:37 PM Revision ec6e6666: Merge pull request #3171 from phroggster/patch-2
-
03:33 PM Revision 66ee91c2: add array index how value for authserver list
- (cherry picked from commit db0c1e142c98a6253204d69218557b91a8754337)
-
03:33 PM Revision 83f7fabd: Merge pull request #3177 from brunostein/fix_authmode_translated
- 03:30 PM Revision 74dd2936: Only configure wireless MAC address if a spoofed MAC address is set
- (cherry picked from commit a6c4a66da2ee8b0d4d54480dd690700b8c16bb13)
-
03:30 PM Revision 90d0e0e0: Merge pull request #3179 from valneacsu/fix_wifi_settings_overwrite
- 03:22 PM Revision a3a89277: Improve gwlb.inc notification mechanisms
- 1) Unlink earlier to reduce the chances of any concurrency issues;
2) Translate and improve output of available notif... -
03:21 PM Revision 58c0e164: Merge pull request #3184 from NewEraCracker/gwlb-fix
-
03:12 PM Todo #6755 (Resolved): Remove GLXSB references from 2.4
- All gone.
-
03:11 PM Bug #6821 (Resolved): Static ARP attribute not applied when saving a DHCP static mapping
- Works
-
03:06 PM Feature #6822 (Resolved): diag_arp.php: Teach the ARP Table display to also display the status
- Works great
-
03:02 PM Bug #6849 (Resolved): OpenVPN cipher list output changed, breaking the GUI list of ciphers
- Appears to be working correctly on 2.3.3 and 2.4 snapshots.
-
02:49 PM Bug #6739 (Resolved): OpenVPN compression settings in the GUI are no longer translated into the correct running options.
- This seems to be OK now. The comp-noadapt change was confirmed to work on an affected system (remote client had no LZ...
-
02:49 PM Bug #6719 (Resolved): OpenVPN DNS Leak Windows 10
- New options are being pushed correctly when selected.
-
02:48 PM Revision d3007fbe: Remove invalid parameter --flash-size
-
02:34 PM Todo #6853 (Resolved): Convert nanobsd installation to full install during upgrade
- 2.4 doesn't support nanobsd anymore, convert all nanobsd installations to full install during upgrade from 2.3 to 2.4...
- 02:08 PM Revision 54596b88: Improve gwlb.inc notification mechanisms
- 1) Unlink earlier to reduce the chances of any concurrency issues;
2) Translate and improve output of available notif... -
11:44 AM Bug #6650: Option needed to disable HSTS
- Having same issue, all HTTP sites are also broken like the original example. Need option in pfsense to disable HSTS.
-
11:30 AM Bug #6806 (Feedback): Form validation for DHCP NTP Servers does not allow hyphens
- Applied in changeset commit:c68dbfc7580180cd9d47bdbecaeeb6cf835fe210.
- 10:34 AM Revision e01e164c: Backport save_widget_settings with 3 arguments from RELENG_2_3
- Commit 6f1410582412fe771f51bd8b67bcbb952da97db6 introduced code relying on this
Also available in: Atom